{"audit":{"version":"1.5","generated_at":"2026-10-04T10:29:30.133293+00:00","generated_by":"Agenstry","report_url":"https://agenstry.com/agents/www.payperbyte.io","methodology_url":"https://agenstry.com/methodology","verifier_jwks_url":"https://agenstry.com/.well-known/jwks.json","subject":{"domain":"www.payperbyte.io","name":"PayPerByte","url":"https://www.payperbyte.io/.well-known/agent.json"}},"identity":{"provider":{"organization":"PayPerByte","url":"https://www.payperbyte.io"},"registry_verification":null,"signature":{"signed":false,"signature_valid":null}},"protocol":{"version":null,"supports_streaming":false,"supports_push_notifications":false},"operational":{"live_state":"endpoint_404","live_responds":false,"last_status_code":200,"last_elapsed_ms":522,"last_error":null},"track_record":{"first_seen":"2026-10-04T08:39:47.814340+00:00","last_checked":"2026-10-04T08:39:47.814340+00:00","last_seen_ok":"2026-10-04T08:39:47.814340+00:00","checks_total":1,"checks_ok":1,"uptime_pct":100.0,"uptime_window_days":30,"uptime_probes":1,"archived":false,"archived_reason":null},"conformance":{"score":30,"grade":"F","summary":"F-grade: card is reachable but fails most operational signals.","criteria":[{"key":"valid_card","label":"Valid AgentCard","points":10,"max_points":10,"status":"pass","detail":"Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification)."},{"key":"live_responds","label":"Live JSON-RPC","points":0,"max_points":25,"status":"fail","detail":"Card declares a URL but that URL returns 404."},{"key":"protocol_version","label":"Protocol version","points":0,"max_points":10,"status":"fail","detail":"No protocolVersion in card."},{"key":"signature","label":"JWS signature","points":0,"max_points":10,"status":"info","detail":"Card is unsigned (most published agents are)."},{"key":"uptime","label":"Uptime track record","points":0,"max_points":15,"status":"info","detail":"Only 1 probe so far, need ≥5 for an uptime grade."},{"key":"skills","label":"Skill declaration","points":10,"max_points":10,"status":"pass","detail":"Declares 12 skills with structured metadata."},{"key":"verified_identity","label":"Verified Identity","points":5,"max_points":10,"status":"partial","detail":"Provider declared: PayPerByte (https://www.payperbyte.io). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit."},{"key":"freshness","label":"Freshness + modern flags","points":5,"max_points":5,"status":"pass","detail":"declares 1 modern capability flag(s) (x402); seen in upstream source within 0d"},{"key":"security","label":"Security declaration","points":0,"max_points":5,"status":"info","detail":"Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated."}]},"card_read":{"findings":[],"clean":true,"source_url":"https://www.payperbyte.io/.well-known/agent.json"},"skills":[{"id":"weather","name":"Weather (US, multi-city)","description":"NWS weather forecasts for 5 US cities (NYC, LA, Chicago, Houston, Miami)","tags":["general","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/weather","method":"GET","signer":"0xa820763c023a929e83c59e4fd5a623e5a8efe941"},{"id":"earthquakes","name":"Earthquakes","description":"USGS recent earthquakes worldwide (M2.5+)","tags":["general","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/earthquakes","method":"GET","signer":"0xa1a55406de233901257aec7b499a26f040ba3cfa"},{"id":"runtime-eol","name":"Runtime EOL","description":"End-of-life dates and status for language runtimes, frameworks, OSes (endoflife.date)","tags":["general","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/runtime-eol","method":["GET","POST"],"signer":"0x17a67d0d18f9b93f064a23d2076074ea8802216f"},{"id":"threat-intel","name":"Security Advisories Digest","description":"Recent CVE highlights + CISA known-exploited-vulnerability entries, relayed from public sources (NVD, CISA KEV)","tags":["general","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/threat-intel","method":["GET","POST"],"signer":"0xb90b00f891dc534a5b59c60170661b868f3c26de"},{"id":"address-reputation","name":"Address Reputation Oracle","description":"Know-Your-Agent (KYA) counterparty screening — reputation pillar. Agentic-payments go/no-go verdict: