/x402/gas/preview this post tells you to call is retired β the path returns 404 and is no longer listed. Any command below that uses it will not work. The free way to read an endpointβs price is to call it and read the 402 challenge β for example /x402/gas. For what is live right now, see the catalogue.An independent audit probed 5,077 x402 endpoints and found roughly 76% are dead or invalid β DNS failures, connection refusals, timeouts, paths that never existed, and 200s that were never x402 at all. Only about 135 endpoints passed full verification. The best-performing seller on the registry had earned $0.70 total.
This is not a failure of the x402 protocol. Payment works when both sides actually implement it. This is a failure of discovery: the catalogs the ecosystem is building treat "listed" and "running" as the same thing. They are not. A listing is not a service, and the only way to know the difference is to check.
The method matters, so the audit published it: one throttled HTTP GET per endpoint, a 10-second timeout, redirects not followed. Pass = HTTP 402 with a well-formed payment challenge. Fail = anything else, including a 200 that happens to respond.
The headline is worse than it looks. "Live" in most registries means "returned something." Here it meant "returned a well-formed x402 challenge." Of the ~24% that responded at all, a large share weren't running x402 β they were plain HTTP services, parked domains, or app shells that happened to be up.
The ecosystem's headline numbers are "200 million transactions" and "$24 million settled per month." The audit's estimate of real commercial volume: roughly $28k/day β under a million a month, a rounding error against the claim. The gap is protocol signaling.
A challenge-response round-trip that never results in a payment is still an x402 "transaction" in telemetry. A facilitator attestation for a zero-amount verification is still counted. Probes like the audit's own β and the thousands of crawlers, health checks, and directory validators running daily β are real protocol activity, but they are not sales. The audit estimates 95%+ of the 200M transactions are signaling, not settled commerce.
There is a deeper problem that liveness probes alone cannot see: being listed is not being paid. A host can respond to a GET, even respond with a 402, and still be unable to complete a transaction β because it cannot sign a payment challenge, or holds no wallet that can receive settlement.
The missing primitive is a signed receipt that binds a payment to a response. Today's x402 receipts are facilitator attestations: they prove a facilitator observed a settlement, not that a specific endpoint served a specific response to a specific payment. There is no standardized endpoint-signed payload establishing causality. That gap shows up in four places:
Ed25519-signed payloads are the natural fit: cheap to verify, tiny in size, and aligned with agent identity models (SSH-style agent keys, passkeys) rather than EVM secp256k1. The protocol needs a receipt primitive that a payer can verify without trusting either the endpoint or the facilitator.
This isn't one registry's bug β it's the current state of the category:
| Catalog | Scale | Verification | Failure mode |
|---|---|---|---|
| Coinbase that platform | ~100K services auto-indexed | None described; pay-first | Agent pays, then learns the endpoint is dead |
| Circle Agent Discovery (Aug 6) | 900+ services | None mentioned at launch | Liveness unproven for the vast majority |
| CDP Bazaar | 22,545 probed (Jul 2026) | None | 74% dead on first contact |
| minia2a | 326 services | Probe on register + auto-delist + trial-first | Endpoint proven before credits are spent |
Circle launched its agent discovery layer on August 6 with 900+ services and no verification mechanism described. Coinbase's that platform indexes thousands of services but is pay-first β an agent spends before it knows the endpoint works. When listing is free and verification is absent, abandonment is the equilibrium. The Liveness Law is the pattern: the cheaper it is to get listed, the more of that registry is dead.
Verification has to be automated, continuous, and cheap. A probe is not a purchase β it is a single GET that costs nothing and asks one question: are you a real x402 endpoint, right now?
This is the probe minia2a runs against every endpoint at registration time. A pass is not "it returned something" β it must return a well-formed payment challenge:
// Probe a newly-registered endpoint before it is allowed to be listed.
// Pass = HTTP 402 with a well-formed x402 payment challenge.
async function probeEndpoint(endpoint) {
const res = await fetch(endpoint, {
method: 'GET',
redirect: 'manual', // do not follow redirects
signal: AbortSignal.timeout(10_000), // hard timeout, then fail
headers: { 'User-Agent': 'minia2a-x402-validator/1.0' }
});
if (res.status !== 402) {
return { ok: false, reason: `HTTP ${res.status}, expected 402` };
}
const pay = {
network: res.headers.get('x-402-network'),
chainId: res.headers.get('x-402-chain-id'),
currency: res.headers.get('x-402-currency'),
address: res.headers.get('x-402-address'),
};
// A real x402 host quotes settlement terms. A 402 with no payment
// headers is a wall, not a protocol endpoint.
return (pay.currency && pay.address)
? { ok: true, pay }
: { ok: false, reason: '402 without payment terms' };
}
Registration is the first gate, not the last. Every proxied call tracks health per service, and the failure threshold is ruthless β three consecutive failures and the listing is pulled from the registry entirely:
// Called on every failed upstream call. Three consecutive failures
// de-lists the service so no new agent can discover it.
function trackFailure(service) {
service.failedCalls = (service.failedCalls || 0) + 1;
service.consecutiveFails = (service.consecutiveFails || 0) + 1;
if (service.consecutiveFails >= 3) {
service.active = false; // auto-delisted β no longer discoverable
console.error(`[proxy] Auto-delisted ${service.name} β 3 consecutive failures`);
}
registry.save(service);
}
The distinction from a "liveness check" is that this runs inside the payment path. The audit probed once and published a snapshot; minia2a re-verifies on every call, so a service that goes dark is removed from the directory within three failures β before the next agent ever sees it.
The economic form of verification is a trial. Instead of trusting a registry entry, the agent calls the endpoint for free and judges the response itself. That is strictly stronger than any off-band probe: the agent verifies delivery, not just presence.
# Verify delivery before spending a cent.
curl -s https://minia2a.uk/x402/gas/preview # metadata: params, price
export WALLET=0xYOUR_WALLET SERVICE=x402-gas TS=$(date +%s)
export SIG=0xYOUR_SIGNATURE # EIP-191 personal_sign of: minia2a trial:$WALLET:$SERVICE:$TS
curl "https://minia2a.uk/x402/gas?wallet=$WALLET" \
-H "X-Wallet-Signature: $SIG" -H "X-Trial-Timestamp: $TS" # free trial (credits)
# Once credits are exhausted, the same URL becomes a real x402 wall:
curl -i https://minia2a.uk/x402/gas
# HTTP/1.1 402 Payment Required
# X-402-Network: base
# X-402-Currency: USDC
# X-402-Address: 0xf16Fβ¦4ECA
minia2a runs all three mechanisms in sequence: probe on register (presence), auto-delist after 3 consecutive failures (continuity), and trial-first (delivery). Every registered agent gets 5 free trial calls, and every endpoint is triable before a single USDC moves. As of this writing the live registry holds 326 services, has served ~12,000 free trials to 319 unique agents β and none of those trials went to an endpoint that failed its registration probe.
Three things would move the ecosystem past the audit's findings:
The audit's numbers are the spec for all three. A discovery layer that implements them turns a catalog of dead links into a market.
326 probed, continuously health-checked x402 services. Probe on register, auto-delist after 3 failures, 5 free trial calls per agent.
Inspect any endpoint live: curl https://minia2a.uk/x402/preview
Data sources: independent x402 endpoint audit (5,077 endpoints, July 2026); 24K Labs / gold-402 verification findings (CDP Bazaar, 22,545 endpoints, July 2026); Coinbase that platform registry analysis; Circle Agent Discovery launch (August 6, 2026); minia2a /api/stats (August 9, 2026).