# KushBitx AgentProof Base crypto-security and SpendGuard APIs for people, applications and AI agents. npm SDK: npm install @kushbitx/sdk Quickstart: https://staging.kushbitx.com/quickstart Live free integration diagnostic: https://staging.kushbitx.com/integration-check Reviewed third-party MCP stdio example (pinned revision, no signing or payment): https://github.com/mengxin10086/kushbitx-mcp-agent/tree/0e4d32267d4692d32cfb7c451d391cd59093a883 External compatibility reference: HumanMirror supplied sanitized SpendGuard v52 adapter evidence accepted for request and response compatibility only. This is not a security certification, endorsement, customer claim or paid integration: https://humanmirror.fr/ AGENTS.md integration block: https://staging.kushbitx.com/integrations/agent-instructions.md Terms: https://staging.kushbitx.com/terms Privacy: https://staging.kushbitx.com/privacy Trust Center: https://staging.kushbitx.com/trust Security policy: https://staging.kushbitx.com/security Security advisories: https://staging.kushbitx.com/security/advisories Security contact metadata: https://staging.kushbitx.com/.well-known/security.txt Zero-dependency browser/URL SDK: https://staging.kushbitx.com/sdk/kushbitx.mjs Free data coverage before paying: POST /api/token-coverage (same input as token-risk; availability only, not a risk verdict). Free SpendGuard preview: POST /api/spendguard/evaluate — caller-supplied advisory policy only. Its response lists optional paid evidence checks but never invokes or charges them automatically. Protected SpendGuard pilot: POST /api/spendguard/policies creates a 30-day server-side policy and returns separate one-time admin and agent keys. Store both keys; they cannot be recovered. Protected decisions: POST /api/spendguard/decisions with Authorization: Bearer . The request contains payment facts, never policy limits. Decisions are idempotent by policyId + requestId. Human approval: POST /api/spendguard/decisions/{decisionId}/approve with the admin key. SpendGuard never holds a wallet key or executes the payment. SpendGuard UI: https://staging.kushbitx.com/spendguard Discovery: https://staging.kushbitx.com/api/services OpenAPI: https://staging.kushbitx.com/openapi.json Coverage guide: https://staging.kushbitx.com/guides/base-token-checks Support and integrations: admin@kushbitx.com POST /api/token-preview — free market data; no security verdict, wallet or payment required. Input example: {"chain":"base","address":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"} POST /api/token-risk — 0.25 USDC POST /api/transaction-preflight — 0.05 USDC POST /api/verify-payment — 0.01 USDC The runnable /examples/agent.mjs covers the free token preview, free SpendGuard preview and all three paid services. Use --service=token-risk, --service=preflight or --service=payment. Paid runs require explicit --paid, viem and a locally configured dedicated wallet. The SDK exposes wallet-free previews, protected SpendGuard policy and decision calls, paid-service challenge discovery, recovery preparation and submission of an externally produced PAYMENT-SIGNATURE. It never stores, requests or signs with a private key. Each paid endpoint returns HTTP 402 with a PAYMENT-REQUIRED header. The initial unsigned request does not charge a wallet. Use an x402 v2 client to authorize the displayed USDC amount on Base, retry the same input with PAYMENT-SIGNATURE, and consume the HTTP 200 JSON result. Handle errors before acting on a result. INCOMPLETE verdicts and null scores mean missing evidence, never zero risk. Prepare recovery with POST /api/orders {path,input}, store its id and key, then send Report-Id and Recovery-Key with the paid request. POST /api/orders/recover {id,key} restores the original report for 30 days without another payment. A 202 response means pending; do not authorize again. Add txHash to recovery only for interrupted settlements. Exact retries with the same PAYMENT-SIGNATURE and input also restore completed reports.