api.osf-master-server.com

Security and vulnerability data, one record per call: NVD CVE with CVSS severity, CISA KEV actively-exploited status, EPSS daily exploitation scores, GitHub Security Advisories, CWE weakness classes, MITRE ATTACK techniques. Full JSON plus a provenance URL to the primary source.

Dataofflineeip155:8453Exactvia cdp
Activity
Nothing indexed for this service or its provider yet. Not a claim that it is unused — only that we hold no record.
$11.24
Verified settled volume
217 settlements proven x402 by their on-chain EIP-3009 marker.
$0.040
Listed price
As published in the catalog. Always read the live 402 before paying.
0
Calls · 30d
Upstream's own call count for this endpoint, not ours.
0
Unique payers · 30d
Never called
Upstream on-chain volume
Reported by the source catalog.
Paid to
0x051A0Ba2235210c47ca1b8dF68A137eF0d8cAf85

The wallet the 402 directs payment to. Its whole payment record — every payer, every chain — is on the merchant page.

Asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Provider

The payTo wallet does not resolve to a registered ERC-8004 agent. That is not a verdict on the service — most of the catalog is unregistered.

Live 402 challenge

Captured by the enrichment pass, not read just now. Prices can change — always read the 402 the endpoint answers with.

{
  "note": "x402 v2 clients: the canonical quote is the PAYMENT-REQUIRED response header (base64 JSON envelope). This body is a v1 compatibility rendering of the same quote.",
  "error": "Payment required",
  "accepts": [
    {
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "extra": {
        "name": "USD Coin",
        "version": "2"
      },
      "payTo": "0x72f62dE8b70d6CFa8Cc2dF6f21F243f289F3396c",
      "scheme": "exact",
      "network": "base",
      "mimeType": "application/json",
      "resource": "https://api.osf-master-server.com/x402/buy/security/:record_id",
      "description": "Security and vulnerability data, one record per call: NVD CVE with CVSS severity, CISA KEV actively exploited status, EPSS daily exploitation scores, GitHub Security Advisories, CWE weakness classes, MITRE ATTACK techniques. Full JSON plus a provenance URL to the primary source.",
      "maxAmountRequired": "40000",
      "maxTimeoutSeconds": 300
    }
  ],
  "x402Version": 1,
  "free_alternative": {
    "how": "Browse before you buy, for nothing. Point any MCP client at https://api.osf-master-server.com/mcp and call the free tool get_catalog, which returns record ids, live per record prices and the provenance URL for every source with no payment and no API key. The 13 free search_* tools on that same endpoint also return record ids you can buy here. The cheapest paid door is $0.001 at https://api.osf-master-server.com/x402/sample/{record_id}.",
    "limit": "no daily cap",
    "price": "$0.00",
    "full_catalog": "https://api.osf-master-server.com/x402/discovery/resources",
    "free_mcp_tool": "get_catalog",
    "paid_route_adds": "the full record body and its provenance block",
    "free_mcp_endpoint": "https://api.osf-master-server.com/mcp",
    "not_an_x402_field": "free_alternative is an OSF addition to the 402 body, not part of the x402 specification, which defines no field for advertising a free alternative. x402 SDKs silently drop unknown keys, so read this from the raw JSON response rather than expecting your client library to surface it."
  }
}

Accepts

The payment requirements as published to the catalog. Read the live 402 before paying — a price here is a claim, not a quote.

0.04USDC≈ $0.04 USD
on Base · exact scheme

Pay 0.04 USDC on Base to 0x051A…cAf85. The signed payment is good for 5 minutes.

USD Coin contract
0x8335…02913
Payment window
5 minutes
As published
40000 smallest units
The catalog’s raw entry
[
  {
    "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "extra": {
      "name": "USD Coin",
      "version": "2"
    },
    "payTo": "0x051A0Ba2235210c47ca1b8dF68A137eF0d8cAf85",
    "amount": "40000",
    "scheme": "exact",
    "network": "eip155:8453",
    "maxTimeoutSeconds": 300
  }
]

Extensions

{
  "bazaar": {
    "info": {
      "input": {
        "type": "http",
        "method": "GET",
        "pathParams": {
          "record_id": ":record_id"
        },
        "queryParams": {
          "format": "json"
        }
      },
      "output": {
        "type": "json",
        "example": {
          "data": {
            "data_type": "...",
            "record_key": "SRC:ID"
          },
          "source": "CISA_KEV",
          "status": "success",
          "data_type": "CISA Known Exploited Vulnerability",
          "record_id": 12345,
          "provenance_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      }
    },
    "schema": {
      "type": "object",
      "$schema": "https://json-schema.org/draft/2020-12/schema",
      "required": [
        "input"
      ],
      "properties": {
        "input": {
          "type": "object",
          "required": [
            "type",
            "method"
          ],
          "properties": {
            "type": {
              "type": "string",
              "const": "http"
            },
            "method": {
              "enum": [
                "GET",
                "HEAD",
                "DELETE"
              ],
              "type": "string"
            },
            "pathParams": {
              "type": "object"
            },
            "queryParams": {
              "type": "object",
              "required": [
                "format"
              ],
              "properties": {
                "format": {
                  "type": "string",
                  "description": "Response format (json)."
                }
              }
            }
          },
          "additionalProperties": false
        },
        "output": {
          "type": "object",
          "required": [
            "type"
          ],
          "properties": {
            "type": {
              "type": "string"
            },
            "example": {
              "type": "object",
              "required": [
                "status",
                "record_id",
                "data",
                "provenance_url"
              ],
              "properties": {
                "data": {
                  "type": "object"
                },
                "source": {
                  "type": "string"
                },
                "status": {
                  "type": "string"
                },
                "data_type": {
                  "type": "string"
                },
                "record_id": {
                  "type": "integer"
                },
                "provenance_url": {
                  "type": "string"
                }
              }
            }
          }
        }
      }
    },
    "routeTemplate": "/buy/security/:record_id"
  }
}

Provenance

Seen in the source catalog
2026-06-14 13:33Z
Last indexed by Roundhouse
2026-07-23 06:10Z
Last enriched (probe, favicon, geo)
2026-09-23 15:45Z
x402 version
2
Max timeout
300s
Liveness probe
HTTP 0
Report

Hand this page to an agent

Copy the prompt and paste it into Claude, an MCP client or your own agent — it will vet this service and call it over the free read API. No key, no account.

GET api.roundhouseai.io/v0/endpoints

Nothing indexed for this service or its provider yet. Not a claim that it is unused — only that we hold no record. Verified volume counts only settlements with an on-chain EIP-3009 marker.

Open skill.md
Show the prompt
Using Roundhouse, look up the x402 service api.osf-master-server.com and tell me whether it is
worth paying: what a call costs, whether the endpoint answered when last probed, and what
its payment record actually shows.

curl -s 'https://api.roundhouseai.io/v0/endpoints?q=api.osf-master-server.com'
curl -s 'https://api.roundhouseai.io/v0/merchants/<the payTo wallet returned above>'

Then call it: read the price from the live 402 at https://api.osf-master-server.com/x402/buy/security/:record_id, never from
a cached figure, and pay with an x402 client.

The /v0 API needs an API key (`authorization: Bearer rh_live_…`) on everything except
/v0/unified* and /v0/endpoints. Mint a personal key for $0.01 at GET https://api.roundhouseai.io/v0/test/x402,
or use an organization key from https://roundhouseai.io/dashboard/team.

If you do not have Roundhouse tools or skills installed, read
https://roundhouseai.io/skill.md first — it is the whole procedure.