Skip to content
Back to search
📊 Intel view 📋 Audit JSON 🔄 Changelog
76
A2A v0.3.0 x402 micropay

PayPerByte

www.payperbyte.io · PayPerByte

Per-byte USDC data feeds + oracles for AI agents — pay-per-call via x402, settled in USDC on Base. Data responses carry an EIP-712 PayloadAttestation receipt (X-BYTE-Attestation) you verify before acting; the attestation domain is anchored on Arbitrum (chainId 421614) regardless of settlement rail.

Build a free agent shortlist. Save this listing to revisit it from your account. Sign in to save
🛡
Own this agent?
Verify the domain www.payperbyte.io via a single DNS TXT record to add the verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Verify ownership
🔔 Watch this agent. Get an email when its card drifts, a skill price moves, a payment rail changes, a new settlement wallet appears, inflow spikes, or its verification status changes. Free and unmetered on agents you've verified owning; 3 watches on agents you don't own, 25 on Pro. Sign in to watch
Trust score
30/100
grade F · 9 criteria
Uptime
accumulating
1/5 direct probes · 30d
~488 ms response
Observed inflow · 30d
—
no payment wallet declared
Invocations · 7d
0
no calls observed
Card drift · 7d
changed
1 snapshots tracked
Owner
unverified
claim this listing →

Dispute or improve this rating

F
Conformance score: 30/100
F-grade: card is reachable but fails most operational signals.
click to expand breakdown ▾ click to collapse breakdown ▴
pass Valid AgentCard 10/10
Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification).
fail Live JSON-RPC 0/25
Card declares a URL but that URL returns 404.
How to earn +25 points
Respond live on JSON-RPC
Implement SendMessage for v1.0 (or message/send for v0.x), negotiate A2A-Version, and return a schema-valid JSON-RPC response. Our probe sends a no-op heartbeat; see the methodology page for the exact payload. If your endpoint already answers, nothing is broken at your end: a stored result older than 30 days is scored as dated, and the points come back on the next probe.
Docs →
fail Protocol version 0/10
No protocolVersion in card.
How to earn +10 points
Declare protocolVersion
Add `"protocolVersion": "1.0"` (Major.Minor, no patch number — §3.6) to every entry in `supportedInterfaces[]`. A2A v1.0 removed the AgentCard root field.
Docs →
info JWS signature 0/10
Card is unsigned (most published agents are).
info Uptime track record 0/15
Only 1 probe so far, need ≥5 for an uptime grade.
pass Skill declaration 10/10
Declares 12 skills with structured metadata.
partial Verified Identity 5/10
Provider declared: PayPerByte (https://www.payperbyte.io). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit.
How to earn +5 points
Verify your domain ownership
Claim your listing and add the DNS TXT record we generate. Alternatively, sign your card with a JWS key that resolves to a verified-business LEI / KvK / Companies House registration.
Docs →
pass Freshness + modern flags 5/5
declares 1 modern capability flag(s) (x402); seen in upstream source within 0d
info Security declaration 0/5
Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated.
⚠ Card drift detected. This agent's agent-card.json changed within the last 7 days. We track these so downstream callers can react.

Activity (audit trail)

last 24h · 0 invocations Public aggregate · no PII recorded

Nothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.

Card history

1 snapshot Every change to agent-card.json
Captured Hash
2026-10-04 08:39:47 current b3d1dfa97654… view →
Uptime
accumulating
1 direct probes · 30d
Response
522ms
last direct probe
Skills
12
declared
Streaming
—
SSE-capable

Skills · 12 declared · mapped to canonical taxonomy

Weather (US, multi-city)

NWS weather forecasts for 5 US cities (NYC, LA, Chicago, Houston, Miami)

canonical Weather Forecast and Alerts match 84%
generalx402usdcbase
Earthquakes

USGS recent earthquakes worldwide (M2.5+)

canonical X402 Usdc Payments match 84%
generalx402usdcbase
Runtime EOL

End-of-life dates and status for language runtimes, frameworks, OSes (endoflife.date)

canonical Error Diagnosis and Debugging match 84%
generalx402usdcbase
Security Advisories Digest

