# Dark0rbits Base: https://dark0rbits.thetempleofdoom.com ## API - `GET /signup` — No-KYC signup page (humans): username + password, 4+ chars, ~10 seconds. Agents: POST /inbox form act=register&u=NAME&p=PASS -> session cookie dark0rbits_tok (30 days) + $1 free trial credit. - `GET/POST /api/settings` — Per-account UI tunables (bg, warp, parallax, density, speed, twinkle, hue, grid, scan, toast, type). Agents can theme their own client. GET returns current; POST form key=val applies (validated + clamped). - `GET /deaddrop` — Burn-after-read encrypted notes. POST /api/deaddrop/create (body, burn_after 1-10, ttl_hours 1-72, password optional) -> token. FREE. - `GET /shot` — Page capture: POST /api/shot/create {url} then GET /api/shot/status/. SSRF-guarded. FREE. - `GET /score` — Composite fraud score: IP 45% + disposable-email 25% + BIN 30%. FREE. - `GET /api/ip?target=` — Caller IP intel (auto) or any IP you pass: geo, ASN, ISP, VPN/hosting flags, rDNS. - `GET /api/phone?num=` — Phone OSINT: validity, country, region, carrier, line type (mobile/landline/voip), timezones, risk flags + free deep-dive lead links. Any format. - `GET /api/user?u=` — Username OSINT: probes 16 platforms in parallel (GitHub, Reddit, Telegram, Steam…) → per-site found/not-found/unknown + lead links. - `GET /api/domain?d=` — Domain OSINT: RDAP registration (registrar/dates/status), full DNS (A/AAAA/MX/NS/TXT/CNAME via DoH), certificate-transparency subdomains. Passive. - `POST /api/forensics` — Deep image forensics: all EXIF IFDs, decoded GPS + map links, XMP, embedded thumbnail, hashes, editor flags, ELA verdict. - `POST /api/card` — Luhn + BIN intel. Nothing stored/charged. - `POST /api/sms/rent` — Rent disposable number, 30 min, refundable. - `GET /api/sms/check?pid=` — Poll SMS code. - `GET /api/sms/cancel?pid=` — Cancel + refund. - `GET /api/sms/history` — Rental history. - `POST /api/proxy/test` — Tunnel CONNECT via Pleiades gateway, return egress IP/geo. - `POST /api/steg/hide` — LSB steganography → PNG download. - `POST /api/steg/extract` — Extract hidden text. - `POST /api/track/create` — Create free trackable file. Returns upload_url + token. Login required (POST /inbox act=register). - `GET /api/track/events?token=` — Open events for a trackable (auth via account). - `GET /api/hash?s=` — md5/sha1/sha256/sha512. - `GET /api/hdr?url=` — Fetch URL, return status + headers. - `POST /api/deaddrop/create` — AES-GCM encrypted burn-after-read note. Returns /drop/ URL. FREE. Reads decrement; note self-destructs at 0 or at TTL. - `GET /drop/` — Read a dead-drop (password-protected if set). Each view burns one read. - `POST /api/shot/create` — Screenshot queue. Headless Chromium PNG if available, else rendered-text capture (status=text_fallback). FREE. Poll /api/shot/status/. - `GET /api/shot/status/` — Shot result: base64 PNG (png_b64) or text preview + page intel. - `GET /dms` — Dead man switch: arm switches with pre-written payload messages; check in via curl or they seal as burn-after-read dead-drops when the window lapses. FREE. - `POST /api/dms/create` — Arm a switch: label, interval_hours (24/48/72/168), 1-5 payloads, optional custodian note. Returns token + checkin_url. Auth: session or Bearer key. - `GET /api/dms/list` — List your switches with status ARMED/LATE/TRIGGERED and drop URLs after trigger. Auth required. - `POST /api/dms/checkin?token=` — Check in (no auth, token IS the key) -> 200 'checked in'. Resets the window. Missing the window seals payloads as /drop/ links. - `POST /chain` — Create a custody chain. Form: name. Login required. - `POST /chain/add` — Append an entry to a chain. Form: log (id), data. Login required. 60/min. - `GET /chain/export?log=` — Portable JSON receipt with seed, all entries, hashes and verification verdict. Login required. - `GET /api/chain/list` — Your chains with link counts and integrity verdicts. Login required. - `GET /api/chain/entries?log=&verify=1` — Full entry list for a chain; verify=1 adds verified, links, first_bad_seq. Login required. - `POST /api/ghost/encode` — Embed a secret in zero-width characters between words of cover text (cover, secret, password optional). Carrier looks identical to the cover. 60/min. - `POST /api/ghost/decode` — Extract hidden message from text (text, password optional). 60/min. - `GET /api/chaff?seed=` — Deterministic fake persona from a seed passphrase: name, usernames, birthdate, email pattern, password format, consistent security answers, avatar. Same seed = same persona. Stateless — nothing stored. region=US|UK|DE|NL|XX, domain= for email. - `POST /api/tracer/case` — Create a leak-tracing case: per-recipient invisible zero-width watermarks on document text. name, text, recipients=a,b,c. Returns case_id + watermarked variants. Login. - `GET /api/tracer/identify?case_id=&text=` — Identify which recipient leaked: paste leaked fragment, get leaker + confidence. Login. - `POST /api/traceout/run` — Hop-by-hop path trace from this host: per-hop IP, rDNS, rtt, geo. FREE. - `GET /api/traceout/history?limit=` — Your recent trace runs: target, resolved IP, hop count, complete flag. - `POST /api/tchain/create` — Arm a breadcrumb trap chain: nhops (2-8) tripwire URLs where each hop's decoy note carries the next hop. Fires inbox alerts with geo per hop + summary when fully burned. Login. - `GET /api/tchain/status?chain_id=` — Per-hop chain state: seq, fired, timestamp, IP. Login. - `GET /api/score?ip=&email=&bin=` — Composite fraud score 0-100 + weighted breakdown: IP intel (VPN/hosting/abuse geo), disposable-email domain, BIN country/type risk. FREE. - `POST /canary` — Create canary trap. Form: tag, kind (link|pixel|cred|file), rearm (0|1). Login required. Link = /c/, pixel = /c/.png, honeyfile = /c//download, credential returned by /api/canary/list. - `GET /api/canary/list` — Your traps with hit counts, links, generated honeytoken credentials. Login required. - `GET /api/canary/hits?token=` — Full hit log for a trap: ts, ip, ua, lang, ref + geolocated city/ISP/VPN flags per hit. Login required. - `POST /api/eh` — Email header forensics v2: origin IP (+source), origin_geo, hop chain, per-hop relay delays (delays), SPF/DKIM/DMARC verdicts, spoof flags. Handles pasted headers or .eml content. FREE 20/min. ## ACCOUNT TUNABLES (machine-settable) GET/POST /api/settings — keys: bg, warp, parallax, density (0-2.5), speed (0-3), twinkle (0-3), hue (-180-180), grid, scan, toast, type (1|0). Agents driving browsers (or building clients) can persist a theme per API key: POST form-encoded key=value. Values validated server-side. ## KEYBOARD Ctrl+K / Cmd+K — command palette on any page. Type tool name, Enter navigates.