x402 census · agent402.tools · c1dd7ea87814 · JSON
POST /api/webhook-verify
live
Verify a webhook's HMAC signature against the correct per-provider scheme: GitHub (X-Hub-Signature-256, sha256=hex), Stripe (Stripe-Signature t/v1 over "<t>.<body>" with replay tolerance), Shopify (X-Shopify-Hmac-Sha256, base64), Slack (X-Slack-Signature, v0:<ts>:<body> with replay tolerance). Constant-time comparison; the secret is never echoed. Pass the RAW request body string - signatures are …
Verdict: live. The unpaid GET reached a valid 402. The live amount equals the catalog price.
Facts from the catalogs
| Field | Value |
|---|---|
| URL | https://agent402.tools/api/webhook-verify |
| Method | POST |
| Price | $0.001 USDC = 1000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Network | eip155:8453 (base); also accepts eip155:137, eip155:42161, eip155:143, eip155:43114, eip155:1329, eip155:10, eip155:4663, eip155:42220, solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp, stellar:pubnet |
| payTo | 0xaBF4FAbd7c416fB67202E5f9002389Fc75e2a9D0 |
| Seller | agent402.tools |
| Catalogs | cdp (row updated 2026-09-30) |
| Listed since (lower bound) | 2026-09-30 (earliest catalog timestamp; catalogs report last-update times only) |
| Last catalog update | 2026-09-30 |
| CDP quality counters | 1 calls and 1 unique payers in 30 days, last call 2026-09-21 (catalog-reported, not verified on chain) |
| Category (keyword rule) | other/unknown |
| Templated path | no |
| x402Version in catalog | 2 |
| Service name / tags | Webhook signature verify · validation, webhook, hmac, signature, security |
Unpaid probe (census of 2026-09-30)
| Field | Value |
|---|---|
| Probed at | 2026-09-30T23:41:47.090Z |
| HEAD | 402 |
| GET | 402 |
| Verdict | live live: valid 402 to an unpaid GET |
| 402 carried in | body |
| x402Version in the 402 | 2 |
| accepts[0] | {"scheme":"exact","network":"eip155:8453","amount":"1000","payTo":"0xaBF4FAbd7c416fB67202E5f9002389Fc75e2a9D0","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","maxTimeoutSeconds":300,"extra":{"name":"USD Coin","version":"2"}} |
| Live amount equals catalog price | yes |
| Live payTo equals catalog payTo | yes |
| extensions.bazaar in the 402 | yes |
| PAYMENT-REQUIRED header | no |
| WWW-Authenticate offer | Payment id="hdNbmAjpyNVcDbDG70SpKyd_h7QQ |
| Content type / server / CORS | application/json / railway-hikari / * |
| Latency | 1,240 ms |
| Error | Payment required |
No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.
On-chain facts for the payTo (public address)
| Field | Value |
|---|---|
| Distinct payers | 120 |
| Payments | 1,253 |
| USDC volume | $12.29 |
| Median payment | $0.003 |
| First / last payment | 2026-06-18 / 2026-09-30 |
| Sampler-shaped share of payments | 61.8% |
| Payers that are not samplers | 2 |
| Source | forensics-2026-09-30 |
| Address | 0xaBF4FAbd7c416fB67202E5f9002389Fc75e2a9D0 (contract: EIP7702StatelessDeleGator) |
Declared input and output (extensions.bazaar)
{
"input": {
"body": {
"payload": "{\"hello\":\"world\"}",
"provider": "github",
"secret": "it's a secret",
"signature": "sha256=8d4063f0a81aa1531d9891a028a68cf2bb537ecdf0e82557674d71e168d570f9"
},
"bodyType": "json",
"method": "POST",
"type": "http"
},
"output": {
"type": "json",
"example": {
"provider": "github",
"reason": "signature matches the recomputed HMAC for this payload and secret",
"scheme": "X-Hub-Signature-256: sha256=hex(HMAC-SHA256(secret, rawBody))",
"valid": true
}
}
}
Try it (unpaid: shows the 402)
curl -si -X POST 'https://agent402.tools/api/webhook-verify' -H 'accept: application/json' -H 'content-type: application/json' --data '{}'
The catalog declares POST. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.
Paid checks (x402, USDC on Base)
GET https://bazaar.agentexchange.work/r/c1dd7ea87814/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"c1dd7ea87814"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.
Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on agent402.tools.