{"uid":"cap_pW4oeGaTy4ja0eGvirqaB","slug":"session-risk-stolen-session-cookie-check-by-email-4a53cd6d","name":"Session Risk / Stolen Session Cookie Check by Email","description":"Check whether an email address has an active stolen session cookie circulating in a criminal archive — a signal of account takeover that bypasses password resets and 2FA entirely. Call to detect AiTM/session-hijack attacks before an authenticated agent session is trusted.","url":"https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod/v1/payg/session-risk","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"email":{"type":"string","description":"Email address to check for active session/AiTM exposure"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.3","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.3/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.3","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.3","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ETDKcqbwKwHHhgNVnXzar","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.3","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks whether an email address has an active stolen session cookie circulating in a criminal archive, signaling an account takeover via AiTM/session-hijacking attack.","exampleAgentPrompt":"Before I let this user proceed, check if the email address jsmith@acmecorp.com has any active stolen session cookies or AiTM-hijacked sessions showing up in criminal archives — I need to know the session count and highest severity.","exampleUseCases":[{"title":"Pre-login session hijack gate","prompt":"Before granting access to our internal dashboard, check whether the email alice@example.com has any active stolen session cookies circulating in criminal archives — flag it if anything shows up so we can step up authentication."},{"title":"Periodic agent trust verification","prompt":"Our AI agent is running on behalf of bob@company.com — can you check if that email has any live stolen session cookies in criminal archives right now? I want to make sure the session hasn't been silently hijacked."},{"title":"Security incident triage for compromised user","prompt":"We got an alert that carol@mybusiness.com might be targeted — check if her email has any active stolen session cookies or AiTM attack signals in criminal archives so we know if an account takeover is in progress."}],"resultDescription":"Returns a JSON object with: 'found' (boolean indicating whether active stolen sessions were found), 'sessions' (array of matching session records from criminal archives), 'session_count' (integer count of active stolen sessions), and 'highest_severity' (severity signal for the worst discovered session). Also echoes back the queried email address.","failureModes":["Email address not provided or malformed — returns validation error","Email not found in any criminal archive — returns found: false with empty sessions array","Criminal archive lookup timeout — may return error or incomplete results","Rate limit exceeded for pay-per-call endpoint","Network/API gateway error from AWS execute-api infrastructure"],"whenToPreferThis":"Use this endpoint when you need to detect active session cookie theft or AiTM (adversary-in-the-middle) attacks specifically — situations where password resets and 2FA are insufficient because the attacker holds a live authenticated session token. Prefer this over standard breach or credential checks when the threat model involves post-authentication session hijacking rather than password compromise. Ideal as a pre-trust gate for AI agent sessions, enterprise SSO flows, or high-value account actions.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T16:30:04.481Z","isFirstParty":false}