Developer API

Security intelligence
for developers & agents

Breach detection, SIM swap monitoring, infostealer exposure, domain lookalike scanning, and live threat intelligence — REST API, no monthly minimum, no commitments.

Unlike leading enterprise threat intelligence platforms that charge per API key and per user seat, RelayShield charges only for the calls you make. One API key, no seat fees, no per-user licensing.

Enter your email to get started. You'll be redirected to a secure checkout to save a card. Your API key arrives by email instantly.

No monthly minimum · Pay only for calls made · Cancel anytime

How billing works: There is no free tier, but there is no minimum spend either. You save a card to get your API key — you are only charged for calls you actually make. A test run of 10 breach checks costs $1.00. Most teams spend $0 in their first week while integrating. Threat Intelligence subscriptions ($499/$999/mo) are separate and billed monthly.
Endpoints & pricing
Pay only for what you use. Billed monthly via Stripe. No monthly minimum. Low-volume ad-hoc testing costs pennies — a 10-call integration test runs $0.10–$0.50 total.
/v1/metered/breach
$0.10 / call
Email breach check — breach name, date, and exposed data classes across 13B+ compromised accounts
/v1/metered/sim-swap
$0.25 / call
SIM swap detection via telco carrier lookup database — confirms whether a number has been ported or swapped, with carrier name and swap timestamp
/v1/metered/infostealer
$0.50 / call
Infostealer malware log check — a single infected device exposes every saved password across 50+ services simultaneously: banking credentials, credit card autofill, email, SaaS tools, and active session cookies that bypass 2FA. Returns infection date, OS, malware path, and at-risk service counts
/v1/metered/domain
$0.30 / call
Typosquat domain scan — active lookalikes via DNS + cert transparency
/v1/metered/oauth-watchlist
$0.30 / call
OAuth & token exposure — combines breach history watchlist with live stealer log corpus. Detects stolen credentials and OAuth tokens with category-level severity scores: cloud consoles and code repositories (CRITICAL), identity providers and payment processors (HIGH), productivity SaaS (MEDIUM)
/v1/metered/supply-chain
$0.10 / call
Vendor / supply chain risk — breach exposure + infostealer hits per vendor domain. Up to 10 domains per call. Returns per-domain risk score: CRITICAL · HIGH · MEDIUM · LOW
/v1/metered/session-risk
$0.30 / call
Active session hijack detection — identifies stolen session cookies in criminal stealer log archives before attackers use them. Detects AiTM attacks that bypass 2FA without needing the user's password. Returns severity-ranked results by service category
/v1/metered/identity-graph
$0.35 / call
Identity correlation — links an email to associated phone numbers and domains seen alongside it in criminal channel dumps. Pivot from one compromised identifier to find all others exposed in the same breach or stealer log
/v1/metered/ransomware-risk
$0.40 / call
Ransomware victim check — queries 100+ active ransomware group leak sites. Returns victim list status, responsible group(s), and count of pre-ransomware credentials found in stealer logs before the incident
/v1/metered/nhi-exposure
$0.40 / call
Non-human identity (NHI) detection — scans stealer log corpus for API keys, tokens, and machine credentials (AWS IAM keys, GitHub PATs, Stripe secrets, private keys, Slack tokens) linked to your domain or vendor supply chain domains
/v1/metered/secret-scan
$0.35 / call
GitHub/GitLab public repo secret detection — searches public code repositories for accidentally committed secrets (API keys, tokens, private keys) associated with a domain. Covers own domain and vendor supply chain domains
/v1/metered/target-risk
$0.50 / call
Target probability scoring — correlates 6 threat signals (ransomware victim listing, stealer log hits, breach exposure, criminal channel mentions, high-EPSS CVEs, pre-ransomware credentials) into a 0–100 risk score with 4-tier rating and recommended action
/v1/metered/crypto-intel
$0.30 / call
Crypto asset surface — wallet address risk, token honeypot & tax flags, NFT contract risk, counterparty screening across EVM, Solana, TON, and Bitcoin
/v1/metered/asset-intel
$0.15 / call
Asset watchlist & continuous monitoring — register domains and IPs for ongoing IOC surveillance. Actions: register assets, sweep all registered assets against 2.1M+ IOC corpus, list or remove. Webhook push alerts fire automatically when new IOCs match your registered assets
/v1/metered/threat-actor
$0.30 / call
Threat actor intelligence — two actions in one endpoint. exploit-chatter: detect pre-publication CVE PoC discussion in criminal channels before NVD/KEV publication, with EPSS score and KEV status. actor-lookup: track a threat actor or malware campaign (e.g. LummaC2, APT29) — returns IOC count, IOC breakdown by type, MITRE ATT&CK group info, aliases, and techniques
/v1/metered/cve-identity-risk
$0.40 / call
CVE × identity risk correlation — pass a CVE ID and domain to get a composite risk score (0–100) combining CISA KEV status, EPSS exploitation probability, infostealer corpus hits for exploiting malware families, ransomware victim listing, and exploit chatter signals. The only API that closes the loop from vulnerability to live identity exposure for a specific organization
/v1/metered/identity-risk-score
$0.35 / call
Domain identity risk score — a security credit score (0–100, grade A–F) for any domain across 6 dimensions: breach exposure, infostealer density, IOC corpus presence, ransomware victim listing, active session exposure, and CVE exposure. MSPs can embed this in client QBRs, insurance renewal reports, and onboarding risk assessments

