{"uid":"cap_TYLnTrFt_z5ObrCwnCh8q","slug":"npm-package-health-supply-chain-metadata-snapshot-1b7781b0","name":"npm Package Health & Supply-Chain Metadata Snapshot","description":"Purchase: npm Package Health & Supply-Chain Metadata Snapshot","url":"https://api.the402.ai/v1/services/svc_f1d0e8843dad4e5e/purchase","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"type":"object","properties":{"job_id":{"type":"string"},"status":{"type":"string"},"thread_id":{"type":"string"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.021","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.021/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.021","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.021","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_4GQugvj2WjZEaVdjJH11n","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.021","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Purchases a health and supply-chain metadata snapshot for a given npm package, returning a job ID for async result retrieval.","exampleAgentPrompt":"Can you pull a health and supply-chain metadata snapshot for the npm package 'lodash' — I want to know if it's well-maintained, safe to use, and free of known supply-chain risks?","exampleUseCases":null,"resultDescription":"Returns a JSON object containing a job_id (string identifying the async job), status (current processing state), and thread_id (for tracking the request thread). The actual metadata snapshot is retrieved via a separate job-status endpoint using the job_id.","failureModes":["Payment failure: insufficient USDC balance or x402 payment rejected — results in 402 Payment Required","Invalid or non-existent npm package name — may return an error or empty snapshot","Service timeout if upstream npm registry or analysis pipeline is slow","Missing required parameters (e.g. no package name) — likely 400 Bad Request","Rate limiting or quota exceeded — 429 Too Many Requests"],"whenToPreferThis":"Choose this endpoint when you need structured, AI-ready npm package health and supply-chain metadata — including maintenance signals, dependency risk, and provenance info — as a paid data product via micropayment. Prefer this over manual npm registry scraping when you need aggregated, pre-analyzed health signals in a single call, or when operating inside an x402-capable agent framework that handles USDC micropayments automatically.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T16:28:49.351Z","isFirstParty":false}