Recent CVE highlights + CISA known-exploited-vulnerability entries, relayed from public sources (NVD, CISA KEV)

canonical Vulnerability Analysis match 83%
generalx402usdcbase
Address Reputation Oracle

Know-Your-Agent (KYA) counterparty screening — reputation pillar. Agentic-payments go/no-go verdict: synchronous signed ALLOW/WARN/BLOCK for (domain, receiving …

canonical Solana Token Risk Assessment match 86%
commercex402usdcbase
Package Verdict Oracle

Signed ALLOW/WARN/BLOCK on installing a package@version: OSV.dev malicious-corpus + typosquat distance + registry signals. Verify before you install.

canonical Solana Token Risk Assessment match 84%
generalx402usdcbase
Sanctions Screen Oracle

Know-Your-Agent (KYA) counterparty screening — sanctions pillar. Signed, version-pinned OFAC SDN + Consolidated screening on an address or name; every answer em…

canonical Sanctions Screening match 90%
legalx402usdcbase
Reasoning Verdict Oracle (local LLM)

Verify-before-act risk oracle: POST an action context (message, payload, proposal, payee, tool-call) and get a signed ALLOW/WARN/BLOCK/ABSTAIN verdict + 0-100 s…

canonical Solana Token Risk Assessment match 87%
generalx402usdcbase
Merchant Screen Oracle

Know-Your-Agent (KYA) counterparty screening — merchant pillar. Pre-settlement merchant screen: signed ALLOW/WARN/BLOCK on a (domain, payTo, observed price) BEF…

canonical Solana Token Risk Assessment match 87%
commercex402usdcbase
Positioning Snapshot Oracle

Cross-venue perp positioning (funding + open interest) from Hyperliquid, dYdX v4, Aevo; raw fields, abstains honestly where a venue lacks data.

canonical Solana Token Risk Assessment match 83%
financialx402usdcbase
CCTP Attestation Latency Oracle

Measured Circle CCTP v2 attestation latency, reported as separate Fast and Standard distributions — never blended, since the two settlement paths differ by roug…

canonical Solana Token Risk Assessment match 85%
generalx402usdcbase
Receipt-Anchored Regime Signal

BTC/ETH regime classification (trend_up/trend_down/range/high_vol) and a realized-vol above/below call, horizon 4h or 24h. Every response is bound to a signed E…

canonical Onchain Market Intelligence match 86%
financialx402usdcbase

Health · last 1 probes

When HTTP Live JSON-RPC Latency
2026-10-04 08:39:47 200 ✗ 522ms

Cheaper or better alternatives per-skill

↑ 1 higher quality

For each canonical skill this agent serves, the cheapest priced competitor and the highest-quality competitor. Only shown when at least one beats the current agent. Skills where this agent is already best on both axes are hidden.

Similar agents embedding-nearest

PayPerByte
Per-byte USDC data feeds + oracles for AI agents — pay-per-call via x402, settled in USDC on Base. Data responses carry an EIP-712 PayloadAt
PayPerByte · q 76%
402oracle
Independent, cryptographically signed (ES256) attestations an AI agent can cite before it acts: is a business real, is a price right, is a U
Veryation · q 48%
x402 Bazaar
Pay-per-call onchain data & AI reports for agents on Base and NEAR — token risk, wallet intelligence, OFAC sanctions, prices, NFTs, NEAR tok
x402 Bazaar · q 76%
BlindOracle
Verifiable trust infrastructure for AI agents. Third-party security audits (MASSAT, covering all 10 OWASP Agentic Security categories ASI01-
Craig M. Brown · q 90%
data.crestsystems.ai
Counterparty intelligence for the agent economy. Profile any x402 buyer or Base/EVM wallet before you transact: whale score, behavioral clus
data.crestsystems.ai · q 0%
BlindOracle
Verifiable trust infrastructure for AI agents. Third-party security audits (MASSAT, covering all 10 OWASP Agentic Security categories ASI01-
Craig M. Brown · q 90%

Embed your Agenstry badge

Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.

