HTTP

API

Public machine endpoints. CORS is open. Demo key surf_live_demo000000000000 — optional on inspect, preflight, and ingest. Missing key bills the demo meter. Bad key returns 401. Killed hops return 410 and do not bill.

GET /h/:code

$0.40 / 1k

302 to the hop destination if the host is on the allow-list. Killed hops return 410. Demo code: xai.

GET /px/:code

$0.15 / 1k

Returns a 1×1 GIF. Embed as an image. Demo code: pxdemo.

POST /mcp

$0.25 / 1k on tool call

Model Context Protocol. Tool name preflight_url. Cursor / Claude: type http, url this origin + /mcp. initialize, tools/list, then tools/call. Same unwrap + next as GET /v1/preflight.

GET /v1/preflight

$0.25 / 1k

Pass url= as a query (or JSON on POST). Unwraps short links (t.co, bit.ly, lnkd.in, youtu.be). Returns final_url, unwrapped, verdict, and next: fetch or skip. We never return the page body. Private hosts and odd ports are refused.

GET /v1/inspect

$0.20 / 1k

Classifies the caller from User-Agent: bot, browser, or script. Device and engine included. This is the product computers actually need.

POST /v1/event

$0.10 / 1k

JSON body optional. Authorization: Bearer surf_live_… bills that meter. { "name": "signup" }. Returns 202 with a request id.

Call it from here

Same requests a script would make. Watch the console log update.

GET /h/xai

Mint more endpoints in the console or settle usage on billing.