# Ironfang > Ironfang Ltd builds developer infrastructure products and operates the UK infrastructure behind them: rendering, website evidence, e-invoice validation, disposable integration test environments and session replay. One account, one API key format and one portal cover every product. The products are Ironfang Render, Ironfang Audit, Ironfang Finance, Ironfang Rig and Ironfang Analytics. Each is self-service and has a REST API under https://api.ironfang.com with an OpenAPI 3.1 contract. One platform API key format, minted in the portal at https://portal.ironfang.com and sent as a bearer token, works across them; each key carries the scopes of the products it may use. An MCP server at https://mcp.ironfang.com/mcp offers the products as tools to AI assistants over OAuth. - Ironfang Render: Screenshots, PDFs, templated images, QR codes and short video clips from a URL or a block of HTML. - Ironfang Audit: Website audits run against rules and rule packs, on demand or on a schedule, producing findings and signed, independently timestamped evidence bundles that anyone can verify offline. - Ironfang Finance: Invoice validation against EN 16931 and Peppol BIS Billing 3 (UBL), XRechnung 3.0.2 (UBL and CII) and ZUGFeRD / Factur-X (CII XML or hybrid PDF), JSON-to-UBL generation, readable PDFs and signed validation reports. - Ironfang Rig: Disposable external environments for integration tests: temporary inboxes, public callback URLs, mock HTTP endpoints and connector routes to a local port, allocated per run. - Ironfang Analytics: Session replay for websites: records visits from the first page unless the visitor opts out, masks card numbers in the browser, and keeps each recording with the visitor's IP address, browser and page details for 28 days. Renderwolf, Auditwolf and Financewolf are the names Ironfang Render, Ironfang Audit and Ironfang Finance launched under. They are not separate products, and nothing new uses them. Each survives only as a compatibility alias of something with a current name, or inside an identifier that cannot change without breaking a client. None is deprecated with a removal date; all are superseded. - Renderwolf is Ironfang Render. Aliases that still answer: API base https://api.ironfang.com/renderwolf; API base https://api.ironfang.com; site paths under /renderwolf (301 to /render); scopes renderwolf:* (read as render:*); MCP tools renderwolf.* (callable, never listed; use render.*). Stable identifiers that keep the old spelling: HTTP response headers X-Renderwolf-*; webhook headers Renderwolf-Signature, Renderwolf-Timestamp and Renderwolf-Event-Id; default storage key prefix renderwolf/; packages @ironfang/renderwolf (npm) and ironfang-renderwolf (PyPI); repository ironfang-ltd/renderwolf-action. - Auditwolf is Ironfang Audit. Aliases that still answer: API base https://api.ironfang.com/auditwolf; site paths under /auditwolf (301 to /audit); scopes auditwolf:* (read as audit:*); MCP tools auditwolf.* (callable, never listed; use audit.*). Stable identifiers that keep the old spelling: webhook headers Auditwolf-Signature, Auditwolf-Timestamp and Auditwolf-Event-Id; crawler User-Agent Auditwolf-Spiderwolf/1.0; default export key prefix auditwolf/; the product value auditwolf in the plans catalogue served at /audit/v1/plans. - Financewolf is Ironfang Finance. Aliases that still answer: API base https://api.ironfang.com/financewolf; site paths under /financewolf (301 to /finance); scopes financewolf:* (read as finance:*). Stable identifiers that keep the old spelling: schema identifiers financewolf/einvoice/.../v1 in API payloads; canonicalisation identifiers financewolf-json/1 and financewolf-ubl/...; the product value financewolf-einvoicing in signed reports; HTTP headers X-Financewolf-* and webhook headers Financewolf-Signature, Financewolf-Timestamp and Financewolf-Event-Id; packages @ironfang/financewolf (npm) and ironfang-financewolf (PyPI); repository ironfang-ltd/financewolf-integrations. ## Ironfang Render Use it when: You need an image, PDF or clip of a web page or of your own HTML without running a browser. Free tier: 250 credits a month, no card; free output carries a small Ironfang Render badge. - [Product overview](https://ironfang.com/render): Screenshots, PDFs, templated images, QR codes and short video clips from a URL or a block of HTML. - [Documentation](https://ironfang.com/render/docs): The reference for the API at https://api.ironfang.com/render. - [OpenAPI specification](https://api.ironfang.com/render/openapi.yaml): The machine-readable contract, version 1.0.0. Also served as JSON at the same path with a .json extension. - [Authentication](https://ironfang.com/render/docs#auth): A platform API key sent as a bearer token. Scopes begin render: (render:*, render:render, render:sign, render:templates:read, render:templates:write, render:destinations, render:usage:read). - [Errors](https://ironfang.com/render/docs#errors): One JSON error body with a stable code, a message, a documentation link and the request id. - [MCP tools](https://ironfang.com/docs/mcp): Available, 17 tools named render.