Measured 2026-09-15 · reproducible · not a live query

Our first pass asked what a vendor check costs. The question before that one is who the listing actually points to.

A Monid discovery result gives an agent a brand name and, often, a verified tag. Neither of those names the operator behind the endpoint. The closest thing Monid publishes is the documentation URL on the listing — so we read one per provider, 62 in all.

The ordering is the whole point, so we measured it. Across 3 queries, a discovery result carried description, endpoint, hints, metrics, price, provider, providerName, score, tags. docUrl was not among them: it appears only after a separate inspect call, alongside categories, input, method, notes, summary. So an agent choosing a tool sees the brand and the verified tag, and cannot see the documentation host until it asks for it. Balance $20.68 before and $20.68 after — asking costs nothing.
62
providers inspected, one listing each
out of 409 endpoints surfaced
30
document at a host that does not match the brand asserted (48%)
$0.00
cost of the entire sweep — discovery and inspection settle nothing

29 brands, one counterparty

Of the 30 mismatches, 29 document at a single host: parse.bot. An agent picking any of these by name gets a listing documented in the same place. We call that host the listing's counterparty — the host a screen should be pointed at. It is evidence about who stands behind the endpoint, not proof of who operates it or receives the payment.

AAA Gas Prices · AccuWeather · Artificial Analysis · Built In · Capterra · Clutch · Crunchbase · Finviz · G2 · GetApp · Homes.com · IQAir · Idealist · Indeed · LMArena · Levels.fyi · LoopNet · MarketBeat · Nasdaq · SECForm4 · StockAnalysis · The Companies API · Trustpilot · Weather Underground · Web3 Career · Wellfound · Y Combinator · Yahoo Finance · Zillow

A further 3 listings publish no documentation URL at all. 32 of the 62 carry verified while not documenting on their own host — but read that with its base rate: 58 of the 62 listings carry verified at all (94%), including 26 of the 29 that do document on their own host. The tag sits on both sides of the split, so it cannot tell an agent which side it is looking at.

This is not an allegation of deception. parse.bot is named openly in each listing's own documentation URL. We called none of these endpoints, so we make no claim about the data they return. The narrow point is that providerName and verified are what an agent sees when it selects, and neither of them carries this fact.

Knowing the counterparty halves the bill

A cohort screen that bills once per listed brand pays 29 times for one host — and points its evidence at the brand's own website instead of the host its own listing documents. Resolving counterparties first fixes the target and the price at once.

59
screenable listings
31
distinct documentation hosts
−47%
planned: $3.5046 → $1.8414
the run then spent $1.7820

What the paid screen found

30 hosts screened, covering 58 listed brands, for $1.7820 against a $2.0000 ceiling. Each host was screened at its registrable domain, https://<host> — so a subdomain that serves the API, such as api.strale.io, is not what earned the grade.

A6
B1
C7
D5
F11

16 of 30 — 53% — grade D or F on security headers. These are the hosts the listings document, and so the hosts a screen should target. parse.bot, the host behind 29 brand names, grades C.

What the C on parse.bot actually is. The cohort run kept only a grade letter, which is not enough to say anything fair about a host standing behind 29 listings, so we re-screened that one host and kept the detail. https://parse.bot returned 200 with 6 security headers present (strict-transport-security, x-frame-options, x-content-type-options, referrer-policy, permissions-policy, x-xss-protection) and 1 missing: content-security-policy. That single absence is the whole of the C. It is a real gap and it is not a bad posture.
CounterpartyGradeScoreBrands
parse.bot fronted C 75 29
ahrefs.com A 90 1
exa.ai A 90 1
firecrawl.dev A 100 1
octen.ai A 100 1
peopledatalabs.com A 90 1
tinyfish.ai A 90 1
apify.com B 80 1
blockrun.ai C 75 1
contactout.com C 70 1
elevenlabs.io C 60 1
google.dev C 70 1
hunter.io C 75 1
ploid.com C 75 1
alibabacloud.com D 45 1
apollo.io D 55 1
clay.com D 45 1
minimax.io D 45 1
semrush.com D 55 1
akta.pro F 35 1
asksurf.ai F 35 1
browserbase.com F 35 1
byteplus.com fronted F 10 1
context.dev F 35 1
itsgloria.ai F 35 1
kling.ai F 10 1
mrscraper.com F 30 1
strale.io F 35 1
suzanne3d.com F 35 1
tryfundable.ai F 35 1

1 host could not be screened (kadec0.xyz) — answered non-2xx, billed $0.0000, recorded as failed. Unscreened is not a pass.

3 listings were excluded before spending because they publish no host to point evidence at: DefiLlama, Simple FS, TikHub. Unevaluated is not clean.

Which rail paid for this

Every figure on this page settled on Monid's prepaid rail, against a workspace balance a person topped up. Nothing here shows an agent buying a counterparty screen without an account.

The account-free rail is proven separately, in the companion repo monid-x402: a live 402, a signed EIP-3009 authorization, and settled $0.01 USDC payments on Base. The clearest run is a pair three minutes apart on 2026-09-15 against the same seller. At 19:37:10 the gate refused — the seller's merchant card had renamed the field the gate reads for wash confidence, coverage came back unknown, and the gate treated unknown as refuse rather than as clean: signer_invocation_count: 0, nothing spent. At 19:40:40, reading the new field name, the same payment settled: transaction 0x3d93b3b7…, block 51355947, signer_invocation_count: 1, $0.01. The payer wallet holds no ETH at all; the facilitator submits and pays gas. Those payments bought a context.dev scrape, not a counterparty screen. Receipt.

What this does and does not establish

UNABLE_TO_VERIFY_OPERATOR: docUrl identifies who documents this endpoint, not who operates it, receives payment, or holds the data. A matching host is not proof of first-party operation.
Security-header evidence describes the HTTP response of one host at one moment. It is not a judgement of the vendor, its data quality, or its trustworthiness, and a passing grade is not an approval to spend.

Coverage is providers surfaced by the listed queries; not a guaranteed full enumeration. The sweep ran 25 seed queries; re-running it may surface listings this one did not.

Reproduce it

npm ci && npm run build
node dist/cli.js catalog-provenance --out evidence/catalog-provenance.json   # free
node dist/cli.js cohort-screen --confirm-spend --max-total 2                 # paid

The first command settles nothing; we read the workspace balance either side and it did not move. The second is the only one that spends, and it refuses before the first call if the live inspected price would breach the ceiling.