CoreMesh Instant
COREMESH INSTANT API

Paid tools over HTTP 402.

Protected routes use x402 v2, the exact payment scheme, real USDC on Base mainnet, and the receiving address published in the API catalog.

No server spending key. The service contains only a public receiving address. Verification and settlement are delegated to a production x402 facilitator.

Payment flow

  1. Call a protected endpoint without payment.
  2. Read the PAYMENT-REQUIRED header from the HTTP 402 response.
  3. Use an x402-compatible client to sign the USDC authorization.
  4. Retry with PAYMENT-SIGNATURE.
  5. On success, read PAYMENT-RESPONSE and the JSON result.
curl -i "https://instant.coremesh.online/v1/ssl-report?host=example.com"
# HTTP/2 402 + PAYMENT-REQUIRED
GET/v1/url-health$0.02

URL Health

Checks a public HTTP(S) URL. Private, reserved, local, nonstandard-port, and HTTPS-downgrade targets are rejected. Redirects are revalidated and capped.

GET /v1/url-health?url=https%3A%2F%2Fexample.com
GET/v1/ssl-report$0.02

SSL Report

Connects to port 443 using a DNS-pinned public address and validates the hostname and certificate chain.

GET /v1/ssl-report?host=example.com
GET/v1/domain-report$0.03

Domain Report

Returns bounded A, AAAA, MX, NS, TXT, CAA, and SPF results.

GET /v1/domain-report?domain=example.com
POST/v1/json-repair$0.01

JSON Repair

POST /v1/json-repair
Content-Type: application/json

{"input":"{name:'CoreMesh', active:true,}"}
POST/v1/webhook-verify$0.01

Webhook Verify

Payload and signing-key values are processed in memory and excluded from application logs.

{
  "payload": "raw request body",
  "secret": "your signing key",
  "signature": "sha256=...",
  "algorithm": "sha256",
  "encoding": "hex"
}
POST/v1/hash$0.01

Hash

{"input":"hello","inputEncoding":"utf8","algorithm":"sha256"}

Limits and failure behavior

  • JSON body limit: 32 KiB.
  • Outbound URL/TLS timeout: 8 seconds.
  • URL redirects: maximum 3.
  • Only ports 80 and 443 are accepted by URL Health; SSL Report is fixed to 443.
  • Private and reserved address ranges are blocked after DNS resolution.
  • Handlers returning HTTP 4xx/5xx do not count as successful service delivery.
  • Rate limits apply per client and route.

Machine-readable contract: /openapi.json. Live pricing and wallet: /api/catalog.