Choose a lint, then pay and retry
Every paid route answers 402 first. The v1 terms are in the JSON body and the v2
terms are standard base64 in the PAYMENT-REQUIRED header. An x402-capable client
holding USDC on Base or Solana reads those terms, pays, and retries the same request — the
accepts array in the 402 is the authoritative list of rails. There is no
login or API key; the payment is the authorization.
POST /lint — $0.10 per report
Sends ONE unauthenticated request to the URL you name and lints the response: HTTP status, the v1 body envelope, the v2 PAYMENT-REQUIRED header envelope, dual-stack consistency, and CDP Bazaar discovery requirements. Returns a grade and a specific fix for each finding. It identifies technical blockers; it does not verify a listing or payment.
First, request the quote. This unpaid call returns HTTP 402 with the price and payment terms. It does not return the report yet.
Then let an x402-capable client pay and retry the same request. A successful paid retry returns the report.
Example paid reportgenerated by the current engine
This build-computed example shows the successful paid response shape. The unpaid curl above returns the 402 quote instead.
POST /lint/one — $0.015 per report
The same outbound probe as /lint, reported for exactly one check you name. For settling a single question — "is my v2 header base64url", "does my bazaar info validate against its own schema" — without buying the whole catalogue. The answer says whether the check PASSED, and when the check did not apply to this response it says that instead of quietly passing. GET /check lists every check id, and publishes the batch arithmetic — so you can work out where the full report becomes the cheaper buy before paying for any of it.
First, request the quote. This unpaid call returns HTTP 402 with the price and payment terms. It does not return the report yet.
Then let an x402-capable client pay and retry the same request. A successful paid retry returns the report.
Example paid reportgenerated by the current engine
This build-computed example shows the successful paid response shape. The unpaid curl above returns the 402 quote instead.
POST /presence — $0.06 per report
The question the stuck-seller threads open with: "I settle payments — why can nobody find me?" Fetches your 402, reads the payTo and resource it declares, then checks three public surfaces: the full CDP Bazaar discovery catalog (scanned end to end — its payTo filter is documented but inert, so the honest read is the whole catalog), the x402scan explorer, and USDC transfer activity to your payTo on Base. Per-registry verdict with the evidence and a specific way in for each miss. A surface that cannot be read reports `unknown`, never a guessed `not_found`. /lint answers whether your declaration is right; this answers whether the world can see it.
First, request the quote. This unpaid call returns HTTP 402 with the price and payment terms. It does not return the report yet.
Then let an x402-capable client pay and retry the same request. A successful paid retry returns the report.
Example paid reportgenerated by the current engine
This build-computed example shows the successful paid response shape. The unpaid curl above returns the 402 quote instead.
{
"target": {
"url": "https://10x402.com/lint/one",
"method": "POST",
"status": 402
},
"identity": {
"payTo": [
"0x885E7BEF433eb78F5976b28A7c10739c98DB11E5"
],
"declaredUrl": "https://10x402.com/lint/one"
},
"registries": {
"bazaar": {
"verdict": "listed",
"evidence": {
"source": "CDP discovery catalog, scanned in full",
"catalog_total": 15060,
"matches": [
{
"resource": "https://10x402.com/lint/one",
"x402Version": 2,
"lastUpdated": "2026-08-20T04:20:41.394Z",
"payTo": "0x885E7BEF433eb78F5976b28A7c10739c98DB11E5"
}
],
"resources_on_same_payTo": 4
},
"fix": null
},
"x402scan": {
"verdict": "listed",
"evidence": {
"source": "x402scan public explorer API, looked up by payTo",
"match": {
"resource": "https://10x402.com/lint/one",
"method": "POST",
"x402Version": 2,
"lastUpdated": "2026-08-20T04:21:14.065Z"
}
},
"fix": null
}
},
"onchain": {
"verdict": "active",
"evidence": {
"source": "Base via Blockscout tokentx",
"incoming_transfers_in_window": 4,
"window": "all transfers",
"latest": {
"value": "100000",
"tokenSymbol": "USDC",
"timeStamp": "1787199643",
"hash": "0x3321c354d365c5ddd1494edda84bb2ccd0191303638f9dfb280b8c7303c7b675",
"from": "0x632ff2f904cc6ab6d741a42014c4c483f328e92f",
"to": "0x885e7bef433eb78f5976b28a7c10739c98db11e5",
"contractAddress": "0x833589fcd6edb6e08f4c7c32d4f71b54bda02913"
}
},
"fix": null
},
"summary": {
"listed": 2,
"of": 2,
"unknown": 0,
"settlement_seen": true
},
"notes": [
"Verdicts are observations of public read surfaces at one moment, not guarantees. An `unknown` means the surface could not be read and says nothing about the listing.",
"x402-list (manual registry) is not machine-checkable and is not covered here."
