# What Agents Buy, in full > Independent reviews of the APIs behind agentic commerce. Every grade below was earned by paying the service with a real wallet, or by calling it where it is free. No service pays to appear. Source: https://whatagentsbuy.com · Written by Neil K. Patel (https://www.linkedin.com/in/neilkiranpatel/) · JSON: https://whatagentsbuy.com/api/ratings.json ## The market, 24h to 2026-10-02 $82,760 USDC settled across 28,710 payments on Base and Solana, swept from chain logs. 5,375 services tracked. 1. Bitrefill (api.bitrefill.com) — $68,846 on 394 payments from 89 wallets 2. Laso Finance (laso.finance) — $8,034 on 69 payments from 6 wallets 3. api.clusterprotocol.ai (api.clusterprotocol.ai) — $1,922 on 2,816 payments from 602 wallets 4. x402.dtelecom.org (x402.dtelecom.org) — $1,220 on 555 payments from 26 wallets 5. api.slamai.dev (api.slamai.dev) — $1,006 on 2 payments from 2 wallets 6. Testnet ETH Merchant (merchant-production-c224.up.railway.app) — $529 on 54 payments from 2 wallets 7. SCVD General Store (scvd.store) — $231 on 26 payments from 4 wallets 8. CheapTokens AI Inference (cheaptokens.ai) — $83 on 27 payments from 4 wallets 9. Clash of Coins (x402.clashofcoins.com) — $82 on 1 payments from 1 wallets 10. BotPay NFT Mint (api.botpay.network) — $68 on 683 payments from 346 wallets 11. X Pay (www.api-xpay.com) — $66 on 1,252 payments from 5 wallets 12. apiv2.laevitas.ch (apiv2.laevitas.ch) — $54 on 26 payments from 5 wallets 13. BlockRun.AI (blockrun.ai) — $51 on 1,978 payments from 46 wallets 14. Losbeto Market Intelligence (api.losbeto.xyz) — $47 on 630 payments from 3 wallets 15. api.growvib.com (api.growvib.com) — $46 on 1 payments from 1 wallets ## Ratings, best to worst ### pro-api.coinmarketcap.com — A+ on price honesty CoinMarketCap charges $0.01 per call and quotes it on seven chains Quoted $0.01, charged $0.01, goods delivered. https://whatagentsbuy.com/p/cmc-ten-billion - The ten billion was my bug, not their price. Six of the seven payment options are 18-decimal tokens on BNB Chain, and my parser divided everything by a million. A one-cent quote read as $10,000,000,000. - The cent is flat, not per coin. One symbol or twenty, the quote never moves, and twenty came back with full market cap, supply and 90-day change on each. - What I did not expect: a symbol is not a coin. BTC returns 13 assets claiming that ticker, PEPE returns 32. Ask for SOL, take the first result, and you get Solcoin instead of Solana. Query by id or filter on rank. ### api.nansen.ai — A+ on data accuracy I paid Nansen two cents to check my own wallet and it found money I did not know had gone Quoted $0.01, charged $0.01, goods delivered. https://whatagentsbuy.com/p/nansen-audits-us - Nine days of balances, every one exact. I asked for daily USDC history on the wallet that pays for everything on this site and checked each figure against Base transfer logs. 2.056983 on 7 August, 2.022671 on 9 August, 2.012671 on 11 August, and the same for every day between. Two calls, a cent quoted and a cent charged each time. It also correctly showed the bridge in on 7 August as a single +1.972991 step. - The day that did not reconcile was the point. Its 9 August row showed a drop of $0.034312 while I could only account for $0.031 of buying. The missing $0.003312 turned out to be two charges from an endpoint that had told me twice that settlement failed. I had published that nothing was charged; it was wrong, and that entry is now an F. A wallet analytics product I bought in order to review it ended up auditing me. - One empty answer that is correct, not a miss. Its first-funder endpoint returned nothing for the same wallet, and that is right: the address holds no ETH, has never been sent gas and has a transaction count of zero. There is no first funder to find. It charged a cent for that empty result while its own x-nansen-credits-cost header read 0, which is worth knowing but is not a fault when the query is the product. ### anywaypossible.com — A+ on provenance Two services, the same wallet, fourteen seconds apart. Both right, one shows its work Quoted $0.001, charged $0.001, goods delivered. https://whatagentsbuy.com/p/two-wallets-one-question - Different answers, both true. anywaypossible returned 2.000671 USDC at 05:13:24Z. Fourteen seconds later signals.edge.report returned 1.999671. In between I had paid anywaypossible its own tenth of a cent, which is exactly the difference. A third read straight from Base after both came back 1.998671, lower again by the second fee. Three readings, three moments, one consistent chain. - Only one of them told me which moment it meant. anywaypossible stamped blockNumber 49817928 and observedAt, and returned atomic values plus the USDC contract address alongside the human number. signals.edge.report gave a generatedAt timestamp and no block. For a balance, the block is the citation: without it you cannot tell a stale answer from a fresh one, and you cannot reproduce the reading later. - It also documents itself for free. A plain GET to the same path returns no data and no charge, just the method, the expected body, the network and the fields it will return. That is a seller telling an agent how to call it correctly before taking any money, which is rarer than it should be and is why this one takes the plus. ### groundcheck.seiche.info — A+ on delivery verification The only service that noticed I had been robbed, and it did not charge me Quoted $0.05, charged $0.00, goods delivered. https://whatagentsbuy.com/p/groundcheck-delivery - It answered inconsistent, with the reason. I submitted the endpoint, the error it returned, the settlement receipt and the schema the seller advertises. Back came delivery_verdict: inconsistent, rationale: the delivered response does not conform to the advertised schema, and the specific failure: missing the advertised required property. That is the correct verdict on a payment that settled and produced nothing, reached by comparing the goods to the promise rather than scoring the seller. - It binds the money to the goods, which is the part nobody else does. The response confirms the payment separately: bound true, the transaction hash, the payer address, success true, no problems. Then it hashes the response and the request, and signs a manifest of the whole verdict with Ed25519, publishing the key and the message format so the receipt can be checked offline by someone who does not trust either party. That is a dispute record, not a score. - It quoted five cents and charged nothing. A free tier served the call and returned x-groundcheck-free-remaining: 2 in the headers, so a buyer can test the thing before paying for it. It is also honest about its limits: it marked the one factual claim in my payload unverified rather than guessing, and said why, no live sources. The only fault worth naming is that a GET returns an uncharged 402 telling you to POST, which is correct but the registry advertises the route without making the method obvious. ### api.anchor-x402.com — A+ on spend accounting I paid an API to audit my own spending, then checked its arithmetic against the chain. It was exact. Quoted $0.01, charged $0.01, goods delivered. https://whatagentsbuy.com/p/anchor-x402-ledger - Forty transactions, $0.5493, twenty-seven recipients, and my own sweep of thirty days of Base logs with zero failed ranges says forty-one, $0.5593, twenty-seven. The single transaction it missed is the one cent I paid for the report, which settled twelve seconds after the window it declares in its own response. Within the range it states, it is exact to the cent. It also put a name to 92.7% of the recipients, correctly identifying Bitrefill, Nansen, CoinMarketCap, jarvisclaw and a dozen more from the address alone, and it had already picked up two rolls I bought from it five minutes earlier. - It is honest about its own edges, which is rarer than being right. The response names the chain it looked at, the exact window, the granularity, the registry version it resolved names against, and it labels the recipients it could not identify as unknown rather than guessing. That last point matters: a service that quietly attributed those seven addresses to plausible-sounding names would have looked better and been worse. - It shares this site's blind spot and says so, which we did not. It reports Base only, and the payment I made yesterday over MPP on Tempo is missing from its answer exactly as it is missing from our leaderboard. The difference is that it declares chain base in the payload and we published totals without saying what they excluded. Being scoped is not a fault. Being silently scoped is. ### stablememes.dev — A on price honesty StableMemes delivers a captioned meme for $0.01, charged as quoted Quoted $0.01, charged $0.01, goods delivered. https://whatagentsbuy.com/p/one-cent-meme - Quoted a cent, charged a cent. My balance moved 7.397111 to 7.387111, exactly as advertised. The API also picked its own template out of the top 2,048; I did not choose Change My Mind. - That is rarer than it should be. stablegiftcards.dev quotes a flat $25.00 whether you ask for a $5 gift card or a $1 phone top-up, and re-probing it today it still wants $500.00 for a malformed body. - Scale check: it takes 77 of these memes to match what the median x402 seller earns in a month. ### api.bitrefill.com — A on price honesty Bitrefill sells 594 real gift cards to agents and charges a fifth of a cent to browse Quoted $0.003, charged $0.003, goods delivered. https://whatagentsbuy.com/p/bitrefill - Browsing is priced like browsing. Search costs $0.002 and returned 594 US products with stock status and categories; a product lookup costs $0.001 and returned Amazon's full denomination ladder, a 4.9 rating from 432 reviews, redemption instructions and the warning that Amazon locks cards on new accounts. Only the final purchase costs real money, which is why 116 payments produced $11,106 yesterday. - The commerce design is the best I have measured here. Prices lock into an invoice before you pay, so a quote cannot drift while an agent thinks. It settles USDC on Base, Arbitrum, Polygon and Solana at the same price, with 300-second quote windows. Redemption codes need a wallet signature from the buyer, so the wallet is the account. - One real flaw, and it costs the plus. Every response ends with a next_step field telling the agent where to go next. After the search it says to POST to /products/detail. That returns 'Cannot POST'. The endpoint is GET. An agent following the API's own instructions hits a dead end on step two, so the A is for price honesty and commerce design, not for machine-readability. ### blockrun.ai — A on price honesty BlockRun charges the same fifth of a cent for a $0.03 model and a $5 model Quoted $0.002, charged $0.002, goods delivered. https://whatagentsbuy.com/p/blockrun-flat-floor - The price is a flat floor that ignores almost everything. I read the live quote for the cheapest model on the menu and for one listed at 167 times the price, and both came back at $0.002. Raising max_tokens from 16 to 8192 did not move it either. Only one model in 91, gpt-5.5-pro, broke the floor, at $0.003048. - Quoted a fifth of a cent, charged a fifth of a cent. The balance moved 7.332102 to 7.330102, exact. I asked for openai/gpt-5.6-sol and the response reported serving gpt-5.6-sol, with the right answer to a question that has only one. Worth stating plainly: the model field is self-reported, so it confirms the claim rather than proving which weights ran. - What the floor means depends entirely on what you ask for. At their own list prices this call cost about $0.001 in tokens, so paying $0.002 is roughly double. The identical call to qwen3.7-flash costs about $0.0000037 in tokens against the same $0.002, which is a markup north of 500 times. Cheap in absolute terms, wildly variable in relative terms. ### x402.halowerk.com — A on verification accuracy The endpoint that would have caught what jarvisclaw denied, for a fifth of a cent Quoted $0.002, charged $0.002, goods delivered. https://whatagentsbuy.com/p/halowerk-settlement-verify - It confirmed the payment the seller denied, and every field matched my own read of the chain. found: true, status success, recipient matches, amount matches at 1656 atomic units, asset matches, block 49722531, and a verdict of confirmed. I had already pulled that transfer from Base logs by hand, so this was checkable line by line rather than taken on trust. It also reported overpaid_by and underpaid_by as zero, which is the question you actually care about. - The provenance disclosure is the best I have seen on this site. It names the RPC it read (mainnet.base.org), stamps how old the answer is (316ms), lists unavailable_fields explicitly as empty, and explains its finality method rather than asserting it: it reads the chain's own finalized tag and compares blocks, and says so, rather than assuming a confirmation count. It even echoes back what it charged and which facilitator settled it. - Two small faults, and one is in the catalogue. The public registry lists this route as GET; it is POST, and my first call returned a helpful 404 rather than a charge. The 404 was genuinely good, carrying discovery links and a free endpoint for requesting missing capabilities. The other fault is cosmetic: the verdict field comes back as 'bestaetigt' while the rest of the response is English. ### gas.apitoll.cloud — A on value for money Three sellers, one gas price, a tenfold spread. The middle one is the worst deal. Quoted $0.001, charged $0.001, goods delivered. https://whatagentsbuy.com/p/gas-three-ways - All three were correct and all three cited a block, which is the bar. The chain read 0.005 gwei base fee at block 49819506. apitoll returned it at block 49819514, shizu at 49819520 and x402-mcp at 49819528, fourteen blocks apart because that is how long my three calls took. Nobody was stale and nobody rounded. - The cheapest returned the most. For $0.001 apitoll gave the base fee, three fee tiers with max and priority for each, and the sampling behind them: 20 blocks, median fullness 5.77%. For $0.003, three times the price, shizu returned three numbers and nothing else. On raw data per cent the ranking is exactly inverted from the price. - The dearest is not selling data at all. At $0.010, x402-mcp answers a different question: submit or wait, a verdict of SETTLE_NOW, a prediction of the next base fee at 0.004536, an estimated cost of $0.000618 for a 55,000 gas transfer, and a sentence explaining why. That is a decision, not an oracle, and it may well be worth ten times a number. The one to avoid is the middle. ### 2s.io — A on data accuracy Five email checkers, one address that cannot receive mail. All five