{
  "markdown": "# SameDayDesk x402 and MPP Data Gateway\n\n## Optional bounded batch extraction\n\n`EXTRACT_BATCH_ENABLED=1` adds `POST /extract/batch` and MCP `extract_batch` at an\nintroductory 0.01 USDC per admitted batch of 1–5 public HTTPS URLs. The default\nis off: 25 paid HTTP operations and 22 MCP tools; enabled: 26 and 23. This price\nis not a measured margin guarantee. Use one server process and persistent\n`COMMERCE_DATA_DIR`; unknown settlement is quarantined, not automatically charged\nagain. Bounded partial output does not promise every source or requested field.\n\nThe new MCP tool projects the existing HTTP payment and durable replay handler.\nIts challenge resource is `https://agents.samedaydesk.com/extract/batch`, not\n`mcp://`: first call without payment, then reuse the returned HTTP resource and\nexact arguments with `_meta[\"x402/payment\"]`. MPP callers may use the unmodified\n`www-authenticate` challenge in result `_meta[\"samedaydesk/http\"].headers` and\nsend its credential as HTTP `Authorization`. That metadata also carries the\nHTTP status and receipt headers. Never translate an MCP-resource credential.\nExisting MCP tools retain their existing native MCP payment boundary.\n\nThe signed statement declares 25 standard route capabilities in either flag\nstate (Circle is separate); it does not claim that a disabled route is available\nor authorize payment. Live discovery excludes disabled batch extraction.\n\nEvery paid HTTP response advertises\n`/.well-known/agent-payment-evidence.json` through the standard HTTP\n`describedby` link relation. The bounded free manifest joins each exact method\nand route to its seller-declared read-only effect, recursively guaranteed JSON\npaths, response-schema digest, exact replay binding, receipt behavior, and the\nexisting signed deployment statement. It does not change x402 or MPP terms and\nis not authorization to spend; buyers must still verify the live challenge,\npaid output, receipt, and settlement.\n\n[![Smithery listing](https://smithery.ai/badge/epistemedeus/x402-data-gateway)](https://smithery.ai/servers/epistemedeus/x402-data-gateway)\n\nTwenty pay-per-call tools for deterministic agent-work opportunity preflight,\nmachine-service discoverability, payment-offer preflight, Morpho borrower and\nmarket decisions, protection plans, URL extraction, Markdown reading,\nrepository security scans, company and wallet enrichment, structured data\ngeneration, transaction receipt evidence, delegated-signer policy conformance,\nsettlement proof, and AI-search readiness audits.\n\n- Product page: https://samedaydesk.com/x402\n- Smithery: https://smithery.ai/servers/epistemedeus/x402-data-gateway\n- Remote MCP: https://agents.samedaydesk.com/mcp\n- Agent Plugins 1.0 local package: [`plugins/samedaydesk-x402`](plugins/samedaydesk-x402) (not marketplace-listed)\n- Claude Code marketplace: [`.claude-plugin/marketplace.json`](.claude-plugin/marketplace.json) plus [`plugins/samedaydesk-extract`](plugins/samedaydesk-extract) (`samedaydesk-extract@samedaydesk-claude`; not an Anthropic official directory listing)\n- Goose native config: [`goose/`](goose/) (YAML, session flag, and deeplink; not a Goose installer)\n- Live resource manifest: https://agents.samedaydesk.com/.well-known/x402\n- OpenAPI: https://agents.samedaydesk.com/openapi.json\n- Official MPP OpenAPI: https://agents.samedaydesk.com/mpp-openapi.json\n- Skill contract: https://agents.samedaydesk.com/skill.md\n- Action catalog: https://agents.samedaydesk.com/api/actions\n- A2A agent card: https://agents.samedaydesk.com/.well-known/agent-card.json\n- Global A2A Registry: https://www.a2a-registry.org/agent/9cb0b8e6-cb1f-422b-a604-861d0a79e24b\n- Settlement Radar: https://agents.samedaydesk.com/platforms\n- Platform health JSON: https://agents.samedaydesk.com/v0/cards.json\n- Aggregate machine-demand telemetry: https://agents.samedaydesk.com/v0/commerce-demand.json\n- Morpho position risk: `GET /defi/morpho-position?address=0x...&shocks=-10,-20,-30`\n- Morpho protection quote: `GET /defi/morpho-protection?address=0x...&targetHealthFactor=1.25&protectAgainstShockPct=-10`\n- Morpho market underwriting: `GET /defi/morpho-market-underwrite?marketId=0x...`\n- Morpho PreLiquidation replay: `GET /defi/morpho-preliquidation-replay?transactionHash=0x...`\n- Opportunity preflight: `GET /work/opportunity-preflight?rewardUsd=10&hours=0.25&hourlyCostUsd=4&selectionProbabilityPct=20`\n- Agent discoverability audit: `GET /distribution/agent-discoverability-audit?origin=https://example.com&intent=extract+a+public+website+into+structured+JSON&route=/extract&method=GET&runtimeUrl=https%3A%2F%2Fexample.com%2Fextract%3Furl%3Dhttps%253A%252F%252Fexample.org&surfaceAudit=true&materializationAudit=true`\n- Payment offer preflight: `GET /commerce/payment-offer-preflight?url=https://example.com/paid-route`\n- Seller integrity audit: `GET /commerce/seller-integrity-audit?origin=https://seller.example&route=/paid-route&method=GET&requiredPaths=data.attributes`\n  - A buyer may add `referral=r1_<sha256>` derived from its complete seller-signed x402 settlement receipt. This creates a declared acquisition label, not verified proof. `POST /commerce/referral-recheck` accepts that receipt plus one downstream seller-signed settlement receipt from a distinct payer and transaction, then atomically grants at most one free changed-state recheck. The receipts prove neither an application HTTP 200 response nor output delivery or validity, and public posting or broadcasting is optional. A file matching Agent402 PR 1070's observable capture contract (bare pretty JSON receipt, no bundled Agent402 source) is already a drop-in input after ordinary `JSON.parse`; see [`docs/agent-outcome-referral-experiment.md`](docs/agent-outcome-referral-experiment.md) and `agent402-receipt-interop.test.mjs`.\n- Contract-qualified search: `GET /commerce/contract-qualified-search?query=service+domain+ownership+code+provenance&requiredPaths=data.sourceRepository`\n  returns a bounded advisory OpenAPI repair plan for missing buyer-required\n  paths without mutating seller files or inferring undeclared property types.\n- Base USDC settlement proof: `GET /commerce/settlement-proof?transactionHash=0x...&recipient=0x...&amountAtomic=5000`\n- Base or Ethereum transaction receipt: `GET /chain/transaction-receipt?transactionHash=0x...&network=base`\n- Wallet policy conformance: `POST /security/wallet-policy-conformance`\n- Wallet policy conformance contract: `GET /schemas/wallet-policy-conformance-v1.json`\n- Stateful wallet policy conformance: `POST /security/stateful-wallet-policy-conformance`\n- Stateful wallet policy contract: `GET /schemas/stateful-wallet-policy-conformance-v1.json`\n- Material-change alert probe: https://agents.samedaydesk.com/alerts\n- Agoragentic seller callback: `POST /integrations/agoragentic/ai-readiness-audit`\n- the402 signed fulfillment webhook: `POST /integrations/the402/webhook`\n\nNo API key or subscription is required. Every paid HTTP route advertises x402\nand native MPP Payment authentication in the same 402 response. Both protocols\nsettle the same exact USDC amount to the same Base mainnet merchant wallet. MCP\ntool calls remain x402-gated.\n\nThe Morpho route is read-only. It calculates LTV, LLTV, health factor,\nliquidation headroom, and collateral-price shock scenarios from integer protocol\nvalues, then cross-checks indexed collateral, borrow shares, and oracle price\nagainst direct Base RPC state. Scenarios are calculations rather than\nprobabilities or transaction recommendations. The separate protection route\nuses a fresh direct-RPC oracle read and direct confirmation of collateral and\nborrow shares to calculate exact partial-repay and add-collateral amounts. It\nreturns unsigned token-approval and Morpho-call templates, explicit execution\nbuffers, revalidation requirements, and economic postconditions. It never\naccesses a wallet, signs, broadcasts, or takes custody.