Every paid route takes GET

Buy with a URL alone. Half the paid resources in the x402 market are GETs, and a wallet that can only sign a URL should still be able to buy. Every s2ar route takes GET with query parameters and answers exactly what the POST answers: the same receipt, the same record, the same price. Four tools, four GETs, each quoted keyless first.

4calls answered
4receipts re-hashed
3records verified
$0.02list price for a stranger
1,764ms end to end
pass · 3 records verified

Run 2026-10-11 05:26 UTC against api.s2ar.dev 0.1.1 · 4 calls · 1,764 ms · list price $0.02 for a stranger (these ran on the operator's key and cost nothing) · every number on this page re-derived by tools/walkthrough.py before it was written

1. sym/read by GET

curl -s -X GET 'https://api.s2ar.dev/v1/sym/read?repo=BurntSushi%2Fripgrep&ref=14.1.1&file=crates%2Fcore%2Fflags%2Fdefs.rs&symbol=Glob+as+Flag' \
  -H "Authorization: Bearer $S2AR_KEY"

→ HTTP 200 · 224 ms · list price $0.005 · receipt sha256:598d5e19ec2bace6…

tokens_est565
receipt.evidence_hashsha256:598d5e19ec2bace6…
the answer, as JSON
{
  "tokens_est": 565,
  "receipt.evidence_hash": "sha256:598d5e19ec2bace68778add369e74f054ca7dc43c2583e0e1e0c4cbefa58a832"
}

The text field:

impl Glob as Flag (crates/core/flags/defs.rs, lines 2459-2512)
 2459	impl Flag for Glob {
 2460	    fn is_switch(&self) -> bool {
 2461	        false
 2462	    }
 2463	    fn name_short(&self) -> Option<u8> {
… 49 more lines
re-derived by the generator
✓receipt sha256:598d5e19ec2bace6… re-derived: sha256 over the canonical answer, header and body agree

2. assert by GET

The checks travel as a JSON string in the query; the verdict is the same signed record the POST issues.

curl -s -X GET 'https://api.s2ar.dev/v1/assert?text=%7B%22status%22%3A+%22ok%22%2C+%22count%22%3A+3%7D&checks=%5B%7B%22check%22%3A+%22json_valid%22%7D%2C+%7B%22check%22%3A+%22required_keys%22%2C+%22keys%22%3A+%5B%22status%22%2C+%22count%22%5D%7D%5D' \
  -H "Authorization: Bearer $S2AR_KEY"

PASS → HTTP 200 · 148 ms · list price $0.005 · receipt sha256:c1499a40953ba1d7…

verdictpass
passed2
checks2
record_sha256d251a92952bfbc61…
the answer, as JSON
{
  "verdict": "pass",
  "passed": 2,
  "checks": 2,
  "record_sha256": "d251a92952bfbc61defcc713ed12651e37020c6d1c4ae194037ce5855c609fdc"
}

Assay badge for record d251a92952bfbc61

re-derived by the generator
✓receipt sha256:c1499a40953ba1d7… re-derived: sha256 over the canonical answer, header and body agree
✓record d251a92952bfbc61… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json)
✓as the prose says: verdict = "pass" · passed = 2

3. score by GET

curl -s -X GET 'https://api.s2ar.dev/v1/score?form=haiku&text=An+old+silent+pond%0AA+frog+jumps+into+the+pond%E2%80%94%0ASplash%21+Silence+again.' \
  -H "Authorization: Bearer $S2AR_KEY"

PASS → HTTP 200 · 677 ms · list price $0.005 · receipt sha256:2912f5a3cd97a7f0…

acceptedtrue
composite1.0
record_sha2568df2a8705a89d7f8…
the answer, as JSON
{
  "accepted": true,
  "composite": 1.0,
  "record_sha256": "8df2a8705a89d7f8b0d855deb31c26b484978f73d8832809285a3677c8a4baa8"
}

Assay badge for record 8df2a8705a89d7f8

re-derived by the generator
✓receipt sha256:2912f5a3cd97a7f0… re-derived: sha256 over the canonical answer, header and body agree
✓record 8df2a8705a89d7f8… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json)
✓the verdict is accepted: true under policy verse/2, as the prose says

4. inspect by GET

curl -s -X GET 'https://api.s2ar.dev/v1/x402/inspect?resource=https%3A%2F%2Fapi.s2ar.dev%2Fx402%2Fv1%2Fscore&method=GET' \
  -H "Authorization: Bearer $S2AR_KEY"

PASS → HTTP 200 · 715 ms · list price $0.005 · receipt sha256:8dcf4a3ade31a696…

verdictpass
passed11
checks11
summary.price_usd0.005
record_sha256925605529013a145…
the answer, as JSON
{
  "verdict": "pass",
  "passed": 11,
  "checks": 11,
  "summary.price_usd": 0.005,
  "record_sha256": "925605529013a145ec34c62b1e7af412a25a6ab671c02543c5074753262231cd"
}

Assay badge for record 925605529013a145

re-derived by the generator
✓receipt sha256:8dcf4a3ade31a696… re-derived: sha256 over the canonical answer, header and body agree
✓record 925605529013a145… fetched back from /v1/verify: sealed, signed, and signed by assay-1 (the key at /.well-known/assay.json)
✓as the prose says: verdict = "pass"

A JSON body is still accepted everywhere, and POST merges over the query. The receipt on each answer is re-hashed here; the records are fetched back and checked against the published key.

What this cannot buy

From the signed proceedings (/.well-known/proceedings.json), verbatim:

Failed calls are never charged. Nothing about a caller is kept. The rules: the charter.