{"uid":"cap_O9G7L7PNO7Ry_DZUdq0Qh","slug":"dependency-truth-npm-pypi-version-verifier-e7665d43","name":"Dependency Truth – npm/PyPI Version Verifier","description":"Deterministic package, repository, security, and citation evidence APIs payable per call with x402.","url":"https://dependency-truth.inboxtzdjqv.workers.dev/v1/dependency-truth?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"package":{"type":"string","description":"Exact package name"},"ecosystem":{"enum":["npm","pypi"],"type":"string","description":"Package registry"},"claimedDate":{"type":"string","description":"Optional YYYY-MM-DD publication claim to check"},"claimedVersion":{"type":"string","description":"Optional version claim to check"}}},"responseSchema":{"type":"json","example":{"claim":{"version":"5.1.0","dateCurrent":null,"publishedDate":null,"versionCurrent":true},"flags":[],"yanked":false,"package":"express","ecosystem":"npm","fetchedAt":"2026-09-20T12:00:00.000Z","deprecated":null,"publishedAt":"2025-03-31T14:24:25.696Z","stableVersion":"5.1.0","provenanceUrls":["https://www.npmjs.com/package/express","https://registry.npmjs.org/express"]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_RlmNgeS593L21KLccwaWL","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches the current stable release of an npm or PyPI package and validates a claimed version or publication date against live registry metadata.","exampleAgentPrompt":"Can you verify whether express 5.1.0 is the current stable npm release, and check if it was actually published on 2025-03-31?","exampleUseCases":[{"title":"Validate AI-generated dependency suggestions","prompt":"My AI coding assistant told me to use requests 2.31.0 for Python — can you check if that's actually the current stable PyPI version or if something newer is out?"},{"title":"Audit requirements file before deployment","prompt":"We're about to deploy and I want to confirm that fastapi is still at version 0.111.0 on PyPI and hasn't been yanked or deprecated — can you check?"},{"title":"Fact-check a blog post package claim","prompt":"I read a tutorial that says lodash 4.17.21 is the latest npm release — can you verify that's still the current stable version and confirm when it was published?"}],"resultDescription":"Returns a JSON object with the current stable version, its publication timestamp, whether the package is deprecated or yanked, a claim object indicating whether the supplied version and/or date match registry truth, any warning flags, and direct provenance URLs to the npm or PyPI registry pages for audit.","failureModes":["Package not found in the specified ecosystem returns an error or null stable version","Misspelled package name yields no match","Unsupported ecosystem value (anything other than 'npm' or 'pypi') fails schema validation","Registry is temporarily unavailable causing a fetch timeout","Scoped npm package names (e.g. @scope/pkg) may require exact formatting"],"whenToPreferThis":"Choose this endpoint when you need to programmatically verify whether a specific npm or PyPI package version claim is accurate against live registry data — especially in CI pipelines, AI agent tool-use, documentation audits, or supply-chain checks. Prefer it over manual registry lookups when you also need a structured claim-validation result (versionCurrent, publishedDate match) rather than just browsing the registry. It is ideal when the agent must confirm facts about a dependency without relying on potentially stale training data.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:48:47.452Z","isFirstParty":false,"canonicalSlug":"dependency-truth-npm-pypi-version-verifier-e7665d43"}