# payload402 npm License Triage

> payload402 npm License Triage is a paid API for AI agents from payload402.edgebytenet.workers.dev, paid per call via x402, $0.01/call, status unknown (last checked 2026-09-14).

Resolves the declared license for a specific npm package version, normalizes it to SPDX, and returns a permissive-default compatibility flag for coding agents.

## Facts

- Endpoint: POST https://payload402.edgebytenet.workers.dev/mcp-license
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-09-14
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/payload402-npm-license-triage-1ecd5cba
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_ZbFmm3DzhvTjbjRhZeqsP

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability payload402-npm-license-triage-1ecd5cba -d '<json body>'
```

Example prompt: Before I add axios@1.6.0 as a dependency, can you check its npm license and tell me if it's permissive-compatible?

## When to prefer this

Choose this endpoint when a coding agent needs a quick, verifiable license check on a specific npm package version before adding it as a dependency mid-task. It is ideal for automated workflows, CI pipelines, and agent-driven coding assistants that need a machine-readable SPDX identifier and compatibility flag without invoking a full SBOM or legal compliance tool. Prefer this over LLM-recalled license knowledge when accuracy and source traceability matter.

## Known failure modes

- Package name or version not found on npm registry — returns error or empty result
- Unrecognized or non-standard license string that cannot be normalized to SPDX — may return raw license with no SPDX field
- Network or upstream npm registry unavailability causing timeout
- Malformed input schema or missing required toolName field — returns validation error
- Ambiguous or compound license expressions (e.g. (MIT OR Apache-2.0)) may require manual review

## How this service works

npm package license triage for coding agents: call before npm install or adding a dependency mid-task. Returns declared license, SPDX normalization, and permissive-default compatible yes/no/unknown from the public npm registry. Triage only — not compliance-grade SBOM or legal advice. Workflow: call GET /license/check (or MCP check_npm_license) before npm install; if compatible=no, pick another package or escalate to human; if unknown, treat as risk. Example: left-pad@1.0.0 before install. Also: Convert amounts between ISO 4217 currencies using ECB daily reference rates (Frankfurter). Use for invoices, travel budgets, expense reports, and shopping comparisons when you need a verifiable rate instead of LLM arithmetic. Not live tradable FX — rates follow ECB business-day publication. Also: Resolve a place name or lat/lon to IANA timezone and coordinates (Open-Meteo). Use for agent scheduling, travel logistics, and local-time questions without LLM guessing. Not IP geolocation. Also: Translate short text between languages (Azure Translator). Use when an agent needs a verifiable string in another language for UI copy, messages, or research snippets — not legal, medical, or certified translation.

## Output

A JSON object containing the package name, resolved version, declared license string, SPDX-normalized license identifier, a compatibility policy label (e.g. 'permissive-default'), a yes/no compatible flag, the data source ('npm-registry'), a human-readable reason, and a triage disclaimer noting this is not legal or compliance advice.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "toolName",
    "inputSchema"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "mcp"
    },
    "toolName": {
     "type": "string"
    },
    "description": {
     "type": "string"
    },
    "inputSchema": {
     "type": "object"
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "spdx": "MIT",
  "policy": "permissive-default",
  "reason": "Permissive license matches permissive-default policy",
  "source": "npm-registry",
  "license": "MIT",
  "package": "lodash",
  "version": "4.17.21",
  "compatible": "yes",
  "disclaimer": "Triage indicator only, not legal or compliance advice"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/payload402-npm-license-triage-1ecd5cba/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from payload402.edgebytenet.workers.dev](https://www.zero.xyz/host/payload402.edgebytenet.workers.dev/llms.txt)