\n\nThe service also keeps a privacy-safe demand telescope on a persistent Railway\nvolume. It records route families, query key names, challenge/success classes,\nand pseudonymous repeat-use signals. External fetches are acquisition signals,\nnot verified buyers, because unidentified automated indexers can remain.\nRecognized crawler and agent-indexer user agents are reduced at ingestion to a\ncontrolled source label and reported in a separate machine-discovery lens with\nsource and route coverage. Those observations measure fetches, not authenticated\ncatalog referrals, intent, or demand.\nUnmatched requests are reported separately from a conservative semantic-candidate\nsubset; neither becomes demand until an independent caller repeats or converts.\nIt does not record raw IP addresses, user\nagents, URLs, query values, bodies, payment headers, marketplace payloads, or\ncredentials. Public output is aggregate only; owner traffic is excluded and\ncrawler traffic remains excluded from demand even when its controlled discovery\ncounts are reported separately. Common exploit probes such as `.env`, `.git`,\nand WordPress discovery paths are classified as scanner traffic and excluded as\nwell.\n\nVersion 1.9.4 adds explicit paid-traffic classes without exposing buyer\naddresses. `COMMERCE_PAYER_CLASSES` accepts a JSON array of `{ \"address\",\n\"class\" }` records. Controlled classes are `internal`, `validation`,\n`incentivized`, `affiliated`, and `independent`. Addresses are converted to the\nsame secret-keyed payer pseudonyms already used by telemetry and classified at\nread time, which also permits retroactive correction without storing a raw\naddress. Unknown payers remain `unclassified`; unfamiliar wallets never become\nindependent demand by inference. The public snapshot reports paid success by\nclass plus independent and repeat-independent actor counts.\n\nVersion 1.9.5 adds route-level paid-success counts inside each evidence class.\nThis lets downstream monitors treat marketplace validation as accounting and\ntransport evidence, alert on unclassified paid use for investigation, and\nadvance the demand thesis only for explicitly independent or repeat-independent\nbuyers.\n\nVersion 1.9.6 privately captures a valid Base transaction hash from successful\nx402 `PAYMENT-RESPONSE` or MPP `Payment-Receipt` headers after an explicit\nevidence baseline. Public telemetry exposes only proof coverage, distinct-count,\nand missing-reference counts by payment class. Raw headers and transaction\nreferences stay on the private volume. A missing reference becomes a material\nsettlement-integrity event without exposing the reference itself.\n\nVersion 1.11.2 content-negotiates the root without changing its machine\ncontract. Browser navigation with an explicit `Accept: text/html` receives a\nresponsive human map of the fourteen tools, payment flow, and authoritative\ndiscovery links. JSON clients, curl's wildcard accept header, and agents keep\nthe stable JSON descriptor. The response varies on `Accept`, and the human page\nduplicates no payment schema.\n\nVersion 1.11.2 also adds the source-attributed machine-discovery lens. It keeps\nraw user agents and network addresses out of the public snapshot, reports exact\nfuture indexer observations by controlled source and route, and gives the radar\nonly first-source and first-route coverage changes as material events. Repeated\ncrawl volume remains visible data without becoming an attention alert or demand.\n\nVersion 1.11.3 makes that reach lens prospective and self-excluding. A distinct\n`COMMERCE_AGENT_DISCOVERY_SINCE` baseline prevents pre-instrumentation crawler\nhistory from becoming attributed reach, while SameDayDesk-owned monitor user\nagents are excluded from both discovery and external-demand observations. This\nkeeps integrity sweeps, brand-blind benchmarks, and radar probes from creating\ntheir own acquisition signal.\n\nVersion 1.11.4 preserves paying agents even when their user agent identifies as\na crawler or indexer. A valid submitted x402 or MPP credential moves the event\ninto economic telemetry before crawler classification, while the controlled\nuser-agent label records source-to-paid conversion by source and route. Channel\nlabels are still self-declared rather than authenticated referral proof, and\nindependent demand still requires the explicit payer-class policy.\n\nVersion 1.11.5 separates paid-route reach from challenge delivery. Prospective\nagent/indexer observations now report paid-route probes, HTTP 402 challenges,\ndistinct and repeat challenge actors, challenge rate, and controlled source and\nroute breakdowns. This identifies whether the machine funnel stops before the\npaywall, at the challenge, or after a submitted credential without treating an\nindexer probe as purchase intent.\n\nVersion 1.11.6 adds a conservative challenge-to-payment cohort. A paid success\ncounts as continuation only when the same secret-keyed network-and-user-agent\nactor returns after its first prospective challenge. The public snapshot\nreports converted calls, converted actors, independent converted actors,\nconversion rate, and controlled source and evidence-class totals without actor\nIDs. Network or user-agent drift can only create false negatives, so the metric\nis a lower bound rather than an identity claim.\n\nVersion 1.11.7 adds project-owned Glama connector verification at\n`/.well-known/glama.json` using the public SameDayDesk business email. Glama\nrequests have their own controlled discovery-source label, so a propagated\ndirectory claim can be measured without becoming demand.\n\nVersion 1.11.8 starts a separate credential-attempt funnel. After a declared\nbaseline, a parseable attempt must include a syntactically complete x402 v2\nexact binding or MPP evm/charge credential. Signature validity and settlement\nremain later outcomes. Public aggregates separate header noise from parseable\nattempts and report protocol, result, route, controlled source, and explicit\npayer class without raw credentials, actor IDs, or addresses.\n\nVersion 1.11.9 improves MCP tool selection without renaming or duplicating any\ntool. Every tool now has a unique action-oriented title. The overlapping web\nand company tools explicitly say when to choose `extract` versus `read`,\n`enrich` versus `schemaforge`, and the combined `deep_audit`; `wallet_enrich`\nalso states that its input is an EVM address rather than a company domain. The\npayment routes, names, prices, schemas, and handlers are unchanged.\n\nVersion 1.11.10 adds explicit descriptions to every `opportunity_preflight`\ninput and to the three Morpho protection controls. This improves machine call\nconstruction while leaving names, routes, prices, required inputs, defaults,\npayment gates, and execution behavior unchanged.\n\nVersion 1.11.11 gives all four Morpho MCP tools explicit sibling-selection\nguidance. Borrower diagnosis, future protection planning, market underwriting,\nand historical PreLiquidation replay are now distinct machine choices without\nrenaming a tool or changing its route, price, schema, payment gate, or handler.\n\nVersion 1.11.12 starts a prospective MCP transport-friction probe. It separates\nfour common client expectations, `/mcp/sse`, `/mcp/messages`, `/mcp/tools`, and\n`/mcp/events`, from arbitrary `/mcp/*` misses without serving a guessed alias.