Check a recipient address before you pay it
onchain_agent_scan_recipientUSE WHEN an agent is about to pay or transfer to an address: an x402 payTo, a treasury sweep, a top-up. Pass the chain and the recipient; add the token, the origin whose 402 named the address and the paying wallet for a fuller reading. Sato Scan answers five questions, each with its own date and gap.
WHAT IT READS: (1) does the recipient only LOOK like an address the payer pays, matching its first and last characters without being it; (2) is the token the issuer's contract, keyed by contract address and never by symbol; (3) did the paid party declare the address, through the origin that served it or an identity that names it; (4) does the address carry a structural mark from what it did onchain; (5) is the paying wallet itself the target of address poisoning.
RULES: a reading describes what was looked at inside the stated limits, on the date given. unknown means Sato Hub holds no record either way. go means the payee was declared, the token is the issuer's contract and nothing was found within the limits: it is never a clearance. caution and no name the rule and the observed fact that decided them. A mark describes what an address did, not who controls it. The recipient, token, paying wallet, origin and amount are not stored; only the chain is. Nothing is signed or sent.
Returns (json): { schema: "sato.scan.recipient/v1", verdict: go | caution | no | unknown, rule, reason, answers: { token, lookalike, declared, marks, targeted }, limits, limits_text, as_of, method_version, caveat }. Read-only.
Example: { chain: "Base", to: "0x1bc0c42215582d5A085795f4baDbaC3ff36d1Bcb", token: "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913", origin: "https://api.example.com/paid" }
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| to | Yes | The recipient address the agent is about to pay: the x402 payTo, the treasury address, the top-up target. | |
| from | No | The paying wallet. Lets the reading compare against that wallet's own history and say whether it is being targeted by address poisoning. | |
| chain | Yes | Chain the payment would settle on: Base, Solana, Tempo, Polygon, BNB Chain, Arbitrum, Avalanche, Optimism, Ethereum, SKALE Base, Sei, X Layer, Monad, Robinhood Chain, World Chain, Abstract. | |
| token | No | The token contract (or Solana mint) the payment would use. Lets the reading say whether it is the issuer's contract. Keyed by address, never by symbol. | |
| amount | No | Amount in the token's base units. Read for context only; never stored. | |
| origin | No | The https URL whose 402 response named `to` (a public host; no credentials). Lets the reading say whether that origin declared the address. | |
| response_format | No | Text format; structuredContent is JSON either way. | markdown |