Reference
HTTP API
The endpoints behind the site — openapi.json is the authority; this is the tour.
Everything the site does rides a plain HTTP API. The machine-readable authority is /api/openapi.json — this page is the guided tour.
The error envelope
Every error response carries a machine-readable code and, where recovery exists, a next_action an agent can follow without reading prose:
{
"code": "LINK_EXPIRED",
"message": "This link has expired. Request a fresh link by email.",
"next_action": {
"method": "POST",
"endpoint": "/api/audit/aud_.../resend-link",
"body": { "email": "the email this audit was purchased with" }
}
}Scans & scores
| endpoint | what it does |
|---|---|
POST /api/scan | Run a pre-check on a URL; returns the full scored result. |
GET /api/score/{domain} | The stored result for a domain. |
GET /api/leaderboard | Ranked domains, filterable and pageable. |
GET /api/badge/{domain} | The embeddable score badge (SVG). |
The audit lifecycle
| endpoint | what it does |
|---|---|
POST /api/audit/gate | Exchange your email for a short-lived plan-generation token (plan generation live-probes your target, so it isn't anonymous). |
POST /api/audit/plan | Generate the evaluation plan for a target; returns the scenario preview and audit id. |
POST /api/audit/checkout | Complete a drafted plan's payment (quoted/negotiated audits; self-serve checkout is currently by arrangement — see /contact). Requires explicit consent to the Terms. |
GET /api/audit/{id} | Full audit state: status, plan, results, published findings, evidence pointers. Signed-link auth (the token from your email). |
GET /api/audit/{id}/stream | Live progress as server-sent events while the audit runs. |
GET /api/audit/{id}/artifact | Download one evidence artifact (traces, logs, the report), scoped to your audit. |
POST /api/audit/{id}/rerun | Re-run the failing scenarios — optionally a subset, via {"scenarios": [...]}. |
POST /api/audit/{id}/credentials | Submit sealed credentials (see Credentials — values are encrypted in your browser). |
POST /api/audit/{id}/resend-link | Rotate and re-email your signed links if one leaked or expired. |
Auth model
There are no API keys to manage. Customer access rides signed links: the URL in your email carries a scoped, expiring token bound to your audit — results links can read and re-run, credential links can only submit credentials, and re-sending links revokes everything previously issued. Signing in (magic link) additionally puts your audits in a dashboard, but the API works fully from the signed links alone. The Fix Loop credential is the same machinery with an MCP-specific scope.