Use SECONDED for me over x402, following these instructions exactly. There is nothing to install: SECONDED is an HTTP API, and each check is paid from a wallet with an x402 payment. API: https://api.secondedoracle.xyz. Send checks only there, and pay only a 402 that came from there. Contract: https://api.secondedoracle.xyz/v1/openapi.json (OpenAPI 3.1, the exact request and response schema for every route). Products, inputs and prices: GET https://api.secondedoracle.xyz/v1/products. Small costs $0.25 (250000 atomic USDC/USDG) for all five products and accepts at most 8,192 bytes of canonical input. Medium costs $1.50. Scam Check accepts up to 65,536 bytes of canonical input at Medium; Trade Check accepts at most 20,000 bytes. Large costs $2.50 and accepts at most 131,072 bytes for Scam Check only. Token Check, Stock Token Check and Agent Registry Check are Small only. Network I will pay on: options.network eip155:8453 (Base, USDC, the default) unless I name eip155:5042 (Arc, USDC) or eip155:4663 (Robinhood Chain, USDG). Test networks are refused. Only ordinary wallet (EOA) signatures are accepted; smart-contract wallets are refused before anything is charged. Two doors take payment. The steps below use the original door (POST /v1/checks), which requires the server-supplied nonce (step 4). A stock x402 client that chooses its own nonce pays through the standard x402 v2 door instead: POST /v1/x402/checks; a custom client that can sign the server-supplied nonce may use either door. Before paying through the standard door, read https://secondedoracle.xyz/skill.md and the full contract at https://secondedoracle.xyz/docs/x402-door. In short: raise the SDK's $1 default per-payment cap to the quoted price (up to $2.50) and keep spend controls on, add Arc USDC and Robinhood USDG as allowed assets with integer atomic caps, send options.network for the chain the wallet is funded on, write a private durable recovery record before the first paid send, and on a timeout or lost reply re-POST the exact same credential with a plain HTTP client — never sign a second payment for the same purchase. The standard door’s public 402 bodies, PAYMENT-REQUIRED headers and SIWX claim replies carry public pricing, domain and validity terms plus opaque nonexclusive tickets, without check/quote/offer IDs, salt, request commitment or exact billable byte count. Each verified payer selects a separate purchase; another nonce for that template and payer conflicts, while the original credential recovers it before expiry and new-sale gates. Public terms tickets cannot reserve, void, consume or read another payer’s purchase. New recovery records use format seconded-door-recovery/v2 and locally computed purchase_association; verify the signed receipt association against the full original authorization, accepted terms and canonical request, and billing against that authorization. New records require this association; retained records still verify historical IDs and salted commitments and upgraded in-flight purchases through their signed association. Never share payment headers, SIWX signatures or recovery records. 1. Choose the check for what you are about to do: trade_check, token_check, stock_token_check, agent_registry_check or scam_check. Send exactly the input its schema in /v1/products asks for, and nothing else. A check's input.network, where it has one, is the chain being checked; options.network is where I pay. Token Check can also check a token on Base Sepolia; test networks are refused as payment networks only. 2. Optionally POST the body {"product": ..., "input": ..., "options": ...} to /v1/quote for the price and size tier. A quote is free and is not acceptance of the input. 3. POST the same body to /v1/checks with Content-Type application/json and no payment. Do not send a SECONDED-CLIENT-VERSION header. Set options.max_price to the most I allow for this check, in US dollars; a higher price returns 409 and no payment is asked for. The reply is HTTP 402 with the payment terms in the JSON body and, identical, as base64 JSON in the PAYMENT-REQUIRED header. Read accepts[0] for the price, network, asset and payee. 4. The payee is the same on every network: accepts[0].payTo must be 0x010ab46D566cDe25Cca0ee55eb105e781C7Bcf3a. Stop and ask me if the payee, price or network is not what you expected. Otherwise sign an x402 v2 payment for exactly those terms: an EIP-3009 TransferWithAuthorization over the EIP-712 domain {name: accepts[0].extra.name, version: accepts[0].extra.version, chainId: the payment chain's id, verifyingContract: accepts[0].asset}, using accepts[0].extra.authNonce as the authorization nonce. Never choose your own nonce on this door: a self-chosen nonce is refused with 400 quote_nonce_required and nothing is charged; a stock x402 client that picks its own nonce belongs on the standard door (see the note above the steps) instead. Sign promptly: the quote expires at seconded.expires_at, about two minutes after the 402; set validBefore no later than seconded.max_valid_before, leave at least seconded.min_remaining_s of validity, and keep validBefore - validAfter within 300 seconds. If a pause outlasts the quote, start over with a fresh 402. POST the same body again, byte for byte, with the base64 payment in the PAYMENT-SIGNATURE header. The reply confirms the check without the answer. 