Coinbase's x402 Bazaar is the closest thing the emerging paid-agent
internet has to a public catalog. Anyone shipping an HTTP endpoint
gated behind the
HTTP
402 x402 payment protocol can route responses through Coinbase's
CDP facilitator and end up auto-indexed at
api.cdp.coinbase.com/platform/v2/x402/discovery/resources.
The catalog is unauthenticated, paginated, and JSON — perfect for
empirical mapping.
So we mapped it. This post is a straight read of the whole catalog, with a specific focus on the corner we compete in: paid endpoints that sell ERC-8004 identity, agent reputation, on-chain-agent trust scoring, or agent directory data.
What is in the catalog
The full public Bazaar carries 15,342 paid endpoints
(as of 13 August 2026), spread across 1,418 unique
payTo addresses and
1,585 unique resource hosts. The top-volume hosts
by listed-endpoint count are a mix of tinkering hobbyists and
real commercial data providers:
| Host (as of 2026-08-13) | Listed endpoints |
|---|---|
api.delx.ai | 825 |
k2so.wrong.systems | 599 |
agent402.tools | 480 |
x402.orthogonal.com | 434 |
x402.forgemesh.io | 415 |
oracles-production.up.railway.app | 369 |
api.x402node.dev | 325 |
library.forgemesh.io | 317 |
x402.glassnode.com | 297 |
k2so-8080.on.ascii.dev | 278 |
Two of the top-fifteen hosts (x402.glassnode.com,
api.24klabs.ai) are commercial data
brands — the catalog is being used seriously by at least a handful
of paid data companies, not only hobbyists.
The ERC-8004 / agent-reputation corner
Keyword-scanning the description
and resource fields across the
catalog for erc-8004, erc8004, 8004, onchain agent, agent
reputation, agent intel, agent trust, agent directory, agent
discovery, onchainagent returns 66 hits. That
is the entire agent-intelligence corner of the paid-agent internet
as x402 Bazaar currently sees it.
Filtered down to endpoints that ship something close to what we sell (agent-reputation lookups, KYA / know-your-agent trust profiles, agent-directory records, cross-chain agent-readiness audits), the direct field looks like this:
| Vendor / endpoint (as of 2026-08-13) | Price (USDC) | 30d calls / payers | Networks |
|---|---|---|---|
trust-agent.io/v1/reputation | $0.002 | 2 / 1 | Base |
trust-agent.io/v1/verify/quick (OFAC + ERC-8004 rep) | $0.002 | 3 / 1 | Base |
trust-agent.io/v1/verify/deep | $0.01 | 2 / 1 | Base |
trust-agent.io/v1/verify/batch (10 addrs) | $0.01 | 2 / 1 | Base |
api.thetrustlayer.xyz/agent/base:{addr} | $0.001 | 3 / 2 | Base |
x402.devvizion.com/v0/agent-rep | $0.015 | 3 / 3 | Base |
graphadvocate.com/agent/score (0-100 rep composite incl. ERC-8004) | $0.02 | 2 / 1 | Base |
graphadvocate.com/onchain-x402/address | $0.01 | 1 / 1 | Base |
x402.asterpay.io/v1/agent/deep-analysis/batch (7-component KYA trust) | $0.01 | 9 / 5 | Base + Polygon + Arb + Op + Ethereum + Solana |
x402.asterpay.io/v2/x402/agent-readiness (well-known / MCP / agent.json scoring) | $0.02 | 3 / 3 | 6 chains |
api.insumermodel.com/v1/attest (signed 38-chain attestation) | $0.05 | 3 / 1 | Base |
api.insumermodel.com/v1/trust (signed wallet trust profile) | $0.15 | 1 / 1 | Base |
replenum.com/x402/attention/rank (agents ranked by economic confidence) | $0.015 | 3 / 1 | Base |
api.verifyproceed.com/v1/x402/guard (pre-execution safety verification) | $0.01 | 1 / 1 | Base |
Source: local scan of the full x402 Bazaar
/discovery/resources dump, filtered
by keyword. Prices and call counts are point-in-time snapshots as
of 13 August 2026 UTC.
