Request
Name the contract withchain and address, or the project with slug or domain. chain and address go together: one without the other answers 400.
chain is one of the names on Supported chains, or a decimal EVM chain id: chain=1 and chain=ethereum return the same card. A chain Trustblock does not record answers 200 with no card, never an error, so an explorer can send every chain it serves.
The five cards
The worst state wins, in this order. “Open” means neither fixed nor acknowledged, across every audit still in force.
An incident stays on the card while it is later than the latest audit in force, or less than twelve months old.
The first four come with
isFound: true. The last comes with isFound: false: the project is unknown, has no audit, or the chain is not one Trustblock records. The Etherscan card also sends status, the same value as isFound, for templates that hide the card on status: false.
The contract line
When the request names a contract and an audit’s own scope names that address, both cards addcontractLine:
null) and the card describes the project as a whole. A renderer that ignores contractLine shows exactly what it showed before.
The Blockscout card
Errors and caching
A missing project and a failure are different answers. “No audit” is a200 and is meant to be rendered. When the lookup itself fails, the route answers 503 if a dependency was briefly unreachable (with Retry-After, in seconds) or 500 otherwise. Neither says anything about the project, so neither should be cached as a card.
A lookup by
chain and address may be answered from a cache for up to five minutes, so a new audit or a correction reaches the card within that time.
The full request and response schemas are in the Etherscan card and Blockscout card references.