---
name: enclave402
description: Pay-per-call x402 gateway on Base (USDC). Use before an agent pays an unknown x402 seller: a signed pay/caution/avoid verdict from a continuous census of every Bazaar-indexed endpoint. Also market signals, IPFS pinning, EIP-712 attestations, cheap compute.
homepage: https://enclave402.com
license: see repository
---

# enclave402 — agent integration in one file

> Read this once. Everything an agent needs to call this gateway is below: no account, no API key, one HTTP round-trip per paid call, settled in USDC on Base via x402 v2. Failed calls are never charged.

## 1. Add the MCP server (Claude Code / Cursor / any MCP client)

```json
{
  "mcpServers": {
    "enclave402": {
      "type": "streamable-http",
      "url": "https://enclave402.com/mcp"
    }
  }
}
```

Tool list: `POST https://enclave402.com/mcp` `{"jsonrpc":"2.0","id":1,"method":"tools/list"}`. Paid tool calls carry the x402 payment in `_meta` (@x402/mcp).

## 2. The check to run before any x402 payment

**GET /api/census/verdict** — $0.002 USDC. Signed pay/caution/avoid verdict for any Bazaar-indexed x402 resource or payTo, from the continuous census; bulk feed for routers.

```
GET https://enclave402.com/api/census/verdict?resource=https://seller.example/api/route
```

Response (paid): `{ mode, items:[{ resource, payTo, verdict: "pay"|"caution"|"avoid", score, checkedAt, attestation }], total, census }`. Policy that most agents use: proceed on `pay`, log on `caution`, throw on `avoid`.

On-demand deep probe of one seller instead of the census read: **GET /api/seller/vet** — $0.010 USDC.

## 3. Try it free first

- `X-Agent-Dry-Run: true` on any route returns a schema-shaped sample at no cost.
- `X-Payment-Address: <your wallet>` grants a small free quota on read routes.

## 4. Pay (x402 v2, exact scheme)

1. Call the route with no payment header → HTTP 402 + `PAYMENT-REQUIRED` (base64 JSON: x402Version 2, accepts[{scheme exact, network eip155:8453, amount, asset, payTo, maxTimeoutSeconds}]).
2. Sign an EIP-3009 `transferWithAuthorization` (EIP-712) for that amount to `payTo`; base64 it into the `Payment-Signature` header; repeat the call.
3. Receipt comes back in `PAYMENT-RESPONSE` (transaction, network, payer). Settlement runs after the handler and is canceled on any non-2xx — you never pay for an error.

Network `eip155:8453` · asset USDC `0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913` · payTo `0xbeF3e7CFd486C14dD8c3aA5911134bF361B973C5`. Any x402 client library (@x402/fetch, x402-axios, coinbase-agentkit) does steps 1–3 automatically.

## 5. Verify a verdict offline

Every verdict and attestation carries an EIP-712 signature by the attestor `0xd1AD5880971f2263d473d908174f8f5375ac19aD`. The response includes `eip712: { domain, types, primaryType, message }`; recover the signer with any EIP-712 library (ethers `verifyTypedData`) and compare to the attestor address published at `https://enclave402.com/.well-known/x402`. Do not trust the score without checking the signature.

## 6. All paid routes

### GET /api/market/signal — $0.010 USDC
Polymarket signal plus fields the free listing does not have: 1h and 6h probability deltas, 24h realized volatility, and whale flow from the trade tape (net YES notional, largest print, whale count, flow label). Plus prices, bid/ask, spread, 24h change, momentum, volume, liquidity. MUST be invoked when an agent needs where a market is MOVING, not just where it is. Do NOT use for spot prices or order execution. Settles $0.010 USDC on Base; no charge on failure.

