---
search:
  tags:
    - Merchant Registry
    - POST
seo:
  description: >-
    Merchant server authenticates with access:check scope and asserts the…
    Reference for the POST /v1/access/merchant-check endpoint in the agentsub
    Gateway API.
sidebar:
  label: Check an independently verified AgentID identity for your own merchant offer
  badge: POST
title: Check an independently verified AgentID identity for your own merchant offer
type: openapi-operation
---
Merchant server authenticates with access:check scope and asserts the AgentID issuer/subject independently verified by its own application. An atomic lookup checks the merchant-owned active offer, canonical agent registration and current clearance. The response contains no owner identity or private balance. No registration, grant, hold, capture or fee is created; native application resource permissions remain the merchant responsibility.

`POST /v1/access/merchant-check`

**Request body** (`application/json`, required)

- `offerId` (string, required)
- `agentIdentity` (object, required)

Request body example:

```json
{
  "offerId": "string",
  "agentIdentity": {
    "issuer": "https://auth.agentid.com",
    "subject": "string"
  }
}
```

**Responses**

- `200` — Current access decision; no funds reserved or consumed
- `400` — Invalid offer request
- `401` — \`unauthorized\` problem; live 401s advertise \`WWW-Authenticate: Bearer resource\_metadata=...\`
- `403` — Identity, ownership, scope or policy denied (\`human\_required\`, \`owner\_claim\_required\`, \`scope\_required\`, \`FROZEN\`, \`CAP\_EXCEEDED\`, \`SCOPE\_FORBIDDEN\`)
- `404` — Registered agent or active merchant-owned offer not found

Response example, 200:

```json
{
  "agentId": "string",
  "agentIdentity": {
    "issuer": "string",
    "subject": "string"
  },
  "merchantId": "string",
  "offerId": "string",
  "allowed": true,
  "paymentRequired": true,
  "priceUc": "string",
  "voucherEndpoint": "string"
}
```
