2026-08-05 · ATLAS LOG · EVIDENCE
The seventeen alias pairs
This is the evidence appendix to A payTo address is not a service. Every pair we retired is listed below with what decided it. Two of them rest on weaker footing than the rest, and they are marked.
Read the left column as "this hostname is no longer listed separately" and the right column as "this is the row that kept the service". Nothing was deleted: each retired row is still in our records with its original payment and on-chain receipt attached, and the retired hostname is attached to the canonical row as an alias so that searching for it still finds the service.
What decided each one
- redirect — the retired host answered every path we tried with a 308 to the same path on the canonical host, including its own
openapi.jsonand.well-known/x402. - declared — the retired host's own
openapi.jsonnames the canonical domain in itsserversarray. These three would have been caught by reading that one field alone. - identical docs — the two hosts publish byte-identical self-description (
openapi.json, root document, or both). Where they differed only in each host's own name, that one string was normalised before comparing. - backend fingerprint — something in the paid response could only come from one shared backend: the same signing key, or a cached payload from the other host's call.
- structural only — no single-shot proof; decided on the shape of the whole service. Both such cases are explained under the table.
| Retired hostname | Kept | Decided by | The specific evidence |
|---|---|---|---|
| mlb-stats-api.fly.dev | fanfare.run | redirect | 308 to the identical path on all five we tried: /mlb/schedule, /v1/fantasy/mlb/slate-context, /openapi.json, /.well-known/x402, /. The canonical host serves both routes directly. |
| skills.onesource.io | api.onesource.io | redirect | 308 to the identical path on /api/chain/allowance, /api/chain/network-info, /openapi.json, /.well-known/x402, /. |
| x402-gateway-production.up.railway.app | x402engine.app | declared identical docs | Its own OpenAPI names https://x402engine.app as its server. All three self-description surfaces byte-identical: openapi.json 202,828 B, .well-known/x402 302,459 B, root 132,893 B. |
| global-econ-x402-production.up.railway.app | globalapi.dev | declared identical docs | Its own OpenAPI names https://globalapi.dev as production server. openapi.json byte-identical at 48,021 B; both hosts answer both recorded routes with identical 402 challenges. |
| shoppi-backend.onrender.com | api.reloadpi.com | declared identical docs | Its own OpenAPI names https://api.reloadpi.com/ai as production server. openapi.json 23,868 B and root 1,000 B byte-identical. |
| x402-finance-api-production.up.railway.app | finance.payapi.market | identical docs | openapi.json byte-identical at 5,349 B (title "UK Finance Data API"); 402 challenge carries the same description verbatim; same route, same payTo. |
| x402-vehicle-api-production.up.railway.app | vehicle.payapi.market | identical docs | openapi.json byte-identical at 3,761 B (title "UK Vehicle Data API"); root byte-identical at 63 B; same route, same payTo. |
| web-production-18a32.up.railway.app | property.payapi.market | identical docs | openapi.json 26,429 B, same SHA-256 on both (title "UK Property Data API"); root byte-identical at 90 B; same POST /stamp-duty, same price, same payTo. |
| x402-weather-api-production-04c4.up.railway.app | weather.payapi.market | identical docs | openapi.json 4,376 B, same SHA-256 on both (title "Weather Data API"); root byte-identical at 97 B; same POST /current, same price, same payTo. |
| signal-engine-production-d88d.up.railway.app | api.signalfuse.co | identical docs | openapi.json byte-identical — 24,129 B, SHA-256 3fb5e790… on both (re-checked 2026-08-05). The document declares a single templated route /v1/arena/{strategy_id}/{symbol}; our two rows differed only in which strategy was substituted. This is the pair whose payTo values differ — the service pays out per strategy, and both hosts return the same address for the same strategy. |
| x402-agent-store.rileycraig14.workers.dev | store.agentexchange.work | identical docs | Root byte-identical at 10,105 B. The two openapi.json files differ by exactly 17 bytes — the length difference between the two hostnames — and are identical once each host's single mention of its own name is normalised. Same route, price and description string. |
| chat.anchor-x402.com | api.anchor-x402.com | identical docs | openapi.json 39,692 B and .well-known/x402 26,129 B byte-identical; both hosts answer both /v1/screen and /v1/aura; same payTo. Third hostname found for this one service (see the row below). |
