Matches registry
The supplied integrity string equals the value returned for that exact package and version.
TableProof independent agent tools
Supply exact public npm package versions and optional SHA-512 integrity values. Receive a dated comparison with registry metadata and OSV advisory IDs, including source hashes and pagination evidence.
The supplied integrity string equals the value returned for that exact package and version.
The supplied string differs. Investigate the discrepancy before drawing a conclusion.
Unavailable sources or incomplete advisory pages never become a successful complete report.
0.01 USDC on Base for a completed batch of 1–3 packages. Introductory fixed price.
POST /v1/npm-integrity through an x402-compatible client with its own purchase permission. An unsigned valid request returns payment requirements. Native Dots purchasing and paid settlement are unverified.
{"packages":[{"name":"lodash","version":"4.17.20"}]}Add optional expected_integrity containing one canonical sha512-… value from a public lockfile. Exact final numeric versions only; no ranges, prereleases, URLs or duplicate coordinates. Maximum 16,000 UTF-8 request bytes.
See the dated live-source example · Request schema · Payment requirements
A match compares supplied text with registry metadata. It does not verify installed bytes, maintainer identity, authenticity or package safety. OSV results use upstream version matching and do not establish exploitability. Zero returned advisories does not mean safe.
No packages downloaded, installed or executed; no transitive dependency analysis or upgrade compatibility testing. Reads fixed npm and OSV hosts only, with a 30-second collection budget, 10 seconds/262,144 bytes per response and at most 3 OSV pages per package. Sources may change after the observation.
Missing registry versions are reported as not found. Incomplete or unknown observations return503 and the current middleware skips settlement. Complete observations can report mismatches or advisories; the price is for checking, not a favorable result.
Public package coordinates and integrity values only. Request contents are not stored; aggregate settled-response counts are not proof of revenue. No private lockfiles, credentials or customer data. No OpenAI/npm/OSV affiliation.
Free alternatives: query the npm registry and OSV API directly. This service combines their observations into one small report.
Tried this tool? Share optional anonymous feedback. Nothing is sent until you choose an experience and submit. No order or follow-up is created.