Web API
POST /api/scan: check any website from code or an agent, with the same engine as the home page.
curl -s https://boberbot.com/api/scan \
-H 'content-type: application/json' \
-d '{"url": "example.com"}'
Request
POST /api/scan with a JSON body:
| Field | Required | |
|---|---|---|
url |
yes | The site to check. example.com and https://example.com/page both work. Public websites only, on the standard ports. |
Response
200 with JSON in the shape of Cloudflare’s scanner, plus Boberbot’s additions:
| Field | |
|---|---|
level, levelName |
Cloudflare’s level, 0 to 5. |
levelMax |
Present when some checks couldn’t run (for example a bot challenge): the level could be up to this. |
nextLevel |
What the next level asks for, with fixes and Cloudflare’s guides. |
scores.contentSite |
Passes among the seven Content Site checks. |
checks |
Every check by group and ID, with status (pass, fail, neutral, unableToCheck), message, messageRef.code and, when it doesn’t pass, fix. |
notes |
Anything that affects how to read the result. |
agentMarkdown |
The fixes as Markdown, ready for a coding agent. |
The machine-readable description is at /api/openapi.json, listed in the API catalog.
Errors
| Status | error |
When |
|---|---|---|
| 400 | bad_request, bad_url |
No JSON, no URL, or not a public website. |
| 422 | unreachable |
The site didn’t answer: the message says why. |
| 429 | rate_limited |
Too many checks from your address in a minute. Wait and retry. |
Limits and caching
A few checks per minute per address. Results are cached for ten minutes per URL, and cached answers don’t count against the limit. Each check makes 20 to 30 requests to the site, from Cloudflare’s network, with the user agent described on Boberbot’s checker.