{"uid":"cap_jpOruqFLWpO_NfvMg7W4t","slug":"nhi-api-key-token-exposure-check-5eadbc1c","name":"NHI API Key & Token Exposure Check","description":"Check whether API keys or tokens tied to a domain — used by non-human identities like AI agents, service accounts, or CI/CD — appear exposed in criminal stealer logs. Call to audit whether the credentials an autonomous agent relies on have already been compromised upstream.","url":"https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod/v1/payg/nhi-exposure","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"Your own domain"},"vendor_domains":{"type":"array","items":{"type":"string"},"description":"Optional: vendor/supply-chain domains, up to 10"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.4","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.4/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.4","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.4","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_aoWfZOcqGGszoGOtHXZRw","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.4","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks whether API keys or tokens associated with a domain — used by non-human identities such as AI agents, service accounts, or CI/CD pipelines — have been exposed in criminal infostealer logs.","exampleAgentPrompt":"Check whether any API keys or tokens tied to acmecorp.com have shown up in criminal infostealer logs — I want to know if the credentials our AI agents and CI/CD pipelines use have been compromised.","exampleUseCases":[{"title":"Auditing AI agent credential safety","prompt":"Before we deploy our new AI agent to production, can you check if any API keys or tokens associated with our domain agentlabs.io have been exposed in stealer logs? I need to make sure the credentials it relies on haven't already been stolen."},{"title":"CI/CD pipeline token compromise check","prompt":"We had a security scare last week — can you scan whether any service account tokens or API keys linked to devops.mycompany.com appear in any known infostealer or criminal credential dumps?"},{"title":"Vendor NHI credential risk review","prompt":"We're onboarding a third-party integration from partnervendor.com and they'll have API access to our systems — can you check if their domain's non-human identity credentials have turned up in any stealer logs before we grant them access?"}],"resultDescription":"Returns whether API keys or tokens associated with the queried domain have been found in criminal infostealer logs, including details about the nature of the exposure, affected credential types, and risk indicators relevant to non-human identities like AI agents, service accounts, and CI/CD credentials.","failureModes":["Domain not found or unrecognized — returns no results","Invalid or missing domain input — returns 400 error","No stealer log data available for queried domain — empty result set","Rate limit exceeded — returns 429 error","Payment not processed — returns 402 error","Internal server error if upstream threat intelligence is unavailable — returns 500"],"whenToPreferThis":"Choose this endpoint when you specifically need to audit non-human identity credentials (API keys, tokens, service account secrets) for a domain against infostealer and criminal log databases — as opposed to checking human user passwords or email credentials. Ideal for pre-deployment security reviews of AI agent credentials, CI/CD pipeline audits, and third-party vendor NHI risk assessments.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:38:38.406Z","isFirstParty":false}