# Bounty Engineer Bounty Engineer exposes a multi-rail machine-buyable agent commerce and reliability API, deterministic web-intelligence tools, recurring products, sponsored distribution, and an evidence-gated autonomous paid-engineering agent. x402 is one payment rail, not the only rail. Public status: https://bounty-engineer-status.onrender.com/ Revenue API: https://bounty-engineer-x402-prod.onrender.com/ PayPal checkout: https://bounty-engineer-x402-prod.onrender.com/paypal GitHub operator: https://github.com/gatoprd ## Machine Buyer Pull — honest recurring discovery from independent observations GET https://bounty-engineer-x402-prod.onrender.com/machine-pull GET https://bounty-engineer-x402-prod.onrender.com/v1/machine-pull GET https://bounty-engineer-x402-prod.onrender.com/.well-known/machine-buyer-pull.json This is a free, self-updating, automated source-filtered discovery report; it is NOT a list of verified buyers. It joins only actual live public merchant paid endpoints with a delayed, anonymized NoHumans directory aggregate of generic search-interest terms seen for at least 2 days and by at least 2 client IPs. Search totals EXCLUDE reported seller self-lookup traffic. The directory's client IP figures are upper bounds, not unique people, AI agents or confirmed paying organizations. Its checked catalogue already found listings for all observed terms; there is no demonstrated unserved demand. Never purchase, message, impersonate or bulk-solicit these searchers, which cannot be individually identified from the aggregate data. The feed does not make any payments and never calls the independent directory to generate demand signals. Real verified x402 settlement totals are shown separately. Promoting matching Bounty Engineer tools does not establish revenue, intent to buy, conversion or recurring customer commitments. Existing free registry self-submissions respect their rate limits/cooldowns. ## JSON Delta Witness and new Policy Gate Existing basic, real tool: POST /v1/delta-witness at $0.003. New deterministic rule-driven paid tool: POST /v1/delta-policy-gate at $0.03. Free working input checksum preview: POST /v1/delta-witness/preview Real sample and terms: https://bounty-engineer-x402-prod.onrender.com/delta-witness Both use only caller-supplied before/after JSON. The policy gate additionally accepts blocked_paths, required_changed_paths, pinned baseline hashes, block_type_changes, block_removals, max_changed_fields. Hashes are SHA256 digests of inputs but no external state is authenticated, notarized or signed. Seller never authorizes or initiates buyer payments. Each paid request requires explicit buyer-funded x402 USDC or a previously funded prepaid account. ## Autonomous Treasury Court — machine-to-machine settlement evidence Read-only independent receipt reconciliation for DAO treasuries, contract- controlled wallets, unattended accounts-payable software and business settlement controllers that can fund x402/PayPal prepaid payments under buyer-owner authorization. Not restricted to AI agents or humans. Public landing and working onchain free preview (one real Base transaction): https://bounty-engineer-x402-prod.onrender.com/treasury-court GET/POST https://bounty-engineer-x402-prod.onrender.com/v1/treasury-court/preview Machine-readable contract: https://bounty-engineer-x402-prod.onrender.com/.well-known/treasury-court.json Paid real receipt bundle: POST https://bounty-engineer-x402-prod.onrender.com/v1/treasury-court Price $49.90 in buyer-authorized x402 USDC; optional existing funded PayPal prepaid route POST /v1/prepaid/treasury-court. Supports 1-8 receipt hashes on eip155:8453; confirms only actual Base mainnet USDC Transfer logs, recipient, optional sender, expected amount, block age, confirmations and duplicate transaction hashes. Emits SHA-256 of observed source fields; this does NOT verify invoices/contracts, card settlement, legal discharge, wallet ownership or finality beyond configured confirmations. No signing, customer invoice data collection, custody, sale simulation or seller-initiated purchases. Never claim external adoption or paid volume without actual verified buyer evidence. The existing free registry distribution engine submits truthful product descriptors during its normal scheduled cycles; no social posts, spam, artificial buyer calls or paid ads. ## Independent Proof-of-Fix Gate — agent-to-agent buyer QA A scoped PR metadata QA tool built for the actual public TaskBounty in-house solver request for independent JS/TS reviewers. Public landing and free live GitHub head-SHA quote: https://bounty-engineer-x402-prod.onrender.com/proof-of-fix GET/POST https://bounty-engineer-x402-prod.onrender.com/v1/pr-evidence/quote Body: {"pr_url":"https://github.com/owner/repo/pull/42", "required_checks":["CI"],"require_test_changes":true} Paid, buyer-authorized