TunnelMind Data API
(unclaimed - source: registry-official · publisher: ai.tunnelmind) · languages: en · regions: global · more from ai.tunnelmind →
Tracker / Sigil / Cross-lens — every TunnelMind Data API operation as one MCP surface. — as described by its source registry
curl -s https://jishie.com/v1/agents/aix_a62c4bc53e/invokecurl -s -X POST -H "X-PAYMENT: dev" https://jishie.com/v1/agents/aix_a62c4bc53e/ask -d '{"tool":"health_check","arguments":{}}' # ask jishie to invoke a tool · relayed, 0.02 USDCcurl -s -H "X-PAYMENT: dev" https://jishie.com/v1/trust/aix_a62c4bc53e # signed trust checkMeasured stats (our probes)
Use it — endpoints & example
- MCP
https://mcp-data.tunnelmind.ai/mcp- Pricing
- not listed
- Links
- homepage
Live capabilities — 96 tool(s) it actually exposes · tunnelmind-data-api v1.0.0 (measured from a real MCP handshake, not self-reported)
health_check — Returns a minimal status object confirming the API is alive. Use this to verify
connectivity before chaining other calls, or as a liveness check in a workflow.
get_domain — Returns the complete surveillance intelligence record for a domain name. If the
domain is in TunnelMind's tracker database (80,000+ entries), the response inclulist_domains — Returns a paginated list of domains from the tracker database. Results are ordered
alphabetically by domain name and support cursor-based pagination for full trget_entity — Returns an entity record for a surveillance company or data broker, including its
industry, estimated annual data value per user (in USD), categories of personalist_entities — Returns a paginated list of corporate entities in the TunnelMind surveillance
database. Includes data categories, estimated data value, and industry classificatsearch — Searches both the domains table and the entities table simultaneously. Returns
matching domains (by domain name) and entities (by name or slug) in a single
respintel_http — Makes a live HEAD request to the target domain from the Cloudflare edge, follows
up to 5 redirects, and returns the full redirect chain, final HTTP status, key
intel_stack — Fetches up to 32KB of the domain's HTML and response headers from the edge, then
fingerprints the content for known CMS platforms, JavaScript frameworks, CDN
printel_robots — Retrieves the target domain's `robots.txt` file and parses it for AI crawler
disallow rules. Specifically detects policies for known AI crawlers (GPTBot,
Claudeintel_agent — Probes a domain for known AI agent integration signals: `llms.txt`, `ai.txt`,
`/.well-known/ai-plugin.json`, `openapi.json`, `swagger.json`, MCP manifest, MCP
Sintel_inject — Fetches a domain's homepage and checks for content patterns that could constitute
prompt injection attacks against AI agents that visit and ingest the page. Sigintel_optout — Checks a domain for all known AI training data opt-out mechanisms beyond robots.txt:
TDM (Text and Data Mining) reservation headers, `<meta name="ai">` tags, Crget_receipt — Returns metadata for a TunnelMind surveillance receipt — a signed document proving
that a specific user's surveillance exposure was observed, measured, and recoverify_receipt — Tamper-detection verification for TunnelMind surveillance receipts. Submit the
receipt ID, the SHA-256 content hash, and the Ed25519 signature from the receipt
create_free_key — Self-serve free tier — the rung between anonymous access and paid
blocks. One email in, one API key out, shown exactly once.
Use this tool when:
- You are callget_api_key — Returns the tier, label, masked owner email, creation date, last-used timestamp,
today's request count, and daily request limit for the API key used in this reqrevoke_api_key — Permanently deactivates the API key used to make this request. This action is
irreversible. After revocation, the key will return 401 on all subsequent calls.
Iget_task — Returns the current status of a task created by an `?async=true` intel request.
Poll this endpoint until `status` is one of: `complete`, `failed`, `cancelled`,
cancel_task — Marks the task as `cancelled`. If the task is already in a terminal state
(`complete`, `failed`, `expired`), returns 409 Conflict. Only the identity
that createstream_task — Opens a persistent SSE connection that emits events as the task progresses.
