v1.1: agent layer (llms.txt, openapi, /api catalog, GET+POST everywhere, /api/card, /api/sms/history) + human layer (auto-poll codes, countdowns, copy buttons, card auto-format, geo builder)

This commit is contained in:
2026-09-29 18:21:13 -07:00
parent d7bcf46342
commit a12b202f60

142
app.py
View File

@@ -66,6 +66,10 @@ footer{color:var(--dim);text-align:center;padding:2rem;font-size:.85rem}footer a
</nav><main>{{body}}</main>
<footer>Built for agents &amp; humans · <a href="{{bmac}}" target=_blank rel=noopener>☕ fuel the lab</a></footer>
<script defer src="https://analytics.thetempleofdoom.com/script.js" data-website-id="953c15df-ba4c-453a-a7c6-465fa9e3f202"></script>
<script>
function cp(t){navigator.clipboard.writeText(t).then(function(){toast('Copied ✓')})}
function toast(m){var d=document.createElement('div');d.textContent=m;d.style.cssText='position:fixed;bottom:20px;left:50%;transform:translateX(-50%);background:var(--acc);color:#111;padding:.5rem 1rem;border-radius:8px;font-weight:700;z-index:99';document.body.appendChild(d);setTimeout(function(){d.remove()},1500)}
</script>
</body></html>"""
def page(sec, body):
@@ -75,6 +79,73 @@ def kv(pairs):
rows = "".join(f"<div>{k}</div><div>{v}</div>" for k, v in pairs)
return f'<div class="card"><div class="kv">{rows}</div></div>'
# ---------- 0. AGENT DISCOVERY ----------
API_INDEX = {
"service": "AURIGA toolbox",
"description": "IP intel, card BIN validation, 30-min SMS rentals, residential proxy lab, free utilities. Human UI at /, all tools also JSON APIs.",
"endpoints": [
{"method": "GET", "path": "/api/ip", "desc": "Everything about the caller's IP: geo, ASN, ISP, VPN/proxy/hosting flags, rDNS, request headers."},
{"method": "POST", "path": "/api/card", "params": {"num": "card number (digits or formatted)"}, "desc": "Luhn + BIN intel: brand, issuer, country, type, prepaid risk flags. Nothing stored/charged."},
{"method": "POST", "path": "/api/sms/rent", "params": {"service": "SMSPool service id or keyword (273=discord, 395=google, telegram, whatsapp, other)", "country": "country id (1=US,2=UK,4=NL,150=DE)"}, "desc": "Rent a disposable number for 30 min. Returns number + orderid. Cancel before a code = full refund."},
{"method": "GET", "path": "/api/sms/check", "params": {"pid": "orderid"}, "desc": "Poll for the received SMS code."},
{"method": "GET", "path": "/api/sms/cancel", "params": {"pid": "orderid"}, "desc": "Cancel order + refund."},
{"method": "GET", "path": "/api/sms/history", "desc": "Your rental history from this site."},
{"method": "POST", "path": "/api/proxy/test", "params": {"user": "Pleiades gateway username", "pass": "password (geo suffixes allowed)"}, "desc": "Tunnel CONNECT through the Pleiades gateway, return real egress IP + geo."},
{"method": "GET", "path": "/api/hash", "params": {"s": "string"}, "desc": "md5/sha1/sha256/sha512."},
{"method": "GET", "path": "/api/hdr", "params": {"url": "target URL"}, "desc": "Fetch URL, return status + all response headers."},
],
"payment": "SMS meters against the house SMSPool account; proxy plans at the Pleiades storefront. BTCPay BTC only — no Stripe.",
}
@app.route("/api")
def api_index(): return jsonify(API_INDEX)
@app.route("/robots.txt")
def robots():
return "User-agent: *\nAllow: /\n", 200, {"Content-Type": "text/plain"}
@app.route("/llms.txt")
def llms():
eps = "\n".join(f"- `{e['method']} {e['path']}` — {e['desc']} Params: {e.get('params','-')}" for e in API_INDEX["endpoints"])
body = f"# AURIGA toolbox\n\nNetwork toolbox for humans and agents. Base: https://auriga.thetempleofdoom.com\n\n## API\n{eps}\n\nAll responses JSON. POST bodies are form-encoded. Human pages at /, /card, /sms, /proxy, /tools.\n"
return body, 200, {"Content-Type": "text/plain"}
