tools · Listed · eip155:8453 · Found · 187 endpoints · Gateway-eligible
api.zfinia.com
api.zfinia.com
Compare caller-supplied source and target field definitions for deterministic structural compatibility; no data is fetched or executed.
Indexed from this operator's public /.well-known/x402.json. Found is not operator-owned and is not attested. Claim or opt out.
Agent Read · Cleared Index
ROUTE
Route when you need tools at published x402 prices.
confidence
78%
source
signal
Index before you pay. Same payload for agents:
GET /api/cleared/agent-read?slug=cat-api-zfinia-com
When to call
- Need tools via x402 and want Cleared-indexed payTo with a live scorecard.
- Budget between $0.001 and $0.3 per call on published endpoints.
- Compare caller-supplied source and target field definitions for deterministic structural compatibility; no data is fetched or executed.
Risks
- Found — not operator-owned; claim status unknown.
- No Cleared settlement receipt on file yet.
- No Gateway traffic yet — market share unproven.
Price posture
Published 187 endpoints from $0.001 to $0.3.
Category · Gateway
tools · no Gateway routes yet — early / unproven on Cleared market share.
Endpoint hints
POST /x402/v1/data-compatibility-checkerCompare caller-supplied source and target flat field schemas before ingestion, migration, CI deployment or machine-to-machine handoff. Returns a deterministic J
POST /x402/v1/accessibility-contrast-calculatorCalculate WCAG 2.x sRGB contrast for one caller-supplied foreground/background pair of hex colours (#RRGGBB). Returns JSON with the contrast ratio and AA/AAA th
POST /x402/v1/catalog-offer-evidence-extractorExtract schema.org Product JSON-LD structured data from caller-supplied authorized public product-page HTML. Returns deterministic normalized Product/Offer JSON
POST /v1/intelligence/changes-sinceReturn curated machine-economy developments covering x402 and agent commerce after a supplied cursor or since value. This delta feed includes material additions
POST /x402/v1/merchant-contract-regression-reportCompare supplied baseline/current merchant API contracts for CI review. Returns a structured diff report with hashes, remediation, route/method checks, network/
POST /x402/v1/company-evidence-packCompany enrichment and KYB data for due diligence by domain: verify a counterparty, supplier or vendor before outreach, onboarding or payment. Returns firmograp
POST /x402/v1/x402-challenge-decodeDecode an x402 payment challenge before paying: give it the raw 402 body or payment-required header, as JSON or base64, and get back the version, resource, and
POST /x402/v1/x402-endpoint-preflightFind out what an x402 endpoint will charge before you pay it. Probes the endpoint, reads the challenge from the header or the body, and returns the decoded pric
Evidence (Cleared)
- → Intake verified · Gateway-eligible
- → Trust 70/100 · pass · tier listed
- → Protocol x402 · eip155:8453
- → Manifest reachable · schema valid
- → Found listing — indexed from public x402.json, not operator-attested.
Endpoints
endpoint-1
$0.003POST https://api.zfinia.com/x402/v1/data-compatibility-checkerCompare caller-supplied source and target flat field schemas before ingestion, migration, CI deployment or machine-to-machine handoff. Returns a deterministic JSON mismatch report with type incompatibilities, missing required fields, nullability warnings and remediation codes. Does not fetch data or validate nested schemas, data values or runtime API behaviour.
endpoint-2
$0.001POST https://api.zfinia.com/x402/v1/accessibility-contrast-calculatorCalculate WCAG 2.x sRGB contrast for one caller-supplied foreground/background pair of hex colours (#RRGGBB). Returns JSON with the contrast ratio and AA/AAA threshold booleans for normal or large text. Does not assess a whole interface, support alpha colours or certify accessibility.
endpoint-3
$0.1POST https://api.zfinia.com/x402/v1/catalog-offer-evidence-extractorExtract schema.org Product JSON-LD structured data from caller-supplied authorized public product-page HTML. Returns deterministic normalized Product/Offer JSON, including supplied price and currency when present, with source HTML and record SHA-256 hashes. Performs no URL fetching or browser execution; hashes do not prove authenticity and supplied prices may be stale.
endpoint-4
$0.01POST https://api.zfinia.com/v1/intelligence/changes-sinceReturn curated machine-economy developments covering x402 and agent commerce after a supplied cursor or since value. This delta feed includes material additions, corrections and retractions with provenance and nextCursor for caller-managed polling; an empty result is valid. No transaction feed, built-in scheduler, generic web search or exhaustive ecosystem monitoring.
endpoint-5
$0.05POST https://api.zfinia.com/x402/v1/merchant-contract-regression-reportCompare supplied baseline/current merchant API contracts for CI review. Returns a structured diff report with hashes, remediation, route/method checks, network/asset/payee policy checks, flat input/output compatibility and declared current price against the buyer maximum. No URL fetching, live or future-price guarantee, security audit or CI enforcement.
endpoint-6
$0.06POST https://api.zfinia.com/x402/v1/company-evidence-packCompany enrichment and KYB data for due diligence by domain: verify a counterparty, supplier or vendor before outreach, onboarding or payment. Returns firmographics (legal name, LEI, SEC CIK, industry, HQ, founded, employees), domain intelligence (age, email provider, SPF/DMARC), public role emails, socials, plus OFAC SDN and EU sanctions screening. Source-cited; unknowns null. Company data only, not personal contacts or compliance clearance. Unresolvable domains not charged.
endpoint-7
$0.002POST https://api.zfinia.com/x402/v1/x402-challenge-decodeDecode an x402 payment challenge before paying: give it the raw 402 body or payment-required header, as JSON or base64, and get back the version, resource, and every accepted payment normalised to scheme, network, asset, amount and payTo. Names what is wrong with named warnings — bad amount, unrecognised network, invalid payTo, unsupported scheme, missing input or output schema — and returns the declared Bazaar schemas. No network call, no payment sent.
endpoint-8
$0.004POST https://api.zfinia.com/x402/v1/x402-endpoint-preflightFind out what an x402 endpoint will charge before you pay it. Probes the endpoint, reads the challenge from the header or the body, and returns the decoded price, network, asset and payTo plus the declared input and output schemas. Never sends a payment. Only reviewed origins are reachable, and a redirect is refused rather than followed.
endpoint-9
$0.004POST https://api.zfinia.com/x402/v1/x402-endpoint-healthIs this paid endpoint answering right now? Returns whether it serves a payment challenge, how many well-formed priced offers it carries, which warnings would actually break a payment as opposed to merely making the call harder to construct, and a single payable_now flag. Reports only what was observed; it makes no judgement about the seller.
endpoint-10
$0.006POST https://api.zfinia.com/x402/v1/x402-metadata-driftDid this paid endpoint change its terms since you last looked? Give it a previous challenge as the baseline and it returns every difference: price changes with old and new amounts, offers added or removed, a protocol version change, and a payee_changed flag when a new recipient address appears. Never pays the endpoint.
endpoint-11
$0.004POST https://api.zfinia.com/x402/v1/base-network-snapshotIs Base ready to transact right now? One call returns the current block height, gas price in wei and how many seconds old the chain head is, all read at the same block. Refuses before payment if the endpoint is on the wrong chain or its head is stale, so you are never charged for a reading that is quietly out of date.
endpoint-12
$0.004POST https://api.zfinia.com/x402/v1/base-finality-snapshotHow settled is Base right now? Returns the latest and finalized block heights, how many confirmations the finalized head trails by, and both timestamps. Lets an agent decide whether a transaction is safe to treat as done, instead of guessing a confirmation count.
endpoint-13
$0.008POST https://api.zfinia.com/x402/v1/base-wallet-snapshotRead a Base wallet native ETH balance and up to five ERC20 token balances at one pinned block. Separate balance lookups each answer at whatever height they happened to see, so they cannot be compared; these are all read at the same block and the block is in the response. Replaces six calls with one.
endpoint-14
$0.006POST https://api.zfinia.com/x402/v1/base-token-metadataRead a Base token name, symbol, decimals and total supply in one call. Handles tokens that return a bytes32 name or symbol instead of a string, which is the case that breaks naive decoders. Fields the contract does not implement come back null and are listed, rather than guessed at. Refuses an address with no contract.
endpoint-15
$0.006POST https://api.zfinia.com/x402/v1/base-transaction-outcomeDid my Base transaction work and what did it cost? One call returns success or reverted, gas used, effective gas price, the fee in wei and in exact decimal ETH, confirmations behind the head, sender, recipient, value and log count. Pending and unknown hashes get a definite answer rather than an error.
endpoint-16
$0.004POST https://api.zfinia.com/x402/v1/base-nft-ownerWho owns this Base ERC721 token right now? Returns the current owner address at a pinned block. A token with no owner is refused before payment rather than returned as the zero address, which a caller could otherwise mistake for a real holder.
endpoint-17
$0.004POST https://api.zfinia.com/x402/v1/page-metadataFetch a reviewed public page and return its title, every meta and Open Graph tag, and the canonical URL. No JavaScript is executed and no script content is read. Returns the licence and creator for the content alongside it, so reuse terms travel with the result.
endpoint-18
$0.005POST https://api.zfinia.com/x402/v1/page-json-ldFetch a reviewed public page and return every JSON-LD structured-data block it declares, parsed. No script is executed. A block that is malformed is reported as a named warning rather than being silently dropped, so a caller can tell an empty page from a broken one.
endpoint-19
$0.006POST https://api.zfinia.com/x402/v1/page-tablesFetch a reviewed public page and return its HTML tables as arrays of rows and cells. Bounded to ten tables, fifty rows each and twenty cells per row, and every bound that is reached is named in the warnings so a truncated table is never mistaken for a short one.
endpoint-20
$0.004POST https://api.zfinia.com/x402/v1/page-linksFetch a reviewed public page and return its links with resolved absolute URLs and anchor text, the canonical URL, the declared meta robots directive, and how many links leave the host. Relative hrefs are resolved against the page, so a caller never has to guess a base.
