vokko.eu / report / x402.org
x402.org
Origin-owner checklist from missing spec fields. Not a login. Not a grade letter.
presence 2026-09-01T14:19:19.388Z · callability 2026-09-01T14:19:19.388Z · live re-run is €29/mo
7 items an origin owner can fix without completing checkout.
ucp · ucp.missing
No machine UCP profile at /.well-known/ucp.
Publish JSON with a YYYY-MM-DD version, services, capabilities, and payment_handlers.
x402 · x402.html
/.well-known/x402 is HTML, not a payment document.
Serve JSON with x402Version, or HTTP 402 with PAYMENT-REQUIRED (V2) / X-PAYMENT (V1). Do not put a marketing page on this path.
mpp · mpp.missing
No WWW-Authenticate: Payment challenge on the observed GETs.
If you speak MPP, challenge with WWW-Authenticate: Payment. There is no public /.well-known/mpp.
tap · tap.missing
No HTTP Message Signatures directory.
GET /.well-known/http-message-signatures-directory should return JSON 200 if you speak TAP.
mcp · mcp.missing
No MCP manifest JSON.
Publish /.well-known/mcp.json (or /.well-known/mcp) as JSON naming the server endpoint.
a2a · a2a.missing
No A2A agent card.
Publish /.well-known/agent-card.json (preferred) or /.well-known/agent.json with name and skills.
openapi · openapi.missing
No OpenAPI document at the usual paths.
Publish /openapi.json (or /.well-known/openapi.json) if you have an HTTP API.
Protocol matrix · GET /report/x402.org JSON · GET /api/v1/hosts/x402.org