X/LinkedIn
●  BASE · --:--:-- UTC
TRY 402
pay-per-call
APIs for
AI agents
signed
on Base
in USDC

nsgoods

nsgoods is a suite of twelve x402 pay-per-call APIs for AI agents on Base + Solana — signed, provable, with a free preview on every service.

● 12 services · live on Base + Solana

Independently verified, in public.

An independent consumer verified our frozen preflight_v3 contract offline: 9/9 tamper cases rejected, every component and envelope signature checked.

Published by Maha Strategies as external integration evidence — fixture-only, not a live-endpoint result.

Our exports and response signatures have been independently verified by AsterPay (September 2026).

ExactZK (independent zkML provenance project) independently verified the nsgoods signing construction by counter test, recomputed the JCS digests of specific published attestations and matched them to the values we publish, and checked that our signed manifest is the authority scoping the signing key. September 2026. This verification covers those signatures and our manifest only, not our services.

Independent reproductions: we rebuild third party deployed artifacts on a clean disposable host and publish signed attestations. Six signed attestation records are in our /proof/index.json, covering four independent reproductions of the ExactZK bundle, including the first signed reproduction of the solo circuit's verifying key, now filed on chain; four of the records are also published in the upstream ExactZK zkML provenance bundle.

In production: SafeGate evidence references our signed screening verdict by hash and request id. In a self funded live run on Base mainnet on 25 September 2026, the verdict SafeGate retained was checked from both sides: same bytes, same signer, same request id. Case study, published by SafeGate →

their record →  ·  /proof

Public observatory: x401 adoption →  ·  weekly payability report →

More third party records that reference nsgoods, none written or paid for by us: /proof/observed.html

Payment traffic is public by design. Inspect it yourself on Basescan

Integrations, in production.
Walpulse

In production: Walpulse renders our signed sanctions verdicts inside its own product UI. Their reader does not trust them or us, the UI verifies the EIP-191 signature on every render. "If it fails, the row is not a fact." (their words, on X)

Case study: how the integration works

Waveline

Waveline, by Dimos Papageorgiou, sells its artist insights to AI agents over x402: 0.005 USDC on Base. It is the first site nsgoods checked end to end before it opened to agents. We made its first mainnet payment, and nsgoods Watchdog checks its payment terms every 15 minutes.

Docs and verifiable transactions

SafeGate

SafeGate by Nurexen Labs. Post-payment commerce verification and evidence infrastructure for agent commerce. On Base, its paid evidence can reference nsgoods signed sanctions verdicts by hash and request ID.

Case study: how the integration works

safegatelabs.xyz

In the wild

From nohumans.directory's weekly report (September 2026), covering our measurement exchange over their catalogue:

“nsgoods — a weekly payability observatory that scanned our catalogue and wrote to us with numbers.”
“He also found a hole in our changes feed we could not have found ourselves.”

The same report answers a probing question of ours against their own data, prints a finding of ours they cannot verify themselves and says so, and carries a labelling correction we made to our own earlier figure. Full text: their report →

01 — Services

Twelve oracles.
One cup each.

01 Kraken Crypto SignalsSigned BUY/SELL/HOLD trading signals + confidence for Kraken pairs — signals.nsgoods.org from $0.005+
Endpoints
GET /backtest$0.25
GET /signals/top$0.10
GET /history$0.05
GET /regime/changed$0.02
GET /signals?pair=BTC/USD$0.01
GET /indicators$0.005
GET /signals/previewFREE
Example
curl https://signals.nsgoods.org/signals/preview
→ {"pair":"BTC/USD","signal":"…","signed_by":"0x…"}
Try preview — live

          
02 Agent Trust OracleERC-8004 agent reputation / trust scores (0-100) across five EVM chains — trust.nsgoods.org $0.005+
Endpoints
GET /agent-trust?agent=<id>&chain=<name>$0.005
GET /agent-trust/previewFREE
Example
curl https://trust.nsgoods.org/agent-trust/preview
→ {"agent":…,"score":…,"components":{…},"signed_by":"0x…"}
Try preview — live

          
03 CMC Regime SkillDeterministic market regime (TREND_UP/DOWN/CHOP/RISK_OFF) + strategy spec — regime.nsgoods.org $0.01+
Endpoints
GET /regime?id=1 (1=BTC · 1027=ETH · 1839=BNB)$0.01
GET /provable/headFREE
Example
curl https://regime.nsgoods.org/provable/head
→ {"count":1887,"head":{"regime":"RISK_OFF",…}}
Try — latest signed snapshot

          
04 Extractability OracleGEO extractability score 0-100 for any web page: can AI crawlers quote it? — schema.nsgoods.org $0.01+
Endpoints
GET|POST /extractability$0.01
GET /extractability/preview?url=<url>FREE
Example
curl "https://schema.nsgoods.org/extractability/preview?url=https://example.com"
→ {"score":…,"grade":"…"}
Try preview — live

