# Trust History Oracle 0.1.1

Base Sepolia testnet alpha (eip155:84532). Mainnet is disabled. Test USDC only; historical evidence is not a safety guarantee.

Use cases: npm dependency-history screening; package instructions that predate registration; exact-URL public-web history; web provenance; agent supply-chain security.

## Free resources

- https://trust-history-oracle.delicate-yellowhorn.workers.dev/health
- https://trust-history-oracle.delicate-yellowhorn.workers.dev/openapi.json
- https://trust-history-oracle.delicate-yellowhorn.workers.dev/llms.txt
- https://trust-history-oracle.delicate-yellowhorn.workers.dev/developers.md
- https://trust-history-oracle.delicate-yellowhorn.workers.dev/llms-full.txt
- https://trust-history-oracle.delicate-yellowhorn.workers.dev/.well-known/ard.json
- https://trust-history-oracle.delicate-yellowhorn.workers.dev/.well-known/ai-catalog.json
- https://trust-history-oracle.delicate-yellowhorn.workers.dev/.well-known/api-catalog
- https://trust-history-oracle.delicate-yellowhorn.workers.dev/sitemap.xml

## Paid x402 resources

- GET https://trust-history-oracle.delicate-yellowhorn.workers.dev/v1/package?ecosystem=npm&name=PACKAGE — $0.001 test USDC. Screen npm dependency history for agent supply-chain security using registry creation and publication evidence.
- GET https://trust-history-oracle.delicate-yellowhorn.workers.dev/v1/url-history?url=URL — $0.002 test USDC. Inspect bounded exact-URL public-web history and web provenance using Common Crawl evidence.
- GET https://trust-history-oracle.delicate-yellowhorn.workers.dev/v1/chronology?ecosystem=npm&name=PACKAGE&instruction_url=URL — $0.01 test USDC. Compare archived package instructions with registration time to detect chronology anomalies for agent supply-chain security.

An unpaid request returns HTTP 402 with a base64 JSON PAYMENT-REQUIRED header and Bazaar metadata. Inspect this challenge before deciding whether to pay. Discovery and health require no payment. Reports identify sources, coverage, unknowns, and limitations.

## Evidence and limitations

Package history uses npm registry evidence. Exact URLs use bounded Common Crawl searches; an absent result does not prove a URL never existed. Chronology compares archived references with npm registration and does not establish malicious intent. The oracle is not an antivirus product.

## Completion measurement

Only a successful HTTP 200 settlement receipt is measured. The completion record stores public transaction hash, network, route, and timestamp; repeated transactions count once. No payer, IP, query, package name, URL, user agent, signature, or response body is stored in completion records.
