Blooms
Security
Distribute keys once for serverless applications
Threat intelligence, breach lookup, vulnerability feeds and scanning.
71 listed · 24 need no key · 13 work in the browser
Security
Distribute keys once for serverless applications
Security
Ephemeral zero-knowledge encrypted data sharing
Security
FishFish is an automated service designed to quickly detect and mitigate phishing threats before they can be exploited for malicious purposes. It provides a streamlined solution for identifying harmful resources efficiently.
Security
A REST API to access high level cryptographic functions and methods
Security
Programmatic interfaces to engage with the Microsoft Security Response Center (MSRC)
Security
U.S. National Vulnerability Database
Security
Security and developer utility API -- malware, vulnerability, and domain checks, no signup
Security
Virushee file/data scanning
Security
Encrypting & decrypting text messages
Security
Generate certificate signing requests and private keys without OpenSSL
Security
CVE records with NVD KEV and EPSS enrichment
Security
Hash decryption MD5, SHA1, SHA3, SHA256, SHA384, SHA512
Security
Email address threat and risk prediction
Security
An API for escaping different kind of queries
Security
Lists of filters for adblockers and firewalls
Security
Free VPN, proxy, Tor and datacenter IP detection. 13 sources, active probing
Security
Mozilla observatory http scanner
Security
Mozilla observatory tls scanner
Security
Generate random passwords of varying complexities
Security
Phishing database
Security
Scans the requesting client's IP for open TCP ports with fast or deep modes on IPv4/IPv6
Security
Deep SSL/TLS server analysis with A+ to F grading
Security
UK Police data
Security
Database of malicious URLs used for malware distribution
Counts and timings below come from our own scheduled checks of this category.
We track 71 in this category, of which 50 responded at our last check. 24 of them need no API key.
24 of the 71 entries here need no credential. Filter this page by "no key" to see them, or browse the no-key collection for every keyless API across all categories.
8 entries in this category need no key and return CORS headers, which is the combination that lets you call them straight from client-side JavaScript. The rest need a server or a proxy in between.
Of the keyless options that responded at our last check, CVE.report was quickest at a median 332 ms. Speed is only one factor — coverage and licensing usually matter more — but it is measured here rather than claimed.
We call every listing on a schedule and record the status code, response time and whether CORS headers came back. Those results drive the badges on this page. Across the whole catalogue, 487 of 2,712 entries were not responding at the last full run, which is the sort of thing an unchecked list never tells you.