Everything you need to know about wallet auth, from getting started to technical details.
No. An oracle brings off-chain data onto a blockchain, usually as a feed that contracts read. InsumerAPI works the other way round. It reads wallet state, evaluates a condition the caller writes, and returns a signed yes or no that can be used anywhere: a web server, an AI agent, a point-of-sale terminal, or a smart contract. The caller decides the condition and what to do with the answer.
For a balance condition it returns the verdict, not the balance, unless you ask for a Merkle proof, which carries the proven value.
You do not have to take the answer on faith. The signature proves the attestation came from us, unaltered, and anyone can check it offline against our published keys. On EVM chains an optional Merkle proof lets you check the balance itself against the block header.
Smart contracts can use these attestations too. Our published contract adapters verify the signature on-chain and expose the result through standard interfaces, one of which (ERC-8183) is called a trust oracle. There the contract is the consumer, and InsumerAPI is still the source of the signed attestation.
POST /v1/attest, which checks wallet conditions and returns a boolean signed with ECDSA and a post-quantum ML-DSA-65 signature, or a standard JWT with a post-quantum twin beside it. Other endpoints include wallet trust profiles, batch trust, compliance checks, and credit management. See the developer documentation for details.
attest and trust support x402 pay-per-call. Send a request with no credentials, get a 402 quote, pay the quoted USDC amount on Base, Polygon, Arbitrum, Arc or Solana, retry. $0.05 per attestation, settled on-chain.
npx -y mcp-server-insumer, runtime agent access for Claude Desktop, Cursor, Windsurf), LangChain (pip install langchain-insumer), ElizaOS plugin (@insumermodel/plugin-eliza), LlamaIndex tool spec (pip install llama-index-tools-insumer), and OpenAI GPT (GPT Store). Plus a Claude Code skill (smithery skill add douglasborthwick/insumer-skill) that helps Claude Code write wallet auth into your project. Plus two framework adapters that package the wallet auth primitive into host-shaped surfaces: WDK protocol module (@insumermodel/wdk-protocol-wallet-auth) for Tether's Wallet Development Kit, and mppx condition-gate (@insumermodel/mppx-condition-gate) for Machine Payments Protocol routes. Attestations are independently verifiable with insumer-verify (npm install insumer-verify). OpenAPI 3.1 spec available at /openapi.yaml.
erc8004_agent verifies ERC-8004 agent registration, and erc7710_delegation verifies a principal really delegated authority to an agent, checked against live chain state. The MCP server and LangChain SDK make integration straightforward for agent frameworks.
POST /v1/attest, POST /v1/trust, POST /v1/trust/batch, GET /v1/credits, and POST /v1/credits/buy. Agents that buy a key via POST /v1/keys/buy with USDC or USDT on an EVM chain receive an Insumer Access pass (soulbound ERC-721) minted to their wallet on Base; x402 payers become eligible after $1 of spend and claim it on their first wallet-signed request. The same wallet can then sign requests with its private key and present them in an Authorization: Wallet header instead of X-API-Key. The signed message is SIWE (EIP-4361) scoped to api.insumermodel.com; the signature is EIP-191 personal_sign; single-use nonce; Issued At within the last 5 minutes. Other endpoints return 501 for this scheme. The five-endpoint coverage lets an SBT-holding agent run the full read-side lifecycle (attest, generate trust profiles, check balance, top up credits) without ever handling an API key. For your own API, Skye Meta’s @skyemeta/access middleware on npm accepts wallet-signed requests beside API keys. See the full Authentication reference.
sig, kid) and post-quantum ML-DSA-65 (pqSig, pqKid). Fetch our public keys from /.well-known/jwks.json or GET /v1/jwks, then verify with insumer-verify (npm or PyPI), which reports each signature as its own verdict, or check the ECDSA signature with any standard crypto library. JWT-format results can be verified by standard JWT libraries. No callback to the API is required.
POST /v1/attest or the merchant endpoints. Stores, clubs and communities that want it run for them use Skye Meta, a separate company that licenses InsumerAPI.
format: "jwt" for a standard JWT, or proof: "merkle" for a blockchain-anchored storage proof. See How It Works for the full flow.
format: "jwt" to an attestation request returns a standard ES256-signed JWT alongside the normal response. The JWT contains claims for pass/fail, condition results, and block context. It can be verified by any standard JWT library via the JWKS endpoint, making it compatible with Kong, Nginx, Cloudflare Access, AWS API Gateway, and similar systems. A post-quantum twin, pqJwt, comes beside it.
proof: "merkle" to an attestation request returns an EIP-1186 Merkle storage or account proof anchored to a specific block hash. This makes the attestation independently verifiable against the blockchain state trie without trusting the API. Available on 27 of 31 EVM chains. Costs 2 credits instead of 1.
Ask InsumerChat in the bottom right corner, reach out to our team.