x402 List

x402 Protocol Service Directory

Lazaretto

Verification PAYMENT-READY

payment-ready until 2026-09-13

Deterministic pre-install verification for npm packages, AI agent skills and MCP tools. The free lockfile check matches every exactly pinned dependency against OSV and OpenSSF malicious-package advisories with no account. A paid scan adds behavioral analysis with file-and-line evidence. It reports credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, and returns a signed attestation that verifies offline. No LLM runs in the scan path, so the same input yields the same verdict. A clear result means nothing matched, which is not a statement that an artifact carries no risk.

Pay from $0.03 to $3.00 in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.

BASE URL https://lazaretto.dev WEBSITE https://lazaretto.dev ENDPOINTS 2 NETWORK Base ASSET USDC MEMBER SINCE 2026-08-12 MONITORED SINCE 2026-08-12

VERDICT

ranking generation 3

solid 92/100 #13 of 64 in Verification by measured score

What the score read on this service: status online, 100% uptime 30d, 1354ms response p95, x402 compliance 14 of 14, $0.03 price against the category. Each of those is measured, and each is published in full below.

The score comes from our own monitoring, never from reviews, operator claims, or a language model: reliability, x402 compliance, price against the category, a deterministic risk flag, and a small on-chain traction term, weighted by ranking generation 3. It is not placement anyone can buy: the paid verify tier is reported beside it and is not one of its inputs. Every component below stays published and read-only.

It is a score inside Verification, and only there: price and speed are scored against the whole category field, every listing in it that carries no danger flag, the scored service included, which here means 64 listings, this one among them. That set is wider than the 64 the position above is counted against, because a listing we have measured too little of to rank still sits in the field the price and the speed are normalized over. The same service in a different field would read differently. The same engine answers GET /api/v1/best, and asked for a different pool (the whole directory, or another filter) it returns a different number for this service under this same ranking generation. Neither is more correct: they answer different questions, and the methodology states which is which.

Bands on the 0 to 100 measured score: strong at 93 and above, solid from 75, mixed from 55, weak below 55. Price and speed are scored against the whole category field, every listing in it that carries no danger flag, the scored service included, so the score places a service in its own field.

ALTERNATIVES IN VERIFICATION

Other Verification services in this directory, ordered by the same measured score. The figures are ours: 30-day uptime from our own probes, 30-day settlement volume read on-chain (a conservative undercount, and null where we cannot measure it, never a zero).

Ranked alternative x402 services in the same category, with band, measured score, 30-day uptime and 30-day on-chain settlement volume
SERVICE BAND SCORE UPTIME 30D VOL 30D
Rubric Protocol — Post-Quantum AI Attestation strong 99 100% ---
HostDeFi Token Risk API strong 97 100% ---
scvd.store — evidence observatory for the x402 economy strong 97 100% ---
probe402 strong 96 100% ---
Hermes Plant strong 95 100% ---
5 of 63 other ranked services in Verification

ASSESSMENT

updated 4h ago

The parts the verdict above is computed from, each with its proof. Click any chip. Measured values stay read-only; unknown is honest, and an unknown is never counted as a zero.

reliability 100%
uptime 24h
100%
uptime 7d
100%
uptime 30d
100%
uptime 90d
100%
response p95
1354ms
avg response
512ms
total checks
2,216

Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.

compliance A (14/14)

14 of 14 x402 conformance checks pass. Full checklist below.

jump to compliance checklist

price $0.03 to $3.00 (p71 in Verification)
price (min)
$0.03
price (max)
$3.00
category percentile (min)
p71 in Verification
category percentile (max)
p89 in Verification
endpoints / prices
2 / 2
model
tiered
stability
100%
risk clean

No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.

domain age
54d
registrar
CloudFlare, Inc.
hosting
custom
domain created
2026-07-10

Identity facts, not a risk score.

traction ---

This service settles on a network x402-list does not measure yet, so on-chain volume is not counted here. Shown as unmeasured, not zero.

WHAT IT DOES

ai-derived

No AI synthesis has been produced for this service yet.

ENDPOINTS

Service endpoints with HTTP method, path, description, pricing, and network
METHOD PATH DESCRIPTION PRICE NETWORK ASSET 402 CHANNEL
POST /v1/credits/topup $3.00 Base USDC header
POST /v1/scan $0.03 Base USDC header
2 endpoints

REQUEST / RESPONSE EXAMPLE

An unpaid request to POST /v1/credits/topup returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.

