# Dependency Truth – npm/PyPI Version Verifier

> Dependency Truth – npm/PyPI Version Verifier is a paid API for AI agents from dependency-truth.inboxtzdjqv.workers.dev, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Fetches the current stable release of an npm or PyPI package and validates a claimed version or publication date against live registry metadata.

## Facts

- Endpoint: POST https://dependency-truth.inboxtzdjqv.workers.dev/v1/dependency-truth?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/dependency-truth-npm-pypi-version-verifier-e7665d43
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_O9G7L7PNO7Ry_DZUdq0Qh

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability dependency-truth-npm-pypi-version-verifier-e7665d43 -d '<json body>'
```

Example prompt: Can you verify whether express 5.1.0 is the current stable npm release, and check if it was actually published on 2025-03-31?

## When to prefer this

Choose this endpoint when you need to programmatically verify whether a specific npm or PyPI package version claim is accurate against live registry data — especially in CI pipelines, AI agent tool-use, documentation audits, or supply-chain checks. Prefer it over manual registry lookups when you also need a structured claim-validation result (versionCurrent, publishedDate match) rather than just browsing the registry. It is ideal when the agent must confirm facts about a dependency without relying on potentially stale training data.

## Known failure modes

- Package not found in the specified ecosystem returns an error or null stable version
- Misspelled package name yields no match
- Unsupported ecosystem value (anything other than 'npm' or 'pypi') fails schema validation
- Registry is temporarily unavailable causing a fetch timeout
- Scoped npm package names (e.g. @scope/pkg) may require exact formatting

## How this service works

Deterministic package, repository, security, and citation evidence APIs payable per call with x402.

## Output

Returns a JSON object with the current stable version, its publication timestamp, whether the package is deprecated or yanked, a claim object indicating whether the supplied version and/or date match registry truth, any warning flags, and direct provenance URLs to the npm or PyPI registry pages for audit.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "package": {
   "type": "string",
   "description": "Exact package name"
  },
  "ecosystem": {
   "enum": [
    "npm",
    "pypi"
   ],
   "type": "string",
   "description": "Package registry"
  },
  "claimedDate": {
   "type": "string",
   "description": "Optional YYYY-MM-DD publication claim to check"
  },
  "claimedVersion": {
   "type": "string",
   "description": "Optional version claim to check"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "claim": {
   "version": "5.1.0",
   "dateCurrent": null,
   "publishedDate": null,
   "versionCurrent": true
  },
  "flags": [],
  "yanked": false,
  "package": "express",
  "ecosystem": "npm",
  "fetchedAt": "2026-09-20T12:00:00.000Z",
  "deprecated": null,
  "publishedAt": "2025-03-31T14:24:25.696Z",
  "stableVersion": "5.1.0",
  "provenanceUrls": [
   "https://www.npmjs.com/package/express",
   "https://registry.npmjs.org/express"
  ]
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/dependency-truth-npm-pypi-version-verifier-e7665d43/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from dependency-truth.inboxtzdjqv.workers.dev](https://www.zero.xyz/host/dependency-truth.inboxtzdjqv.workers.dev/llms.txt)
