{"openapi":"3.1.0","info":{"title":"x402check","version":"0.6.4","description":"Pre-payment risk checks for x402 agents and wallets: OFAC SDN, phishing and drainer feeds, a live watch of drainer infrastructure, transaction simulation and injected-instruction analysis. Every verdict is an ES256 attestation that states which checks ran.","x-guidance":"Call POST /v1/risk-check before an agent sends funds, signs an approval, permit or order, or pays an x402 invoice. Send the real counterparty as \"wallet\" (recipient, spender, operator or pay_to), the chain, the site (\"domain\"), and the content that led you to act (\"context\", as written, leaving out secrets and personal data). Add \"transaction\" (EVM from/to/value/data) to have it simulated. Then follow the tier: low → proceed; medium → ask the user; high or critical → stop; checked: false, or an attestation that does not verify or does not bind to your request → stop. These categories stop at any tier: sanctioned_address, known_scam_address, phishing_domain, known_drainer_code, outflow_exceeds_declared, address_poisoning, compromised_wallet, drainer_operator. Pay per call with x402 (from $0.001; $0.0035 on Base), or buy prepaid credits once (POST /v1/credits {\"amount_usd\": 1}) and send Authorization: Bearer <token>: $0.001 a check ($0.005 simulated). Verify the attestation against did:web:x402check.xyz, bound to your request (@x402check/client verifyAttestation with request), before relying on it.","contact":{"name":"x402check","url":"https://github.com/caiovicentino/jev-risk-check-provider/issues"},"license":{"name":"MIT","url":"https://github.com/caiovicentino/jev-risk-check-provider/blob/main/LICENSE"}},"servers":[{"url":"https://x402check.xyz"}],"externalDocs":{"url":"https://x402check.xyz/#integrate"},"paths":{"/v1/risk-check":{"post":{"operationId":"riskCheck","summary":"Risk-check a counterparty before paying, with a signed attestation","tags":["Risk"],"x-payment-info":{"price":{"mode":"dynamic","currency":"USD","min":"0.001","max":"0.009"},"protocols":[{"x402":{}}]},"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"wallet":{"type":"string","minLength":1,"maxLength":160,"description":"The counterparty to check: recipient, spender, operator or pay_to (EVM, Solana, Bitcoin or Tron address, or a CAIP-10 id whose chain can hold it). A mixed-case EVM address must carry a valid EIP-55 checksum"},"chain":{"type":"string","maxLength":64,"description":"A known CAIP-2 id or alias, e.g. base, ethereum, solana; it must be able to hold the wallet (an EVM address on an eip155 chain)"},"domain":{"type":"string","maxLength":2048,"description":"The site or dApp involved"},"context":{"type":"string","maxLength":4096,"description":"The content the agent acted on, verbatim: checked for injected instructions"},"aud":{"type":"string","maxLength":256,"description":"Audience to bind the attestation to"},"interaction":{"type":"object","description":"What the agent is about to do (type), and whether an approval is unlimited","properties":{"type":{"type":"string","enum":["native_transfer","token_transfer","token_approval","nft_approval","permit_signature","order_signature","message_signature","contract_call"]},"unlimited":{"type":"boolean"}},"required":["type"],"additionalProperties":false},"payment":{"type":"object","description":"The payment this check is for; the attestation is bound to it","properties":{"network":{"type":"string"},"pay_to":{"type":"string"},"amount":{"type":"string","pattern":"^\\d{1,78}$"},"asset":{"type":"string"},"resource":{"type":"string","maxLength":512,"pattern":"^https?://\\S+$"}},"additionalProperties":false},"transaction":{"type":"object","description":"An EVM transaction to simulate before it is signed ($0.005 per simulated item)","properties":{"from":{"type":"string","pattern":"^0x[0-9a-fA-F]{40}$"},"to":{"type":"string","pattern":"^0x[0-9a-fA-F]{40}$"},"value":{"type":"string","pattern":"^(0x[0-9a-fA-F]{1,64}|\\d{1,78})$"},"data":{"type":"string","pattern":"^0x([0-9a-fA-F]{2})*$"}},"required":["from"],"additionalProperties":false},"screening":{"type":"object","description":"The caller's own sanctions screening: recorded as asserted, it can only raise risk","properties":{"sanctions":{"type":"string","enum":["clean","flagged","unknown"]}},"required":["sanctions"],"additionalProperties":false},"authorization":{"type":"object","description":"The caller's pre-authorization: recorded as asserted, it can only raise