databutler-provenance

Live trust signals for domains and software packages, computed per request from RDAP, npm and PyPI: registration age, registrar, nameservers, maintainers…

Community: Submitted by a user or imported; check the owner before granting accessOnlineNo sign-inGlobalFreeRead-only

What it can do

  • Domain Provenance: Who runs this domain? Live RDAP lookup: registration date and age, registrar, nameservers, status, whether the registrant is redacted, plus a typosquat check (edit-distance / brand-
  • Package Provenance: Who publishes this package, and is it a typosquat? Live npm or PyPI lookup: first-publish date and age, release count, latest version, maintainers/author, linked repo, plus a typos

What data it sees

Do you need an account

No: the server works without sign-in

Live trust signals for domains and software packages, computed per request from RDAP, npm and PyPI: registration age, registrar, nameservers, maintainers, linked repo, and homoglyph-aware typosquat resemblance to well-known brands and packages. Descriptive signals, not a verdict — use before trusting an unfamiliar domain or dependency. Free, no auth. From databutler.dev.

Server tool list (2)

Raw names from tools/list. Only developers need these.

domain_provenanceWho runs this domain? Live RDAP lookup: registration date and age, registrar, nameservers, status, whether the registrant is redacted, plus a typosquat check (edit-distance / brand-substring) against high-value brands. A very recently registered domain resembling a bank or big brand is a classic phishing signal — but report it as a signal, not a conclusion.
package_provenanceWho publishes this package, and is it a typosquat? Live npm or PyPI lookup: first-publish date and age, release count, latest version, maintainers/author, linked repo, plus a typosquat check against popular package names. Use when an agent is about to install or recommend an unfamiliar dependency.