Enables client applications to check web resources (most commonly URLs) against Google-generated lists of unsafe web resources. The Safe Browsing APIs are for non-commercial use only.
Bring your own key. This API needs your own Google Safe Browsing API key - get one from the provider, add it once below, and the proxy injects it on every call. Your OmniStream plan covers the unified SDK, key storage, and proxy - the provider's own rate limits still apply to your key.
This is a community listing. If you own this API, you can request ownership.
npm install omnistream-sdkimport { OmniClient } from "omnistream-sdk";
const omni = new OmniClient({ token: process.env.OMNI_KEY! });
// One key reaches every API on the marketplace.
const data = await omni.call("google-safebrowsing/safebrowsing.encodedFullHashes.get");One install, one key - the same client calls every API on the marketplace.
V1 error format.
OAuth access token.
Data format for response.
JSONP
Selector specifying which fields to include in a partial response.
API key. Your API key identifies your project and provides you with API access, quota, and reports. Required unless you provide an OAuth 2.0 token.
OAuth 2.0 token for the current user.
Returns response with indentations and line breaks.
Available to use for quota purposes for server-side applications. Can be any arbitrary string assigned to a user, but should not exceed 40 characters.
Upload protocol for media (e.g. "raw", "multipart").
Legacy upload protocol for media (e.g. "media", "multipart").
A serialized FindFullHashesRequest proto.
A client ID that (hopefully) uniquely identifies the client implementation of the Safe Browsing API.
The version of the client implementation.
Finds the full hashes that match the requested hash prefixes.
/**
* GoogleSafeBrowsingAPI - generated by OmniStream from Google Safe Browsing API's OpenAPI spec.
* One typed method per endpoint. A single Omni key reaches the API.
*/
const DEFAULT_BASE = "https://grid.skinvaults.online/v1/proxy/google-safebrowsing";
export class GoogleSafeBrowsingAPIError extends Error {
status: number;
code?: string;
constructor(status: number, code: string | undefined, message?: string) {
super(message || `GoogleSafeBrowsingAPI error ${status}`);
this.name = "GoogleSafeBrowsingAPIError";
this.status = status;
this.code = code;
}
}
export interface GoogleSafeBrowsingAPIOptions {
baseUrl?: string;
fetch?: typeof fetch;
timeoutMs?: number;
}
export class GoogleSafeBrowsingAPI {
/** @param token Your OmniStream key (one key for every API). */
constructor(private token: string, private opts: GoogleSafeBrowsingAPIOptions = {}) {
if (!token) throw new Error("GoogleSafeBrowsingAPI: token is required");
}
rateLimit: { remainingMinute?: number; remainingDay?: number } | null = null;
private async _request(method: string, path: string, { params, body }: { params?: Record<string, unknown>; body?: unknown } = {}): Promise<any> {
const f = this.opts.fetch ?? globalThis.fetch;
const url = new URL((this.opts.baseUrl ?? DEFAULT_BASE).replace(/\/+$/, "") + path);
if (params) for (const [k, v] of Object.entries(params)) if (v != null) url.searchParams.set(k, String(v));
const headers: Record<string, string> = { "x-omni-key": this.token };
if (body !== undefined) headers["content-type"] = "application/json";
const res = await f(url, { method, headers, body: body !== undefined ? JSON.stringify(body) : undefined });
this.rateLimit = {
remainingMinute: Number(res.headers.get("x-ratelimit-remaining-minute")) || undefined,
remainingDay: Number(res.headers.get("x-ratelimit-remaining-day")) || undefined,
};
const data = await res.json().catch(() => ({}));
if (!res.ok) throw new GoogleSafeBrowsingAPIError(res.status, data?.error?.code, data?.error?.message);
return data.data ?? data;
}
safebrowsingEncodedFullHashesGet(params: { "encodedRequest": string; "$.xgafv"?: string; "access_token"?: string; "alt"?: string; "callback"?: string; "fields"?: string; "key"?: string; "oauth_token"?: string; "prettyPrint"?: boolean; "quotaUser"?: string; "upload_protocol"?: string; "uploadType"?: string; "clientId"?: string; "clientVersion"?: string }): Promise<any> {
return this._request("GET", "/v4/encodedFullHashes/{encodedRequest}", { params });
}
