We probe every service in the public x402 catalog, once an hour, from our own infrastructure, and have done since 2026-07-12. We never paid a service and no service paid us. Here is what the data says, as opposed to what the ecosystem says about itself. This is a living census rather than a snapshot: every number on this page recomputes each hour from current data.
As of 2026-09-17 10:47 UTC · 1,985 services rated · 67 days observed · rates and grades measured over the trailing 7 days · methodology and raw data are public.
The launch-day edition of this census (21 July 2026) is kept frozen at /state-of-x402/2026-07-21, so the figures quoted when it was published stay checkable.
The public catalog advertises 15,856 payable items across 2,084 hostnames, an average of about 7 listings per hostname. Much of that item count is many near-identical auto-generated routes from a few operators, so listings are a badly inflated way to size the ecosystem. (We measure the listing sprawl, not intent, and most probed services do return a valid 402.)
The receiver wallets show that fewer operators sit behind those hostnames than the counts suggest. The 1,985 rated services list 1,094 distinct primary receiver wallets (about 2,167 if you count every address they have rotated through). The gap is not facilitators pooling money for strangers: it is single operators running many endpoints. The most-used address collects for 89 hostnames that all belong to one project, and the pattern repeats down the list, with operators fanning a single settlement wallet across dozens of their own subdomains and platform deployments (Vercel, Railway, Fly). You can usually read the owner straight off the names.
We cannot cleanly convert wallets to operators (some services rotate receivers, some list several), so treat the wallet count as an approximation, not a census. But the direction is unambiguous: a distinct domain is not a distinct business, and much of the apparent breadth is one operator's suite of micro-APIs behind many names.
Three shrinking numbers: roughly 15,856 catalog listings, 2,084 hostnames, and on the order of 1,094 receiver wallets. Size x402 by wallets, not by rows.
Of the 1,985 services with enough evidence to rate, here is the grade distribution:
A 1661 · B 264 · C 42 · D 10 · F 8
A probed x402 endpoint is usually up and spec-compliant: 83% earn an A. But that is the surviving population. Separately, 9 domains in the catalog never returned a single valid payment challenge in the trailing 7 days, and 6 serve their content with a 200 and no payment challenge at all. A further 28 we cannot judge either way: every path they list is a URI template such as /v1/company/:number, so there is no address for us to test. That is a limit of the measurement, and we report it rather than scoring them badly for it. Reliability is not uniform either: 1,635 services answered every single probe, while 350 flapped in and out. Absence from a leaderboard, or a green badge on a good hour, is not the same as a dependable endpoint.
97% of services speak x402 v2, the current spec; the rest are still on v1. On price, 1,938 services demand what they advertise, but 41 persistently charge a live price that does not match their catalog price. And discovery is still thin: only 58% expose the /.well-known/x402 descriptor that is supposed to make them self-describing to agents.
The catalog reports a 30-day call-volume figure for each service. Its rank correlation with our independent quality score is about -0.01: weak. The busiest endpoints are not the best ones, which is exactly why volume is not an input to our score. For latency, the field's median handshake is 274 ms and the 90th percentile is 773 ms.
We indexed USDC settlement on Base and Solana for every receiver wallet a service lists. Over 30 days about $926,546 reached those wallets from all sources (counting each receiver wallet once), of which about $40,816 arrived in amounts that match the prices services advertise. Those are not competing numbers; they are two honest bounds. Receiver wallets are general-purpose and take in USDC from far more than x402, so the amount actually settled through x402 sits somewhere between a floor of roughly $40,816 and a ceiling of $926,546.
The lesson is not that volume is fake. It is that no single wallet total, ours or anyone else's, is a reliable measure of what a service transacts through x402. Treat every volume claim as a bound to verify, not a fact.
Everything above is the supply side: what exists and how it behaves. The demand side, who is actually paying, is its own study, but one number is worth stating here. Our on-chain index is dominated by a single relationship: one payer wallet sent one receiver wallet 2,258,300 USDC payments in 30 days, which is about 77% of every transfer we index. That is one client calling one endpoint roughly 0.9 times a second, not 2,258,300 independent decisions. And it dominates only the count: by value that pair is about 3% of the USDC we index, because each of its payments is a fraction of a cent. A payment count says nothing about what a service earns, and any ecosystem-wide payment total is meaningless until that pair is set aside.
With it removed, real demand looks broad but shallow: most paying wallets appear once, pay a single service, and do not come back, the shape of first-touch trials rather than agents doing sustained paid work. We size it properly in the demand study; for now, read any x402 volume figure, ours included, as an upper bound.
Honesty about our own limits. Today the grade measures the paid-request handshake: protocol validity (a spec-valid 402), latency (how fast it answers), and price integrity (whether what a service charges matches what it advertises), plus availability, our hourly probe-success rate. What it does not yet do is pay. We do not verify that a paid response returns correct or complete content. Availability, too, is a success rate from our own infrastructure, not a guarantee of uptime between probes. Where we can, we also cross-check from a second network path; in the most recent cross-check 9 services answered differently from that second vantage than from our prober, a reminder that any single viewpoint, including ours, is partial.
Scores and grades are opinions derived from a published method, and every number here traces to probes we ran. The full register is free to read and free for agents to query as typed JSON. Rated parties never pay us, and there is no way to buy a listing, a grade, or a removal. If you operate a service and think we got something wrong, every report card has a dispute link.
See the live register at x402register.com.