{"uid":"cap_0M2CVl2dMtp_38waXPEbY","slug":"scrapecheck-hash-verification-17379b6d","name":"ScrapeCheck Hash Verification","description":"Checksum tier (deterministic, no LLM): verifies the exact bytes served at a public URL hash to a claimed sha256, by independent double re-fetch. Use it to confirm a download or artifact matches its published checksum. Bodies up to 3 MB; dynamic pages return unverifiable, never a guess. sha256 only. First 100 checks per client are free: resend with header X-Use-Free-Allowance: yes and no payment to use them.","url":"https://scrapecheck.fly.dev/verify-hash","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","description":"public HTTPS URL"},"claim":{"type":"object","description":"see the route description; there is no asked field - this tier adjudicates exactly what it accepts"}}},"responseSchema":{"type":"json","example":{"engine":"web_field_v1/0.2.0+2ae28205cac4","key_id":"k2","reasons":["the body served at the URL hashes to the claimed sha256 (64 bytes, stable across two immediate fetches)"],"verdict":"pass","evidence":{"lens_votes":{},"refetched_at":"2026-08-28T00:00:00.000Z","refetch_excerpt":"sha256:92fa12e2…","second_fetch_at":"2026-08-28T00:00:01.000Z"},"signature":"ed25519:…","check_type":"url_hash_v1","confidence":0.95,"verdict_id":"00000000-0000-0000-0000-000000000000","source_hash":"sha256:…","verifier_url":"https://scrapecheck.fly.dev"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_kemaARqQV6huIfDvJN_Sl","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Independently re-fetches a public URL twice and verifies that the served bytes match a claimed SHA-256 checksum","exampleAgentPrompt":"Can you verify that the file at https://releases.example.com/app-v2.1.0.tar.gz actually hashes to sha256 abc123def456...? I want to confirm the bytes served right now match what the project published.","exampleUseCases":[{"title":"Software release integrity check","prompt":"Before I install this package, can you confirm that https://github.com/example/project/releases/download/v3.0/binary.tar.gz has a sha256 of e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855? I want to be sure the file hasn't been swapped out."},{"title":"Verifying a deployed artifact before deploy","prompt":"We're about to deploy from a build artifact at https://builds.internal.example.com/artifacts/service-v1.4.2.zip — please verify its SHA-256 is 9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a8 so we know it matches what CI published."},{"title":"Auditing a vendor-distributed file","prompt":"A vendor sent us a download link for https://vendor.example.com/sdk/sdk-latest.zip and claims its sha256 is 2c624232cdd221771294dfbb310acbc4a56ae0e. Can you independently fetch it twice and confirm whether that hash is correct?"}],"resultDescription":"A structured response indicating whether the bytes currently served at the given URL match the claimed SHA-256 hash, based on two independent fetches. Includes the actual computed hash, match status (true/false), and notes if the page is dynamic or the body exceeds the 3 MB limit (in which case verification is unverifiable rather than guessed).","failureModes":["URL is not publicly accessible or returns non-200 status — verification fails with an error","Response body exceeds 3 MB limit — endpoint returns unverifiable status, never a guess","Dynamic page content varies between the two fetches — returns unverifiable, not a match/no-match verdict","URL uses a non-HTTPS scheme — rejected as invalid input","SHA-256 hash format is malformed or uses an unsupported algorithm — request rejected","Network timeout or transient fetch error on one or both fetches — verification fails with error"],"whenToPreferThis":"Choose this endpoint when you need deterministic, tamper-evident confirmation that a specific public URL is currently serving bytes that match a known SHA-256 hash — for example, verifying software releases, build artifacts, or distributed files before installation or deployment. It is preferable over manual checksum tools when you need an independent double-fetch (not trusting a single download) and an auditable result. Use it when your content is static (not dynamically rendered) and under 3 MB. For verifying JSON field values, XML paths, redirects, or text presence on a page, use sibling ScrapeCheck tiers instead.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:39:39.655Z","isFirstParty":false}