HostDeFi website screenshot

HostDeFi

HostDeFi is a non-custodial Solana token-risk service that scans a mint before a purchase — mint and freeze authority state, liquidity depth and lock status, holder concentration, dangerous Token-2022 extensions, sell simulation and contract flags. The public contract is an OpenAPI 3.1 document of 32 operations served from hostdefi.com/api with API-key authentication. HostDeFi also exposes an x402 machine-payment surface: an authority quick-check endpoint that returns HTTP 402 with a signed payment challenge, priced in USDC and payable on either Solana or Base, so an agent can buy a single check without an account.

HostDeFi publishes 7 APIs on the APIs.io network, including Token Risk API, Analyze Token API, Health API, and 4 more. Tagged areas include Solana, Token Risk, DeFi, rug pull, and x402.

HostDeFi’s developer surface includes authentication, pricing, support, and 22 more developer resources.

44.4/100 developing ▬ flat Agent 43/100 agent ready Full breakdown ↓
scored 2026-09-14 · rubric v0.22.0
1 APIs 1 MCP Servers
SolanaToken RiskDeFirug pullx402

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-14 · rubric v0.22.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/hostdefi: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 7

Individual APIs this provider publishes, each with its own machine-readable definition.

HostDeFi Token Risk API

Token risk scanning for Solana mints — authority state, liquidity, holder concentration, Token-2022 extension flags and sell simulation. 26 operations, API-key authentication.

HostDeFi Analyze Token API

The Analyze Token API from HostDeFi — 1 operation(s) for analyze token.

HostDeFi Health API

The Health API from HostDeFi — 1 operation(s) for health.

HostDeFi Keys API

The Keys API from HostDeFi — 1 operation(s) for keys.

HostDeFi Scan API

The Scan API from HostDeFi — 1 operation(s) for scan.

HostDeFi Usage API

The Usage API from HostDeFi — 1 operation(s) for usage.

HostDeFi x402 (machine-payable) API

Pay-per-call lane for AI agents (x402 protocol): no key, no account - pay USDC per request and get the same A+-F Safety Read. Free tier and API-key plans are unchanged and remai...

Scroll for all 7

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Hostdefi Rate Limits

3 limits

RATE LIMITS

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Hostdefi Authentication

apiKey · 1 scheme

SECURITY

Hostdefi Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Hostdefi Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Hostdefi Agentic Access