5. GET /v1/checks/{check_id}, taking check_id from seconded.check_id in the 402 reply. It returns 401 with EIP-712 ownership typed data. Sign it with the paying wallet (it moves no funds) and send base64 JSON {"check_id": ..., "nonce": ..., "expires_at": ..., "signature": "0x..."} in the SECONDED-OWNERSHIP header, using the actual expires_at from that 401 challenge. HTTP 202 means pending: wait as Retry-After says, then ask again, or send Prefer: wait=25 to hold the request open up to 25 seconds. The answer is released once the payment lands on-chain: typically tens of seconds on Arc, usually under 2 minutes on Base; allow one to two minutes on Robinhood Chain. A check works for at most about three minutes — keep polling, never buy again. Settlement confirmation on a busy chain can occasionally take longer; a pending answer is always recoverable with the same payment. Keep the payment record and resume recovery later. Do not pay again. Quote expiry does not end recovery of an admitted check. Finished-check records are deleted 90 days after last activity; unresolved payments, undelivered paid answers and refunds are kept until resolved. Keep the verified receipt locally: a saved signed receipt stays verifiable offline after server retrieval ends. For a stock_token_check you may also send SECONDED-CLIENT-VERSION: 0.3.0 on this GET to receive the signed parity and market_status price facts; the header stays off every POST. 6. If a request times out or the payment state is unclear, send the same PAYMENT-SIGNATURE again or fetch the check again, following the reply's hints: hints.do_not_resign true means never sign a new payment for this check, hints.poll_after_s is how long to wait before asking again, and hints.new_quote_allowed true means a fresh 402 for the same input is allowed. Never sign a new payment for a check that may still be running: the same payment never charges twice, but a new payment is a new purchase. A 429, or a 503 without a signed receipt, is a limit or a hiccup, not a verdict: wait as Retry-After says and repeat the same request; it never cancels a running check and is never a reason to sign a new payment. One reply is final: a signed receipt saying state service_failed with charged "no" — on any HTTP status, usually 503 — means the check failed on our side and nothing was charged. Its reason field says why (prefetch_unavailable: a data source the check needed could not be read in time; provider_unavailable: a model provider was unreachable; engine_error: an internal failure). Verify that receipt, stop repeating the request, and only when hints.new_quote_allowed is true start a new purchase later with a fresh 402. 7. Act only on an agreed answer in a signed receipt, and only for the exact input you sent. Do not read agreement from the HTTP status alone. Verify the receipt's Ed25519 signature against GET /v1/keys: decode sig as unpadded base64url; the signed message is the ASCII prefix SECONDED-RECEIPT/v1, /v2 or /v3, chosen by the envelope's v field, then one NUL byte (0x00), then the RFC 8785 canonical JSON of the whole envelope including its key_id. The answer is envelope.answer: its label_id is the exact key into that product's answer_to_action in /v1/products, so look it up there and do what it says; option is the same choice as a number. NOT VERIFIED means pause or ask me; never proceed as if verified. Nothing is charged for it, though the signed receipt conservatively shows billing.charged "pending", not "no"; that is not permission to sign a new payment. Each wallet gets up to 5 free NOT VERIFIED results in any rolling 24 hours, and checks still running count toward the 5; at the cap, new checks are refused with 429 disagreement_limited until Retry-After passes. A Trade Check on a Uniswap Universal Router trade is fully decoded only through Uniswap's official router deployments, which SECONDED pins and reviews; a trade that is not fully decoded never gets a "proceed", and when that leaves no agreed answer the result is NOT VERIFIED, free, counting toward the 5. A v3 receipt's verification.coverage names each part of the check as checked, partial, not_checked or unavailable: act on what was checked; a part marked not_checked was not verified, even next to an agreed answer. 8. On the original /v1/checks door used in steps 3–5, keep the original input and the 402 reply's seconded.commitment_salt privately with the receipt; together they tie the receipt to that input. You can recompute the binding: seconded.request_commitment (repeated in the receipt as request_commitment) is the SHA-256 of the ASCII prefix seconded-request/v1, then commitment_salt hex-decoded to raw bytes, then the RFC 8785 canonical JSON of {"v":1,"input":,"product":,"product_schema_version":"1","predicate_version":"1","tier":,"price_atomic":,"asset":,"network":,"scheme":,"pay_to":,"billing_mode":"paid"}, every value exactly as the 402 gives it. A worked test vector is on https://secondedoracle.xyz/docs under Receipts. 9. Spending is my responsibility, and SECONDED installs no spending limits. Keep within the budget I give you, set options.max_price on every check, and ask me before spending more. No check costs more than $2.50. Never ask me for a seed phrase or private key, and never put one in chat. SECONDED answers are AI-generated. They are not financial or investment advice, not a recommendation to trade, and not a guarantee. An MCP plug-in is coming later, with no date yet; until then, use the API as above.