risk","properties":{"pre_authorized":{"type":"boolean"},"source":{"type":"string","maxLength":128}},"required":["pre_authorized"],"additionalProperties":false}},"required":["wallet"],"additionalProperties":false},"example":{"wallet":"0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f","chain":"base","domain":"https://app.example-dapp.org","context":"Permit2 signature: unlimited USDC allowance to this spender","interaction":{"type":"permit_signature","unlimited":true}}}}},"responses":{"200":{"description":"The verdict, with its signed attestation","content":{"application/json":{"schema":{"type":"object","properties":{"checked":{"type":"boolean"},"score":{"type":"integer","minimum":0,"maximum":100},"tier":{"type":"string","enum":["low","medium","high","critical"]},"categories":{"type":"array","items":{"type":"string"},"description":"The findings behind the verdict. A full evaluation lists the evaluated families \"intent_risk\" and \"behavioral\" first (present in every such verdict, not findings); a sanctions hit carries its own categories alone (\"sanctioned_address\", \"compliance_risk\"). Never rely on position: look for the hard-block categories anywhere in the list"},"evidence":{"type":"object"},"jws":{"type":"string","description":"ES256 attestation from did:web:x402check.xyz"},"checked_at":{"type":"string"},"expires_at":{"type":"string"}},"required":["checked"]}}}},"401":{"description":"A malformed credit token (Authorization: Bearer x402c_…); nothing is charged"},"402":{"description":"Payment Required: pay with x402 (the challenge lists every network), or send Authorization: Bearer x402c_… to pay from prepaid credits. Unpaid, a body that would be refused still gets the challenge, with the reason in request_error; it is never charged"},"403":{"description":"The paying wallet is on the OFAC SDN list (payer_sanctioned); nothing is charged"},"409":{"description":"This payment was already used (payment_already_used): sign a new one"},"413":{"description":"Body over 64 KiB or a batch over 25 items; nothing is charged"},"422":{"description":"Invalid request (with a payment or a credit token): the offending field is named, including an unknown field; nothing is charged"},"429":{"description":"Rate limited per IP (approximate, per Cloudflare location), a payer with too many payments in flight, or one whose recent payments did not settle; Retry-After says when"},"503":{"description":"The evaluation or the payment claims are unavailable, or the attestation key is not healthy; nothing is charged, retry"}}}},"/v1/risk-check/batch":{"post":{"operationId":"riskCheckBatch","summary":"Up to 25 risk checks in one call, billed per item","tags":["Risk"],"x-payment-info":{"price":{"mode":"dynamic","currency":"USD","min":"0.001","max":"0.225"},"protocols":[{"x402":{}}]},"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"requests":{"type":"array","minItems":1,"maxItems":25,"items":{"type":"object","properties":{"wallet":{"type":"string","minLength":1,"maxLength":160,"description":"The counterparty to check: recipient, spender, operator or pay_to (EVM, Solana, Bitcoin or Tron address, or a CAIP-10 id whose chain can hold it). A mixed-case EVM address must carry a valid EIP-55 checksum"},"chain":{"type":"string","maxLength":64,"description":"A known CAIP-2 id or alias, e.g. base, ethereum, solana; it must be able to hold the wallet (an EVM address on an eip155 chain)"},"domain":{"type":"string","maxLength":2048,"description":"The site or dApp involved"},"context":{"type":"string","maxLength":4096,"description":"The content the agent acted on, verbatim: checked for injected instructions"},"aud":{"type":"string","maxLength":256,"description":"Audience to bind the attestation to"},"interaction":{"type":"object","description":"What the agent is about to do (type), and whether an approval is unlimited","properties":{"type":{"type":"string","enum":["native_transfer","token_transfer","token_approval","nft_approval","permit_signature","order_signature","message_signature","contract_call"]},"unlimited":{"type":"boolean"}},"required":["type"],"additionalProperties":false},"payment":{"type":"object","description":"The payment this check is for; the attestation is bound to it","properties":{"network":{"type":"string"},"pay_to":{"type":"string"},"amount":{"type":"string","pattern":"^\\d{1,78}$"},"asset":{"type":"string"},"resource":{"type":"string","maxLength":512,"pattern":"^https?://\\S+$"}},"additionalProperties":false},"transaction":{"type":"object","description":"An