{"openapi":"3.1.0","info":{"title":"Revettr","description":"Counterparty risk scoring API for agentic commerce.\n\n**Should this agent send money to this counterparty?**\n\nRevettr scores counterparties by analyzing multiple signal groups in parallel:\n\n- **Domain intelligence**: WHOIS age, DNS configuration (MX, SPF, DMARC), SSL certificate validity\n- **IP intelligence**: Geolocation, VPN/proxy/Tor detection, datacenter classification\n- **Wallet analysis**: On-chain transaction history, wallet age, counterparty diversity\n- **Sanctions screening**: OFAC, EU, and UN sanctions list matching (when available)\n\nSend whatever data you have — more signals means higher confidence. Payment is via x402 (USDC on Base).\n\nBuilt by [L Squared Digital Holdings](https://revettr.com).\n","contact":{"name":"L Squared Digital Holdings","url":"https://revettr.com/"},"license":{"name":"Proprietary"},"version":"0.1.0","x-guidance":"Revettr scores counterparties 0-100 for agentic commerce. Send a POST to /v1/score with any combination of: domain, ip, wallet_address, company_name. Payment is $0.01 USDC via x402 on Base (network configured via settings.NETWORK). No API keys needed."},"paths":{"/health":{"get":{"tags":["System"],"summary":"Health check","description":"Check API status and signal source availability. Always unprotected (no payment required).","operationId":"health_health_get","responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{}}}}}}},"/v1/score":{"post":{"tags":["Scoring"],"summary":"Score a counterparty","description":"Score a counterparty before sending money.\n\nSend any combination of inputs — the API runs all applicable signal checks\nin parallel and returns a composite score.\n\n**Inputs** (all optional, provide at least one):\n- `domain` — triggers WHOIS age, DNS, and SSL checks\n- `ip` — triggers geolocation, VPN/proxy/Tor, and datacenter detection\n- `wallet_address` — triggers on-chain history, wallet age, and counterparty analysis\n- `company_name` — triggers sanctions screening (OFAC, EU, UN)\n\n**Scoring**:\n- Each signal group produces a score from 0 (highest risk) to 100 (safest)\n- The composite score combines available signals into a single risk assessment\n- A score of 0 on any critical signal forces the composite to 0\n- Confidence increases with more input fields provided\n\n**Tier differences**:\n- **Paid** ($0.01 USDC per request via x402): runs the full wallet signal\n  including Tier 3 InsumerAPI cross-chain enrichment, scoring 8 chains\n  in total (5 direct + Solana, XRPL, Bitcoin via InsumerAPI).\n- **Free tier** (100 requests/day per IP): runs Tiers 1 and 2 of the\n  wallet signal (Base RPC + Alchemy + ERC-8004) but skips Tier 3\n  InsumerAPI cross-chain enrichment to keep Revettr's upstream costs\n  bounded. Free-tier signed envelopes carry `wallet.insumer_skipped: true`\n  so verifiers can distinguish them from paid envelopes.\n\n**Pricing**: $0.01 USDC per request via x402 on Base.","operationId":"risk_score_v1_score_post","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScoreRequest"}}},"required":true},"responses":{"200":{"description":"Composite risk score with per-signal breakdown","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScoreResponse"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}},"402":{"description":"Payment Required — pay via x402 (USDC on Base), MPP (pathUSD on Tempo), or Stellar (XLM)"}},"x-payment-info":{"pricingMode":"fixed","price":"0.01","authMode":"payment","x402":{"network":"eip155:8453","asset":"USDC"},"mpp":{"method":"tempo","chain_id":4217,"currency":"pathUSD"},"stellar":{"network":"stellar:testnet","asset":"XLM"},"protocols":["x402","mpp","stellar"]}}},"/v1/score/batch":{"post":{"tags":["Scoring"],"summary":"Score multiple counterparties","description":"Score up to 10 counterparties in a single request.\n\nEach item in the requests array follows the same format as POST /v1/score.\nResults are returned in the same order as the requests.\nPartial success is supported — individual failures return score 50 with error flags.\n\n**Tier differences** (mirror POST /v1/score):\n- **Paid** ($0.008 USDC per counterparty in 10+ batch via x402): runs full\n  wallet signal including Tier 3 InsumerAPI cross-chain enrichment.\n- **Free tier** (counts against the same 100/day IP limit): skips Tier 3\n  InsumerAPI cross-chain enrichment to bound Revettr's upstream costs.\n\n**Pricing**: $0.01 USDC per counterparty via x402 on Base (same as individual requests).