regime · Listed · Found · 58 endpoints · Not used for Gateway
RelayShield
RelayShield
Security intelligence for agents. Wallet and counterparty screening, credential and breach exposure, infostealer logs, lookalike domains and SIM swap risk. Ever
Not used for Gateway
Listed — live manifest, not yet verified · not used for Gateway Still catalogued — dead/unreachable knowledge is index value. (Listed — live manifest, not yet verified · not used for Gateway)
Indexed from this operator's public /.well-known/x402.json. Found is not operator-owned and is not attested. Claim or opt out.
Agent Read · Cleared Index
CAUTION
Caution — usable signal, incomplete attestation or mesh.
confidence
67%
source
signal
Index before you pay. Same payload for agents:
GET /api/cleared/agent-read?slug=relayshield-7ko1
When to call
- Budget between $0.00 and $0.5 per call on published endpoints.
- Security intelligence for agents. Wallet and counterparty screening, credential and breach exposure, infostealer logs, lookalike domains and SIM swap risk. Ever
Risks
- Found — not operator-owned; claim status unknown.
- No Cleared settlement receipt on file yet.
- Endpoint response check pending or failed.
- No Gateway traffic yet — market share unproven.
Price posture
Published 58 endpoints from $0.00 to $0.5.
Category · Gateway
regime · no Gateway routes yet — early / unproven on Cleared market share.
Endpoint hints
POST /v1/payg/breachCheck whether an email address appears in known data breaches. Returns breach count, source names, dates, and exposed data types (passwords, emails, etc). Call
POST /v1/payg/bulk-identity-riskScore up to 10 organizational domains, each with up to 5 associated agent/employee emails, for combined breach/infostealer/session/CVE risk in one call. Built f
POST /v1/payg/cert-expiryCheck how many days remain before a domain's TLS certificate expires, via Certificate Transparency logs. Call to catch a lapsing certificate before it causes an
POST /v1/payg/domainScan a domain for phishing lookalikes: typosquats, homoglyphs, and common phishing registration patterns. Returns matched lookalike domains found in the wild. C
POST /v1/payg/identity-graphCorrelate an email address against the criminal breach/stealer corpus to surface linked phone numbers, secondary domains, and other identifiers tied to the same
POST /v1/payg/identity-risk-scoreReturn a 0-100 domain security score across 6 identity-risk dimensions (breach exposure, infostealer density, ransomware exposure, session exposure, CVE exposur
POST /v1/payg/infostealerCheck whether an email address's credentials were harvested by infostealer malware and appear in a criminal stealer-log marketplace, detected 24-72 hours ahead
POST /v1/payg/ip-intelLook up passive DNS resolution history and reputation for a domain or IP address. For a domain: which IPs it has resolved to over time. For an IP: which hostnam
Evidence (Cleared)
- → Intake listed · not used for Gateway
- → Trust 55/100 · fail · tier listed
- → Protocol x402
- → Manifest reachable · schema valid
- → Found listing — indexed from public x402.json, not operator-attested.
Endpoints
endpoint-1
$0.00POST https://api.relayshield.net/v1/payg/breachCheck whether an email address appears in known data breaches. Returns breach count, source names, dates, and exposed data types (passwords, emails, etc). Call before trusting a new user identity or granting elevated access.
endpoint-2
$0.00POST https://api.relayshield.net/v1/payg/bulk-identity-riskScore up to 10 organizational domains, each with up to 5 associated agent/employee emails, for combined breach/infostealer/session/CVE risk in one call. Built for enterprise AI-governance platforms scoring many identities per customer in one pass, the recommended entry point for agent-governance and identity-posture integrations.
endpoint-3
$0.00POST https://api.relayshield.net/v1/payg/cert-expiryCheck how many days remain before a domain's TLS certificate expires, via Certificate Transparency logs. Call to catch a lapsing certificate before it causes an outage, especially relevant as CA/Browser Forum rules shrink standard certificate lifespans toward 47 days by 2029.
endpoint-4
$0.00POST https://api.relayshield.net/v1/payg/domainScan a domain for phishing lookalikes: typosquats, homoglyphs, and common phishing registration patterns. Returns matched lookalike domains found in the wild. Call to detect brand-impersonation phishing campaigns targeting a company before they're reported elsewhere.
