Quick start
Base URL:
https://mysmartcopilot.com/tool-api/v1/
POST endpoints take a JSON body (Content-Type: application/json); GET endpoints take query parameters. Responses are
JSON with "ok": true on success (only qr with "format": "svg" returns the image itself), errors are
JSON too, and GET /tool-api/v1/ lists all endpoints. Browsers may call the API from any site: responses carry
Access-Control-Allow-Origin: * and no credentials are used.
With curl:
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/json/format \
-H 'Content-Type: application/json' \
-d '{"json":"{\"name\":\"MySmartCoPilot\",\"tools\":[\"json\",\"emi\"],\"free\":true}","indent":2}'
From JavaScript:
const res = await fetch('https://mysmartcopilot.com/tool-api/v1/hash', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({"text":"hello world","algorithm":"sha256"}),
});
const data = await res.json();
if (!data.ok) throw new Error(data.error.message);
console.log(data.hash);
Business licence keys
The licence key of a Business pass also works as an API key. Send it in the X-Api-Key header, from your own server rather
than a web page: anyone who has the key can use its quota and the pass. For example, with the key in the environment variable MYSMARTCOPILOT_KEY:
curl -s -i -X POST https://mysmartcopilot.com/tool-api/v1/hash \
-H 'Content-Type: application/json' \
-H "X-Api-Key: $MYSMARTCOPILOT_KEY" \
-d '{"text":"hello world","algorithm":"sha256"}'
- 120 requests a minute, counted per key: every server and address that uses the key shares them. Like the
anonymous limit, it is approximate, because it is counted in memory on each Cloudflare server that handles your requests.
- Up to 10,000 calls per calendar month (UTC). Every call the key is accepted for counts, including one that the
endpoint then rejects as invalid input.
-
When the month’s calls are used up, you get
429 with a Retry-After header until 00:00 UTC on the 1st. Without the
X-Api-Key header, the anonymous limit still applies.
- A Pro licence key gets
403: a Pro pass raises the limits of the server-side checks on the website, and API access is part of Business. - The automatic pause described above applies to key holders too, and
GET /tool-api/v1/ lists this allowance under limits.businessLicenceKey.
Answers to a valid Business key carry these headers, and browsers on other sites can read them too. 404, 405 and 503
answers have none of them: the key has not been checked by then.
Headers on answers to a Business licence key | Header | Value |
| X-RateLimit-Limit | Requests a minute for this key (120). |
| X-RateLimit-Remaining | Requests you can send right now. Used requests come back gradually, all of them within a minute. |
| X-Quota-Limit | Calls per calendar month (10,000). |
| X-Quota-Remaining | Calls left this month. |
| X-Quota-Reset | When the month’s calls start again: 00:00 UTC on the 1st, as an ISO 8601 time. |
A refusal for the per-minute limit comes before the month is counted, so it has X-RateLimit-* and Retry-After but no
X-Quota-* headers. A refused body (400, 413, 415) has been counted, so it has them.
What the key adds, plainly: twice the anonymous rate (120 instead of 60 requests a minute),
counted per licence instead of per IP address, so it works the same from serverless platforms and from shared or changing addresses, and the quota headers.
It is not the only way to call the API and does not raise the total number of calls: use without a key stays open to everyone and has no monthly cap.
Endpoints
The example responses below were produced by running the real API code when this page was built.
Pretty-print or minify JSON. Strict RFC 8259 parsing; numbers and strings are kept exactly as written.
Same job in your browser, without uploading anything: JSON Formatter
Body fields for json/format | Field | Type | Required | Description |
| json | string | Yes | The JSON text (up to 100,000 characters). |
| indent | number | "tab" | No | Spaces per level, 0–8 (0 = minified). Default 2. |
| sortKeys | boolean | No | Sort object keys alphabetically. Default false. |
Request
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/json/format \
-H 'Content-Type: application/json' \
-d '{"json":"{\"name\":\"MySmartCoPilot\",\"tools\":[\"json\",\"emi\"],\"free\":true}","indent":2}'
Response
{
"ok": true,
"output": "{\n \"name\": \"MySmartCoPilot\",\n \"tools\": [\n \"json\",\n \"emi\"\n ],\n \"free\": true\n}",
"stats": {
"keys": 3,
"objects": 1,
"arrays": 1,
"maxDepth": 2,
"duplicateKeys": []
}
}
POST /tool-api/v1/json/validate
Check whether text is valid JSON and get the exact line and column of the first error.