🤗 Try the Agentic Attack Surface live on Hugging Face — no signup required to explore the MCP schema. Space · announcement post

/v1/metered/tech-stack-cve
$0.20 / call
Agent framework & tech stack exploit monitoring — pass a declared tech stack (or a domain to pull its stored stack) and get back CISA KEV / high-EPSS CVEs actively targeting it. Covers AI agent orchestration frameworks (Langflow, LangChain, AutoGPT, CrewAI, Flowise, n8n self-hosted) and their common companion infrastructure (Nacos, MinIO) — the exact vector used in the first documented autonomous-AI-agent ransomware operation (JadePuffer, July 2026)
/v1/metered/mcp-registry-risk
$0.35 / call
MCP server & agent-tool registry reputation — checks an MCP server URL or package name against RelayShield's criminal IOC corpus, typosquat/near-miss detection against well-known MCP domains, and domain registration age. Early-mover coverage for the MCP ecosystem, where dedicated security tooling is still minimal industry-wide
/v1/metered/prompt-injection-breach
$0.35 / call
Prompt-injection-sourced breach detection — flags stolen session/credential exposure whose source dump text suggests an AI agent (rather than a traditional phishing/malware campaign) was involved in obtaining it. A best-effort signal based on how the breach was described, not a confirmed attribution
/v1/metered/bulk-ioc
$0.50 / batch (up to 100 IOCs)
Bulk IOC enrichment — submit up to 100 indicators in a single call. Built for SIEM log-enrichment pipelines. Returns malware family, threat actor, confidence score, and first/last seen for each indicator
/v1/metered/ioc-pivot
$0.20 / call
IOC pivot — given one known-malicious indicator, discover all related infrastructure sharing the same malware family. Surfaces full C2 networks from a single indicator
/v1/metered/brand-monitor
$0.35 / call
Brand monitoring — scans the full IOC corpus for your brand name. Returns phishing domains, malware C2 infrastructure referencing your name, dark web mentions, and image/logo mentions extracted via OCR from infostealer-archive screenshots
/v1/metered/card-exposure
$0.30 / call
Stolen payment card exposure check — pass a client-computed SHA-256 hash of a card number, or just a 6-8 digit BIN, to check against RelayShield's stolen-card corpus (sourced from infostealer logs). RelayShield never accepts or stores a raw card number
/v1/metered/bulk-identity-risk
$2.00 / call
Hierarchical org + agent-level risk scoring — up to 10 organizational domains plus up to 5 agent/service-account identities per domain in a single call. Each domain returns a 0–100 risk score across 6 dimensions; each agent identity returns breach, infostealer, and stolen-session signals. A critically exposed agent automatically elevates the organizational risk rating. Purpose-built for MSP weekly client sweeps and AI agent governance use cases
/v1/metered/cert-expiry
$0.05 / call
TLS certificate expiry & renewal risk — checks Certificate Transparency logs for how many days remain before a domain's live certificate expires. Returns a 4-tier risk level (CRITICAL/HIGH/MEDIUM/LOW) and a plain-English recommendation. Increasingly relevant as CA/Browser Forum rules shrink standard certificate lifespans toward 47 days by 2029
/v1/metered/ip-intel
$0.10 / call
Passive DNS & IP reputation — pass a domain to get its historical IP resolution history plus reputation, or pass an IP to get reverse resolution history (hostnames that have pointed to it), AS owner, country, and malicious/suspicious vendor detection counts
Threat Intelligence API NEW

