<!-- Markdown copy of https://insumermodel.com/developers/ for agents. -->

> Docs for InsumerAPI, wallet auth for developers and AI agents: quickstart, API reference, MCP server, SDKs and verifiers. Get a free key and make a signed call.
>
> Page: https://insumermodel.com/developers/ · API: https://api.insumermodel.com · OpenAPI: https://insumermodel.com/openapi.json · Index for agents: https://insumermodel.com/llms.txt

# InsumerAPI docs

Send a wallet and a condition. Get a signed boolean.

One API call verifies token balances across 37 blockchains, NFT ownership across 33, and EAS attestations on 5. Every result is ECDSA-signed. Verify it client-side. No country restriction: the API reads public chain state, so it works the same from anywhere.

## Your first signed result in one call

Get a free API key. Replace `YOUR_API_KEY`. Run this.

AI agents: buy a key autonomously with USDC via `POST /v1/keys/buy`, no email required. EVM agents that hold the Insumer Access pass can then sign requests with `Authorization: Wallet` instead of `X-API-Key` on five endpoints (`/v1/attest`, `/v1/trust`, `/v1/trust/batch`, `GET /v1/credits`, `/v1/credits/buy`). See [Authentication](https://insumermodel.com/developers/api-reference/#auth).

```javascript
// Node 18+, save as app.mjs (ES module)
const res = await fetch("https://api.insumermodel.com/v1/attest", {
  method: "POST",
  headers: { "Content-Type": "application/json", "X-API-Key": "YOUR_API_KEY" },
  body: JSON.stringify({
    wallet: "0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045",
    conditions: [{
      type: "token_balance",
      contractAddress: "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913", // USDC on Base
      chainId: 8453,
      threshold: "1"
    }]
  })
});

const response = await res.json();
console.log(response.data.attestation.pass); // true or false, signed (sig, kid, pqSig, pqKid)
```

```python
import requests

response = requests.post(
    "https://api.insumermodel.com/v1/attest",
    headers={"X-API-Key": "YOUR_API_KEY"},
    json={
        "wallet": "0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045",
        "conditions": [{
            "type": "token_balance",
            "contractAddress": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",  # USDC on Base
            "chainId": 8453,
            "threshold": "1",
        }],
    },
).json()

print(response["data"]["attestation"]["pass"])  # True or False, signed (sig, kid, pqSig, pqKid)
```

```bash
curl -X POST https://api.insumermodel.com/v1/attest \
  -H "Content-Type: application/json" \
  -H "X-API-Key: YOUR_API_KEY" \
  -d '{
    "wallet": "0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045",
    "conditions": [{
      "type": "token_balance",
      "contractAddress": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "chainId": 8453,
      "threshold": "1"
    }]
  }'

# Response: { "ok": true, "data": { "attestation": { "pass": true, "results": [...] }, "sig": "...", "kid": "insumer-attest-v2", "pqSig": "...", "pqKid": "insumer-attest-pq1" }, "meta": {...} }
```

One credit per call. Boolean, not balance: the result says whether the wallet meets the condition, never what it holds. Need a full fact profile of a wallet instead? `POST /v1/trust` takes just an address and returns 155 checks across 27 chains in 10 dimensions (up to 176 across 29 in 14 with optional Solana/XRPL/Bitcoin/Tron wallets). Both endpoints also run keyless via [x402 pay-per-call](https://insumermodel.com/pricing/#x402) ($0.05 per attestation, USDC on Base, Polygon, Arbitrum, Arc, or Solana), and attest covers agent standing: `erc8004_agent` registration and `erc7710_delegation` validity. [Custom conditions →](https://insumermodel.com/developers/verification/) | [Trust profiles →](https://insumermodel.com/developers/trust/)

### Verify the signature

Every attestation is ECDSA-signed, with a post-quantum signature beside it. Verify it client-side so you don't have to trust the network.

```javascript
// ES module (e.g. verify.mjs). npm install insumer-verify @noble/post-quantum   (the second package adds the post-quantum check)
import { verifyAttestation } from "insumer-verify";

// Pass the full API response from above, not response.data
const result = await verifyAttestation(response, {
  jwksUrl: "https://api.insumermodel.com/v1/jwks"
});

console.log(result.valid);   // true: signature matches the published key
console.log(result.checks);  // per-check breakdown (signature, conditionHashes, freshness, expiry, pq)
```

```python
# pip install "insumer-verify[pq]"   ([pq] adds the post-quantum signature check)
from insumer_verify import verify_attestation

# Pass the full API response, not response["data"]
result = verify_attestation(response, jwks_url="https://api.insumermodel.com/v1/jwks")

print(result["valid"])   # True: signature matches the published key
print(result["checks"])  # per-check breakdown (signature, conditionHashes, freshness, expiry, pq)
```

