Fingerprint a suspected phishing/smishing kit from a live URL (static HTML fetch only i…
Fingerprint a suspected phishing/smishing kit from a live URL (static HTML fetch only in v1 — no JS rendering in the Lambda; submit caller-rendered HTML via the html field for JS-heavy kits) or from caller-supplied kit HTML. Returns a stable kit_<sha256> ID,…
by RelayShield · verified provider · updated 2026-09-27
What it does
Fingerprint a suspected phishing/smishing kit from a live URL (static HTML fetch only in v1 — no JS rendering in the Lambda; submit caller-rendered HTML via the html field for JS-heavy kits) or from caller-supplied kit HTML. Returns a stable kit_<sha256> ID, extracted kit signals, corpus evidence, and a best-effort family match. Per-victim nonces and credentials are stripped before hashing, so the same kit fingerprints identically across sightings. Call to turn one suspicious link into a matchable kit identity.
Tags: phishing-kit · smishing · threat-intelligence
Use with an agent
- Discover. Agents find this listing with
GET https://bazaar.saylorinnovations.com/discovery/search?query=…, the MCP toolsearch_resources, or/discovery/resources. - Inspect. Fetch
/resources/20402.jsonfor the price and payment options. - Pay. Call
GET https://api.relayshield.net/v1/payg/scamkit-fingerprint. The provider answers402with its payment requirements. An x402 client signs one of the options below and retries withPAYMENT-SIGNATURE. - Execute. The provider returns
200with the data. Agent Bazaar is not in the request path and never sees your payment.
For humans
You don't need an account or an API key; you need a wallet holding a small amount of USDC on Base, Solana, and an x402-capable client (see the examples below). Call the endpoint unpaid first to see exactly what it asks for.
Pricing & payment
- Price
- $0.5 / request
- Protocol
- x402 v2
- Auth
- No account or API key. Pay per request.
- Networks
- Base, Solana
x402 payment requirements
| Scheme | Network | Asset | Amount | Pay to | Timeout |
|---|---|---|---|---|---|
| exact | Base eip155:8453 | USDC | $0.5 | 0x002CfD89c5636F45E3C8576D6E35154748412bAc | 300s |
| exact | Solana solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp | USDC | $0.5 | E64PiTT7U8ZUWFKdkrBFw1YzdD2bU1gKcuGnBRVqp7M6 | 60s |
accepts[] (raw JSON)
[
{
"scheme": "exact",
"network": "eip155:8453",
"payTo": "0x002CfD89c5636F45E3C8576D6E35154748412bAc",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"amount": "500000",
"amountUsd": 0.5,
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"payTo": "E64PiTT7U8ZUWFKdkrBFw1YzdD2bU1gKcuGnBRVqp7M6",
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"amount": "500000",
"amountUsd": 0.5,
"maxTimeoutSeconds": 60
}
]Examples
curl "https://api.relayshield.net/v1/payg/scamkit-fingerprint"
# -> 402 Payment Required, accepts[] lists how to pay
# retry with a PAYMENT-SIGNATURE (or PAYMENT header) once paidconst res = await fetch("https://api.relayshield.net/v1/payg/scamkit-fingerprint");
if (res.status === 402) {
const { accepts } = await res.json();
// pay one of accepts[] via an x402 client, then retry with the payment header
}import httpx
res = httpx.get("https://api.relayshield.net/v1/payg/scamkit-fingerprint")
if res.status_code == 402:
accepts = res.json()["accepts"]
# pay one of accepts[] via an x402 client, then retry with the payment headerDetails
- Provider
- RelayShield
- Endpoint
- https://api.relayshield.net/v1/payg/scamkit-fingerprint
- Machine-readable
/resources/20402.json