From a12b202f609243bda881bef736c66e49b7043952 Mon Sep 17 00:00:00 2001 From: drjones Date: Tue, 29 Sep 2026 18:21:13 -0700 Subject: [PATCH] v1.1: agent layer (llms.txt, openapi, /api catalog, GET+POST everywhere, /api/card, /api/sms/history) + human layer (auto-poll codes, countdowns, copy buttons, card auto-format, geo builder) --- app.py | 142 ++++++++++++++++++++++++++++++++++++++++++++++++++++----- 1 file changed, 131 insertions(+), 11 deletions(-) diff --git a/app.py b/app.py index 4fa0381..04e5c6e 100644 --- a/app.py +++ b/app.py @@ -66,6 +66,10 @@ footer{color:var(--dim);text-align:center;padding:2rem;font-size:.85rem}footer a
{{body}}
+ """ def page(sec, body): @@ -75,6 +79,73 @@ def kv(pairs): rows = "".join(f"
{k}
{v}
" for k, v in pairs) return f'
{rows}
' +# ---------- 0. AGENT DISCOVERY ---------- +API_INDEX = { + "service": "AURIGA toolbox", + "description": "IP intel, card BIN validation, 30-min SMS rentals, residential proxy lab, free utilities. Human UI at /, all tools also JSON APIs.", + "endpoints": [ + {"method": "GET", "path": "/api/ip", "desc": "Everything about the caller's IP: geo, ASN, ISP, VPN/proxy/hosting flags, rDNS, request headers."}, + {"method": "POST", "path": "/api/card", "params": {"num": "card number (digits or formatted)"}, "desc": "Luhn + BIN intel: brand, issuer, country, type, prepaid risk flags. Nothing stored/charged."}, + {"method": "POST", "path": "/api/sms/rent", "params": {"service": "SMSPool service id or keyword (273=discord, 395=google, telegram, whatsapp, other)", "country": "country id (1=US,2=UK,4=NL,150=DE)"}, "desc": "Rent a disposable number for 30 min. Returns number + orderid. Cancel before a code = full refund."}, + {"method": "GET", "path": "/api/sms/check", "params": {"pid": "orderid"}, "desc": "Poll for the received SMS code."}, + {"method": "GET", "path": "/api/sms/cancel", "params": {"pid": "orderid"}, "desc": "Cancel order + refund."}, + {"method": "GET", "path": "/api/sms/history", "desc": "Your rental history from this site."}, + {"method": "POST", "path": "/api/proxy/test", "params": {"user": "Pleiades gateway username", "pass": "password (geo suffixes allowed)"}, "desc": "Tunnel CONNECT through the Pleiades gateway, return real egress IP + geo."}, + {"method": "GET", "path": "/api/hash", "params": {"s": "string"}, "desc": "md5/sha1/sha256/sha512."}, + {"method": "GET", "path": "/api/hdr", "params": {"url": "target URL"}, "desc": "Fetch URL, return status + all response headers."}, + ], + "payment": "SMS meters against the house SMSPool account; proxy plans at the Pleiades storefront. BTCPay BTC only — no Stripe.", +} + +@app.route("/api") +def api_index(): return jsonify(API_INDEX) + +@app.route("/robots.txt") +def robots(): + return "User-agent: *\nAllow: /\n", 200, {"Content-Type": "text/plain"} + +@app.route("/llms.txt") +def llms(): + eps = "\n".join(f"- `{e['method']} {e['path']}` — {e['desc']} Params: {e.get('params','-')}" for e in API_INDEX["endpoints"]) + body = f"# AURIGA toolbox\n\nNetwork toolbox for humans and agents. Base: https://auriga.thetempleofdoom.com\n\n## API\n{eps}\n\nAll responses JSON. POST bodies are form-encoded. Human pages at /, /card, /sms, /proxy, /tools.