CyberAware UK

Scam-Intel API

Verified scam verdicts for URLs, phone numbers and messages — backed by live threat feeds, and cryptographically signed on paid tiers.

Check something (free)

curl 'https://api.cyberawareuk.co.uk/v1/check?text=http://example-suspicious.tld'
{
  "verdict": "scam",
  "type": "phishing",
  "confidence": 0.99,
  "signals": ["feed match: phishing", "seen 3x"],
  "source": "feed"
}

Endpoints

EndpointWhat it doesTier
GET /v1/check?text=…Verdict for a URL, phone or messageFree (rate-limited)
POST /v1/checkSame, JSON body {"text":…}Free (rate-limited)
GET /v1/company?q=…UK company risk flags (Companies House)Free (rate-limited)
GET /v1/attest/public-keyEd25519 public key for verificationFree
POST /v1/attest/verifyVerify a signed attestation offlineFree
GET /healthService livenessFree

Paid tier — signed attestations

Send an X-API-Key header and every verdict comes back as a signed, expiring attestation: an Ed25519 signature over sha256(verdict|evidence|source|observed_at). Anyone can verify it against the public key — no trust in us required. That is the product: a decision with provenance, not just an answer.

curl -H 'X-API-Key: ***'   'https://api.cyberawareuk.co.uk/v1/check?text=…'
Want a key? Email [email protected] with your use case. See /docs for the full reference.

Sources: URLhaus (abuse.ch), OpenPhish. Attribution as required. Verdicts are advisory and provided without warranty.