HostDeFi

HostDeFi is a non-custodial Solana token-risk service that scans a mint before a purchase — mint and freeze authority state, liquidity depth and lock status, holder concentration, dangerous Token-2022 extensions, sell simulation and contract flags. The public contract is an OpenAPI 3.1 document of 26 operations served from hostdefi.com/api with API-key authentication. HostDeFi also exposes an x402 machine-payment surface: an authority quick-check endpoint that returns HTTP 402 with a signed payment challenge, priced in USDC and payable on either Solana or Base, so an agent can buy a single check without an account.

HostDeFi publishes 1 API on the APIs.io network: Token Risk API. Tagged areas include Solana, Blockchain, Token Risk, Security, and DeFi.

17.9/100 emerging ▬ flat Agent 27/100 agent aware Full breakdown ↓
scored 2026-08-25 · rubric v0.14.0
1 APIs 1 MCP Servers
SolanaBlockchainToken RiskSecurityDeFix402Agent CommerceCryptoMCPMachine Payments

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-25 · rubric v0.14.0
Composite quality — 17.9/100 · emerging
Contract Quality 11.6 / 21
Developer Ergonomics 1.6 / 17
Access Clarity 0.0 / 17
Operational Transparency 0.0 / 11
Contract Governance 0.0 / 10
Discoverability 6.1 / 9
Regulatory Posture 0.0 / 15
Agent readiness — 27/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 10
Documented Reversibility 0 / 6
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Delegated User Identity 0 / 6
Protected Resource Metadata 0 / 5
Registration Without a Human 0 / 6
Agentic Commerce Surface 0 / 5
Regulatory Posture applies to this provider. Its tags matched the Payments regime, so Regulatory Posture carries 15 points of the composite. If this regime is wrong for your business, say so on your provider repo — the applicability map is public and we will correct it.
The six quality facets above are damped to 85 points between them, because the conditional facet above carries the other 15. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 85% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/hostdefi: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

HostDeFi Token Risk API

Token risk scanning for Solana mints — authority state, liquidity, holder concentration, Token-2022 extension flags and sell simulation. 26 operations, API-key authentication.

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Commercial 1

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: hostdefi
name: HostDeFi
description: 'HostDeFi is a non-custodial Solana token-risk service that scans a mint before a purchase — mint and freeze
  authority state, liquidity depth and lock status, holder concentration, dangerous Token-2022 extensions, sell simulation
  and contract flags. The public contract is an OpenAPI 3.1 document of 26 operations served from hostdefi.com/api with API-key
  authentication. HostDeFi also exposes an x402 machine-payment surface: an authority quick-check endpoint that returns HTTP
  402 with a signed payment challenge, priced in USDC and payable on either Solana or Base, so an agent can buy a single check
  without an account.'
type: Index
url: https://raw.githubusercontent.com/api-evangelist/hostdefi/refs/heads/main/apis.yml
created: '2026-08-21'
modified: '2026-08-21'
specificationVersion: '0.23'
tags:
- Solana
- Blockchain
- Token Risk
- Security
- DeFi
- x402
- Agent Commerce
- Crypto
- MCP
- Machine Payments
tags_raw:
- solana
- token risk
- defi
- rug pull
- x402
apis:
- aid: hostdefi:hostdefi-token-risk-api
  name: HostDeFi Token Risk API
  description: Token risk scanning for Solana mints — authority state, liquidity, holder concentration, Token-2022 extension
    flags and sell simulation. 26 operations, API-key authentication.
  humanURL: https://hostdefi.com/docs/api/
  baseURL: https://hostdefi.com/api
  tags:
  - Solana
  - Token Risk
  - Security
  properties:
  - type: OpenAPI
    url: openapi/hostdefi-token-risk-api-openapi.yml
  - type: Documentation
    url: https://hostdefi.com/docs/api/
  - type: APIReference
    url: https://hostdefi.com/api/v1/openapi.json
  - type: FinOps
    url: finops/hostdefi-x402-challenge.json
  - type: MCPServer
    url: mcp/hostdefi-tools-list.json
common:
- type: MCPServer
  url: mcp/hostdefi-tools-list.json
- type: FinOps
  url: finops/hostdefi-x402-manifest.json
- type: LLMsTxt
  url: llms/hostdefi-llms.txt
- type: Website
  url: https://hostdefi.com
- type: DeveloperPortal
  url: https://hostdefi.com/docs/api/
maintainers:
- FN: HostDeFi
  email: apisio@hostdefi.com
  url: https://hostdefi.com
x-provenance:
  added: '2026-08-21'
  method: searched
  source: https://hostdefi.com/llms.txt
  note: 'Submitted via apis.io/add on 2026-08-20 (twice, as "HostDeFi" and "HostDeFi Token Risk API" — one provider, two records
    at the gate). The submitted APIs.json URL, https://hostdefi.com/apis.json, returns 404 against a control that also 404s,
    so the 404 is real; that is a bad pointer in the submission, not an absent surface. NO API-CATALOG IS RECORDED, DELIBERATELY.
    https://hostdefi.com/.well-known/api-catalog returns HTTP 200, but the body is the site''s HTML homepage, not a linkset.
    Recording it as an APICatalog would hand HostDeFi credit for a discovery document it does not serve. The path answering
    200 is not the same as the artifact existing. The x402 surface was verified live. GET /api/v1/x402/authority/solana/{mint}
    without a payment header returns HTTP 402 with x402Version 1 and two `accepts` entries — USDC on Solana and on Base, maxAmountRequired
    5000, 60-second timeout, with a named feePayer. The saved challenge in finops/ is that response verbatim. The REST API
    was probed at /api/v1/health and returned 200. One thing for the provider rather than for us: the published contract lists
    a second server, https://awake-integrity-production-faa0.up.railway.app, which also answers /v1/health with 200. That
    looks like a staging backend reachable from a production specification.

    CORRECTION, recorded because it matters more than the finding. This record was first built by hand from llms.txt plus
    probed paths, and it UNDER-reported the provider. The Add-API gate''s own stub named two artifacts the hand pass missed,
    and both are real: a hosted MCP server at https://hostdefi.com/api/v1/mcp, which answers tools/list anonymously with NINE
    tools, and an x402 discovery manifest at https://hostdefi.com/.well-known/x402 serving application/json with x402Versions
    [1,2], a payTo address and a facilitator. The MCP tools carry their own prices in their descriptions: scan_token and get_x402_pricing
    are free, token_risk_verdict $0.01/call, pregrad_signals $0.03, radar_alerts $0.01, x402_provider_risk $0.02, swap_evm_quote
    $0.01, swap_evm_price $0.002, and buy_api_key $5 as a single payment that mints a 30-day Agent-plan key -- an agent can
    buy its own credential. Guessing paths and reading llms.txt was not sufficient here; the gate''s discovery was better
    than the hand pass.'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/hostdefi"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/hostdefi/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/hostdefi/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.