\nFree tier: counts against the same 100/day IP limit.","operationId":"risk_score_batch_v1_score_batch_post","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BatchScoreRequest"}}},"required":true},"responses":{"200":{"description":"Array of risk scores","content":{"application/json":{"schema":{}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}},"402":{"description":"Payment Required — pay via x402 (USDC on Base), MPP (pathUSD on Tempo), or Stellar (XLM)"}},"x-payment-info":{"pricingMode":"fixed","price":"0.01","authMode":"payment","x402":{"network":"eip155:8453","asset":"USDC"},"mpp":{"method":"tempo","chain_id":4217,"currency":"pathUSD"},"stellar":{"network":"stellar:testnet","asset":"XLM"},"protocols":["x402","mpp","stellar"]}}},"/v1/waitlist":{"post":{"tags":["Waitlist"],"summary":"Register an agent on the waitlist","description":"Register your agent on the Revettr waitlist.\n\nWe're not building for you — we're building for your agents.\n\nYour agent pays $0.001 USDC via x402 to register. The wallet address is\nrecovered from the payment. No forms. No emails. If your agent can pay,\nit can register.\n\n**Pricing**: $0.001 USDC via x402 on Base.","operationId":"waitlist_register_endpoint_v1_waitlist_post","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/WaitlistRequest"}}},"required":true},"responses":{"200":{"description":"Registration confirmation with position","content":{"application/json":{"schema":{}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}},"402":{"description":"Payment Required — pay via x402 (USDC on Base), MPP (pathUSD on Tempo), or Stellar (XLM)"}},"x-payment-info":{"pricingMode":"fixed","price":"0.01","authMode":"payment","x402":{"network":"eip155:8453","asset":"USDC"},"mpp":{"method":"tempo","chain_id":4217,"currency":"pathUSD"},"stellar":{"network":"stellar:testnet","asset":"XLM"},"protocols":["x402","mpp","stellar"]}}},"/v1/waitlist/count":{"get":{"tags":["Waitlist"],"summary":"Waitlist count","description":"Current waitlist size. Resets on cold starts — the audit log is the source of truth.","operationId":"waitlist_count_endpoint_v1_waitlist_count_get","responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{}}}}}}},"/v1/score/session":{"post":{"tags":["Scoring"],"summary":"Score a counterparty and receive a reusable session token","description":"Score a counterparty and receive a signed session token.\n\nPay once ($0.01 USDC) and receive a JWS session token valid for 1 hour.\nThe token attests to the counterparty's risk score and can be presented\nto any verifier for the TTL duration without re-scoring or re-paying.\n\nIdeal for agents making many micropayments to the same counterparty\nwithin a session. Score once, transact many times.\n\n**Pricing**: $0.01 USDC per session via x402 on Base, MPP on Tempo, or Stellar.","operationId":"score_session_v1_score_session_post","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/SessionScoreRequest"}}},"required":true},"responses":{"200":{"description":"Signed JWS session token valid for 1 hour","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SessionScoreResponse"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/v1/session/verify":{"get":{"tags":["Scoring"],"summary":"Verify a session token","description":"Verify a Revettr session token.\n\nAccepts a JWS session token (from POST /v1/score/session) and verifies:\n1. The signature is valid (ES256, kid: revettr-attest-v1)\n2. The token has not expired (exp claim)\n\nReturns the score, tier, subject, and expiry if valid.\n\n**Free endpoint** — no payment required. Rate limited to 60/minute.","operationId":"verify_session_v1_session_verify_get","parameters":[{"name":"token","in":"query","required":true,"schema":{"type":"string","title":"Token"}}],"responses":{"200":{"description":"Token validity status with score and expiry","content":{"application/json":{"schema":{}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/v1/risk-check":{"post":{"tags":["Scoring"],"summary":"Facilitator-facing risk check (x402 extension format)","description":"Score a counterparty and return the result in x402 risk-check extension format.\n\nDesigned for **facilitators** implementing the x402 `risk-check` extension.\nThe response matches the `RiskCheckResult` schema exactly — facilitators\nembed it directly into `SettleResponse.extensions[\"risk-check\"]`.\n\nOne call per payer, cached for the 1-hour TTL. Facilitators amortize this\nacross all voucher settlements for the same payer within the batch window.