32 operations · 10 acting

32 operations · 10 acting

AGENTIC

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 5

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 5

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: hostdefi
name: HostDeFi
description: 'HostDeFi is a non-custodial Solana token-risk service that scans a mint before a purchase — mint and freeze
  authority state, liquidity depth and lock status, holder concentration, dangerous Token-2022 extensions, sell simulation
  and contract flags. The public contract is an OpenAPI 3.1 document of 32 operations served from hostdefi.com/api with API-key
  authentication. HostDeFi also exposes an x402 machine-payment surface: an authority quick-check endpoint that returns HTTP
  402 with a signed payment challenge, priced in USDC and payable on either Solana or Base, so an agent can buy a single check
  without an account.'
type: Index
url: https://raw.githubusercontent.com/api-evangelist/hostdefi/refs/heads/main/apis.yml
deliveryModel:
  model: unknown
  open_source: false
  commercial: false
  callable_host: true
  label: Delivery model not determined — needs a product licence on record
  confidence: low
  source:
  - openapi
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-09-02'
  method: derived
created: '2026-08-21'
modified: '2026-09-03'
specificationVersion: '0.23'
tags:
- Solana
- Token Risk
- DeFi
- rug pull
- x402
tags_raw:
- solana
- token risk
- defi
- rug pull
- x402
apis:
- aid: hostdefi:hostdefi-token-risk-api
  name: HostDeFi Token Risk API
  description: Token risk scanning for Solana mints — authority state, liquidity, holder concentration, Token-2022 extension
    flags and sell simulation. 26 operations, API-key authentication.
  humanURL: https://hostdefi.com/docs/api/
  baseURL: https://hostdefi.com/api
  tags:
  - Solana
  - Token Risk
  - Security
  properties:
  - type: OpenAPI
    url: openapi/hostdefi-token-risk-api-openapi.yml
  - type: Documentation
    url: https://hostdefi.com/docs/api/
  - type: APIReference
    url: https://hostdefi.com/api/v1/openapi.json
  - type: FinOps
    url: finops/hostdefi-x402-challenge.json
  - type: MCPServer
    url: mcp/hostdefi-mcp.yml
  - type: ToolCrosswalk
    url: mcp/hostdefi-tool-crosswalk.yml
- aid: hostdefi:hostdefi-analyze-token-api
  name: HostDeFi Analyze Token API
  description: The Analyze Token API from HostDeFi — 1 operation(s) for analyze token.
  humanURL: https://hostdefi.com/docs/api/
  baseURL: https://hostdefi.com/api
  tags:
  - Analyze Token
  properties:
  - type: OpenAPI
    url: openapi/hostdefi-analyze-token-api-openapi.yml
- aid: hostdefi:hostdefi-health-api
  name: HostDeFi Health API
  description: The Health API from HostDeFi — 1 operation(s) for health.
  humanURL: https://hostdefi.com/docs/api/
  baseURL: https://hostdefi.com/api
  tags:
  - Health
  properties:
  - type: OpenAPI
    url: openapi/hostdefi-health-api-openapi.yml
- aid: hostdefi:hostdefi-keys-api
  name: HostDeFi Keys API
  description: The Keys API from HostDeFi — 1 operation(s) for keys.
  humanURL: https://hostdefi.com/docs/api/
  baseURL: https://hostdefi.com/api
  tags:
  - Keys
  properties:
  - type: OpenAPI
    url: openapi/hostdefi-keys-api-openapi.yml
- aid: hostdefi:hostdefi-scan-api
  name: HostDeFi Scan API
  description: The Scan API from HostDeFi — 1 operation(s) for scan.
  humanURL: https://hostdefi.com/docs/api/
  baseURL: https://hostdefi.com/api
  tags:
  - Scans
  tags_raw:
  - Scan
  properties:
  - type: OpenAPI
    url: openapi/hostdefi-scan-api-openapi.yml
- aid: hostdefi:hostdefi-usage-api
  name: HostDeFi Usage API
  description: The Usage API from HostDeFi — 1 operation(s) for usage.
  humanURL: https://hostdefi.com/docs/api/
  baseURL: https://hostdefi.com/api
  tags:
  - Usage
  properties:
  - type: OpenAPI
    url: openapi/hostdefi-usage-api-openapi.yml
- aid: hostdefi:hostdefi-x402-machine-payable-api
  name: HostDeFi x402 (machine-payable) API
  description: 'Pay-per-call lane for AI agents (x402 protocol): no key, no account - pay USDC per request and get the same
    A+-F Safety Read. Free tier and API-key plans are unchanged and remain the better per-call price for steady use.'
  humanURL: https://hostdefi.com/docs/api/
  baseURL: https://hostdefi.com/api
  tags:
  - x402 (machine-payable)
  properties:
  - type: OpenAPI
    url: openapi/hostdefi-x402-machine-payable-api-openapi.yml
