API Reference

Public API endpoints

Endpoints that are safe to call without an account. Authenticated account/dashboard endpoints are not documented publicly yet.

This lists only unauthenticated, public endpoints. A full API-key-based developer API for authenticated actions (managing monitored domains, pulling compliance reports programmatically, etc.) does not exist yet Follow-up — today those actions go through the dashboard.

Health & scanning

GET/api/health
Returns service status. No parameters, no authentication.
POST/api/passive/scan
Runs a real passive security scan (TLS, HSTS, CSP, SPF, DKIM, DMARC, DNS, exposure) against a domain you provide. Body: {"domain": "example.com"}. This is the same engine that powers the homepage's free-scan tool. Rate-limited; SSRF-protected against internal/private targets.

Enterprise SSO / SAML discovery

GET/.well-known/openid-configuration
OpenID Connect discovery document for AWMZA ID (used by other AWMZA properties to log in via AWMZA's own identity provider).
GET/api/saml/metadata
SAML 2.0 Service Provider metadata XML (entity ID and ACS URL) — give this to your IdP administrator when setting up SAML SSO for your enterprise account.

Vulnerability disclosure

GET/.well-known/security.txt
Machine-readable security contact, per RFC 9116. See also our responsible disclosure policy.