Docs · 11
Ownership check
Gate your own app, API or agent with one request.
Why#
If you host an app, API or agent yourself, you can sell access to it on EVERYNTH without handing out codes that get shared. Sell a product (a secret text such as your app's URL is enough), then have your app ask EVERYNTH whether the visitor's wallet bought it. Access follows the wallet, not a string.
The endpoint#
GET https://everynth.org/api/verify?product=<productId>&wallet=<address>
200 { "owned": true, "since": "2026-09-21T10:00:00.000Z" }
200 { "owned": false, "since": null }
400 { "error": "product and wallet are required" }- Public: no API key, no session.
- CORS-open (
Access-Control-Allow-Origin: *), so a browser app can call it directly. sinceis the time of the first paid purchase of that product by that wallet.- Removed products still answer
owned: truefor their buyers.
Prove the wallet first#
Anyone can ask whether any wallet owns a product, so the answer only means something once your app knows the visitor controls that wallet. Do what EVERYNTH does at sign-in: ask the wallet to sign a message, verify the signature, then trust the address.
// browser: wallet adapter
const msg = new TextEncoder().encode(`${location.host} sign-in ${Date.now()}`);
const sig = await wallet.signMessage(msg); // Uint8Array(64)
// send { wallet, msg, sig } to your server and verify there:
// node
import { createPublicKey, verify } from "node:crypto";
import { PublicKey } from "@solana/web3.js";
const spki = Buffer.concat([Buffer.from("302a300506032b6570032100", "hex"), new PublicKey(wallet).toBytes()]);
const ok = verify(null, msg, createPublicKey({ key: spki, format: "der", type: "spki" }), sig);Gate the app#
const PRODUCT = "d80f8bf3-9c1a-4e06-b4c1-b24d6866a838"; // from your product's URL, /p/<id>
const res = await fetch(`https://everynth.org/api/verify?product=${PRODUCT}&wallet=${wallet}`);
const { owned } = await res.json();
if (!owned) location.href = `https://everynth.org/p/${PRODUCT}`;Cache the answer for a few minutes per wallet if your app is busy; ownership never goes away once granted, so stale answers only ever err on the side of a buyer who bought seconds ago.
For agents and servers#
The same endpoint works from a server. An agent that needs to know whether its principal bought a dataset calls it with the principal's wallet. A pay-per-call gate (x402) that lets the agent itself pay is on the roadmap; today an agent buys through the same wallet flow a person does.
Next