{"uid":"cap_Vn1rGI1obYUlwOOAOguDN","slug":"agentstools-license-compliance-scanner-4530858f","name":"AgentsTools License Compliance Scanner","description":"License-compliance verdict for a whole dependency list or parsed manifest in one call. Accepts name-at-version strings, a parsed package.json, a requirements.txt list or go.mod imports, resolves each declared SPDX license, and returns a per-dependency plus aggregate verdict with the worst copyleft contamination point. Automated indicators, not legal advice.","url":"https://api.agentstools.dev/license/scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"ecosystem":{"enum":["npm","pypi","go","maven","cargo","nuget"],"type":"string","description":"Default ecosystem for entries without one"},"dependencies":{"type":"array","items":{"type":"string"},"description":"Dependencies as name, name-at-version, or ecosystem-prefixed"},"distribution":{"enum":["saas","binary","internal"],"type":"string","description":"How you ship it (default saas)"},"target_license":{"type":"string","description":"Your project SPDX license"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.15","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.15/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.15","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.15","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Wk-zt3W0H6iyFxcChe3it","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.15","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans a full dependency list or package manifest for SPDX license compliance and returns per-dependency plus aggregate copyleft contamination verdicts.","exampleAgentPrompt":"Scan these npm dependencies for license compliance — ['react@18.2.0', 'lodash@4.17.21', 'gpl-module@2.0.0'] — we're shipping a SaaS product under MIT and I need to know if any of them are copyleft problems.","exampleUseCases":[{"title":"Pre-release OSS license audit","prompt":"Before we release our SaaS app, can you check these Python packages for license issues — ['flask@3.0.0', 'sqlalchemy@2.0.0', 'gplv3-lib@1.0.0'] — we're under Apache-2.0 and distributing as SaaS?"},{"title":"Go module compliance check for enterprise","prompt":"We're shipping a binary to enterprise customers and need to know if our Go dependencies are safe — scan ['github.com/gorilla/mux@v1.8.0', 'github.com/agpl-project/core@v0.3.1'] for copyleft issues against our MIT license."},{"title":"New dependency vetting before merge","prompt":"A developer wants to add 'react-pdf@7.0.0' and 'pdfmake@0.2.9' to our npm project — can you check both for copyleft contamination before I approve the PR? We distribute as SaaS."}],"resultDescription":"Returns a per-dependency breakdown of resolved SPDX license identifiers and compliance verdicts, plus an aggregate verdict identifying the worst copyleft contamination point across all listed dependencies. Includes automated risk indicators but is not legal advice.","failureModes":["Unrecognized or unpublished package versions may fail to resolve a license","Ambiguous or dual-licensed packages may return uncertain verdicts","Ecosystem mismatch between declared ecosystem and actual package registry can cause lookup failures","Malformed dependency strings not matching name-at-version convention return validation errors","Non-SPDX or proprietary licenses may not be resolved and appear as unknown"],"whenToPreferThis":"Use this endpoint when you need a fast, automated, whole-manifest license compliance check across npm, PyPI, Go, Maven, Cargo, or NuGet ecosystems in a single API call, especially when you need per-dependency granularity plus an aggregate copyleft contamination verdict for CI/CD pipelines or pre-release audits.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T07:05:13.692Z","isFirstParty":false}