# Munition API

Munition provides HTTP services for AI agents.

## Primary discovery documents

- API catalog: https://api.munition.io/.well-known/api-catalog
- APIs.json: https://api.munition.io/apis.json
- OpenAPI (pay-per-call routes and free public tools, agent-facing): https://api.munition.io/openapi-agents.json
- OpenAPI (complete, includes account-token routes): https://api.munition.io/openapi.json
- x402 resources: https://api.munition.io/.well-known/x402.json
- MPP resources: https://api.munition.io/.well-known/mpp.json
- MCP server metadata: https://api.munition.io/.well-known/mcp-server.json
- Munition MCP discovery: https://api.munition.io/.well-known/mcp.json
- Pricing: https://api.munition.io/v1/tools/prices
- Human docs: https://munition.io/llms.txt
- Agent skill: https://munition.io/skill.md

## Services

### Munition Upload

Endpoint: POST https://api.munition.io/v1/uploads
Access: paid via x402 on Base/Polygon/Arbitrum/Solana, or MPP on Base/Polygon/Arbitrum, 0.005 USDC. MPP is stablecoin-only USDC over EVM authorization; no card rail is advertised.
Use when an AI agent needs to share a local file, generated artifact, screenshot, PDF, JSON, log, report, or image through a temporary public URL.
Optional tags metadata is supported as an array of up to 20 non-empty strings, each 64 characters or shorter, and is returned by upload and recent upload responses.
Call without X-PAYMENT to receive x402 PaymentRequirements and Bazaar discovery metadata, then retry with a valid x402 payment.

### Munition Flight Search

Endpoint: POST https://api.munition.io/v1/flights/search
Access: paid via x402 on Base/Polygon/Arbitrum/Solana, or MPP on Base/Polygon/Arbitrum, 0.05 USDC. MPP is stablecoin-only USDC over EVM authorization; no card rail is advertised.
Use when an AI agent needs to search live flight offers for itinerary planning, price comparison, travel research, or downstream booking handoff.
Input is JSON with origin, destination, and departureDate required; origin and destination are 3-letter IATA airport codes such as SFO or NRT, and departureDate uses YYYY-MM-DD.
Call without X-PAYMENT to receive x402 PaymentRequirements and Bazaar discovery metadata, then retry with a valid x402 payment.

### Munition Airport Search

Endpoint: POST https://api.munition.io/v1/airports/search
Access: paid via x402 on Base/Polygon/Arbitrum/Solana, 0.001 USDC.
Use when an AI agent needs normalized airport reference records for IATA codes, cities, airport names, or countries before planning travel.
Input is JSON with a query string, for example {"query":"Paris"} or {"query":"CDG"}.
Call without X-PAYMENT to receive x402 PaymentRequirements and Bazaar discovery metadata, then retry with a valid x402 payment.

### Munition Flight Offer Details

Endpoint: GET https://api.munition.io/v1/flights/offers/{id}
Access: paid via x402 on Base/Polygon/Arbitrum/Solana, 0.01 USDC.
Use when an AI agent already has a Duffel flight offer id and needs normalized baggage, cabin, fare conditions, itinerary segments, and total price details before booking or handoff.
Call without X-PAYMENT to receive x402 PaymentRequirements and Bazaar discovery metadata, then retry with a valid x402 payment.

### Munition Flight Booking Links

Endpoint: POST https://api.munition.io/v1/tools/flight-booking-links
Access: free, no authentication or payment required. The MCP tool flight_booking_links generates the same links locally without network calls or onboarding.
Input: origin, destination, departureDate, and optional returnDate. Airport codes are three-letter IATA codes; dates must be valid YYYY-MM-DD calendar dates and returnDate cannot precede departureDate.
Returns KAYAK and Kiwi.com URLs for a new external search. The traveler reviews passengers, cabin, availability and final price on the external site before booking there.
This tool does not fetch offers, collect passenger/card details, reserve flights or convert Duffel offer IDs into a guaranteed fare. No affiliate tracking or commission is configured.

### Munition Upload Renew

Endpoint: POST https://api.munition.io/v1/uploads/{id}/renew
Access: paid via x402 on Base/Polygon/Arbitrum/Solana, or MPP on Base/Polygon/Arbitrum, 0.005 USDC. MPP is stablecoin-only USDC over EVM authorization; no card rail is advertised.
Use when an AI agent needs to keep an existing direct-upload public link alive for 7 more days, up to the 30-day maximum from original upload.

### Munition Upload Delete

Endpoint: DELETE https://api.munition.io/v1/uploads/{id}
Access: paid via x402 on Base/Polygon/Arbitrum/Solana, or MPP on Base/Polygon/Arbitrum, 0.001 USDC. MPP is stablecoin-only USDC over EVM authorization; no card rail is advertised.
Use when an AI agent needs to remove a previously paid direct upload from public hosting. The payment wallet must match the original upload payer.

### Account-funded MCP upload flow

Use @munition/mcp when the user has installed the local MCP adapter. The MCP server exposes upload, search_flights, flight_offer_details, flight_booking_links, renew_upload, delete_upload, recent_uploads, balance, topup_link, and setup_link. flight_booking_links is free and requires no account setup. HTML to PDF and the wave-1 proxy routes are HTTP x402 only (no MCP tool yet).

