Every paid route takes GET
Buy with a URL alone. Half the paid resources in the x402 market are GETs, and a wallet that can only sign a URL should still be able to buy. Every s2ar route takes GET with query parameters and answers exactly what the POST answers: the same receipt, the same record, the same price. Four tools, four GETs, each quoted keyless first.
Run 2026-10-11 05:26 UTC against api.s2ar.dev 0.1.1 · 4 calls · 1,764 ms · list price $0.02 for a stranger (these ran on the operator's key and cost nothing) · every number on this page re-derived by tools/walkthrough.py before it was written
1. sym/read by GET
curl -s -X GET 'https://api.s2ar.dev/v1/sym/read?repo=BurntSushi%2Fripgrep&ref=14.1.1&file=crates%2Fcore%2Fflags%2Fdefs.rs&symbol=Glob+as+Flag' \
-H "Authorization: Bearer $S2AR_KEY"
| tokens_est | 565 |
|---|---|
| receipt.evidence_hash | sha256:598d5e19ec2bace6… |
the answer, as JSON
{
"tokens_est": 565,
"receipt.evidence_hash": "sha256:598d5e19ec2bace68778add369e74f054ca7dc43c2583e0e1e0c4cbefa58a832"
}
The text field:
impl Glob as Flag (crates/core/flags/defs.rs, lines 2459-2512)
2459 impl Flag for Glob {
2460 fn is_switch(&self) -> bool {
2461 false
2462 }
2463 fn name_short(&self) -> Option<u8> {
… 49 more lines
| re-derived by the generator | |
|---|---|
| ✓ | receipt sha256:598d5e19ec2bace6… re-derived: sha256 over the canonical answer, header and body agree |
2. assert by GET
The checks travel as a JSON string in the query; the verdict is the same signed record the POST issues.
curl -s -X GET 'https://api.s2ar.dev/v1/assert?text=%7B%22status%22%3A+%22ok%22%2C+%22count%22%3A+3%7D&checks=%5B%7B%22check%22%3A+%22json_valid%22%7D%2C+%7B%22check%22%3A+%22required_keys%22%2C+%22keys%22%3A+%5B%22status%22%2C+%22count%22%5D%7D%5D' \
-H "Authorization: Bearer $S2AR_KEY"
PASS
| verdict | pass |
|---|---|
| passed | 2 |
| checks | 2 |
| record_sha256 | d251a92952bfbc61… |
the answer, as JSON
{
"verdict": "pass",
"passed": 2,
"checks": 2,
"record_sha256": "d251a92952bfbc61defcc713ed12651e37020c6d1c4ae194037ce5855c609fdc"
}
| re-derived by the generator | |
|---|---|
| ✓ | receipt sha256:c1499a40953ba1d7… re-derived: sha256 over the canonical answer, header and body agree |
| ✓ | record d251a92952bfbc61… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json) |
| ✓ | as the prose says: verdict = "pass" · passed = 2 |
3. score by GET
curl -s -X GET 'https://api.s2ar.dev/v1/score?form=haiku&text=An+old+silent+pond%0AA+frog+jumps+into+the+pond%E2%80%94%0ASplash%21+Silence+again.' \
-H "Authorization: Bearer $S2AR_KEY"
PASS
| accepted | true |
|---|---|
| composite | 1.0 |
| record_sha256 | 8df2a8705a89d7f8… |
the answer, as JSON
{
"accepted": true,
"composite": 1.0,
"record_sha256": "8df2a8705a89d7f8b0d855deb31c26b484978f73d8832809285a3677c8a4baa8"
}
| re-derived by the generator | |
|---|---|
| ✓ | receipt sha256:2912f5a3cd97a7f0… re-derived: sha256 over the canonical answer, header and body agree |
| ✓ | record 8df2a8705a89d7f8… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json) |
| ✓ | the verdict is accepted: true under policy verse/2, as the prose says |
4. inspect by GET
curl -s -X GET 'https://api.s2ar.dev/v1/x402/inspect?resource=https%3A%2F%2Fapi.s2ar.dev%2Fx402%2Fv1%2Fscore&method=GET' \
-H "Authorization: Bearer $S2AR_KEY"
PASS
| verdict | pass |
|---|---|
| passed | 11 |
| checks | 11 |
| summary.price_usd | 0.005 |
| record_sha256 | 925605529013a145… |
the answer, as JSON
{
"verdict": "pass",
"passed": 11,
"checks": 11,
"summary.price_usd": 0.005,
"record_sha256": "925605529013a145ec34c62b1e7af412a25a6ab671c02543c5074753262231cd"
}
| re-derived by the generator | |
|---|---|
| ✓ | receipt sha256:8dcf4a3ade31a696… re-derived: sha256 over the canonical answer, header and body agree |
| ✓ | record 925605529013a145… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json) |
| ✓ | as the prose says: verdict = "pass" |
A JSON body is still accepted everywhere, and POST merges over the query. The receipt on each answer is re-hashed here; the records are fetched back and checked against the published key.
What this cannot buy
From the signed proceedings (/.well-known/proceedings.json), verbatim:
- placement or routing position
- a different verdict or grade
- buyer data
- amendment access
- a revocation
Failed calls are never charged. Nothing about a caller is kept. The rules: the charter.