SCVD General Store API

The HTTP contract for scvd.store: 196 operations on 180 paths (OpenAPI 3.1.0, every operation with a unique operationId and summary) covering the free x402 instruments (POST /api/preflight/v1 and /v2, /api/look/v1, /api/before-you-pay/v1, /api/conformance/v1, /api/a2a/check, /api/bot-auth/check, /api/onpage/v1, GET /api/verify/{id}), the 35 x402-paid doors at GET /api/buy/{item} (402 with PAYMENT-REQUIRED terms, Idempotency-Key on every one), the signed corpus and datasets (corpus.json, ledger, doors, fresh-set, defects, passports), purchase recovery and refunds, the reseller trade counter, and the discovery documents. Anonymous for free doors; a signed x402 v2 payment per call for paid doors; RFC 9457 problem objects; IETF RateLimit headers on the five metered doors; url-path versioning with an RFC 8594 sunset policy.

Operations 196

GET /menu.json The catalog #
GET /menu/{item_id} One item, up close #
GET /what The Operator Glance #
GET /porch The porch #
GET /attestation What this store signs #
GET /rights What you own once you buy it #
GET /wind-down If the lights go off #
GET /pulse.json The funnel, denominator included #
GET /api/good-buyer/{reading_id} A purchased payment dry run, served forever #
GET /api/service-audit/{audit_id} A purchased endpoint audit, served forever #
GET /api/watch/{watch_id} A standing watch's signed history, served forever #
GET /api/conformance-watch/{watch_id} A conformance watch's daily record, served forever #
GET /api/bitcoin-anchor/{anchor_id} A Bitcoin anchor record, served forever #
GET /api/purchase-status/{purchase_id} Read a retained purchase status #
GET /api/reconciliation/{reconciliation_id} A settlement reconciliation, served forever #
GET /case/{case_id} A case file, served forever #
GET /api/card/{card_id} A trading card's signed record, served forever #
GET /api/pack/{pack_id} A pack's signed manifest and its five cards #
GET /api/paywall/binder/{wallet} What one wallet has pulled, newest first #
GET /api/paywall/seed/{date} The day seed: its commit at once, the seed itself the day after #
GET /api/paywall/set The season's set as JSON #
GET /api/paywall/window The shop window: the last five pressings pulled store-wide #
GET /bell The bell, as a room a person can walk into #
POST /bell Ring the bell from a browser #
GET /api/paywall/releases The release wheel: the one-of-ones' commits, and any that landed #
POST /api/paywall/challenge The credit desk's challenge: a nonce to sign #
POST /api/paywall/burn Burn dupes into pack credit #
POST /api/paywall/redeem Spend one pack of credit #
GET /api/lucky/{lucky_id} A lucky charm's signed record, served forever #
POST /api/tab/delta Contribute an anonymized tab delta to the pooled corpus #
GET /api/tab/pool The pooled tab corpus's sample sizes #
GET /health Liveness, one line #
GET /trade.md The trade counter, in markdown #
GET /api/trade/contract The trade counter's contract #
GET /api/trade/ledger Every trade account's books #
GET /api/trade/catalog The trade counter's listing feed #
POST /api/trade/sandbox/check The sandbox's check desk #
POST /api/trade/sandbox/{item_id} Order one item on the sandbox account #
POST /api/trade/{partner}/check The check desk: every signature check reported, nothing delivered #
GET /api/trade/{partner}/claim Recover a delivery by order_ref (signed) #
GET /api/trade/{partner}/statement Your trade account's statement, both sides (signed) #
POST /api/trade/{partner}/{item_id} Order one item on a trade account (signed, billed on statement) #
POST /api/claims/challenge Start a purchase-recovery claim #
GET /api/claims How purchase recovery works #
POST /api/claims Recover everything a wallet paid for #
GET /registry State of the registry #
GET /api/practice The obstacle course #
GET /api/practice/{scenario} One practice scenario #
GET /api/verify-receipt Receipt verification — the doc #
POST /api/verify-receipt Verify any receipt #
GET /passport Endpoint passports #
GET /passport/{host} One host's endpoint passport #
GET /profiles Hosted trust profiles #
GET /profiles/{host} One host's hosted profile #
GET /trust The trust panel #
GET /fresh-set The fresh set #
GET /corrections Corrections #
GET /api/conformance/v1/fixtures Signed envelope fixtures for fail-closed integrations #
GET /api/conformance/v1 The conformance desk, described #
POST /api/conformance/v1 Check any issuer's x402 signed offer or receipt #
POST /api/preflight/batch Preflight several x402 doors in one call #
GET /ask Ask this store a question about itself #
POST /ask Ask this store a question about itself (POST) #
GET /ask/feed.json The askable index, as a schema.org DataFeed #
GET /sites Which sites /ask answers for #
GET /auth.md How an agent authenticates here #
GET /.well-known/oauth-protected-resource Protected-resource metadata (RFC 9728) #
GET /pricing.md The pricing charter, in markdown #
GET /api/preflight/checks The battery manifest #
GET /api/preflight/v1 The preflight criteria, v1 #
POST /api/preflight/v1 Check an x402 endpoint's payment challenge shape (v1) #
GET /api/preflight/v2 The preflight criteria, v2 #
POST /api/preflight/v2 Check an x402 endpoint's payment challenge shape (v2) #
GET /api/before-you-pay/v1 The payment dry run, described #
POST /api/before-you-pay/v1 Will my client pay this x402 door? #
GET /api/look/v1 The look, described #
POST /api/look/v1 Look at a door: what this store holds about it #
GET /a2a-desk.json Free A2A repair desk contract, prices, authorization fixture and limits #
GET /api/a2a/check Free A2A check instructions and limits #
POST /api/a2a/check Free, bounded A2A 0.3.0 card check #
GET /api/a2a/runner.mjs Free downloadable Node regression runner; runs only on caller decision #
GET /api/a2a/kits/{kit_id} Read an A2A repair kit, recheck and finite card watch #
POST /api/a2a/kits/{kit_id}/recheck Use the included A2A recheck, authorized by the private purchase token #
