API and MCP server

Your agent checks before it connects

An agent gets permissions once and uses them without asking. The arLET’S MCP server lets it check a tool's public site first: who it shares data with, who is behind it, where its forms send data. Results in under a minute, including what was not checked.

01

Connect the MCP server

Claude Code:

claude mcp add --transport http arlets https://cybersecure.yesfor.ai/api/mcp

Claude (desktop app and claude.ai): Settings → Connectors → Add custom connector, URL https://cybersecure.yesfor.ai/api/mcp. Other MCP clients connect with the same URL (Streamable HTTP transport).

02

Two tools

sprawdz_adres requests a check and waits up to 50 seconds for the result. It returns findings with severity, what they mean and what to do, data recipients, a list of what was out of scope and a link to the result.

wynik_sprawdzenia reads the result by token when it was not ready on the first call. A result is kept for 30 days.

03

Skill for Claude Code

The skill tells the agent when to check (before connecting a tool, before entering data) and how to report the result without pretending that no findings means "safe".

mkdir -p ~/.claude/skills/arlets-sprawdz
curl -so ~/.claude/skills/arlets-sprawdz/SKILL.md https://cybersecure.yesfor.ai/skill/SKILL.md

View the skill

04

Plain API

Request:

curl -X POST https://cybersecure.yesfor.ai/api/v1/sprawdzenia \
  -H "content-type: application/json" \
  -d '{"adres":"narzedzie.pl"}'
# 202 {"token":"…","status":"oczekuje","wynik_url":"…","api_url":"/api/v1/sprawdzenia/…"}

The domain only, without visiting the website: the domena field instead of adres. Accepts a domain, a website address or the sender's email address. Optionally powinna_nalezec_do (the domain or brand it should belong to) and sytuacja: platnosc (payment), logowanie (sign-in) or kontakt (contact). On the MCP server this is the sprawdz_domene tool.

curl -X POST https://cybersecure.yesfor.ai/api/v1/sprawdzenia \
  -H "content-type: application/json" \
  -d '{"domena":"faktury@firma-pl.com","powinna_nalezec_do":"firma.pl","sytuacja":"platnosc"}'

With an organization API key (portal, API keys) add the Authorization header. The key's daily limit then applies instead of the limit of five checks per IP address. A wrong or revoked key returns 401, an exceeded limit returns 429 with a Retry-After header.

curl -X POST https://cybersecure.yesfor.ai/api/v1/sprawdzenia \
  -H "authorization: Bearer arl_live_…" \
  -H "content-type: application/json" \
  -d '{"adres":"narzedzie.pl"}'

Result:

curl https://cybersecure.yesfor.ai/api/v1/sprawdzenia/<token>
# {"status":"gotowe","decyzja":{"werdykt":"conditional","zalecane_dzialanie":"verify",…},
#  "powody":[…],"znalezienia":[…],"poza_zakresem":[…],"czego_nie_wiemy":[…],…}

05

Limits

The check is passive: plain GET requests, like a visitor's browser. No login, no bypassing protections, no active tests. No findings means "not visible from the outside", never "safe".

Rate limits: the same URL 3 times per hour from one caller; without a key 5 checks per day from one IP address, with an API key the key's daily limit. You send only the page URL to the server. Keys and tokens are decoded in your browser at /en/paste, where nothing leaves the tab.