]
}
POST /monitor/verdict — $0.005 per report
The latest stored day for one host: agenteconomy.report, apistrust.com and the CDP Bazaar quality block side by side, plus what the endpoint itself answered to an unpaid request on the verb its own catalogue row declares and on GET. Read-time flags name the two findings that matter — a liveness contradiction between the instruments, and `wrongly-dead`: rated at uptime 0.0 while answering 402 on its declared verb. Stamped with the day it was measured, and if the stored probe is more than 36 hours old the answer says so instead of pretending to be current. Nothing is fetched to serve it.
First, request the quote. This unpaid call returns HTTP 402 with the price and payment terms. It does not return the report yet.
Then let an x402-capable client pay and retry the same request. A successful paid retry returns the report.
Example paid reportgenerated by the current engine
This build-computed example shows the successful paid response shape. The unpaid curl above returns the 402 quote instead.
{
"kind": "monitor",
"endpoint": "verdict",
"host": "10x402.com",
"subject_kind": "host",
"probeable": true,
"as_of": "2026-08-27",
"state": "probed",
"freshness": {
"probed_at": "2026-08-27T11:47:12.000Z",
"probe_age_hours": 0.2,
"stale": false,
"stale_after_hours": 36,
"day": "2026-08-27",
"days_behind_utc_today": 0,
"reads": "the stored probe is 0.2 h old, inside the 36 h bound."
},
"instruments": {
"agenteconomy": {
"source": "agenteconomy.report/s/ratings.json (CC BY 4.0)",
"observed": true,
"uptime": 0,
"score": 0,
"tier": "D",
"settled_usd_14d": 1.33,
"organic_paying_agents": 5,
"flag": "NEW",
"reads": "uptime 0.0 — dead at this instrument, score 0, tier D, $1.33 settled over 14 days, 5 organic paying agents (the rater's own term for its non-bot payer count), flagged NEW"
},
"apistrust": {
"source": "apistrust.com host table",
"observed": true,
"score": 100,
"endpoints": 4,
"endpoints_down": 0,
"reads": "score 100, 0 of 4 endpoints down"
},
"bazaar": {
"source": "CDP Bazaar discovery catalogue, per-resource quality block",
"observed": true,
"calls_30d": 4,
"unique_payers_30d": 3,
"last_called_at": "2026-08-27T03:22:07.269Z",
"resource": "https://10x402.com/lint/one",
"declared_method": "POST",
"reads": "4 calls in 30 days, 3 unique payers, last called 2026-08-27T03:22:07.269Z, declares POST"
}
},
"probe": {
"ran": true,
"ts": 1787831232,
"at": "2026-08-27T11:47:12.000Z",
"declared_method": "POST",
"declared": {
"asked": true,
"answered": true,
"status": 402,
"latency_ms": null,
"reads": "answered 402 (latency not recorded)"
},
"get": {
"asked": true,
"answered": true,
"status": 405,
"latency_ms": null,
"reads": "answered 405 (latency not recorded)"
},
"evidence": {
"payment_required_header": {
"seen": true,
"reads": "the x402 v2 PAYMENT-REQUIRED header was present"
},
"v1_body_x402version": {
"seen": true,
"reads": "an x402 v1 body carrying x402Version was present"
},
"note": "Both are read from the DECLARED-verb response — a GET-only reading of a POST endpoint is the wrong reading."
},
"reads": "on POST, its declared verb, it answered 402 (latency not recorded); on GET it answered 405 (latency not recorded) — which is exactly the shape a GET-only rater records as dead"
},
"flags": [
{
"id": "liveness-contradiction",
"statement": "agenteconomy.report rated this host dead — uptime 0.0 — while apistrust.com recorded 0 of its endpoints down: none. Both instruments had data for this host; one says dead, the other says live."