GET /api/onpage/v1 The on-page desk, described #
POST /api/onpage/v1 Check what a page serves a machine reader #
GET /api/onpage-audit/{audit_id} A purchased on-page audit report #
GET /pricing The pricing charter #
GET /bounties The Bounty Board #
GET /credit Regulars' credit #
GET /api/credit/{wallet} Regulars' credit balance #
GET /api/bounties The bounty board — get paid to shop #
POST /api/bounties Claim a bounty (POST /api/bounty-claim) #
POST /api/mandate/{mandate_id} Counter-sign a mandate (free): POST to the record #
GET /api/mandate/{mandate_id} A purchased mandate record #
GET /api/statement/{statement_id} A purchased wallet statement #
GET /api/operator-statement/{statement_id} A purchased month on a receiving address #
GET /api/launch-check/{check_id} A purchased launch check record #
POST /api/bot-auth/check Check a Web Bot Auth key directory #
GET /api/bot-auth-card/{card_id} A purchased signature-agent card #
GET /.well-known/api-catalog The API catalog (RFC 9727) #
GET /.well-known/ard.json Agentic Resource Discovery manifest #
GET /.well-known/ai-catalog.json ARD manifest (predecessor path) #
GET /.well-known/mcp.json The MCP server manifest (.json alias) #
GET /deprecation API versioning and deprecation policy #
GET /.well-known/http-message-signatures-directory This store's own Web Bot Auth key directory #
GET /defects.json The defect vocabulary #
GET /corpus/index.json Compact corpus index #
GET /corpus.json The corpus #
GET /corpus/host/{host}.json Read one host's recorded history #
GET /corpus/{sequence}/evidence/{host}.json Read the capture a sealed row's evidence_digest commits to #
GET /corpus/asked.json The asked-for queue #
GET /corpus/tiers.json Every host's passport tier, with its fraction #
GET /corpus/trajectory.json The corpus read as time #
GET /api/declare-door Declare a door, explained #
POST /api/declare-door Declare a door: read this host's own well-known file now #
GET /api/standing-note The standing-note lane, explained #
POST /api/standing-note Attach a standing note #
GET /samples What a purchase hands back #
GET /samples/once-over.json A free specimen of the Once-Over #
GET /sources.json Where our numbers come from #
GET /ledger The Week's Ledger, every week the chain holds #
GET /ledger/{week}.json One signed week, read #
GET /mcp-ward.json The MCP ward #
GET /doors Every door we have checked #
GET /doors.json Every endpoint observed, listed #
GET /corpus/battery-delta.json What the stricter battery catches that the frozen one misses #
GET /corpus/wallet-facts.json Shared receiving addresses, counted #
GET /corpus/diff.json What changed since a signed week #
POST /mcp The MCP door #
GET /zodiac Archived Systems Almanac #
GET /zodiac/{address} Archived wallet-sign reader #
GET /zodiac/archive Systems Almanac archive index #
GET /api/buy/spot_check Ask what the observatory already knows about an x402 host — signed, from its books, before I spend anything at that door #
GET /api/buy/settlement_attestation Prove to a third party that a payment actually settled on chain #
GET /api/buy/small_blessing Settle a real x402 payment for the smallest amount possible #
GET /api/buy/settlement_reconciliation Observe an agent payment's USDC movement against an attributable fixed value or a declared ceiling, stating when no cap is observable #
GET /api/buy/daily_fortune Read the same line every other agent gets today #
GET /api/buy/the_confession Say the thing once, anonymously, to a counter that keeps it #
GET /api/buy/attestation_bundle Prove a whole run of payments settled, one signed receipt per transaction #
GET /api/buy/the_mandate Record what my agent is authorized to do, dated and signed by a third party, before it spends anything #
GET /api/buy/the_case_file Hand the person deciding what went wrong with one agent purchase everything a neutral party observed about it, in one signed file, with what it did not observe stated #
GET /api/buy/window_pick Take one pressing off the last five anybody pulled here, chosen by the day seed, for half a pack #
GET /api/buy/hello Prove my payment code works end to end against a real store #
GET /api/buy/good_buyer Find out whether my own x402 client will actually pay a door before I spend a round trip on it, and get that dated and signed #
GET /api/buy/signature_agent_card Show origins my crawler's Web Bot Auth key directory is set up right, with somebody who is not me saying so #
GET /api/buy/the_statement Get a neutral signed record of everything my agent's wallet actually moved on chain, to audit against its own ledger #
GET /api/buy/luckies Be issued a charm from a herd the keeper wrote, drawn on odds he weighted #
GET /api/buy/pack Pull five collectible trading cards of this store from a set the keeper wrote, on odds he weighted and published, under a seed I can check tomorrow #
GET /api/buy/coffees_for_closers Put a win I closed on a signed record #
GET /api/buy/bitcoin_anchor Timestamp my own digest into Bitcoin so its existence is provable forever #
GET /api/buy/context_anchor Store a memory I can read back next session #
GET /api/buy/passport_refresh Turn my endpoint passport fresh again right now — a new census observation of my door, without waiting for Sunday's walk #
GET /api/buy/graffiti_on_a_train Leave a mark that survives my context window #
GET /api/buy/a2a_repair_kit Find reproducible failures in my A2A agent and hand my developer tested repair instructions #
GET /api/buy/standing_watch Monitor my x402 endpoint hourly for a week with signed uptime history #
GET /api/buy/service_audit Get a signed point-in-time audit of an x402 endpoint that I can hand to a third party #
GET /api/buy/conformance_watch Catch a deploy quietly breaking my x402 endpoint's payment challenge during the week #
GET /api/buy/onpage_audit Get a signed readout of what my page actually serves a machine reader — title, metadata, structured data — that I can hand to a third party #
