# Sentinel > Pre-payment address screening for AI agents. One paid call returns an OFAC > sanctions match, known-bad labels (mixer, drainer, exploit, ransomware, phishing, > scam, darknet), lookalike / address-poisoning detection, EIP-55 validity and live > on-chain hygiene for any EVM address — with a 0-100 risk score > (PAY_OK / CAUTION / DO_NOT_PAY) and a reason string for every point of that score. > Paid per call in USDC on Base over x402: no account, no API key, no signup, no KYC. Base URL: https://sentinel.pentest.i.ng ## Why this exists Every buyer on an x402 rail is an agent about to move money to an address it has never seen. Sentinel answers that one question before the payment is signed. The score is additive and explainable: if it says DO_NOT_PAY, `reasons[]` says why, and every match carries its source. ## Free — no payment, no key, no rate limit worth worrying about - `GET /v1/sanctions` — the complete OFAC SDN EVM address list (120 addresses), JSON - `GET /v1/sanctions/delta?days=7` — addresses added since the snapshot N days ago - `GET /sanctions.txt` — the same list as plain text, one address per line - `GET /feed.xml` — Atom feed of newly-sanctioned addresses (subscribe to it) - `GET /v1/pricing` — the price table, machine-readable - `GET /v1/sources` — data provenance, per-source counts and the full scoring table - `GET /v1/service` — a service card, JSON - `GET /.well-known/x402` — the x402 resource manifest - `GET /openapi.json` — OpenAPI 3.1 with `x-payment-info` on every paid operation ## Paid — USDC on Base, x402 `exact` scheme - `POST /v1/screen` — **$0.02** — EVM address -> pre-payment risk verdict: OFAC sanctions, known-bad labels, lookalike/poisoning detection and on-chain hygiene - `GET /v1/lookup` — **$0.02** — EVM address (query param) -> pre-payment risk verdict: OFAC sanctions, known-bad labels, lookalike detection, on-chain hygiene - `POST /v1/screen/batch` — **$0.10** — Up to 25 EVM addresses -> risk verdicts in one call (5x cheaper per address; the tier to use before a payout run) ## How to pay (the whole protocol, three steps) 1. Call the route with no payment. You get **HTTP 402** with a base64 JSON challenge in the `Payment-Required` response header (and in the body). 2. Decode it, take `accepts[0]`, and sign an exact-amount USDC `transferWithAuthorization` (EIP-3009) for that `network` and `payTo`. 3. Retry the **identical** request with the signed payload in the `PAYMENT-SIGNATURE` header. On success the response carries a settlement receipt in `Payment-Response`. Wrapping `fetch` with `@x402/fetch` and registering the exact EVM scheme does all three steps for you. An unpaid probe with an empty body reaches the 402 — never a 422. ## Request and response shapes - `POST /v1/screen` — body `{"address": "0x…", "chain": "base"}` - `GET /v1/lookup` — query `?address=0x…&chain=base` - `POST /v1/screen/batch` — body `{"addresses": ["0x…", "0x…"], "chain": "base"}` (max 25) A verdict carries: `address`, `chain`, `valid_address`, `checksum_ok`, `risk_score`, `risk_level`, `verdict`, `sanctions_match`, `label_matches`, `lookalike_of_known_bad`, `matches{sanctions[],labels[],lookalike[]}`, `onchain`, `reasons[]`, `evidence`, and `dataset` (freshness). Chains: base, ethereum. ## Scoring (published, not secret) sanctions 100 · ransomware 95 · mixer/drainer 90 · exploit 85 · darknet 80 · phishing 70 · scam 65 · reported-scam 50 · +45 lookalike of a sanctioned address · +25 lookalike of a known-bad address · +10 invalid EIP-55 checksum. `PAY_OK` < 25 · `CAUTION` 25-59 · `DO_NOT_PAY` >= 60. ## Data 3,302 labelled addresses, rebuilt daily (last: 2026-10-06). - reported_scam: 2,530 - phishing: 376 - unknown_bad: 242 - sanctions: 120 - scam: 30 - exploit: 12 - darknet: 2 - mixer: 1 Sources: OFAC SDN digital-currency addresses (US Government public domain), ScamSniffer, MyEtherWallet ethereum-lists. Public data only; no personal data stored. Snapshots on disk: 1 day(s). The delta feed becomes meaningful from the second daily build. ## Other documents - A2A agent card: https://sentinel.pentest.i.ng/.well-known/agent-card.json - Agent registration (EIP-8004): https://sentinel.pentest.i.ng/.well-known/agent-registration.json - OpenAPI 3.1: https://sentinel.pentest.i.ng/openapi.json - x402 manifest: https://sentinel.pentest.i.ng/.well-known/x402 - Interactive docs: https://sentinel.pentest.i.ng/docs ## Contact The operator is reachable at hermes@pentest.i.ng. Signal aggregation over public data — not legal, compliance or financial advice.