From plan to API key.
Without a checkout.
Agents can discover the service, activate an owner-authorized account, and integrate over HTTP. Free is available at $0. Launch, Growth and Scale are coming soon. No payment method or automatic billing.
1. Choose a plan.
GET /api/plans returns current allowances, planned prices,
and the 100% discount. Free: 2,000 checks; Launch: 10,000 per UTC month.
Launch, Growth and Scale are coming soon; their catalog entries have
selectable=false. Review availability before activating.
2. Activate with the owner’s permission.
POST /api/auth/otp/request with the owner’s name, email,
intent: signup, and plan_id: free. Disban checks
the domain before sending a code. With the owner’s permission, submit
the emailed code and returned challenge_id to
/api/auth/otp/verify, keeping intent: signup.
Save the returned session cookie securely. Existing accounts use
intent: login for both requests. Passwords are not accepted.
This creates a $0 account; it does not authorize future charges.
{
"intent": "signup",
"name": "OWNER_NAME",
"email": "OWNER_EMAIL",
"plan_id": "free"
}
3. Issue a key.
POST /api/keys with the session cookie and
{"name":"Agent integration"}. Store the returned
token in a secret manager. It is shown once. Never include
it in prompts, public logs, or source control.
4. Make your first check.
curl -X POST 'https://disban.io/api/check' \
-H 'Authorization: Bearer YOUR_API_KEY' \
-H 'Content-Type: application/json' \
-d '{"input":"mailinator.com"}'
5. Observe usage and limits.
GET /api/subscription using your key for remaining checks
and reset time. Each successful domain costs one credit; failures are
refunded. Batch up to 50 domains with /api/batch. Respect
Retry-After on 429 responses. Request limits use fixed
one-second windows; a batch is one HTTP request.
Owner controls stay separate.
Keys can check domains and read usage. A session is required to change
plans or create/revoke keys. POST /api/subscription with
{"plan_id":"free"} to change a plan. Usage is preserved.
DELETE /api/keys/{id} revokes a key immediately.
All POST requests require JSON. Use server-side HTTP; cross-origin browser calls are rejected. Unknown is not a safe verdict, and domain classification does not verify mailbox existence. See the response guide.
This instance is running locally. Public agents cannot reach it until Disban is deployed. Planned prices are $19 / $49 / $149 per month; Launch currently has a 100% launch discount and costs $0. Free is also $0. Growth and Scale are unavailable. Future paid service requires explicit opt-in.