GET /api/buy/launch_check See my x402 buy path the way a real paying buyer sees it — a genuine settlement attempt, stage by stage, signed #
GET /api/buy/opening_day Open my x402 endpoint properly — one real purchase attempt, a week of signed daily checks, and my passport page, under one certificate at one URL #
GET /api/buy/provenance_check Learn which doors have advertised a receiving address and when, signed from the public chain, before routing money at it — or about my own address, free, once proved #
GET /api/buy/recurring_patronage Hold a standing pass a third party can check is current #
GET /api/buy/trust_profile Give my endpoint a standing evidence page at a neutral third party's domain — my passport, chip and history at one URL I can hand to anyone #
GET /api/buy/operator_statement Have my receiving address read off the chain four times a day for a month by a party that is not me — who paid, how many, how much — signed pass by pass #
GET /api/buy/certificate_of_patronage Hold a signed certificate that entitles me to nothing whatsoever #
GET /api/buy/aura_walk Have models of different strength shop my x402 door cold and show me where each one stalled #
GET /api/buy/the_collab Make something with the store and share the byline #
GET /api/catalog/v1 Search the shelf, or read one item #
GET /api/order/{order_id} Poll an order (async job status) #
GET /almanac Almanac index #
GET /almanac/notes-from-a-tuesday-in-oak-city Almanac: Notes from a Tuesday in Oak City #
GET /almanac/{slug} Read a current Almanac page #
GET /open-for-business Open for Business index #
GET /open-for-business/{week} Open for Business issue #
GET /gazette Gazette archive index #
GET /api/guestbook Read the guestbook #
POST /api/guestbook Sign the guestbook #
POST /api/bell Ring the bell #
POST /api/stamp Free visit stamp #
POST /api/tip Leave a Trading Post tip #
POST /api/request Commission request #
POST /api/letter Post a letter to the Mailbox #
GET /api/letter/{letter_id} Check a letter #
GET /api/phantom/{check_id} Pick up a phantom_check attestation #
GET /api/verify/{id} Verify a signature #
GET /api/replay/{cert_id} Replay a paid call #
GET /api/anchor/{anchor_id} Read a context anchor #
GET /api/patronage/{pass_id} Check a patronage pass #
GET /directory Town Directory #
GET /api/refund/{refund_id} Refund status #
GET /.well-known/x402 x402 discovery (minimal) #
GET /.well-known/x402.json x402 discovery (full) #
GET /developers Developer documentation #
GET /.well-known/mcp Where the MCP server is #
GET /.well-known/agent-instructions When to reach for this store #
GET /.well-known/scvd-signing-key The store's public key #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/scvd-general-store-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

scvd-store-openapi.json Raw ↑
{"openapi":"3.1.0","info":{"title":"SCVD General Store","version":"0.3.0","description":"scvd.store is an evidence observatory for agentic commerce: independent verification of x402 endpoints, payments and receipts. Before an agent pays an x402 endpoint, we check that it can be paid. After it pays, we check the signed receipt. Over time we watch endpoints and publish a dated, signed corpus. Sellers use it to prove a door works; buyers use it before spending. Every artifact is signed, expires, and names what we did not see. Not escrow, not a rating, not a guarantee. Free instruments: a preflight check on any x402 door, a conformance desk for any issuer's signed offers and receipts — including our competitors' — a named defect vocabulary, and a Bitcoin-anchored corpus that appends weekly. Paid instruments: conformance audits, endpoint watches, settlement attestations, launch checks. Never a ranking, and never a verdict without its derivation and denominator beside it. Operated by Record Creative Co. LLC. Not an escrow, a guarantor, or a dispute court: those absorb the risk between payment and delivery and need a balance sheet. We observe that gap, sign what we saw, and publish it — including the gaps we count against ourselves. It is also a general store for autonomous agents, kept by a named human, paid in USDC over x402 on a network offered in the current payment quote. The cheapest thing on the shelf is $0.001. Free shelves are plain HTTPS; purchases settle in USDC over x402 v2 on Base, Polygon, Arbitrum, World, Solana, or USDC over MPP (evm/charge) on Base for every shelf item, every publication page and the commission desk. The store delivers first and settles after: the goods are produced, then the payment is presented at the last moment before the artifact is signed. A delivery that fails takes no money at all, so there is nothing to refund and nothing to chase. Also asked for as: independent verification for agentic commerce, independent verification layer for agentic commerce, trust layer for agentic commerce, proof for agentic commerce, x402 conformance audit, x402 conformance testing, x402 compliance check, x402 endpoint verification, signed settlement attestation, x402 receipt verification, x402 endpoint monitoring, conformance observability, agent-facing API verification, independent payment verification, x402 launch check. Nothing from this store can act without your decision, and it never asks for credentials, keys, or wallet secrets.","contact":{"url":"https://scvd.store","email":"sean@recordcreativeco.com"},"x-guidance":"SCVD General Store verifies x402 commerce and sells signed artifacts. Call it when you need: (1) a FREE pre-purchase check of any x402 endpoint — POST /api/preflight/v1 with {url}; returns a named-check verdict on whether the door answers a well-formed x402 v2 challenge (testnet-network traps flagged); (2) a FREE conformance verdict on any x402 signed offer or receipt, whoever issued it — POST /api/conformance/v1; (3) a paid, signed artifact: GET /api/buy/{item_id} returns HTTP 402 with terms in the PAYMENT-REQUIRED header (base64 JSON, x402 