Every API here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for apis
7 MCP tools reach this
find_apisBrowse and filter every API in the catalog.
get_api_artifactsOne API's artifacts, grouped by type.
get_openapiThe primary OpenAPI for this API.
find_similar_apisAPIs that look like this one.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This API
curl "https://apis.io/api/v1/apis/scvd-store-a2a-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: SCVD General Store A2a API
version: 0.3.0
description: 'scvd.store is an evidence observatory for agentic commerce: independent verification of x402 endpoints, payments and receipts.'
contact:
url: https://scvd.store
email: sean@recordcreativeco.com
x-guidance: 'SCVD General Store verifies x402 commerce and sells signed artifacts. Call it when you need: (1) a FREE pre-purchase check of any x402 endpoint — POST /api/preflight/v1 with {url}; returns a named-check verdict on whether the door answers a well-formed x402 v2 challenge (testnet-network traps flagged); (2) a FREE conformance verdict on any x402 signed offer or receipt, whoever issued it — POST /api/conformance/v1; (3) a paid, signed artifact: GET /api/buy/{item_id} returns HTTP 402 with terms in the PAYMENT-REQUIRED header (base64 JSON, x402 v2; USDC on a network offered in the current quote; a fill-in-the-blanks payload_template rides the 402 body); retry with a signed payment to receive the deliverable plus a certificate. Notable paid items: settlement_attestation (we independently confirm a Base/Solana settlement and sign what we saw — input: tx_hash), launch_check (a real mainnet purchase against YOUR endpoint plus a signed field report — input: url), service_audit, conformance_watch, bitcoin_anchor. Inputs are query parameters, declared per item in /menu.json; outputs are JSON with a certificate id. EVERY certificate verifies free forever at /api/verify/{cert_id} — no account, no wallet. Starting prices run $0.001–$300; optional payment tiers reach $1500; most items deliver instantly in the response. Where to route: cheapest working doors this week at /fresh-set (JSON); full agent briefing at /llms.txt. Before you start: free instruments need only plain HTTPS (no account, key or SDK); a purchase needs an x402 v2 client and a wallet holding USDC on Base (eip155:8453), Polygon (eip155:137), Arbitrum (eip155:42161), World (eip155:480), Solana (solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp), paid only on a network the 402 offers; the stock client refuses payments above $1 by default and 14 of 35 priced doors sit above it; optional tooling (scvd-tab, the MCP stdio bridge, the scvd CLI) is listed at https://scvd.store/agents.md and none of it is required.'
servers:
- url: https://scvd.store
tags:
- name: A2a
paths:
/api/a2a/check:
get:
security: []
summary: Free A2A check instructions and limits
responses:
'200':
description: Desk contract
content:
application/json:
schema:
$ref: '#/components/schemas/A2aDesk'
'304':
$ref: '#/components/responses/NotModified'
'400':
$ref: '#/components/responses/BadRequest'
'404':
$ref: '#/components/responses/NotFound'
'429':
$ref: '#/components/responses/TooManyRequests'
'500':
$ref: '#/components/responses/ServerError'
operationId: get_api_a2a_check
parameters:
- name: If-None-Match
in: header
required: false
schema:
type: string
description: Conditional GET. Send the ETag a previous answer carried (a SHA-256 of the exact bytes served, not a version somebody maintains) and an unchanged document answers 304 with no body. Send it on a schedule instead of re-downloading what you already hold.
