---
title: "The look — what this store holds about one x402 door"
description: "Send a URL. We knock once — the same single probe the free preflight makes, under the same limiter — and fold the answer with everything the signed chain already holds about that host: the rounds since we first met it, the tier with its fraction and its rows, the last probed round with its failed checks and the catalog's agreement, the passport decision, the shared-wallet fact. Two halves, kept apart: what the door said just now, and what we held before you asked. And one reproduction: the live probe against one signed row — the last probed row, or the week you name with 'since' — classed same, moved, instrument_moved, not_comparable or no_such_round by the rule at /criteria#result-class, the row cited by entry URL and digest. Free."
canonical: "https://scvd.store/api/look/v1"
url: "https://scvd.store/api/look/v1"
version: "v1"
method: "POST"
price: "free"
auth: "none"
---

# The look — what this store holds about one x402 door

Send a URL. We knock once — the same single probe the free preflight makes, under the same limiter — and fold the answer with everything the signed chain already holds about that host: the rounds since we first met it, the tier with its fraction and its rows, the last probed round with its failed checks and the catalog's agreement, the passport decision, the shared-wallet fact. Two halves, kept apart: what the door said just now, and what we held before you asked. And one reproduction: the live probe against one signed row — the last probed row, or the week you name with "since" — classed same, moved, instrument_moved, not_comparable or no_such_round by the rule at /criteria#result-class, the row cited by entry URL and digest. Free.

## How to call it

```
POST https://scvd.store/api/look/v1
Content-Type: application/json

{"url": "https://the-door-you-are-asking-about/..."}
```

Free, and no account exists to open. The whole procedure for every door
in this store is at https://scvd.store/auth.md.

## Request

- **`url`** — REQUIRED. The https x402 door you are asking about.

## The question it answers

Not 'is this door shaped right' alone — that is the preflight, and it rides inside this answer whole. Not 'what does the chain say' alone — that is the per-host history and the passport, and they ride inside too. This answers the question an agent holds with a URL in one hand and a wallet in the other: what does this store hold about this door, now and before now, in one call.

## Why it is not a score

Not a score, a rating, a rank, or a safety threshold. Two kinds of fact, kept apart: what the door answered to one probe just now, and what the signed chain already holds about the host, as counts with their denominators and the tier line with its fraction and rows. Whether that is enough to pay is the reader's decision; this store does not draw the line and sells nothing that would.

## What it cannot tell you

- Whether to pay. The reader draws that line; this store does not, and sells nothing that would.
- Whether the door delivers after payment. No probe and no history can; that is a fact about the world.
- Whether your own client will sign what the door serves — that is the payment dry run, free, named in next_steps.
- Anything about a host the chain never met, beyond that it never met it. Thin history is a fact about our coverage, not about the door, and the gaps are counted against us by reason.
- Anything newer than the hold on the held half: the chain's fold for a host is re-derived at most every 600 seconds, and the artifact says when it was taken.

## The ladder

- **`free_first`**
  - **`the_door`** — https://scvd.store/api/preflight/v2 — the live half on its own. Free.
  - **`the_history`** — https://scvd.store/corpus/host/{host}.json — the held half's rows. Free.
  - **`the_buyer`** — https://scvd.store/api/before-you-pay/v1 — will your client pay it. Free.
  - **`this_door`** — https://scvd.store/api/look/v1 — both halves in one call. Free. This tool.
- **`paid`**
  -
    - **`id`** — service_audit
    - **`name`** — The Once-Over
    - **`why`** — the live probe as a signed, dated artifact at its own URL, with the door's other surfaces read beside the 402
    - **`price`** — $5 fixed, one-off; nothing here charges again by itself, ever — there is no mechanism that could
    - **`price_usdc`** — 5
    - **`cadence`** — one_off
    - **`buy_url`** — https://scvd.store/api/buy/service_audit
  -
    - **`id`** — passport_refresh
    - **`name`** — The Refresh
    - **`why`** — a census look at this host now rather than Sunday, folded into the passport the same hour
    - **`price`** — $1 fixed, one-off; nothing here charges again by itself, ever — there is no mechanism that could
    - **`price_usdc`** — 1
    - **`cadence`** — one_off
    - **`buy_url`** — https://scvd.store/api/buy/passport_refresh

## Expected outcome

HTTP 200 and a report with a `now` half (the preflight verdict and the whole preflight), a `held` half (counts with their denominators, the tier line with its fraction and rows, the last probed round, the passport decision), and `now_against_held` stating same, changed, no_prior or not_comparable with both sides named. A host the chain never met comes back with never_met true and no tier read from nothing.

## Errors

-
  - **`code`** — url_missing
  - **`http`** — 400
  - **`means`** — no url was supplied, or the body was not JSON at all
  - **`what_to_do`** — POST {"url": "https://your-endpoint/..."} with Content-Type: application/json. Retrying the same body will fail identically.
-
  - **`code`** — url_unparseable
  - **`http`** — 400
  - **`means`** — the string supplied is not a URL
  - **`what_to_do`** — Fix the string. This is never a fact about the endpoint.
-
  - **`code`** — target_refused
  - **`http`** — 400
  - **`means`** — the URL is real but this store's published probe-target law refuses it: https only, default port, no credentials, and nothing private, loopback, link-local or reserved-internal
  - **`what_to_do`** — Name a public https URL on its default port. The refusal is a statement about US and never an observation about that host — we did not look.
-
  - **`code`** — own_host_refused
  - **`http`** — 400
  - **`means`** — the URL is this store's own hostname, which a Cloudflare Worker cannot fetch
  - **`what_to_do`** — Probe us from your side instead; our own 402s pass these checks in CI on every build and you should not take that on faith.
-
  - **`code`** — budget_spent
  - **`http`** — 429
  - **`means`** — the probe budget for this minute is spent — a cost bound on our side, never a fact about your endpoint
  - **`what_to_do`** — Read Retry-After (a whole minute) or the RateLimit fields beside it, and come back. Do not treat this as a verdict.

## Security

- **`what_this_does_in_your_name`** — One outbound GET to the URL you supplied — the same single unauthenticated probe the free preflight makes, metered on the same budget — and then a read of this store's own signed chain. NOTHING IS SIGNED for you, no wallet is touched, no payment is presented and no key of yours is asked for or could be given. Private, loopback and link-local addresses are refused before any request leaves, and so is this store's own hostname.
- **`what_it_stores_about_you`** — Nothing keyed to you. The chain's fold for the host you asked about is held briefly under the host's name so the next caller does not pay for the same fold; it holds nothing about who asked. The call is counted for rate limiting and for the store's published traffic tallies; there is no account, no cookie and no caller identifier.
- **`what_we_never_do`** — No account, cookie, caller identifier or IP-based budget. Budgets bound our cost, not caller rank. Requests are never sold, shared or published. The weekly census reads public discovery feeds, never these requests.
- **`standards`** — Disclosure is private-first and symmetric: notify the operator before publication, including our own defects. Corrections are dated and public. Signed artifacts verify offline against our published key.
- **`reporting`** — https://scvd.store/.well-known/security.txt for a vulnerability, https://scvd.store/corrections for something we got wrong.

## Our conflict of interest

This store sells signed observations of doors like the one you are asking about, so it has an interest in you wanting more than the free answer. That cuts against padding the free answer, not for it: everything the chain holds about a host is served here and at /corpus/host/{host}.json for nothing, and the paid rungs buy a signature and a fresh look, never a better verdict.
