Attest a hash
Last updated: 2026-10-10
POST /v1/attest signs a timestamped receipt over a SHA-256 you supply. Price: US$0.002 per call.
Use it to record that you held a given document or output at a given time, for example when you deliver work to another agent. We never see the document, only its hash.
Request
{
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
"note": "delivery of report v3 to order 77"
}
With an x402 payment you can add "idempotency_key": "order-77-delivery" so a retry gets the same receipt. Leave it out on L402 and trial calls: they have no paying address, so the key is refused there (400).
| Field | Required | Meaning |
|---|---|---|
sha256 | yes | 64 hex characters |
note | no | up to 280 characters; only its SHA-256 goes into the receipt and our records |
idempotency_key | no, x402 only | 1 to 128 printable ASCII characters without spaces; a retry with the same key, hash and note gets the same receipt |
Response
From the free sample (GET /v1/sample/attest), shortened:
{
"attestation": {
"sha256": "e3b0c442…",
"note_sha256": "…",
"seq": 1,
"issued_at": "2026-10-09T14:20:14.636Z",
"idempotency_key": null,
"idempotency_key_sha256": null,
"first_seen": true
},
"receipt": "eyJhbGciOiJFZERTQSIs…",
"tier": "paid"
}
seqis our running count of attestations.idempotency_keyandidempotency_key_sha256are null when no key was sent, as in the sample.first_seenis false when the same key returns an earlier receipt.- Reusing an
idempotency_keywith a different hash or note gets 409idempotency_conflict, not charged. The payment is verified first, then released without being taken. - We keep only the SHA-256 of your key. The receipt carries
idempotency_key_sha256, and the live answer also echoes the key you sent. - If the payment fails to settle (502
settle_failed), the receipt was already made and is kept. A retry with the same key and hash gets it (first_seen: false) and pays once. Itspaymentblock names the payer and price but is not a record that a payment settled: the receipt attests the hash and the time, not the payment. To avoid paying twice when the failed payment did go through, retry with the same payment-identifier (see payments). - Keys are scoped to the paying address, so two payers can use the same key without affecting each other. Trial calls and L402 calls have no paying address, so they cannot use
idempotency_key(400, and an L402 token is not spent).
What it shows
The receipt shows that this SHA-256 was sent to us by the stated time. It does not show who made the document, what it contains, or that it was not made earlier.