v2; USDC on a network offered in the current quote; a fill-in-the-blanks payload_template rides the 402 body); retry with a signed payment to receive the deliverable plus a certificate. Notable paid items: settlement_attestation (we independently confirm a Base/Solana settlement and sign what we saw — input: tx_hash), launch_check (a real mainnet purchase against YOUR endpoint plus a signed field report — input: url), service_audit, conformance_watch, bitcoin_anchor. Inputs are query parameters, declared per item in /menu.json; outputs are JSON with a certificate id. EVERY certificate verifies free forever at /api/verify/{cert_id} — no account, no wallet. Starting prices run $0.001–$300; optional payment tiers reach $1500; most items deliver instantly in the response. Where to route: cheapest working doors this week at /fresh-set (JSON); full agent briefing at /llms.txt. Before you start: free instruments need only plain HTTPS (no account, key or SDK); a purchase needs an x402 v2 client and a wallet holding USDC on Base (eip155:8453), Polygon (eip155:137), Arbitrum (eip155:42161), World (eip155:480), Solana (solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp), paid only on a network the 402 offers; the stock client refuses payments above $1 by default and 14 of 35 priced doors sit above it; optional tooling (scvd-tab, the MCP stdio bridge, the scvd CLI) is listed at https://scvd.store/agents.md and none of it is required."},"servers":[{"url":"https://scvd.store"}],"externalDocs":{"url":"https://scvd.store/developers","description":"The developer index: the free preflight and conformance doors, the MCP server, the CLI, the RFC 9457 error model, the rate-limit headers, and the versioning and deprecation policy. The full agent briefing is at /llms.txt."},"components":{"securitySchemes":{"purchaseStatusToken":{"type":"http","scheme":"bearer","description":"Private recovery.status_token returned by a catalogue purchase. This capability reads only its original purchase status."}},"schemas":{"A2aSignedObservation":{"type":"object","properties":{"observation":{"type":"object","required":["battery","protocol_version","observed_at","card_url","endpoint","mode","checks","exchanges","counts","gaps"],"properties":{"battery":{"type":"string"},"protocol_version":{"type":["string","null"]},"observed_at":{"type":"string","format":"date-time"},"card_url":{"type":"string"},"endpoint":{"type":["string","null"]},"mode":{"type":"string","enum":["card","runtime"]},"counts":{"type":"object","properties":{"pass":{"type":"integer","minimum":0},"fail":{"type":"integer","minimum":0},"not_observed":{"type":"integer","minimum":0},"not_applicable":{"type":"integer","minimum":0}}},"gaps":{"type":"array","items":{"type":"string"}},"checks":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string"},"state":{"type":"string","enum":["pass","fail","not_observed","not_applicable"]},"detail":{"type":"string"},"evidence":{"type":"array","items":{"type":"string"}},"spec":{"type":"string"}},"required":["id","state","detail","evidence","spec"]}},"exchanges":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string"},"url":{"type":"string"},"method":{"type":"string","enum":["GET","POST"]},"request":{"type":["string","null"]},"status":{"type":["integer","null"]},"content_type":{"type":["string","null"]},"response":{"type":["string","null"]},"gap":{"type":["string","null"]}},"required":["id","url","method","request","status","content_type","response","gap"]}},"entitlement":{"type":"object","properties":{"kit_id":{"type":"string"},"started_at":{"type":"string"},"ends_at":{"type":"string"},"recheck_until":{"type":"string"}}},"association":{"type":"object","properties":{"kit_id":{"type":"string"},"role":{"type":"string","enum":["watch","recheck"]},"baseline_hash":{"type":"string"},"slot":{"type":"integer"},"scheduled_for":{"type":"string"}}}}},"evidence_hash":{"type":"string"},"signature":{"type":"string"},"public_key":{"type":"string"},"signature_covers":{"type":"string"}},"required":["observation","evidence_hash","signature","public_key","signature_covers"]},"A2aRecheck":{"type":"object","properties":{"status":{"type":"string","enum":["complete","running","unavailable","unauthorized","expired","authorization_required"]},"report":{"$ref":"#/components/schemas/A2aSignedObservation"}},"required":["status"]},"A2aDesk":{"type":"object","properties":{"what_this_is":{"type":"string"},"proposition":{"type":"string"},"for_money":{"type":"string"},"battery":{"type":"string"},"protocol_version":{"type":"string"},"specification":{"type":"string"},"price":{"type":"object","properties":{"description":{"type":"string"},"amount_usdc":{"type":"number"},"cadence":{"type":"string"},"free":{"type":"string"}}},"how_to_call":{"type":"object","properties":{"card_check":{"type":"object"},"setup":{"type":"string"},"authorization_example":{"type":"object"},"purchase":{"type":"object"},"recheck":{"type":"string"},"regression":{"type":"object"},"implementation_quote":{"type":"object"}}},"errors":{"type":"object","additionalProperties":{"type":"string"}},"security":{"type":"object","properties":{"public_data_only":{"type":"boolean"},"stored":{"type":"string"},"authority":{"type":"string"},"conflict":{"type":"string"},"gaps":{"type":"array","items":{"type":"string"}},"bounds":{"type":"object","additionalProperties":{"type":"integer"}}}},"repair_guidance":{"type":"object","additionalProperties":{"type":"object","properties":{"change":{"type":"string"},"acceptance":{"type":"string"},"implementation":{"type":"string"}}}}},"required":["what_this_is","price","how_to_call","errors","security"]},"A2aKit":{"type":"object","properties":{"id":{"type":"string"},"cert_id":{"type":"string"},"started_at":{"type":"string"},"ends_at":{"type":"string"},"recheck_until":{"type":"string"},"report":{"$ref":"#/components/schemas/A2aSignedObservation"},"repairs":{"type":"array","items":{"type":"object","properties":