GitHub PR and check-run evidence: POST https://bounty-engineer-x402-prod.onrender.com/v1/independent-pr-evidence Price $49.90 x402 USDC; or buyer-funded POST /v1/prepaid/independent-pr-evidence with a pre-existing private key and max-credits/idempotency limits. The paid route independently reads exact public PR head, changed JS/TS/test filenames and statuses, and observed public GitHub CI check results BEFORE payment settlement. Upstream failures do not produce a paid report. This DOES NOT clone repositories, execute the reported tests, verify CI signatures, prove fail-before-pass regression, or guarantee the fix is correct. Use it as source-grounded PR review triage only. Original independent *synthetic demonstration*, not customer work: GET https://bounty-engineer-x402-prod.onrender.com/v1/proof-of-fix/demo The five-case JS default-value boundary example exercises both intentionally broken and corrected code; all claims are narrow to this synthetic sample. Offers for actual custom repo reproduction/testing require a funded buyer mandate through the TaskBounty agent profile and a publicly agreed scope. Listing discovery, sample generation, and replying to requests are not sales. ## Release Sentinel — Machine-paid software supply chain checks Independent, live npm package registry metadata + OSV known-vulnerability queries for non-AI CI/CD runners, package managers, deployment controllers and background jobs. No AI model or human prompt is needed once a purchasing organization sets its own approved spending policy. Seller does not initiate purchases. Public machine buyer introduction and live FREE metadata tester: https://bounty-engineer-x402-prod.onrender.com/release-sentinel GET/POST https://bounty-engineer-x402-prod.onrender.com/v1/release-sentinel/quote Free quote fetches npm registry metadata only; does NOT consult OSV or charge. The buyer can optionally buy live npm+OSV evidence at $0.049 via: POST https://bounty-engineer-x402-prod.onrender.com/v1/release-sentinel-evidence POST https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/release-sentinel-evidence Required JSON: {"name":"lodash","version":"4.17.21"}. Optional expected_integrity is the buyer's lockfile-pinned npm sha512 SRI. Optional boolean policy: block_on_vulnerability, block_install_scripts, require_registry_signature, require_provenance_signal. Reports disclose matched known OSV advisories, scripts, observed registry integrity and metadata signals, and SHA-256 of independently retrieved evidence. They do NOT download packages, independently verify Sigstore signatures, attest to overall safety or guarantee clean installations. Errors from upstream services fail closed before x402 settlement. A no-spend-default buyer CI script is published at https://bounty-engineer-x402-prod.onrender.com/release-sentinel-buyer.mjs . Buyer funding and approval are mandatory for paid calls. DO NOT auto-spend third-party funds or infer recurring purchases without actual buyer adoption. ## Machine Reflex for non-AI systems Machine Reflex allows ordinary non-AI event producers (IoT gateways, CI/CD pipelines, data integration jobs, warehouse services, smart-device relays and scheduled backend jobs) to inspect CloudEvents 1.0 before a customer-approved incident purchase. The producer/event source does not need an LLM, AI agent or human interaction. Machine onboarding: https://bounty-engineer-x402-prod.onrender.com/machine-reflex Free machine quote (GET for schema example, POST to evaluate): https://bounty-engineer-x402-prod.onrender.com/v1/machine-reflex/quote Optional paid evidence report: POST /v1/machine-reflex-evidence ($0.019 USDC x402). Alternative customer-prepaid API call: POST /v1/prepaid/machine-reflex-evidence. Default no-spend Node client: https://bounty-engineer-x402-prod.onrender.com/machine-reflex-client.mjs CloudEvents fields: specversion="1.0", id, source, type, optional time, data object. The free quote detects only caller-supplied anomalies (duplicate source/id within history, missing fields, sequence gaps, unexpected types, timestamp drift and metric thresholds). Healthy events do not recommend purchases. Buyers enable the paid call only after authorizing a hard price/credit budget, funding the buyer-side payment method and explicitly activating their own automation. The system will not sign, charge, buy, auto-fund or take physical actions on behalf of a customer without that customer's approved configuration. Do not confuse caller-supplied hashes with signed independent attestations or verified industrial sensor measurements. Integrations are available for customers to activate, not evidence of external adoption or guaranteed paid volume. ## Paid API for agents Resource: GET https://bounty-engineer-x402-prod.onrender.com/v1/audit?url=https://example.com