what-am-i-signing

unreachable

Deterministic pre-transaction safety tools for AI agents on Base + a live feed of freshly-detected malicious addresses (address-poisoning blocklist). No LLM, evidence-backed, USDC via x402.

Settled via Coinbase.

Transactions · 30d
0
Volume · 30d
$0.00
Unique buyers · 30d
0
Uptime · 30d
73.1%
Latency p50
47ms
Reported calls · 30d
5

Endpoints (25 live)

  • GET /v1/threats/recent — Live feed of freshly-detected malicious addresses on Base — address-poisoning seeders caught via zero-value transfer sprays, updated continuously by our on-chain collector. Poll ?since=<unix> to ingest only new threats into your agent's blocklist. Deterministic, evidence-backed, machine-readable. (0.005 USDC on Base)
  • POST /v1/listing-doctor — Why is my x402 service not listed — or listed but never paid? Send your endpoint URL; we fetch your 402 envelope, run the exact SDK validation the CDP facilitator runs, check catalog presence, and return per-check pass/fail with concrete fix hints. Includes two undocumented traps we verified against the live facilitator: a buyer must echo your bazaar extension into the settle payload, and a description over 500 characters makes the facilitator reject every payment. Deterministic, no LLM. (0.25 USDC on Base)
  • POST /v1/sign-decode — Decode an EVM signature request (EIP-712 typed data, Permit/Permit2, or ERC-20 approve calldata) into a structured intent: what token, which spender, how much, until when, plus risk_flags and an action_hint. Deterministic, no LLM. Answers an agent's question 'what am I about to sign?' (0.005 USDC on Base)
  • POST /v1/recipient-check — Pre-send safety check: is this recipient a known malicious address (caught live on Base seeding address-poisoning via zero-value transfer sprays), or a look-alike of an address you trust? Checks our continuously-updated threat DB + deterministic look-alike logic. Answers an agent's 'is it safe to send here?' before every transfer. (0.005 USDC on Base)
  • GET /v1/listing/watch — Is your x402 service still listed? The Bazaar removes resources that go without settlement, and no one tells you. We keep a daily snapshot of the whole catalog since June, so we can show whether your domain is present today, how its resource count moved day by day, and how long since each resource was last paid for. In our latest scan 620 of 2,147 domains are no longer present. Measured from our own snapshots. (0.01 USDC on Base)
  • GET /v1/revenue/scope — How much does your x402 service actually earn, and where does that put you among your peers? We measure real USDC inflows to every payTo address in the Bazaar catalog over 30 days and return the distribution. Pass ?domain=<yours> for your own revenue, calls, unique payers and percentile, plus the cohort of services in your price band. Omit it for the market distribution alone. Individual competitors are never listed. Measured, not estimated. (0.25 USDC on Base)
  • POST /v1/approval-risk — Audit standing ERC-20/Permit2 approvals for danger. Raw allowance lookups exist elsewhere; this is the risk layer: pass your current approvals and we rank which to revoke — unlimited allowance, unknown (non-registry) spender, or the classic drainer pattern (unlimited AND unknown). Deterministic, no LLM, no external calls. Answers an agent's question 'which of my approvals are dangerous?' (0.005 USDC on Base)
  • GET /v1/buyers/profile — Who actually pays you, and what else do they buy? We build the payer-to-service map across the whole Bazaar catalog from on-chain settlement, so we can tell you how many distinct agents paid you, how often each returns, and what share of your buyers also pay other x402 services. Pass ?domain=<yours>; omit for the market-wide buyer pool. Individual buyer addresses are never disclosed. (0.02 USDC on Base)
  • POST /v1/preflight — One-call pre-transaction guard for agents: bundle the transaction you're about to sign/send and get every applicable safety check in a single payment — signature-intent decode, live threat-DB + address-poisoning look-alike on the recipient, and a drainer audit of standing approvals. By design no combined safe/danger verdict is emitted; each sub-check's flags & evidence come back verbatim so your agent decides. Replaces 4 separate 402 round-trips with 1. Deterministic, no LLM. (0.02 USDC on Base)
  • POST /v1/address-poison-check — Before sending funds, check if the recipient is an address-poisoning look-alike. Give us the recipient and your known/intended addresses; we flag when the recipient shares the displayed head AND tail of one you know but differs in the middle — the exact signature of a poisoning attack that fools copy-paste. Deterministic, no LLM, no external calls. Answers an agent's question 'is this really the address I mean?' (0.005 USDC on Base)
  • GET /v1/payment/debug — Your 402 envelope can pass every static check and still not get you paid. We build a real signed payment at your listed price and submit it to the CDP facilitator verify endpoint, which checks signature, requirements and the on-chain transfer simulation. Nothing settles, so no money moves. You get back whether a real payment would be accepted, and if not, the facilitator own reason verbatim. Pass ?url= or ?domain=. (0.25 USDC on Base)
  • GET /v1/sales/gap — Listed, able to charge, and still not selling? We join the Bazaar catalog with measured on-chain revenue and report the median profile of the top fifth of earners, of everyone earning anything, and of those earning nothing, alongside your own. In our data the top fifth list 14 resources to the zero group one, and write 190-character descriptions to their 370. Correlations across services, not advice. ?domain=. (0.03 USDC on Base)
  • GET /v1/listing-doctor (free)
  • GET /v1/sign-decode (free)
  • GET /v1/market/pulse (0.02 USDC on Base)
  • GET /v1/catalog/changes (0.02 USDC on Base)
  • GET /v1/approval-risk (free)
  • GET /v1/recipient-check (free)
  • GET /v1/listing/visibility (0.02 USDC on Base)
  • GET /v1/infra/platform-health (0.02 USDC on Base)

+5 more endpoints.

First seen · last seen · last active