{"uid":"cap_axifgez2p7FvH0HYMPCWV","slug":"packages-melchiorlabs-com-npm-package-evidence-1494f5cf","name":"packages.melchiorlabs.com NPM Package Evidence","description":"Pay per request for a stable, citation-ready npm package evidence record: registry facts, integrity, and provenance over x402.","url":"https://packages.melchiorlabs.com/v1/npm/evidence","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"package":{"type":"string","maxLength":214,"description":"Public npm package name, scoped or unscoped, lowercase."},"version":{"type":"string","default":"latest","maxLength":64,"description":"Exact semver or dist-tag."},"nodeVersion":{"type":"string","maxLength":64,"description":"Exact stable semver; enables the node_engine_mismatch flag."}}},"responseSchema":{"type":"json","example":{"flags":["provenance_attestation_missing"],"digests":{"input":"…","result":"…"},"license":"MIT","requestId":"89416332-bc4e-43da-b0e2-32af08677d9e","limitations":["This report states public npm registry facts only; it does not certify that the package is safe, trustworthy, maintained, or free of vulnerabilities."],"distribution":{"integrity":"sha512-…","attestationUrl":null,"signatureCount":1},"repositoryUrl":"git+https://github.com/example/example.git","resolvedVersion":"2.19.0"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_IFXFyidesfU8osLPdiKAr","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a citation-ready evidence record for an npm package, including registry facts, integrity digests, license, repository URL, resolved version, and provenance attestation status.","exampleAgentPrompt":"Can you pull a citation-ready evidence record for the npm package 'lodash' at version 4.17.21 — I need the integrity hash, license, repository URL, and whether it has provenance attestation?","exampleUseCases":[{"title":"Audit trail for dependency review","prompt":"I need a stable, citable evidence record for the npm package 'express' version 4.18.2 — grab the integrity hash, license, resolved version, and provenance status so I can attach it to our dependency audit report."},{"title":"Verify open-source package before shipping","prompt":"Before we ship, can you check the npm package 'axios' at version 1.6.0 and tell me whether it has a provenance attestation, what its integrity digest is, and what license it's under?"},{"title":"Citation for security compliance documentation","prompt":"I need a citation-ready evidence record for 'chalk' version 5.3.0 from the npm registry — give me the repository URL, signature count, integrity hash, and any provenance flags so I can include it in our compliance docs."}],"resultDescription":"A JSON object containing the resolved version, license, repository URL, sha512 integrity digest of the package, attestation URL (if available), signature count, provenance flags (e.g. provenance_attestation_missing), a unique request ID, and a disclaimer about the scope of the report.","failureModes":["Package or version not found in the npm registry — returns an error indicating unresolvable package","Network or registry availability issues causing lookup failure","Invalid package name format causing a validation error","Provenance/attestation data unavailable, surfaced as a flag rather than a hard failure"],"whenToPreferThis":"Choose this endpoint when you need a stable, pay-per-request, citation-ready evidence record for an npm package — particularly for audit trails, compliance documentation, or software supply chain verification where a single authoritative snapshot of registry facts, integrity, and provenance status is required. Prefer this over scraping the npm registry directly when you need a structured, request-ID-backed artifact suitable for citation.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:37:21.550Z","isFirstParty":false}