Check a URL for phishing signs without fetching it
Check a URL for phishing signs without fetching it: raw IP hosts, punycode, user@host, credential words in the host, very long hosts and deep subdomains. The verdict is suspicious or unknown, never clean, because no threat database is consulted; the response says what ran. POST /v1/reputation with {url}. Pay per request in USDC; no account, no API key.
Answeringour last check, 2026-10-10
1 of 1checks answered this week
905 msmedian answer time
$0.005listed price per call
$0.005price it asked us
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://agent.pocket.network/v1/url-phishing-reputation
| Category | Everything else |
|---|---|
| Provider host | agent.pocket.network |
| Networks | eip155:8453 |
| Payment schemes | exact |
| Self-reported calls, 30 days | 32 from 3 payers (the provider's figure, not ours) |
Our checks, last 30 days
| Day | Result | HTTP | Asked | Time |
|---|---|---|---|---|
| 2026-10-10 | valid payment request | 402 | $0.005 | 905 ms |
Example input (from the provider)
{
"body": {
"url": "http://192.168.1.1/login"
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"description": "The body of POST /v1/reputation.",
"properties": {
"url": {
"description": "The URL to check (http or https). It is not fetched.",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST",
"PUT",
"PATCH"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"properties": {
"data": {
"description": "For POST /v1/reputation, a JSON object with url, host, verdict (malicious, suspicious, clean or unknown), heuristics, threat_matches, checked_sources (each source and whether it ran) and verdict_scope. A bad request answers 400 with an `error` string. Properties are pinned from live paid responses; nothing is required, because every route's 2xx response is validated against this one schema.",
"properties": {
"checked_sources": {
"items": {
"properties": {
"source": {
"type": "string"
},
"status": {
"type": "string"
}
},
"type": "object"
},
"type": "array"
},
"heuristics": {
"items": {
"type": "string"
},
"type": "array"
},
"host": {
"type": "string"
},
"service": {
"type": "string"
},
"threat_matches": {},
"url": {
"type": "string"
},
"verdict": {
"type": "string"
},
"verdict_scope": {
"type": "string"
}
},
"type": "object"
},
"portal": {
"properties": {
"provenance": {
"const": "third-party-supplier"
},
"schemaCheck": {
"enum": [
"passed",
"undeclared",
"unchecked"
]
},
"serviceId": {
"const": "url-phishing-reputation"
}
},
"required": [
"provenance",
"serviceId",
"schemaCheck"
],
"type": "object"
}
},
"required": [
"portal",
"data"
],
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}