Pay 0.005 USDC, verify a JWT signature plus the canonical claims (iss / aud / exp / nbf) against an inline publicKey (PEM) or sharedSecret. Supports HS256/384/512 + RS256/384/512. Constant-time HMAC compare, configurable clock-skew tolerance, alg=none rejected. Stateless — caller supplies their key in the request body, BitBooth never stores it. Same plumbing-primitive thesis as webhook-sig-verify, different protocol family.
curl -X POST https://app.heinrichstech.com/v1/cdp/jwt-verify \
-H 'content-type: application/json' \
-d '{"token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.e30.inig0CiOiStD0iTCeMFEp7JIxs14iyVhOKLCNK6hBv8","sharedSecret":"test_secret"}'
# 1. Server returns 402 with a PAYMENT-REQUIRED header containing the x402 challenge.
# 2. Pick a compatible accepts[] option and pay its exact advertised amount.
# Listed primary: 0.005 USDC to 0xDa2F35d283c42dd60B965322394bc658a5c1769F on Base mainnet (eip155:8453).
# 3. Retry the same request with PAYMENT-SIGNATURE. The selected facilitator
# verifies and settles, then the response unlocks.
This call does not sign or spend. It lets your agent inspect the exact live price, recipient, asset, and network choices before choosing a compatible x402 buyer.
const res = await fetch('https://app.heinrichstech.com/v1/cdp/jwt-verify', {
method: 'POST',
headers: { 'content-type': 'application/json' },
body: JSON.stringify({"token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.e30.inig0CiOiStD0iTCeMFEp7JIxs14iyVhOKLCNK6hBv8","sharedSecret":"test_secret"}),
});
if (res.status !== 402) throw new Error(`Expected 402, received ${res.status}`);
const challenge = await res.json();
console.table(challenge.accepts.map(({ network, asset, amount, payTo }) => ({
network, asset, amount, payTo,
})));
Agents and ecosystem indexers can discover this endpoint without scraping. Hit the JSON feeds below or read the OpenAPI spec directly; the fresh 402 challenge remains canonical for price, asset, recipient, and network availability.