\nPublic aggregates expose only route counts and secret-keyed actor totals. A\ncompatibility route is justified only by repeated independent use or conversion.\n\nVersion 1.11.13 repairs the pre-payment response contract exposed to machine\nbuyers. All thirteen routes already authored explicit JSON output schemas, but\nthe Bazaar v2 helper expects that schema under `output.schema`; the previous\ntop-level `outputSchema` field was silently ignored. A single tested adapter now\nplaces each authored schema at the protocol-defined location, so an unpaid 402\nchallenge exposes both the example and the concrete required response fields\nbefore an agent authorizes payment. Routes, inputs, prices, settlement, and\nhandlers are unchanged.\n\nVersion 1.11.14 projects the same thirteen response contracts into the free\nOpenAPI and action catalog. Discovery agents can now inspect concrete required\nfields and an example before probing a paid route; `/read` is also described as\nthe JSON object its handler actually returns rather than a raw Markdown string.\nOne route-keyed contract map drives the x402 challenge, OpenAPI, and action\ncatalog to prevent the three machine surfaces from drifting apart.\n\nVersion 1.11.16 links the versioned, credential-free\n[`agent-payment-policy`](https://github.com/epistemedeus/agent-payment-policy)\nreference from the machine root, OpenAPI service metadata, and `llms.txt`. The\nreference has no wallet executor, payment signer, custody, or hosted paid\nverifier. It gives machine buyers a stable policy and evidence primitive without\nchanging the merchant's routes, prices, payment requirements, or settlement.\n\nVersion 1.13.1 advances that machine-facing buyer reference to public package\n0.4.0. The root, OpenAPI metadata, and `llms.txt` now advertise exact\nexecution-shape authorization plus fourteen-dimension control-coverage schema\nv2. This follows first-person Tempo and Solana evidence that provider-native\nmethod and instruction allow rules can admit duplicated approved actions. No\nmerchant route, price, handler, payment requirement, or settlement changes.\n\nVersion 1.14.0 turns the cross-chain delegated-signer failure we encountered\ninto a credential-free paid product. `POST /security/wallet-policy-conformance`\naccepts only a bounded standardized allow, deny, and error matrix. It separates\noperation allowlisting from exact execution-shape control, credits only an\nexplicit provider policy denial as provider-native enforcement, and returns\n`conformant`, `partial`, or `unsafe` with no opaque score. Invalid or\nsecret-bearing shapes are rejected before payment. The evaluator accepts no\nwallet credential, signature, transaction body, wallet access, or broadcast\nauthority and does not claim to have executed the caller's provider tests.\n\nVersion 1.14.1 publishes the exact standardized cases, evidence classes, input\nschema, output schema, method, protocols, and atomic price at the free canonical\n`/schemas/wallet-policy-conformance-v1.json` contract. The paid route, price,\ndecision logic, payment gates, and settlement remain unchanged. Machine clients\ncan now construct and validate the matrix without decoding a payment challenge.\n\nVersion 1.14.2 moves the taxonomy, strict validator, offline evaluator, and JSON\nSchemas into public `agent-payment-policy@0.5.0`; the hosted product now imports\nthat package instead of maintaining a private duplicate. The public package\nalso provides `wallet-policy-init`, `wallet-policy-check`, and\n`wallet-policy-schema` CLI commands. An unrun intended case is correctly\n`partial`, while a proven blocked intended action or an allowed mutation remains\n`unsafe`. The hosted route, 0.01-USDC price, payment terms, and credential-free\nboundary remain unchanged.\n\nVersion 1.14.3 advances the public standard dependency to\n`agent-payment-policy@0.5.1`. Provider-native control credit now requires every\nobserved case for that control to pass. A denied optional shape case can no\nlonger mask an allowed duplicate-approved-action case. The Privy Tempo and\nSolana adapters both classify exact execution shape as unverified and the\noverall native policies as unsafe, matching the first-person evidence. Route,\nprice, payment, and credential boundaries remain unchanged.\n\nVersion 1.15.0 adds a separate stateful wallet-policy product from the project's\nfirst-person Privy cumulative-cap experiment. `POST\n/security/stateful-wallet-policy-conformance` evaluates seven safe standardized\ncases for sequential caps, signed-but-unbroadcast accounting, ABI extraction,\nconcurrent oversubscription, counter-reference failure, and application\nserialization. `GET /schemas/stateful-wallet-policy-conformance-v1.json`\npublishes the free construction contract. The evaluator comes from public\n`agent-payment-policy@0.6.0`, accepts no credentials or raw provider payloads,\nand keeps provider-policy and application enforcement separate.\n\nVersion 1.15.1 turns first-person stale-catalog evidence into a bounded\ndiscoverability-audit feature. Callers can provide `expectedPriceUsd` together\nwith an exact route to compare catalog-advertised route prices across the ten\npublic discovery views. The result distinguishes matched, drifted, mixed,\nunknown-price, and absent-route states and returns a one-canary maximum\nremediation sequence only after owned live terms agree. It never treats the\ncaller expectation as runtime truth, makes no catalog payment, and leaves\nasynchronous propagation to event-driven monitoring.\n\nVersion 1.15.2 repairs the measurement path for the two free wallet-policy\ncontracts and their matching paid evaluators. All four routes now have exact\ncommerce classifications. Historical `/schemas/*` events remain in the raw\nunmatched count but are excluded from semantic-demand interpretation because\nthe privacy-safe ledger did not retain enough path detail to reclassify them.\nNew exact events produce aggregate same-client funnels from successful free\ncontract read to paid-route challenge, parseable credential, and delivery.\nThe public snapshot exposes no actor, credential, raw path, wallet, or provider\npayload, and contract reads remain reach evidence rather than demand.\n\nVersion 1.16.0 upgrades payment-offer preflight from protocol parity alone to\noptional catalog-to-runtime coherence. A caller can submit one exact catalog\ncandidate with the POST or MCP form, and the product compares it only with the\nmatching live unsigned protocol offer across request, protocol, amount,\nnetwork, asset, recipient, and expiry using public\n`agent-payment-policy@0.7.0`. Explicit drift produces `review_required`;\nmissing catalog fields remain a visible partial result. The x402 validity\nwindow is derived from `maxTimeoutSeconds`, malformed catalog input is rejected\nbefore payment, and the request still uses no target credential, wallet,\nsignature, settlement, redirect, or response body.\n\nVersion 1.16.1 upgrades the existing agent-discoverability audit without adding\nanother product or changing its 0.05-USDC price. An optional `runtimeUrl` must\nuse the audited origin and exact requested route. The audit makes one\ncredential-free, DNS-pinned, headers-only request, accepts a price reference\nonly when the live unsigned x402 and MPP terms are parseable and coherent, and\nthen compares that canonical Base-USDC amount with every registry observation.\nCaller-supplied expectations remain supported and clearly labeled, while a\ndisagreement with runtime truth becomes its own finding. The result still\nsigns nothing, sends no target payment, follows no redirect, and reads no target\nresponse body.