Agent Exchange x402 census and directory

x402 census · payai.agentstools.dev · 30d95ded9e70 · JSON

GET /threat/hash

live

File-hash reputation and known-file context for a SOC or DFIR agent. Give an md5, sha1 or sha256 hash and get CIRCL hashlookup known-file status, a hashlookup trust score and file metadata (name, size, mimetype, source, database), plus malware family when a licensed feed is enabled. A known distribution or system file lowers the alert priority; an unknown hash is not itself evidence of malice. In…

Verdict: live. The unpaid GET reached a valid 402. The live amount equals the catalog price.

Facts from the catalogs

FieldValue
URLhttps://payai.agentstools.dev/threat/hash
MethodGET
Price$0.008 USDC = 8000 atomic units of EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
Networksolana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp (solana)
payToAytHnvc6bZx1ALTy7b5Px7hcavoSYszG9aeKvDcZ8R1u
Sellerpayai.agentstools.dev
Catalogspayai (row updated 2026-09-30)
Listed since (lower bound)2026-09-30 (earliest catalog timestamp; catalogs report last-update times only)
Last catalog update2026-09-30
CDP quality countersnot in the CDP catalog
Category (keyword rule)identity/trust/kyc
Templated pathno
x402Version in catalog2
Service name / tagsthreat-hash-reputation · threat-intelligence, hash, malware, file-reputation, hashlookup

Unpaid probe (census of 2026-09-30)

FieldValue
Probed at2026-09-30T23:35:57.706Z
HEAD402
GET402
Verdictlive live: valid 402 to an unpaid GET
402 carried inheader+body
x402Version in the 4022
accepts[0]{"scheme":"exact","network":"eip155:8453","amount":"8000","payTo":"0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","maxTimeoutSeconds":300,"extra":{"name":"USD Coin","version":"2"}}
Live amount equals catalog priceyes
Live payTo equals catalog payTono
extensions.bazaar in the 402yes
PAYMENT-REQUIRED headeryes
WWW-Authenticate offernone
Content type / server / CORSapplication/json / uvicorn / none
Latency2,197 ms
ErrorPayment required

No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.

On-chain facts for the payTo (public address)

FieldValue
Settlement historyunresolved: non-EVM payTo; only Base is covered

Declared input and output (extensions.bazaar)

{
 "input": {
  "type": "http",
  "method": "GET",
  "queryParams": {
   "hash": "d41d8cd98f00b204e9800998ecf8427e"
  }
 },
 "output": {
  "type": "json",
  "example": {
   "algo": "md5",
   "hash": "d41d8cd98f00b204e9800998ecf8427e",
   "reasons": [
    "Hash is a KNOWN file in CIRCL hashlookup with high trust."
   ],
   "sources": [
    "circl_hashlookup"
   ],
   "verdict": "benign_known",
   "confidence": 0.75,
   "disclaimer": "Automated reputation/threat indicators, not a guarantee; for triage.",
   "known_file": true,
   "is_malicious": false,
   "malware_family": [],
   "hashlookup_trust": 100
  }
 }
}

Try it (unpaid: shows the 402)

curl -si -X GET 'https://payai.agentstools.dev/threat/hash' -H 'accept: application/json'

The catalog declares GET. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.

Paid checks (x402, USDC on Base)

GET https://bazaar.agentexchange.work/r/30d95ded9e70/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"30d95ded9e70"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.

Catalog references: PayAI listing status · this record as JSON · all resources on payai.agentstools.dev.