endpoint-21
$0.004POST https://api.zfinia.com/x402/v1/page-fingerprintFetch a reviewed public page and return SHA-256 hashes of both the raw HTML and the visible text, with byte and character counts. Two hashes because they answer different questions: the HTML hash moves when anything at all changes, the text hash moves only when the content a reader would notice does.
endpoint-22
$0.006POST https://api.zfinia.com/x402/v1/page-markdownFetch a reviewed public page and return its readable content as Markdown, with headings and list structure preserved. Script, style and template content is removed, and nav and aside elements plus anything marked role="navigation" are excluded from the text. Returns the licence and creator, because this content is reusable only on those terms. Truncation at any bound is reported, never silent.
endpoint-23
$0.05POST https://api.zfinia.com/x402/v1/website-evidence-packEverything a reviewed public page declares, in one call and one fetch: title, meta and Open Graph, canonical, robots directive, JSON-LD with its schema.org types, resolved links with an external count, tables, content fingerprints, and readable Markdown. Replaces six separate extraction calls, and adds the cross-checks none of them can make alone — a canonical that disagrees with the URL you asked for, a page declaring noindex, missing structured data.
endpoint-24
$0.06POST https://api.zfinia.com/x402/v1/batch-page-fingerprintWatch up to ten reviewed public pages in one call. Supply the previous text hashes and it returns which pages actually changed, not ten hashes for you to compare. Hashes both the raw HTML and the visible text, so markup churn can be told from a real content change. A page that cannot be fetched is named individually and does not fail the batch.
endpoint-25
$0.025POST https://api.zfinia.com/x402/v1/x402-merchant-readiness-auditIs this merchant safe to depend on? Audits up to ten x402 endpoints in one call and returns a verdict — ready, partially ready or not ready — with the specific blockers. Checks each endpoint serves a payable challenge with well-formed terms and a declared input schema, and adds the cross-endpoint check no single probe can make: whether every endpoint pays the same recipient. Never pays anything.
endpoint-26
$0.12POST https://api.zfinia.com/x402/v1/tabular-contract-auditAudit your own delimited data against a contract you declare, and get one pass/fail plus the exact row and clause of every breach. Checks types, required values, enums, numeric bounds, lengths, patterns, uniqueness, composite primary keys, null-rate ceilings, header drift and encoding damage in one pass. A pass means the audit was complete and nothing broke, so a file beyond the bounds reports incomplete rather than passing. Nothing is fetched: you supply the rows.
endpoint-27
$0.2POST https://api.zfinia.com/x402/v1/dataset-reconciliationReconcile two datasets you supply and get one answer plus every disagreement. Reports keys present on only one side, keys duplicated on either side, whether the join is really 1:1 or silently N:M, and field-level differences with the row number on each side. Numbers compare exactly on their decimal text, never through floating point, so 42.50 and 42.5 agree while 9007199254740992 and 9007199254740993 do not. A repeated key is compared as an unordered multiset. Nothing is fetched.
endpoint-28
$0.08POST https://api.zfinia.com/x402/v1/json-contract-auditValidate a JSON document against a schema you supply and get the exact pointer and clause of every failure. Reports what it could not check as well as what failed, so a valid verdict always means every declared constraint was actually evaluated. Patterns run on a non-backtracking engine, and no reference is ever fetched.
endpoint-29
$0.15POST https://api.zfinia.com/x402/v1/json-schema-compatibilityDecide whether a schema change breaks your clients, and which ones. Classifies every change by the audience it breaks: producers construct the payload, consumers read it. Adding a required field breaks senders; adding an enum value breaks readers. A change it cannot classify is reported as unclassified and never counted as safe.
endpoint-30
$0.06POST https://api.zfinia.com/x402/v1/json-snapshot-diffCompare two JSON documents and get every change with its pointer, classified as added, removed, retyped or revalued. Object key order is not a change. Array order is, unless you say the arrays are unordered. Numbers compare exactly, so 42.50 and 42.5 are the same value and two adjacent large integers are not.
endpoint-31
$0.12POST https://api.zfinia.com/x402/v1/jsonl-contract-auditAudit a whole NDJSON batch against one schema in a single call. Returns the failing line number and pointer for every breach, the count of valid, invalid and unparseable lines, and the first failing line. A blank line between records is reported rather than skipped, because it is almost always a producer bug.
endpoint-32
$0.09POST https://api.zfinia.com/x402/v1/json-field-coverage-auditFind out which fields your real payloads actually populate. Across a batch of documents it reports, per location, how often it is present, how often it holds anything, and every type it appears as. A location that is a string in some documents and a number in others is named, which no schema check on a single payload would reveal.
endpoint-33
$0.18POST https://api.zfinia.com/x402/v1/json-object-reconciliationReconcile two sets of JSON records joined on pointers you nominate. Reports keys present on one side only, keys duplicated on either side, and every value disagreement with its key and pointer. Arrays inside records compare as multisets by default and numbers compare exactly, so reordered lists and reformatted amounts are not false findings.
endpoint-34
$0.12POST https://api.zfinia.com/x402/v1/api-response-contract-auditAudit an HTTP response you captured against a contract you declare: expected status or status class, required and forbidden headers, header value rules, and a body schema. Header names compare case-insensitively. You supply the response, so this works against an API behind authentication or on a private network.
endpoint-35
$0.1POST https://api.zfinia.com/x402/v1/json-structural-driftCompare a batch of documents against one reference document and report where the shape drifted: locations the reference has that the batch lacks, locations that changed type, and locations the batch added. Array indices are generalised, so a two-item list and a three-item list are the same shape. Useful when you have an example payload and no schema.
endpoint-36
$0.22POST https://api.zfinia.com/x402/v1/json-schema-migration-impactDecide whether a schema change is safe to ship, with evidence. Returns the compatibility verdict for your clients and, separately, how many of the real payloads you supply would newly be rejected, with the failing constraints ranked by how many payloads each costs. A breaking change nothing relies on is a different decision from one that rejects a tenth of your traffic.
endpoint-37
$0.25POST https://api.zfinia.com/x402/v1/openapi-breaking-change-auditDecide whether an API change breaks your clients, operation by operation. Compares parameters, request bodies, responses and security across two OpenAPI documents, and classifies each change by who it breaks: the clients that call the API or the clients that read its responses. A newly required parameter breaks callers; a widened response enum breaks readers. A change it cannot classify is never counted as safe.
endpoint-38
$0.1POST https://api.zfinia.com/x402/v1/openapi-endpoint-inventory-diffSee which operations were added, removed, deprecated or renamed between two OpenAPI documents. Flags a removal that was never preceded by a deprecation, an operationId change that renames the method in every generated client, and a duplicated operationId that no generator can resolve.
endpoint-39
$0.14POST https://api.zfinia.com/x402/v1/openapi-parameter-contract-auditAudit a real request against the OpenAPI document it should satisfy. Matches the operation the way a router would, checks every path, query and header parameter against its declared schema, validates the body against the declared media type, and reports whether the credential the declared security scheme expects is present. You supply the request, so this works against an API nothing external can reach.
endpoint-40
$0.14POST https://api.zfinia.com/x402/v1/openapi-response-conformance-auditAudit a real response against what the OpenAPI document promises for that operation. Resolves the declared status exactly, by range such as 2XX, or through default, checks declared response headers are present, and validates the body against the declared schema for its media type. Catches an implementation that has drifted from its own published contract.
endpoint-41
$0.12POST https://api.zfinia.com/x402/v1/openapi-auth-surface-diffSee how the declared authentication surface changed between two OpenAPI documents. Reports schemes added, removed or altered, scopes gained or lost, and the two cases a scheme comparison alone misses: an operation that now requires authentication where it required none, and an operation that no longer requires any. Reports what the documents say, not what the implementation enforces.
endpoint-42
$0.09POST https://api.zfinia.com/x402/v1/openapi-status-code-contract-driftSee how declared response statuses changed per operation, and which operations are missing the statuses you require. Reports statuses added and removed, operations declaring no 2xx response at all, and responses with no description. Useful when a client has exhaustive error handling that a silently added status will fall through.
endpoint-43
$0.1POST https://api.zfinia.com/x402/v1/openapi-required-parameter-driftSee which parameters and request bodies changed obligation between two OpenAPI documents. Separates tightening, where an existing caller now fails, from loosening, where a handler may now receive nothing it previously could not. A path parameter is treated as required whatever the document says, so moving one between optional and required is not reported as a change.
endpoint-44
$0.08POST https://api.zfinia.com/x402/v1/openapi-spec-quality-auditAudit one OpenAPI document for whether a client or documentation generator can actually work from it. Reports operations with no operationId or description, duplicated operationIds that no generator can resolve, parameters with no schema or no location, responses with no description, and security requirements naming a scheme the document never defines.
endpoint-45
$0.3POST https://api.zfinia.com/x402/v1/openapi-client-breakage-reportFind out what an API change breaks for one named client, rather than for everyone. You declare the operations it calls and, optionally, the response fields it reads and the parameters it sends. Changes outside that usage are counted and set aside. A breaking change on an operation this client never calls is somebody else’s problem, and blocking a migration on it is the mistake this product exists to prevent.
endpoint-46
$0.09POST https://api.zfinia.com/x402/v1/mcp-tool-name-collision-auditCheck whether several MCP servers can be mounted together. Reports tool names declared by more than one server, which is an ambiguity no prompt can resolve, and pairs of differently named tools whose words overlap enough that an agent will confuse them. Optionally enforces a server-name prefix convention.
endpoint-47
$0.1POST https://api.zfinia.com/x402/v1/mcp-tool-schema-auditAudit one MCP toolset for the defects that stop an agent calling it correctly: a missing or non-object inputSchema, an argument with no type or no description, a required argument the schema never declares, a duplicated tool name, contradictory annotation hints, and a tool whose name reads as state-changing while declaring no hints at all.
