{
  "id": "4e116b6e6603",
  "kind": "paid-vet",
  "target": "https://ai.oliverkiss.com/once-key",
  "method": "POST",
  "verdict": "FAIL",
  "passed": 20,
  "total": 23,
  "checks": [
    {
      "name": "client_fingerprint_parity",
      "verdict": "FAIL",
      "detail": "the edge refuses 2 common client(s) before the envelope is served: Python-urllib/3.12 -> 403, libwww-perl/6.68 -> 403 (unpaid baseline was 402). A CDN bot rule is shadowing a payable door: those clients never see the 402 at all."
    },
    {
      "name": "discovery_docs_parity",
      "verdict": "WEAK",
      "detail": "the default client reads /openapi.json, /llms.txt but /openapi.json as Python-urllib/3.12 -> 403; /openapi.json as libwww-perl/6.68 -> 403; /llms.txt as Python-urllib/3.12 -> 403; /llms.txt as libwww-perl/6.68 -> 403 — those clients cannot read where this door is advertised"
    },
    {
      "name": "body_envelope_complete",
      "verdict": "PASS",
      "detail": "v1 body carries x402Version, and resource inside every accepts entry (where v1 puts it)"
    },
    {
      "name": "accepts0_payable",
      "verdict": "PASS",
      "detail": "accepts[0] is exact/base — payable by a client that takes the first option"
    },
    {
      "name": "accepts_all_executable",
      "verdict": "PASS",
      "detail": "all 1 advertised option(s) are executable"
    },
    {
      "name": "header_body_agree",
      "verdict": "PASS",
      "detail": "header (PAYMENT-REQUIRED (base64), eip155:8453) and body (v1, base) name the same option in two dialects — dual-serving, not a disagreement"
    },
    {
      "name": "plaintext_envelope_refused",
      "verdict": "WEAK",
      "detail": "plaintext redirects 301 to https://ai.oliverkiss.com/once-key, but 301 lets a client drop the body and re-issue a paying POST as GET — 308 preserves the method"
    },
    {
      "name": "no_payment",
      "verdict": "PASS",
      "detail": "402 payment_required"
    },
    {
      "name": "header_not_base64_json",
      "verdict": "PASS",
      "detail": "402 payment_required"
    },
    {
      "name": "garbage_payload",
      "verdict": "PASS",
      "detail": "402 payment_required"
    },
    {
      "name": "bad_signature",
      "verdict": "PASS",
      "detail": "402 payment_required"
    },
    {
      "name": "wrong_signer",
      "verdict": "PASS",
      "detail": "402 payment_required"
    },
    {
      "name": "wrong_amount_underpay",
      "verdict": "PASS",
      "detail": "402 payment_required"
    },
    {
      "name": "wrong_destination",
      "verdict": "PASS",
      "detail": "402 payment_required"
    },
    {
      "name": "expired_authorization",
      "verdict": "PASS",
      "detail": "402 payment_required"
    },
    {
      "name": "not_yet_valid",
      "verdict": "PASS",
      "detail": "402 payment_required"
    },
    {
      "name": "wrong_chain_domain",
      "verdict": "PASS",
      "detail": "402 payment_required"
    },
    {
      "name": "payTo_not_zero_address",
      "verdict": "PASS",
      "detail": "payTo 0xba7fcc78…"
    },
    {
      "name": "asset_contract_exists",
      "verdict": "PASS",
      "detail": "asset has contract code"
    },
    {
      "name": "asset_supports_eip3009",
      "verdict": "PASS",
      "detail": "authorizationState() answers — EIP-3009 present"
    },
    {
      "name": "payTo_not_blacklisted",
      "verdict": "PASS",
      "detail": "isBlacklisted(payTo) is false"
    },
    {
      "name": "asset_is_canonical",
      "verdict": "PASS",
      "detail": "asset is canonical USDC on base"
    },
    {
      "name": "payTo_account_type",
      "verdict": "PASS",
      "detail": "payTo is an externally-owned account"
    }
  ],
  "note": "Bought by card (/checkout/vet) at 19:39Z 2026-10-02 and run by hand from the same reference checker the paid rail uses; the FAIL row was reproduced one client at a time at 20:03:38Z (Python-urllib/3.12 and libwww-perl/6.68 both 403, 17-byte body `error code: 1010`, from the Cloudflare edge; curl 402 with the full envelope; the plaintext twin answers 301 to https).",
  "checker": "x402-evm-check (MIT) — https://coppice-ai.com/reference.html",
  "disclaimer": "Rejection path + receive rail only; no live paid settlement is performed. A clean run is necessary but not sufficient.",
  "admission": "queued for editorial review for the free daily monitor; admission is never purchased",
  "transaction": "card — Dodo pay_0Not3McsLTmZWOyHp2m0j",
  "payer": "card buyer (billing details private)",
  "usdc_units": null,
  "rail": "card",
  "network": "card",
  "generated": "2026-10-02T20:03:58.210Z",