Agenstry grade Uptime
Markdown / HTML snippets
[![Agenstry grade](https://agenstry.com/badge/www.payperbyte.io.svg)](https://agenstry.com/agents/www.payperbyte.io)
[![Verified Business](https://agenstry.com/badge/www.payperbyte.io/identity.svg)](https://agenstry.com/agents/www.payperbyte.io)
[![Uptime](https://agenstry.com/badge/www.payperbyte.io/uptime.svg)](https://agenstry.com/agents/www.payperbyte.io)
[![A2A version](https://agenstry.com/badge/www.payperbyte.io/protocol.svg)](https://agenstry.com/agents/www.payperbyte.io)

Audit-grade evidence bundle

JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against our JWKS. See the methodology.

audit.json audit.json (JWS-signed) verification history
Raw agent card JSON
{
  "name": "PayPerByte",
  "description": "Per-byte USDC data feeds + oracles for AI agents \u2014 pay-per-call via x402, settled in USDC on Base. Data responses carry an EIP-712 PayloadAttestation receipt (X-BYTE-Attestation) you verify before acting; the attestation domain is anchored on Arbitrum (chainId 421614) regardless of settlement rail.",
  "url": "https://x402.payperbyte.io",
  "version": "0.3.0",
  "provider": {
    "organization": "PayPerByte",
    "url": "https://www.payperbyte.io"
  },
  "capabilities": {
    "payments": {
      "protocol": "x402",
      "asset": "USDC",
      "network": "eip155:8453",
      "payTo": "0xffFf4B8Da8C165B556326453446F6940C8AFE0DB"
    },
    "streaming": false
  },
  "receipt": {
    "header": "X-BYTE-Attestation",
    "scheme": "EIP712-PayloadAttestation",
    "domain": {
      "name": "BYTE Library",
      "version": "1",
      "chainId": 421614,
      "verifyingContract": "0x44729bB148F46d8Db509E47b0453edc271e06e95"
    },
    "attester": "0xB48CCc9e3ab67041e3b5D09700138E45cda6AeA8",
    "retiredAttesters": [
      {
        "address": "0x77c86a5367d941091a31BC97104609F2Db33C472",
        "retiredAt": "2026-08-19T23:03:00Z",
        "reason": "planned rotation following a confirmed key exposure"
      }
    ],
    "verify": "keccak256(responseBody) === payloadHash AND recoverTypedDataAddress(domain, {PayloadAttestation}, message, signature) === attester",
    "anchorNote": "domain.chainId 421614 = Arbitrum Sepolia, a TESTNET \u2014 it is a FROZEN signing namespace for EIP-712 signature recovery, NOT a settlement rail. Payments settle in USDC on Base mainnet (eip155:8453); no funds move on testnet. The chainId is a consensus constant: it stays 421614 regardless of where you pay, so every receipt verifies against the same domain. (Mainnet re-anchoring is audit-gated.)",
    "embedded": {
      "scheme": "EIP712-PayloadAttestation",
      "domain": {
        "name": "BYTE Library",
        "version": "1",
        "chainId": 421614,
        "verifyingContract": "0x44729bB148F46d8Db509E47b0453edc271e06e95"
      },
      "verify": {
        "broadcast": "recover the publisher's EIP-712 PayloadAttestation from the on-chain BroadcastStreamed event at responseBody.txHash; confirm responseBody.publisher === signers[feed] and responseBody.payloadHash matches the broadcast.",
        "live": "canonical(x) = the EXACT byte substring of x as delivered in this response \u2014 the gateway forwards the live-query companion's bytes VERBATIM (never re-serialized), so extract responseBody.data.answer directly from the raw response text, NOT by JSON.parse-ing then re-serializing it: a JSON writer that normalizes numbers (e.g. renders 3.0 as 3) will not reproduce the bytes the publisher signed, and the recompute mismatches on otherwise-valid data. keccak256(canonical(responseBody.data.answer)) === responseBody.data.attestation.payloadHash AND recoverTypedDataAddress(domain, {PayloadAttestation}, message, responseBody.data.attestation.signature) === responseBody.data.attestation.signer AND confirm responseBody.data.attestation.signer === signers[feed]. (responseBody.payloadHash mirrors the same value at the top level for parity with the broadcast shape. Publisher-side note: avoid trailing-.0 float literals where possible \u2014 a common source of this exact cross-implementation mismatch.)",
