Read this first — it saves you an hour
WalletTriage has no API key and no signup. Instead, every call to the paid endpoint costs $0.01 in USDC on Base, paid through the x402 protocol: your side digitally signs that one payment with a wallet key.
Postman cannot finish a paid call — and neither can any other HTTP client.
Postman, Insomnia and curl speak HTTP; the payment step needs a
cryptographic signature from a wallet, which they cannot produce. That is not a
limitation of your setup. Nobody does the paid call with Postman alone.
So the practical route is:
- Postman — explore the API for free and see the exact response shape (steps 1–2)
- A 15-line script — the actual paid scan (step 3)
A free scan in Postman (sandbox)
This returns the exact same JSON shape the paid endpoint does — same risk engine, synthetic data.
- Postman → New → HTTP Request
- Method: GET
- Paste this URL:
https://api.wallettriage.com/sandbox/scan?address=0x0000000000000000000000000000000000000002
Leave Authorization and Headers completely empty. Hit Send.
You get 200 OK with risk_score, risk_level,
findings[], plus "sandbox": true, "data_source": "fixture"
and a leading entry in caveats.
The four fixture addresses
| Address | What it demonstrates |
|---|---|
0x…0001 | critical — exposure to a contract flagged by the threat feed |
0x…0002 | high — unlimited allowance to an unknown spender |
0x…0003 | medium — bounded allowance to an unknown spender |
0x…0004 | low — reputable spenders only, spam token suppressed |
Write the zeros out in full — 40 characters after 0x. Any other address
returns 400 listing the fixtures. Optional chain parameter:
eth (default), base, polygon, arbitrum,
optimism, bsc.
The data is synthetic. Never use a sandbox response to make a security decision about a real wallet.
Discover the price of a paid scan
Duplicate the request and point it at the paid endpoint with any real address:
https://api.wallettriage.com/scan?address=0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045
Hit Send. You get 402 Payment Required.
That is the expected answer, not an error — it is how the API quotes its price.
Open the response Headers tab and find PAYMENT-REQUIRED.
It is base64-encoded JSON holding the price, the network (Base) and the asset (USDC);
paste it into any base64 decoder to read it.
Still zero cost, still no wallet.
The paid scan
3.1 — Create a throwaway wallet
Never use your main wallet. Whoever holds a private key controls that
wallet's funds entirely, with no recovery. Create a brand-new account (a fresh account
exported from MetaMask, or cast wallet new), take its private key
(0x + 64 hex characters) and fund it with 1–2 USDC on the Base
network.
You do not need ETH: payments are gasless — the facilitator submits the transaction and pays gas. One dollar buys about 100 scans.
3.2 — Run the script (Node 20+)
In an empty folder:
npm init -y npm pkg set type=module npm install @x402/fetch @x402/evm viem
Create scan.mjs:
import { x402Client, wrapFetchWithPayment } from '@x402/fetch';
import { ExactEvmScheme } from '@x402/evm';
import { privateKeyToAccount } from 'viem/accounts';
const KEY = '0xYOUR_THROWAWAY_WALLET_PRIVATE_KEY';
const TARGET = '0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045'; // address to check
const client = new x402Client();
client.register('eip155:*', new ExactEvmScheme(privateKeyToAccount(KEY)));
// safety cap: refuse anything above $0.10 (atomic units, USDC has 6 decimals)
client.registerPolicy((_v, reqs) => reqs.filter(r => BigInt(r.amount) <= 100000n));
const paidFetch = wrapFetchWithPayment(fetch, client);
const res = await paidFetch(`https://api.wallettriage.com/scan?address=${TARGET}`);
console.log(JSON.stringify(await res.json(), null, 2));
node scan.mjs
The script runs the whole loop for you: it receives the 402, signs the
payment locally, retries with the X-PAYMENT header and prints the verdict.
The response carries a PAYMENT-RESPONSE header — your settlement receipt,
including the transaction hash.
Your private key never leaves your machine. Only the signature travels, and each signature authorizes one fixed amount to one recipient — it is not a spending allowance. The policy line above caps it further and refuses locally, before signing.
3.3 — What about pasting the header into Postman?
Once the script works you can copy the X-PAYMENT header it generated into a
Postman request. But a signature is valid for one single call — the second
attempt is rejected. It is useful for inspecting the protocol, not for real use.
Shortcut: using an AI agent instead
If you work in Claude Desktop or another MCP-capable client, skip the script entirely.
Add this to your MCP config (e.g. claude_desktop_config.json):
{
"mcpServers": {
"wallettriage": {
"command": "npx",
"args": ["-y", "wallettriage-mcp"],
"env": {
"GATEWAY_URL": "https://api.wallettriage.com",
"EVM_PRIVATE_KEY": "0xYOUR_THROWAWAY_KEY",
"MAX_PAYMENT_ATOMIC": "100000"
}
}
}
}
Then just ask, in plain language: "is this address risky?". Tools:
check_address_risk (paid) and get_pricing (free).
Omit EVM_PRIVATE_KEY and the server starts in sandbox-only
mode: free synthetic responses with the identical schema. Build and test your whole
integration first; fund a wallet only once it works.
When something goes wrong
| What you see | What it means |
|---|---|
402 on /scan | Expected without payment. That is step 2, not a failure. |
400 invalid_address on the sandbox | Address is not one of the four fixtures — usually a missing zero. |
429 rate_limited | Per-IP limit. Wait out the Retry-After window. |
503 threat_feed_unavailable | The live signal is degraded, so no reliable verdict is possible. No payment is taken. Retry shortly. |
502 data_provider_error | Upstream on-chain data provider failed. Retry. |
unable to verify the first certificate | Antivirus or a corporate proxy is intercepting TLS (common on Windows). Add "NODE_OPTIONS": "--use-system-ca" to your env block so Node trusts your system certificate store. Never disable TLS verification. |
What it costs
Steps 1 and 2 are free and already validate your entire integration — the sandbox runs the same engine and returns the same schema. Only step 3 charges: $0.01 per scan, no subscription, no minimum, no card. If you don't call, you don't pay.
