How to Tell an API Gateway's Official Site from Look-Alikes: 6 Checks Before You Pay
Disclosure: LLM API Guide is maintained by the SeedRouter team. The checks below work for any API gateway; SeedRouter is used as the example.
Why check first
An API gateway sees your prompts, code snippets and API keys. Money paid to a look-alike site is usually gone for good, and pasting a real key into a look-alike's config can leak it. Copycats often reuse the original name, copy and even page design, changing only the domain ending.
Check 1: Read the full domain
- Look at the whole domain in the address bar:
.net,.ai,.organd.comare different websites. - Bookmark the official site on your first visit and use the bookmark, not short links from chats, comments or ads.
- Subdomains of the official domain belong to it; something like
officialname-login.comdoes not.
Check 2: Look up the registration date
Use RDAP or WHOIS, for example by opening:
https://rdap.org/domain/seedrouter.net
The registration event shows when the domain was registered. seedrouter.net was registered on 2026-05-28. Be careful with a site that calls itself official but whose domain is only weeks old.
The date is a signal, not proof: parked domains held for sale can be older, so combine it with the next checks.
Check 3: Find the official notice
Legitimate services publish their official domains, support address and API endpoint, and keep them consistent across the homepage, docs and dashboard. SeedRouter's official channels page lists:
| Item | Official value |
|---|---|
| Website | https://seedrouter.net (launched May 2026) |
| API base URL | https://seedrouter.net/v1 |
| Support | support@seedrouter.net |
| Setup tool download | seedrouter.net/doc/onboarding/ only |
| Not affiliated | seedrouter.ai, seedrouter.org, seedrouter.io, seedrouter.com and others |
Check 4: Base URL and key come from the same site
- The base URL in the docs should be the official domain or one of its subdomains.
- Create API keys only in the official dashboard, never use keys someone "opened for you".
- In Codex or Claude Code, the base URL and key must come from the same site; otherwise you get 401 errors or send requests to a third party.
Check 5: Pay only in the official dashboard
- The top-up page should be inside the official dashboard after you sign in.
- Do not transfer money to personal accounts or "top-up agents" in group chats.
- The official team never asks for your password, verification code or API key in direct messages.
Check 6: Run a small test and read the usage logs
Use a trial or a small top-up for a few requests, then compare the model name, token counts and charges in the usage logs with the price table. New SeedRouter accounts get two free popular-model trials, so you can test before paying.
If you find a copycat
- Take screenshots and save the URL.
- Report it to the genuine service's support, for SeedRouter support@seedrouter.net.
- If the site is phishing for accounts or payments, report it to Google Safe Browsing and similar services.
Summary
Domain, registration date, official notice, base URL, payment flow and a small test: when all six line up, you are on the official site. For setup steps see Use a Third-Party API with Codex CLI and Use a Third-Party API with Claude Code.
FAQ
Which is the official SeedRouter website?
The only official SeedRouter website is seedrouter.net, launched in May 2026. seedrouter.ai, seedrouter.org, seedrouter.io and seedrouter.com are not operated by SeedRouter.
Is the domain registered first always the genuine one?
Not necessarily. Parked domains held for sale can be registered earlier. Read the registration date together with the official notice, docs and support channels.
Can a balance topped up on a look-alike site be moved to the official site?
No. Accounts and balances on different sites are completely separate, and the official service cannot look up another site's orders.