APIs for
AI agents
on Base
in USDC
nsgoods
nsgoods is a suite of twelve x402 pay-per-call APIs for AI agents on Base + Solana — signed, provable, with a free preview on every service.
● 12 services · live on Base + Solana
An independent consumer verified our frozen preflight_v3 contract offline: 9/9 tamper cases rejected, every component and envelope signature checked.
Published by Maha Strategies as external integration evidence — fixture-only, not a live-endpoint result.
Our exports and response signatures have been independently verified by AsterPay (September 2026).
ExactZK (independent zkML provenance project) independently verified the nsgoods signing construction by counter test, recomputed the JCS digests of specific published attestations and matched them to the values we publish, and checked that our signed manifest is the authority scoping the signing key. September 2026. This verification covers those signatures and our manifest only, not our services.
Independent reproductions: we rebuild third party deployed artifacts on a clean disposable host and publish signed attestations. Six signed attestation records are in our /proof/index.json, covering four independent reproductions of the ExactZK bundle, including the first signed reproduction of the solo circuit's verifying key, now filed on chain; four of the records are also published in the upstream ExactZK zkML provenance bundle.
In production: SafeGate evidence references our signed screening verdict by hash and request id. In a self funded live run on Base mainnet on 25 September 2026, the verdict SafeGate retained was checked from both sides: same bytes, same signer, same request id. Case study, published by SafeGate →
Public observatory: x401 adoption → · weekly payability report →
More third party records that reference nsgoods, none written or paid for by us: /proof/observed.html
Payment traffic is public by design. Inspect it yourself on Basescan
In production: Walpulse renders our signed sanctions verdicts inside its own product UI. Their reader does not trust them or us, the UI verifies the EIP-191 signature on every render. "If it fails, the row is not a fact." (their words, on X)
Case study: how the integration works
Waveline, by Dimos Papageorgiou, sells its artist insights to AI agents over x402: 0.005 USDC on Base. It is the first site nsgoods checked end to end before it opened to agents. We made its first mainnet payment, and nsgoods Watchdog checks its payment terms every 15 minutes.
SafeGate by Nurexen Labs. Post-payment commerce verification and evidence infrastructure for agent commerce. On Base, its paid evidence can reference nsgoods signed sanctions verdicts by hash and request ID.
Case study: how the integration works
From nohumans.directory's weekly report (September 2026), covering our measurement exchange over their catalogue:
“nsgoods — a weekly payability observatory that scanned our catalogue and wrote to us with numbers.”
“He also found a hole in our changes feed we could not have found ourselves.”
The same report answers a probing question of ours against their own data, prints a finding of ours they cannot verify themselves and says so, and carries a labelling correction we made to our own earlier figure. Full text: their report →
Twelve oracles.
One cup each.
| GET /backtest | $0.25 |
| GET /signals/top | $0.10 |
| GET /history | $0.05 |
| GET /regime/changed | $0.02 |
| GET /signals?pair=BTC/USD | $0.01 |
| GET /indicators | $0.005 |
| GET /signals/preview | FREE |
curl https://signals.nsgoods.org/signals/preview
→ {"pair":"BTC/USD","signal":"…","signed_by":"0x…"}
| GET /agent-trust?agent=<id>&chain=<name> | $0.005 |
| GET /agent-trust/preview | FREE |
curl https://trust.nsgoods.org/agent-trust/preview
→ {"agent":…,"score":…,"components":{…},"signed_by":"0x…"}
| GET /regime?id=1 (1=BTC · 1027=ETH · 1839=BNB) | $0.01 |
| GET /provable/head | FREE |
curl https://regime.nsgoods.org/provable/head
→ {"count":1887,"head":{"regime":"RISK_OFF",…}}
| GET /solar-legality?state=<state> | $0.005 |
| GET /solar-legality/all | $0.02 |
| GET /solar-legality/preview | FREE |
curl "https://solar.nsgoods.org/solar-legality/preview?state=california"
→ {"state":"california","legal_status":"…"}
| GET /screen?address=<addr>&chain=<base|ethereum|bsc|polygon|mantle|solana> | $0.005 |
| GET /screen/preview?address=<addr>&chain=<name> | FREE |
curl "https://trust.nsgoods.org/screen/preview?address=0x…&chain=base"
→ {"malicious":…,"sanctioned":…,"hard_flags":[…],"soft_flags":[…],"sources":[…],"screening_verdict":"…","signed_by":"0x…"}
OFAC sanctions — Chainalysis on-chain oracle (EVM) malicious-address — GoPlus (EVM + Solana)
| GET /screen?address=<addr>&chain=<chain> | $0.005 |
| GET /screen/preview | FREE |
Solana mainnet · USDC (SPL) · gasless (facilitator feePayer) payTo 35tCuyL3E7M88jfhTeEaRxhrbuKFyQLWgxJQyf5QcLLe
curl "https://sanctions.nsgoods.org/screen/preview"
→ {"preview":true,"demo_address":"0x19aa…4dff","input_ignored":false,"sanctioned":true,"matched_label":"ETH","verdict":"deny","sdn_snapshot_at":"…","signed_by":"0x57fF…"}
OFAC SDN exact-address match (live counts: sanctions.nsgoods.org/health) Negative-evidence only — deny, or "no SDN match" (≠ safe). No heuristic/GoPlus layer.
