{"ok":true,"kind":"crawlcheck-capability-registry-entry","v":1,"domain":"brightdata.com","page":"https://crawlcheck.io/registry/capabilities/brightdata.com","row":{"domain":"brightdata.com","host":"brightdata.com","report_id":"ymx1bey8zb","scanned_at":"2026-10-06T04:19:52.729Z","manifest":"fdb1149dd4938fa88efe2823ff4f037b0b1474a5f9c6cf4bcb7d5a2c24316fde","declared":9,"protocols":["api"],"by_policy":{"metadata":9},"verified":0,"mismatches":0,"self_scan":false},"policy_classes":[{"id":"public_read_only","safety":"read_only_public","label":"Public read-only","automatic":true,"invoke":"May be called without credentials. CrawlCheck calls it only to check the declaration: GET with no input, on the scanned origin."},{"id":"authenticated_read_only","safety":"read_only_authenticated","label":"Authenticated read-only","automatic":false,"invoke":"Never called by CrawlCheck. An agent needs the user's own credentials and consent."},{"id":"reversible_write","safety":"reversible_write","label":"Reversible write","automatic":false,"invoke":"Never invoked automatically. Needs the owner's written authorisation and a test account."},{"id":"irreversible_write","safety":"irreversible_write","label":"Irreversible write","automatic":false,"invoke":"Never invoked automatically. Deletes or changes something that cannot be undone."},{"id":"financial","safety":"financial","label":"Financial","automatic":false,"invoke":"Never invoked automatically. Moves money or creates a charge."},{"id":"external_communication","safety":"external_communication","label":"External communication","automatic":false,"invoke":"Never invoked automatically. Sends a message, email or notification to someone."},{"id":"identity","safety":"identity_or_account","label":"Identity and accounts","automatic":false,"invoke":"Never invoked automatically. Creates, signs in to or changes an account or credential."},{"id":"unknown","safety":"unknown","label":"Unknown","automatic":false,"invoke":"Never invoked. Its effect cannot be read from the declaration, so it is treated as the riskiest case."},{"id":"metadata","safety":"metadata_only","label":"Metadata","automatic":false,"invoke":"Nothing to invoke: a listing, a server card or a skill file, not an operation."}],"items":[{"capability_id":"cap1:e4e89040577f7e0445bb","protocol":"api","operation":"Bright Data REST API - base endpoint","method":null,"endpoint":"https://api.brightdata.com","declared":{"by":"https://brightdata.com/.well-known/api-catalog","declaration_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","authentication":"unknown","params_required":null,"media":null,"safety_class":"metadata_only","safety_basis":"an API the catalog lists; its operations are in its own description"},"policy":{"id":"metadata","label":"Metadata","automatic":false,"invoke":"Nothing to invoke: a listing, a server card or a skill file, not an operation."},"observed":{"state":"not_attempted","verified":false,"at":null,"status":null,"content_type":null,"sha256":null,"mismatches":[],"not_attempted_because":"on another origin (api.brightdata.com): only the scanned origin is called"}},{"capability_id":"cap1:a7289e1a8e9058791bce","protocol":"api","operation":"Web Unlocker API, SERP API and Proxy Networks - unified request endpoint","method":null,"endpoint":"https://api.brightdata.com/request","declared":{"by":"https://brightdata.com/.well-known/api-catalog","declaration_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","authentication":"unknown","params_required":null,"media":null,"safety_class":"metadata_only","safety_basis":"an API the catalog lists; its operations are in its own description"},"policy":{"id":"metadata","label":"Metadata","automatic":false,"invoke":"Nothing to invoke: a listing, a server card or a skill file, not an operation."},"observed":{"state":"not_attempted","verified":false,"at":null,"status":null,"content_type":null,"sha256":null,"mismatches":[],"not_attempted_because":"on another origin (api.brightdata.com): only the scanned origin is called"}},{"capability_id":"cap1:fff16d89069ef58e56fe","protocol":"api","operation":"Web Scraper API - 1300+ pre-built scrapers","method":null,"endpoint":"https://api.brightdata.com/datasets/v3","declared":{"by":"https://brightdata.com/.well-known/api-catalog","declaration_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","authentication":"unknown","params_required":null,"media":null,"safety_class":"metadata_only","safety_basis":"an API the catalog lists; its operations are in its own description"},"policy":{"id":"metadata","label":"Metadata","automatic":false,"invoke":"Nothing to invoke: a listing, a server card or a skill file, not an operation."},"observed":{"state":"not_attempted","verified":false,"at":null,"status":null,"content_type":null,"sha256":null,"mismatches":[],"not_attempted_because":"on another origin (api.brightdata.com): only the scanned origin is called"}},{"capability_id":"cap1:7cefa1c7700caea134a6","protocol":"api","operation":"Dataset Marketplace - 350+ ready-made datasets","method":null,"endpoint":"https://api.brightdata.com/datasets","declared":{"by":"https://brightdata.com/.well-known/api-catalog","declaration_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","authentication":"unknown","params_required":null,"media":null,"safety_class":"metadata_only","safety_basis":"an API the catalog lists; its operations are in its own description"},"policy":{"id":"metadata","label":"Metadata","automatic":false,"invoke":"Nothing to invoke: a listing, a server card or a skill file, not an operation."