{
  "version": "0.2",
  "effectiveDate": "2026-07-26",
  "url": "https://api.x402lint.dev/terms.txt",
  "contact": "jcislo918@gmail.com",
  "machineSummary": {
    "demoService": false,
    "informationalOnly": true,
    "notAdvice": true,
    "collectsPersonalData": false,
    "inputRetention": "submitted origin URL cached with the scan result up to 24h; settlement facts (payer, tx hash) may be logged",
    "payment": "x402 per-call, USDC on Base",
    "pricing": "POST /v1/scan $0.15, GET /v1/report $0.02 — kept in sync with src/manifest.ts",
    "chargedForErrors": false,
    "warranty": "AS-IS",
    "liabilityCap": "fees paid in prior 30 days",
    "notEndorsement": true,
    "gradeIsConformanceOnly": true,
    "listsScannedOrigins": true,
    "listsThirdPartyScannedOrigins": true,
    "optOutAvailable": true,
    "verificationMethod": "domain-control token at /.well-known/x402lint-challenge"
  },
  "sections": [
    {
      "id": "acceptance",
      "title": "Parties & Acceptance",
      "summary": "Using the Service, including having a deployed agent call the API, accepts these Terms. Under UETA/E-SIGN electronic-agent rules, deploying an agent is the principal's acceptance; each request and payment binds you."
    },
    {
      "id": "service",
      "title": "Service Description",
      "summary": "x402lint is a conformance scanner for x402 seller origins. It runs 25 versioned, read-only checks (GET/HEAD probes only; no real payments against the target) and returns an A-F grade with per-check evidence and one-line fixes. Findings are informational conformance signals, not a warranty of security, compliance, or fitness."
    },
    {
      "id": "payment",
      "title": "Payment Terms",
      "summary": "Paid endpoints are priced per call in USD and settled as USDC via x402 on Base: POST /v1/scan $0.15, GET /v1/report $0.02. The free GET /v1/status and GET /v1/checks endpoints require no payment. Compute-first / settle-after means you are not charged for errors — invalid URL (400), no-fresh-report (404), scanner failure (503), or still-running (504) never settle. Taxes and network fees are the buyer's. No bundles or subscriptions."
    },
    {
      "id": "refunds",
      "title": "Refund Policy",
      "summary": "The Service settles only after successfully computing a billable result, so charge-without-delivery should not occur. A completed scan of a broken or unreachable target is a valid, billable deliverable. Otherwise all sales are final."
    },
    {
      "id": "privacy",
      "title": "Privacy",
      "summary": "The submitted origin URL is used to run the scan and is cached with the scan result for up to 24 hours. Scans are read-only probes of the target's public surface. Payment settlement facts (payer address, tx hash) may be logged for accounting."
    },
    {
      "id": "acceptable-use",
      "title": "Acceptable Use",
      "summary": "Only scan origins you own or are authorized to assess. No unlawful use. No circumventing rate limits or payment. Free endpoints are rate-limited; abusive traffic may be throttled or blocked. The Service refuses to probe loopback, private, and link-local addresses (SSRF guard)."
    },
    {
      "id": "warranty",
      "title": "AS-IS / No Warranty",
      "summary": "The Service and output are provided AS IS and AS AVAILABLE with no warranties. No uptime, latency, or continuity guarantee and no SLA. A grade is a point-in-time conformance signal, not a certification."
    },
    {
      "id": "liability",
      "title": "Limitation of Liability",
      "summary": "No liability for indirect, incidental, or consequential damages. Total aggregate liability is capped at fees paid to the Service in the prior 30 days."
    },
    {
      "id": "governing-law",
      "title": "Governing Law & Disputes",
      "summary": "Governed by the laws of the operator's country of establishment (Poland) and applicable EU law; disputes go before the competent courts there, subject to mandatory consumer-protection rights."
    },
    {
      "id": "directory-listing",
      "title": "Directory Listing, Verification & Opt-Out",
      "summary": "Origins scanned via x402lint — including those scanned by a third party, not only the operator — may be listed in a public directory at x402lint.dev with the conformance grade and publicly-observable branding (name, description, icon) auto-collected from the origin using only publicly-available data; an operator may verify domain control by serving a one-time token at /.well-known/x402lint-challenge (POST /v1/verify/start then /v1/verify/confirm) and then opt the origin out of the directory and/or suppress branding (POST /v1/listing), with opt-out requests from verified owners honored within 24 hours."
    },
    {
      "id": "changes",
      "title": "Changes to Terms",
      "summary": "We may update these Terms; the version, effective date, and canonical URL will be revised and published. Continued use after changes take effect constitutes acceptance."
    }
  ]
}
