ShieldAPI

active

x402-native security intelligence API for AI agents. Use ShieldAPI as the paid security/trust preflight before an agent pays, connects to MCP, installs packages or skills, opens URLs, delegates work, or executes untrusted instructions. Pay per request with USDC micropayments on Base. No accounts, no API keys. Add shieldapisource=<campaign or X-ShieldAPI-Source for pilot attribution.

AIBasex402 v2exactvainplex.dev ↗︎

Settled via Coinbase.

Transactions · 30d
10
Volume · 30d
$0.018
Unique buyers · 30d
8
Uptime · 30d
76.3%
Latency p50
292ms
Reported calls · 30d
7

Endpoints (27 live)

  • GET /api/cdp/check-email — ShieldAPI - x402 security preflight before agents trust an identity, sender, or email counterparty (0.005 USDC on Base)
  • GET /api/cdp/check/ip — ShieldAPI - x402 security preflight before agents connect to IP infrastructure (0.002 USDC on Base)
  • GET /api/cdp/check-password-range — ShieldAPI - x402 security preflight before agents accept or store credential material (0.001 USDC on Base)
  • POST /api/cdp/scan/skill — Scans CDP skills and returns skill-related insights. (0.02 USDC on Base)
  • POST /api/cdp/check/prompt — Checks prompts for safety and policy risks before use. (0.005 USDC on Base)
  • POST /api/cdp/check/mcp/trust — ShieldAPI - x402 security preflight before agents connect to MCP servers or grant tool access (0.02 USDC on Base)
  • POST /api/scan-skill — AI skill/plugin supply chain security scanner (8 categories) (0.02 USDC on Base)
  • GET /api/cdp/scan/skill (free)
  • GET /api/cdp/full/scan (0.01 USDC on Base)
  • GET /api/cdp/check/mcp/trust (free)
  • GET /api/check-domain (0.003 USDC on Base)
  • GET /api/cdp/check/prompt (free)
  • GET /api/cdp/check/package (0.01 USDC on Base)
  • GET /api/check-prompt (free)
  • GET /api/check-ip (0.002 USDC on Base)
  • GET /api/check-password-range (0.001 USDC on Base)
  • GET /api/check-url (0.003 USDC on Base)
  • GET /api/scan-skill (free)
  • GET /api/cdp/check/domain (0.003 USDC on Base)
  • GET /api/check-mcp-trust (free)

+7 more endpoints.

MCP tools (9)

ShieldAPI — Security Intelligence for AI Agents https://shield.vainplex.dev/mcp

  • shieldapi.check_domain — Check domain reputation: DNS records, blacklists (Spamhaus, SpamCop, SORBS), SPF/DMARC, SSL.
  • shieldapi.check_email — Check if an email address has been exposed in known data breaches via HIBP.
  • shieldapi.check_ip — Check IP reputation: blacklists, Tor exit node detection, reverse DNS.
  • shieldapi.check_password — Check if a password hash (SHA-1) has been exposed in known data breaches via HIBP.
  • shieldapi.check_password_range — Look up a SHA-1 hash prefix in the HIBP k-Anonymity database.
  • shieldapi.check_prompt — Detect prompt injection in text. Analyzes across 4 categories (direct injection, encoding tricks, exfiltration, indirect injection) with 200+ detection patterns. Designed for real-time inline usage before processing untrusted user input. Returns boolean verdict, confidence score (0-1), matched patterns with evidence, and decoded content if encoding obfuscation was detected. Response time <100ms p95.
  • shieldapi.check_url — Check a URL for malware, phishing, and other threats. Uses URLhaus + heuristic analysis.
  • shieldapi.full_scan — Run all security checks on a target (URL, domain, IP, or email). Most comprehensive scan.
  • shieldapi.scan_skill — Scan an AI agent skill/plugin for security issues across 8 risk categories (Snyk ToxicSkills taxonomy). Checks for prompt injection, malicious code, suspicious downloads, credential handling, secret detection, third-party content, unverifiable dependencies, and financial access patterns. Static analysis only — no code execution. Returns risk score (0-100), severity-ranked findings with file locations, and human-readable summary.

First seen · last seen · last active