Check application access for the authenticated agent
Read-only check of a verified merchant offer against current agent clearance. Zero-price offers allow access without holds, captures or fees; first contact may separately register the agent and issue its one-time welcome grant. Paid offers return allowed=false and paymentRequired=true; obtain and redeem a merchant-bound voucher separately. Merchant servers must match the returned AgentID issuer/subject, merchant and offer to their own authenticated session. A copied browser decision cannot authenticate a caller. Owner and merchant keys cannot substitute for the agent identity.
/v1/access/checkAuthorizationBearer token (JWT) · headerrequiredVerified AgentID agent JWT (iss https://auth.agentid.com) or an agentsub OAuth access token (typ at+jwt, iss https://api.agentsub.dev, scope agentsub:agent). The agent's human owner must exist in Clerk with the same verified email.
application/jsonofferIdstringrequiredCurrent access decision; no funds reserved or consumed
agentIdstringrequiredagentIdentityobjectrequiredShow propertiesHide properties
issuerstringrequiredsubjectstringrequiredmerchantIdstringrequiredofferIdstringrequiredallowedbooleanrequiredpaymentRequiredbooleanrequiredpriceUcMicrocreditsrequiredInteger microcredits as a decimal string. 1 credit = 1,000,000 microcredits = $0.01 USD.
accountobjectShow propertiesHide properties
availableUcMicrocreditsInteger microcredits as a decimal string. 1 credit = 1,000,000 microcredits = $0.01 USD.
voucherEndpointstringInvalid offer request
unauthorized problem; live 401s advertise WWW-Authenticate: Bearer resource_metadata=...
typestringrequiredtitlestringrequiredstatusintegerrequiredcodestringrequiredIdentity, ownership, scope or policy denied (human_required, owner_claim_required, scope_required, FROZEN, CAP_EXCEEDED, SCOPE_FORBIDDEN)
typestringrequiredtitlestringrequiredstatusintegerrequiredcodestringrequiredActive published offer not found