\n\n**Pricing**: $0.01 USDC per request via x402 on Base.\nFree tier: 100 requests/day per IP (skips InsumerAPI cross-chain enrichment).","operationId":"risk_check_v1_risk_check_post","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScoreRequest"}}},"required":true},"responses":{"200":{"description":"RiskCheckResult for embedding in SettleResponse.extensions['risk-check']","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RiskCheckResult"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/v1/risk-check/batch":{"post":{"tags":["Scoring"],"summary":"Batch risk check for facilitators (x402 extension format)","description":"Score multiple payers and return results in x402 risk-check extension format.\n\nDesigned for **facilitators** settling batches from multiple payers simultaneously.\nEach result matches the `RiskCheckResult` schema for direct embedding into\n`SettleResponse.extensions[\"risk-check\"]`.\n\n**Pricing**: $0.01 USDC per payer (total = payers * $0.01) via x402 on Base.","operationId":"risk_check_batch_v1_risk_check_batch_post","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RiskCheckBatchRequest"}}},"required":true},"responses":{"200":{"description":"List of RiskCheckResults for multiple payers","content":{"application/json":{"schema":{}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/v1/attest":{"post":{"tags":["Scoring"],"summary":"Generate a signed compliance_risk attestation","description":"Generate a signed compliance_risk attestation for the given counterparty.\n\nReturns a compact JWS (RFC 7515) alongside the full envelope metadata.\nThe attestation covers domain intelligence, IP reputation, sanctions\nscreening (OFAC/EU/UN), and wallet history. Verify signatures against\n`https://revettr.com/.well-known/jwks.json` (kid: `revettr-attest-v1`,\nalg: ES256).\n\nThis endpoint is free tier (10 req/min per IP) and does not require\npayment. It returns the attestation envelope only, without the full\nscoring detail exposed on POST /v1/score.","operationId":"attest_v1_attest_post","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScoreRequest"}}},"required":true},"responses":{"200":{"description":"Compact JWS attestation envelope","content":{"application/json":{"schema":{}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}}}},"/v1/iss-verdict":{"post":{"tags":["Scoring"],"summary":"Pre-call risk verdict for an MCP issuer (iss)","description":"Return an advisory risk verdict for a validated MCP `iss` (issuer).\n\nPrototype for goal-plan WP2.5 (spec B8). The MCP RC (locks 2026-07-28)\nmandates client-side validation of the `iss` parameter — an *identity* check.\nThis endpoint attaches a *risk* verdict at that step: given the validated\nissuer, it maps `iss` → Revettr's existing counterparty signals and returns\nthe same signed `RiskCheckResult` the `/v1/risk-check` engine produces.\n\n**Advisory and non-blocking** — the response always carries `advisory: true`;\nthe MCP client owns the decision. Free (no payment) for the prototype.\n\nBody: `{ \"iss\": \"...\", \"iss_kind\": \"url\"|\"did\"|\"client_id\", \"context\": {...} }`\nThe only RC-coupled logic lives in `app.integrations.iss_verdict.normalize_iss`.","operationId":"iss_verdict_v1_iss_verdict_post","responses":{"200":{"description":"Advisory verdict envelope wrapping a signed RiskCheckResult","content":{"application/json":{"schema":{}}}}}}}},"components":{"schemas":{"BatchScoreRequest":{"properties":{"requests":{"items":{"$ref":"#/components/schemas/ScoreRequest"},"type":"array","maxItems":10,"minItems":1,"title":"Requests"}},"type":"object","required":["requests"],"title":"BatchScoreRequest","description":"Batch scoring request — up to 10 counterparties."},"FreezeRisk":{"properties":{"symbol":{"type":"string","title":"Symbol","description":"Stablecoin symbol assessed"},"issuer":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Issuer","description":"Issuing entity"},"jurisdiction":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Jurisdiction","description":"Issuer jurisdiction"},"risk_tier":{"type":"string","title":"Risk Tier","description":"Issuer freeze-risk tier: low, medium, high, unknown"},"freeze_risk_score":{"anyOf":[{"type":"integer","maximum":100.0,"minimum":0.0},{"type":"null"}],"title":"Freeze Risk Score","description":"Issuer freeze-risk score: 0 = highest risk, 100 = safest. Null if issuer unknown."