x402 paid API: send your CMakeLists.txt, Makefile, or package.json and get back a reproducibility score plus concrete findings — unpinned dependencies, machine-specific absolute paths, .PHONY traps, deprecated CMake policies — with line numbers.
An unpaid GET returns 402 Payment Required with the price and payment terms — that is the x402 protocol.
curl -i "https://<this-host>/audit?src=cmake_minimum_required(VERSION+3.0)"
Any x402 client pays $0.01/call in USDC on Base; payment settles to the operator wallet and the call goes through. Works with any x402-enabled agent or fetch framework (e.g. x402-fetch).
import { wrapFetchWithPayment } from "x402-fetch";
const fetchWithPay = wrapFetchWithPayment(fetch, { wallet });
const res = await fetchWithPay("https://<this-host>/audit?src=..." + encodeURIComponent(src));
const report = await res.json();
{
"tool": "CMakeLists.txt",
"score": 80,
"findings": [
{"sev":"high","line":3,"msg":"Machine-specific absolute path ..."},
{"sev":"med","msg":"find_package(Foo) without a version ..."}
],
"auditedAt":"...",
"tool":"veribuild-audit v1"
}
Honest scope: static analysis of the text you send. No execution of your code, no network calls, 32 KB limit. Detects the classes of mistakes that cause the majority of “builds on my machine but not in Docker/CI” failures.