Paid tools over HTTP 402.
Protected routes use x402 v2, the exact payment scheme, real USDC on Base mainnet, and the receiving address published in the API catalog.
No server spending key. The service contains only a public receiving address. Verification and settlement are delegated to a production x402 facilitator.
Payment flow
- Call a protected endpoint without payment.
- Read the PAYMENT-REQUIRED header from the HTTP 402 response.
- Use an x402-compatible client to sign the USDC authorization.
- Retry with PAYMENT-SIGNATURE.
- On success, read PAYMENT-RESPONSE and the JSON result.
curl -i "https://instant.coremesh.online/v1/ssl-report?host=example.com"
# HTTP/2 402 + PAYMENT-REQUIREDGET
/v1/url-health$0.02URL Health
Checks a public HTTP(S) URL. Private, reserved, local, nonstandard-port, and HTTPS-downgrade targets are rejected. Redirects are revalidated and capped.
GET /v1/url-health?url=https%3A%2F%2Fexample.comGET
/v1/ssl-report$0.02SSL Report
Connects to port 443 using a DNS-pinned public address and validates the hostname and certificate chain.
GET /v1/ssl-report?host=example.comGET
/v1/domain-report$0.03Domain Report
Returns bounded A, AAAA, MX, NS, TXT, CAA, and SPF results.
GET /v1/domain-report?domain=example.comPOST
/v1/json-repair$0.01JSON Repair
POST /v1/json-repair
Content-Type: application/json
{"input":"{name:'CoreMesh', active:true,}"}POST
/v1/webhook-verify$0.01Webhook Verify
Payload and signing-key values are processed in memory and excluded from application logs.
{
"payload": "raw request body",
"secret": "your signing key",
"signature": "sha256=...",
"algorithm": "sha256",
"encoding": "hex"
}POST
/v1/hash$0.01Hash
{"input":"hello","inputEncoding":"utf8","algorithm":"sha256"}Limits and failure behavior
- JSON body limit: 32 KiB.
- Outbound URL/TLS timeout: 8 seconds.
- URL redirects: maximum 3.
- Only ports 80 and 443 are accepted by URL Health; SSL Report is fixed to 443.
- Private and reserved address ranges are blocked after DNS resolution.
- Handlers returning HTTP 4xx/5xx do not count as successful service delivery.
- Rate limits apply per client and route.
Machine-readable contract: /openapi.json. Live pricing and wallet: /api/catalog.