},"sanction_exposure":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Sanction Exposure","description":"Issuer sanction exposure: low, medium, high"},"exchange_concentration":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Exchange Concentration","description":"Float concentration on a small venue set: low, medium, high"},"freeze_event_count":{"type":"integer","title":"Freeze Event Count","description":"Count of documented freeze events for this issuer","default":0},"flags":{"items":{"type":"string"},"type":"array","title":"Flags","description":"Freeze-risk flags triggered"},"available":{"type":"boolean","title":"Available","description":"False when the issuer is not in the registry","default":true},"notes":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Notes","description":"Human-readable context"}},"type":"object","required":["symbol","risk_tier"],"title":"FreezeRisk","description":"Additive issuer-level freeze-risk assessment for a stablecoin.\n\nCaptures the risk that the *issuer* of a stablecoin can unilaterally freeze\nor claw back a counterparty's balance — independent of the counterparty's own\nrisk. Populated only when the request names a ``stablecoin``. Advisory: it\ndoes not feed the composite score."},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"type":"array","title":"Detail"}},"type":"object","title":"HTTPValidationError"},"HarnessHygiene":{"properties":{"subscript":{"anyOf":[{"type":"integer","maximum":100.0,"minimum":0.0},{"type":"null"}],"title":"Subscript","description":"Harness-hygiene subscript 0-100 (100 = best-contained). ADVISORY ONLY; not part of the composite."},"signals":{"additionalProperties":{"$ref":"#/components/schemas/HarnessSignal"},"type":"object","title":"Signals","description":"Per-signal breakdown"},"evidence_basis":{"type":"string","title":"Evidence Basis","description":"'attested' | 'inferred' | 'mixed' | 'none'"},"claim_verified":{"anyOf":[{"type":"boolean"},{"type":"null"}],"title":"Claim Verified","description":"True if a JWS harness claim verified against the operator JWKS; False if supplied but unverifiable; None if no claim supplied"},"claim_kid":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Claim Kid","description":"kid of the verified claim signer, if any"},"flags":{"items":{"type":"string"},"type":"array","title":"Flags","description":"e.g. 'self_asserted_unverified', 'claim_expired', 'inferred_low_confidence'"}},"type":"object","required":["evidence_basis"],"title":"HarnessHygiene","description":"ADDITIVE, ADVISORY subscript on the counterparty's execution-harness\ncontainment posture (goal plan WP3.3).\n\nThe strongest finding in the agent-risk corpus is that the *harness* (sandbox,\nverification loop, scoped credentials, session recording) dominates the model:\na weaker model in a well-contained harness is materially lower risk than a\nstronger model with broad credentials and no guardrails. This subscript lets a\npayer read that operational posture alongside the v4 score.\n\nIt is **never** folded into the frozen v4 composite — asserting good hygiene\ncannot raise the score a counterparty is gated on. Null when no harness claim\nwas supplied and nothing could be inferred (serializes exactly like\n``freeze_risk`` when not applicable)."},"HarnessSignal":{"properties":{"present":{"anyOf":[{"type":"boolean"},{"type":"null"}],"title":"Present","description":"True if asserted/inferred present; False if asserted absent; None if unknown"},"source":{"type":"string","title":"Source","description":"'attested' | 'inferred' | 'unknown'"},"detail":{"additionalProperties":true,"type":"object","title":"Detail","description":"Raw evidence: claim ref, inference method, etc."}},"type":"object","required":["source"],"title":"HarnessSignal","description":"One harness-hygiene signal (e.g. sandbox, verification_loop).\n\n``present`` is ``True`` when the property is asserted or inferred present,\n``False`` when asserted absent, and ``None`` when unknown. Unknown signals\nare excluded from the subscript math entirely (they neither help nor hurt)."},"ModelProvenanceClaim":{"properties":{"model_id":{"anyOf":[{"type":"string","maxLength":256},{"type":"null"}],"title":"Model Id","description":"Namespaced model identity the claimant asserts, e.g. 'anthropic/claude-opus-4.x'. Normalized at ingest (lowercased, NFC, whitespace-collapsed). A claim, never verified against the vendor.","examples":["anthropic/claude-opus-4.x","openai/gpt-class-4.x"]},"version_hash":{"anyOf":[{"type":"string","maxLength":128},{"type":"null"}],"title":"Version Hash","description":"Opaque, prefix-tagged content hash of the asserted model build (e.g. 