Home Marketplace marketplace-api.k1.kiva.org
Mostly Safe

Yes — marketplace-api.k1.kiva.org looks mostly safe

65/ 100 trust score
Industry: Marketplace Checked Sep 4, 2026 Marketplace average: 51 28 signals

In plain English

This is an API endpoint for Kiva's marketplace, not a public website you'd visit in a browser. It belongs to a legitimate nonprofit, so the risk is low overall. The main caveat is that it still supports outdated encryption, which developers should account for when integrating.

Cross-referenced 28 live signals from Google Safe Browsing, VirusTotal, WHOIS and more on Sep 4, 2026. How we score →

Where the score comes from

We look at six areas. Here's how marketplace-api.k1.kiva.org did in each.
55
Security

The site uses a valid SSL certificate from Amazon, but it still accepts outdated TLS 1.0 and 1.1 protocols, which are known to be vulnerable. For an API, that's a moderate concern—developers should enforce a minimum of TLS 1.2 when connecting.

80
Identity

This is clearly a subdomain of kiva.org, a well-known nonprofit micro-lending platform. While no specific WHOIS data is available for this subdomain, the parent domain's reputation is strong. The lack of a dedicated about page is normal for an API endpoint.

70
Reputation

No blacklist entries, no malware flags. The site isn't ranked in the top 1 million, which is expected for an internal API. There's no Wayback Machine history, but that's also common for API subdomains that aren't crawled.

65
Transparency

The site returns a 403 Forbidden page with no contact info, about page, or social media presence. For a backend API, this is normal—transparency expectations are minimal. Bot protection blocks inspection, which isn't a negative for this kind of service.

70
Compliance

No privacy policy or terms of service are exposed on this subdomain, which is appropriate for an API that isn't intended for consumer interaction. The parent organization (Kiva) has its own legal pages, so compliance obligations are met at the main domain level.

70
Infrastructure

DNS resolves to three Amazon IPs, loading fast. No DNSSEC is set, and no email records exist—both typical for an API. The server uses AWS Elastic Load Balancer, a standard setup. Overall infrastructure is solid but not exceptional.

What we checked

The 28 signals behind this report.
Security & Transport
Certificate Issuer
Amazon
Google Web Risk
Clean
Legacy TLS
Accepted
SSL Certificate
Valid
Security Headers
0 of 6
Server
awselb/2.0
TLS Version
TLS 1.2
Identity & WHOIS
About Page
Not found
Branding
Missing
Business Disclosure
Not found
Contact Info
Unable to check
Legal Pages
Unable to check
Infrastructure & DNS
DNS Blacklists
Clean
DNS Resolution
3 IP(s)
DNSSEC
Not enabled
Email (MX Records)
None
Hosting Network (ASN)
AS16509 AMAZON-02
Page Load Time
748ms
Reputation & Reach
Page Heading
403 Forbidden
Page Title
403 Forbidden
Sitemap
Not found
Social Media Presence
Unable to check
Structured Data
None found
Tranco Rank
Not ranked
Trustpilot
No Trustpilot profile
Web Archive History
No archive found
Website Status
Bot protection detected
robots.txt
Not found

Run this site? Show your score.

Add a trust badge so visitors can see your live score for themselves.

Get your badge →
verified.fyi
marketplace-api.k1.kiva.org
65
N Partner pick
This site checks out. Stay covered everywhere: NordVPN's Threat Protection blocks known scam sites before they load.
Try NordVPN →

This domain is a subdomain of kiva.org, the well-known micro-lending nonprofit. The signals confirm it's a backend API for Kiva's marketplace, not a consumer-facing website. That explains why you get a 403 Forbidden page and find no about section, contact info, or social media presence—all normal for an API endpoint.

What matters for trust: the parent organization is legitimate, the SSL certificate is valid, and there are no malware or blacklist flags. The one real weakness is that the server still accepts deprecated TLS 1.0 and 1.1 protocols, which have known security flaws. For a developer integrating this API, that's a concern—you should configure your client to reject those old versions.

For consumers, there's nothing to worry about. You won't land on this page accidentally, and it doesn't ask you for money or personal information. If you're looking for Kiva's main site, go to kiva.org. The subdomain itself isn't a scam; it's just an internal tool with a minor security gap.

More Marketplace sites

How similar sites score. See all →