other · Listed · eip155:8453 · Found · 7 endpoints · Gateway-eligible
api.trustsource.cc
trustsource
X402 endpoints at api.trustsource.cc.
Indexed from this operator's public /.well-known/x402.json. Found is not operator-owned and is not attested. Claim or opt out.
Agent Read · Cleared Index
ROUTE
Route when you need other at published x402 prices.
confidence
78%
source
signal
Index before you pay. Same payload for agents:
GET /api/cleared/agent-read?slug=cat-api-trustsource-cc
When to call
- Need other via x402 and want Cleared-indexed payTo with a live scorecard.
- X402 endpoints at api.trustsource.cc.
Risks
- Found — not operator-owned; claim status unknown.
- No Cleared settlement receipt on file yet.
- No Gateway traffic yet — market share unproven.
Price posture
7 endpoints — confirm price on manifest before pay.
Category · Gateway
other · no Gateway routes yet — early / unproven on Cleared market share.
Endpoint hints
GET /safefetchFetches a URL server-side and returns **sanitized, agent-ready text** plus a **prompt-injection risk verdict** (SAFE / REVIEW / BLOCK). Detects indirect prompt
GET /urlcheckOne call → one CLEAR / REVIEW / BLOCK verdict on any URL, fusing domain trust (WHOIS age, TLD risk, DNS, registrar), a live TLS certificate check, and typosquat
GET /emailtrustGrade a domain's email-auth posture (SPF, DKIM, DMARC, BIMI, MX) and report whether the sender can be spoofed. Returns an A–F grade, a `spoofable` flag, the par
GET /trustscoreReturns a 0–100 trust score for any domain or URL. Analyzes domain age (WHOIS), TLD risk, DNS presence, and registrar reputation. Returns structured JSON includ
GET /sslcheckLive TLS handshake to the target domain. Returns 0–100 SSL score, certificate chain details, expiry, trusted CA detection, TLS protocol version, cipher quality,
GET /headersFetches the target URL and audits HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-*
GET /robotsFetches and parses the target domain's robots.txt and detects policies across 24 known AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot, By
Evidence (Cleared)
- → Intake verified · Gateway-eligible
- → Trust 70/100 · pass · tier listed
- → Protocol x402 · eip155:8453
- → Manifest reachable · schema valid
- → Found listing — indexed from public x402.json, not operator-attested.
Endpoints
Injection-safe content fetch
$MeteredGET https://api.trustsource.cc/safefetchFetches a URL server-side and returns **sanitized, agent-ready text** plus a **prompt-injection risk verdict** (SAFE / REVIEW / BLOCK). Detects indirect prompt injection that an agent cannot detect itself without first ingesting it: instructions hidden in `display:none` elements, HTML comments, `alt` attributes and off-screen text; invisible Unicode-Tag (U+E0000) and zero-width smuggling; homoglyph-obfuscated and base64-encoded payloads; ChatML / `[INST]` delimiter spoofing; markdown-image data exfiltration; and tool-call bait. Findings are weighted by WHERE they occur — the same phrase is low-risk in visible prose (security blogs discuss injection constantly) and high-risk when concealed. The returned `content.text` has hidden elements and invisible control characters removed, so a model only ever sees what a human would see. **Payment:** 0.01 USDC per call via x402 (Base Mainnet). **Caching:** 10 minutes per URL.
Composite URL safety verdict
$MeteredGET https://api.trustsource.cc/urlcheckOne call → one CLEAR / REVIEW / BLOCK verdict on any URL, fusing domain trust (WHOIS age, TLD risk, DNS, registrar), a live TLS certificate check, and typosquat / lookalike-brand detection into a single graded 0–100 answer with human-readable reasons. Use before an agent clicks, fetches, submits data to, or transacts with a link — the go/no-go it can gate on. **Payment:** 0.01 USDC per call via x402 protocol (Base Mainnet). **Caching:** Results cached for 1 hour per domain.
Email-authentication posture grade
$MeteredGET https://api.trustsource.cc/emailtrustGrade a domain's email-auth posture (SPF, DKIM, DMARC, BIMI, MX) and report whether the sender can be spoofed. Returns an A–F grade, a `spoofable` flag, the parsed DMARC policy and SPF qualifier, and specific misconfiguration issues. Judge a sender domain before trusting an email, or confirm your own domain won't be silently rejected by Gmail/Yahoo/Microsoft's 2026 rules. **Payment:** 0.003 USDC per call via x402 protocol (Base Mainnet). **Caching:** Results cached for 6 hours per domain.
Domain trust and safety score
$MeteredGET https://api.trustsource.cc/trustscoreReturns a 0–100 trust score for any domain or URL. Analyzes domain age (WHOIS), TLD risk, DNS presence, and registrar reputation. Returns structured JSON including a tier (TRUSTED/MODERATE/CAUTION/HIGH_RISK), full scoring breakdown, and detailed signals. **Payment:** 0.003 USDC per call via x402 protocol (Base Mainnet). Clients must handle HTTP 402 responses by paying the specified amount and retrying with the payment proof header. **Caching:** Results are cached for 1 hour per domain.
SSL/TLS certificate intelligence
$MeteredGET https://api.trustsource.cc/sslcheckLive TLS handshake to the target domain. Returns 0–100 SSL score, certificate chain details, expiry, trusted CA detection, TLS protocol version, cipher quality, and security warnings. **Payment:** 0.002 USDC per call via x402 protocol (Base Mainnet). **Caching:** Results are cached for 6 hours per domain.
HTTP security header audit
Not used$MeteredGET https://api.trustsource.cc/headersFetches the target URL and audits HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-*). Returns a defense-in-depth letter grade A+ through F with per-header analysis and notes. **Note:** This is a hardening signal, not an active vulnerability scan. Many legitimate marketing sites grade F. **Payment:** 0.003 USDC per call via x402 protocol (Base Mainnet). **Caching:** Results cached up to 4 hours per URL.
robots.txt + AI bot policy detection
Not used$MeteredGET https://api.trustsource.cc/robotsFetches and parses the target domain's robots.txt and detects policies across 24 known AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot, Bytespider, and more). Returns parsed rules, sitemap URLs, and an AI-friendliness tier (OPEN / SELECTIVE / BLOCKED_AI / BLOCKED_ALL / NO_ROBOTS_TXT). **Payment:** 0.002 USDC per call via x402 protocol (Base Mainnet). **Caching:** Results cached up to 12 hours per domain.
Checks
reachable
valid
2026-10-08T02:01:45.154Z
No settlement evidence found in chain signals.
Gateway routing
Score ≥70/100 — Cleared attestation pass. Route via Gateway before pay.
Claim this listing to upgrade to Cleared attestation.
Claim listing