'sha256:9f2c...'). Revettr never computes it and cannot verify it corresponds to real weights; only well-formedness is checked.","examples":["sha256:9f2c0b1e..."]},"execution_harness":{"anyOf":[{"type":"string","maxLength":256},{"type":"null"}],"title":"Execution Harness","description":"Identifier of the runtime that ran the model, ideally a resolvable did:web. Reserved for the harness-attested tier (follow-on work); recorded today."},"claim_type":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Claim Type","description":"self_asserted | harness_attested | provider_attested. Only self_asserted is verifiable in this build; higher tiers are recorded but flagged attestation_not_yet_verified.","default":"self_asserted"}},"type":"object","title":"ModelProvenanceClaim","description":"Self-asserted claim of which model/harness executed the scored action.\n\nEvery field is independently nullable (spec B4 §2.1): a claimant may supply\na ``model_id`` without a ``version_hash``, or vice versa. Missing is not\ninvalid — it is itself a (weak) signal. None of these fields is ever\nvalidated against the vendor; they are *claims*, recorded and tier-classified."},"ProvenanceSignal":{"properties":{"available":{"type":"boolean","title":"Available","description":"False when no model_provenance claim was supplied"},"trust_tier":{"type":"string","title":"Trust Tier","description":"Verifiability tier (NOT a quality rating): self_asserted | harness_attested | provider_attested. Only self_asserted is verified in this build."},"confidence":{"type":"number","maximum":1.0,"minimum":0.0,"title":"Confidence","description":"How sure we are the claim is genuine (0.0-1.0). NOT a measure of model quality."},"model_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Model Id","description":"Normalized claimed model identity, or null"},"version_hash":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Version Hash","description":"Claimed opaque build hash, or null"},"claim_type":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Claim Type","description":"self_asserted | harness_attested | provider_attested, as claimed"},"registry_match":{"type":"boolean","title":"Registry Match","description":"True if the (model_id, version_hash) pair matches a known-model registry entry (string match only, never proof)","default":false},"advisory_delta":{"type":"integer","maximum":5.0,"minimum":-15.0,"title":"Advisory Delta","description":"Suggested, NON-BINDING adjustment a relying party MAY apply [-15..+5]. Never applied to the v4 score.","default":0},"flags":{"items":{"type":"string"},"type":"array","title":"Flags","description":"e.g. 'no_provenance_supplied', 'version_hash_missing', 'registry_match', 'registry_flagged'"},"rationale":{"type":"string","title":"Rationale","description":"Human-readable disambiguator for the claim/quality orthogonality","default":""}},"type":"object","required":["available","trust_tier","confidence"],"title":"ProvenanceSignal","description":"ADDITIVE, ADVISORY model-provenance signal (goal plan WP3.4 / spec B4).\n\nCaptures *which model the counterparty claims executed the action* and\nclassifies the **verifiability of that claim** — not the model's quality.\nA perfectly recorded claim that the counterparty runs a weak model gets\n*high* confidence (we are sure what was claimed) and a *negative-ish*\nadvisory delta; the two axes are orthogonal and ``rationale`` disambiguates.\n\nNever folded into the frozen v4 composite. ``advisory_delta`` is the only\nnumber a relying party MAY apply, and it is non-binding and clamped\nasymmetrically (provenance can lower trust meaningfully, raise it modestly).\nPresent as ``available=False`` when no claim was supplied so a relying party\ncan tell \"not asked\" from \"asked, weak.\""},"RiskCheckBatchRequest":{"properties":{"payers":{"items":{"$ref":"#/components/schemas/ScoreRequest"},"type":"array","maxItems":10,"minItems":1,"title":"Payers"}},"type":"object","required":["payers"],"title":"RiskCheckBatchRequest","description":"Batch risk-check request for facilitators — up to 10 payers."