'
# ---------- 0. AGENT DISCOVERY ----------
API_INDEX = {
"service": "AURIGA toolbox",
"description": "IP intel, card BIN validation, 30-min SMS rentals, residential proxy lab, free utilities. Human UI at /, all tools also JSON APIs.",
"endpoints": [
{"method": "GET", "path": "/api/ip", "desc": "Everything about the caller's IP: geo, ASN, ISP, VPN/proxy/hosting flags, rDNS, request headers."},
{"method": "POST", "path": "/api/card", "params": {"num": "card number (digits or formatted)"}, "desc": "Luhn + BIN intel: brand, issuer, country, type, prepaid risk flags. Nothing stored/charged."},
{"method": "POST", "path": "/api/sms/rent", "params": {"service": "SMSPool service id or keyword (273=discord, 395=google, telegram, whatsapp, other)", "country": "country id (1=US,2=UK,4=NL,150=DE)"}, "desc": "Rent a disposable number for 30 min. Returns number + orderid. Cancel before a code = full refund."},
{"method": "GET", "path": "/api/sms/check", "params": {"pid": "orderid"}, "desc": "Poll for the received SMS code."},
{"method": "GET", "path": "/api/sms/cancel", "params": {"pid": "orderid"}, "desc": "Cancel order + refund."},
{"method": "GET", "path": "/api/sms/history", "desc": "Your rental history from this site."},
{"method": "POST", "path": "/api/proxy/test", "params": {"user": "Pleiades gateway username", "pass": "password (geo suffixes allowed)"}, "desc": "Tunnel CONNECT through the Pleiades gateway, return real egress IP + geo."},
{"method": "GET", "path": "/api/hash", "params": {"s": "string"}, "desc": "md5/sha1/sha256/sha512."},
{"method": "GET", "path": "/api/hdr", "params": {"url": "target URL"}, "desc": "Fetch URL, return status + all response headers."},
],
"payment": "SMS meters against the house SMSPool account; proxy plans at the Pleiades storefront. BTCPay BTC only — no Stripe.",
}
@app.route("/api")
def api_index(): return jsonify(API_INDEX)
@app.route("/robots.txt")
def robots():
return "User-agent: *\nAllow: /\n", 200, {"Content-Type": "text/plain"}
@app.route("/llms.txt")
def llms():
eps = "\n".join(f"- `{e['method']} {e['path']}` — {e['desc']} Params: {e.get('params','-')}" for e in API_INDEX["endpoints"])
body = f"# AURIGA toolbox\n\nNetwork toolbox for humans and agents. Base: https://auriga.thetempleofdoom.com\n\n## API\n{eps}\n\nAll responses JSON. POST bodies are form-encoded. Human pages at /, /card, /sms, /proxy, /tools.\n"
return body, 200, {"Content-Type": "text/plain"}
@app.route("/ai-plugin.json")
def aiplugin():
return jsonify({"name_for_model": "auriga", "schema_version": "v1",
"description_for_model": "IP intelligence, card BIN validation, disposable SMS number rentals (30 min, refundable), residential proxy egress testing, hashing/URL/DNS utilities.",
"api": {"type": "openapi", "url": "https://auriga.thetempleofdoom.com/openapi.json"},
"auth": {"type": "none"}, "contact_email": "indianaholmes1@icloud.com"})
@app.route("/openapi.json")
def openapi():
B = "https://auriga.thetempleofdoom.com"
ps = {"openapi": "3.0.0", "info": {"title": "AURIGA", "version": "1.1.0"}, "paths": {}}
def add(path, method, desc, params=None, req=False):
item = {"summary": desc}
if params:
if method == "get":
item["parameters"] = [{"name": k, "in": "query", "required": req, "schema": {"type": "string"}, "description": v} for k, v in params.items()]
else:
item["requestBody"] = {"content": {"application/x-www-form-urlencoded": {"schema": {"type": "object", "properties": {k: {"type": "string", "description": v} for k, v in params.items()}, "required": [k for k in params] if req else []}}}}
ps["paths"][path] = ps["paths"].get(path, {}) | {method: {"responses": {"200": {"description": "ok"}}, **item}}
add("/api/ip", "get", "Caller IP intel: geo/ASN/ISP/VPN flags/headers")
add("/api/card", "post", "Luhn + BIN validation", {"num": "card number"}, req=True)
add("/api/sms/rent", "post", "Rent disposable number, 30 min", {"service": "service id/keyword", "country": "country id"}, req=True)
add("/api/sms/check", "get", "Poll SMS code", {"pid": "orderid"}, req=True)
add("/api/sms/cancel", "get", "Cancel + refund", {"pid": "orderid"}, req=True)
add("/api/sms/history", "get", "Rental history")
add("/api/proxy/test", "post", "Test Pleiades gateway creds", {"user": "username", "pass": "password"}, req=True)
add("/api/hash", "get", "Hashes of s", {"s": "string"}, req=True)
