One independent check before your agent signs a financial transaction.
Five readings about one payment: who you are paying, what the bytes actually do, what the seller published, whether the endpoint is still there, and what a policy makes of it. Each of those is free on its own. What is sold is the sixth thing, which is what they say about each other.
An agent that checks the counterparty and then signs has checked the wrong thing if the calldata pays somebody else. A policy that allows a payment has said nothing about whether the endpoint still serves the path. These are the comparisons, each one named by the two readings it sits between.
The bytes pay an address you never checked
the calldata · the address you asked about
A spotless counterparty record is about a party this transaction does not pay. Nothing in either reading alone can see it, and no reputation score prevents it.
An unlimited approval wearing the shape of a payment
the calldata · the amount you named
Not a payment at all: a standing permission that outlives the transaction. The amount you think you are sending is not the amount at risk.
The seller does not name the address the bytes pay
the seller's own listing · the calldata
Two claims by two different parties, and they disagree. Which one is wrong is not ours to say; that they disagree is.
The policy allowed, and the endpoint is not served
the policy · our unpaid handshake with the endpoint
The policy reads the counterparty record. A path that answers 404 is not a fact about the counterparty, and the two never meet.
This address has never been paid on this chain
the chain you named · where it has actually settled
The seller may accept both. Nothing we read says they do, and the listing agreeing on every other point is what makes this worth a look rather than a shrug.
The listing is old, and the endpoint now quotes something else
the catalogue's price · what the endpoint quoted when we last asked
Catalogue entries are written once and not revisited by their sellers. The live quote is the only thing that can contradict one.
A check is worth what its parts cover. Every share below is over a stated denominator, because a coverage figure without one says nothing: an endpoint nobody listed is not one we failed to probe.
542 of 53,205 catalogued endpoints asked, without paying, whether they are still there. 307 answered with their price.
nightly records. Separately, 218,597 addresses have been paid on the rails we read; the two count different things and are not divided into one another.
The transaction
transferWithAuthorization, approve, transfer. Anything else is refused rather than guessed at: decoding without the ABI means guessing where each argument begins.
Beside those: the seller’s own published price, payee and network for 53,205 endpoints, and 3,679 open vaults an allocate_capital check can be run against.
One request, per decision
Priced by the call over x402 at a cent, with no account and no commitment, so an agent can buy it itself. A monthly plan needs a person, a card and a key; an agent has none of those.
Machine-readable, with its reasons
A verdict your code can branch on, and beside it the comparisons that produced it, each naming the two readings that disagree. You can show your user why, not just what.
Testable before you trust it
Fifteen published cases you can run against us yourself, each asserting a property rather than a figure, so it does not rot. Nine of them describe answers we got wrong in production before we read the output.
POST /v1/check-action
x-api-key: …
{
"action": "pay",
"recipient": "0x…",
"chain": "base",
"asset": "0x8335…2913",
"amountUsd": 0.01,
"resource": "https://…",
"calldata": "0x…",
"policy": "conservative"
}Send calldata whenever you have it: it is what makes the strongest comparison possible. Everything is optional except a subject, and the parts you leave out are reported as not run rather than as passed. The five component readings are free on their own routes, listed in the API reference; this one needs a plan.