tags:
- A2a
post:
security: []
summary: Free, bounded A2A 0.3.0 card check
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- url
properties:
url:
type: string
format: uri
responses:
'200':
description: Unsigned checks, evidence, repairs and gaps
content:
application/json:
schema:
type: object
properties:
reading:
type: object
required:
- battery
- protocol_version
- observed_at
- card_url
- endpoint
- mode
- checks
- exchanges
- counts
- gaps
properties:
battery:
type: string
protocol_version:
type:
- string
- 'null'
observed_at:
type: string
format: date-time
card_url:
type: string
endpoint:
type:
- string
- 'null'
mode:
type: string
const: card
counts:
type: object
properties:
pass:
type: integer
minimum: 0
fail:
type: integer
minimum: 0
not_observed:
type: integer
minimum: 0
not_applicable:
type: integer
minimum: 0
gaps:
type: array
items:
type: string
checks:
type: array
items:
type: object
properties:
id:
type: string
state:
type: string
enum:
- pass
- fail
- not_observed
- not_applicable
detail:
type: string
evidence:
type: array
items:
type: string
spec:
type: string
required:
- id
- state
- detail
- evidence
- spec
exchanges:
type: array
items:
type: object
properties:
id:
type: string
url:
type: string
method:
type: string
enum:
- GET
- POST
request:
type:
- string
- 'null'
status:
type:
- integer
- 'null'
content_type:
type:
- string
- 'null'
response:
type:
- string
- 'null'
gap:
type:
- string
- 'null'
required:
- id
- url
- method
- request
- status
- content_type
- response
- gap
repairs:
type: array
items:
type: object
properties:
check:
type: string
evidence:
type: array
items:
type: string
spec:
type: string
change:
type: string
acceptance:
type: string
implementation:
type: string
status:
type: string
const: suggested_not_applied
signed:
type: boolean
const: false
next:
type: string
required:
- reading
- repairs
- signed
- next
'400':
description: Target refused
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
'404':
$ref: '#/components/responses/NotFound'
'429':
description: Budget exhausted; retry after 60 seconds
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
'500':
$ref: '#/components/responses/ServerError'
operationId: post_api_a2a_check
tags:
- A2a
/api/a2a/runner.mjs:
get:
security: []
summary: Free downloadable Node regression runner; runs only on caller decision
responses:
'200':
description: JavaScript attachment; Node 22+
content:
text/javascript:
schema:
type: string
'304':
$ref: '#/components/responses/NotModified'
'400':
$ref: '#/components/responses/BadRequest'
'404':
$ref: '#/components/responses/NotFound'
'429':
$ref: '#/components/responses/TooManyRequests'
'500':
$ref: '#/components/responses/ServerError'
operationId: get_api_a2a_runner_mjs
parameters:
- name: If-None-Match
in: header
required: false
schema:
type: string
description: Conditional GET. Send the ETag a previous answer carried (a SHA-256 of the exact bytes served, not a version somebody maintains) and an unchanged document answers 304 with no body. Send it on a schedule instead of re-downloading what you already hold.
tags:
- A2a
/api/a2a/kits/{kit_id}:
get:
security: []
summary: Read an A2A repair kit, recheck and finite card watch
parameters:
- name: kit_id
in: path
required: true
schema:
type: string
responses:
'200':
description: Signed observations and suggested repairs; Accept text/html for a human report
content:
application/json:
schema:
$ref: '#/components/schemas/A2aKit'
'400':
$ref: '#/components/responses/BadRequest'
'404':
description: Kit not found
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
'429':
$ref: '#/components/responses/TooManyRequests'
'500':
$ref: '#/components/responses/ServerError'
operationId: get_api_a2a_kits_kit_id
tags:
- A2a
/api/a2a/kits/{kit_id}/recheck:
post:
security: []
summary: Use the included A2A recheck, authorized by the private purchase token
parameters:
- name: kit_id
in: path
required: true
schema:
type: string
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- token
properties:
token:
type: string
maxLength: 100
responses:
'200':
description: Stored signed recheck; retries return the same result
content:
application/json:
schema:
$ref: '#/components/schemas/A2aRecheck'
'202':
description: Recheck started; no automatic replay after interruption
content:
application/json:
schema:
$ref: '#/components/schemas/A2aRecheck'
'400':
description: Invalid body or operator authorization absent
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
'403':
description: Token invalid
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
'404':
$ref: '#/components/responses/NotFound'
'410':
description: Recheck period ended
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
'429':
$ref: '#/components/responses/TooManyRequests'
'500':
$ref: '#/components/responses/ServerError'
'503':
description: Instrument failure; no pass claimed
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
operationId: post_api_a2a_kits_kit_id_recheck
tags:
- A2a
components:
schemas:
A2aSignedObservation:
type: object
properties:
observation:
type: object
required:
- battery
- protocol_version
- observed_at
- card_url
- endpoint
- mode
- checks
- exchanges
- counts
- gaps
properties:
battery:
type: string
protocol_version:
type:
- string
- 'null'
observed_at:
type: string
format: date-time
card_url:
type: string
endpoint:
type:
- string
- 'null'
mode:
type: string
enum:
- card
- runtime
counts:
type: object
properties:
pass:
type: integer
minimum: 0
fail:
type: integer
minimum: 0
not_observed:
type: integer
minimum: 0
not_applicable:
type: integer
minimum: 0
gaps:
type: array
items:
type: string
checks:
type: array
items:
type: object
properties:
id:
type: string
state:
type: string
enum:
- pass
- fail
- not_observed
- not_applicable
detail:
type: string
evidence:
type: array
items:
type: string
spec:
type: string
required:
- id
- state
- detail
- evidence
- spec
exchanges:
type: array
items:
type: object
properties:
id:
type: string
url:
type: string
method:
type: string
enum:
- GET
- POST
request:
type:
- string
- 'null'
status:
type:
- integer
- 'null'
content_type:
type:
