{"info":{"title":"Onrender","version":"1.0.0"},"openapi":"3.1.0","paths":{"/api/contract-check":{"get":{"responses":{"200":{"description":"Successful response"},"402":{"description":"Payment Required"}},"x-payment-info":{"offers":[{"amount":"50000","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","description":"Onrender: Api Contract Check","intent":"charge","method":"evm","recipient":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E"}]},"summary":"EVM token contract safety check: honeypot detection, mint/blacklist/pausable/self-destruct capability, ownership renouncement, transfer tax, and a real token-impersonation check (does the symbol claim to be USDC/WETH/DAI/cbBTC at the wrong address — the token equivalent of npm typosquatting)."}},"/api/domain-check":{"get":{"responses":{"200":{"description":"Successful response"},"402":{"description":"Payment Required"}},"x-payment-info":{"offers":[{"amount":"20000","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","description":"Onrender: Api Domain Check","intent":"charge","method":"evm","recipient":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E"}]},"summary":"Domain liveness check / verify / audit: DNS resolution (A/MX/NS/TXT records), whether mail routing exists, HTTP reachability."}},"/api/mcp-audit":{"get":{"responses":{"200":{"description":"Successful response"},"402":{"description":"Payment Required"}},"x-payment-info":{"offers":[{"amount":"60000","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","description":"Onrender: Api Mcp Audit","intent":"charge","method":"evm","recipient":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E"}]},"summary":"MCP server safety audit: completes a real initialize+tools/list handshake, then statically scans every tool's name/description/schema for hidden unicode (tool-poisoning), prompt-injection-style phrasing, and tools that quietly combine multiple high-privilege capabilities (network+filesystem+exec+credential access). If a GitHub repo is supplied, folds in a real software-supply-chain signal too."}},"/api/repo-health":{"get":{"responses":{"200":{"description":"Successful response"},"402":{"description":"Payment Required"}},"x-payment-info":{"offers":[{"amount":"20000","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","description":"Onrender: Api Repo Health","intent":"charge","method":"evm","recipient":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E"}]},"summary":"GitHub repo health check / audit / verify: stars, forks, open issues, last commit age, archived status, license."}},"/api/trust-check":{"get":{"responses":{"200":{"description":"Successful response"},"402":{"description":"Payment Required"}},"x-payment-info":{"offers":[{"amount":"20000","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","description":"Onrender: Api Trust Check","intent":"charge","method":"evm","recipient":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E"}]},"summary":"npm package trust check / risk score / security audit: registry age, weekly downloads, GitHub org/stars, OSV.dev vulnerabilities, typosquat detection."}},"/api/x402-doctor":{"get":{"responses":{"200":{"description":"Successful response"},"402":{"description":"Payment Required"}},"x-payment-info":{"offers":[{"amount":"1000000","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","description":"Onrender: Api X402 Doctor","intent":"charge","method":"evm","recipient":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E"}]},"summary":"Audits another x402 service for the exact failure modes that cause aggregators (agent-tools.cloud, x402scan, Bazaar) to mark it 'down' or make its 402 challenge unreadable: missing/invalid /.well-known/x402 descriptor, an unpaid request returning 500/404 instead of a clean 402, a malformed or missing payment-required challenge, and drift between the descriptor's advertised terms and the live chall"}}},"x-service-info":{"description":"Onrender is an x402-native service at https://x402-api-catalog.onrender.com, indexed from the x402 Bazaar (Coinbase's public discovery directory). It charges callers itself in USDC on Base and is paid directly at its own wallet; Monex Protocol passes your request and payment headers through untouched. 6 endpoints listed."}}