---
name: nod402-risk
description: Check whether it is safe to pay an x402 invoice, and score the counterparty wallet.
---

# A check before a machine payment

When an agent receives a 402 and is about to sign a payment, ask nod402 first.

## Before signing

Decode the PAYMENT-REQUIRED header (base64 JSON) and send:

POST https://nod402.com/v1/prepay
{ "envelope": <decoded envelope>, "url": "<resource url>", "maxPrice": "<limit in USD>" }

The response carries verdict = allow | warn | block, plus reasons explaining each decision.

- **block** — do not sign. Causes: the recipient changed, a test network in production,
  price at least twice the catalogue price, an unencrypted channel, a sanctioned address, grade F.
- **warn** — proceed, but log it and stay inside your limit.
- **allow** — an ordinary payment.

## Check a counterparty

GET https://nod402.com/v1/wallet?chain=base&address=<address>

Useful to a seller: whether to serve this wallet, and how large a channel to open for it.

## Important

Missing data is not the same as "fine". If status is insufficient_data there are too few
observations and the verdict will be warn. That is more honest than handing a new endpoint
a failing grade.