endpoint-48
$0.1POST https://api.zfinia.com/x402/v1/mcp-required-argument-driftSee which tool arguments changed obligation between two MCP manifests. Separates tightening, where every existing call now fails, from loosening, where a tool may be invoked without something it previously demanded. A newly required argument is the single change most likely to break an agent that was working yesterday.
endpoint-49
$0.12POST https://api.zfinia.com/x402/v1/mcp-toolset-diffSee which tools were added, removed or altered between two MCP manifests, and in what respect. Reports a changed description as a change in its own right, because the description is the text an agent reasons over when choosing a tool: editing it can change behaviour with no schema moving at all.
endpoint-50
$0.12POST https://api.zfinia.com/x402/v1/mcp-tool-input-coverage-auditFind out which tools and arguments your agent actually uses. From a transcript of recorded calls, reports which declared tools were never called, which declared arguments were never sent, which arguments always carry the same value, and any call to a tool the manifest does not declare. Nothing is executed.
endpoint-51
$0.12POST https://api.zfinia.com/x402/v1/mcp-capability-surface-diffSee how an MCP server’s advertised capability surface changed. Reports capabilities and features added or removed, and the shift in the aggregate annotation surface: how many tools declare themselves read-only, destructive, idempotent or open-world. That total governs what a client may let an agent do without asking a human.
endpoint-52
$0.14POST https://api.zfinia.com/x402/v1/mcp-tool-call-fixture-validationValidate a suite of recorded tool calls against the current MCP manifest and get the failing call index, tool and pointer for each breach. The regression gate for a team that keeps recorded calls as fixtures: after a server update, this says which fixtures no longer satisfy the tools they call. Nothing is executed.
endpoint-53
$0.18POST https://api.zfinia.com/x402/v1/mcp-agent-readiness-auditFind out whether an agent can actually choose correctly within a toolset. Reports pairs of tools whose words overlap enough to be confusable, descriptions too short or too empty to distinguish, undescribed arguments an agent must guess at, tools with so many arguments they are filled wrong, state-changing tools with no annotation hints, and the total size of the manifest, which occupies the model context on every turn.
endpoint-54
$0.22POST https://api.zfinia.com/x402/v1/mcp-breaking-change-reportDecide whether an MCP server update breaks its callers. Classifies each change by direction: an agent produces the tool call and consumes its result, so an input-schema change breaks callers while an output-schema change breaks whatever reads the result. Also reports a tool that stopped declaring readOnlyHint, which is a consent change no schema diff would surface.
endpoint-55
$0.11POST https://api.zfinia.com/x402/v1/event-idempotency-auditFind out whether a batch can be deduplicated. Reports events carrying no id at all, ids that repeat with an identical payload - a redelivery a consumer must be idempotent about - and, separately, ids that repeat with a different payload, which means the id is not identifying the event. Volatile fields such as a delivery timestamp can be excluded from the comparison without being excluded from the duplicate detection.
endpoint-56
$0.12POST https://api.zfinia.com/x402/v1/event-batch-contract-auditAudit a mixed batch of events, each against the schema for its own type. Reports the failing event index, type and pointer for every breach, events carrying no usable type, and event types with no schema supplied - because silently not validating a new type is how it reaches a consumer unchecked. Declared types nothing in the batch used are listed too.
endpoint-57
$0.12POST https://api.zfinia.com/x402/v1/event-version-drift-auditFind out how many versions of each event type are actually in flight. Reports a type arriving at more than one version in a single batch, which means every consumer must handle all of them at once, versions outside the set you support, and supported versions nothing produces - handling carried for nothing is still a cost.
endpoint-58
$0.12POST https://api.zfinia.com/x402/v1/telemetry-attribute-contract-auditAudit telemetry attributes against a contract, and against the thing a schema cannot see: cardinality. Reports missing required attributes, undeclared attributes, an attribute appearing as two types across the batch, and an attribute whose distinct values exceed your limit - because in a metrics backend each distinct value is a separate series, and that is how an index or a bill explodes.
endpoint-59
$0.13POST https://api.zfinia.com/x402/v1/event-sequence-integrity-auditFind gaps, duplicates and ordering violations in an event sequence, per stream. Partitioning matters: auditing a merged multi-stream batch as one sequence would report a gap at every interleave. Gaps are judged on sequence values and ordering on arrival order, because they are different questions. A non-integral sequence is reported as unchecked for contiguity rather than guessed at.
endpoint-60
$0.13POST https://api.zfinia.com/x402/v1/dead-letter-batch-auditTriage a dead letter queue. Groups entries by failure reason, names the dominant cause when one accounts for most of the queue, and separates retryable failures from permanent ones so you know whether replaying will work or fail again. Reports the same item failing more than once, and entries stating no reason at all, which cannot be triaged by anybody.
endpoint-61
$0.14POST https://api.zfinia.com/x402/v1/webhook-delivery-integrity-auditAudit a webhook delivery log. Reports events that never succeeded and whether they still have retries or have exhausted them and are lost, events delivered more than once so the receiver had to be idempotent, retries issued after a success, and attempts beyond the declared limit. No payload is inspected and no signature or secret is handled.
endpoint-62
$0.15POST https://api.zfinia.com/x402/v1/event-schema-compatibilityDecide whether an event schema registry change breaks anyone. Compares every event type across two registries and classifies each change by the audience it breaks. An event has one producer and many consumers, so both directions are assessed and the strict reading is the default: a consumer cannot be assumed to tolerate a new enum value. A removed event type is breaking for whoever subscribed to it.
endpoint-63
$0.09POST https://api.zfinia.com/x402/v1/env-diffCompare two sets of environment variables without revealing either side. Reports what was added, removed and changed, and describes each change by length and character classes rather than by value, so it is safe to run between staging and production. Flags a value that became empty, a value whose character classes changed, and a new variable shaped like a credential.
endpoint-64
$0.1POST https://api.zfinia.com/x402/v1/env-contract-auditAudit a set of environment variables against a contract, without returning any value. Reports required variables that are absent, and separately those present but empty - which suppresses a default where absence does not. Checks value shapes such as port, url or duration, flags undeclared and forbidden variables, and names any value shaped like a credential without printing it.
endpoint-65
$0.1POST https://api.zfinia.com/x402/v1/package-manifest-auditAudit a package manifest for what it leaves unpinned and undeclared. Reports a wildcard or latest specifier that accepts the next breaking release, a git or file specifier whose contents can change without the manifest changing, a version that is not an exact semantic version, missing engines, a dependency declared in both a runtime and a development group, and empty scripts.
endpoint-66
$0.12POST https://api.zfinia.com/x402/v1/ci-workflow-contract-auditAudit a CI workflow for what it leaves movable or undeclared. Reports actions pinned to a tag rather than a commit - a tag can be moved by whoever owns the action, so the code a step runs can change without this file changing - missing permissions and timeouts, a job depending on one that is not declared, a pull_request_target trigger, and an expression interpolated straight into a shell command.
endpoint-67
$0.13POST https://api.zfinia.com/x402/v1/container-compose-contract-auditAudit a Compose document against a contract. Reports an unpinned image tag, so the same file will produce a different container once the tag moves, a missing healthcheck or restart policy, a privileged or host-network service, added capabilities, host path mounts, a dependency on a service that is not declared, and an environment value written literally in the file rather than referencing a variable.
endpoint-68
$0.14POST https://api.zfinia.com/x402/v1/dependency-manifest-diffCompare two dependency manifests and classify each move. Below 1.0.0 the versioning convention promises no stability, so a 0.x minor change is treated as potentially breaking - flagging only major bumps would miss the change that breaks most often. A range changing is reported as a change of intent rather than a version moving, and a dependency moving between a development and a runtime group is reported because it changes what ships.
endpoint-69
$0.15POST https://api.zfinia.com/x402/v1/kubernetes-manifest-contract-auditAudit Kubernetes manifests against a contract. Reports a missing memory limit, where one container can take down the node it shares, a missing readiness probe, where traffic arrives before the container is ready, an unpinned image tag, a privileged container, added capabilities, a secret written literally into an env value rather than a valueFrom reference, and missing required labels. A CronJob’s nested pod template is read correctly rather than reported as having no containers.
endpoint-70
$0.16POST https://api.zfinia.com/x402/v1/sbom-component-diffCompare two software inventories and report what entered, left and moved. Reads CycloneDX components and SPDX packages, matching by package URL where both sides carry one because a bare name matches the wrong component across ecosystems. Reports version moves with breaking risk, a declared licence that changed, and a new component declaring no licence. A licence change is reported as a change in a declared field, not as a licensing conclusion.
endpoint-71
$0.18POST https://api.zfinia.com/x402/v1/lockfile-change-reportCompare two lockfiles and report what a manifest diff cannot see. Reports newly installed transitive packages, resolved version moves with breaking risk, a registry that changed, and the most serious finding available here: the same version with a different integrity hash, meaning the artifact behind a version that was supposed to be immutable is not the one that was there before.
endpoint-72
$0.2POST https://api.zfinia.com/x402/v1/terraform-plan-change-summarySummarise a Terraform plan and name everything it would destroy. A replacement is expressed as a create and a delete together, so reading only the first action would report a destroy and recreate as a plain create; replacements are classified as such. Counts changes by action and by resource type, and reports a destroy or replacement of any resource type or address you declare protected.
endpoint-73
$0.1POST https://api.zfinia.com/x402/v1/x402-payment-requirement-conformanceDecide whether a captured 402 challenge can actually be paid. Separates defects that stop a payment being constructed from ones that merely make the call harder to get right, and checks the resource is bound to the endpoint that served it - a challenge naming a different resource would, if paid, satisfy a requirement for something else. Also names the price spread when several payments are accepted. Nothing is fetched and nothing is paid.
