Catalog / company

amazonaws.com

20 agent-payable APIs. Every listing carries a tested call recipe - endpoint, auth shape, pricing, and known gotchas - on its detail page. amazonaws.com

APICategoryPrice / callUptime 30dStatusDocs
Breach API
Check whether an email address appears in known data breaches. Returns breach count, source names, dates, and exposed data types (passwords, emails, etc). Call before trusting a new user identity or granting elevated access.
-$0.10-listedcall recipe →
Bulk Identity Risk API
Score up to 10 organizational domains, each with up to 5 associated agent/employee emails, for combined breach/infostealer/session/CVE risk in one call. Built for enterprise AI-governance platforms scoring many identities per customer in one pass — the recommended entry point for agent-governance and identity-posture integrations.
-$2.00-listedcall recipe →
Check Whether API Keys Or Tokens Tied To A Domain API
Check whether API keys or tokens tied to a domain — used by non-human identities like AI agents, service accounts, or CI/CD — appear exposed in criminal stealer logs. Call to audit whether the credentials an autonomous agent relies on have already been compromised upstream.
-$0.40-listedcall recipe →
Identity Graph API
Correlate an email address against the criminal breach/stealer corpus to surface linked phone numbers, secondary domains, and other identifiers tied to the same compromised identity. Call to map the blast radius of a known compromise across an organization.
-$0.35-listedcall recipe →
Identity Risk Score API
Return a 0-100 domain security score across 6 identity-risk dimensions (breach exposure, infostealer density, ransomware exposure, session exposure, CVE exposure, threat-actor targeting) with a letter grade and plain-English risk factors. Call as a single-number identity health check before onboarding, financing, or partnering with a domain.
-$0.35-listedcall recipe →
Infostealer API
Check whether an email address's credentials were harvested by infostealer malware and appear in a criminal stealer-log marketplace — detected 24-72 hours ahead of public breach databases. Call to catch device-level compromise before stolen session cookies or saved passwords are used for account takeover.
-$0.15-listedcall recipe →
LLM Credential Exposure API
Check whether a domain's LLM/AI provider API keys (OpenAI, Anthropic, Google, Groq, xAI, Replicate) appear exposed in criminal stealer logs — LLMjacking, a fast-growing threat where a leaked key becomes a live, uncapped billing liability rather than just a data exposure. Call to catch an exposed key before the drain, not after the invoice.
-$0.40-listedcall recipe →
Mcp Registry Risk API
Assess an MCP server URL for supply-chain and registry risk before your agent connects to it or grants it tool-calling access — flags unverified publishers, known-malicious servers, and other trust signals. Call before an autonomous agent adds a new MCP server to its toolset.
-$0.35-listedcall recipe →
NFT Security API
Screen an NFT contract for known scam, wash-trading, or malicious-approval risk signals before your agent buys, bids on, or approves it. Returns risk level and risk flags plus basic collection metadata. Call before an autonomous agent interacts with an unfamiliar NFT contract.
-$0.10-listedcall recipe →
Prompt Injection Breach API
Check whether an email address tied to an AI agent session has an active stolen session or credential exposure that could enable a prompt-injection-driven account takeover. Call to audit whether an agent's own session integrity has already been compromised upstream, not just what the agent is being asked to do.
-$0.35-listedcall recipe →
Ransomware Risk API
Check whether a domain appears on a known ransomware group's victim/leak-site list, and whether pre-ransomware credential harvesting was detected beforehand. Call to assess active ransomware exposure for a domain, not just historical breach history.
-$0.40-listedcall recipe →
Scan A Domain For Phishing Lookalikes API
Scan a domain for phishing lookalikes — typosquats, homoglyphs, and common phishing registration patterns. Returns matched lookalike domains found in the wild. Call to detect brand-impersonation phishing campaigns targeting a company before they're reported elsewhere.
-$0.50-listedcall recipe →
Scan File API
Scan a file (via its public download URL) for malware using VirusTotal's multi-engine analysis. Returns an async analysis ID to poll. Call before an agent downloads, opens, or executes a file attachment from an untrusted source.
-$0.10-listedcall recipe →
Scan URL API
Scan a URL for phishing or malware using heuristic signals (Google Safe Browsing, RDAP domain age, known IOC corpus) plus VirusTotal multi-engine analysis. Returns an async analysis ID to poll. Call before an agent clicks, fetches, or shares a link from an untrusted source.
-$0.05-listedcall recipe →
Scan Wallet API
Screen an EVM wallet address for known scam, exploit, or sanctions-list association before your agent transacts with it. Returns a risk level and specific risk flags. Call before an autonomous agent sends funds to or interacts with an unfamiliar wallet.
-$0.10-listedcall recipe →
Secret Scan API
Scan public GitHub/GitLab repositories associated with a domain for exposed API keys, tokens, and credentials committed in source code. Call to detect a common supply-chain exposure vector before it's exploited.
-$0.35-listedcall recipe →
Session Risk API
Check whether an email address has an active stolen session cookie circulating in a criminal archive — a signal of account takeover that bypasses password resets and 2FA entirely. Call to detect AiTM/session-hijack attacks before an authenticated agent session is trusted.
-$0.30-listedcall recipe →
Sim Swap API
Check whether a phone number has had a SIM swap or carrier port in the last 24 hours via real-time carrier lookup. A recent swap is a strong signal of an active account-takeover attempt targeting SMS-based 2FA. Call before trusting an SMS OTP from this number.
-$0.25-listedcall recipe →
Token Security API
Screen an ERC-20/BEP-20 token contract for honeypot, mintable-supply, hidden-owner, and other rug-pull risk signals before your agent trades it. Returns risk level, specific critical/warning flags, and basic token metadata. Call before an autonomous trading agent buys or approves spending on an unfamiliar token.
-$0.05-listedcall recipe →
Wallet Risk API
Screen a wallet address across EVM, Solana, TON, or Bitcoin for known scam, exploit, drainer, or sanctions-list association before your agent transacts with it. Returns a risk level and specific risk flags. The recommended first call for any autonomous trading or DeFi agent before interacting with a new counterparty wallet.
-$0.05-listedcall recipe →
Call these APIs - Get API Key →Back to catalog