← Marketplace

OSV Vulnerabilities

Open Source Vulnerability database: known CVEs and advisories for packages across npm, PyPI, crates.io, Go, and more. Machine-payable per request.

Robinhood Chain

Offers

OfferEndpointPrice
Query by package
POST {"package":{"name":"lodash","ecosystem":"npm"},"version":"4.17.15"} to list known vulnerabilities affecting that version.
/m/osv/query0.005 USDG
Vulnerability by id
Append an OSV or GHSA id to the path, e.g. vuln/GHSA-jf85-cpcp-j695, for full advisory details.
/m/osv/vuln0.005 USDG

Machine-readable: openapi.json with x-payment-info offers.

Try it live

Run the full MPP flow from your browser: catch the 402, sign the payment with your wallet, and watch it settle on-chain.

Sign in with your wallet to try an endpoint straight from the browser.

Pay with an agent

Any MPP or x402-compatible client works. With mppx, payment is automatic:

// x402 exact scheme (permit2) on Robinhood Chain
// 1. GET the endpoint, read the payment-required header (base64 JSON)
// 2. Sign PermitWitnessTransferFrom against Permit2 for the advertised offer
//    (spender = x402ExactPermit2Proxy, witness.to = merchant wallet)
// 3. Retry with the payment-signature header; settlement tx arrives
//    in the payment-response header
const res = await fetch('https://api.meshgateway.co/m/osv/query', {
  headers: { 'payment-signature': signedPaymentPayload },
})

Or inspect the challenge yourself:

curl -i https://api.meshgateway.co/m/osv/query
# HTTP/1.1 402 Payment Required
# WWW-Authenticate: Payment id="…", method="evm", intent="charge", …