ProfitCollector Utility API

active

Decision-grade security/due-diligence outcome reports ($20-$100) plus deterministic paid utilities ($0.001+) for software agents and automated workflows.

SearchBasex402 v2exactbakhour.ca ↗︎

Settled via Coinbase.

Transactions · 30d
7
Volume · 30d
$0.035
Unique buyers · 30d
4
Uptime · 30d
62.9%
Latency p50
46ms
Reported calls · 30d
3

Endpoints (45 live)

  • GET /dns/lookup — Resolve ONE DNS record type for a domain -- the cheapest, narrowest domain-check endpoint. For all record types at once, use /domain/intelligence. For a bundled DNS+TLS+headers audit, use /web/audit (raw) or /security/posture (scored). For mail-security plus a scored verdict, use /domain/due-diligence. (0.005 USDC on Base)
  • POST /security/repo-risk-report/deep — Everything in the standard repository risk report, plus a repository-wide secret/credential exposure scan across the current tracked file tree (AWS keys, private key blocks, GitHub/Slack/Stripe tokens, generic high-entropy secrets). Findings report file, line, and pattern type only -- matched values are never returned by the server. (50 USDC on Base)
  • POST /x402/service-trust-report — One-shot trust report on any x402-protected endpoint. Fetches its unpaid 402 challenge and checks: payment-requirements structure (valid scheme/network/asset/payTo/amount), the host's TLS certificate, whether the payTo address currently holds a nonzero on-chain balance of the payment asset (free Base RPC call), whether the priced asset is a recognized major stablecoin, whether the challenge's own 'resource' field actually points at the host you just queried (a real, concrete inconsistency when it doesn't), and -- when the seller publishes one -- whether its own '/.well-known/x402' discovery manifest agrees with what the live challenge just returned (payTo/price cross-check). No payment is ever sent to the target being checked. Different from an aggregate reputation-tier lookup: this is a live, on-demand technical check of the ONE target you're about to pay right now, not a cached historical score across many services. Built for a buyer agent about to sign a payment authorization to an unfamiliar x402 seller and wanting a second opinion before it pays -- compute this yourself and you still need a free Base RPC call plus TLS/manifest fetch logic; this returns the interpreted verdict in one call. (0.02 USDC on Base)
  • POST /quebec/invoice-compliance-check — Quebec Bill 96 / QST invoice-compliance check: verifies GST (5%) and QST (9.975%) were each calculated correctly on the subtotal per Revenu Quebec's current formula (independent, NOT compounded -- that was the pre-2013 method), and flags whether a French version of the invoice text is present and structurally matches the other-language version's amounts, per Charter of the French Language s.57/89/91. Pure arithmetic + text check, no AI judgment: the tax check is exact; the language check states plainly what it can't verify (visual prominence, translation quality) rather than overclaiming. Not legal or tax advice -- flags likely issues for a professional to confirm. See github.com/sbakhour (docs/QC_INVOICE_CHECK_DUE_DILIGENCE.md in the ProfitCollector repo) for the sourced rules. (1.5 USDC on Base)
  • POST /data/transform — Automatically normalize and transform common structured text (0.01 USDC on Base)
  • POST /json/pretty — Pretty-print valid JSON (0.002 USDC on Base)
  • POST /json/validate — Validate JSON and return parsing details (0.002 USDC on Base)
  • POST /quebec/invoice-generate — Assembles a Quebec-aware bilingual invoice document: computes GST (5%) and QST (9.975%) exactly per Revenu Quebec's current formula, and lays out the French and English text you supply (both required per line item -- this does not translate) with French given structural equal-or-greater prominence per Charter of the French Language s.89/91. Returns structured JSON plus a ready-to-use HTML render. Different artifact from the compliance-check endpoint above: that inspects an invoice you already have, this assembles one you can actually send. Not legal or tax advice -- does not verify translation accuracy. See docs/QC_INVOICE_CHECK_DUE_DILIGENCE.md in the ProfitCollector repo for the sourced tax rules this reuses. (2.5 USDC on Base)
  • POST /base64/decode — Base64 decode UTF-8 text (0.001 USDC on Base)
  • POST /hash/sha256 — Generate SHA-256 hash from text (0.001 USDC on Base)
  • POST /text/stats — Calculate text statistics (0.002 USDC on Base)
  • POST /freshdep/scan — One-shot hosted freshdep scan: clones the given public repository, checks its root requirements.txt and/or package-lock.json for pinned dependency versions published more recently than a freshness threshold -- a lightweight tripwire against the 'hijacked maintainer account publishes a malicious release' pattern (event-stream, ua-parser-js, debug, stylus, litellm). Publish timestamps come straight from the official pypi.org/registry.npmjs.org registry APIs. The free, open-source freshdep CLI (github.com/sbakhour/freshdep) does the same check locally with no per-scan limit; this hosted version is the buy-it-once path for a one-off check without installing anything, bounded to the first 25 pinned dependencies found per scan. (25 USDC on Base)
  • POST /security/repo-risk-report/due-diligence — Everything in the deep repository risk report, plus real maintainer/project-health signals from OpenSSF Scorecard (commit activity, code review practice, branch protection, release signing, and more) and a composite, prioritized due-diligence summary with an overall recommendation. Built for pre-acquisition or pre-dependency technical triage -- human technical due diligence for a codebase typically costs $5,000-$95,000; this is an automated baseline, not a replacement for that review. (100 USDC on Base)
  • POST /hash/sha512 — Generate SHA-512 hash from text (0.001 USDC on Base)
  • POST /security/repo-risk-report/standard — Audit a public GitHub/GitLab repository's declared dependencies against the free, public OSV.dev vulnerability database and return an SBOM-style component inventory, real CVE/GHSA matches with severity and fixed versions, and a dependency freshness assessment. For a developer, security team, or agent deciding whether to depend on, acquire, or trust a codebase. (20 USDC on Base)
  • POST /text/dedupe-lines — Remove duplicate lines from text while preserving order (0.002 USDC on Base)
  • POST /media/image/convert — Convert and optionally resize a public HTTPS image into an AI/social-ready format (0.02 USDC on Base)
  • POST /json/minify — Minify valid JSON (0.002 USDC on Base)
  • POST /domain/due-diligence — The most comprehensive domain assessment: DNS + mail security (SPF/DKIM/DMARC) + TLS + HTTP headers, scored -- the ONLY endpoint in this group that adds mail-security analysis. Use this for a one-shot decision-grade verdict on an unfamiliar domain (e.g. vendor/counterparty due diligence); use /dns/lookup, /ssl/check, /security/headers, /web/audit or /security/posture instead when you only need one fact or a cheaper directional signal. (2 USDC on Base)
  • POST /base64/encode — Base64 encode UTF-8 text (0.001 USDC on Base)

+25 more endpoints.

First seen · last seen · last active