# Norravex x402 Endpoint Audit > A deterministic conformance and safety audit for public x402 HTTP 402 > responses, sold per report with no account, subscription, or API token. ## Paid resource - Endpoint: `POST https://norravex.com/api/x402/audit` - Price: US$0.10 per report - Payment: canonical USDC on Base - Scheme and network: `exact` on `eip155:8453` - Asset: `0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913` - Input limit: 32 KiB ## Inputs - URL mode: submit one public HTTPS endpoint URL. The audit performs one bounded GET after payment verification, pins public DNS, validates the TLS hostname, refuses redirects, and caps the response at 256 KiB. - Payload mode: submit a captured HTTP 402 status, allowlisted headers, body, and resource URL. This mode makes no outbound request. ## Output The paid JSON response contains a verdict, 0–100 score, normalized payment options, 16 ordered checks, actionable remediations, a deterministic SHA-256 fingerprint, and an audit timestamp. - Product page: https://norravex.com/x402-endpoint-audit.html - Synthetic example: https://norravex.com/x402-audit-example.json - OpenAPI 3.1: https://norravex.com/x402-audit-openapi.json - x402 discovery: https://norravex.com/.well-known/x402 - Service health: https://norravex.com/api/x402/health ## Limitations - The audit checks protocol conformance, not seller honesty, solvency, or fulfillment quality. - It performs no payment or contract simulation against the audited endpoint. - Facilitator compatibility is a point-in-time observation. - A passing report is not an endorsement. - Directory listings, metadata checks, probes, and unpaid requests are not customers, sales, revenue, or profit.