Integration · Developer tools
Connect Claude & ChatGPT to RelayShield
Ask your AI whether a work email shows up in a data breach, whether a phone number was recently SIM-swapped, or whether a link is known phishing. RelayShield checks cover breaches, infostealer logs, stolen session cookies, exposed OAuth tokens, lookalike domains, ransomware leak sites and certificate expiry. Each check is a billed lookup on your RelayShield account.
Free plan, no credit card. Takes about a minute.
Try asking
“Has [email protected] been in a data breach?”
The AI checks the address against known breaches and lists where it was exposed.
“Check [email protected] against infostealer logs.”
It checks whether credentials for that address show up in logs from malware on an infected device.
“Was +4512345678 SIM-swapped recently?”
It checks the number for a recent SIM swap or carrier port.
What your AI can do
Identity exposure
Check an email for breaches, infostealer logs, stolen session cookies and exposed OAuth tokens, and build one incident timeline.
Domain and brand threats
Scan for lookalike domains, ransomware leak sites, published secrets, brand abuse and certificate expiry, and score a domain's risk.
Links, phones and vendors
Check links for phishing or malware, detect SIM swaps, screen crypto wallets and assess breach exposure across your vendors.
“Are there phishing lookalikes of ourcompany.com?”
It scans for active lookalike domains of your domain.
“Is this email phishing? Here is the sender, subject and text.”
It scores the email from the sender, subject, body, links and attachment names you give it. Nothing is sent.
“When do the TLS certificates for ourcompany.com expire?”
It reads certificate transparency logs and shows when the domain's certificates expire.
20 tools for RelayShield
These tools are switched on when you connect. You can switch any of them off, or require your approval before it runs.
check_cert_expiryChanges dataCheck when a `domain`'s TLS certificates expire, based on certificate transparency logs. Each call is a billed lookup.check_email_breachesChanges dataCheck an `email` address against known data breaches and list where it was exposed. Each call is a billed lookup.check_email_infostealerChanges dataCheck an `email` address against infostealer malware logs to see if its credentials were stolen from an infected device. Each call is a billed lookup.check_linksChanges dataCheck one link (`url`) or up to 25 links (`urls`) for known phishing or malware abuse. Each call is a billed lookup.check_oauth_token_exposureChanges dataFind exposed OAuth tokens and SaaS credentials linked to an `email` address. Each call is a billed lookup.check_ransomware_leaksChanges dataCheck whether a `domain` appears on ransomware leak sites. Each call is a billed lookup.check_session_riskChanges dataCheck whether stolen session cookies for an `email` address are circulating, before they can be used to take over accounts. Each call is a billed lookup.check_sim_swapChanges dataDetect a recent SIM swap or carrier port for a `phone` number (E.164 format, e.g. +4512345678). Each call is a billed lookup.check_vendor_riskChanges dataAssess breach and infostealer exposure across your vendors. Pass `vendor_domains` and/or `vendor_emails`. Each call is a billed lookup.check_wallet_riskChanges dataScreen a crypto wallet `address` for risk before transacting with it. Each call is a billed lookup.get_domain_risk_scoreChanges dataScore a `domain` from 0 to 100 across six identity-exposure dimensions. Each call is a billed lookup.get_identity_graphChanges dataCorrelate an `email` address with phone numbers and domains seen alongside it in leak data. Each call is a billed lookup.get_incident_timelineChanges dataBuild one timeline of breach, stolen-session, SIM swap and lookalike-domain signals for an identity. Needs `email`; add `phone` and `domain` to include those checks. Each call is a billed lookup.get_ip_domain_intelChanges dataGet passive DNS and reputation for an `ip` address or a `domain`. Each call is a billed lookup.get_target_riskChanges dataScore how likely a `domain`'s organisation is to be targeted by attackers. Each call is a billed lookup.lookup_threat_actorChanges dataLook up a threat actor or campaign (`action` actor-lookup with `actor`), or exploit chatter about a CVE (`action` exploit-chatter with `cve_id`). Each call is a billed lookup.monitor_brand_abuseChanges dataFind abuse of a `brand` name (phishing, impersonation) across RelayShield's threat indicator data. Each call is a billed lookup.scan_lookalike_domainsChanges dataScan a `domain` for active phishing lookalike domains. Each call is a billed lookup.scan_published_secretsChanges dataFind secrets (keys, passwords) published in public sources such as GitHub for your `domain`, plus optional `vendor_domains`. Each call is a billed lookup.score_phishing_emailVisible to othersScore an email you suspect is phishing. Pass what you have: `from_address`, `from_name`, `subject`, `body_text`, `links`, `attachment_names`. Nothing is sent. Each call is a billed lookup.
Set up in three steps
- 1
Pick the app
Create a free PipMCP account and choose RelayShield from the app list.
- 2
Paste your key
Paste your RelayShield API key (it starts with rs_live_). On the RelayShield developer page, enter your email under Get API key and the key arrives right away. It includes 100 free calls, after which you add a card for pay-per-call billing.
- 3
Add the link to your AI
You get a personal MCP link. Add it to Claude, ChatGPT or Cursor:
- Click your name, then Settings › Connectors › Add custom connector.
- Paste your link as the Remote MCP server URL.
- Switch it on from the + menu in a chat.
Questions
What can the AI do in RelayShield?
It can check emails for breaches, infostealer logs, stolen sessions and exposed OAuth tokens, and correlate an email with phones and domains. It can check phone numbers for SIM swaps, links for phishing, domains for lookalikes, ransomware leaks, published secrets and certificate expiry, score domain and target risk, look up threat actors, screen crypto wallets and score suspected phishing emails.
Does the AI see my RelayShield credentials?
No. Your RelayShield API key is encrypted at rest and never shown to the AI. After you save it, it is not shown again, not even to you. The AI only sees the results of the tools it calls.
Can I control what the AI is allowed to do?
Yes. You choose which tools are switched on, for example only breach and SIM swap checks. Since every lookup is billed by RelayShield, tools can require your approval before they run. Every tool call is logged.
Does it work with ChatGPT?
Yes. In ChatGPT go to Settings › Apps & Connectors › Advanced and turn on Developer mode, then add your PipMCP link. Developer mode needs a paid ChatGPT plan: Plus, Pro, Business or Enterprise. The same link also works in Claude (Settings › Connectors › Add custom connector), Cursor and other MCP clients.
What does it cost?
PipMCP has a free plan with no credit card required. Paid plans bill per completed task. You also need your own RelayShield account. RelayShield bills its lookups to that account.
Does every check cost money?
Every RelayShield tool call is a billed lookup on your RelayShield account. A new key comes with 100 free calls, and after that you add a card for pay-per-call billing. Switching on only the checks you need keeps the AI to those.
Let your AI work in RelayShield today.
Start free. Your key stays encrypted, and you decide what the AI may do.
Connect RelayShield freePipMCP is not affiliated with RelayShield. Product names are trademarks of their owners.






