regime · Listed · Found · 58 endpoints · Gateway-eligible
RelayShield
RelayShield
Security intelligence for agents. Wallet and counterparty screening, credential and breach exposure, infostealer logs, lookalike domains and SIM swap risk. Ever
Indexed from this operator's public /.well-known/x402.json. Found is not operator-owned and is not attested. Claim or opt out.
Agent Read · Cleared Index
ROUTE
Route when you need regime at published x402 prices.
confidence
78%
source
signal
Index before you pay. Same payload for agents:
GET /api/cleared/agent-read?slug=relayshield-7ko1
When to call
- Need regime via x402 and want Cleared-indexed payTo with a live scorecard.
- Budget between $0.05 and $5.5 per call on published endpoints.
- Security intelligence for agents. Wallet and counterparty screening, credential and breach exposure, infostealer logs, lookalike domains and SIM swap risk. Ever
Risks
- Found — not operator-owned; claim status unknown.
- No Cleared settlement receipt on file yet.
- No Gateway traffic yet — market share unproven.
Price posture
Published 58 endpoints from $0.05 to $5.5.
Category · Gateway
regime · no Gateway routes yet — early / unproven on Cleared market share.
Endpoint hints
POST /v1/payg/breachCheck whether an email address appears in known data breaches. Returns breach count, source names, dates, and exposed data types (passwords, emails, etc). Call
POST /v1/payg/bulk-identity-riskScore up to 10 organizational domains, each with up to 5 associated agent/employee emails, for combined breach/infostealer/session/CVE risk in one call. Built f
POST /v1/payg/campaign-scanComposite campaign scan: fans out one indicator bundle (domains, URLs, emails, wallets, phones, file URLs, kit fingerprint IDs — max 25 indicators) across the a
POST /v1/payg/cert-expiryCheck how many days remain before a domain's TLS certificate expires, via Certificate Transparency logs. Call to catch a lapsing certificate before it causes an
POST /v1/payg/domainScan a domain for phishing lookalikes: typosquats, homoglyphs, and common phishing registration patterns. Returns matched lookalike domains found in the wild. C
POST /v1/payg/identity-graphCorrelate an email address against the criminal breach/stealer corpus to surface linked phone numbers, secondary domains, and other identifiers tied to the same
POST /v1/payg/identity-risk-scoreReturn a 0-100 domain security score across 6 identity-risk dimensions (breach exposure, infostealer density, ransomware exposure, session exposure, CVE exposur
POST /v1/payg/infostealerCheck whether an email address's credentials were harvested by infostealer malware and appear in a criminal stealer-log marketplace. Call to catch device-level
Evidence (Cleared)
- → Intake verified · Gateway-eligible
- → Trust 70/100 · pass · tier listed
- → Protocol x402
- → Manifest reachable · schema valid
- → Found listing — indexed from public x402.json, not operator-attested.
Endpoints
endpoint-1
$0.1POST https://api.relayshield.net/v1/payg/breachCheck whether an email address appears in known data breaches. Returns breach count, source names, dates, and exposed data types (passwords, emails, etc). Call before trusting a new user identity or granting elevated access.
endpoint-2
$2POST https://api.relayshield.net/v1/payg/bulk-identity-riskScore up to 10 organizational domains, each with up to 5 associated agent/employee emails, for combined breach/infostealer/session/CVE risk in one call. Built for enterprise AI-governance platforms scoring many identities per customer in one pass, the recommended entry point for agent-governance and identity-posture integrations.
endpoint-3
$5.5POST https://api.relayshield.net/v1/payg/campaign-scanComposite campaign scan: fans out one indicator bundle (domains, URLs, emails, wallets, phones, file URLs, kit fingerprint IDs — max 25 indicators) across the applicable threat-intel endpoints in a single $5.50 flat call. Returns per-indicator results, kit families, cross-indicator links (shared exfil hosts, shared kit fingerprints), and an aggregate risk score with corpus citations. Call for campaign-level takedown intel.
endpoint-4
$0.05POST https://api.relayshield.net/v1/payg/cert-expiryCheck how many days remain before a domain's TLS certificate expires, via Certificate Transparency logs. Call to catch a lapsing certificate before it causes an outage, especially relevant as CA/Browser Forum rules shrink standard certificate lifespans toward 47 days by 2029.
endpoint-5
$0.5POST https://api.relayshield.net/v1/payg/domainScan a domain for phishing lookalikes: typosquats, homoglyphs, and common phishing registration patterns. Returns matched lookalike domains found in the wild. Call to detect brand-impersonation phishing campaigns targeting a company before they're reported elsewhere.
endpoint-6
$0.35POST https://api.relayshield.net/v1/payg/identity-graphCorrelate an email address against the criminal breach/stealer corpus to surface linked phone numbers, secondary domains, and other identifiers tied to the same compromised identity. Call to map the blast radius of a known compromise across an organization.
