← nohumans.directory · state of the network

We paid 550 x402 endpoints. Here's what came back.

Census window 2026-08-16 to 2026-08-21 · published 2026-08-25 · figures marked live are recomputed from the database on request · machine-readable twin: JSON

Total cost: $5.40. We sent 1,333 real USDC payments to every payable endpoint in this index — unprompted, at our own cost, across the population rather than on request. Every purchase record is hash-chained and signed by our scout wallet (0x54E163e9B8eDDa194D83F46AdD921bfA5fc5f4E0), which announces itself with an X-Verified-By header on every request. Nothing here was sampled, requested by a seller, or done covertly.

1,301 endpoints purchased from · 676 delivered of 1,233 that required payment (54.8%) — live

What only a census can see

69 endpoints advertise a per-call price and answer for free. Roughly an eighth of the purchased set isn't wired to charge at all. Fine either way — but the listing and the wire disagree, and an agent budgeting for the listed price learns the truth only by paying.

52 endpoints settled our payment on-chain and then rejected the request (HTTP 400/422), usually over a required parameter documented nowhere. The money is gone; the agent has no recourse. Another 25 took payment and still answered 402; 16 answered 5xx; 8 returned 404 for a route they had just been paid for; 4 re-priced between quote and settlement. The full outcome table, one row per endpoint by latest attempt, is live at /stats — including the failures caused by our own client, named individually and subtracted from nothing.

Correction, 2026-08-27: “settled our payment on-chain” was unproven for nearly all of these rows, and a chain audit refutes it for most. The scout's non-200 path recorded that a signed payment authorization was attached; it never consulted the chain to see whether the seller settled it. Audited retroactively against Base (the query validated both directions: it finds every known delivered settlement at the same addresses, and its zeros are therefore real absences): of wave 5's 99 “paid”-then-400 calls, 96 never settled — they cost nothing; 3 are chain-confirmed settled, $0.0045 in total. Of the first census's 405 4xx attempt-rows across 164 listings, 241 are proven unsettled at payTo addresses that passed a positive control; 124 remain unknown (no control transaction available at the current address, reported as unknown rather than folded into either side); at most 34 rows — ≤$0.452 — may have genuinely settled, an upper bound that also absorbs settlements from delivered calls whose proof was missing at the time. Two are chain-confirmed. So the honest version of this finding: on a rejected request, most sellers decline the money — conditional settlement is largely how the network already behaves — and the real capital loss to this failure class, project-wide, is measured in tenths of a cent plus a bounded residue. The failure that remains fully real is the one this page now documents twice over: contracts were published in-band and buyers, ours first, did not read them.

One number that surprised us: zero

Not one of the 550 endpoints declares a machine-readable response schema. Delivery can be verified: something came back, parsed, matched the medium. Conformance — did the response match what the seller promised — cannot currently be verified for any endpoint on this network, by us or by anyone, because nothing is promised in checkable form. Sellers: declare a response_schema on your listing; you would be the first.

Correction, 2026-08-27: that zero measured our submission form, not the network. One unpaid request to every active listing (1,675 attempted, 1,639 collected), keeping the whole 402 challenge instead of extracting a price from it, found 82% (1,366) carry the extensions.bazaar block in the challenge body and/or the v2 payment-required header. Within that, 463 endpoints declare a genuine field-level response-body schema — for these, conformance is measurable today by anyone who reads the challenge — 1,119 provide a worked output example, 934 declare their parameters in some machine-readable shape (448 with required fields marked), 101 carry SDK envelope boilerplate only, and 36 hosts additionally serve schemas at /.well-known/x402. Figures amended the same day: the first derivation (live for about three hours: 64%, 227, 841, 460) read a corpus whose collector had truncated 27% of payment-required headers at 4KB and counted the cut-off challenges as declaring nothing; both corpora are retained. The uncomfortable part: our own scout parsed these exact challenges 1,333 times during the census and kept only the price. Method: single unpaid GET per endpoint on 2026-08-27; 36 errors not retried; 18 endpoints rate-limited us, so absence is unproven for those. Dated entry on /methodology; machine-readable figures in this report's JSON twin.

Three verification models now exist. They see different things.

x402-list verifies delivery on request, for a fee: rigorous, seller-initiated, and self-selecting — one service currently holds its verified badge. vet402 buys covertly at scale and publishes settlement (531 of 1,233 attempts at last reading): proof that money moved, silent so far on whether goods arrived. A census — paying everyone, uninvited — is the only shape that measures the failures nobody would volunteer for: the endpoints that don't charge, and the ones that take the money and refuse service. Each model covers blind spots the others have. The ecosystem is better for having all three; this page exists so the census data is citable next to theirs.

Addendum — wave 5, 2026-08-26

The census above covers 2026-08-16 to 2026-08-21. On 2026-08-26 we paid a second, deliberately different slice: 359 endpoints that had never actually been purchased from (no prior attempt carrying a settlement hash), priced at $0.005 or below, cheapest first. 171 paid calls, $0.41, 140 delivered.

The pass rate across all purchases fell from 69.0% to 61.5%. Read that carefully: the network did not get worse — we measured a part of it we had not measured before. The first census took the top of the catalog by reputation; this slice took the cheap, mostly newer tail, and it is markedly less reliable. 99 of these endpoints settled a payment and then rejected the request with a 400, usually naming the missing parameter in the error body — the same defect an operator fixed within a day of being told about it after the first census. Live totals, always current, are at /stats; the figures in the census above stay frozen at their stated window.

Correction to the 99, 2026-08-27, amended the same day: 97 of them had declared their parameters all along — 87 with fields marked required, 10 in a declared machine-readable shape without a required marker — inside the extensions.bazaar block of the very challenge we paid against. Our buyer read the price out of the challenge and nothing else. Only 2 of 99 carried no machine-readable declaration at all. (The first derivation, live for about three hours, said 46/53: our census collector had truncated 27% of payment-required headers at 4KB and counted the cut-off ones as declaring nothing — the same error shape as the original “zero declare”, one layer down, caught while preparing to name specific sellers on the strength of it.) All 11 vibesprings.net failures declared required parameters; the seller was told the same day. Settling payment before validating the request remains the sellers' half of this defect — a malformed call should cost the buyer nothing — but the contract was almost always published and almost never read, including by us. The scout now refuses to pay when a challenge declares required parameters the call omits (shipped 2026-08-27); listings graded failing on a 400 their own challenge explains will be regraded on the next wave. Declaration status measured 2026-08-27, one day after the wave.

What this does not establish

A delivered paid call proves that one call, at one moment, returned something. It does not prove the content was correct or fresh, and no behavior-based verification — ours or anyone's — can see who operates an endpoint today. Corrections: 9 endpoints originally graded as failures were re-graded delivered after on-chain confirmation (2026-08-21); the correction is visible in the outcome table rather than folded into totals. One withdrawn rate is documented at /stats.

Method & reuse

Basis: each endpoint's latest attempt, dry runs excluded. Full method: /methodology. Every figure as JSON: /v1/stats · this report's twin. License CC-BY-4.0 — reuse with attribution to nohumans.directory.

state of the network · methodology · stats · sellers · integrate · terms · privacy