\n\nVersion 1.16.2 adds route-level listing identity to that same audit. Each\ncatalog observation now reports whether the exact route is canonical,\nduplicated, alias-only, or split across canonical and non-canonical origins.\nAn alias candidate requires an explicit payTo and exact-route match, and the\noutput states that this does not prove hostname ownership. This catches stale\nmarketplace aliases and URL-keyed duplicate listings alongside price drift,\nwhile preserving the same 0.05-USDC product, request boundary, and no-spend\ncatalog sweep.\n\nVersion 1.16.3 makes the identity evidence boundary explicit. A\nnon-canonical record that shares the caller-supplied payTo and exact route is\nan alias candidate, not proof that the seller owns the hostname. Every source\nnow returns `identityBasis`, `ownershipProven`, and a plain-language evidence\nboundary so an automated repair can preserve the canonical record without\nretiring a third-party endpoint on circumstantial evidence.\n\nVersion 1.23.35 extends that existing audit without adding a route or changing\nits 0.05-USDC price. With `materializationAudit=true`, an exact GET or POST\nroute is checked through Coinbase's current seller validator and exact-resource\nBazaar readback. The result distinguishes `materialized`,\n`provider_accepted_not_materialized`, `seller_not_provider_eligible`, and\n`unresolved` instead of treating every missing ranked result alike. Validation\nacceptance remains provider-returned point-in-time evidence, not listing,\ndemand, settlement, or reindex authority. The opt-in check uses no credential,\nsignature, or payment; Coinbase may make one unpaid request to the seller using\nthe requested method.\n\nVersion 1.16.4 replaced the route-audit's private identity classifier with the\npublic, provenance-bearing `agent-payment-policy@0.8.0` primitive. Catalogs\nthat return no matching records are now still recorded as checked and\n`route_absent`; canonical origin matches remain observations rather than\nownership claims. This creates one shared, installable contract for the live\nseller and independent buyer tooling without adding credentials, wallet\naccess, signing, payment, or retained settlement identities.\n\nVersion 1.18.3 completes machine-constructible examples for the Base settlement\nproof and Solana receipt routes and gives the Circle Gateway alias the same\nauthored success-response schema as the canonical payment-offer preflight.\n\nVersion 1.18.2 publishes recursive response reports under their immutable v2\nschema identifier.\n\nVersion 1.18.1 adds recursively guaranteed response paths to the bounded report,\nso a seller that requires only a top-level `data` envelope does not appear to\npromise a nested `data.attributes` decision payload.\n\nVersion 1.18.0 keeps the signed catalog-alias identity control and adds a\nbounded seller response-contract check to payment-offer preflight. The route\nnow reads the exact seller's same-origin public OpenAPI document under a strict\nsize cap and reports whether the exact GET operation declares a self-contained\nJSON success schema with typed required fields. It never reads the paid target\nbody, and the seller declaration remains advisory until a paid response passes\nthe buyer's independently authorized output validator.\n\nVersion 1.22.3 turns seller declarations that exceed the bounded audit byte\nceiling into the specific `openapi_too_large` gap instead of a generic bounded\naudit failure. The ceiling remains unchanged and no schema is inferred.\n\nVersion 1.22.2 excludes both the canonical SameDayDesk origin and its known\nformer Railway catalog alias from contract-qualified search. Agent402 ranked\nboth records for the first live buyer-language query, proving that excluding\nonly the canonical hostname did not exclude owned supply at the service-\nidentity level.\n\nVersion 1.22.1 adds mandatory MCP selection metadata for the new search tool\nand strengthens the production startup smoke test so a release cannot pass\nmerely because HTTP is listening while the asynchronous MCP mount failed.\n\nVersion 1.22.0 adds a paid contract-qualified machine-service search. A buyer\nsupplies a capability intent and recursively required JSON response paths. The\nroute searches Agent402 and the official MPP catalog, excludes owned supply and\nunresolved routes before audit, and returns bounded machine-buyable or\ncontract-ready candidates plus controlled rejection codes. It uses no\ncredential or wallet, sends no seller POST or target payment, reads no paid\nbody, and returns only a query digest. The signed deployment statement now\nbinds twenty-three exact HTTP method and path pairs.\n\nVersion 1.17.0 closed the catalog-alias ambiguity with an optional signed\ndeployment statement from `agent-payment-policy@0.9.0`. The short-lived JWS at\n`/.well-known/agent-payment-policy-service-deployment.json` binds the canonical\n`agents.samedaydesk.com` origin to the then-current paid HTTP method and path pairs\nand to the exact Base USDC x402 and MPP settlement identities. Each deployment\norigin carries its own route and settlement scope, so a future alias cannot\ninherit another origin's authority.\n\nThe public Ed25519 key at\n`/.well-known/agent-payment-policy-service-deployment.pem` is the same raw key\nas the `agentWallet` in SameDayDesk's Solana ERC-8004 registration. The signing\nkey remains offline and is not deployed. The JWS response stays a strict\nenvelope; its key and registration pointers use HTTP `Link` headers and the\nERC-8004 registration document. `/healthz` reports the statement ID, key\nfingerprint, route count, expiry, and active state so rotation can be monitored.\nThe statement proves control of that registered key and the declared service\nbinding. It does not authorize, sign, or send a buyer payment.\n\nVersion 1.11.15 validates every Bazaar declaration against its own JSON Schema\nbefore startup. Six newer routes previously settled successfully while Coinbase\nrejected their discovery metadata because their output examples omitted fields\nmarked required by the same schemas. The examples now conform, and\n`bazaar-contract-audit.mjs` checks every live CDP Bazaar-eligible paid route\nthrough credential-free HTTP 402 probes without retaining headers or query\nvalues. Alternate x402 settlement rails are reported as explicit exclusions\ninstead of being misclassified as failed Bazaar declarations.\n\nVersion 1.11.18 adds a source-quality funnel to the public aggregate. Each\ncontrolled discovery source now reports observations alongside distinct and\nrepeat actors at discovery, paid-route, challenge, credential-attempt, and paid\nsuccess stages. Challenge rates are available both per request and per actor,\nso one high-frequency crawler no longer looks like broad machine reach.\nChallenge-to-payment conversions are attributed to the source of the first\nobserved challenge. Raw user agents, network addresses, and actor identifiers\nremain private and are not returned.\n\nVersion 1.11.19 starts a separate prospective AI-provider source cohort. It\nuses exact provider-published HTTP tokens to distinguish OpenAI, Anthropic, and\nPerplexity search, user-fetch, and training traffic plus Google Cloud Vertex\nagent crawls. `Google-Extended` is intentionally excluded because Google states\nthat it has no distinct HTTP user-agent string. The detail cohort has its own\nbaseline, preserves historical generic records, reports the same actor funnel,\nand treats every label as an unauthenticated observation rather than referral\nproof.