Skip to content
DEVELOPERS

Vigilbase Developers

Public API docs, OpenAPI, developer API keys on Vigilbase One, and agent quickstart — free for any signed-up user.

Quickstart

Run a non-intrusive security headers scan with zero auth:

curl -sS -X POST https://vigilbase.com/api/v1/agent/tools/security-headers/execute \
  -H "Content-Type: application/json" \
  -d '{"target":"https://example.com"}'

Email authentication check:

curl -sS -X POST https://vigilbase.com/api/v1/agent/tools/email-security/execute \
  -H "Content-Type: application/json" \
  -d '{"target":"example.com"}'

CLI: npx @vigilbase/cli run security-headers https://example.com --json

Authentication and scopes

Anonymous callers get free-tier scopes tools:read, tools:execute, and badges:read at 10 requests/minute per IP.

Optional developer API keys (created on one.vigilbase.com/developers) raise the limit to 30 requests/minute. Keys are user-scoped — they belong to your Vigilbase One account, not an organization. Send Authorization: Bearer <key> or X-Api-Key: <key>.

  • tools:read — list agent tools
  • tools:execute — run allowlisted scans
  • badges:read — security grade badges

Developer API keys

Create free API keys on Vigilbase One — sign up takes a minute and no sales form is required. Keys are user-scoped, include tools:read, tools:execute, and badges:read, and raise the agent rate limit to 30 requests/minute on vigilbase.com.

curl -sS https://vigilbase.com/api/v1/agent/tools \
  -H "Authorization: Bearer YOUR_ONE_API_KEY"

API endpoints

  • GET /api/v1/agent/tools — catalog
  • POST /api/v1/agent/tools/security-headers/execute
  • POST /api/v1/agent/tools/email-security/execute
  • POST /api/v1/developer/keys — deprecated; create keys on One instead
  • GET /api/badge/{domain} — SVG badge
  • GET /openapi.json — OpenAPI 3.1 document

Legacy /api/agent/* aliases still work and return Deprecation / Sunset headers pointing at the v1 successor.

Typed JSON errors

Failures return application/problem+json (RFC 9457) with a machine-readable code, human-readable message/detail, and optional hint for recovery.

{
  "success": false,
  "error": {
    "code": "rate_limit_exceeded",
    "message": "Rate limit exceeded. Retry after the indicated delay.",
    "hint": "Free tier allows 10 requests/minute. Create a developer API key on One for a higher limit."
  },
  "type": "https://vigilbase.com/developers/errors/rate-limit-exceeded",
  "title": "Rate Limit Exceeded",
  "status": 429,
  "detail": "Rate limit exceeded. Retry after the indicated delay.",
  "code": "rate_limit_exceeded",
  "retryAfterSec": 12
}

Rate limits

Responses include RateLimit and RateLimit-Policy headers, plus RateLimit-Limit / RateLimit-Remaining / RateLimit-Reset and X-RateLimit-* aliases. HTTP 429 sets Retry-After.

Versioning and deprecation

Current major version is v1 under /api/v1/. Responses include API-Version: 1. Breaking changes will ship as /api/v2/. Deprecated unversioned aliases advertise Deprecation: true, a Sunset date, and a Link rel="successor-version" header.

When to use Vigilbase APIs

  • Grade HTTP security headers or email auth (SPF/DKIM/DMARC) from an agent without driving a browser
  • Embed a previously measured website-security grade badge
  • Discover agent skills via /.well-known/agent-skills/index.json

Prefer the browser UI (with email verification) for intrusive scanners such as website-security and react2shell.

Machine-readable discovery