EVM token safety check
POST /api/token-safetyIs this EVM token safe to trade? Send POST /api/token-safety with the required field address and pay $0.005 per call over x402 or MPP (there is no free tier). It returns a JSON object with chain, address, verdict, because, blocking and 4 more.
One deterministic call returns a verdict (ok, caution, unsafe) with the named facts behind it: honeypot, can-sell, buy and sell tax, mintable supply, hidden or reclaimable ownership, pausable transfers, blacklist, modifiable slippage, upgradeable proxy, verified source, LP lock share and holder counts. Covers Base, Ethereum, Polygon, Arbitrum, Optimism, BSC, Gnosis and Celo. No model in the path, so the same token always gives the same answer; checks the upstream could not answer are listed as unknown rather than counted as safe. For the cited, researched version see token-risk; for Solana mints see sol-token-safety.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
chain | string | no | One of: base, ethereum, polygon, arbitrum, optimism, bsc, gnosis, celo. |
address | string | yes | Token contract address (0x…). Also accepted as addr, wallet, account. |
Example request
curl -i -X POST https://agent402.tools/api/token-safety \
-H "Content-Type: application/json" \
-d '{"chain":"base","address":"0x940181a94A35A4569E4529A3CDfB74e38FD98631"}'
Without payment this returns HTTP 402 Payment Required with the exact price for token-safety; any x402 v2 or MPP client pays it and retries.
Example response
{
"chain": "base",
"address": "0x940181a94A35A4569E4529A3CDfB74e38FD98631",
"verdict": "caution",
"because": "supply is mintable",
"blocking": [],
"warnings": [
"supply is mintable"
],
"unknown": [],
"facts": {
"honeypot": false,
"cannotSellAll": false,
"cannotBuy": false,
"openSource": true,
"proxy": false,
"mintable": true,
"ownerAddress": null,
"ownerRenounced": null,
"hiddenOwner": false,
"canTakeBackOwnership": false,
"transferPausable": false,
"blacklist": false,
"slippageModifiable": false,
"buyTaxPct": 0,
"sellTaxPct": 0,
"holderCount": 754627,
"lpHolderCount": 175,
"lpLockedPct": 0,
"creatorPct": 0,
"ownerPct": 0,
"fakeToken": null
},
"source": "GoPlus token_security"
}
| Field | Type | Always present | In the example |
|---|---|---|---|
chain | string | yes | base |
address | string | yes | 0x940181a94A35A4569E4529A3CDfB74e38FD98631 |
verdict | string | yes | caution |
because | string | yes | supply is mintable |
blocking | array | yes | 0 items in the example |
warnings | array of string | yes | 1 item in the example |
unknown | array | yes | 0 items in the example |
facts | object | yes | 21 fields: honeypot, cannotSellAll, cannotBuy, openSource, proxy, mintable |
source | string | yes | GoPlus token_security |
From an MCP client
catalog.call {
"slug": "token-safety",
"params": {
"chain": "base",
"address": "0x940181a94A35A4569E4529A3CDfB74e38FD98631"
}
}
The hosted connector at https://agent402.tools/mcp needs a payment for token-safety; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.
Errors and behavior
addressis required. An input the tool rejects returns an HTTP 4xx whose body carrieserror,tool,expected,requiredandexample, so the caller can correct it.- A paid call that ends in any status of 400 or above is not charged over x402, MPP or a prepaid credits key: settlement is cancelled when the tool fails. The exception is a Tempo push credential, a transfer the buyer sent before the call: it settles before the tool runs, so if the tool then fails the payment is recorded as a refund owed to the paying wallet.
- Wallet-only: this tool reaches the network or stored state, so it has no proof-of-work tier. A prepaid card-credits key issued earlier (
Authorization: Bearer a402_...) also pays it. - A
GETorHEADto /api/token-safety returns the same 402 quote, so the price can be read without a body. - An
Idempotency-Keyheader makes a retried paid call replay the first 200 instead of charging again (an answer larger than 1 MB is not replayed).
Paid call (JavaScript agent)
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);
const res = await payFetch("https://agent402.tools/api/token-safety", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
"chain": "base",
"address": "0x940181a94A35A4569E4529A3CDfB74e38FD98631"
}),
});
Related tools
Known-address label lookup
POST /api/address-labelLabel a known EVM address from a curated, committed dataset: major stablecoin + token contracts (the USDC and USDG contr…
Token total supply
GET /api/chain/total-supplyThe circulating total supply of an ERC-20, read from the token contract itself rather than from an aggregator, so it is …
Token price by contract address
GET /api/coin-price-by-contractLive price, market cap, 24h volume and 24h change for ERC-20 / SPL / other chain tokens looked up by CONTRACT ADDRESS on…
NFT owner lookup (ERC-721 ownerOf)
GET /api/erc721-ownerWho owns this NFT? Calls ownerOf(tokenId) on any ERC-721 contract on Ethereum, Base, Polygon, Arbitrum, or Optimism. Com…
Solana token safety check
POST /api/sol-token-safetySafety headline for any Solana SPL token mint: RugCheck risk score (raw + 0-100 normalised), the named risks with level …
ERC-20 token metadata
POST /api/token-metadataResolve an ERC-20 contract address to its on-chain metadata: symbol, decimals, name, and logo URL where available. Use t…