Snitch documentation
Snitch watches contracts and delivers signed exploit alerts. This guide covers the hosted API. A self-hosted binary is available on the Treasury plan.
Quickstart
Install the CLI and authenticate:
npm install -g @snitch/cli
snitch login --token $SNITCH_TOKENAdd a contract to your watchlist:
snitch watch 0x9f2c...a41 --chain base --label "Vault v2"
# → watching 1 contract
# → alerts → telegram, webhookCore concepts
A watch is a contract plus the set of alert channels attached to it. Every pending transaction that touches a watched contract is simulated against current state. If the simulation moves value the caller is not entitled to, Snitch raises a detection.
A detection carries the call trace, the estimated value at risk, and a Foundry proof. Alerts are signed so downstream automation can verify the source.
API reference
All endpoints are authenticated with a bearer token.
GET /v1/watches list watches
POST /v1/watches create a watch
DELETE /v1/watches/:id remove a watch
GET /v1/detections list detections
GET /v1/detections/:id detection + proofCreate a watch:
curl https://snitch.biz.id/v1/watches \
-H "Authorization: Bearer $SNITCH_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"address": "0x9f2c...a41",
"chain": "base",
"label": "Vault v2"
}'Webhooks
Snitch posts every detection to your webhook as JSON, signed with an HMAC-SHA256 header so you can verify authenticity.
POST /your-endpoint
X-Snitch-Signature: sha256=...
{
"id": "det_01H...",
"chain": "base",
"contract": "0x9f2c...a41",
"type": "reentrancy",
"value_at_risk_usd": 1042210,
"proof_url": "https://api.snitch.biz.id/proofs/det_01H...",
"detected_at": "2026-10-09T06:51:00Z"
}Self-hosted
The Treasury plan ships the detection engine as a self-hosted binary. Point it at your own RPC endpoints and keep all telemetry inside your infrastructure.
snitch-engine run \
--rpc $RPC_URL \
--watch-file watches.yaml \
--webhook https://internal.yourco.dev/snitchNeed something not covered here? Contact the team.