WebsiteCoach API
Use the WebsiteCoach API to fetch cached website report JSON and prioritized action items for internal dashboards, client portals, and workflow automation.
Ludwig Makhyan · Founder, WebsiteCoach ·
What the WebsiteCoach API is for
The WebsiteCoach API gives registered users programmatic access to the same report data they can view in the app. It is intended for internal dashboards, client portals, reporting workflows, and automation tools that need website health data in JSON format.
The public documentation intentionally avoids exposing private tokens, internal implementation details, admin-only routes, or sensitive crawl settings. Users generate and manage their own API tokens from the signed-in profile area.
Cached report JSON
Fetch the latest saved report for a domain, including scores, metrics, departments, and evidence fields.
Action items endpoint
Pull the prioritized fix list only, including priority, department, description, metric, target, and confidence.
AI repair prompts
Fetch copy-paste-ready prompts for AI coding tools, with audit evidence, URLs, learn links, and manual fallback instructions for provider-side fixes.
History-aware access
API report views are attached to the authenticated user so the same domains appear in account and admin history.
Token controls
Users can create separate tokens for different tools and revoke a token without exposing passwords or sessions.
Public API endpoints
Full cached report
Use this when your app needs the complete saved report for a domain.
GET https://websitecoach.com/api/reports?url=example.com&token=YOUR_TOKEN&lang=enAction items only
Use this for ticket creation, executive dashboards, or integrations that only need the prioritized fix list.
GET https://websitecoach.com/api/actionitems?url=example.com&token=YOUR_TOKEN&lang=enAI repair payloads
Use this when your workflow sends WebsiteCoach findings into ChatGPT, Claude, Gemini, Cursor, or another AI coding assistant.
GET https://websitecoach.com/api/payload?url=example.com&token=YOUR_TOKENThe response returns every action item with department, priority, learn URL, audit evidence, and a structured prompt. Prompts tell the AI to inspect the user's stack first and, when a fix belongs in DNS, CDN, email, registrar, CMS, or another external console, to provide a detailed manual runbook instead of inventing code changes.
Bearer token format
Server-side apps can send the token in an Authorization header instead of the query string.
Authorization: Bearer YOUR_TOKENToken and data safety
Keep tokens server-side
- Do not place API tokens in public JavaScript, mobile apps, screenshots, or shared documents.
- Create separate tokens for separate apps so one integration can be revoked without breaking the others.
- Use HTTPS only and rotate tokens when a teammate, vendor, or system no longer needs access.
- The API only returns report data available to the authenticated token owner; it does not expose passwords, sessions, billing secrets, admin routes, or private crawl headers.
Access and limits
API access is available to registered users. Each user can create up to 10 active API tokens from their profile.
API calls are designed for cached report retrieval and action-item workflows. Fresh scans and credit-based refresh behavior may change over time, so public integrations should rely on the documented cached report and action-item endpoints.
To create or revoke tokens, sign in and open API tokens.
Need a private integration?
For partner or enterprise use cases, contact WebsiteCoach before building against non-public behavior. Public documentation is the stable contract.
Related topics