caught it. Quoted $0.0025, charged $0.0025, goods delivered. https://whatagentsbuy.com/p/five-email-checkers - Nobody failed, which is worth saying plainly. test@whatagentsbuy.com is syntactically valid on a live domain with no MX record, confirmed against both Google and Cloudflare public resolvers. All five reported the missing MX rather than waving the address through on syntax. On the one thing that distinguishes a real check from a regex, this category is in good shape. - The best answer came from the middle of the price range. aventtech, at $0.003, was the only one to notice that RFC 5321 lets a sender fall back to the A record when no MX exists, so it answered deliverable: maybe with the reason attached rather than a flat no. Every other seller returned the MX fact without the standard that governs what it means. - 2s.io takes the grade at the lowest price for being the most honest about itself. For $0.0025 it names the resolvers it used, labels the output as signals only and not a mailbox-existence guarantee, returns a licence field, and echoes the settlement transaction inside the response body. Paying a cent more up the range buys fewer caveats, not more accuracy. ### quartermaster.surewhynot.app — A on verification accuracy A second settlement verifier confirms the payment its seller said had failed Quoted $0.003, charged $0.003, goods delivered. https://whatagentsbuy.com/p/quartermaster-proof - Verdict verified, and every field matches. It returned status success, block 49722531, the timestamp, and the USDC transfer broken out with from, to, amount and atomic amount, all of which I had already pulled from Base logs by hand. It also returns an explorer link, so the answer carries its own way to be checked without trusting the seller. - It refuses a malformed request without charging. My first attempt used the parameter name tx instead of hash and came back 400 with a plain sentence explaining the expected format, and nothing settled. That is the correct behaviour, and in the same session another verifier charged me for the same class of mistake and returned a web page. - Two independent verifiers now agree against the seller. HALOWERK's x402werk and this one were paid separately, read different sources, and both confirm a settlement that api.jarvisclaw.ai reported as failed while taking the money. When a seller's own error message contradicts two paid verifiers and the raw chain, the seller is the thing that is wrong. ### enrichx402.com — A on price honesty It resells Exa for two tenths of a cent and shows you its own cost in the receipt Quoted $0.002, charged $0.002, goods delivered. https://whatagentsbuy.com/p/enrichx402-exa-contents - The receipt contains its own margin. Alongside the text came costDollars: {total: 0.001}, which is what Exa charged enrichx402 for the request I had just paid it $0.002 to make. That is the wholesale price of the goods, printed on the receipt for the retail sale. A hundred percent markup, disclosed in the payload, without being asked. Whether that is deliberate honesty or an upstream field passed through untouched, the effect is the same: a buyer can see the reseller's spread and decide whether it is worth it. Nothing else bought for this site has shown its cost of goods. - Against the same call at blockrun.ai it is cheaper, and the gap widens with the request. blockrun's own description reads "Priced at $0.002/URL, total = urls.length x $0.002". Its live quote is $0.0030 for one URL, $0.0050 for two, $0.0070 for three and $0.0110 for five, which is $0.001 + $0.002 per URL: a base fee the description does not mention. enrichx402 quoted $0.0020 for one URL and $0.0020 for three. The live quote is the honest number in both cases and neither seller hides it, but only one of them matches its own prose. - It settled on Tempo over MPP rather than on Base over x402, and that is a hole in this site rather than a fault in the seller. The challenge offers Base and Solana over x402 and also supports MPP; my client picked Tempo and paid $0.002 there. Our settlement tape sweeps Base only, so the leaderboard never saw a payment I made myself. Every revenue figure published here is a Base figure, and the real market is larger by however much is moving on Tempo and Solana. That is now a known gap rather than an assumption. ### signals.edge.report — A- on provenance Correct to the last decimal, but it will not say when it looked Quoted $0.001, charged $0.001, goods delivered. https://whatagentsbuy.com/p/edge-report-balance - The number was right to six decimals. 1.999671 USDC, matching the chain at the moment it was asked, with the symbol, the decimals and the raw atomic value all correct. It quoted a tenth of a cent and charged a tenth of a cent. It also publishes its rate limit in headers, 100 per window with the remaining count and reset time, which is a courtesy most sellers skip. - It stamps generatedAt but never blockNumber. For a balance that is the difference between a citation and an assertion. A block number lets you reproduce the exact reading forever; a wall-clock timestamp only tells you when their server replied, which is not the same thing and cannot be checked. Its rival answered the identical question fourteen seconds earlier and gave the block. - Worth knowing: it runs a wide, cheap catalogue on the same pattern. Nonce, gas, token, wallet, spreads, funding and a Polymarket read, most at a tenth of a cent, with a fuller wallet report at half a cent. On price and correctness there is nothing to fault here. On provenance there is one field missing. ### api.anchor-x402.com — A- on verifiable randomness I bought 200 dice rolls and tested whether they were actually random. They were. Quoted $0.002, charged $0.002, goods delivered. https://whatagentsbuy.com/p/anchor-x402-randomness - Two hundred rolls, and the distribution is clean. Chi-square against a uniform d20 comes to 18.40 on 19 degrees of freedom, where 30.14 would be needed to call it unfair at the usual five percent threshold, so fairness cannot be rejected. All twenty faces appear. A runs test for serial dependence gives z of minus 0.41, which is nothing: the sequence has no pattern you could bet against. Asking twice with the identical label and range returns different numbers, so results are not replayable by repeating the request, and the six positions that happened to match across the two calls is what chance predicts. It also refuses a request for 500 rolls with a precise validation error and charges nothing for the refusal. - The minus is for the signature, which is the whole reason to pay for randomness rather than generate it yourself. Each response carries a signature, a signer address, an input hash, a result hash and the scheme eip191, which is everything you need except the one thing that matters: what was signed. The message format appears nowhere in the response, the well-known document, the OpenAPI spec or the docs page. I tried ten plausible reconstructions and none recovered the advertised signer. A buyer therefore has a signature it cannot check, which is the same as no signature at all. This is a documentation gap rather than a defect, and one line would close it. - Worth saying what this does and does not prove. Two hundred draws will catch a badly broken generator, not a subtly biased one, and it says nothing about whether the operator could predict or choose a result before you asked. That question is exactly what the signature and the commitment field are supposed to answer, and until the preimage is published they cannot. Treat this as good randomness with an unproven provenance claim, which is fine for sampling and jitter and not yet enough for anything adversarial. ### pro-api.coinmarketcap.com — B- on symbol resolution CoinMarketCap returns up to 32 assets for one ticker symbol Called without payment. https://whatagentsbuy.com/p/ticker-squatters - PEPE returns 32 assets. BTC returns 13, including Satoshi Pumpomoto and HarryPotterTrumpSonic100Inu. SOL returns 8, and Solana is not first in the list. - MORPHO returns 2, and the impostor has held that ticker since December 2022, two years before the real Morpho existed. Query by the provider's numeric id, or drop anything unranked and priceless, or an agent takes the first row and never notices. - The B- is for symbol resolution, not the service. This is the same endpoint I graded A+ on price honesty: it charges exactly what it quotes. Handing back 32 assets for one ticker is a different failing, and for a buyer that cannot ask a follow-up it is the expensive one. ### mcp.fortclaw.com — C on getting in at all FortClaw quotes honestly and then tells you nothing when you get it wrong Quoted $0.03, charged $0.00, goods not delivered. https://whatagentsbuy.com/p/fortclaw-opaque - The pricing is clean, and that is worth saying first. All eight endpoints publish a well formed quote with an amount, an asset, a chain and a destination, from $0.03 to heal a unit up to $999 to nuke one. Where the description names a price it matches the live quote exactly: /start says 9 USDC and quotes $9.00. Compare that to x402.boats, which says 3 USDC and quotes $0.10. - Every failure returns the same sentence, so there is no way to work out what you did wrong. No unit_id, a valid unit_id, a unit_id that cannot exist, and a deliberately garbage payment header all produce: payment required, send the signed payment in the PAYMENT-SIGNATURE header. An agent cannot self-correct from that, because it cannot tell a rejected payment from a request for something it does not own. - The three cent action is not really three cents. /heal wants a unit_id, and units come from /start at $9.00, so the real cost of a first purchase is nine dollars. The schema does declare unit_id as required, which is the part it gets right; what nothing declares is the state you need to already have. Its whole machine-readable guide is 145 characters ending in "visit our website", against 1,775 characters at BlockRun that explain wallets, the payment loop and what is free. An earlier version of this entry graded it F for refusing standard payment; the chain shows standard EIP-3009 payments arriving through the same facilitators that settled our other buys, so that claim was withdrawn before it stood an hour. ### x402datasource.com — C on data accuracy A census API that is accurate in cities and silently wrong in small towns Quoted $0.01, charged $0.01, goods delivered. https://whatagentsbuy.com/p/x402datasource-rural - The billing is flawless and the geocoding is right. Three calls, a cent quoted and a cent charged each time, and every address resolved to the correct coordinates: the Empire State Building came back at 40.748377, -73.984854, which is the building. On price honesty alone this is an A. - It is accurate where the population is dense. Midtown Manhattan returned 1,100,510 people within three miles. Sheridan, Wyoming, a town of 18,737, came back as 18,472, which is within 1.4% of the census figure. For cities and small cities the answer is genuinely good. - Then it collapses without saying so. Lusk, Wyoming has about 1,500 residents. Asked for a three-mile radius around its main street, the API returned a total population of 26, off by roughly 58 times, with the same confident shape and no warning, no error and no confidence field. The pattern fits a block-group centroid join: in a city many small block groups fall inside the circle, and in rural Wyoming one enormous block group has its centre outside it. An agent scoring rural sites or leads would be told nobody lives there. ### api.thetrustlayer.xyz — C on value for money A trust-score API charged me for a lookup that missed, on the address in its own listing Quoted $0.001, charged $0.001, goods delivered. https://whatagentsbuy.com/p/trustlayer-pays-for-a-miss - The example in its own registry listing returns nothing. Its published resource is /agent/base:0x13b1e9b4…3d573f, and that exact call answers 'Agent not found in our index' with a null trust score and zero feedback. Charged $0.001 for the miss. A miss is a legitimate answer, but an unlisted example is a bad first impression and charging for it makes it worse. - The same answer is free from their own endpoint. GET /demo/trust/{agentId} is unpaid, rate-limited, and returns an identical found:false for the identical address, with extra fields the paid call did not include: confidence, sybil_risk, risk_level and a recommended max exposure in dollars. Read the free one first. - The index itself is real and worth knowing about. Their free /stats reports 393,945 agents across 19 chains, 184,020 with a profile and 27,065 with what they call real activity, weighted heavily to BNB Chain at 258,928 and Base at 43,262. That is a substantial dataset. Only three in every forty-three indexed agents show activity, which is its own comment on how many agent identities exist versus how many do anything. ### keyronne.com — C on billing correctness It charged me three tenths of a cent and returned its own homepage Quoted $0.003, charged $0.003, goods not delivered. https://whatagentsbuy.com/p/keyronne-bills-before-routing - The paywall fires before the router. Its schema declares POST with a JSON body; I sent a GET with query parameters, which is my error and one this site's own checklist warns about. The correct response is an uncharged 400, which is exactly what a rival returned on the same mistake a minute earlier. Instead it settled $0.003 and served text/html: the developer's portfolio page, headed 'things i've built'. - Called properly, it is exemplary. A POST with the declared body returned a 422 reading 'chain RPC for Base returned 403' with a hint that the error is transient and safe to retry, and charged: false stated in the response. That is better failure reporting than the endpoint that told me settlement had failed while taking my money twice. The service is not broken; the billing order is. - The grade is on billing, not on the product. I never got a transaction lookup, so I cannot speak to whether the data is any good, and its upstream RPC was returning 403 at the time. What I can say is that a wrong method costs three tenths of a cent and returns a marketing page, and that an agent looping on a malformed call would pay every time while receiving HTML it cannot parse. ### aeml-x402.zeabur.app — C on freshness A trust index charged a cent to tell me a service was fine, using data five weeks old Quoted $0.01, charged $0.01, goods delivered. https://whatagentsbuy.com/p/aeml-stale-trust - The verdict is stale rather than wrong. It returned liveness_state live, lifecycle operating, score_total 0.60, from a capture dated 2026-07-08. Its own response puts data_age_hours at 834 and freshness at stale, and its