x402 List

x402 Protocol Service Directory

HexScan

Verification

Smart contract risk triage API. Send a contract address, get a composite risk score (0-100) with honeypot detection, tax analysis, source verification, and heuristic findings. Not an audit.

Pay from $0.10 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.

UPTIME 24H 100% 7D 100% 30D 100%
BASE URL https://hexscan.xyz WEBSITE https://hexscan.xyz ENDPOINTS 1 NETWORK Base ASSET USDC MEMBER SINCE 2026-07-21 MONITORED SINCE 2026-07-21

ASSESSMENT

updated 55m ago

Evidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.

reliability 100%
uptime 24h
100%
uptime 7d
100%
uptime 30d
100%
uptime 90d
100%
response p95
765ms
avg response
352ms
total checks
24
compliance A (11/11)

11 of 11 x402 conformance checks pass. Full checklist below.

jump to compliance checklist

price $0.10 (p85 in Verification)
price (min)
$0.10
category percentile (min)
p85 in Verification
endpoints / prices
1 / 1
model
flat
stability
100%
risk clean

No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.

traction $0 30d · 0 buyers
volume 30d
$0
buyers 30d
0
settlements 30d
0
last settlement
---
top buyer share
-
trend 7d vs 30d
-
networks
eip155:8453

Conservative undercount: only USDC settlements via facilitators we measure are counted. A measured floor, not an estimate.

Top buyer share is a concentration signal, not part of the ranking score.

WHAT IT DOES

ai-derived

Scans and verifies smart contracts on the blockchain

category
contract-scanning
in
query params
contract-scanningverificationblockchain

AI-generated summary. The measured data is never altered by it.

ENDPOINTS

Service endpoints with HTTP method, path, description, pricing, and network
METHOD PATH DESCRIPTION PRICE NETWORK ASSET
GET /scan $0.10 Base USDC
1 endpoints

REQUEST / RESPONSE EXAMPLE

An unpaid request to GET /scan returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.

// request
curl -i 'https://hexscan.xyz/scan'
// 402 response (captured by monitor) · 1 payload · click to expand
[
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x841Ef35b7b7ee4C820BFF040369a8Ade4741b45d",
        "amount": "100000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://hexscan.xyz/scan",
      "mimeType": "application/json",
      "description": "Smart contract risk triage - honeypot detection, tax analysis, source verification. Not an audit."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "body": {
              "chain": "ethereum",
              "address": "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48"
            },
            "type": "http",
            "method": "POST",
            "bodyType": "json"
          },
          "output": {
            "type": "json",
            "example": {
              "riskLevel": "MINIMAL",
              "riskScore": 5,
              "tokenName": "USD Coin"
            }
          }
        }
      }
    },
    "x402Version": 2
  }
]

UPTIME

07-21 · uptime 100.0% · 352ms avg07-2107-21
RESPONSE TIME
07-21 · 352ms avg07-21 · 352ms avg07-2107-21
30d UPTIME 100%
UPTIME 30D 100%
AVG RESP 334ms
TOTAL CHECKS 27

RECENT CHECKS

TIME STATUS RESP
● OK 89ms
● OK 116ms
● OK 371ms
● SLOW 558ms
● OK 135ms
● OK 163ms
● OK 122ms
● SLOW 667ms
● OK 120ms
● SLOW 770ms
● OK 393ms
● OK 184ms
● OK 93ms
● SLOW 765ms
● OK 124ms
● OK 142ms
● OK 167ms
● SLOW 744ms

OVER TIME

All charts share the 30d window selected here. Every series is also served as JSON at /api/v1/services/hexscan/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.

PRICE (captured 402, USD)
building price history ($0.10)
SUB-SCORES (uptime + x402 compliance)
building assessment history (1 day so far)
VOLUME (on-chain settlement, USD)
no on-chain volume yet
DISTINCT BUYERS
no distinct buyers yet

COMPLIANCE

11/11 checks pass · grade A
  • 402 payload captured
  • accepts[] array present
  • payTo address recoverable
  • payTo at accepts[0].payTo (conformant shape)
  • payTo is a valid on-chain address
  • atomic price declared
  • atomic price in a sane range
  • asset (token) address declared
  • network resolves to CAIP-2
  • payment scheme declared
  • served over HTTPS

EMBED THIS BADGE

Show that HexScan is monitored on x402-list. Paste this on your site or README, it links back to this live listing.

HexScan listed on x402-list
status
HexScan uptime on x402-list
live uptime
// HTML
<a href="https://x402-list.com/services/hexscan?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/hexscan.svg" alt="HexScan listed on x402-list" height="28">
</a>
// Markdown
[![HexScan on x402-list](https://x402-list.com/badge/hexscan.svg)](https://x402-list.com/services/hexscan?utm_source=badge&utm_medium=referral&utm_campaign=embed)
// HTML · live uptime variant
<a href="https://x402-list.com/services/hexscan?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/hexscan.svg?data=uptime" alt="HexScan uptime on x402-list" height="28">
</a>

RUN THIS SERVICE?

Keep this listing accurate: propose changes to the name, description, website, category or add new endpoints to monitor. Ownership is verified with a domain proof and every change is reviewed manually; measured data stays read-only.

[ update this listing ]