# Services from sicher.halowerk.com on Zero

> sicher.halowerk.com serves 10 paid API services for AI agents, indexed by Zero. Each is callable per call with payment handled by Zero.

Canonical page: https://www.zero.xyz/host/sicher.halowerk.com
Live health (JSON, refreshed every minute): https://www.zero.xyz/host/sicher.halowerk.com/health.json

## Services

- [Sicher JWT Verify](https://www.zero.xyz/c/sicher-jwt-verify-c61bb30a/llms.txt): $0.002/call via x402. Verifies a JWT's structure, claims (expiry, nbf, iat, issuer, audience, lifetime), and cryptographic signature (HMAC, RSA, RSA-PSS, ECDSA) against a shared secret, PEM key, or JWKS endpoint.
- [Sicher SBOM Generator](https://www.zero.xyz/c/sicher-sbom-generator-ce83f509/llms.txt): $0.005/call via x402. Parses dependency files (package-lock.json, package.json, requirements.txt, go.mod, Cargo.lock) and generates a Software Bill of Materials in CycloneDX 1.5 or SPDX 2.3 format with package URLs per component.
- [Sicher Log Chain Verifier](https://www.zero.xyz/c/sicher-log-chain-verifier-5b7a5b90/llms.txt): $0.005/call via x402. Verifies the cryptographic integrity of an ordered audit log chain by recomputing SHA-256 record hashes and validating hash linkage, with optional Merkle root verification.
- [Sigstore Rekor Provenance Verifier](https://www.zero.xyz/c/sigstore-rekor-provenance-verifier-a513873f/llms.txt): $0.005/call via x402. Searches the Sigstore Rekor transparency log for entries matching an artifact hash and returns signing identity, inclusion time, source repository, and workflow provenance for all matching entries.
- [Sicher Hash Reputation Lookup](https://www.zero.xyz/c/sicher-hash-reputation-lookup-f8bc4e8d/llms.txt): $0.005/call via x402. Queries abuse.ch MalwareBazaar, ThreatFox, and URLhaus to determine whether a file hash (MD5, SHA-1, or SHA-256) is associated with known malware, returning a consolidated known-malicious or unknown verdict.
- [Sicher Webhook Signature Verifier](https://www.zero.xyz/c/sicher-webhook-signature-verifier-74a69c9d/llms.txt): $0.002/call via x402. Verifies a webhook payload signature against the canonical signing scheme of a named provider, using constant-time comparison, and returns the reconstructed signed string for debugging mismatches.
- [Sicher CVE Check — Package Vulnerability Scanner](https://www.zero.xyz/c/sicher-cve-check-package-vulnerability-scanner-deed6825/llms.txt): $0.005/call via x402. Queries OSV.dev for vulnerabilities across multiple package ecosystems and returns CVE identifiers, severity, summaries, and the minimum fixed version for each affected package.
- [sicher.halowerk.com Container Image Inspector](https://www.zero.xyz/c/sicher-halowerk-com-container-image-inspector-d2b36c86/llms.txt): $0.005/call via x402. Fetches and parses the manifest, config, and layer metadata of an OCI or Docker container image directly from its registry without pulling layers or running the image.
- [sicher.halowerk.com License Check](https://www.zero.xyz/c/sicher-halowerk-com-license-check-154add3c/llms.txt): $0.002/call via x402. Looks up the declared open-source licence for each submitted package via deps.dev and categorises it by copyleft obligation level relevant to commercial and SaaS distribution.
- [sicher.halowerk.com TLS Chain Inspector](https://www.zero.xyz/c/sicher-halowerk-com-tls-chain-inspector-4cc7e2a2/llms.txt): $0.002/call via x402. Opens a TLS connection to a hostname and returns the full certificate chain with detailed per-cert metadata plus health signals like expiry countdown, coverage check, self-signed flags, and weak algorithm detection.

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

- [Zero catalog index](https://www.zero.xyz/llms.txt)