},"observed":{"state":"not_attempted","verified":false,"at":null,"status":null,"content_type":null,"sha256":null,"mismatches":[],"not_attempted_because":"on another origin (api.brightdata.com): only the scanned origin is called"}},{"capability_id":"cap1:3914ea2111c56ca06e25","protocol":"api","operation":"Scraper Studio - build and run custom scrapers","method":null,"endpoint":"https://api.brightdata.com/dca","declared":{"by":"https://brightdata.com/.well-known/api-catalog","declaration_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","authentication":"unknown","params_required":null,"media":null,"safety_class":"metadata_only","safety_basis":"an API the catalog lists; its operations are in its own description"},"policy":{"id":"metadata","label":"Metadata","automatic":false,"invoke":"Nothing to invoke: a listing, a server card or a skill file, not an operation."},"observed":{"state":"not_attempted","verified":false,"at":null,"status":null,"content_type":null,"sha256":null,"mismatches":[],"not_attempted_because":"on another origin (api.brightdata.com): only the scanned origin is called"}},{"capability_id":"cap1:4b3e33f561ae315adf05","protocol":"api","operation":"Browser API - managed cloud browsers over CDP","method":null,"endpoint":"https://api.brightdata.com/browser_sessions","declared":{"by":"https://brightdata.com/.well-known/api-catalog","declaration_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","authentication":"unknown","params_required":null,"media":null,"safety_class":"metadata_only","safety_basis":"an API the catalog lists; its operations are in its own description"},"policy":{"id":"metadata","label":"Metadata","automatic":false,"invoke":"Nothing to invoke: a listing, a server card or a skill file, not an operation."},"observed":{"state":"not_attempted","verified":false,"at":null,"status":null,"content_type":null,"sha256":null,"mismatches":[],"not_attempted_because":"on another origin (api.brightdata.com): only the scanned origin is called"}},{"capability_id":"cap1:f4ea11a7435659fc1906","protocol":"api","operation":"Bright Data MCP server - streamable HTTP endpoint","method":null,"endpoint":"https://mcp.brightdata.com/mcp","declared":{"by":"https://brightdata.com/.well-known/api-catalog","declaration_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","authentication":"unknown","params_required":null,"media":null,"safety_class":"metadata_only","safety_basis":"an API the catalog lists; its operations are in its own description"},"policy":{"id":"metadata","label":"Metadata","automatic":false,"invoke":"Nothing to invoke: a listing, a server card or a skill file, not an operation."},"observed":{"state":"not_attempted","verified":false,"at":null,"status":null,"content_type":null,"sha256":null,"mismatches":[],"not_attempted_because":"on another origin (mcp.brightdata.com): only the scanned origin is called"}},{"capability_id":"cap1:d142911961f7a4c222e6","protocol":"api","operation":"MCP server - OAuth 2.1 protected resource metadata (RFC 9728)","method":null,"endpoint":"https://mcp.brightdata.com/.well-known/oauth-protected-resource","declared":{"by":"https://brightdata.com/.well-known/api-catalog","declaration_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","authentication":"unknown","params_required":null,"media":null,"safety_class":"metadata_only","safety_basis":"an API the catalog lists; its operations are in its own description"},"policy":{"id":"metadata","label":"Metadata","automatic":false,"invoke":"Nothing to invoke: a listing, a server card or a skill file, not an operation."},"observed":{"state":"not_attempted","verified":false,"at":null,"status":null,"content_type":null,"sha256":null,"mismatches":[],"not_attempted_because":"on another origin (mcp.brightdata.com): only the scanned origin is called"}},{"capability_id":"cap1:8178a213928d46aaf5aa","protocol":"api","operation":"Bright Data - OAuth 2.1 authorization server metadata (RFC 8414)","method":null,"endpoint":"https://brightdata.com/.well-known/oauth-authorization-server","declared":{"by":"https://brightdata.com/.well-known/api-catalog","declaration_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","authentication":"unknown","params_required":null,"media":null,"safety_class":"metadata_only","safety_basis":"an API the catalog lists; its operations are in its own description"},"policy":{"id":"metadata","label":"Metadata","automatic":false,"invoke":"Nothing to invoke: a listing, a server card or a skill file, not an operation."