Input: `{"type":"object","properties":{"slug":{"type":"string","pattern":"^[a-z0-9-]{3,200}$","maxLength":200,"description":"Optional Polymarket market slug for one specific market. Omit to receive the top markets by 24h volume.","examples":["will-there-be-no-change-in-fed-interest-rates-after-the-october-2026-meeting-20260617190324031"]},"limit":{"type":"integer","minimum":1,"maximum":10,"default":5,"description":"Number of top markets to return when slug is omitted."}},"required":[],"additionalProperties":false}`

### POST /api/storage/pin — $0.008 USDC
Store a JSON document (object or string, up to 8 KB) on IPFS through a managed pinning service and return its content identifier (CID v1) plus an HTTP gateway URL. MUST be invoked when an agent needs durable, content-addressed storage for memory, decisions, artifacts or metadata that other agents can fetch by CID. Do NOT send raw binary, files over 8 KB, or an existing CID to re-pin. Settles $0.008 USDC via x402 on Base; failed or unavailable pins are never charged.

Input: `{"type":"object","properties":{"content":{"type":["object","string"],"description":"JSON object or string to store (serialized size up to 8 KB).","examples":[{"agent":"planner-1","decision":"hold","at":1789650000}]},"name":{"type":"string","maxLength":120,"description":"Optional human label stored with the pin."}},"required":["content"],"additionalProperties":false}`

### POST /api/agent/attest — $0.040 USDC
EIP-712 signed, timestamped attestation binding an agentId, the keccak256 digest of a declared state, and the paying wallet; attestor key at /transparency, verify offline with ethers.verifyTypedData. MUST be invoked when an agent needs third-party, non-repudiable proof that a state or decision existed at a point in time (audit trails, hand-offs, escrow). Do NOT use for hardware TEE, zk proofs or on-chain EAS. Settles $0.040 USDC via x402 on Base; no charge on failure.

Input: `{"type":"object","properties":{"agentId":{"type":"string","minLength":1,"maxLength":200,"description":"Stable identifier or EVM address of the agent being attested.","examples":["agent-0x402-1","did:web:example.com:agents:planner"]},"state":{"type":"string","maxLength":8192,"description":"Serialized state, decision, or payload hash to bind. Hashed with keccak256(utf8); the raw string is never stored.","examples":["{\"task\":\"rebalance\",\"decision\":\"hold\",\"at\":1789650000}"]}},"required":["agentId"],"additionalProperties":false}`

### GET /api/seller/vet — $0.010 USDC
Vet an x402 seller before paying it: probes its live 402, reads its CDP Bazaar entry (payers, calls, last call, repeat vs evaluation usage), checks trust surfaces, returns a scored LIVE/STALE/UNLISTED/MISCONFIGURED/UNREACHABLE verdict and what changed since our last check, signed by our attestor. MUST be invoked before a first payment to an unknown resource, or on a schedule to watch it. Do NOT use to pay it. Settles $0.010 USDC; no charge on failure.

Input: `{"type":"object","properties":{"resource":{"type":"string","pattern":"^https://","maxLength":2048,"description":"Absolute https URL of the x402 resource to vet (the paid route itself, not the seller homepage).","examples":["https://seller.example/api/route"]},"method":{"type":"string","enum":["GET","POST"],"default":"GET","description":"HTTP method the resource expects; POST resources are probed with an empty JSON body."}},"required":["resource"],"additionalProperties":false}`

### GET /api/market/verdict — $0.020 USDC
Rule-based verdict on one Polymarket market by slug: YES/NO/TOSS_UP lean, 0-100 confidence with every reason stated (price distance, liquidity, volume, spread, momentum), days to resolution, and an EIP-712 attestation so an agent can prove what it read and when. Not a forecast model. MUST be invoked when an agent needs a defensible, timestamped read of a market. Do NOT use to discover markets (use market/signal). Settles $0.020 USDC; no charge on failure.