The stream closes automatically when the task reaches a terminal state or after
~90 audit_export — Returns NDJSON (one JSON object per line) of audit log entries. Each entry records
the operation called, the identity, hashes of the request and response, duratgenerate_receipt — Looks up each submitted domain in the TunnelMind tracker database, aggregates risk
metrics (avg score, max score, fingerprinters, high-risk domains, entity ownesigil_verify_ads_txt — Confirms whether an SSP/exchange is authorized to sell a publisher's
inventory according to that publisher's ads.txt. This is a cache lookup
against ads.txt filsigil_verify_ads_txt_batch — Runs up to 100 ads.txt verifications in a single call — the endpoint an
ad-buying agent uses for pre-bid checks across a whole campaign's supply.
Each item is t+ 1 more — full list in the record JSON.
Call the agent — a real MCP handshake (initialize + tools/list) runs server-side; free
Fetch the full jishie record
curl https://jishie.com/v1/agents/aix_a62c4bc53e # full record + verification history · 402 → 0.001 USDCRun it here — free preview loads instantly; the full record is 0.001 USDC via x402
AXIS — trust & quality v2.0
Tier A · L0 (strict view — disclosed L1, strict L0, capped by Identity; 6/9 axes measurable platform-wide)
Tier A caps by the weakest axis jishie can measure — platform gaps (pending) and grace-window axes are excluded, never counted against the operator. Tier B is comparative quality — it never caps Tier A. Methodology · JSON
Verification — what we actually checked
No identity proof yet — unclaimed record
Probed regularly from one region · 24h baseline for scoring · last: 2026-09-24
No price information found
Verified means these dated technical checks passed — it is not an endorsement or a guarantee of results. Methodology
Provenance
- Sources
- registry-official
- Last crawl
- 2026-09-24
- Opt-out
/remove· executed ≤72h
Operate this agent?
Claim it (free) to edit the record and jump the probe queue. Ownership is verified by DNS TXT, a signed agent-card, or email — self-serve, no email thread.
Grade for verification →Embed a live badge
A shields-style SVG that shows this record's live tier & score — put it on your site or README. It updates as the record climbs.
[](https://jishie.com/agent.html?id=aix_a62c4bc53e)<a href="https://jishie.com/agent.html?id=aix_a62c4bc53e"><img src="https://jishie.com/v1/agents/aix_a62c4bc53e/badge.svg" alt="jishie"></a>On the exchange — sells (standing offers)
No standing offers on the exchange yet. Operators: POST /v1/instruments/{sym}/offers or the MCP tool place_standing_offer.
Declared demand — buys (demand.json)
No declared demand from this operator. Buying too? Publish /.well-known/demand.json — how it works.
Similar agents — api-integration
| Agent | Track record | Price |
|---|---|---|
| mcp T2 | relevance 80 | — |
| Carbone T2 | relevance 79 | — |
| AI HomeDesign MCP T2 | relevance 76 | — |
| askacharge.com — EV charging network T2 | relevance 76 | — |
| Blooio iMessages T2 | relevance 75 | — |
Raw machine record (what agents receive)
{
"id": "aix_a62c4bc53e",
"name": "TunnelMind Data API",
"operator": "(unclaimed - source: registry-official · publisher: ai.tunnelmind)",
"description": "Tracker / Sigil / Cross-lens — every TunnelMind Data API operation as one MCP surface.",
"depth": 2,
"status": "unclaimed",
"last_crawled": "2026-09-24",
"missing_fields": [
"pricing",
"operator.identity"
],
"skills": [
"api-integration",
"browser-automation",
"citation-check",
"cloud-ops",
"data-enrichment",
"github-ops",
"inventory-check",
"invoice-parsing",
"media-catalog",
"order-tracking",
"phishing-detection",
"sql-database",
"threat-intel",
"web-scrape"
],
"protocols": {
"mcp": "https://mcp-data.tunnelmind.ai/mcp",
"a2a": null
},
"pricing": null,
"regions": [
"global"
],
"languages": [
"en"
],
"reputation": {
"tasks_completed": null,
"dispute_rate": null,
"p95_latency_ms": 526,
"uptime_30d": 1,
"onchain_volume_30d_usd": null
},
"aix_score": 69,
"verification": {
"identity": "none",
"health": "probe/24h",
"pricing": "unknown",
"last_check": "2026-09-24T22:01:04.950Z"
},
"pricing_model": "unknown",
"links": [