- string
- 'null'
response:
type:
- string
- 'null'
gap:
type:
- string
- 'null'
required:
- id
- url
- method
- request
- status
- content_type
- response
- gap
entitlement:
type: object
properties:
kit_id:
type: string
started_at:
type: string
ends_at:
type: string
recheck_until:
type: string
association:
type: object
properties:
kit_id:
type: string
role:
type: string
enum:
- watch
- recheck
baseline_hash:
type: string
slot:
type: integer
scheduled_for:
type: string
evidence_hash:
type: string
signature:
type: string
public_key:
type: string
signature_covers:
type: string
required:
- observation
- evidence_hash
- signature
- public_key
- signature_covers
A2aDesk:
type: object
properties:
what_this_is:
type: string
proposition:
type: string
for_money:
type: string
battery:
type: string
protocol_version:
type: string
specification:
type: string
price:
type: object
properties:
description:
type: string
amount_usdc:
type: number
cadence:
type: string
free:
type: string
how_to_call:
type: object
properties:
card_check:
type: object
setup:
type: string
authorization_example:
type: object
purchase:
type: object
recheck:
type: string
regression:
type: object
implementation_quote:
type: object
errors:
type: object
additionalProperties:
type: string
security:
type: object
properties:
public_data_only:
type: boolean
stored:
type: string
authority:
type: string
conflict:
type: string
gaps:
type: array
items:
type: string
bounds:
type: object
additionalProperties:
type: integer
repair_guidance:
type: object
additionalProperties:
type: object
properties:
change:
type: string
acceptance:
type: string
implementation:
type: string
required:
- what_this_is
- price
- how_to_call
- errors
- security
A2aRecheck:
type: object
properties:
status:
type: string
enum:
- complete
- running
- unavailable
- unauthorized
- expired
- authorization_required
report:
$ref: '#/components/schemas/A2aSignedObservation'
required:
- status
Problem:
type: object
description: An RFC 9457 problem object. `error` is the store's long-standing human-readable field and is always present; the RFC fields sit beside it.
properties:
type:
type: string
format: uri
description: A URI identifying the problem class. Dereferenceable at this origin where one exists.
title:
type: string
description: A short, stable summary of the problem class.
status:
type: integer
description: The HTTP status code, repeated in the body.
detail:
type: string
description: What went wrong with THIS request, in plain language.
instance:
type: string
format: uri
description: The request path.
error:
type: string
description: The store's human-readable message. Always present, including on responses that predate the typed model.
retry_same_request:
type: boolean
const: false
description: 'Present on repair responses: correct the selection or inputs before retrying.'
next_step:
type: object
description: Optional free read after a refusal. Catalog and input repairs also include an equivalent MCP read. No payment or buyer arguments are forwarded.
required:
- method
- url
- payment_required
properties:
method:
type: string
const: GET
url:
type: string
format: uri
payment_required:
type: boolean
const: false
mcp:
type: object
required:
- url
- tool
- arguments
properties:
url:
type: string
format: uri
tool:
type: string
const: find_in_catalog
arguments:
type: object
properties:
item_id:
type: string
additionalProperties: false
required:
- error
A2aKit:
type: object
properties:
id:
type: string
cert_id:
type: string
started_at:
type: string
ends_at:
type: string
recheck_until:
type: string
report:
$ref: '#/components/schemas/A2aSignedObservation'
repairs:
type: array
items:
type: object
properties:
check:
type: string
evidence:
type: array
items:
type: string
spec:
type: string
change:
type: string
acceptance:
type: string
implementation:
type: string
status:
type: string
const: suggested_not_applied
recheck:
anyOf:
- $ref: '#/components/schemas/A2aRecheck'
- type: 'null'
watch:
type: object
properties:
scope:
type: string
complete:
type: boolean
slots_due:
type: integer
slots_recorded:
type: integer
slots_observed:
type: integer
slots_missed:
type: array
items:
type: integer
slots_without_observation:
type: array
items:
type: integer
passes:
type: array
items:
type: object
properties:
slot:
type: integer
report:
$ref: '#/components/schemas/A2aSignedObservation'
required:
- id
- cert_id
- report
- repairs
- recheck
- watch
responses:
NotFound:
description: No such resource. The body names where to look instead.
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
ServerError:
description: Something fell off a shelf. Nothing was charged.
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
TooManyRequests:
description: 'Too many requests, from the edge rather than from the store''s own logic. Retry after the interval named in Retry-After; the store does not charge for a refusal. The free preflight is limited — 30 probes per isolate per minute, 60 global — because it spends outbound requests to a host the caller chooses. Every answer the limiter METERED carries the IETF RateLimit fields — the 200 and the 429 — so you can pace against the live number instead of discovering the ceiling by being refused: RateLimit-Limit / -Remaining / -Reset report whichever of the two buckets is closer to binding, and RateLimit / RateLimit-Policy name both. Past either ceiling it returns 429 with Retry-After. A validation refusal (400, e.g. a missing or unprobeable URL) returns BEFORE either bucket is touched and carries no RateLimit fields, because a malformed request never spent a probe; this contract used to declare them on those responses too, which described a header that had never been sent. No other operation enforces an application-level ceiling, and so returns no RateLimit headers: declaring a ceiling nothing enforces would be worse than declaring none. A 429 can also arrive from the edge under abuse conditions. A refused request is never charged for. The two figures above are read from the limiter''s own constants, not restated here — this string asserted that NO limit existed for a day after one shipped.'