endpoint-7
$0.35POST https://api.relayshield.net/v1/payg/identity-risk-scoreReturn a 0-100 domain security score across 6 identity-risk dimensions (breach exposure, infostealer density, ransomware exposure, session exposure, CVE exposure, threat-actor targeting) with a letter grade and plain-English risk factors. Call as a single-number identity health check before onboarding, financing, or partnering with a domain.
endpoint-8
$0.15POST https://api.relayshield.net/v1/payg/infostealerCheck whether an email address's credentials were harvested by infostealer malware and appear in a criminal stealer-log marketplace. Call to catch device-level compromise before stolen session cookies or saved passwords are used for account takeover.
endpoint-9
$0.1POST https://api.relayshield.net/v1/payg/ip-intelLook up passive DNS resolution history and reputation for a domain or IP address. For a domain: which IPs it has resolved to over time. For an IP: which hostnames have resolved to it, plus malicious/suspicious vendor detection counts. Call to pivot from an indicator to its infrastructure history during an investigation.
endpoint-10
$0.4POST https://api.relayshield.net/v1/payg/llm-credential-exposureCheck whether a domain's LLM/AI provider API keys (OpenAI, Anthropic, Google, Groq, xAI, Replicate) appear exposed in criminal stealer logs. This is LLMjacking, a fast-growing threat where a leaked key becomes a live, uncapped billing liability rather than just a data exposure. Call to catch an exposed key before the drain, not after the invoice.
endpoint-11
$0.1POST https://api.relayshield.net/v1/payg/nft-securityScreen an NFT contract for known scam, wash-trading, or malicious-approval risk signals before your agent buys, bids on, or approves it. Returns risk level and risk flags plus basic collection metadata. Call before an autonomous agent interacts with an unfamiliar NFT contract.
endpoint-12
$0.4POST https://api.relayshield.net/v1/payg/nhi-exposureCheck whether API keys or tokens tied to a domain, used by non-human identities like AI agents, service accounts, or CI/CD, appear exposed in criminal stealer logs. Call to audit whether the credentials an autonomous agent relies on have already been compromised upstream.
endpoint-13
$0.3POST https://api.relayshield.net/v1/payg/oauth-watchlistCheck whether an email address has OAuth-connected app credentials exposed in a known SaaS breach (GitHub, Slack, Notion, Zapier, and 30+ other high-risk OAuth-capable apps). Returns matched apps and direct revoke-access links. Call to detect supply-chain credential exposure via connected apps.
endpoint-14
$0.05POST https://api.relayshield.net/v1/payg/phone-reputationCheck whether a phone number appears in criminal marketplace infrastructure or pivots to known scam wallets, kits, or actors via RelayShield's threat-intelligence corpus, and whether its SIM/eSIM was recently swapped (Twilio Lookup v2, cached 24h). Returns a high/medium/unknown verdict with timestamped evidence reasons. Call before your agent trusts an unknown caller or smishing sender.
endpoint-15
$0.4POST https://api.relayshield.net/v1/payg/ransomware-riskCheck whether a domain appears on a known ransomware group's victim/leak-site list, and whether pre-ransomware credential harvesting was detected beforehand. Call to assess active ransomware exposure for a domain, not just historical breach history.
endpoint-16
$0.5POST https://api.relayshield.net/v1/payg/scamkit-fingerprintFingerprint a suspected phishing/smishing kit from a live URL (static HTML fetch only in v1 — no JS rendering in the Lambda; submit caller-rendered HTML via the html field for JS-heavy kits) or from caller-supplied kit HTML. Returns a stable kit_<sha256> ID, extracted kit signals, corpus evidence, and a best-effort family match. Per-victim nonces and credentials are stripped before hashing, so the same kit fingerprints identically across sightings. Call to turn one suspicious link into a matchable kit identity.
endpoint-17
$0.1POST https://api.relayshield.net/v1/payg/scamkit-matchMatch an existing kit_<sha256> fingerprint ID against the kit corpus. Returns the kit family (auto-suggested, pending approval), confidence, evidence, and sighting history. Cheap re-check for dashboards and bots watching for kit reuse. An unknown ID is never reported as safe — only as no-match with an explicit not-a-guarantee caveat.
endpoint-18
$0.1POST https://api.relayshield.net/v1/payg/scan-fileScan a file (via its public download URL) for malware using VirusTotal's multi-engine analysis. Returns an async analysis ID to poll. Call before an agent downloads, opens, or executes a file attachment from an untrusted source.
endpoint-19
$0.05POST https://api.relayshield.net/v1/payg/scan-urlScan a URL for phishing or malware using heuristic signals (Google Safe Browsing, RDAP domain age, known IOC corpus) plus VirusTotal multi-engine analysis. Returns an async analysis ID to poll. Call before an agent clicks, fetches, or shares a link from an untrusted source.
