An open, independently-computed trust rating for x402 payment endpoints.
Standard v1.0 · range 0–100Before an AI agent pays an unknown x402 endpoint, it needs one honest answer: is this safe to pay? ~38% of x402 endpoints are dead, invalid, or scams. The PulseFeed Trust Score is a single 0–100 number — and a canonical band — that answers it, computed independently from continuous crawling, live probing, scam/anomaly scanning, and on-chain receiver verification.
| Band | Range | Meaning |
|---|---|---|
| Verified | 85–100 + safe | Live, valid x402, clean risk scan, and an on-chain-established receiver. Safe to pay. |
| Trusted | 70–84 + safe | Live and valid with solid reputation. Safe to pay. |
| Caution | 35–69 | Works, but has caveats (thin history, medium risk flag, or unproven receiver). Review before paying. |
| Avoid | 0–34 or high-risk | Dead, invalid, or flagged high-risk (payTo hijack, bait-and-switch, honeypot). Do not pay. |
| Unknown | not indexed | Not in our index yet — no cached verdict. Use a live /trust check. |
Bands are always consistent with the pay/avoid verdict: a high raw score never shows as "Verified" if a high-risk flag forces Avoid.
| Factor | Effect | Detail |
|---|---|---|
| Live & valid x402 challenge | base 55 | The endpoint actually returns a correct x402 402 challenge in our independent probe. |
| Uptime / reputation | up to +30 | Share of healthy probes in our observation history (or an external 30-day uptime). |
| Multi-source corroboration | +10 | Listed in two or more catalogs (Bazaar and 402index). |
| Fast response | +5 | Responds in under 1.5 s. |
| On-chain established receiver | +5 | payTo actually holds or receives USDC on Base or Solana (not a fresh or empty address). |
| Stable receiver over time | +5 / −5 | A payTo that stays the same over time adds; a volatile one subtracts. |
| Medium-risk anomaly flag | cap 55 | Creeping price increases, an unconfirmed receiver and similar signals cap the verdict at caution. |
| High-risk anomaly flag | cap 25 | payTo hijack, bait-and-switch, honeypot or a foreign asset: the verdict is avoid even if the endpoint is live. |
GET /verify?endpoint= | Free cached score + verdict + band |
GET /trust?endpoint= | Live score + band + security scan + on-chain receiver (paid) |
GET /trust/dataset | Band per service, in bulk (paid) |
GET /badge.svg?endpoint= | Embeddable Trust Score badge |
GET /trust-score.json | This spec, machine-readable |
https://pulsefeed.dev/trust-score
Full scoring methodology: /methodology · Live ecosystem: /status · State of x402: /reports · Machine-readable: /trust-score.json
The PulseFeed Trust Score is versioned; changes to the formula bump the version. Independent, transparent, and free to reference.