TokenGuard Base / Guides

Check if a Base token is a honeypot via API

A honeypot token lets you buy but blocks you from selling. Here is how to catch one with a single HTTP call before a bot or agent sends funds.

The problem

On Base anyone can deploy an ERC-20 and open a Uniswap or Aerodrome pool within minutes. Some contracts are written so that transfers into the pool revert for everyone except the deployer, which makes the token impossible to sell. A price chart will not show this; the only dependable test is to try the sell path. Doing that yourself means an RPC provider, pool discovery across several DEX factories and bytecode analysis.

How /token-risk answers it

GET /token-risk takes one ERC-20 address. It looks for the token's pools against WETH and USDC on Uniswap v2, v3 and Aerodrome, picks the deepest, and simulates transferring the token into that pool. If the simulation reverts, the token gets 60 risk points, which alone maps to the AVOID verdict. The same call lists owner-controllable functions found in the bytecode (mint, blacklist, pause, fee setters), whether ownership is renounced, liquidity in USD and the pools it found. Points add up to a 0-100 riskScore: 60 and above is AVOID, 30-59 HIGH_RISK, 12-29 CAUTION, below 12 LOW_RISK. Every contribution appears as an entry in flags.

Request and response

Example for BRETT, a widely traded Base token.

$ curl -i "https://tokenguard.imac2014ville.workers.dev/token-risk?token=0x532f27101965dd16442E59d40670FaF5eBB142E4"
HTTP/2 402
payment-required: eyJ4NDAyVmVyc2lvbiI6Mi4uLn0=   # base64 JSON: scheme "exact", network eip155:8453,
                                                  # asset USDC, amount 20000 (= $0.02)
# An x402 client signs the payment, then retries with a PAYMENT-SIGNATURE header.

The paid response (abridged sample; liquidity and price move with the market):

{
  "ok": true,
  "symbol": "BRETT",
  "decimals": 18,
  "verdict": "LOW_RISK",
  "riskScore": 0,
  "flags": [],
  "ownershipRenounced": true,
  "ownerFunctionsDetected": ["enableTrading()"],
  "sellSimulation": { "simulated": true, "sellToPoolSucceeds": true },
  "liquidityUsd": 1325299,
  "priceUsd": 0.00525,
  "disclaimer": "Automated on-chain heuristics, not financial advice. ..."
}

JavaScript with @x402/fetch

import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

const signer = privateKeyToAccount(process.env.PRIVATE_KEY); // wallet holding USDC on Base
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(signer) }],
});
const res = await pay("https://tokenguard.imac2014ville.workers.dev/token-risk?token=0x532f27101965dd16442E59d40670FaF5eBB142E4");
const r = await res.json();
if (!r.sellSimulation.sellToPoolSucceeds || r.verdict === "AVOID") throw new Error("do not buy: " + r.flags.map(f => f.issue).join("; "));

Pricing

/token-risk costs $0.02 per call. There is no API key and no account: each request is paid in USDC on Base over x402. Malformed input returns 400 and failed lookups return a non-2xx status, so those are not charged.

Limitations

More guides

Sister services