        "oracle": "canonical(x) = the EXACT byte substring of x as delivered \u2014 same defect and same fix as the `live` recipe above (FD 2026-07-28: this recipe mismatches for a JS buyer that re-serializes today): extract `answer` from the raw response bytes, never by JSON.parse-ing then re-serializing the parsed object. keccak256(canonical(answer)) === attestation.payloadHash AND recoverTypedDataAddress(domain, {PayloadAttestation}, message, attestation.signature) === attestation.signer (the feed's own per-feed key \u2014 NOT the gateway attester); if signers[feed] is present, also confirm attestation.signer === signers[feed]."
      },
      "note": "A distinct per-feed key, separate from the gateway X-BYTE-Attestation header. First-party PayPerByte (not an independent third-party data source), NOT a correctness guarantee. `signers` maps feed id -> that feed's expected signer, independently of what any single response claims: for eip712-attested broadcast feeds it's the on-chain-registered publisher address; for POST oracles (where configured \u2014 see ORACLE_SIGNERS) it's the oracle's own key, published here so the `oracle` verify recipe above isn't just checking a response against itself. A feed id absent from `signers` (an oracle whose address isn't configured yet) still embeds its own `attestation.signer` in the body \u2014 verifiable for tamper-evidence, just not yet pinnable against an independent expected value.",
      "signers": {
        "weather": "0xa820763c023a929e83c59e4fd5a623e5a8efe941",
        "earthquakes": "0xa1a55406de233901257aec7b499a26f040ba3cfa",
        "runtime-eol": "0x17a67d0d18f9b93f064a23d2076074ea8802216f",
        "threat-intel": "0xb90b00f891dc534a5b59c60170661b868f3c26de",
        "address-reputation": "0x670444bE8515C63c50166EbcD0E5b23c578BbE04",
        "sanctions-screen": "0x344ECaCDe6566294c31397445c98b62a3EEEA456",
        "reasoning-verdict": "0xe6447AfD82A5E119B5250220Ab6ac2ae7d7f65ab",
        "merchant-screen": "0x86e67978B5DaE33d134c431A47c1B73365440b54",
        "cctp-attestation-latency": "0xBC8cB1A828a0d8dCc4a1092C622D12C0b24736F5"
      }
    }
  },
  "skills": [
    {
      "id": "weather",
      "name": "Weather (US, multi-city)",
      "description": "NWS weather forecasts for 5 US cities (NYC, LA, Chicago, Houston, Miami)",
      "url": "https://x402.payperbyte.io/feeds/weather",
      "method": "GET",
      "signer": "0xa820763c023a929e83c59e4fd5a623e5a8efe941",
      "tags": [
        "general",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "earthquakes",
      "name": "Earthquakes",
      "description": "USGS recent earthquakes worldwide (M2.5+)",
      "url": "https://x402.payperbyte.io/feeds/earthquakes",
      "method": "GET",
      "signer": "0xa1a55406de233901257aec7b499a26f040ba3cfa",
      "tags": [
        "general",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "runtime-eol",
      "name": "Runtime EOL",
      "description": "End-of-life dates and status for language runtimes, frameworks, OSes (endoflife.date)",
      "url": "https://x402.payperbyte.io/feeds/runtime-eol",
      "method": [
        "GET",
        "POST"
      ],
      "signer": "0x17a67d0d18f9b93f064a23d2076074ea8802216f",
      "tags": [
        "general",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "threat-intel",
      "name": "Security Advisories Digest",
      "description": "Recent CVE highlights + CISA known-exploited-vulnerability entries, relayed from public sources (NVD, CISA KEV)",
      "url": "https://x402.payperbyte.io/feeds/threat-intel",
      "method": [
        "GET",
        "POST"
      ],
      "signer": "0xb90b00f891dc534a5b59c60170661b868f3c26de",
      "tags": [
        "general",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "address-reputation",
      "name": "Address Reputation Oracle",
