x402 List

x402 Protocol Service Directory

Lazaretto

Verification PAYMENT-READY

payment-ready until 2026-08-19

Deterministic pre-install malware verification for npm packages, AI agent skills, and MCP tools. Behavioral scan with file-and-line evidence for 0.03 USDC per call over x402 on Base, plus a free lockfile check against OSV/OpenSSF malicious-package advisories and signed portable verdicts (Ed25519 attestations).

Pay from $0.03 to $3.00 in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.

listed 2026-08-12 · no on-chain settlement recorded yet

BASE URL https://lazaretto.dev WEBSITE https://lazaretto.dev ENDPOINTS 2 NETWORK Base ASSET USDC MEMBER SINCE 2026-08-12 MONITORED SINCE 2026-08-12

ASSESSMENT

updated 2h ago

Evidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.

reliability 100%
uptime 24h
100%
uptime 7d
100%
uptime 30d
100%
uptime 90d
100%
response p95
479ms
avg response
479ms
total checks
1

Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.

compliance A (14/14)

14 of 14 x402 conformance checks pass. Full checklist below.

jump to compliance checklist

price $0.03 to $3.00 (p56 in Verification)
price (min)
$0.03
price (max)
$3.00
category percentile (min)
p56 in Verification
category percentile (max)
p97 in Verification
endpoints / prices
2 / 2
model
tiered
stability
100%
risk clean

No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.

domain age
33d
registrar
CloudFlare, Inc.
hosting
custom
domain created
2026-07-10

Identity facts, not a risk score.

traction $0.00 30d · 0 buyers
volume 30d
$0.00
buyers 30d
0
settlements 30d
0
first settlement
---
last settlement
---
top buyer share
-
trend 7d vs 30d
-
networks
eip155:8453
volume all-time
$0
settlements all-time
0
median settlement 30d
-
max settlement 30d
-
settled via
-

Conservative undercount: only USDC settlements via facilitators we measure are counted. A measured floor, not an estimate.

Top buyer share is a concentration signal, not part of the ranking score.

WHAT IT DOES

ai-derived

No AI synthesis has been produced for this service yet.

ENDPOINTS

Service endpoints with HTTP method, path, description, pricing, and network
METHOD PATH DESCRIPTION PRICE NETWORK ASSET 402 CHANNEL
POST /v1/credits/topup $3.00 Base USDC header
POST /v1/scan $0.03 Base USDC header
2 endpoints

REQUEST / RESPONSE EXAMPLE

An unpaid request to POST /v1/credits/topup returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.

// request
curl -i -X POST 'https://lazaretto.dev/v1/credits/topup'
// 402 response (captured by monitor) · 2 payloads · click to expand
[
  {
    "error": "payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x428df107e32E08288fcAC6567f4F40bc4eAB4Da0",
        "amount": "30000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 60
      }
    ],
    "resource": {
      "url": "https://lazaretto.dev/v1/scan",
      "mimeType": "application/json",
      "description": "Deterministic behavioral scan of an npm package, repo, skill, or file for malicious signals, with evidence bound to a content hash."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "body": {
              "depth": "full",
              "target": {
                "ref": "[email protected]",
                "type": "npm_package"
              }
            },
            "type": "http",
            "method": "POST",
            "bodyType": "json"
          },
          "output": {
            "type": "json",
            "example": {
              "risk": "none",
              "verdict": "clear",
              "confidence": "high",
              "target_hash": "sha256:aa57b3ac555f3bfe2357e8a2e7ddfaa77934597887502db9ca0e660d388bf85f"
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method",
                "bodyType",
                "body"
              ],
              "properties": {
                "body": {
                  "required": [
                    "target"
                  ],
                  "properties": {
                    "depth": {
                      "enum": [
                        "lookup",
                        "full"
                      ],
                      "type": "string"
                    },
                    "target": {
                      "type": "object",
                      "required": [
                        "type"
                      ],
                      "properties": {
                        "ref": {
                          "type": "string"
                        },
                        "type": {
                          "enum": [
                            "inline",
                            "raw_url",
                            "npm_package",
                            "github_repo",
                            "clawhub_skill"
                          ],
                          "type": "string"
                        },
                        "content": {
                          "type": "string"
                        }
                      }
                    }
                  }
                },
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "POST",
                    "PUT",
                    "PATCH"
                  ],
                  "type": "string"
                },
                "bodyType": {
                  "enum": [
                    "json",
                    "form-data",
                    "text"
                  ],
                  "type": "string"
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  },
  {
    "error": "specify a bundle: {\"bundle\":\"starter\"|\"pro\"|\"scale\"}",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "credits": 150,
          "version": "2"
        },
        "payTo": "0x428df107e32E08288fcAC6567f4F40bc4eAB4Da0",
        "amount": "3000000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 60
      }
    ],
    "resource": {
      "url": "https://lazaretto.dev/v1/credits/topup",
      "mimeType": "application/json",
      "description": "Lazaretto 150 scan credits"
    },
    "x402Version": 2
  }
]

