Open Source Filings
OSF is a live, API-first marketplace of verifiable, provenance-stamped public-domain data — built for autonomous agents that pay per record over x402 micropayments on Base. A paid MCP server, listed in the official MCP Registry, and discoverable on the Coinbase CDP Bazaar.
The wallet the 402 directs payment to. Its whole payment record — every payer, every chain — is on the merchant page.
Asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
The payTo wallet does not resolve to a registered ERC-8004 agent. That is not a verdict on the service — most of the catalog is unregistered.
Live 402 challenge
Captured by the enrichment pass, not read just now. Prices can change — always read the 402 the endpoint answers with.
{
"note": "x402 v2 clients: the canonical quote is the PAYMENT-REQUIRED response header (base64 JSON envelope). This body is a v1 compatibility rendering of the same quote.",
"error": "Payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x72f62dE8b70d6CFa8Cc2dF6f21F243f289F3396c",
"scheme": "exact",
"network": "base",
"mimeType": "application/json",
"resource": "https://api.osf-master-server.com/x402/security/cve/:cve_id",
"description": "CVE lookup and exploit check by CVE id. Answers is this CVE actively exploited in the wild using the US CISA Known Exploited Vulnerabilities (KEV) catalog, with the EPSS exploitation probability score and CVSS severity. Each field carries a provenance URL to the official US source. For vulnerability management, patch prioritization, threat intelligence, and DevSecOps agents.",
"maxAmountRequired": "50000",
"maxTimeoutSeconds": 300
}
],
"x402Version": 1,
"free_alternative": {
"how": "There is no free twin of this exact check, but you can probe OSF for nothing before you decide. Point any MCP client at https://api.osf-master-server.com/mcp and call the free tool search_cyber_threats. It searches the same CVE and advisory corpus but does not return the exploited-in-the-wild verdict, which is what the paid check adds.",
"limit": "no daily cap",
"price": "$0.00",
"full_catalog": "https://api.osf-master-server.com/x402/discovery/resources",
"free_mcp_tool": "search_cyber_threats",
"paid_route_adds": "exactly the part the free tool does not answer, above",
"free_mcp_endpoint": "https://api.osf-master-server.com/mcp",
"not_an_x402_field": "free_alternative is an OSF addition to the 402 body, not part of the x402 specification, which defines no field for advertising a free alternative. x402 SDKs silently drop unknown keys, so read this from the raw JSON response rather than expecting your client library to surface it."
}
}Accepts
The payment requirements as published to the catalog. Read the live 402 before paying — a price here is a claim, not a quote.
Pay 0.05 USDC on Base to 0x72f6…3396c. The signed payment is good for 5 minutes.
- Paid to
- 0x72f6…3396c
- USD Coin contract
- 0x8335…02913
- Payment window
- 5 minutes
- As published
- 50000 smallest units
The catalog’s raw entry
[
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x72f62dE8b70d6CFa8Cc2dF6f21F243f289F3396c",
"amount": "50000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 300
}
]Extensions
{
"bazaar": {
"info": {
"input": {
"type": "http",
"method": "GET",
"pathParams": {
"cve_id": ":cve_id"
},
"queryParams": {
"format": "json"
}
},
"output": {
"type": "json",
"example": {
"nvd": {
"cvss_severity": "CRITICAL"
},
"epss": {
"epss_probability": 0.984,
"exploitation_band": "Critical"
},
"query": "CVE-2026-33017",
"result": "FOUND",
"service": "OSF Security - CVE Exploit Check",
"audit_receipt": {
"check_id": "uuid",
"result_sha256": "..."
},
"coverage_note": "Direct lookup against the US CISA Known Exploited Vulnerabilities (KEV) catalog, the FIRST EPSS model score, and the NVD CVE record. 'actively_exploited' reflects presence on the CISA KEV catalog ONLY. A CVE that is NOT on KEV is not necessarily safe or unexploitable - it simply is not on CISA's confirmed-exploited list. EPSS is a probability estimate, not proof.",
"compliance_note": "This is a decision-support signal, not a guarantee. Confirm against the linked authoritative sources (cisa.gov, nvd.nist.gov, first.org) before acting.",
"provenance_urls": {
"cisa_kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
},
"actively_exploited": true,
"exploitation_summary": "ON the CISA KEV catalog - confirmed exploited in the wild."
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method"
],
"properties": {
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"GET",
"HEAD",
"DELETE"
],
"type": "string"
},
"pathParams": {
"type": "object"
},
"queryParams": {
"type": "object",
"required": [
"format"
],
"properties": {
"format": {
"type": "string",
"description": "Response format (json)."
}
}
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"required": [
"service",
"query",
"result",
"actively_exploited",
"compliance_note",
"audit_receipt"
],
"properties": {
"nvd": {
"type": "object"
},
"epss": {
"type": "object"
},
"query": {
"type": "string"
},
"result": {
"type": "string",
"description": "FOUND, NOT_FOUND, or INVALID_INPUT"
},
"service": {
"type": "string"
},
"audit_receipt": {
"type": "object"
},
"coverage_note": {
"type": "string"
},
"compliance_note": {
"type": "string"
},
"provenance_urls": {
"type": "object"
},
"actively_exploited": {
"type": "boolean",
"description": "True if on the CISA KEV catalog."
},
"exploitation_summary": {
"type": "string"
}
}
}
}
}
}
},
"routeTemplate": "/x402/security/cve/:cve_id"
}
}Provenance
- Seen in the source catalog
- 2026-08-26 06:17Z
- Last indexed by Roundhouse
- 2026-09-25 06:10Z
- Last enriched (probe, favicon, geo)
- 2026-09-14 04:15Z
- x402 version
- 2
- Max timeout
- 300s
- Liveness probe
- HTTP 0
Hand this page to an agent
Copy the prompt and paste it into Claude, an MCP client or your own agent — it will vet this service and call it over the free read API. No key, no account.
GET api.roundhouseai.io/v0/endpoints
This endpoint's own trailing-30-day call count, as published by the upstream catalog and snapshotted daily. 30 snapshots so far. Verified volume counts only settlements with an on-chain EIP-3009 marker.
Show the promptHide the prompt
Using Roundhouse, look up the x402 service Open Source Filings and tell me whether it is worth paying: what a call costs, whether the endpoint answered when last probed, and what its payment record actually shows. curl -s 'https://api.roundhouseai.io/v0/endpoints?q=Open%20Source%20Filings' curl -s 'https://api.roundhouseai.io/v0/merchants/<the payTo wallet returned above>' Then call it: read the price from the live 402 at https://api.osf-master-server.com/x402/security/cve/:cve_id, never from a cached figure, and pay with an x402 client. The /v0 API needs an API key (`authorization: Bearer rh_live_…`) on everything except /v0/unified* and /v0/endpoints. Mint a personal key for $0.01 at GET https://api.roundhouseai.io/v0/test/x402, or use an organization key from https://roundhouseai.io/dashboard/team. If you do not have Roundhouse tools or skills installed, read https://roundhouseai.io/skill.md first — it is the whole procedure.