check.tf

Public API

Read-only access to the check.tf database for bots, server plugins, browser extensions and anything else you build. It runs on its own server at https://api.check.tf, so heavy use never slows down the site.

Free

No paid tiers, no credit card. Ever.

600 requests / minute

Per token. Enough to check every player joining a busy server.

Token auth

Create up to 5 tokens below and revoke them any time.

Your API tokens

Authentication & limits

Send the token in the Authorization header (or X-API-Key):

Authorization: Bearer ctf_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Every response carries X-RateLimit-Remaining and X-RateLimit-Reset. Over the limit you get 429 with Retry-After: just wait and retry. Please cache results for a few minutes and use /v1/players for batches instead of many single lookups.

Never put a token in public code or a browser extension's source. Revoke it here if it leaks.

Endpoints

GET/v1/player/:steamid

One player by SteamID64.

curl -H "Authorization: Bearer $TOKEN" https://api.check.tf/v1/player/76561198000000000
{
  "steamid64": "76561198000000000",
  "steamid3": "[U:1:39734272]",
  "status": "cheater",          // "cheater" | "exploiter" | "supporter" | "cleared" | "unknown"
  "name": "xX_aimer_Xx",
  "note": null,
  "url": "https://check.tf/player/76561198000000000",
  "reports": [{ "id": 12, "cheats": ["aimbot"], "created_at": "…", "url": "…" }],
  "supporter_of": []
}
GET/v1/players?steamids=a,b,c

Up to 100 players in one request. Made for server plugins checking everyone on the server.

curl -H "Authorization: Bearer $TOKEN" "https://api.check.tf/v1/players?steamids=76561198000000000,76561198000000001"
{ "players": [ { "steamid64": "…", "status": "unknown", … }, … ] }
GET/v1/cheaters?since=<unix> → ?cursor=<next_cursor>

For keeping your own copy in sync. Returns players whose status changed after `since`, oldest first, up to 1000 per page (limit). Only players that are or were public: a status of "unknown" means a mark was removed, so drop them. Then call again with ?cursor=<next_cursor> until it is null. Pages are cached for 30 s.

curl -H "Authorization: Bearer $TOKEN" "https://api.check.tf/v1/cheaters?since=0&limit=1000"
{
  "players": [{ "steamid64": "…", "steamid3": "…", "status": "cheater", "name": "…", "updated_at": 1791370000 }],
  "next_cursor": "1791370000_76561198000000000"   // null when you're up to date
}
GET/v1/playerlist

Cheaters, exploiters and cheater supporters in the TF2 Bot Detector format (attributes cheater, exploiter, suspicious). No token needed: add the URL as a remote player list.

https://api.check.tf/v1/playerlist