x402 · USDC on Base

Check the payee before your agent pays.

Pay-per-call risk checks for AI agents that spend money: sanctions screening, domain age, and a clear allow, hold or block on every 402 challenge. No account, no API key. Your agent pays a cent and gets an answer.

  • Read-only: never holds your funds
  • No charge on our errors
  • Public data, refreshed daily
  • Every decision explains itself
  • On-chain verifiable payments
  • Open-source client (MIT)

How to verify each of these →

# 1. Unpaid call returns 402 with payment terms
GET /v1/check?domain=shop.example
→ 402 Payment Required  ($0.01 USDC, Base)

# 2. Agent pays with any x402 client, retries
→ 200 OK
{
  "risk": "medium",
  "flags": ["new_domain"],
  "domain": { "ageDays": 12, "hasA": true },
  "sanctions": { "address_match": null }
}

# Preflight a 402 challenge against your rules
POST /v1/preflight   allow hold block

How it works

Agents now pay for APIs, data and checkout on their own. SpendPreflight sits in front of that decision. It is read-only: it never signs, settles or holds funds.

Your agent hits a paywall

A service answers HTTP 402 with payment terms, or your agent builds a cart.

It asks SpendPreflight first

Send the challenge and your rules: caps, allowlists, new-domain threshold. We screen the payee and the domain.

It gets a decision and a receipt

Allow, hold for a human, or block, with plain reasons and a hashed receipt you can log.

Pricing

Per call, paid inline over x402 in USDC on Base. Requests that fail validation are not charged.

Payee check

GET /v1/check
$0.01 per call
  • Wallet address screened against the OFAC SDN list
  • Payee name matching, exact and possible
  • Domain registration age and DNS presence
  • Risk: low, medium, high, with flags

Spend preflight

POST /v1/preflight
$0.02 per call
  • Accepts x402 v1 and v2 challenges, or a cart
  • Your rules: per-payment max, hold threshold, daily cap
  • Network and asset checks (USDC only by default)
  • Allow, hold or block with reasons and a receipt

API

Open-source client guard: npm i spendpreflight · npm · GitHub (MIT, maintained by SpendPreflight).

Base URL https://api.spendpreflight.com. Use any x402-compatible client. Free endpoints: /, /health, /v1/sample, /v1/rules/default.

# Payee check (any combination)
GET /v1/check
  ?domain=merchant.com
  &address=0xPayeeWallet
  &name=Merchant%20LLC
# Spend preflight
POST /v1/preflight
{
  "challenge": { ...402 body... },
  "rules": {
    "max_per_payment_usd": 1,
    "hold_above_usd": 0.25,
    "daily_cap_usd": 25,
    "new_domain_days": 30,
    "domain_allowlist": ["api.trusted.com"]
  },
  "context": { "spent_today_usd": 3.10 }
}

Sanctions data comes from the public OFAC SDN list, refreshed daily; every response includes data_as_of. Informational screening only. Not legal advice, not a compliance certification, and not a guarantee. Verify matches before acting.

Use it from any AI assistant

SpendPreflight is a remote MCP server. Add one URL and your assistant gets three tools: check_payee, preflight_payment and get_service_info. The first 3 calls each day are free. After that each call is paid inline over x402, with no account and no API key.

https://api.spendpreflight.com/mcp

Claude, ChatGPT

Settings → Connectors → Add custom connector, then paste the URL above.

Cursor, Windsurf, VS Code

Add a remote MCP server to your MCP config:

{ "mcpServers": { "spendpreflight": {
  "url": "https://api.spendpreflight.com/mcp" } } }

Gemini CLI, Claude Code, others

Use any remote MCP option with the URL. For stdio-only clients:

npx mcp-remote https://api.spendpreflight.com/mcp

Your own agent (TypeScript)

Guard every x402 payment in-process, with free local rules and optional paid screening:

npm i spendpreflight

Custom GPTs, Gemini function calling and other OpenAPI tooling can import openapi.json directly.

For teams turning on agent spending

If you are about to let agents pay through x402, agent checkout or a company card, we can set up the policy layer with you: a written rule set, a receipt log, and a hold queue a person actually reviews.

Rule set

Merchant allowlists, amount caps and new-domain holds, written with your finance or ops owner.

Receipts

Every decision logged with a hash of what the agent saw, for audit and dispute.

Exception inbox

Holds go to a human. Nothing is auto-approved that your rules didn't allow.

Talk to us: contact@spendpreflight.com