VirusTotal alternative

A commercial VirusTotal API alternative, built for the moment before someone clicks.

VirusTotal is a great analyst tool: paste a URL, read what dozens of engines think, thirty seconds to a minute later. It was never built to sit inside a commercial product, and its own terms of service say so. SkanQRCode is a fast URL check API built for exactly that: a verdict in under 500 ms, licensed for commercial use from day one.

Fast URL check API

One call, a verdict, before the open.

var req = URLRequest(url: URL(string: "https://api.skanqrcode.com/v1/check")!)
req.httpMethod = "POST"
req.setValue("Bearer \(apiKey)", forHTTPHeaderField: "Authorization")
req.httpBody = try JSONEncoder().encode(["target": url])
let (data, _) = try await URLSession.shared.data(for: req)
let result = try JSONDecoder().decode(CheckResponse.self, from: data)
if result.action == "block" { return } // never UIApplication.shared.open(url)

Comparison

VirusTotal API vs. SkanQRCode

Both keep the same job in mind, tell a caller whether a URL is safe, they are just built for different moments.

Typical response timeSeconds to about a minute for a URL not already cachedFast path under 500 ms
Commercial usePublic API is for non-commercial use; commercial use needs an Enterprise contractCommercial from day one, on every paid plan
Built forAnalyst review in a browser tab, after the factThe moment between decode and open, before a user or agent acts
Free tierRate-limited public API, non-commercial only1,000 API calls / mo, sandboxed, commercial testing allowed
Agent / MCP supportREST API only, no MCP serverMCP server and REST API, same verdict either way
Verdict formatPer-engine detection counts to interpret yourselfOne verdict, one action: allow, warn, or block

FAQ

VirusTotal API, commercial use, and speed.

Is the VirusTotal API free for commercial use?

No. VirusTotal's public API terms of service restrict it to non-commercial use. Shipping it inside a commercial product, a QR scanner app, an MDM tool, an AI agent, requires a separate VirusTotal Enterprise contract.

How fast is the VirusTotal API for a URL scan?

It depends on whether VirusTotal has already analyzed that URL. A cached result can return quickly; a URL its engines have not seen before commonly takes somewhere around 15 to 60 seconds, often cited around 30 seconds, to finish scanning. That is fine for after-the-fact analysis, and too slow for the window between a QR scan and opening the link.

What is a faster alternative to VirusTotal for real-time URL checks?

SkanQRCode is built specifically for that window: a fast path under 500 ms, commercial use on every paid plan, and the same check available as a direct REST API or an MCP server for AI agents.

Can I use VirusTotal inside a commercial QR scanner or AI agent?

Not on the public API, per VirusTotal's own terms. SkanQRCode is commercial from day one: the free plan is sandboxed for testing, and every paid plan is explicitly licensed for production use.

Early access

Keep the workflow. Lose the thirty-second wait.

If VirusTotal is the tool you reach for after something already happened, this is the check for the moment before it does.

Get an API key when v0 ships

1,000 free API calls a month. No card. Tell us what you are wiring it into.

What are you building?

Built alongside developers securing mobile apps and autonomous agents.