catalogue / tools / Archives & binary / Archive Inspect API

Archive Inspect API

Lists the entries of a remote zip, tar or tar.gz (paths, sizes, compression and CRC) without extracting any of them.

Endpoint
POST /v1/archive-inspect
Price
$0.003 per call
Family
Archives & binary

01When to use it

  • Seeing inside an archive without extracting it needs a real zip/tar reader and a hardened fetch, plus the decompression-bomb care that reads declared sizes instead of inflating, not something an agent does inline.

When not to use it

  • The input is over 100 MB (104,857,600 bytes): archive-inspect answers too_large (413).
  • The destination needs more than 60 s to answer: the call ends with upstream_timeout (424).
  • The destination is on a private or local network: the network guard refuses it with blocked_target (403).

02Parameters

FieldTypeRequiredDescription
urlstringyesAbsolute http(s) URL of the archive (at most 100 MB, also the cap on an inflated tar.gz), up to 2048 characters; redirects are followed and the format (zip, tar or gzip-compressed tar) is decided from the magic bytes, not the extension.
max_entriesintegernoHow many entries to list, 1 to 10000 (default 1000), taken in archive order and then sorted by name; any beyond the limit still count in total_entries and set truncated. Default: 1000.

03Limits

LimitValue
Size cap100 MB (104,857,600 bytes)
Timeout60 s

04Example

The published example of archive-inspect, verbatim: the request body and the response it returns.

Request
POST /v1/archive-inspect
content-type: application/json
payment-signature: <base64 x402 payload>

{
  "url": "https://grist.tools/samples/archives/bundle.zip",
  "max_entries": 1000
}
Response
200 OK
payment-response: <base64 settlement receipt>

{
  "source_url": "https://grist.tools/samples/archives/bundle.zip",
  "kind": "zip",
  "compression": "none",
  "entry_count": 5,
  "total_entries": 5,
  "total_uncompressed_bytes": 159,
  "encrypted": false,
  "truncated": false,
  "entries": [
    {
      "name": "data/",
      "is_directory": true,
      "entry_type": "directory",
      "size": 0,
      "compressed_size": 0,
      "compression": "none",
      "encrypted": false,
      "crc32": "00000000"
    },
    {
      "name": "data/squares.csv",
      "is_directory": false,
      "entry_type": "file",
      "size": 31,
      "compressed_size": 33,
      "compression": "deflate",
      "encrypted": false,
      "crc32": "89761172"
    },
    {
      "name": "docs/",
      "is_directory": true,
      "entry_type": "directory",
      "size": 0,
      "compressed_size": 0,
      "compression": "none",
      "encrypted": false,
      "crc32": "00000000"
    },
    {
      "name": "docs/readme.md",
      "is_directory": false,
      "entry_type": "file",
      "size": 116,
      "compressed_size": 94,
      "compression": "deflate",
      "encrypted": false,
      "crc32": "b6cd27c3"
    },
    {
      "name": "hello.txt",
      "is_directory": false,
      "entry_type": "file",
      "size": 12,
      "compressed_size": 12,
      "compression": "store",
      "encrypted": false,
      "crc32": "af083b2d"
    }
  ]
}

Sample file: archives/bundle.zip. Tiny zip of five entries (a stored greeting, a deflated markdown note, a deflated five-row CSV and two directories), built with jszip at a pinned entry date.

Response fieldTypeIn the example
source_urlstring"https://grist.tools/samples/archives/bundle.zip"
kindstring"zip"
compressionstring"none"
entry_countnumber5
total_entriesnumber5
total_uncompressed_bytesnumber159
encryptedbooleanfalse
truncatedbooleanfalse
entriesarray5 items, each with name, is_directory, entry_type, size, compressed_size, compression, encrypted and crc32

