Skip to content
Boberbot

Web API

POST /api/scan: check any website from code or an agent, with the same engine as the home page.

curl -s https://boberbot.com/api/scan \
  -H 'content-type: application/json' \
  -d '{"url": "example.com"}'

Request

POST /api/scan with a JSON body:

Field Required
url yes The site to check. example.com and https://example.com/page both work. Public websites only, on the standard ports.

Response

200 with JSON in the shape of Cloudflare’s scanner, plus Boberbot’s additions:

Field
level, levelName Cloudflare’s level, 0 to 5.
levelMax Present when some checks couldn’t run (for example a bot challenge): the level could be up to this.
nextLevel What the next level asks for, with fixes and Cloudflare’s guides.
scores.contentSite Passes among the seven Content Site checks.
checks Every check by group and ID, with status (pass, fail, neutral, unableToCheck), message, messageRef.code and, when it doesn’t pass, fix.
notes Anything that affects how to read the result.
agentMarkdown The fixes as Markdown, ready for a coding agent.

The machine-readable description is at /api/openapi.json, listed in the API catalog.

Errors

Status error When
400 bad_request, bad_url No JSON, no URL, or not a public website.
422 unreachable The site didn’t answer: the message says why.
429 rate_limited Too many checks from your address in a minute. Wait and retry.

Limits and caching

A few checks per minute per address. Results are cached for ten minutes per URL, and cached answers don’t count against the limit. Each check makes 20 to 30 requests to the site, from Cloudflare’s network, with the user agent described on Boberbot’s checker.