Skip to main content
The Attestations API indexes the Attestation Registry and Schema Registry contracts and serves them as JSON. The Attestation Explorer is built on it, and the x402 Human Proof SDKs call it to check pairings.
The API is internal infrastructure, not a general-purpose public API, and every endpoint is rate-limited. A production integration should depend only on the endpoints marked Yes under “Used to verify an agent” below. If you need a higher limit, contact the Billions integration team.

Endpoints

Base URLs

The examples on this page use production unless they say otherwise. Records never move between environments. See Environments.

Responses and pagination

List endpoints take page_number and page_size, and wrap results in the same envelope:
  • nextPage is null on the last page.
  • uniqueItems on the attestations list is the number of distinct attesters.
  • creationTime and expirationTime are Unix timestamps in seconds.
  • iden3 IDs and nullifiers are strings, because they are too large for a JavaScript number.

Attestations

List and filter

Add any of these query parameters to narrow the list. They combine. Revoked attestations are left out of this list. Expired ones are not.

Look up an ownership attestation

This is the lookup behind every verification. Filter by the AgentOwnership schema and the agent’s DID:
Start from a recovered signer address instead by using recipientEthereumAddress=<0x…>, as the direct API path does. A paired agent returns one item:
A DID with no pairing returns 200 with "totalItems": 0 and "data": []. Inspect Attestations explains every field of this response.

Read decoded data

decodedDataJson is a string containing JSON, so parse it a second time. Each field’s value sits under value.value, and values come back as strings, numbers included. For example, a Review attestation on testnet:

Get one attestation

Returns everything in the list item, plus: Unlike the list, this endpoint also returns revoked attestations. An unknown ID returns 404 with {"message":"Attestation not found"}.

Identities

Every attestation where the identity is the attester or the recipient, in the same paginated envelope plus an identity field. The API tells a DID, an Ethereum address and an iden3 ID apart by their format. Pass an agent DID to find its human, or a human DID to find all of that person’s agents. This is the lookup the Explorer runs.

Nullifier

userId is the human’s iden3 ID: the fromId of an ownership attestation. The nullifier is a stable, privacy-preserving identifier for that person, so you can count per person, for example one reward each, without learning who they are. A missing userId returns 400 with {"message":"userId query parameter is required"}, and a non-integer one returns 400 with {"message":"userId must be a valid integer"}.

Schemas

Each schema in the list:
The single-schema endpoint adds the creator (creator, creatorDid, creatorId), the creation transaction (txid), revocable, the raw definition (schemaRaw, for example uint8 stars,string comment), and a page of attestations written against it. See Schemas for what each schema records.
The response has a type field saying what matched. A schema ID returns:
A DID returns attesterDid or recipientDid, depending on which side it appears on.

Health check

Returns Ok when the service is up.

Missing, revoked and failed lookups

Example: average rating for an agent

The Review schema holds star ratings. Reviews exist on testnet, so this example uses the testnet base URL. It pages through every review of one agent and averages the stars:
Against that DID it currently prints 4.00 stars from 1 reviews. Testnet data changes, so your numbers may differ.