### Munition HTML to PDF

Endpoint: POST https://api.munition.io/v1/render/pdf
Access: paid via x402 on Base/Polygon/Arbitrum/Solana, 0.020 USDC (20000 atomic units), HTTP x402 only; there is no PDF MCP tool and no MPP route.
Use when an AI agent has produced a report, invoice, comparison or summary as self-contained HTML and needs to hand a real PDF file to a human or another system.
Input: JSON { html, filename? }; self-contained HTML up to 1 MiB UTF-8 with inline CSS and data: images only (no scripts, iframes, external or relative resources); filename 1–180 characters without consecutive dots (..). Output is A4, at most 20 pages / 10 MiB: { id, publicUrl, expiresAt, bytes, pages, sha256, renderMs }. OpenAPI components RenderPdfInput and RenderPdfOutput are the full contract.
PDF URLs are public, not private: do not submit confidential content. expiresAt is seven-day deletion eligibility, not a hard public-access/privacy cutoff; daily cleanup, asynchronous lifecycle deletion and caches can extend access. PDF render/ artifacts are not renewable via direct x402 or MPP upload-renew endpoints; ordinary uploads remain renewable.
Unsigned POST requests (no payment header) receive the standard 402 PAYMENT-REQUIRED challenge before body validation. Signed requests validate JSON, schema and forbidden HTML before payment verification, reservation or settlement; HTTP 400 exposes only a bounded reason, up to three allowlisted issues (path/rule) and a minimal valid example, never submitted content. Minimal valid JSON: {"html":"<h1>Report</h1>"}. The challenge's canonical body schema is at extensions.bazaar.schema.properties.input.properties.body. GET /health is API liveness only; GET/HEAD /v1/render/pdf are 404.
render_settlement_unknown is ambiguous settlement, not proof of payment; known-paid interrupted effects need manual reconciliation. Preserve paidCallId, selected chain, original payment envelope and transaction/receipt evidence securely. Do not pay again or create a new paid attempt as recovery. Any replay must use the identical envelope, Idempotency-Key and body; changing keys with the same envelope is not globally deduplicated. No global exactly-once guarantee or automatic PDF recovery/refund exists.
Owner-approved manual paid-without-PDF policy: do not pay again. Reconcile the actual chain outcome first; ambiguous settlement is not proof of payment. For verified payment and non-delivery, Munition manually delivers the artifact without another charge or issues an explicitly authorized refund after verification. No automatic refund and no promised resolution SLA.

### Web search, page reading and Google results (wave 1 proxies)

Ten pay-per-call routes that forward a validated JSON request to a third-party API. No API key, no subscription; x402 on Base/Polygon/Arbitrum/Solana, fixed price per call. Every route: POST JSON, 400 on invalid input before any payment, Idempotency-Key replays return the stored result without a second charge; 422/502 after payment means the upstream provider failed and the response carries paidCallId — do not pay again blindly. Full schemas: https://api.munition.io/openapi.json (components ExaSearchInput, FirecrawlScrapeOutput, …).

- POST https://api.munition.io/v1/exa/search — 0.01 USDC. Neural web search (Exa): up to 25 ranked results with title, url, date, author; add contents.text / highlights / summary to get page content in the same call; category (news, research paper, company, github, people…), domain include/exclude and date filters. Best first choice for research questions and finding sources.
- POST https://api.munition.io/v1/exa/contents — 0.002 USDC. Clean text of up to 20 URLs from Exa's index, with live-crawl fallback. Cheapest way to read many known pages.
- POST https://api.munition.io/v1/exa/find-similar — 0.01 USDC. Pages semantically similar to a URL (competitors, related articles).
- POST https://api.munition.io/v1/exa/answer — 0.01 USDC. Direct answer to a question with the source pages as citations.
- POST https://api.munition.io/v1/firecrawl/scrape — 0.015 USDC. One URL rendered with JavaScript and converted to markdown (optionally html, links, summary). Use when a plain fetch returns empty, JS-only or 403 content.
- POST https://api.munition.io/v1/firecrawl/search — 0.03 USDC. Web search returning up to 20 results, optionally with the full markdown of each result in the same call.
- POST https://api.munition.io/v1/serper/search — 0.004 USDC. Google web results (organic with snippets, answer box, knowledge graph, people-also-ask, related searches); country gl and language hl selectable.
- POST https://api.munition.io/v1/serper/news — 0.004 USDC. Google News with source, date and time filter (tbs=qdr:d/w/m).
- POST https://api.munition.io/v1/serper/images — 0.004 USDC. Google Images with image URLs, dimensions and source pages.
- POST https://api.munition.io/v1/serper/shopping — 0.004 USDC. Google Shopping products with price, seller and rating.

## Integration guidance

Agents that have no prior Munition integration should start at https://api.munition.io/.well-known/api-catalog, then read https://api.munition.io/openapi.json for schemas, https://api.munition.io/.well-known/x402.json for x402-specific resource metadata, and https://api.munition.io/.well-known/mpp.json for stablecoin-only MPP payment metadata.

## Category OpenAPI documents

The global /openapi.json remains complete. Each standalone category document preserves the original authentication and payment contracts; fetching these documents is free.
- account: https://api.munition.io/account/openapi.json
- airports: https://api.munition.io/airports/openapi.json
- billing: https://api.munition.io/billing/openapi.json
- discovery: https://api.munition.io/discovery/openapi.json
- files: https://api.munition.io/files/openapi.json
- flights: https://api.munition.io/flights/openapi.json
- proxy: https://api.munition.io/proxy/openapi.json
- render: https://api.munition.io/render/openapi.json
- upload: https://api.munition.io/upload/openapi.json