RelayShield's edge is OSINT threat hunting most vendors can't reach — our own collection pipeline runs continuous, verified monitoring across 122 active criminal Telegram channels (infostealer markets, credential dumps, breach announcements), not a static feed subscription. That's layered with 3.2M+ indicators aggregated from 17 authoritative external sources (abuse.ch, Spamhaus, AbuseIPDB, AlienVault OTX, PhishTank, CISA KEV, MITRE ATT&CK/ATLAS, and more). Emails, domains, IPs, hashes, phone numbers, and wallet addresses — 24–72 hours ahead of public breach databases.

All 26 metered endpoints included. Both TI subscription tiers cover unlimited access to all metered API endpoints above — breach, SIM swap, infostealer, domain, OAuth & token exposure, supply chain, session hijack detection, crypto asset surface, asset intel monitoring, threat actor intelligence, CVE × identity risk correlation, domain identity risk scoring, bulk IOC enrichment, IOC pivot, brand monitoring, bulk identity risk, agent framework exploit monitoring, MCP registry risk, prompt-injection breach detection, certificate expiry risk, and passive DNS/IP reputation — in addition to the Threat Intelligence IOC and CVE feeds. No per-endpoint add-ons. One subscription, full access.

MSP — $499/mo MSSP — $999/mo
Calls / month 10,000 Unlimited
IOC types Email · Phone · Domain · Wallet
Intel sources Criminal Telegram channels, ThreatFox, URLhaus, CISA KEV, Feodo Tracker, AbuseIPDB, MalwareBazaar, PhishTank, Emerging Threats, AlienVault OTX
Lead time vs HIBP 24–72 hours
Rate limit ~333 calls/day None
Support Standard email Priority + SLA
Best for SOC teams, SOAR playbooks, incident response MSSPs with continuous multi-client monitoring
/v1/intel/telegram
$499 / mo
In-house SOC teams — up to 10,000 calls/month across all endpoints. Includes IOC lookup, CVE intelligence, and all 8 metered endpoints. Embed in SOAR playbooks, SIEM enrichment, or incident response workflows.
Subscribe — $499/mo
/v1/intel/telegram
$999 / mo
MSSPs & MDRs — unlimited calls across all endpoints, priority support + SLA. Includes IOC lookup, CVE intelligence, and all 8 metered endpoints. For teams running continuous enrichment pipelines across multiple client environments.
Subscribe — $999/mo
CVE & Ransomware Intelligence

Look up CISA Known Exploited Vulnerabilities by CVE ID or keyword — cross-referenced for active ransomware campaign activity. Included on all TI subscription tiers.

POST /v1/intel/cve
Exact CVE ID lookup
{"cve_id": "CVE-2024-1234"}
POST /v1/intel/cve
Keyword scan — vendor, product, or CVE name
{"keyword": "apache"}
Response includes: CVE ID · vendor/product · vulnerability name · date added to KEV · ransomware_campaign_use flag · known ransomware groups
Automated Feed Formats — STIX/TAXII, MISP & SIEM/SOAR Push

Pull our IOC corpus with your SIEM's built-in TAXII client or MISP instance — no custom integration work, both require a TI subscription and support incremental pulls via added_after + pagination. Or configure a destination once and have real-time findings pushed to you as they fire.