The JWKS publishes five entries over two keys. Three key IDs share the same P-256 key: `insumer-attest-v1`, `insumer-attest-v2` and `insumer-trust-v2`, followed by two RFC 9964 `AKP` entries, `insumer-attest-pq1` and `insumer-trust-pq1`, for the ML-DSA-65 post-quantum key (`pqSig`/`pqKid` on every attest and trust response). Resolve the key by the `kid` on the response you are verifying, never by position; the `kid` also tells you which verification rules to apply. Static copy also at [/.well-known/jwks.json](https://insumermodel.com/.well-known/jwks.json). [insumer-verify on npm →](https://www.npmjs.com/package/insumer-verify)

In production: [AsterPay KYA](https://insumermodel.com/blog/asterpay-kya-erc8183-attestation-integration.html) and [Revettr](https://revettr.com) use InsumerAPI in production.

**46** Endpoints **37** Blockchains **ECDSA** Signed **ACP + UCP** Compatible

## Four layers. One pipeline.

Every endpoint maps to this pipeline. Blockchain state in, signed attestation out.

### Read

37 chains 
Tokens on 37, NFTs on 33, EAS on 5

### Sign

ECDSA P-256 attestation 
or ES256 JWT via JWKS

### Trust

155–176 checks → 10–14 dimensions 
Signed wallet profiles

### Use

Commerce, compliance 
Access control, agent trust

`POST /v1/attest` → Read + Sign · `POST /v1/trust` → Read + Sign + Trust · `POST /v1/acp/discount` → Full pipeline

## Explore the API

### Quickstart

Get an API key and make your first attestation call in under 5 minutes. No setup required.

[Start here →](https://insumermodel.com/developers/quickstart/)

### Verification

Boolean attestation across ten condition types: token balances, NFT ownership, EAS attestations, Farcaster identity, view calls, ratio rules, agent standing, and account code. ECDSA-signed, optional Merkle proofs.

[Verification docs →](https://insumermodel.com/developers/verification/)

### Wallet Trust Profiles

155 curated checks across 27 chains in 10 dimensions (up to 176 across 29 in 14 with optional chains). ECDSA-signed fact profiles for agent-to-agent trust. Single and batch endpoints.

[Trust docs →](https://insumermodel.com/developers/trust/)

### Compliance Gating

Verify KYC attestations on-chain. Pre-configured templates for Coinbase Verifications and Gitcoin Passport, plus the `farcaster_id` condition.

[Compliance docs →](https://insumermodel.com/developers/compliance/)

### AI Agent Commerce

ACP and UCP protocol integration. Verify holdings, generate discount codes, validate at checkout. Built for autonomous agents.

[Commerce docs →](https://insumermodel.com/developers/commerce/)

### Merchant Onboarding

Programmatic merchant setup. Create, verify domain, configure tokens and NFTs, publish to directory. No dashboard needed.

[Onboarding docs →](https://insumermodel.com/developers/onboarding/)

### API Reference

Complete reference for the core endpoints. Auth, response format, rate limits, and every parameter documented.

[Full reference →](https://insumermodel.com/developers/api-reference/)

New

### Wallet Auth

Gate any API on wallet state using standard JWT bearer tokens. Compatible with any OAuth-compatible gateway or middleware. No blockchain knowledge required.

[Wallet Auth docs →](https://insumermodel.com/developers/verification/#wallet-auth)

New

### WDK Wallet Auth

A fifth protocol module for Tether's [Wallet Development Kit](https://docs.wdk.tether.io/) alongside Swap, Bridge, Lending, and Fiat. Pre-transaction condition checks for any WDK-based wallet. Live on npm.

[WDK docs →](https://insumermodel.com/developers/wdk/)

### API Topology

Interactive visual graph of the core endpoints. See how they connect across the reference patterns with credit costs and data flows.

