gpt55-token-gateway · Vulnerability Disclosure

558686 Xyz Vulnerability Disclosure

Vulnerability disclosure

gpt55-token-gateway publishes a vulnerability disclosure policy for reporting security issues.

x402Agentic PaymentsMCPA2AAI GatewayOpenAI-CompatibleLLMAI AgentsUSDCBaseAPI RelayDeveloper Tools
Program:

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
source: https://github.com/wangletiand/gpt55-x402-gateway/blob/main/SECURITY.md
corroboration:
  - https://raw.githubusercontent.com/wangletiand/gpt55-x402-gateway/main/SECURITY.md   # 200, 838 B, saved as 558686-xyz-SECURITY.md
  - https://github.com/wangletiand/gpt55-x402-gateway/blob/main/README.md                # "Support and Security: For security reports, follow SECURITY.md"
  - https://gpt55.558686.xyz/.well-known/security.txt                                    # 404
  - https://gpt55.558686.xyz/security                                                    # 404
  - https://gpt55.558686.xyz/privacy                                                     # 200 - "Wallet boundary" section repeats the never-share-keys rule
checked: '2026-09-19'
summary: >-
  The provider publishes a vulnerability disclosure policy as a SECURITY.md in its public
  repository: report privately by email to ops@400860.xyz, never in a public issue, with the
  minimum sanitized reproduction (route, method, response status, impact) and every secret and
  wallet signature redacted. Scope is the default branch and the live service
  https://gpt55.558686.xyz. There is no RFC 9116 security.txt on any host, no bug bounty, no
  PGP key, no acknowledgement or fix timeline, and no safe-harbour language. The repository has
  issues disabled, so email is the only channel. The contact domain (400860.xyz) is the sibling
  record in this catalog and also hosts the Sub2API recharge shop, which is how the two records
  are known to share an operator.
policy:
  url: https://github.com/wangletiand/gpt55-x402-gateway/blob/main/SECURITY.md
  raw: https://raw.githubusercontent.com/wangletiand/gpt55-x402-gateway/main/SECURITY.md
  file: 558686-xyz-SECURITY.md
  contact: mailto:ops@400860.xyz
  reporting_verbatim: >-
    Report security issues privately by email to `ops@400860.xyz`. Do not open a public issue
    containing credentials, private keys, seed phrases, payment headers, API keys, personal data,
    or unredacted payment evidence.
  scope_verbatim: >-
    Security updates apply to the default branch of this repository and the live service at
    `https://gpt55.558686.xyz`.
  wallet_boundary_verbatim: >-
    The service never needs a buyer's private key. Any optional real-payment mode in this
    repository runs locally in the buyer-controlled Node.js process. The default mode is
    quote-only and does not sign or broadcast a transaction.
  response_sla: not-stated
  safe_harbour: not-stated
  pgp_key: none
  bug_bounty: none
  platforms: []
security_txt:
  served: false
  probed: ['https://gpt55.558686.xyz/.well-known/security.txt -> 404', 'https://sub2api.558686.xyz/.well-known/security.txt -> 200 SPA shell (not a document)', 'https://x402-*.558686.xyz/.well-known/security.txt -> 410']
sub2api:
  note: 'No security policy, contact or security.txt on sub2api.558686.xyz or api.558686.xyz; the Sub2API docs advise revoking a leaked key immediately in the console.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/558686-xyz-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.