{"uid":"cap_AzQwJJrhUVzeHUCAXVrVx","slug":"netintel-rpki-route-origin-validator-3a11cbf9","name":"NetIntel RPKI Route-Origin Validator","description":"RPKI Route-Origin Validation for an IPv4 prefix and origin AS, computed per RFC 6811 from the bulk Validated ROA Payload set. Returns the ROA status, the covering ROA count and the matching ROAs with their origin, max length and trust anchor.","url":"https://payai.agentstools.dev/netintel/rpki","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","required":["prefix"],"properties":{"origin":{"type":"string","description":"Optional origin AS number; if omitted it is resolved from the IP-to-ASN table"},"prefix":{"type":"string","description":"Public IPv4 prefix in CIDR form or a bare address"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.008","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.008/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_HVjruIvN01P2PLZFXDrdL","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.008","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates whether an IPv4 prefix and origin AS pair is covered by a valid Route Origin Authorization (ROA), returning RFC 6811 RPKI status, covering ROA count, and matching ROA details.","exampleAgentPrompt":"Can you check the RPKI validation status of the prefix 1.1.1.0/24 with origin AS13335 — tell me if it's valid, how many ROAs cover it, and what the matching ROA details and trust anchors are?","exampleUseCases":[{"title":"BGP route hijack investigation","prompt":"I'm seeing a suspicious BGP announcement for 8.8.8.0/24 from AS15169 — can you run an RPKI route-origin validation on that prefix and origin AS and tell me if it's valid, invalid, or not found?"},{"title":"Network operator ROA compliance check","prompt":"We just set up a new ROA for our prefix 203.0.113.0/24 with origin AS64500 — can you validate it against the current RPKI data to confirm our ROA is covering the prefix correctly and what trust anchor it's anchored to?"},{"title":"Security audit of upstream provider routes","prompt":"I need to audit whether the route 45.33.32.0/21 announced by AS63949 is RPKI-valid — can you check the ROA status, how many ROAs cover it, and list the matching ROA details?"}],"resultDescription":"Returns the RFC 6811 RPKI validation state (valid, invalid, or not-found) for the queried prefix-origin pair, the number of ROAs that cover the prefix, and a list of matching ROAs each containing the authorized origin AS, maximum prefix length, and the trust anchor (e.g. ARIN, RIPE, APNIC).","failureModes":["Invalid CIDR notation or non-public IP prefix returns an error","Unknown or private ASN may yield no matching ROAs (not-found status)","If origin AS is omitted and IP-to-ASN resolution fails, validation may be incomplete","Stale VRP dataset could cause mismatch with live RPKI state","Non-IPv4 (IPv6) prefixes may not be supported"],"whenToPreferThis":"Choose this endpoint when you need fast, standards-compliant RFC 6811 RPKI route-origin validation for a specific IPv4 prefix — especially when you need covering ROA details including trust anchors. Prefer over raw RPKI lookups when you want both the validation verdict and full matching ROA metadata in a single call without maintaining your own VRP dataset.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T07:12:14.029Z","isFirstParty":false}