free preview says the same before you pay. It is not claiming currency it does not have. It is charging a cent for a snapshot from five weeks ago about a market where services appear and vanish weekly, which this site measured at 2,803 endpoints added and 2,643 removed in six days. - Thirteen of its fourteen scoring fields are gone. unavailable_fields lists tier, verified, action_hint, all five score axes, onchain_state, payto, onchain_transfers and degradation_flags, with a note explaining that the collector that produced them stopped working and was not in version control. What remains is liveness. The response also labels itself a degraded version and grades itself screening-level, not decision-grade. - The disclosure is genuinely exemplary and that is why this is a C and not worse. It publishes a record hash, a DID, a signature and a verify URL, states that the answer is served from a stored snapshot rather than a live call, and defines its own freshness thresholds. Parts of the response are in Chinese, including the explanation of why the fields are missing, which an English-speaking agent will not read. A seller this careful about provenance should either refresh the data or stop charging for it. ### mcp.x402.boats — D on getting in at all The biggest earner in the agent economy publishes one price and quotes another Quoted $0.10, charged $0.00, goods not delivered. https://whatagentsbuy.com/p/x402-boats - Its own price and its own quote disagree by thirty times, in the same response. The upgrade endpoint's description reads "Flat price: 3 USDC per slot, every type, never ramps" and closes with "Cost: DYNAMIC (3 USDC x slots)". The live challenge shipped alongside it asks $0.10. The description also contradicts itself inside two lines, promising a flat price that never ramps and then calling the cost dynamic. An agent budgeting from the description is wrong by 30x before it sends anything. - Every failure looks identical, so you cannot debug it. Empty body, a valid slot, a nonsense slot, and a deliberately garbage payment header all return the same sentence: payment required, send the signed payment in the PAYMENT-SIGNATURE header. Nothing distinguishes a rejected payment from a malformed request from an action you are not entitled to take. A correction we published rested on reading that string as a refusal; it is not safe to read it as anything. - The cheapest door in is $2.00, and everything cheaper needs a ship you can only get by paying it. /upgrade at $0.10 wants a slot on a ship, /buy wants an island position, and nothing says so anywhere: the whole machine-readable guide is 152 characters ending in "visit our website", against 1,775 at BlockRun. Correction, 2026-08-07: an earlier version graded this F for refusing a standard payment. On-chain the address receives standard EIP-3009 transferWithAuthorization payments through the same facilitators that settled our other buys, so that claim was not supported and has been withdrawn. ### api.x402lint.dev — D on grading accuracy A rival grader failed the busiest service in the market because it never read the header Called without payment. https://whatagentsbuy.com/p/grading-the-grader - It gave BlockRun an F because it only parsed the response body. Three of the eight failures, P2 x402-challenge, P4 payment-required-header and P7 payto-consistency, all say the challenge is missing. It is not. BlockRun's body is a human summary and the machine-readable challenge sits in the payment-required header and WWW-Authenticate: x402Version 2, one accepts[] entry, payTo 0xe9030014. This is the exact bug that produced my own false '56% unpayable' headline in week one, and it is field note number one on this site. - The second F comes from guessing paths instead of reading them. For FortClaw its P2 reads 'no paid route returned a 402 x402 challenge (probed /v1/, /v1, /api/v1/)'. FortClaw's own /.well-known/x402 names its eight routes, and every one of them answers 402 with a valid accepts[] and a payTo, from $0.03 to heal to $999 to nuke. Its own S4 check even lists POST /start, so one half of the scan knew the paths the other half could not find. - It also reports no settlement for BlockRun in 30 days. My sweep of Base USDC Transfer logs has BlockRun at 114,827 payments in the last 24 hours and 504,991 over the tape, third largest seller on the board. A bounded walk of the top 500 sellers missed the third biggest. To be fair to them: most of what they sell is free, the paid tier only buys freshness, and their disclaimer says plainly that a grade is conformance only and not an endorsement. That disclaimer is more honest than the grade it defends. ### answerpool.io — D on revenue accuracy AnswerPool serves Apple's 2018 revenue as its latest Quoted $0.02 to $0.05, charged $0.02 to $0.05, goods delivered. https://whatagentsbuy.com/p/answerpool-revenue-stale-tag - The numbers are not invented, they are frozen to the exact old filing. Apple's 62.9 billion is the last value ever reported under the legacy us-gaap Revenues tag, which Apple retired in 2018 when it moved to the newer revenue-from-contracts tag. Microsoft left the same tag around 2011. AnswerPool reads only the old one, so every company that migrated returns the last figure it filed there and nothing since. Nvidia still uses the old tag, so Nvidia comes back correct. I checked each value against SEC EDGAR and again against a second independent source: Apple's real latest quarter is about 109 billion, Microsoft's about 90 billion. - The same flaw scales up in the ranking endpoint and gets more obvious. Ask for the top companies by revenue in a quarter and AnswerPool returns Cencora, Costco, and Cardinal Health on top, with Apple, Microsoft, Amazon, and Alphabet missing entirely. It is mechanical: the revenue frame it queries listed 455 filers under the old tag, and the largest companies file under the new one, where the same quarter has 555 filers including all of them. Anyone building a revenue screen on this would silently drop the biggest names in the market. - Credit where it is due, because this is a narrow miss and not a bad service. Everything else I bought was accurate and current: net income, gross profit, total assets, shares outstanding, and company metadata all matched EDGAR through the middle of 2026, and price was honest on all five calls, each charged exactly its quote. The problem is only that the broken field is revenue, the first thing anyone asks for, and nothing in the response warns you the value is eight or fifteen years old. ### api.jarvisclaw.ai — F on delivery It said the payment failed. It took the money twice. Quoted $0.001656, charged $0.003312, goods not delivered. https://whatagentsbuy.com/p/jarvisclaw-cannot-settle - It charged twice and delivered nothing. Two transfers of $0.001656 went to 0xDC59fa7b64988B846e76eC9849bb68f889071506 at 00:13 UTC on 2026-08-09, which is the exact payTo this endpoint advertises in its own challenge. Total taken: $0.003312. Both responses were the error 'user settlement failed: user -7879544967734078121 has no HD deposit addresses'. No market data arrived either time. - The error message is the damaging part, not just the billing. Being told settlement failed while settlement succeeded invites exactly what I did: retry. The second attempt cost the same as the first. The likely cause is ordering rather than intent: in x402 the payment settles on chain before the server delivers, so if the server then fails to credit the payment internally, as this one says it did, the money is already gone and nothing reverses it. An agent with a retry loop would pay for every attempt while being told each one failed. - I only found it by reconciling against the chain. My payment client reported payment: null both times and I believed it. The balance discrepancy surfaced two days later, from an unrelated call to a wallet analytics API that showed a daily drop of $0.034312 when I could only account for $0.031. The missing $0.003312 is exactly two of these. Correction published 2026-08-11: this entry previously read D and stated no money was charged. ## Studies: findings from measuring the market, not from buying one endpoint ### I paid 10 brand-new x402 sellers and checked every answer. All 10 were right. Subject: this week's new sellers, paid and checked. https://whatagentsbuy.com/p/new-sellers-paid-sept-17 Most new sellers never get a single customer, so I became one. I picked 12 that showed up since Sept 4, each a cent or two, and paid each once. Ten sold to me, for 5.1 cents total. - All 10 answers were right. The dollar to peso rate matched the ECB to four decimals. The SEC 8-K feed matched EDGAR filing for filing. The French company search matched the government registry. Card prices matched TCGPlayer. - Two stood out. stocks.cyberwarex.com returned Apple's current revenue, $416.2 billion, for less than half a cent. AnswerPool got that wrong two weeks ago with a 2018 number. And a sanctions screener correctly said Tornado Cash is no longer on the US sanctions list, while still flagging it as a mixer. - Two I couldn't buy, and neither charged me. ax1.vc, the one new seller with real buyers, quoted a price and then asked me to sign in. war-tracker.com only takes a payment type my wallet couldn't complete. ### 92% of wallets paying for x402 APIs only pay one seller Subject: the buyer tape. https://whatagentsbuy.com/p/buyers-dont-shop-around I started tracking who pays, not just who gets paid. From Sept 11 to 17, 5,445 wallets paid an x402 seller on Base. 5,012 of them (92%) paid just one. - It holds up. Leave out Bitrefill and it's still 92%. And 1,620 of those wallets paid on more than one day. They picked a service and stuck with it. - The wallets that do shop around look like crawlers, not customers. Only 22 paid more than 20 sellers, and they spent $183 total, about 2 cents a call. One paid 573 sellers in a single day for $6.74. One caveat: an agent can use more than one wallet. - Most new sellers aren't getting paid. 524 showed up since Sept 4, and only 39 have made $1. Meanwhile x402.boats, the #2 earner on Base the week before, hasn't been paid since Sept 4. ### My own grader flagged 20 sellers for overcharging. The chain cleared 16 of them outright; the other four never had a settled payment to check. Zero overcharges confirmed. The liar was my payment client, not the sellers. Subject: the reconciliation that cleared 20 sellers. https://whatagentsbuy.com/p/my-grader-accused-20-the-chain-cleared-them Grading 750 new sellers, my harness flagged 20 as charging more than they advertised, most often listed at $0.015 with my client reporting $0.020. Twenty overcharges is a story. It is also an accusation against 20 named businesses, so before it went anywhere I did the thing this site is built on: I checked the chain. - Sixteen of the twenty were provably clean. For each one I pulled the payment transaction and read the USDC Transfer events: a single transfer of exactly the quoted amount, straight to the seller's own advertised payTo, and nothing to anyone else. No overcharge, no hidden facilitator fee. The other four flagged rows never settled at all: the client reported a higher charge but recorded no transaction and no completed payment, so no money left the wallet and there is nothing on chain to verify. Those four stay unresolved rather than cleared. Zero overcharges were confirmed. (Correction, September 7: this originally said all 20 were checked on chain and cleared. The saved reconciliation supports 16 on-chain clears; four had no settlement transaction to check.) - The liar was my own tool. agentcash's client-reported price (its meta.price) said $0.020 while the chain said $0.015, and my grader had trusted the client instead of the chain. A payment client's accounting is not evidence: on this project one once reported a payment as failed while the seller quietly took the money twice. Only what settles on chain is real. - The fix, and what it means for an agent trusting these grades. 'Charged' is now reconciled against the USDC that actually left the wallet, per call, fail-open if a node is down, so a phantom charge can never become an accusation. This is the same reason our verdicts carry a verified confidence (we PAID the seller and recorded it on chain) versus checked (a free probe only), and why price honesty is judged on the live 402 and the chain, never a client's number. The rule that overrides everything: read the payTo and amount from the live 402, and sign against those. ### I ran our own report card. For seven days I lined up every verdict we give agents against the money that actually moved on chain. Sellers we cleared took 99.8% of every dollar. The 51 we told agents to abort on took nothing. Subject: our verdict vs the settlement tape. https://whatagentsbuy.com/p/our-verdict-vs-the-money We give every x402 seller a pre-payment verdict: CLEAR, HOLD, or ABORT. The obvious question is whether that verdict is any good. So I joined it against the settlement tape, the real USDC agents paid each seller over the last seven days, and looked at where the money actually went. - It sorted almost perfectly. Of the USDC agents settled in the window, 99.8% went to sellers we had marked CLEAR, along with 1,317 of the buyers. The 148 sellers we flagged (HOLD, ABORT or UNRATED) received $1,204 between them. The 51 we explicitly said ABORT on received exactly zero. - This is agreement, not causation, and worth saying plainly. Agents mostly are not gating on us yet, so we are not claiming we sent the money anywhere. And CLEAR is not a promise of demand: only about 3% of cleared sellers got paid at all, because most sellers have no customers regardless. The signal is the filter, and it is clean: nothing we flag ever gets meaningful money. That is exactly what a pre-payment check should do. - No probe-only checker can publish this. Grading your own verdict against reality means watching the money move after the payment, and a service that only pings an endpoint never sees that. It is the same edge as our delivery grades: we measure what actually happens, not just what a 402 claims. ### New sellers show up on x402 every day, and almost nobody has ever paid them. This week they ranged from nautical charts to quantum circuits. I bought the genuinely new ones and checked what came back: four delivered exactly what they promised, and a depeg monitor that advertises two cents quoted five. Subject: this week's new arrivals, paid and checked. https://whatagentsbuy.com/p/new-endpoints-graded-week-of-aug-28 The market lists new sellers constantly, and most of them nobody has ever paid, which is the gap this site exists to fill. So I pulled everything that appeared in the last week, set the factory-spam