endpoint-5
$0.00POST https://api.relayshield.net/v1/payg/identity-graphCorrelate an email address against the criminal breach/stealer corpus to surface linked phone numbers, secondary domains, and other identifiers tied to the same compromised identity. Call to map the blast radius of a known compromise across an organization.
endpoint-6
$0.00POST https://api.relayshield.net/v1/payg/identity-risk-scoreReturn a 0-100 domain security score across 6 identity-risk dimensions (breach exposure, infostealer density, ransomware exposure, session exposure, CVE exposure, threat-actor targeting) with a letter grade and plain-English risk factors. Call as a single-number identity health check before onboarding, financing, or partnering with a domain.
endpoint-7
$0.00POST https://api.relayshield.net/v1/payg/infostealerCheck whether an email address's credentials were harvested by infostealer malware and appear in a criminal stealer-log marketplace, detected 24-72 hours ahead of public breach databases. Call to catch device-level compromise before stolen session cookies or saved passwords are used for account takeover.
endpoint-8
$0.00POST https://api.relayshield.net/v1/payg/ip-intelLook up passive DNS resolution history and reputation for a domain or IP address. For a domain: which IPs it has resolved to over time. For an IP: which hostnames have resolved to it, plus malicious/suspicious vendor detection counts. Call to pivot from an indicator to its infrastructure history during an investigation.
RelayShield llm-credential-exposure
$0.4POST https://api.relayshield.net/v1/payg/llm-credential-exposureCheck whether a domain's LLM/AI provider API keys (OpenAI, Anthropic, Google, Groq, xAI, Replicate) appear exposed in criminal stealer logs. This is LLMjacking, a fast-growing threat where a leaked key becomes a live, uncapped billing liability rather than just a data exposure. Call to catch an exposed key before the drain, not after the invoice. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, agent-security
RelayShield mcp-registry-risk
$0.35POST https://api.relayshield.net/v1/payg/mcp-registry-riskRelayShield mcp registry risk check · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield nft-security
$0.1POST https://api.relayshield.net/v1/payg/nft-securityScreen an NFT contract for known scam, wash-trading, or malicious-approval risk signals before your agent buys, bids on, or approves it. Returns risk level and risk flags plus basic collection metadata. Call before an autonomous agent interacts with an unfamiliar NFT contract. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield nhi-exposure
$0.4POST https://api.relayshield.net/v1/payg/nhi-exposureCheck whether API keys or tokens tied to a domain, used by non-human identities like AI agents, service accounts, or CI/CD, appear exposed in criminal stealer logs. Call to audit whether the credentials an autonomous agent relies on have already been compromised upstream. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, infostealer, sim-swap, agent-security · Built with @piprail/sdk
RelayShield oauth-watchlist
$0.3POST https://api.relayshield.net/v1/payg/oauth-watchlistCheck whether an email address has OAuth-connected app credentials exposed in a known SaaS breach (GitHub, Slack, Notion, Zapier, and 30+ other high-risk OAuth-capable apps). Returns matched apps and direct revoke-access links. Call to detect supply-chain credential exposure via connected apps. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield prompt-injection-breach
$0.35POST https://api.relayshield.net/v1/payg/prompt-injection-breachRelayShield prompt injection breach check · Keywords: x402, security, wallet-screening, crypto-security, sanctions, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield ransomware-risk
$0.4POST https://api.relayshield.net/v1/payg/ransomware-riskCheck whether a domain appears on a known ransomware group's victim/leak-site list, and whether pre-ransomware credential harvesting was detected beforehand. Call to assess active ransomware exposure for a domain, not just historical breach history. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, credentials, infostealer, sim-swap, agent-security · Built with @piprail/sdk
RelayShield scan-file
$0.1POST https://api.relayshield.net/v1/payg/scan-fileScan a file (via its public download URL) for malware using VirusTotal's multi-engine analysis. Returns an async analysis ID to poll. Call before an agent downloads, opens, or executes a file attachment from an untrusted source. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield scan-url
$0.05POST https://api.relayshield.net/v1/payg/scan-urlScan a URL for phishing or malware using heuristic signals (Google Safe Browsing, RDAP domain age, known IOC corpus) plus VirusTotal multi-engine analysis. Returns an async analysis ID to poll. Call before an agent clicks, fetches, or shares a link from an untrusted source. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, agent-security · Built with @piprail/sdk
