One request, in under a minute
Send your key in the x-api-key header. Every response is a small, stable envelope: metadata plus the engine's full report under result.
Request
# Scan a wallet for risky token approvals across 5 EVM chains
curl -s "https://veriql.pages.dev/api/v1/scan?address=0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045" \
-H "x-api-key: vq_live_your_key_here"
Response
{
"version": "1",
"endpoint": "scan",
"requestId": "req_2b1e0c…",
"result": {
"address": "0xd8da…6045",
"score": { "score": 49, "grade": "D", "label": "At risk",
"drivers": [{ "label": "1 dangerous approval", "points": -51 }] },
"dangerCount": 1, "warnCount": 0,
"findings": [{ "chainId": 1, "chainName": "Ethereum",
"approval": { "tokenSymbol": "USDC", "spender": "0x…",
"risk": "danger", "isUnlimited": true,
"riskReasons": ["spender on GoPlus blacklist"] } }],
"totalExposureUsd": 1240.55
},
"disclaimer": "Read-only, best-effort risk signal. Detects known patterns; may miss novel attacks. Not financial advice."
}
API keys
Pass your key as the x-api-key request header (or a ?key= query param for quick tests). Keys look like vq_live_…. Grab one from the pricing section below.
1 credit per call
Each successful (2xx) response spends one credit. Malformed requests and errors are always free.
Live balance headers
Every response carries X-Credits-Remaining and X-RateLimit-Remaining, so you always know where you stand.
Instant, no signup
Grab a free key in one click, or buy a credit pack in USDT/USDC and your key is provisioned automatically.
Endpoints
Three GET endpoints, all under /api/v1. Each returns the uniform envelope with the engine's full, auditable report under result.
/api/v1/scanWallet approval-risk scan across 5 EVM chains (Ethereum, BNB Chain, Polygon, Arbitrum, Base). Returns a 0-100 Security Score with itemised drivers, every risky approval, and a best-effort USD value-at-risk.
| Parameter | Required | Description |
|---|---|---|
| address | yes | The public EVM address to scan (0x…). |
/api/v1/tokenToken / contract security check (honeypot, taxes, mintable supply, hidden owner, proxy, and more) with each finding surfaced as a plain-English flag. EVM chains and Tron.
| Parameter | Required | Description |
|---|---|---|
| address | yes | The token contract address. |
| chainId | no | Chain id or key (e.g. 1, base, tron). Defaults to Ethereum. |
/api/v1/launchA rigorous, transparent 0-100 launch-safety score built from contract, holder, liquidity and trading signals. Returns the score, a band, the full metrics, and every penalty as an itemised driver, so you can show your users exactly why. EVM chains, Tron and Solana.
| Parameter | Required | Description |
|---|---|---|
| address | yes | The token contract / mint address. |
| chainId | no | Chain id or key (e.g. 1, base, solana). Defaults to Ethereum. |
/api/v1/blocklistDrain Watch lookup: is this a known drainer/scam address? Answered entirely from Veriql's own in-memory blocklist (no upstream call), so it's fast and cheap. A hit returns its category, a computed confidence, and every contributing source; a miss means no known listing found: not "safe". Covers EVM, Bitcoin, Solana and Tron.
| Parameter | Required | Description |
|---|---|---|
| address | yes | The address to check, in the format native to chain. |
| chain | no | One of evm, btc, solana, tron. Defaults to evm. |
Request
# Look up an address against the Drain Watch blocklist
curl -s "https://veriql.pages.dev/api/v1/blocklist?address=0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045&chain=evm" \
-H "x-api-key: vq_live_your_key_here"
Response
{
"version": "1",
"endpoint": "blocklist",
"requestId": "req_9f3a1d…",
"result": {
"listed": false,
"category": null,
"confidence": null,
"first_seen": null,
"sources": []
},
"disclaimer": "Read-only, best-effort risk signal. Detects known patterns; may miss novel attacks. Not financial advice."
}
Metered like the other endpoints: 1 credit per successful call, with a generous free allowance. The same list also ships free, unauthenticated, as a public feed and an open JSON export.
Machine-readable: the full contract is published as an OpenAPI 3.1 spec, and an llms.txt is provided for AI agents and coding assistants.
We show the math
Most risk APIs hand you an opaque number. Veriql returns the drivers behind every score, the exact deductions, flags and metrics, so you can display an auditable breakdown to your users and defend the verdict.
Scores with drivers
The wallet Security Score and the launch-safety score each ship an itemised drivers array: every penalty, labelled, with its point cost.
Honest by design
We never label an asset "safe". A clean result means no known risks were found, not a guarantee. Every response carries that disclaimer.
Read-only, non-custodial
Public on-chain data only. Nothing to connect, nothing to sign, no key to your users' funds ever touches the API.
Call Veriql from Claude & Cursor
Veriql ships a Model Context Protocol server, so an AI agent can run the risk checks itself: veriql_scan, veriql_token, veriql_launch. Add it with your key:
claude_desktop_config.json · .cursor/mcp.json
{
"mcpServers": {
"veriql": {
"command": "npx",
"args": ["-y", "@veriql/mcp"],
"env": { "VERIQL_API_KEY": "vq_live_your_key" }
}
}
}
Every agent call runs through your metered credits. Start with a free key. Same read-only engine, same "shows-the-math" output. The @veriql/mcp package is rolling out to npm; until it lands you can run the server straight from the repo (npm run mcp).
Prepaid credits, priced under the incumbents
1 credit = 1 successful call. Buy a pack in USDT/USDC, get your key instantly, top up anytime. Start free: no card, no signup.
How metering works: one credit per successful (2xx) response; failed requests are free; each key also has a per-minute rate limit. Every response carries X-Credits-Remaining and X-RateLimit-Remaining. Paid keys are provisioned automatically once the payment confirms on-chain, then shown on the claim page.
Status codes
Errors share the envelope shape: { "version": "1", "error": { "code", "message" } }.
| Status | Code | Meaning |
|---|---|---|
| 400 | invalid_request | Missing or malformed address, or an unsupported chain. |
| 401 | unauthorized | Missing, invalid, or revoked API key. |
| 402 | quota_exhausted | Out of credits (or monthly quota reached). Top up to keep calling. |
| 429 | rate_limited | Per-minute rate exceeded. Back off and retry. |
| 501 | not_enabled | The API is not enabled on this deployment. |
Questions
Where does the data come from?
Approval and token-security data come from GoPlus Security; liquidity and trading data from DexScreener. Veriql adds the transparent 0-100 scoring and the auditable driver breakdown on top.
Is a clean result a guarantee?
No. A clean result means none of the automated checks tripped, no known risks were found. Contracts can be upgraded and liquidity can be pulled. Treat it as a signal, not a promise.
How do I get a key?
Click "Get a free key" for an instant key with 1,000 credits, or buy a credit pack in USDT/USDC. Your key is provisioned automatically and shown on the next page. Top up anytime by pasting your key above.
What chains are covered?
The wallet scan covers 5 EVM chains. Token checks cover EVM chains and Tron. The launch-safety score adds Solana.