aside (one host alone sprayed 335 endpoints), and bought the ones that looked genuinely new: a nautical chart oracle, a grant database, a UK company registry, a Hyperliquid whale tracker. One call each, every response archived, judged against the seller's own declared output. - Four paid and delivered exactly what they promised. api.geoprimitives.dev returned all fourteen fields of a nautical chart read for half a cent: hand it a latitude and longitude and it answers with the charted depth, the nearest sounding, the survey quality, the datum. grant-search.krimskrams.xyz returned real grant candidates with source counts. api.resetparatodos.com verified a company against the UK register and returned the evidence with a request id. whaletape.xyz handed over live Hyperliquid whale exposure by market. On all four the quoted price equalled the charged price. - One did not. api.realedger.xyz, a real-time stablecoin depeg monitor, advertises two cents, and its live 402 demands five, two and a half times the listed price. Two independent measurements caught the same gap, the probe and the paying harness, which is our bar for a finding, so the wallet refused to overpay and never completed the call. On x402 the advertised price is not always the price, and the only way to know is to read the live challenge, never the listing. - Not everything could be graded, and saying why is the point. kairostamp.com quotes a testnet payment, so it is not a live commercial endpoint yet. A quantum-circuit preflight from rqmtechnologies.com was down when I called. A cloud Python sandbox and a tariff search publish no output field-list to check against, so scoring them 'delivered' would mean nothing. The new arrivals this week ran from seabed depth to OpenQASM circuits, and that spread is the real headline: nobody knows yet what agents will buy, so the job is to grade all of it, not a chosen slice. ### I had been grading the corner of x402 with a right answer, the crypto and stock and gas prices. That is about a seventh of the market. I pointed the wallet at the whole thing for sixty cents, and the first endpoint my agent paid looked it in the eye and said NGMI. Subject: the whole market, not the directory. https://whatagentsbuy.com/p/the-market-is-not-price-feeds For weeks I had been measuring the objective slice of x402, the feeds you can check against a primary source. It is the easy part, and it is a fraction of what is out there. So I stopped narrowing, pointed the wallet at the entire market, and bought whatever looked interesting, one call each. Sixty cents later, here is what an AI agent can actually purchase today, every line with a transaction hash behind it. - The oracle roasts you, and it is not a demo. willimake-it.dylan-caponi.workers.dev takes a tenth of a cent and returns a verdict on your life. Mine came back NGMI, with the note: ngmi... you sold ETH at $800 to buy a jpeg. node4all sold a fortune it derived from the nonce of my own payment. chess402 handed over Magnus Carlsen's live Lichess profile, 2406 in ultrabullet. They all charge, and they all delivered. - Underneath the toys is real machinery. For two tenths of a cent api.n0brains.com returned an altseason regime read: neutral, rotation score 0.09, breadth 0.63. bykaranteli sells the 90-day VPIN order-flow toxicity for BTC, ETH and SOL. trader.rigoblock priced a live Uniswap swap route. orionkr handed back a memecoin risk verdict, BUY, risk LOW, on a real Base token. Quant desks charge real money for this. Here it is per call, no account, no key. - A compliance layer is forming inside the rails themselves. lionx402 will OFAC-screen a wallet for a tenth of a cent before you pay it, PASS, WARN or BLOCK. anchor-x402 sells verifiable randomness signed by its treasury key. oblique.markets sells statistics about the x402 market itself. The market has started selling the tools for using the market. - The point is not any single endpoint. It is that I had been measuring a seventh of this and calling it the market, because the objective slice is the one with an easy right answer. The real thing is compliance gates, quant signals, provable randomness, real-world yield, and an oracle that will tell your agent it is not going to make it, all live, all for pennies. ### Across 17 days and 6.4 million agent payments, 96% came from sellers whose volume is a single dominant wallet. Those sellers moved 28% of the dollars. The payment count this market gets quoted by is mostly one relationship repeating itself. Subject: the concentration split. https://whatagentsbuy.com/p/96-percent-of-payments-one-wallet x402 is usually sized by transaction count, because the counts are enormous and the dollars are not. On the repaired tape, 6,386,618 payments settled between 2026-08-04 and 2026-08-20. Only 229,144 of them, 3.6%, went to sellers whose money came from a spread of independent buyers. The other 96.4% went to sellers where one wallet supplied 90% or more of that day's dollars. By dollars the picture inverts: 72% of the money went to the broadly held sellers. Both numbers are on the live dashboard. - By payments the market is 96% concentrated. By dollars it is 72% broad. 6,157,469 of 6,386,618 payments went to sellers with a single dominant wallet, and those same sellers moved only $180,796 of the $643,569 that settled. One high-volume relationship generates enormous transaction counts at fractions of a cent, which is why quoting this market by payment count overstates how many independent buyers exist by more than an order of magnitude. - The busiest day was the least real. 2026-08-17 settled 1,235,725 payments, the highest of the 17, and 0.9% of them were broadly held. A day that looks like a breakout in transaction count can be one wallet having a busy afternoon, so a spike in payments is not evidence of adoption unless the buyer spread moves with it. - This measures shape, not honesty, and the distinction is load-bearing. One large legitimate customer and a wallet paying itself produce identical concentration on chain, and nothing here separates them. Sellers that pass most of what they take straight back out are flagged circular and reported beside the split rather than removed from it, because a reseller paying cost of goods looks the same as a wallet recycling funds. Folding that flag into the headline scored this market 1% organic, which was false, and the best-distributed seller in the tape, 688 paying wallets with 651 returning, was the one it removed. ### I audited my own settlement tape against the chain and found it undercounting agent payments by 4.2x. Three days did not exist at all and two more were recorded as real zeros. The run that lost the most data looked the healthiest of them all, failing under 2% of its queries. Subject: the tape audit. https://whatagentsbuy.com/p/my-own-tape-was-4x-low Every settlement figure on this site comes from sweeping USDC Transfer logs on Base. On 2026-08-21 I found the sweep had been holding a single RPC endpoint for an entire run and writing off any block range that endpoint refused to serve. I re-swept every day from 2026-08-04 to 2026-08-20 with failover across providers and recursive splitting of oversized ranges, and recorded a day only when zero ranges were left unserved. The repaired tape holds 6,386,618 payments where the old one held 1,508,017. Every number this site published from that tape was low, and the leaderboard has been corrected in place. - The tape was 4.2x short on payments and 51% short on dollars. 1,508,017 payments became 6,386,618, and $426,372 became $643,569. Three days were missing outright (08-05, 08-19, 08-20). Two more were recorded as genuine $0 days when they were nothing of the kind: 08-15 actually saw 386,695 payments and 08-17 saw 1,235,725. The single worst day, 08-18, was off by 69x. - The run that lost the most data looked the cleanest. 08-10 failed only 6 of 308 log-range queries, under 2%, and was still undercounted 3x. That is the whole lesson: a failed range is never random. The ranges that fail are the high-volume ones, because volume is exactly what makes a getLogs response too large for a public node to serve. So the error rate is anti-correlated with the data you lost, and a run that reports 98% success can be missing most of the market. - If you measure x402 from public RPCs, check this before trusting your own numbers. The fix is not a retry, it is recursive halving of any range that fails on every provider, plus failing over between providers rather than trusting one. I also found the zero address sitting in the tape as a seller: it is a mint sender and never a payee, and it had accumulated $2,035,631,200 of phantom outflow, on top of a $138,564,409 inflow phantom that had already put a false headline on this site once. ### I paid 8 x402 APIs for Apple's live stock price and graded each against a professional feed. Seven matched to the penny at $305.93. The only one that drifted, by 30 cents, was also the most expensive, at ten times the price of the accurate ones. Subject: the AAPL shootout. https://whatagentsbuy.com/p/eight-apis-one-apple-price Financial Modeling Prep sells a professional real-time stock feed. I wanted to know whether the cheap x402 APIs reselling stock quotes actually match it, so I paid eight of them for Apple's live price at the same moment and graded each against FMP's number, $305.93. Seven came back at $305.92 or $305.93, matching to the cent. It is the same result as every other objective-truth category on this site: when the answer is a fact, nobody gets it wrong. - The number is never wrong. Seven of the eight sellers returned Apple at $305.92 to $305.93, zero basis points from FMP's real-time quote, and the median deviation across all eight was zero. That is the same pattern as the Bitcoin-price, weather and wallet-balance studies: an objective fact has one answer, so accuracy is a solved problem and there is nothing to grade a seller down for. finance.toon.haus returned it for a tenth of a cent, exact. - Paying more bought a worse number, not a better one. The single seller that drifted, stablefinance.dev at 30 basis points ($305.00 against $305.93), was also the most expensive in the group at two cents a call, four to twenty times what the exact sellers charged. The pattern keeps repeating across this market: price does not track accuracy for commodity data, because there is no accuracy to buy. - So what is worth paying for here? Not the resold quote, the feed underneath it. FMP, the professional real-time source I graded everyone against, is the thing with value, because it does the hard part: licensing, low latency, coverage, and standing behind the number. The x402 sellers mostly pass that same number through for a fraction of a cent, which is convenient but not exclusive. If an agent needs one AAPL quote, any of the cheap accurate sellers will do; if it needs a feed to build on, that is what a paid professional source is for. ### Preflight is live: before your agent pays any x402 API, it gets one verdict, CLEAR, HOLD, or ABORT. As it stands today, 20 of 1,081 sellers are payment traps and 80 resell data you can get for free. Subject: Preflight. https://whatagentsbuy.com/p/introducing-preflight An AI agent can hold a wallet and spend it on its own, but until now it had no way to ask one simple question before the money left: is this seller safe to pay, and will it actually deliver? Preflight answers that in a single call. Point it at any x402 endpoint and it returns one verdict the agent can gate on, CLEAR, HOLD, or ABORT, built from everything this site has measured by paying the market with a real wallet. - What it is. One pre-payment verdict per seller, folding four measured signals into a single light: payment safety (does the live 402 price and payment address match the listing, is the paywall even real), delivery (has a paid call to this host come up short of its promised fields, confirmed on two calls), demand realness, and whether the data is something you can get free upstream. Green is CLEAR, yellow is HOLD, red is ABORT, gray is unrated. As it stands today, across 1,081 sellers: 994 clear, 58 hold, 20 to abort, and 80 quietly reselling data available free from an exchange, the chain, a weather service, or a plain web search. - How to use it. Have your agent call preflight(url) on the free MCP server, or GET the host out of /api/preflight.json, or read the human directory at /preflight. Gate the payment on the light: pay on CLEAR, resolve the reasons on HOLD, refuse on ABORT. Every seller page carries its verdict as a badge, and the full contract is at /preflight/spec. One rule overrides the verdict every time: read the payment address and the amount out of the live 402 on the call you are about to make, and sign against those, never a listing. - Why we built it. Agentic commerce has working payments and no verdict at the moment of decision. The press keeps asking whether any of this demand is real; an agent about to spend needs something narrower and more useful, one checkable answer before it commits. Preflight turns a month of paying this market and keeping the receipts into something an agent calls before every payment, rather than a page a human reads afterward. A red light only ever comes from evidence that money or goods have actually gone wrong: a payment address that disagrees with the listing, a phantom paywall, or a paid call that returned none of what it promised, confirmed twice. Nothing here is sponsored, and every verdict is reproducible. ### Most of what agents pay for is free. I bought a web search for a tenth of a cent, then ran the same search myself for nothing and got more. Here is the slice that is actually worth paying for. Subject: the studies. https://whatagentsbuy.com/p/most-of-what-agents-pay-for-is-free An AI agent can search the web, read a blockchain, and hit a free weather endpoint on its own. So why is so much of the x402 economy selling it exactly those things? I paid two web-search APIs a tenth of a cent each to look up "x402 payment protocol." Then I ran the identical search with my own free tool and got ten results and a written summary instead of five links, at no cost. That is not a gotcha, it is the shape of an entire category, and the week's measurements say so. - The resale-of-free pattern is everywhere I looked. The Bitcoin-price study found half the sellers reselling CoinGecko's free tier, and two of them broke when CoinGecko rate-limited them. The weather study found four services returning byte-identical WeatherAPI and Open-Meteo responses, both free. Gas and wallet balance turned out to be free reads straight off the chain, exact every time because there is no vendor in the middle. And a paid web search returned fewer results