},"RiskCheckResult":{"properties":{"checked":{"type":"boolean","title":"Checked","description":"Whether a risk check was performed"},"score":{"anyOf":[{"type":"integer","maximum":100.0,"minimum":0.0},{"type":"null"}],"title":"Score","description":"Risk score 0-100 (0 = highest risk, 100 = safest)"},"tier":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Tier","description":"Risk tier: \"low\", \"medium\", \"high\", \"critical\""},"provider":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Provider","description":"Provider DID (e.g., did:web:revettr.com)"},"categories":{"anyOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}],"title":"Categories","description":"Attestation categories covered"},"jws":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Jws","description":"Compact JWS (RFC 7515) signed attestation"},"jwks_url":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Jwks Url","description":"URL to provider's JWKS for signature verification"},"checked_at":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Checked At","description":"ISO 8601 timestamp when the check was performed"},"expires_at":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Expires At","description":"ISO 8601 expiry timestamp for the attestation"}},"type":"object","required":["checked"],"title":"RiskCheckResult","description":"Facilitator-facing risk-check result.\n\nMatches the x402 risk-check extension SettleResponse format exactly.\nFacilitators embed this verbatim into SettleResponse.extensions[\"risk-check\"].\nSee: x402-foundation/x402 specs/extensions/risk-check.md"},"ScoreRequest":{"properties":{"domain":{"anyOf":[{"type":"string","maxLength":253},{"type":"null"}],"title":"Domain","description":"Domain or URL of the counterparty (e.g., 'example.com' or 'https://example.com')","examples":["uniswap.org","https://aave.com"]},"ip":{"anyOf":[{"type":"string","maxLength":45},{"type":"null"}],"title":"Ip","description":"IP address of the counterparty server","examples":["104.18.28.72","8.8.8.8"]},"wallet_address":{"anyOf":[{"type":"string","maxLength":42},{"type":"null"}],"title":"Wallet Address","description":"EVM wallet address on Base chain (0x...)","examples":["0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045"]},"solana_wallet":{"anyOf":[{"type":"string","maxLength":44},{"type":"null"}],"title":"Solana Wallet","description":"Solana wallet address — adds cross-chain trust dimension"},"xrpl_wallet":{"anyOf":[{"type":"string","maxLength":35},{"type":"null"}],"title":"Xrpl Wallet","description":"XRPL wallet address (r...) — adds cross-chain trust dimension"},"bitcoin_wallet":{"anyOf":[{"type":"string","maxLength":62},{"type":"null"}],"title":"Bitcoin Wallet","description":"Bitcoin wallet address (bc1...) — adds cross-chain trust dimension"},"stellar_wallet":{"anyOf":[{"type":"string","maxLength":56},{"type":"null"}],"title":"Stellar Wallet","description":"Stellar wallet address (G...) — adds Stellar chain scoring","examples":["GAAZI4TCR3TY5OJHCTJC2A4QSY6CJWJH5IAJTGKIN2ER7LBNVKOCCWN7"]},"chain":{"anyOf":[{"type":"string","maxLength":20},{"type":"null"}],"title":"Chain","description":"Blockchain network for wallet analysis (default: base)","default":"base","examples":["base","ethereum"]},"company_name":{"anyOf":[{"type":"string","maxLength":200},{"type":"null"}],"title":"Company Name","description":"Legal or business name to screen against sanctions lists (OFAC, EU, UN)","examples":["Acme Corp","John Smith"]},"email":{"anyOf":[{"type":"string","maxLength":254},{"type":"null"}],"title":"Email","description":"Email address — future signal, not yet scored"},"amount":{"anyOf":[{"type":"number","maximum":1000000000000.0,"minimum":0.0},{"type":"null"}],"title":"Amount","description":"Transaction amount in USD — for context, does not affect score today","examples":[100.0,5000.0]},"publish_to_registry":{"type":"boolean","title":"Publish To Registry","description":"If true and the wallet has an ERC-8004 agent registration, write the score as a Validation entry on-chain. Scores become permanently public.","default":false},"stablecoin":{"anyOf":[{"type":"string","maxLength":12},{"type":"null"}],"title":"Stablecoin","description":"Stablecoin symbol the counterparty settles in (e.g., 'USDC', 'USDT', 'USD1'). When provided, the response includes an additive issuer freeze-risk assessment. Does not affect the composite score.","examples":["USDC","USD1"]},"harness_claim":{"anyOf":[{"type":"string","maxLength":8192},{"type":"null"}],"title":"Harness Claim","description":"Optional operator-signed harness claim (compact JWS, ES256) asserting the counterparty's execution-harness containment posture (sandbox, verification loop, scoped credentials, session recording). When supplied and verified, the response includes an additive, ADVISORY harness_hygiene subscript. Never affects the composite score."