common:
- type: AgenticAccess
  url: agentic-access/hostdefi-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/hostdefi-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/hostdefi-domain-security.yml
- type: Authentication
  url: authentication/hostdefi-authentication.yml
- type: MCPServer
  url: mcp/hostdefi-mcp.yml
- type: FinOps
  url: finops/hostdefi-x402-manifest.json
- type: LLMsTxt
  url: llms/hostdefi-llms.txt
- type: Website
  url: https://hostdefi.com
- type: DeveloperPortal
  url: https://hostdefi.com/docs/api/
- type: AgentCard
  url: a2a/hostdefi-a2a.yml
- type: WellKnown
  url: well-known/hostdefi-well-known.yml
- type: SecurityTxt
  url: well-known/hostdefi-security.txt
- type: Security
  url: https://hostdefi.com/why
- type: ErrorCatalog
  url: errors/hostdefi-problem-types.yml
- type: Lifecycle
  url: lifecycle/hostdefi-lifecycle.yml
- type: Conformance
  url: conformance/hostdefi-conformance.yml
- type: Conventions
  url: conventions/hostdefi-conventions.yml
- type: Plans
  url: plans/hostdefi-plans-pricing.yml
- type: RateLimits
  url: rate-limits/hostdefi-rate-limits.yml
- type: Packages
  url: packages/hostdefi-packages.yml
- type: DataModel
  url: data-model/hostdefi-data-model.yml
- type: AgentSkill
  url: skills/_index.yml
- type: Overlay
  url: overlays/hostdefi-token-risk-api-overlay.yaml
- type: Pricing
  url: https://hostdefi.com/docs/api/
- type: Support
  url: https://t.me/hostdefiapps
maintainers:
- FN: HostDeFi
  email: apisio@hostdefi.com
  url: https://hostdefi.com
x-provenance:
  added: '2026-08-21'
  method: searched
  source: https://hostdefi.com/llms.txt
  note: 'Submitted via apis.io/add on 2026-08-20 (twice, as "HostDeFi" and "HostDeFi Token Risk API" — one provider, two records
    at the gate). The submitted APIs.json URL, https://hostdefi.com/apis.json, returns 404 against a control that also 404s,
    so the 404 is real; that is a bad pointer in the submission, not an absent surface. NO API-CATALOG IS RECORDED, DELIBERATELY.
    https://hostdefi.com/.well-known/api-catalog returns HTTP 200, but the body is the site''s HTML homepage, not a linkset.
    Recording it as an APICatalog would hand HostDeFi credit for a discovery document it does not serve. The path answering
    200 is not the same as the artifact existing. The x402 surface was verified live. GET /api/v1/x402/authority/solana/{mint}
    without a payment header returns HTTP 402 with x402Version 1 and two `accepts` entries — USDC on Solana and on Base, maxAmountRequired
    5000, 60-second timeout, with a named feePayer. The saved challenge in finops/ is that response verbatim. The REST API
    was probed at /api/v1/health and returned 200. One thing for the provider rather than for us: the published contract lists
    a second server, https://awake-integrity-production-faa0.up.railway.app, which also answers /v1/health with 200. That
    looks like a staging backend reachable from a production specification.

    CORRECTION, recorded because it matters more than the finding. This record was first built by hand from llms.txt plus
    probed paths, and it UNDER-reported the provider. The Add-API gate''s own stub named two artifacts the hand pass missed,
    and both are real: a hosted MCP server at https://hostdefi.com/api/v1/mcp, which answers tools/list anonymously with NINE
    tools, and an x402 discovery manifest at https://hostdefi.com/.well-known/x402 serving application/json with x402Versions
    [1,2], a payTo address and a facilitator. The MCP tools carry their own prices in their descriptions: scan_token and get_x402_pricing
    are free, token_risk_verdict $0.01/call, pregrad_signals $0.03, radar_alerts $0.01, x402_provider_risk $0.02, swap_evm_quote
    $0.01, swap_evm_price $0.002, and buy_api_key $5 as a single payment that mints a 30-day Agent-plan key -- an agent can
    buy its own credential. Guessing paths and reading llms.txt was not sufficient here; the gate''s discovery was better
    than the hand pass.'
image: https://hostdefi.com/logo512.png
x-enrichment:
  date: '2026-09-03'
  status: enriched
  artifacts_added: 25
  pass: local-v2

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/hostdefi"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/hostdefi/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/hostdefi/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.