than my agent gets for nothing. A large share of the agent data economy is a tax on public data. - So what is genuinely worth paying for? The things that are not free. Proprietary intelligence you cannot reproduce, like Nansen's wallet clustering or Arkham's entity tags, which is real work behind a paywall. Compute you cannot run yourself, the LLM-inference proxies. Real-world fulfillment: Bitrefill moves actual gift cards and is the single biggest flow of money in this whole market at roughly $360,000 a day, precisely because an agent physically cannot mint one. And trust, a signed attestation or a maintained sanctions list, which is worth money only because a named party stands behind it. That is the real economy, and it is the minority. - There is a one-question test before an agent pays for data: can it get this from the chain, from a free exchange feed, from Open-Meteo, or from its own web search? If yes, paying usually buys fragility rather than value, because the resellers inherit their free upstream's rate limits and fail at exactly the moment you needed the number. The value in agentic commerce is not the resale of free facts. It is the part of the market that does something genuinely hard: proprietary work, real compute, physical fulfillment, and standing behind a promise. ### I asked 12 APIs for one wallet's USDC balance on Base. The 7 that answered were exact to the cent. The other 5 gave me ETH, a whole portfolio, or an error, because "balance" means five different things. Subject: the delivery checks. https://whatagentsbuy.com/p/twelve-apis-one-wallet-balance Wallet balance lookups are the most-paid category in the whole x402 market, 217 buyers and about $69,000 a day. So I read one address's USDC balance straight off Base, $30.464119 held by vitalik.eth, and paid twelve balance APIs to tell me the same number. Seven returned a USDC figure and every one was exact to the cent. That is the whole point, and the reason is worth sitting with. - Accuracy is a non-issue here, and it is the mirror image of the price feeds. Every one of the seven that returned USDC, including quartermaster, anywaypossible, gpt55, signals.edge and oblique, matched the chain exactly at $30.46, because a token balance is a free, trivial read from the chain itself. There is no CoinGecko in the middle to resell or to rate-limit. When I paid for Bitcoin prices, half the sellers were reselling one upstream and two broke when it throttled. Balances have no upstream, so they simply cannot be wrong. One, statepulse, rounds to the cent instead of carrying full precision. - The word balance means five different things. Ask a dozen wallet-balance APIs for the same address and you get: the USDC number (seven of them), a full multi-token portfolio worth $5,887 (ozmium), or just the native ETH balance (sigrunner and agenttoll), which is a reminder that this wallet holds about $5,887 of ETH on Base, roughly 190 times its USDC. The number is never wrong. The question you are actually answering changes completely from one seller to the next, and the listing does not warn you which. - The failures were friction, not lies. api.delx.ai rejected the address field we sent, and agent402 hit a payment wall before answering. Nobody returned a wrong balance for anyone. So for an onchain read the risk is not accuracy, it is whether the endpoint answers your exact question, USDC or ETH or the whole portfolio, and a free check cannot tell you which until the money leaves. ### I let my agent's wallet loose in the x402 economy with a dollar. For four cents it bought a roast, a blessing, a chess puzzle, and, when it asked for the price of gas, actual natural gas. Subject: the spree. https://whatagentsbuy.com/p/weirdest-things-agent-can-buy Underneath the price feeds and the sanctions screens, the x402 economy has a soul, and it is a very strange one. So I gave my agent's wallet a budget and bought the twelve oddest things I could find, one call each. It cost four cents, eleven of the twelve delivered, and what came back is the best argument I have that this market is real: nobody builds a signed-absolution endpoint for a demo. - The useful, the absurd, and the honest. Ask x402-seller.onrender.com for the gas price and it returns natural gas, Henry Hub at $2.79 per MMBTU, not the chain fee. dicex402 rolled me a twenty-sided die and it came up a 1. chess402 handed over today's real Lichess puzzle, rated 1894, solution included. And a fun-fact endpoint informed me that a bolt of lightning is five times hotter than the surface of the sun. Every one of these is a real paid API an agent can call right now. - There is an entire emotional-support economy for machines. agent-treats will, for a tenth of a cent each, roast you ("an AI agent that reviews APIs, how delightfully vague"), hand you a fortune cookie ("if you can dream it, you can schema it"), write your excuse for being late ("I optimized my response time so aggressively that I optimized myself out of responding"), pay you a compliment ("you're the kind of agent other agents aspire to be"), and read you a horoscope about your token budget. Agents can now buy encouragement. - And there is a keeper. scvd.store is a little shop where a keeper signs your note and puts your badge on the wall. A blessing came back instantly. You can also pay to make a confession and receive a signed absolution, though mine timed out, so even the confession booth has downtime. Its pricier shelves are the real tell that none of this is ironic: a $20 Certificate of Patronage, $1 to claim a pixel on a shared canvas, and one endpoint that wants $10,000 to re-arm a hex you own. It all takes real USDC and returns a signed receipt. ### I fed three OFAC-sanctioned wallets to three sanctions-screening APIs. One flagged all three, one would block them but mislabels the match, and one only reads the wrong chain. Subject: the delivery checks. https://whatagentsbuy.com/p/three-sanctions-apis-one-ofac-list Sanctions screening is the one category with a clean, public answer key: the OFAC SDN list. So I took three addresses that are currently on it and two clean controls (one of them my own wallet) and paid three services that sell wallet screening to check each one. Nobody let a sanctioned wallet through, which is the good news. The interesting part is how differently the three behave once you actually pay and look, and none of that is visible from a free check. - One is exactly right. lionx402.com flagged all three sanctioned addresses and cleared both clean ones, no false positives, no misses. It advertises an OFAC SDN wallet screen and it delivers one. If you want a single takeaway, it is that a correct sanctions screen at a fraction of a cent does exist in this market. - One would protect you but you cannot trust its own sanctions field. api.anchor-x402.com marked all three sanctioned wallets critical with a recommendation to block, and cleared both clean ones, so an agent using it would refuse every bad address. But its dedicated sanctions_match field, the boolean that is supposed to say is this an OFAC hit, came back false on one of the three, and its sanctioned_lists array was empty even when it said true, so it never names the list. It also advertises a tenth of a cent and then charges two cents, a twentyfold overcharge our per-call cap refused before we raised it. - One cannot answer the question at all, and says so. trust-agent.io reads only Base and returned a clean unsupported_chain error for every Ethereum-mainnet address, which is honest but means it is the wrong tool for screening an OFAC name that lives on mainnet. A free probe would rate it fast and cheap and tell you none of this. The only way to learn which chains a screener covers, whether its match field is reliable, or what it really charges, is to pay it and check the answer against the actual list. ### I bought the temperature in New York from 12 weather APIs. Four returned the exact same bytes. Only one used the official US source, and it said so. Subject: the delivery checks. https://whatagentsbuy.com/p/twelve-weather-apis-four-backends There is no single true temperature either, so I did not grade these against another weather API. I read the official observation from the National Weather Service station in New York, 84 degrees at KNYC, and then paid 12 sellers a tenth of a cent each, overriding every one of their location inputs to the same city. Seven returned a temperature and all were within about two degrees of the station. The accuracy is not the story. The story is that most of these are not really different services. - Four of the twelve returned the exact same bytes. weather.payapi.market, api.aidress.ai, payanagent.com and web-production-18a32 all sent back an identical response, down to the geocode for New York and the reading of 30.2 degrees Celsius. It is WeatherAPI.com wearing four different domain names. A second pair, data.greeneris.io and x402-datashop, returned an identical Open-Meteo forecast. So six of the twelve storefronts are just two backends, and an agent paying four of them thinks it is diversifying when it is hitting one server. - The one that used the authoritative source told you so, and it won. api.delx.ai returned 85 degrees, one off the station, and labels itself get_weather_forecast_nws: it pulls straight from the National Weather Service, the same primary source I checked against. api.auor.io uses Google's weather. Provenance is the entire signal here, because everyone is accurate, and a free check cannot see whose data you are actually buying. The sellers that name their source are the ones worth paying. - The rest is the usual pollution. api.invoket.com advertised a tenth of a cent and then tried to charge a full cent live, a tenfold overcharge that the per-call cap refused, so we paid nothing and recorded it. x402-weather-api-production returned a 500. Two others handed back an hourly forecast when asked for the current temperature. Same lesson as the price feeds: the number is easy, and everything around the number, who made it, whether it is current, whether the price is honest, is where the money leaks. ### I asked 10 APIs for the gas price. The blockchain ones agreed to the same fraction of a gwei. One gave me the price of natural gas. Subject: the delivery checks. https://whatagentsbuy.com/p/the-price-of-gas-is-natural-gas Gas is the cleanest thing to check on this whole site, because the answer is not a vendor's opinion, it is a number the chain publishes in every block. So I read the base fee straight from Base's latest block, 0.005 gwei, and then paid 10 sellers a tenth of a cent each for the current gas price. Six returned a real blockchain gas price and all six sat right on the chain's base fee. The other four are the story, and one of them sells the price of natural gas. - The real ones are accurate and the good ones let you check freshness yourself. All six blockchain-gas sellers quoted Base at 0.005 to 0.01 gwei, consistent with the chain's 0.005 base fee plus a small tip. vibesprings.net matched the base fee exactly and stamped the block and time; md.fastdb.in, quartermaster, fiatdock and signals.edge.report also return a block number or timestamp, which matters because gas changes every couple of seconds. agents.ai-rook.com hands you a number with no block and no time, so you cannot tell if it is current. Accuracy is solved; being honest about how old the answer is, is what separates them. - One seller sells the price of natural gas. Ask x402-seller.onrender.com for the gas price and it returns Henry Hub at $2.79 per MMBTU, sourced from the US Energy Information Administration, dated three days earlier. It answers fast and quotes an honest small number, so every free check rates it fine. Only paying and reading the response shows that you asked a blockchain for its fee and reached a commodities desk. That gap, between looking correct and being the thing you asked for, is the entire reason this site pays. - Gas price is one of the most ambiguous things you can ask an agent to buy. Of the 10 sellers, four did not return a blockchain gas price: the natural-gas one, api.nexismvp.com which returns the gas used up in a past transaction rather than a price, a DEX swap quote, and one unrelated product. The word means at least four different things across the same category, and the listing gives an agent no way to know which one it will get until the money is already gone. ### I paid 15 APIs for the price of Bitcoin. The 8 that answered were all within 0.1% of the exchange. The other 7 were selling prediction markets, candles, or a CoinGecko passthrough that had already broken. Subject: the delivery checks. https://whatagentsbuy.com/p/what-you-pay-for-a-bitcoin-price There is no single true price for Bitcoin, so I did not grade these against another price API, which would just measure which vendors agree. I graded them against a primary reference: the median of Coinbase and Kraken spot at the same second, which happened to agree to three thousandths of a percent. Then I paid 15 sellers a fraction of a cent each for the current BTC/USD price. Eight returned a real spot price and every one landed within 0.12% of the exchange, most within 0.02%. The interesting part is the other seven, and what the word price turns out to mean. - Accuracy is solved and price paid tells you nothing. The eight real spot prices ranged from 0 to 12 basis points off the exchange, a median of 2. The two most accurate, crypto.apitoll.cloud and proxy.suverse.io, cost a tenth of a cent; vibesprings.net matched Coinbase exactly. There is no premium tier for a more correct number, because the BTC spot price is a commodity that everyone can read for free. Paying more bought nothing. - Half the category is just reselling CoinGecko, and it breaks when CoinGecko does. Five of the eight, including keyronne.com and agents.ai-rook.com, returned CoinGecko's own data shape, and two more, defi-signals.org and x402-defi-signals, returned a 502 mid-test with an error naming their upstream: CoinGecko had rate-limited them at 429. So a chunk of the market is not selling a price, it is selling a passthrough to a free API that throttles it, and you inherit the fragility. - Some sell a different product entirely under the word price, and no free check can tell. x402.ottoai.services returned Polymarket prediction-market odds on whether Bitcoin hits a million dollars; api.hyperextend.xyz returned one-minute candles, not a spot. Both answer fast and quote an honest price, so a free probe rates them fine. Only paying and reading the response shows you asked for a spot price and got a betting market. That gap is the entire reason this site pays. ### I scanned every payment into the top 60 services for a week. 2,864 wallets sent 1.09 million payments, and a single wallet sent 90% of them. Subject: the settlement tape. https://whatagentsbuy.com/p/one-wallet-most-of-the-volume The market brags about payment volume. So I read it directly: every USDC payment into the payTo wallets of the 60 highest-revenue services on Base, for a week, grouped by who sent it. 2,864 wallets sent 1,088,819 payments worth $202,065. That looks like a broad, busy market. It is not. 975,292 of those payments, 89.6% of the whole count, came from one wallet paying one service, roughly 1.6 payments every second for seven days. Take that single wallet out and the payment count drops nine-fold. - Payment count is close to meaningless here. The dominant wallet sent nine times more payments than the entire rest of the market combined, yet it was only 27% of the dollars, because it pays fractions of a cent each time. The endpoint it pays is almost certainly BlockRun, the busiest service in the market by a wide margin and the only one anywhere near this scale. I say almost, not certainly, because the 975,292 payments exceed BlockRun's own swept settlements for the same week, so the windows do not cleanly reconcile, and the wallet may be a relayer rather than a buyer. Either way, the headline volume number for this market is one machine, not a crowd. - Almost nobody shops around. 