Skip to main content
Glama

x402 Technical Audit

audit_x402_endpoint
Read-onlyIdempotent

Technical audit for API developers launching or debugging x402. Returns deeper read-only evidence of payment configuration, schemas, redirects, CORS, cache behavior, OpenAPI, llms.txt, agent metadata, and x402 discovery consistency. Requires an explicitly authorized x402 purchase; does not test settlement, paid delivery, or actual marketplace indexing.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
methodNoGET
resource_urlYesPublic HTTPS x402 resource to inspect without payment credentials.
max_price_usdNo
expected_networkNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
corsYes
scoreYes
checksYes
issuesYes
paymentYes
profileYes
decisionYes
evidenceYes
resourceYes
discoveryYes
expiresAtYes
requestIdYes
observedAtYes
operationalYes
claimBoundaryYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A3.6/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, non-destructive, openWorld). The description adds meaningful context: it requires an explicitly authorized x402 purchase, returns read-only evidence, and does not test settlement, paid delivery, or marketplace indexing — useful scope boundaries an agent cannot derive from annotations alone.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three tight sentences, front-loaded with purpose before the evidence list and constraints. The middle sentence is a dense enumeration but each item earns its place by telling the agent what is returned.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be spelled out, and the description does summarize the covered domains. However, for a 4-parameter tool with 25% schema coverage, the missing parameter guidance on method, max_price_usd, and expected_network leaves a real gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 25%, with just resource_url documented. The description never explains method, max_price_usd, or expected_network, so it fails to compensate for the undocumented parameters. There is even mild tension with the schema, which says the resource can be inspected without payment credentials while the description mentions an authorized purchase.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Technical audit for API developers launching or debugging x402') and enumerates the evidence domains it returns. The word 'deeper' implicitly positions it against the sibling inspect_x402_endpoint, but the distinction is not made explicit.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context for when to reach for it (launching or debugging x402) and states exclusions ('does not test settlement, paid delivery, or actual marketplace indexing'). It stops short of naming the alternative tool or a concrete when-not condition relative to inspect_x402_endpoint.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources