Free HTTP API for agents and scripts
Four endpoints that answer a question about a web page, with no API key, no signup and no account. They are the same engines that run the tools on this site, so a script and a visitor get the same answer. Use them over HTTP directly, or let an AI agent call them over MCP.
Endpoints
/api/compliance-scan GET
Scans a website for nine essentials: privacy policy, terms, cookie consent, imprint, accessibility statement, data processing agreement, security headers, meta tags and hreflang. It follows the site's own links to find the legal pages, so one call covers the pages it can reach. Up to five sites per call, and twelve page fetches for the whole call.
curl "https://mahope.tools/api/compliance-scan?url=https://example.com"
Returns score out of 100, a letter grade, and
passed/failed/not_checked counts out of
total. results holds the same checks in three lists —
passed, failed, notChecked — where each entry has a
label and a details sentence, so the fix is written out for each one
that failed. pages_read lists the pages it actually read.
/api/profile GET
Profiles one page: title and meta description, Open Graph and Twitter tags, JSON-LD types, heading structure, image alt coverage, hreflang count and security headers. Returns a weighted score out of 21 with a letter grade.
curl "https://mahope.tools/api/profile?url=https://example.com"
Returns score, grade, and the raw
headings, og and security blocks.
/api/header-check GET
Fetches a URL and returns its response headers, following redirects and reporting where it ended up.
curl "https://mahope.tools/api/header-check?url=https://example.com"
Returns every response headers object plus status,
finalUrl and redirected.
/api/clean-copy POST
Converts HTML to clean Markdown or plain text. Send the HTML as html, and
mode as plain if you want text instead of Markdown — the same engine
as the Clean Copy extension. 50 000 characters per call.
curl -X POST https://mahope.tools/api/clean-copy \
-H 'Content-Type: application/json' \
-d '{"html":"<h1>Hej</h1>","mode":"markdown"}'
Returns markdown — the converted text, also when
mode is plain — plus the mode you asked for,
input_chars and output_chars. Send 50 001 characters and you get
413, not a truncated answer.
Two ways to call it
HTTP, from anything
The four endpoints above are plain GET/POST calls. They work from
a shell script, a CI job, a spreadsheet formula or an agent that speaks HTTP. Nothing to
install.
MCP, from an AI agent
passiv-mcp exposes the same four tools to Claude Desktop, Claude Code, Cursor and any other MCP client. One command, then your agent picks the tool itself.
npx @mahope/passiv-mcp
Limits
| Endpoint | Limit | What happens at the limit |
|---|---|---|
/api/clean-copy | 120 per hour, 50 000 characters per call | HTTP 429 with the server's own sentence, or 413 for oversized input |
/api/compliance-scan | 30 per hour, 5 sites and 12 pages per call | HTTP 429, or 400 if you send more than five sites |
/api/header-check | 60 per hour | HTTP 429 |
/api/profile | 30 per day, 500 000 characters per page | HTTP 429, resets at midnight UTC |
Limits are counted per IP address — except /api/profile, which
counts per visitor. A shared office network can therefore reach the first three faster than one
developer. A 429 is final — the server has already said how long it lasts, so retrying only
spends more of your own budget. Treat it as the answer.
Good to know
- Only public addresses. Local and private network addresses are refused with HTTP 400, on the first request and on every redirect hop.
- Responses are JSON. Errors carry
{"ok":false,"error":"…"}with a real status code — 400 for a bad URL or a private target, 413 for oversized input, 429 for a limit, 502 when the target site itself failed. - A target that is slow or unreachable gives you a 502, which is worth one retry. A 400, a 413 or a 429 is not.
- URLs you scan are fetched server-side and not stored.
The same tools in a browser
If you would rather click than call: compliance checker, page profile and security headers run three of the four same engines. Every answer the API gives, you can get by hand on this site.