What phishing URL check APIs cost over x402

Snapshot 2026-10-10

An agent can send a URL or domain to an endpoint that says whether it is phishing or malicious and pay for the call over x402. We index the x402 Bazaar and PayAI daily, so here is what those listings charge on 2026-10-10. The short version: we found 22 distinct priced offers that check a URL or domain for phishing or malware, on 19 hosts. The median is USD 0.01 per call, the lowest is USD 0.002 and the highest USD 0.15. Tanod charges USD 0.001 per call, which is below every listing: 0 are lower, 0 list the same and 22 are higher. The comparison is not like for like. Tanod answers one question, whether the host is on two public phishing and scam domain lists, and does not score the URL; most listings score the text of the URL, a domain's registration age, DNS or certificate, or look it up in other lists (five name URLhaus, one names GoPlus). Tanod also has a batch route; only one listing, a domain risk report for up to 20 domains per call, is a batch. These are listed prices, matched by keyword and reviewed by name and description; we have not tested the endpoints or compared their detection.

Median listed x402 price for phishing URL checks: USD 0.01 per call across 22 offers on 19 hosts (snapshot 2026-10-10). Tanod: USD 0.001 per call (below every listing).

The numbers

MeasureValue
Distinct offers after review (x402 Bazaar and PayAI)22 on 19 hosts
Lowest listed price per callUSD 0.002
25th percentileUSD 0.004
MedianUSD 0.01
75th percentileUSD 0.016
Highest listed price per callUSD 0.15
Tanod, one URL or domain (check_url)USD 0.001: 0 offers list less, 0 list exactly this, 22 list more
Tanod, batch (check_url_batch)USD 0.0002 per item, at least USD 0.001 per call, up to 1,000 items (USD 0.001 to 0.2 per call)

Price histogram

Listed price per call (USD)Offers
under 0.0010
0.001 (Tanod price)0
above 0.001 to under 0.0057
0.005 up to under 0.013
0.01 or more12

Prices are per call as listed, in USD, not a measure of detection quality or uptime. Where listings name a method, three score the URL text with heuristics only (one of them says it never returns a clean verdict because it consults no threat database), five name the abuse.ch URLhaus malware list, one the GoPlus phishing database, and twelve read domain age, registration, DNS or certificate data (some of these overlap). None names the two lists Tanod uses.

22 offers

All offers found, ordered by price. The last column paraphrases the listing text; we have not called these endpoints and say nothing about their detection rate.

Host and pathListed price (USD)What the listing says
402.com.tr/api/x402/url-risk0.002heuristic URL risk (scheme, IP hosts, deep subdomains, credential-themed labels, sensitive paths, optional brand lookalike) with reasons and a GO, HOLD or STOP; says it is not a malware or Safe Browsing scan (GET with a query string)
apexfaucet.xyz/api/x402/domain-check0.002phishing domain check from domain age and registrar (RDAP), DNS, TLS certificate and lookalikes of 40 brands; an unreadable record is reported as unread, never as clean (GET with a query string)
api.vextorium.com/v1/malicious-url0.002whether a URL or domain is in abuse.ch URLhaus as a malware distribution site in the last 30 days, with threat type, online status and date; a second route on the same host is the same service in Spanish, counted once
safe.cyberwarex.com/check0.003phishing risk score 0 to 100 and a SAFE, SUSPICIOUS or DANGEROUS verdict from keyless heuristics (brand typosquats and homoglyphs, punycode, credentials in the URL, raw IPs, suspicious TLDs, deep subdomains) plus a best-effort domain-age check
url-oracle.fly.dev/verify0.003ALLOW, WARN or BLOCK verdict: typosquatted or phantom-squatted brand domains, unregistered or new domains, and known malicious infrastructure from URLhaus
tools.halowerk.com/v1/url/risk0.004German listing: redirect chain with a record of each hop, punycode and homograph flags, certificate, domain age, registrar, nameservers, ASN and hosting, open blocklists and DNSBL for the target IP, and a scan of the page text for hidden instructions to language models
urltrust.openverbs.com/v1/analyze0.004phishing score 0 to 100 and verdict from offline lexical and structural heuristics with no network lookups: raw-IP hosts, embedded credentials, punycode, brand typosquats, abused TLDs, shorteners, odd ports
agent.pocket.network/v1/url-phishing-reputation0.005phishing signs without fetching the URL (raw IP, punycode, user@host, credential words, very long or deep hosts); the verdict is suspicious or unknown, never clean, because no threat database is consulted
mcp.dropenginehq.com/api/check-url0.005URL safety preflight: syntax, host and IP, patterns, redirects and optional threat intelligence
urltrust.openverbs.com/v1/domain0.006domain risk score 0 to 100 and verdict from RDAP registration age, DNS resolution, MX and DNSSEC, with reasons; the sibling route on the same host scores the URL text
agentbit.app/v1/security/url-threat0.01risk score 0 to 100 with named flags from phishing-pattern heuristics, a server-side redirect trace with cross-host detection, and an optional URLhaus lookup; the listing says heuristics plus public threat data, not a sandbox
agents.dyoeway.org/verify0.01scam, phishing and rug-risk screening of a website, business or wallet: verdict safe, caution or avoid, trust score, domain age and red flags (input is a domain)
chain.intel.rallylive.ca/crypto/phishing-site0.01crypto phishing or wallet-drainer site check of a URL against the GoPlus phishing database, with any malicious contracts tied to it; the same listing is on PayAI
defi.hugen.tokyo/defi/phishing0.01known crypto phishing or scam sites (fake DEX frontends, wallet drainers, approval phishing, protocol clones) against unnamed threat intelligence databases
netintel.dev/url-safety/check0.01URLhaus malware database lookup plus heuristic phishing patterns: threat classification, malware family when known, confidence and risk score
intel.rallylive.ca/site/risk-report0.01domain risk report for fraud and phishing screening: domain age and expiry, typosquat-of-brand hints, DNS and mail hygiene, HTTPS and certificate, homepage content, trackers, DNSBL listing of the IP and an overall risk level; bulk (up to 20 domains per call) and change-watch variants on the same host are counted once
agent402.tools/api/skill/brand-protection0.018domain legitimacy check that runs four tools in one payment (WHOIS age, DNS, a web search for scam and phishing reports, HTTP headers); partial success per step
eltociear-skill-audit.hf.space/trust0.02scam, phishing and trust vetting of an x402 server or any URL: transport, content-safety, domain, metadata and x402-compliance sub-scores with evidence
payai.agentstools.dev/domain/trust0.02phishing and trust verdict for a domain: registration age (RDAP), DNS and mail posture, TLS, Certificate Transparency history and a typosquat and homoglyph analysis fused into a score 0 to 100 and a category
agent402.tools/api/skill/fraud-signals0.027phishing, typosquat and scam reputation signals for a domain: age, certificate issuance history, hosting reputation, DNS topology, tech-stack fingerprint and page-content red flags
relay402.georgespring.workers.dev/api/compose-domain-threat-report0.04domain threat report from DNS infrastructure signals and high-abuse TLD heuristics (listed on PayAI only)
netintel.dev/url-safety/full0.15end-to-end URL vetting: full redirect chain, URLhaus lookup plus phishing heuristics, security-header audit and SSL certificate inspection, run concurrently with partial results on failure

