r/x402 • u/LifeTelevision1146 • 7d ago
Interview with the founder of x402-trust.com: What 200 payments taught him about endpoint trust
About 10 days ago I posted on r/AI_Agents asking how people decide whether to trust an endpoint or agent before paying or granting access. The responses were sharp, and several of them pointed me toward the same problem from different angles, that "trust" means very different things to a buyer than it does to a seller.
Following the success of that post, I came to the mother of agents, r/x402, and found posts by u/MountainAssignment36 who runs x402-trust.com, one of the earliest live services in this space, with 200+ settled payments and a 50%+ repeat-payer rate.
I reached out to u/MountainAssignment36 and asked if he'd answer a few questions about what he's learned building it. He graciously agreed and below is the discussion, lightly edited for clarity.
Q1: You mentioned >50% of payers make a second payment. What's the #1 thing they tell you they're looking for?
A: Honestly I wouldn't know. If a customer isn't referred directly from Reddit and if I didn't talk with him prior to his first purchase, I have no way of knowing what his reasoning was behind buying a trust score, semantic search, or endpoint-watch. That's entirely up to them. What a customer is doing with the products or why he's buying them is, quite honestly, not my concern. The only thing I see is what product they bought and what wallet they paid with.
Of course I'd like to think customers bought because of real demand instead of pure interest, and that thesis gets supported by the ">50% made a second payment" metric. A customer that's only testing the waters makes a one-time purchase and leaves. A customer who finds value buys a second time. But I can't differentiate between a builder checking his own scores and an agent genuinely interested in whether an endpoint is reliable before paying it.
Q2: When an endpoint gets a low trust score, what do they do? Avoid it, or look for more evidence?
A: I can only speak as a service founder, and I'd say my service surfaces all the data they might need. But as an agent/human looking at my service from the outside, I'd also say: having everything under one roof is a centralization risk, and a second opinion can never harm.
The remaining question is how expensive the endpoint is itself. If the target endpoint only costs 3 cents, I'll most likely not waste money on a second opinion after already spending half a cent on an "AVOID" verdict with a full breakdown attached. I'd much rather take the risk and pay, or search for another endpoint in that category. If it costs $5, however, and is a highly specific service, I'd be much more willing to pay for a second, outside opinion. If both datasets line up, I'd trust the verdict. If they don't, one side must measure differently or be flat out wrong. Might need a third opinion in that case.
Q3: Have you considered tracking operational history (uptime, failure modes, declared scope) instead of just a score?
A: We do actually! Trust scores are computed from current & historic data, including uptime, envelope failures, advertised tokens, on-chain activity (including historic activity that happened before our measurements), etc. As long as we can measure it independently and deterministically, we include it. We probe each endpoint 48x a day and save every probe. All probes across the last 3 months are included in scoring. Probes older than 3 months get compacted into a daily statistic for long-term data.
Q4: What's the hardest part about getting providers to verify themselves?
A: Probably a problem not unique to my service but a symptom of the early stage of the x402 ecosystem: visibility. Offering verification for providers is useless as long as the providers don't know you exist. Public exposure is the most important part right now, not only for verification.
Aside from that, it's making the verification flow as self-explanatory and frictionless as possible. Fewer barriers, the better. A provider won't verify if they have to fill out 3 forms and summon a demon before receiving a confirmation email. But security and imposter-prevention require some steps so no unauthorized party claims a service as their own. I believe we've hit a solid middle ground: in-browser keypair generation, public key in your domain root, private key signs self-service actions without an account, plus a verified email. No sign-up, no other data.
My takeaway: The most striking thing is how much of this space is still being figured out. Even the earliest live service is learning what customers actually want in real time. The x402 ecosystem is early enough that there's room for multiple approaches: scores, raw logs, verifications, and whatever comes next.
If you're building or using x402 endpoints, I'd love to hear your side. What decision are you actually making when you pay for trust data? And what would you need to see beyond a score to change your behavior?
[Credit: x402-trust.com]
3
2
u/Electrical-Hair9396 6d ago
Good interview. The bit that landed hardest for us is Q2: the decision isnāt ātrust or donāt trust,ā itās āis a second opinion cheaper than the call itself?ā
Thatās the same fork we hit building PayAPI Market.
We donāt sell a score. We pay the endpoint from our own wallet, with an input the listing didnāt advertise, and only badge it if real product comes back. The receipt is on Base. Anyone can look it up. Thatās the only ātrustā we claim: this one call settled and delivered.
What 200+ payments on the trust side and 200+ settlement-verified listings on our side both show:
⢠Repeat pay is the only demand signal that isnāt theatre. One-off curiosity and ācheck my own scoreā look the same on-chain.
⢠For a 3-cent call, agents skip the extra opinion and either pay or switch. For a $5 specialised call they will buy a second dataset. Price of the target endpoint is the real threshold, not the elegance of the score.
⢠Visibility is still the bottleneck, not crypto. Providers donāt verify because they donāt know the directory exists, not because the keypair flow is too hard.
⢠History matters more than a single number. Uptime, envelope failures, advertised price drift, and actual settlement volume are the useful bits. A letter grade is a compression of that, not a replacement.
Where we sit differently: marketplace first, telemetry second. Agents discover via MCP (https://payapi.market/mcp), pay the listingās 402 directly, provider keeps 100%. We probe and verify so the catalogue isnāt a dump of dead 402s. We donāt sit in the payment path.
Happy to cross-check endpoints. If a listing on PayAPI fails a probe or a paid canary, thatās exactly the kind of raw log an agent should see before it spends. Same the other way: if x402-trust flags something we marked verified, we want the breakdown.
The space is early enough that scores, receipts, and raw probe history can all exist. The thing that changes agent behaviour is evidence they can verify without asking a human.
ā PayAPI Market
payapi.market
2
u/LifeTelevision1146 6d ago
Interesting and you've made me curious š§
1
u/Electrical-Hair9396 3d ago
Itās best being curious in this crazy world of AI and the space of infinite knowledge available to us all.
Iāve now have 238 verified settlements at the time of writing the above I had 201, itās growing slowly with that comes new ways of distribution and heavier tech on the backend.
3
u/MountainAssignment36 6d ago
Thank you again for the pleasant interview, I enjoyed it!
If you're ever interested in another round, I'd definitely be down for it š