Manifest domain mismatch
accountAssociation is signed for www.mintboard.example, while the app runs on the apex domain.
The free Doctor checks public Farcaster surfaces. A focused repair can also cover one reproducible Base App standard-web, wallet, SIWE, notification, or app-side Base.dev verification blocker.
Free and read-only. No wallet or repository access required.
Need a human fix? See the exact $79 repair scope →
Private, staging, or Base App issue? Request a rescue without a public scan →
Public evidence, not a generic score. Every finding names the failed check, likely impact, and what to verify next.
accountAssociation is signed for www.mintboard.example, while the app runs on the apex domain.
No fc:miniapp metadata was found on the shared URL.
The public surface cannot prove that sdk.actions.ready() fires in the client.
Automated checks are read-only. Runtime and repository findings remain unverified until reproduced in the affected client.
Seeing “Failed to retrieve debug information”? Follow the manifest debugging guide →
App missing from search? Separate technical blockers from indexing signals →
Images failing validation? Check embed, icon, screenshot, hero, and OG roles separately →
Migrating into Base App? Separate the 2026 standard-web path from Farcaster →
Base.dev verification says “Something went wrong”? Separate project state, the production response, and Base App readiness →
Call either paid endpoint directly. No account or API key; canonical USDC settles on Base before the dossier is released.
A deterministic snapshot of the public integration surface. It reports exposed manifest, embed, SDK-readiness, and delivery signals without claiming cryptographic or client-runtime verification.
/api/x402/miniapp-auditOriginal-byte JFS verification, fresh finalized Optimism custody and key state, pinned registry-code hashes, strict manifest/embed checks, and bounded PNG byte evidence.
readyForRelease is always false/api/x402/miniapp-deep-releaseBoth products inspect one public HTTPS launch URL. Neither is a security audit, runtime guarantee, or release approval. Never auto-repurchase after an indeterminate result.
These are public, read-only diagnostics sent to builders who asked for feedback. They demonstrate the evidence format, not completed repairs or customer endorsements.
The public app returns X-Frame-Options: SAMEORIGIN and a self-only frame-ancestors policy, preventing third-party client embedding.
The live manifest publishes frame but no miniapp entry. The report separates that migration warning from checks that already pass.
Farcaster coverage is listed below. Base App repairs are bounded separately to one reproducible standard-web or app-side Base.dev integration blocker.
Manifest availability and shape, account association, exact domain match, launch URLs, icons, and discovery metadata.
fc:miniapp metadata, images, actions, page-specific targets, rich-card rendering, and share flows.
Saved-app behavior, capability wiring, webhook configuration, events, and the notification delivery path.
SDK readiness, splash behavior, client context, viewport, safe areas, scrolling, keyboard, and touch failures.
No vague recommendations. No payment for a diagnosis presented as a fix.
A verified fix means the reported failure no longer reproduces, the affected flow passes its documented check, and the repair adds no new Doctor blockers.
For Farcaster, run the free public Doctor scan. For a Base App blocker, describe the exact failing flow on the request form.
We reproduce the failure and state what must change before requesting any access.
Grant the minimum repository or deployment access needed. We patch one integration failure.
You receive before-and-after evidence. Only then do we request 79 USDC on Base.
Never send funds in response to an unsolicited message. A payment request appears only on your private order page after you approve the evidence.
Mini App Doctor scans public URLs automatically. First-contact outreach that points builders to a specific diagnostic may also be automated and always identifies itself.
Automation is not treated as proof. Repair scope is confirmed against the actual failure before access is requested.
TLMNT will never request a seed phrase, private key, wallet custody, or production signing secret.
Yes. It performs automated, read-only checks against a public URL. No wallet, payment, or repository access is needed.
No. It only requests publicly accessible pages, metadata, images, and endpoints. Repair work starts only after you explicitly grant scoped access.
For Farcaster: manifest, embed, launch, notification, SDK, and Mini App-specific mobile failures. For Base App: one bounded standard-web migration, wallet, SIWE, notification, or app-side Base.dev verification blocker. The public scanner itself covers Farcaster surfaces only.
New product features, smart-contract work, wallet custody, full redesigns, growth work, or unrelated infrastructure failures. If the problem is outside scope, no payment is due.
Usually temporary repository access or a source bundle. Deployment access is requested only when verification needs it. Never send a seed phrase, private key, or production signing secret.
Once the failure is reproducible and the access needed for the agreed repair is available.
After the agreed failure is fixed and the verification evidence is ready. Payment is 79 USDC on Base. No verified fix means no payment.
Yes. Public scans are automated and initial outreach may be automated. Findings include reproducible evidence and can contain false positives, so repair scope is confirmed before access or payment.
Run the Farcaster public checks first. For a Base App blocker, request a scoped reproduction directly. Pay only after the fix is proven.
Base App blocker or no public URL? Request the rescue directly →Free · Read-only · No wallet required