Purpose: Audit a public HTML page for title, meta description, canonical URL, OpenGraph, JSON-LD presence, deterministic issue flags and a compact score. x402: - protocol: x402 V2 - payment model: exact - settlement network: Solana mainnet - price: USD 0.01 per request - response is delivered only after successful payment verification/settlement - Bazaar discovery metadata is attached to the payment requirement Input: - url: absolute public HTTP/HTTPS URL - private/local/link-local destinations, credentials and unusual ports are blocked ## Non-x402 automatic payment rails Machine Payments Protocol (MPP) via Stripe: - Status: https://bounty-engineer-x402-prod.onrender.com/mpp/status - Catalog: https://bounty-engineer-x402-prod.onrender.com/mpp/catalog - Supported premium tools use HTTP 402 + Authorization: Payment through the MPP/Stripe rail. - The public status reports whether MPP is actually configured and ready. A configured route is never presented as live if initialization failed. Credential-free direct wallet credits: - Catalog: https://bounty-engineer-x402-prod.onrender.com/wallet/catalog - Solana USDC: POST https://bounty-engineer-x402-prod.onrender.com/wallet/solana/start with {"product":"agent_micro","asset":"USDC","payer":""}. - Native SOL: POST the same endpoint with {"product":"agent_micro","asset":"SOL","payer":""}; the service returns a short-lived exact SOL quote. - Bitcoin: POST https://bounty-engineer-x402-prod.onrender.com/wallet/bitcoin/start with {"product":"launch"}. - No Stripe, no x402 facilitator and no seller merchant API key are required for these rails. - Solana USDC and native SOL invoices reconcile by unique Solana Pay reference plus exact asset/amount verification. Bitcoin invoices reconcile by exact reserved satoshi amount plus confirmed recipient output. - A private prepaid API key is issued with the invoice but receives zero credits until settlement is independently verified on-chain. - Buyers can poll GET /wallet/status?order=...; successful settlement activates the existing prepaid API automatically. Direct Solana USDC sponsorship: - Catalog: https://bounty-engineer-x402-prod.onrender.com/sponsor/catalog - Start invoice: POST https://bounty-engineer-x402-prod.onrender.com/sponsor/solana/start - Confirm transaction: POST https://bounty-engineer-x402-prod.onrender.com/sponsor/solana/confirm - Payment is verified server-side before placement activation. No x402 facilitator is involved. PayPal recurring revenue: - Monthly API credits renew automatically after buyer authorization. - Featured and Prime sponsorship plans are recurring. - Completed payments are counted only after PayPal server verification; redirects and checkout opens never count as revenue. ## PayPal API credits Human buyers can purchase prepaid API credits or a monthly recurring credit allocation at: https://bounty-engineer-x402-prod.onrender.com/paypal Paid API-key resource: GET https://bounty-engineer-x402-prod.onrender.com/v1/audit-key?url=https://example.com Authorization: Bearer API credentials are issued only after a PayPal transaction is independently verified server-to-server and passes recipient, status, currency, amount, product and transaction-id checks. ## Paid engineering The autonomous agent continuously searches approved funded or policy-compatible GitHub bounty programs. It verifies funding, payout route, AI contribution policy, acceptance criteria, availability, testability and competing implementations before work or submission. For maintainers, a useful paid issue should state exact acceptance criteria, reward amount/currency, payout method, AI-agent policy, assignment rules and reproducible test expectations. ## Evidence policy HTTP 402 responses, checkout opens, issue titles, proposed rewards, merges and estimates are not revenue. Only unique verified payment settlements count. Private payout destinations, payer details, receipt data and API keys are never published here. There is no guaranteed income claim. ## Free buyer routing POST https://bounty-engineer-x402-prod.onrender.com/v1/recommend-tool Body: {"goal":"compare three GitHub bounties"} This free machine endpoint selects the most appropriate paid Bounty Engineer tool, returns the current price, input shape and direct x402 endpoint. ## Premium agent products - Bounty Intelligence: $0.01 - Autonomous Bounty Due Diligence: $0.75 - Bounty Deal Desk: $1.50 - Agent Opportunity Underwriter: $4.90 - Autonomous Execution Blueprint: $9.90 - Agent Revenue Command Center: $19.90 - Tool Call Dry Run: $0.01 - Tool Response Shield: $0.01 - Schema Drift Guard: $0.03 - x402 Payment Preflight: $0.05 Use the cheap tiers for screening and the higher tiers only when deeper evidence, execution control or portfolio decisioning materially reduces wasted compute or submission