{"uid":"cap_EWVDRPJy-ZxxFH00wWIsS","slug":"llm-credential-exposure-check-d34effb0","name":"LLM Credential Exposure Check","description":"Check whether a domain's LLM/AI provider API keys (OpenAI, Anthropic, Google, Groq, xAI, Replicate) appear exposed in criminal stealer logs — LLMjacking, a fast-growing threat where a leaked key becomes a live, uncapped billing liability rather than just a data exposure. Call to catch an exposed key before the drain, not after the invoice.","url":"https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod/v1/payg/llm-credential-exposure","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"Your own domain"},"vendor_domains":{"type":"array","items":{"type":"string"},"description":"Optional: vendor/supply-chain domains, up to 10"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.4","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.4/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.4","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.4","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_mQoUV-R7EHyJYKXMCHXqU","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.4","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks whether a domain's AI/LLM provider API keys (OpenAI, Anthropic, Google, Groq, xAI, Replicate) have been harvested by infostealer malware and exposed in criminal stealer logs.","exampleAgentPrompt":"Check if our company domain acmecorp.com has any OpenAI, Anthropic, or other AI provider API keys showing up in criminal infostealer logs — I want to know before we get a surprise billing drain from LLMjacking.","exampleUseCases":[{"title":"Pre-breach AI key audit","prompt":"Before we renew our OpenAI and Anthropic subscriptions, can you check if acmecorp.com has any AI provider credentials exposed in stealer logs? I don't want to keep paying for keys that are already in criminal hands."},{"title":"Vendor AI credential vetting","prompt":"We're about to give a third-party vendor access to our AI pipeline — can you check if their domain techpartner.io has any LLM API keys showing up in infostealer databases? I want to make sure they haven't already been compromised."},{"title":"Incident response LLMjacking check","prompt":"We just got an unexpected spike on our OpenAI bill and I'm worried someone is LLMjacking us — can you check if startupxyz.com has any AI API key credentials exposed in stealer logs right now?"}],"resultDescription":"Returns whether the queried domain has LLM/AI provider API keys (OpenAI, Anthropic, Google, Groq, xAI, Replicate) appearing in criminal infostealer logs, indicating active LLMjacking risk. Likely includes which providers are affected, exposure signals, and severity or recency context.","failureModes":["Domain not found or unresolvable — no results returned","False negatives if stealer log coverage is incomplete for a given provider","No data available for very new or obscure domains","Rate limiting or payment failure at $0.40 USDC per call","API gateway timeout if stealer log database query is slow"],"whenToPreferThis":"Choose this endpoint when you need to specifically check whether AI/LLM provider API keys for a domain are exposed in infostealer logs — distinct from general credential breach checks. It is purpose-built for the LLMjacking threat vector (leaked keys being used for uncapped AI billing fraud) and covers major AI providers (OpenAI, Anthropic, Google, Groq, xAI, Replicate) explicitly. Prefer it over generic breach checkers when the risk you care about is unauthorized AI API usage and runaway billing, not just password exposure.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:52:28.960Z","isFirstParty":false}