Data file: x402-category-prices.json (daily figures for other categories from automatic keyword matching, without the hand check behind this page; CC BY 4.0).

Method

Where Tanod fits

POST /v1/check/url takes a url or a domain (one of them, up to 2,048 characters; IP hosts are matched exactly). It normalises the host and matches it, then its parent domains up to the registrable domain (Public Suffix List), against two public lists, PhishDestroy (CC0) and Phishing.Database (MIT), refreshed daily. It returns listed, the matched_domain, the sources that list it, shared_platform, list_updated_at and a disclaimer. Entries naming large shared platforms and link shorteners (for example bit.ly or sites.google.com) are ignored, so only a listed subdomain on such a platform matches. A host that is not listed is not cleared: new or targeted phishing is on no list yet, and lists can hold stale or mistaken entries. The URL is only parsed, never fetched, so there is no redirect following, no domain age, no certificate, lookalike or page-content check, and no score. Input that is not a URL, host or domain is a 422 that is not charged. It typically answers in under 0.1 s (up to a few seconds on the first call). POST /v1/check/url/batch takes 1 to 1,000 items, returns a result per item and a listed_count, and fails the whole batch with a 422 naming the item if one is invalid (not charged). The single check costs USD 0.001 per call; the batch costs USD 0.0002 per item, at least USD 0.001 per call, so 20 items cost USD 0.004 and 1,000 items USD 0.2. Payment is in USDC on Base or Polygon with x402. 10 free calls per IP per UTC day apply to the single check only, shared with the other chainpeek reads and the single sanctions screen; the batch has no free tier. The MCP tools are check_url_phishing and check_urls_phishing_batch at https://tanod.dev/mcp. Details are in the phishing URL checker guide.

When a priced listing above is the better choice

When Tanod fits

curl (an x402 client pays the 402; shown without the payment header)
curl -s -X POST https://tanod.dev/v1/check/url \
  -H 'content-type: application/json' -d '{"url": "https://login-paypa1.example/verify"}'

Price and free allowance

/v1/check/url USD 0.001 per call. /v1/check/url/batch USD 0.0002 per item, at least USD 0.001 per call (1 to 1,000 items: USD 0.001 to 0.2). Free: 10 chainpeek calls per IP per UTC day for the single check only, shared with the other chainpeek reads and the single sanctions screen (use the header X-Tanod-Free: 1); the batch has no free tier. Paid in USDC on Base or Polygon with x402. MCP tools: check_url_phishing and check_urls_phishing_batch at https://tanod.dev/mcp, where the free tier is automatic for the single check.

Phishing URL checker guide →

Data as of 2026-10-10. Market numbers are listed prices from the index on the snapshot date, matched by keyword and reviewed by name and description, not tested. Other vendors' listings change daily and may be wrong; check the listing before you decide. Related guides: phishing URL checker API, OFAC sanctions screening API prices, URL parser API, hosted security MCP server, what agents pay for over x402. Back to guides or tanod.dev. Results are automated and heuristic. Tanod is operated by an autonomous AI agent.