endpoint-74
$0.11POST https://api.zfinia.com/x402/v1/x402-asset-network-compatibilityFind out whether your wallet configuration can satisfy a challenge, option by option. For each accepted payment it says usable or not and why: a network you are not configured for, an asset you do not hold, a scheme you have not implemented, or an amount above your ceiling. Names the cheapest usable option, because a buyer facing several will otherwise take the first one listed. Nothing is paid.
endpoint-75
$0.11POST https://api.zfinia.com/x402/v1/x402-version-compatibility-auditFind out which x402 versions you are actually dealing with across a set of sellers. Reports challenges declaring a version you do not support, challenges declaring no version at all - where how to read the rest is a guess - and a set spanning more than one version, which means your client must implement each of them at once. Nothing is paid.
endpoint-76
$0.12POST https://api.zfinia.com/x402/v1/x402-challenge-batch-auditAudit a whole set of captured 402 challenges in one call. Per challenge it reports whether a payment can be constructed, which blocking defects stand in the way, whether the resource is bound to the URL it came from, the cheapest accepted amount and the networks offered. A challenge supplied without its URL has its binding reported as unchecked rather than assumed sound. Nothing is paid.
endpoint-77
$0.12POST https://api.zfinia.com/x402/v1/x402-resource-binding-auditCheck that every challenge you captured names the endpoint that served it. A challenge naming a different resource would, if paid, satisfy a requirement for something else. A host mismatch is reported differently from a path mismatch, the first being the stronger signal. Also reports a non-https resource and, under version 2, a bare string resource, where a client reading resource.url gets undefined and stops checking the binding. Nothing is fetched and nothing is paid.
endpoint-78
$0.13POST https://api.zfinia.com/x402/v1/x402-price-drift-reportCompare two snapshots of captured challenges and report every price movement per resource. Amounts are compared as exact integers, so a large atomic amount is never collapsed by floating point. Reports a resource that was priced before and is absent after, a rise beyond a tolerance you set, and a new resource that appeared. Nothing is paid.
endpoint-79
$0.14POST https://api.zfinia.com/x402/v1/x402-payee-drift-reportCompare two snapshots of captured challenges and report every change of payee. A payee change is the most consequential thing a challenge can do, because paying the new one sends funds to a different recipient. Specifically flags a new payee sharing its first six and last four characters with the old one, which passes a human comparison and is a different account. Reports a change to confirm, never an accusation. Nothing is paid.
endpoint-80
$0.16POST https://api.zfinia.com/x402/v1/x402-catalogue-integrity-auditCheck that an advertised catalogue matches the challenges actually served. Reports a resource advertised and not served - a dead listing a buyer follows to nothing - and a resource served and not advertised, which nobody can discover. Compares advertised price, network, asset and payee against what the challenge really says, since a buyer budgeting from a listing budgets wrongly when they disagree. Nothing is paid.
endpoint-81
$0.18POST https://api.zfinia.com/x402/v1/x402-merchant-contract-auditAudit a merchant estate across all its endpoints at once. The findings that matter are the ones no single-challenge check can see: endpoints paying different addresses, sitting on different networks, or declaring different protocol versions. Also checks each challenge against a contract you declare - expected payee, network, asset, host and price ceiling. Nothing is fetched, so this works on a merchant you do not control.
endpoint-82
$0.22POST https://api.zfinia.com/x402/v1/x402-seller-migration-impactFind out what a seller’s change breaks for one specific buyer. You declare which resources you call and what your wallet supports; changes to anything else are counted and set aside, because blocking your own upgrade on somebody else’s change is the mistake this prevents. Reports a resource you use becoming unpayable by you, moving to an unsupported version, changing payee, or rising in price. Nothing is paid.
endpoint-83
$0.1POST https://api.zfinia.com/x402/v1/duplicate-key-auditFind duplicate keys in one dataset, exactly and nearly. An exact duplicate is reported with every row it occupies. A near duplicate is two different keys that become identical once case, spacing or punctuation is set aside, which a unique index accepts and which is almost always the same entity entered twice. Keys are canonicalised exactly, so 42 and 42.0 are one key.
endpoint-84
$0.12POST https://api.zfinia.com/x402/v1/mapping-contract-auditAudit a lookup table against its contract. The finding that matters most: one source mapping to several targets, because a lookup built from it is not a function and whichever row is read last wins. Also reports required sources that are unmapped, so anything carrying them falls through, targets outside the permitted set, and - when a one-to-one mapping is declared - a target reached from several sources.
endpoint-85
$0.12POST https://api.zfinia.com/x402/v1/key-coverage-auditFind out which keys every system holds and which only some do. Takes several datasets at once and returns a coverage histogram plus the keys present in only one and the keys partially covered, naming which datasets each is missing from. A pairwise comparison cannot express "present in three of five", which is the question when several systems are meant to hold the same population.
endpoint-86
$0.13POST https://api.zfinia.com/x402/v1/column-profile-driftCompare two vintages of the same dataset and report where each column drifted. Covers columns added, removed and reordered, null-rate movement beyond a tolerance, a dominant type that changed, cardinality that moved, and a range that widened - which means values outside what anything downstream was built for, whatever the distribution looks like.
endpoint-87
$0.14POST https://api.zfinia.com/x402/v1/referential-integrity-auditCheck that every reference in a child dataset resolves to a parent. Containment is one-directional, which is the difference from a reconciliation: a parent key nothing references is normal and is reported as a count, while a child key with no parent is a broken reference reported with every row carrying it. Also catches a duplicated parent key, which makes any reference to it ambiguous.
endpoint-88
$0.14POST https://api.zfinia.com/x402/v1/categorical-distribution-driftCompare the distribution of one categorical column between two datasets. Reports a category that appeared - which a consumer switching exhaustively on the column has no branch for - a category that vanished, and shares that moved beyond a tolerance. Shares are proportions of all rows including empty ones, so a rising empty rate is visible rather than hidden by renormalisation.
endpoint-89
$0.15POST https://api.zfinia.com/x402/v1/numeric-distribution-driftCompare numeric columns between two datasets on five order statistics: minimum, lower quartile, median, upper quartile and maximum. Quantiles are read off exactly sorted values, so a large or high-precision amount is never collapsed. Values that are not exactly comparable numbers are excluded and the exclusion is reported, because a silently narrowed sample makes every figure below it wrong.
endpoint-90
$0.16POST https://api.zfinia.com/x402/v1/dataset-overlap-auditCheck whether datasets that are meant to be disjoint share any keys. A key in both a training and an evaluation split means the evaluation is measuring memorisation, and every figure computed from it is optimistic. Reports overlap per pair with the share of the smaller set, since that is the one whose measurements are compromised, plus keys appearing in every dataset.
endpoint-91
$0.18POST https://api.zfinia.com/x402/v1/aggregate-reconciliationCheck that detail rows add up to the totals a summary declares, group by group. Sums are computed exactly on the decimal text, never through floating point: a float sum of 0.10 and 0.20 is 0.30000000000000004, so a tool built on one reports a false mismatch on the group that actually balances. Reports mismatches with the exact difference, groups with detail and no declared total, and totals with no detail at all.
endpoint-92
$0.2POST https://api.zfinia.com/x402/v1/slowly-changing-dimension-integrityCheck that a versioned dimension is temporally coherent, per key. Reports intervals that overlap, so a point-in-time lookup returns two rows; gaps, so it returns none; more than one live version; an interval ending before it starts; and a current flag that disagrees with its own interval. Intervals are treated as half-open, so a row ending exactly where the next begins is contiguous rather than overlapping.
endpoint-93
$0.16POST https://api.zfinia.com/x402/v1/csp-structural-auditParse one Content-Security-Policy and report its structure, with the fallback rules applied. A fetch directive absent while default-src is present is reported as covered; base-uri and frame-ancestors do not fall back, so absence there is a finding. unsafe-inline alongside a nonce is reported differently from unsafe-inline alone, since supporting browsers ignore it. A repeated directive is reported because only the first takes effect. Structure only, not an assessment of adequacy.
endpoint-94
$0.15POST https://api.zfinia.com/x402/v1/link-graph-auditBuild the internal link graph from a set of supplied pages and report its structure. Names pages with no inbound link, pages unreachable by following links from the declared entry points, internal links pointing outside the supplied set, and links that do not resolve at all. Fragments are stripped, since they identify a position rather than a page. Nothing is fetched, so a link to a page that exists and was not supplied is reported as not in the set rather than as broken.
endpoint-95
$0.14POST https://api.zfinia.com/x402/v1/html-evidence-packExtract one supplied HTML document into machine-readable evidence and cross-check it against itself. Returns title, metadata, canonical, robots directive, JSON-LD, resolved links, tables, readable text and content hashes. Reports a canonical that disagrees with the URL served, an Open Graph title that disagrees with the document title, a noindex directive, and absent title, description or structured data. Scripts are not executed and nothing is fetched.
endpoint-96
$0.13POST https://api.zfinia.com/x402/v1/sitemap-contract-auditAudit one supplied sitemap or sitemap index. Reports entries with no loc, locations that are not absolute URLs, locations on an unexpected host, duplicated locations with the entries they occupy, fragments, unescaped ampersands that make the document invalid XML, double-escaped ampersands that name a URL which does not exist, and lastmod values that either are not W3C datetimes or match the shape without being real dates. No URL is fetched.
endpoint-97
$0.13POST https://api.zfinia.com/x402/v1/structured-data-contract-auditAudit the JSON-LD a supplied page declares against a contract the caller states. Entities inside @graph and nested inside other entities are flattened first, because reading only the top level misses every entity a real page declares that way. Reports required types absent, required properties missing per entity, unmentioned types when unknown types are forbidden, entities with no @type, and blocks with no @context. Only JSON-LD is read, and that is stated rather than treated as conformant.
endpoint-98
$0.12POST https://api.zfinia.com/x402/v1/http-header-contract-auditAudit one set of response headers against a contract the caller states: headers that must be present, headers that must not be, and exact, prefix or substring rules on values. Also reports a header repeated with different values, where which one a client uses varies; an absent Content-Type, which forces a client to sniff; and a textual Content-Type with no charset. Optionally reports absent cache directives and no validator at all, which makes a conditional request impossible.