},"observed":{"state":"not_attempted","verified":false,"at":null,"status":null,"content_type":null,"sha256":null,"mismatches":[],"not_attempted_because":"metadata: describes a surface, is not itself an action"}}],"mismatches":[],"certificate":{"certificate_id":"ccap1:0c5ce5e650f7cf3df74bd9eccbd59905f7ea78edb61b0ac439ff32a80ac70071","certificate":{"kind":"crawlcheck-capability-certificate","v":1,"subject":"brightdata.com","domain":"brightdata.com","record":"ymx1bey8zb","report":"https://crawlcheck.io/r/ymx1bey8zb","manifest_sha256":"fdb1149dd4938fa88efe2823ff4f037b0b1474a5f9c6cf4bcb7d5a2c24316fde","measured_at":"2026-10-06T04:19:52.729Z","verification_checked_at":"2026-10-06T04:19:59.119Z","verification_policy":"public GETs with no required input and one read-only MCP tool with no required input, on the scanned origin only; redirects recorded, not followed","invocation_rule":"capabilities are read from declarations only; nothing is invoked. Later verification may call read_only_public operations alone; every other class needs the site owner's authorisation and a test account, and unknown is never called","counts":{"declared":9,"verified":0,"mismatches":0},"items":[{"id":"cap1:e4e89040577f7e0445bb","protocol":"api","operation":"Bright Data REST API - base endpoint","method":null,"endpoint":"https://api.brightdata.com","declared_by_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","safety_class":"metadata_only","policy":"metadata","observed":"not_attempted","status":null,"observed_sha256":null},{"id":"cap1:a7289e1a8e9058791bce","protocol":"api","operation":"Web Unlocker API, SERP API and Proxy Networks - unified request endpoint","method":null,"endpoint":"https://api.brightdata.com/request","declared_by_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","safety_class":"metadata_only","policy":"metadata","observed":"not_attempted","status":null,"observed_sha256":null},{"id":"cap1:fff16d89069ef58e56fe","protocol":"api","operation":"Web Scraper API - 1300+ pre-built scrapers","method":null,"endpoint":"https://api.brightdata.com/datasets/v3","declared_by_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","safety_class":"metadata_only","policy":"metadata","observed":"not_attempted","status":null,"observed_sha256":null},{"id":"cap1:7cefa1c7700caea134a6","protocol":"api","operation":"Dataset Marketplace - 350+ ready-made datasets","method":null,"endpoint":"https://api.brightdata.com/datasets","declared_by_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","safety_class":"metadata_only","policy":"metadata","observed":"not_attempted","status":null,"observed_sha256":null},{"id":"cap1:3914ea2111c56ca06e25","protocol":"api","operation":"Scraper Studio - build and run custom scrapers","method":null,"endpoint":"https://api.brightdata.com/dca","declared_by_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","safety_class":"metadata_only","policy":"metadata","observed":"not_attempted","status":null,"observed_sha256":null},{"id":"cap1:4b3e33f561ae315adf05","protocol":"api","operation":"Browser API - managed cloud browsers over CDP","method":null,"endpoint":"https://api.brightdata.com/browser_sessions","declared_by_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","safety_class":"metadata_only","policy":"metadata","observed":"not_attempted","status":null,"observed_sha256":null},{"id":"cap1:f4ea11a7435659fc1906","protocol":"api","operation":"Bright Data MCP server - streamable HTTP endpoint","method":null,"endpoint":"https://mcp.brightdata.com/mcp","declared_by_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","safety_class":"metadata_only","policy":"metadata","observed":"not_attempted","status":null,"observed_sha256":null},{"id":"cap1:d142911961f7a4c222e6","protocol":"api","operation":"MCP server - OAuth 2.1 protected resource metadata (RFC 9728)","method":null,"endpoint":"https://mcp.brightdata.com/.well-known/oauth-protected-resource","declared_by_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","safety_class":"metadata_only","policy":"metadata","observed":"not_attempted","status":null,"observed_sha256":null},{"id":"cap1:8178a213928d46aaf5aa","protocol":"api","operation":"Bright Data - OAuth 2.1 authorization server metadata (RFC 8414)","method":null,"endpoint":"https://brightdata.com/.well-known/oauth-authorization-server","declared_by_sha256":"f048b7aef96ca294a135474fbac10c92661ae123b48f484c86d6de6e1909a20f","safety_class":"metadata_only","policy":"metadata","observed":"not_attempted","status":null,"observed_sha256":null}],"mismatches":[]},"signature":{"alg":"Ed25519","kid":"hcIAczGf-8EFBnkunmZlvFWnD2nHHeHeC9cM4BTiBVo","certificate_sha256":"0c5ce5e650f7cf3df74bd9eccbd59905f7ea78edb61b0ac439ff32a80ac70071","message":"the UTF-8 bytes of \"crawlcheck-capability-certificate-v1\\n\" followed by certificate_sha256 (hex), where certificate_sha256 = SHA-256 of the certificate as canonical JSON (keys sorted, no whitespace)","sig":"rbfW6ZghoBcHHHjCz8HhRquTHMgvrcXzakjp6gH84LiSZGYgJgkmTpqdzJobIXF_8Odl9ej0gYZUed3auzYvCw"},"issuer":{"name":"CrawlCheck observer","key":{"jwk":{"kty":"OKP","crv":"Ed25519","x":"Ny5tAiGdpyVWTm64G1_0g_sTo4ocLL7kqjZ6cK7G5KM"},"directory":"https://crawlcheck.io/.well-known/http-message-signatures-directory"}}},"verify":"https://crawlcheck.io/api/registry/capabilities/verify?domain=brightdata.com"}