Agent Exchange x402 census and directory

x402 census · iot.halowerk.com · 5574a65b2b85 · JSON

POST /v1/device-auth

live

Canonicalizes device_id, nonce and message, computes an HMAC-SHA256 tag with caller-supplied ephemeral key material, and optionally compares a claimed tag in constant time. It does not provision devices, store keys or replace asymmetric device identity; do not submit long-lived production secrets.

Verdict: live. The unpaid GET reached a valid 402 (confirmed by the re-probe of 2026-10-02).

Facts from the catalogs

FieldValue
URLhttps://iot.halowerk.com/v1/device-auth
MethodPOST
Price$0.002 USDC = 2000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Networkeip155:8453 (base)
payTo0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E
Selleriot.halowerk.com
Catalogscdp (row updated 2026-09-15)
Listed since (lower bound)2026-09-15 (earliest catalog timestamp; catalogs report last-update times only)
Last catalog update2026-09-15
CDP quality counters2 calls and 2 unique payers in 30 days, last call 2026-09-15 (catalog-reported, not verified on chain)
Category (keyword rule)chain-rpc
Templated pathno
x402Version in catalog2
Service name / tagsnone

Unpaid probe (census of )

FieldValue
Probenot probed in this build

Latest re-probe

FieldValue
Re-probed at2026-10-02T09:13:42.000Z (cron)
Verdict nowlive changed from unprobed
HEAD / GET402 / 402
accepts[0]{"scheme":"exact","network":"eip155:8453","amount":"2000","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","maxTimeoutSeconds":300,"extra":{"name":"USD Coin","version":"2"}}
Live amount equals catalog priceyes
Latency1,000 ms
Errornone

On-chain facts for the payTo (public address)

FieldValue
Distinct payers13
Payments94
USDC volume$0.33
Median payment$0.003
First / last payment2026-08-10 / 2026-09-30
Sampler-shaped share of payments98.9%
Payers that are not samplers1
Sourceforensics-2026-09-30
Address0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E (contract: EIP7702StatelessDeleGator)

Declared input and output (extensions.bazaar)

{
 "input": {
  "body": {
   "device_id": "sensor-berlin-17",
   "ephemeral_key": "example-ephemeral-key-2026",
   "message": "boot:4.2.1",
   "nonce": "20260831-0001"
  },
  "bodyType": "json",
  "method": "POST",
  "type": "http"
 }
}

Try it (unpaid: shows the 402)

curl -si -X POST 'https://iot.halowerk.com/v1/device-auth' -H 'accept: application/json' -H 'content-type: application/json' --data '{}'

The catalog declares POST. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.

Paid checks (x402, USDC on Base)

GET https://bazaar.agentexchange.work/r/5574a65b2b85/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"5574a65b2b85"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.

Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on iot.halowerk.com.