Pay 0.005 USDC, verify a webhook signature against the provider canonical HMAC scheme. Supports stripe, github, vercel, cdp, slack, and generic HMAC-SHA256. Constant-time compare, clock-skew tolerance on timestamp-bearing providers. Stateless — caller supplies their secret in the request body, BitBooth never stores it. The boring API plumbing primitive every agent reinvents poorly.
curl -X POST https://app.heinrichstech.com/v1/cdp/webhook-sig-verify \
-H 'content-type: application/json' \
-d '{"provider":"generic","payload":"{\"event\":\"test\"}","signature":"14c2b69d0f7114b125aa4bc17be322d0f1f33be4ffa762e91b3cabfeb4295151","secret":"test_secret"}'
# 1. Server returns 402 with a PAYMENT-REQUIRED header containing the x402 challenge.
# 2. Pick a compatible accepts[] option and pay its exact advertised amount.
# Listed primary: 0.005 USDC to 0xDa2F35d283c42dd60B965322394bc658a5c1769F on Base mainnet (eip155:8453).
# 3. Retry the same request with PAYMENT-SIGNATURE. The selected facilitator
# verifies and settles, then the response unlocks.
This call does not sign or spend. It lets your agent inspect the exact live price, recipient, asset, and network choices before choosing a compatible x402 buyer.
const res = await fetch('https://app.heinrichstech.com/v1/cdp/webhook-sig-verify', {
method: 'POST',
headers: { 'content-type': 'application/json' },
body: JSON.stringify({"provider":"generic","payload":"{\"event\":\"test\"}","signature":"14c2b69d0f7114b125aa4bc17be322d0f1f33be4ffa762e91b3cabfeb4295151","secret":"test_secret"}),
});
if (res.status !== 402) throw new Error(`Expected 402, received ${res.status}`);
const challenge = await res.json();
console.table(challenge.accepts.map(({ network, asset, amount, payTo }) => ({
network, asset, amount, payTo,
})));
Agents and ecosystem indexers can discover this endpoint without scraping. Hit the JSON feeds below or read the OpenAPI spec directly; the fresh 402 challenge remains canonical for price, asset, recipient, and network availability.