All workflows

Release Sentinel / npm Registry-OSV Gate

Live, independent npm dependency release risk evidence for non-AI package managers, CI/CD runners and deployment controllers. Check pinned sha512 integrity, lifecycle scripts, optional npm signature/provenance metadata and known OSV vulnerabilities before installing an exact package version. Live registry+OSV preflight runs prior to payment settlement, and errors prevent fulfillment; buyer authorization is required.

5 credits per call · $0.049 USDC with x402

Sample input

{
  "name": "lodash",
  "version": "4.17.21",
  "policy": {
    "block_on_vulnerability": true,
    "block_install_scripts": true
  }
}

Worked sample output

{
  "ok": true,
  "mode": "release_sentinel_example",
  "example_only": true,
  "not_live": true,
  "name": "lodash",
  "version": "4.17.21",
  "decision": "illustrative_only",
  "warning": "Worked schema example, not live npm or OSV verification. Paid fulfillment runs independent source checks."
}

Worked example using published sample data only. Own-data execution is paid.

Connect in curl

Set BOUNTY_API_KEY privately after your payment is verified. Change the retry key for each new logical request.

curl 'https://bounty-engineer-x402-api.onrender.com/v1/prepaid/release-sentinel-evidence' \
  -H "Authorization: Bearer $BOUNTY_API_KEY" \
  -H 'Content-Type: application/json' \
  -H 'Idempotency-Key: workflow-request-001' \
  -H 'X-Max-Credits: 5' \
  --data '{"name":"lodash","version":"4.17.21","policy":{"block_on_vulnerability":true,"block_install_scripts":true}}'

Connect in n8n

Download the inactive n8n template. Import it, configure the private Header Auth credential, inspect the sample and run it manually. A new execution creates a new billable request; there is no automatic schedule.

Use an HTTP POST to https://bounty-engineer-x402-api.onrender.com/v1/prepaid/release-sentinel-evidence. Send JSON and these headers; store the Bearer token as a private credential.

{
  "method": "POST",
  "headers": {
    "Authorization": "Bearer YOUR_PRIVATE_API_KEY",
    "Content-Type": "application/json",
    "Idempotency-Key": "UNIQUE_PER_LOGICAL_REQUEST",
    "X-Max-Credits": "5"
  },
  "body": {
    "name": "lodash",
    "version": "4.17.21",
    "policy": {
      "block_on_vulnerability": true,
      "block_install_scripts": true
    }
  }
}

Reuse a retry key only for the same input. Failed execution returns reserved credits. Full integration and recovery guide · Machine-readable recipe