          
05 Solar Legality OracleUS 50-state plug-in / balcony solar legality — status, utilities, legislation. CC BY 4.0 — solar.nsgoods.org from $0.005+
Endpoints
GET /solar-legality?state=<state>$0.005
GET /solar-legality/all$0.02
GET /solar-legality/previewFREE
Example
curl "https://solar.nsgoods.org/solar-legality/preview?state=california"
→ {"state":"california","legal_status":"…"}
Try preview — live

          
06 Agent ScreeningSigned OFAC sanctions + malicious-address screening for any EVM or Solana address — trust.nsgoods.org $0.005+
Endpoints
GET /screen?address=<addr>&chain=<base|ethereum|bsc|polygon|mantle|solana>$0.005
GET /screen/preview?address=<addr>&chain=<name>FREE
Example
curl "https://trust.nsgoods.org/screen/preview?address=0x…&chain=base"
→ {"malicious":…,"sanctioned":…,"hard_flags":[…],"soft_flags":[…],"sources":[…],"screening_verdict":"…","signed_by":"0x…"}
Sources
OFAC sanctions — Chainalysis on-chain oracle (EVM)
malicious-address — GoPlus (EVM + Solana)
07 Sanctions Screening OracleMulti-chain OFAC SDN exact-address screening — multi-chain OFAC SDN exact-address screening (live counts: sanctions.nsgoods.org/health), settles on Solana (USDC), sanctions.nsgoods.org $0.005+
Endpoints
GET /screen?address=<addr>&chain=<chain>$0.005
GET /screen/previewFREE
Settlement (Solana, not Base)
Solana mainnet · USDC (SPL) · gasless (facilitator feePayer)
payTo 35tCuyL3E7M88jfhTeEaRxhrbuKFyQLWgxJQyf5QcLLe
Example
curl "https://sanctions.nsgoods.org/screen/preview"
→ {"preview":true,"demo_address":"0x19aa…4dff","input_ignored":false,"sanctioned":true,"matched_label":"ETH","verdict":"deny","sdn_snapshot_at":"…","signed_by":"0x57fF…"}
Coverage
OFAC SDN exact-address match (live counts: sanctions.nsgoods.org/health)
Negative-evidence only — deny, or "no SDN match" (≠ safe). No heuristic/GoPlus layer.
Verify signature
Verifying the signature on /screen/preview. The preview response adds four fields after signing: preview, demo_address, input_ignored, note. Strip all four, plus signature and signed_by, before you verify. The paid /screen response adds nothing after signing, so there you strip only signature and signed_by. Canonicalise the remainder as json.dumps(sort_keys=True, separators=(',',':'), ensure_ascii=True) — non-ASCII is therefore \uXXXX-escaped — and recover with EIP-191 personal_sign (the Ethereum signed-message prefix).
08 x402 Payability CheckIs this x402 endpoint payable? Reachable + well-formed 402 + (Solana) destination-ATA existence. Signed, x402 on Base — payable.nsgoods.org $0.005+
Endpoints
GET /payable?resource=<https-url>$0.005
GET /payable/previewFREE
Settlement
Base (USDC, payTo 0xc87a06…5EF990) or Solana (USDC-SPL, payTo 35tCuyL3…) — Base first
Example
curl "https://payable.nsgoods.org/payable/preview"
→ {"schema_version":2,"verdict":"PAYABLE","payable_networks":["solana:5eykt…"],"options":[{"network":"solana:5eykt…","verdict":"PAYABLE","detail":{"ata_exists":true,"token_program":"spl"}}],"preview":true,"demo_resource":"https://sanctions.nsgoods.org/screen","signed_by":"0x41Fb…"}
Method
Reachable + well-formed 402 + (Solana) destination-ATA existence. Derive ATA = find_program_address([payTo, tokenProgram, mint], ATokenGP…); ≤3 RPC calls. Every response signed.
Verify signature
Recover the signer over the canonical JSON with signature + signed_by removed; recover == signed_by. On /payable/preview strip the four post-sign fields first (preview, demo_resource, input_ignored, note). Canonicalise as json.dumps(sort_keys=True, separators=(',',':'), ensure_ascii=True) — non-ASCII is \uXXXX-escaped — and recover with EIP-191 personal_sign (the Ethereum signed-message prefix).
09 Solana Settlement VerificationDid a Solana transaction credit the declared amount of the mint to the payee? Signed finalized-mainnet verdict — VERIFIED / REFUTED / UNCONFIRMED / NOT_FOUND, with a per-field breakdown. x402 on Base — x402.nsgoods.org/settle $0.01+
Endpoints
GET /settle?tx=<sig>&payee=<addr>&amount=<atomic>&mint=<mint>$0.01
GET /settle/previewFREE
Settlement
Base (USDC, payTo 0xc87a06…5EF990). The subject verified is on Solana; the paid call settles on Base.
Verdicts
VERIFIED — finalized and every asserted field matches (amount is the exact net credited to payee at token-account level)