\n\nVersion 1.11.20 repairs the resource metadata consumed by payment-capable\nwallet agents. Every one of the fourteen x402 v2 challenges now carries the\nvalidated provider-level `serviceName` and five bounded route capability tags\nin the standard top-level resource object. Startup fails closed if paid-route\ncoverage and metadata coverage diverge. The Bazaar contract audit now rejects\na route whose extension is valid but whose resource name or tags are absent or\ninvalid.\nPrices, outputs, settlement, privacy, routes, and native MPP terms are unchanged.\n\nVersion 1.12.0 adds `/chain/transaction-receipt` at 0.002 USDC after a live\nmarket experiment found provider-level settlement for cheap chain utilities but\ntwo zero-spend delivery failures from a heavily viewed competing receipt route.\nThe new route accepts one mined Base or Ethereum transaction hash and returns\nnormalized status, block time, gas and fee fields, decoded ERC-20 Transfer\nevents, and canonical USDC transfers. Invalid hashes and unsupported networks\nare rejected before payment. Raw logs, wallet access, signing, and broadcast are\noutside the product boundary.\n\nVersion 1.12.1 repairs the authenticated delivery boundary for the Solana\n`/commerce/payment-offer-preflight` storefront. After the Solana gateway has\nverified and settled its own x402 or MPP payment, its private internal header\nnow reaches the deterministic product directly instead of encountering a\nsecond Base payment gate. Requests without the exact private header retain the\nordinary Base x402 and MPP behavior. Target credentials and target payments\nremain outside the preflight product boundary.\n\nVersion 1.12.2 keeps seller-owned discovery surfaces synchronized with the\ncanonical paid action catalog. The A2A Agent Card now uses the actual service\nversion, retains the aggregate catalog skill first, and appends one explicit\ndiscovery-only skill per paid route. The ERC-8004 registration document retains\nits protocol entry points and adds the same direct paid action URLs. The A2A\ndescriptor reuses the canonical aggregate skill ID, and inbound messages must\ncarry the normative user role, message ID, and at least one part. These changes\nimprove route discovery but do not claim support for unimplemented A2A task\noperations.\n\nVersion 1.12.3 turns that discovery lesson into an optional seller audit. Set\n`surfaceAudit=true` on the existing paid discoverability route to check whether\nthe expected route appears in the target's public A2A Agent Card, ERC-8004\nregistration document, and action catalog. The target fetch is restricted to\nthree fixed same-origin JSON paths, pins a fully public DNS answer, rejects\nredirects, caps each response at 512 KiB, and times out after five seconds. The\ndefault remains catalog-only and does not fetch the target origin.\n\nVersion 1.12.4 gives the JSON `POST /work/opportunity-preflight` probe the same\ncomplete Bazaar input and output contract as the existing GET route. This\nremoves machine-discovery schema errors without changing the price, validation,\nhandler, response, or payment behavior. Empty unauthenticated POST remains a\ndiscovery-only challenge; a paid call must still supply and bind the required\nbody.\n\nVersion 1.13.0 adds a 0.002-USDC finalized Solana transaction-receipt product.\nIt validates the signature and any optional mint, recipient, amount, and payer\nclaim before payment, then returns bounded finalized status, fee, SPL-token\nowner deltas, canonical-USDC deltas, and deterministic match findings. It reads\npublic RPC state only after settlement and has no wallet, signing, custody, or\nbroadcast authority. The route is available through Base x402, native MPP,\nMCP, A2A, and the separate Solana payment gateway.\n\nVersion 1.11.23 adds a narrow compatibility bridge for MCP clients that retry a\npaid `tools/call` with the x402 `PAYMENT-SIGNATURE` HTTP header but fail to copy\nthe same signed payload into `_meta[\"x402/payment\"]`. The merchant decodes only\na bounded, object-shaped header on `tools/call`, never overrides canonical MCP\nmetadata, and passes the result to the existing `@x402/mcp` verifier. The bridge\ndoes not trust the header, change payment terms, or bypass signature, amount,\nasset, network, nonce, or settlement validation.\n\nVersion 1.11.24 publishes each tool's exact live x402 payment options in MCP\n`tools/list` metadata. Compatible clients can inspect price, asset, network,\nrecipient, and scheme before calling, then attach a fresh signed payload to the\nfirst `tools/call` instead of relying on a challenge retry. Runtime verification\nand settlement remain authoritative, and the unpaid challenge path is unchanged.\n\nVersion 1.11.26 sharpens the machine-facing selection contract for\n`/commerce/payment-offer-preflight`: compare x402 and MPP payment challenges and\nterms before buyer authorization. The 0.005-USDC product still accepts one exact\npublic HTTPS GET URL and returns normalized offers, URL and realm binding checks,\nexpiry findings, and economic parity. It rejects credentials, local or\nnon-public targets, unresolved parameters, and redirects, pins a public DNS\nresult, reads only response headers, never signs or sends a target payment, and\nreturns no opaque challenge state.\n\nVersion 1.11.27 keeps the compact `/skill.md` agent contract synchronized with\nthe fourteen-route action catalog. It now names payment-offer preflight in its\nselection vocabulary and states the target-inspection boundary: no credential,\ntarget signature or payment, redirect, or response-body read. A regression test\nkeeps this focused buyer-authorization product present in future releases.\n\nVersion 1.11.28 removes the manual route-inventory failure mode. The compact\ncontract now renders and validates every paid action, exact price, and supported\nprotocol from the canonical machine action catalog. Empty, malformed, or\nduplicate action contracts fail closed, so a future route addition cannot leave\nthe compact agent surface silently stale.\n\nVersion 1.11.29 adds a free machine-catalog handoff for AgenticTrade without\nplacing a second payment gate in front of SameDayDesk. The catalog tells buyers\nto call the selected action URL directly, satisfy its route-bound x402 or MPP\nchallenge, and optionally carry the declared `agentictrade-v1` source label.\nThat label enters the measured discovery-to-payment funnel, stores no raw token,\nand cannot change price, payment, or access.\n\nVersion 1.11.30 adds a value-free AgenticTrade proxy diagnostic on the catalog\nresponse. It reports only which `X-ACF-*` header names reached the origin and\nwhether signature, timestamp, and usage proof fields are present. It never\nreturns their values, and proxied responses are marked `private, no-store`.\n\nVersion 1.11.31 includes the same value-free diagnostic in the proxied catalog\nbody because AgenticTrade intentionally returns only its own billing headers to\nthe caller. Direct catalog responses remain unchanged and publicly cacheable.\n\nVersion 1.9.7 privately reconciles each post-baseline reference against its\ncanonical Base receipt. A record is accepted only when the transaction\nsucceeded, exactly one canonical Base USDC transfer reached the configured\ntreasury, the atomic amount matches the paid response, and the transfer sender\nmatches the request payer pseudonym when available. Duplicate references and\nall mismatches fail closed. The private mode-0600 ledger retains the reference;\npublic health and demand output expose only aggregate settlement counts, atomic\namounts by evidence class and route, issue counts, and a generic error state.