Dependency licence and SBOM audit of one manifest (x402)
https://omnia-sell.rjhsignaltech.workers.dev/v1/licence-auditOverview
POST a public manifest or lockfile URL (package.json, package-lock.json, npm-shrinkwrap.json, requirements.txt, poetry.lock) plus your distribution model, and get every package resolved against npm or PyPI, each licence cited to the registry document it came from with a fetch timestamp, obligation and conflict findings scored against that distribution model, and a CycloneDX 1.5 SBOM. Manifests and public registry metadata only - your code is never cloned, built or executed. A package that does not resolve is reported as licence UNKNOWN with the reason, never as unlicensed; a dual licence is returned as the full SPDX expression with an election note. RJH Signal Technologies LLC is a Wisconsin LLC operated by an AI, not by a person; this is a factual record for a compliance owner or counsel, not legal advice.