\n" + return body, 200, {"Content-Type": "text/plain"} + +@app.route("/ai-plugin.json") +def aiplugin(): + return jsonify({"name_for_model": "auriga", "schema_version": "v1", + "description_for_model": "IP intelligence, card BIN validation, disposable SMS number rentals (30 min, refundable), residential proxy egress testing, hashing/URL/DNS utilities.", + "api": {"type": "openapi", "url": "https://auriga.thetempleofdoom.com/openapi.json"}, + "auth": {"type": "none"}, "contact_email": "indianaholmes1@icloud.com"}) + +@app.route("/openapi.json") +def openapi(): + B = "https://auriga.thetempleofdoom.com" + ps = {"openapi": "3.0.0", "info": {"title": "AURIGA", "version": "1.1.0"}, "paths": {}} + def add(path, method, desc, params=None, req=False): + item = {"summary": desc} + if params: + if method == "get": + item["parameters"] = [{"name": k, "in": "query", "required": req, "schema": {"type": "string"}, "description": v} for k, v in params.items()] + else: + item["requestBody"] = {"content": {"application/x-www-form-urlencoded": {"schema": {"type": "object", "properties": {k: {"type": "string", "description": v} for k, v in params.items()}, "required": [k for k in params] if req else []}}}} + ps["paths"][path] = ps["paths"].get(path, {}) | {method: {"responses": {"200": {"description": "ok"}}, **item}} + add("/api/ip", "get", "Caller IP intel: geo/ASN/ISP/VPN flags/headers") + add("/api/card", "post", "Luhn + BIN validation", {"num": "card number"}, req=True) + add("/api/sms/rent", "post", "Rent disposable number, 30 min", {"service": "service id/keyword", "country": "country id"}, req=True) + add("/api/sms/check", "get", "Poll SMS code", {"pid": "orderid"}, req=True) + add("/api/sms/cancel", "get", "Cancel + refund", {"pid": "orderid"}, req=True) + add("/api/sms/history", "get", "Rental history") + add("/api/proxy/test", "post", "Test Pleiades gateway creds", {"user": "username", "pass": "password"}, req=True) + add("/api/hash", "get", "Hashes of s", {"s": "string"}, req=True) + add("/api/hdr", "get", "HTTP response headers of url", {"url": "url"}, req=True) + return jsonify(ps) + +def param(name): + return request.form.get(name) or request.args.get(name) or request.args.get("orderid") or request.form.get("orderid") + +def human(n): + return n + # ---------- 1. WHAT'S MY IP ---------- @app.route("/ip") def ip_route(): return ip_lookup() @@ -173,10 +244,29 @@ def card(): It cannot tell you if a card has available funds. Fraud "flagged" status lives at the issuer, not in any database we can legally query.""" body = f"""

