HALOWERK sicherwerk
activeHALOWERK sicherwerk — bezahlte Endpunkte nach x402. Preise in USDC auf Base Mainnet.
- Transactions · 30d
- 0
- Volume · 30d
- $0.00
- Unique buyers · 30d
- 0
- Uptime · 30d
- 100.0%
- Latency p50
- 291ms
- Reported calls · 30d
- 17
Endpoints (22 live)
POST/v1/webhook-signature— Providers each build their signing string differently — some sign only the body, others prepend a timestamp, an id, or a version marker in a fixed order — and getting that order wrong produces a mismatch that looks exactly like an attack. This checks the signature the way the named provider actually specifies, with constant-time comparison, and returns the string that was signed so a mismatch can be debugged instead of guessed at. (0.002 USDC on Base)POST/v1/log-chain-verify— Recomputes every record hash from a canonical JSON representation of id, sequence, timestamp, previous_hash and payload, then checks that each record points to the hash of the record before it. If a root_hash is supplied, the same computed record hashes are folded into a deterministic binary Merkle tree with the last leaf duplicated on odd levels. (0.005 USDC on Base)POST/v1/oss-openssl-csr-self-signature-audit— Runs the pinned OpenSSL build against a submitted certificate request and answers two questions a registration authority has to settle before it signs anything: does the request carry a valid self-signature over its own body, and what exactly is being requested. The reply names the subject, the public key parameters and every requested extension as OpenSSL parses them, so a policy check compares against the parsed request rather than the text an applicant supplied. (0.002 USDC on Base)POST/v1/oss-openssl-public-key-math-audit— Takes a public key in SubjectPublicKeyInfo PEM form and runs the pinned OpenSSL build's own consistency checks over it, then reports the algorithm, the key size in bits and the parameters it found. This catches keys that parse but are structurally unusable: a modulus that is not a valid product, curve parameters that do not match a known group, a size that no longer meets the build's security level. The reported bit count comes from the key itself, not from the label a producer attached. (0.002 USDC on Base)POST/v1/oss-openssl-pkcs12-certificate-store-build— Builds a PKCS#12 container holding certificates only, for the common case where a runtime insists on PKCS#12 as its trust store format. The password is explicitly empty and reported back as such, so nothing depends on an undocumented default, and the reply states outright that the store contains no private keys. That matters: a PKCS#12 file is the usual carrier for a key, and a consumer must be able to tell a trust store from an identity store without opening it. (0.002 USDC on Base)POST/v1/oss-openssl-rfc3161-request-build— Produces a ready-to-post RFC 3161 TimeStampReq for a SHA-256 digest you already computed. The pinned OpenSSL build encodes the message imprint, adds a fresh nonce so a replayed response can be detected, and sets the flag that asks the timestamp authority to include its signing certificate in the reply. The result is returned as a binary artifact together with the imprint it was built around, so the caller can check that the request really covers the intended digest. (0.001 USDC on Base)POST/v1/oss-zip-archive-inventory-audit— Reads the central directory of a supplied ZIP archive with the pinned unzip build and reports what it would do if you unpacked it, without unpacking anything. Every entry is listed with its uncompressed size and method, and three specific hazards are named: paths that climb out of the target directory, names the archive repeats so that a later entry silently overwrites an earlier one, and a total uncompressed size far out of proportion to the archive. (0.002 USDC on Base)POST/v1/oss-gnupg-detached-signature-verify— Checks a detached OpenPGP signature against the bytes it claims to cover, using the pinned GnuPG build and nothing else. What comes back is the verdict in GnuPG's own terms, the fingerprint that actually signed, the signature timestamp, the algorithms used, and whether the key is expired or revoked. A wrong key, a tampered byte or a signature made by someone else each produce a distinct verdict rather than a bare false. (0.002 USDC on Base)POST/v1/oss-openssl-tls12-cipher-policy-expand— Takes a cipher policy in OpenSSL syntax and resolves it into the concrete list of TLS 1.2 cipher suites that the pinned build would actually offer, in the order it would offer them. This closes the gap between a policy string in a configuration file and what a server ends up negotiating: aliases expand, exclusions apply, and suites below the build's security level drop out silently in normal operation. Here they simply do not appear in the list, and the count says how many survived. (0.001 USDC on Base)POST/v1/oss-openssl-certificate-bundle-normalize— Accepts up to sixteen certificates in any PEM shape and returns a single normalized bundle. Duplicates are identified by their canonical DER encoding, not by the PEM text, so the same certificate supplied twice with different line wrapping, different header text or trailing whitespace