the402 endpoint detail

← All endpoints

api.agentstools.dev threat hash

https://api.agentstools.dev/threat/hash

payable

File-hash reputation and known-file context for a SOC or DFIR agent. Give an md5, sha1 or sha256 hash and get CIRCL hashlookup known-file status, a hashlookup trust score and file metadata (name, size, mimetype, source, database), plus malware family when a licensed feed is enabled. A known distribution or system file lowers the alert priority; an unknown hash is not itself evidence of malice. Ind

We sent a real GET request to this endpoint and it answered 402 with payment requirements we could parse.
Price
$0.008
Network
base
Pay to
0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493
Spec dialect
v2 (declares x402Version 2)
Transport
PAYMENT-REQUIRED header
HTTP method
GET
Response latency
700 ms
Payment options
1 usable of 1
Last checked
2026-08-10T09:12:44.445Z (1d ago)
Category
search

Re-check it yourself:
curl "https://api.the402.dev/validate?url=https%3A%2F%2Fapi.agentstools.dev%2Fthreat%2Fhash"