io.github.89rat/code402

code402

Discover machine-payable APIs, probe x402 payment terms, and run seller operations. Non-custodial.

1.0.1
Version
remote
Transport
24
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 24 tools scanned
  • metadata: scanned

No findings.

Tools (24)

  • crypto_ticker

    Spot USD price for a crypto ticker or CoinGecko id from public price feeds, cached 60 s. Result carries a signed receipt.

  • erc20_balance

    Raw and formatted ERC-20 balanceOf for an address on Base, with decimals read from the token. Result carries a signed receipt.

  • fx_spot_price_oracle

    Reference fiat and stablecoin conversion rate from a static table, not a live feed. Returns rate and inverse; result carries a signed receipt.

  • block_info

    Base block header: number, timestamp, transaction count and base fee for the latest or a given block. Result carries a signed receipt.

  • tx_activity

    Outbound transaction count (nonce) and contract-or-EOA check for an address on Base. Result carries a signed receipt.

  • token_contract_risk

    Deterministic Base contract facts: ERC-20 metadata, proxy slots, owner(), privileged-function selectors and flags. Not a safety verdict. Result carries a signed receipt.

  • clean_markdown_scraper

    Fetch a public web page by URL (or take your HTML) and return Markdown plus headings. No JavaScript rendering. Result carries a signed receipt.

  • context_distill

    Deterministic text digest: word count, top-5 most frequent meaningful words (stop words excluded), first sentence, and a keccak-256 content hash. Pure function — no external calls, no ML.

  • instant_json_schema_verifier

    Validate JSON data payloads against schema definitions. Preflighted for agent tool call pipelines.

  • balance_check

    Native ETH and one ERC-20 balance (default USDC) for an address on Base, raw and formatted. Result carries a signed receipt.

  • calculate_fx_savings

    Arithmetic comparison of a USDC settlement against comparator percentages YOU supply (bank_fee_pct, custodial_fee_pct) across 14 global fiat currencies. The comparators are assumptions, not measurements of any bank or provider; no protocol fee is deducted on this rail.

  • iban_check

    Validate IBAN structure and MOD-97 checksum. Does not establish account ownership, beneficiary identity or absence of fraud.

  • lei_check

    Validate a 20-character LEI and MOD-97 check digits. No registry lookup, active-registration check or legal-entity identity verification.

  • vat_mod97_check

    Check the supported Belgian VAT format and MOD-97 checksum. BE only; not VIES, other EU VAT formats, registration status or tax compliance.

  • swift_bic_check

    Check SWIFT/BIC structure and country code. Does not establish bank existence, active routing or beneficiary identity.

  • batch_validate

    Run up to 50 supported {tool, value} checks in one request. Each result states its scope. Compare the current batch quote with individual quotes; savings depend on batch size.

  • vendor_onboarding_pack

    Check supplied IBAN, LEI, Belgian VAT and UK company-number fields in one result. Structural checks only; no ownership, registry or fraud clearance.

  • india_supplier_check

    One call, one receipt: GSTIN + PAN + UPI VPA + IFSC for an Indian counterparty. Four deterministic structural checks, each stating its own scope. Built for cross-border procurement where the buyer is an agent that cannot open an INR account.

  • pre_disbursement_guard

    Evaluate supplied identifiers, domain-age evidence and mismatch signals. Requires a preceding receipt hash. An advisory result is not verified identity, fraud clearance or authorization to release funds.

  • gstin_check

    Validate an Indian GSTIN by structure (2-digit state code + PAN + entity code + 'Z') and its mod-36 cross-sum checksum.

  • ifsc_check

    Check the 11-character Indian IFSC format, including its fifth-character zero. No bank-branch registry lookup or account verification.

  • sanctions_address_screen

    Exact EVM-address comparison against the identified address snapshot and existing operator block policy. Current legal status is unknown; is_sanctioned is null. valid=false preserves a local block; valid=null never authorizes a transaction. Names are not screened. Missing, stale or incomplete evidence is explicit; no UN/EU coverage or sanctions clearance is provided.

  • check_price

    Instant zero-cost pricing hook for code402 tools. Returns the live price, an opaque quote_id, TTL, and the settlement URL. Free forever — feeds the price index into an agent planner's context without creating any financial obligation. If the planner acts on the quote, it hits the settlement_url with an EIP-3009 signed voucher.

  • receipt_verify

    Verifies a signed XDR-1 receipt from ANY x402 service: recomputes the canonical digest and recovers the signer, then compares it to the declared signer. Free forever — no account, no quota, no storage (stateless). A valid receipt proves the signer signed that tool call at that timestamp; it does NOT prove funds moved or any business claim.