1cent Web Intelligence for AI Agents
REMOTE · 1CENT.MAXZOA.RU · SCANNED AUG 3
SSRF-safe web intelligence: 4 outcomes, 32 paid x402 tools, 3 free tools and a URL preview.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability82
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 4625 tokens (~128/item across 36 items; 35 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management13
- Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · 1cent.maxzoa.ru
claude mcp add --transport http ru-maxzoa-1cent https://1cent.maxzoa.ru/mcp
[mcp_servers.ru-maxzoa-1cent] url = "https://1cent.maxzoa.ru/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ru-maxzoa-1cent": {
"type": "remote",
"url": "https://1cent.maxzoa.ru/mcp",
"enabled": true
}
}
} openclaw mcp add ru-maxzoa-1cent --url https://1cent.maxzoa.ru/mcp --transport streamable-http
mcp_servers:
ru-maxzoa-1cent:
url: "https://1cent.maxzoa.ru/mcp" {
"mcpServers": {
"ru-maxzoa-1cent": {
"type": "http",
"url": "https://1cent.maxzoa.ru/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +57
- Authorization: unverified → partial ▲ security
- HTTPS: unverified → pass ▲ security
- Transport: fail → pass ▲ security
- HSTS header: fail → pass ▲ security
- The server rewrote its instructions, which are the text every model session reads security
- Endpoint reachability: not serving MCP → reachable ▲ functional
- MCP protocol: unverified → pass ▲ functional
- Stability: unverified → 0.10 ▲ functional
- Schema quality: unverified → 100 ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- 1 Aug 26 −56
- Endpoint reachability: reachable → not serving MCP ▼ security
- Stability: 0.03 → unverified ▼ security
- HTTPS: pass → unverified ▼ security
- Authorization: partial → unverified ▼ security
- Transport: pass → fail ▼ security
- HSTS header: pass → fail ▼ security
- Schema quality: 100 → unverified ▼ functional
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- 31 Jul 26 +3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +59
- HTTPS: unverified → pass ▲ security
- Authorization: unverified → partial ▲ security
- HSTS header: fail → pass ▲ security
- Transport: fail → pass ▲ security
- Tool coverage: unverified → 100 ▲ functional
- Schema quality: unverified → 100 ▲ functional
- MCP protocol: unverified → pass ▲ functional
- First check of Schema quality: fail functional
- First check of Schema quality: excellent functional
- First check of Tool coverage: 100 functional
- First check of Tool coverage: 100 functional
- First check of Schema quality: fail functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 12
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://1cent.maxzoa.ru/mcp/ · Declared URL https://1cent.maxzoa.ru/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=maxzoa.ru | CN=YE1,O=Let's Encrypt,C=US | 23 Jul 2026 | 21 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 51d8e5b3fde8999caaa7222b059c6ead0cf |
| SANs: *.maxzoa.ru, maxzoa.ru | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of 1cent.maxzoa.ru. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ru. | present | 51575 | 8 | Verified |
| maxzoa.ru. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'self'; script-src 'self' https://cdn.jsdelivr.net 'unsafe-inline'; style-src 'self' https://cdn.jsdelivr.net 'unsafe-inline'; img-src 'self' data: https://fastapi.tiangolo.com; connect-src 'self'; frame-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | no-referrer |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Transports 3 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://1cent.maxzoa.ru/mcp | Redirected | 308 | https://1cent.maxzoa.ru/mcp/ |
| streamable-http · followed | https://1cent.maxzoa.ru/mcp/ | Verified | 200 | |
| http (plaintext) | http://1cent.maxzoa.ru/mcp | HTTPS enforced | 308 | https://1cent.maxzoa.ru/mcp/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
catalog.tools.search Start here: find a 1cent tool and current price ~76
Start here before choosing a paid operation. Search the local 1cent catalog without fetching a URL or requiring payment. Returns up to five matching tools with purpose, current atomic Base USDC price and REST path.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | Short capability phrase such as 'redirect chain', 'security headers' or 'extract article text'. |
| Name | Type | Req | Description |
|---|---|---|---|
| results | array | yes | — |
No examples provided.
demo.live.pulse Free live demo: check fixed example.com ~52
Run the real SSRF-protected URL Pulse service against the fixed https://example.com/ target without payment. The tool accepts no URL, is rate-limited per client and preserves normal cache and audit behavior.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| demo | boolean | — | — |
| fixed_target | string | yes | — |
| payment_required | boolean | — | — |
| rate_limit_per_hour | integer | yes | — |
| result | — | yes | — |
No examples provided.
demo.url.pulse Free demo: preview a URL Pulse result ~47
Return a precomputed example of 1cent URL Pulse output without payment, database access or any network request. This fixed demonstration never accepts a URL and never fetches an external resource.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| demo | boolean | yes | — |
| network_request_performed | boolean | yes | — |
| payment_required | boolean | yes | — |
| reachable | boolean | yes | — |
| source | string | yes | — |
| status_code | integer | yes | — |
| summary | string | yes | — |
| title | string | yes | — |
| url | string | yes | — |
No examples provided.