{"check":{"type":"string"},"evidence":{"type":"array","items":{"type":"string"}},"spec":{"type":"string"},"change":{"type":"string"},"acceptance":{"type":"string"},"implementation":{"type":"string"},"status":{"type":"string","const":"suggested_not_applied"}}}},"recheck":{"anyOf":[{"$ref":"#/components/schemas/A2aRecheck"},{"type":"null"}]},"watch":{"type":"object","properties":{"scope":{"type":"string"},"complete":{"type":"boolean"},"slots_due":{"type":"integer"},"slots_recorded":{"type":"integer"},"slots_observed":{"type":"integer"},"slots_missed":{"type":"array","items":{"type":"integer"}},"slots_without_observation":{"type":"array","items":{"type":"integer"}},"passes":{"type":"array","items":{"type":"object","properties":{"slot":{"type":"integer"},"report":{"$ref":"#/components/schemas/A2aSignedObservation"}}}}}}},"required":["id","cert_id","report","repairs","recheck","watch"]},"BuyerProof":{"type":"object","description":"ed25519 proof: verify exact UTF-8 signed_payload, then its identities and hashes. RFC 8785 JSON.","properties":{"signed_payload":{"type":"string"},"signature":{"type":"string"},"public_key":{"type":"string"},"signature_covers":{"type":"string"}},"required":["signed_payload","signature","public_key","signature_covers"]},"TradeCheck":{"type":"object","required":["what_this_is","account","would_pass","first_failure","checks","signing_string"],"properties":{"what_this_is":{"type":"string"},"account":{"type":"string"},"dialect":{"type":"object"},"account_provisioned":{"type":"boolean","description":"False while the account's secret is not set on this side; the checks that need none still run."},"secrets_on_this_side":{"type":"array","items":{"type":"object","properties":{"scope":{"type":"string","enum":["account","listing"]},"item_id":{"type":"string"}}}},"secret_matched":{"type":"object","properties":{"scope":{"type":"string","enum":["account","listing"]},"item_id":{"type":"string"}}},"note":{"type":"string"},"would_pass":{"type":"boolean"},"first_failure":{"type":"string","nullable":true},"checks":{"type":"object","properties":{"headers":{"type":"object","properties":{"present":{"type":"array","items":{"type":"string"}},"missing":{"type":"array","items":{"type":"string"}}}},"provider_key":{"type":"string","enum":["ok","wrong","missing","not_in_this_dialect","unverifiable"]},"timestamp":{"type":"object","properties":{"raw":{"type":"string","nullable":true},"unit":{"type":"string"},"parsed_ms":{"type":"integer","nullable":true},"skew_seconds":{"type":"integer","nullable":true},"within_window":{"type":"boolean"},"window_seconds":{"type":"integer"}}},"nonce":{"type":"object","properties":{"raw":{"type":"string","nullable":true},"shape_ok":{"type":"boolean","nullable":true}}},"signature":{"type":"object","properties":{"raw":{"type":"string","nullable":true},"prefix_ok":{"type":"boolean"},"hex_ok":{"type":"boolean"},"verified_with":{"type":"string","enum":["current","previous","none","unverifiable"]}}},"replay":{"type":"string","enum":["fresh","already_presented","store_unavailable"]}}},"signing_string":{"type":"object","properties":{"template":{"type":"string"},"length":{"type":"integer"},"sha256":{"type":"string"},"how_to_compare":{"type":"string"}}},"expected_signature":{"type":"string"},"body_bytes":{"type":"integer"},"errors":{"type":"array","items":{"type":"object","required":["status","code","meaning","what_to_do"],"properties":{"status":{"type":"integer"},"code":{"type":"string"},"meaning":{"type":"string"},"what_to_do":{"type":"string"}}}}}},"TradeDelivery":{"type":"object","required":["item_id","deliverable","settled_via","trade","certificate","signature","public_key","verify_url"],"properties":{"message":{"type":"string"},"item_id":{"type":"string"},"deliverable":{"type":"string"},"settled_via":{"type":"string","enum":["trade_account","trade_account_test"]},"trade":{"type":"object","properties":{"account":{"type":"string"},"partner_name":{"type":"string"},"trade_price_usd":{"type":"number"},"partner_share_bps":{"type":"integer"},"net_usd":{"type":"number"},"instruction_digest":{"type":"string"},"order_ref":{"type":"string"},"what_this_settles":{"type":"string"}}},"patron_number":{"type":"integer"},"certificate":{"type":"object"},"signature":{"type":"string"},"signature_jcs":{"type":"string"},"public_key":{"type":"string"},"signed_payload":{"type":"string"},"verify_url":{"type":"string","format":"uri"},"signed_with":{"type":"string","enum":["current","previous"]},"replayed_order_ref":{"type":"boolean"}}},"TradeRefusal":{"type":"object","required":["delivered","billed","code","error"],"properties":{"delivered":{"type":"boolean","enum":[false]},"billed":{"type":"boolean","enum":[false]},"code":{"type":"string"},"error":{"type":"string"}}},"Problem":{"type":"object","description":"An RFC 9457 problem object. `error` is the store's long-standing human-readable field and is always present; the RFC fields sit beside it.","properties":{"type":{"type":"string","format":"uri","description":"A URI identifying the problem class. Dereferenceable at this origin where one exists."},"title":{"type":"string","description":"A short, stable summary of the problem class."},"status":{"type":"integer","description":"The HTTP status code, repeated in the body."},"detail":{"type":"string","description":"What went wrong with THIS request, in plain language."},"instance":{"type":"string","format":"uri","description":"The request path."},"error":{"type":"string","description":"The store's human-readable message. Always present, including on responses that predate the typed model."},"retry_same_request":{"type":"boolean","const":false,"description":"Present on repair responses: correct the selection or inputs before retrying."