verifyHumanProofRequest. The direct API path calls the REST endpoints below itself. checkAttestation is a lookup for a DID you already trust.
Checked against @billionsnetwork/x402-human-proof-server 0.1.9 and @billionsnetwork/x402-human-proof-client 0.1.7. Examples query production. For testnet URLs, see Environments.
verifyHumanProofRequest
@billionsnetwork/x402-human-proof-server. Verifies a signed human proof, derives the agent DID from the signer, and looks up the DID’s ownership attestation and the human’s nullifier through the API. It does not need x402: you can call it from any server, with no payment or facilitator involved.
Returns when the proof is valid and the DID is paired:
humanAddress is the attestation’s fromEthereumAddress. For pairings made with the Verified Agent Identity skill, that is the relay that submitted the transaction, not the person’s wallet. Identify the person by humanDid or humanId.
Returns otherwise: { allowed: false, reason, did? }. did is present for not_registered.
Treat every
reason as “not verified”. Branch on it only to show the agent a more useful error.
Throws when the Attestations or nullifier API returns an error status or can’t be reached. Catch it and treat it as “not verified”, or retry later.
Does not check: whether the nonce was issued by you or used before, and the signed domain. Do both yourself, as in Path A, Step 3.
createPoUVerifier
The lookup takes the most recent ownership attestation for the DID. The API leaves revoked attestations out. Expiry is not checked.
checkAttestation
@billionsnetwork/x402-human-proof-client. Returns whether a DID holds at least one attestation for a schema.
true or false. Revoked attestations are not counted.
checkAttestation returns false when the API responds with an error status. A false can mean “not paired” or “API unavailable”. If you need to tell them apart, call the REST endpoint below directly.REST endpoints
Base URL:https://attestations-api.billions.network/api/v1. These answer the pairing question only. Pair them with your own proof of control, as in Path B.
Find a DID’s ownership attestation
recipientEthereumAddress=<0x…> instead of recipientDid when you start from a recovered signer address, as Path B does. A paired DID returns one item:
200 with "totalItems": 0 and "data": []. Inspect Attestations explains every field.
Get one attestation
txid, expirationTime, revocable, revoked, revocationTime and rawData to the fields above, and returns revoked attestations too. An unknown ID returns 404 with {"message":"Attestation not found"}.
All attestations for an identity
identity field. Pass an agent DID to find its human, or a human DID to find all of that person’s agents. This is the lookup the Explorer runs.
Resolve a nullifier
userId is the human’s iden3 ID, the fromId of an ownership attestation. Both values are strings, because they are too large for a JavaScript number. A missing userId returns 400 with {"message":"userId query parameter is required"}, and a non-integer one returns 400 with {"message":"userId must be a valid integer"}.