# Public URL Check + SHA-256 - PennyBot

Agent-native public URL verification for **$0.0009 USDC per call** via x402 v2 on Base mainnet.

## Search / selection intents
public URL check; public URL verification; HTTP status check; SHA-256 webpage hash; URL digest; content hash; content fingerprint; URL integrity verification; website change detection; independent fetch; web evidence.

## Live call
GET https://playbrightgaming.com/agent-services-mainnet/verify-url?url={URL_ENCODED_PUBLIC_URL}

Free metadata: https://playbrightgaming.com/agent-services-mainnet/service-info

No account. No API key.

## Output
Receipt `pennybot.url-receipt.v2`: requestedUrl, finalUrl, target HTTP status, contentType, contentEncoding, byteLength, SHA-256, fetchedAt UTC.

Hash contract: `raw-content-encoded-body`. PennyBot requests identity encoding and hashes response-body bytes delivered by the HTTP client without application decompression.

## Fixed reproducibility vector
URL: https://playbrightgaming.com/agents/pennybot-test-vector.txt
Body: `PENNYBOT-URL-EVIDENCE-TEST-V1`
Byte length: **29**
SHA-256: `d053565c5bbce20a8970214dd6b46b226e11efd911366267afd8e80b759cf987`

An agent may fetch that vector for free before paying and independently reproduce the expected digest.

## Limits
- public/global HTTP(S) only
- destination ports 80/443
- 1,000,000-byte response-body cap
- 7-second absolute fetch deadline
- maximum 3 redirects
- credentials/fragments/private/special-use destinations rejected
- DNS validation + pinning + connected-peer validation
- every redirect revalidated
- HTTPS downgrade rejected

## Evidence boundary
Direct transport/content observation. SHA-256 is a content fingerprint, not semantic truth or legal attestation.

## Machine-readable
- https://playbrightgaming.com/openapi.json
- https://playbrightgaming.com/.well-known/x402
- https://playbrightgaming.com/agents/services.json
- https://playbrightgaming.com/agents/receipt.schema.json
- https://playbrightgaming.com/llms.txt