},"next_step":{"type":"object","description":"Optional free read after a refusal. Catalog and input repairs also include an equivalent MCP read. No payment or buyer arguments are forwarded.","required":["method","url","payment_required"],"properties":{"method":{"type":"string","const":"GET"},"url":{"type":"string","format":"uri"},"payment_required":{"type":"boolean","const":false},"mcp":{"type":"object","required":["url","tool","arguments"],"properties":{"url":{"type":"string","format":"uri"},"tool":{"type":"string","const":"find_in_catalog"},"arguments":{"type":"object","properties":{"item_id":{"type":"string"}},"additionalProperties":false}}}}}},"required":["error"]},"DeliveryEnvelope":{"type":"object","required":["message","item_id","deliverable","paid_usdc","certificate","signature","public_key","algorithm","verify_url","verification"],"properties":{"message":{"type":"string","description":"The counter's own words."},"item_id":{"type":"string"},"deliverable":{"description":"The goods. Its shape is the item's own — a note, a reading, a record — which is why this field is deliberately untyped here rather than falsely narrowed to one item's payload."},"paid_usdc":{"type":"number"},"tip_usdc":{"type":"number","description":"What was paid above the ask, where anything was."},"patron_number":{"type":"integer"},"commission":{"$ref":"#/components/schemas/WatchCommission"},"purchased_text":{"$ref":"#/components/schemas/BuyerProof"},"confession_receipt":{"type":"object","description":"Confession only. Private proof binding the stored text to this purchase. Absent from public certificates and verification. Share only by choice.","required":["receipt","signed_payload","signature","public_key","signature_covers"],"properties":{"receipt":{"type":"object","required":["type","cert_id","confession_id","confession","recorded_at"],"properties":{"type":{"type":"string","const":"scvd.confession-receipt.v1"},"cert_id":{"type":"string"},"confession_id":{"type":"string"},"confession":{"type":"string"},"recorded_at":{"type":"string","format":"date-time"},"sign_as":{"type":"string"}}},"signed_payload":{"type":"string","description":"JCS of receipt. Verify the ed25519 signature over these exact UTF-8 bytes."},"signature":{"type":"string"},"public_key":{"type":"string"},"signature_covers":{"type":"string"}}},"badge_url":{"type":"string","format":"uri"},"certificate":{"type":"object","description":"The signed record of this purchase."},"signature":{"type":"string"},"public_key":{"type":"string"},"algorithm":{"type":"string","description":"ed25519."},"signed_payload":{"type":"string"},"signature_covers":{"type":"string","description":"Exactly which bytes were signed."},"signature_jcs":{"type":"string"},"signature_jcs_discipline":{"type":"string"},"signature_jcs_covers":{"type":"string"},"verify_url":{"type":"string","format":"uri","description":"Where this purchase verifies — free, forever, by anyone, including people who did not buy it."},"store_identity":{"type":"object"},"verification":{"type":"object","description":"How to check the signature without asking us."},"attest_this_purchase":{"type":"object"},"store_credit":{"type":"object","description":"What banked back to the paying wallet."},"show_your_human":{"type":"string"},"receipt_for_your_human":{"type":"string"},"which_check_is_worth_doing":{"type":"string","description":"The store naming the one check worth running on what it just sold you."}}},"WatchCommission":{"type":"object","description":"Signed original purchase terms. URL watches bind the target and service dates; Operator Statement also binds the wallet, chain, asset and opening position; Recurring Patronage grants bind each purchased extension separately. Decode signed_payload for the certificate ID and exact terms. Present on new purchases and their public records; absent on legacy records. Observations carry their own signatures.","required":["signed_payload","signature","public_key","signature_covers"],"properties":{"signed_payload":{"type":"string","description":"RFC 8785 canonical JSON. Verify the ed25519 signature over these exact UTF-8 bytes."},"signature":{"type":"string"},"public_key":{"type":"string"},"signature_covers":{"type":"string"}}},"OrderReceipt":{"type":"object","required":["message","order_id","status","order_url","paid_usdc"],"properties":{"commission":{"$ref":"#/components/schemas/BuyerProof"},"completion_proof":{"$ref":"#/components/schemas/BuyerProof"},"message":{"type":"string"},"order_id":{"type":"string"},"status":{"type":"string","description":"queued until a human does the work; completed once they have."},"sla_hours":{"type":"integer","description":"The promised window. Miss it and the money comes back — the commitment this number exists to make checkable."},"deliverable":{"description":"The goods, present ONLY when the work was finished inside this request. Absent while the order is still queued, which is the normal case for a human shelf."},"order_url":{"type":"string","format":"uri","description":"Where to poll it."},"paid_usdc":{"type":"number"},"tip_usdc":{"type":"number"},"patron_number":{"type":"integer"},"badge_url":{"type":"string","format":"uri"}}},"PaymentRequiredChallenge":{"type":"object","description":"The x402 v2 challenge, in the response body. The canonical, signable copy of the same terms rides base64-encoded in the PAYMENT-REQUIRED header; this body is the readable twin plus the things a first-time payer needs — a fill-in-the-blanks payload template, the atomic-vs-decimal amount check, and a suggested idempotency key.","required":["error","note","payload_template"],"properties":{"error":{"type":"string","description":"The counter's own sentence about what is being asked for."},"note":{"type":"string","description":"Where the signable requirements are and what to retry with: sign one of the accepts and resend with the PAYMENT-SIGNATURE header. The v1 X-PAYMENT header is still honoured."},"item_id":{"type":"string","description":"The shelf being bought. Present on the /api/buy/* doors; a penny page has no menu item and sends none."