// request
curl -i -X POST 'https://lazaretto.dev/v1/credits/topup'
// 402 response (captured by monitor) · 2 payloads · click to expand
[
  {
    "error": "payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x428df107e32E08288fcAC6567f4F40bc4eAB4Da0",
        "amount": "30000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 60
      }
    ],
    "resource": {
      "url": "https://lazaretto.dev/v1/scan",
      "mimeType": "application/json",
      "description": "Deterministic behavioral scan of an npm package, repo, skill, or file for malicious signals, with evidence bound to a content hash."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "body": {
              "depth": "full",
              "target": {
                "ref": "[email protected]",
                "type": "npm_package"
              }
            },
            "type": "http",
            "method": "POST",
            "bodyType": "json"
          },
          "output": {
            "type": "json",
            "example": {
              "risk": "none",
              "verdict": "clear",
              "confidence": "high",
              "target_hash": "sha256:aa57b3ac555f3bfe2357e8a2e7ddfaa77934597887502db9ca0e660d388bf85f"
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method",
                "bodyType",
                "body"
              ],
              "properties": {
                "body": {
                  "required": [
                    "target"
                  ],
                  "properties": {
                    "depth": {
                      "enum": [
                        "lookup",
                        "full"
                      ],
                      "type": "string"
                    },
                    "target": {
                      "type": "object",
                      "required": [
                        "type"
                      ],
                      "properties": {
                        "ref": {
                          "type": "string"
                        },
                        "type": {
                          "enum": [
                            "inline",
                            "raw_url",
                            "npm_package",
                            "github_repo",
                            "clawhub_skill"
                          ],
                          "type": "string"
                        },
                        "content": {
                          "type": "string"
                        }
                      }
                    }
                  }
                },
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "POST",
                    "PUT",
                    "PATCH"
                  ],
                  "type": "string"
                },
                "bodyType": {
                  "enum": [
                    "json",
                    "form-data",
                    "text"
                  ],
                  "type": "string"
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "specify a bundle: {\"bundle\":\"starter\"|\"pro\"|\"scale\"}",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "credits": 150,
          "version": "2"
        },
        "payTo": "0x428df107e32E08288fcAC6567f4F40bc4eAB4Da0",
        "amount": "3000000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 60
      }
    ],
    "resource": {
      "url": "https://lazaretto.dev/v1/credits/topup",
      "mimeType": "application/json",
      "description": "Lazaretto 150 scan credits"
    },
    "x402Version": 2
  }
]

OVER TIME

All charts use the 30d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/lazaretto/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.

UPTIME
08-12 · uptime 100.0% · 242ms avg08-13 · uptime 100.0% · 433ms avg08-14 · uptime 100.0% · 482ms avg08-15 · uptime 100.0% · 487ms avg08-16 · uptime 100.0% · 412ms avg08-17 · uptime 100.0% · 368ms avg08-18 · uptime 100.0% · 346ms avg08-19 · uptime 100.0% · 513ms avg08-20 · uptime 100.0% · 545ms avg08-21 · uptime 100.0% · 365ms avg08-22 · uptime 100.0% · 395ms avg08-23 · uptime 100.0% · 357ms avg08-24 · uptime 100.0% · 442ms avg08-25 · uptime 100.0% · 505ms avg08-26 · uptime 100.0% · 489ms avg08-27 · uptime 100.0% · 442ms avg08-28 · uptime 100.0% · 633ms avg08-29 · uptime 100.0% · 701ms avg08-30 · uptime 100.0% · 382ms avg08-31 · uptime 100.0% · 354ms avg09-01 · uptime 100.0% · 579ms avg09-02 · uptime 100.0% · 693ms avg09-03 · uptime 100.0% · 649ms avg09-04 · uptime 100.0% · 797ms avg09-05 · uptime 100.0% · 895ms avg09-06 · uptime 100.0% · 862ms avg08-1209-06
30d UPTIME 100%
RESPONSE TIME
08-12 · 242ms avg08-12 · 242ms avg08-13 · 433ms avg08-13 · 433ms avg08-14 · 482ms avg08-14 · 482ms avg08-15 · 487ms avg08-15 · 487ms avg08-16 · 412ms avg08-16 · 412ms avg08-17 · 368ms avg08-17 · 368ms avg08-18 · 346ms avg08-18 · 346ms avg08-19 · 513ms avg08-19 · 513ms avg08-20 · 545ms avg08-20 · 545ms avg08-21 · 365ms avg08-21 · 365ms avg08-22 · 395ms avg08-22 · 395ms avg08-23 · 357ms avg08-23 · 357ms avg08-24 · 442ms avg08-24 · 442ms avg08-25 · 505ms avg08-25 · 505ms avg08-26 · 489ms avg08-26 · 489ms avg08-27 · 442ms avg08-27 · 442ms avg08-28 · 633ms avg08-28 · 633ms avg08-29 · 701ms avg08-29 · 701ms avg08-30 · 382ms avg08-30 · 382ms avg08-31 · 354ms avg08-31 · 354ms avg09-01 · 579ms avg09-01 · 579ms avg09-02 · 693ms avg09-02 · 693ms avg09-03 · 649ms avg09-03 · 649ms avg09-04 · 797ms avg09-04 · 797ms avg09-05 · 895ms avg09-05 · 895ms avg09-06 · 862ms avg09-06 · 862ms avg08-1209-06
AVG RESP 514ms
PRICE (captured 402, USD)
08-12 · $1.51509-06 · $1.515$1.51508-1209-06

Median across 2 endpoints. Use the selector to isolate one.