synchronous signed ALLOW/WARN/BLOCK for (domain, receiving address, amount, chain) BEFORE releasing USDC. ar-v1 ruleset over RDAP/TLS/DNS/Wayback domain signals + on-chain receiving-address signals + curated known-bad blocklist. The verdict carries an embedded EIP-712 PayloadAttestation — recompute keccak256(answer) and recover the signer before acting. Scope: screens the counterparty tuple you supply — not identity verification of the calling agent.","tags":["commerce","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/address-reputation","method":"POST"},{"id":"pkg-verdict","name":"Package Verdict Oracle","description":"Signed ALLOW/WARN/BLOCK on installing a package@version: OSV.dev malicious-corpus + typosquat distance + registry signals. Verify before you install.","tags":["general","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/pkg-verdict","method":"POST"},{"id":"sanctions-screen","name":"Sanctions Screen Oracle","description":"Know-Your-Agent (KYA) counterparty screening — sanctions pillar. Signed, version-pinned OFAC SDN + Consolidated screening on an address or name; every answer embeds the pinned list-state (date + sha256) it was judged against. Primary source: official U.S. Treasury Sanctions List Service exports incl. the digital-currency address annex, parsed and content-sha256-pinned first-party — not a resold vendor list. Scope: screens the counterparty you supply — not identity verification of the calling agent. Receipt deadline: this feed's EIP-712 receipt is minted with a 10-year freshness window (not the platform's usual 300s), by design — evidence-grade compliance records need to stay independently verifiable long after the screening decision itself has aged. This is a durability choice, not a licence to act on stale data: the receipt still proves only which key signed which exact bytes — it carries no signed observation time, so it never establishes WHEN the screening ran (an external existence-in-time anchor is what would), and never that the screening result is still current. Re-screen before relying on an old answer for a new decision.","tags":["legal","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/sanctions-screen","method":"POST"},{"id":"reasoning-verdict","name":"Reasoning Verdict Oracle (local LLM)","description":"Verify-before-act risk oracle: POST an action context (message, payload, proposal, payee, tool-call) and get a signed ALLOW/WARN/BLOCK/ABSTAIN verdict + 0-100 safe-to-proceed score + reasons from a LOCAL model (no data egress). The verdict carries an embedded EIP-712 PayloadAttestation — recompute keccak256(answer) and recover the signer before acting. Advisory: the receipt proves provenance/integrity, not correctness.","tags":["general","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/reasoning-verdict","method":"POST"},{"id":"merchant-screen","name":"Merchant Screen Oracle","description":"Know-Your-Agent (KYA) counterparty screening — merchant pillar. Pre-settlement merchant screen: signed ALLOW/WARN/BLOCK on a (domain, payTo, observed price) BEFORE an agent settles an x402 payment. ms-v1 ruleset over first-party signals measured at query time — RDAP domain age, live TLS handshake (cert age, issuer, SAN match), off-domain redirect probe, brand-similarity distance vs a committed known-brand corpus, and the merchant's own advertised x402 manifest price. Method disclosed per field; unmeasurable signals report unverified and only lower confidence. The verdict carries an embedded EIP-712 PayloadAttestation — recompute keccak256(answer) and recover the signer before acting. Trust boundary: the payTo and price are values you assert, not values we observe on your payment — the verdict is a point-in-time snapshot of the exact tuple you supplied, and it neither sees nor constrains the address you ultimately settle to. Before releasing funds compare answer.query against the 402 challenge you are about to pay (answer.query.address is lowercased — compare case-insensitively). The receipt proves provenance and integrity, not correctness. Every query is logged and retained: the domain, the payTo address and price you supplied, the verdict, and a