[Explore topology →](https://insumermodel.com/workbench/)

See what shipped and when on the [changelog](https://insumermodel.com/developers/changelog/). Or read the [AI agent verification guide](https://insumermodel.com/ai-agent-verification-api/) for a complete walkthrough.

## Works with your stack

#### Claude Code Skill

Claude Code · Authoring helper

Helps Claude Code write correct, signature-verifying integration code into your project. Activates on phrases like "add wallet auth", "gate by token holdings", or "verify wallet eligibility". Includes hard-stop guardrails on inline keys and unverified responses.

`git clone https://github.com/insumerapi/insumer-skill.git ~/.claude/skills/insumer` [View on Smithery →](https://smithery.ai/skills/douglasborthwick/insumer-skill) [View source on GitHub →](https://github.com/insumerapi/insumer-skill)

#### MCP Server

Claude Desktop · Cursor · Windsurf

27 tools. Verify holdings, EAS attestations, compliance templates, wallet trust profiles, batch trust, ACP/UCP commerce, and onboard merchants.

`npx -y mcp-server-insumer`

Or connect by URL, no install and no key: `https://api.insumermodel.com/mcp` serves ten tools on a shared daily allowance (ChatGPT, claude.ai connectors, hosted agents).

[View on npm →](https://www.npmjs.com/package/mcp-server-insumer) [View source on GitHub →](https://github.com/insumerapi/mcp-server-insumer) [View on Glama →](https://glama.ai/mcp/servers/insumerapi/mcp-server-insumer)

#### LangChain SDK

Python · Any LangChain agent

26 tools. Verify holdings, EAS attestations, compliance templates, wallet trust profiles, batch trust, ACP/UCP commerce, domain verification, and code validation.

`pip install langchain-insumer` [View on PyPI →](https://pypi.org/project/langchain-insumer/) [View source on GitHub →](https://github.com/insumerapi/langchain-insumer)

#### LlamaIndex Tool Spec

Python · Any LlamaIndex agent

Single `InsumerToolSpec` with six methods: `attest_wallet`, `get_trust_profile`, `list_compliance_templates`, `get_jwks`, `buy_api_key`, `buy_credits`. Wallet auth plus the full agentic commerce loop: agents can buy their own API key on-chain (USDC or BTC) and top up credits, no human in the loop.

`pip install llama-index-tools-insumer` [View on PyPI →](https://pypi.org/project/llama-index-tools-insumer/) [View source on GitHub →](https://github.com/insumerapi/llama-index-tools-insumer)

#### OpenAI GPT

GPT Store · Custom GPTs

Use the OpenAPI spec directly in GPT Actions. Available via the GPT Store for end-user access.

`insumermodel.com/openapi.yaml`

#### Attestation Verifier

Node.js · Browser · TypeScript · Python

Reference library to independently verify attestation signatures, condition hashes, block freshness, expiry, and the post-quantum signature. Verifies both raw ECDSA attestations and Wallet Auth JWT tokens, auto-detected. Same checks and same test vectors in both languages.

`npm install insumer-verify` `pip install insumer-verify` [View on npm →](https://www.npmjs.com/package/insumer-verify) [View on PyPI →](https://pypi.org/project/insumer-verify/) [View source on GitHub →](https://github.com/insumerapi/insumer-verify)

#### ElizaOS Plugin

ElizaOS · Autonomous Agents

10 actions covering the full agent lifecycle: key purchase, merchant onboarding, verification, trust profiling, ACP/UCP commerce.

`npm install @insumermodel/plugin-eliza` [View on npm →](https://www.npmjs.com/package/@insumermodel/plugin-eliza) [View source on GitHub →](https://github.com/insumerapi/eliza-plugin-insumer)

Browse code examples on [GitHub](https://github.com/insumerapi/insumer-examples).

### Where to find InsumerAPI

The same server and packages, listed where agents and developers look. Every entry below is published by InsumerAPI.