safebrowsingEncodedUpdatesGet(params: { "encodedRequest": string; "$.xgafv"?: string; "access_token"?: string; "alt"?: string; "callback"?: string; "fields"?: string; "key"?: string; "oauth_token"?: string; "prettyPrint"?: boolean; "quotaUser"?: string; "upload_protocol"?: string; "uploadType"?: string; "clientId"?: string; "clientVersion"?: string }): Promise<any> {
return this._request("GET", "/v4/encodedUpdates/{encodedRequest}", { params });
}
/** Finds the full hashes that match the requested hash prefixes. */
safebrowsingFullHashesFind(body: unknown, params: { "$.xgafv"?: string; "access_token"?: string; "alt"?: string; "callback"?: string; "fields"?: string; "key"?: string; "oauth_token"?: string; "prettyPrint"?: boolean; "quotaUser"?: string; "upload_protocol"?: string; "uploadType"?: string }): Promise<any> {
return this._request("POST", "/v4/fullHashes:find", { body, params });
}
/** Reports a Safe Browsing threat list hit to Google. Only projects with TRUSTED_REPORTER visibility can use this method. */
safebrowsingThreatHitsCreate(body: unknown, params: { "$.xgafv"?: string; "access_token"?: string; "alt"?: string; "callback"?: string; "fields"?: string; "key"?: string; "oauth_token"?: string; "prettyPrint"?: boolean; "quotaUser"?: string; "upload_protocol"?: string; "uploadType"?: string }): Promise<any> {
return this._request("POST", "/v4/threatHits", { body, params });
}
/** Fetches the most recent threat list updates. A client can request updates for multiple lists at once. */
safebrowsingThreatListUpdatesFetch(body: unknown, params: { "$.xgafv"?: string; "access_token"?: string; "alt"?: string; "callback"?: string; "fields"?: string; "key"?: string; "oauth_token"?: string; "prettyPrint"?: boolean; "quotaUser"?: string; "upload_protocol"?: string; "uploadType"?: string }): Promise<any> {
return this._request("POST", "/v4/threatListUpdates:fetch", { body, params });
}
/** Lists the Safe Browsing threat lists available for download. */
safebrowsingThreatListsList(params: { "$.xgafv"?: string; "access_token"?: string; "alt"?: string; "callback"?: string; "fields"?: string; "key"?: string; "oauth_token"?: string; "prettyPrint"?: boolean; "quotaUser"?: string; "upload_protocol"?: string; "uploadType"?: string }): Promise<any> {
return this._request("GET", "/v4/threatLists", { params });
}
/** Finds the threat entries that match the Safe Browsing lists. */
safebrowsingThreatMatchesFind(body: unknown, params: { "$.xgafv"?: string; "access_token"?: string; "alt"?: string; "callback"?: string; "fields"?: string; "key"?: string; "oauth_token"?: string; "prettyPrint"?: boolean; "quotaUser"?: string; "upload_protocol"?: string; "uploadType"?: string }): Promise<any> {
return this._request("POST", "/v4/threatMatches:find", { body, params });
}
}
export default GoogleSafeBrowsingAPI;
No reviews yet. Be the first to rate this API.
Yes. Google Safe Browsing API uses apiKey authentication, so you bring your own key from the provider. You store it once on OmniStream and the proxy injects it into every call, so your code only ever sends your Omni key.
Enables client applications to check web resources (most commonly URLs) against Google-generated lists of unsafe web resources. The Safe Browsing APIs are for non-commercial use only. It exposes 7 endpoints over GET, POST, including GET /v4/encodedFullHashes/{encodedRequest}, GET /v4/encodedUpdates/{encodedRequest}, POST /v4/fullHashes:find.
Install the OmniStream SDK for your language and call Google Safe Browsing API through it. The client is generated from this API's OpenAPI spec, so parameters and responses are fully typed, and the same client also calls every other API in the marketplace.
You can start on the free plan. OmniStream charges for the unified SDK, key storage and proxy rather than for Google Safe Browsing API itself, and Google Safe Browsing API's own rate limits still apply to your provider key.
QuickChart: An API to generate charts and QR codes using QuickChart services.
Reports a Safe Browsing threat list hit to Google. Only projects with TRUSTED_REPORTER visibility can use this method.
Fetches the most recent threat list updates. A client can request updates for multiple lists at once.
Lists the Safe Browsing threat lists available for download.
Finds the threat entries that match the Safe Browsing lists.