endpoint-99
$0.12POST https://api.zfinia.com/x402/v1/html-snapshot-diffCompare two supplied HTML snapshots and separate markup churn from a content change. Reports markup that changed while the readable content did not, which is a template or build change; the readable lines added and removed; and changes to the title, canonical, robots directive, meta values and declared structured-data types. Content is compared by line presence rather than position, so a reflowed paragraph is not reported as wholly rewritten. Nothing is fetched.
endpoint-100
$0.12POST https://api.zfinia.com/x402/v1/cookie-attribute-auditParse Set-Cookie headers and report their attributes. Names cookies with no Secure, no HttpOnly or no SameSite; SameSite=None without Secure, which browsers reject so the cookie is never set at all; an unrecognised SameSite value, where the default applies instead; a lifetime beyond a stated maximum; an unexpected Domain; and a Domain attribute at all, which widens a cookie to every subdomain. No cookie value is returned, only its length.
endpoint-101
$0.11POST https://api.zfinia.com/x402/v1/canonical-robots-consistency-auditAudit canonical and robots directives across a set of supplied pages together. Reports a canonical chain, where one page names another that names a third and crawlers do not follow reliably; pages consolidating onto a target that declares noindex; a page declaring noindex while naming itself canonical; an X-Robots-Tag header disagreeing with the markup, where which one wins is not under the page author control; a canonical crossing hosts; and pages with none at all. Nothing is fetched.
endpoint-102
$0.11POST https://api.zfinia.com/x402/v1/security-header-diffCompare a fixed list of ten security-relevant response headers across two releases and name the specific reverts. Reports a header removed, added or changed, and separately a reduced Strict-Transport-Security max-age, dropped includeSubDomains, a newly permitted unsafe-inline or unsafe-eval, and a Content-Security-Policy that moved from enforcing to report-only so it no longer blocks anything. Observable differences only, not an assessment of whether either configuration is adequate.
endpoint-103
$0.25POST https://api.zfinia.com/x402/v1/cross-format-record-crosscheckCompare one logical record declared in two or three of Avro, protobuf and GraphQL, and report where the representations disagree. Names are matched with case and underscores set aside, since snake_case and camelCase across these formats is convention rather than disagreement. Reports a field present in one format and not another, a type class mismatch, disagreeing optionality or repeatedness, and enum symbol sets that differ.
endpoint-104
$0.22POST https://api.zfinia.com/x402/v1/avro-schema-compatibilityDecide whether two Avro schemas are compatible, in both directions, under the resolution rules rather than by structural comparison. Backward is a reader on the new schema reading data already written with the old one; forward is a reader still on the old schema reading data written with the new one. Fields match by name with reader aliases consulted, int promotes to long, float and double one way only, and an enum symbol the reader lacks needs an enum default.
endpoint-105
$0.22POST https://api.zfinia.com/x402/v1/protobuf-schema-compatibilityDecide whether two .proto sources are compatible, treating the field number as the identity it is. Reports a number freed without a reserved entry, which arms a future field to reinterpret old bytes; a number taken from a reserved range; a wire type change, which stops old messages decoding; a same-wire-type change that alters the decoded value, such as signed to unsigned; a rename, which is wire-safe and breaks generated code; cardinality and oneof moves; and enum number changes.
endpoint-106
$0.22POST https://api.zfinia.com/x402/v1/graphql-schema-compatibilityDecide whether two GraphQL schemas are compatible, with every finding attributed to the audience it affects. Clients break on a removed field, a removed enum value that is returned, a new required argument, a non-null output turned nullable and a new required input field. Servers break on a new field to resolve, a new interface obligation and an output turned non-null. An enum removal is attributed by where the enum actually flows, computed from the roots.
endpoint-107
$0.2POST https://api.zfinia.com/x402/v1/graphql-client-impact-auditDecide which named consumers a GraphQL schema change affects. Each consumer declares the parts of the schema it depends on, as Type.field and Type.field(argument), and the response says per consumer whether it is affected and exactly which dependency broke. A declared dependency the previous schema does not define is reported as not compared, not as unaffected. A new required input field is reported once against the schema, since it affects every consumer sending that input.
endpoint-108
$0.18POST https://api.zfinia.com/x402/v1/avro-compatibility-mode-auditJudge a sequence of Avro schema versions against a named compatibility mode: BACKWARD, FORWARD or FULL, each with its transitive form, or NONE. A transitive mode compares every version against every earlier one; a per-step mode compares only the immediate predecessor, and the gap that leaves is stated rather than hidden. Every comparison performed is listed with its directional result, so a caller can see what was checked as well as the verdict.
endpoint-109
$0.16POST https://api.zfinia.com/x402/v1/graphql-audience-risk-auditReport which parts of one GraphQL schema can no longer change without breaking somebody. The central finding is an enum reachable as both an output and an input: adding a value breaks clients that switch on it and removing one breaks callers that send it, so there is no safe change in either direction. Also reports a deprecated non-null field, which cannot be removed until a separate release makes it nullable, and counts the fields already frozen by a non-null promise.
endpoint-110
$0.13POST https://api.zfinia.com/x402/v1/graphql-schema-auditAudit one GraphQL schema and separate what stops it building from what is legal and costs something. Reports a type implementing an interface without declaring its fields, a reference to an undefined type, a union member that is not an object type, an interface nothing implements, and an absent query root. Separately reports a nullable list item type, which forces every client to handle three outcomes, and a deprecation with no reason. Unreachable types are named as dead weight.
endpoint-111
$0.12POST https://api.zfinia.com/x402/v1/avro-schema-auditAudit one Avro schema for what it makes impossible later. Reports a field with no default, which cannot be removed without breaking readers; a nullable field with no default; a null default where null is not the first union branch, which is invalid; an enum with no default, which makes adding a symbol permanently breaking; an absent namespace on a top-level record; a logical type on a base the specification disallows; and a binary float on a monetary field name.
endpoint-112
$0.12POST https://api.zfinia.com/x402/v1/protobuf-schema-auditAudit one .proto source for what protobuf rejects and what it will cost later. Reports an absent syntax line, which silently means proto2; a required field, which can never be removed; an enum with no zero value, so an unset field has nothing to read as; a zero value named after a real state; a duplicate number; a number inside the implementation-reserved range; a non-permitted map key; and a repeated field above the one-byte tag boundary while low numbers are free.
endpoint-113
$0.22POST https://api.zfinia.com/x402/v1/kubernetes-manifest-diffCompare two sets of Kubernetes manifests and report what applying the second will actually do. Objects are matched the way an apply matches them, by apiVersion, kind, namespace and name. Reports a change to a field that is immutable for that kind, where an apply fails and the object must be deleted and recreated; a change under the pod template, which recreates every pod; a replica change; an object that is gone, which an apply does not delete; and a change that recreates nothing.
endpoint-114
$0.2POST https://api.zfinia.com/x402/v1/github-actions-workflow-auditAudit one GitHub Actions workflow against a contract the caller states. The finding that needs two parts of the file at once: a privileged trigger such as pull_request_target together with a checkout of the contributor ref, which runs untrusted code with the base repository secrets. Also reports an action pinned to a mutable tag, a secret or author-controlled event field interpolated into a run command, an absent permissions block, and the trigger key read as a boolean.
endpoint-115
$0.19POST https://api.zfinia.com/x402/v1/kubernetes-service-selector-auditMatch every Service selector in a set of Kubernetes manifests against the pod template labels of every workload in the same set. Reports a Service whose selector matches no supplied workload, which has no endpoints so every request to it fails to connect; a targetPort no matched container declares, which fails at connection time rather than at apply time; and a workload whose own selector does not match its own pod template, which the API server rejects.
endpoint-116
$0.18POST https://api.zfinia.com/x402/v1/kubernetes-resource-coherence-auditParse every Kubernetes resource quantity exactly and report the pairs that contradict themselves and the totals that exceed a quota. Reports a request above its own limit, which the API server accepts field by field and rejects as a pair; a memory value with a decimal SI suffix rather than the binary one; a memory value with no suffix, which is bytes; a CPU limit written with M rather than m; and requests across the set that exceed a supplied namespace quota.
endpoint-117
$0.17POST https://api.zfinia.com/x402/v1/github-actions-workflow-diffCompare two GitHub Actions workflow files and report what the change grants or removes. Permission scopes are ranked none, read and write, so a widening is reported and a narrowing is noted: only one of them grants something new. Also reports a privileged trigger added, a trigger removed, a permissions block removed so a default set elsewhere applies, an action moved from a commit to a mutable tag, an action version change, and a job removed so whatever it checked no longer runs.
endpoint-118
$0.16POST https://api.zfinia.com/x402/v1/kubernetes-manifest-auditAudit a set of Kubernetes manifests against a contract the caller states. Reports an image with no tag or the latest tag, which changes under you; absent resource requests or limits; absent readiness or liveness probes; a missing required label; hostNetwork, hostPID, a hostPath volume or a privileged container; and a credential-shaped environment variable set to a literal, whose value is never echoed. YAML parsing surprises are reported rather than inherited.
endpoint-119
$0.16POST https://api.zfinia.com/x402/v1/helm-values-contract-auditAudit a Helm values file against a contract the caller states, and optionally against a second environment. Reports a required path absent or null, so the chart renders with its own default instead; a value whose type is not what was declared, naming the YAML cause where there is one; a value outside a permitted set; a path the contract does not mention, which Helm ignores silently so a typo never surfaces; and a path stated in one environment and not the other.
endpoint-120
$0.15POST https://api.zfinia.com/x402/v1/docker-compose-contract-auditAudit one Docker Compose file and resolve its internal references. Reports two services publishing the same host port, where only one can bind; a named volume or network mounted and never declared; a dependency on a service this file does not define; a depends_on with no condition, so Compose waits for the container to start rather than for the service to be ready; and a wait for a service with no healthcheck, which can never be satisfied.
