RelayShield API

active

Identity-compromise and threat-intelligence checks over a plain REST API. Every endpoint is POST, takes a JSON body, and returns a JSON envelope. Pay per call in USDC over x402 with no signup and no API key, or use a key with prepaid credits and a free tier of 100 calls. Screen a counterparty wallet, a token contract, an MCP server, a domain or an email against a corpus collected continuously…

AIBaseSolanax402 v2exactrelayshield.net ↗︎

Settled via Coinbase.

Transactions · 30d
2
Volume · 30d
$0.15
Unique buyers · 30d
2
Uptime · 30d
100.0%
Latency p50
40ms
Reported calls · 30d
7

Endpoints (31 live)

  • POST /v1/payg/breach — Check whether an email address appears in known data breaches. Returns breach count, source names, dates, and exposed data types (passwords, emails, etc). Call before trusting a new user identity or granting elevated access. (0.1 USDC on Solana)
  • POST /v1/payg/scan-url — Scan a URL for phishing or malware using heuristic signals (Google Safe Browsing, RDAP domain age, known IOC corpus) plus VirusTotal multi-engine analysis. Returns an async analysis ID to poll. Call before an agent clicks, fetches, or shares a link from an untrusted source. (0.05 USDC on Base)
  • POST /v1/payg/mcp-registry-risk — Assess an MCP server URL for supply-chain and registry risk before your agent connects to it or grants it tool-calling access — flags unverified publishers, known-malicious servers, and other trust signals. Call before an autonomous agent adds a new MCP server to its toolset. (0.35 USDC on Solana)
  • POST /v1/payg/secret-scan-text — Scan text or a unified diff for leaked secrets and credentials (49 NHI credential patterns). Check before you commit or paste. (0.05 USDC on Base)
  • POST /v1/payg/scamkit-fingerprint — Fingerprint a suspected phishing/smishing kit from a live URL (static HTML fetch only in v1 — no JS rendering in the Lambda; submit caller-rendered HTML via the html field for JS-heavy kits) or from caller-supplied kit HTML. Returns a stable kit_<sha256> ID, extracted kit signals, corpus evidence, and a best-effort family match. Per-victim nonces and credentials are stripped before hashing, so the same kit fingerprints identically across sightings. Call to turn one suspicious link into a matchable kit identity. (0.5 USDC on Base)
  • POST /v1/payg/scamkit-match — Match an existing kit_<sha256> fingerprint ID against the kit corpus. Returns the kit family (auto-suggested, pending approval), confidence, evidence, and sighting history. Cheap re-check for dashboards and bots watching for kit reuse. An unknown ID is never reported as safe — only as no-match with an explicit not-a-guarantee caveat. (0.1 USDC on Base)
  • POST /v1/payg/campaign-scan — Composite campaign scan: fans out one indicator bundle (domains, URLs, emails, wallets, phones, file URLs, kit fingerprint IDs — max 25 indicators) across the applicable threat-intel endpoints in a single $5.50 flat call. Returns per-indicator results, kit families, cross-indicator links (shared exfil hosts, shared kit fingerprints), and an aggregate risk score with corpus citations. Call for campaign-level takedown intel. (5.5 USDC on Base)
  • POST /v1/payg/ip-intel — Look up passive DNS resolution history and reputation for a domain or IP address. For a domain: which IPs it has resolved to over time. For an IP: which hostnames have resolved to it, plus malicious/suspicious vendor detection counts. Call to pivot from an indicator to its infrastructure history during an investigation. (0.1 USDC on Solana)
  • POST /v1/payg/cert-expiry — Check how many days remain before a domain's TLS certificate expires, via Certificate Transparency logs. Call to catch a lapsing certificate before it causes an outage, especially relevant as CA/Browser Forum rules shrink standard certificate lifespans toward 47 days by 2029. (0.05 USDC on Solana)
  • POST /v1/payg/scan-wallet — Screen an EVM wallet address for known scam, exploit, or sanctions-list association before your agent transacts with it. Returns a risk level and specific risk flags. Call before an autonomous agent sends funds to or interacts with an unfamiliar wallet. (0.1 USDC on Base)
  • POST /v1/payg/domain — Scan a domain for phishing lookalikes: typosquats, homoglyphs, and common phishing registration patterns. Returns matched lookalike domains found in the wild. Call to detect brand-impersonation phishing campaigns targeting a company before they're reported elsewhere. (0.5 USDC on Base)
  • POST /v1/payg/session-risk — Check whether an email address has an active stolen session cookie circulating in a criminal archive, a signal of account takeover that bypasses password resets and 2FA entirely. Call to detect AiTM/session-hijack attacks before an authenticated agent session is trusted. (0.3 USDC on Base)
  • POST /v1/payg/secret-scan — Scan public GitHub repositories, npm and PyPI packages, Docker Hub images, Hugging Face models and Spaces, and Postman public workspaces and collections for API keys, tokens and credentials already published against a domain. Repo-only scanners miss credentials shipped inside released packages and images. Every hit is verified against the credential pattern before it is reported. (0.35 USDC on Solana)
  • POST /v1/payg/scan-file — Scan a file (via its public download URL) for malware using VirusTotal's multi-engine analysis. Returns an async analysis ID to poll. Call before an agent downloads, opens, or executes a file attachment from an untrusted source. (0.1 USDC on Solana)
  • POST /v1/payg/target-risk — Score a domain's probability of being an active or upcoming cyberattack target using a 6-signal correlation model (breach, infostealer, ransomware, session, CVE, and threat-actor targeting history). Call for proactive risk triage, not just after-the-fact breach checking. (0.5 USDC on Base)
  • POST /v1/payg/supply-chain — Check up to 10 vendor domains for combined breach, infostealer, and dark-web risk exposure in one call. Returns a composite risk score per vendor. Call to assess third-party API/vendor risk before an agent integrates with or continues calling an external service. (0.1 USDC on Solana)
  • POST /v1/payg/token-security — Screen an ERC-20/BEP-20 token contract for honeypot, mintable-supply, hidden-owner, and other rug-pull risk signals before your agent trades it. Returns risk level, specific critical/warning flags, and basic token metadata. Call before an autonomous trading agent buys or approves spending on an unfamiliar token. (0.05 USDC on Base)
  • POST /v1/payg/ransomware-risk — Check whether a domain appears on a known ransomware group's victim/leak-site list, and whether pre-ransomware credential harvesting was detected beforehand. Call to assess active ransomware exposure for a domain, not just historical breach history. (0.4 USDC on Solana)
  • POST /v1/payg/nhi-exposure — Check whether API keys or tokens tied to a domain, used by non-human identities like AI agents, service accounts, or CI/CD, appear exposed in criminal stealer logs. Call to audit whether the credentials an autonomous agent relies on have already been compromised upstream. (0.4 USDC on Solana)
  • POST /v1/payg/wallet-screen-batch — Screen up to 10 wallet addresses (any chain: EVM, Solana, TON, Bitcoin) for known scam or exploit association in a single call. Returns per-address risk level and flags. Use for bulk counterparty screening in trading or portfolio-monitoring agent workflows. (0.5 USDC on Base)

+11 more endpoints.

First seen · last seen · last active