x402 · Algorand mainnet · live
Authen

Authen

An agent can generate an opinion cheaply. It cannot prove that a specific artifact existed at a specific moment, signed by a key anyone can check. Authen sells that — one HTTP call, one micropayment, no account.

POST bytes, pay $0.05 over x402, and receive a signed timestamped attestation you can verify offline, forever, without us. Anyone else can verify it too, for free. There is no login, no API key and no subscription: the payment is the authorization.

What an attestation actually claims

“This node observed bytes with this SHA-256 digest at this time.”

Not authorship. Not ownership. Not that the content is true, and not that it did not exist earlier. The wording is deliberately narrow — an attestation that overpromises is worse than none, because the first counterexample discredits every one ever issued.

Try it — no payment, no signup

The signing key is public. Fetch it and check this node is who it says it is:

curl https://authen.hvym.link/api/v1/identity

Verification is free and always will be. An attestation nobody can afford to check is worth nothing:

curl -X POST https://authen.hvym.link/api/v1/verify \
     -H 'Content-Type: application/json' \
     -d '{"attestation":"<b64url-sig>.<b64url-payload>"}'

Endpoints

RoutePriceWhat it does
POST /api/v1/notarize $0.05 Hash any bytes, up to 32 MiB, and return a signed Ed25519 attestation.
POST /api/v1/c2pa/sign $0.15 Embed C2PA Content Credentials into an image and return it, manifest signed, pixels untouched.
POST /api/v1/verify free Check an attestation is internally consistent and correctly signed.
POST /api/v1/c2pa/verify free Read an embedded C2PA manifest and report its validation state.
GET /api/v1/identity free This node's signing key, as an Ed25519 hex key and as Algorand and Stellar addresses.

Paid routes answer 402 with an x402 challenge in the PAYMENT-REQUIRED header. Any x402 v2 client on Algorand mainnet can settle it; the request header is PAYMENT-SIGNATURE. Nothing you send is stored — bytes are hashed and discarded inside the request.

Content Credentials

/api/v1/c2pa/sign embeds a signed C2PA manifest and carries an Authen attestation inside it, so a provenance claim travels with the file rather than beside it. Signing is pixel-lossless: the container is rewritten to hold the manifest, the decoded image is bit-identical.

Worth stating plainly: this node's certificate authority is not on the C2PA conformance trust list. Conformant validators will report the signature as cryptographically valid and the signer as untrusted. That is the honest status of every self-hosted C2PA signer today.

Paying for it

Any x402 v2 client on Algorand mainnet works. If your agent does not have a wallet yet, Obolus is an MCP server that gives it a disposable one — no human provisioning anything:

uv tool install obolus
claude mcp add obolus -e OBOLUS_NETWORK=mainnet -- obolus-mcp

On PyPI as obolus. Note the network: Authen settles on Algorand mainnet only, and Obolus starts on testnet unless told otherwise — a testnet wallet will not pay these routes. Fund it before the first call; a new wallet holds nothing. It answers 402s and never serves them, so Authen is one resource among any it can pay, and nothing about either is coupled to the other.