# Sentinel402 > Paid tools for AI agents over x402: a PII and secret guardrail that scans outbound payloads, a prompt-injection scanner for untrusted inputs, live citable data (crypto, stocks, news, weather, GitHub, sports, FX, npm/PyPI, ENS, IP geolocation), and an RCP/1 retrieval server backed by that live data. Paid per call with [x402](https://x402.org) and [MPP](https://mpp.dev) (Machine Payments Protocol — Tempo × Stripe) in USDC on **Base mainnet**. No API keys, no accounts, no signup. Send a request, get HTTP 402, sign, retry. Both x402 v2 (`PAYMENT-SIGNATURE`) and v1 (`X-PAYMENT`) clients are supported, and every 402 also carries an MPP `WWW-Authenticate: Payment` challenge (method "evm", intent "charge") — same price, same USDC, same receiving wallet. ## Paid endpoints - **POST /v1/scan** — $0.02 — PII and secret guardrail for outbound agent payloads - **POST /v1/scan/batch** — $0.05 — Batch PII/secret scan: up to 20 payloads, one payment - **POST /v1/audit** — $0.03 — Compliance audit report: PCI-DSS / GDPR / HIPAA / secrets verdicts - **GET /v1/data/{collection}** — $0.003 — Live crypto, stocks, news, weather, GitHub, sports, FX, packages, ENS and IP data - **POST /rcp/retrieve** — $0.003 — RCP/1 retrieval over live data, with citations - **POST /mcp** — $0.02 — MCP tool: PII/secret guardrail - **POST /mcp** — $0.05 — MCP tool: batch PII/secret scan - **POST /mcp** — $0.03 — MCP tool: compliance audit verdicts - **POST /mcp** — $0.003 — MCP tool: live data by collection - **POST /v1/scan/prompt** — $0.01 — Prompt-injection guardrail for untrusted agent inputs - **POST /v1/scan/prompt/batch** — $0.03 — Batch prompt-injection scan: up to 20 texts, one payment - **POST /mcp** — $0.01 — MCP tool: prompt-injection guardrail - **POST /v1/credits/buy** — $5 — Prepaid credit pack: $5 -> 5,000 units, spend via X-Credit-Token on every paid route ## Prepaid credit bundles (Durable Objects) Buy ONCE: `POST /v1/credits/buy` ($5 settled on-chain via x402/MPP) returns a bearer token for 5000 units (1 unit = $0.001). Then call ANY paid route with `X-Credit-Token: ` — units are deducted atomically from a Durable Object (no double-spend, no per-call settlement, no facilitator round-trip). - Balance (free): `GET /v1/credits/balance` with the same `X-Credit-Token` header. - Scheme + per-route unit costs (free): `GET /v1/credits`. - Packs expire after 90 days; unused units lapse. Credits are prepaid and non-refundable; per-call payment always still works. ## Free endpoints - `/` — Landing page (HTML, carries the ARD link tags). Send Accept: application/json — or GET /service-card — for the machine-readable service card - `/service-card` — The agent-readable JSON service card (always JSON) - `/agents.md` — What to call and how to pay, for an agent that has already arrived - `/.well-known/security.txt` — RFC 9116 security contact - `/openapi.json` — OpenAPI 3.1 + x-payment-info — the canonical discovery contract (x402scan, MPP registries) - `/llms.txt` — Markdown overview for LLM crawlers - `/.well-known/agent.json` — Open 402 Directory registry manifest (v1.3, x402 + MPP) - `/.well-known/agent-card.json` — A2A Agent Card - `/.well-known/x402` — x402 payment discovery document - `/.well-known/mpp` — MPP (Machine Payments Protocol) discovery document - `/.well-known/ard.json` — ARD manifest (Agent Resource Discovery — Neuronto + federated registries) - `/.well-known/ai-catalog.json` — Same ARD manifest under the predecessor draft name - `/robots.txt` — Crawler policy + the Agentmap line pointing at the ARD manifest - `/health` — Liveness + config diagnostics (503 when misconfigured) - `/rules` — PII detection catalogue - `/prompt-rules` — Prompt-injection detection catalogue - `/rcp/initialize` — RCP handshake (free) - `/rcp/info` — RCP server info + collections (free) - `/rcp/catalog/list` — RCP collection catalog (free) - `/mcp` — MCP initialize / tools/list / ping are free; tools/call is paid - `/v1/trial` — Rate-limited free PII scan (conversion funnel) - `/v1/credits` — Credit-bundle scheme info: pack price, unit value, per-route unit costs, expiry - `/v1/credits/balance` — Remaining credit balance for an X-Credit-Token (free to read) - `/og-image.png` — Open Graph share image (og:image) for the landing page ## Protocols - **MCP** at `https://pii-guardrail.chronokey.workers.dev/mcp` (streamable