*. Screenshots, PDFs, QR codes, template renders, clips, batches, signed render URLs, webhook delivery destinations, jobs and usage. Storage destinations carry credentials and stay in the portal. - [Ironfang Render vs ScreenshotOne and Urlbox](https://ironfang.com/render/compare): Price per thousand renders, feature by feature, and a section naming what the rivals do better. Checked against their own pricing pages and dated. - [ScreenshotOne alternative](https://ironfang.com/render/screenshotone-alternative): Direct comparison with parameter mappings for switching. - [Urlbox alternative](https://ironfang.com/render/urlbox-alternative): Direct comparison with parameter mappings for switching. - [Guides and quickstarts](https://ironfang.com/render/guides): Worked examples and one-request quickstarts; each is listed under Guides below. - [n8n community node](https://www.npmjs.com/package/@ironfang/n8n-nodes-ironfang): Screenshots, PDFs, template images, signed URLs and usage as n8n steps. - [GitHub Action](https://github.com/ironfang-ltd/renderwolf-action): Capture pages from a workflow. The repository keeps its launch-era name; the product is Ironfang Render. ## Ironfang Audit Use it when: You need to check a website against your own rules and keep verifiable evidence of what it showed and when. Free tier: 100 credits a month, 1 site, 7 days of hosted retention; no card. - [Product overview](https://ironfang.com/audit): Website audits run against rules and rule packs, on demand or on a schedule, producing findings and signed, independently timestamped evidence bundles that anyone can verify offline. - [Documentation](https://ironfang.com/audit/docs): The reference for the API at https://api.ironfang.com/audit. - [OpenAPI specification](https://api.ironfang.com/audit/openapi.yaml): The machine-readable contract, version 1.0.0. Also served as JSON at the same path with a .json extension. - [Authentication](https://ironfang.com/audit/docs#api-keys): A platform API key sent as a bearer token. Scopes begin audit: (audit:*, audit:read, audit:run, audit:manage, audit:evidence, audit:integrations). - [Errors](https://ironfang.com/audit/docs#errors): One JSON error body with a stable code, a message, a documentation link and the request id. - [MCP tools](https://ironfang.com/docs/mcp): Available, 9 tools named audit.*. Read sites, audits, findings, rules and usage, and start a bounded audit of a site. Changing a rule, a site, a monitor or a finding stays in the portal and the REST API. - [Verify evidence](https://ironfang.com/audit/verify): Upload an evidence ZIP or download the open-source offline verifier. - [Verifier and CLI source](https://github.com/ironfang-ltd/cli): Apache 2.0 source and signed cross-platform releases of the ironfang command-line client. ## Ironfang Finance Use it when: You need to check or produce a Peppol BIS Billing 3 invoice or credit note, check an XRechnung or ZUGFeRD / Factur-X invoice, or understand a validation rule such as BR-CO-10. Ironfang Finance does not transmit invoices, operate a certified Peppol Access Point, register participants, certify legal or tax compliance, or guarantee recipient acceptance. Plans: Free includes 250 validations per UTC calendar month, with no card. Build is £29 for 5,000, Pro is £99 for 25,000, Platform is £299 for 100,000 operations per subscription month. Paid plans share validation and generation allowance; authenticated generation requires a paid plan; paid plans serve UK and EU businesses. GBP prices include applicable tax, with no automatic overage. The anonymous validator and JSON playground are free with request and rate limits, and anonymous results are transient. Ironfang Render credits do not pay for Ironfang Finance operations. - [Product overview](https://ironfang.com/finance): Invoice validation against EN 16931 and Peppol BIS Billing 3 (UBL), XRechnung 