Competitor scan
What's a competitor using? Tech stack, HTTP headers, WHOIS, and page metadata in one call.
4 tools run server-side in one request. You pay once, settle once, and get a single response - no orchestration, no per-step payments, and a partial-success envelope if any step fails. USDC over x402 on any supported chain.
When to use this pack
Competitive intelligence - fingerprint their infrastructure, hosting, frameworks, and page metadata.
Tools in this pack
All 4 run inside the single $0.014 call above. Each is also callable on its own if you only need one part.
- Tech stack detection POST /api/tech-stack Detect the technology stack of a public website: CDN, web server, language/runtime, frontend framework (Next.js, Nuxt, SvelteKit, Remix, Astro, React, Vue, Angular), CMS (WordPress, Drupal, Ghost, Shopify, Wix, Squarespace, Webflow), analytics (GA, GTM, PostHog, Mixpanel, Segment, Hotjar, Plausible, Fathom), and payments (Stripe, PayPal). Signature-based; no third-party API.
- HTTP headers + security analysis POST /api/http-headers Fetch a URL and return every response header plus a security analysis: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP/CORP/COEP. Scores 0–100 by presence, flags weak HSTS, and warns on Server/X-Powered-By identity leaks. SSRF-protected.
- Domain WHOIS (RDAP) POST /api/whois Domain registration data via RDAP (the structured WHOIS successor): registrar, creation/expiry dates, status, nameservers.
- Page metadata GET /api/meta Fetch page metadata for a URL: title, description, OpenGraph, Twitter cards, canonical URL, favicon.
Bought one at a time, these 4 tools cost $0.015 together; the pack is that sum less a 10% bundle discount, rounded up to the $0.001 settlement floor, which is $0.014.
Workflow
- Fingerprint the tech stack - CMS, framework, CDN, analytics, third-party scripts.
- Fetch HTTP headers for server info, caching strategy, and security posture.
- Pull WHOIS for domain age, registrar, and hosting provider.
- Get page metadata - title, description, OG tags for their positioning.
Arguments
| Name | Required | Description | Example |
|---|---|---|---|
url | yes | Competitor URL (e.g. https://stripe.com) | https://stripe.com |
What one call returns
A JSON object with pack, args, steps, summary; steps holds one entry per tool (tech-stack, http-headers, whois, meta), each with its own result or error. Full example on the API page.
Call it directly
Any x402 client pays the 402 and gets the whole workflow back in one response. With the agent402-client SDK (npm i agent402-client, an ES module):
import { Agent402 } from "agent402-client";
// payFetch: an x402-wrapped fetch your wallet signs (@x402/fetch).
// Tools on the free tier need no options: new Agent402() pays them by proof-of-work.
// an existing prepaid credits key also works: new Agent402({ creditsKey })
const client = new Agent402({ fetch: payFetch });
const result = await client.call("skill-competitor-scan", {"url":"https://stripe.com"});
Run it in Claude
claude mcp add agent402 -s user -- npx -y agent402-mcp@latest
Then paste this prompt into Claude:
Scan the competitor at https://stripe.com using Agent402's competitor-scan skill pack. Get (1) tech stack, (2) HTTP headers, (3) WHOIS, (4) page metadata. Summarize their infrastructure and positioning.