add("/api/hdr", "get", "HTTP response headers of url", {"url": "url"}, req=True)
return jsonify(ps)
def param(name):
return request.form.get(name) or request.args.get(name) or request.args.get("orderid") or request.form.get("orderid")
def human(n):
return n
# ---------- 1. WHAT'S MY IP ----------
@app.route("/ip")
def ip_route(): return ip_lookup()
def ip_lookup():
ip = request.headers.get("X-Real-IP") or request.remote_addr or ""
st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719")
d = jf(b) or {}
hdrs = {k: v for k, v in request.headers.items() if k.lower() in
("user-agent","accept-language","x-forwarded-for","cf-connecting-ip","cf-ipcountry","x-real-ip")}
proxy_hint = any(k.lower().startswith(("x-forwarded","via","proxy")) for k in request.headers.keys())
rows = [
("YOUR IP", f"{d.get('query', ip)}"),
("Country", f"{d.get('country','?')} ({d.get('countryCode','?')}) 🏴 {d.get('flag') if 'flag' in d else ''}".strip()),
("Region / City", f"{d.get('regionName','?')} / {d.get('city','?')} {d.get('zip','')}"),
("Lat, Lon", f"{d.get('lat','?')}, {d.get('lon','?')} · TZ: {d.get('timezone','?')} · UTC offset {d.get('offset','?')}s"),
("ISP", d.get('isp','?')), ("Organization", d.get('org','?')), ("AS", d.get('as','?') if d.get('as') else d.get('asname','?')),
("Reverse DNS", str(d.get('reverse','—'))),
("Connection", f"mobile: {d.get('mobile')} · proxy/VPN: {d.get('proxy')} · hosting: {d.get('hosting')}"),
("Local guess", d.get('district') or '—'),
("Proxy headers seen", "YES ⚠ (you're behind a relay)" if proxy_hint else "none — looks direct"),
("Currency", d.get('currency','?')),
]
hdr_rows = "".join(f"
{k}
{v}
" for k, v in hdrs.items())
body = f"""
WHATS MY IP
Every drop of intel we can legally scrape, always on.
{kv(rows)}
Headers you sent
{hdr_rows}
Live check — your browser also resolved this page in
….
API: GET /api/ip → same data as JSON. Agent-friendly.
"""
return page("ip", body)
@app.route("/api/ip")
def api_ip():
ip = request.headers.get("X-Real-IP") or request.remote_addr or ""
st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719")
d = jf(b) or {}
d["headers_seen"] = {k: v for k, v in request.headers.items()}
return jsonify(d)
# ---------- 2. CARD CHECK ----------
def luhn_ok(num):
digits = [int(c) for c in num]
odd = digits[-1::-2]; even = digits[-2::-2]
s = sum(odd)
for d in even:
d *= 2
if d > 9: d -= 9
s += d
return s % 10 == 0
BRANDS = [("4","Visa"),("51","Mastercard"),("52","Mastercard"),("53","Mastercard"),("54","Mastercard"),("55","Mastercard"),
("22","Mastercard"),("23","Mastercard"),("24","Mastercard"),("25","Mastercard"),("26","Mastercard"),("27","Mastercard"),
("34","Amex"),("37","Amex"),("6011","Discover"),("65","Discover"),("644","Discover"),("645","Discover"),("646","Discover"),("647","Discover"),("648","Discover"),("649","Discover"),
("50","Maestro"),("56","Maestro"),("57","Maestro"),("58","Maestro"),("63","Maestro"),("67","Maestro"),
("30","Diners"),("36","Diners"),("38","Diners"),("39","Diners"),
("35","JCB"),("62","UnionPay"),("7","Mir")]
def brand_of(num):
for pfx, b in BRANDS:
if num.startswith(pfx): return b
return "Unknown"
@app.route("/card", methods=["GET", "POST"])
def card():
result = ""
num = re.sub(r"\D", "", request.form.get("num", ""))[:19]
if num:
tags = []
ok = luhn_ok(num)
tags.append(('LUHN VALID' if ok else 'LUHN INVALID — fake/dead number'))
brand = brand_of(num)
bin8 = num[:8]
bl = bin_lookup(bin8)
bank = (bl.get("bank") or {}).get("name", "—")
country = (bl.get("country") or {}).get("name", "—")
ctype = bl.get("type", "—")
prepaid = bl.get("prepaid", "—")
if not bl: tags.append('BIN DB no data — structure-only result')
flags = []
if ctype == "prepaid" or prepaid is True: flags.append("PREPAID — commonly flagged by merchants")
if ctype == "debit": flags.append("DEBIT")
if ctype == "credit": flags.append("CREDIT")
length = len(num)
rng = {"Visa":(13,16,19),"Mastercard":(16,),"Amex":(15,),}.get(brand, (13,15,16,19))
if length not in rng: tags.append(f'LENGTH {length} WRONG for {brand}')
else: tags.append(f'length {length} valid for {brand}')
result = f"""
{kv([("Brand",brand),("BIN",bin8),("Bank / Issuer",bank),("Country",country),("Type",str(ctype)),("Prepaid",str(prepaid))])}
Nothing is stored. No charge, no auth, no $0 check — this is BIN + math validation only.
