generated: '2026-09-19' method: probed source: >- Live responses from https://api.warppay402.com on 2026-09-19 (HTTP 402 challenges on POST /api/v1/tools/web-scraper, GET /api/v1/feeds/base-yields and GET /public_data_feed/index.json; JSON-RPC initialize/tools/list on /mcp; /.well-known/agent.json), the provider's OpenAPI at /openapi.json, and the @warppay402/server README (x402 V2 compliance claims). No marketing compliance page exists; the site is four Google Sites pages. description: >- Standards the WarpPay402 surface actually conforms to, judged from what the host serves. This is a payments-for-agents provider whose whole access model is the x402 protocol, so the domain-standard signature lives in the 402 response itself rather than in the OpenAPI, which declares no securitySchemes. domain_standard: id: x402 version: 2 conforms: true role: resource server (merchant) — every metered operation issues the challenge and verifies the settlement evidence: - url: https://api.warppay402.com/api/v1/tools/web-scraper observed: >- POST without payment -> HTTP 402; response header PAYMENT-REQUIRED (base64 JSON) and body {"error":"Payment required", "x402Version":2,"resource":{url,description,mimeType},"accepts":[{scheme:"exact",network:"eip155:8453",asset:, amount:"1000",maxTimeoutSeconds:300,payTo},...solana, eip155:42161, eip155:5042],"extensions":{"bazaar":{schemaVersion "2.0", JSON Schema 2020-12 input schema, info.input/output}}}; Access-Control-Expose-Headers: PAYMENT-REQUIRED, PAYMENT-RESPONSE; X-Guard-Inspected: true. - url: https://api.warppay402.com/.well-known/x402-manifest.json observed: HTTP 200, 19 endpoints with method + costUSD, paymentNetwork eip155:8453, acceptedAsset Base USDC. - url: openapi/warppay402-com-openapi.yml observed: every operation declares a 402 response ("Payment Required - x402 USDC micropayment challenge"). note: >- x402 is the de-facto standard for HTTP-native agent micropayments (Coinbase-originated, open spec). It is not yet a scored standard in scoring.yml (memory x402-adoption-measured: measure, do not score) — recorded here as evidence, with the challenge observed on the documented operation path rather than the base URL. conformance: - id: x402 conforms: true version: '2' evidence: see domain_standard above — live 402 with PAYMENT-REQUIRED header and x402Version 2 body on three operation paths. - id: x402-bazaar-discovery-extension conforms: true version: '2.0' evidence: extensions.bazaar block in every observed 402 body (schemaVersion "2.0", per-tool JSON Schema 2020-12 input schema, info.input / info.output examples). - id: caip-2 conforms: true evidence: >- Network identifiers are CAIP-2 chain ids throughout (eip155:8453, eip155:42161, eip155:5042, solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp) in the 402 accepts[], the agent card payment.networks and the SDK README. - id: json-schema-2020-12 conforms: true evidence: >- $schema https://json-schema.org/draft/2020-12/schema on the bazaar input schemas in the 402 body; MCP tools/list inputSchema objects are plain JSON Schema (no $schema declared). - id: mcp conforms: true version: '2024-11-05' evidence: >- POST https://api.warppay402.com/mcp initialize -> {"protocolVersion":"2024-11-05","capabilities":{"tools":{},"resources":{},"prompts":{}}, "serverInfo":{"name":"WarpPay402 Backend","version":"1.0.0"}}; tools/list returns 19 tools with inputSchema. Both the Streamable-HTTP style (direct JSON response to POST) and the legacy HTTP+SSE transport (GET /mcp -> event: endpoint) are served. - id: a2a conforms: false grade: flavored evidence: >- /.well-known/agent.json (legacy path; canonical agent-card.json 302s to it) has capabilities as an object and skills as an array but no protocolVersion, no preferredTransport and no A2A endpoint — a discovery manifest for the MCP/x402 gateway. Detail in a2a/warppay402-com-a2a.yml. - id: openapi-3.1 conforms: true evidence: >- https://api.warppay402.com/openapi.json declares openapi 3.1.0 with 19 path operations; no components.schemas, no securitySchemes, no servers[] (added in the refined copy from the documented base). - id: rfc9457 conforms: false evidence: >- Error bodies are {"error": "", ...} JSON (402) or text/plain "404 Not Found"; no application/problem+json anywhere. - id: oauth2 conforms: false evidence: No OAuth surface — /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource 404 on api.warppay402.com; access is paid per call, not delegated. - id: oidc conforms: false evidence: /.well-known/openid-configuration 404 on all hosts. - id: rfc8414 conforms: false evidence: /.well-known/oauth-authorization-server 404. - id: rfc9728 conforms: false evidence: /.well-known/oauth-protected-resource 404 on the API/MCP host. - id: rfc9116 conforms: false evidence: /.well-known/security.txt 404 on warppay402.com (301->www), www.warppay402.com and api.warppay402.com. - id: rfc9727 conforms: false evidence: /.well-known/api-catalog 404 on all hosts. - id: pagination conforms: false evidence: No list operations; nothing paginates. - id: idempotency conforms: false evidence: >- No Idempotency-Key header or equivalent is documented for the REST tools. The @warppay402/server README documents server-side nonce stores (MemoryNonceStore / RedisNonceStore) that reject a replayed PAYMENT-SIGNATURE — replay protection for the payment, not a client-controlled idempotent-retry contract for the operation. - id: rfc8594 conforms: false evidence: No Deprecation or Sunset headers observed; no deprecation policy published. compliance_program: certifications: [] note: No SOC 2 / ISO 27001 / PCI claims anywhere on the site, npm READMEs or GitHub; no trust center. No Compliance pointer emitted.