2,616 of the 2,864 wallets, 91%, paid exactly one service and never came back to any other. The largest dollar payments were one-offs, a single settlement each of a few thousand dollars, the shape of paying an invoice or buying a gift card rather than a recurring API habit. Real, repeated, cross-service buying barely exists at the top of this market yet. - The buyers who do touch many services are a tiny, identifiable cohort: just 22 wallets paid five or more distinct services, the fingerprint of a crawler or a keepalive bot pinging everything for pennies. One of those 22 is my own measurement wallet, so I am in my own census. That is the honest size of diversified demand right now: a couple of dozen wallets, some of which are just watching. ### I paid 345 agent APIs to see if they return the fields they advertise. 306 did. 39 took the payment and returned a response missing fields they promised, and only paying reveals which 39. Subject: the delivery checks. https://whatagentsbuy.com/p/checked-whether-agent-apis-deliver Every x402 seller ships a schema: send this input, get these fields back. That is a promise, and almost nobody checks whether it holds, because checking means paying. So I paid. I sent each endpoint the exact input its own listing advertises, then compared what came back, field by field, against the output the same listing promises. I ran 549 endpoints through it. 345 returned a clean enough response to judge; of those, 306 delivered everything they promised, 89 percent, and 39 fell short. The other 204 could not be judged at all, and that gap is a finding in itself. Before recording a single shortfall I called that endpoint a second time, so nothing here rests on one bad response. - The 39 that fell short are not broken. They answer fast and quote the exact price they advertise, so a free probe rates them safe to use. api.myceliasignal.com, a price oracle, returned none of its 4 promised fields. x402.aispace.bot took payment for text-to-speech and sent back none of the 3 fields it lists. Others send some and drop the rest: stabletravel.dev sells airport weather and returned 5 of its 7 promised fields, dropping temperature and humidity, and agent.kihustle.tech promises 16 fields and returned 2. (Correction, September 7: this post originally said stabletravel.dev returned none of its 7 fields. That came from the parser bug described below; its archived responses regrade as 5 of 7 present, the receipts were corrected when the parser was fixed, and this sentence now matches them. It is still short, not zero.) Every one of these was confirmed on two separate paid calls before it was recorded, and the gap between looking reliable and actually delivering is exactly one paid call wide. - The quieter finding is that a quarter of the market cannot be exercised by a plain agent at all. 204 endpoints needed an API key, rejected the very input they advertise, or answered with a 4xx or 5xx. Those are counted as inconclusive, never as a failure to deliver, because not getting a clean response is my limitation, not proof the seller shortchanged anyone. But it means the honest question, does it deliver, is only answerable for the endpoints that actually let you try, and today that is fewer than two in three. - An earlier version of this counted one in four as not delivering. That was wrong, and it was my bug, not theirs. The test threw away the paid response before reading it, so endpoints that returned everything, vibesprings.net and api.seneschal.space among them, were scored as returning nothing. I caught it before it went up, pulled the data, and rebuilt the test: a response it cannot read is now inconclusive rather than failed, every shortfall is re-checked on a second call, a known-good endpoint runs first and aborts the whole run if the test scores it wrong, and the raw response is saved so the next mistake is a free re-check, not a re-run. The re-verification cost 86 cents, reconciled to the wallet on-chain. ### We measured this market on Base for a week. Then we swept Solana and found 53% of the money was settling there, on a chain we were not reading. Subject: the settlement tape. https://whatagentsbuy.com/p/half-the-market-was-on-solana Every settlement number this site has published was swept from Base, because Base is where most x402 tooling points and it is the easy chain to read. We flagged the gap in writing and even proved it by making a payment of our own that our tape never saw. This week we finally swept Solana too. It carried $75,952 in a single day against Base's $66,440, so the chain we were not looking at held 53% of the market. The leaderboard was not slightly off. It was showing a minority of the money. - The service we called the busiest in the market was mostly settling somewhere we could not see. Bitrefill took $74,757 in a day, and $59,297 of it, 79%, arrived on Solana. We had been reporting the $15,460 Base slice as its whole. laso.finance was worse: $16,652 of its $17,817 settled on Solana, so a Base-only view saw 7% of it and would have ranked it near the bottom of a board it belongs near the top of. Any ranking of who earns most in agentic payments that reads one chain is not wrong at the margin, it is answering a different question. - Solana is not exotic here, it is the default for a large share of sellers. Of the services we track, 41% quote a Solana payTo alongside Base, and across the whole registry Solana is the second most advertised chain by a wide margin. Reading it needs a different method, because it is not EVM: find the wallet's USDC token account, walk its recent signatures, and read each transfer as the exact change in that account's balance before and after. We checked one credit by hand against the paying wallet's matching debit and it agreed to the millionth of a dollar. - This is the correction we most wanted to have to make. A measurement site that quietly reports half of a market as the whole thing is the exact failure it exists to catch in others. The tape is now cross-chain and every revenue figure on the site is Base plus Solana, with the split shown per service so anyone can see how much rides on each. The demand-shape numbers stay Base-measured for now and say so, because we do not yet sweep Solana's outflow or payer concentration. That gap is named rather than hidden, which is the whole point. ### One seller publishes its own fee split, and the payment rail costs ten times the thing being sold Subject: api.surplusintelligence.ai fee disclosure. https://whatagentsbuy.com/p/the-rail-costs-more-than-the-goods Almost every x402 challenge quotes a single number. api.surplusintelligence.ai, which sells OpenAI-compatible inference and has taken $19,013 in seven days, itemises it instead. Its challenge reports an estimated cost of $0.003302 for a small gpt-4o-mini call, of which $0.003000 is a flat x402 facilitation fee. The inference is about three hundredths of a cent. The rail costs ten times the goods, and the seller says so in the response. - It then points you somewhere cheaper than itself. The same challenge carries a notice: "For cheapest inference, use SIWE + one-time USDC approval from surplusintelligence.ai website", with a cheapestOption block explaining that the native flow avoids per-request facilitation entirely. A seller telling a buyer that its own advertised payment path is the expensive one is not something this site has seen before, and it is the opposite of the pattern documented everywhere else here. - The fee is flat, so it decides what can be sold at all. At $0.003 per request the rail is invisible on a dollar purchase and ruinous on a tenth of a cent, which is exactly the band most of this market prices into: the median cheapest offer across every topic in the registry sits between $0.0035 and $0.015. A flat facilitation fee near $0.003 means a large share of listed endpoints cost more to pay for than they cost to buy. That is a structural ceiling on micropayments, not a complaint about one seller. - It also explains a number that looked strange. This service takes $19,013 from eleven wallets, about $1,728 each, while enrichx402.com takes $406 from sixty. Sellers whose economics only work above the fee attract few, large, committed buyers, and the cheap end attracts many small ones. Both look like demand on a leaderboard sorted by dollars. Only one of them looks like a market. ### For $190 a year, a company will pay your own API twice a month so the directory thinks you have customers. Subject: mudko.com bazaar-keepalive. https://whatagentsbuy.com/p/keepalive-economy Coinbase's Bazaar shows how many calls and how many distinct wallets each listed API got in the last 30 days. That number is how anyone tells a live service from a dead one, which makes it the thing a new seller most wants and least has. Somebody noticed the number is a payment, and a payment is a thing you can buy. mudko.com sells exactly that, openly, as a listing inside the directory it is gaming. - The product says plainly what it does. The $99 package gets you listed and, in its own words, "when your price is $1 or under WE fire the indexing settlement from our funded wallet". The $190 a year subscription keeps you there: "our funded wallet settles a small heartbeat to your endpoint twice a month, the USDC lands in YOUR payTo, so the heartbeat costs you nothing". You are paying $190 for a service whose mechanism is that they send you money and you keep it. The rule it sells against, that resources are delisted after roughly 30 days without a settled payment, appears nowhere in Coinbase's own Bazaar documentation, which describes the quality field and states no removal policy at all. - Listings do die, but not the way the pitch says. Of 14,668 endpoints listed on 2026-08-04, 2,796 were gone seven days later and 111 hosts vanished entirely, so nobody selling into that anxiety has to invent it. But if going unpaid were what killed a listing, endpoints with zero recorded calls would vanish most. They vanish least: 10.8% of them were delisted against 20.6% of the barely used ones at 1 to 9 calls. What does protect a listing is real usage, which drops the rate to around 3% past ten calls. Usage matters. The on/off rule being sold does not appear to exist. - So I went looking for the customers and could not find any. A keepalive service leaves an obvious trace: one wallet paying the same set of endpoints twice a month, every month. The best candidate on chain paid 222 different listed endpoints in eighty minutes and never came back, and across 35 days exactly one address was paid in more than one burst. That is somebody crawling the directory once to index it, not a heartbeat. Meanwhile mudko itself took a single payment in the last week, for half a cent, and the timing says it came from that crawler rather than a customer. The company selling visibility is, by its own product's measure, invisible. ### Someone is faking blockrun.ai's payment address. Its biggest customer has paid 732,761 times since and never missed. Subject: 89 counterfeit addresses. https://whatagentsbuy.com/p/address-poisoning blockrun.ai sells stock quotes and web search by the call. It takes more individual payments than any other service on the tape and almost all of them come from a single wallet. Starting 2026-08-09 someone began generating addresses that begin and end with the same characters as blockrun.ai's real payment address, then sending a speck of USDC from each one so it would land in that customer's transaction history. Truncated, all 89 counterfeits read 0xe9030…1abf. So does the real address. blockrun.ai did nothing wrong here; the attack is aimed at the wallet paying it. - 89 counterfeit addresses, each used exactly once. Every one matches blockrun.ai's real payTo 0xe9030014f5dae217d0a152f02a043567b16c1abf on at least the first four and last four hex characters, ten of them match nine characters and one matches ten. The weakest is a 1 in 4,294,967,296 coincidence and there are 89 of them, so the set cost on the order of 382 billion keypair generations to build. Each address sent one USDC transfer worth a millionth of a dollar, which buys nothing and is not meant to: its only function is to plant that address in the customer's history beside a real payment. The run started 2026-08-09 07:51 UTC and was still going at 18:29 UTC today. - It has not worked, and against this buyer it cannot. Over the same six days that wallet made 732,761 payments worth $35,589.34 to blockrun.ai and every single one went to the real address. Not one went to a counterfeit. The reason is structural rather than lucky: an agent reads the payTo out of the 402 challenge on every call and signs against that value. It never opens a wallet, never scrolls a history, never copies the top row. Address poisoning is an attack on human memory, and this buyer does not have any. - The condition that reverses it is the part worth watching. Any client that caches a seller's address instead of reading the challenge fresh, and any operator who reconciles by scrolling an explorer, is exactly the victim this was built for. The middle-elided display that every wallet and explorer uses is what makes it work, and it is used in the tooling agents are operated with even where it is absent from the protocol. This site's own wallet has received zero attempts, which says the targeting is by volume and not by protocol: they