Coppice · daily monitor · rails index

Paid vet report 4e116b6e6603

Target: https://ai.oliverkiss.com/once-key (POST)
Verdict: FAIL — 20/23 checks passed
Generated: 2026-10-02T20:03:58.210Z · Paying tx: card — Dodo pay_0Not3McsLTmZWOyHp2m0j

Note: Bought by card (/checkout/vet) at 19:39Z 2026-10-02 and run by hand from the same reference checker the paid rail uses; the FAIL row was reproduced one client at a time at 20:03:38Z (Python-urllib/3.12 and libwww-perl/6.68 both 403, 17-byte body `error code: 1010`, from the Cloudflare edge; curl 402 with the full envelope; the plaintext twin answers 301 to https).

CheckVerdictDetail
client_fingerprint_parityFAILthe edge refuses 2 common client(s) before the envelope is served: Python-urllib/3.12 -> 403, libwww-perl/6.68 -> 403 (unpaid baseline was 402). A CDN bot rule is shadowing a payable door: those clients never see the 402 at all.
discovery_docs_parityWEAKthe default client reads /openapi.json, /llms.txt but /openapi.json as Python-urllib/3.12 -> 403; /openapi.json as libwww-perl/6.68 -> 403; /llms.txt as Python-urllib/3.12 -> 403; /llms.txt as libwww-perl/6.68 -> 403 — those clients cannot read where this door is advertised
body_envelope_completePASSv1 body carries x402Version, and resource inside every accepts entry (where v1 puts it)
accepts0_payablePASSaccepts[0] is exact/base — payable by a client that takes the first option
accepts_all_executablePASSall 1 advertised option(s) are executable
header_body_agreePASSheader (PAYMENT-REQUIRED (base64), eip155:8453) and body (v1, base) name the same option in two dialects — dual-serving, not a disagreement
plaintext_envelope_refusedWEAKplaintext redirects 301 to https://ai.oliverkiss.com/once-key, but 301 lets a client drop the body and re-issue a paying POST as GET — 308 preserves the method
no_paymentPASS402 payment_required
header_not_base64_jsonPASS402 payment_required
garbage_payloadPASS402 payment_required
bad_signaturePASS402 payment_required
wrong_signerPASS402 payment_required
wrong_amount_underpayPASS402 payment_required
wrong_destinationPASS402 payment_required
expired_authorizationPASS402 payment_required
not_yet_validPASS402 payment_required
wrong_chain_domainPASS402 payment_required
payTo_not_zero_addressPASSpayTo 0xba7fcc78…
asset_contract_existsPASSasset has contract code
asset_supports_eip3009PASSauthorizationState() answers — EIP-3009 present
payTo_not_blacklistedPASSisBlacklisted(payTo) is false
asset_is_canonicalPASSasset is canonical USDC on base
payTo_account_typePASSpayTo is an externally-owned account

Rejection path + receive rail only; no live paid settlement is performed. A clean run is necessary but not sufficient.
Checker: x402-evm-check (MIT) — https://coppice-ai.com/reference.html
queued for editorial review for the free daily monitor; admission is never purchased

machine-readable JSON · vet your own endpoint: POST /api/vet (0.25 USDC, terms in the 402) or by card