SUB-SCORES (uptime + x402 compliance)
08-12 uptime: 100.0% compliance: 100% checks08-13 uptime: 100.0% compliance: 100% checks08-14 uptime: 100.0% compliance: 100% checks08-15 uptime: 100.0% compliance: 100% checks08-16 uptime: 100.0% compliance: 100% checks08-17 uptime: 100.0% compliance: 100% checks08-18 uptime: 100.0% compliance: 100% checks08-19 uptime: 100.0% compliance: 100% checks08-20 uptime: 100.0% compliance: 100% checks08-21 uptime: 100.0% compliance: 100% checks08-22 uptime: 100.0% compliance: 100% checks08-23 uptime: 100.0% compliance: 100% checks08-24 uptime: 100.0% compliance: 100% checks08-25 uptime: 100.0% compliance: 100% checks08-26 uptime: 100.0% compliance: 100% checks08-27 uptime: 100.0% compliance: 100% checks08-28 uptime: 100.0% compliance: 100% checks08-29 uptime: 100.0% compliance: 100% checks08-30 uptime: 100.0% compliance: 100% checks08-31 uptime: 100.0% compliance: 100% checks09-01 uptime: 100.0% compliance: 100% checks09-02 uptime: 100.0% compliance: 100% checks09-03 uptime: 100.0% compliance: 100% checks09-04 uptime: 100.0% compliance: 100% checks09-05 uptime: 100.0% compliance: 100% checks09-06 uptime: 100.0% compliance: 100% checksuptimecompliance08-1209-06

checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression

PILLARS OVER TIME (measured)

Measured site and economics pillars from the assessment history, so the latest value shown elsewhere on this page reads as a point on a trend rather than a permanent state.

VOLUME (on-chain settlement, USD)
This service settles on a network x402-list does not measure yet, so on-chain volume is not counted here. Shown as unmeasured, not zero.
DISTINCT BUYERS
This service settles on a network x402-list does not measure yet, so distinct on-chain buyers are not counted here. Shown as unmeasured, not zero.

COMPLIANCE

14/14 checks pass · grade A

last 402 captured 2026-08-12 · last up 2026-09-06

  • 402 payload captured
  • accepts[] array present
  • payTo address recoverable
  • payTo at accepts[0].payTo (conformant shape)
  • payTo is a valid on-chain address
  • atomic price declared
  • atomic price in a sane range
  • asset (token) address declared
  • network resolves to CAIP-2
  • payment scheme declared
  • served over HTTPS
  • declares the current x402 version (2)
  • EIP-712 domain parameters present on every EVM entry
  • x402 v2 envelope delivered in the payment-required header

SITE PILLARS

  • homepage reachable
  • openapi doc
  • pricing page
  • llms.txt
  • robots.txt
  • terms page
recent checks (18) live · click to expand
TIME STATUS RESP CAUSE
● SLOW 992ms
● SLOW 829ms
● SLOW 1008ms
● OK 620ms
● OK 771ms
● SLOW 1039ms
● SLOW 828ms
● OK 680ms
● SLOW 1303ms
● OK 683ms
● SLOW 1033ms
● SLOW 1188ms
● SLOW 1122ms
● OK 745ms
● OK 664ms
● SLOW 1166ms
● SLOW 955ms
● OK 760ms

EMBED THIS BADGE

Show that Lazaretto is monitored on x402-list. Paste this on your site or README, it links back to this live listing.

Lazaretto listed on x402-list
status
Lazaretto uptime on x402-list
live uptime
// HTML
<a href="https://x402-list.com/services/lazaretto?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/lazaretto.svg" alt="Lazaretto listed on x402-list" height="28">
</a>
// Markdown
[![Lazaretto on x402-list](https://x402-list.com/badge/lazaretto.svg)](https://x402-list.com/services/lazaretto?utm_source=badge&utm_medium=referral&utm_campaign=embed)
// HTML · live uptime variant
<a href="https://x402-list.com/services/lazaretto?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/lazaretto.svg?data=uptime" alt="Lazaretto uptime on x402-list" height="28">
</a>

RUN THIS SERVICE?

Keep this listing accurate: propose changes to the name, description, website, category or add new endpoints to monitor. Ownership is verified with a domain proof and every change is reviewed manually; measured data stays read-only.

[ update this listing ]

Earn the verified tier: x402list pays a real call to this endpoint and, if it delivers, the service is delivery-verified. The fee covers the cost of the probe, not the badge; there is no refund if the call does not deliver. Agent and API only, no in-browser signing. See /api.

[ verify this service ($0.25) ]

To request delisting, email info@x402-list.com or update your listing at /services/lazaretto/update.