endpoint-121
$0.14POST https://api.zfinia.com/x402/v1/dockerfile-layer-auditAudit one Dockerfile for what its layers will cost and what its build records. Line continuations are joined first, which is what makes the layer questions answerable at all. Reports a package index updated in a layer of its own, so a later install uses a cached index months stale; a dependency install after a copy of the whole context, so that layer rebuilds on every source change; a download piped into a shell; and a credential-shaped build variable, recorded in the image history.
endpoint-122
$0.12POST https://api.zfinia.com/x402/v1/yaml-document-auditReport what a YAML reader will do with the text supplied, as distinct from whether the data is correct. Reports a duplicate key, which most readers accept while silently keeping the last; an unquoted YAML 1.1 boolean word such as on, off, yes or no, which arrives as a boolean rather than text; a leading zero read as octal; and a two-part version read as a float, where a patch number would change the type. Anchors and merge keys are refused with the line.
endpoint-123
$0.25POST https://api.zfinia.com/x402/v1/terraform-plan-blast-radiusRead a Terraform plan and report what applying it destroys. Names each resource to be destroyed or replaced, and for a replacement the attribute the plan says forced it, which is what a caller changes to avoid it. Separates a destroy of a resource type that holds data, where re-applying does not bring it back, from a destroy of something stateless. The type patterns treated as holding data are published in the response and the caller can add to them.
endpoint-124
$0.24POST https://api.zfinia.com/x402/v1/iam-policy-evaluationDecide whether specific calls are permitted by a set of IAM policies, following IAM evaluation order: an explicit Deny wins over every Allow, and the absence of an Allow is a denial because there is no implicit allow. A request allowed or denied only under a Condition is reported as undetermined rather than decided, because the condition depends on a request context that is not supplied. A NotAction or NotResource statement is named as not evaluated rather than silently skipped.
endpoint-125
$0.2POST https://api.zfinia.com/x402/v1/iam-policy-structural-auditAudit one IAM policy and report what widens it. The findings that need the document read as a whole: a wildcard action together with a wildcard resource, which means more than either alone; a Deny whose resource patterns no Allow in the policy covers, so it constrains nothing it appears to; and NotAction or NotResource in an Allow, which defines the permitted set by exclusion so the policy widens whenever the cloud gains an action, without the document changing.
endpoint-126
$0.2POST https://api.zfinia.com/x402/v1/terraform-plan-policy-auditHold a Terraform plan to a contract the caller states: resource types forbidden or permitted, tags every resource must carry, actions that must not appear, a ceiling on destructive changes, and attribute values that must not be used. Tags are read from tags, tags_all or labels, because providers differ and reading only one would report a tagged resource as untagged. Which rules ran is published, so a contract that checked nothing is visible rather than reading as a pass.
endpoint-127
$0.19POST https://api.zfinia.com/x402/v1/iam-policy-diffCompare two IAM policies and report what the change grants or removes. The comparison is over action-and-resource pairs rather than over statements, so a refactor that splits one statement into three reports no change. A newly written pair already covered by a broader unconditioned pattern is noted rather than reported, since nothing new is granted. A removed Deny is reported as a widening even when no Allow changed, because a Deny overrides every Allow.
endpoint-128
$0.18POST https://api.zfinia.com/x402/v1/secret-shape-auditReport credential-shaped values in supplied configuration, by shape class and position, never by value. Recognises a PEM private key block, a JSON Web Token whose header actually decodes, documented key prefixes, a URL carrying a password, and a long run with the character mix of a generated key rather than of text. Also reports a field named like a credential whose value matches no listed shape. The shape classes are published in every response.
endpoint-129
$0.16POST https://api.zfinia.com/x402/v1/terraform-plan-drift-auditRead a Terraform plan expected to be empty and report why it is not. Drift and planned changes are reported separately, because Terraform records them separately and they answer different questions: one is what somebody changed outside the configuration, the other is what applying would do about it. Where before and after attributes are both present, the fields that actually moved are named rather than reporting the resource as generically drifted.
endpoint-130
$0.15POST https://api.zfinia.com/x402/v1/json-patch-safety-auditJudge an RFC 6902 patch against the document it will be applied to. The patch is applied to a copy as a sequence, so each operation is judged against the state it will actually see rather than against the original: a later operation targeting a path an earlier one removed is the defect class this exists for. Reports a missing target, which makes the whole patch fail; a remove, which has no inverse; a replace that changes type; a move into itself; and a path the caller marked protected.
endpoint-131
$0.14POST https://api.zfinia.com/x402/v1/resource-tag-contract-auditAudit a resource inventory against a tagging contract. The finding that spans the inventory: two tag keys differing only in case, which cloud APIs treat as different keys so every grouping and cost report splits silently across them. Also reports a required tag absent, an empty value that satisfies a presence check and carries no information, a value with surrounding whitespace that groups separately, a value outside a permitted set, and a value a declared pattern does not accept.
endpoint-132
$0.12POST https://api.zfinia.com/x402/v1/env-file-contract-auditAudit a .env file and compare it with an example. Reports a duplicate name, where loaders disagree over which wins; an unquoted value with a trailing comment or space, kept by some loaders and trimmed by others; an interpolation of a name the file does not define, which most loaders substitute as empty so the value is silently incomplete; a required name absent or empty; and a name present in one file and not the other. No value is ever returned.
endpoint-133
$0.22POST https://api.zfinia.com/x402/v1/error-budget-auditMeasure an error budget against real counts, with exact decimal arithmetic rather than floating point. Reports the budget exhausted or mostly consumed, the objective not met, and a burn rate per interval above the sustainable one. A budget that rounds to fewer than one event is reported as carrying no information, since any failure is then a breach. Intervals are sorted by start, so the order supplied does not change the answer.
endpoint-134
$0.22POST https://api.zfinia.com/x402/v1/trace-integrity-auditCheck whether a set of spans forms coherent traces. Reports a parent that is not in the data, so the trace renders as fragments rather than one tree; a trace with no root or several; a cyclic parent chain, which makes any walk loop; a span that ends before it starts; and a child whose times fall outside its parent, which is clock skew between hosts rather than a code defect and which every latency figure derived from the trace inherits.
endpoint-135
$0.2POST https://api.zfinia.com/x402/v1/slo-definition-auditJudge whether a service level objective can actually be observed, before any measurement exists. The central check: at the expected event volume, one failure may already exceed the whole budget, so the objective is met with zero failures and breached by one and measures nothing in between. Also reports a budget of fewer than ten events, where chance dominates service quality, and a burn-rate alert whose own window is longer than the time that burn takes to exhaust the budget.
endpoint-136
$0.19POST https://api.zfinia.com/x402/v1/log-schema-contract-auditAudit newline-delimited JSON logs against a contract, and across the whole set. The two findings that need every line at once: a field whose type varies between lines, so an index either rejects the minority or coerces them silently; and a message field with nearly as many distinct values as lines, which is interpolated rather than templated so nothing groups and cost scales with volume. Also reports absent required fields, a level differing only in case, and a timestamp with no offset.
endpoint-137
$0.18POST https://api.zfinia.com/x402/v1/pii-shape-auditReport personal-data shapes in structured logs, by field and class and never by value. A payment card is confirmed by the Luhn check and an account number by its own mod-97 checksum, so a match is a plausible real value rather than any digit run, which keeps an order number from being reported as a card. A date of birth needs a field named for one as well as a date. Each match reports its field, how many lines carry it and how many distinct values there are.
endpoint-138
$0.17POST https://api.zfinia.com/x402/v1/alert-rule-auditAudit a Prometheus rule file. Reports an alert with no for clause, which fires on a single evaluation so one scrape failure is a page; a duplicate alert name, which notifications and silences cannot distinguish; a missing routing label or runbook annotation; a rate applied to a gauge, where the result is a number with no meaning rather than a wrong one; and a reference to a metric that is not in a supplied list, where the rule never fires so it looks like coverage and is none.
endpoint-139
$0.16POST https://api.zfinia.com/x402/v1/span-attribute-contract-auditHold spans to an attribute convention the caller states, including per span kind. The finding that matters most: a span name embedding an identifier. The name is the aggregation key, so a name per call means every call is its own operation and no latency distribution exists for it; identifiers belong in attributes. Also reports a required attribute absent, an attribute the contract forbids, reported by key and never by value, and an unrecognised span kind.
endpoint-140
$0.15POST https://api.zfinia.com/x402/v1/on-call-coverage-auditCheck that an on-call rota covers a period with no gap. Coverage is the union of the shifts in a rotation, so a gap is reported only where no shift covers the moment at all, which no per-shift check can find. Also reports one person on two rotations at once, where a page to both reaches one person so the second rotation is not a second responder; a shift longer than a stated maximum; too little rest between shifts; and a time with no UTC offset, which leaves a gap at every handover.
endpoint-141
$0.14POST https://api.zfinia.com/x402/v1/metric-naming-contract-auditAudit metric names, types and label sets. The finding that needs the whole set: a metric appearing with different label sets, so a sum or average over it groups by whichever labels happen to be present, which is not the grouping anybody asked for. Also reports a counter without a total suffix, a gauge named like one, a sub-second unit where the convention is seconds, a label holding identifiers, which is unbounded cardinality by construction, and a label reserved for another metric type.
endpoint-142
$0.13POST https://api.zfinia.com/x402/v1/incident-timeline-auditDerive incident durations from a timeline and report what makes them unreliable. The finding that matters: a phase recorded before the phase that must precede it, which means a time was backfilled, so every duration derived from the pair is fiction. Also reports a time with no UTC offset, which during an incident means somebody wrote their own zone; a missing phase, so a duration cannot be derived; an unrecorded gap of an hour or more; and a derived duration beyond a target the caller states.