OVER TIME

All charts use the 90d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/lazaretto/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.

UPTIME
08-12 · uptime 100.0% · 292ms avg08-1208-12
90d UPTIME 100%
RESPONSE TIME
08-12 · 292ms avg08-12 · 292ms avg08-1208-12
AVG RESP 292ms
PRICE (captured 402, USD)
building price history ($1.515)

Median across 2 endpoints. Use the selector to isolate one.

SUB-SCORES (uptime + x402 compliance)
building assessment history (1 day so far)

checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression

VOLUME (on-chain settlement, USD)
no on-chain volume yet
DISTINCT BUYERS
no distinct buyers yet

COMPLIANCE

14/14 checks pass · grade A

last 402 captured 2026-08-12 · last up 2026-08-12

  • 402 payload captured
  • accepts[] array present
  • payTo address recoverable
  • payTo at accepts[0].payTo (conformant shape)
  • payTo is a valid on-chain address
  • atomic price declared
  • atomic price in a sane range
  • asset (token) address declared
  • network resolves to CAIP-2
  • payment scheme declared
  • served over HTTPS
  • declares the current x402 version (2)
  • EIP-712 domain parameters present on every EVM entry
  • x402 v2 envelope delivered in the payment-required header

SITE PILLARS

  • homepage reachable
  • openapi doc
  • pricing page
  • llms.txt
  • robots.txt
  • terms page
recent checks (9) live · click to expand
TIME STATUS RESP CAUSE
● OK 162ms
● SLOW 566ms
● OK 213ms
● OK 183ms
● OK 352ms
● OK 165ms
● OK 163ms
● OK 343ms
● SLOW 479ms

EMBED THIS BADGE

Show that Lazaretto is monitored on x402-list. Paste this on your site or README, it links back to this live listing.

Lazaretto listed on x402-list
status
Lazaretto uptime on x402-list
live uptime
// HTML
<a href="https://x402-list.com/services/lazaretto?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/lazaretto.svg" alt="Lazaretto listed on x402-list" height="28">
</a>
// Markdown
[![Lazaretto on x402-list](https://x402-list.com/badge/lazaretto.svg)](https://x402-list.com/services/lazaretto?utm_source=badge&utm_medium=referral&utm_campaign=embed)
// HTML · live uptime variant
<a href="https://x402-list.com/services/lazaretto?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/lazaretto.svg?data=uptime" alt="Lazaretto uptime on x402-list" height="28">
</a>

RUN THIS SERVICE?

Keep this listing accurate: propose changes to the name, description, website, category or add new endpoints to monitor. Ownership is verified with a domain proof and every change is reviewed manually; measured data stays read-only.

[ update this listing ]

Earn the verified tier: x402list pays a real call to this endpoint and, if it delivers, the service is delivery-verified. The fee covers the cost of the probe, not the badge; there is no refund if the call does not deliver. Agent and API only, no in-browser signing. See /api.

[ verify this service ($0.25) ]

To request delisting, email info@x402-list.com or update your listing at /services/lazaretto/update.