{"_id":"402coffee-verify","name":"402coffee-verify","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"402coffee-verify","version":"0.1.0","description":"Gate payments on verified x402 agents. One free call to 402.coffee — check if a paying agent is certified safe (pays correctly, refuses over-priced scams, verifies the recipient). Zero dependencies.","type":"module","main":"index.js","types":"index.d.ts","bin":{"402coffee-verify":"bin/402coffee-verify.js"},"exports":{".":{"types":"./index.d.ts","import":"./index.js"},"./middleware":{"import":"./middleware.js"}},"engines":{"node":">=18"},"keywords":["x402","agent","payments","verification","trust","usdc","base","conformance","402.coffee"],"license":"MIT","homepage":"https://api.402.coffee/integrations","_id":"402coffee-verify@0.1.0","_nodeVersion":"24.16.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-1v1tajtoQeiagTcz2KN7bETiwEMiTDDZmAPZba0vabkyvqHQEP6snYnZ8YBOjgPSbyLhK4mZJPLZm0xkVp5YGA==","shasum":"39654e04771783f26daf002853ee17458d7d6a1a","tarball":"https://registry.npmjs.org/402coffee-verify/-/402coffee-verify-0.1.0.tgz","fileCount":6,"unpackedSize":17133,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDsV+YYbVlrqfOsRn6osHB0poIeM/P8PlzDzTiK+vpfbwIgRglLZDeE4o4BhSBREKBYfhmi/qESS2rg+9cd84H/79M="}]},"_npmUser":{"name":"englishdoggy","email":"ebookthe@gmail.com"},"directories":{},"maintainers":[{"name":"englishdoggy","email":"ebookthe@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/402coffee-verify_0.1.0_1783709333473_0.657567370054003"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-10T18:48:53.332Z","0.1.0":"2026-07-10T18:48:53.620Z","modified":"2026-07-10T18:48:53.811Z"},"maintainers":[{"name":"englishdoggy","email":"ebookthe@gmail.com"}],"description":"Gate payments on verified x402 agents. One free call to 402.coffee — check if a paying agent is certified safe (pays correctly, refuses over-priced scams, verifies the recipient). Zero dependencies.","homepage":"https://api.402.coffee/integrations","keywords":["x402","agent","payments","verification","trust","usdc","base","conformance","402.coffee"],"license":"MIT","readme":"# 402coffee-verify\n\nGate payments on **verified x402 agents**. One free call to [402.coffee](https://api.402.coffee/docs) tells you whether a paying agent holds a current certificate proving it pays correctly, refuses deliberately over-priced orders, and checks who it's paying — before you transact with it.\n\n- **Free** — the `/verify` check costs nothing. (An optional paid `/score` gives a decision-grade 0–100 risk number.)\n- **Zero dependencies**, Node 18+.\n- Composes with your existing trust/reputation stack: those tell you the counterparty was worth paying; this tells you the agent won't get swapped at signing.\n\n## Install\n\n```bash\nnpm install 402coffee-verify\n```\n\n## Library\n\n```js\nimport { verify, passesGate, verifyGate } from \"402coffee-verify\";\n\n// Raw status\nconst result = await verify(\"0xAGENT…\");\nresult.verified;                       // true = ≥1 current PASS, no current FAIL\nresult.capabilities.scam_resistance;   // { tested, result, fresh, expired, valid_until }\n\n// One-shot gate\nconst { ok } = await verifyGate(\"0xAGENT…\", {\n  require: [\"scam_resistance\", \"recipient_awareness\"], // must hold these\n  fresh: true,                                         // non-expired cert required\n});\nif (!ok) throw new Error(\"agent not certified safe\");\n```\n\n## CLI\n\n```bash\nnpx 402coffee-verify 0xAGENT… --require scam_resistance,recipient_awareness\n# exit 0 = pass, 1 = fail, 2 = usage/network error → drop straight into CI/scripts\n```\n\n## Middleware (Express)\n\n```js\nimport { requireVerifiedAgent } from \"402coffee-verify/middleware\";\n\n// Reads the wallet from the `x-agent-wallet` header (override with getWallet)\napp.post(\"/paid-endpoint\",\n  requireVerifiedAgent({ require: [\"scam_resistance\"], fresh: true }),\n  handler\n);\n```\n\n## Next.js App Router / hono / edge\n\n```js\nimport { guardAgent } from \"402coffee-verify/middleware\";\n\nexport async function POST(req) {\n  const wallet = req.headers.get(\"x-agent-wallet\");\n  const gate = await guardAgent(wallet, { require: [\"recipient_awareness\"] });\n  if (!gate.ok) return gate.response;   // ready 402 Response\n  // …serve the paid action…\n}\n```\n\n## Paid score (optional, $0.10)\n\n`/score` returns a deterministic 0–100 risk score with itemized on-chain evidence. It costs $0.10 in USDC on Base, so you must pass an **x402-paying fetch** (e.g. `wrapFetchWithPayment` from `@x402/fetch`) — with a plain fetch you get back the 402 payment terms, not a score.\n\n```js\nimport { score } from \"402coffee-verify\";\nimport { wrapFetchWithPayment } from \"@x402/fetch\";\n\nconst payingFetch = wrapFetchWithPayment(fetch, wallet);\nconst s = await score(\"0xAGENT…\", { fetchImpl: payingFetch });\n// s.score, s.tier, s.components, s.payment_history …\n```\n\n## What \"verified\" means\n\n`verified === true` only when the agent has **at least one current (non-expired) PASS and no current FAIL**. Certificates are valid for 30 days (behaviour drifts); require a fresh one for anything that matters. Every result 402.coffee returns is a fact it observed on-chain — never a subjective grade or a safety guarantee.\n\nDocs: <https://api.402.coffee/docs> · Test your own agent: <https://api.402.coffee/inspect>\n\nMIT © Agent Café / 402.coffee\n","readmeFilename":"README.md","_rev":"1-b7fd9f2dd53aa46a991cedff773791c6"}