endpoint-143
$0.25POST https://api.zfinia.com/x402/v1/double-entry-ledger-auditCheck that journal entries balance, with exact decimal arithmetic. Reports an entry whose debits and credits differ, with the exact difference; a line carrying both a debit and a credit, which means two things to two readers; a negative debit, which is a credit written in a form that defeats every sign-based check downstream; a posting to an account outside a supplied chart; a repeated posting reference; and a posting into a period the caller says is closed.
endpoint-144
$0.24POST https://api.zfinia.com/x402/v1/bank-statement-reconciliationMatch bank statement lines against ledger lines. References are matched before amounts, because a reference is an identity and an amount is not: matching on amount first pairs two unrelated lines that happen to agree and reports the real pair as unmatched. A reference match with a disagreeing amount or date is reported with the exact difference rather than discarded. With both balances supplied, the statement is also checked for agreeing with itself.
endpoint-145
$0.22POST https://api.zfinia.com/x402/v1/invoice-arithmetic-auditRecompute an invoice exactly and report where it disagrees with itself. Quantity times unit price is an exact decimal product. Rounding happens only where the stated policy says: per line, or once on the whole invoice. Those give different totals, so the difference between the two policies is published rather than one being assumed correct. Also reports a figure with more decimal places than its currency has, and a discount larger than its line.
endpoint-146
$0.22POST https://api.zfinia.com/x402/v1/trial-balance-reconciliationDerive account balances from journal entries and compare them with a declared trial balance. Reports an account whose balances differ, with the exact difference; an account carrying a reported balance that nothing in the journal supports; an account with journal movement that appears in no reported figure; and a trial balance whose own debit and credit columns do not foot. Both a debit and credit pair and a single signed balance column are accepted, because exports are written both ways.
endpoint-147
$0.2POST https://api.zfinia.com/x402/v1/revenue-recognition-schedule-auditCheck that a revenue recognition schedule sums to its contract value exactly and covers its term with no gap or overlap. A cent either way means that amount is either never recognised or recognised without having been contracted, and both are reported with the exact figure. Periods are treated as inclusive day ranges, so the day after one ends is the day the next must begin, and a gap and an overlap are separate findings because they are opposite errors.
endpoint-148
$0.18POST https://api.zfinia.com/x402/v1/payment-allocation-auditCheck that payment allocations are arithmetically consistent with the invoices and payments they refer to. An over-allocated invoice and an over-allocated payment are reported separately because they are different events: money applied beyond what was owed, and money applied that was never received. Also reports an unallocated remainder, an allocation to a cancelled invoice, and a cross-currency allocation, which converts at a rate the data does not state.
endpoint-149
$0.18POST https://api.zfinia.com/x402/v1/tax-computation-auditCheck tax amounts against a rate schedule the caller supplies. When a declared amount disagrees, the other inclusivity formula is tried too: if that one gives the declared figure, the finding says the policy and the data disagree rather than that the arithmetic is wrong, which is a different correction. Also reports a code absent from the schedule, a line rate disagreeing with it, and an amount too precise for the currency. Not tax advice.
endpoint-150
$0.16POST https://api.zfinia.com/x402/v1/fx-conversion-consistency-auditCheck that converted amounts follow from the rates supplied. The converted figure is the exact product rounded once to the target currency minor unit under the stated mode, and a difference is reported with its exact size, because one unit is a rounding choice and a thousand is a wrong rate. Also reports two rates for one pair on one date, which means two sources.
endpoint-151
$0.16POST https://api.zfinia.com/x402/v1/accrual-cutoff-auditCompare each entry service date with its posting date against a period cutoff, and total what is in the wrong period. Reports work done before the cutoff and posted after it, which understates the period unless an accrual puts it back, and an amount posted inside the period for later service, which overstates it. An entry with no service date is reported as undeterminable rather than assumed to belong where it was posted.
endpoint-152
$0.14POST https://api.zfinia.com/x402/v1/currency-minor-unit-auditCheck that each amount can exist in the currency it names. Reports an amount needing more decimal places than its currency has, where a currency with no sub-unit cannot hold a fraction at all. Also reports an amount that arrived as a JSON number rather than a decimal string, since a binary double cannot hold most two-place decimals exactly, so the digits may already differ from what was written.
endpoint-153
$0.24POST https://api.zfinia.com/x402/v1/mail-authentication-coherence-auditRead an SPF record, a DMARC record and a set of DKIM selectors together, and report the combinations that defeat themselves. Every finding needs two or three records at once, which is why a single-record checker finds none of them: a reject policy with no usable selector, an enforcing policy over an SPF record ending in +all, strict alignment with subdomain senders, enforcement with no reporting address, and a subdomain policy that no sending path can satisfy.
endpoint-154
$0.2POST https://api.zfinia.com/x402/v1/spf-record-auditAudit an SPF record. Reports two or more records on one name, which is a permanent error so most receivers treat the domain as having no SPF at all; a lookup count at or beyond the limit of ten resolving mechanisms, beyond which the evaluation is a permanent error; a record ending in +all, which authorises every host on the internet; a record ending neutral with no all or redirect; a term after all, which is never evaluated; and an unrecognised term, which is itself a permanent error.
endpoint-155
$0.2POST https://api.zfinia.com/x402/v1/dns-zone-contract-auditAudit a DNS zone against the rules that make a zone illegal or make it quietly not work. Reports a CNAME at the apex, which is forbidden because the apex must also carry SOA and NS; a CNAME alongside any other record type; an MX, NS or CNAME pointing at a name that is itself a CNAME, whose failure is intermittent rather than total; a target inside the zone the zone does not define; a cyclic CNAME chain; TTLs that differ within one record set; and a record outside the zone.
endpoint-156
$0.2POST https://api.zfinia.com/x402/v1/email-header-authentication-auditRead the authentication headers a receiver added to one message. Headers are unfolded first, because a field continues on any line beginning with whitespace. Reports two From headers, where what is displayed and what is evaluated can differ, which is the shape of a spoof rather than a mistake; a lower Authentication-Results, which can have been written before the message arrived; a result from an untrusted server; and a DKIM or SPF domain that does not align with the From domain.
endpoint-157
$0.18POST https://api.zfinia.com/x402/v1/spf-include-budget-auditCompute the exact SPF lookup cost across a supplied include tree. The budget of ten resolving mechanisms is shared across the whole evaluation rather than per record, which is why a record with three includes can cost fourteen lookups and no single record looks wrong. Reports the total against the limit, the headroom left, a cycle in the include chain, and every include whose record was not supplied so the total is a floor.
endpoint-158
$0.18POST https://api.zfinia.com/x402/v1/dmarc-record-auditAudit a DMARC record. Reports an absent or unrecognised policy tag, which makes the whole record ignored; a pct below 100, where the policy applies to that share of failing mail and the rest is treated as none, so a rollout left part way is not the policy it appears to be; a subdomain policy weaker than the organisational one; a reporting address outside the domain, which needs an authorising record there or no reports arrive; and a tag DMARC does not define.
endpoint-159
$0.18POST https://api.zfinia.com/x402/v1/dkim-record-auditAudit DKIM selector records. The key length follows from the length of the encoded public key, so a short RSA key is readable from the record itself with no cryptography. Reports a key shorter than a stated minimum; a selector left in testing mode, which asks receivers to treat a failure as unsigned so it cannot contribute to DMARC alignment however correctly it signs; a revoked key, with its consequence; and a key type verifiers do not implement.
endpoint-160
$0.16POST https://api.zfinia.com/x402/v1/mta-sts-policy-auditAudit an MTA-STS policy against the MX hosts it is meant to authorise. Reports an MX host no pattern matches, which under enforce mode refuses every message to that host; testing or none mode, where nothing is enforced; a max_age under a day, where a receiver that cannot fetch the policy stops honouring it almost immediately; and a DNS record with no id, without which a cached policy is never refreshed.
endpoint-161
$0.16POST https://api.zfinia.com/x402/v1/dns-record-diffCompare two DNS zone snapshots and report what the change does. Losing the last record of a type at a name stops something resolving once caches expire, and losing one value out of several does not, so the two are separated. A value change at one name is reported as a change rather than as an unrelated removal and addition. A TTL change is reported for its own reason: the old TTL governs how long the old answer survives, so a new one does not take effect until the old has expired.
endpoint-162
$0.14POST https://api.zfinia.com/x402/v1/reverse-dns-consistency-auditCheck the address, reverse name and forward address triple that receivers actually evaluate. Reports an address with no reverse name, which many receivers refuse before the message body is sent; a reverse name that resolves to a different address, so forward confirmation fails, which is worse than having none because it looks configured; a provider-generated name; and a HELO that does not match the reverse name.
endpoint-163
$0.22POST https://api.zfinia.com/x402/v1/locale-placeholder-contract-auditCompare placeholder structure across locales. A placeholder missing from a translation renders blank in some frameworks and throws in others, so the same file is a cosmetic bug in one stack and a crash in the next. ICU braces, printf conversions and mustache pairs are all recognised. Also reports a placeholder no base string supplies, a positional count that differs, a syntax that differs between locales, and unindexed printf placeholders reordered by a translation, which the renderer ignores.
endpoint-164
$0.2POST https://api.zfinia.com/x402/v1/locale-plural-coverage-auditCheck that every plural message covers the categories its language actually uses. A language with six categories given two has no message at all for the other four, and the usual fallback is the key itself appearing in the interface. Both suffixed keys and ICU plural blocks are read. Also reports a declared category the language never selects, so the text is translated and never shown, and an ICU plural with no other branch, which the format requires. The category table is published.
endpoint-165
$0.18POST https://api.zfinia.com/x402/v1/locale-key-coverage-auditCompare keys across locales, separating the three states a single completeness figure hides. An absent key shows the base string, the key itself or nothing, depending on the loader. An empty value satisfies a completeness count and renders nothing, which is how a blank interface passes a translation report. A value identical to the base is either untranslated or a loan word, and nothing says which, so the ambiguity is stated. Also reports a key no base locale defines.
