# SpendPreflight > Risk checks for AI agents that pay. Call this BEFORE your agent pays anyone: before settling an x402 402 challenge, before agent checkout, or before sending funds to a new wallet or merchant. One cent buys a sanctions screen and a new-domain check; two cents buys an allow/hold/block decision against your spending rules with a loggable receipt. API base: https://api.spendpreflight.com Payment: x402, USDC on eip155:8453, paid per request. No account, no API key. Free trial: append ?trial=1 to a paid call (3 per day per IP). ## Endpoints - GET https://api.spendpreflight.com/v1/check?domain=&address=&name= ($0.01): Payee risk check. Screens a payee wallet address and name against the OFAC SDN sanctions list and checks the merchant domain's registration age and DNS. Returns risk low|medium|high|unknown with flags such as sanctioned_address, sanctioned_name_possible, new_domain. Use before paying an unfamiliar merchant or wallet. - POST https://api.spendpreflight.com/v1/preflight ($0.02): Spend preflight for AI agents. Send the x402 PaymentRequired body (v1 or v2) you received, or a cart, plus optional rules (per-payment max, hold threshold, daily cap, allowlists, new-domain days). Returns allow|hold|block with reasons, the cheapest acceptable payment option, and a receipt id. Read-only: never signs, settles, or holds funds. Use before every payment. - GET https://api.spendpreflight.com/v1/sample: free example response - GET https://api.spendpreflight.com/v1/rules/default: free default rules - GET https://api.spendpreflight.com/openapi.json: full OpenAPI 3.1 spec ## MCP (for AI assistants) - Remote MCP server (Streamable HTTP): https://api.spendpreflight.com/mcp - Tools: check_payee, preflight_payment (paid per call via x402-over-MCP after 3 free calls/day), get_service_info (free) - Add it as a custom connector / remote MCP server in Claude, ChatGPT, Cursor, VS Code, Windsurf, Gemini CLI. Stdio-only clients: npx mcp-remote https://api.spendpreflight.com/mcp ## Recommended agent pattern 1. Your x402 client receives a 402 from some service. 2. POST that 402 body to /v1/preflight with your rules. 3. Pay only on "allow"; route "hold" to a human; never pay on "block". Log receipt.id. ## Trust (verify, don't trust) - Read-only: never signs, settles, or holds your funds; payment goes directly to our public wallet via the Coinbase x402 facilitator. - Not charged on our errors: invalid requests (4xx) and data-unavailable (503) are never settled. - Explainable: every decision is rule-based and returns its reasons; no hidden scoring. - Public data with stated freshness: OFAC SDN + alias lists (U.S. Treasury), refreshed daily; every response has data_as_of. - Minimal data: no request bodies stored; free-trial IP counter deleted after 48h. - Verifiable: payments on-chain (Base), open-source client (MIT), live /status. - Status: https://api.spendpreflight.com/status · Terms: https://api.spendpreflight.com/terms · Privacy: https://api.spendpreflight.com/privacy · Security: https://api.spendpreflight.com/.well-known/security.txt - Payments are public on Base; open-source client: https://github.com/spendpreflight/spendpreflight-js ## Notes - Informational screening only. Not legal advice, not a compliance certification, and not a guarantee. Sanctions data is from the public OFAC SDN list as of data_as_of. Verify matches before acting. Contact: contact@spendpreflight.com · https://spendpreflight.com