API and MCP server
Your agent checks before it connects
An agent gets permissions once and uses them without asking. The arLET’S MCP server lets it check a tool's public site first: who it shares data with, who is behind it, where its forms send data. Results in under a minute, including what was not checked.
01
Connect the MCP server
Claude Code:
claude mcp add --transport http arlets https://cybersecure.yesfor.ai/api/mcp
Claude (desktop app and claude.ai): Settings → Connectors → Add custom connector, URL https://cybersecure.yesfor.ai/api/mcp. Other MCP clients connect with the same URL (Streamable HTTP transport).
02
Two tools
sprawdz_adres requests a check and waits up to 50 seconds for the result. It returns findings with severity, what they mean and what to do, data recipients, a list of what was out of scope and a link to the result.
wynik_sprawdzenia reads the result by token when it was not ready on the first call. A result is kept for 30 days.
03
Skill for Claude Code
The skill tells the agent when to check (before connecting a tool, before entering data) and how to report the result without pretending that no findings means "safe".
mkdir -p ~/.claude/skills/arlets-sprawdz curl -so ~/.claude/skills/arlets-sprawdz/SKILL.md https://cybersecure.yesfor.ai/skill/SKILL.md
04
Plain API
Request:
curl -X POST https://cybersecure.yesfor.ai/api/v1/sprawdzenia \
-H "content-type: application/json" \
-d '{"adres":"narzedzie.pl"}'
# 202 {"token":"…","status":"oczekuje","wynik_url":"…","api_url":"/api/v1/sprawdzenia/…"}The domain only, without visiting the website: the domena field instead of adres. Accepts a domain, a website address or the sender's email address. Optionally powinna_nalezec_do (the domain or brand it should belong to) and sytuacja: platnosc (payment), logowanie (sign-in) or kontakt (contact). On the MCP server this is the sprawdz_domene tool.
curl -X POST https://cybersecure.yesfor.ai/api/v1/sprawdzenia \
-H "content-type: application/json" \
-d '{"domena":"faktury@firma-pl.com","powinna_nalezec_do":"firma.pl","sytuacja":"platnosc"}'With an organization API key (portal, API keys) add the Authorization header. The key's daily limit then applies instead of the limit of five checks per IP address. A wrong or revoked key returns 401, an exceeded limit returns 429 with a Retry-After header.
curl -X POST https://cybersecure.yesfor.ai/api/v1/sprawdzenia \
-H "authorization: Bearer arl_live_…" \
-H "content-type: application/json" \
-d '{"adres":"narzedzie.pl"}'Result:
curl https://cybersecure.yesfor.ai/api/v1/sprawdzenia/<token>
# {"status":"gotowe","decyzja":{"werdykt":"conditional","zalecane_dzialanie":"verify",…},
# "powody":[…],"znalezienia":[…],"poza_zakresem":[…],"czego_nie_wiemy":[…],…}05
Limits
The check is passive: plain GET requests, like a visitor's browser. No login, no bypassing protections, no active tests. No findings means "not visible from the outside", never "safe".
Rate limits: the same URL 3 times per hour from one caller; without a key 5 checks per day from one IP address, with an API key the key's daily limit. You send only the page URL to the server. Keys and tokens are decoded in your browser at /en/paste, where nothing leaves the tab.