Tech stack detection
POST /api/tech-stackDetect the technology stack of a public website: CDN, web server, language/runtime, frontend framework (Next.js, Nuxt, SvelteKit, Remix, Astro, React, Vue, Angular), CMS (WordPress, Drupal, Ghost, Shopify, Wix, Squarespace, Webflow), analytics (GA, GTM, PostHog, Mixpanel, Segment, Hotjar, Plausible, Fathom), and payments (Stripe, PayPal). Send POST /api/tech-stack with the required field url and pay $0.005 per call over x402 or MPP (there is no free tier). It returns a JSON object with url, detected, byCategory, generator, server and 2 more.
Signature-based; no third-party API.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
url | string | yes | Public http(s) URL to fingerprint Also accepted as link, uri, href, page. |
Example request
curl -i -X POST https://agent402.tools/api/tech-stack \
-H "Content-Type: application/json" \
-d '{"url":"https://example.com"}'
Without payment this returns HTTP 402 Payment Required with the exact price for tech-stack; any x402 v2 or MPP client pays it and retries.
Example response
{
"url": "https://example.com/",
"detected": [
{
"category": "server",
"name": "nginx"
}
],
"byCategory": {
"server": [
"nginx"
]
},
"generator": null,
"server": "nginx",
"poweredBy": null,
"fetchedAt": "2026-06-19T22:00:00.000Z"
}
| Field | Type | Always present | In the example |
|---|---|---|---|
url | string | yes | https://example.com/ |
detected | array of objects | yes | 1 item in the example |
byCategory | object | yes | 1 field: server |
generator | null | no | null |
server | string | yes | nginx |
poweredBy | null | no | null |
fetchedAt | string | yes | 2026-06-19T22:00:00.000Z |
From an MCP client
catalog.call {
"slug": "tech-stack",
"params": {
"url": "https://example.com"
}
}
The hosted connector at https://agent402.tools/mcp needs a payment for tech-stack; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.
Errors and behavior
urlis required. An input the tool rejects returns an HTTP 4xx whose body carrieserror,tool,expected,requiredandexample, so the caller can correct it.- A paid call that ends in any status of 400 or above is not charged over x402, MPP or a prepaid credits key: settlement is cancelled when the tool fails. The exception is a Tempo push credential, a transfer the buyer sent before the call: it settles before the tool runs, so if the tool then fails the payment is recorded as a refund owed to the paying wallet.
- Wallet-only: this tool reaches the network or stored state, so it has no proof-of-work tier. A prepaid card-credits key issued earlier (
Authorization: Bearer a402_...) also pays it. - A
GETorHEADto /api/tech-stack returns the same 402 quote, so the price can be read without a body. - An
Idempotency-Keyheader makes a retried paid call replay the first 200 instead of charging again (an answer larger than 1 MB is not replayed).
Paid call (JavaScript agent)
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);
const res = await payFetch("https://agent402.tools/api/tech-stack", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
"url": "https://example.com"
}),
});
Part of these workflows
Tech stack detection is one step in these 5 skill packs, each sold as a single call:
- Security audit - Enumerate a domain's external attack surface in one workflow: certs, DNS posture, email auth, HTTP security headers, and tech stack.
- Fraud signals - Is this domain trustworthy, or is it a phishing site / typosquat / scam? Pull the reputation signals an analyst checks before clicking anything: domain age, cert issuance history, hosting reputation, DNS topology, tech-stack fingerprint, and page-content red flags. Different from a security audit - this is about whether the domain is what it claims to be.
- Domain intel - Full domain security and SEO intelligence in one call: WHOIS, DNS, TLS cert, HTTP headers, tech stack, robots policy, and certificate transparency.
- Competitor scan - What's a competitor using? Tech stack, HTTP headers, WHOIS, and page metadata in one call.
- Entity enrichment - Company name → verified identity + web footprint dossier: Wikidata facts, the official LEI legal-entity record, the SEC EDGAR filer, domain registration, tech stack, and brand favicon - in one pass.
Related tools
Certificate transparency search
POST /api/cert-transparencySearch public Certificate Transparency logs for every cert issued to a domain. Two independent public CT search services…
HTTP headers + security analysis
POST /api/http-headersFetch a URL and return every response header plus a security analysis: HSTS, CSP, X-Frame-Options, X-Content-Type-Option…
ASN + IP geolocation
POST /api/asn-infoLook up the Autonomous System (ASN), prefix, country, registry, and allocation date for an IPv4 address - or for a hostn…
Email deliverability check
POST /api/email-deliverabilityEnd-to-end email-auth report for a domain: SPF + DMARC + DKIM (probes common selectors automatically) + MX records + sco…
TLS certificate
POST /api/tls-certInspect the TLS certificate of any public host: subject, issuer, validity window, days remaining, SANs, and SHA-256 fing…
Domain security & deliverability audit (graded)
POST /v1/domain-auditHand over a domain and get one graded security & email-deliverability audit: SPF, DMARC, DKIM and MX (why your mail land…