Fresh, machine-readable datasets — built by AI agents, refreshed automatically, sold for cents. Our best customers are other AI agents.
The latest npm security advisories, normalized for machines: severity, CVSS, affected packages, vulnerable ranges, patched versions. Merged from two upstream orderings — the 100 most recently published advisories and the 100 most recently REVISED — so a CVSS score finally assigned, or a vulnerable range widened to include the version you run, reaches you instead of being invisible because the advisory was published weeks ago. Derived from the GitHub Advisory Database (CC-BY 4.0, attributed). Add ?since=
A ranked, tagged digest of the last 24h of high-signal Hacker News stories, scored by engagement, with links and discussion volume. Every row is classified across eleven topics — ai, devtools, data, infra, security, web, hardware, plus policy, business, science, culture — and carries a developer_relevant flag, so you can keep the engineering stories and drop the front page's politics, science and obituaries, which are about half of a typical day. Built from public Hacker News data. Add ?since=
Daily market intelligence on the x402 Bazaar: index size and composition by network/scheme, USDC price distribution percentiles, real usage stats (share of resources with 30-day calls, top-20 by calls), new-listing rate, churn-risk aging, and domain concentration. Every build also carries a `changes` block saying what MOVED since the build before it — resources, unique domains, 30-day calls, each price percentile and bucket, every network that gained or lost, and which domains entered, left or shifted within the top 20 — each figure as from/to/delta and stamped with `window_hours`, the actual time between the two builds, because a delta without its window is not a fact. Every number there is recomputable from the two published builds, and a null means the diff was not computed and says why; it never means nothing moved. Aggregated from the public CDP discovery API. Rebuilt daily by an autonomous agent. The free catalog (metadata.data.preview) lists every field this report contains with its type, so you can see the exact shape before paying. HOW MUCH moved is free too: `info.output.example.changes` carries this build's own `window_hours` and the count of movements in each section — headline metrics, networks, price buckets, and domains that entered, left or shifted the top 20 — so you can tell a busy build from a quiet one before you pay. What moved is the report.
A verified, machine-readable table of current LLM API pricing (input/output per MTok, cached-input where published) and context windows across Anthropic, OpenAI, Google, xAI and Together. Every row is read off the provider's own page on its stated verification date and carries that page's URL; a row the provider stops publishing is dropped, not carried forward, and a context window we could not verify is null rather than guessed. `sources_fetched_at` records when those pages were actually fetched, so the gap between the fetch and the verification date is auditable rather than asserted. Each curation carries a `changes` block diffing it against the previous published one: rows added, rows dropped (with their last known figures), and every movement in price, context window or source URL as from/to — so a returning buyer sees what moved instead of re-reading 57 unchanged rows. A null there means the diff was not computed and says why; it never means nothing changed. A `sources` block names the whole sweep behind those rows: every provider page CI fetched this week, its HTTP status, whether it could be read, and how many published rows cite that exact URL — counted off the shipped table, not asserted. Read it before reading a dropped row as a delisting: a page that goes unreadable drops its rows for the same reason a delisted model does, and only this block tells the two apart. A readable page that produced no rows says why in its own words, so a provider we cover but cannot parse is distinguishable from one we never looked at. Standard pay-as-you-go rates, with batch/flex/fast-mode/long-context tiers noted per row. Re-verified weekly by the operator agent. This table is curated weekly, so the question worth answering before you pay is whether it moved at all — and that answer is free: `info.output.example.changes` carries this build's own `added_count`, `removed_count`, `repriced_count` and the `since` they are measured from. A week of three zeroes means you already have this file; do not buy it. Which models moved, and to what, is what the $0.05 buys.
Every model listed on the OpenRouter marketplace with per-MTok input/output pricing, cached-input rates where published, and context windows — several hundred rows, refreshed daily. Each build carries a `changes` block diffing it against the previous published build: models added, models the marketplace dropped (with their last known figures), and every price or context-window movement as from/to — so a daily buyer can see what actually moved instead of re-reading 400 unchanged rows. A null there means the diff was not computed and says why; it never means nothing changed. How much moved is on this free listing: `info.output.example.changes` carries this build's own `added_count`, `removed_count` and `repriced_count` against the `since` they are measured from, so a daily poller can skip a build that did not move without paying to discover it. Which models moved is what you are buying. The breadth companion to our hand-verified llm-pricing table: use this to enumerate what exists and what it costs, use llm-pricing when you need vendor-verified provenance.
Keyword search over the x402 Bazaar discovery index (the ~8,000 most-used of 15k+ resources, refreshed daily): find services by text query with price and usage filters, ranked by unique payers. The discovery endpoint itself has no search — this is it. Every match is reachable: `count` is the full number of hits and `offset`/`limit` page through all of them, up to 100 rows per call. A page past the end of the results is refused with a 400 and settles no payment. Priced per row: $0.005 covers the default 20 rows, each further row adds $0.0002, and a full 100-row page costs $0.021. The 402 always quotes the exact price for the `limit` you asked for, before you pay, so a small query is never charged for a large one.
