Api Discover
Find API docs, developer portal, candidate base URLs and auth docs.
POST /api/discoverCanonical contracts come from the production manifest registry.
Find API docs, developer portal, candidate base URLs and auth docs.
POST /api/discoverCompose bounded API discovery with one deterministic OpenAPI or Swagger preflight into a concise agent-readiness state. The check does not authenticate, call discovered API operations, or prove business-level API correctness.
POST /api/readinessPreflight one public Apify Actor before a paid automation run using only public Store and default-build OpenAPI metadata. Forest checks agentic-payment eligibility, pricing/budget signals and top-level input compatibility without starting an Actor, buying credit, authenticating or making an external payment.
POST /automation/preflightResolve public product or listing availability with explicit normalized states. It reports only provider evidence and never infers inventory, reserves items or places an order.
POST /commerce/availabilityReport whether a public item appears buyable with explicit blockers such as out-of-stock or unknown. This is a preflight only: it never signs in, buys, creates an order or guarantees checkout.
POST /commerce/buyabilityResolve a public product redirect, canonical URL and stable provider identifiers using bounded HTTP and structured data. It does not execute JavaScript or assert unavailable facts.
POST /commerce/canonical-productPreflight an item into a fresh isolated commerce session without touching a customer cart. Sessions are ephemeral and payment/order creation is never attempted.
POST /commerce/cart-preflightCheaply detect material public product changes in price, availability, selected variant or seller using a deterministic hash. Timestamps, images and analytics noise are excluded.
POST /commerce/changedCheck whether an isolated cart can reach checkout and expose blockers without payment. It never logs in, creates an order or finalizes checkout.
POST /commerce/checkout-preflightReport public delivery options for an isolated ephemeral cart and destination when the provider exposes them. No customer cart, payment or order is touched.
POST /commerce/delivery-optionsReturn a normalized current offer price for a public product or listing. Provider fields missing from the source remain null; no price prediction, purchase or customer authentication is performed.
POST /commerce/priceExtract public SKU, GTIN, UPC, EAN, ISBN, MPN and provider identifiers from a product source. Missing identifiers stay null and are never guessed.
POST /commerce/product-identifiersNormalize a public product URL into current title, selected variant, price, currency, availability and buyability. Uses bounded read-only provider responses or JSON-LD; it never buys, logs in or guarantees unpublished stock.
POST /commerce/product-stateCombine public product resolution, one fresh isolated anonymous cart, optional delivery lookup and checkout handoff evidence into one bounded purchase preflight. Shopify Ajax and WooCommerce Store API are supported; Forest never logs in, touches a customer session, creates an order or attempts payment.
POST /commerce/purchase-preflightCheck a requested quantity against public variant constraints and known availability. Unknown stock remains unknown; this capability never reserves or purchases inventory.
POST /commerce/quantity-preflightResolve requested product options to a canonical public variant when the provider exposes them. Ambiguous or missing options are reported explicitly; no checkout or cart mutation occurs.
POST /commerce/variant-resolveWatch an OCI tag for digest and platform changes with a deterministic hash. Registry timestamps and unrelated annotations are ignored; no layers are pulled.
POST /container/changedResolve a mutable OCI tag to an immutable content digest using bounded Distribution manifest metadata. It does not assert signature or vulnerability status.
POST /container/digestReturn deterministic OS/architecture variants from an OCI image index or manifest list. It reads bounded manifest metadata only and never downloads image layers.
POST /container/platformsDiscover OCI 1.1 artifacts referring to an image digest, such as SBOM or attestation evidence. Presence is reported only; Forest does not verify signatures or download blobs.
POST /container/referrersReturn manifest-declared OCI config and layer sizes before an agent pulls an image. Values are registry declarations, not a compressed download or vulnerability measurement.
POST /container/sizeCheck an anonymously readable OCI image tag and resolve its manifest digest through the standard Distribution API. No blob pull, push, delete or private registry access is performed.
POST /container/tag-stateCompose bounded DNS propagation, TLS validity and HTTP health observations into one conservative deployment-readiness state. Optional DNS change evidence is included when a previous hash is supplied; this is not a deployment guarantee or worldwide propagation claim.
POST /deploy/readinessDetect material public DNS answer changes with a deterministic hash. TTL-only changes do not count and no arbitrary resolver or AXFR operation is exposed.
POST /dns/changedCompare one public DNS record type across a fixed bounded set of independent public DNS-over-HTTPS resolvers. Answers, TTL ranges and resolver disagreement are normalized; this is not an authoritative or worldwide DNS view.
POST /dns/consensusResolve one bounded public DNS record type into normalized answers. AXFR, resolver abuse and private-network probing are blocked; TTL and authority are null when unavailable.
POST /dns/lookupCheck whether a DNS change has reached the configured public resolvers. Compare public DoH answers with an optional expected answer set and return complete, partial, not_observed or unknown. Scope is a fixed bounded resolver set; Forest does not claim worldwide propagation.
POST /dns/propagationPerform a bounded static discovery pass for machine-usable documentation: llms.txt, Markdown alternates, developer/API/auth docs, OpenAPI/Swagger and MCP candidates. Candidates are returned only after bounded verification. Maximum 10 HTTP requests, no JavaScript, recursive crawl or authenticated content.
POST /docs/discoverMX/SPF/DMARC preflight; not mailbox verification.
POST /domain/mail-preflightResolve a bare public domain into operational registration, DNS, HTTPS/TLS and mail-policy state using IANA-routed RDAP, DNS, MX/TXT/SPF/DMARC and a bounded TLS probe. No registrant personal data, vulnerability scanning, mailbox existence or deliverability claim. Provider uncertainty is explicit.
POST /domain/preflightRegistration/registrar/expiry/status without unrelated domain checks.
POST /domain/registration-stateResolve one exact 20-character Legal Entity Identifier against the public GLEIF LEI record API and return a compact normalized legal-entity reference snapshot. Forest reports source facts only and does not turn LEI status into a KYC, AML, credit or legal decision.
POST /entity/lei-resolveDetect material public HTTP endpoint changes using bounded response metadata and deterministic hashing. ETag and Last-Modified are evidence; arbitrary body downloads are capped.
POST /http/changedPerform one bounded public HTTP health probe with status, redirects, content type and size basics. It uses central SSRF protection and does not duplicate full page scraping.
POST /http/healthMeasure bounded sequential timing samples for one public HTTP endpoint. Samples are hard-capped at three and this is never a load-testing or port-scanning service.
POST /http/latencyReturn the current public application route; do not submit application.
POST /job/apply-routeCheap watchdog for closed/materially changed job state.
POST /job/changedNormalize compensation explicitly published by the job source; never infer missing salary.
POST /job/compensationReturn structured application fields/questions where publicly exposed.
POST /job/form-schemaNormalize whether a public job is still published/open and its canonical apply route.
POST /job/preflightDetect material marketplace listing changes in active state, price, seller, condition or quantity with a deterministic hash. It does not place bids, purchases or infer hidden listing facts.
POST /marketplace/listing-changedNormalize public marketplace listing activity, offer, seller, condition and quantity hints. eBay credentials are optional configuration; no buying, bidding or seller mutation is supported.
POST /marketplace/listing-stateReturn seller identity and publicly published seller signals for a marketplace listing. Missing feedback or business fields remain null; no customer or seller account access is attempted.
POST /marketplace/seller-stateFind public MCP server candidates and registry metadata.
POST /mcp/discoverRead-only MCP handshake/tools-list preflight; no destructive tool calls.
POST /mcp/preflightVerify OpenAPI/Swagger document reachability, parseability, operations/auth/servers.
POST /openapi/preflightNormalize declared package license metadata toward SPDX; no legal compatibility conclusion.
POST /package/licenseNormalize npm or PyPI package reality: existence, requested-version existence, resolved/latest version, staleness, deprecation/yank state when available, license and runtime requirement. No dependency graph or vulnerability analysis. Public registries only; unsupported provider fields are null.
POST /package/preflightKnown vulnerabilities for package+version; normalized evidence, not a safety verdict.
POST /package/securityResolve a public GitHub release into the most plausible downloadable asset for a normalized OS/architecture target, excluding source/signature/checksum files and linking checksum companions when present. Returns ambiguity instead of silently choosing tied candidates. No private repositories or customer authentication.
