Current scope · FAQ
Frequently asked questions
Short answers about the current Tool402 routes and their boundaries.
Current local facts
Read the boundary before the route
These answers describe the present prototype without adding a product claim or a new action.
What is Tool402?
Tool402 is a Hedera testnet prototype for agent tool discovery. An agent can find a capability and inspect the current local route boundary. A configured 402 response is not evidence that payment completed.
How does the Tool402 flow work?
The current RiskScan route flow is Discover → Request → a result or 402 Payment Required → inspect the boundary → choose the next step. A route does not turn a payment requirement into proof of settlement.
What does RiskScan Quick assess?
RiskScan Quick assesses caller-supplied declarations about identity, pricing, limitations, and evidence. It is a bounded technical assessment, not financial, legal, insurance, identity, or security advice.
What is x402?
x402 is the payment boundary used by a tool to say that payment is required before access. The native Hedera mode uses hedera:testnet, but the descriptor is the source of truth for the current host. Receiving a 402 challenge alone is not proof of a completed payment.
What does the B03 consumer-agent path do?
Its non-payable preflight reads the descriptor, makes one unsigned initial request, and stops before payment construction, signing, retry, settlement, or result parsing. A paid B03 request remains a separate Human Ops testnet action.
Can I back RiskScan?
Only when /explore/riskscan/back has an OPEN offering. It first prepares HEDERA_FUNDING, then asks MetaMask for a separate HBAR transfer on Hedera Testnet. A signature is not a payment, and note units are allocated only after the issuer signs the allocation.
Does the Provider path deploy an ATS asset?
Not by opening the wizard, reviewing it, or signing one stage. The issuer wallet follows four separate stages: record the draft, prepare ATS_CREATE, create and attach the revenue-note candidate in MetaMask, then publish after the required receipt conditions. A relayed accepted signature is not an on-chain fact.
What does World verification do?
The signed dashboard can request a World App Selfie Check for the connected Hedera Testnet account. It confirms a live person, not identity or KYC; when verified, the browser-bound result lasts 30 days. It is unavailable when the host is not configured.
Is there a public MCP endpoint?
No. A public MCP endpoint is not part of the current local routes.

