{"uid":"cap_UfXhufy_xDI2D4zNV3ARZ","slug":"relayshield-llm-credential-exposure-scanner-59e403be","name":"RelayShield LLM Credential Exposure Scanner","description":"RelayShield Landing Site","url":"https://api.relayshield.net/v1/payg/llm-credential-exposure","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"Your own domain"},"vendor_domains":{"type":"array","items":{"type":"string"},"description":"Optional: vendor/supply-chain domains, up to 10"}}},"responseSchema":{"type":"json","example":{"ok":true,"data":{"found":false,"findings":[],"domains_checked":1,"highest_severity":null,"providers_affected":[]}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.4","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.4/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.4","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.4","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Cdi3W9QBaS4vb3dq9VUBN","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.4","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans a domain for exposed LLM API credentials (keys, tokens, secrets) and returns findings with severity levels and affected providers","exampleAgentPrompt":"Can you scan acmecorp.com for any exposed LLM API credentials — things like OpenAI keys, Anthropic tokens, or other AI provider secrets that might be visible on the site?","exampleUseCases":[{"title":"Pre-launch security audit for SaaS","prompt":"Before we go live, can you check startup-app.io for any accidentally exposed LLM API keys or AI provider credentials that might be visible on the domain?"},{"title":"Incident response credential check","prompt":"We just had a potential security incident — can you scan mybusiness.com right now to see if any LLM credentials like OpenAI or Hugging Face tokens are exposed, and tell me the severity?"},{"title":"Routine compliance monitoring","prompt":"Run a scan on devplatform.net to check if any LLM API keys or AI service credentials are leaking, and list which AI providers are affected if any are found."}],"resultDescription":"Returns a JSON object indicating whether any LLM credentials were found (found: boolean), an array of findings with details, the number of domains checked, the highest severity level among findings (or null if none), and a list of affected AI provider names.","failureModes":["Invalid or unreachable domain returns an error or empty findings","Network timeout if the target domain is slow to respond","False negatives if credentials are behind authentication walls","Rate limiting if the same domain is scanned too frequently","Malformed domain input may return a validation error"],"whenToPreferThis":"Choose this endpoint when you need to proactively detect exposed LLM/AI provider API keys and secrets on a specific domain — particularly useful for security audits, pre-deployment checks, or incident response. Prefer this over generic secret-scanning tools when the focus is specifically on LLM and AI service credentials (OpenAI, Anthropic, Hugging Face, etc.) rather than general secrets like database passwords or SSH keys.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:49:52.999Z","isFirstParty":false}