x402 v2 Regression Benchmark
What It Tests
The benchmark contains ten public JavaScript fixtures for selected x402 v2 buyer-payment shapes:
- paid Fetch without a policy hook
- paid Fetch with an abort-capable hook
- paid Fetch with an abort return inside an obvious constant-dead branch
- paid Axios with a hook on the wrong client
- automatic paid MCP with an observer-only hook
- automatic paid MCP with an abort-capable
onPaymentRequiredhook - a lookalike
checkBeforePaymentimport from an untrusted module - raw
PAYMENT-SIGNATUREconstruction - malformed x402 source
- an ordinary Fetch negative control
What It Establishes
The current release candidate returns the expected status, exit code, policy-seam state, and analysis-completeness state for all ten fixtures.
This is maintainer-produced regression evidence. The analyzer recognizes specific syntactic abort or denial returns and rejects obvious constant-dead branches; it does not establish general reachability, complete x402 coverage, policy quality, cross-file proof, runtime enforcement, settlement behavior, production readiness, or external adoption.
Run The Benchmark
npm run benchmark:adversarial
The runner writes both:
artifacts/adversarial-benchmark.jsonartifacts/adversarial-benchmark.md
Packed-Package Smoke
The package smoke harness installs local npm tarballs into a fresh temporary project and reruns the same corpus:
npm run smoke:external-agent
That runner writes:
artifacts/external-agent-smoke.jsonartifacts/external-agent-smoke.md
This verifies local tarballs. It does not prove npm publication or that the public GitHub Action tag exists.
Configuration Boundary
monarch.config.json is not part of the current contract. Custom sinks, custom guard names, and ignore paths remain unsupported.
Open a GitHub issue with a minimal fixture when the default analyzer misses a real x402 buyer path.