@app.route("/ai-plugin.json")
def aiplugin():
return jsonify({"name_for_model": "auriga", "schema_version": "v1",
"description_for_model": "IP intelligence, card BIN validation, disposable SMS number rentals (30 min, refundable), residential proxy egress testing, hashing/URL/DNS utilities.",
"api": {"type": "openapi", "url": "https://auriga.thetempleofdoom.com/openapi.json"},
"auth": {"type": "none"}, "contact_email": "indianaholmes1@icloud.com"})
@app.route("/openapi.json")
def openapi():
B = "https://auriga.thetempleofdoom.com"
ps = {"openapi": "3.0.0", "info": {"title": "AURIGA", "version": "1.1.0"}, "paths": {}}
def add(path, method, desc, params=None, req=False):
item = {"summary": desc}
if params:
if method == "get":
item["parameters"] = [{"name": k, "in": "query", "required": req, "schema": {"type": "string"}, "description": v} for k, v in params.items()]
else:
item["requestBody"] = {"content": {"application/x-www-form-urlencoded": {"schema": {"type": "object", "properties": {k: {"type": "string", "description": v} for k, v in params.items()}, "required": [k for k in params] if req else []}}}}
ps["paths"][path] = ps["paths"].get(path, {}) | {method: {"responses": {"200": {"description": "ok"}}, **item}}
add("/api/ip", "get", "Caller IP intel: geo/ASN/ISP/VPN flags/headers")
add("/api/card", "post", "Luhn + BIN validation", {"num": "card number"}, req=True)
add("/api/sms/rent", "post", "Rent disposable number, 30 min", {"service": "service id/keyword", "country": "country id"}, req=True)
add("/api/sms/check", "get", "Poll SMS code", {"pid": "orderid"}, req=True)
add("/api/sms/cancel", "get", "Cancel + refund", {"pid": "orderid"}, req=True)
add("/api/sms/history", "get", "Rental history")
add("/api/proxy/test", "post", "Test Pleiades gateway creds", {"user": "username", "pass": "password"}, req=True)
add("/api/hash", "get", "Hashes of s", {"s": "string"}, req=True)
add("/api/hdr", "get", "HTTP response headers of url", {"url": "url"}, req=True)
return jsonify(ps)
def param(name):
return request.form.get(name) or request.args.get(name) or request.args.get("orderid") or request.form.get("orderid")
def human(n):
return n
# ---------- 1. WHAT'S MY IP ----------
@app.route("/ip")
def ip_route(): return ip_lookup()
@@ -173,10 +244,29 @@ def card():
It cannot tell you if a card has available funds. Fraud "flagged" status lives at the issuer, not in any database we can legally query.</div>"""
body = f"""
<h1>CARD <span>CHECK</span></h1><p class=sub>Is it real? Luhn + BIN intelligence: issuer, brand, type, country, prepaid risk flags.</p>
<div class=card><form method=post><input name=num placeholder="4539 1488 0343 6467" style="width:70%" value="{num}"> <button>Check</button></form></div>
<div class=card><form method=post><input id=cardnum name=num placeholder="4539 1488 0343 6467" style="width:70%" value="{num}" autocomplete=off inputmode=numeric> <button>Check</button></form>
<div style=color:var(--dim);font-size:.85rem;margin-top:.4rem>Paste anything — spaces, dashes, junk all stripped. Nothing stored.</div></div>
<script>
var cn=document.getElementById('cardnum');
cn.addEventListener('input',function(){{
var v=this.value.replace(/\\D/g,'').slice(0,19);this.value=v.replace(/(.{{4}})/g,'$1 ').trim()}});
</script>
{result}"""
return page("card", body)
@app.route("/api/card", methods=["POST"])
def api_card():
num = re.sub(r"\D", "", param("num") or "")[:19]
if not num: return jsonify({"ok": False, "error": "num required"})
ok = luhn_ok(num)
st, b = http(f"https://lookup.binlist.net/{num[:8]}", headers={"Accept-Version": "3"})
bl = jf(b) or {}
return jsonify({"ok": True, "luhn": ok, "brand": brand_of(num), "length_ok": len(num) in
