# Preflight Package Version Check

> Preflight Package Version Check is a paid API for AI agents from preflight402.com, paid per call via x402, $0.05/call, status unknown (last checked 2026-10-02).

Verifies that a specific package version exists in npm, PyPI, or crates.io, returning its publication timestamp, deprecation/yanked status, artifact hashes, and optional SRI/hex digest comparison.

## Facts

- Endpoint: POST https://preflight402.com/v1/deps/version-check?utm_source=zero.xyz
- Price: $0.05/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/preflight-package-version-check-83435ee9
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_9d0t6ACIYLWRN56tGHtmw

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability preflight-package-version-check-83435ee9 -d '<json body>'
```

Example prompt: Before we pin it, check whether lodash version 4.17.20 exists in the npm registry, confirm it isn't deprecated, and verify its integrity hash matches sha512-abc123xyz.

## When to prefer this

Use this endpoint when an AI agent is about to install, pin, or lock a specific dependency version and needs to confirm that exact version exists in the official registry, check its deprecation status, and optionally verify a known artifact hash — especially in automated pipelines where hallucinated or misremembered version numbers could introduce supply-chain risk. Prefer this over general package search endpoints when you have an exact name+version and need ground-truth registry confirmation rather than discovery.

## Known failure modes

- Package name or version not found in specified registry — returns existence: false
- Invalid ecosystem value — validation error on input
- Malformed version string — parsing error returned
- Expected integrity hash format unrecognized — mismatch or format error
- Registry temporarily unavailable — upstream timeout error
- Rate limiting or payment failure — 402 or 429 response

## How this service works

Call before pinning or installing a specific package version in npm, PyPI or crates.io. Returns whether that exact version exists in the official registry, its publication timestamp, whether it is deprecated or yanked, its published artifact hashes, and whether an expected SRI/hex digest matches. Compares registry metadata only and never returns a safety verdict.

## Output

Returns a structured response indicating whether the exact package version exists in the specified registry, its publication timestamp, whether it is deprecated or yanked, the published artifact hashes for that version, and whether a provided expected SRI or hex digest matches the registry-recorded hash. Does not return a security safety verdict.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "name": {
   "type": "string",
   "maxLength": 214,
   "minLength": 1
  },
  "version": {
   "type": "string",
   "maxLength": 128,
   "minLength": 1
  },
  "filename": {
   "type": "string",
   "maxLength": 255,
   "minLength": 1
  },
  "ecosystem": {
   "enum": [
    "npm",
    "pypi",
    "crates"
   ],
   "type": "string"
  },
  "expected_integrity": {
   "type": "string",
   "maxLength": 255,
   "minLength": 1
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/preflight-package-version-check-83435ee9/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from preflight402.com](https://www.zero.xyz/host/preflight402.com/llms.txt)