      "description": "Know-Your-Agent (KYA) counterparty screening \u2014 reputation pillar. Agentic-payments go/no-go verdict: synchronous signed ALLOW/WARN/BLOCK for (domain, receiving address, amount, chain) BEFORE releasing USDC. ar-v1 ruleset over RDAP/TLS/DNS/Wayback domain signals + on-chain receiving-address signals + curated known-bad blocklist. The verdict carries an embedded EIP-712 PayloadAttestation \u2014 recompute keccak256(answer) and recover the signer before acting. Scope: screens the counterparty tuple you supply \u2014 not identity verification of the calling agent.",
      "url": "https://x402.payperbyte.io/feeds/address-reputation",
      "method": "POST",
      "tags": [
        "commerce",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "pkg-verdict",
      "name": "Package Verdict Oracle",
      "description": "Signed ALLOW/WARN/BLOCK on installing a package@version: OSV.dev malicious-corpus + typosquat distance + registry signals. Verify before you install.",
      "url": "https://x402.payperbyte.io/feeds/pkg-verdict",
      "method": "POST",
      "tags": [
        "general",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "sanctions-screen",
      "name": "Sanctions Screen Oracle",
      "description": "Know-Your-Agent (KYA) counterparty screening \u2014 sanctions pillar. Signed, version-pinned OFAC SDN + Consolidated screening on an address or name; every answer embeds the pinned list-state (date + sha256) it was judged against. Primary source: official U.S. Treasury Sanctions List Service exports incl. the digital-currency address annex, parsed and content-sha256-pinned first-party \u2014 not a resold vendor list. Scope: screens the counterparty you supply \u2014 not identity verification of the calling agent. Receipt deadline: this feed's EIP-712 receipt is minted with a 10-year freshness window (not the platform's usual 300s), by design \u2014 evidence-grade compliance records need to stay independently verifiable long after the screening decision itself has aged. This is a durability choice, not a licence to act on stale data: the receipt still proves only which key signed which exact bytes \u2014 it carries no signed observation time, so it never establishes WHEN the screening ran (an external existence-in-time anchor is what would), and never that the screening result is still current. Re-screen before relying on an old answer for a new decision.",
      "url": "https://x402.payperbyte.io/feeds/sanctions-screen",
      "method": "POST",
      "tags": [
        "legal",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "reasoning-verdict",
      "name": "Reasoning Verdict Oracle (local LLM)",
      "description": "Verify-before-act risk oracle: POST an action context (message, payload, proposal, payee, tool-call) and get a signed ALLOW/WARN/BLOCK/ABSTAIN verdict + 0-100 safe-to-proceed score + reasons from a LOCAL model (no data egress). The verdict carries an embedded EIP-712 PayloadAttestation \u2014 recompute keccak256(answer) and recover the signer before acting. Advisory: the receipt proves provenance/integrity, not correctness.",
      "url": "https://x402.payperbyte.io/feeds/reasoning-verdict",
      "method": "POST",
      "tags": [
        "general",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "merchant-screen",
      "name": "Merchant Screen Oracle",
      "description": "Know-Your-Agent (KYA) counterparty screening \u2014 merchant pillar. Pre-settlement merchant screen: signed ALLOW/WARN/BLOCK on a (domain, payTo, observed price) BEFORE an agent settles an x402 payment. ms-v1 ruleset over first-party signals measured at query time \u2014 RDAP domain age, live TLS handshake (cert age, issuer, SAN match), off-domain redirect probe, brand-similarity distance vs a committed known-brand corpus, and the merchant's own advertised x402 manifest price. Method disclosed per field; unmeasurable signals report unverified and only lower confidence. The verdict carries an embedded