[**Official MCP Registry**com.insumermodel/insumer: the npm package and the hosted endpoint, verified through this domain.](https://registry.modelcontextprotocol.io/v0.1/servers?search=com.insumermodel/insumer) [**Glama: hosted connector**The endpoint at api.insumermodel.com/mcp, ten tools, no key.](https://glama.ai/mcp/connectors/com.insumermodel/insumer) [**Glama: MCP server**The npm package, all 27 tools, with your own key.](https://glama.ai/mcp/servers/insumerapi/mcp-server-insumer) [**Smithery**insumerapi/insumer: the hosted server, connect by URL.](https://smithery.ai/servers/insumerapi/insumer) [**mcp.so**Remote server listing with setup lines for common MCP clients.](https://mcp.so/servers/insumerapi) [**mcpservers.org**Listing on the Awesome MCP Servers directory: hosted URL and npm package.](https://mcpservers.org/servers/insumerapi/mcp-server-insumer) [**GitHub: insumerapi**Source for the MCP server, the verifier, the agent skills and the examples.](https://github.com/insumerapi)

Also listed in [awesome-mcp-servers](https://github.com/punkpeye/awesome-mcp-servers), [TensorBlock MCP directory](https://github.com/TensorBlock/awesome-mcp-servers), and [awesome-erc8004](https://github.com/sudeepb02/awesome-erc8004).

## Choose Your Plan

Free tier: 10 free verifications plus 100 requests a day. Pro ($29/mo, 1,000 credits) and Enterprise ($99/mo, 5,000 credits) for production. Agents can buy credits directly with USDC, USDT, or BTC.

[View Pricing & Plans →](https://insumermodel.com/pricing/)

[Already have a key? Manage your account →](https://insumermodel.com/developers/account/)

## In production

AsterPay KYA

### ERC-8183 agent trust scoring

Know Your Agent hook for ERC-8183 agentic commerce. One `POST /v1/attest` call evaluates 4 conditions (USDC balance, Coinbase KYC, Coinbase country-of-residence attestation, Gitcoin Passport) that feed their KYA trust score. JWT verified via JWKS.

[Case study →](https://insumermodel.com/blog/asterpay-kya-erc8183-attestation-integration.html) [GitHub →](https://github.com/AsterPay/erc8183-kya-hook)

SettlementWitness

### Pre- and post-transaction wallet auth

Settlement Attestation Records for agent commerce. `POST /v1/attest` qualifies the wallet before a transaction, then verifies state change after settlement. ECDSA-signed pre/post pair.

[Case study →](https://insumermodel.com/blog/settlementwitness-insumer-api-pre-post-agent-commerce.html)

Revettr

### Counterparty risk scoring for x402 payments

Pre-payment risk assessment for AI agent transactions. Calls `POST /v1/trust` to profile counterparty wallets across 10 dimensions, up to 14 with optional wallets, before agents settle via x402.

[revettr.com →](https://revettr.com)

### Working with

DJD Agent Score

### On-chain trust scoring for AI agent wallets

Cold-start identity signal in the Coinbase x402 ecosystem. Uses `POST /v1/attest` to check Base USDC balance as one dimension of an agent trust score.

[Architecture pattern →](https://insumermodel.com/blog/djd-agent-score-insumer-api-integration.html) [GitHub →](https://github.com/jacobsd32-cpu/djdagentscore)

## Built into the protocol

Knowledge Context Protocol

### RFC-0004: Trust, Provenance, and Compliance

KCP defines how AI agents discover and access structured knowledge. We contributed the `attestation_url` pattern to RFC-0004, enabling any KCP manifest to require attestation verification before granting agent access. InsumerAPI is the first production implementation. The pattern is mechanism-agnostic: on-chain tokens, Verifiable Credentials, OIDC, or SPIFFE all fit.

[Read the full article →](https://insumermodel.com/blog/kcp-rfc-0004-attestation-url-standard.html) [RFC-0004 on GitHub →](https://github.com/Cantara/knowledge-context-protocol/blob/main/RFC-0004-Trust-and-Compliance.md)

NIST NCCoE

### AI Agent Identity and Authorization

We submitted comments to the NIST National Cybersecurity Center of Excellence proposing on-chain attestation verification as a complement to OAuth, OIDC, and SPIFFE for AI agent identity. The submission addresses all six question areas in NIST's concept paper, from cold-start trust to prompt injection resistance.

[Read our submission summary →](https://insumermodel.com/blog/nist-nccoe-ai-agent-identity-submission.html) [NCCoE project page →](https://www.nccoe.nist.gov/projects/software-and-ai-agent-identity-and-authorization)

Wallet auth is in active standards work across UCP, A2A, Ethereum ERCs, and the IETF. [See the standards page](https://insumermodel.com/standards/).