HTTP). `initialize`, `tools/list` and `ping` are free; `tools/call` is paid per tool. - **RCP/1** at `https://pii-guardrail.chronokey.workers.dev/rcp/` (JSON-RPC 2.0). `initialize`, `info`, `catalog/list`, `ping` are free; `retrieve` is paid. - **REST** at `https://pii-guardrail.chronokey.workers.dev/v1/*`. - **MPP** on every paid route: pay the 402's `WWW-Authenticate: Payment` challenge with an EIP-3009 authorization (nonce = keccak256(challenge.id + challenge.realm)) in `Authorization: Payment `; receipt in `Payment-Receipt`. Details: `https://pii-guardrail.chronokey.workers.dev/.well-known/mpp`. ## Live data collections - `crypto` — Crypto spot price. Live spot price and 24h change for a crypto asset, in USD. Binance primary, Coinbase fallback. Fresh 30s. Args: symbol. - `weather` — Current weather. Current conditions plus today's high/low for a city or place name. Geocoded automatically. Fresh 900s. Args: place. - `github` — Recent GitHub commits. The 5 most recent commits for a public repository, with sha, message, author and permalink. Fresh 120s. Args: repo. - `sports` — Live sports scores. Current scoreboard for a league: scores, status and start times. Fresh 60s. Args: league. - `fx` — FX reference rates. ECB daily reference exchange rates between fiat currencies. Fresh 3600s. Args: base, quotes. - `hn` — Hacker News front page. Current Hacker News top stories with points, comment counts and links — or a single story by its HN id. Fresh 300s. Args: limit, story. - `wiki` — Wikipedia summary. The lead summary of any Wikipedia page — the canonical citable 'what is X' answer, with a canonical URL. Fresh 3600s. Args: page, lang. - `stocks` — Stock & ETF quotes. Latest price, previous close and change for a stock, ETF or index ticker (crypto pairs like BTC-USD work too). Yahoo Finance. Fresh 60s. Args: symbol. - `news` — News headlines. Current news headlines from Google News — top stories, or search results for a query, each with source and publish time. Fresh 300s. Args: q, limit. - `geo` — IP geolocation. Geolocation, timezone and ISP/ASN for an IPv4 or IPv6 address. Pass ip=me to locate the calling client. Fresh 86400s. Args: ip. - `npm` — npm package metadata. Latest version, description, license, homepage and dependency count for an npm package. Fresh 3600s. Args: package. - `pypi` — PyPI package metadata. Latest version, summary, license and homepage for a PyPI (Python) package. Fresh 3600s. Args: package. - `hnsearch` — Hacker News search. Search Hacker News (official Algolia API) for stories matching a query — relevance-ranked, with points, comment counts and links. Fresh 300s. Args: q, limit. - `ens` — ENS name resolution. Ethereum Name Service: resolve a name to its address (name=vitalik.eth) or reverse-resolve an address to its ENS name (address=0x…). Exactly one of the two. Fresh 3600s. Args: name, address. - `arxiv` — arXiv research papers. Search arXiv (or fetch one paper by id): title, authors, abstract, published date and the canonical abs URL — citable research context for RAG agents. Fresh 3600s. Args: q, id, limit. Crypto symbols: BTC, ETH, SOL, USDC, XRP, DOGE, ADA, AVAX, LINK, MATIC. Sports leagues: NBA, NFL, MLB, NHL, EPL, UCL, LALIGA, SERIEA, BUNDESLIGA, MLS. ## PII detection 50 rules (46 on by default), regex + checksum (Luhn, IBAN mod-97, ABA 3-7-1, SSA ranges). Engine 1.3.0. Never echoes detected secrets back in plaintext. Zero retention: nothing is logged or stored. Full catalogue: `https://pii-guardrail.chronokey.workers.dev/rules`. ## How to pay ``` curl -i -X POST https://pii-guardrail.chronokey.workers.dev/v1/scan -H 'content-type: application/json' -d '{"text":"..."}' # -> HTTP 402 with BOTH rails: # x402: decode the PAYMENT-REQUIRED header (v2) or the JSON body (v1) # sign an EIP-3009 transferWithAuthorization for the exact amount # retry with: -H 'PAYMENT-SIGNATURE: ' # MPP: parse WWW-Authenticate: Payment (method="evm", intent="charge") # sign the SAME EIP-3009 authorization but with # nonce = keccak256(challenge.id + challenge.realm) # retry with: -H 'Authorization: Payment ' ``` Discovery documents: `/openapi.json` (canonical, x402scan + MPP) · `/.well-known/agent.json` · `/.well-known/agent-card.json` · `/.well-known/x402` · `/.well-known/mpp` Health: `https://pii-guardrail.chronokey.workers.dev/health`