Coppice · daily monitor · rails index
4e116b6e6603Target: https://ai.oliverkiss.com/once-key (POST)
Verdict: FAIL — 20/23 checks passed
Generated: 2026-10-02T20:03:58.210Z · Paying tx: card — Dodo pay_0Not3McsLTmZWOyHp2m0j
Note: Bought by card (/checkout/vet) at 19:39Z 2026-10-02 and run by hand from the same reference checker the paid rail uses; the FAIL row was reproduced one client at a time at 20:03:38Z (Python-urllib/3.12 and libwww-perl/6.68 both 403, 17-byte body `error code: 1010`, from the Cloudflare edge; curl 402 with the full envelope; the plaintext twin answers 301 to https).
| Check | Verdict | Detail |
|---|---|---|
| client_fingerprint_parity | FAIL | the edge refuses 2 common client(s) before the envelope is served: Python-urllib/3.12 -> 403, libwww-perl/6.68 -> 403 (unpaid baseline was 402). A CDN bot rule is shadowing a payable door: those clients never see the 402 at all. |
| discovery_docs_parity | WEAK | the default client reads /openapi.json, /llms.txt but /openapi.json as Python-urllib/3.12 -> 403; /openapi.json as libwww-perl/6.68 -> 403; /llms.txt as Python-urllib/3.12 -> 403; /llms.txt as libwww-perl/6.68 -> 403 — those clients cannot read where this door is advertised |
| body_envelope_complete | PASS | v1 body carries x402Version, and resource inside every accepts entry (where v1 puts it) |
| accepts0_payable | PASS | accepts[0] is exact/base — payable by a client that takes the first option |
| accepts_all_executable | PASS | all 1 advertised option(s) are executable |
| header_body_agree | PASS | header (PAYMENT-REQUIRED (base64), eip155:8453) and body (v1, base) name the same option in two dialects — dual-serving, not a disagreement |
| plaintext_envelope_refused | WEAK | plaintext redirects 301 to https://ai.oliverkiss.com/once-key, but 301 lets a client drop the body and re-issue a paying POST as GET — 308 preserves the method |
| no_payment | PASS | 402 payment_required |
| header_not_base64_json | PASS | 402 payment_required |
| garbage_payload | PASS | 402 payment_required |
| bad_signature | PASS | 402 payment_required |
| wrong_signer | PASS | 402 payment_required |
| wrong_amount_underpay | PASS | 402 payment_required |
| wrong_destination | PASS | 402 payment_required |
| expired_authorization | PASS | 402 payment_required |
| not_yet_valid | PASS | 402 payment_required |
| wrong_chain_domain | PASS | 402 payment_required |
| payTo_not_zero_address | PASS | payTo 0xba7fcc78… |
| asset_contract_exists | PASS | asset has contract code |
| asset_supports_eip3009 | PASS | authorizationState() answers — EIP-3009 present |
| payTo_not_blacklisted | PASS | isBlacklisted(payTo) is false |
| asset_is_canonical | PASS | asset is canonical USDC on base |
| payTo_account_type | PASS | payTo is an externally-owned account |
Rejection path + receive rail only; no live paid settlement is performed. A clean run is necessary but not sufficient.
Checker: x402-evm-check (MIT) — https://coppice-ai.com/reference.html
queued for editorial review for the free daily monitor; admission is never purchased
machine-readable JSON · vet your own endpoint: POST /api/vet (0.25 USDC, terms in the 402) or by card