{"specimen":true,"mark":"SPECIMEN","what_this_is":"A free, unsigned sample of the Once-Over — the $5 signed audit of one x402 endpoint at one moment. Every field below is the field a buyer gets, produced by the same check battery the paid artifact runs, against a constructed door that fails on purpose so the sample shows the instrument finding something rather than a column of ticks.","not_signed":"This sample is NOT signed and will NOT verify, and that is the difference between it and the thing it is a sample of. A purchased Once-Over carries an ed25519 signature over its own bytes plus the public key that checks it, and answers at /api/verify/{id} forever. This carries neither and answers nowhere. If you are ever handed one of these as evidence about anybody, the missing signature is your answer.","not_about_anyone":"The endpoint named here does not exist and cannot: .example is a reserved domain (RFC 2606) that never resolves. No request was made to produce this, no host was contacted, and nothing here is an observation about any real operator. The failures shown are constructed to demonstrate what the instrument reports when it finds something.","of_item":"service_audit","price_of_the_real_thing":"$5","buy_url":"https://scvd.store/api/buy/service_audit","sample":{"audit_id":"saudit_specimen_not_a_real_audit","url":"https://a-shop-that-sells-widgets.example/api/widget","observed_at":"2026-08-29T00:00:00.000Z","criteria":"preflight-v2: the published check battery documented at https://scvd.store/api/preflight/v2 (GET). The audit runs those checks and no others; the criteria page is the contract.","verdict":"not_ready","checks":[{"name":"status-402","ok":true,"detail":"answered 402 Payment Required"},{"name":"payment-required-header","ok":true,"detail":"PAYMENT-REQUIRED header present, base64 JSON parses"},{"name":"x402-version","ok":true,"detail":"x402Version is 2"},{"name":"accepts","ok":true,"detail":"1 accepts entry, each carrying scheme, network, amount, asset, payTo — the same fields this store's own till refuses to sign offers without"},{"name":"payto-payable","ok":true,"detail":"every accepts entry names a payable address for its own network"},{"name":"amount-atomic","ok":false,"detail":"accepts[0].amount \"0.01\" contains a decimal point — x402 amounts are ATOMIC units (USDC has 6 decimals), so a dollar-typed amount underprices by a factor of a million."},{"name":"network-mainnet","ok":true,"detail":"no accepts entry offers a known testnet"},{"name":"transfer-method-signable","ok":true,"detail":"every accepts entry that names an authorization standard names one a published client can build"}],"advisories":[{"name":"amount-not-atomic","detail":"accepts amount \"0.01\" contains a decimal point. x402 amounts are ATOMIC units (USDC has 6 decimals: $0.005 is \"5000\"). A dollar-typed amount here underprices by a factor of a million."},{"name":"missing-eip712-domain-extra","detail":"accepts entry on eip155:8453 carries no extra.name/extra.version. A standard EVM client builds its EIP-712 signing domain from that object; without it the client cannot sign, the refusal is silent on your side, and signability-filtered directories read your door as unknown."},{"name":"no-bazaar-extension","detail":"no extensions.bazaar block in the PAYMENT-REQUIRED header (the placement this check reads, because it is the one discovery ingesters read). Not a defect, and the rest of this sentence is inference rather than measurement: ingestion-based directories are documented as discovering services from this block, so without one we expect this endpoint to be findable mainly by buyers who already hold the URL. We do not run a directory ingester and have not watched one skip it. Falsified by this endpoint appearing in an ingestion-built directory with no bazaar block present."},{"name":"no-input-contract","detail":"the challenge declares no input contract (no extensions.bazaar.info.input). If this resource needs parameters, a buyer cannot discover that before paying — they sign, get refused for a missing field, and their logs record it as your endpoint failing. In the August 2026 field run this shape was the largest single cause of refused purchases at endpoints that were otherwise working. If the resource genuinely needs nothing, this advisory costs you nothing."