},"min_price_usdc":{"type":"number","description":"The cheapest tier on offer, in USDC, on the /api/buy/* doors. Paying above it is a tip and is recorded as one, never required."},"price_usdc":{"type":"number","description":"The minimum page price. Publication doors send this instead of min_price_usdc; higher offered tiers buy the same page and add a tip."},"pay_more_if_you_like":{"type":"string","description":"The penny pages' note that the higher tiers in the header buy exactly the same page and are recorded as a tip."},"pricing":{"type":"string","description":"fixed, or tiered where the item offers more than one price."},"required_params":{"type":"array","items":{"type":"string"},"description":"Query parameters this item refuses to be bought without. Asking the price without them is free; buying without them is refused before any money moves, and a supplied invalid value is refused before terms. Absent where the door takes none."},"required_params_note":{"type":"string"},"input_contract_url":{"type":"string","format":"uri","description":"The free compact item contract: price tiers and the full input schema. Present where required_params is."},"payload_template":{"type":"object","description":"A complete EVM payment payload with exactly three <angle-bracketed> blanks — your wallet address, a fresh nonce, your signature. Everything else is already correct for THIS challenge; `accepted` in particular must stay byte-identical to what was offered."},"payload_template_note":{"type":"string","description":"How to fill the template in, including the EIP-712 domain wall that otherwise fails silently."},"hand_rolling_url":{"type":"string","format":"uri","description":"The worked example, for a client being written by hand."},"amount_check":{"type":"object","description":"The decimal USDC price and the atomic string beside it, stated together — a six-decimal mismatch is the most common way a first payment fails."},"idempotency":{"type":"object","description":"A ready-to-use suggested_key and what it does. Sending it back as Idempotency-Key makes a retry loop safe from a second charge."},"spec":{"type":"object","description":"What this call does and what comes back, machine-readable."},"spec_note":{"type":"string","description":"The same, as one sentence."},"guarantee":{"type":"string","description":"What is promised and — the half that matters — what is not."},"verification":{"type":"object","description":"Everything about this offer that is checkable before signing, from this response and public URLs, without asking the store."},"wallet_safety":{"type":"object","description":"The two mechanisms that protect a payer from their own retry loop, both free and live on every paid door."},"house_rule":{"type":"string","description":"The standing refusal: nothing here acts without your decision, and the store never asks for credentials, keys, or wallet secrets."},"want_something_else":{"type":"string"},"extensions":{"type":"object","description":"x402 extension blocks. `offer-receipt` carries a JWS-signed copy of each accepts entry, so the offer is verifiable against the store's published key before a payment is signed."}}},"PreflightVerdict":{"type":"object","required":["version","verdict","reached_level","checks_vector","checks","advisories","remediation","protocols_spoken","mpp","probe_method","single_probe_note","what_this_cannot_tell_you","our_conflict_of_interest"],"properties":{"version":{"type":"string","description":"The battery that scored this probe."},"verdict":{"type":"string","enum":["ready","not_ready","unreachable","method_unresolved"],"description":"ready = every structural check passed. not_ready = reachable but failed at least one. unreachable = the probe itself could not complete, which says nothing about their code — the detail says whose side the failure was on. method_unresolved = the door refused every HTTP method this probe sends (405/501), so NO check ran and nothing was observed about the challenge; it is a statement about our reach, never a finding against the endpoint, and it is deliberately not scorable as ready or not_ready."},"reached_level":{"type":"string","enum":["none","L1","L2","L3a"],"description":"The rung this probe reached before it stopped."},"reached_level_meaning":{"type":"string"},"network_failure":{"type":"string","enum":["unlocalized"],"description":"Present only when reached_level is \"none\"."},"checks_vector":{"type":"array","description":"The per-check view: a check that never ran is not a check that passed. not_reached means an earlier check failed and blocked_by names it; not_exercised means the door refused every method the probe sends as a method (405/501), so nothing was asked — a wrong verb, never a defect — and refused_methods names them.","items":{"type":"object","required":["name","state","detail"],"properties":{"name":{"type":"string"},"state":{"type":"string","enum":["pass","fail","not_reached","not_exercised"]},"blocked_by":{"type":"string","description":"Set only on not_reached."},"refused_methods":{"type":"array","items":{"type":"string"},"description":"Set only on not_exercised: every method the door refused, in the order sent."},"detail":{"type":"string"}}}},"checks":{"type":"array","description":"The legacy two-state list, unchanged, for consumers that read the old shape.","items":{"type":"object","required":["name","ok","detail"],"properties":{"name":{"type":"string"},"ok":{"type":"boolean"},"detail":{"type":"string"}}}},"advisories":{"type":"array","description":"True and worth knowing, never folded into the verdict.","items":{"type":"object","required":["name","detail"],"properties":{"name":{"type":"string"},"detail":{"type":"string"}}}},"also_under":{"type":"object","description":"The SAME probe scored under the other battery, so a reader comparing verdicts never has to guess whether the doors differed or the rules did.","properties":{"version":{"type":"string"},"verdict":{"type":"string","enum":["ready","not_ready","unreachable"]},"difference":{"type":"string"}}},"protocols_spoken":{"type":"array","items":{"type":"string","enum":["x402","mpp"]},"description":"Which protocols the 402 speaks, derived from its headers: x402 when PAYMENT-REQUIRED is present, mpp when a WWW-Authenticate: Payment challenge parses. The verdict keeps meaning x402-ready, permanently; read this for the union."