# OrionCMD Checks > Pay-per-call website checks for agents: TLS certificate (from CT logs), DNS/email-auth, domain expiry, and a site-health bundle. Also available as an MCP server at /mcp. Payments: x402 v2, scheme "exact", USDC on Base mainnet (eip155:8453), asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, payTo 0x2dAF658B01e257206375798a15832E9f547D65dD. No accounts or API keys. Flow: call the paid URL -> HTTP 402 with a base64 JSON PAYMENT-REQUIRED header -> sign an EIP-3009 USDC authorization for one of `accepts` -> retry with PAYMENT-SIGNATURE -> 200 + PAYMENT-RESPONSE (settlement receipt). Invalid input returns 400 and is never charged; upstream failures return 5xx and are not settled. Client libraries: @x402/fetch (wrapFetchWithPayment), @x402/axios, or any x402 v2 client. ## Paid endpoints - [GET /v1/cert](https://orioncmd-checks-mcp.dario-9fa.workers.dev/v1/cert) $0.01: Certificate status from CT logs + live HTTPS probe. Issuer, validity, days left, % of lifetime used, renewal cadence and a renewal-stall heuristic from Certificate Transparency logs (NOT the live served cert), plus a live HTTPS pass/fail probe from Cloudflare's edge. Query: `domain`. Example: https://orioncmd-checks-mcp.dario-9fa.workers.dev/v1/cert?domain=example.com - [GET /v1/dns](https://orioncmd-checks-mcp.dario-9fa.workers.dev/v1/dns) $0.01: Live DNS / email-auth / CAA / DNSSEC check. NS, A/AAAA/CNAME, MX, SPF, DMARC, CAA (tree-climbing) and DNSSEC via Cloudflare DoH, with plain-English findings. Query: `domain`. Example: https://orioncmd-checks-mcp.dario-9fa.workers.dev/v1/dns?domain=example.com - [GET /v1/expiry](https://orioncmd-checks-mcp.dario-9fa.workers.dev/v1/expiry) $0.01: Domain registration expiry via RDAP. Registrar, registration and expiry dates, days left, EPP status and nameservers from the registry's RDAP server. Query: `domain`. Example: https://orioncmd-checks-mcp.dario-9fa.workers.dev/v1/expiry?domain=example.com - [GET /v1/site-health](https://orioncmd-checks-mcp.dario-9fa.workers.dev/v1/site-health) $0.03: Bundle: cert + DNS + expiry + renewal-stall + LE 64-day note. Runs the cert, DNS and expiry checks together and returns a summary, the renewal-stall heuristic and the Let's Encrypt 64-day (2027-02-10) note. Partial results if one source fails. Query: `domain`. Example: https://orioncmd-checks-mcp.dario-9fa.workers.dev/v1/site-health?domain=example.com ## Free endpoints - GET https://orioncmd-checks-mcp.dario-9fa.workers.dev/v1/validate?domain=: validate/normalize a domain before paying - POST https://orioncmd-checks-mcp.dario-9fa.workers.dev/mcp: MCP server (stateless streamable HTTP); free tools validate_target and pricing, paid tools via x402 in _meta ## Discovery - OpenAPI: https://orioncmd-checks-mcp.dario-9fa.workers.dev/openapi.json - x402 manifest: https://orioncmd-checks-mcp.dario-9fa.workers.dev/.well-known/x402 - API catalog (RFC 9727): https://orioncmd-checks-mcp.dario-9fa.workers.dev/.well-known/api-catalog - Sitemap: https://orioncmd-checks-mcp.dario-9fa.workers.dev/sitemap.xml ## MCP discovery Server Card (SEP-2127): /mcp/server-card. AI Catalog: /.well-known/ai-catalog.json. ## Honesty Certificate details come from Certificate Transparency logs, not the live served certificate; the live probe is pass/fail only. Results are data, not guarantees.