# POST /package/audit/lockfile: $0.05 per call

Audit a whole lockfile for known vulnerabilities and malware in one call: package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt, poetry.lock, uv.lock, Pipfile.lock, Cargo.lock or go.sum, up to 1,000 exact versions checked against OSV.dev, with affected packages, severity and versions to upgrade to. POST {url} (raw file) or {content, filename}.

- **Price:** $0.05 in USDC, the same on Base, Solana, Polygon, Arbitrum. Failed calls are never charged.
- **Free trial:** no, paid only (it uses a paid AI model or data source, or costs more than the trial covers). Other ways to pay: x402 or [prepaid credits](/credits).
- **Tier:** deep
- **Answers cached for:** 1 hour(s)
- **Data sources:** OSV.dev (free); The lockfile you point to
- **Lane:** AI coding agents ([OpenAPI](/openapi/coding.json))
- **Live health:** [status page](/status)

## Free sample

See an answer for the demo input first, free (no payment, 10 a minute): [https://aayatai.com/sample/package-audit-lockfile](/sample/package-audit-lockfile). It is a stored real answer when we have one, otherwise an example marked `"kind": "illustrative"`.

```bash
curl "https://aayatai.com/sample/package-audit-lockfile"
```

## 1. See the price (free)

Call it without paying: you get `402 Payment Required` and a `PAYMENT-REQUIRED` header with the exact price and where to pay.

```bash
curl -i -X POST https://aayatai.com/package/audit/lockfile -H "content-type: application/json" -d '{"content":"requests==2.19.0\nurllib3==1.26.18\n","filename":"requirements.txt"}'
```

## 2. Pay and call (TypeScript)

```bash
npm install @x402/fetch @x402/evm viem
```

```ts
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

// A wallet used only by your agent, holding a little USDC on Base.
const account = privateKeyToAccount(process.env.WALLET_PRIVATE_KEY as `0x${string}`);
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});

const res = await pay("https://aayatai.com/package/audit/lockfile", {
  method: "POST",
  headers: { "content-type": "application/json" },
  body: JSON.stringify({"content":"requests==2.19.0\nurllib3==1.26.18\n","filename":"requirements.txt"}),
});
console.log(await res.json());
```

## 3. Or as an MCP tool

```ts
// MCP server: https://aayatai.com/mcp (Streamable HTTP). With the x402 MCP client (see /start):
const result = await client.callTool("package-audit-lockfile", {"content":"requests==2.19.0\nurllib3==1.26.18\n","filename":"requirements.txt"});
```

## Inputs

- `url` (string): Raw lockfile address, e.g. https://raw.githubusercontent.com/owner/repo/main/package-lock.json.
- `content` (string): Or: the lockfile text itself (up to 60 KB; use url for bigger files).
- `filename` (string): The file's name when sending content, e.g. poetry.lock (helps detect the format).
- `format` (string; one of `package-lock`, `yarn`, `pnpm`, `requirements`, `poetry`, `uv`, `pipfile`, `cargo`, `gosum`): Force the format if detection fails.

Bad inputs are rejected with HTTP 400 before any payment is asked for.

## Example answer

```json
{
  "format": "requirements",
  "ecosystem": "pypi",
  "source": "content",
  "found": 2,
  "checked": 2,
  "truncated": false,
  "verdict": "fix",
  "vulnerablePackages": 1,
  "counts": {
    "critical": 0,
    "high": 1,
    "moderate": 2,
    "low": 0,
    "unknown": 0
  },
  "packages": [
    {
      "name": "requests",
      "version": "2.19.0",
      "vulnerabilities": [
        {
          "id": "GHSA-x84v-xcm2-53pg",
          "aliases": [
            "CVE-2018-18074"
          ],
          "summary": "Insufficiently Protected Credentials in Requests",
          "severity": "high",
          "fixedIn": [
            "2.20.0"
          ],
          "published": "2018-10-29T19:06:39Z",
          "url": "https://osv.dev/vulnerability/GHSA-x84v-xcm2-53pg"
        }
      ],
      "upgradeTo": "2.32.4"
    }
  ],
  "cleanCount": 1,
  "detailsTruncated": false,
  "checkedAt": "2026-09-28T12:00:00.000Z"
}
```

## Related

- [GET /docs/find](/services/docs-find) ($0.003): Find the AI-ready docs for any library or API: checks the project's docs site (from its npm, PyPI, crates or Go metadata) or any company domain (docs., develope
- [GET /docs/lib](/services/docs-lib) ($0.005): Up-to-date docs for any npm, PyPI, crates or Go library, trimmed for a coding agent's context: finds the project's own llms.txt and docs pages (or the latest re
- [POST /docs/answer](/services/docs-answer) ($0.02): Ask a coding question about any npm, PyPI, crates or Go library and get an answer written only from its current docs (project llms.txt, docs pages or latest REA
- [GET /openapi](/services/openapi) ($0.005): Understand any public API fast: give its OpenAPI/Swagger spec URL, its docs or base URL, or a name from the APIs.guru directory (?api=stripe.com); we find the s
- [GET /library/research](/services/library-research) ($0.10): Premium research report on a library or API for coding agents: reads its current docs for your goal, checks version, safety and repository health, gathers what 
- [GET /package/check](/services/package-check) ($0.005): Should a coding agent install this package?
- [GET /dependency/verdict](/services/dependency-verdict) ($0.03): "Should I use this dependency?" in one call for npm, PyPI, crates or Go: full package safety check (vulnerabilities, malware, typosquats, deprecation, licence, 
- [GET /dependency/report](/services/dependency-report) ($0.08): Premium "should I use this dependency?" report: package safety (vulnerabilities, malware, typosquats, deprecation), GitHub repository health, licence compatibil

New here? [Getting started in 60 seconds](/start). All services: [Aayat AI](/).