Tech stack detection

$0.005 per call · USDC via x402 · POST /api/tech-stack

Detect the technology stack of a public website: CDN, web server, language/runtime, frontend framework (Next.js, Nuxt, SvelteKit, Remix, Astro, React, Vue, Angular), CMS (WordPress, Drupal, Ghost, Shopify, Wix, Squarespace, Webflow), analytics (GA, GTM, PostHog, Mixpanel, Segment, Hotjar, Plausible, Fathom), and payments (Stripe, PayPal). Send POST /api/tech-stack with the required field url and pay $0.005 per call over x402 or MPP (there is no free tier). It returns a JSON object with url, detected, byCategory, generator, server and 2 more.

Signature-based; no third-party API.

Category: Network & domains · Tags: security audit research fingerprint

TRY IN PLAYGROUND →

Parameters

NameTypeRequiredDescription
urlstringyesPublic http(s) URL to fingerprint Also accepted as link, uri, href, page.

Example request

curl -i -X POST https://agent402.tools/api/tech-stack \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com"}'

Without payment this returns HTTP 402 Payment Required with the exact price for tech-stack; any x402 v2 or MPP client pays it and retries.

Example response

{
  "url": "https://example.com/",
  "detected": [
    {
      "category": "server",
      "name": "nginx"
    }
  ],
  "byCategory": {
    "server": [
      "nginx"
    ]
  },
  "generator": null,
  "server": "nginx",
  "poweredBy": null,
  "fetchedAt": "2026-06-19T22:00:00.000Z"
}
FieldTypeAlways presentIn the example
urlstringyeshttps://example.com/
detectedarray of objectsyes1 item in the example
byCategoryobjectyes1 field: server
generatornullnonull
serverstringyesnginx
poweredBynullnonull
fetchedAtstringyes2026-06-19T22:00:00.000Z

From an MCP client

catalog.call {
  "slug": "tech-stack",
  "params": {
    "url": "https://example.com"
  }
}

The hosted connector at https://agent402.tools/mcp needs a payment for tech-stack; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.

Errors and behavior

Paid call (JavaScript agent)

import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);

const res = await payFetch("https://agent402.tools/api/tech-stack", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({
    "url": "https://example.com"
  }),
});

Part of these workflows

Tech stack detection is one step in these 5 skill packs, each sold as a single call:

Related tools

Certificate transparency search

$0.005 · POST /api/cert-transparency

Search public Certificate Transparency logs for every cert issued to a domain. Two independent public CT search services…

HTTP headers + security analysis

$0.003 · POST /api/http-headers

Fetch a URL and return every response header plus a security analysis: HSTS, CSP, X-Frame-Options, X-Content-Type-Option…

ASN + IP geolocation

$0.001 · POST /api/asn-info

Look up the Autonomous System (ASN), prefix, country, registry, and allocation date for an IPv4 address - or for a hostn…

Email deliverability check

$0.002 · POST /api/email-deliverability

End-to-end email-auth report for a domain: SPF + DMARC + DKIM (probes common selectors automatically) + MX records + sco…

TLS certificate

$0.001 · POST /api/tls-cert

Inspect the TLS certificate of any public host: subject, issuer, validity window, days remaining, SANs, and SHA-256 fing…

Domain security & deliverability audit (graded)

$0.60 · POST /v1/domain-audit

Hand over a domain and get one graded security & email-deliverability audit: SPF, DMARC, DKIM and MX (why your mail land…