Same job in your browser, without uploading anything: JSON Validator
Body fields for json/validate | Field | Type | Required | Description |
| json | string | Yes | The JSON text (up to 100,000 characters). |
Request
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/json/validate \
-H 'Content-Type: application/json' \
-d '{"json":"{\"a\": 1,}"}'
Response
{
"ok": true,
"valid": false,
"error": {
"message": "Trailing comma is not allowed before '}'",
"line": 1,
"column": 9
}
}
POST /tool-api/v1/text/stats
Count words, characters (Unicode-aware), sentences, paragraphs and lines, with reading and speaking time.
Same job in your browser, without uploading anything: Word Counter
Up to 20,000 characters per request.
Body fields for text/stats | Field | Type | Required | Description |
| text | string | Yes | The text to analyse (up to 20,000 characters). |
Request
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/text/stats \
-H 'Content-Type: application/json' \
-d '{"text":"MySmartCoPilot tools run in your browser. Files stay on your device!"}'
Response
{
"ok": true,
"stats": {
"words": 11,
"characters": 68,
"charactersNoSpaces": 58,
"letters": 56,
"sentences": 2,
"paragraphs": 1,
"lines": 1,
"utf8Bytes": 68,
"readingMinutes": 0.05,
"speakingMinutes": 0.08,
"avgWordLength": 5.09,
"longestWord": "MySmartCoPilot"
}
}
POST /tool-api/v1/calc/emi
Monthly instalment (EMI), total interest and total payment for a reducing-balance loan; optional year-by-year schedule.
Same job in your browser, without uploading anything: EMI Calculator
Body fields for calc/emi | Field | Type | Required | Description |
| principal | number | Yes | Loan amount (1 to 1,000,000,000,000). |
| annualRatePercent | number | Yes | Yearly interest rate in percent (0–60). |
| months | integer | Yes | Tenure in months (1–600). |
| schedule | "none" | "yearly" | No | Add a year-by-year breakdown. Default "none". |
Request
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/calc/emi \
-H 'Content-Type: application/json' \
-d '{"principal":500000,"annualRatePercent":9.5,"months":60}'
Response
{
"ok": true,
"emi": 10500.93,
"totalInterest": 130055.84,
"totalPayment": 630055.84
}
POST /tool-api/v1/hash
MD5, SHA-1, SHA-256, SHA-384 or SHA-512 digest of UTF-8 text, as hex or Base64.
Same job in your browser, without uploading anything: Hash Generator
Body fields for hash | Field | Type | Required | Description |
| text | string | Yes | Text to hash, encoded as UTF-8 (up to 100,000 characters; empty is allowed). |
| algorithm | "md5" | "sha1" | "sha256" | "sha384" | "sha512" | Yes | Hash function. MD5 and SHA-1 are not collision-resistant — use them only for checksums. |
| encoding | "hex" | "base64" | No | Output encoding. Default "hex" (lower case). |
Request
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/hash \
-H 'Content-Type: application/json' \
-d '{"text":"hello world","algorithm":"sha256"}'
Response
{
"ok": true,
"algorithm": "sha256",
"encoding": "hex",
"hash": "b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9"
}
GET /tool-api/v1/uuid
Generate random (v4) or time-ordered (v7) UUIDs.
Same job in your browser, without uploading anything: UUID Generator
Query parameters for uuid | Parameter | Type | Required | Description |
| version | 4 | 7 | No | UUID version. Default 4. |
| count | integer | No | How many to generate, 1–100. Default 1. |
Request
curl -s 'https://mysmartcopilot.com/tool-api/v1/uuid?version=7&count=2'
Response
{
"ok": true,
"version": 7,
"uuids": [
"01a10c6e-7d79-738d-8106-436fbd834079",
"01a10c6e-7d79-738e-88f5-7225935ceda2"
]
}
POST /tool-api/v1/base64/encode
Encode UTF-8 text as Base64 (standard or URL-safe alphabet).