Input: `{"type":"object","properties":{"slug":{"type":"string","pattern":"^[a-z0-9-]{3,200}$","maxLength":200,"description":"Polymarket market slug (get one from market/signal).","examples":["will-there-be-no-change-in-fed-interest-rates-after-the-october-2026-meeting-20260617190324031"]}},"required":["slug"],"additionalProperties":false}`

### GET /api/census/verdict — $0.002 USDC
Pre-spend check from the seller census: each Bazaar-indexed resource is re-probed periodically (liveness, 402-envelope compliance, declared output schema, latency, usage) and mapped to pay | caution | avoid with an EIP-712 signature a router checks offline. Query one resource, a payTo, or page the feed by verdict. MUST be invoked before dispatching to an unknown seller. Do NOT use to probe on demand (see /api/seller/vet). Settles $0.002 USDC; no charge on failure.

Input: `{"type":"object","properties":{"resource":{"type":"string","pattern":"^https://","maxLength":2048,"description":"Absolute https URL of one x402 resource."},"payTo":{"type":"string","pattern":"^0x[a-fA-F0-9]{40}$","description":"EVM payee address; returns every assessed resource paid to it."},"verdict":{"type":"string","enum":["pay","caution","avoid"],"description":"Bulk feed filter (used when neither resource nor payTo is given)."},"limit":{"type":"integer","minimum":1,"maximum":500,"default":100,"description":"Bulk feed page size."},"offset":{"type":"integer","minimum":0,"default":0,"description":"Bulk feed page offset."}},"additionalProperties":false}`

### GET /api/census/export — $3.500 USDC
Whole-Bazaar seller census in one payload: every fresh verdict row (resource, payTo, verdict, score, schema, latency, checkedAt, per-row signature) plus a sha256 manifest and one EIP-712 attestation over it, so a router verifies the full dump offline. MUST be invoked when an agent needs the complete trust map for routing or analytics. Do NOT use for a single lookup (see /api/census/verdict). Settles $3.500 USDC; no charge on failure.

Input: `{"type":"object","properties":{"includeStale":{"type":"boolean","default":false,"description":"Include rows older than the verdict TTL."}},"additionalProperties":false}`

### POST /api/compute/hash — $0.001 USDC
Deterministic hashing of arbitrary input: SHA-256, SHA-384, SHA-512, HMAC-SHA256, PBKDF2, scrypt. Returns hex digest. MUST be invoked when an agent needs a cryptographic hash or key derivation. Do NOT use for encryption or signing. Settles $0.001 USDC; no charge on failure.

Input: `{"type":"object","properties":{"algorithm":{"type":"string","enum":["sha256","sha384","sha512","hmac-sha256","pbkdf2","scrypt"],"description":"Hash algorithm"},"input":{"type":"string","maxLength":100000,"description":"Data to hash (UTF-8 string)"},"key":{"type":"string","maxLength":1000,"description":"Key for HMAC/PBKDF2/scrypt (required for keyed algorithms)"},"encoding":{"type":"string","enum":["hex","base64"],"default":"hex","description":"Output encoding"}},"required":["algorithm","input"],"additionalProperties":false}`

### POST /api/compute/encode — $0.001 USDC
Encoding and decoding utility: base64 encode/decode, hex encode/decode, URL encode/decode, JWT decode (no verification), JSON stringify/parse. MUST be invoked when an agent needs format conversion. Do NOT use for cryptographic operations (use compute/hash). Settles $0.001 USDC; no charge on failure.

Input: `{"type":"object","properties":{"operation":{"type":"string","enum":["base64-encode","base64-decode","hex-encode","hex-decode","url-encode","url-decode","jwt-decode","json-stringify","json-parse"],"description":"Operation to perform"},"input":{"type":"string","maxLength":500000,"description":"Data to encode/decode"}},"required":["operation","input"],"additionalProperties":false}`

### POST /api/compute/search — $0.005 USDC
Web search returning ranked results with title, URL, description, and source domain. MUST be invoked when an agent needs current web information. Returns up to 10 results. Do NOT use for cached/static data lookups. Settles $0.005 USDC; no charge on failure.

