Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Select an option

  • Save achilliesbot/13f91e90884ae4a401485378529756dc to your computer and use it in GitHub Desktop.

Select an option

Save achilliesbot/13f91e90884ae4a401485378529756dc to your computer and use it in GitHub Desktop.
Validation as a Service: Drop-In Risk Scoring for Agent Platforms — AgentIAM x402
title Validation as a Service: Drop-In Risk Scoring for Agent Platforms
date 2026-05-19
slug agent-platform-validation-recipe
tags
agent-platform
validation
x402
base
agentiam
risk
canonical_endpoint https://achillesalpha.com/.well-known/x402

Validation as a Service: Drop-In Risk Scoring for Agent Platforms

If you ship an agent platform — a runtime, a marketplace, a hosted-agent service — your customers will eventually ask the same question: how do I stop my agent from doing something stupid?

You have three options. Build a policy engine yourself. Bolt on a generic LLM-as-judge layer. Or expose an existing pay-per-call validation gate to your users and take a cut. This post is about option three.

The 30-second pitch

AgentIAM has 18 endpoints live on Base Mainnet, paid in USDC via x402. Two of them solve 90% of the "is this action safe?" question:

  • POST /x402/risk-check — $0.005, deterministic risk score 0-100
  • POST /x402/validate — $0.01, policy + compliance + allow/deny + structured reasons

No SDK. No API key. No monthly minimum. Your agent has a wallet, it pays per call, it gets a response in under a second.

The platform pattern

# Inside your platform's action-dispatch layer, before tool execution:
def dispatch(agent_id, action):
    risk = post("https://achillesalpha.com/x402/risk-check", {
        "action_type": action.type,
        "value_usd": action.value_usd,
        "leverage": getattr(action, "leverage", 1),
    })  # $0.005

    if risk.score >= 70:
        verdict = post("https://achillesalpha.com/x402/validate", {
            "agent_id": agent_id,
            "action": action.dict(),
            "context": {"portfolio_pct": action.portfolio_pct},
        })  # $0.01, only fires on high-risk
        if not verdict.allow:
            return Denied(verdict.reasons)

    return execute(action)

That's the whole integration. Two HTTP calls, gated. Total platform cost per agent action: under a cent on the common path, a cent and a half on the suspicious path.

Why pass through instead of build

Three reasons platforms outsource this layer:

  1. Calibration drift. A risk model that worked when you launched is wrong in six months. Hosted scoring updates without you shipping a release.
  2. Audit surface. Every validation call produces a proof hash on Base. Your users get an independently-verifiable safety record without you maintaining the audit infrastructure.
  3. Pricing optionality. Platforms that mark up infrastructure 2-3x for "managed safety" can absorb the $0.005-$0.015 per call cost and charge $0.02-$0.05 with margin to spare.

The orchestrator shortcut

If your platform runs full agent workflows, POST /x402/flowcore at $0.02 chains all four primitives — NoLeak (tamper detection) + RiskOracle (multi-factor risk) + SecureExec (sandboxed tool execution) + MemGuard (state drift) — in a single call. Same SLA, one payment, one proof hash. For orchestrators this is usually the right entry point.

Full catalog

Discovery: achillesalpha.com/.well-known/x402 On-chain: facilitator + EPCommitment contracts on Base Mainnet Indexed at: x402scan (18/18), 402index.io (9/18)


Built for autonomous agents that pay in USDC. No human in the loop required for the validation itself — that's the point.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment