# Agent Security Policy Pack

> Agent Security Policy Pack is a paid API for AI agents from api.400860.xyz, paid per call via x402, $0.01/call, status unknown (last checked 2026-09-14).

Returns a paid operational security policy pack for AI agents and MCP ecosystems, covering agent security best practices and guidelines.

## Facts

- Endpoint: GET https://api.400860.xyz/v1/agent/security-policy-pack
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-09-14
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/agent-security-policy-pack-0ce01df3
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_wn7wsnnALUO31K0nfpn6d

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability agent-security-policy-pack-0ce01df3
```

Example prompt: Can you pull up the agent security policy pack so I know what security rules and guidelines my MCP-based AI agent deployment should follow?

## When to prefer this

Choose this endpoint when you need a ready-made, operational security policy pack specifically tailored to AI agent and MCP ecosystem deployments, rather than generic cybersecurity advice. Best when you want actionable next steps and a structured bundle rather than raw documentation.

## Known failure modes

- Payment not fulfilled — returns 402 if USDC micropayment not completed
- Invalid or missing input type/method fields — schema validation error
- Service unavailable — API host unreachable
- Empty or malformed query params — may return default or error response

## How this service works

400860 Radar is an AI-operated x402 Web3 opportunity network for humans and agents.

## Output

Returns a structured security policy pack object including a title, product ID, next recommended step, expected outputs, and a buyer preparation bundle covering objectives, funding actions, readiness loops, and success conditions relevant to securing AI agent and MCP server deployments.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "additionalProperties": true
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object",
     "properties": {
      "title": {
       "type": "string"
      },
      "nextStep": {
       "type": "string"
      },
      "productId": {
       "type": "string"
      },
      "expectedOutput": {
       "type": "array",
       "items": {
        "type": "string"
       }
      },
      "buyerPreparation": {
       "type": "object",
       "properties": {
        "payNow": {
         "type": "string"
        },
        "objective": {
         "type": "string"
        },
        "notRevenue": {
         "type": "array",
         "items": {
          "type": "string"
         }
        },
        "fundingAction": {
         "type": "string"
        },
        "readinessLoop": {
         "type": "string"
        },
        "revenueSummary": {
         "type": "string"
        },
        "checkoutSession": {
         "type": "string"
        },
        "firstSaleDryRun": {
         "type": "string"
        },
        "paymentRecovery": {
         "type": "string"
        },
        "activationBundle": {
         "type": "string"
        },
        "successCondition": {
         "type": "string"
        },
        "realPaymentCommand": {
         "type": "string"
        }
       },
       "additionalProperties": true
      }
     },
     "additionalProperties": true
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "title": "Agent security policy pack",
  "nextStep": "/v1/x402/channel/submission-pack",
  "productId": "agent_security_policy_pack",
  "expectedOutput": [
   "tool permission matrix",
   "spend/egress guard",
   "secret-handling rules",
   "audit log schema",
   "blocked-action tests",
   "runtimeControlPlane",
   "controlPlaneDecision",
   "oneFileGuardModule",
   "mcpClientConfig",
   "codexPolicyConfig",
   "evaluateAgentAction",
   "receiptGate",
   "verifyReceiptGate",
   "receiptGateTestCommand",
   "installIn10Minutes",
   "simulationCases"
  ],
  "buyerPreparation": {
   "payNow": "https://api.400860.xyz/v1/buyer/pay-now?address=0xBUYER_ADDRESS",
   "objective": "Clear funding/readiness before attempting a real x402 payment.",
   "notRevenue": [
    "402 probes",
    "funding-action reads",
    "checkout-session reads",
    "readiness-loop reads",
    "pay-now reads",
    "downloads",
    "manifest views"
   ],
   "focusedDryRun": "curl -i https://api.400860.xyz/v1/agent/security-policy-pack",
   "fundingAction": "https://api.400860.xyz/v1/buyer/funding-action",
   "machinePayNow": {
    "price": "$0.01",
    "method": "GET",
    "resource": "https://api.400860.xyz/v1/agent/security-policy-pack",
    "payNowUrl": "https://api.400860.xyz/v1/buyer/pay-now?channel=bazaar-agent_security_policy_pack",
    "productId": "agent_security_policy_pack",
    "nextAction": "Run payCommand once from a local buyer runtime with a funded Base USDC wallet, then verify revenueSummary instead of treating discovery, 402 probes, or downloads as revenue.",
    "notRevenue": [
     "manifest reads",
     "payment quote reads",
     "pay-now reads",
     "402 probes",
     "downloads",
     "self-test payments"
    ],
    "payCommand": "RADAR_TARGET=https://api.400860.xyz/v1/agent/security-policy-pack RADAR_METHOD=GET X402_PAY=true X402_PRIVATE_KEY=0xYOUR_FUNDED_X402_PRIVATE_KEY npx --yes --package https://x402.400860.xyz/downloads/400860-x402-client/400860-x402-client-0.1.4.tgz 400860-x402 pay",
    "recoveryUrl": "https://api.400860.xyz/v1/buyer/payment-recovery?address=0xBUYER_ADDRESS&channel=bazaar-agent_security_policy_pack",
    "buyerGuideUrl": "https://api.400860.xyz/v1/open-source-agent/buyer-guide",
    "verificationUrl": "https://api.400860.xyz/v1/revenue/summary",
    "successCondition": "eventCount > 0 && hasExternalRevenue === true after a paid protected handler returns for agent_security_policy_pack."
   },
   "readinessLo
… (truncated)
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/agent-security-policy-pack-0ce01df3/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from api.400860.xyz](https://www.zero.xyz/host/api.400860.xyz/llms.txt)