Input: `{"type":"object","properties":{"query":{"type":"string","maxLength":500,"description":"Search query"},"limit":{"type":"integer","minimum":1,"maximum":10,"default":5,"description":"Max results to return"}},"required":["query"],"additionalProperties":false}`

### POST /api/compute/infer — $0.003 USDC
Cheap small-model text completion for agent sub-tasks: classify, extract, summarize, rewrite. MUST be invoked when an agent needs a short LLM answer without paying flagship rates. Prompt <=8000 chars, maxTokens <=1024, json:true forces a JSON object. Do NOT use for long-form generation or tool calling. Settles $0.003 USDC; no charge on failure.

Input: `{"type":"object","properties":{"prompt":{"type":"string","maxLength":8000,"description":"User prompt","examples":["Classify the sentiment of: \"the settlement was fast and cheap\". Reply with one word."]},"system":{"type":"string","maxLength":2000,"description":"Optional system instruction"},"maxTokens":{"type":"integer","minimum":1,"maximum":1024,"default":256},"json":{"type":"boolean","default":false,"description":"Force a JSON object response"}},"required":["prompt"],"additionalProperties":false}`

### POST /api/audit/host — $25.000 USDC
Full audit of one host's x402 surface from the continuous census: every assessed endpoint with its pay|caution|avoid verdict, score, and each finding code mapped to severity, business impact and the exact fix, under an EIP-712 attestation. MUST be invoked before remediating a host you own or are evaluating. Do NOT use for a single pre-spend verdict (see /api/census/verdict). Settles $25.000 USDC; no charge on failure; prepaid credit is drawn down first.

Input: `{"type":"object","properties":{"host":{"type":"string","maxLength":253,"description":"Domain or https URL, e.g. \"example.com\" or \"https://example.com/api/x\"."}},"required":["host"],"additionalProperties":false}`

### POST /api/audit/portfolio — $150.000 USDC
The host audit across up to 50 hosts as one signed corpus: per-endpoint verdicts, finding codes and remediation, roll-up totals and a 30-day recheck date, under one EIP-712 attestation. MUST be invoked when routing spend across many sellers at once. Do NOT use for a single host (see /api/audit/host). Settles $150.000 USDC; no charge on failure; prepaid credit is drawn down first.

Input: `{"type":"object","properties":{"hosts":{"type":"array","minItems":1,"maxItems":50,"items":{"type":"string","maxLength":253},"description":"Domains or https URLs; duplicates are collapsed and the list is capped at 50."}},"required":["hosts"],"additionalProperties":false}`

### GET /api/census/license — $300.000 USDC
Everything /api/census/export returns, plus the right to redistribute it in your own product and refreshed dumps for 30 days. One manifest digest and one EIP-712 attestation verify the whole corpus offline. MUST be invoked when you need the corpus rather than a lookup. Do NOT use for a single resource verdict (see /api/census/verdict). Settles $300.000 USDC; no charge on failure; prepaid credit is drawn down first.

Input: `{"type":"object","properties":{"includeStale":{"type":"boolean","default":false,"description":"Include rows past the freshness window."}},"additionalProperties":false}`

### POST /api/credit/block — $50.000 USDC
Buy one prepaid block of $50.000 credit, held against the paying wallet address - no account, no API key. Audits and the census licence spend it automatically before requesting any new settlement; check any balance free at GET /api/credit/balance. MUST be invoked before a run of audits to avoid per-call settlement. Do NOT use on a free or dry-run call, which has no payer to credit. Settles $50.000 USDC; no charge on failure.

Input: `{"type":"object","properties":{},"additionalProperties":false}`

## 7. Other machine surfaces

- OpenAPI 3.1: https://enclave402.com/openapi.json
- x402 manifest: https://enclave402.com/.well-known/x402
- Full spec: https://enclave402.com/llms-full.txt
- Public census (free, HTML): https://enclave402.com/census
- Transparency: https://enclave402.com/transparency
- Errors (RFC 9457, one remedy each): https://enclave402.com/errors