05Call it from code

JavaScript
// archive-inspect: $0.003 per call, paid in USD Coin on eip155:8453 via x402
// Install: npm install @x402/fetch@2 @x402/evm@2 viem@2
// Save as client.mjs (ES module, Node 18+), export EVM_PRIVATE_KEY with the paying wallet's key in your shell, then run: node client.mjs
// The wrapper reads the 402 (payment-required), signs and retries with payment-signature.
import { wrapFetchWithPayment, x402Client, decodePaymentResponseHeader } from '@x402/fetch'
import { ExactEvmScheme } from '@x402/evm/exact/client'
import { privateKeyToAccount } from 'viem/accounts'

const account = privateKeyToAccount(process.env.EVM_PRIVATE_KEY)
const client = new x402Client().register('eip155:8453', new ExactEvmScheme(account))
const fetchWithPayment = wrapFetchWithPayment(fetch, client)

const body = {
  "url": "https://grist.tools/samples/archives/bundle.zip",
  "max_entries": 1000
}

const res = await fetchWithPayment('https://grist.tools/v1/archive-inspect', {
  method: 'POST',
  headers: { 'content-type': 'application/json' },
  body: JSON.stringify(body),
})
console.log(res.status, await res.json())
const settle = res.headers.get('payment-response')
if (settle) console.log(decodePaymentResponseHeader(settle).transaction)
Python
# archive-inspect: $0.003 per call, paid in USD Coin on eip155:8453 via x402
# Install: pip install "x402[requests,evm]>=2.24,<3"
# The session reads the 402 (payment-required), signs and retries with payment-signature.
import os
from eth_account import Account
from x402 import x402ClientSync
from x402.http import decode_payment_response_header
from x402.http.clients.requests import x402_requests
from x402.mechanisms.evm.exact import register_exact_evm_client
from x402.mechanisms.evm.signers import EthAccountSigner

account = Account.from_key(os.environ["EVM_PRIVATE_KEY"])
client = x402ClientSync()
register_exact_evm_client(client, EthAccountSigner(account), networks="eip155:8453")
session = x402_requests(client)

payload = {
    "url": "https://grist.tools/samples/archives/bundle.zip",
    "max_entries": 1000
}

res = session.post("https://grist.tools/v1/archive-inspect", json=payload)
print(res.status_code, res.json())
settle = res.headers.get("payment-response")
if settle:
    print(decode_payment_response_header(settle).transaction)
curl
# archive-inspect: $0.003 per call, paid in USD Coin on eip155:8453 via x402
# 1. Unpaid call: HTTP 402, the requirements in the payment-required header (base64 JSON) and in the body.
curl -i -X POST 'https://grist.tools/v1/archive-inspect' -H 'content-type: application/json' -d '{"url":"https://grist.tools/samples/archives/bundle.zip","max_entries":1000}'

# 2. Same call with the signed payment (an EIP-3009 authorization, EIP-712 signed: it cannot be
#    typed by hand). x-payment is accepted as the v1 alternative. HTTP 200 carries payment-response.
curl -i -X POST 'https://grist.tools/v1/archive-inspect' -H 'content-type: application/json' -H 'payment-signature: <base64 x402 payload>' -d '{"url":"https://grist.tools/samples/archives/bundle.zip","max_entries":1000}'

06Errors

CodeHTTPFor this service
invalid_input400The body does not match the schema; its fields are url and max_entries.
blocked_target403
unreachable_target424
upstream_timeout424
unsupported_content_type415
too_large413
unprocessable422
internal500

Input that is rejected before the tool runs (malformed JSON, schema mismatch, body over the size limit) is never charged.

When each code is raised, and what it means for payment: /docs/archive-inspect.

07Questions

How much does a archive-inspect call cost?
$0.003 per call, paid in USDC on Base via x402, with no account and no API key.
What does archive-inspect return?
A JSON object with 9 top-level fields: source_url, kind, compression, entry_count, total_entries, total_uncompressed_bytes, encrypted, truncated and entries. The example on this page is a real call over archives/bundle.zip.
What happens when a archive-inspect call fails?
The tool answers with a typed JSON error from the errors table. Payment is settled only after the tool has produced its result; a call that fails inside the tool is never settled. A 503 upstream_unavailable can follow a settled call; the x402 payments guide covers it, 429, 402 and an uncertain 500.