# Submitting a tool to wecanuseai.com

This is a machine-readable submission path: an AI agent can call it directly on a
builder's behalf, using the same endpoint the web form uses. There is no manual review
queue: once the given email is confirmed, an automatic check reads the tool's page, and
the listing appears when that check has run.

## Submit

```
POST https://wecanuseai.com/api/submit
Content-Type: application/json

{
  "name": "Tool name",
  "url": "https://example.com",
  "category": "optional, one id from GET /api/taxonomy, for example text",
  "description": "20-500 characters.",
  "contact_email": "owner@example.com",
  "data_collection_statement": "Plainly state what user data, if any, this tool collects."
}
```

`turnstile_token` is optional and only relevant to the browser form (it gates spam there);
omit it entirely when calling this endpoint directly.

Response (`201`):

```json
{ "id": "…", "status": "pending" }
```

Nothing is public yet. A confirmation link is emailed to `contact_email`: the listing
goes live only once that link is opened, which is the actual anti-abuse gate for this
endpoint (works identically whether a human or an agent submitted it).

## Reporting a listed tool

```
POST https://wecanuseai.com/api/report
Content-Type: application/json

{
  "tool_id": "the id from /api/tools",
  "description": "20-500 characters, the specific concern rather than a vague complaint."
}
```

Reports are triaged automatically for substance before they count toward anything. No
email or identity is required to file one: reporting a privacy concern shouldn't require
giving up your own privacy.

## Listing what's live

```
GET https://wecanuseai.com/api/tools
```

Returns `{ "tools": [...] }`: only tools with a confirmed submission, current at the
time of the request.
