How it works Capabilities Attribution Pricing Docs Follow on X Get API access

API access · sandbox first

Request an API key.

Tell us the operator and the agents you want to name. We read every request and reply either way, including when the honest answer is that Defeat is not ready for what you are building.

Tell us who you are.

That does not look like an email address.

We scope keys to an operator, so we need the name.

Where your signing key will be published.

Enter a bare domain, like acme.co.

A sentence or two is plenty.

Signing is the product. We cannot issue a live key without this.

We use this to size the sandbox and nothing else. No newsletter, no reselling.

Request recorded

Your request is ready to send.

We keep the queue short on purpose, because every operator gets read by a person rather than filtered by a form.

reference req_000000
operator acme.co
  1. We check the operator domain resolves and that you can serve a key at the well-known path.
  2. You get a sandbox key, three mailboxes, and the flag spec, usually within two working days.
  3. Publish your key, send one signed message to yourself, and we move you to a live key.