REFUTED — finalized but ≥1 field mismatch (per-field breakdown shown)
UNCONFIRMED — found, not yet finalized · NOT_FOUND — not seen as of the searched slot
Example
curl "https://x402.nsgoods.org/settle/preview"
→ {"schema_version":"settle_v1","verdict":"VERIFIED","fields":[{"field":"amount","asserted":"415803","observed":"415803","match":true}],"commitment":"finalized","slot":443406404,"signer":"0x57fF…","signature":"0x…","preview":true}
Verify signature
Strip the post-sign fields (preview, note); remove envelope.signature (keep signer); canonicalise json.dumps(sort_keys=True, separators=(',',':'), ensure_ascii=True) and recover with EIP-191 personal_sign; recover == signer.
10 Preflight CompositeOne call, three independent signed checks of one address — payability + OFAC sanctions + ERC-8004 trust, each its own signed sub-result, no aggregate score. x402 on Base — x402.nsgoods.org/preflight $0.015+
Endpoints
GET /preflight?address=<0x>&chain=<caip2>&role=<payer|payee|escrow_destination>$0.015
GET /preflight/previewFREE
Components
payability — can the address settle (transfer simulation)
sanctions — OFAC SDN exact-address screen
trust — ERC-8004 reputation (DATA / NO_DATA)
Each is signed on its own; no aggregate score, only a components_evaluated count.
Settlement
Base (USDC, payTo 0xc87a06…5EF990).
Example
curl "https://x402.nsgoods.org/preflight/preview"
→ {"schema_version":"preflight_v3","components":[{"component":"payability","verdict":"PAYABLE"},{"component":"sanctions","verdict":"CLEAR"},{"component":"trust","verdict":"NO_DATA"}],"components_evaluated":3,"envelope":{"signer":"0x57fF…","signature":"0x…"},"preview":true}
Verify signature
Strip the post-sign fields (preview, note); verify each component (remove component_digest + component_signature, canonicalise, sha256 == digest, recover EIP-191 to signer) and the envelope (remove envelope.signature, keep signer, recover).
11 WatchdogSigned monitoring of any x402 endpoint — EIP-191 alerts when it goes unreachable, its payability verdict degrades, or its declared payTo / networks / asset changes. $5 per endpoint for 30 days; free tier one endpoint per verified channel. x402 on Base — x402.nsgoods.org/watchdog $5.00+
Endpoints
GET /watchdog/register?endpoint=<https-url>&channel=<email|webhook>FREE tier
GET /watchdog/register/paid (after 402) — one endpoint, 30 days$5.00
GET /watchdog/previewFREE
Alert types (9, closed)
endpoint_unreachable / endpoint_recovered
verdict_degraded / verdict_restored
payto_changed / networks_changed / asset_changed
self_inconsistent_402_detected
listing_disappeared_from_catalog (weak)
Each alert carries, verbatim, what it does NOT mean.
Subscription
One paid x402 call = 30-day subscription for one endpoint.
Free tier: one endpoint per verified channel (email or webhook).
Verification (email code / webhook nonce) required before any alert.
Settlement
Base (USDC, payTo 0xc87a06…5EF990).
Verify signature
Every alert is EIP-191-signed by 0x57fF…350c: remove digest + signature, canonicalise (sorted keys, compact separators, non-ASCII escaped), sha256 == digest, recover to signer.
12 Multi-List Sanctions ScreeningFour-list screening (OFAC, UN, EU, UK Sanctions List (FCDO)) — per-list matched/clear + that list's version date in one signed verdict, explicit list_health, dual-rail USDC — sanctions.nsgoods.org/screen-multi $0.01+
Endpoints
GET /screen-multi?address=<addr>&chain=<chain>$0.01
GET /screen-multi/previewFREE
Coverage (four lists)
OFAC SDN · UN Consolidated · EU FSF (official, public token) · UK Sanctions List (FCDO)
Each list: matched/clear + that list's version date, in one signed body.
list_health: a stale or unavailable feed is reported, never a silent clear.
Headline verdict keeps /screen semantics — deny only on an OFAC SDN match.
Settlement (dual-rail)
USDC on Base (payTo 0xc87a06…5EF990) or Solana (payTo 35tCuyL3…QcLLe).
Verify signature
Signed by 0x57fF…350c. Paid response: strip signature + signed_by. /screen-multi/preview: also strip preview, demo_address, input_ignored, note. Canonicalise (sorted keys, compact separators, non-ASCII escaped) and recover with EIP-191 personal_sign; recover == signed_by.

