GET /listings/{id}/unlock is the paid route. It follows x402 v2:
- Unpaid:
402 with a base64 JSON PAYMENT-REQUIRED header listing the payment options.
- Paid retry: send the signed Cardano transaction in
PAYMENT-SIGNATURE. The API verifies and submits it with its own facilitator, then answers 200 with the content and a base64 JSON PAYMENT-RESPONSE header whose transaction is the tx hash.
With the x402 client
Check the deployment you pay into. A protected quote names an escrow; only pay one that matches Simpuru’s deployment, never just any address a server returns. The repository’s buyer uses isOurDeployment from @simpuru/core/escrow, which also compares the arbiter key and parameters.
After paying
- Recompute
sha256(content) and compare it with the listing’s contentHash.
- Follow the purchase at
GET /purchases/{tx}. See Purchases and timelines.
- Asking again after a dropped connection: send an
X-Simpuru-Proof header (see Authentication) to get the content you already paid for without paying again.
Or let an account pay
A signed-in account can buy from its Simpuru wallet with POST /me/buy { listingId, mode }. It takes 20–60 seconds and returns { purchase, content, alreadyOwned }.