Token & contract risk report (on-chain evidence)
POST /v1/token-riskHand over a token contract address (and chain) and get one evidence-based on-chain risk report: whether the source is verified, holder concentration (top-1 / top-10 share of supply, distinguishing pools/contracts from wallets), and supply + market context, with a top-holders appendix. Send POST /v1/token-risk with the required field address and pay $0.60 per call over x402 with USDC on an EVM chain. It returns a JSON object with report, address, chain, sources, tables and 1 more.
Evidence, never a 'safe' or 'scam' verdict - on-chain checks can't see off-chain rugs, so a clean report is not an endorsement. USDC (x402/MPP). Not cached.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
address | string | yes | Token contract address (0x + 40 hex). Also accepted as addr, wallet, account. |
chain | string | no | Chain, one of: base, ethereum, polygon, arbitrum, optimism, bsc, gnosis (default base). |
format | string (one of: markdown, json) | no | Response shape (default markdown report). |
Example request
curl -i -X POST https://agent402.tools/v1/token-risk \
-H "Content-Type: application/json" \
-d '{"address":"0x4200000000000000000000000000000000000006","chain":"base"}'
Without payment this returns HTTP 402 Payment Required with the exact price for token-risk; any x402 v2 or MPP client pays it and retries.
Example response
{
"report": "# Token & Contract Risk Report: EXAMPLE (0x…)\n\n## Snapshot\n...\n\n## Risk summary\n... This is not financial advice and not exhaustive.",
"address": "0x0000000000000000000000000000000000000000",
"chain": "base",
"sources": [],
"tables": [
{
"name": "holders",
"label": "Top holders",
"columns": [
"Rank",
"Address",
"Share of supply",
"Type",
"Label"
],
"rows": [
[
"1",
"0x…",
"42.10%",
"contract",
"Uniswap V3 Pool"
]
]
}
],
"meta": {
"tier": "token-risk",
"address": "0x…",
"chain": "base",
"name": "Example",
"symbol": "EXMP",
"verified_source": true,
"holder_count": 1234,
"top1_share_pct": 42.1,
"top10_share_pct": 71.5,
"synthesis_model": "anthropic/claude-opus-5",
"disclaimer": "Evidence-based on-chain risk signals only. Not financial advice."
}
}
| Field | Type | Always present | In the example |
|---|---|---|---|
report | string | yes | # Token & Contract Risk Report: EXAMPLE (0x…) ## Snapshot ... ## Risk summa... |
address | string | yes | 0x0000000000000000000000000000000000000000 |
chain | string | yes | base |
sources | array | yes | 0 items in the example |
tables | array of objects | yes | 1 item in the example |
meta | object | yes | 11 fields: tier, address, chain, name, symbol, verified_source |
From an MCP client
catalog.call {
"slug": "token-risk",
"params": {
"address": "0x4200000000000000000000000000000000000006",
"chain": "base"
}
}
The hosted connector at https://agent402.tools/mcp needs a payment for token-risk; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.
Errors and behavior
addressis required. An input the tool rejects returns an HTTP 4xx whose body carrieserror,tool,expected,requiredandexample, so the caller can correct it.- A paid call that ends in any status of 400 or above is not charged over x402, MPP or a prepaid credits key: settlement is cancelled when the tool fails.
- Wallet-only: this tool runs a model, so it has no proof-of-work tier. A prepaid card-credits key (
Authorization: Bearer a402_...) also pays it. - Model-backed: the answer is generated by a model, so the same input can produce different wording.
- Long-running: payment settles after the work finishes, so only EVM exact payments are offered.
- A
GETorHEADto /v1/token-risk returns the same 402 quote, so the price can be read without a body. - An
Idempotency-Keyheader makes a retried paid call replay the first 200 instead of charging again (an answer larger than 1 MB and a streamed response are not replayed).
Paid call (JavaScript agent)
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);
const res = await payFetch("https://agent402.tools/v1/token-risk", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
"address": "0x4200000000000000000000000000000000000006",
"chain": "base"
}),
});
Related tools
Token & contract risk report - PRO (static scan + reputation)
POST /v1/token-risk/proThe deeper tier: everything in the standard report plus a deterministic static-pattern scan of the verified source (tx.o…
Ticker pack: dossier, insider flow and institutional holders
POST /v1/ticker-packOne ticker, one purchase, the full picture. Runs the company due-diligence dossier (SEC filings, XBRL financials, ground…
Domain security & deliverability audit (graded)
POST /v1/domain-auditHand over a domain and get one graded security & email-deliverability audit: SPF, DMARC, DKIM and MX (why your mail land…
Domain security audit - PRO (attack surface + stack)
POST /v1/domain-audit/proThe deeper tier: everything in the standard audit plus the attack surface from Certificate Transparency logs (subdomains…
Company due-diligence dossier (grounded, cited)
POST /v1/dossierHand over a ticker and get one due-diligence dossier back. Pulls the company's SEC EDGAR filings (10-K / 10-Q / 8-K) and…
Company due-diligence dossier - MAX (exhaustive)
POST /v1/dossier/maxThe exhaustive due-diligence tier: more filings, a full year of Form 4 insider activity, wider web research (up to 8 ang…