POST /release/asset-resolveFind checksum/signature companion assets for a release asset.
POST /release/checksumCheck whether a repository has a usable latest/tagged release before deployment/download.
POST /release/preflightNormalize the latest public GitHub Actions workflow/run state. Reads only; dispatch, rerun, cancellation, private repositories and customer OAuth are unsupported.
POST /repo/actions-stateResolve whether a public GitHub branch exists and return its current head commit without cloning. Branch protection is null when the public API does not expose it.
POST /repo/branch-stateCheaply detect material public repository state changes with a deterministic hash of existence, branch and archive state. Timestamps and unrelated metadata do not trigger a change.
POST /repo/changedResolve a public GitHub ref to commit metadata without fetching a diff. Verification is reported as published by GitHub and is not independently re-signed by Forest.
POST /repo/commit-stateCheck lightweight metadata for a path in a public GitHub repository at an optional ref. It does not clone or download large file contents.
POST /repo/file-preflightResolve the current public GitHub repository state without cloning or customer OAuth. Archived, fork, branch and license fields reflect only public API facts; private repositories are unsupported.
POST /repo/preflightFetch and interpret one bounded public robots.txt for a target URL and user-agent token. Forest reports applicable rules, sitemap hints and a deterministic allowed/disallowed/unknown protocol observation; this is not authorization, legal advice or an anti-bot bypass.
POST /robots/contextCheap watchdog: material service state changed since prior canonical hash?
POST /service/changedResolve the live state of a named service component.
POST /service/component-statusReturn active service incidents in normalized form.
POST /service/incidentsNormalize a public Atlassian Statuspage into operational, maintenance, degraded, partial_outage, major_outage or unknown state, with components, active incidents and scheduled maintenance. V1 accepts an explicit status-page URL; it does not discover arbitrary providers or infer hidden service health.
POST /service/statusDetect material public certificate changes in fingerprint, issuer, SANs or validity window using a deterministic hash. Handshake timing noise is ignored.
POST /tls/changedReturn only the public certificate validity window and remaining lifetime for TLS port 443. It does not scan ciphers, vulnerabilities or private hosts.
POST /tls/expiryInspect one public TLS endpoint and return certificate identity and validity-window facts. This is a bounded preflight, not a vulnerability scanner or security guarantee.
POST /tls/preflightExtract PDF/CSV/XLS/XLSX/ZIP/JSON/XML links from static public HTML by suffix or download filename. Resolve relative/base links and deduplicate. Limits: 500 links, 8s, 5 redirects, 2 MiB. No JavaScript or file downloads; existence, MIME, size and file safety are unverified. Empty results are valid. 0.003 Base Sepolia test USDC per success; invalid inputs/errors are not settled.
POST /page/downloadsExtract bounded static HTML form structure without submitting anything. Forest returns field names/types/labels/constraints and submit-control structure, but never current values, textarea contents, hidden tokens, passwords, cookies or authentication material.
POST /page/formsExtract bounded generic metadata and normalized JSON-LD entities from one static public HTML page. Forest returns only compact fields and key/type summaries, never arbitrary raw JSON-LD; JavaScript rendering and domain-specific business interpretation are excluded.
POST /page/structuredDetect meaningful changes in normalized static page metadata and JSON-LD with a deterministic semantic hash. Transport noise and malformed JSON-LD counts are excluded; callers can fetch full details with web.page-structured only when the state changes.
POST /page/structured-changedDetect bounded changes across one static page surface using one HTML fetch plus at most one robots.txt fetch. Forest hashes HTTP identity, page metadata, normalized JSON-LD, downloadable links, form schema and robots context without storing snapshots, rendering JavaScript or submitting anything.
POST /site/changed-sinceCheck whether a public URL responds now, then return origin status, final URL, response headers, cache validators and up to 5 redirects. Uses HEAD; GET only on 405/501. Limits: 8s, 2 MiB. Origin 4xx/5xx are observations; no JavaScript, login or availability guarantee.
POST /url/preflightSearch machine-payable x402 resources and normalize discovery metadata.
POST /x402/discoverRead-only probe of x402 PaymentRequired requirements; does not pay.
POST /x402/preflight