Skill: User onboarding
POST /api/skill/user-onboardingTake a signup form submission and run the full onboarding workup deterministically: validate the email, score the chosen password, mint a stable internal ID, derive a URL-safe handle from the display name, generate a recovery / API secret, hash the password for storage, and verify the 2FA setup code. Send POST /api/skill/user-onboarding with the required fields email, password, displayName, totpSecret and 1 more and pay $0.008 per call over x402 or MPP (there is no free tier). It returns a JSON object with pack, args, steps and summary.
One pass, every step a pure-CPU call. User onboarding skill pack: one x402 payment runs 7 underlying tools (email-validate, password-strength, uuid, slugify, password, hash, totp); partial-success per step.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
email | string | yes | User-supplied email address |
password | string | yes | User-chosen password (plaintext, will be scored then hashed; never logged) |
displayName | string | yes | User-supplied display name (will be slugified into a URL handle) |
totpSecret | string | yes | Base32 TOTP secret generated during 2FA enrollment (server-side state) |
totpCode | string | yes | 6-digit code the user typed in to confirm their authenticator app is wired up |
Example request
curl -i -X POST https://agent402.tools/api/skill/user-onboarding \
-H "Content-Type: application/json" \
-d '{"email":"ada@example.com","password":"S0meStrongPassw0rd!","displayName":"Ada Lovelace","totpSecret":"JBSWY3DPEHPK3PXP","totpCode":"492039"}'
Without payment this returns HTTP 402 Payment Required with the exact price for skill-user-onboarding; any x402 v2 or MPP client pays it and retries.
Example response
{
"pack": "user-onboarding",
"args": {
"email": "ada@example.com",
"password": "S0meStrongPassw0rd!",
"displayName": "Ada Lovelace",
"totpSecret": "JBSWY3DPEHPK3PXP",
"totpCode": "492039"
},
"steps": [
{
"slug": "email-validate",
"ok": true,
"result": {}
},
{
"slug": "password-strength",
"ok": true,
"result": {}
},
{
"slug": "uuid",
"ok": true,
"result": {}
},
{
"slug": "slugify",
"ok": true,
"result": {}
},
{
"slug": "password",
"ok": true,
"result": {}
},
{
"slug": "hash",
"ok": true,
"result": {}
},
{
"slug": "totp",
"ok": true,
"result": {}
}
],
"summary": "7/7 steps succeeded"
}
| Field | Type | Always present | In the example |
|---|---|---|---|
pack | string | yes | user-onboarding |
args | object | yes | 5 fields: email, password, displayName, totpSecret, totpCode |
steps | array of objects | yes | 7 items in the example |
summary | string | yes | 7/7 steps succeeded |
From an MCP client
catalog.call {
"slug": "skill-user-onboarding",
"params": {
"email": "ada@example.com",
"password": "S0meStrongPassw0rd!",
"displayName": "Ada Lovelace",
"totpSecret": "JBSWY3DPEHPK3PXP",
"totpCode": "492039"
}
}
The hosted connector at https://agent402.tools/mcp needs a payment for skill-user-onboarding; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.
Errors and behavior
- Arguments left out fall back to the pack's own defaults. Each step reports on its own; the call succeeds when at least one step does, and a run where every step fails is refused (400 when the input caused it, 502 otherwise).
- A paid call that ends in any status of 400 or above is not charged over x402, MPP or a prepaid credits key: settlement is cancelled when the tool fails. The exception is a Tempo push credential, a transfer the buyer sent before the call: it settles before the tool runs, so if the tool then fails the payment is recorded as a refund owed to the paying wallet.
- Wallet-only: this tool reaches the network or stored state, so it has no proof-of-work tier. A prepaid card-credits key issued earlier (
Authorization: Bearer a402_...) also pays it. - A
GETorHEADto /api/skill/user-onboarding returns the same 402 quote, so the price can be read without a body. - An
Idempotency-Keyheader makes a retried paid call replay the first 200 instead of charging again (an answer larger than 1 MB is not replayed).
Paid call (JavaScript agent)
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);
const res = await payFetch("https://agent402.tools/api/skill/user-onboarding", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
"email": "ada@example.com",
"password": "S0meStrongPassw0rd!",
"displayName": "Ada Lovelace",
"totpSecret": "JBSWY3DPEHPK3PXP",
"totpCode": "492039"
}),
});
Related tools
Skill: Convert anything to markdown
POST /api/skill/any-to-markdownConvert anything at a URL - HTML, PDF, or an image - to clean markdown. The 'I have a URL but it might be any content-ty…
Skill: API health check
POST /api/skill/api-healthIs this API endpoint healthy? Liveness check, response headers, and TLS certificate status in one pass. API health check…
Skill: API investigation
POST /api/skill/api-investigationPoint at an unknown API endpoint and figure out how to use it: auth scheme, content type, version, rate limits, OpenAPI/…
Skill: Article digest
POST /api/skill/article-digestQuick research brief on any topic - web search results plus an AI-generated answer in one pass. Article digest skill pac…
Skill: Brand protection
POST /api/skill/brand-protectionIs this domain legitimate? WHOIS age, DNS resolution, scam/phishing search results, and HTTP headers for a quick trust a…
Skill: Cheapest rail right now
POST /api/skill/cheapest-railWhere should an agent transact this minute? Live gas on Ethereum + every major L2 side by side, Base gas tiers, a fee es…