# Tech Stack Detector | Wappalyzer & BuiltWith Alternative (`thistle_dragonfly/tech-stack-detector`) Actor

See what any website is built with (7,600+ technologies) and which SaaS the company runs, straight from DNS: Google Workspace or Microsoft 365, DocuSign, Atlassian, HubSpot and more. Bulk input, $4 per 1,000 domains.

- **URL**: https://apify.com/thistle\_dragonfly/tech-stack-detector.md
- **Developed by:** [Emma](https://apify.com/thistle_dragonfly) (community)
- **Categories:** Lead generation, Developer tools, SEO tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

$4.00 / 1,000 domain scanneds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## Tech Stack Detector

Find out what any website is built with. Give it a list of domains and you get the CMS, ecommerce platform, analytics, CDN, frameworks and the rest of the stack for each one. The fingerprint database covers more than 7,600 technologies, with versions where a site exposes them.

It also reads public DNS records, which shows things a homepage never does: whether the company runs on Google Workspace or Microsoft 365, which email security gateway sits in front of their inbox, and which SaaS tools they verified their domain with. That last part covers DocuSign, Atlassian, Zoom, Slack, HubSpot, Salesforce, Stripe, OpenAI, Miro, Jamf, OneTrust, Notion, Figma and about 80 others.

Price is $4 per 1,000 domains. Sites that can't be reached are free.

### What you can do with it

- Build lead lists: Shopify stores using Klaviyo, companies on Microsoft 365 behind Proofpoint, HubSpot users without Salesforce.
- Add a tech stack column to a CRM export or spreadsheet.
- Measure how common a technology is across a list of sites.
- Qualify agency prospects before outreach (which CMS, is analytics set up, which site builder).
- Check a domain's email security setup: gateway, DMARC policy, DNS and CDN providers.
- Give an AI agent a clean JSON profile of a company's website in one call.

### Input

| Field | What it does |
|---|---|
| `domains` | Domains or URLs, for example `stripe.com` or `https://www.notion.so`. Duplicates are removed. |
| `includeDns` | SaaS, email provider, security gateway and DMARC from DNS. On by default. |
| `includeMetadata` | Title, description, language, social profiles and tracking IDs. On by default. |
| `minConfidence` | Hide weak detections. Default 50. |
| `maxConcurrency` | How many sites are checked in parallel. Default 20. |

```json
{ "domains": ["stripe.com", "allbirds.com", "techcrunch.com"] }
```

### Output

One result per domain. This is a real result, shortened:

```json
{
  "domain": "techcrunch.com",
  "httpStatus": 200,
  "technologyCount": 39,
  "technologyNames": ["Anthropic", "OpenAI", "Cloudflare", "WordPress", "MySQL", "Atlassian Cloud", "Box", "Dropbox", "Zendesk", "Cloudflare DNS", "HubSpot", "Sailthru"],
  "technologiesByCategory": { "CDN": ["Cloudflare"], "CMS": ["WordPress"], "SEO": ["Yoast SEO", "Yoast SEO Premium", "Google Search Console"], "Tag managers": ["Google Tag Manager"] },
  "technologies": [{ "name": "WordPress", "categories": ["CMS", "Blogs"], "version": "6.9.9", "confidence": 100, "website": "https://wordpress.org", "implied": false, "source": "http" }],
  "emailProvider": "Microsoft 365",
  "emailSecurity": ["Mimecast"],
  "emailSendingServices": ["Zendesk", "HubSpot"],
  "saasVerifications": ["Airtable", "Anthropic (Claude)", "Apple Business", "Atlassian", "DocuSign", "Dropbox", "Figma", "Google Search Console", "KnowBe4", "OpenAI (ChatGPT Enterprise)", "Slido"],
  "dnsProvider": "Cloudflare DNS",
  "dmarcPolicy": "reject",
  "dmarcVendors": ["Mimecast DMARC Analyzer"],
  "sslIssuer": "Let's Encrypt",
  "title": "TechCrunch | Startup and Technology News",
  "language": "en-US",
  "socialProfiles": { "x": "https://twitter.com/techcrunch", "linkedin": "https://www.linkedin.com/company/techcrunch", "youtube": "https://www.youtube.com/user/techcrunch" },
  "trackingIds": { "googleTagManager": ["GTM-M24PKK8"] },
  "scannedAt": "2026-09-28T18:02:32+00:00"
}
```

The Overview tab of the dataset puts domain, technologies, email provider, SaaS and DNS provider in one table. Export to CSV, Excel, JSON or Google Sheets from there.

