LEI

LowEndInsight

Open source supply chain risk and agentic analysis

Beta. Analysis is free during beta, up to the monthly allowance on each account. The service is provided with no warranty and any use is at your own risk — see terms.

Use it from an agent — no account needed

During beta, analysis is free. An agent that has never been here is still asked once for 500 credits ($0.50) — the smallest amount these payment rails will settle. That buys an account rather than analysis: nothing is deducted from it while analysis is free, and it stays yours to spend when charging resumes. An account costs nothing to create, so without it every allowance would be an allowance per attacker.

The flow below is the one that will apply when beta ends, and it is the flow you integrate against today.

  1. Ask. POST /v1/analyze with no credentials returns 402 Payment Required and a WWW-Authenticate: Payment challenge naming the amount, the asset and where to send it.
  2. Pay and retry the same request with Authorization: Payment <credential>. An MPP client does both steps for you.
  3. Receive the analysis, a Payment-Receipt, and a Lei-Api-Key.
  4. Come back with Authorization: Bearer lei_… and spend the balance without paying again.

Payments are in test mode. Stablecoin payments use pathUSD on Tempo testnet, and no real money moves.

What the first request returns

curl -i -X POST https://lowendinsight.dev/v1/analyze \
  -H "Content-Type: application/json" \
  -d '{"urls": ["https://github.com/kitplummer/clikan"]}'

HTTP/2 402
www-authenticate: Payment id="…", realm="lowendinsight.dev",
  method="tempo", intent="charge", request="…"

Paying with an MPP client

import { Mppx, tempo } from 'mppx/client'

const mppx = Mppx.create({ methods: [tempo({ account })], polyfill: false })

const res = await mppx.fetch('https://lowendinsight.dev/v1/analyze', {
  method: 'POST',
  headers: { 'content-type': 'application/json' },
  body: JSON.stringify({ urls: ['https://github.com/kitplummer/clikan'] }),
})

const key = res.headers.get('lei-api-key')   // keep it: it holds your balance

A machine-readable version of this guide is at /llms.txt.

Pricing when beta ends

None of these are charged today. They are published now so that nothing about them is a surprise later, and we will tell account holders before charging begins.

A repository with a cached report5 credits$0.005
A repository analyzed fresh50 credits$0.05
A block, bought when an agent's balance runs out15,000 credits$15.00

One credit is $0.001. A cached report is cheaper because someone has already paid for the work: every analysis makes the next request for that repository cheaper, whoever makes it.

Ways to pay

PathwayForHowNow
Stablecoin
MPP tempo
Any agent, no account Transfer pathUSD on Tempo testnet to the address in the challenge. Stripe verifies and settles it. Available
Card through an agent wallet
MPP stripe, Shared Payment Token
Agents with an API key A Shared Payment Token from an agent wallet such as Link. Not offered without an account: a card token identifies no one to hold the balance. Available
Free tier People Sign up for an API key: 200 analyses a month. Available
Pro People Sign up and subscribe through Stripe Checkout: $29/month, including $15.00 of usage. Available

With an API key

Analyze a repo

curl -X POST https://lowendinsight.dev/v1/analyze \
  -H "Authorization: Bearer lei_…" \
  -H "Content-Type: application/json" \
  -d '{"urls": ["https://github.com/kitplummer/clikan"]}'

Check a job result

curl https://lowendinsight.dev/v1/analyze/{uuid}

Analyze an SBOM

curl -X POST https://lowendinsight.dev/v1/analyze/sbom \
  -H "Authorization: Bearer lei_…" \
  -H "Content-Type: application/json" \
  -d '{"sbom": <cyclonedx-or-spdx-json>}'

API Endpoints

Method Path Description
POST /v1/analyze Submit URLs for analysis (blocking, async, or stale mode)
GET /v1/analyze/{uuid} Retrieve analysis results by job UUID
POST /v1/analyze/sbom Analyze repos from a CycloneDX or SPDX SBOM
GET /v1/cache/export Export cache for air-gapped deployment
POST /v1/cache/import Import pre-warmed cache
GET /v1/cache/stats Cache statistics

See the full interactive API documentation for request/response schemas and examples.

No account, and why

An agent has no signup, email or organization to give, and asking for one would turn away the consumers this service is built for. The payment is the identity: the wallet that paid holds the balance.

What we keep: money and counts. Each purchase and debit is recorded with the paying wallet and the amount, the financial record of what was paid and spent. We also keep monthly analysis counts.

What we don't keep: which repositories a wallet analyzed. They aren't recorded against the payer, and routine production logs don't name them.

Reports are cached by repository, not by who asked. That is what makes a cached report cheaper for everyone.

No free allowance for wallets. A wallet costs nothing to create, so a free allowance per wallet would be a free allowance per attacker. Access comes from credits.

A stablecoin transfer is public on the Tempo testnet chain, as every on-chain payment is. What it paid for is not.

Risk Indicators

  • Contributor count — bus factor risk
  • Contributor risk — overall contributor risk level
  • Functional contributors — concentration of commits
  • Functional contributors risk — contributor concentration risk level
  • Commit currency — weeks since last commit
  • Commit currency risk — staleness risk level
  • Large recent commit risk — codebase volatility
  • Recent commit size % — last commit as % of codebase
  • SBOM risk — dependency/supply chain risk
  • Agentic classification — human / mixed / agent based on bot/AI commit ratio
  • Agentic contribution ratio — fraction of commits from bots or AI agents (0.0–1.0)
  • Restricted contributors — whether any contributors have restricted GitHub profiles (requires GitHub token)

Agentic thresholds: human < 0.3, mixed 0.3–0.7, agent > 0.7

Agentic Classification

Each repository is classified based on the ratio of commits attributed to automated or AI contributors:

humanRatio < 0.3 — predominantly human-authored
mixedRatio ≥ 0.3 — mix of human and agentic
agentRatio ≥ 0.7 — predominantly agentic

Risk Levels

criticalImmediate attention needed
highSignificant concern
mediumWorth monitoring
lowHealthy indicator

Try it