EVM transaction to simulate before it is signed ($0.005 per simulated item)","properties":{"from":{"type":"string","pattern":"^0x[0-9a-fA-F]{40}$"},"to":{"type":"string","pattern":"^0x[0-9a-fA-F]{40}$"},"value":{"type":"string","pattern":"^(0x[0-9a-fA-F]{1,64}|\\d{1,78})$"},"data":{"type":"string","pattern":"^0x([0-9a-fA-F]{2})*$"}},"required":["from"],"additionalProperties":false},"screening":{"type":"object","description":"The caller's own sanctions screening: recorded as asserted, it can only raise risk","properties":{"sanctions":{"type":"string","enum":["clean","flagged","unknown"]}},"required":["sanctions"],"additionalProperties":false},"authorization":{"type":"object","description":"The caller's pre-authorization: recorded as asserted, it can only raise risk","properties":{"pre_authorized":{"type":"boolean"},"source":{"type":"string","maxLength":128}},"required":["pre_authorized"],"additionalProperties":false}},"required":["wallet"],"additionalProperties":false}}},"required":["requests"],"additionalProperties":false},"example":{"requests":[{"wallet":"0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f","chain":"base","domain":"https://app.example-dapp.org","context":"Permit2 signature: unlimited USDC allowance to this spender","interaction":{"type":"permit_signature","unlimited":true}},{"wallet":"0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045","chain":"base"}]}}}},"responses":{"200":{"description":"The verdict, with its signed attestation","content":{"application/json":{"schema":{"type":"object","properties":{"results":{"type":"array","items":{"type":"object","properties":{"checked":{"type":"boolean"},"score":{"type":"integer","minimum":0,"maximum":100},"tier":{"type":"string","enum":["low","medium","high","critical"]},"categories":{"type":"array","items":{"type":"string"},"description":"The findings behind the verdict. A full evaluation lists the evaluated families \"intent_risk\" and \"behavioral\" first (present in every such verdict, not findings); a sanctions hit carries its own categories alone (\"sanctioned_address\", \"compliance_risk\"). Never rely on position: look for the hard-block categories anywhere in the list"},"evidence":{"type":"object"},"jws":{"type":"string","description":"ES256 attestation from did:web:x402check.xyz"},"checked_at":{"type":"string"},"expires_at":{"type":"string"}},"required":["checked"]}}},"required":["results"]}}}},"401":{"description":"A malformed credit token (Authorization: Bearer x402c_…); nothing is charged"},"402":{"description":"Payment Required: pay with x402 (the challenge lists every network), or send Authorization: Bearer x402c_… to pay from prepaid credits. Unpaid, a body that would be refused still gets the challenge, with the reason in request_error; it is never charged"},"403":{"description":"The paying wallet is on the OFAC SDN list (payer_sanctioned); nothing is charged"},"409":{"description":"This payment was already used (payment_already_used): sign a new one"},"413":{"description":"Body over 64 KiB or a batch over 25 items; nothing is charged"},"422":{"description":"Invalid request (with a payment or a credit token): the offending field is named, including an unknown field; nothing is charged"},"429":{"description":"Rate limited per IP (approximate, per Cloudflare location), a payer with too many payments in flight, or one whose recent payments did not settle; Retry-After says when"},"503":{"description":"The evaluation or the payment claims are unavailable, or the attestation key is not healthy; nothing is charged, retry"}}}},"/v1/credits":{"post":{"operationId":"buyCredits","summary":"Buy (or, with Authorization, top up) prepaid credits: a token for checks at $0.001","tags":["Credits"],"x-payment-info":{"price":{"mode":"dynamic","currency":"USD","min":"0.10","max":"100.00"},"protocols":[{"x402":{}}]},"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"amount_usd":{"type":"number","minimum":0.1,"maximum":100,"multipleOf":0.01}},"required":["amount_usd"]},"example":{"amount_usd":1}}}},"responses":{"200":{"description":"The token (shown once, on purchase) and the balance","content":{"application/json":{"schema":{"type":"object","properties":{"token":{"type":"string"},"credited_usd":{"type":"string"},"balance_usd":{"type":"string"}},"required":["balance_usd"]}}}},"402":{"description":"Payment Required: the pack price, on every network"},"422":{"description":"Invalid pack amount"}}}}}}