summary of the signals behind it. Producing a verdict requires live outbound requests against the screened domain itself — the merchant may observe this traffic; screening is not covert.","tags":["commerce","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/merchant-screen","method":"POST"},{"id":"positioning-snapshot","name":"Positioning Snapshot Oracle","description":"Cross-venue perp positioning (funding + open interest) from Hyperliquid, dYdX v4, Aevo; raw fields, abstains honestly where a venue lacks data.","tags":["financial","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/positioning-snapshot","method":"POST"},{"id":"cctp-attestation-latency","name":"CCTP Attestation Latency Oracle","description":"Measured Circle CCTP v2 attestation latency, reported as separate Fast and Standard distributions — never blended, since the two settlement paths differ by roughly two orders of magnitude (~8s vs ~15-19min) and a single percentile would describe neither. Built from first-party polling of real burns on Base, Arbitrum, and Optimism: every figure is a BOUNDED observation (burn -> first poll that saw the attestation complete), never an exact measurement, and the bound width ships alongside every distribution. Percentiles are withheld below an 8-measured-sample floor per (chain, path) bucket — a p95 over a handful of samples is arithmetic, not evidence. Unclassifiable samples are excluded, never bucketed; empty is reported as no_data, never as a low latency. The embedded EIP-712 PayloadAttestation proves which key signed these exact answer bytes — recompute keccak256(answer) and recover the signer before acting — never a claim that the measured latency will hold for your own transfer.","tags":["general","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/cctp-attestation-latency","method":"POST"},{"id":"regime-signal","name":"Receipt-Anchored Regime Signal","description":"BTC/ETH regime classification (trend_up/trend_down/range/high_vol) and a realized-vol above/below call, horizon 4h or 24h. Every response is bound to a signed EIP-712 DeliveryReceipt anchored on Base via EAS; the scoring rule is published and deterministic against public Chainlink rounds, independently recomputable by anyone — see https://x402.payperbyte.io/methodology and https://x402.payperbyte.io/track-record — v1-baseline model: a deterministic persistence/threshold rule, not a trained model — see https://x402.payperbyte.io/methodology for the exact published formula.","tags":["financial","x402","usdc","base"],"examples":[],"inputModes":[],"outputModes":[],"url":"https://x402.payperbyte.io/feeds/regime-signal","method":"POST"}],"provenance":[{"source":"smithery","first_seen":"2026-10-04T08:39:47.814340+00:00"}],"recent_probes":[{"fetched_at":"2026-10-04T08:39:47.814340+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":522,"live_responds":false}],"catalog_attestation":null,"operator_revenue_evidence":{"evidence_class":"operator_submitted","authenticity":{"rung":"no_operator_evidence","rank":0,"why":"No verifiable operator evidence has been submitted for this agent.","thresholds":{"min_independent_payers":3,"min_verified_usd":25.0},"engine_table":"agent_authenticity","merge_rule":"max(existing_rank, rank)"},"metric_metadata":{"provenance":"operator_submitted_evidence","confidence":"attested","coverage":{"numerator":0},"as_of":"2026-10-04T10:29:30.140359+00:00","definition":"Revenue proofs submitted by the verified owner and re-checked by Agenstry against the settlement chain or the operator's own Stripe account. Only independently confirmed proofs are counted."},"counts":{"retained":0,"verified":0,"unverifiable":0},"verified":{"gross_usd":0.0,"transactions":0,"independent_payers":0},"detail_url":"https://agenstry.com/api/agents/www.payperbyte.io/evidence","dispute_url":"https://agenstry.com/agents/www.payperbyte.io/dispute"},"verification_history":[],"signatures":[{"protected":"eyJhbGciOiJFUzI1NiIsImprdSI6Imh0dHBzOi8vYWdlbnN0cnkuY29tLy53ZWxsLWtub3duL2p3a3MuanNvbiIsImtpZCI6ImFnZW50ZmluZGVyLWVzMjU2LTEiLCJ0eXAiOiJKT1NFIn0","signature":"1Qf5hE-RJA8Duu4jgGqhUUenLmdRANllGZdSvt6HvDYnb2AuyRtL13_Y1Kt5j1xlB_ZQiSh0T205IB5jJkgqsg"}]}