{"uid":"cap_NEbQKQIZm9gS0DBs1DhCr","slug":"tinstop-domain-security-audit-api-ce4bf677","name":"Tinstop Domain Security Audit API","description":"Tinstop is a machine-payable Website Intelligence API for domain security and performance audits: DNS, SSL/TLS, HTTP security headers, SPF/DKIM/DMARC email authentication, and Google PageSpeed. Pay per call with x402 using USDC on Base. No accounts or API keys.","url":"https://tinstop.com/v1/domain/audit","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"The domain name to audit (e.g. 'example.com'). Do not include http:// or https:// protocol prefixes."}}},"responseSchema":{"type":"object","title":"AuditResponse","required":["domain","score","subscores","issues","checks","audited_at","cached","scan_id"],"properties":{"score":{"type":"integer","title":"Score","description":"Calculated security risk score (0-100), where 100 is optimal"},"cached":{"type":"boolean","title":"Cached","description":"True if response was served from cache"},"checks":{"type":"object","title":"Checks","description":"Raw check results for DNS records, SSL certificates, headers, and email authentication","additionalProperties":true},"domain":{"type":"string","title":"Domain","description":"Audited domain name"},"issues":{"type":"array","items":{"type":"object","title":"AuditIssue","required":["severity","type","impact","fix"],"properties":{"fix":{"type":"string","title":"Fix","description":"Actionable recommendation to resolve the issue"},"type":{"type":"string","title":"Type","description":"Specific category identifier for the issue"},"impact":{"type":"string","title":"Impact","description":"Details regarding security impact"},"severity":{"type":"string","title":"Severity","description":"Issue severity: critical, high, medium, or low"}}},"title":"Issues","description":"Identified security issues and vulnerabilities"},"scan_id":{"type":"string","title":"Scan Id","description":"The unique database record tracking ID for this scan"},"subscores":{"type":"object","title":"Subscores","description":"Weighted category scores: dns (15%), ssl (30%), headers (25%), email (30%)","additionalProperties":{"type":"integer"}},"audited_at":{"type":"string","title":"Audited At","description":"ISO 8601 UTC timestamp of the audit request"},"request_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Request Id","description":"Gateway request tracking ID"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"registry","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_trMCRETaNqrRQAE3ytXSF","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a comprehensive security and performance audit of a domain, checking DNS, SSL/TLS, HTTP headers, SPF/DKIM/DMARC email authentication, and Google PageSpeed, returning a scored risk report with actionable issue fixes.","exampleAgentPrompt":"Can you run a full security audit on stripe.com and tell me the overall score, any critical or high-severity issues, and what I should fix first?","exampleUseCases":[{"title":"Pre-launch security check for new site","prompt":"Before we go live, can you audit the domain myStartupApp.io and give me a full security report — I want to know the overall score and any critical issues with SSL, DNS, or missing security headers?"},{"title":"Email deliverability troubleshooting","prompt":"Our emails keep landing in spam — can you audit acmecorp.com and check whether our SPF, DKIM, and DMARC records are properly configured, and tell me exactly what to fix?"},{"title":"Vendor security due diligence","prompt":"I need to evaluate a supplier's security posture — can you audit partnerdomain.com and show me its security score broken down by DNS, SSL, headers, and email authentication?"}],"resultDescription":"Returns a JSON object containing: an overall security score (0-100, 100 = optimal), weighted category subscores for DNS (15%), SSL (30%), headers (25%), and email authentication (30%), a list of identified issues with severity (critical/high/medium/low), human-readable impact descriptions, and actionable fix recommendations, plus raw check results, a unique scan ID, audit timestamp, and whether the response was served from cache.","failureModes":["Invalid domain format (including http:// prefix) — API likely returns a validation error","Domain does not exist or is unreachable — may return empty or partial check results","Payment failure via x402/USDC — request blocked if payment not confirmed","Rate limits or upstream DNS/SSL provider timeouts — may result in incomplete audit data","Cached responses returned for recently audited domains — data may not reflect very recent changes"],"whenToPreferThis":"Choose this endpoint when you need a comprehensive, multi-dimensional domain security audit in a single call without requiring an account or API key. It is ideal for agents that need to programmatically assess domain health covering DNS, SSL, email authentication, and HTTP headers together, rather than piecing together multiple specialized tools. The pay-per-call USDC model via x402 makes it suitable for on-demand, low-friction agent workflows where subscriptions are impractical.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:34:49.680Z","isFirstParty":false}