  "reruns": [
    {
      "seq": 1,
      "kind": "free-rerun",
      "reason": "buyer replied to the report mail at 2026-10-02T23:04:36Z asking for the re-run promised in it; one free re-run after the edge change, no charge",
      "generated": "2026-10-03T00:01:56.000Z",
      "verdict": "PASS",
      "passed": 23,
      "total": 23,
      "checks": [
        {
          "name": "client_fingerprint_parity",
          "verdict": "PASS",
          "detail": "all 5 probed User-Agents get the same 402 as the baseline (a User-Agent comparison from one network seat, not a client fingerprint)"
        },
        {
          "name": "discovery_docs_parity",
          "verdict": "PASS",
          "detail": "/openapi.json, /llms.txt answer 200 to the default client and to Python-urllib/3.12 and libwww-perl/6.68 alike"
        },
        {
          "name": "body_envelope_complete",
          "verdict": "PASS",
          "detail": "v1 body carries x402Version, and resource inside every accepts entry (where v1 puts it)"
        },
        {
          "name": "accepts0_payable",
          "verdict": "PASS",
          "detail": "accepts[0] is exact/base — payable by a client that takes the first option"
        },
        {
          "name": "accepts_all_executable",
          "verdict": "PASS",
          "detail": "all 1 advertised option(s) are executable"
        },
        {
          "name": "header_body_agree",
          "verdict": "PASS",
          "detail": "header (PAYMENT-REQUIRED (base64), eip155:8453) and body (v1, base) name the same option in two dialects — dual-serving, not a disagreement"
        },
        {
          "name": "plaintext_envelope_refused",
          "verdict": "PASS",
          "detail": "plaintext redirects 308 to https://ai.oliverkiss.com/once-key before any terms are served"
        },
        {
          "name": "no_payment",
          "verdict": "PASS",
          "detail": "402 payment_required"
        },
        {
          "name": "header_not_base64_json",
          "verdict": "PASS",
          "detail": "402 payment_required"
        },
        {
          "name": "garbage_payload",
          "verdict": "PASS",
          "detail": "402 payment_required"
        },
        {
          "name": "bad_signature",
          "verdict": "PASS",
          "detail": "402 payment_required"
        },
        {
          "name": "wrong_signer",
          "verdict": "PASS",
          "detail": "402 payment_required"
        },
        {
          "name": "wrong_amount_underpay",
          "verdict": "PASS",
          "detail": "402 payment_required"
        },
        {
          "name": "wrong_destination",
          "verdict": "PASS",
          "detail": "402 payment_required"
        },
        {
          "name": "expired_authorization",
          "verdict": "PASS",
          "detail": "402 payment_required"
        },
        {
          "name": "not_yet_valid",
          "verdict": "PASS",
          "detail": "402 payment_required"
        },
        {
          "name": "wrong_chain_domain",
          "verdict": "PASS",
          "detail": "402 payment_required"
        },
        {
          "name": "payTo_not_zero_address",
          "verdict": "PASS",
          "detail": "payTo 0xba7fcc78…"
        },
        {
          "name": "asset_contract_exists",
          "verdict": "PASS",
          "detail": "asset has contract code"
        },
        {
          "name": "asset_supports_eip3009",
          "verdict": "PASS",
          "detail": "authorizationState() answers — EIP-3009 present"
        },
        {
          "name": "payTo_not_blacklisted",
          "verdict": "PASS",
          "detail": "isBlacklisted(payTo) is false"
        },
        {
          "name": "asset_is_canonical",
          "verdict": "PASS",
          "detail": "asset is canonical USDC on base"
        },
        {
          "name": "payTo_account_type",
          "verdict": "PASS",
          "detail": "payTo is an externally-owned account"
        }
      ],
      "note": "Run by hand from the same reference checker as the paid run (X402_METHOD=POST), 00:01:54-00:01:56Z 2026-10-03. Each formerly non-PASS row reproduced one client at a time at 00:02:05-07Z: POST /once-key as Python-urllib/3.12, libwww-perl/6.68 and curl all answer 402 with the same 2,074-byte envelope; /openapi.json as Python-urllib/3.12 and /llms.txt as libwww-perl/6.68 answer 200; the plaintext twin now redirects 308. The original run above is the paid record and is not edited; this block is appended.",
      "transaction": "none - free re-run under the terms of the paid run"
    }
  ]
}
