---
title: "Pricing. Lazaretto"
description: "Free lockfile and known-bad checks with no account. 10 free full scans a day on a developer key. $0.03 per scan over x402, or prepaid packs that never expire."
url: "https://lazaretto.dev/pricing"
---

[Home](https://lazaretto.dev/) / Pricing

Pricing

# Free to start. Pay per scan when you want the code read.

Checking whether a version is known malware is free for everyone, with no account. Reading the code costs one credit per verdict, and an error is never billed.

### Free

$0 no account, no key

- Lockfile check, whole tree
- Pull request diff of a lockfile
- Known-bad hash lookups
- Attestation lookup and verification
- The free MCP tools and the GitHub Action

[Check a lockfile](https://lazaretto.dev/#check)

### Free dev tier

$0 10 scans a day

- 10 full behavioral scans a day
- Refills daily, never expires
- Works in the API, MCP and CI
- No card, wallet or account

[Get a free key](https://lazaretto.dev/start)

### Pay per call

$0.03 per scan

- USDC on Base over x402
- No account and no key
- Discoverable in the x402 Bazaar
- Nothing charged for an error

[How x402 works](https://lazaretto.dev/agents#x402)

## Capacity packs

For CI, whole-tree scans and anything past the free daily allowance. One purchase, no subscription, and the credits never expire.

### Starter

$3 150 scans

- $0.020 per scan
- No daily cap, never expires
- API, MCP and CI on one key

[Buy with a card](https://lazaretto.dev/buy)

### Pro

$12 700 scans

- $0.017 per scan
- No daily cap, never expires
- API, MCP and CI on one key

[Buy with a card](https://lazaretto.dev/buy)

### Scale

$25 1,600 scans

- $0.016 per scan
- No daily cap, never expires
- API, MCP and CI on one key

[Buy with a card](https://lazaretto.dev/buy)

## What costs a credit

One credit is one verdict.

| Call | Cost |
| --- | --- |
| Full scan of one artifact (`POST /v1/scan`, `scan_artifact`) | 1 credit |
| MCP server check (`scan_mcp_server`) or tool list check (`check_mcp_tools`) | 1 credit |
| Whole-tree scan (`POST /v1/scan/batch`, `scan_lockfile_deep`), up to 25 per call | 1 credit per package |
| Creating a watch (`POST /v1/watch`) | 1 credit |

## Never billed

- An `error` verdict, over the API, MCP or x402.
- A package that errors inside a whole-tree scan. Credits reserved for it are returned.
- Reading a watch you created.
- Anything on the free list above, at any volume within the rate limits.

## Ways to pay

### Card

Stripe hosted checkout at [lazaretto.dev/buy](https://lazaretto.dev/buy). The key appears once on the confirmation page. Card buyers can opt in to automatic reload, described in Section 5 of the [Terms](https://lazaretto.dev/terms).

### USDC over x402, per call

No account and no key: `POST /v1/scan` answers 402 with the price, the client pays $0.03 on Base and retries. Built for agents holding a wallet. [How it works](https://lazaretto.dev/agents#x402).

### USDC over x402, a pack

`POST /v1/credits/topup` with `{"bundle":"starter"}` settles once and returns a key, or tops up the key you send.

### Free developer key

10 scans a day with no payment at all. [Get one in the browser](https://lazaretto.dev/start) or `POST /v1/trial`.

## Larger volume or a platform?

Embedding verdicts in a registry, a marketplace or an agent platform, or need an invoice? Email [contact@lazaretto.dev](mailto:contact@lazaretto.dev?subject=Pricing).

Prices are in US dollars. x402 payments settle in USDC on Base. See the [Terms](https://lazaretto.dev/terms) for refunds and the rest.

---

Machine-readable index: https://lazaretto.dev/llms.txt. OpenAPI: https://lazaretto.dev/openapi.json. MCP endpoint: https://lazaretto.dev/mcp. Any page on this site is available as markdown by adding .md to its path.
