Your first paid scan, step by step

Written for someone who has never called a crypto-paid API. Steps 1 and 2 are free and need nothing but Postman. Step 3 costs one cent.

Read this first — it saves you an hour

WalletTriage has no API key and no signup. Instead, every call to the paid endpoint costs $0.01 in USDC on Base, paid through the x402 protocol: your side digitally signs that one payment with a wallet key.

Postman cannot finish a paid call — and neither can any other HTTP client. Postman, Insomnia and curl speak HTTP; the payment step needs a cryptographic signature from a wallet, which they cannot produce. That is not a limitation of your setup. Nobody does the paid call with Postman alone.

So the practical route is:

STEP 01 · FREE

A free scan in Postman (sandbox)

This returns the exact same JSON shape the paid endpoint does — same risk engine, synthetic data.

  1. Postman → New → HTTP Request
  2. Method: GET
  3. Paste this URL:
https://api.wallettriage.com/sandbox/scan?address=0x0000000000000000000000000000000000000002

Leave Authorization and Headers completely empty. Hit Send.

You get 200 OK with risk_score, risk_level, findings[], plus "sandbox": true, "data_source": "fixture" and a leading entry in caveats.

The four fixture addresses

AddressWhat it demonstrates
0x…0001critical — exposure to a contract flagged by the threat feed
0x…0002high — unlimited allowance to an unknown spender
0x…0003medium — bounded allowance to an unknown spender
0x…0004low — reputable spenders only, spam token suppressed

Write the zeros out in full — 40 characters after 0x. Any other address returns 400 listing the fixtures. Optional chain parameter: eth (default), base, polygon, arbitrum, optimism, bsc.

The data is synthetic. Never use a sandbox response to make a security decision about a real wallet.

STEP 02 · FREE

Discover the price of a paid scan

Duplicate the request and point it at the paid endpoint with any real address:

https://api.wallettriage.com/scan?address=0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045

Hit Send. You get 402 Payment Required. That is the expected answer, not an error — it is how the API quotes its price.

Open the response Headers tab and find PAYMENT-REQUIRED. It is base64-encoded JSON holding the price, the network (Base) and the asset (USDC); paste it into any base64 decoder to read it.

Still zero cost, still no wallet.

STEP 03 · $0.01

The paid scan

3.1 — Create a throwaway wallet

Never use your main wallet. Whoever holds a private key controls that wallet's funds entirely, with no recovery. Create a brand-new account (a fresh account exported from MetaMask, or cast wallet new), take its private key (0x + 64 hex characters) and fund it with 1–2 USDC on the Base network.

You do not need ETH: payments are gasless — the facilitator submits the transaction and pays gas. One dollar buys about 100 scans.

3.2 — Run the script (Node 20+)

In an empty folder:

npm init -y
npm pkg set type=module
npm install @x402/fetch @x402/evm viem

Create scan.mjs:

import { x402Client, wrapFetchWithPayment } from '@x402/fetch';
import { ExactEvmScheme } from '@x402/evm';
import { privateKeyToAccount } from 'viem/accounts';

const KEY    = '0xYOUR_THROWAWAY_WALLET_PRIVATE_KEY';
const TARGET = '0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045'; // address to check

const client = new x402Client();
client.register('eip155:*', new ExactEvmScheme(privateKeyToAccount(KEY)));
// safety cap: refuse anything above $0.10 (atomic units, USDC has 6 decimals)
client.registerPolicy((_v, reqs) => reqs.filter(r => BigInt(r.amount) <= 100000n));

const paidFetch = wrapFetchWithPayment(fetch, client);
const res = await paidFetch(`https://api.wallettriage.com/scan?address=${TARGET}`);
console.log(JSON.stringify(await res.json(), null, 2));
node scan.mjs

The script runs the whole loop for you: it receives the 402, signs the payment locally, retries with the X-PAYMENT header and prints the verdict. The response carries a PAYMENT-RESPONSE header — your settlement receipt, including the transaction hash.

Your private key never leaves your machine. Only the signature travels, and each signature authorizes one fixed amount to one recipient — it is not a spending allowance. The policy line above caps it further and refuses locally, before signing.

3.3 — What about pasting the header into Postman?

Once the script works you can copy the X-PAYMENT header it generated into a Postman request. But a signature is valid for one single call — the second attempt is rejected. It is useful for inspecting the protocol, not for real use.

Shortcut: using an AI agent instead

If you work in Claude Desktop or another MCP-capable client, skip the script entirely. Add this to your MCP config (e.g. claude_desktop_config.json):

{
  "mcpServers": {
    "wallettriage": {
      "command": "npx",
      "args": ["-y", "wallettriage-mcp"],
      "env": {
        "GATEWAY_URL": "https://api.wallettriage.com",
        "EVM_PRIVATE_KEY": "0xYOUR_THROWAWAY_KEY",
        "MAX_PAYMENT_ATOMIC": "100000"
      }
    }
  }
}

Then just ask, in plain language: "is this address risky?". Tools: check_address_risk (paid) and get_pricing (free).

Omit EVM_PRIVATE_KEY and the server starts in sandbox-only mode: free synthetic responses with the identical schema. Build and test your whole integration first; fund a wallet only once it works.

When something goes wrong

What you seeWhat it means
402 on /scanExpected without payment. That is step 2, not a failure.
400 invalid_address on the sandboxAddress is not one of the four fixtures — usually a missing zero.
429 rate_limitedPer-IP limit. Wait out the Retry-After window.
503 threat_feed_unavailableThe live signal is degraded, so no reliable verdict is possible. No payment is taken. Retry shortly.
502 data_provider_errorUpstream on-chain data provider failed. Retry.
unable to verify the first certificateAntivirus or a corporate proxy is intercepting TLS (common on Windows). Add "NODE_OPTIONS": "--use-system-ca" to your env block so Node trusts your system certificate store. Never disable TLS verification.

What it costs

Steps 1 and 2 are free and already validate your entire integration — the sandbox runs the same engine and returns the same schema. Only step 3 charges: $0.01 per scan, no subscription, no minimum, no card. If you don't call, you don't pay.

Back to Integrate