Verifying the signature on /screen/preview. The preview response adds four fields after signing: preview, demo_address, input_ignored, note. Strip all four, plus signature and signed_by, before you verify. The paid /screen response adds nothing after signing, so there you strip only signature and signed_by. Canonicalise the remainder as json.dumps(sort_keys=True, separators=(',',':'), ensure_ascii=True) — non-ASCII is therefore \uXXXX-escaped — and recover with EIP-191 personal_sign (the Ethereum signed-message prefix).
| GET /payable?resource=<https-url> | $0.005 |
| GET /payable/preview | FREE |
Base (USDC, payTo 0xc87a06…5EF990) or Solana (USDC-SPL, payTo 35tCuyL3…) — Base first
curl "https://payable.nsgoods.org/payable/preview"
→ {"schema_version":2,"verdict":"PAYABLE","payable_networks":["solana:5eykt…"],"options":[{"network":"solana:5eykt…","verdict":"PAYABLE","detail":{"ata_exists":true,"token_program":"spl"}}],"preview":true,"demo_resource":"https://sanctions.nsgoods.org/screen","signed_by":"0x41Fb…"}
Reachable + well-formed 402 + (Solana) destination-ATA existence. Derive ATA = find_program_address([payTo, tokenProgram, mint], ATokenGP…); ≤3 RPC calls. Every response signed.
Recover the signer over the canonical JSON with signature + signed_by removed; recover == signed_by. On /payable/preview strip the four post-sign fields first (preview, demo_resource, input_ignored, note). Canonicalise as json.dumps(sort_keys=True, separators=(',',':'), ensure_ascii=True) — non-ASCII is \uXXXX-escaped — and recover with EIP-191 personal_sign (the Ethereum signed-message prefix).
| GET /settle?tx=<sig>&payee=<addr>&amount=<atomic>&mint=<mint> | $0.01 |
| GET /settle/preview | FREE |
Base (USDC, payTo 0xc87a06…5EF990). The subject verified is on Solana; the paid call settles on Base.
VERIFIED — finalized and every asserted field matches (amount is the exact net credited to payee at token-account level) REFUTED — finalized but ≥1 field mismatch (per-field breakdown shown) UNCONFIRMED — found, not yet finalized · NOT_FOUND — not seen as of the searched slot
curl "https://x402.nsgoods.org/settle/preview"
→ {"schema_version":"settle_v1","verdict":"VERIFIED","fields":[{"field":"amount","asserted":"415803","observed":"415803","match":true}],"commitment":"finalized","slot":443406404,"signer":"0x57fF…","signature":"0x…","preview":true}
Strip the post-sign fields (preview, note); remove envelope.signature (keep signer); canonicalise json.dumps(sort_keys=True, separators=(',',':'), ensure_ascii=True) and recover with EIP-191 personal_sign; recover == signer.
| GET /preflight?address=<0x>&chain=<caip2>&role=<payer|payee|escrow_destination> | $0.015 |
| GET /preflight/preview | FREE |
payability — can the address settle (transfer simulation) sanctions — OFAC SDN exact-address screen trust — ERC-8004 reputation (DATA / NO_DATA) Each is signed on its own; no aggregate score, only a components_evaluated count.
Base (USDC, payTo 0xc87a06…5EF990).
curl "https://x402.nsgoods.org/preflight/preview"
→ {"schema_version":"preflight_v3","components":[{"component":"payability","verdict":"PAYABLE"},{"component":"sanctions","verdict":"CLEAR"},{"component":"trust","verdict":"NO_DATA"}],"components_evaluated":3,"envelope":{"signer":"0x57fF…","signature":"0x…"},"preview":true}
Strip the post-sign fields (preview, note); verify each component (remove component_digest + component_signature, canonicalise, sha256 == digest, recover EIP-191 to signer) and the envelope (remove envelope.signature, keep signer, recover).
| GET /watchdog/register?endpoint=<https-url>&channel=<email|webhook> | FREE tier |
| GET /watchdog/register/paid (after 402) — one endpoint, 30 days | $5.00 |
| GET /watchdog/preview | FREE |
endpoint_unreachable / endpoint_recovered verdict_degraded / verdict_restored payto_changed / networks_changed / asset_changed self_inconsistent_402_detected listing_disappeared_from_catalog (weak) Each alert carries, verbatim, what it does NOT mean.