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
headers:
Retry-After:
schema:
type: integer
description: Seconds to wait before retrying.
NotModified:
description: 'Not Modified: the ETag you sent still names these exact bytes. No body; every other header is as the 200 would carry it.'
BadRequest:
description: The request was malformed or a required parameter was missing.
content:
application/problem+json:
schema:
$ref: '#/components/schemas/Problem'
application/json:
schema:
$ref: '#/components/schemas/Problem'
securitySchemes:
purchaseStatusToken:
type: http
scheme: bearer
description: Private recovery.status_token returned by a catalogue purchase. This capability reads only its original purchase status.
externalDocs:
url: https://scvd.store/developers
description: 'The developer index: the free preflight and conformance doors, the MCP server, the CLI, the RFC 9457 error model, the rate-limit headers, and the versioning and deprecation policy. The full agent briefing is at /llms.txt.'
x-agentcash-provenance:
ownershipProofs:
- '0xd0716b334368fed445d000f12c7e586a6c86e13bd543333bab6c04695df236320c5dbfa4f0beb6807cc486c0ed4fd5a38892a8148d5aa80377db9f35ed4c4b151c'
- 4HduymBCHhwyLgtMyXRpDX3JHQR3oyqTSytsXqCamzCc4ed9fJeBSpDUDSLwfZ59mZaw9ggdMNURPNBi4P6BRU47
x-scvd-ucp:
profile: https://scvd.store/.well-known/ucp
checkout: advertised
x-scvd-native-checkout:
mcp:
protocol: mpp
payment_method: evm
intent: charge
transport: mcp
method: tools/call
path: /mcp
challenge_key: org.paymentauth/payment-required
challenge_location: error.data, or result._meta with ?payment=tool-result
credential_meta_key: org.paymentauth/credential
receipt_meta_key: org.paymentauth/receipt
idempotency_meta_key: x402/idempotency-key
terms: 'each item''s payment_capabilities row with transport http: same network, asset and amount_atomic'
webmcp:
protocol: mpp
payment_method: evm
intent: charge
transport: webmcp
script: /webmcp.js
quote_tool: quote_store_purchase
challenge_field: payment_challenge
complete_tool: complete_store_purchase
credential_argument: signed_credential
receipt_field: payment_receipt
terms: 'each item''s payment_capabilities row with transport http: same network, asset and amount_atomic'
x-rate-limiting:
application_level_limit: true
limited_paths:
- /api/preflight/v1
- /api/preflight/v2
- /api/before-you-pay/v1
- /api/look/v1
- /api/preflight/batch
headers_returned:
- RateLimit-Limit
- RateLimit-Remaining
- RateLimit-Reset
- RateLimit-Policy
- RateLimit
note: 'The free preflight is limited — 30 probes per isolate per minute, 60 global — because it spends outbound requests to a host the caller chooses. Every answer the limiter METERED carries the IETF RateLimit fields — the 200 and the 429 — so you can pace against the live number instead of discovering the ceiling by being refused: RateLimit-Limit / -Remaining / -Reset report whichever of the two buckets is closer to binding, and RateLimit / RateLimit-Policy name both. Past either ceiling it returns 429 with Retry-After. A validation refusal (400, e.g. a missing or unprobeable URL) returns BEFORE either bucket is touched and carries no RateLimit fields, because a malformed request never spent a probe; this contract used to declare them on those responses too, which described a header that had never been sent. No other operation enforces an application-level ceiling, and so returns no RateLimit headers: declaring a ceiling nothing enforces would be worse than declaring none. A 429 can also arrive from the edge under abuse conditions. A refused request is never charged for. The two figures above are read from the limiter''s own constants, not restated here — this string asserted that NO limit existed for a day after one shipped.'
policy_url: https://scvd.store/developers
x-versioning:
scheme: url-path
note: 'Breaking changes arrive as a new version in the path (/api/preflight/v1 → /v2). A published version''s SHAPE never changes under a client: fields are added, never removed or retyped.'
deprecation: A version being retired serves the RFC 8594 Deprecation and Sunset headers on every response for at least 90 days before it stops answering, and the date is published at /developers before the headers appear.
sunset_headers:
- Deprecation
- Sunset
# --- truncated at 32 KB (32 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/scvd-store/refs/heads/main/openapi/scvd-store-a2a-api-openapi.yml