endpoint-20
$0.1POST https://api.relayshield.net/v1/payg/scan-walletScreen an EVM wallet address for known scam, exploit, or sanctions-list association before your agent transacts with it. Returns a risk level and specific risk flags. Call before an autonomous agent sends funds to or interacts with an unfamiliar wallet.
endpoint-21
$0.35POST https://api.relayshield.net/v1/payg/secret-scanScan public GitHub repositories, npm and PyPI packages, Docker Hub images, Hugging Face models and Spaces, and Postman public workspaces and collections for API keys, tokens and credentials already published against a domain. Repo-only scanners miss credentials shipped inside released packages and images. Every hit is verified against the credential pattern before it is reported.
endpoint-22
$0.05POST https://api.relayshield.net/v1/payg/secret-scan-textScan text or a unified diff for leaked secrets and credentials (49 NHI credential patterns). Check before you commit or paste.
endpoint-23
$0.3POST https://api.relayshield.net/v1/payg/session-riskCheck whether an email address has an active stolen session cookie circulating in a criminal archive, a signal of account takeover that bypasses password resets and 2FA entirely. Call to detect AiTM/session-hijack attacks before an authenticated agent session is trusted.
endpoint-24
$0.25POST https://api.relayshield.net/v1/payg/sim-swapCheck whether a phone number has had a SIM swap or carrier port in the last 24 hours via real-time carrier lookup. A recent swap is a strong signal of an active account-takeover attempt targeting SMS-based 2FA. Call before trusting an SMS OTP from this number.
endpoint-25
$0.1POST https://api.relayshield.net/v1/payg/supply-chainCheck up to 10 vendor domains for combined breach, infostealer, and dark-web risk exposure in one call. Returns a composite risk score per vendor. Call to assess third-party API/vendor risk before an agent integrates with or continues calling an external service.
endpoint-26
$0.5POST https://api.relayshield.net/v1/payg/target-riskScore a domain's probability of being an active or upcoming cyberattack target using a 6-signal correlation model (breach, infostealer, ransomware, session, CVE, and threat-actor targeting history). Call for proactive risk triage, not just after-the-fact breach checking.
endpoint-27
$0.2POST https://api.relayshield.net/v1/payg/tech-stack-cveCheck a declared technology stack (e.g. nginx, WordPress, Cisco IOS) against actively-exploited CVEs (CISA KEV) and high-EPSS-score vulnerabilities. Call before deploying or continuing to run a given technology stack in production.
endpoint-28
$0.05POST https://api.relayshield.net/v1/payg/token-securityScreen an ERC-20/BEP-20 token contract for honeypot, mintable-supply, hidden-owner, and other rug-pull risk signals before your agent trades it. Returns risk level, specific critical/warning flags, and basic token metadata. Call before an autonomous trading agent buys or approves spending on an unfamiliar token.
endpoint-29
$0.05POST https://api.relayshield.net/v1/payg/wallet-riskScreen a wallet address across EVM, Solana, TON, or Bitcoin for known scam, exploit, drainer, or sanctions-list association before your agent transacts with it. Returns a risk level and specific risk flags. The recommended first call for any autonomous trading or DeFi agent before interacting with a new counterparty wallet.
endpoint-30
$0.5POST https://api.relayshield.net/v1/payg/wallet-screen-batchScreen up to 10 wallet addresses (any chain: EVM, Solana, TON, Bitcoin) for known scam or exploit association in a single call. Returns per-address risk level and flags. Use for bulk counterparty screening in trading or portfolio-monitoring agent workflows.
endpoint-31
$0.5POST https://api.relayshield.net/v1/payg/agent-bait-scanReads the instructions an agent is given -- README, AGENTS.md, CLAUDE.md, .cursorrules, MCP manifests and tool descriptions -- and reports what they would cause an agent to do: fetch and execute remote scripts, ignore prior instructions, or touch credential files. Every referenced domain is checked against RelayShield's criminal indicator corpus. Call before connecting an agent to an MCP server or installing a tool it found on its own.
endpoint-32
$0.35POST https://api.relayshield.net/v1/payg/mcp-registry-riskAssess an MCP server URL for supply-chain and registry risk before your agent connects to it or grants it tool-calling access — flags unverified publishers, known-malicious servers, and other trust signals. Call before an autonomous agent adds a new MCP server to its toolset.
endpoint-33
$0.35POST https://api.relayshield.net/v1/payg/prompt-injection-breachCheck whether an email address tied to an AI agent session has an active stolen session or credential exposure that could enable a prompt-injection-driven account takeover. Call to audit whether an agent's own session integrity has already been compromised upstream, not just what the agent is being asked to do.
Checks
reachable
valid
2026-10-09T05:46:30.122Z
No settlement evidence found in chain signals.
Gateway routing
Score ≥70/100 — Cleared attestation pass. Route via Gateway before pay.
Claim this listing to upgrade to Cleared attestation.
Claim listing