Wuzzy is provable, decentralized search. Every result carries onchain proof of what was crawled and when, so an agent can check what it bought instead of trusting the operator.
There is no account and no API key. A signed payment is the only credential.
Ask without paying. The API answers 402 with what it will take, in both versions of the x402
protocol at once: version 2 in a PAYMENT-REQUIRED header, version 1 in the body. Use whichever
your client speaks. The quote is the same.
The PAYMENT-REQUIRED header is base64 encoded JSON. Decoded, it reads:
The body carries the same quote for version 1 clients:
Sign an authorization for that quote, base64 encode the payment, and retry with it in the header
for its version: PAYMENT-SIGNATURE for version 2, X-PAYMENT for version 1. A payment sent in
the other version's header is refused, and so is a request carrying both.
The settlement comes back in the same version: PAYMENT-RESPONSE, or X-PAYMENT-RESPONSE for a
version 1 payment.
amount, which version 1 calls maxAmountRequired, is in USDC's atomic units, six decimals, so
10000 is one cent.
Two ordering guarantees are worth knowing, because they are what make the meter safe to point an autonomous agent at:
403 without being charged to find out.Any x402 client handles the handshake for you. The signing is an EIP-3009 authorization, which is gasless for the payer: you need USDC, not ETH.
The reference client is the demo agent in the Wuzzy repository. It is deliberately small and imports nothing from the server, so it is readable as an example of what an outsider can build against the public API alone:
Under the hood it is @x402/fetch, which is the
shortest path if you are writing your own.
The scoped @x402/* packages speak protocol version 2 by default, and so does this example.
Version 2 names Base by its CAIP-2 id, eip155:8453, rather than as base. Clients still on
version 1, such as the unscoped x402-fetch, are answered too, with nothing to configure on
either side.
If you configured @x402/fetch for version 1 only, add the version 2 scheme. These docs used
to show ExactEvmSchemeV1 on its own. That client now throws
No client registered for x402 version: 2 before paying anything, because the scoped packages
read the PAYMENT-REQUIRED header before the body and sign in the version the header names.
Register ExactEvmScheme on eip155:8453 as below, alongside the version 1 scheme or instead of
it, or use registerExactEvmScheme, which registers both.
spendControls is worth setting rather than leaving off. It is a ceiling on what one request
may spend without asking again, and there is no default worth trusting: quote first, then set
it deliberately.
provenance is the point. It says which procedure produced the hash, what the hash is, when
the page was fetched, and where to check the attestation. Verify a result
walks through confirming it yourself.
total is a floor, not a count, whenever exhaustive is false. Both retrieval arms take a
fixed number of candidates and fusion reorders those, so the corpus can hold more matches than
the window saw. Render 103+ and page with hasMore rather than comparing offset against
total.
Pass offset. Every page of a query is served from the same fixed retrieval window, so pages
cannot overlap or shift under a reader between requests.