Free on every service: /health · preview · /provable/head · /provable/verify · /.well-known/x402 · /openapi.json · /llms.txt

02 — How x402 works

No accounts.
No API keys.

01

An agent calls a paid endpoint. Plain HTTP — nothing to sign up for.

02

It receives HTTP 402 Payment Required with the price and payment instructions.

03

It pays USDC on Base and retries. The data comes back — signed.

03 — Why nsgoods

Trust nothing.
Verify everything.

Live

Verifiable delivery

Every paid call to nsgoods data services (extractability, agent-trust, regime, solar) returns a signed proof of delivery: a tamper-proof Ed25519 receipt any agent can verify independently. Verify at /proof/pubkey on each service.

  • ECDSA-signed responses — recover the signer, prove authenticity.
  • Public hash-chain proofs — tamper-evident history for every service.
  • Free preview on every service — try before paying a cent.
  • Machine-discoverable — manifests, OpenAPI, llms.txt. MCP-ready.
  • Just HTTP and USDC on Base — nothing else between the agent and the data.
Independently scored
x402 trust score: Agent Trust x402 trust score: Kraken Signals x402 trust score: Extractability x402 trust score: Solar Legality x402 trust score: Market Regime x402 trust score: Market Scan x402 trust score: Sanctions Screening x402 trust score: Payability x402 trust score: Settlement x402 trust score: Watchdog x402 trust score: Preflight

Independent trust and compliance scores by x402.fuchss.app, probed up to 48x a day, badges recomputed every 24h.

x402-list.com: nsgoods Agent Trust & Screening Oracle — listed, 100% measured uptime x402-list.com: nsgoods Sanctions Screening Oracle — listed, measured uptime

Monitored by x402-list.com · measured uptime, updated live

04 — Guarantee

Money-back
guarantee

Testnet proven · Base Sepolia

We built and publicly proved an on-chain escrow-bond guarantee for x402 calls. If a paid service fails to deliver, the buyer is compensated from the seller's USDC bond — enforced by a smart contract, triggered by a signed delivery verdict. Proven end-to-end on Base Sepolia. Mainnet next.

01

Seller posts a bond — USDC locked in a contract.

02

Verifier signs the delivery verdict — DELIVERED or FAILED.

03

FAILED → buyer is paid from the bond — automatic, on-chain.

05 — About

Built by Nikolaos Dimitriadis — indie dev building for the agent economy. Liverpool, UK.

X @nickbuildsai  ·  LinkedIn

MCP server

Read only. No wallet. No payments handled by this server.

Endpoint: https://mcp.nsgoods.org/mcp (Streamable HTTP, no sign in).

Eight tools, all free, 300 calls per IP per day:

  • find_endpoints: search the catalogue by host or keyword, with the latest verdict and the observed price per endpoint, optional sort by price
  • payability_verdict: verdict, history, remediation hint and price for one exact URL
  • catalogue_stats: size of the catalogue, verdict counts, payable endpoints per network, median price
  • host_summary: per host verdict mix, first and last seen, gone since
  • drift_status: verdict changes between scans
  • x401_status: current x401 emitter count
  • verify_signature: verify any nsgoods signed response offline against our manifest
  • reports: links to the weekly payability reports

Data comes from our weekly full scan of the x402 catalogue plus a price sweep. Current totals are live at https://mcp.nsgoods.org/health. Every answer carries an as_of date. For a live check use the paid /payable endpoint.

Connect from Claude

  1. Settings, then Connectors, then Add custom connector
  2. Name: nsgoods. URL: https://mcp.nsgoods.org/mcp. No sign in.
  3. Add, then start a new conversation and ask, for example: Using nsgoods, find the cheapest payable endpoint for ERC20 balance on Base

Any MCP client that supports Streamable HTTP works the same way. Health: https://mcp.nsgoods.org/health.

06 — FAQ
What is nsgoods?
A suite of twelve x402 pay-per-call APIs built for AI agents: trading signals, ERC-8004 agent trust scores, signed OFAC sanctions + malicious-address screening, multi-chain OFAC SDN exact-address screening (multi-chain OFAC SDN exact-address screening (live counts: sanctions.nsgoods.org/health), settled on Solana), deterministic market-regime detection, web extractability scoring, US plug-in solar legality data, x402 payability checks, and Watchdog signed endpoint monitoring. Each is signed, verifiable via a public hash chain, and offers a free preview.
How do agents pay?
Via the x402 protocol on Base mainnet, settled in USDC: call → HTTP 402 with price → pay → retry. No account or API key. This hub takes no payments; each service is paid at its own endpoint.
Are responses verifiable?
Yes — every paid response carries an ECDSA signature, and each service appends results to a public tamper-evident sha256 hash chain, so nothing can be rewritten after the fact.
Is it live?
Yes — all twelve services are live with real paid traffic (one settles on Solana, the rest on Base). See/health for a per-service summary.