true402
terms of trade

What you agree
to by paying.

There is no signup, so there is no moment where you click accept. Sending a valid payment is the agreement, and this page is all of it. Every clause below describes what the running service actually does — you can verify each one against the API before you spend anything.

§01 · identity

Your wallet is the account.

No registration, no API key, no KYC, no email. We do not know who you are and do not try to find out. The address that signs a payment is the only identity in the system, and the only thing reputation attaches to.

It follows that we cannot recover, freeze, reassign, or refund on the strength of a claim about who you are. There is no support channel that can override the chain.

§02 · price

The quote is exact.

An unpaid request returns HTTP 402 carrying the price, the asset, the recipient and the network. Sign an authorization for exactly the quoted amount and retry with the PAYMENT-SIGNATURE header.

  • Underpayment is rejected — the request is not served.
  • Overpayment is refused with 402, never credited. Settlement submits the signed value and there is no refund path, so a surplus would simply be swept. Refusing is the only honest answer.
  • One authorization buys exactly one response. A replayed authorization is rejected, not double-charged.

Prices are published per endpoint and can change. The price that binds is the one in the 402 you were served; it is quoted for that resource and does not carry to another.

§03 · failure

You are charged on success only.

Settlement is submitted only when the endpoint returns a 2xx. If the service errors, times out, or is unconfigured, your signed authorization is never submitted — nothing moves on-chain, so there is nothing to refund.

Settlement happens after the response is sent, so it never delays your result. A settlement that fails on-chain is our loss, not your debt.

One case that rule does not cover, and it is the sharp one: a response that was produced but never reached you. If the endpoint returned a 2xx and the connection then failed — your client timed out, the socket dropped, a proxy gave up — settlement has already been submitted and your authorization is spent. From here the two are indistinguishable: we see the status our own handler returned, not whether the bytes arrived.

Retrying that same PAYMENT-SIGNATURE header returns 402 payment_replayed. Getting the answer means signing a new authorization, which is a second payment for one result. There is no idempotency key, no receipt to redeem, and no way to ask for that response again — we do not keep it, so there is nothing on this side to re-send. The gap is real, and we would rather write it down than let you find it.

The same mechanism has a favourable half. A call that fails before returning a 2xx gives the authorization back, so the same signed header can be retried while it is still valid instead of being burned on our failure. It is only the produced-but-undelivered case that costs you twice, and what bounds it is the price of one call. Set a generous client timeout, don’t hang up early, and store the response the moment it arrives.

§04 · free calls

A small daily allowance.

Some endpoints serve a few free calls per day per client IP, with no wallet. The per-operation description in the OpenAPI spec states which. It is a giveaway, not an entitlement: the quota, the eligible endpoints and the allowance itself can change or end at any time, and a 402 simply means this caller has spent theirs.

§05 · fair use

Limits, plainly.

  • 300 requests per minute per IP.
  • 1 MB request body, 30 s timeout.
  • Endpoints that fetch a URL you supply will not reach private, loopback or link-local addresses. Do not point them at infrastructure you do not own.

Automated use is the point — this service is built for agents. Traffic that degrades the service for others may be rate-limited or blocked.

§06 · what the answers are

Observation, not advice.

The on-chain endpoints report what was observed in the data available to them. That is a measurement, not a verdict, and it is not financial advice.

  • “None observed” never means “safe.” It means nothing was found in the range covered — which the answers state explicitly, so you can see the limits of what was checked.
  • A token or address can change behaviour after we look at it. Upgradeable contracts make this routine.
  • You decide what to do with an answer. Losses from acting on one are yours.
§07 · reuse

The answer is yours to resell.

A response you paid for is yours to keep and to use commercially. Cache it, store it as long as you like, put it in your own database, build a product on it, redistribute it, resell it. No attribution, no field-of-use restriction, no separate licence to sign, no per-seat anything. We do not claim ownership of what an endpoint returns you, and we will never come back to charge you again for a copy you already hold.

The limit is the obvious one: we can only grant what is ours to grant. Where an answer is assembled from a third-party source, that source’s terms are between you and them, and a third-party service you reach through the registry sets its own (§08). Neither is ours to waive. Whatever true402 itself could claim over a response, it doesn’t.

§08 · the registry

Free to list. Never in your flow.

Listing a service is free and needs no approval. Third-party services are paid directly at their own address — we are not a party to that payment, take no cut of it, and cannot reverse it. Their terms are theirs.

Ranking is settlement history: settled count, volume, distinct counterparties, age, recency. There is no paid placement. Listings that never transact sink on their own, and a listing may be removed if it is dormant, unreachable, or abusive.

Which has a consequence we would rather you read here than work out later. Every one of those signals comes from settlements we observed, in our own ledger. Because buyers pay a third-party service directly, its settlements never touch that ledger, and nothing here ingests them from anywhere else — so a third-party listing scores zero however much it actually sells. Among listings on zero the order is fixed and public: our own services first, then the oldest registration, then id. If you are listing in order to be ranked, read what a listing does and does not do first.

You are responsible for what you list, including having the right to offer it.

§09 · availability

No SLA. No warranty.

The service is provided as-is. There is no uptime guarantee and no warranty of accuracy, fitness or continuity. Endpoints, prices and this page can change, and an endpoint can be withdrawn. Because you are charged only on success, an outage costs you nothing but time.

To the fullest extent the law allows, liability for any claim arising from use of this service is limited to the amount you actually paid for the call it arose from.

§10 · data

What we keep.

Short version: no accounts, so no personal data to collect. The long version — every log, hash and retention rule — is on the privacy page.

§11 · contact

One address.

contact@true402.dev — also published in the OpenAPI spec and in security.txt for vulnerability reports.

Last updated 2026-08-23.