# CookieScope API
> Programmatic GDPR, ePrivacy, and CCPA Compliance Engine.

CookieScope audits unauthorized zero-consent tracking cookies, external font IP transfers (Munich Regional Court LG München I, Az. 3 O 17493/20), and Subresource Integrity (SRI) script hashes.

## Core Endpoints
- [Execute Privacy Audit](https://consent.scopekit.net/v1/audit?domain=example.com): Full 3-vector audit with 0-100 privacy score and legal verdict.
- [Interactive API Documentation](https://consent.scopekit.net/docs): Interactive Swagger API documentation console.
- [OpenAPI 3.0 Specification](https://consent.scopekit.net/v1/openapi.json): Standard machine-readable OpenAPI schema for agents and developers.
- [Sister Tool: MailLock Deliverability](https://maillock.agentlabs.workers.dev): Audit SPF, DMARC, DKIM, and dangling CNAME takeovers.
- [Sister Tool: GEOScope AI Search Audit](https://geoscope.agentlabs.workers.dev): Audit website AI bot visibility and /llms.txt optimization.
- [Sister Tool: StackScope Tech Intelligence](https://stackscope.agentlabs.workers.dev): Sub-50ms website tech stack and framework detection.

## Authentication
Tier 1 Diagnostic endpoints (/v1/audit, /v1/audit/cookies, /v1/audit/fonts, /v1/audit/sri) are free.
Tier 2 (Pro Remediation: Consent Shield, Font Shield) and Tier 3 (Agency Suite: Printable Compliance Certificate) require an API key passed via 'X-API-Key' or '?api_key='.
Evaluation key: 'cookiescope_eval_2026'.
