An agent can generate an opinion cheaply. It cannot prove that a specific artifact existed at a specific moment, signed by a key anyone can check. Authen sells that — one HTTP call, one micropayment, no account.
POST bytes, pay $0.05 over x402, and receive a signed timestamped attestation you can verify offline, forever, without us. Anyone else can verify it too, for free. There is no login, no API key and no subscription: the payment is the authorization.
“This node observed bytes with this SHA-256 digest at this time.”
Not authorship. Not ownership. Not that the content is true, and not that it did not exist earlier. The wording is deliberately narrow — an attestation that overpromises is worse than none, because the first counterexample discredits every one ever issued.
The signing key is public. Fetch it and check this node is who it says it is:
curl https://authen.hvym.link/api/v1/identity
Verification is free and always will be. An attestation nobody can afford to check is worth nothing:
curl -X POST https://authen.hvym.link/api/v1/verify \
-H 'Content-Type: application/json' \
-d '{"attestation":"<b64url-sig>.<b64url-payload>"}'
| Route | Price | What it does |
|---|---|---|
| POST /api/v1/notarize | $0.05 | Hash any bytes, up to 32 MiB, and return a signed Ed25519 attestation. |
| POST /api/v1/c2pa/sign | $0.15 | Embed C2PA Content Credentials into an image and return it, manifest signed, pixels untouched. |
| POST /api/v1/verify | free | Check an attestation is internally consistent and correctly signed. |
| POST /api/v1/c2pa/verify | free | Read an embedded C2PA manifest and report its validation state. |
| GET /api/v1/identity | free | This node's signing key, as an Ed25519 hex key and as Algorand and Stellar addresses. |
Paid routes answer 402 with an x402 challenge in the
PAYMENT-REQUIRED header. Any x402 v2 client on Algorand mainnet
can settle it; the request header is PAYMENT-SIGNATURE. Nothing
you send is stored — bytes are hashed and discarded inside the request.
/api/v1/c2pa/sign embeds a signed
C2PA manifest and carries an Authen
attestation inside it, so a provenance claim travels with the file rather
than beside it. Signing is pixel-lossless: the container is rewritten to hold
the manifest, the decoded image is bit-identical.
Worth stating plainly: this node's certificate authority is not on the C2PA conformance trust list. Conformant validators will report the signature as cryptographically valid and the signer as untrusted. That is the honest status of every self-hosted C2PA signer today.
Any x402 v2 client on Algorand mainnet works. If your agent does not have a wallet yet, Obolus is an MCP server that gives it a disposable one — no human provisioning anything:
uv tool install obolus
claude mcp add obolus -e OBOLUS_NETWORK=mainnet -- obolus-mcp
On PyPI as obolus.
Note the network: Authen settles on Algorand mainnet only, and
Obolus starts on testnet unless told otherwise — a testnet wallet will not pay
these routes. Fund it before the first call; a new wallet holds nothing. It
answers 402s and never serves them, so Authen is one resource among any it can
pay, and nothing about either is coupled to the other.