3.0.2 (UBL and CII) and ZUGFeRD / Factur-X (CII XML or hybrid PDF), JSON-to-UBL generation, readable PDFs and signed validation reports. - [Documentation](https://ironfang.com/docs/finance): The reference for the API at https://api.ironfang.com/finance. - [OpenAPI specification](https://api.ironfang.com/finance/openapi.yaml): The machine-readable contract, version 1.4.0. Also served as JSON at the same path with a .json extension. - [OpenAPI specification, V2: XRechnung, and the family-aware validation contract](https://api.ironfang.com/finance/v2/openapi.yaml): A further published contract for this product. Also served as JSON at the same path with a .json extension. - [Authentication](https://ironfang.com/docs/finance#api): A platform API key sent as a bearer token. Scopes begin finance: (finance:einvoices:rulesets:read, finance:einvoices:read, finance:einvoices:write). - [Errors](https://ironfang.com/problems): RFC 9457 problems; each stable code has a page saying what it means and whether to retry. - [MCP tools](https://ironfang.com/docs/mcp): Reference tools only, 3 tools named finance.*. Reference only: what a validation rule means and how to fix it, and which rulesets the validator runs. Validating and generating documents, results and jobs are REST-only; the Ironfang Finance API takes a platform API key and has no OAuth delegation yet. - [Validation rule reference](https://ironfang.com/docs/finance/rules): What each explained EN 16931 and Peppol BIS Billing 3 rule means, why it fails and how to fix the invoice, with failing and corrected documents. - [Validation rule reference as Markdown](https://ironfang.com/docs/finance/rules.md): The same index without page chrome; every rule page also answers with .md appended. - [Free Peppol invoice validator](https://ironfang.com/tools/peppol-validator): Validate a UBL invoice or credit note in the browser, anonymously, with no account and no key. - [Free XML invoice viewer](https://ironfang.com/tools/invoice-viewer): Open a UBL invoice or credit note as a readable document and download it as a PDF, anonymously; UBL to PDF at /tools/ubl-to-pdf, guide at /docs/finance/invoice-viewer. - [JSON to UBL generation](https://ironfang.com/docs/finance/generation): The generation schema, examples and quickstarts in curl, TypeScript, Python and Go. - [Signed validation reports](https://ironfang.com/docs/finance/reports): Issuing a signed report and verifying one offline. - [Runtime rulesets](https://api.ironfang.com/finance/v1/einvoices/rulesets): Immutable ruleset identities, specification releases and observed runtime versions, as JSON, with no key. - [Postman collection](https://ironfang.com/finance/postman.collection.json): Generated from the OpenAPI contract; supply credentials privately. - [Postman collection (V2)](https://ironfang.com/finance/postman-v2.collection.json): Generated from the V2 contract: Peppol BIS Billing 3, XRechnung and ZUGFeRD / Factur-X, XML or PDF; its Getting started folder needs no key. ## Ironfang Rig Use it when: You are testing an application that sends email, receives webhooks or calls third-party HTTP APIs, and need real addresses that exist only for the run. Ironfang Rig records what reached the addresses it allocated; it does not run tests. Free tier: Included with an Ironfang account in the initial release: no separate plan and no charge for runs, resources or events, within the documented limits (runs up to 24 hours; 32 resources and 64 expectations per suite; 500 messages, 1,000 callbacks and 5,000 mock calls per run). Pricing will be published before anything is charged. - [Product overview](https://ironfang.com/rig): Disposable external environments for integration tests: temporary inboxes, public callback URLs, mock HTTP endpoints and connector routes to a local port, allocated per run. - [Documentation](https://ironfang.com/rig/docs): The reference for the API at https://api.ironfang.com/rig. - [OpenAPI specification](https://api.ironfang.com/rig/openapi.yaml): The machine-readable contract, version 0.1.0. Also served as JSON at the same path with a .json extension. - [Authentication](https://ironfang.com/rig/docs#api-keys): A platform API key sent as a bearer token. Scopes begin rig: (rig:read, rig:write, rig:run, rig:connector). - [Errors](https://ironfang.com/rig/docs#errors): One JSON error body with a stable code, a message, a documentation link and the request id. - [MCP tools](https://ironfang.com/docs/mcp): Available, 19 tools named rig.