Skip to main content

Installation

Quick start

API reference

Constructor

Set userAgent to prepend your app’s identifier to outbound requests so AgentScore support can trace traffic back to you:

client.assess(address, options?)

On-the-fly trust assessment with policy evaluation. Available on every tier, gated by monthly quota.
Returns AssessResponse with decision, decision_reasons, and identity_method ("wallet" or "operator_token").

Server-side signer-match + OFAC SDN screening

Pass signer: { address, network } to opt into server-side wallet-signer-match and OFAC SDN wallet-address screening in a single round trip:
Set signer.address: null for rails with no wallet signer (Stripe SPT, card); the response’s signer_match.kind will be wallet_auth_requires_wallet_signing. Wallet-OFAC SDN enforcement on the signer block is unconditional whenever a signer is supplied; no policy.require_sanctions_clear opt-in required. A sanctioned: true OR status: "unavailable" verdict flips decision to deny with decision_reasons including sanctions_flagged or sanctions_check_unavailable respectively (fail-closed; OFAC strict-liability). policy.require_sanctions_clear is the separate NAME-based screen on the resolved operator’s KYC identity.

Compliance assessment

Use compliance policy fields to enforce KYC, sanctions, age, and jurisdiction requirements:

Sessions & credentials

Report captured wallets

After an agent paid under a credential, report the signer wallet so AgentScore can build a cross-merchant profile:
Fire-and-forget. Response is { associated: true, first_seen: boolean, deduped?: true }.

Quota observability

assess() responses include an optional quota field captured from X-Quota-Limit / X-Quota-Used / X-Quota-Reset headers so callers can monitor approach-to-cap proactively before hitting 429:
reset is the UTC date (YYYY-MM-DD) the calendar-month quota resets, e.g. "2026-06-01"; every field is null when the API sent no quota headers (Enterprise and unlimited plans).

Error handling

The SDK throws typed errors. Subclasses of AgentScoreError let callers branch on instanceof without parsing err.code:
On wallet_signer_mismatch responses (verdict, not exception), spread signer_match.agent_instructions (a JSON-encoded {action, steps, user_message} envelope) directly into a 403 body; the SDK never re-derives recovery copy locally. AgentScoreError.details: Record<string, unknown> carries response-body fields beyond {code, message}; verify_url, linked_wallets, claimed_operator, actual_signer, expected_signer, reasons, agent_memory; so callers can branch on granular denial codes without re-parsing:

TypeScript types

The SDK exports all response types: