Vigilbase Developers
Quickstart
Run a non-intrusive security headers scan with zero auth:
curl -sS -X POST https://vigilbase.com/api/v1/agent/tools/security-headers/execute \
-H "Content-Type: application/json" \
-d '{"target":"https://example.com"}'Email authentication check:
curl -sS -X POST https://vigilbase.com/api/v1/agent/tools/email-security/execute \
-H "Content-Type: application/json" \
-d '{"target":"example.com"}'CLI: npx @vigilbase/cli run security-headers https://example.com --json
Authentication and scopes
Anonymous callers get free-tier scopes tools:read, tools:execute, and badges:read at 10 requests/minute per IP.
Optional developer API keys (created on one.vigilbase.com/developers) raise the limit to 30 requests/minute. Keys are user-scoped — they belong to your Vigilbase One account, not an organization. Send Authorization: Bearer <key> or X-Api-Key: <key>.
tools:read— list agent toolstools:execute— run allowlisted scansbadges:read— security grade badges
Developer API keys
Create free API keys on Vigilbase One — sign up takes a minute and no sales form is required. Keys are user-scoped, include tools:read, tools:execute, and badges:read, and raise the agent rate limit to 30 requests/minute on vigilbase.com.
curl -sS https://vigilbase.com/api/v1/agent/tools \ -H "Authorization: Bearer YOUR_ONE_API_KEY"
API endpoints
GET /api/v1/agent/tools— catalogPOST /api/v1/agent/tools/security-headers/executePOST /api/v1/agent/tools/email-security/executePOST /api/v1/developer/keys— deprecated; create keys on One insteadGET /api/badge/{domain}— SVG badgeGET /openapi.json— OpenAPI 3.1 document
Legacy /api/agent/* aliases still work and return Deprecation / Sunset headers pointing at the v1 successor.
Typed JSON errors
Failures return application/problem+json (RFC 9457) with a machine-readable code, human-readable message/detail, and optional hint for recovery.
{
"success": false,
"error": {
"code": "rate_limit_exceeded",
"message": "Rate limit exceeded. Retry after the indicated delay.",
"hint": "Free tier allows 10 requests/minute. Create a developer API key on One for a higher limit."
},
"type": "https://vigilbase.com/developers/errors/rate-limit-exceeded",
"title": "Rate Limit Exceeded",
"status": 429,
"detail": "Rate limit exceeded. Retry after the indicated delay.",
"code": "rate_limit_exceeded",
"retryAfterSec": 12
}Rate limits
Responses include RateLimit and RateLimit-Policy headers, plus RateLimit-Limit / RateLimit-Remaining / RateLimit-Reset and X-RateLimit-* aliases. HTTP 429 sets Retry-After.
Versioning and deprecation
Current major version is v1 under /api/v1/. Responses include API-Version: 1. Breaking changes will ship as /api/v2/. Deprecated unversioned aliases advertise Deprecation: true, a Sunset date, and a Link rel="successor-version" header.
When to use Vigilbase APIs
- Grade HTTP security headers or email auth (SPF/DKIM/DMARC) from an agent without driving a browser
- Embed a previously measured website-security grade badge
- Discover agent skills via
/.well-known/agent-skills/index.json
Prefer the browser UI (with email verification) for intrusive scanners such as website-security and react2shell.