{"uid":"cap_d8KrVeDVeEbPMeuhLNeCJ","slug":"pkgproof-package-verification-8fb81f27","name":"pkgproof Package Verification","description":"One pkgproof package verification","url":"https://x402.pkgproof.net/v1/verify","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"name":{"type":"string","description":"Package name. ASCII only; homoglyph and Unicode-confusable names are refused before any upstream call."},"version":{"type":"string","description":"Optional. Omit to verify the package rather than one release."},"ecosystem":{"enum":["npm"],"type":"string","description":"npm is the only ecosystem this service verifies."}}},"responseSchema":{"type":"json","example":{"name":"left-pad","reasons":[{"code":"package_exists","kind":"fact","detail":"left-pad 1.3.0 is published on the npm registry.","source":"npm registry","verdict":"safe"},{"code":"no_known_advisories","kind":"fact","detail":"OSV lists no advisories for this version.","source":"osv.dev","verdict":"safe"}],"sources":{"osv.dev":"https://api.osv.dev","npm registry":"https://registry.npmjs.org"},"verdict":"safe","version":"1.3.0","ecosystem":"npm","checked_at":"2026-08-26T12:00:00Z"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_6F1Ry1GsRCcdiFsjAIQbN","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Verifies the authenticity and integrity of a software package, returning a proof-of-verification result for a single package lookup.","exampleAgentPrompt":"Can you verify that the npm package lodash version 4.17.21 is authentic and hasn't been tampered with — I need a pkgproof verification before I approve it for our production build?","exampleUseCases":[{"title":"Pre-deploy dependency integrity check","prompt":"Before we ship this release, verify that the Python package requests version 2.31.0 is authentic and shows a valid pkgproof integrity result — I don't want any supply chain surprises."},{"title":"CI pipeline package gating","prompt":"In our CI pipeline we're about to install express version 4.18.2 from npm — run a pkgproof verification on it and fail the build if the package doesn't come back clean."},{"title":"Security audit of third-party library","prompt":"We're auditing our dependencies and I need you to verify that the npm package axios version 1.6.0 has a valid proof of authenticity from pkgproof before I greenlight it for the team."}],"resultDescription":"Returns a verification result indicating whether the specified software package is authentic and its integrity is intact, including a proof status, any detected anomalies, and metadata about the verified package version.","failureModes":["Package not found in registry — returns not-found or unrecognized package error","Invalid or missing package version — endpoint may return validation error","Network or upstream registry unreachable — service may return a timeout or upstream error","Tampered or unverified package — returns a failed verification status rather than a positive proof","Malformed request payload — returns 400-level error for missing required fields"],"whenToPreferThis":"Use this endpoint when you need a paid, authoritative single-package integrity verification with a cryptographic or provenance proof — particularly in security-sensitive workflows like CI/CD pipelines, pre-deployment audits, or supply chain risk assessments where a simple checksum comparison is not sufficient and a trusted third-party attestation is required.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:35:27.673Z","isFirstParty":false}