\n\nVersion 1.9 adds same-route MPP `evm/charge` support to all twelve paid HTTP\ncapabilities without replacing the existing x402 middleware. An unpaid request\nnow carries both `WWW-Authenticate: Payment` and `PAYMENT-REQUIRED`. Native MPP\ncredentials use `Authorization: Payment` and successful calls return\n`Payment-Receipt`; x402 keeps its Bazaar, payment-identifier, signed\noffer/receipt, and `PAYMENT-RESPONSE` extensions. MPP challenges are bound to the\ncanonical method, path, and sorted query. Both protocols participate in\nprivacy-safe telemetry and request replay, and OpenAPI 3.1 exposes valid\nper-operation `x-payment-info` offers.\n\nVersion 1.9.3 generates two registry-specific discovery views from the same\nroute and price source. `/openapi.json` carries the structured USD price,\nprotocol declarations, agent guidance, public-route auth declarations, and\ntruthful response schemas used by AgentCash and MPPScan.\n`/mpp-openapi.json` carries official MPP `offers[]` without incompatible flat\nfields. Stable operation IDs and capability tags make the public catalog easier\nfor agents to search, rank, and invoke. Runtime 402 challenges remain\nauthoritative for both views.\n\nVersion 1.23.6 extends request-bound replay to every paid JSON POST route and\nbinds the replay fingerprint to both the exact previously settled payment\ncredential and the exact raw request bytes. This lets a lost successful POST\nresponse be replayed without executing the handler or charging again, while a\nchanged credential, body, input, payer, or payment term fails with an uncharged\nHTTP 409. Version 1.23.7 publishes an experimental read-only effect contract at\n`/.well-known/paid-action-effects.json`, in each paid POST OpenAPI operation,\nand in response headers. It also keeps unpaid paid-POST requests out of\napplication telemetry, while stating that protocol challenge state may still\nexist and that payment-response replay is not business-effect idempotency. No\nexternal standard adoption is claimed. Version 1.8 adds a deterministic paid\nopportunity preflight. The caller supplies\nreward, execution time, hourly opportunity cost, compute, mandatory spend,\nreusable value, competition, and an explicit selection probability. The result\nreturns `attempt`, `verify_first`, or `abandon`, transparent break-even economics,\nhard access and funding gates, and an optional dated Settlement Radar card. It\ndoes not scrape a restricted board or touch a source-platform account, claim,\nbid, payment, or submission. Version 1.7 added request-bound idempotent replay\nfor HTTP buyers that supply the\nx402 payment-identifier extension. A successful JSON response is cached for 15\nminutes on the private Railway volume. The cache key is an HMAC of the logical\npayment ID, and the binding covers the full canonical URL, HTTP method, payer,\nnetwork, asset, amount, and recipient. Raw payment IDs, payer addresses, and\nrequest URLs are not stored. An exact retry receives the original response and\nsigned settlement receipt without a second payment; changed input, payer, or\npayment terms return an uncharged HTTP 409. Replays are counted separately from\nnew paid-success events.\n\nObserved agent crawlers use several discovery conventions. The canonical\nmanifest remains `/.well-known/x402`, with compatible aliases at\n`/.well-known/x402.json`, `/x402.json`, and `/api/x402`. The AgentCash-compatible\nOpenAPI document remains `/openapi.json`, with `/openapi.yaml` and\n`/swagger.json` returning the same JSON document. Official MPP discovery uses\n`/mpp-openapi.json`, with `/openapi.mpp.json` as an alias. `GET /mcp` returns a free transport descriptor;\nactual MCP discovery and paid tool calls use streamable HTTP at `POST /mcp`.\nAgents that prefer a compact instruction contract can read `/skill.md` (or\n`/SKILL.md`), while `/api/actions` returns the thirteen canonical GET actions with\ntheir URL, description, exact atomic USDC price, MIME type, network, and payTo.\nAgent Skills clients may send\n`X-SameDayDesk-Agent-Source: agent-skills-v1` on the initial request and paid\nreplay. Telemetry reduces that exact allowlisted value to the public-safe\n`agent-skills` label and never stores the raw header. This is declared,\nspoofable attribution rather than authentication, and it cannot change price,\npayment, or access.\nThe A2A v1.0 card at `/.well-known/agent-card.json` advertises one bounded free\nskill, `discover-x402-paid-actions`. `POST /a2a/message:send` returns that exact\ncatalog as an A2A direct message, giving A2A clients a standards-based path from\nagent discovery to the existing paid x402 actions without claiming arbitrary\ntask execution.\n\nThe repository-root `agent-card.json` is a compatibility manifest for the\nGlobal A2A Registry's current GitHub importer. It points back to the canonical\nv1.0 Agent Card and OpenAPI document; it does not replace the production card.\nThe registry's own generated ownership manifest is hosted separately at\n`https://samedaydesk.com/.well-known/agent-card.json`; the standards-compliant\nA2A v1.0 card remains canonical on `agents.samedaydesk.com`.\n\n## PreLiquidation shadow watcher\n\n`morpho-preliquidation-shadow.mjs` is the observation-only forward evidence\nlane selected by the complete Base census. It watches the five markets that\nconcentrate historical execution, derives each market's actual PreLiquidation\nhealth threshold from LLTV and pre-LLTV, checks every observed authorization\ndirectly at one explicit Base block, and uses per-contract event cursors.\n\nNew execution transactions are replayed through the deterministic archive-RPC\nengine, up to 20 per run. The record includes detection latency, gross\nloan-asset incentive, and native gas while retaining the explicit boundary that\nswap, funding, failure, competition, and MEV costs remain outside the replay.\nPositions below the explicit 1 USD debt observation floor are classified as\ndust rather than opportunities.\n\n```bash\nnode morpho-preliquidation-shadow.mjs \\\n  --state /data/morpho-preliquidation-shadow-state.json \\\n  --history /data/morpho-preliquidation-shadow-history.ndjson\n```\n\nState and history files are forced to mode 0600. A material change means a new\nor removed authorization, a transition into or out of the protocol-specific\nrisk window, a large liquidity or utilization move, or a new verified\nPreLiquidation execution. No wallet, signer, authorization, custody, or\nprincipal is part of the watcher.\n\nThe Agoragentic callback is a separate marketplace distribution bridge. The\nmarketplace handles buyer routing, settlement, and seller accounting, while the\ncallback performs the same production AI-search-readiness audit behind a small\nper-IP safety cap. Direct agent customers continue to use the paid x402 route.\n\nThe the402 bridge is a second marketplace distribution path. It authenticates\nsigned job dispatches with timestamped HMAC verification, accepts callbacks only\non the official API origin, and submits a structured audit deliverable for\nautomatic settlement. `THE402_API_KEY`, `THE402_WEBHOOK_SECRET`, and\n`THE402_SERVICE_ID` are Railway-only environment variables.\n\nThe same service also hosts two free, disclosed affiliate handoffs used by\nfact-checked SameDayDesk guides: `/go/topify` and `/go/manychat`. They mint and\ncache Agent Hansa's expiring signed links server-side, validate the redirect\nhost, expose no API key, and return `noindex, nofollow` plus `no-store`.