},"model_provenance":{"anyOf":[{"$ref":"#/components/schemas/ModelProvenanceClaim"},{"type":"null"}],"description":"Optional self-asserted claim of which model/harness executed (or will execute) the scored action. When supplied, the response includes an additive, ADVISORY provenance_signal that classifies the verifiability of the claim (NOT model quality). Never affects the composite score."}},"type":"object","title":"ScoreRequest","description":"Send whatever data you have about a counterparty. More fields = higher confidence score.\n\nAt minimum, provide one of: domain, ip, wallet_address, or company_name.","examples":[{"domain":"uniswap.org","ip":"104.18.28.72","wallet_address":"0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045"},{"wallet_address":"0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045"},{"company_name":"Sketchy LLC","domain":"sketchy-service.xyz"}]},"ScoreResponse":{"properties":{"score":{"type":"integer","maximum":100.0,"minimum":0.0,"title":"Score","description":"Composite risk score: 0 = highest risk, 100 = safest"},"tier":{"type":"string","title":"Tier","description":"Risk tier: low (80-100), medium (60-79), high (30-59), critical (0-29)"},"confidence":{"type":"number","maximum":1.0,"minimum":0.0,"title":"Confidence","description":"Confidence level (0.0-1.0) based on how many signal groups were available"},"signals_checked":{"type":"integer","title":"Signals Checked","description":"Number of signal groups evaluated"},"flags":{"items":{"type":"string"},"type":"array","title":"Flags","description":"All risk flags triggered across all signals"},"signal_scores":{"additionalProperties":{"$ref":"#/components/schemas/SignalScore"},"type":"object","title":"Signal Scores","description":"Per-signal-group breakdown (domain, ip, wallet, sanctions)"},"metadata":{"additionalProperties":true,"type":"object","title":"Metadata","description":"Request metadata including latency, version, and inputs provided"},"freeze_risk":{"anyOf":[{"$ref":"#/components/schemas/FreezeRisk"},{"type":"null"}],"description":"Additive issuer freeze-risk assessment. Present only when the request names a stablecoin; does not affect the composite score."},"harness_hygiene":{"anyOf":[{"$ref":"#/components/schemas/HarnessHygiene"},{"type":"null"}],"description":"ADDITIVE advisory subscript on the counterparty's execution-harness containment. Present only when a harness claim is supplied or a signal can be inferred; never part of the frozen v4 composite."},"provenance_signal":{"anyOf":[{"$ref":"#/components/schemas/ProvenanceSignal"},{"type":"null"}],"description":"ADDITIVE advisory model-provenance signal. Present only when a model_provenance claim is supplied; classifies the verifiability of the claim, never the model's quality, and never part of the frozen v4 composite."}},"type":"object","required":["score","tier","confidence","signals_checked"],"title":"ScoreResponse","description":"Composite counterparty risk assessment.\n\nScore ranges:\n- 80-100 (low risk): Counterparty appears legitimate\n- 60-79 (medium risk): Some signals warrant caution\n- 30-59 (high risk): Multiple risk indicators present\n- 0-29 (critical risk): Strong risk signals — do not transact\n\nA score of 0 indicates a hard match (e.g., exact sanctions match)."},"SessionScoreRequest":{"properties":{"domain":{"anyOf":[{"type":"string","maxLength":253},{"type":"null"}],"title":"Domain","description":"Domain or URL of the counterparty"},"ip":{"anyOf":[{"type":"string","maxLength":45},{"type":"null"}],"title":"Ip","description":"IP address of the counterparty server"},"wallet_address":{"anyOf":[{"type":"string","maxLength":42},{"type":"null"}],"title":"Wallet Address","description":"EVM wallet address on Base chain (0x...)"},"solana_wallet":{"anyOf":[{"type":"string","maxLength":44},{"type":"null"}],"title":"Solana Wallet","description":"Solana wallet address"},"xrpl_wallet":{"anyOf":[{"type":"string","maxLength":35},{"type":"null"}],"title":"Xrpl Wallet","description":"XRPL wallet address (r...)"},"bitcoin_wallet":{"anyOf":[{"type":"string","maxLength":62},{"type":"null"}],"title":"Bitcoin Wallet","description":"Bitcoin wallet address (bc1...)"},"stellar_wallet":{"anyOf":[{"type":"string","maxLength":56},{"type":"null"}],"title":"Stellar Wallet","description":"Stellar wallet address (G...)"