It cannot tell you if a card has available funds. Fraud "flagged" status lives at the issuer, not in any database we can legally query.
"""
body = f"""
CARD CHECK
Is it real? Luhn + BIN intelligence: issuer, brand, type, country, prepaid risk flags.
Paste anything — spaces, dashes, junk all stripped. Nothing stored.
{result}"""
return page("card", body)
def bin_lookup(bin8):
st, b = http(f"https://lookup.binlist.net/{bin8}", headers={"Accept-Version": "3"})
bl = jf(b) or {}
if not bl.get("bank") and not bl.get("type") and not bl.get("scheme"):
st, b = http(f"https://data.handyapi.com/bin/{bin8}")
h = jf(b) or {}
if h.get("Status") == "SUCCESS":
return {"bank": {"name": h.get("Issuer")}, "country": {"name": h.get("Country", {}).get("Name") if isinstance(h.get("Country"), dict) else h.get("Country")},
"type": str(h.get("Type", "")).lower() or None, "prepaid": "prepaid" in str(h.get("Type","")).lower() or None, "scheme": h.get("Scheme")}
return bl
@app.route("/api/card", methods=["POST"])
def api_card():
num = re.sub(r"\D", "", param("num") or "")[:19]
if not num: return jsonify({"ok": False, "error": "num required"})
ok = luhn_ok(num)
bl = bin_lookup(num[:8])
return jsonify({"ok": True, "luhn": ok, "brand": brand_of(num), "length_ok": len(num) in
{"Visa":(13,16,19),"Mastercard":(16,),"Amex":(15,)}.get(brand_of(num),(13,15,16,19)),
"bin": {"issuer": (bl.get("bank") or {}).get("name"), "country": (bl.get("country") or {}).get("name"),
"type": bl.get("type"), "prepaid": bl.get("prepaid")},
"flags": (["prepaid-risk"] if (bl.get("type")=="prepaid" or bl.get("prepaid") is True) else []) + (["luhn-invalid"] if not ok else [])})
# ---------- SMS ABUSE GUARD ----------
def sms_guard():
"""Return None if allowed, else a JSON-able reason string."""
con = db(); now = int(time.time())
ip = request.headers.get("X-Real-IP") or request.remote_addr or "?"
