ScanPay โ Code Security Scanner with x402 v2 Micropayments
Deterministic AST-based security scanning for Python and JavaScript/TypeScript. No code execution. No AI inference. Just fast, reliable vulnerability detection. Pay per scan with Solana micropayments โ $0.10/scan.
๐ฏ What It Does
ScanPay analyzes source code for security vulnerabilities using deterministic AST parsing. No AI, no code execution โ just fast, reliable pattern matching that catches 45+ vulnerability classes before code runs.
Built for AI agents that generate code: scan before execution, block dangerous patterns, log audit trails.
โจ Features
- 45+ vulnerability patterns across Python and JS/TS/TSX
- Deterministic analysis โ same input always produces same output
- x402 v2 payment protocol โ pay per scan with SOL on Solana
- Dual language support โ Python (
astmodule) and JS/TS (tree-sitter) - No false AI hallucinations โ pure rule-based detection
- FastAPI-powered โ sub-100ms scan latency
- SARIF output โ industry-standard vulnerability report format
- Batch scanning โ scan multiple files in one request
๐ Quick Start
Using the Live API (testnet)
# Health check
curl https://repository-nil-camcorder-divx.trycloudflare.com/api/v1/health
# List available products
curl https://repository-nil-camcorder-divx.trycloudflare.com/api/v1/products
# Scan code (requires payment)
curl -X POST https://repository-nil-camcorder-divx.trycloudflare.com/api/v1/scan \
-H "Content-Type: application/json" \
-d '{"source_code":"eval(userInput)","language":"python"}'
# โ 402 Payment Required (0.0007 SOL)
Self-Host
git clone https://github.com/Misterio070/scanpay.git
cd scanpay
pip install -r requirements.txt
python main.py
# โ http://localhost:8484
๐ณ Payment Flow (x402 v2)
- Client requests scan โ receives
402 Payment Required - Client pays 0.0007 SOL (~$0.10) to merchant wallet via Solana
- Client retries with
X-PAYMENTheader containing payment proof - Server verifies payment on-chain, runs scan, returns results
Merchant wallet: JDKXvegmW5j4sAJPB6YCA9ffJbN422WLMmCWCcpy1vm4
๐ค For AI Agents (MCP Server)
ScanPay includes an MCP server for AI agents to scan code before execution:
{
"mcpServers": {
"scanpay": {
"command": "npx",
"args": ["-y", "scanpay-cli", "scanpay-mcp"],
"env": { "SCANPAY_URL": "https://repository-nil-camcorder-divx.trycloudflare.com" }
}
}
}
Agents call scan_code to check code for vulnerabilities before running it.
Network: Solana testnet (mainnet coming soon)
๐ Configuration
cp .env.example .env
| Env Var | Default | Description |
|---|---|---|
SCANPAY_PAYMENT_MODE | disabled | disabled, testnet, or mainnet |
SCANPAY_MERCHANT_WALLET | โ | Solana wallet address |
SCANPAY_PRICE_LAMPORTS | 700000 | Price in lamports (0.0007 SOL) |
SCANPAY_RPC_URL | https://api.devnet.solana.com | Solana RPC endpoint |
SCANPAY_PORT | 8484 | Server port |
๐งช Detected Vulnerabilities
Python
eval()/exec()โ code injectionsubprocesswithshell=Trueโ command injectionpickle.loads()โ deserialization attacksos.system()โ command injection- SQL injection patterns
- Path traversal (
../) - Hardcoded credentials
- And more...
JavaScript/TypeScript
eval()โ code injectioninnerHTMLโ XSSdocument.write()โ XSSnew Function()โ code injection- SQL injection patterns
- Prototype pollution
- And more...
๐ API Reference
GET /api/v1/health
Returns service status and configuration.
GET /api/v1/products
Returns available scan products and pricing.
POST /api/v1/scan
Scans source code for vulnerabilities. Requires payment in testnet/mainnet mode.
Request:
{
"source_code": "eval(userInput)",
"language": "python"
}
Response (200):
{
"status": "ok",
"findings": [
{
"rule": "PY001",
"severity": "critical",
"message": "Use of eval() detected โ code injection risk",
"line": 1
}
],
"summary": {
"total": 1,
"critical": 1,
"high": 0,
"medium": 0,
"low": 0
}
}
๐ค Built For
- AI Agents โ scan generated code before execution
- CI/CD Pipelines โ pre-deployment security gate
- IDE Extensions โ real-time vulnerability detection
- Code Review โ automated security audit
๐ License
MIT