A protocol preflight lab for agent services

Ship your ASP
with confidence.

Catch endpoint, HTTP and x402 compatibility problems before your service reaches marketplace review.

Deterministic checks No login required No secrets requested Free A2MCP utility
probekit://scan/https://api.example.com/agents/search live
01Resolving endpoint_
02Checking HTTPS
03Calling service
04Inspecting HTTP 402
05Decoding PAYMENT-REQUIRED
06Validating X Layer fields
07Generating report
Live mini audit
Try:
Problem

One broken header can block a great service.

clientservice
Symptom

Endpoint mismatch

Your service works locally but is unreachable from the marketplace.

clientservice
Symptom

Payment challenge failure

HTTP 402 is returned, but the challenge cannot be decoded or validated.

clientservice
Symptom

Unclear remediation

You know the endpoint failed, but not which field needs to change.

How it works

Three steps between draft and marketplace.

01

Paste your endpoint

Provide a public HTTPS API and choose GET or POST.

02

Run the protocol scan

ProbeKit inspects connectivity, HTTP behavior, JSON and x402 structure.

03

Fix and rerun

Receive exact evidence and remediation for every failed check.

Protocol coverage

Sixteen deterministic checks. Zero guessing.

Connectivity
Public HTTPS
TLS-secured public endpoint.
Connectivity
Safe public hostname
Blocks private and local ranges.
Connectivity
Endpoint reachability
Network connectivity from a public probe.
HTTP
HTTP 200 behavior
Free endpoints return success.
x402
HTTP 402 behavior
Paid endpoints return a challenge.
HTTP
JSON response
Parseable JSON body.
x402
PAYMENT-REQUIRED
Challenge header present.
x402
Base64 decoding
Challenge decodes cleanly.
x402
x402 version
Protocol version declared.
x402
Resource metadata
Resource identifier present.
X Layer
X Layer network
Chain identifier is X Layer.
X Layer
Asset address
Well-formed ERC-20 asset.
X Layer
Recipient address
Valid recipient address.
X Layer
Amount
Numeric amount declared.
X Layer
Timeout
Sensible request timeout.
Connectivity
Response latency
Fast enough for review.
Example audit report

Every failure explains itself.

Audit complete
api.example.com
82
/ 100
Almost ready
8 passed2 warnings1 failed
Check

PAYMENT-REQUIRED header

The endpoint returned HTTP 402, but the payment challenge was not present in the expected header.

Recommended fix
Base64-encode the x402 v2 challenge and return it in the PAYMENT-REQUIRED response header.
Security

A scanner should never become an attack surface.

ProbeKit runs deterministic, read-only checks with strict egress hygiene. Nothing is stored, nothing is executed.

  • HTTPS-only requests
  • Private-network blocking
  • Redirect validation
  • Strict timeout
  • Response-size limits
  • No secret forwarding
  • No remote HTML execution
  • No authentication required
Built for agent services

Standardized. Machine-callable. Predictable.

ProbeKit is designed for standardized machine-callable services that take parameters and return clear results.

Data APIs
Software utilities
Research tools
Validation services
Paid x402 endpoints
Free A2MCP endpoints
FAQ

Straight answers.

Is ProbeKit an official OKX certification?+

No. ProbeKit is an independent technical preflight tool. Passing its checks does not guarantee marketplace approval.

Does ProbeKit make payments?+

The MVP validates x402 challenge structure but does not submit or settle payments.

Does it support free endpoints?+

Yes. Free endpoints that return their result directly with HTTP 200 can be audited.

Do I need an account?+

No account is required for the MVP.

Are my secrets required?+

No. Do not submit API keys, authorization headers or payment credentials.

NoteASP ProbeKit is an independent preflight tool. Passing these checks does not guarantee marketplace approval.

Find the failure before review does.

No login. No wallet. No secrets.