44 terms spanning the data (page type, verified URL, IAB category), the policy model (default-deny, egress rule, zero trust), and the product mechanics (lookup, quota, database license) — each defined in a few sentences with its own anchor link, so any term here can be linked to directly from anywhere else on the site.
Every term below carries its own anchor — click the # beside any definition, or add #term-name to this page's URL, to link straight to it from a spec, a ticket, or another page on this site. Several of the definitions elsewhere on the site link back here rather than re-explaining a term inline, which is the whole point of keeping one canonical, alphabetically sorted reference instead of scattering slightly different phrasings of the same idea across dozens of pages.
Terms here fall into three groups, and knowing which group a word belongs to makes it easier to find what you actually need. Data terms describe the dataset itself — page type, verified URL, IAB category, Open PageRank — the vocabulary for talking about what a lookup returns. Policy terms describe the enforcement model built around that data — default-deny, egress rule, zero trust, least privilege — the vocabulary for talking about how a decision gets made. Product terms describe how the data and policy model are actually bought and deployed — lookup, quota, database license, OEM licensing — the vocabulary for talking about integration and cost. Most terms below sit clearly in one group, though a few, like page type itself, straddle more than one on purpose, since the data and the policy built on it are not really separable in practice. If a question format suits you better than a glossary, the full FAQ covers much of the same ground as 28 questions and answers instead of standalone definitions.
signup, password_reset, cart, checkout, upload, post_create, comment, subscribe. Because these pages create accounts, spend money, or publish content, they are the surfaces almost every agent policy denies by default, verified the same way as any other page type: never guessed.X-API-Key HTTP header (recommended for production) or an api_key query parameter; a missing or invalid key returns a 401 response.cart and subscribe), and almost universally denied by default, with a purchase-authorized agent under human approval as the rare, narrowly scoped exception.login, signup, password_reset. These carry account-takeover risk if an agent reaches them, which is why they are grouped and denied together in nearly every sample policy on this site.verdict_scope value returned when a bare domain, rather than a full URL, is submitted to the lookup API. A domain-root verdict describes the domain's baseline evaluation and is not a judgment about any specific deeper page reachable from it./login, /signin, an identity-provider subdomain — which is why it is verified per domain rather than guessed from a common path.GET /api/check, that returns an allow/deny verdict and the domain's page-type record. Priced from $99/month for 90,000 lookups (Pro) up to $1,997/month for 2,000,000 lookups (Business), with custom volumes beyond 10M/month.global_rank. Useful for policies that weight an unranked or brand-new domain differently from an established one.checkout because it commits to an ongoing charge and often a persistent account state, so agent policies can deny it separately from a one-off purchase.Every definition above is deliberately short, 40 to 80 words, enough to know what a term means and how it is used but not enough to make the case for it. For the reasoning, the trade-offs, and worked examples behind a specific term, these are the pages that go deeper — and the 2026 incidents that made several of these terms matter in the first place, from credential surface to upload page, are covered incident by incident on the incident analysis page.
Download the free 100-domain sample and match these definitions to actual verified records.