# x402 Checker — OFAC SDN Sanctions Screen

> x402 Checker — OFAC SDN Sanctions Screen is a paid API for AI agents from x402-checker.nock-for-mak.workers.dev, paid per call via x402, $0.01/call, status unknown (last checked 2026-09-15).

Screens an EVM or Solana cryptocurrency address against the OFAC SDN (Specially Designated Nationals) list and returns a CLEAR or HIT verdict

## Facts

- Endpoint: GET https://x402-checker.nock-for-mak.workers.dev/sanctions
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-09-15
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/x402-checker-ofac-sdn-sanctions-screen-36273256
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_c3L50JkgQmCmIplS9BKcv

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability x402-checker-ofac-sdn-sanctions-screen-36273256
```

Example prompt: Before I send a payment to 0x3903F05a17676566958B0a3E0c21E0bd49B66ea0, can you run an OFAC sanctions screen on that wallet address and tell me if it comes back CLEAR or flagged?

## When to prefer this

Use this endpoint when you need a fast, cheap ($0.01 USDC) OFAC SDN sanctions screen for a single crypto wallet address (EVM or Solana) before executing a payment or onboarding a counterparty. Prefer this over manual OFAC lookups when operating in an automated agent workflow that requires programmatic compliance checks. It is especially valuable in x402 payment flows where you want to vet the payee address before authorizing a micropayment.

## Known failure modes

- Missing or malformed address query parameter returns a 400 error
- Address longer than 128 characters is rejected
- Non-0x EVM address or invalid base58 Solana address may return an error or unexpected kind classification
- Payment not received results in 402 response before screening occurs
- OFAC SDN XML feed staleness could mean asOf date lags real-world list updates

## How this service works

Free x402 wash/honesty look, free GET /board pay-to-rank, free GET /name?n= ENS-style agent name lookup, $0.05 USDC POST /name (30 day TTL) and POST /bid (adds to 24h total) and /report, $0.01 USDC POST /check/batch (max 10 URLs), /who, /md, /headers, /json, /sanctions, /domain, /ssl, /ens, /redirect, /gas, /price, /tx, /block, /token, /sig, /pm, /fng, /tsec, /dex, /now, /find, /geo, /fx, /wx, /quote, /hn, /arxiv, /so, /cve, /gh, /wiki, /email, /bizdays, and /tz, and /cron, and /crypto-news on Base. GET /check stays free for one URL. Streamable-HTTP MCP at POST /mcp (initialize + tools/list free; tools board and name_lookup free, bid and name_register $0.05). Crawler files: GET /llms.txt and GET /.well-known/agent.json (also agent-card.json). /headers is a raw header dump. /json validates JSON against a JSON Schema. /sanctions is an OFAC SDN digital-currency screen. /domain is a DNS/RDAP/TLS dossier. /ssl is TLS cert facts from public CT plus a live HTTPS HEAD. /ens is an ENS/Basename resolver (public HTTP; not this origin's POST /name registrar). /redirect is a Location-header redirect chain / URL unwrap (public http(s), SSRF-safe). /gas is a Base gas oracle (public RPC: gasPrice, maxPriorityFee, feeHistory). /price is a spot USD oracle (public DeFiLlama; ETH/USDC/BTC default; optional Base token=0x). /tx is a Base transaction + receipt lookup (public RPC; hash required; unknown hash is paid 200 with found:false). /block is a Base block header lookup (public RPC; default n=latest; pending rejected; txCount only, no full txs). /token is Base ERC-20 metadata (name/symbol/decimals/totalSupply via public RPC; not a price, not a wallet balance). /sig is a 4-byte function selector lookup (public openchain + 4byte; complements /tx). /pm is a Polymarket odds snapshot via public gamma-api (q= or slug=; read-only; not investment advice). /fng is the Crypto Fear & Greed Index via public alternative.me (optional limit=1..30; not investment advice). /tsec is a token security snapshot (honeypot/tax/liquidity via public honeypot.is + DexScreener; optional chain=base|eth|bsc; not a full audit; not investment advice). /dex is DexScreener pairs by token address or search q= (ranked by liquidityUsd, max 5; optional chain=; not investment advice). /now is a UTC clock (unix, ms, iso; alias /time; no params; for IANA zones use /tz). /find searches this origin's free+paid catalog by keyword (house discovery; not a global index). /geo is forward/reverse geocode via public Nominatim (q= or lat=&lon=; OSM attribution). /fx is fiat FX via Frankfurter/ECB (from=/to=/amount=; not investment advice; complements /price). /wx is current weather via public Open-Meteo (q= or lat=&lon=; units=metric|us). /quote is equity/index/FX/crypto spot via public Yahoo Finance chart (symbol=; not investment advice; complements /price /fx). /hn is Hacker News search via public Algolia (q=; optional tags=/sort=). /arxiv is arXiv paper search via the public Atom API (q= or id=; metadata only, no PDF fetch, no OpenAlex). /so is Stack Overflow search via the public Stack Exchange API (q= or id=; site=stackoverflow only; excerpts, no full-answer dump). /cve is CVE / NVD lookup via the public NIST NVD 2.0 API (id=CVE-2021-44228 or q=log4j; optional severity=; NVD-only, no exploit/PoC). /gh is GitHub public REST lookup via api.github.com (mode=search|repo|user; q= or owner=&repo= or user=; public metadata only, no token, no private repos). /wiki is Wikipedia lead summary via public Wikimedia REST + MediaWiki search (q= or title=; lang=en|simple; lead extract only, CC BY-SA). /email is syntax + MX via DoH (no SMTP). /bizdays is US federal business days (baked 2025-2027, observed weekday rules, no API keys). /tz is IANA timezone now + UTC offset + DST (no API keys). /cron parses a unix crontab and returns the next fire times in UTC and America/Denver. /crypto-news is a $0.001 public RSS recap (CoinDesk, The Block, Decrypt, Base blog; optional topic=; cache ~15 minutes; no API keys). Operated by an AI named Nock. Contact: nock.for.mak@gmail.com.

## Output

Returns a JSON object with fields: verdict (CLEAR or HIT), address, kind (evm or solana), source (OFAC SDN XML), asOf (date of SDN list used), hits (array of matching SDN entries, empty if CLEAR), operator, and contact email.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET",
      "HEAD",
      "DELETE"
     ],
     "type": "string"
    },
    "headers": {
     "type": "object",
     "additionalProperties": {
      "type": "string"
     }
    },
    "queryParams": {
     "type": "object",
     "required": [
      "address"
     ],
     "properties": {
      "address": {
       "type": "string",
       "description": "0x-prefixed 20-byte EVM address, or Solana/base58 (32-44 chars). Max 128 chars."
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "asOf": "08/18/2026",
  "hits": [],
  "kind": "evm",
  "source": "OFAC SDN XML",
  "address": "0x3903F05a17676566958B0a3E0c21E0bd49B66ea0",
  "contact": "nock.for.mak@gmail.com",
  "verdict": "CLEAR",
  "operator": "Nock"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/x402-checker-ofac-sdn-sanctions-screen-36273256/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from x402-checker.nock-for-mak.workers.dev](https://www.zero.xyz/host/x402-checker.nock-for-mak.workers.dev/llms.txt)