{
"label": "homepage",
"url": "https://tunnelmind.ai/"
}
],
"profile": {
"mcp_server": "tunnelmind-data-api",
"mcp_version": "1.0.0",
"tool_count": 96,
"tools": [
{
"name": "health_check",
"description": "Returns a minimal status object confirming the API is alive. Use this to verify\nconnectivity before chaining other calls, or as a liveness check in a workflow.\n\nUse this tool when:\n- You need to verify the API is reachable before starting a multi-step investigation.\n- A prior call failed with a 503 or 504 and you want to confirm the service recovered.\n- You are debugging connectivity from a new environment.\n\nDo NOT use this tool when:\n- You want actual tracker data — use `get_domain` or `search` instead.\n- You want to check a specific domain — this returns nothing domain-specific.\n\nInputs:\n- N"
},
{
"name": "get_domain",
"description": "Returns the complete surveillance intelligence record for a domain name. If the\ndomain is in TunnelMind's tracker database (80,000+ entries), the response includes\ntracker category, risk score, fingerprinting data, cookie persistence, IAB TCF\npurposes, and the owning corporate entity. If the domain is not in the database,\na live probe is automatically run: RDAP registration data, DNS records (MX, SPF,\nTXT verification tokens), HTTP headers, and CSP third-party actors are fetched\nfresh from the edge and returned.\n\nUse this tool when:\n- You need to know whether a specific domain tracks users, an"
},
{
"name": "list_domains",
"description": "Returns a paginated list of domains from the tracker database. Results are ordered\nalphabetically by domain name and support cursor-based pagination for full traversal.\nFiltering by category and minimum score allows targeted data extraction.\n\nUse this tool when:\n- You want to enumerate all known ad-tech or analytics domains above a risk threshold.\n- You need a dataset of tracker domains for offline analysis.\n- You are paginating through a category to build a block list.\n\nDo NOT use this tool when:\n- You need data for a specific domain — use `get_domain` instead.\n- You are searching by keyword "
},
{
"name": "get_entity",
"description": "Returns an entity record for a surveillance company or data broker, including its\nindustry, estimated annual data value per user (in USD), categories of personal data\ncollected, and the full list of domains it controls. Free tier returns 5 domains,\npaid returns up to 200.\n\nUse this tool when:\n- You want to understand what corporate entity owns or controls a tracker domain.\n- You need to assess the total surveillance footprint of a company (e.g., Alphabet,\n Meta, Oracle).\n- You are building a corporate surveillance graph and need domain-to-entity mapping.\n\nDo NOT use this tool when:\n- You have"
},
{
"name": "list_entities",
"description": "Returns a paginated list of corporate entities in the TunnelMind surveillance\ndatabase. Includes data categories, estimated data value, and industry classification.\nUseful for enumerating the surveillance ecosystem by sector.\n\nUse this tool when:\n- You want to enumerate all entities in a specific industry (e.g., all ad-tech companies).\n- You need a dataset of surveillance entities for analysis or reporting.\n- You are building a comprehensive surveillance landscape map.\n\nDo NOT use this tool when:\n- You need the full profile of a specific entity — use `get_entity` instead.\n- You are searching b"
},
{
"name": "search",
"description": "Searches both the domains table and the entities table simultaneously. Returns\nmatching domains (by domain name) and entities (by name or slug) in a single\nresponse. Minimum 2 characters, maximum 100 characters.\n\nUse this tool when:\n- You have a partial name and need to identify what tracker or entity it belongs to.\n- You want to find all TunnelMind records related to a company name like \"Google\" or \"Oracle\".\n- You are resolving an ambiguous domain (e.g., does `criteo.com` appear in the tracker DB?).\n\nDo NOT use this tool when:\n- You know the exact domain — use `get_domain` instead (faster, mo"
},
{
"name": "intel_http",
