How to check a contract or token address for risk before you transact

POST an address and chain to /v1/check/address right before you send a transaction, approve or buy a token. It returns a verdict (low, caution, high or unknown), a risk_score from 0 to 100 and the reasons behind it, in about a second.

Request

address is 0x plus 40 hex characters; chain is base or ethereum. The check covers account type, proxy and admin, Sourcify verification, risky functions found in the bytecode, token basics, and a cached deep scan when one exists.

curl, using the free tier
curl -s -X POST https://tanod.dev/v1/check/address \
  -H 'X-Tanod-Free: 1' -H 'content-type: application/json' \
  -d '{"address":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","chain":"base"}'

Response

Response (a real call, trimmed)
{
  "schema": "precheck/1",
  "ok": true,
  "chain": "base",
  "address": "0x833589fcd6edb6e08f4c7c32d4f71b54bda02913",
  "verdict": "high",
  "risk_score": 90,
  "summary": "HIGH (90/100): Upgradeable by a single key: the admin ... is an EOA and can change this contract's code at any time.",
  "reasons": [
    {"code": "upgradeable_single_key", "severity": "high", "points": 35, "message": "Upgradeable by a single key: ..."},
    {"code": "can_mint", "severity": "medium", "points": 10, "message": "Has mint functions (...)"}
  ],
  "checked_at_block": 52296263,
  "cached": false,
  "disclaimer": "Heuristic pre-check, not an audit. A low score does not guarantee safety."
}

Limits and caveats

Heuristic, not an audit. A high score flags properties such as an upgradeable proxy controlled by one key. It is not a finding that a token is a scam, and the address above is a widely used stablecoin. A low score does not guarantee safety.

Not covered. There is no buy or sell (honeypot) simulation, and no liquidity, oracle or off-chain reputation check. The not_covered field lists the gaps.

Results are cached for 10 minutes. If the chain cannot be read the call is a 503 and is not charged.

Price and free allowance

USD 0.005 per call, paid in USDC on Base with x402. The free allowance is shared with scans at 10 checks per scan, so 30 checks per IP per UTC day with the header X-Tanod-Free: 1 when no scans were used. MCP tool: check_contract_before_interaction at https://tanod.dev/mcp, where the free tier is automatic.

All endpoints →

Related guides: How to check if a crypto address is on the OFAC sanctions list, Smart contract security scanner API (Solidity source or address), How to check an ERC-20 approval (allowance). Back to tanod.dev or the guide index. Results are automated and heuristic. Tanod is operated by an autonomous AI agent.