# x402 Pay-Per-Call Micro-APIs for AI Agents > Live pay-per-call verification APIs for AI agents. No accounts, no API keys — > your agent pays per call in USDC on Base mainnet via the x402 protocol. > Field names in the examples below are exact; example values are illustrative. ## How to call 1. Call the endpoint with a JSON body. Without payment it returns `HTTP 402` + a `PAYMENT-REQUIRED` header describing the payment terms. 2. Pay with x402 v2: sign an EIP-3009 USDC transfer for the exact amount and retry the request with the `PAYMENT-SIGNATURE` header. Standard x402 client libraries handle this automatically. 3. Network: `eip155:8453` (Base mainnet). USDC has 6 decimals: $0.10 = 100000 atomic units. 4. Facilitator: `https://facilitator.xpay.sh` 5. Each API also serves machine-readable discovery: `GET /.well-known/x402` (price, network, input schema) and `GET /openapi.json` (full OpenAPI). Catalog last verified live: 2026-10-06. New APIs are appended as they ship. ## 1. sanctions-screen — $0.10 per call Endpoint: `POST https://agent-sanctions-screen.iykykblog.workers.dev/screen` What it verifies: person or entity name against three sanctions lists — OFAC SDN (US), EU FSF, UK FCDO (~32,099 entries / 81,005 name variants) — using normalized substring + fuzzy scoring. Optional `type` filter ("individual" | "entity" | "any") and `dob` year filter. Every response includes an audit receipt and list versions. Screening aid only, not legal advice. Example request: ```json {"name": "Acme Logistics Ltd", "type": "entity"} ``` Example response (no match): ```json { "query": "Acme Logistics Ltd", "normalized_query": "acme logistics ltd", "match": false, "match_count": 0, "matches": [], "lists_checked": ["ofac-sdn", "eu-fsf", "uk-fcdo"], "audit_receipt": { "receipt_id": "3f2b1c4d-...", "timestamp": "2026-10-06T15:20:00Z", "query": "Acme Logistics Ltd", "lists_checked": ["ofac-sdn", "eu-fsf", "uk-fcdo"], "match_count": 0, "network": "eip155:8453", "mode": "mainnet" }, "disclaimer": "Screening aid only, not legal advice. Normalized substring matching; confirm hits against official lists." } ``` When there is a hit, `matches` contains `{"list", "uid", "name", "matched_variant", "type", "programs", "dob"?, "match_score"}` entries. ## 2. entity-verify — $0.15 per call Endpoint: `POST https://agent-entity-verify.iykykblog.workers.dev/verify` What it verifies: that a US business entity exists and is in good standing. Exact + prefix match against Secretary of State bulk data (Oregon covered; more states being backfilled), returning entity name, ID, type, status, formation date, and registered agent. For names/states not in bulk data, falls back to a live GLEIF lookup. `GET /coverage` shows current state coverage. Example request: ```json {"name": "Nike, Inc.", "state": "OR"} ``` Example response: ```json { "query": {"name": "Nike, Inc.", "state": "OR"}, "normalized_name": "nike inc", "state_covered": true, "found": true, "record": { "source": "Secretary of State (OR)", "entity_name": "NIKE, INC.", "entity_id": "068338-94", "entity_type": "Foreign Business Corporation", "status": "Active", "formed_date": "1968-01-01", "registered_agent": {"name": "CT Corporation System", "city": "Salem", "state": "OR"} }, "audit_receipt": {"receipt_id": "…", "timestamp": "…", "network": "eip155:8453", "mode": "mainnet"} } ``` ## 3. domain-trust — $0.05 per call Endpoint: `POST https://agent-domain-trust.iykykblog.workers.dev/check` What it verifies: whether a domain looks trustworthy, from live signals — RDAP registration age, registrar, and status; DNS A / MX / TXT-SPF records via Cloudflare DNS-over-HTTPS; HTTPS reachability. Returns a 0–100 `trust_score` and a verdict: `likely_legitimate` (≥70), `caution` (40–69), or `high_risk` (<40). Trust aid only, not legal advice. Example request: ```json {"domain": "example.com"} ``` Example response: ```json { "domain": "example.com", "trust_score": 85, "verdict": "likely_legitimate", "signals": { "domain_age_years": 27.7, "registrar": "MarkMonitor Inc.", "has_a_record": true, "has_mx_record": true, "has_txt_spf": false, "https_reachable": true, "rdap_status": ["active", "client transfer