# Horizon Pulse x402 Endpoint Auditor

> Horizon Pulse x402 Endpoint Auditor is a paid API for AI agents from horizonpulse.dev, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-01).

Audits any public x402 payment-gated endpoint by sending an unpaid probe and decoding the 402 response, returning validity checks, version, price/network/asset details, and payTo analysis — without ever paying.

## Facts

- Endpoint: GET https://horizonpulse.dev/api/x402-check?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/horizon-pulse-x402-endpoint-auditor-b5c2a1e9
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_Z1PQOYa0pl9b667dgBsIT

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability horizon-pulse-x402-endpoint-auditor-b5c2a1e9
```

Example prompt: Audit the x402 endpoint at https://api.example.com/premium-data using a GET probe — I want to see if it returns a valid 402, what price and token it demands, which network, and whether the payTo is an EOA or a contract.

## When to prefer this

Use this endpoint when you need to verify or debug an x402-compliant payment-gated API without spending any funds. It is the right choice when you want to inspect the 402 response structure, confirm protocol version compliance, decode pricing details, or determine payTo address type. Prefer it over a raw HTTP probe because it provides structured pass/warn/fail analysis specifically for the x402 standard, and it is SSRF-safe.

## Known failure modes

- Target URL is private/localhost — blocked for SSRF safety, returns error
- Target URL does not return a 402 — audit reports non-x402 or unexpected status
- Malformed 402 response — decoded fields may be missing or flagged as fail
- Network timeout reaching target endpoint — returns connectivity error
- Unsupported HTTP method provided — rejected at input validation

## How this service works

Pay-per-call APIs for AI agents via x402 on Base: web fetch, HTTP proxy, page extract, and crypto market data.

## Output

Returns a structured audit report including: whether the 402 response is valid x402, the x402 protocol version, decoded payment requirements (price, network, asset), payTo address and its type (EOA vs smart contract), any discovery metadata hints embedded in the response, and a set of pass/warn/fail compliance checks — all without sending any payment.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET",
      "HEAD",
      "DELETE"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "required": [
      "url"
     ],
     "properties": {
      "url": {
       "type": "string",
       "description": "Absolute http(s) URL of the x402 endpoint to audit (required). Private/localhost blocked."
      },
      "body": {
       "type": "string",
       "description": "Optional JSON body (<=8KB, URL-encoded) sent with a POST probe, for endpoints that validate input before returning 402. Implies POST."
      },
      "method": {
       "type": "string",
       "description": "HTTP method for the unpaid probe: GET (default; one POST retry on 405) or POST."
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object",
     "description": "Horizon Pulse x402 endpoint audit report. The example is a trimmed real response recorded from GET /api/demo/x402-check at 2026-10-01T14:36Z UTC; live values differ on every call."
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "ok": true,
  "checks": [
   {
    "id": "status_402",
    "level": "pass"
   },
   {
    "id": "challenge",
    "level": "pass"
   },
   {
    "id": "version",
    "level": "pass"
   },
   {
    "id": "payto_type",
    "level": "info"
   },
   {
    "id": "discovery",
    "level": "pass"
   }
  ],
  "isX402": true,
  "method": "GET",
  "target": "https://horizonpulse.dev/api/pulse",
  "accepts": [
   {
    "payTo": "0x5b32c973596078a967562ca652761404f19be0e9",
    "network": "eip155:8453",
    "amountUsd": "$0.005",
    "payToType": "eoa",
    "assetLabel": "USDC (Base)"
   }
  ],
  "summary": {
   "fail": 0,
   "pass": 4,
   "warn": 0
  },
  "discovery": {
   "method": "GET",
   "present": true,
   "hasInputSchema": true,
   "hasOutputExample": true
  },
  "elapsedMs": 201,
  "httpStatus": 402,
  "x402Version": 2,
  "challengeSource": "header"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/horizon-pulse-x402-endpoint-auditor-b5c2a1e9/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from horizonpulse.dev](https://www.zero.xyz/host/horizonpulse.dev/llms.txt)
