developer.mastercard.com F · 38/100
7 passed 25 warnings 0 failed audit-mnej6dk6
SSL / TLS Valid HTTPS · 653ms
x402 discovery /.well-known/x402.json (non-JSON) · 650ms
Agent discovery /.well-known/agent.json not valid JSON · 586ms
llms.txt Found (453091 chars) · 812ms
security.txt Not found · 1404ms
CORS headers No CORS header (OK if server-to-server only) · 724ms
Security headers 3/5 — missing: content-security-policy · 773ms
Response time 701ms avg · 701ms
MCP server No MCP endpoint found
API endpoints 1 endpoints found
Error handling Returns 401 for unknown paths · 1542ms
x402 compliance No x402 payment gates found · 913ms
Rate limiting No rate-limit headers (may still be rate-limited server-side) · 939ms
Documentation No documentation endpoint
robots.txt AI crawlers robots.txt exists but no AI crawler rules · 1405ms
AI plugin manifest /.well-known/ai-plugin.json not valid JSON · 961ms
OpenAPI spec No OpenAPI/Swagger spec found
Privacy / GDPR No privacy policy or GDPR endpoint
Status / Health No status or health endpoint
EU AI Act disclosure /.well-known/model-card.json found (1629 chars) · 1088ms
Travel Rule (FATF) /.well-known/travel-rule.json found (non-JSON, 1629 chars) · 1107ms
A2A Protocol (Google) agent.json found but invalid JSON · 1170ms
DNSSEC No DNSSEC — domain is vulnerable to DNS spoofing
CAA Records No CAA records — any CA can issue certificates
DMARC / SPF No DMARC or SPF records found
Auth maturity No authentication detected — open API or check failed
API versioning /v1
Human oversight /agent/stop — auth-protected (EU AI Act Art. 14) · 1744ms
Terms of Service No Terms of Service endpoint found
Content-Type No application/json responses (1 paths tested)
Wallet trust No wallet address found in x402 or agent.json
ERC-8004 on-chain No EVM wallet found to verify on-chain registration
38
25 issues to fix
Warning — 25
Agent discovery needs attention

/.well-known/agent.json not valid JSON

security.txt needs attention

Not found

CORS headers needs attention

No CORS header (OK if server-to-server only)

Security headers needs attention

3/5 — missing: content-security-policy

Response time needs attention

701ms avg

MCP server needs attention

No MCP endpoint found

Error handling needs attention

Returns 401 for unknown paths

x402 compliance needs attention

No x402 payment gates found

Rate limiting needs attention

No rate-limit headers (may still be rate-limited server-side)

Documentation needs attention

No documentation endpoint

robots.txt AI crawlers needs attention

robots.txt exists but no AI crawler rules

AI plugin manifest needs attention

/.well-known/ai-plugin.json not valid JSON

OpenAPI spec needs attention

No OpenAPI/Swagger spec found

Privacy / GDPR needs attention

No privacy policy or GDPR endpoint

Status / Health needs attention

No status or health endpoint

Travel Rule (FATF) needs attention

/.well-known/travel-rule.json found (non-JSON, 1629 chars)

A2A Protocol (Google) needs attention

agent.json found but invalid JSON

DNSSEC needs attention

No DNSSEC — domain is vulnerable to DNS spoofing

CAA Records needs attention

No CAA records — any CA can issue certificates

DMARC / SPF needs attention

No DMARC or SPF records found

Auth maturity needs attention

No authentication detected — open API or check failed

Terms of Service needs attention

No Terms of Service endpoint found

Content-Type needs attention

No application/json responses (1 paths tested)

Wallet trust needs attention

No wallet address found in x402 or agent.json

ERC-8004 on-chain needs attention

No EVM wallet found to verify on-chain registration

Share on X Run new audit
🔒 Probe trust badge — unlock at score 60+

Fix your failing checks to earn the Probe verified badge. Display it on your site footer and README to show compliance.

⚡ Fix my API — $29 Current score: 38/100 → need 60+
Badge preview Shield preview
2026-03-31 11:25:40 UTC · getprobe.xyz