One paid x402 call = 30-day subscription for one endpoint. Free tier: one endpoint per verified channel (email or webhook). Verification (email code / webhook nonce) required before any alert.
Base (USDC, payTo 0xc87a06…5EF990).
Every alert is EIP-191-signed by 0x57fF…350c: remove digest + signature, canonicalise (sorted keys, compact separators, non-ASCII escaped), sha256 == digest, recover to signer.
| GET /screen-multi?address=<addr>&chain=<chain> | $0.01 |
| GET /screen-multi/preview | FREE |
OFAC SDN · UN Consolidated · EU FSF (official, public token) · UK Sanctions List (FCDO) Each list: matched/clear + that list's version date, in one signed body. list_health: a stale or unavailable feed is reported, never a silent clear. Headline verdict keeps /screen semantics — deny only on an OFAC SDN match.
USDC on Base (payTo 0xc87a06…5EF990) or Solana (payTo 35tCuyL3…QcLLe).
Signed by 0x57fF…350c. Paid response: strip signature + signed_by. /screen-multi/preview: also strip preview, demo_address, input_ignored, note. Canonicalise (sorted keys, compact separators, non-ASCII escaped) and recover with EIP-191 personal_sign; recover == signed_by.
Free on every service: /health · preview · /provable/head · /provable/verify · /.well-known/x402 · /openapi.json · /llms.txt
No accounts.
No API keys.
An agent calls a paid endpoint. Plain HTTP — nothing to sign up for.
It receives HTTP 402 Payment Required with the price and payment instructions.
It pays USDC on Base and retries. The data comes back — signed.
Trust nothing.
Verify everything.
Verifiable delivery
Every paid call to nsgoods data services (extractability, agent-trust, regime, solar) returns a signed proof of delivery: a tamper-proof Ed25519 receipt any agent can verify independently. Verify at /proof/pubkey on each service.
- ECDSA-signed responses — recover the signer, prove authenticity.
- Public hash-chain proofs — tamper-evident history for every service.
- Free preview on every service — try before paying a cent.
- Machine-discoverable — manifests, OpenAPI, llms.txt. MCP-ready.
- Just HTTP and USDC on Base — nothing else between the agent and the data.
One command in Claude Desktop or Cursor exposes the nsgoods oracles as MCP tools. Every preview is free; paid tools need EVM_PRIVATE_KEY — a low-balance Base wallet (USDC).
Independent trust and compliance scores by x402.fuchss.app, probed up to 48x a day, badges recomputed every 24h.
Monitored by x402-list.com · measured uptime, updated live
Money-back
guarantee
Testnet proven · Base Sepolia
We built and publicly proved an on-chain escrow-bond guarantee for x402 calls. If a paid service fails to deliver, the buyer is compensated from the seller's USDC bond — enforced by a smart contract, triggered by a signed delivery verdict. Proven end-to-end on Base Sepolia. Mainnet next.
Seller posts a bond — USDC locked in a contract.
Verifier signs the delivery verdict — DELIVERED or FAILED.
FAILED → buyer is paid from the bond — automatic, on-chain.
Built by Nikolaos Dimitriadis — indie dev building for the agent economy. Liverpool, UK.
X @nickbuildsai · LinkedIn
MCP server
Read only. No wallet. No payments handled by this server.
Endpoint: https://mcp.nsgoods.org/mcp (Streamable HTTP, no sign in).
Eight tools, all free, 300 calls per IP per day:
find_endpoints: search the catalogue by host or keyword, with the latest verdict and the observed price per endpoint, optional sort by pricepayability_verdict: verdict, history, remediation hint and price for one exact URLcatalogue_stats: size of the catalogue, verdict counts, payable endpoints per network, median pricehost_summary: per host verdict mix, first and last seen, gone sincedrift_status: verdict changes between scansx401_status: current x401 emitter countverify_signature: verify any nsgoods signed response offline against our manifestreports: links to the weekly payability reports
Data comes from our weekly full scan of the x402 catalogue plus a price sweep. Current totals are live at https://mcp.nsgoods.org/health. Every answer carries an as_of date. For a live check use the paid /payable endpoint.
Connect from Claude
- Settings, then Connectors, then Add custom connector
- Name:
nsgoods. URL:https://mcp.nsgoods.org/mcp. No sign in. - Add, then start a new conversation and ask, for example: Using nsgoods, find the cheapest payable endpoint for ERC20 balance on Base
Any MCP client that supports Streamable HTTP works the same way. Health: https://mcp.nsgoods.org/health.