risk. Workflow tools (x402 or the same PayPal prepaid key): - Agent Purchase Rescue Protocol: POST /v1/purchase-rescue — $0.009. Determine the safest recovery from HTTP 402 payment deadlocks, incorrect payee or network, budget overspend, unsettled receipts and duplicate intents. No automatic spending, retries or settlement. Requires buyer-provided sanitized attempt status and hard USD budget. - Free example: https://bounty-engineer-x402-prod.onrender.com/v1/free-preview?tool=purchase-rescue - Agent setup: https://bounty-engineer-x402-prod.onrender.com/workflows/purchase-rescue - JSON Contract Check: POST /v1/json-contract-check — $0.005. Strict supported schema subset; no inferred repair. - JSON Change Set: POST /v1/json-change-set — $0.005. Changed fields, source hashes, configurable ignore paths. - Evidence Pack: POST /v1/evidence-pack — $0.02. Exact quote presence, source offsets and declared freshness; not a truth check. - Context Pack: POST /v1/context-pack — $0.01. Verbatim relevance selection under a character budget, with source offsets. - Data Quality Gate: POST /v1/data-quality-gate — $0.02. Batch schema and composite uniqueness checks for up to 200 records. - Provider Route Plan: POST /v1/provider-route-plan — $0.01. Route across supplied providers by reliability, trust, latency and price. - Result Consensus Gate: POST /v1/result-consensus-gate — $0.02. Measure exact cross-provider and field-level agreement. - Retry Policy Plan: POST /v1/retry-policy-plan — $0.005. Bounded retry/stop/review decisions for transient failures. - Batch Budget Plan: POST /v1/batch-budget-plan — $0.005. Hard-budget allocation across prioritized metered calls. - Structured Record Merge: POST /v1/structured-record-merge — $0.015. Provenance-aware merging where enough supplied sources agree. - Tool Output Quality Gate: POST /v1/tool-output-quality-gate — $0.01. Reject stale, incomplete or schema-invalid tool output. - Agent Commerce Plan: POST /v1/agent-commerce-plan — $0.025. Provider routing plus affordability for repeated machine purchases. ## Margin Exchange - Free Margin Quote: POST /v1/margin-quote — free. Supply a task, current unit price and expected call count (or up to five items). Returns only savings economics and a SHA-256 commitment; exact alternative routes remain hidden. - Margin Exchange Unlock: POST /v1/margin-unlock — $0.02. Available only when projected single-purchase savings are at least $0.10. Reveals the committed selected route and ordered fallbacks. - Margin Portfolio Unlock: POST /v1/margin-portfolio-unlock — $0.10. Available only when projected portfolio savings are at least $0.50. - Both unlocks use the same Solana x402 settlement or verified PayPal prepaid API key. - The free quote does not guarantee provider equivalence or future price; buyers must re-read the destination's live 402 challenge before purchasing. ## Tender Engineer - Tender Engineer Search: POST /v1/tender-search — $0.10. Search bounded current TED procurement notices. - Tender Engineer Match: POST /v1/tender-match — $0.25. Rank bounded TED results against supplied capabilities with transparent reasons. - Tender UI: https://bounty-engineer-x402-prod.onrender.com/tender-engineer - Tender calls use the same verified PayPal prepaid key or Solana x402 settlement as the rest of the ecosystem. Free worked samples: https://bounty-engineer-x402-prod.onrender.com/v1/free-preview?tool=TOOL_ID Current prepaid tool list and exact credit costs: https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/catalog ## Autonomous revenue ecosystem Live status: https://bounty-engineer-status.onrender.com/#revenue-ecosystem Production receive paths are reported independently: - x402 Solana USDC pay-per-call - Stripe MPP machine payments where runtime credentials make the rail ready - PayPal prepaid API-credit purchases - PayPal monthly recurring API credits - PayPal recurring sponsor placements - direct Solana USDC API-credit invoices with automatic on-chain reconciliation - direct native SOL API-credit invoices with automatic on-chain reconciliation - direct Bitcoin API-credit invoices with automatic confirmed-output reconciliation - direct Solana USDC sponsor invoices - evidence-gated paid engineering / bounty execution - receive-only Solana, USDC and Bitcoin balance monitoring External opportunity feeds include TaskBounty, Superteam, SkillMarket, Opire, BountyHub, GitPay, Daydreams and additional public paid-work feeds. Discovery is not revenue: funding, AI policy, payout compatibility, acceptance criteria and platform claim requirements remain hard gates before autonomous execution or payout attribution. The system has a zero-automatic-outgoing-spend policy. It does not stake funds, pay claim fees, expose private keys, or label unexplained wallet balance changes as revenue.