web.site.feeds Site Feeds ~132
Discover declared RSS and Atom feeds. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.site.llms_txt Site Llms Txt ~136
Return bounded llms.txt text when publicly available. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.site.openapi Site Openapi ~133
Discover and summarize bounded public OpenAPI documents. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.site.robots Site Robots ~134
Fetch and parse the origin robots.txt policy. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.site.security_txt Site Security Txt ~134
Parse public security.txt fields without following contacts. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.site.sitemaps Site Sitemaps ~134
Discover up to five bounded sitemap resources. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.access_flags Url Access Flags ~137
Report heuristic authentication, paywall and JavaScript access flags. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.canonical Url Canonical ~136
Resolve requested, final and declared canonical URLs with evidence. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.changed URL Changed ~142
Compare a public HTTP or HTTPS URL with its previously stored normalized content hash. Creates a baseline on first use, then reports whether content changed and returns current and previous hashes with timestamps. JavaScript is not executed. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to reuse cache; set fresh=true only for a new fetch.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| baseline_created | boolean | yes | — |
| changed | — | yes | — |
| checked_at | string | yes | — |
| current_hash | string | yes | — |
| first_seen_at | — | — | — |
| previous_checked_at | — | — | — |
| previous_hash | — | yes | — |
| quality | — | — | — |
No examples provided.
web.url.content_type Url Content Type ~136
Classify MIME type, charset and bounded content length. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.diff Url Diff ~134
Return a bounded normalized diff against the previous snapshot. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.extract URL Extract ~180
Extract normalized main text and optional links from a public HTTP or HTTPS document. Returns title, author, publication time, language, content hash, truncation and cache state. Output size and fetch time are bounded; JavaScript is not executed. Pass url as an absolute public HTTP(S) URL. Set include_links=true only when normalized links are needed. Keep fresh=false to reuse cache.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| include_links | boolean | — | Set true to include bounded normalized links in extraction output; false returns the main document text without the optional link list. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| author | — | yes | — |
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| from_cache | boolean | yes | — |
| language | — | yes | — |
| links | array | yes | — |
| published_at | — | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| text | string | yes | — |
| text_length | integer | yes | — |
| title | — | yes | — |
| truncated | boolean | yes | — |
| url_final | string | yes | — |
No examples provided.
web.url.hash Url Hash ~135
Compute a versioned SHA-256 of normalized content. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.headers Url Headers ~131
Return allowlisted response headers only. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.headings Url Headings ~137
Return the bounded heading hierarchy from h1 through h6. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.images Url Images ~135
List up to 100 image references without downloading images. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.jsonld Url Jsonld ~135
Extract bounded JSON-LD blocks without executing scripts. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.language Url Language ~133
Report declared and heuristically detected document language. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.links Url Links ~133
Extract up to 200 normalized safe links. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.markdown Url Markdown ~133
Convert readable HTML content to bounded Markdown. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.metadata Url Metadata ~136
Extract title, description, author, dates and canonical metadata. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.passport URL Passport ~155
Inspect a public HTTP or HTTPS URL and return a structured site passport. Includes pulse fields, registrable domain, robots and sitemap discovery, feeds, OpenAPI hints, and page metadata. Uses at most eight external HTTP requests and does not execute JavaScript. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to reuse cache; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| auth_required | boolean | yes | — |
| canonical_url | — | yes | — |
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| content_length | integer | yes | — |
| content_type | string | yes | — |
| discovery | — | yes | — |
| from_cache | boolean | yes | — |
| language | — | yes | — |
| metadata | — | yes | — |
| quality | — | — | — |
| reachable | boolean | yes | — |
| redirect_count | integer | yes | — |
| request_id | string | yes | — |
| requires_javascript | boolean | yes | — |
| response_time_ms | integer | yes | — |
| robots_allowed | boolean | yes | — |
| site | — | yes | — |
| status_code | integer | yes | — |
| suspected_paywall | boolean | yes | — |
| title | — | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.pulse URL Pulse ~150
Check a public HTTP or HTTPS URL before expensive browsing or AI processing. Returns availability, redirects, content type, page metadata, language, cache state, content hash, robots policy, and access restrictions. Does not execute JavaScript. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to reuse cache; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| auth_required | boolean | yes | — |
| canonical_url | — | yes | — |
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| content_length | integer | yes | — |
| content_type | string | yes | — |
| from_cache | boolean | yes | — |
| language | — | yes | — |
| quality | — | — | — |
| reachable | boolean | yes | — |
| redirect_count | integer | yes | — |
| request_id | string | yes | — |
| requires_javascript | boolean | yes | — |
| response_time_ms | integer | yes | — |
| robots_allowed | boolean | yes | — |
| status_code | integer | yes | — |
| suspected_paywall | boolean | yes | — |
| title | — | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.rag_chunks Url Rag Chunks ~136
Split readable text into deterministic bounded RAG chunks. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.redirects Url Redirects ~132
Return the safely validated redirect chain. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.security_headers Url Security Headers ~134
Assess common response security headers as static evidence. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.social_cards Url Social Cards ~134
Extract bounded Open Graph and Twitter Card fields. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.status Url Status ~134
Check HTTP reachability, status and final URL. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.text Url Text ~130
Return bounded normalized readable text. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.timing Url Timing ~133
Return measured end-to-end fetch timing. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.tls Url Tls ~135
Inspect the public HTTPS certificate on port 443. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.
web.url.word_stats Url Word Stats ~135
Estimate words, characters, sentences and reading time. Use only for public HTTP(S) resources; it does not execute JavaScript or bypass access controls. Pass url as an absolute public HTTP(S) URL. Keep fresh=false to allow cache reuse; set fresh=true only when a new upstream fetch is required.
| Name | Type | Req | Description |
|---|---|---|---|
| fresh | boolean | — | Set true only when a new upstream fetch is required; false allows the bounded cached result and is cheaper for the origin. |
| url | string | yes | Absolute public HTTP or HTTPS URL to inspect. Private, loopback, link-local, metadata-service and otherwise SSRF-sensitive destinations are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| checked_at | string | yes | — |
| content_hash | string | yes | — |
| data | object | yes | — |
| from_cache | boolean | yes | — |
| quality | — | — | — |
| request_id | string | yes | — |
| tool | string | yes | — |
| url_final | string | yes | — |
| url_requested | string | yes | — |
No examples provided.