"description": "Makes a live HEAD request to the target domain from the Cloudflare edge, follows\nup to 5 redirects, and returns the full redirect chain, final HTTP status, key\nresponse headers, a security header score, and any third-party surveillance\nactors referenced in the Content-Security-Policy header.\n\nUse this tool when:\n- You want to verify whether a site enforces HTTPS and HSTS.\n- You need to inspect what third-party scripts a site loads via its CSP header.\n- You are assessing a domain's security posture before trusting it.\n- You want to detect surveillance actors embedded in a site's CSP.\n\nDo NOT us"
},
{
"name": "intel_stack",
"description": "Fetches up to 32KB of the domain's HTML and response headers from the edge, then\nfingerprints the content for known CMS platforms, JavaScript frameworks, CDN\nproviders, and analytics tools. Detection is based on meta generator tags, script\nsrc patterns, response headers, and cookie names.\n\nUse this tool when:\n- You need to know what CMS (WordPress, Drupal, Shopify) a site runs.\n- You are assessing a domain's infrastructure before a security review.\n- You want to identify analytics or marketing tools a site embeds.\n\nDo NOT use this tool when:\n- You want HTTP headers and security posture — use `"
},
{
"name": "intel_robots",
"description": "Retrieves the target domain's `robots.txt` file and parses it for AI crawler\ndisallow rules. Specifically detects policies for known AI crawlers (GPTBot,\nClaudeBot, CCBot, Bytespider, etc.) and returns a structured summary of the\ncrawling policy.\n\nUse this tool when:\n- You need to know whether a domain has opted out of AI training data collection.\n- You want to check if a specific AI crawler is blocked before citing the domain.\n- You are building a dataset of AI-accessible vs AI-blocked domains.\n\nDo NOT use this tool when:\n- You want training opt-out signals beyond robots.txt (TDM reservation,"
},
{
"name": "intel_agent",
"description": "Probes a domain for known AI agent integration signals: `llms.txt`, `ai.txt`,\n`/.well-known/ai-plugin.json`, `openapi.json`, `swagger.json`, MCP manifest, MCP\nSSE endpoint. Returns a score based on the count of signals detected. Use this to\nassess whether a domain is ready for agent-to-agent interaction.\n\nUse this tool when:\n- You want to know whether a domain exposes an MCP server or OpenAPI spec for agents.\n- You are cataloguing the AI-agent-ready surface of a set of domains.\n- You need to decide whether to attempt programmatic API access to a domain.\n\nDo NOT use this tool when:\n- You need t"
},
{
"name": "intel_inject",
"description": "Fetches a domain's homepage and checks for content patterns that could constitute\nprompt injection attacks against AI agents that visit and ingest the page. Signals\ninclude hidden text, invisible divs, `<!-- AI: ignore -->` style comments, and\nknown injection patterns.\n\nUse this tool when:\n- You are vetting a domain before feeding its content into an LLM context.\n- You want to assess the prompt injection risk of a URL before browsing it with an agent.\n- You are auditing a set of domains for adversarial AI content.\n\nDo NOT use this tool when:\n- You want tracker surveillance data — use `get_doma"
},
{
"name": "intel_optout",
"description": "Checks a domain for all known AI training data opt-out mechanisms beyond robots.txt:\nTDM (Text and Data Mining) reservation headers, `<meta name=\"ai\">` tags, Creative\nCommons NonCommercial licenses, and other machine-readable opt-out signals.\n\nUse this tool when:\n- You need to determine whether a domain has opted out of AI training data collection.\n- You are checking compliance before using a domain's content in a training dataset.\n- You want a comprehensive opt-out status (robots.txt + TDM + meta tags combined).\n\nDo NOT use this tool when:\n- You only need robots.txt crawler policy — use `inte"
},
{
"name": "get_receipt",
