PROOFRUN / LIVE BOUNDED PILOT

Check before
you say done.

Independent HTTP acceptance checks for coding agents. Send the tests your deployment must pass. Get observed results, including failures and what could not be verified.

0.01 USDC for up to 5 checks. Live bounded pilot on Base with x402. Enroll an authorized read-only target before paying. Failures and unverified checks are delivered results, not guaranteed passes.

What the pack checks

Each result includes observation time, actual status, response-body SHA-256, byte count and pass / fail / unverified. A failed acceptance test is a delivered result, not a reason to hide evidence.

One task, one report

{"checks":[
  {"id":"health","url":"https://your-deployment.example/health",
   "status":200,"json":[{"path":["ready"],"equals":true}]}
]}

x402 payment: Base native USDC. Keep your random read token, idempotency key and original payment header private. Replay returns the original report rather than a fresh observation. Retention: 7 days.

Safe target enrollment

First attest you own or are authorized to test the origin and that selected GET paths have no side effects. Then serve our random proof file at that HTTPS origin. Domain control is checked separately. Enrollment binds at most 5 exact paths for 24 hours.

No auth headers, query secrets, redirects or private-network targets. Only verified exact paths can be tested.

Start over HTTP or MCP

MCP: /mcp, Streamable HTTP. Tools: enroll_target, verify_target, verify_deployment. Payment signatures come from your wallet, never ours.

POST /v1/enrollments
Authorization: Bearer YOUR_RANDOM_PRIVATE_READ_TOKEN
{"origin":"https://your-deployment.example",
 "paths":["/health"],"owner_authorized":true,
 "read_only_paths":true}

Serve returned expected_file JSON at proof_url.
POST /v1/enrollments/ENROLLMENT_ID/verify
Authorization: Bearer SAME_PRIVATE_READ_TOKEN

POST /v1/checks
Authorization: Bearer SAME_PRIVATE_READ_TOKEN
X-ProofRun-Enrollment: ENROLLMENT_ID
Idempotency-Key: YOUR_UNIQUE_16_TO_64_CHAR_ID
Content-Type: application/json

Unsigned request returns 402 and PAYMENT-REQUIRED.
Review amount/network/recipient before wallet signing.
Repeat same request with PAYMENT-SIGNATURE from wallet.
Save original request/header; never create a new signature
when outcome is uncertain. Read GET /v1/reports/ID instead.

Pending proof expires in 10 minutes; verified enrollment in 24 hours. Requests may return 429 at pilot capacity. Report reads return the original observation, not a fresh test.

What this does not prove

No security certification, visual inspection, full application correctness, payment correctness or legal ownership judgment. Hashes identify observed bytes; they are not a notarized proof. Free curl and local tests may be enough for your task. Use hosted independent checks when that is the work you need.

OpenAPI · Machine catalog · Service health

Bounded pilot. No uptime SLA or customer demand claim. MCP endpoint available; directory indexing is not yet verified.