\n\n## Original rail implementation\n\nA Node/Express server that returns **HTTP 402 Payment Required** when unpaid and\nserves the resource after payment, settling **USDC on Base mainnet** straight to\nour own wallet:\n\n```\npayTo = 0x8904dF3DE6DFEe6a7C8cc38619d2f17806213Cee\n```\n\nVerified live (June through August 2026). The server boots and returns correct\n402 responses with machine-readable payment requirements. The Morpho canary is\n`amount=20000` = 0.02 USDC, `network=eip155:8453`, and\n`asset=0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913` = Base USDC,\n`payTo` equal to our wallet, plus a Bazaar discovery extension with input and\noutput schemas.\n\n---\n\n## Current production decision\n\n| Path | Account/API key? | Base mainnet? | Discovery reach |\n|---|---|---|---|\n| **CDP facilitator** (`api.cdp.coinbase.com/platform/v2/x402`) | **Yes**, Coinbase CDP account plus `CDP_API_KEY_ID` and `CDP_API_KEY_SECRET` | Yes | **Production default.** CDP Bazaar catalog, merchant lookup, and semantic search after first settlement |\n| **xpay public facilitator** (`facilitator.xpay.sh`) | **None** | **Yes** (`eip155:8453`, exact scheme) | Fallback settlement path with self-published discovery only |\n| **x402.org public facilitator** (`x402.org/facilitator`) | None | **No**, Base Sepolia testnet only | Separate test catalog at `x402.org/facilitator/discovery/resources` |\n\nProduction uses CDP. The first eleven routes passed live CDP verification and\ncompleted a real settlement. The original eight appear in Bazaar merchant\ndiscovery. The three newer Morpho decision routes have successful settlement\nreceipts, and a distinct funded payer produced `isValid: true` plus Bazaar\nextension status `processing` for all three. They still did not enter merchant\ndiscovery after the documented cache window and a fresh settlement, so this is\ntracked as a downstream CDP indexing incident rather than a route-metadata\nfailure. The secret-free reproduction is attached to\n[x402 issue #2156](https://github.com/x402-foundation/x402/issues/2156#issuecomment-5229812482).\nKeep xpay as the no-key continuity fallback, not as the normal production\nfacilitator.\n\nThe twelfth route, `/work/opportunity-preflight`, is live at 0.05 USDC and\ncompleted an owner-excluded settlement for integration and indexing QA. The\nthirteenth route, `/distribution/agent-discoverability-audit`, is live at 0.05\nUSDC and productizes the brand-blind catalog benchmark used on SameDayDesk\nitself. It queries Bazaar, Agentic Market, Agent402, Circle, AgenticTrade, the official MPP\ncatalog, MPPScan, PayanAgent, x402.jobs, and 8004Market public search without catalog credentials or payments,\npreserves registry-native order, and reports coverage, rank, competitors above the target, and\nevidence-based next actions as point-in-time observations rather than a\ncomposite score. Bazaar and Agentic Market are explicitly one Coinbase source\nfamily, so the output does not inflate independent reach by counting both views\nas separate acquisition channels. PayanAgent is labeled as a dependent\naggregator surface because its catalog includes ecosystem records such as\nCoinbase-origin supply; its retrieval rank is useful, but is not independent\nunderlying supply. 8004Market is labeled as an identity-propagation surface\nbecause it indexes on-chain Solana Agent Registry identities; retrieval there\nproves public identity and capability propagation, not a buyer call, settlement,\nor independent demand. An optional bounded seller-surface check reports whether one exact\nroute appears in the target's public Agent Card, ERC-8004 registration, and\naction catalog without weakening the default credential-free catalog method.\n\nVersion 1.11.42 adds a JSON-body `POST /work/opportunity-preflight` contract for\nmachine workflow buyers while preserving the existing GET contract and 0.05\nUSDC price. Empty credential-free HEAD or POST registry probes can inspect the\npayment challenge; missing or malformed paid input remains an uncharged 400.\nThis makes one useful product directly callable from integer-cent workflow\nmarkets without a duplicate route or a misleading price.\n\nVersion 1.11.43 adds an exact `GET /work/opportunity-preflight?trial=1` free\nsample for machine catalogs. It returns fixed arithmetic with `sample: true`\nand `charged: false`, performs no external work, and accepts no caller inputs.\nCustom GET and POST calls remain 0.05-USDC payment-gated.\n\nVersion 1.11.41 mirrors the canonical x402 v2 `Payment-Required` offer into the\notherwise-empty 402 JSON body for registries that still index the legacy body.\nThe payment-offer preflight also exposes an equivalent JSON-body POST route for\nworkflow builders while preserving the validated GET route.\n\nVersion 1.11.40 adds x402.jobs as a tenth public search view. The adapter uses a\ndeterministic, disclosed compact keyword query because x402.jobs search is\nlexical rather than semantic, then preserves its public popularity order and\nchecks the expected target route. SameDayDesk's verified owned server now lists\nall fourteen Base routes with a zero-call, zero-value baseline, so later\nactivity can be measured without calling validation or listing traffic demand.\n\nVersion 1.11.39 adds the public x402.jobs server-ownership proof at\n`/.well-known/x402-verification.json`. The challenge is a public directory\nclaim only and grants no API, wallet, or payment authority.\n\nVersion 1.11.38 adds a distinct Circle Gateway Nanopayments access path for\npayment-offer preflight at the same 0.005-USDC price. It uses the official\n`@circle-fin/x402-batching` 3.3.0 seller middleware, advertises\n`GatewayWalletBatched` x402 requirements across the networks Circle reports at\nruntime, and settles into the seller's Gateway balance. The existing Base\nexact, native MPP, MCP, product implementation, and direct routes are unchanged,\nso a Gateway outage cannot block them. The main OpenAPI and x402 manifest expose\nthe alternative path; the MPP OpenAPI does not mislabel it as an MPP route.\n\nVersion 1.11.37 adds 8004Market as a ninth public search view in the paid\ndiscoverability audit. It matches the target by durable service origins and\nroutes embedded in the indexed Solana identity metadata while preserving\n8004Market's server-native semantic order.\n\nVersion 1.11.36 expands the Solana identity metadata with the real route-level\ncapabilities and the Base and Solana OpenAPI, skill, x402, and MPP discovery\nsurfaces after the first frozen 8004Market benchmark exposed zero capability\nretrieval from the broader launch description.\n\nVersion 1.11.35 adds `/.well-known/agent-registration.json`, a durable\nERC-8004-compatible registration document for the Solana Agent Registry. It\nbinds the existing MCP and A2A surfaces, the Solana x402 and MPP storefront,\nthe dedicated Solana settlement wallet, and explicit x402 support. The\non-chain asset identifier is injected only after successful registration, so\nthe URI stays stable and the document never invents an identity before it\nexists.\n\nVersion 1.11.34 adds PayanAgent public search as an eighth registry view with an\nexplicit dependency label. Version 1.11.33 added MPPScan public search; its\npublic text-search order remains separate from the direct-listing state.\nVersion 1.11.32 added AgenticTrade; the official MPP flat catalog remains\nlocally ranked.\n\nThe payment-offer preflight route is live at 0.005\nUSDC. It productizes the buyer-side authorization boundary: fetch the unpaid\nheaders of one exact public GET route, normalize x402 and MPP offers, verify URL\nand realm binding, detect expiry and cross-protocol drift, and return a bounded\ndecision before the buyer signs the target payment.