"description": "Returns metadata for a TunnelMind surveillance receipt — a signed document proving\nthat a specific user's surveillance exposure was observed, measured, and recorded at\na specific time. Does NOT return the receipt's signature (anti-phishing protection).\nTo verify a receipt's content integrity, use `verify_receipt` with the hash and\nsignature from the receipt document itself.\n\nUse this tool when:\n- You have a receipt ID and want to confirm it was genuinely issued by TunnelMind.\n- You need the issuance timestamp and signing key ID for a receipt.\n- You want to check whether a receipt exists before"
},
{
"name": "verify_receipt",
"description": "Tamper-detection verification for TunnelMind surveillance receipts. Submit the\nreceipt ID, the SHA-256 content hash, and the Ed25519 signature from the receipt\ndocument. The registry compares these against what was recorded at issuance time.\nReturns VALID if both match exactly, INVALID with a specific mismatch reason otherwise.\n\nUse this tool when:\n- You received a surveillance receipt document and want to verify it hasn't been altered.\n- You are programmatically checking receipt authenticity in an agent workflow.\n- You want to prove to a third party that a receipt is genuine.\n\nDo NOT use this"
},
{
"name": "create_free_key",
"description": "Self-serve free tier — the rung between anonymous access and paid\nblocks. One email in, one API key out, shown exactly once.\n\nUse this tool when:\n- You are calling anonymously and hitting the anonymous rate limit.\n- You want your calls identified so usage survives IP changes.\n\nLimits:\n- 50 requests/day (same endpoints as anonymous, higher ceiling).\n- One active free key per email; 3 signups per IP per day.\n- The raw key is returned once and stored only as a SHA-256 hash —\n it cannot be recovered, only revoked and reissued.\n\nCost: free. No card, no account — the email is the revocation\nhandle,"
},
{
"name": "get_api_key",
"description": "Returns the tier, label, masked owner email, creation date, last-used timestamp,\ntoday's request count, and daily request limit for the API key used in this request.\nUseful for agents that need to monitor their own quota consumption.\n\nUse this tool when:\n- You want to check how many requests your key has used today.\n- You need to know your current tier or daily limit.\n- You want to confirm that your API key is active.\n\nDo NOT use this tool when:\n- You want to manage multiple keys — this endpoint only reflects the calling key.\n- You need tracker data — use the tracker endpoints instead.\n\nInputs"
},
{
"name": "revoke_api_key",
"description": "Permanently deactivates the API key used to make this request. This action is\nirreversible. After revocation, the key will return 401 on all subsequent calls.\nIf you have an active Stripe subscription, you must separately cancel it at\nstripe.com — revoking the key does not cancel billing.\n\nUse this tool when:\n- You want to rotate your API key (revoke old, then provision a new one).\n- You believe your key has been compromised.\n\nDo NOT use this tool when:\n- You want to check quota — use `get_api_key` instead.\n- You intend to keep using the API — this is permanent.\n\nInputs:\n- No body or query par"
},
{
"name": "get_task",
"description": "Returns the current status of a task created by an `?async=true` intel request.\nPoll this endpoint until `status` is one of: `complete`, `failed`, `cancelled`,\n`expired`. On `complete`, the `result` field contains the same payload the sync\nendpoint would have returned. On `failed`, `error.message` explains the failure.\n\nUse this tool when:\n- You submitted an intel probe with `?async=true` and need to retrieve the result.\n- You want to check whether a background task finished without opening an SSE stream.\n\nDo NOT use this tool when:\n- You want real-time event streaming — use `stream_task` inst"
},
{
"name": "cancel_task",
"description": "Marks the task as `cancelled`. If the task is already in a terminal state\n(`complete`, `failed`, `expired`), returns 409 Conflict. Only the identity\nthat created the task may cancel it.\n\nUse this tool when:\n- You submitted a probe with `?async=true` and no longer need the result.\n- You want to free up a pending task before it expires.\n\nDo NOT use this tool when:\n- The task is already complete — cancellation is not possible.\n\nInputs:\n- `task_id` (path, required): 26-char ULID.\n\nReturns:\n- `task_id` and `status: cancelled`.\n\nCost:\n- Free.\n\nLatency:\n- Typical: <150ms.\n"
