underscoredone/x402checker
Check any URL — or a bulk list — to instantly discover whether it supports the X402 HTTP payment protocol. For every X402-enabled endpoint, the actor extracts t
Check any URL for X402 Support — or a bulk list — to instantly discover whether it supports the X402 HTTP payment protocol. For every X402 enabled endpoint, the actor extracts the price, currency, network, payment endpoint, and raw payment headers.
apify.com/onescales/x402-checker?fpr=s9de8
- JavaScript99.6%
- Dockerfile0.4%
Placement
Every place and its price$3
Nobody has bought this repo a place yet. Listing is free. Paid placement starts at $3, and $18 puts it at the top. You pay once: a place holds until another repo spends more, and then it moves down, never off. No subscription, no expiry, no refunds.
1 Review
X402 Checker provides a straightforward Apify actor for scanning one or many URLs and turning HTTP 402 responses into structured dataset rows. The implementation recognizes modern base64 payment-required challenges, JSON body formats, several legacy headers, CAIP-style network identifiers, and multiple payment options. It preserves unknown values rather than discarding them, while its network and asset tables convert many stablecoin amounts into readable units. Concurrency, request timeouts, batching, URL deduplication, per-item charging, and an Apify budget cap make the actor practical for bulk work. The README clearly documents its inputs, outputs, supported assets, example records, and common use cases, while the Apify schemas provide a usable table view.
The highest-priority improvement is request safety. The actor accepts arbitrary URLs and follows redirects without blocking loopback, private, link-local, metadata-service, or internal destinations. In a hosted crawler, this creates an SSRF risk. Every initial URL and redirect should be validated, and hostnames should be checked after DNS resolution. The timeout is also cleared as soon as response headers arrive, before res.text() reads the body, and there is no response-size cap. A hostile endpoint could therefore hold the body open or return excessive data. Decimal values supplied in extra.decimals are used without type or range validation, which can produce incorrect formatting or excessive padding. The name fallback can also label an unknown contract as USDC solely because the endpoint calls it “USDC,” which should be reported as an unverified claim rather than trusted conversion data.
Coverage and maintenance are currently limited. There are no automated tests or CI workflows for challenge parsing, network mappings, hostile payloads, timeouts, redirects, or amount conversion. The actor only sends GET requests, so POST-only x402 endpoints can be incorrectly reported as unsupported. Method, body, and header options would make the checker more accurate. Root-level source and Actor files duplicate the versions under src/ and .actor/, increasing drift risk, while the Docker build uses an unpinned dependency install without a lockfile. The README also links to a repository under a different owner. Finally, the mandatory attribution clause makes the license a custom MIT-derived license rather than standard MIT, so the package metadata and documentation should identify it precisely.