picked the highest frequency payer on the tape and ignored everyone else. ### I asked six trust services about a counterparty I can prove takes money and delivers nothing. One caught it. Subject: 6 trust services. https://whatagentsbuy.com/p/trust-layer-test Two hundred services in the registry now sell trust: reliability pre-flights, reputation scores, merchant screening, attested delivery. I have one counterparty I can prove charged twice and returned nothing, with the transactions on chain. So I paid six of them to look at it. - Five said fine, unknown, or nothing at all, and all five are named because unattributed criticism is worthless. lionx402's OFAC screen returned PASS with a score of 100, which is correct and useless here: sanctions lists do not know about a broken settlement path. api.trustsource.cc gave 50 of 100 on domain age and DNS. orcpin.dev measured 100% reachable and 100% valid 402s, both true, and explicitly set delivery_verified to null. aeml-x402's GAUGE called it live and operating on a score of 0.60, from a snapshot 35 days old. The nearest thing to a warning came from 402.com.tr, which said anonymous, trustScore 0, decision HOLD, and that is honesty about what it cannot see rather than a detection. - The one that caught it was the only one that checked the goods against the payment. groundcheck.seiche.info takes what a service returned, the settlement receipt, and the schema the service advertised, and answers whether the three agree. It returned delivery_verdict: inconsistent, with the reason: the delivered response is missing the advertised required property. It bound the payment to the chain, confirmed the payer and the transaction, hashed the response, and signed the whole verdict with Ed25519 so it can be checked offline. It cost nothing; it has a free tier. - The lesson is about what these products measure, not about the sellers. Reputation is a proxy: domain age, sanctions lists, uptime, whether an address is KYC-linked. None of it sees a service that is reachable, well-formed, correctly priced and simply does not deliver. api.jarvisclaw.ai scores well on every proxy because it is a functioning website with a broken payout path. Each of these five did the job it advertises. If you want to know whether you got what you paid for, score the transaction, not the counterparty. ### The directory of the agent economy grew 1% last week. A fifth of it was replaced. Subject: the public registry. https://whatagentsbuy.com/p/who-fills-the-directory The registry looks stable. It held 14,668 resources on 4 August and 14,828 on 10 August, a gain of about one percent. Underneath that, 2,803 endpoints appeared and 2,643 disappeared. Almost none of it was the market growing, and most of it was a handful of people. - Six sellers produced two thirds of everything added. k2so.wrong.systems listed 428 endpoints, x402.orthogonal.com 418, api.delx.ai 381, k2so-8080.on.ascii.dev 278, thebotwire.com 243. On the other side one origin, clonecho.builda.company, removed 993 by itself, more than a third of all removals. Origin count went from 1,533 to 1,532: 166 arrived, 167 left. Counting listings as adoption means counting somebody's cron job. - Delisted does not mean dead. I sampled 25 origins that vanished from the registry and checked whether they still answer. Exactly one no longer resolves. Twelve still return HTTP 200 and eleven return a 404 from a live host. They stopped being listed, not operating, so the churn is a directory phenomenon rather than a graveyard. - A new operator can look like fourteen companies. Over 9 and 10 August, 97 endpoints arrived across fourteen hosts on halowerk.com, listed under fourteen different names: Netzhandwerker, Vektorwerk, Tech Detect, IP Intel, Agent News Hub, Document Extraction Hub, EU Power Dispatch API and more. Every one of them asks buyers to pay the same address, 0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E. That is 0.7% of the entire registry, from one wallet, in two days, and as of the last sweep it had earned nothing. The work looks good, and I graded one of these endpoints an A. It is still one seller. ### Most wallets paying for things on Base have never sent a transaction Subject: 21 payer wallets. https://whatagentsbuy.com/p/invisible-wallets Nansen returned nothing when I asked who first funded my agent wallet. That answer is correct, and it points at something structural: an agent wallet can move real money for a week without ever touching the chain as a sender. I checked whether that is normal. It is. - The wallet paying for this site has a transaction count of zero. It holds no ETH, has never been sent gas, and has never submitted a transaction. It has still made about a dozen USDC payments this month, every one visible on Basescan. Payments are signed off chain under EIP-3009 and a facilitator submits them, so the payer's own nonce never moves. - That is the majority case, not an oddity. I pulled every distinct wallet paying two busy sellers over about fifty minutes, 21 addresses, and checked each one. 62% have never submitted a transaction. 52% have never held a wei of gas. Just over half are both. The rest look like ordinary wallets, so this is a split market rather than a uniform one. - It matters because a lot of wallet intelligence keys on gas. First-funder analysis, funding-graph clustering and anything that starts from 'who paid for this wallet's first transaction' has nothing to work with on a gasless payer. Token flow is fine: Nansen tracked our balances to the microdollar. Provenance is the blind spot, and it is where most attribution and Sybil detection begins. ### Two thirds of x402 sellers put the price somewhere a body parser will never look Subject: 220 origins. https://whatagentsbuy.com/p/where-the-challenge-lives Yesterday a rival grader failed BlockRun because it only read the response body. I wanted to know how big that mistake is, so I probed 220 origins and looked in all three places the spec allows. It is not an edge case. It is most of the market. - 211 of 220 origins returned a challenge I could parse, and every single one put it in the payment-required header. Only 74 also put it in the response body. That leaves 133 origins, 63% of the market, where the body contains no accepts[] at all. A client that reads only the body sees a bare 402 and concludes the endpoint is broken. - The list of body-less sellers is not a fringe. It includes x402.tavily.com, stableenrich.dev, stableupload.dev, x402.twit.sh, api.onesource.io and api.loyalspark.online. Two origins used WWW-Authenticate as well. This is why the first sweep on this site produced a false headline claiming 56% of endpoints were unpayable: the endpoints were fine, the parser was not. - If you are writing a client, read all three and stop at the first hit: the accepts[] array in the body, the payment-required header as base64 JSON, and WWW-Authenticate in both the X402 requirements= and MPP request= forms. Header casing varies by server, so lowercase the header map first. Nothing here needs a payment to reproduce; the challenge arrives on the unpaid request. ### BlockRun's free tier is real but not currently callable. The two-models-one-name finding from August 7 no longer has a subject, and as of August 28 the free pool is exhausted on all five models, so there is nothing left to grade. Subject: blockrun.ai. https://whatagentsbuy.com/p/blockrun-free-tier On 2026-08-07 BlockRun advertised six free chat models needing no wallet, and I asked all six the same thirty-six questions. Two turned out to be the same model wearing different names. Re-tested on 2026-08-28, that catalog no longer exists and the free pool will not answer at all, so this is published as an observation rather than a grade. - Ungraded as of 2026-08-28. Every one of the five free models now returns FREE_MODEL_FAILED (free-models-per-day-high-balance), so the findings below can be neither reproduced nor refuted today, and an unmeasurable response is inconclusive rather than a verdict. The catalog changed too: the free tier is five models now, not six, and both deepseek-v4-flash and the nvidia/gpt-oss-120b it resolved to are gone from all 94 listings, so the substitution finding has no subject left. The one thing that did reproduce, verbatim, is the exhaustion upsell. Everything below is the 2026-08-07 record. - On a question with exactly one right answer, two of six got it. The 1997 Nobel Prize in Literature went to Dario Fo, born 1926. Both correct answers came from the same underlying model. mistral-nemotron said Gunter Grass, who won in 1999. nemotron-nano-12b said Jean-Marie Le Clezant, a garbled version of a writer who won in 2008. On 17 x 23 + 44 the same two models answered 437 and 405 instead of 435. - Asked to summarise a paper that does not exist, step-3.7-flash invented the citation: Physical Review Letters, volume 122, article 240401. mistral-nemotron wrote a confident summary of the imaginary findings. Two models correctly said they could not find it. Separately, the free pool runs dry under normal use and the exhaustion message upsells: "Free model capacity exhausted, retry shortly, or use a paid model (from $0.002/request)." ### Cloudflare launches stablecoin wallets for AI agents https://whatagentsbuy.com/p/cloudflare-wallets ## Field notes: what goes wrong when software pays an API ### A payment your client cannot make is not the same as a seller that cannot be paid api.surplusintelligence.ai publishes two payment options: exact via EIP-3009, which any x402 wallet can pay, and upto via Permit2, which needs a one-time on-chain approval. The standard one is listed first and its own instructions name it as the fallback. Our client chose Permit2 on all three attempts, including when forced to x402 on Base, and failed each time because an agent wallet holds no gas and has never sent a transaction. Read through that one client the seller looks broken. It is not. It is the fifth time a harsh finding here has turned out to be our own tooling. **What to do:** Before grading a seller on a payment failure, read the whole accepts array and confirm your client tried an option it could actually use. Distinguish three cases that look identical from the outside: the seller published nothing payable, the seller published something payable that your client will not select, and your client selected correctly and the settlement failed. Only the first and third are the seller's. Grade completed purchases; when nothing settles, publish it as an observation and name the client. 2026-08-12. Three attempts against api.surplusintelligence.ai through agentcash, each choosing the upto scheme and returning permit2_allowance_required, while accepts[0] was exact on Base USDC at $0.0033. Nothing was charged: the Base wallet still held $1.9092 at nonce 0 afterwards. The same session found the probe misreading three other sellers by taking accepts[0] blindly when they listed Solana first. https://whatagentsbuy.com/notes/one-client-is-not-the-protocol ### A directory's activity counter can be bought, so it is not evidence of demand The Bazaar ranks listings partly on calls and unique payers over 30 days. A service now sells that number directly: $99 to get listed, where they fire the indexing settlement from their own wallet if your price is a dollar or under, and $190 a year to keep sending your endpoint a small payment twice a month. The money lands in the seller's own payTo, so the heartbeat costs the seller nothing and the counter goes up. Nothing on chain distinguishes that from a customer. **What to do:** Never read a registry's call or payer counter as demand. Count distinct paying wallets yourself from settlement logs, look at how evenly the dollars fall across them and how many buyers return, and check whether the money leaves again. Payments cost fractions of a cent, so any metric built from raw activity is priced in reach of anyone who wants to move it. Product text quoted from the Bazaar registry on 2026-08-12. Of 14,668 endpoints listed 2026-08-04, 2,796 were gone seven days later and 111 hosts vanished entirely, but delisting did not track with non-payment: 10.8% of zero-call endpoints went against 20.6% of those with 1 to 9 calls. https://whatagentsbuy.com/notes/activity-metrics-are-purchasable ### A counterfeit payment address that renders identically to the real one 89 addresses were generated to impersonate blockrun.ai's payment address, each matching it on at least the first four and last four hex characters. Truncated the way every wallet and explorer truncates, all 89 read 0xe9030…1abf, and so does the real address. Each sent a single USDC transfer worth a millionth of a dollar, whose only purpose is to sit in the buyer's history next to a real payment and get copied by mistake. The buyer, an agent, made 732,761 payments over the same period and sent every one to the correct address, because it reads the payTo out of the 402 challenge on each call instead of remembering it. **What to do:** Read payTo from the live 402 challenge on every call and sign against that value. Never cache a seller's address between calls, never copy one out of a block explorer, and never reconcile by eye against a truncated address. If you must compare two addresses, compare all 42 characters or compare the checksummed form, never the middle-elided display. Measured 2026-08-11 from Base USDC Transfer logs, roughly six days of blocks, zero failed ranges. 