Offline format and checksum validation for strings that agents often need to check: IBAN, EU VAT numbers, Polish NIP, REGON and PESEL, and email syntax.
Each check costs $0.001, paid per call with x402 (HTTP 402 Payment Required) in USDC on Base (mainnet), network eip155:8453.
No account and no API key are needed.
Privacy: We never store the values you check; we count requests and public payment data.
Values are sent only in the POST body, processed in memory and never logged or stored. Personal identifiers are masked in responses. For statistics we record only: time, endpoint template, check type, method, status, outcome, (for paid calls) whether the value was valid, the User-Agent (first 200 chars), Cloudflare's verified-bot category, country, network operator (ASN), the Referer host, and for paid calls the payer wallet address and transaction hash (both public on-chain). No IP addresses, bodies, query strings or other headers.
| Endpoint | Check | Price |
|---|---|---|
GET /api/types | List of checks, price, network, payTo | free |
POST /api/validate/iban | IBAN: country length + ISO 13616 mod-97 checksum | $0.001 USDC |
POST /api/validate/eu-vat | EU VAT number: per-country format (offline, no VIES); PL also NIP checksum | $0.001 USDC |
POST /api/validate/pl-nip | Polish NIP tax id: 10 digits + weighted mod-11 checksum | $0.001 USDC |
POST /api/validate/pl-regon | Polish REGON: 9 or 14 digits + mod-11 checksum | $0.001 USDC |
POST /api/validate/pl-pesel | Polish PESEL: checksum + encoded birth date and sex | $0.001 USDC |
POST /api/validate/email | Email address syntax (dot-atom local part, LDH domain; no DNS) | $0.001 USDC |
POST https://x402-test.crewofthecaptain.com/api/validate/pl-nip
content-type: application/json
{"value": "5260250274"}
The first call returns 402 with a base64 PAYMENT-REQUIRED header (x402 v2, scheme exact, asset USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, payTo 0xACeaEeBF0Dc8DC7762F2FdE4885f219888e9D045).
An x402 client (e.g. @x402/fetch) signs an EIP-3009 authorization and retries with a PAYMENT-SIGNATURE header. Gas is paid by the facilitator.
The response is {"type","valid","normalized","reason"}; personal identifiers come back masked. Values in query strings are rejected (400) for privacy, and you are not charged for any 4xx answer.
Machine-readable: /openapi.json · /llms.txt · /api/types
Format checks only: EU VAT is not looked up in VIES, and email domains are not resolved.