com.402cron/402cron

402cron

Paid cron for AI agents: we call your https URL on schedule, signed. No account, paid with x402.

1.0.1
Version
remote
Transport
16
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 16 tools scanned
  • metadata: scanned

No findings.

Tools (16)

  • get_pricing

    What a delivery costs, which packs exist, and the exact x402 payment requirements for each. Balance is counted in DELIVERIES, not money, and packs never expire. Call this before buying.

  • get_docs

    One section of the machine documentation: quickstart, headers, signature, notice, errors, billing or limits. Omit `section` to get the whole document.

  • get_service_status

    Whether the service is currently selling, on which network, and if not — why not. This is configuration, not liveness: the full health endpoint is at /health.

  • list_tasks

    Your tasks and their state. Needs your management token as an Authorization header on this connection.

  • get_task

    A single task: schedule, destination, state, next run, and how many failures in a row it carries.

  • create_task

    Register a schedule against a destination you have already verified. Idempotent on "name": the same name updates the existing task instead of creating a second one. Creating costs nothing; each delivery ATTEMPT costs one credit.

  • update_task

    Change the schedule, destination, method, timeout, headers or body of an existing task. Omit a field to leave it unchanged — sending null is refused, because "unchanged" and "cleared" must not look the same. State is NOT editable here: use pause_task and resume_task.

  • pause_task

    Stop firing until you resume. Nothing is charged while a task is paused.

  • resume_task

    Start firing again on the schedule. Refused if your balance is empty — buy deliveries first.

  • run_task_now

    Deliver immediately, outside the schedule. THIS COSTS ONE CREDIT per attempt, exactly like a scheduled firing, and a timeout or unreachable host is retried up to three times — so one call can cost up to three credits. Use it to test a destination.

  • delete_task

    Move the task to the recycle bin. It stops firing immediately and can be restored for 30 days with restore_task; after that it is unrecoverable. Credits already spent are not refunded.

  • restore_task

    Bring a task back from the recycle bin within 30 days. It comes back PAUSED — resume it explicitly.

  • register_destination

    Claim an https:// URL you control. We answer with a challenge and a SIGNING SECRET that is shown ONCE and never again — store it before you do anything else; it is what lets you verify that a delivery really came from us. The permission covers that path and everything beneath it, nothing above. Verification is one request from us to the exact URL you registered: POST, headers X-402cron-Challenge: <value> and X-402cron-Event: verify, JSON body {"challenge":"<value>"}. Reply within 5 seconds, without a redirect, with a body that is the bare value or {"challenge":"<value>"}; we read the first 512 bytes and do not check the HTTP status (2xx is fine). Then call POST /api/destinations/{id}/verify within 15 minutes of registering. A fixed-response webhook cannot pass: you need an endpoint you can program. Registering a URL that is still pending issues a new challenge and a new signing secret every time — the old secret immediately stops verifying deliveries; a verified URL is left untouched u

  • verify_destination

    Verification is one request from us to the exact URL you registered: POST, headers X-402cron-Challenge: <value> and X-402cron-Event: verify, JSON body {"challenge":"<value>"}. Reply within 5 seconds, without a redirect, with a body that is the bare value or {"challenge":"<value>"}; we read the first 512 bytes and do not check the HTTP status (2xx is fine). Then call POST /api/destinations/{id}/verify within 15 minutes of registering. A fixed-response webhook cannot pass: you need an endpoint you can program. Registering a URL that is still pending issues a new challenge and a new signing secret every time — the old secret immediately stops verifying deliveries; a verified URL is left untouched unless you add ?rotate=1. The daily verification allowance (10 per destination, 40 per client, UTC day) does not reset on re-registration. Until this passes, no task may point at the destination.

  • list_destinations

    The URLs you have claimed and whether each is verified. The signing secrets are never shown again.

  • delete_destination

    Remove a claimed URL. Refused while a task still points at it — delete the task first.