# balance: refuse if house SMSPool balance below $5
st, b = sms_api("request/balance")
bal = jf(b) or {}
try: bal = float(bal.get("balance", 0))
except Exception: bal = 0
if bal < 5: return f"house balance too low (${bal:.2f}) — rentals paused"
# per-IP: max 1 active rental, 3/hour, 8/day
row = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE status='active' AND purchase_id IN (SELECT purchase_id FROM sms_rentals WHERE created > ?)", (now-86400*7,)).fetchone()
# active count overall (any IP) cap 3 concurrent
act = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE status='active' AND expires > ?", (now,)).fetchone()["c"]
if act >= 3: return "too many active rentals right now — try again later"
h = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-3600,)).fetchone()["c"]
if h >= 6: return "hourly rental cap reached"
d = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-86400,)).fetchone()["c"]
if d >= 15: return "daily rental cap reached"
return None
# ---------- 3. SMS RENTALS ----------
SMSP = "https://api.smspool.net"
SERVICES = [("google","Google"),("discord","Discord"),("telegram","Telegram"),("whatsapp","WhatsApp"),("other","Other/Any")]
COUNTRIES = [("1","United States"),("2","United Kingdom"),("4","Netherlands"),("22","Russia"),("150","Germany")]
def sms_api(path, **kw):
if kw:
kw["key"] = SMSP_KEY
data = urllib.parse.urlencode(kw).encode()
return http(f"{SMSP}/{path}", data=data, method="POST")
return http(f"{SMSP}/{path}?key={SMSP_KEY}")
@app.route("/sms", methods=["GET", "POST"])
def sms():
msg, listing = "", ""
if request.method == "POST":
act = request.form.get("act")
if act == "rent":
guard = sms_guard()
if guard:
msg = f'
PAUSED {guard}
'
else:
svc, ctry = request.form["service"], request.form["country"]
st, b = sms_api("purchase/sms", service=svc, country=ctry)
d = jf(b) or {}
if d.get("success") == 1:
con = db()
now = int(time.time())
con.execute("INSERT INTO sms_rentals(phone,service,country,purchase_id,cost,status,created,expires) VALUES(?,?,?,?,?,?,?,?)",
(d.get("number"), svc, ctry, str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800))
con.commit()
msg = f'
RENTED Your number: +{d.get("number")} · expires in 30 min · order #{d.get("purchase_id")}
'
else:
msg = f'
RENT FAILED
{b[:400]}
'
elif act == "check":
pid = request.form["pid"]
st, b = sms_api("sms/check", orderid=pid)
d = jf(b) or {}
sms_txt = d.get("sms") or d.get("code") or ""
status = d.get("status", "?")
color = "ok" if sms_txt else "warn"
msg = f'
STATUS: {status} {"" + str(sms_txt) + "" if sms_txt else "no code yet — poll again in 10s"}
'
elif act == "cancel":
pid = request.form["pid"]
st, b = sms_api("sms/cancel", orderid=pid)
d = jf(b) or {}
ok = d.get("success") == 1
con = db(); con.execute("UPDATE sms_rentals SET status=? WHERE purchase_id=?", ("refunded" if ok else "cancel-failed", pid)); con.commit()
msg = f'
{"CANCELLED + REFUNDED" if ok else "CANCEL FAILED"}
'
st, b = sms_api("sms/instructions")
con = db()
hist = con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 8").fetchall()
hist_rows = "".join(f"
'
else:
con = db()
con.execute("INSERT INTO proxy_checks(user_key,egress_ip,geo,ok,ts) VALUES(?,?,?,?,?)", (user[:12], "", "", 0, int(time.time())))
con.commit()
result = f'
AUTH/TUNNEL FAILED
{resp[:200]!r}
'
except Exception as e:
result = f'
ERROR {e}
'
body = f"""
PROXY LAB
Rent residential proxies on the Pleiades rail — your existing gateway user:pass works here, same keys as everywhere.
{result}
Geo session builder — append these to your password to steer the egress:
yourpassword
Chain them: pass_region-us_session-x9k2_lifetime-30m. Same gateway keys as the storefront.
Rent more — buy GB plans & geo-targeted sessions at the storefront:
{PLEIADES_APP}.
API: POST /api/proxy/test (user, pass) → egress IP + geo JSON.