},
{
"id": "wrongly-dead",
"statement": "Rated at uptime 0.0 — but when this service sent an unpaid POST to the resource its own catalogue row declares, it answered 402: the response a live, paid x402 endpoint gives. The rating and the endpoint disagree, and the endpoint was asked directly."
}
],
"notes": [
"Every number here is a STORED observation of a public surface, re-served. Nothing was fetched to answer this call, so the `as_of` day is the truth about when it was measured.",
"NULL and 0 are different claims throughout: a NULL instrument column means that instrument had no row for this host that day, a 0 means it reported zero, and a probe status of 0 means it was asked and answered nothing at all.",
"Flags are computed at read time from the stored rows, never stored. GET /monitor names the roster criteria in full, free."
]
}
POST /monitor/history — $0.03 per report
The full daily series for one host, oldest first: what each instrument reported that day and what the declared-verb probe found, with the flags computed per day. This is the half the free page deliberately does not give away — a single day says what a rating is, and the series says whether it is drifting, whether a correction stuck, and how long a wrong liveness reading has been costing you. A day the capture did not run is simply absent, and a day that was captured but not probed says so rather than reading as a silent endpoint.
First, request the quote. This unpaid call returns HTTP 402 with the price and payment terms. It does not return the report yet.
Then let an x402-capable client pay and retry the same request. A successful paid retry returns the report.
Example paid reportgenerated by the current engine
This build-computed example shows the successful paid response shape. The unpaid curl above returns the 402 quote instead.
{
"kind": "monitor",
"endpoint": "history",
"host": "10x402.com",
"subject_kind": "host",
"probeable": true,
"as_of": "2026-08-27",
"state": "series",
"days_held": 1,
"first_day": "2026-08-27",
"last_day": "2026-08-27",
"probed_days": 1,
"series": [
{
"day": "2026-08-27",
"state": "probed",
"instruments": {
"agenteconomy": {
"source": "agenteconomy.report/s/ratings.json (CC BY 4.0)",
"observed": true,
"uptime": 0,
"score": 0,
"tier": "D",
"settled_usd_14d": 1.33,
"organic_paying_agents": 5,
"flag": "NEW",
"reads": "uptime 0.0 — dead at this instrument, score 0, tier D, $1.33 settled over 14 days, 5 organic paying agents (the rater's own term for its non-bot payer count), flagged NEW"
},
"apistrust": {
"source": "apistrust.com host table",
"observed": true,
"score": 100,
"endpoints": 4,
"endpoints_down": 0,
"reads": "score 100, 0 of 4 endpoints down"
},
"bazaar": {
"source": "CDP Bazaar discovery catalogue, per-resource quality block",
"observed": true,
"calls_30d": 4,
"unique_payers_30d": 3,
"last_called_at": "2026-08-27T03:22:07.269Z",
"resource": "https://10x402.com/lint/one",
"declared_method": "POST",
"reads": "4 calls in 30 days, 3 unique payers, last called 2026-08-27T03:22:07.269Z, declares POST"
}
},
"probe": {
"ran": true,
"ts": 1787831232,
"at": "2026-08-27T11:47:12.000Z",
"declared_method": "POST",
"declared": {
"asked": true,
"answered": true,
"status": 402,
"latency_ms": null,
"reads": "answered 402 (latency not recorded)"
},
"get": {
"asked": true,
"answered": true,
"status": 405,
"latency_ms": null,
"reads": "answered 405 (latency not recorded)"
},
"evidence": {
"payment_required_header": {
"seen": true,
"reads": "the x402 v2 PAYMENT-REQUIRED header was present"
},
"v1_body_x402version": {
"seen": true,
"reads": "an x402 v1 body carrying x402Version was present"
},
"note": "Both are read from the DECLARED-verb response — a GET-only reading of a POST endpoint is the wrong reading."
},
"reads": "on POST, its declared verb, it answered 402 (latency not recorded); on GET it answered 405 (latency not recorded) — which is exactly the shape a GET-only rater records as dead"
},
"flags": [
{
"id": "liveness-contradiction",
"statement": "agenteconomy.report rated this host dead — uptime 0.0 — while apistrust.com recorded 0 of its endpoints down: none. Both instruments had data for this host; one says dead, the other says live."
