Dependency checks an AI agent can buy per request.
Agent Dev Preflight API gives coding agents deterministic npm and PyPI vulnerability, license, provenance, upgrade and risk checks before they change dependencies or ship code. No subscription. No API key. Pay only for the request with x402.
Recommended: one full dependency preflight
POST /v1/dependencies/preflight — 0.10 USDC
For most coding-agent workflows, start here. One request checks up to 20 exact npm/PyPI versions for OSV vulnerabilities, upgrade gaps, license metadata, provenance and deterministic risk.
npx awal@latest x402 pay https://agent-dev-preflight-api.bonkoturyu.workers.dev/v1/dependencies/preflight?src=technical-community -X POST -d '{"packages":[{"ecosystem":"npm","name":"express","version":"4.18.2"}]}' --max-amount 100000 --json
Coinbase Agentic Wallet CLI uses USDC atomic units for --max-amount; 100000 is 0.10 USDC. Authenticate and fund the wallet before the first paid call.
Built for agent workflows
Before dependency changes
Check exact installed versions for known vulnerabilities, version gaps and package metadata before an autonomous coding agent edits a lockfile.
Before a PR or release
Run a deterministic dependency preflight across up to 20 npm/PyPI packages and receive structured JSON suitable for policy gates.
Without account setup
An x402-compatible client receives HTTP 402, authorizes the exact USDC amount, retries the request and receives the protected result.
Current paid API
| Endpoint | Price / request | Purpose |
|---|---|---|
POST /v1/package/risk |
0.03 USDC | Deterministic package risk preflight for AI coding agents using OSV and npm/PyPI registry metadata. |
POST /v1/dependencies/vulnerabilities |
0.05 USDC | Batch OSV vulnerability lookup for exact installed npm/PyPI dependency versions before code changes or releases. |
POST /v1/dependencies/preflight |
0.10 USDC | Full dependency security preflight for AI coding agents: vulnerabilities, upgrade gap, license metadata, provenance and risk. |
POST /v1/package/provenance |
0.03 USDC | Software supply-chain package provenance, registry and integrity metadata for autonomous developer workflows. |
POST /v1/dependencies/licenses |
0.03 USDC | Batch npm/PyPI license metadata triage for autonomous dependency review workflows. |
POST /v1/package/upgrade |
0.03 USDC | Dependency upgrade-gap check comparing an exact installed package version with the registry latest version. |
Try the discovery path for free
curl -s https://agent-dev-preflight-api.bonkoturyu.workers.dev/v1/catalog
curl -s https://agent-dev-preflight-api.bonkoturyu.workers.dev/v1/discovery-manifest
# Observe an x402 payment requirement without spending funds:
curl -i -X POST https://agent-dev-preflight-api.bonkoturyu.workers.dev/v1/package/risk \
-H 'content-type: application/json' \
--data '{"package":{"ecosystem":"npm","name":"express","version":"4.18.2"}}'
A payment-capable x402 client can then satisfy the returned PAYMENT-REQUIRED challenge. The paid response is deterministic JSON; the service does not invoke an LLM in the request path.
Discovery
All six paid resources advertise x402 Bazaar metadata and are actively validated by CDP Bazaar. Agents can also inspect the provider-local discovery manifest directly.