collapses into one entry. The reply gives the input count, the unique count and the resulting bundle, which makes it usable as a preparation step before a trust store is built or shipped. (0.002 USDC on Base)POST/v1/oss-openssl-x509-purpose-evaluate— Reads the constraints inside a single certificate — basic constraints, key usage, extended key usage — and reports, per role, whether the certificate permits being used that way under the pinned OpenSSL build's rules. Roles covered are TLS client, TLS server, S/MIME signing and encryption, and timestamp signing. This answers the frequent confusion where a certificate is deployed for a purpose its own extensions forbid, and the failure only shows up as an opaque handshake error later. (0.001 USDC on Base)POST/v1/oss-openssl-asn1-structure-diagnose— Parses a definite-length binary artifact and returns every ASN.1 object it contains with its byte offset, nesting depth, header and content lengths, whether it is constructed, and the type as OpenSSL names it. This is the tool for the moment a certificate, key or signature is rejected with an unhelpful parse error and the question is which byte is wrong. Because offsets are exact, a diff against a known-good artifact localises the difference instead of describing it. (0.001 USDC on Base)POST/v1/oss-openssl-cms-envelope-encrypt— Wraps the supplied bytes in a CMS EnvelopedData envelope using the pinned OpenSSL build, addressed to every recipient certificate you pass in. A single content-encryption key protects the payload and is itself encrypted once per recipient, so any one holder of a matching private key can decrypt, and nobody else can. The reply names the cipher actually used and the recipient count, so an agent can record what it produced rather than assume it. (0.002 USDC on Base)POST/v1/oss-openssl-dh-group-check— Runs the pinned OpenSSL build's parameter checks over a supplied finite-field Diffie-Hellman group and reports whether it passes, along with the detail output that says why. The point is to catch parameters that are syntactically fine but cryptographically unsafe before they reach a handshake: a non-prime modulus, a generator of small order, a group below the build's security level. (0.003 USDC on Base)POST/v1/hash-reputation— Queries three abuse.ch metadata services for an MD5, SHA-1 or SHA-256 value. It reports known malware metadata, associated ThreatFox indicators, and URLhaus payload provenance, then derives a conservative known-malicious or unknown verdict. No endpoint for sample retrieval is called and no binary is downloaded. A missing record means unknown to these sources, not proven benign. VirusTotal is deliberately not used because its public terms do not permit redistribution in this paid product. (0.005 USDC on Base)POST/v1/provenance-verify— Searches the Sigstore Rekor log for entries matching an artefact hash and returns what a provenance claim is actually worth: the log index and inclusion time, the signing identity from the certificate, and where available the source repository and workflow reference that produced it. Several entries for one hash are all returned, because a rebuild or a second signer is a fact worth seeing rather than collapsing. (0.005 USDC on Base)POST/v1/tls-chain— Opens a TLS connection and reports the chain the server presents. Per certificate: subject and issuer, validity window with days remaining, serial, SHA-256 fingerprint, key type and size, and the subject alternative names. Above that it answers the questions a monitor asks: is the requested hostname covered by the leaf certificate including wildcard rules, how many days until the nearest expiry, is any certificate self-signed or signed with a weak algorithm, does the server send its… (0.002 USDC on Base)POST/v1/cve-check— Queries OSV.dev for a list of packages with versions across npm, PyPI, Go, Maven, crates.io, NuGet, RubyGems, Packagist and the Linux distributions. For each package it returns the vulnerabilities found with their identifiers, severity and summary, and the single figure that decides what to do next: the lowest version that fixes all of them, derived from the fixed-version events in the affected ranges. (0.005 USDC on Base)POST/v1/license-check— Looks up the declared licence of each package through deps.dev and sorts the result by the only question that matters for a closed, sold product: what does this licence demand. Permissive licences need attribution. Weak copyleft affects changes to the library itself. Strong copyleft can force disclosure of the whole work on distribution. Network copyleft such as AGPL and SSPL bites on operating the software as a service, which is the sharpest case for a paid API. (0.002 USDC on Base)POST/v1/container-inspect— Reads the manifest and config of an OCI or Docker image straight from the registry — a few kilobytes, never the layers, and the image is never run. Returns the digest, the platforms a multi-arch index covers, every layer with its size and the command that produced it, and the runtime configuration: entrypoint, command, working directory, exposed ports, volumes and environment variable names. (0.005 USDC on Base)
+2 more endpoints.
First seen · last seen