The same data as your account page, as JSON: monitored sites with their state and outages, your reports with score and findings, and the free AI crawler check on demand.
Create a keyRequires an active monitoring subscription
Every endpoint answers with JSON and reads only the data of the account that owns the key: its monitored sites and the reports scanned or bought with its e-mail address.
1
Sign in and subscribe to site health monitoring ($4.99 a month): the API comes with it.
2
Open Account → API keys, create a key and copy it: it is shown once.
3
Send it as a bearer token with each request.
§ 2
Authentication
Requires an active monitoring subscription
API access comes with the site health monitoring subscription ($4.99 a month), while it is active or cancelled but not yet ended. The month of monitoring included with a full report does not include it. Without a subscription your keys are kept, but every request answers 403 subscription_required; the same keys work again once a subscription is active.
Keys look like al_live_ followed by 32 characters. Send one in the Authorization header:
An account can have up to 5 active keys. Revoke a key on the account page and it stops working at once. We store only a SHA-256 fingerprint of each key, so a lost key cannot be shown again: make a new one.
The API is for servers and scripts. It sends no CORS headers, so a web page on another site cannot call it from a visitor's browser. Never put a key in front-end code.
§ 3
Rate limits
60 requests a minute per key, counted over a sliding minute. Every answer carries:
X-RateLimit-Limit the limit (60)
X-RateLimit-Remaining requests left in the current minute
X-RateLimit-Reset when the oldest request leaves the window (Unix seconds)
Over the limit you get 429 with a Retry-After header in seconds. POST /api/v1/ai-checks also has the free tool's own limit: 6 checks a minute per key, and a site checked in the last 10 minutes gets that result back (cached: true). Requests with a wrong key are limited to 20 a minute per IP address.
429
{
"error": "rate_limited",
"message": "Rate limit of 60 requests per minute per key reached. Retry in 12 s."
}
§ 4
Conventions
Times are ISO-8601 in UTC, without fractions: 2026-10-06T09:14:03Z. A missing time is null.
Add ?lang=tr to get human-readable text (incident descriptions, alert lines, finding titles) in Turkish; the default is English.
Hosts are matched with and without www.
Fields may be added to v1 answers; existing fields keep their name and meaning. Breaking changes get a new version in the path.
§ 5
Errors
Errors use the HTTP status and a JSON body with a machine-readable code and a sentence for people:
Code
Status
Meaning
missing_key
401
No Authorization: Bearer header.
invalid_key
401
The key is malformed, unknown or revoked.
subscription_required
403
The account has no active monitoring subscription. The same keys work again once it has one.
rate_limited
429
Too many requests: wait Retry-After seconds.
bad_request
400
A parameter or the JSON body is not valid.
not_found
404
No such endpoint, or nothing with that id or host on your account.
unreachable
422
AI check only: the site did not answer.
unavailable
503
Our side failed. Try again shortly.
§ 6
Endpoints
Shapes are exact; the values are an example.
GET/api/v1/sites
List monitored sites
Every site monitored for your account, with its state now: up or down, 30-day uptime, TLS days left, ads.txt, how many AI crawlers can read the homepage, the last and next daily check, and the outage going on, if any. monitoring is false once the subscription or the month included with a report has ended.
Everything in the list, plus the AI crawler breakdown, the 5 most recent outages and the 10 most recent alerts (with the lines the e-mail said and whether it was sent).
Outages found by the 5-minute uptime check that ended after since or are still going on, newest first. An outage opens after two failed checks in a row.
Scans you ran while signed in and reports bought with your e-mail address, newest first: score and verdict (null until a scan is done, or when the site blocked us), when the report is unlocked until, and the deep scan an unlock started.
Score, verdict, issue counts by severity, category scores and every failing finding with its title and severity. The pages and parameters behind a finding (evidence) are included only when your account has the site unlocked: everything for a full report, the AI findings for an AI visibility report.
Runs the free “Can AI see your site?” check of one homepage (about 20 seconds) and returns the full result: each AI crawler's robots.txt rule and simulated request, meta directives, llms.txt and the sitemap. 201 for a new check, 200 for a cached one.