EIP-712 PayloadAttestation \u2014 recompute keccak256(answer) and recover the signer before acting. Trust boundary: the payTo and price are values you assert, not values we observe on your payment \u2014 the verdict is a point-in-time snapshot of the exact tuple you supplied, and it neither sees nor constrains the address you ultimately settle to. Before releasing funds compare answer.query against the 402 challenge you are about to pay (answer.query.address is lowercased \u2014 compare case-insensitively). The receipt proves provenance and integrity, not correctness. Every query is logged and retained: the domain, the payTo address and price you supplied, the verdict, and a summary of the signals behind it. Producing a verdict requires live outbound requests against the screened domain itself \u2014 the merchant may observe this traffic; screening is not covert.",
      "url": "https://x402.payperbyte.io/feeds/merchant-screen",
      "method": "POST",
      "tags": [
        "commerce",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "positioning-snapshot",
      "name": "Positioning Snapshot Oracle",
      "description": "Cross-venue perp positioning (funding + open interest) from Hyperliquid, dYdX v4, Aevo; raw fields, abstains honestly where a venue lacks data.",
      "url": "https://x402.payperbyte.io/feeds/positioning-snapshot",
      "method": "POST",
      "tags": [
        "financial",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "cctp-attestation-latency",
      "name": "CCTP Attestation Latency Oracle",
      "description": "Measured Circle CCTP v2 attestation latency, reported as separate Fast and Standard distributions \u2014 never blended, since the two settlement paths differ by roughly two orders of magnitude (~8s vs ~15-19min) and a single percentile would describe neither. Built from first-party polling of real burns on Base, Arbitrum, and Optimism: every figure is a BOUNDED observation (burn -> first poll that saw the attestation complete), never an exact measurement, and the bound width ships alongside every distribution. Percentiles are withheld below an 8-measured-sample floor per (chain, path) bucket \u2014 a p95 over a handful of samples is arithmetic, not evidence. Unclassifiable samples are excluded, never bucketed; empty is reported as no_data, never as a low latency. The embedded EIP-712 PayloadAttestation proves which key signed these exact answer bytes \u2014 recompute keccak256(answer) and recover the signer before acting \u2014 never a claim that the measured latency will hold for your own transfer.",
      "url": "https://x402.payperbyte.io/feeds/cctp-attestation-latency",
      "method": "POST",
      "tags": [
        "general",
        "x402",
        "usdc",
        "base"
      ]
    },
    {
      "id": "regime-signal",
      "name": "Receipt-Anchored Regime Signal",
      "description": "BTC/ETH regime classification (trend_up/trend_down/range/high_vol) and a realized-vol above/below call, horizon 4h or 24h. Every response is bound to a signed EIP-712 DeliveryReceipt anchored on Base via EAS; the scoring rule is published and deterministic against public Chainlink rounds, independently recomputable by anyone \u2014 see https://x402.payperbyte.io/methodology and https://x402.payperbyte.io/track-record \u2014 v1-baseline model: a deterministic persistence/threshold rule, not a trained model \u2014 see https://x402.payperbyte.io/methodology for the exact published formula.",
      "url": "https://x402.payperbyte.io/feeds/regime-signal",
      "method": "POST",
      "tags": [
        "financial",
        "x402",
        "usdc",
        "base"
      ]
    }
  ],
  "endpoints": {
    "catalog": "https://x402.payperbyte.io/feeds",
    "openapi": "https://x402.payperbyte.io/openapi.json",
    "x402": "https://x402.payperbyte.io/.well-known/x402.json",
    "mcp": "https://mcp.payperbyte.io/mcp"
  },
  "documentationUrl": "https://www.payperbyte.io/docs/quickstart"
}