Developer DocsДокументация для разработчиков

SecuriLayer API DocumentationДокументация SecuriLayer API

Production-grade integration reference with request/response contracts, billing semantics, and anti-abuse behavior.Production-level reference по интеграции: контракты запросов/ответов, биллинговая семантика и anti-abuse поведение.

Quick Start

Use one scoped API key and call `/v1/decision/url` to start.Используйте scoped API key и вызовите `/v1/decision/url` для старта.

curl -X POST https://securilayer.dev/v1/decision/url \
  -H "Content-Type: application/json" \
  -H "X-API-Key: sl_xxxxx" \
  -d '{"url":"https://example.com"}'
import requests

resp = requests.post(
    "https://securilayer.dev/v1/decision/url",
    headers={"X-API-Key": "sl_xxxxx"},
    json={"url": "https://example.com"},
    timeout=10,
)
resp.raise_for_status()
data = resp.json()
print(data["verdict"], data.get("reason_codes", []))
const res = await fetch("https://securilayer.dev/v1/decision/url", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    "X-API-Key": "sl_xxxxx"
  },
  body: JSON.stringify({ url: "https://example.com" })
});
const data = await res.json();
console.log(data.verdict, data.reason_codes);
$ch = curl_init('https://securilayer.dev/v1/decision/url');
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, [
  'Content-Type: application/json',
  'X-API-Key: sl_xxxxx'
]);
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode(['url' => 'https://example.com']));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$result = curl_exec($ch);
curl_close($ch);
echo $result;

Need an API key? Create it in DashboardНужен API ключ? Создайте в кабинете

Authentication

HeaderValueNotesКомментарий
X-API-Keysl_xxxxxRequired for API-key routes. Create keys in Dashboard; never place them in client-side code.Обязателен для API-key маршрутов. Создавайте ключи в кабинете; не размещайте их в клиентском коде.
AuthorizationBearer <jwt>Used for dashboard/session routes.Используется для dashboard/session маршрутов.
Key typeТип ключаScope
extensionOnly browser extension endpoints and extension telemetry; it does not unlock the public API or dashboard sections.Только endpoints расширения и telemetry; не открывает публичный API или разделы ЛК.
api_standardCore API checks; requires an active API Package entitlement.Основные API-проверки; требует активный API Package entitlement.
api_creditsPay-as-you-go checks with token billing; credits do not unlock paid dashboard product sections.Pay-as-you-go проверки с токен-биллингом; кредиты не открывают платные разделы ЛК.
api_enterpriseDedicated limits, SLA, custom policy contracts and managed integration terms.Выделенные лимиты, SLA, кастомные policy-контракты и managed integration terms.

Endpoints

MethodPathRequestResponse
POST/v1/decision/url{"url": "string"}DecisionResponse
POST/v1/decision/text{"text": "string"}DecisionResponse
POST/v1/check/phone{"phone": "string"}DecisionResponse
POST/v1/check/media{"file": "base64"}DecisionResponse
GET/v1/credits/balance-{"tokens": int, "usd_balance": float}
GET/v1/decisions?limit=50Decision history for org_idИстория решений для org_id

Response Format

{
  "verdict": "SAFE | SUSPICIOUS | DANGER",
  "confidence": 0.93,
  "reason_codes": ["HOMOGRAPH", "NEW_DOMAIN"],
  "explanation": "Potential domain spoofing pattern",
  "decision_id": "b54f5f7e-2e5a-4ad1-9f65-4fbe818f8e44",
  "billing_mode": "subscription | credits | overflow",
  "tokens_used": 1
}
CodeDescriptionОписаниеSeverity
HOMOGRAPHSuspicious domain visual spoofingВизуальная подмена доменаhigh
REDIRECT_MISMATCHUnexpected redirect chain mismatchНесоответствие в цепочке редиректовmedium
DRAINER_PATTERNCrypto wallet drainer signature detectedОбнаружен паттерн crypto drainercritical
GOV_IMPERSONATIONGovernment authority impersonationИмперсонация госструктурыcritical
X-Quota-Remaining · X-Credits-Balance · X-Billing-Mode

Error Codes

StatusMeaningЗначениеWhat to doЧто делать
401Invalid or missing API keyОтсутствует или неверный API ключCreate/rotate key in DashboardСоздать/ротировать ключ в кабинете
402Insufficient balance or expired subscriptionНедостаточный баланс или истёкшая подпискаTop up credits or renew planПополнить Credits или продлить план
422Invalid input (blocked SSRF, malformed URL, etc.)Неверный ввод (SSRF, некорректный URL и т.д.)Validate client payloadПровалидировать payload на клиенте
429Rate limit exceeded (tokens not charged)Превышен rate limit (токены не списываются)Retry with backoffПовторить с backoff
503Temporary service degradationВременная деградация сервисаRetry later and monitor statusПовторить позже и проверить статус

Billing / Tokens

Check typeТип проверкиTokensUSD
URL / Text1$0.004
Phone3$0.012
Media8$0.032
Sandbox20$0.080
LLM explain5$0.020

Starter

$29 → 7,250 tokens

Growth

$99 → 26,125 tokens (+5%)

Scale

$299 → 82,225 tokens (+10%)

Pro

$999 → 287,212 tokens (+15%)

Enterprise

$2,500 → 750,000 tokens (+20%)

API Credits are metered for eligible API calls and overflow only. They do not bypass plan gates for Evidence Packs, SIEM, Webhooks, Agent Security, platform response quotas, team roles, or tenant isolation. On HTTP 429 tokens are not charged.API Credits списываются только за разрешённые API-вызовы и overflow. Они не обходят gates тарифов для Evidence Packs, SIEM, Webhooks, Agent Security, platform response quotas, ролей команды или tenant isolation. При HTTP 429 токены не списываются.

Real Use Cases

1) Telegram mini app1) Telegram mini app

Validate links posted by users before publishing to group chat.Проверка ссылок пользователей до публикации в группе.

2) E-commerce moderation2) E-commerce модерация

Scan links in product reviews and comments to block phishing campaigns.Проверка ссылок в отзывах и комментариях для блокировки фишинга.

3) Discord bot wrapper3) Discord bot wrapper

Custom bot delegates detection to SecuriLayer API while keeping your own command UX.Свой бот передаёт детектирование в SecuriLayer API, сохраняя ваш UX команд.

4) Bulk URL checker4) Bulk URL checker

Rate-limit aware Python batch script with retries and result persistence.Batch-скрипт на Python с учётом rate-limit и retry-политики.

Partner Review Checklist

Before submitting SecuriLayer to a marketplace, AI connector directory, wallet integration review, or grant milestone, use this checklist against production endpoints only. Reviewers should see the same contract that customers use: HTTPS host, documented endpoint, scoped auth, clear error behavior, quota headers, and no hidden dependency on internal dashboard routes.

Artifacts

OpenAPI, Postman, SDK README files, public API contract, MCP runbook, Chrome Web Store runbook, and production smoke commands must stay current with the live backend.

Commercial boundary

API Credits and API Packages fund eligible external calls. They do not bypass base-plan features, add-on limits, tenant isolation, DPA controls, Evidence Pack exports, SIEM, Webhooks, or platform actions.