Check an x402 endpoint before you pay for it
Autonomous agents discover x402 services faster than people can vet them. A pre-flight check keeps an agent from paying an endpoint that is down, mispriced or malformed.
The problem
An unpaid x402 request should return HTTP 402 with a payment requirement: scheme, network, asset, amount and a pay-to address. Services in the wild get this wrong in small ways. They return 200 or 404 instead, advertise a price you did not expect, respond slowly or omit the metadata that lets agents understand the inputs. Finding out after signing a payment is expensive.
How /x402check answers it
GET /x402check?url=https://... sends an unpaid request to the target and never pays. It reports reachable, the httpStatus, latencyMs, the x402 version, the description, and each payment option with network, asset, amount, USD price and payTo. It also sets discoverable when the 402 carries Bazaar discovery metadata and lists any issues, for example a non-402 status or a missing payTo. Pass method=POST for endpoints that only accept POST.
Request and response
Example checking DepVet's /check endpoint.
$ curl -i "https://baselens.imac2014ville.workers.dev/x402check?url=https://depvet.imac2014ville.workers.dev/check"
HTTP/2 402
payment-required: eyJ4NDAyVmVyc2lvbiI6Mi4uLn0= # base64 JSON: scheme "exact", network eip155:8453,
# asset USDC, amount 10000 (= $0.01)
# An x402 client signs the payment, then retries with a PAYMENT-SIGNATURE header.
The paid response (abridged sample):
{
"url": "https://depvet.imac2014ville.workers.dev/check",
"method": "GET",
"reachable": true,
"httpStatus": 402,
"latencyMs": 534,
"ok": true,
"isX402": true,
"x402Version": 2,
"options": [{
"scheme": "exact", "network": "eip155:8453", "assetSymbol": "USDC",
"amountAtomic": "5000", "priceUsd": 0.005,
"payTo": "0xbBB1338E3990a9Ab5DB36546a28cEe06cCB03D05"
}],
"discoverable": true,
"issues": []
}
JavaScript with @x402/fetch
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";
const signer = privateKeyToAccount(process.env.PRIVATE_KEY); // wallet holding USDC on Base
const pay = wrapFetchWithPaymentFromConfig(fetch, {
schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(signer) }],
});
const target = "https://example.com/paid-endpoint";
const res = await pay("https://baselens.imac2014ville.workers.dev/x402check?url=" + encodeURIComponent(target));
const c = await res.json();
if (!c.ok || c.options[0].priceUsd > 0.05) throw new Error("skip: " + c.issues.join("; "));
Pricing
/x402check costs $0.01 per call. It pays off when the endpoint you are about to call costs more than that. There is no API key and no account: each request is paid in USDC on Base over x402. Malformed input returns 400 and failed lookups return a non-2xx status, so those are not charged.
Limitations
- Only https URLs are checked, with an 8 second timeout, and redirects are not followed.
priceUsdis computed only for USDC, USDbC and DAI assets; other tokens show the raw atomic amount.- The check proves the 402 challenge is well formed. It does not prove the service will deliver a correct result after payment.
More guides
BaseLens overview/openapi.jsonllms.txt
Sister services
- DepVet: npm and PyPI package vetting before install
- TokenGuard: honeypot and rug pull checks for Base tokens, plus pre-screened new launches
- MacroLens: country macro statistics and company registries (Norway, France)
- SkyFeed: weather forecasts, US alerts, earthquakes and public holidays
- ChainRead: gas, balances, ENS and Basename resolution on Base and Ethereum