Paid but unrated: joining x402 demand to ERC-8004 reputation
The obvious follow-up is whether the endpoints in the catalog
that do take paid calls also carry any on-chain
reputation. We ran the direct join: for every earning x402
endpoint on Base, does its pay_to
address equal the owner of any
registered ERC-8004 agent, and if yes, what reputation footprint
does that owner carry? Dated snapshot measurement as of the
2026-09-01 bazaar snapshot (fetched
2026-09-01T11:23:10Z); the numbers refresh when a future task
re-runs the join, not on the daily site build.
Sample: 14,338 x402 endpoints on Base with
quality.l30DaysUniquePayers ≥ 1
in that snapshot — endpoints that actually took at least one
paid call in the preceding 30 days. Of those,
1,291 (9.0%) resolve to a registered ERC-8004
agent owner by exact lowercased
pay_to → owner match,
9 have any reputation feedback event on the
receiving owner, and 0 satisfy the canonical
commerce_backed.py predicate
(feedback backed by a real ERC-8183 job outcome or an
allowlisted hook contract, not a bare thumbs-up).
The endpoint-level rate is a shape claim about publishers as
much as about endpoints, so the publisher-level cut is the more
honest one to read alongside it. Those 1,291 resolvable earning
endpoints collapse to just 26 distinct pay_to
addresses, and the distribution is extremely
head-heavy: on the full base-resolvable set (1,303 endpoints,
no earning filter) the top single publisher alone is
67.2% (875 of 1,303), and the top five cover
99.9%. Of those 26 matched publishers,
4 have any reputation summary row on Base —
and each of the four carries exactly one feedback event
(feedback_count=1,
unique_clients=1), i.e. not a rated publisher in any
meaningful sense. 0 of the 26 carry a
commerce-backed feedback row.
The zero has a specific operational explanation, not a fraud implication: all 44 commerce-backed ERC-8004 agents we track are Virtuals ACP registrants that record identity on-chain via ERC-8004 but publish their commerce through the ACP protocol, not as HTTP endpoints in the Coinbase x402 bazaar. The two rails don't overlap operationally yet, and that is what the join actually measures — the intersection is cleanly empty because the two sides don't currently meet on today's bazaar, not because the measurement missed something. The finding survives the standing 50-per-publisher dedup cap unchanged: capped, the resolvable set collapses from 1,303 → 369 (a 72% cut driven mostly by the 875 → 50 collapse of the top publisher), and the "with any reputation" and "commerce-backed" counts land at exactly the same 9 and 0.
Sample scope: these numbers are bounded to the 14,338 Base
endpoints in the 2026-09-01T11:23:10Z bazaar snapshot that took
≥1 paid call in the last 30 days; they do not describe ERC-8004
agents overall. Every matched fraction
is a lower bound
(is_lower_bound = True) —
pay_to may be a treasury
address distinct from the owner wallet used at registration,
and we index only the ERC-8004 registries on Base + Ethereum,
so publishers registered on other chains or under other
registries are invisible to the join. Full derivation,
predicates, and reproducibility recipe:
docs/evidence/0372-x402-demand-x-reputation-join.md
in the public repo.
Four things the data says
1. The market is not empty. It is nascent, but populated. There are at least five distinct vendors — trust-agent.io, thetrustlayer.xyz, graphadvocate.com, asterpay.io, and devvizion.com — shipping ERC-8004-adjacent reputation or KYA endpoints today. None of them is dominant. The category has a starting field but no incumbent.
2. Prices cluster an order of magnitude below what a commerce-grade answer is worth. Wallet or agent-reputation lookups in the catalog cluster at $0.001–$0.02. Deeper products (attestations, batch trust, compliance-grade profiles) reach $0.05–$0.15. That price band tells the reader what an agent will currently pay per lookup, not what the answer is worth if it is trustworthy — a Sybil-safe, commerce-backed reputation row is not the same object as a self-reported endorsement, and the gap widens with every fake feedback event that hits the ReputationRegistry.
3. Demand is trivial. Nobody has broken out yet. Almost every reputation / intel endpoint in the table above shows one to five paid calls and one to three unique payers over the preceding thirty days. Nobody in the reputation / intel category has crossed ten paid calls and five unique payers in a thirty-day window. The outliers in the wider catalog are utility feeds (gas price, BTC/USD, FX convert) priced at hobby rates — not agent intelligence. First-mover positioning is still available.
