Skip to main content
Reference for what the two paths in Verify an Agent call. The server helper path uses verifyHumanProofRequest. The direct API path calls the REST endpoints below itself. checkAttestation is a lookup for a DID you already trust. Checked against @billionsnetwork/x402-human-proof-server 0.1.9 and @billionsnetwork/x402-human-proof-client 0.1.7. Examples query production. For testnet URLs, see Environments.
This page covers the verification slice of the Attestations API only. The API is internal infrastructure, not a general-purpose public API, and every endpoint is rate-limited. If your integration needs a higher limit, contact the Billions integration team.

verifyHumanProofRequest

@billionsnetwork/x402-human-proof-server. Verifies a signed human proof, derives the agent DID from the signer, and looks up the DID’s ownership attestation and the human’s nullifier through the API. It does not need x402: you can call it from any server, with no payment or facilitator involved.
Arguments Returns when the proof is valid and the DID is paired:
humanAddress is the attestation’s fromEthereumAddress. For pairings made with the Verified Agent Identity skill, that is the relay that submitted the transaction, not the person’s wallet. Identify the person by humanDid or humanId. Returns otherwise: { allowed: false, reason, did? }. did is present for not_registered. Treat every reason as “not verified”. Branch on it only to show the agent a more useful error. Throws when the Attestations or nullifier API returns an error status or can’t be reached. Catch it and treat it as “not verified”, or retry later. Does not check: whether the nonce was issued by you or used before, and the signed domain. Do both yourself, as in Path A, Step 3.

createPoUVerifier

The lookup takes the most recent ownership attestation for the DID. The API leaves revoked attestations out. Expiry is not checked.

checkAttestation

@billionsnetwork/x402-human-proof-client. Returns whether a DID holds at least one attestation for a schema.
Returns true or false. Revoked attestations are not counted.
This is a lookup, not a verification path. It does not show that the caller controls the DID. Only call it with a DID your own signature check produced, never with a DID an agent reported about itself.
checkAttestation returns false when the API responds with an error status. A false can mean “not paired” or “API unavailable”. If you need to tell them apart, call the REST endpoint below directly.

REST endpoints

Base URL: https://attestations-api.billions.network/api/v1. These answer the pairing question only. Pair them with your own proof of control, as in Path B.

Find a DID’s ownership attestation

Filter by recipientEthereumAddress=<0x…> instead of recipientDid when you start from a recovered signer address, as Path B does. A paired DID returns one item:
A DID with no pairing returns 200 with "totalItems": 0 and "data": []. Inspect Attestations explains every field.

Get one attestation

Adds txid, expirationTime, revocable, revoked, revocationTime and rawData to the fields above, and returns revoked attestations too. An unknown ID returns 404 with {"message":"Attestation not found"}.

All attestations for an identity

Every attestation where the identity is the attester or the recipient, in the same paginated envelope plus an identity field. Pass an agent DID to find its human, or a human DID to find all of that person’s agents. This is the lookup the Explorer runs.

Resolve a nullifier

userId is the human’s iden3 ID, the fromId of an ownership attestation. Both values are strings, because they are too large for a JavaScript number. A missing userId returns 400 with {"message":"userId query parameter is required"}, and a non-integer one returns 400 with {"message":"userId must be a valid integer"}.

Missing, revoked and failed lookups