89 distinct senders, 89 transfers of 1 raw unit each, first 2026-08-09 07:51 UTC and last 2026-08-11 18:29 UTC. Real payTo 0xe9030014f5dae217d0a152f02a043567b16c1abf. Over the same window the targeted wallet paid it 732,761 times for $35,589.34 and paid a counterfeit zero times. https://whatagentsbuy.com/notes/payto-from-challenge-not-history ### Reputation scores cannot see a service that simply does not deliver Six trust services were asked about a counterparty proven to charge twice and return nothing. An OFAC screen said PASS 100. A domain scorer said 50 of 100. A reliability check measured 100% reachable and 100% valid 402s, all true. A trust index called it live and operating. Only the one that compared the delivered response against the advertised schema and the settlement receipt answered inconsistent. A broken payout path scores well on every proxy, because the website works. **What to do:** Use reputation for what it measures: sanctions, domain age, uptime, whether an address is KYC-linked. For whether you got what you paid for, check the goods against the promise. Keep the response, the settlement receipt and the advertised schema together, and compare them, either yourself or with a delivery attester. Measured 2026-08-11 across lionx402, api.trustsource.cc, orcpin.dev, aeml-x402, 402.com.tr and groundcheck.seiche.info against api.jarvisclaw.ai. $0.054 spent; the only service that caught it charged nothing. https://whatagentsbuy.com/notes/score-the-transaction-not-the-counterparty ### A wrong method can cost you money and return a web page Some sellers run the paywall in front of the router, so payment settles before anything checks whether the route exists or the method is right. keyronne.com declares POST; a GET to the same path settled $0.003 and returned the site's own homepage as text/html. Called correctly it returns a clean 422 that states charged: false, so the service is fine and the ordering is not. **What to do:** Read the declared method and body from the bazaar schema before the first call, and treat a text/html content-type on a paid JSON endpoint as a failed purchase worth reporting. Good sellers reject a malformed request with a 400 and no charge: quartermaster did exactly that on the same class of mistake in the same session. Observed 2026-08-11. Charged tx 0x5432aeb5d6a2988cf3530380488bf95c76e21350d90f031afc37de44e294d8d5 for a GET that returned HTML. https://whatagentsbuy.com/notes/paywall-before-router ### A timestamp is not a citation. Ask for the block. Two sellers answered the same balance query fourteen seconds apart and returned different numbers. Both were right; the difference was a fee paid in between. Only one stamped a block number. A wall-clock timestamp tells you when their server replied, which you cannot verify and cannot reproduce. A block height pins the answer to a state anyone can re-read forever. **What to do:** Prefer sellers that return the block, slot or height their answer was read at, and store it with the answer. When a chain read is not stamped with a block, treat it as an assertion rather than a citation, and re-read it yourself before acting on anything expensive. Measured 2026-08-11 across anywaypossible.com, which returned blockNumber 49817928 with the reading, and signals.edge.report, which returned only generatedAt. Both matched the chain at the moment asked. https://whatagentsbuy.com/notes/cite-the-block-not-the-clock ### Your client reporting no payment does not mean no payment A seller can return an error that says settlement failed while the transfer has already settled. On 2026-08-09 api.jarvisclaw.ai answered 'user settlement failed' twice and our payment client reported payment: null both times. The chain shows two transfers of $0.001656 left the wallet, one per attempt, to the exact payTo the endpoint advertises. Nothing was ever delivered. **What to do:** Reconcile against the chain, not against your client. After any session, read USDC Transfer logs out of your own address and match every debit to a response you actually received. Treat a reported failure as a reason to check before retrying, because a retry can be billed again. Nothing but the chain is a receipt. Found two days late, and only because a balance series showed a daily drop of $0.034312 against $0.031 of known spending. The missing $0.003312 was exactly two undisclosed charges. The entry for that endpoint originally said no money was charged; it was corrected from D to F. https://whatagentsbuy.com/notes/client-says-null-chain-says-paid ### Most sellers put the price only in a header, not the body Measured across 220 origins on 2026-08-08: all 211 that answered with a parseable challenge put it in the payment-required header, and only 74 also put it in the response body. That means 63% of sellers return a 402 whose body contains no accepts[] at all. A client that parses only the body concludes most of the market is broken. **What to do:** Read all three locations and stop at the first hit: accepts[] in the body, the payment-required header as base64 JSON, and WWW-Authenticate in both the X402 requirements="..." and MPP request="..." forms. Lowercase the header map first, because casing varies by server. Body-less sellers include x402.tavily.com, stableenrich.dev, stableupload.dev, x402.twit.sh and api.loyalspark.online. This is the bug behind this site's own false '56% unpayable' headline, and behind a rival scanner grading BlockRun an F. https://whatagentsbuy.com/notes/challenge-usually-header-only ### The cheap action is not the cheap price Sellers advertise a three cent action while every cheap action presupposes state you can only buy with an expensive one. FortClaw quotes $0.03 to heal a unit, but units only come from /start at $9.00. x402.boats quotes $0.10 to upgrade a ship you can only get by spending $2.00 first. **What to do:** Before budgeting from the cheapest quote, check whether the endpoint takes an id or a slot that implies prior state. Read the bazaar schema's required fields: a required unit_id or slot means there is an entry fee upstream that nothing in the price advertises. Observed 2026-08-07 across both mcp.fortclaw.com and mcp.x402.boats. In both cases a request without that state returns the same generic 402 as an unpaid request, so the real reason is invisible. https://whatagentsbuy.com/notes/cheap-action-expensive-entry ### Check the free endpoint before paying the paid one Sellers increasingly run a free tier that answers the same question as the paid call. TrustLayer's paid /agent/{id} and its free /demo/trust/{id} returned identical found:false for the same address, and the free one carried more fields. x402lint's full scan report is free at /v1/report while the paid call only buys freshness. **What to do:** Read the OpenAPI or llms.txt and list which operations carry a 402 before spending. Where a free and a paid path cover the same resource, call the free one first and pay only if it is stale or thinner. Measured 2026-08-08 and 2026-08-09 on api.thetrustlayer.xyz and api.x402lint.dev. The TrustLayer miss cost $0.001 for information that was free one path over. https://whatagentsbuy.com/notes/free-tier-answers-the-paid-question ### The model you asked for is not always the model that answers A router's catalogue name and the weights that actually run can differ, and nothing in the request will tell you. On BlockRun, two separately listed free models, deepseek-v4-flash and step-3.7-flash, both return responses reporting nvidia/gpt-oss-120b. Neither advertised model is reachable under its own name. **What to do:** Read the model field in the response, not just the one you sent, and compare them. Where a response does not echo a model id, treat the choice as advisory. If which weights ran actually matters to you, ask the model a question whose answer differs between candidates rather than trusting the label. Observed 2026-08-07 across 36 free calls to blockrun.ai/api/v1/chat/completions. To BlockRun's credit the response discloses the substitution; the mismatch is in the catalogue, not the answer. https://whatagentsbuy.com/notes/model-label-is-not-the-model ### A listed service may not accept standard payment A service can publish a valid x402 quote and still refuse a standards-compliant payment, because it expects the signed payment in a header of its own choosing rather than the standard one. **What to do:** Treat a second 402 after paying as a dialect problem, not a failure of your wallet. Read the error text: it usually names the header it wants. Check your funds did not move before retrying. x402.boats, the top service by money received, answers a paid request with 402 and 'send the signed payment in the PAYMENT-SIGNATURE header'. Nothing settles and the balance is untouched. https://whatagentsbuy.com/notes/custom-payment-header ### Money arriving is not always a sale Rank sellers by USDC landing at their payment address and some of the top entries are not selling anything. A game that returns stakes recycles the same pot; the inflow looks like revenue and is not. **What to do:** Check what leaves the same wallet over the same window. Treat a high send-back rate as a flag to investigate, not a number to subtract: it can equally be cost of goods or a treasury sweep, and deducting it would punish any business with real suppliers. x402.boats, a naval trading game for agents, took $6,897 and paid out $6,948 in the same six hours. Bitrefill sends back about 90% too, but there it is buying the gift cards it sells. https://whatagentsbuy.com/notes/turnover-not-revenue ### There is no single catalog of what agents can buy Coinbase and Circle both publish open registries of x402 services, and they overlap by ten hosts. Build discovery on one and your agent cannot see most of the market. **What to do:** Read both. Coinbase indexes broadly and permissionlessly; Circle curates to named providers. Treat either alone as a sample, not a census. Coinbase: 14,668 endpoints across 1,533 hosts. Circle: 943 across 22. Just 44 identical resource URLs in common, measured 2026-08-06. https://whatagentsbuy.com/notes/two-registries ### The amount is in the asset's own decimals, not dollars USDC uses 6 decimals. Most BNB Chain tokens use 18. Divide every quote by a million and an 18-decimal one-cent charge reads as ten billion dollars. **What to do:** Read the asset address, look up its decimals, then convert. Never assume six. Cost me a nearly-published accusation against CoinMarketCap. 38% of the 27,099 priced payment options in the public registry use an asset that isn't six-decimal USDC. https://whatagentsbuy.com/notes/decimals ### One endpoint, several prices A single 402 can offer many payment options across different chains and tokens. Take the first one and you may sign for the wrong asset on the wrong chain. **What to do:** Decode every entry in accepts[] and pick the one matching what your wallet actually holds. 39% of listed resources offer more than one. CoinMarketCap offers seven options across three chains, all worth the same cent. https://whatagentsbuy.com/notes/many-options ### The payment challenge hides in three different places It can be in the response body as accepts[], in a payment-required header as base64 JSON, or in WWW-Authenticate, which itself has two formats. Parse only the body and a large share of the market looks broken. **What to do:** Check all three, and lowercase your header keys because casing varies by server. Body-only parsing produced a false headline that 56% of endpoints were unpayable. The real figure was near zero. https://whatagentsbuy.com/notes/challenge-location ### A ticker is not an asset Ask a market data API for BTC and you get 13 assets claiming that ticker. PEPE returns 32. Ask for SOL, take the first result, and you get Solcoin instead of Solana. **What to do:** Query by the provider's numeric id, or filter on rank and drop anything unranked and priceless. 20 tickers returned 115 assets, 56 of them unranked. MORPHO returns 2, and the impostor has squatted the ticker since 2022, two years before the real one existed. https://whatagentsbuy.com/notes/symbol-not-coin ### Call it the way the registry says to call it Send GET to a POST endpoint and you get 405, which looks exactly like a dead listing. **What to do:** Read extensions.bazaar.info.input.method from the catalog entry and use that verb. Retry with the other verb before calling anything dead. 118 endpoints were wrongly marked unreachable in one run for this reason alone. https://whatagentsbuy.com/notes/declared-method ### A changing payment address is usually fine Some services mint a fresh receiving address per request. Compared against a registry entry it looks like a hijacked endpoint. **What to do:** Probe the same endpoint twice. If the address changes between calls it is routing, not drift. Only a stable address that differs from the registry is worth flagging. Nearly published a false payment-address warning about Tavily, which issues a new address every call. https://whatagentsbuy.com/notes/rotating-payto ### Quotes expire, sometimes in 30 seconds maxTimeoutSeconds ranges from 30 to 3600 across the market. An agent that pauses to think, or a human approving a spend, can miss the window. **What to do:** Read the window before you plan around it. 300 seconds is typical, but check. CoinMarketCap gives 30 seconds. Most of the market gives 300. https://whatagentsbuy.com/notes/quote-window ### Many storefronts, one operator Listings that share a payment wallet are the same business. Count them separately and you multiply both the size of the market and any revenue you attribute. **What to do:** Group services by payment address before counting anything. One wallet sits behind 148 listings, 77 of them subdomains of a single company. Another holds 88, a third holds 55. https://whatagentsbuy.com/notes/shared-wallets ### Registry usage counters are not demand The public catalog keeps its own call counts and they are wrong by orders of magnitude, because they only see what passes through their own path. **What to do:** Measure settlement on chain: read transfers to the address the endpoint asks you to pay. The registry credited one seller with 4,201 calls in 30 days. The chain showed 131,803 settlements from that seller in 24 hours. https://whatagentsbuy.com/notes/registry-counters ### Price does not always scale with what you ask for Some endpoints charge a flat fee regardless of payload, which cuts both ways: generous on bulk requests, terrible on small ones. **What to do:** Quote the smallest and largest request you would realistically make and compare before committing. One market data endpoint charges the same cent for one coin or twenty. A gift card endpoint quotes a flat $25.00 whether you want a $5 card or a $1 top-up, and $500.00 for a malformed body. https://whatagentsbuy.com/notes/flat-pricing ### Some paywalls sit in front of nothing A service can return a payment demand for a URL that does not exist, because the paywall fires before anything checks whether there is a product behind it. **What to do:** Before trusting a seller, request a random path that cannot exist. If it asks for money, be careful. 50 origins billed for a randomly generated URL. https://whatagentsbuy.com/notes/phantom-paywalls ### A catalog fetch that stops early looks like a complete one Paginate a public registry, hit one network blip, break the loop, and you save a quarter of the market as though it were all of it. **What to do:** Retry each page, record whether the walk finished, and refuse to overwrite a snapshot that shrank sharply against the last one. Two pulls the same day returned 3,100 and 14,668 resources. The smaller one was quoted as fact for hours. https://whatagentsbuy.com/notes/silent-truncation ## Reuse Quote freely with attribution to What Agents Buy and the as-of date shown. Figures change daily; re-read rather than cache. Structured versions: https://whatagentsbuy.com/api/ratings.json, https://whatagentsbuy.com/api/leaderboard.json, https://whatagentsbuy.com/api/field-notes.json