| 1c09pdnrx1.execute-api.us-east-1.amazonaws.com | api.anchor-x402.com | backend fingerprint | Byte-identical responses to the same query, and both carry an x402_related block advertising the canonical host's own endpoints. Retired 2026-07-31, ahead of this batch — it is what started it. |
| x402endpoint-utiwoa54hq-uc.a.run.app | laso.finance | backend fingerprint | Both paid captures returned Firebase ID tokens from the same project (iss: securetoken.google.com/kyc-ts), signed with the same key id ee9046ead2e0500010ed5043b483d84b0c52c7c4, for the same subject. 402 challenge identical apart from the resource URL. |
| stable-travel-git-migrate-…-merit-systems.vercel.app | stabletravel.dev | identical docs | A Vercel git-branch preview deployment. Its own OpenAPI tells callers to use https://stabletravel.dev/api/… in all six quick-start examples. Same route, price, challenge description and payTo. A branch preview also disappears when the branch is deleted, so it was never a durable buying surface. |
| silverback-x402.onrender.com | x402.silverbackdefi.app | structural only backend fingerprint | Two paid captures taken 39 minutes apart (18:13:59Z and 18:53:09Z on 2026-06-15) carry the same payload-internal timestamp 2026-06-15T18:14:02.626Z, identical reserves to 17 decimal places, identical 24h volume and trade counts — the later call was served from the cache the earlier one filled. Weaker footing: both hostnames now return HTTP 503 "suspended by its owner", so this rests on June captures, not a live re-test. |
| slamlink-ai-main-50fbb45.d2.zuplo.dev | api.slamai.dev | structural only | All six endpoints the operator lists in the discovery catalog are served by both hosts at identical prices — including the distinctive non-round $0.001585. Route tables match across ten probed paths down to shared quirks (a trailing slash returns HTTP 500 with an empty body on both; /health returns "Healthy" on both). Byte-identical challenge description and outputSchema; one payTo. Weaker footing: see below. |
The two weaker ones, stated plainly.
slamai is the only pair in this batch with no same-input-same-output comparison behind it. We considered buying one, and it would not have settled the question: this endpoint's output is a deterministic function of public chain state, so one deployment and two deployments of the same code both return identical bytes at the same block. Buying "identical responses" would have been compatible with either answer, so we did not spend the money and said so instead. The two hosts do report different Zuplo build ids, so they are two deployments of one project rather than one process — a buyer paying at either hostname still buys the same product from the same operator, which is the question the list has to answer.
silverback was decided on archived June captures because both hostnames were already suspended when we looked. The cache fingerprint is strong evidence about June; it is not evidence about today. If the service comes back and the two hosts start behaving differently, this pair needs re-checking.
slamai is the only pair in this batch with no same-input-same-output comparison behind it. We considered buying one, and it would not have settled the question: this endpoint's output is a deterministic function of public chain state, so one deployment and two deployments of the same code both return identical bytes at the same block. Buying "identical responses" would have been compatible with either answer, so we did not spend the money and said so instead. The two hosts do report different Zuplo build ids, so they are two deployments of one project rather than one process — a buyer paying at either hostname still buys the same product from the same operator, which is the question the list has to answer.
silverback was decided on archived June captures because both hostnames were already suspended when we looked. The cache fingerprint is strong evidence about June; it is not evidence about today. If the service comes back and the two hosts start behaving differently, this pair needs re-checking.
What this table is not. It is not a completeness claim. It lists the pairs our signals caught; a duplicate that none of them can see would simply be absent from it, and we would not know. It also carries no verdicts — whether any of these services is worth buying is a separate question, answered in the catalog and the dataset, not here. The full ruling text for each pair, in the wording a buyer receives, travels in the dataset's
evidence_grade_basis field on each canonical row.
This log is append-only. Entries are dated and never rewritten — corrections get their own entry.