DatoQA — Conversion de fichiers The service has no scheduled closing time. Check /v1/conversions/status for the active flow. In payment_first mode, the quote runs no conversion, and there is no monthly purchase/preparation quota. A quote expires after five minutes; this does not close the service. Unpaid inputs are deleted after expiry. Completed files remain recoverable for 24 hours after completion. Abuse protection can return HTTP 429 with Retry-After; it is not a monthly sales limit. 1. Generate a UUID v4 purchase_id and a cryptographically random 32-byte hex recovery_key. Save both before upload. Never put the recovery key in a URL. 2. POST inputs [{format,data_base64}], output_format and optional options to /v1/paid/conversions/{purchase_id}/prepare with X-Conversion-Key and Content-Type: application/json. MCP convert_file performs the same request and never pays. 3. Inspect the returned flow, input hash, exact recipient, amount and quote expiry. Simple conversions cost 0.01 USDC; documents/OCR cost 0.02 USDC with a maximum of three pages. In payment_first mode, actual pages and conversion success are checked after payment. Any failed conversion or excess page count triggers a full refund to the original payer. The result hash is supplied only after successful conversion. 4. Only with the purchaser's authorization, POST the exact signed x402 v2 PaymentPayload JSON to the same path plus /pay. Keep the same recovery key. Do not use a generic automatic 402 retry. 5. GET the purchase path to follow the state and retrieve the encrypted result. Payment requires exact canonical Base evidence and two L2 confirmations; this is not Ethereum L1 finality. After an ambiguous payment response, keep the purchase identifiers and poll; never create another purchase or submit a new authorization to recover the same purchase. An optional POST {"transaction":"0x..."} to /reconcile supplies a hash for server verification. 6. Failed conversion enters refund_required/refunding/refund_unknown until the refund is confirmed. Only refunded with refund_transaction means the repayment was verified. An unavailable network or facilitator can delay a refund; the service retains the obligation and retries using the same transfer nonce. 7. For delivery=available, decrypt sealed.data_base64 with AES-256-GCM, the 32 raw recovery-key bytes, Base64-decoded iv, and UTF-8 additional authenticated data purchase_id + ":" + request_sha256. The authentication tag is appended to the ciphertext. Verify the decrypted JSON against result_sha256, then verify output_sha256 and output_bytes. Save the file before recover_until. Future conversion payments in payment_first mode go to 0x4F6156f35486F50A2FDD38EA9A284392A87f9828. The full amount stays there until either a confirmed refund or a validated, durably saved conversion result. Only completed-order proceeds are sent to the existing treasury. Other products and old purchases retain their original recipient and recovery contract. Legacy purchases identified by legacy_prepare_first or the absence of flow retain preparation before payment, their original quote/result hashes and recovery deadlines (24 hours from preparation). While legacy mode is active, its published rolling preparation capacity still applies. Never change an existing purchase's destination or submit a second payment to migrate it. Download /downloads/datoqa-conversion-client.mjs (Node.js 24+, dependencies bundled), its .sha256 and /downloads/conversion-client-notices.txt. Commands: prepare request.json NEW_DIRECTORY; pay DIRECTORY WALLET_JSON --approve-one-purchase --max-usdc 0.01 (or 0.02 for that tier); recover DIRECTORY. Use a dedicated funded Base USDC wallet JSON with a privateKey field. Preparation never pays. Payment requires explicit approval and checks the exact recipient, network and price ceiling. The client saves the recovery journal before upload and the signed authorization before submission. After an uncertain response, recover the same purchase; never create a replacement authorization. An explicit retry reuses the saved authorization while valid. Keep purchase.private.json, payment.private.json and the wallet file private. Recovery validates and decrypts the result without another payment. resume-preparation DIRECTORY safely resumes the original preparation. Worked example: CSV to JSON (simple tier, 0.01 USDC) Save this as request.json: {"inputs":[{"format":"csv","data_base64":"bGFiZWwsdmFsdWUKYWxwaGEsb25lCmJldGEsdHdvCg=="}],"output_format":"json"} After downloading the client, run: node datoqa-conversion-client.mjs prepare request.json purchase-example Inspect the quote before approving payment. Only if you agree to spend up to 0.01 USDC, use your dedicated wallet file: node datoqa-conversion-client.mjs pay purchase-example wallet.private.json --approve-one-purchase --max-usdc 0.01 Then retrieve the result with: node datoqa-conversion-client.mjs recover purchase-example The source contains two rows: alpha/one and beta/two. Check both rows in the recovered JSON. If confirmation is pending (payment_unknown, settling or verifying), repeat recover with the same directory. HTTP 200 with a pending state does not yet mean conversion completion. Never create another purchase or authorize another payment to recover this one. Keep the wallet and private journals off public repositories and uploads. Save the output before the recovery deadline. The private conversion pilot remains closed. MCP availability does not authorize spending. Testnet validation does not constitute a mainnet payment.