"""
return page("proxy", body)
@app.route("/api/proxy/test", methods=["POST"])
def api_proxy_test():
user, pw = request.form.get("user",""), request.form.get("pass","")
pauth = base64.b64encode(f"{user}:{pw}".encode()).decode()
try:
s = socket.create_connection((PLEIADES_GW.split(":")[0], int(PLEIADES_GW.split(":")[1])), timeout=15)
s.sendall(f"CONNECT ip-api.com:80 HTTP/1.1\r\nHost: ip-api.com:80\r\nProxy-Authorization: Basic {pauth}\r\n\r\n".encode())
resp = s.recv(4096)
if b"200" not in resp.split(b"\r\n")[0]: return jsonify({"ok": False, "raw": resp[:120].decode("utf-8","replace")})
s.sendall(b"GET /json/?fields=66846719 HTTP/1.1\r\nHost: ip-api.com\r\nConnection: close\r\n\r\n")
data = b""
while True:
c = s.recv(8192)
if not c: break
data += c
s.close()
j = jf(data.split(b"\r\n\r\n",1)[-1].decode("utf-8","replace")) or {}
return jsonify({"ok": True, "egress": j})
except Exception as e:
return jsonify({"ok": False, "error": str(e)})
# ---------- 5. FREE TOOLS ----------
TOOLS_JS = """
function tab(n){document.querySelectorAll('.pane').forEach(p=>p.style.display='none');document.getElementById(n).style.display='block';
document.querySelectorAll('.tbtn').forEach(b=>b.classList.remove('on'));event.target.classList.add('on')}
async function dns(){const d=document.getElementById('dq').value;const o=await (await fetch('https://dns.google/resolve?name='+encodeURIComponent(d)+'&type=A')).json();document.getElementById('do').textContent=JSON.stringify(o,null,1)}
async function hdr(){const u=document.getElementById('hq').value;const r=await (await fetch('/api/hdr?url='+encodeURIComponent(u))).json();document.getElementById('ho').textContent=JSON.stringify(r,null,1)}
function jwt(){try{const t=document.getElementById('jq').value.trim().split('.');const d=s=>JSON.stringify(JSON.parse(atob(s.replace(/-/g,'+').replace(/_/g,'/'))),null,1);document.getElementById('jo').textContent='HEADER\\n'+d(t[0])+'\\n\\nPAYLOAD\\n'+d(t[1])+'\\n\\n(signature: '+t[2]+')'}catch(e){document.getElementById('jo').textContent='Invalid JWT: '+e}}
function genhash(){const i=document.getElementById('hq2').value;['md5','sha1','sha256','sha512'].forEach(a=>{document.getElementById('h_'+a).textContent=hashlib(a,i)})}
function hashlib(a,s){return a}
async function genhash2(){const i=document.getElementById('hq2').value;const r=await(await fetch('/api/hash?s='+encodeURIComponent(i))).json();for(const k of ['md5','sha1','sha256','sha512'])document.getElementById('h_'+k).textContent=r[k]}
function uuids(){let o='';for(let i=0;i<5;i++)o+=crypto.randomUUID()+'\\n';document.getElementById('uo').textContent=o}
function pwgen(){const l=+document.getElementById('pl').value||24;const cs='abcdefghijkmnopqrstuvwxyzABCDEFGHJKLMNPQRSTUVWXYZ23456789!@#$%^&*-_=+';const a=new Uint32Array(l);crypto.getRandomValues(a);document.getElementById('po').textContent=Array.from(a,x=>cs[x%cs.length]).join('')}
"""
@app.route("/api/hdr")
def api_hdr():
url = request.args.get("url","")
if "://" not in url: url = "http://" + url
try:
req = urllib.request.Request(url, headers={"User-Agent":"Auriga/1.0"})
with urllib.request.urlopen(req, timeout=12) as r:
return jsonify({"status": r.status, "final_url": r.url, "headers": dict(r.headers)})
except Exception as e:
return jsonify({"error": str(e)})
@app.route("/api/hash")
def api_hash():
s = request.args.get("s","").encode()
return jsonify({"md5": hashlib.md5(s).hexdigest(), "sha1": hashlib.sha1(s).hexdigest(),
"sha256": hashlib.sha256(s).hexdigest(), "sha512": hashlib.sha512(s).hexdigest()})
@app.route("/tools")
def tools():
body = f"""
FREE TOOLS
High-value, zero-cost, no signup. Agent-friendly APIs underneath each.
DNS Lookup(Google DoH)
API: /api/hdr style JSON via dns.google
HTTP Header Inspector
API: GET /api/hdr?url=…
JWT Decoder (client-side, token never leaves your browser)
Hasher
md5
sha1
sha256
sha512
API: GET /api/hash?s=…
Generators
"""
return page("tools", body)
@app.route("/")
def index():
st, b = http(f"http://ip-api.com/json/{request.headers.get('X-Real-IP') or request.remote_addr}?fields=66846719")
d = jf(b) or {}
con = db()
n_sms = con.execute("SELECT COUNT(*) c FROM sms_rentals").fetchone()["c"]
n_px = con.execute("SELECT COUNT(*) c FROM proxy_checks").fetchone()["c"]
body = f"""
AURIGA TOOLBOX
One page. Every network weapon you actually use. No signup, no fluff.
◈ Whats-My-IP MAX
You're connecting from {d.get('query','?')} — {d.get('city','')}, {d.get('country','')}. Full dump: geo, ASN, ISP, VPN flags, rDNS, headers.