},
{
"id": "wrongly-dead",
"statement": "Rated at uptime 0.0 — but when this service sent an unpaid POST to the resource its own catalogue row declares, it answered 402: the response a live, paid x402 endpoint gives. The rating and the endpoint disagree, and the endpoint was asked directly."
}
]
}
],
"notes": [
"Ordered oldest first, one entry per UTC day this wing captured. A day missing from this series is a day the capture did not run or did not see this host — it is not a day the host was absent from the market.",
"An entry with `state: \"readings-only\"` was captured but not probed: the roster is capped, and being off it says nothing about the host."
]
}
POST /monitor/receipt — $0.12 per report
The artefact to attach to a corrections request. It carries the whole daily series, a CONTRADICTION STATEMENT in plain numbers — how many days two instruments disagreed about whether this host was alive, and on how many of them the endpoint answered 402 to an unpaid request on its declared verb — a SHA-256 digest over the canonical JSON of the document so two copies can be compared in one line, and an attestation naming the probe method, the exact User-Agent every request carried (searchable verbatim in the rater's own access log), and the fact that NO PAYMENT WAS EVER SENT. The digest is an integrity check, not a signature: it proves two copies are the same document, not who issued it.
First, request the quote. This unpaid call returns HTTP 402 with the price and payment terms. It does not return the report yet.
Then let an x402-capable client pay and retry the same request. A successful paid retry returns the report.
Example paid reportgenerated by the current engine
This build-computed example shows the successful paid response shape. The unpaid curl above returns the 402 quote instead.
{
"kind": "monitor",
"endpoint": "receipt",
"host": "10x402.com",
"subject_kind": "host",
"probeable": true,
"issued_at": "2026-08-27T12:00:00.000Z",
"as_of": "2026-08-27",
"state": "receipt",
"days_held": 1,
"first_day": "2026-08-27",
"last_day": "2026-08-27",
"probed_days": 1,
"contradiction": {
"days_held": 1,
"days_in_contradiction": 1,
"days_wrongly_dead": 1,
"days_wrongly_dead_candidate": 0,
"statement": "On 1 of the 1 day(s) held, the two probing instruments disagreed about whether 10x402.com was alive. Most recently, on 2026-08-27: agenteconomy.report recorded uptime 0.0, while apistrust.com recorded 0 of 4 endpoints down at score 100. On 1 of those day(s) this service sent an unpaid POST to https://10x402.com/lint/one — the resource its own catalogue row declares — and it answered 402, the response a live, paid x402 endpoint gives, while the same day's rating recorded it dead. On 2026-08-27 the same resource answered 405 to a GET, which is the reading a GET-only prober takes and files as downtime."
},
"series": [
{
"day": "2026-08-27",
"state": "probed",
"instruments": {
"agenteconomy": {
"source": "agenteconomy.report/s/ratings.json (CC BY 4.0)",
"observed": true,
"uptime": 0,
"score": 0,
"tier": "D",
"settled_usd_14d": 1.33,
"organic_paying_agents": 5,
"flag": "NEW",
"reads": "uptime 0.0 — dead at this instrument, score 0, tier D, $1.33 settled over 14 days, 5 organic paying agents (the rater's own term for its non-bot payer count), flagged NEW"
},
"apistrust": {
"source": "apistrust.com host table",
"observed": true,
"score": 100,
"endpoints": 4,
"endpoints_down": 0,
"reads": "score 100, 0 of 4 endpoints down"
},
"bazaar": {
"source": "CDP Bazaar discovery catalogue, per-resource quality block",
"observed": true,
"calls_30d": 4,
"unique_payers_30d": 3,
"last_called_at": "2026-08-27T03:22:07.269Z",
"resource": "https://10x402.com/lint/one",
"declared_method": "POST",
"reads": "4 calls in 30 days, 3 unique payers, last called 2026-08-27T03:22:07.269Z, declares POST"
}
},
"probe": {
"ran": true,
"ts": 1787831232,
"at": "2026-08-27T11:47:12.000Z",
"declared_method": "POST",
"declared": {
"asked": true,
"answered": true,
"status": 402,
"latency_ms": null,
"reads": "answered 402 (latency not recorded)"
},
"get": {
"asked": true,
"answered": true,
"status": 405,
"latency_ms": null,
"reads": "answered 405 (latency not recorded)"
},
"evidence": {
"payment_required_header": {
"seen": true,
"reads": "the x402 v2 PAYMENT-REQUIRED header was present"
},
"v1_body_x402version": {
"seen": true,
"reads": "an x402 v1 body carrying x402Version was present"
},
"note": "Both are read from the DECLARED-verb response — a GET-only reading of a POST endpoint is the wrong reading."