### Pricing

$0.004 per domain that returns data, so $4 per 1,000. Unreachable or empty sites cost nothing. Platform usage is included in the price.

### How it works

Each homepage is fetched the way a browser would request it, without running JavaScript. Headers, cookies, HTML, script URLs, meta tags and page elements are then matched against the open-source [webappanalyzer](https://github.com/enthec/webappanalyzer) fingerprints (GPL-3.0). DNS records are read over DNS-over-HTTPS and the TLS certificate issuer is recorded.

Some limits to be aware of:

- Tools that only load through JavaScript (some single-page apps, pixels added by a tag manager) can be missed. DNS results still work for those sites.
- Sites with aggressive bot protection may answer with a 403. You still get the DNS results, and the protection vendor itself (Akamai Bot Manager, DataDome, etc) usually shows up.
- Only public information is read. No logins and no personal data.

### API and integrations

Run it through the [Apify API](https://docs.apify.com/api/v2), on an Apify schedule, or from Make, Zapier, n8n and Google Sheets. AI agents can call it through the Apify MCP server. A monthly scheduled run on your target list is an easy way to spot stack changes.

### Feedback

Seeing a wrong or missing detection? Open an issue with the domain and we'll fix the fingerprint.

# Actor input Schema

## `domains` (type: `array`):

Websites to analyze. Bare domains (stripe.com), URLs (https://www.stripe.com/pricing) or a mix. Duplicates are removed automatically.

## `includeDns` (type: `boolean`):

Reads public DNS records (TXT, MX, NS, SPF, DMARC) to find the email provider (Google Workspace, Microsoft 365, etc), the email security gateway, sending services, and SaaS tools the company verified its domain with (DocuSign, Atlassian, Zoom, OpenAI and many more).

## `includeMetadata` (type: `boolean`):

Title, description, language, social profiles (LinkedIn, X, Facebook, GitHub, etc) and tracking IDs (Google Analytics, Tag Manager, Meta Pixel, etc).

## `minConfidence` (type: `integer`):

Only report technologies detected with at least this confidence.

## `maxConcurrency` (type: `integer`):

How many websites to analyze in parallel.

## `requestTimeoutSecs` (type: `integer`):

Give up on a website that does not respond within this time.

## `includeRawDns` (type: `boolean`):

Adds the raw TXT/MX/NS/SOA/DMARC records to each result.

## Actor input object example

```json
{
  "domains": [
    "stripe.com",
    "shopify.com",
    "notion.so"
  ],
  "includeDns": true,
  "includeMetadata": true,
  "minConfidence": 50,
  "maxConcurrency": 20,
  "requestTimeoutSecs": 20,
  "includeRawDns": false
}
```

# Actor output Schema

## `overview` (type: `string`):

Domain, technologies, email provider, SaaS from DNS and DNS provider.

## `results` (type: `string`):

Every field, including per-technology details, DMARC, tracking IDs and social profiles.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "stripe.com",
        "shopify.com",
        "notion.so"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("thistle_dragonfly/tech-stack-detector").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "domains": [
        "stripe.com",
        "shopify.com",
        "notion.so",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("thistle_dragonfly/tech-stack-detector").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "stripe.com",
    "shopify.com",
    "notion.so"
  ]
}' |
apify call thistle_dragonfly/tech-stack-detector --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,thistle_dragonfly/tech-stack-detector"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/qG07Jom4jmwDUkSef/builds/2q0num0YHJY7gzvnm/openapi.json
