Methodology

Effective 2026-10-07

What It Calls reads the code of a public GitHub repository and shows which external APIs it calls, together with the lines of code that show it. It does not rate or judge anything: it lists facts found in the code and where they are. This page explains the rules used to find them.

What it does

Replace github.com in a repository address with whatitcalls.reactiveworks.dev. For example, github.com/owner/repo becomes whatitcalls.reactiveworks.dev/owner/repo.

The server does not clone the repository. It downloads only the files it needs through the GitHub REST API and raw file URLs, reads them in memory, and never writes the source to disk. What is stored is the facts found, their locations (file path and line number) and short quotes shown on the page.

Every piece of evidence is pinned to the commit SHA that was checked. Evidence links point to that line in that commit, so you can see exactly what was read even after the repository changes.

The four repository states

A repository state only says what the code calls. Whether a call is needed is not stated as a state; it is added as a factual sentence on a row only when the evidence is clear.

StateMeaningCondition
Calls external APIs The code contains a statement that actually calls an external API. An HTTP client call, an SDK method call, an address passed to a client constructor, or a constant or config default that flows into such a call, in a code or config file.
Calls external APIs · local option As above, and the code offers a way to switch to a local setup. A local runtime option, a user-set base URL or a local default, backed by code or config. Mentions in the docs only support this.
No external APIs found No external API call was found within the checked scope. Either the whole repository was read, or every manifest, entry point and priority file was read, no manifest lists an SDK of a catalogued provider and no code that was read calls an external API. The second case carries a “partial check n/N” tag.
Needs review Part of the scope could not be read, so we cannot say whether there is a call. Used only when none of the three above applies.

States are statements of fact. “Calls external APIs” does not mean the tool is unusable without an external service, and “No external APIs found” applies to the checked scope.

What counts as a call

Counted

  • External addresses in HTTP client calls (fetch, axios, requests and so on)
  • Provider SDK method calls and address arguments to client constructors
  • Constants and config defaults that flow into those calls, in code or config files

Not counted

  • Addresses in help, log, debug or error messages
  • Comparisons (checks such as host === "api.example.com")
  • Documentation or Markdown inside strings, UI examples and links
  • Comments, tests and example code
  • Calls made only by maintenance scripts (build, release, migrations)
  • Addresses that sit in config but are never requested (including build tool config)

Addresses that are not counted are still listed on the result page as mentions that are not calls.

Local option criteria

“Local option” is shown only when the repository’s own code or config contains one of these:

  • A local runtime option such as Ollama, LM Studio, llama.cpp or vLLM
  • A base URL the user can change (for example an OpenAI-compatible address)
  • A setting whose default is a local address

A README that only says the tool can run locally does not meet this condition.

The “Switch to local” box on a result page shows only settings found in that repository’s code (environment variable names, config keys and so on). We do not recommend other tools in general.

Row tags

Each row of the external API table lists the provider, the call location pinned to the commit (file:line), a feature label and these tags:

TagMeaning
Your API keyThe user supplies an API key or token for this provider.
Sign-in needed (not an API key)The provider uses cloud account permissions, a service account or OAuth.
No credential neededThe provider can be called without a key or sign-in.
PaidPer the pricing catalog, using this provider costs money.
Free tierPer the pricing catalog, the provider has a recurring free allowance.
Cloud by defaultThe default setting is an external host, and the code has a local option.
Can switch to localA setting lets you point the call at a local address.
The repository’s own serviceThe host is on the same domain as the repository owner, name or homepage.
SubcommandOnly a CLI subcommand makes this call.
Separate unitA separate unit inside the repository makes this call, such as a GitHub Action or a browser or editor extension.

Scope tags (subcommand, separate unit) are facts only and do not change the repository state.

Rows with clear evidence may add a factual sentence such as “Stops with a 401 without a key” or “Skips this call without a key”. These are written only when the code shows that an entry point reaches the call and which branch runs when the key is missing.