},
"reads": "on POST, its declared verb, it answered 402 (latency not recorded); on GET it answered 405 (latency not recorded) — which is exactly the shape a GET-only rater records as dead"
},
"flags": [
{
"id": "liveness-contradiction",
"statement": "agenteconomy.report rated this host dead — uptime 0.0 — while apistrust.com recorded 0 of its endpoints down: none. Both instruments had data for this host; one says dead, the other says live."
},
{
"id": "wrongly-dead",
"statement": "Rated at uptime 0.0 — but when this service sent an unpaid POST to the resource its own catalogue row declares, it answered 402: the response a live, paid x402 endpoint gives. The rating and the endpoint disagree, and the endpoint was asked directly."
}
]
}
],
"attestation": {
"method": "One unauthenticated HTTP request to the host's most-recently-called CDP Bazaar resource on the verb that catalogue row declares, and one on GET, taken seconds apart from a Cloudflare Worker. Redirects are not followed. At most 4 KB of each body is read.",
"user_agent": "10x402-monitor/0.1 (+https://10x402.com/monitor)",
"no_payment": "NO PAYMENT WAS EVER SENT. No X-PAYMENT header, no PAYMENT-SIGNATURE, no cookie and no authorization accompanied any request in this document. Every status recorded here is what an unpaid caller sees — which is the only reading comparable with what the rating instruments publish, and the reason this service is a monitor rather than a customer.",
"schedule": {
"capture": "17 */6 * * *",
"probe": "47 */6 * * *",
"timezone": "UTC"
},
"statement": "Every probe in this document was made by 10x402 from a Cloudflare Worker, identifying itself in every request as `10x402-monitor/0.1 (+https://10x402.com/monitor)` — searchable verbatim in the access log of the host it was made against. It sent one unauthenticated request on the verb the subject's own CDP Bazaar row declares and one on GET, followed no redirects, and read at most 4 KB of each response. NO PAYMENT WAS SENT ON ANY OF THEM: a prober that pays is buying the answer it publishes. Instruments are captured every six hours, at :17 past the hour UTC, and probes taken every six hours, at :47 past the hour UTC; the readings are re-served from storage, never re-fetched to answer a call."
},
"verify": "Recompute: take this document, remove the `digest` member, serialise the remainder as canonical JSON (object keys sorted by code unit at every depth, array order preserved, no whitespace, UTF-8), and SHA-256 it. The hex digest must equal `digest.value`. This is an integrity check on the document, NOT a signature: it proves two copies are the same document, and it does not prove who issued it.",
"notes": [
"Ordered oldest first, one entry per UTC day this wing captured. A day missing from this series is a day the capture did not run or did not see this host — it is not a day the host was absent from the market.",
"An entry with `state: \"readings-only\"` was captured but not probed: the roster is capped, and being off it says nothing about the host."
],
"digest": {
"algorithm": "SHA-256",
"encoding": "hex",
"over": "every member of this document except `digest` itself",
"canonicalisation": "object keys sorted at every depth, array order preserved, no whitespace, UTF-8",
"value": "4804689b42260b894dc4a1323944c8986f3b22c47ea34770a83166db2cdc596e"
}
}
POST /lint/envelope — $0.04 per report
Runs the same check catalogue against a response you already have: paste the status, headers and body. Nothing is fetched, so it works for v1/v2 migration work, on staging, on localhost and on an endpoint that is not deployed yet. Cheaper than /lint for that reason: there is no outbound request to make on your behalf.
First, request the quote. This unpaid call returns HTTP 402 with the price and payment terms. It does not return the report yet.
Then let an x402-capable client pay and retry the same request. A successful paid retry returns the report.
Example paid reportgenerated by the current engine
This build-computed example shows the successful paid response shape. The unpaid curl above returns the 402 quote instead.