GET /v1/intel/taxii/*
STIX 2.1 compliant feed — Indicator objects for Splunk, Sentinel, Elastic, or QRadar's built-in TAXII client.
GET /v1/intel/misp/event
Native MISP Event JSON with tagged Attributes — the default/co-primary format for government, CERT/ISAC, and mid-market SOC tooling that STIX-only integration doesn't reach.
POST /v1/siem/configure
Push delivery to Splunk HEC, CEF/QRadar, or Cortex XSOAR's Generic Webhook incident-creation shape — configure a destination once, then real-time findings from breach, domain, infostealer, SIM swap, OAuth, and dark-web-channel monitoring dispatch automatically, no polling required.
Shareable Report Links

Turn any wallet scan, domain check, or vendor sweep result into a persistent, shareable URL. Generation requires a subscription; viewing the resulting link is public with no login required — paste it into a client ticket or incident report.

POST /v1/report/share
Returns a report_id and public share_url for the summary you submit.
Quick start
# Breach check
curl -X POST https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod/v1/metered/breach \
  -H "X-RS-API-KEY: rs_live_your_key_here" \
  -H "Content-Type: application/json" \
  -d '{"email": "user@example.com"}'

# Response
{
  "ok": true,
  "data": {
    "email": "user@example.com",
    "breach_count": 3,
    "breaches": [{ "name": "LinkedIn", "breach_date": "2021-06-22", ... }]
  }
}
Python sample — breach + infostealer in sequence

Copy-paste to run immediately. No SDK required — standard library only.

import urllib.request, json

API_KEY = "rs_live_your_key_here"
BASE    = "https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod"

def rs_post(path, payload):
    data = json.dumps(payload).encode()
    req  = urllib.request.Request(
        f"{BASE}{path}",
        data=data,
        headers={"Content-Type": "application/json", "X-RS-API-KEY": API_KEY},
    )
    with urllib.request.urlopen(req, timeout=10) as r:
        return json.loads(r.read())

email  = "user@example.com"
breach = rs_post("/v1/metered/breach", {"email": email})
print(f"Breaches: {breach.get('breach_count', 0)}")

if breach.get("breach_count", 0) > 0:
    stealer = rs_post("/v1/metered/infostealer", {"email": email})
    print(f"Infostealer exposure: {stealer.get('exposed', False)}")
    if stealer.get("exposed"):
        print(f"  Markets: {stealer.get('markets', [])}")
        print("  ACTION: credential reset + session revocation")
Agent framework SDKs

MCP registry-risk and prompt-injection-breach checks, plus a mandatory pre-execution gate, packaged natively for the agent frameworks you're already building on.

OpenAI Agents SDK

pip install openai-agents-relayshield View on GitHub →

LangChain

pip install langchain-relayshield View on GitHub →

Vercel AI SDK

npm install ai-sdk-relayshield View on GitHub →

LlamaIndex

pip install llamaindex-relayshield View on GitHub →
What practitioners are building
n8n

n8n-nodes-relayshield is verified and available directly on n8n Cloud — search for it on the canvas, no manual install needed.

Featured in n8n's official template gallery

“Check new-hire identity risk and provision Google Workspace accounts with RelayShield” — HR webhook → parallel breach/infostealer checks → Google Workspace provisioning → Notion + Slack. creators.n8n.io/workflows/17255

View template →

“Nice work! You could extend this to trigger when an employee is deactivated in your HR system — run breach + infostealer checks on offboarding, then log to Notion or alert Slack if their credentials are circulating.”

— n8n community member, on the RelayShield breach monitoring workflow template

Used in SOAR playbooks, SIEM enrichment pipelines, MSP onboarding/offboarding automations, and incident response triage workflows. Tell us what you're building.