RelayShield scan-wallet
$0.1POST https://api.relayshield.net/v1/payg/scan-walletScreen an EVM wallet address for known scam, exploit, or sanctions-list association before your agent transacts with it. Returns a risk level and specific risk flags. Call before an autonomous agent sends funds to or interacts with an unfamiliar wallet. · Keywords: x402, security, wallet-screening, crypto-security, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield secret-scan
$0.35POST https://api.relayshield.net/v1/payg/secret-scanScan public GitHub repositories, npm and PyPI packages, Docker Hub images, Hugging Face models and Spaces, and Postman public workspaces and collections for API keys, tokens and credentials already published against a domain. Repo-only scanners miss credentials shipped inside released packages and images. Every hit is verified against the credential pattern before it is reported. · Built with @piprail/sdk
RelayShield secret-scan-text
$0.05POST https://api.relayshield.net/v1/payg/secret-scan-textRelayShield secret scan text check · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield session-risk
$0.3POST https://api.relayshield.net/v1/payg/session-riskCheck whether an email address has an active stolen session cookie circulating in a criminal archive, a signal of account takeover that bypasses password resets and 2FA entirely. Call to detect AiTM/session-hijack attacks before an authenticated agent session is trusted. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield sim-swap
$0.25POST https://api.relayshield.net/v1/payg/sim-swapCheck whether a phone number has had a SIM swap or carrier port in the last 24 hours via real-time carrier lookup. A recent swap is a strong signal of an active account-takeover attempt targeting SMS-based 2FA. Call before trusting an SMS OTP from this number. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield supply-chain
$0.1POST https://api.relayshield.net/v1/payg/supply-chainCheck up to 10 vendor domains for combined breach, infostealer, and dark-web risk exposure in one call. Returns a composite risk score per vendor. Call to assess third-party API/vendor risk before an agent integrates with or continues calling an external service. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, credentials, sim-swap, agent-security · Built with @piprail/sdk
RelayShield target-risk
$0.5POST https://api.relayshield.net/v1/payg/target-riskScore a domain's probability of being an active or upcoming cyberattack target using a 6-signal correlation model (breach, infostealer, ransomware, session, CVE, and threat-actor targeting history). Call for proactive risk triage, not just after-the-fact breach checking. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, credentials, sim-swap, agent-security · Built with @piprail/sdk
RelayShield tech-stack-cve
$0.2POST https://api.relayshield.net/v1/payg/tech-stack-cveCheck a declared technology stack (e.g. nginx, WordPress, Cisco IOS) against actively-exploited CVEs (CISA KEV) and high-EPSS-score vulnerabilities. Call before deploying or continuing to run a given technology stack in production. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield token-security
$0.05POST https://api.relayshield.net/v1/payg/token-securityScreen an ERC-20/BEP-20 token contract for honeypot, mintable-supply, hidden-owner, and other rug-pull risk signals before your agent trades it. Returns risk level, specific critical/warning flags, and basic token metadata. Call before an autonomous trading agent buys or approves spending on an unfamiliar token. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield wallet-risk
$0.05POST https://api.relayshield.net/v1/payg/wallet-riskScreen a wallet address across EVM, Solana, TON, or Bitcoin for known scam, exploit, drainer, or sanctions-list association before your agent transacts with it. Returns a risk level and specific risk flags. The recommended first call for any autonomous trading or DeFi agent before interacting with a new counterparty wallet. · Keywords: x402, security, wallet-screening, crypto-security, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
RelayShield wallet-screen-batch
$0.5POST https://api.relayshield.net/v1/payg/wallet-screen-batchScreen up to 10 wallet addresses (any chain: EVM, Solana, TON, Bitcoin) for known scam or exploit association in a single call. Returns per-address risk level and flags. Use for bulk counterparty screening in trading or portfolio-monitoring agent workflows. · Keywords: x402, security, wallet-screening, crypto-security, sanctions, breach, credentials, infostealer, sim-swap, domain, agent-security · Built with @piprail/sdk
Checks
reachable
valid
2026-08-25T18:02:57.410Z
Intake listed · Listed — live manifest, not yet verified · not used for Gateway · probed 0/3 · No settlement evidence found in chain signals.
Claim this listing to upgrade to Cleared attestation.
Claim listing