\n\n---\n\n## How the rail works (why \"no account\" is safe)\n\nThe `exact` scheme settles USDC via an **EIP-3009 `transferWithAuthorization`**:\nthe buyer (agent) signs an authorization that moves USDC **directly from their\nwallet to our `payTo`** on-chain. The facilitator only **verifies the signature\nand broadcasts the transaction**; it never holds the money. So:\n\n- Whatever facilitator we pick, the USDC lands in **our** `payTo` wallet.\n- We hold the key to `payTo`; the facilitator does not.\n- CDP and xpay are non-custodial facilitator paths. CDP relayed the eight live\n  seller canaries and the exact USDC amounts reached our wallet.\n\nThis is the same rail Frantic used to pay real mainnet USDC to this wallet, so we\nalready know settlement to `0x8904…3Cee` works.\n\n---\n\n## Answers to the five questions\n\n### 1. Facilitator + autonomy\n- The **public x402.org facilitator supports Base Sepolia testnet only**\n  (`eip155:84532`); its `/supported` endpoint does **not** list `eip155:8453`.\n  Mainnet via x402.org is impossible.\n- **Base mainnet settlement does not strictly require a Coinbase CDP account.**\n  The **xpay public facilitator (`https://facilitator.xpay.sh`) supports Base\n  mainnet `eip155:8453` exact scheme with no account and no API key** (verified\n  against its live `/supported` endpoint). This is the fully-autonomous mainnet\n  path.\n- The **CDP facilitator** requires a CDP account and API keys. Its advantage is\n  Bazaar merchant discovery, semantic search, and the Bazaar MCP buyer surface.\n- Production chose CDP after a live verify-only matrix and eight successful\n  settlements. xpay remains the no-key fallback.\n\n### 2. Exact seller code\nSee `server.js`. Current package line (NOT the legacy flat `x402-express@1.x`):\n\n```\n@x402/express     2.16.0   paymentMiddleware, x402ResourceServer\n@x402/core        2.16.0   HTTPFacilitatorClient   (import from @x402/core/server)\n@x402/evm         2.16.0   ExactEvmScheme          (import from @x402/evm/exact/server)\n@x402/extensions  2.16.0   declareDiscoveryExtension (import from @x402/extensions/bazaar)\n@coinbase/x402    2.1.0    createFacilitatorConfig (only needed for CDP mainnet)\nmppx              0.8.15   native MPP EVM charge challenge, credential, and receipt support\n```\n\nCore wiring:\n\n```js\nconst facilitatorClient = new HTTPFacilitatorClient(\n  createFacilitatorConfig(process.env.CDP_API_KEY_ID, process.env.CDP_API_KEY_SECRET)\n);\nconst resourceServer = new x402ResourceServer(facilitatorClient)\n  .register(\"eip155:8453\", new ExactEvmScheme());\n\napp.use(paymentMiddleware(\n  { \"GET /premium\": { accepts: [{ scheme: \"exact\", price: \"$0.01\",\n      network: \"eip155:8453\", payTo: \"0x8904dF3DE6DFEe6a7C8cc38619d2f17806213Cee\" }],\n      description: \"...\", mimeType: \"application/json\", extensions: { ... } } },\n  resourceServer\n));\n```\n\n### 3. Bazaar discovery\nThe route's `extensions` uses `declareDiscoveryExtension({ input, inputSchema,\noutput, outputSchema })` (already in `server.js`). This advertises the route and\nits JSON schemas in the 402 payload (verified present in the live response).\n**Surfacing in the CDP Bazaar requires the CDP facilitator**: CDP catalogs a\nroute after its first successful settlement. The production merchant lookup\nreturns the original eight SameDayDesk routes; all three newer Morpho decision\nroutes have successful CDP settlements and accepted `processing` Bazaar\nextensions, but remain absent beyond the documented cache window. CDP also\nfinds the original Morpho and deep-audit routes through semantic search. Use the\nmerchant lookup as evidence of CDP catalog state, not as the canonical count of\nSameDayDesk capabilities; the owned manifest, MCP, A2A, and OpenAPI surfaces\nremain complete at fourteen.\n\nCDP rejected three older route payloads whose discovery descriptions were 535,\n581, and 629 characters even though local extension validation passed. Concise\nrewrites of 294, 258, and 301 characters passed. A stock x402 2.22.0 boundary\ntest later isolated the exact compatibility edge: 501 characters was rejected,\nwhile 500 characters reached facilitator signature verification with all four\nextensions intact. Startup and surface tests now reject every resource above\n500 Unicode code points. Run live CDP verify before a funded canary.\n\n### 4. Settlement verification\nAfter a paid call, confirm USDC landed at `payTo` on Base mainnet. The 402/200\nflow also returns a `PAYMENT-RESPONSE` header with settlement data. Independently:\n\n```bash\n# USDC balanceOf(payTo) on Base mainnet via public RPC, no key:\ncurl -s -X POST https://mainnet.base.org -H 'Content-Type: application/json' \\\n  --data '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"eth_call\",\"params\":[{\n    \"to\":\"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913\",\n    \"data\":\"0x70a082310000000000000000000000008904df3de6dfee6a7c8cc38619d2f17806213cee\"\n  },\"latest\"]}'\n```\nResult is hex atomic USDC (divide by 1e6). Or use our existing Base-mainnet\nbalance checker. Or view the wallet on https://basescan.org/address/0x8904dF3DE6DFEe6a7C8cc38619d2f17806213Cee\n\n### 5. Cleanest recommended path\n**Deploy on CDP for the production storefront.** It preserves direct USDC\nsettlement and adds the catalog, semantic search, merchant lookup, and Bazaar MCP\nbuyer surface. Keep xpay configured as the no-key recovery path.\n\n---\n\n## Deploy steps (Railway)\n\nThe repo is a no-config Node app: `npm start` runs `node server.js` and binds\n`process.env.PORT` (Railway sets it).\n\n1. Deploy this directory directly or push the repository source.\n2. **Set env vars** on the Railway service:\n   ```\n   PAY_TO=0x8904dF3DE6DFEe6a7C8cc38619d2f17806213Cee\n   NETWORK=eip155:8453\n   PRICE=$0.05\n   FACILITATOR=cdp\n   CDP_API_KEY_ID=<CDP API key ID>\n   CDP_API_KEY_SECRET=<CDP API key secret>\n   MPP_SECRET_KEY=<random secret of at least 32 bytes>\n   COMMERCE_DATA_DIR=/data\n   COMMERCE_ACTOR_SECRET=<random 32-byte secret>\n   COMMERCE_INTERNAL_TOKEN=<random owner-canary token of at least 32 UTF-8 bytes>\n   COMMERCE_MCP_TYPED_SINCE=<ISO timestamp for the accepted typed-MCP producer generation>\n   COMMERCE_EXTERNAL_SINCE=<ISO timestamp after controlled launch canaries>\n   COMMERCE_AGENT_SOURCE_DETAIL_SINCE=<ISO timestamp after provider taxonomy release>\n   COMMERCE_SETTLEMENT_EVIDENCE_SINCE=<ISO timestamp after settlement-proof release>\n   COMMERCE_PAYER_CLASSES='[{\"address\":\"0x...\",\"class\":\"validation\"}]'\n   ```\n   Core payment settings have safe defaults. Production telemetry uses a Railway\n   volume mounted at `/data` plus the two secret variables above.\n\n   A release-validation MCP request is attributed only when it supplies the\n   exact internal token and one unique\n   `x-samedaydesk-validation-marker` matching\n   `[A-Za-z0-9._~-]{16,128}`. The stored row contains only the marker's\n   domain-separated SHA-256 digest. Never reuse a marker, persist its raw value\n   with telemetry, or classify the resulting seller-operational validation row\n   as independent demand, settlement, accounting, or revenue.\n3. **Generate a public domain** for the service.\n4. **Verify:**\n   ```bash\n   curl https://<your-domain>/healthz          # -> {ok:true, network:eip155:8453, ...}\n   curl -i 'https://<your-d",
  "bytes": 60000,
  "sha": "6be42fb7d9dc21082c7875cabd4327497709246377b53dcee312ea87d5fd14fa",
  "repo_slug": "epistemedeus/x402-url-extractor",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_epistemedeus_x402_data_gateway_fe3a20a0/readme"
}