openapi: 3.2.0 info: title: 2s — the (most) everything Domain API version: '1' summary: The (most) everything API. description: 'The (most) everything API for AI agents: 575+ pay-per-call endpoints on one origin.' contact: name: 2s url: https://2s.io email: alley@2s.io x-logo: url: https://2s.io/icon-512.png altText: 2s x-guidance: 'Pay-per-call REST API for AI agents — hundreds of endpoints returning ground-truth data (US public records, company & legal identifiers, finance/SEC, crypto/web3, security & CVEs, medical codes, weather & geocoding, agriculture, energy, maritime, music, and more). Every endpoint is paid per call in USDC via x402 (Base or Solana) — no API key, no signup. Call any endpoint with no auth to get a 402 PaymentRequirements envelope, sign it (EIP-3009 on Base, partial SPL transfer on Solana), and retry with the PAYMENT-SIGNATURE header. Add ?trial=1 for one free real call per endpoint per hour to test before paying. To discover the right endpoint: GET https://2s.io/api/directory for the full catalog, or GET https://2s.io/api/search/endpoints?q= for a ranked match. Per-call price is on each operation as x-payment-info (from $0.001). Batch up to 50 calls behind one payment via POST https://2s.io/api/batch/run.' servers: - url: https://2s.io tags: - name: Domain paths: /api/domain/ct-logs: get: tags: - Domain summary: Certificate Transparency recon for a domain - discover its description: 'Certificate Transparency recon for a domain — discover its subdomains and issued certificates from public CT logs (passive attack-surface mapping). Pass domain. Returns the deduplicated set of subdomains seen across all certs (subdomains + subdomainCount), and the certificates (issuer, validity window, SAN dns names), most recent first. Sourced from SSLMate certSpotter (primary) with a crt.sh fallback — keyless. Live CT-log data over a huge append-only dataset an LLM cannot enumerate. For external attack-surface discovery, shadow-IT/subdomain inventory, and certificate monitoring. Note: CT shows names that ever appeared in a cert, not necessarily live hosts.' operationId: domain_ct-logs deprecated: false security: - x402Payment: [] responses: '200': description: 'Normalized envelope: items = [CT recon result with subdomains + certs]; total = 1.' content: application/json: schema: type: object required: - data - meta properties: data: type: object properties: ok: type: boolean enum: - true items: type: array items: type: object properties: domain: type: string subdomainCount: type: integer subdomains: type: array items: type: string certCount: type: integer certs: type: array items: type: object properties: issuer: type: string nullable: true notBefore: type: string nullable: true notAfter: type: string nullable: true dnsNames: type: array items: type: string required: - issuer - notBefore - notAfter - dnsNames additionalProperties: false truncated: type: boolean provider: type: string required: - domain - subdomainCount - subdomains - certCount - certs - truncated - provider additionalProperties: false total: type: integer nullable: true description: Total matching rows upstream; null when unknown. source: $ref: '#/components/schemas/Source' required: - ok - items - total - source additionalProperties: false meta: $ref: '#/components/schemas/CallMeta' '400': $ref: '#/components/responses/BadRequest' '402': $ref: '#/components/responses/PaymentRequired' '405': $ref: '#/components/responses/MethodNotAllowed' '500': $ref: '#/components/responses/ServerError' '502': $ref: '#/components/responses/UpstreamError' x-2s-id: domain.ct-logs x-2s-version: null x-2s-price: usd: 0.0054 x-2s-accepts: - x402 x-2s-response-shape: normalized x-payment-info: price: mode: fixed currency: USD amount: '0.005400' protocols: - x402: {} parameters: - name: domain in: query required: true description: Domain name to look up. schema: type: string minLength: 3 maxLength: 253 - name: limit in: query required: false description: Maximum number of results to return. schema: type: integer minimum: 1 maximum: 500 - $ref: '#/components/parameters/TrialMode' /api/domain/email-security: get: tags: - Domain summary: Grade a domain's email-authentication and DNS-security description: 'Grade a domain''s email-authentication and DNS-security posture from live DNS in one call: SPF, DMARC (policy + alignment), DKIM (for the supplied or common selectors), MTA-STS, TLS-RPT, DNSSEC, CAA, and BIMI. Pass domain (and optional dkimSelector). Returns an overall letter grade, a summary (spf/dmarcPolicy/dkim/mtaSts/dnssec/caa/bimi + spoofingProtected), and a per-mechanism block with the raw record, parsed tags, and specific issues (e.g. ''DMARC p=none — monitor only'', ''SPF ~all soft-fail'', ''no MTA-STS''). Sourced from live public DNS via DNS-over-HTTPS — an LLM cannot know a domain''s current records. For deliverability/anti-spoofing audits, vendor security review, and phishing-resistance checks. DKIM is selector-based (selectors aren''t enumerable), so ''not found'' only means none of the checked selectors resolved.' operationId: domain_email-security deprecated: false security: - x402Payment: [] responses: '200': description: 'Normalized envelope: items = [posture report with grade + per-mechanism blocks]; total = 1.' content: application/json: schema: type: object required: - data - meta properties: data: type: object properties: ok: type: boolean enum: - true items: type: array items: type: object properties: domain: type: string grade: type: string summary: type: object properties: spf: type: boolean nullable: true dmarcPolicy: type: string nullable: true dkim: type: boolean nullable: true mtaSts: type: boolean nullable: true dnssec: type: boolean nullable: true caa: type: boolean nullable: true bimi: type: boolean nullable: true spoofingProtected: type: boolean required: - spf - dmarcPolicy - dkim - mtaSts - dnssec - caa - bimi - spoofingProtected additionalProperties: false spf: type: object additionalProperties: {} dmarc: type: object additionalProperties: {} dkim: type: object additionalProperties: {} mtaSts: type: object additionalProperties: {} tlsRpt: type: object additionalProperties: {} dnssec: type: object properties: enabled: type: boolean nullable: true required: - enabled additionalProperties: false caa: type: object additionalProperties: {} bimi: type: object additionalProperties: {} note: type: string required: - domain - grade - summary - spf - dmarc - dkim - mtaSts - tlsRpt - dnssec - caa - bimi - note additionalProperties: false total: type: integer nullable: true description: Total matching rows upstream; null when unknown. source: $ref: '#/components/schemas/Source' required: - ok - items - total - source additionalProperties: false meta: $ref: '#/components/schemas/CallMeta' '400': $ref: '#/components/responses/BadRequest' '402': $ref: '#/components/responses/PaymentRequired' '405': $ref: '#/components/responses/MethodNotAllowed' '500': $ref: '#/components/responses/ServerError' '502': $ref: '#/components/responses/UpstreamError' x-2s-id: domain.email-security x-2s-version: null x-2s-price: usd: 0.0045 x-2s-accepts: - x402 x-2s-response-shape: normalized x-payment-info: price: mode: fixed currency: USD amount: '0.004500' protocols: - x402: {} parameters: - name: domain in: query required: true description: Domain name to look up. schema: type: string minLength: 3 maxLength: 253 - name: dkimSelector in: query required: false description: Dkim selector. schema: type: string minLength: 1 maxLength: 63 - $ref: '#/components/parameters/TrialMode' /api/domain/intel: get: tags: - Domain summary: Domain intelligence in one call - composes DNS, WHOIS/RDAP description: 'Domain intelligence in one call — composes DNS, WHOIS/RDAP registration, and the live TLS certificate for a domain. Pass domain (e.g. example.com). Returns a summary (does it resolve, has MX, registrar, domain expiry, whether HTTPS is currently valid, days until cert expiry) plus three independent sections: dns (A/AAAA/MX/NS/TXT records), whois (registrar, registered/expires/updated dates, status codes, nameservers, DNSSEC), and tls (certificate issuer, subject, validity window, SANs, fingerprint). Each section reports found/error independently, so a domain with no HTTPS still returns DNS + WHOIS. For domain due diligence, security recon, expiry monitoring, and vendor onboarding. Individual sources: /api/dns/lookup, /api/domain/whois, /api/net/tls-cert.' operationId: domain_intel deprecated: false security: - x402Payment: [] responses: '200': description: 'Normalized envelope: items = [domain dossier with dns/whois/tls sections]; total = 1.' content: application/json: schema: type: object required: - data - meta properties: data: type: object properties: ok: type: boolean enum: - true items: type: array items: type: object properties: query: type: object properties: domain: type: string required: - domain additionalProperties: false summary: type: object properties: resolves: type: boolean nullable: true hasMx: type: boolean nullable: true registrar: type: string nullable: true expiresAt: type: string nullable: true httpsValid: type: boolean nullable: true certExpiresInDays: type: number nullable: true required: - resolves - hasMx - registrar - expiresAt - httpsValid - certExpiresInDays additionalProperties: false dns: type: object properties: found: type: boolean error: type: string nullable: true data: type: object additionalProperties: {} nullable: true required: - found - error - data additionalProperties: false whois: type: object properties: found: type: boolean error: type: string nullable: true data: type: object additionalProperties: {} nullable: true required: - found - error - data additionalProperties: false tls: type: object properties: found: type: boolean error: type: string nullable: true data: type: object additionalProperties: {} nullable: true required: - found - error - data additionalProperties: false sources: type: array items: $ref: '#/components/schemas/Source' note: type: string required: - query - summary - dns - whois - tls - sources - note additionalProperties: false total: type: integer nullable: true description: Total matching rows upstream; null when unknown. source: $ref: '#/components/schemas/Source' required: - ok - items - total - source additionalProperties: false meta: $ref: '#/components/schemas/CallMeta' '400': $ref: '#/components/responses/BadRequest' '402': $ref: '#/components/responses/PaymentRequired' '405': $ref: '#/components/responses/MethodNotAllowed' '500': $ref: '#/components/responses/ServerError' '502': $ref: '#/components/responses/UpstreamError' x-2s-id: domain.intel x-2s-version: null x-2s-price: usd: 0.012 x-2s-accepts: - x402 x-2s-response-shape: normalized x-payment-info: price: mode: fixed currency: USD amount: '0.012000' protocols: - x402: {} parameters: - name: domain in: query required: true description: Domain name to look up. schema: type: string minLength: 3 maxLength: 253 - $ref: '#/components/parameters/TrialMode' /api/domain/whois: get: tags: - Domain summary: 'Modern WHOIS via RDAP. Query: domain (e.g. example.com)' description: 'Modern WHOIS via RDAP. Query: domain (e.g. example.com). Returns { domain, ldhName, handle, registrar:{ name, ianaId, url, abuseEmail, abusePhone }, registeredAt, expiresAt, updatedAt, statuses (camelCase ICANN EPP codes), nameservers[], dnssecSigned, rdapUrl }. GDPR: registrant personal data is generally redacted upstream and not returned. Some TLDs without RDAP are not supported and return 404 TLD_NOT_SUPPORTED.' operationId: domain_whois deprecated: false security: - x402Payment: [] responses: '200': description: 'Normalized envelope: items = [domain record] (registrar, registration/expiry/update dates, EPP statuses, nameservers, DNSSEC, rdapUrl); total = 1.' content: application/json: schema: type: object required: - data - meta properties: data: type: object properties: ok: type: boolean enum: - true items: type: array items: type: object properties: domain: type: string description: The queried domain, normalized to lowercase. ldhName: type: string description: Registry LDH (letters-digits-hyphen) name. handle: type: string nullable: true description: Registry object handle. registrar: type: object properties: name: type: string nullable: true ianaId: type: string nullable: true url: type: string nullable: true abuseEmail: type: string nullable: true abusePhone: type: string nullable: true required: - name - ianaId - url - abuseEmail - abusePhone additionalProperties: false registeredAt: type: string nullable: true expiresAt: type: string nullable: true updatedAt: type: string nullable: true statuses: type: array items: type: string description: camelCase ICANN EPP status codes. nameservers: type: array items: type: string dnssecSigned: type: boolean nullable: true rdapUrl: type: string nullable: true description: The registry RDAP URL that answered. required: - domain - ldhName - handle - registrar - registeredAt - expiresAt - updatedAt - statuses - nameservers - dnssecSigned - rdapUrl additionalProperties: false total: type: integer nullable: true description: Total matching rows upstream; null when unknown. source: $ref: '#/components/schemas/Source' required: - ok - items - total - source additionalProperties: false meta: $ref: '#/components/schemas/CallMeta' '400': $ref: '#/components/responses/BadRequest' '402': $ref: '#/components/responses/PaymentRequired' '405': $ref: '#/components/responses/MethodNotAllowed' '500': $ref: '#/components/responses/ServerError' '502': $ref: '#/components/responses/UpstreamError' x-2s-id: domain.whois x-2s-version: null x-2s-price: usd: 0.0025 x-2s-accepts: - x402 x-2s-response-shape: normalized x-payment-info: price: mode: fixed currency: USD amount: '0.002500' protocols: - x402: {} parameters: - name: domain in: query required: true description: Domain name to look up. schema: type: string minLength: 3 maxLength: 253 - $ref: '#/components/parameters/TrialMode' components: schemas: Source: type: object description: 'Provenance of the data: upstream provider, source URL, and license.' properties: provider: type: string description: Upstream data provider. url: type: string description: Source URL or documentation link. license: type: string description: License / usage terms for the data. CallMeta: type: object description: Per-call meta envelope — endpoint id, cost, caller kind, settlement details. X402PaymentRequiredV2: type: object description: x402 v2 PaymentRequired envelope. Pick any entry from accepts[], sign for that rail, retry with the PAYMENT-SIGNATURE header. required: - x402Version - accepts properties: x402Version: type: integer const: 2 error: type: string description: Human-readable reason payment is required. resource: type: string description: The resource URL being purchased. accepts: type: array description: Payment requirement options, one per supported network (Base USDC, Solana USDC). items: type: object required: - scheme - network - amount - asset - payTo - maxTimeoutSeconds properties: scheme: type: string enum: - exact network: type: string description: CAIP-2 network id, e.g. "eip155:8453" (Base) or "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp". amount: type: string description: Price in atomic asset units (USDC has 6 decimals). asset: type: string description: Asset contract address / mint. payTo: type: string description: Treasury address to pay. maxTimeoutSeconds: type: integer extra: type: object description: 'Rail-specific extras (EVM: EIP-712 domain name/version; Solana: feePayer).' additionalProperties: true extensions: type: object description: Optional discovery metadata (e.g. bazaar input/output schemas). additionalProperties: true responses: PaymentRequired: description: Payment required. Body contains the x402 PaymentRequirements envelope with a multi-network accepts array; the per-call price is in accepts[].amount (and on the operation as x-2s-price). Sign for whichever rail you hold USDC on (EIP-3009 for Base, partial SPL transfer for Solana) and retry with the PAYMENT-SIGNATURE header (X-PAYMENT also accepted for v1 clients). content: application/json: schema: $ref: '#/components/schemas/X402PaymentRequiredV2' UpstreamError: description: Upstream provider error. MethodNotAllowed: description: Method not allowed — see `Allow` header for the supported method. ServerError: description: Internal server error. BadRequest: description: Bad request — invalid parameters. parameters: TrialMode: name: trial in: query required: false description: 'Try before you buy. Set to 1 for one free real call per endpoint per hour — no wallet or payment needed — to verify the endpoint before paying. Equivalent to sending the "X-2s-Trial: 1" request header. Works on every endpoint.' schema: type: integer enum: - 1 securitySchemes: x402Payment: type: apiKey in: header name: PAYMENT-SIGNATURE description: 'x402 protocol v2: base64-encoded PaymentPayload. Call any paid endpoint without auth to receive a 402 with a multi-network PaymentRequirements envelope. Sign for either rail: EIP-3009 transferWithAuthorization (Base USDC) OR a partial SPL token transfer (Solana USDC). Retry with PAYMENT-SIGNATURE header. X-PAYMENT is also accepted for v1 buyer clients. See https://x402.org.'