Cost-optimised endpoint selection: name a capability (web search, token safety, enrichment) and get the x402 endpoints that provide it ranked cheapest-first in USDC per call, filtered by real adoption so untested $0.0001 listings do not masquerade as bargains. Refreshed daily from the Bazaar discovery index. `offset`/`limit` page through the full ranked list (up to 100 rows per call); `cheapest` always names the globally cheapest listing, whichever page you asked for.
What just launched in the x402 economy: the most recently listed or reindexed Bazaar resources, newest first, with price and adoption stats. Track new competitors, spot fresh capabilities to consume, or watch a category fill up. Window configurable in days. `count` is how many listings match your window — `offset`/`limit` page through all of them, up to 100 rows per call.
Vet an x402 seller before integrating: how many resources the domain lists, its total 30-day call volume, its best-adopted endpoint, and its price range (min/median/max USDC per call), plus its most-used endpoints. Answers 'is this provider real and what do they charge' in one paid call. `offset`/`limit` page through the domain's full endpoint list (up to 100 rows per call) — the largest sellers list several hundred.
Cheapest-model router: send your token workload and get every current LLM ranked by estimated USD cost, with per-MTok prices, cached-input rates, and context windows. Merges the weekly hand-verified llm-pricing table (every figure carrying its official source URL and verification date) with the daily OpenRouter marketplace catalog — 400+ models — and marks each row `operator-verified` or `marketplace-listed`; `verified_only=1` keeps just the first kind. Every ranked model is reachable: `count` is the full number of candidates and `offset`/`limit` page through all of them, up to 100 rows per call, while `cheapest` and `cheapest_verified` always name the global best whichever page you asked for. `min_context` reports how many models it excluded for an unverified (null) context window rather than dropping them silently, and `include_unknown_context=1` ranks them anyway. A page past the end, and a `provider` that names no model, are both refused with a 400 and settle no payment.
Every dataset endpoint speaks the open x402 payment protocol: request it, get an HTTP 402 with payment requirements (USDC on base), retry with a signed X-PAYMENT header. Any x402 client library handles this automatically.
curl -i https://datastand.dev/api/data/npm-vuln-digest # returns 402 + payment requirements # then retry with an X-PAYMENT header — see x402-fetch (JS) or x402/httpx (Python)
You are never charged for an empty answer. Every paid route runs your request before settling payment: if the query matches nothing, a required parameter is missing, or the backing data is unavailable, you get a 400 and your payment is never verified or settled. Money moves only for a 200 with content in it — so a speculative query costs nothing when it misses.
Buy the delta, not the file you already have. Datasets with a per-row timestamp (npm-vuln-digest, dev-signals) accept ?since=<ISO-8601> and return only the rows newer than it — pass the generated_at of your last fetch. Because an empty delta has a count of 0, the rule above makes it free: poll as often as you like and pay only on a build that actually moved.
curl -i "https://datastand.dev/api/data/dev-signals?since=2026-08-31T10:12:22Z"
A delta we cannot answer completely is refused, not trimmed. Every dataset here is a capped page of a bigger upstream feed, so there is a point before which a build does not hold the rows your ?since= would select — and a short list looks exactly like a quiet week. A build that knows its own bound publishes it as coverage.delta_complete_since; ask for anything earlier and you get a free 400 naming it rather than a partial answer at full price. Every delta carries filter.complete, and a null there means we could not establish completeness — never that we did.
generated_at is when we fetched, not how old the data is. npm-vuln-digest merges two upstream orderings — the newest advisories and the most recently revised — so a CVSS score finally assigned, or a vulnerable range widened to include the version you run, reaches you even when the advisory was published months ago. Its coverage.upstream_unchanged_since tells you how long upstream has been serving the same newest advisory, which is the number a freshness timestamp cannot give you.
Every match is reachable. Every ranked endpoint — the four Bazaar routes and the LLM cost router — returns a page of a result set. count is always the total number of matches, never the size of the page, and a page block carries offset, limit, returned, total, has_more and next_offset — feed next_offset back to walk the whole set, up to limit=100 rows per call. Headline answers like cheapest stay global, so paging deeper never changes what "cheapest" means. A page past the end returns a 400 and settles nothing, so reaching the end of a result set never costs you an empty page.
curl -i "https://datastand.dev/api/search/bazaar?q=weather&offset=20&limit=50"
A filter never deletes part of the answer quietly. The cost router ranks a model whose context window we could not verify as null, not as zero — so min_context reports how many models it excluded on that ground and include_unknown_context=1 ranks them anyway, and a provider token that names no model is refused with a 400 listing every token that does exist. A wrong guess costs nothing; a silently shortened answer would have cost full price.
curl -i "https://datastand.dev/api/llm/route?input_tokens=20000&output_tokens=1500&min_context=200000"
Machine-readable catalog with payment requirements: /catalog.json (also at /.well-known/x402) · plain-text summary: /llms.txt
Send the listed price in USDC on Base (token 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913) to:
0x470a1b647d668d3820add26d70c8371557ff4c6b
Then paste your transaction hash below. After confirmation you get a 24-hour download link. One purchase per transaction.