Same job in your browser, without uploading anything: Base64 Encoder & Decoder
Body fields for base64/encode | Field | Type | Required | Description |
| text | string | Yes | Text to encode (UTF-8, up to 100,000 characters). |
| urlSafe | boolean | No | Use the URL-safe alphabet (- and _ instead of + and /). Default false. |
| padding | boolean | No | Add "=" padding. Default true for standard, false for URL-safe. |
Request
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/base64/encode \
-H 'Content-Type: application/json' \
-d '{"text":"नमस्ते MySmartCoPilot ✓"}'
Response
{
"ok": true,
"output": "4KSo4KSu4KS44KWN4KSk4KWHIE15U21hcnRDb1BpbG90IOKckw==",
"bytes": 37
}
POST /tool-api/v1/base64/decode
Decode Base64 (standard or URL-safe, padding optional) back to UTF-8 text.
Same job in your browser, without uploading anything: Base64 Encoder & Decoder
Body fields for base64/decode | Field | Type | Required | Description |
| base64 | string | Yes | Base64 text (whitespace is ignored; up to 100,000 characters). |
Request
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/base64/decode \
-H 'Content-Type: application/json' \
-d '{"base64":"TXlTbWFydENvUGlsb3Qg4pyT"}'
Response
{
"ok": true,
"text": "MySmartCoPilot ✓",
"bytes": 18
}
POST /tool-api/v1/url/encode
Percent-encode text for a URL query value or path segment ("component"), or a whole URL ("uri").
Same job in your browser, without uploading anything: URL Encoder & Decoder
Body fields for url/encode | Field | Type | Required | Description |
| text | string | Yes | Text to encode (up to 100,000 characters). |
| mode | "component" | "uri" | No | "component" (encodeURIComponent, default) or "uri" (encodeURI keeps :/?#&= intact). |
Request
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/url/encode \
-H 'Content-Type: application/json' \
-d '{"text":"price list & offers/2026?q=₹500"}'
Response
{
"ok": true,
"output": "price%20list%20%26%20offers%2F2026%3Fq%3D%E2%82%B9500"
}
POST /tool-api/v1/url/decode
Decode percent-encoded text (%E2%82%B9 → ₹). Optionally treat "+" as a space (form encoding).
Same job in your browser, without uploading anything: URL Encoder & Decoder
Body fields for url/decode | Field | Type | Required | Description |
| text | string | Yes | Percent-encoded text (up to 100,000 characters). |
| plusAsSpace | boolean | No | Decode "+" as a space, as in HTML form data. Default false. |
Request
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/url/decode \
-H 'Content-Type: application/json' \
-d '{"text":"price%20list%20%26%20offers%2F2026%3Fq%3D%E2%82%B9500"}'
Response
{
"ok": true,
"output": "price list & offers/2026?q=₹500"
}
POST /tool-api/v1/qr
Create a QR code as an SVG image (returned in JSON, or as image/svg+xml with "format": "svg").
Same job in your browser, without uploading anything: QR Code Generator
Body fields for qr | Field | Type | Required | Description |
| text | string | Yes | Text or URL to encode (up to 2,953 bytes at level L; less at higher levels). |
| errorCorrection | "L" | "M" | "Q" | "H" | No | Error-correction level (7 %, 15 %, 25 %, 30 % recoverable). Default "M". |
| margin | integer | No | Quiet zone in modules, 0–16. Default 4 (the QR specification minimum). |
| dark | string | No | Module colour as #rrggbb or #rrggbbaa. Default #000000. |
| light | string | No | Background colour as #rrggbb or #rrggbbaa (#ffffff00 = transparent). Default #ffffff. |
| format | "json" | "svg" | No | "json" (default) returns {"ok":true,"svg":"…"}; "svg" returns the image itself. |
Request
curl -s -X POST https://mysmartcopilot.com/tool-api/v1/qr \
-H 'Content-Type: application/json' \
-d '{"text":"https://mysmartcopilot.com/","errorCorrection":"M"}'
Response (long values shortened here)
{
"ok": true,
"svg": "<svg xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 37 37\" shape-rendering=\"crispEdges\"><path fill=\"#ffffff\" d=\"M0 0h37… (1,552 characters)"
}