CARD CHECK

Is it real? Luhn + BIN intelligence: issuer, brand, type, country, prepaid risk flags.

-
+
+
Paste anything — spaces, dashes, junk all stripped. Nothing stored.
+ {result}""" return page("card", body) +@app.route("/api/card", methods=["POST"]) +def api_card(): + num = re.sub(r"\D", "", param("num") or "")[:19] + if not num: return jsonify({"ok": False, "error": "num required"}) + ok = luhn_ok(num) + st, b = http(f"https://lookup.binlist.net/{num[:8]}", headers={"Accept-Version": "3"}) + bl = jf(b) or {} + return jsonify({"ok": True, "luhn": ok, "brand": brand_of(num), "length_ok": len(num) in + {"Visa":(13,16,19),"Mastercard":(16,),"Amex":(15,)}.get(brand_of(num),(13,15,16,19)), + "bin": {"issuer": (bl.get("bank") or {}).get("name"), "country": (bl.get("country") or {}).get("name"), + "type": bl.get("type"), "prepaid": bl.get("prepaid")}, + "flags": (["prepaid-risk"] if (bl.get("type")=="prepaid" or bl.get("prepaid") is True) else []) + (["luhn-invalid"] if not ok else [])}) + # ---------- 3. SMS RENTALS ---------- SMSP = "https://api.smspool.net" SERVICES = [("google","Google"),("discord","Discord"),("telegram","Telegram"),("whatsapp","WhatsApp"),("other","Other/Any")] @@ -204,7 +294,7 @@ def sms(): con.execute("INSERT INTO sms_rentals(phone,service,country,purchase_id,cost,status,created,expires) VALUES(?,?,?,?,?,?,?,?)", (d.get("number"), svc, ctry, str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800)) con.commit() - msg = f'
RENTED Your number: +{d.get("number")} · expires in 30 min · order #{d.get("purchase_id")}
' + msg = f'
RENTED Your number: +{d.get("number")} · expires in 30 min · order #{d.get("purchase_id")}
' else: msg = f'
RENT FAILED
{b[:400]}
' elif act == "check": @@ -223,6 +313,9 @@ def sms(): con = db(); con.execute("UPDATE sms_rentals SET status=? WHERE purchase_id=?", ("refunded" if ok else "cancel-failed", pid)); con.commit() msg = f'
{"CANCELLED + REFUNDED" if ok else "CANCEL FAILED"}
' st, b = sms_api("sms/instructions") + con = db() + hist = con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 8").fetchall() + hist_rows = "".join(f"+{h['phone']} copy{h['service']}{h['status']}#{h['purchase_id']}…" for h in hist) body = f"""

SMS RENTAL

Disposable numbers, 30-minute windows. Cancel before a code arrives = full refund.

@@ -230,12 +323,28 @@ def sms():
-
+ +
Numbers auto-appear below. Codes auto-poll every 10s.
Check / manage -
+
{msg} -
API: POST /api/sms/rent (service,country) · /api/sms/check (pid) · /api/sms/cancel (pid)
""" +
Recent rentals{hist_rows or ''}
NumberServiceStatusOrderWindow
none yet
+ +
API: POST /api/sms/rent (service,country) · GET /api/sms/check?pid= · GET /api/sms/cancel?pid= · GET /api/sms/history
""" return page("sms", body) @app.route("/api/sms/rent", methods=["POST"]) @@ -249,16 +358,22 @@ def api_sms_rent(): con.commit() return jsonify(d) -@app.route("/api/sms/check", methods=["POST"]) +@app.route("/api/sms/check", methods=["GET", "POST"]) def api_sms_check(): - st, b = sms_api("sms/check", orderid=request.form["pid"]) + st, b = sms_api("sms/check", orderid=param("pid")) return jf(b) or jsonify({"error": b[:200]}) -@app.route("/api/sms/cancel", methods=["POST"]) +@app.route("/api/sms/cancel", methods=["GET", "POST"]) def api_sms_cancel(): - st, b = sms_api("sms/cancel", orderid=request.form["pid"]) + st, b = sms_api("sms/cancel", orderid=param("pid")) return jf(b) or jsonify({"error": b[:200]}) +@app.route("/api/sms/history") +def api_sms_history(): + con = db() + rows = con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 50").fetchall() + return jsonify([dict(r) for r in rows]) + # ---------- 4. PROXY LAB ---------- @app.route("/proxy", methods=["GET", "POST"]) def proxy(): @@ -302,9 +417,14 @@ def proxy():

{result} +
Geo session builder — append these to your password to steer the egress: + + +
yourpassword
+
Chain them: pass_region-us_session-x9k2_lifetime-30m. Same gateway keys as the storefront.
+
Rent more — buy GB plans & geo-targeted sessions at the storefront: -{PLEIADES_APP}. Region/country/city suffixes on your password control geo; add -_session-XXXX_lifetime-30m for sticky 30-min IPs.
+{PLEIADES_APP}.
API: POST /api/proxy/test (user, pass) → egress IP + geo JSON.
""" return page("proxy", body)