---
search:
  tags:
    - Services
    - POST
seo:
  description: >-
    Read-only check of a verified merchant offer against current agent
    clearance.… Reference for the POST /v1/access/check endpoint in the agentsub
    Gateway API.
sidebar:
  label: Check application access for the authenticated agent
  badge: POST
title: Check application access for the authenticated agent
type: openapi-operation
---
Read-only check of a verified merchant offer against current agent clearance. Zero-price offers allow access without holds, captures or fees; first contact may separately register the agent and issue its one-time welcome grant. Paid offers return allowed=false and paymentRequired=true; obtain and redeem a merchant-bound voucher separately. Merchant servers must match the returned AgentID issuer/subject, merchant and offer to their own authenticated session. A copied browser decision cannot authenticate a caller. Owner and merchant keys cannot substitute for the agent identity.

`POST /v1/access/check`

**Request body** (`application/json`, required)

- `offerId` (string, required)

Request body example:

```json
{
  "offerId": "string"
}
```

**Responses**

- `200` — Current access decision; no funds reserved or consumed
- `400` — Invalid offer request
- `401` — \`unauthorized\` problem; live 401s advertise \`WWW-Authenticate: Bearer resource\_metadata=...\`
- `403` — Identity, ownership, scope or policy denied (\`human\_required\`, \`owner\_claim\_required\`, \`scope\_required\`, \`FROZEN\`, \`CAP\_EXCEEDED\`, \`SCOPE\_FORBIDDEN\`)
- `404` — Active published offer not found

Response example, 200:

```json
{
  "agentId": "string",
  "agentIdentity": {
    "issuer": "string",
    "subject": "string"
  },
  "merchantId": "string",
  "offerId": "string",
  "allowed": true,
  "paymentRequired": true,
  "priceUc": "string",
  "account": {
    "availableUc": "string"
  },
  "voucherEndpoint": "string"
}
```