{"Visa":(13,16,19),"Mastercard":(16,),"Amex":(15,)}.get(brand_of(num),(13,15,16,19)),
"bin": {"issuer": (bl.get("bank") or {}).get("name"), "country": (bl.get("country") or {}).get("name"),
"type": bl.get("type"), "prepaid": bl.get("prepaid")},
"flags": (["prepaid-risk"] if (bl.get("type")=="prepaid" or bl.get("prepaid") is True) else []) + (["luhn-invalid"] if not ok else [])})
# ---------- 3. SMS RENTALS ----------
SMSP = "https://api.smspool.net"
SERVICES = [("google","Google"),("discord","Discord"),("telegram","Telegram"),("whatsapp","WhatsApp"),("other","Other/Any")]
@@ -204,7 +294,7 @@ def sms():
con.execute("INSERT INTO sms_rentals(phone,service,country,purchase_id,cost,status,created,expires) VALUES(?,?,?,?,?,?,?,?)",
(d.get("number"), svc, ctry, str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800))
con.commit()
msg = f'<div class="card"><span class="tag ok">RENTED</span> Your number: <b style="font-size:1.2rem;color:var(--acc)">+{d.get("number")}</b> · expires in 30 min · order #{d.get("purchase_id")}</div>'
msg = f'<div class="card"><span class="tag ok">RENTED</span> Your number: <b id=bignum style="font-size:1.2rem;color:var(--acc)">+{d.get("number")}</b> <button style="padding:.2rem .6rem;font-size:.8rem" onclick="cp(\'+{d.get("number")}\')">copy</button> · expires in 30 min · order #{d.get("purchase_id")}</div>'
else:
msg = f'<div class="card"><span class="tag bad">RENT FAILED</span><br><pre>{b[:400]}</pre></div>'
elif act == "check":
@@ -223,6 +313,9 @@ def sms():
con = db(); con.execute("UPDATE sms_rentals SET status=? WHERE purchase_id=?", ("refunded" if ok else "cancel-failed", pid)); con.commit()
msg = f'<div class="card"><span class="tag {"ok" if ok else "bad"}">{"CANCELLED + REFUNDED" if ok else "CANCEL FAILED"}</span></div>'
st, b = sms_api("sms/instructions")
con = db()
hist = con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 8").fetchall()
hist_rows = "".join(f"<tr><td>+{h['phone']} <a href=# onclick=\"cp('+{h['phone']});return false\" style=color:var(--acc)>copy</a></td><td>{h['service']}</td><td>{h['status']}</td><td>#{h['purchase_id']}</td><td class=cdown data-exp={h['expires']}>…</td></tr>" for h in hist)
body = f"""
<h1>SMS <span>RENTAL</span></h1><p class=sub>Disposable numbers, 30-minute windows. Cancel before a code arrives = full refund.</p>
<div class="grid2">
@@ -230,12 +323,28 @@ def sms():
<form method=post><input type=hidden name=act value=rent>
<select name=service style="width:100%">{''.join(f'<option value={v}>{n}</option>' for v,n in SERVICES)}</select>
<select name=country style="width:100%;margin:.5rem 0">{''.join(f'<option value={v}>{n}</option>' for v,n in COUNTRIES)}</select>
<button>Rent — 30 min</button></form></div>
<button>Rent — 30 min</button></form>
<div style=color:var(--dim);margin-top:.5rem;font-size:.85rem>Numbers auto-appear below. Codes auto-poll every 10s.</div></div>
<div class=card><b>Check / manage</b>
<form method=post><input type=hidden name=act value=check><input name=pid placeholder="order # (purchase_id)" style="width:100%"><button style="margin:.5rem 0">Poll for code</button></form>
<form method=post><input type=hidden name=act value=check><input name=pid placeholder="order #" style="width:100%"><button style="margin:.5rem 0">Poll for code</button></form>
<form method=post><input type=hidden name=act value=cancel><input name=pid placeholder="order #" style="width:100%"><button style="background:var(--bad);color:#fff">Cancel &amp; refund</button></form></div>
</div>{msg}
<div class=card style=color:var(--dim)>API: POST /api/sms/rent (service,country) · /api/sms/check (pid) · /api/sms/cancel (pid)</div>"""
