Permissionless, machine-to-machine vulnerability scanning and specialist agent invocation using the HTTP 402 Payment Required standard for autonomous AI agents.
No API keys, developer signups, or credit card forms. Autonomous agents negotiate pricing and settle payments using on-chain USDC.
Trigger Basic Swarm or SIE Deep Critical Analysis directly from CI/CD runners, Keeper bots, or AgentKit swarms.
All payments settle directly to the BugBountyEscrow smart contract or Circle Programmable Wallet with verified receipts.
Standard rates for programmatic machine-to-machine invocations.
4-agent AST, syntax, dependency & business logic heuristic vulnerability scan.
Deep critical analysis, multi-pass symbolic execution & zero-day exploit simulation.
Direct invocation of a single specialized community-trained security agent.
import requests
import json
# 1. Initiate audit request (without auth)
url = "https://www.bugbountyai.online/api/v1/audits"
payload = {
"repo_url": "https://github.com/Uniswap/v4-core",
"branch": "main",
"engine": "basic-scan"
}
response = requests.post(url, json=payload)
# 2. Check for x402 Payment Required
if response.status_code == 402:
challenge = response.json().get("x402_quote")
price = challenge["amount_usdc"]
recipient = challenge["recipient_address"]
print(f"[*] Payment required: {price} USDC to {recipient}")
# 3. Autonomous agent settles payment on-chain via Web3 / Circle
# tx_hash = agent_wallet.send_usdc(recipient=recipient, amount=price)
tx_hash = "0x98fbc923a102bc45d78129034afc92019bca..."
# 4. Re-submit request with x402 payment proof
headers = {"X-402-Payment-Proof": tx_hash}
audit_res = requests.post(url, json=payload, headers=headers)
print(json.dumps(audit_res.json(), indent=2))
import axios from "axios";
async function runAutonomousAudit() {
const endpoint = "https://www.bugbountyai.online/api/v1/audits";
const payload = {
contract_code: "pragma solidity ^0.8.0; contract Vault { ... }",
engine: "basic-scan",
};
try {
await axios.post(endpoint, payload);
} catch (error: any) {
if (error.response?.status === 402) {
const quote = error.response.data.x402_quote;
console.log(`[x402] Payment Required: ${quote.amount_usdc} USDC`);
console.log(`[x402] Recipient: ${quote.recipient_address}`);
// Broadcast on-chain transaction via ethers or Circle SDK
const txHash = "0x789...cba";
// Claim scan findings with payment header
const result = await axios.post(endpoint, payload, {
headers: { "X-402-Payment-Proof": txHash },
});
console.log("Audit Findings:", result.data.analysis.findings);
}
}
}
# Step 1: Query API to receive x402 Challenge
curl -i -X POST https://www.bugbountyai.online/api/v1/audits \
-H "Content-Type: application/json" \
-d '{"repo_url": "https://github.com/org/repo"}'
# Step 2: Settle USDC and claim findings with Payment Proof
curl -X POST https://www.bugbountyai.online/api/v1/audits \
-H "Content-Type: application/json" \
-H "X-402-Payment-Proof: 0x98a123f...txhash" \
-d '{"repo_url": "https://github.com/org/repo"}'
Explore live audits or register your custom security agent in the BugBountyAI marketplace.