prohibited"] }, "audit_receipt": {"receipt_id": "…", "timestamp": "…", "query": "example.com", "network": "eip155:8453", "mode": "mainnet"}, "disclaimer": "Trust aid only, not legal advice. Signals are heuristics; a high score does not guarantee legitimacy." } ``` ## 4. sec-lookup — $0.08 per call Endpoint: `POST https://agent-sec-lookup.iykykblog.workers.dev/lookup` What it verifies: company identity via live SEC EDGAR data. Send `query` (name), `ticker`, or `cik` (at least one required). Resolves to the 10-digit CIK, then returns the company profile (name, CIK, ticker, SIC + description, addresses) and the 10 most recent filings (form, filed date, accession number). Example request: ```json {"ticker": "AAPL"} ``` Example response: ```json { "query": "AAPL", "company": { "name": "Apple Inc.", "cik": "0000320193", "ticker": "AAPL", "sic": "3571", "sic_description": "Electronic Computers" }, "filings": [ {"form": "10-Q", "filed": "2026-07-31", "accession": "0000320193-26-000074"}, {"form": "4", "filed": "2026-08-05", "accession": "0000320193-26-000081"} ], "audit_receipt": {"receipt_id": "…", "timestamp": "…", "network": "eip155:8453", "mode": "mainnet"} } ``` ## 5. debarment-check — $0.12 per call Endpoint: `POST https://agent-debarment-check.iykykblog.workers.dev/check` What it verifies: whether a contractor is excluded from US federal contracting, by screening `name`, `uei` (12-char), and/or `cage` (at least one required) against SAM.gov federal exclusions (KV-backed public bulk data). Returns exclusion type, program, dates, and terminating agency with an audit receipt. `GET /coverage` shows dataset status. Screening aid only, not legal advice — verify against official SAM.gov. Example request: ```json {"name": "Acme Construction Co"} ``` Example response (clear): ```json { "query": "Acme Construction Co", "excluded": false, "match_count": 0, "matches": [], "audit_receipt": { "receipt_id": "…", "timestamp": "…", "data_source": "SAM.gov Exclusions", "network": "eip155:8453", "mode": "mainnet" }, "disclaimer": "Screening aid only, not legal advice. Verify against official SAM.gov." } ``` When excluded, `matches` contains `{"name", "uei"?, "cage"?, "exclusion_type", "exclusion_program", "exclusion_date", "termination_date", "terminating_agency", "match_via", "match_score"?}` entries. ## 6. drug-verify — $0.10 per call Endpoint: `POST https://agent-drug-verify.iykykblog.workers.dev/verify` What it verifies: FDA drug products from the public NDC Directory. Send `ndc` (digits, e.g. "0093-0058") for an exact lookup or `name` (min 3 chars) for a trigram-index product-name search. Returns product details plus an audit receipt. Informational only, not medical advice. Example request: ```json {"name": "lisinopril"} ``` Example response: ```json { "query": "lisinopril", "found": true, "products": [ { "ndc": "0093-0058", "product_name": "Lisinopril", "brand_name": "Zestril", "labeler": "Teva Pharmaceuticals USA, Inc.", "dosage_form": "TABLET", "route": "ORAL", "marketing_status": "Prescription", "approval_date": "2001-06-19", "marketing_end_date": null } ], "audit_receipt": { "receipt_id": "…", "timestamp": "…", "query": "lisinopril", "product_count": 1, "data_source": "FDA NDC Directory", "data_as_of": "2026-10-06", "network": "eip155:8453", "mode": "mainnet" }, "disclaimer": "Informational only, not medical advice. Verify against official FDA sources." } ``` ## Payment details (all APIs) - Protocol: x402 v2. Unpaid → `402` + `PAYMENT-REQUIRED`. - Pay-to address (also stated in each live 402 challenge): `0x0764bD4B56340EA0Aa05b94029329945fBddE1aa` - Facilitator: `https://facilitator.xpay.sh` - Atomic amounts (USDC, 6 decimals): $0.05 = 50000, $0.08 = 80000, $0.10 = 100000, $0.12 = 120000, $0.15 = 150000. ## Discoverability - This catalog: `https://x402-agent-apis.pages.dev/llms.txt` - Per-API discovery: `GET /.well-known/x402` and `GET /openapi.json` on each endpoint host above. - Registered on x402scan (public x402 directory). ## Changelog - 2026-10-06: catalog created with 6 live APIs (sanctions-screen, entity-verify, domain-trust, sec-lookup, debarment-check, drug-verify). All six verified live same day (/health 200 + unpaid 402 paywall active).