},"chain":{"anyOf":[{"type":"string","maxLength":20},{"type":"null"}],"title":"Chain","description":"Blockchain network for wallet analysis","default":"base"},"company_name":{"anyOf":[{"type":"string","maxLength":200},{"type":"null"}],"title":"Company Name","description":"Legal or business name to screen against sanctions lists"},"email":{"anyOf":[{"type":"string","maxLength":254},{"type":"null"}],"title":"Email","description":"Email address"},"amount":{"anyOf":[{"type":"number","maximum":1000000000000.0,"minimum":0.0},{"type":"null"}],"title":"Amount","description":"Transaction amount in USD"},"parent_session_id":{"anyOf":[{"type":"string","maxLength":64},{"type":"null"}],"title":"Parent Session Id","description":"Session id of a trusted parent/orchestrator session. When set, this session is SCOPED: its score is capped at the parent's score and its TTL cannot outlive the parent. Revoking the parent revokes this session."},"session_context":{"anyOf":[{"type":"string","maxLength":200},{"type":"null"}],"title":"Session Context","description":"Free-text label for the spawned session/task (e.g., 'invoice-pay-batch-7'). Recorded in the token for audit."},"ttl_seconds":{"anyOf":[{"type":"integer","maximum":3600.0,"minimum":60.0},{"type":"null"}],"title":"Ttl Seconds","description":"Requested token lifetime in seconds (60–3600). Defaults to 3600. Capped at the parent's remaining lifetime for scoped sessions."}},"type":"object","title":"SessionScoreRequest","description":"Session scoring request — same fields as ScoreRequest.\n\nPay once ($0.01) and receive a signed JWS session token valid for 1 hour.\nPresent the token to any verifier for the TTL duration without re-scoring."},"SessionScoreResponse":{"properties":{"session_token":{"type":"string","title":"Session Token","description":"Signed JWS session token (compact serialization)"},"expires_at":{"type":"integer","title":"Expires At","description":"Unix timestamp when the session token expires"},"score":{"type":"integer","maximum":100.0,"minimum":0.0,"title":"Score","description":"Risk score: 0 = highest risk, 100 = safest"},"tier":{"type":"string","title":"Tier","description":"Risk tier: low_risk (80-100), medium_risk (60-79), high_risk (30-59), critical (0-29)"},"subject":{"additionalProperties":true,"type":"object","title":"Subject","description":"Subject details (wallet, domain, or IP scored)"},"counterparty":{"type":"string","title":"Counterparty","description":"Primary identifier of the scored counterparty"},"session_id":{"type":"string","title":"Session Id","description":"Unique id for this session — used to revoke or to scope child sessions"},"parent_session_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Parent Session Id","description":"Parent session id if this session is scoped"},"scoped":{"type":"boolean","title":"Scoped","description":"True when the score was inherited/capped from a parent session","default":false}},"type":"object","required":["session_token","expires_at","score","tier","subject","counterparty","session_id"],"title":"SessionScoreResponse","description":"Response from the session scoring endpoint.\n\nContains a signed JWS session token that can be presented to verifiers\nfor the TTL duration (1 hour) without re-scoring or re-paying."},"SignalScore":{"properties":{"score":{"type":"integer","maximum":100.0,"minimum":0.0,"title":"Score","description":"Signal score: 0 = highest risk, 100 = safest"},"flags":{"items":{"type":"string"},"type":"array","title":"Flags","description":"Risk flags triggered by this signal"},"available":{"type":"boolean","title":"Available","description":"Whether this signal source was reachable","default":true},"details":{"additionalProperties":true,"type":"object","title":"Details","description":"Raw signal data for transparency"}},"type":"object","required":["score"],"title":"SignalScore","description":"Score from a single signal group (0-100)."},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"type":"array","title":"Location"},"msg":{"type":"string","title":"Message"},"type":{"type":"string","title":"Error Type"},"input":{"title":"Input"},"ctx":{"type":"object","title":"Context"}},"type":"object","required":["loc","msg","type"],"title":"ValidationError"},"WaitlistRequest":{"properties":{"agent_name":{"type":"string","maxLength":100,"minLength":1,"title":"Agent Name","description":"Name of the AI agent"},"framework":{"anyOf":[{"type":"string","maxLength":50},{"type":"null"}],"title":"Framework","description":"Agent framework (LangChain, CrewAI, AI SDK, etc.)"},"use_case":{"anyOf":[{"type":"string","maxLength":500},{"type":"null"}],"title":"Use Case","description":"How the agent will use Revettr"}},"type":"object","required":["agent_name"],"title":"WaitlistRequest","description":"Agent waitlist registration body."}}}}