Infrastructure hosts

These hosts are not counted as external APIs. They are listed only under “Data sent out” on the result page:

  • Package and model registries (npm, PyPI, crates.io, model weight downloads and so on)
  • GitHub API, release downloads and update checks
  • Static asset CDNs
  • Analytics and telemetry
  • Documentation sites

Check scope

Basic check

A check reads one commit within these limits:

  • Up to 400 files
  • Up to 8 MB in total
  • Up to 512 KB per file (longer files are read in part and recorded as a partial check reason)

Dependency and build output folders such as node_modules, vendor, dist and build are not read.

Reading order

  1. Manifests (package.json, pyproject.toml, go.mod and so on)
  2. Config files
  3. Dockerfiles
  4. README
  5. Entry point files (main, app, server, index and so on)
  6. Source files whose path names a provider or SDK
  7. Other source files

Items 1–5 are priority files. If a limit keeps some of them from being read, the result says so.

Deep check

When a basic check ends in “Needs review” because a read limit stopped it, the same commit is read once more with wider limits:

  • Up to 2,000 files
  • Up to 64 MB in total
  • The same per-file limit as the basic check (512 KB)

Not followed

  • Git submodules are listed but not read.
  • Git LFS files are pointers only; their content is not downloaded.
  • Symbolic links are listed but not followed.

Language support

Tracing import paths from an entry point to a call is done for JavaScript, TypeScript and Python only. Go, Rust, Ruby, PHP, Java, Kotlin and Swift files are scanned for calls and addresses, but paths are not traced.

Partial checks

When the whole repository could not be read (limits, submodules, unresolved imports and so on), the result shows a “partial check” tag with the number of files read (n/N).

Pricing catalog

Code evidence proves only that a repository calls a provider. Whether that provider is paid or has a free tier comes from a separately maintained pricing catalog. Each entry was checked by opening the provider’s official pricing page, and result pages show that link and the date it was checked.

Catalog edition 2 · 36 providers · last checked 2026-10-05

Criteria

ValueCriterion
free_tier · Free tierThe official page states a free allowance you can keep using after signing up (a monthly or daily allowance, a free plan, free models). If a card is required, that is noted.
paid · PaidUsing it costs money (prepaid credits, pay as you go, subscription). One-time trial credits at sign-up do not count as a free tier.
unverified · UnverifiedThe official page could not be opened, or it had no wording to decide from.

Providers last checked more than 90 days ago are marked “Pricing info outdated” on result pages. Every catalog edit raises the edition number, and results that call the affected provider are published again as new revisions.

Model explanations

The short explanation on a result page is written by a language model. Only sentences tied to claims the server first derived from code evidence (claim IDs) are published. Sentences with content outside those claims, or with evaluative wording, are dropped. The model receives the public README, code lines and rule sentences; strings that look like secrets are masked before sending.

If the model call fails or no sentence passes these checks, the rule-based sentences are published as they are.

Limits

  • Static analysis reads code without running it. It cannot prove every case that may happen at run time.
  • Paths decided at run time, such as dynamic imports, reflection and plugins, are not resolved and are recorded as unresolved.
  • Addresses or settings a user enters at run time cannot be known.
  • Files outside the read limits or language support are not reflected in the result; this is shown as a partial check.

Revisions and rechecks

Each result is one revision, identified by:

  • The commit checked (and the read depth)
  • Scanner and verdict rules version — currently scan-5+verdict-4
  • Pricing catalog edition — currently 2
  • Correction revision

When any of these changes, a new revision is made. If the repository has new commits, use “Check the latest commit” on the result page (once every 10 minutes per repository).

Bookmarklet

Drag the button below to your bookmarks bar. On a GitHub repository page, click the bookmark to open that repository’s result in a new tab.

What It Calls

Clicked on this site, it shows install instructions instead of navigating.

If a result is wrong

Use “This result is wrong” on the result page. How reports are handled is described in the corrections policy.