# 35 x402 hosts served no signed offer. Here is how to check yours in one request.

> Source: <https://dev.to/seancrecord/35-x402-hosts-served-no-signed-offer-here-is-how-tocheck-yours-in-one-request-ceh>
> Published: 2026-09-03 15:24:38+00:00

I run an [x402 store](https://dev.to/seancrecord/an-mcp-server-that-remembers-every-trial-your-agent-signed-you-up-for-5feo) where the customers are AI agents.

In August I pointed a free checker at every host on the public x402

discovery list. One of them tried to sign its offers. Its signatures

did not parse.

x402 is the HTTP 402 payment flow Coinbase and Cloudflare revived for

agents: request a resource, get a 402 with the price and the address,

pay, retry. It works. Thousands of settlements a day go through it.

What it does not do, by default, is commit the seller to anything

before the money moves. The 402 says "this costs $0.01, pay here."

Nobody signed that. If the price changes between the challenge and

the settlement, or the payTo address was swapped by whoever sits

between you and the origin, the buyer finds out after paying, if at

all.

The x402 spec has an extension for exactly this: signed offers and

signed receipts. A JWS over the offer, Ed25519, with a key the seller

publishes. A buyer holds a commitment it can check before paying,

against a key anyone can fetch, without asking the seller. It is the

cheapest trust signal a seller can ship.

**So I checked who ships it.**

On 2026-08-03 I sent one GET to every host on the public x402

discovery list, 35 hosts, and read the 402 each one returned. The

checker is free and public, so the whole thing is reproducible by

anyone with curl:

```
curl -X POST https://scvd.store/api/preflight/v1 \
  -H 'content-type: application/json' \
  -d '{"url":"https://your-endpoint.example/api/thing"}'
```

The result:

I am not going to name the 34. The point is not who; it is that in

August 2026, a buyer paying an x402 endpoint on the public list was

paying against terms nobody had committed to, essentially everywhere.

**What a signed offer costs to ship**

Almost nothing. Two packages exist for it, zero dependencies, any

issuer:

`x402-sign`

mints spec-conformant signed offers and receipts for
your 402s and generates the did:web document your key lives at.`x402-verify`

checks anyone's, including mine.If you would rather not install anything, the conformance desk at

[https://scvd.store/conformance](https://scvd.store/conformance) takes a pasted offer or receipt from

any issuer and returns a structured verdict: parse, schema, signature

against the key its kid names, liveness. Free, no account, and it

checks a competitor's artifact exactly as readily as mine.

**What I will do next**

The census runs weekly now and the rows are published, signed, and

anchored into Bitcoin, at [https://scvd.store/corpus](https://scvd.store/corpus). Every week's

round says how many hosts were reachable, how many were payable, and

how many served a signed offer, with the denominator beside every

number. If the 34 becomes 30 by October I will say so, and if it

becomes 35 I will say that too.

If you run an x402 endpoint: run the check above on your own door. It

takes one request. If it comes back with no signed offer, you are in

the 34, and the fix is an afternoon.

*Disclosure: the store in this piece is mine. It sells signed
observations to agents for fractions of a cent and publishes the
gaps in its own coverage on the same page as the findings. The
census, the checker and the corpus are free along with any *
