# POST /package/audit: $0.02 per call

Audit a whole dependency list in one call: up to 200 exact npm, PyPI, crates or Go package versions checked against OSV.dev for known vulnerabilities and malware. Returns which packages are affected, severity, fixed versions and an overall verdict. POST {ecosystem, packages:["name@version"]} or {ecosystem:"pypi", requirements:"requests==2.31.0\n..."}.

- **Price:** $0.02 in USDC, the same on Base, Solana, Polygon, Arbitrum. Failed calls are never charged.
- **Free trial:** yes, 20 free calls a day from Claude, Cursor or any MCP client ([set-up](/mcp/setup)).
- **Answers cached for:** 1 hour(s)
- **Data sources:** OSV.dev (free)
- **Lane:** AI coding agents ([OpenAPI](/openapi/coding.json))
- **Live health:** [status page](/status)

## Free sample

See an answer for the demo input first, free (no payment, 10 a minute): [https://aayatai.com/sample/package-audit](/sample/package-audit). It is a stored real answer when we have one, otherwise an example marked `"kind": "illustrative"`.

```bash
curl "https://aayatai.com/sample/package-audit"
```

## 1. See the price (free)

Call it without paying: you get `402 Payment Required` and a `PAYMENT-REQUIRED` header with the exact price and where to pay.

```bash
curl -i -X POST https://aayatai.com/package/audit -H "content-type: application/json" -d '{"ecosystem":"npm","packages":["lodash@4.17.15","express@4.21.2"]}'
```

## 2. Pay and call (TypeScript)

```bash
npm install @x402/fetch @x402/evm viem
```

```ts
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

// A wallet used only by your agent, holding a little USDC on Base.
const account = privateKeyToAccount(process.env.WALLET_PRIVATE_KEY as `0x${string}`);
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});

const res = await pay("https://aayatai.com/package/audit", {
  method: "POST",
  headers: { "content-type": "application/json" },
  body: JSON.stringify({"ecosystem":"npm","packages":["lodash@4.17.15","express@4.21.2"]}),
});
console.log(await res.json());
```

## 3. Or as an MCP tool

```ts
// MCP server: https://aayatai.com/mcp (Streamable HTTP). With the x402 MCP client (see /start):
const result = await client.callTool("package-audit", {"ecosystem":"npm","packages":["lodash@4.17.15","express@4.21.2"]});
```

## Inputs

- `ecosystem` (string; one of `npm`, `pypi`, `crates`, `go`; default `npm`): Package ecosystem: npm, pypi, crates (Rust) or go (Go modules).
- `packages` (array): Exact versions, e.g. ["express@4.17.1", "lodash@4.17.15"].
- `requirements` (string): Alternative: requirements.txt-style text, one name==version (or name@version) per line.

Bad inputs are rejected with HTTP 400 before any payment is asked for.

## Example answer

```json
{
  "ecosystem": "npm",
  "checked": 2,
  "verdict": "fix",
  "vulnerablePackages": 1,
  "counts": {
    "critical": 1,
    "high": 3,
    "moderate": 2,
    "low": 0,
    "unknown": 0
  },
  "packages": [
    {
      "name": "lodash",
      "version": "4.17.15",
      "vulnerabilities": [
        {
          "id": "GHSA-p6mc-m468-83gw",
          "aliases": [
            "CVE-2020-8203"
          ],
          "summary": "Prototype Pollution in lodash",
          "severity": "high",
          "fixedIn": [
            "4.17.19"
          ],
          "published": "2020-07-15T19:15:48Z",
          "url": "https://osv.dev/vulnerability/GHSA-p6mc-m468-83gw"
        }
      ],
      "upgradeTo": "4.17.21"
    }
  ],
  "clean": [
    "express@4.21.2"
  ],
  "detailsTruncated": false,
  "source": "OSV.dev",
  "checkedAt": "2026-09-28T12:00:00.000Z"
}
```

## Related

- [GET /docs/find](/services/docs-find) ($0.003): Find the AI-ready docs for any library or API: checks the project's docs site (from its npm, PyPI, crates or Go metadata) or any company domain (docs., develope
- [GET /docs/lib](/services/docs-lib) ($0.005): Up-to-date docs for any npm, PyPI, crates or Go library, trimmed for a coding agent's context: finds the project's own llms.txt and docs pages (or the latest re
- [POST /docs/answer](/services/docs-answer) ($0.02): Ask a coding question about any npm, PyPI, crates or Go library and get an answer written only from its current docs (project llms.txt, docs pages or latest REA
- [GET /openapi](/services/openapi) ($0.005): Understand any public API fast: give its OpenAPI/Swagger spec URL, its docs or base URL, or a name from the APIs.guru directory (?api=stripe.com); we find the s
- [GET /library/research](/services/library-research) ($0.10): Premium research report on a library or API for coding agents: reads its current docs for your goal, checks version, safety and repository health, gathers what 
- [GET /package/check](/services/package-check) ($0.005): Should a coding agent install this package?
- [GET /dependency/verdict](/services/dependency-verdict) ($0.03): "Should I use this dependency?" in one call for npm, PyPI, crates or Go: full package safety check (vulnerabilities, malware, typosquats, deprecation, licence, 
- [GET /dependency/report](/services/dependency-report) ($0.08): Premium "should I use this dependency?" report: package safety (vulnerabilities, malware, typosquats, deprecation), GitHub repository health, licence compatibil

New here? [Getting started in 60 seconds](/start). All services: [Aayat AI](/).