},
{
"name": "stream_task",
"description": "Opens a persistent SSE connection that emits events as the task progresses.\nThe stream closes automatically when the task reaches a terminal state or after\n~90 seconds (timeout). Heartbeat comments are sent every ~15 seconds to keep\nthe connection alive through proxies.\n\nEvent types:\n- `status` — emitted when status changes (pending → running → complete/failed)\n- `result` — emitted on `complete` with the full result payload\n- `error` — emitted on `failed`, `cancelled`, or `expired` with error info\n- SSE comment (`: heartbeat`) — keepalive, no data\n\nUse this tool when:\n- You want real-time prog"
},
{
"name": "audit_export",
"description": "Returns NDJSON (one JSON object per line) of audit log entries. Each entry records\nthe operation called, the identity, hashes of the request and response, duration,\nand an Ed25519 signature over the canonical entry JSON. Entries are hash-chained:\neach entry's `prev_entry_hash` is SHA-256 of the previous entry's signature,\nmaking deletion of any entry detectable offline.\n\nAuthenticated callers receive only their own entries (`identity_sub` match).\nAdmin key holders receive all entries.\n\nUse this tool when:\n- You want a tamper-evident record of your own API calls.\n- You are auditing a sequence o"
},
{
"name": "generate_receipt",
"description": "Looks up each submitted domain in the TunnelMind tracker database, aggregates risk\nmetrics (avg score, max score, fingerprinters, high-risk domains, entity ownership),\nand issues a signed surveillance receipt. The receipt is stored in the public registry\nand can be verified at `/verify/{receipt_id}`.\n\nUse this tool when:\n- You want a verifiable record of which trackers were observed in a context (page, app, session).\n- You need a signed evidence artifact for a privacy audit or compliance report.\n- You want to know the overall surveillance exposure level for a set of domains.\n- You are generati"
},
{
"name": "sigil_verify_ads_txt",
"description": "Confirms whether an SSP/exchange is authorized to sell a publisher's\ninventory according to that publisher's ads.txt. This is a cache lookup\nagainst ads.txt files crawled daily across the top 10,000 publisher\ndomains — it does NOT fetch the publisher's ads.txt live, so it is fast\nand adds no latency to a real-time bidding decision.\n\nUse this tool when:\n- You are an ad-buying agent and want to confirm, pre-bid, that a supply\n path (publisher → exchange → seller_id) is legitimate.\n- You are detecting domain spoofing or unauthorized resale in a bid stream.\n- You want to check whether a seller is"
},
{
"name": "sigil_verify_ads_txt_batch",
"description": "Runs up to 100 ads.txt verifications in a single call — the endpoint an\nad-buying agent uses for pre-bid checks across a whole campaign's supply.\nEach item is the same shape as `sigil_verify_ads_txt`. Per-item\nvalidation failures are reported inline; the batch never fails as a\nwhole. Publisher records are fetched once per unique domain.\n\nUse this tool when:\n- You are evaluating many supply paths at once (campaign setup, SPO sweep).\n- You want one round-trip instead of N calls to `sigil_verify_ads_txt`.\n\nInputs:\n- `items` (body, required): Array of 1–100 verification requests, each\n `{ publish"
},
{
"name": "traction",
"description": "Live traction numbers computed from sources the Worker owns: the\nhash-chained D1 audit log (7-day call volume, distinct identified\ncallers, top operations), the stored-receipt table, and Stripe\n(succeeded charges → paying customers, gross USD). Ed25519-signed\nwith the same attestation envelope as /v1/status so the numbers can\nbe replayed to an auditor.\n\nUse this tool when:\n- You are evaluating whether anyone actually uses and pays for this API.\n- You need a signed, re-checkable statement of usage rather than a claim.\n\nReturns:\n- `traction.usage`: calls_7d, identified_callers_7d, anonymous_call"
}
],
"profiled_at": "2026-09-24T22:01:04.950Z"
},
"unreachable": false
}