},{"name":"signed-offers-not-in-challenge","detail":"no extensions['offer-receipt'] signed offers in the PAYMENT-REQUIRED header or the 402 body — both placements read, on the one path this probe walked. THAT IS WHAT WAS OBSERVED, and it does not distinguish three different things: a door that does not serve signed offers at all, a door that serves them somewhere this probe did not look, and a door that serves them here under a convention this battery does not recognize. Only the first is a fact about your endpoint; the other two are facts about our probe, and we will not publish them as yours. Signed offers are optional in the spec — where they are absent, a buyer has no pre-payment commitment to your terms that would survive a dispute. TO FALSIFY: serve them in the challenge at this path and re-run this check, which is free and needs no account; if you already serve them at another surface, that is the case this advisory cannot see and the corrections desk will record it."}],"also_under":{"battery":"preflight-v1","verdict":"ready","difference":"preflight-v2 folds the L3b consistency trio into the verdict; preflight-v1 reports the same observations as advisories. On this constructed probe the two batteries DISAGREED — which is the whole reason a purchased report carries both. On a REAL purchase the preflight-v2 reading also folds the Solana rail read; no network call was made to build this specimen, so that check is absent here and present there."},"surfaces":{"read_at":"2026-08-29T00:00:00.000Z","challenge_price":null,"no_challenge_price":"the challenge's amount on its first rail is not in atomic units, so it cannot be read as dollars without guessing","rows":[{"surface":"llms.txt","url":"https://a-shop-that-sells-widgets.example/llms.txt","state":"read","price_usdc":0.1,"detail":"names $0.1; the challenge's amount on its first rail is not in atomic units, so it cannot be read as dollars without guessing, so no comparison; the line read: Buy a widget: `GET /api/widget` ($0.10, one widget, signed)."},{"surface":"openapi","url":"https://a-shop-that-sells-widgets.example/openapi.json","state":"absent","detail":"no such surface: 404 at /openapi.json and /.well-known/openapi.json"},{"surface":"resource_url","url":"https://a-shop-that-sells-widgets.example/api/widget","state":"absent","detail":"the challenge names no resource URL other than the one knocked on, so there is no second door to compare"},{"surface":"402_bookend","url":"https://a-shop-that-sells-widgets.example/api/widget","state":"read","agrees":true,"detail":"the 402 read the same both times; the rows above compared against a price that held still"}],"named_a_price":0,"agree":0,"differ":0,"moving":false,"not_read":["mcp tools/list: no standard place a door declares an MCP endpoint, so none is attempted; a door that publishes one is not read as silent, it is not read at all"],"convention":"On llms.txt (the convention ruled 2026-09-02) a price is read only from a code span that holds the endpoint path with a dollar amount beside it, inside the span or in parentheses immediately after it — `GET /api/buy/thing` ($0.05) — and never from prose. On an OpenAPI document, from x-payment-info.price_usdc, the smallest of x-payment.price_usdc_options, or an x-price / x-price-usdc field on the path's operation.","what_this_is":"The door's other surfaces on the same origin, read once each after the battery and compared with the 402 the battery read. Four states per surface: read (names a price), silent (names none), absent (no such surface), unreadable (our read failed). Only a read row can disagree, and counts travel with their denominators — how many surfaces named a price, how many agreed — so the reader divides. The 402 is read again at the end; if it moved, nothing here counts against the door. Prose is never read for a number."},"scope":"One GET at one moment, against the published criteria named above, then two to four more GETs on the same origin for the surfaces section (llms.txt, the OpenAPI document, the challenge's resource URL, and the 402 read again), none of which move the verdict. This reports what the endpoint answered then: it is not an endorsement, not an uptime claim, and says nothing about whether anything is delivered after payment. An unreachable verdict is a fact about the network path between this store and that host at that moment — it does not prove the endpoint is down. Produced automatically; no human looked, and that is the point: a report commissioned by anyone reads the same."}}