<div class=card><b>Recent rentals</b><table><tr><th>Number</th><th>Service</th><th>Status</th><th>Order</th><th>Window</th></tr>{hist_rows or '<tr><td colspan=5 style=color:var(--dim)>none yet</td></tr>'}</table></div>
<script>
setInterval(function(){{
var els=document.querySelectorAll('.cdown');var now=Math.floor(Date.now()/1000);
els.forEach(function(e){{var s=e.dataset.exp-now;if(s>0){{var m=Math.floor(s/60);e.textContent=m+'m '+(s%60)+'s left'}}else e.textContent='expired'}});
}},1000);
var lastMsg='';
setInterval(function(){{
fetch('/api/sms/history').then(r=>r.json()).then(rows=>{{
rows.filter(r=>r.status==='active').forEach(r=>{{
fetch('/api/sms/check?pid='+r.purchase_id).then(x=>x.json()).then(d=>{{
if(d.sms||d.code){{toast('CODE: '+(d.sms||d.code));document.title='✉ CODE '+(d.sms||d.code);}}
}})}});
}})}},10000);
</script>
<div class=card style=color:var(--dim)>API: POST /api/sms/rent (service,country) · GET /api/sms/check?pid= · GET /api/sms/cancel?pid= · GET /api/sms/history</div>"""
return page("sms", body)
@app.route("/api/sms/rent", methods=["POST"])
@@ -249,16 +358,22 @@ def api_sms_rent():
con.commit()
return jsonify(d)
@app.route("/api/sms/check", methods=["POST"])
@app.route("/api/sms/check", methods=["GET", "POST"])
def api_sms_check():
st, b = sms_api("sms/check", orderid=request.form["pid"])
st, b = sms_api("sms/check", orderid=param("pid"))
return jf(b) or jsonify({"error": b[:200]})
@app.route("/api/sms/cancel", methods=["POST"])
@app.route("/api/sms/cancel", methods=["GET", "POST"])
def api_sms_cancel():
st, b = sms_api("sms/cancel", orderid=request.form["pid"])
st, b = sms_api("sms/cancel", orderid=param("pid"))
return jf(b) or jsonify({"error": b[:200]})
@app.route("/api/sms/history")
def api_sms_history():
con = db()
rows = con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 50").fetchall()
return jsonify([dict(r) for r in rows])
# ---------- 4. PROXY LAB ----------
@app.route("/proxy", methods=["GET", "POST"])
def proxy():
@@ -302,9 +417,14 @@ def proxy():
<label style=color:var(--dim)>Password</label><br><input name=pass type=password style="width:100%"><br>
<button style=margin-top:.6rem>Test egress now</button></form></div>
{result}
<div class=card><b>Geo session builder</b> — append these to your password to steer the egress:
<select id=geoK onchange="gb()"><option value="">none</option><option value="_region-us">region US</option><option value="_region-eu">region EU</option><option value="_country-gb">country GB</option><option value="_country-de">country DE</option><option value="_city-london">city London</option></select>
<select id=geoS onchange="gb()"><option value="">rotating</option><option value="_session-a7x9_lifetime-30m">sticky 30-min</option></select>
<div style=margin-top:.5rem><code id=geoOut style=color:var(--acc)>yourpassword</code> <button style="padding:.2rem .6rem;font-size:.8rem" onclick="cp(document.getElementById('geoOut').textContent)">copy</button></div>
<div style=color:var(--dim);font-size:.85rem;margin-top:.4rem>Chain them: <code>pass_region-us_session-x9k2_lifetime-30m</code>. Same gateway keys as the storefront.</div>
<script>function gb(){{var p='yourpassword'+document.getElementById('geoK').value+document.getElementById('geoS').value;document.getElementById('geoOut').textContent=p}}</script></div>
<div class=card><b>Rent more</b> — buy GB plans &amp; geo-targeted sessions at the storefront:
<a href="{PLEIADES_APP}" style=color:var(--acc)>{PLEIADES_APP}</a>. Region/country/city suffixes on your password control geo; add
<code>_session-XXXX_lifetime-30m</code> for sticky 30-min IPs.</div>
<a href="{PLEIADES_APP}" style=color:var(--acc)>{PLEIADES_APP}</a>.</div>
<div class=card style=color:var(--dim)>API: POST /api/proxy/test (user, pass) → egress IP + geo JSON.</div>"""
return page("proxy", body)