{
"grade": "A",
"summary": {
"versions_detected": [
1
],
"payTo": "0x0000000000000000000000000000000000000001",
"network": "base",
"price": "$0.001 (1000 atomic)",
"bazaar_ready": "n/a",
"blockers": [
"V2_HEADER_PRESENT"
]
},
"findings": [
{
"severity": "error",
"code": "V2_HEADER_PRESENT",
"message": "no PAYMENT-REQUIRED response header — this endpoint publishes no x402 v2 envelope.",
"fix": "Add a PAYMENT-REQUIRED response header to the 402 carrying the standard-base64 JSON v2 envelope. This costs you DISCOVERY rather than payment, and the distinction is worth being precise about: @x402/core reads the header first but DOES fall back to a v1 body when there is none, so the current client generation can still pay you. What it cannot do is find you — CDP marks the PAYMENT-REQUIRED header a required indexing check, so a v1-only 402 is not catalogued at all, and a strictly-v2 client cannot pay it either. Keep the v1 body exactly as it is; the two versions share a 402 without either noticing the other.",
"core": false,
"sources": [
{
"kind": "spec",
"ref": "specs/transports-v2/http.md:7-25 § Payment Required Signaling"
},
{
"kind": "cdp-validator",
"ref": "cdp-validator-toolshed.json preflight[6] payment_required_header (required)"
},
{
"kind": "client-code",
"ref": "@x402/[email protected] dist/cjs/http/index.js:1620-1628 — the v2 client DOES fall back to a v1 body"
},
{
"kind": "field-report",
"ref": "x402-foundation/x402#3091 — [email protected] is still a live buyer population"
}
]
},
{
"severity": "info",
"code": "BILLING_TERMS_DISCLOSED",
"message": "no machine-readable billing-terms object was found. Consulted: the 402 (accepts[].extra.billing_terms); /.well-known/x402 resources[].billing_terms (not supplied); OpenAPI x-billing-terms (not supplied). Prose in `description` was not parsed.",
"fix": "Publish a billing-terms object with all four keys, in any ONE of: `accepts[].extra.billing_terms` in the 402 (always read), `resources[].billing_terms` in /.well-known/x402, or `x-billing-terms` on the OpenAPI operation (both read only when the caller supplies them). e.g. {\"billable_unit\":\"1 second\",\"hold\":\"the quote, released in 24h\",\"acceptance_observer\":\"the buyer\",\"silence_window\":\"72h\"}. Any JSON value counts; prose in `description` is not parsed. algonormative/10x402#10's block gives billable_unit and hold only: add acceptance_observer and silence_window. NOTHING REQUIRES THIS (no spec, client or registry): informational, moves neither verdict.",
"core": false,
"sources": [
{
"kind": "field-report",
"ref": "Moltbook 92cd240a… (bitroadai), \"transport success is not billable completion\" — buyers asked for the minimum billable unit and what a hold covers"
},
{
"kind": "field-report",
"ref": "Moltbook 6868a451… / 2d2df453… (relayzero, @miacollective) — who observes acceptance, and how long silence counts as acceptance, as terms a buyer needs before paying"
},
{
"kind": "house-opinion",
"ref": "no spec requires these four, no client parses them, no registry demands them — this check can only REPORT. Key names from house PR algonormative/10x402#10"
},
{
"kind": "spec",
"ref": "specs/x402-specification-v2.md § 6.1 (Payment Flow Models), read 2026-09-09 — SILENT on all four",
"context": true
}
]
}
],
"checks_run": 29
}
POST /lint/envelope/one — $0.004 per report
One named check over a response you already have — the cheapest answer this service sells, and the one to reach for in a test or a CI step that asserts a single property of a 402 it just built. Nothing is fetched. The answer says whether the check PASSED, and when the check did not apply to this response it says that instead of quietly passing. GET /check lists every check id.
First, request the quote. This unpaid call returns HTTP 402 with the price and payment terms. It does not return the report yet.
Then let an x402-capable client pay and retry the same request. A successful paid retry returns the report.
Example paid reportgenerated by the current engine
This build-computed example shows the successful paid response shape. The unpaid curl above returns the 402 quote instead.
Payment terms: USDC on Base at 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913;
base in v1 and eip155:8453 in v2. USDC on Solana may also
be offered, at the same price — the accepts array in each live 402 is the
authority on which rails this deployment takes, and Base is always its first entry.
You are only charged for a report that is served. A bad URL, unreachable target, or malformed
paste settles nothing, even if the payment verified.