$0.01
per call · USD Coin on Base
Screen a URL before your agent follows it: phishing-pattern heuristics (IP-literal hosts, punycode, credentials in the URL, shorteners, deep subdomain nesting), a safe server-side redirect trace with cross-host detection, and an optional URLhaus malware-database lookup. Returns a 0-100 risk score with named flags. Honest scope: heuristics + public threat data, not a sandbox.
Endpoint
POST https://agentbit.app/v1/security/url-threat1
Calls / 30d
1
Unique payers / 30d
Sep 6
Last called
exact
Payment scheme
Call this service
import { wrapFetchWithPayment } from "@x402/fetch";
import { privateKeyToAccount } from "viem/accounts";
const account = privateKeyToAccount(process.env.PRIVATE_KEY);
const fetchWithPay = wrapFetchWithPayment(fetch, account);
const res = await fetchWithPay("https://agentbit.app/v1/security/url-threat", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
"url": "https://bit.ly/3example"
}),
});
const data = await res.json();curl -X POST \
"https://agentbit.app/v1/security/url-threat" \
-H "Content-Type: application/json" \
-d '{"url":"https://bit.ly/3example"}' \
-H "X-PAYMENT: <signed x402 payment>"Example response
{
"disclaimer": "Heuristic and public-threat-data screening, not a sandbox detonation.",
"flags": [
"URL_SHORTENER"
],
"host": "bit.ly",
"redirect_trace": {
"cross_host_redirect": true,
"final_status": 200,
"final_url": "https://example.com/",
"hops": [
{
"status": 301,
"url": "https://bit.ly/3example"
},
{
"status": 200,
"url": "https://example.com/"
}
],
"reachable": true
},
"risk": "clear",
"risk_score": 15,
"url": "https://bit.ly/3example",
"urlhaus": {
"checked": false,
"note": "Set a free abuse.ch Auth-Key in Settings to enable the URLhaus lookup."
}
}Payment details
0x4395c7e383b7e05665aad7f36ed77c01923dd965USD Coin · 0x833589fcd6edb6e08f4c7c32d4f71b54bda02913Is this your API?
Pin it to the top of Search & Web and the homepage with a featured placement.
More from Agentbit & similar services
Agentbit · Util Transform
agentbit.app
Deterministic utility operations for agents: sha256/sha512/HMAC hashing, JWT decode, base64 encode/decode, UUID generation, JSON validation, CSV↔JSON, XML→JSON, URL parsing and semver comparison. Sub-millisecond, no external calls.
Agentbit · Company Research
agentbit.app
One-call company due-diligence dossier: web-signal enrichment (technologies, socials, mail), recent news from live web search, website agent-readiness score and technical risk indicators (DNS, SSL, domain age). Normalized JSON — replaces 4–6 separate calls when researching a vendor, lead or counterparty.
Agentbit · Company Enrich
agentbit.app
Company enrichment from a domain: canonical name, website, description, detected technologies (CMS, e-commerce platform, analytics), social profiles and mail infrastructure (MX). Live signals read from the company website and DNS — no stale database.