Skip to main content

x402 RFP implementation evidence — 2026-08-16

This report records reproducible implementation evidence. It does not claim the excluded third-party Audit Bank deliverable.

Canonical exact settlement and native automatic cataloging

Command:
The runner imports the stock x402Client/x402HTTPClient from @x402/core@2.21.0 and ExactStellarScheme from @x402/stellar@2.21.0. It creates and Friendbot-funds a disposable payer, reads the native resource’s PAYMENT-REQUIRED, signs the canonical { transaction } payload, retries, decodes PAYMENT-RESPONSE, and then queries the Bazaar.
  • Network: stellar:testnet
  • Scheme: exact
  • Asset: native XLM SAC CDLZFC3SYJYDZT7K67VZ75HPJVIEUVNIXF47ZG2FB2RMQQVU2HHGCYSC
  • Sponsored fees advertised: true
  • HTTP result: 200
  • Transaction: ed9fa12d30ed28e5c478f9ee158e0eb7148069236504e06cfd55d718d95b2e34
  • Native Bazaar declaration present in the signed payment: true
  • Automatically cataloged after successful settlement: true
  • Resource: http://localhost:5001/examples/protocol-spec
This path uses paymentMiddleware plus declareDiscoveryExtension; it does not create or update an xWrapper.

Search evaluation

The checked-in judged corpus contains 10 natural-language queries and 12 HTTP/MCP resources. Run pnpm search:seed followed by pnpm search:evaluate against the live discovery service. These are local-loopback measurements and must not be represented as public-host latency. The corpus and evaluator are versioned so later production runs can be compared without changing judgments after seeing results.

Stellar upto

The upstream spec candidate is specs/schemes/upto/scheme_upto_stellar.md; the contract source is contracts/upto-settlement.

Verification transcript

  • API: 32 tests passed
  • SDK: 11 tests passed
  • Soroban contract: 2 tests passed
  • API, SDK, and web production builds passed
  • Live wire conformance check passed for stellar:testnet and stellar:pubnet
  • License gate: 193 production packages checked; 0 strong-copyleft; 0 uncertain
Publishing the upstream PR and hosted CI URL requires a valid GitHub credential. At report time, every account in local gh auth status had an expired token; no PR URL or GitHub CI run is fabricated here.