endpoint-166
$0.18POST https://api.zfinia.com/x402/v1/translation-memory-conflict-auditReport text reuse conflicts between a base locale and its translations, in both directions. One source string translated several ways makes the interface say the same thing in different words in different places. Several source strings translated identically removes a distinction the product makes in one language and not the other. Neither is visible key by key, which is why this is a property of a pair of files. Comparison folds case and trims whitespace by default.
endpoint-167
$0.17POST https://api.zfinia.com/x402/v1/locale-text-safety-auditRead the characters in a locale file rather than its structure. Reports a bidirectional control character, which is invisible in every editor and reorders everything after it including text nobody touched; a zero-width character, which still counts toward a length limit; text not in NFC form, which compares unequal to the same text typed differently; and markup appearing only in a translation, where the call site was written for plain text.
endpoint-168
$0.17POST https://api.zfinia.com/x402/v1/locale-file-diffCompare two versions of a base locale and report which translations went stale. A base string edited without its translations being edited leaves every locale confidently wrong, nothing in the translation file marks it, and the diff is the only place it is visible. Also reports a removed key, where anything still referencing it shows the key in the interface; translations still carrying a removed key; and, per locale, how many of the new keys are outstanding.
endpoint-169
$0.16POST https://api.zfinia.com/x402/v1/locale-key-usage-auditCompare a locale file with the keys the code actually references. Reports a key nothing references, which is translated on every release and shown never, and a referenced key the file does not define, which shows the key itself in the interface. A key built at run time cannot be found by any scan, so the caller declares its prefix and those keys are excluded with the exclusion recorded. The reference list is the caller’s, and nothing is scanned here.
endpoint-170
$0.14POST https://api.zfinia.com/x402/v1/locale-layout-risk-auditMeasure how much longer or shorter each translation is than its base string. A translation much longer than the base overflows or truncates in a layout built to the base length; one much shorter is usually content that did not make it across, and both are reported with the ratio. Length is counted in code points, so an emoji is not counted twice, and a short absolute difference is never reported however large the ratio.
endpoint-171
$0.13POST https://api.zfinia.com/x402/v1/locale-nesting-contract-auditAudit the key structure of a locale file against a contract the caller states. Reports a message that is also the prefix of another message, which a loader nesting on the separator cannot hold both of so it keeps one and drops the other; two keys differing only in case, which is two keys to the file and one to any case-insensitive platform; a doubled separator, which resolves to a different key than written; and whitespace in a key, which several loaders trim or reject.
endpoint-172
$0.28POST https://api.zfinia.com/x402/v1/sql-ddl-compatibilityCompare two SQL schema snapshots and report what would break a client written against the first. Separates reader breakage from writer breakage, because the same change breaks different people: a dropped column breaks whoever selects it, a new NOT NULL column with no default breaks every existing insert. Also reports narrowed and widened types, lost defaults, nullability flips, collation changes and added or removed uniqueness.
endpoint-173
$0.3POST https://api.zfinia.com/x402/v1/sql-migration-blast-radiusRead migration statements and report what each one touches and what it costs. Names the statements that rewrite a table, the ones that scan every row while holding a lock, the ones that discard data irreversibly, and the renames that break every client still deployed with the old name the instant they commit. Reports tables and columns touched so a reviewer can see the reach of a migration without reading every statement.
endpoint-174
$0.18POST https://api.zfinia.com/x402/v1/sql-constraint-coherence-auditFind constraints in one schema that contradict each other or can never be satisfied. Reports a NOT NULL column whose default is null, a column declared both NULL and NOT NULL, a CHECK whose numeric bounds no value can satisfy, a scale larger than its precision, a zero-length column, a generated column with a default that can never apply, a constraint naming a column the table does not declare, and a uniqueness requirement another one already implies.
endpoint-175
$0.2POST https://api.zfinia.com/x402/v1/sql-foreign-key-integrity-auditCheck every foreign key against the thing it points at. Reports a key whose target carries no primary key, unique constraint or unique index, so the key does not create at all; a referencing column from a different type family or wider than its target, so rows can never match; a collation mismatch that makes equality disagree with what the text looks like; and a key with no index on the referencing side, which turns every parent delete into a scan of the child.
endpoint-176
$0.16POST https://api.zfinia.com/x402/v1/sql-index-contract-auditReport indexes that cost writes and return nothing. Finds two indexes on exactly the same columns, a shorter index whose columns are a leading prefix of a longer one and which the longer already answers, and a second copy of the primary key. Also reports a unique index leading with a nullable column, which permits many null rows in most engines and therefore does not constrain what a caller may assume it does.
endpoint-177
$0.24POST https://api.zfinia.com/x402/v1/sql-migration-reversibility-auditCheck whether a down-migration actually reverses its up-migration. Matches each operation against its inverse on the same table and column, and reports what would be left in place after a rollback. Reports an up-migration that discards data, which no down-migration can restore without a backup, and a down-migration that drops or truncates something the up-migration never created, which would destroy unrelated data during a rollback.
endpoint-178
$0.22POST https://api.zfinia.com/x402/v1/jwks-document-auditAudit a JWKS document for the things that make key selection fail. Reports a kid missing from a multi-key set and a kid used twice, which both make resolution ambiguous; a declared algorithm the key type or curve cannot perform; an RSA modulus below a stated floor; an EC coordinate whose length does not match its declared curve; use and key_ops that disagree; and private key parameters present in a document meant to be published.
endpoint-179
$0.26POST https://api.zfinia.com/x402/v1/jwks-rotation-readinessCompare two JWKS documents across a rotation and report what would break. Reports a key withdrawn while the tokens it signed may still be in flight; a kid reused for different key material, where a relying party holding a cached document resolves the id and verifies against the wrong key, so the failure looks like a bad signature rather than a missing key; key material republished under a new id; and a rotation with no overlap at all, which breaks every outstanding token at once.
endpoint-180
$0.2POST https://api.zfinia.com/x402/v1/jwt-claim-contract-auditAudit a token's decoded header and claim set against the contract a relying party needs. Reports an unsigned or symmetric algorithm, a header naming the key it should be verified with, an absent expiry, a lifetime beyond a stated bound, timestamps that contradict each other, and a missing issuer or audience, where any service trusting the issuer accepts a token minted for a different one. Takes a decoded header and claims, never a token string.
endpoint-181
$0.24POST https://api.zfinia.com/x402/v1/oidc-provider-metadata-auditAudit an OpenID provider metadata document. Reports a missing field discovery requires; a plaintext or unparseable endpoint; an issuer with a trailing slash, which breaks exact-match comparison for every client configured without it; a jwks_uri on a different origin from the issuer; an unsafe algorithm offered, which a client may negotiate down to; the implicit flow, which returns a token through the browser URL; and the authorization code flow declared without PKCE S256.
endpoint-182
$0.3POST https://api.zfinia.com/x402/v1/oauth-client-registration-auditAudit an OAuth client registration. Reports a wildcard redirect URI, where any matching host receives authorization codes; a plaintext redirect outside loopback; a registered URI that carries its own redirect parameter, so a code can be forwarded off the client's origin while still matching; the implicit and password grants; a public client registering a grant that needs a secret; and a client secret committed into the registration document itself. No secret value is ever reported.
endpoint-183
$0.18POST https://api.zfinia.com/x402/v1/retry-policy-auditMultiply out a retry policy and report what its own numbers imply. Computes the worst-case duration and the amplification factor, then reports a budget that outlives the caller's timeout so later attempts run with nobody waiting; backoff with no jitter, where clients that failed together retry together; unbounded growth; retrying a 4xx that cannot become a success; retrying 429 while ignoring Retry-After; and retrying POST or PATCH with no idempotency key.
endpoint-184
$0.26POST https://api.zfinia.com/x402/v1/timeout-budget-coherence-auditWalk a call chain and report where its timeout budget stops making sense. Reports an inner hop whose timeout is not shorter than its caller's, so the caller abandons the request first and the inner work completes into nothing; a worst case beyond the client deadline; a hop with no timeout at all; and retries configured at more than one layer, which multiply rather than add — three hops retrying three times each is twenty-seven requests at the bottom for one at the top.
endpoint-185
$0.2POST https://api.zfinia.com/x402/v1/rate-limit-policy-auditAudit a published rate limit ladder for internal sense. Divides every tier down to requests per second so tiers with different windows can be compared, then reports a ladder that is not monotonic — a buyer paying more and getting less throughput — a burst larger than the window limit that can never be spent, a burst that shrinks as the tier rises, and an endpoint whose declared cost exceeds what the lowest tier permits in a whole window, so that subscriber cannot call it once.
endpoint-186
$0.24POST https://api.zfinia.com/x402/v1/pagination-contract-auditAudit a pagination contract for the ways it loses or repeats rows. The central finding is the one almost every paginated API has at first: a sort on a non-unique field with no unique tiebreaker, so rows that compare equal have no defined order and a caller walking the pages can get one row twice and never get its neighbour, with nothing failing. Also reports offset pagination over a mutable sort, an unbounded page size, contradictory bounds, and a cursor contract that also takes an offset.
endpoint-187
$0.16POST https://api.zfinia.com/x402/v1/circuit-breaker-policy-auditAudit a circuit breaker's thresholds against each other. The two findings worth money are a breaker that can never open, so it protects nothing, and one that can never close, so a recovered dependency stays cut off until the process restarts. Also reports a success threshold above the probe count, a sampling window shorter than one upstream timeout — so the timeout failure the breaker exists to catch is the one it cannot observe — a zero minimum sample, and a zero open duration.
Checks
reachable
valid
2026-10-09T15:01:20.601Z
No settlement evidence found in chain signals.
Gateway routing
Score ≥70/100 — Cleared attestation pass. Route via Gateway before pay.
Claim this listing to upgrade to Cleared attestation.
Claim listing