4. Multi-chain listing is a real amplification lever.
The Bazaar auto-index treats each
accepts[] entry as its own catalog
surface. x402.asterpay.io
publishes each product six times — once per chain (Base, Polygon,
Arbitrum, Optimism, Ethereum, Solana) — which turns one product
into six category hits. Anyone entering the field seriously will
want to copy that pattern.
Where we sit
We are not auto-indexed in Bazaar. That is a deliberate custody
choice, not an oversight. Our paid
/v1/intel/* endpoints run as a
self-facilitated x402 flow: payments are settled directly
to our Safe on Base with our own facilitator, rather than routed
through the CDP facilitator that Bazaar's auto-index anchors on.
The trade-off is exactly one thing: we give up automatic Bazaar
listing in exchange for keeping payTo on a Safe we control.
The empirical check for this is straightforward. Zero catalog
entries reference our Safe
(0xaCd134d2AAd0b868EDb395F7d151864188caaF1a)
as any accepts[].payTo. Zero
catalog entries carry
onchainagentintel.io as a resource
host. Bazaar is a facilitator index, not a Web-scraped directory —
so our absence is the expected result of the custody choice, and
the raw catalog dump is the receipt.
What we ship instead is a live index of every ERC-8004 agent we can see on Base and Ethereum mainnet, with an on-chain commerce-backed cohort published as a first-class product:
| Measure (our live all-Ethereum index) | Value |
|---|---|
| ERC-8004 agents indexed (Base + Ethereum) | 25,741 |
| Live agents (endpoint 2xx AND capability declared) | 3,719 |
| Live rate — Base | 9% |
| Live rate — Ethereum mainnet | 56% |
| ReputationRegistry feedback events indexed | 277,710 |
| Commerce-backed agents (got-paid cohort) | 44 |
| Job-outcome feedback rows (T1 / T3 evidence) | 979 |
Live-source: /v1/public/stats.
Liveness itself has been continuously tracked since
2026-07-17.
The trust filter, not the registry dump
The through-line the series has been walking since Report 01 is the shape of the useful signal in ERC-8004: registered is the cheap bar; live is the medium bar; commerce-backed is the honest bar. The Bazaar catalog gives that same distinction its clearest picture yet. Anyone can publish a "reputation" endpoint for a fraction of a cent. Very few can, for any specific agent right now, on Base or Ethereum mainnet, publish a probe-verified liveness answer, a ReputationRegistry row that traces back to an ERC-8183 or Virtuals ACP job outcome, and the counterparties the paying wallet used to hire the agent. That is the layer this post is a map of the surrounding market for.
For any reader who wants to browse the got-paid cohort our index
publishes, the
/commerce-backed-agents
hub ranks it by on-chain job-outcome count. Every commerce-backed
agent has a free per-agent page with its job trail, live-endpoint
composition, and readiness bucket — the same signals a paid
/v1/intel/agent response is built
from.
Three commerce-backed agents you can inspect right now
Not one of the fourteen vendors in the Bazaar reputation table publishes a comparable per-agent trail. These pages are free:
- Lunara (Base) — one of the deepest job-outcome rows in the current commerce-backed cohort.
- Ethy AI (Base) — hosted ACP integration with an actively growing job trail.
- Capminal (Base) — another top-of-cohort commerce-backed profile.
The Ethereum-mainnet side of the same index is browsable from the
Ethereum chain brief, and every
Ethereum-mainnet ERC-8004 agent has a matching free teaser under
/app/agent/ethereum/{id}.
Method note
Everything above is a straight read of Coinbase's public
/platform/v2/x402/discovery/resources
endpoint on 13 August 2026 UTC. All 15,342 catalog items were
downloaded (paginated at limit=1000,
no API key, no funds moved, no writes) and scanned locally. The
server-side query parameters
(payTo,
recipient,
merchant) are ignored by the public
catalog route, so merchant absence was verified by grepping the
full downloaded dump — a stronger check than a server-side filter.
Vendor prices and 30-day call counts are read from each catalog
entry's accepts[] and
metrics fields on the same date.
Reproducible: the catalog is public, our numbers should match any
other reader's scan on the same day up to catalog churn.