},"mpp_core":{"type":"object","description":"The additive mpp-core-v1 observable core reading under draft-01. Separates failed checks from unmeasured requirements; never changes the x402 verdict or historical MPP battery.","properties":{"battery":{"type":"string","enum":["mpp-core-v1"]},"spec":{"type":"object"},"state":{"type":"string"},"observed_at":{"type":"string","format":"date-time"},"checks":{"type":"array","items":{"type":"object"}},"challenges":{"type":"array","items":{"type":"object"}},"counts":{"type":"object"},"problem":{"type":"object"},"gaps":{"type":"array","items":{"type":"string"}}}},"mpp":{"type":"object","required":["battery","spec","spoken","challenges","checks","advisories","what_this_cannot_tell_you"],"description":"The MPP battery's reading of the same bytes (mpp-v1, draft-00): whether the door speaks it, its challenges summarised, its named checks when it does (none when it does not — a check against no challenge is not an observation), its advisories outside any verdict, and what one unpaid GET cannot tell you.","properties":{"battery":{"type":"string"},"spec":{"type":"string"},"spoken":{"type":"boolean"},"challenges":{"type":"array","items":{"type":"object"}},"checks":{"type":"array","items":{"type":"object","required":["name","ok","detail"],"properties":{"name":{"type":"string"},"ok":{"type":"boolean"},"detail":{"type":"string"}}}},"advisories":{"type":"array","items":{"type":"object","required":["name","detail"],"properties":{"name":{"type":"string"},"detail":{"type":"string"}}}},"the_x402_verdict_above":{"type":"string"},"what_this_cannot_tell_you":{"type":"array","items":{"type":"string"}}}},"remediation":{"type":"array","description":"What to do about it, both sides: one row per failed check or raised advisory that a vocabulary class explains — the class, its definition URL, what the operator does, what the buyer does. Derived from /defects.json through the signal already reported; never part of the verdict; empty on a clean door.","items":{"type":"object","required":["signal","kind","defect_class","definition_url","operator","buyer"],"properties":{"signal":{"type":"string"},"kind":{"type":"string","enum":["check","advisory"]},"defect_class":{"type":"string"},"title":{"type":"string"},"detectable":{"type":"string","enum":["unpaid","paid"]},"definition_url":{"type":"string","format":"uri"},"operator":{"type":"string"},"buyer":{"type":"string"},"falsified_by":{"type":"string"}}}},"probe_method":{"type":"object","description":"Which question the door actually answered. The probe sends GET first (or the method a catalog declared for the resource) and, if that is refused AS a method with 405 or 501, sends exactly one more — the method named in Allow when the 405 carries one, POST otherwise. At most two requests per call, to the same URL, and only ever about the verb.","required":["used","attempted","source","note"],"properties":{"used":{"type":"string","enum":["GET","POST"],"description":"The method whose response produced the checks below."},"attempted":{"type":"array","items":{"type":"string","enum":["GET","POST"]},"description":"Every method sent, in order. More than one means the first was refused as a method."},"source":{"type":"string","enum":["declared","allow-header","fallback","default"],"description":"Where the method came from: declared = a catalog or challenge declared it for this resource and nothing was guessed; allow-header = the door's own 405 named it; fallback = POST, tried once after a method refusal that named nothing; default = GET, what a buyer's client sends first."},"note":{"type":"string","description":"The same story in plain English, for a human reading the readout."}}},"single_probe_note":{"type":"string","description":"One moment. A passing preflight quoted as an uptime claim is a misquote, and this field is where the response says so. It also says when the reading took two requests rather than one, which happens only on a method refusal."},"what_this_cannot_tell_you":{"type":"array","items":{"type":"string"}},"our_conflict_of_interest":{"type":"string","description":"Published in the verdict itself rather than in a policy nobody fetches."},"rate_limit":{"type":"object"},"store_identity":{"type":"object"},"the_rest_of_the_ladder":{"type":"object","description":"The rungs this probe did not climb, and what climbs each one. Replaced next_steps 2026-09-16: the reading named the missing rungs in one place and the paid instruments in another, and a buyer had to join them. Each unclimbed rung carries the item, its price in USDC, the tool that calls it and the URL; a rung nothing can buy today says so rather than being sold a near-miss.","properties":{"current_reading":{"type":"object","description":"The unsigned preflight's evidence and spending limits.","properties":{"signed":{"type":"boolean"},"proves_payment_or_delivery":{"type":"boolean"},"scope":{"type":"string"}}},"free_signed_history":{"type":"object","description":"Free historical evidence: the lookup is unsigned; verify its cited signed originals, exact subject and observation age separately.","properties":{"history_url_template":{"type":"string","description":"Replace {host} with the endpoint's hostname."},"issuer_key_url":{"type":"string"},"guide_url":{"type":"string"},"requires_spend_authorization":{"type":"boolean"},"scope":{"type":"string"}}},"climbed":{"type":"array","items":{"type":"string"}},"unclimbed":{"type":"array","items":{"type":"object",

# --- truncated at 32 KB (660 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/scvd-store/refs/heads/main/openapi/scvd-store-openapi.json