{
  "serviceId": "url-phishing-reputation",
  "displayName": "URL Phishing Reputation",
  "description": "Check a URL for phishing signs without fetching it: raw IP hosts, punycode, user@host, credential words in the host, very long hosts and deep subdomains. The verdict is suspicious or unknown, never clean, because no threat database is consulted; the response says what ran. POST /v1/reputation with {url}. Pay per request in USDC; no account, no API key.",
  "category": "security",
  "resourceUrl": "https://agent.pocket.network/v1/url-phishing-reputation",
  "priceUsd": "0.005000",
  "priceVersion": 1,
  "rails": [
    {
      "id": "base",
      "network": "eip155:8453",
      "chainId": 8453,
      "tokenAddress": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "tokenDecimals": 6,
      "payToAddress": "0xF732ea490c5766071785a2310523f7fA2CEbB829"
    }
  ],
  "paymentNetworks": [
    "eip155:8453",
    "eip155:4217"
  ],
  "paymentProtocols": [
    "x402",
    "mpp"
  ],
  "protocols": [
    "rest"
  ],
  "inputSchema": {
    "type": "object",
    "description": "The body of POST /v1/reputation.",
    "properties": {
      "url": {
        "type": "string",
        "description": "The URL to check (http or https). It is not fetched."
      }
    },
    "required": [
      "url"
    ]
  },
  "outputSchema": {
    "type": "object",
    "description": "For POST /v1/reputation, a JSON object with url, host, verdict (malicious, suspicious, clean or unknown), heuristics, threat_matches, checked_sources (each source and whether it ran) and verdict_scope. A bad request answers 400 with an `error` string."
  },
  "methods": {
    "GET /v1/health": "read",
    "GET /v1/version": "read",
    "POST /v1/reputation": "read"
  },
  "firstParty": true,
  "networks": [
    "eip155:8453",
    "eip155:4217"
  ],
  "serving": true,
  "page": "https://agent.pocket.network/services/url-phishing-reputation",
  "descriptor": "https://agent.pocket.network/services/url-phishing-reputation/descriptor.json"
}