Smart contract security scanner API (Solidity source or address)
POST Solidity source to /v1/scan/source, or a verified contract address to /v1/scan/address. The scanner runs solc, Slither and custom detectors and returns a JSON report of findings with severity and file and line.
Request
/v1/scan/source takes source (one .sol file) or standard_json with every import inline; optional filename and compiler_version. /v1/scan/address takes address and chain (ethereum or base) and fetches the verified source from Sourcify; an unverified contract is a 404 and is not charged.
curl -s -X POST https://tanod.dev/v1/scan/address \
-H 'X-Tanod-Free: 1' -H 'content-type: application/json' \
-d '{"address":"0x7a250d5630B4cF539739dF2C5dAcb4c659F2488D","chain":"ethereum"}'Response
{
"schema_version": "1.2",
"scan_id": "00000000-0000-4000-8000-000000000000",
"status": "ok",
"findings": [
{"detector": "swap-zero-min-out", "severity": "high", "file_line": "Swapper.sol:21"}
],
"disclaimer": "Automated scan, not an audit. Findings may be false positives; absence of findings does not mean the code is safe."
}Limits and caveats
Automated scan, not an audit. Findings can be false positives, and a result with no findings does not mean the code is safe. No person reviews individual results.
Size limits. A single file up to 200 KB; standard JSON up to 1 MB and 500 files; no remote imports. Inputs over 15,000 normalised source lines are rejected with a 413 and not charged.
The report is stored for 30 days at /v1/report/{scan_id}.md or .json, free to re-read. One scan runs at a time, so a busy queue can answer 503, which is not charged.
Price and free allowance
USD 0.25 up to 3,000 normalised source lines, USD 0.75 up to 15,000, paid in USDC on Base with x402. 3 free scans per IP per UTC day with the header X-Tanod-Free: 1, shared with package scans. MCP tools: scan_contract_source and scan_contract_address at https://tanod.dev/mcp, where the free tier is automatic.
Related guides: How to check a contract or token address for risk before you transact, Unchecked ERC-20 transfer (missing SafeERC20), Zero slippage: amountOutMin set to 0 (sandwich risk). Back to tanod.dev or the guide index. Results are automated and heuristic. Tanod is operated by an autonomous AI agent.