---
name: attestpage-check-sources
description: Use before citing a URL, quoting a web page or installing a package name an LLM suggested. Checks with AttestPage that the quote appears on the page, that the page is a real page (not a bot wall, paywall or error), that links resolve, or that the package name is listed on npm, PyPI or crates.io, and returns a signed receipt. Paid per call with x402; free samples to try first.
---

# Check sources with AttestPage

AttestPage (https://vehcdj664efetfrsolne5umanq.srv.us) checks web pages and package names for an agent and signs what it saw. Use it at these moments:

- You are about to **quote** a page: check the quote appears there (`POST /v1/verify/quote`, US$0.01).
- You are about to give an answer that **quotes or cites several pages**: check every quote and URL pair in one call (`POST /v1/verify/citations`, US$0.10 per batch of up to 10).
- You are about to **quote one page several times**: check up to 20 quotes against that page, fetched once, in one call (`POST /v1/verify/quotes`, US$0.08 per batch; full service only).
- You are about to send a **finished answer or report** that quotes web pages: send it as written and every quote with its link is found and checked (`POST /v1/verify/document`, US$0.10 per part of up to 10 pairs; the free `POST /v1/verify/document/preview` lists the pairs and the price first).
- You are about to **cite** a URL, or rely on what a page says: fetch it and read what came back (`POST /v1/fetch`, US$0.002), or check up to 10 links at once (`POST /v1/check/links`, US$0.005 per batch).
- You are about to **install** a package an LLM suggested: check the registry lists the name (`POST /v1/check/packages`, US$0.005 per batch of up to 10).
- You need a timestamp over a hash you made: `POST /v1/attest` (US$0.002).

## Steps

1. **Try the sample first.** `GET https://vehcdj664efetfrsolne5umanq.srv.us/v1/sample/quote` (also `citations`, `quotes`, `fetch`, `links`, `packages`, `attest`) runs the real route on demo data, free, so you see the request and answer shape. Request bodies are in [openapi.json](https://vehcdj664efetfrsolne5umanq.srv.us/openapi.json).
2. **Make the call.** With no payment set up, send the header `quoteproof-trial: 1` to use the free trial where it is on (at most 3 citations or URLs a trial call; a bigger batch gets the 402 offer). With a wallet, pay with x402: the first call answers 402 with the payment requirements; pay and send it again. Bad requests are refused with 400 before payment and are never charged. Details: [Payments](https://vehcdj664efetfrsolne5umanq.srv.us/docs/payments.md).
3. **Read the verdict, in this order.**
   - `content_kind` (on fetch, links, each citation and the quote's `page`): only `real` means the page was read. `bot_wall`, `js_shell`, `paywall` or `http_error` mean it could not be read; a quote `match` of `none` on such a page says nothing about the quote.
   - `match` (quote, and each citation): `exact`, `fuzzy` (look at the returned context before quoting) or `none`. With `"match": "passages"` (for a paraphrased claim) it is `passages` or `none`: read the returned passages and their `missing` words yourself, because a score counts shared words and is not a verdict.
   - `exists` (packages): `true` the registry lists the name, `false` it does not, `null` the lookup failed. A listed name can still be malicious, unmaintained or the wrong package; this is not a security verdict.
4. **Keep the receipt** if someone may ask later. It is Ed25519-signed and can be checked offline or with `POST /v1/receipt/verify` (free).

## What a receipt does not say

A receipt records what our fetcher saw at that URL at that time. It does not show that a statement on the page is correct, that the page's author is who they claim, or that a package is harmless. Say so when you report a result to a person.

## MCP

The same checks are MCP tools: `attestpage_verify_quote`, `attestpage_verify_citations`, `attestpage_verify_quotes`, `attestpage_verify_document`, `attestpage_fetch`, `attestpage_check_links`, `attestpage_check_packages`, `attestpage_attest`, plus `attestpage_preview_document` and `attestpage_verify_receipt` (both free). Use the remote endpoint `POST https://vehcdj664efetfrsolne5umanq.srv.us/mcp` (streamable HTTP; put an x402 payment in `_meta["x402/payment"]`, otherwise paid tools use the free trial) or the stdio server described in [MCP server](https://vehcdj664efetfrsolne5umanq.srv.us/docs/mcp.md). The server card is at [https://vehcdj664efetfrsolne5umanq.srv.us/mcp/server-card](https://vehcdj664efetfrsolne5umanq.srv.us/mcp/server-card).