*. Projects and suites, runs and their resources, the timeline and waits, replay, deterministic faults, the local connector bootstrap, evidence manifests and signed receipts. - [GitHub Actions and clients](https://github.com/ironfang-ltd/rig-action): The start and finish actions, and checksummed releases of the ironfang rig command-line client and connector for Linux, macOS and Windows. ## Ironfang Analytics Use it when: You need to see what a visitor actually did on your website, investigate a failed journey or check a suspicious application, masking as much of what they typed as your site needs. Ironfang Analytics never records card numbers, card, CVV, password or one-time-code fields, visitors who opted out or areas the site blocks; it asks for consent first only where the site switches that on, and does not decide whether a visit was fraudulent. Free tier: 1,000 recordings a month and 2 GiB of storage, kept 28 days; no card. - [Product overview](https://ironfang.com/analytics): Session replay for websites: records visits from the first page unless the visitor opts out, masks card numbers in the browser, and keeps each recording with the visitor's IP address, browser and page details for 28 days. - [Documentation](https://ironfang.com/analytics/docs): The reference for the API at https://api.ironfang.com/analytics. - [OpenAPI specification](https://api.ironfang.com/analytics/openapi.yaml): The machine-readable contract, version 0.1.0. Also served as JSON at the same path with a .json extension. - [Authentication](https://ironfang.com/analytics/docs#api-keys): A platform API key sent as a bearer token. Scopes begin analytics: (analytics:*, analytics:sites:read, analytics:sites:write, analytics:sessions:read, analytics:sessions:delete). - [Errors](https://ironfang.com/analytics/docs#errors): One JSON error body with a stable code, a message, a documentation link and the request id. - [MCP tools](https://ironfang.com/docs/mcp): Not available. Not yet available over MCP. Sites, recordings, playback and deletion are in the portal and the REST API. - [Install snippet, opt-out and consent](https://ironfang.com/analytics/docs#install): One script tag pinned by Subresource Integrity, the call that opts a visitor out, and consent-first recording for sites that need it. ## MCP - [MCP server reference](https://ironfang.com/docs/mcp): Endpoint https://mcp.ironfang.com/mcp (POST, streamable HTTP, protocol revisions 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26). OAuth 2.1 with PKCE against https://id.ironfang.com; API keys are refused. Registry name com.ironfang/ironfang. Ironfang Render: available; Ironfang Audit: available; Ironfang Finance: reference tools only; Ironfang Rig: available; Ironfang Analytics: not available. - [MCP server reference as Markdown](https://ironfang.com/docs/mcp.md): The same reference without page chrome, generated from the same data. - [MCP capability catalogue](https://ironfang.com/.well-known/ironfang-mcp.json): Every tool (49) with its input schema, required scopes, read-only, destructive, idempotent and open-world hints, credit cost and task support, plus resources and authentication. JSON, no token needed, generated from the server's own definitions. An Ironfang document, not a standard. - [MCP overview](https://ironfang.com/mcp): What connecting an assistant looks like, which products it reaches and what it costs. Start with ironfang.connection.get, which returns the organisation, scopes, products and credit budgets. Typical first tools: render.screenshot.create, audit.finding.list, finance.rule.get, rig.run.create. 4 Ironfang Render creation tools can run as MCP Tasks; every tool that spends credits says so in its description. ## Machine-readable - [APIs.json](https://ironfang.com/apis.json): The index of Ironfang's public APIs: contracts, documentation, pricing, rate limits, sign-up, support and status, in APIs.json 0.23. - [API catalogue](https://ironfang.com/.well-known/api-catalog): The same APIs as an RFC 9727 linkset. - [API onboarding](https://ironfang.com/.well-known/api-onboarding): How to get an API key: sign up, mint a key in the portal, send it as a bearer token. Per-product versions sit under /render, /audit, /finance, /rig, /analytics. - [API governance ruleset](https://ironfang.com/api/governance/spectral.yaml): The Spectral rules the published contracts pass in CI. - [Sitemap](https://ironfang.com/sitemap.xml): Every indexable page; articles have their own at /sitemap-articles.xml. ## Articles - [Articles](https://ironfang.com/articles): Technical articles from Ironfang. - [Articles feed](https://ironfang.com/articles/feed.xml): RSS. ## Guides - [Generate Open Graph images from reusable templates](https://ironfang.com/render/guides/open-graph-images): Store one template, create a signed URL for each page, and update the design centrally without replacing those URLs. - [HTML invoice template with a working PDF example](https://ironfang.com/render/guides/invoice-pdfs): Download a complete HTML invoice template and the PDF it renders to. Follow the request, the four-page example and the print CSS fixes for clipping, backgrounds and page breaks. - [Convert HTML to PDF in Python](https://ironfang.com/render/guides/html-to-pdf-python): Convert HTML to PDF in Python with the Ironfang Render API. Run the complete script, check the response before saving it, and handle API errors cleanly. - [Screenshots in GitHub Actions](https://ironfang.com/render/guides/screenshots-in-github-actions): Capture deployment previews during pull request workflows and upload them as build artefacts for review. - [Screenshot a page behind a login](https://ironfang.com/render/guides/authenticated-pages): Capture authenticated pages by supplying headers, cookies or an Authorization token before browser navigation. - [Capture screenshots without ads or cookie banners](https://ironfang.com/render/guides/clean-screenshots): Block ad and tracker requests, hide consent banners without recording consent, and remove additional page elements by CSS selector. - [Generate verified, branded QR codes](https://ironfang.com/render/guides/qr-codes): Generate styled QR codes with optional logos. Ironfang Render decodes every result before delivery and returns an error if it cannot be scanned. - [Dark mode QR codes and scanner compatibility](https://ironfang.com/render/guides/dark-mode-qr-codes): Compare standard and inverted QR codes for dark designs, including scanner compatibility and Ironfang Render verification behaviour. - [Website screenshots in Python](https://ironfang.com/render/guides/quickstart-python): Take a website screenshot from Python with one HTTPS request. Includes working code, binary response handling and API error handling. - [Website screenshots in Node.js](https://ironfang.com/render/guides/quickstart-node): Take a website screenshot from Node.js with one HTTPS request. Includes working code, binary response handling and API error handling. - [Website screenshots in PHP](https://ironfang.com/render/guides/quickstart-php): Take a website screenshot from PHP with one HTTPS request. Includes working code, binary response handling and API error handling. - [Website screenshots in Go](https://ironfang.com/render/guides/quickstart-go): Take a website screenshot from Go with one HTTPS request. Includes working code, binary response handling and API error handling. ## Free tools - [Favicon & app icon generator](https://ironfang.com/tools/favicon-generator): One image in, an icon package out: favicon, touch and PWA icons, manifest. - [Full page screenshot](https://ironfang.com/tools/full-page-screenshot): Capture any website as a full page image in PNG, JPEG or WebP, at desktop, tablet or mobile size. - [HTML to image](https://ironfang.com/tools/html-to-image): Render HTML to a PNG, JPG or WebP image at the size you choose, fitted to the content or fixed. - [HTML to PDF converter](https://ironfang.com/tools/html-to-pdf): Turn pasted HTML or a public page into a PDF, with paper size, margins and backgrounds. - [Image converter](https://ironfang.com/tools/image-converter): Convert WebP, PNG or JPEG images to PNG or JPG, with optional resizing. Metadata is stripped. - [XML invoice viewer](https://ironfang.com/tools/invoice-viewer): Open a UBL or Peppol invoice or credit note as a readable document, then download it as a PDF. - [Peppol invoice validator](https://ironfang.com/tools/peppol-validator): Check a UBL invoice or credit note against EN 16931 and Peppol BIS Billing 3 rules, no account needed. - [UBL to PDF converter](https://ironfang.com/tools/ubl-to-pdf): Turn a UBL or Peppol invoice XML into a readable, paginated PDF, keeping the original XML. - [XRechnung validator](https://ironfang.com/tools/xrechnung-validator): Check an XRechnung invoice or credit note in UBL or CII against the official XRechnung 3.0.2 rules. - [XRechnung viewer](https://ironfang.com/tools/xrechnung-viewer): Open an XRechnung in UBL or CII and read it as a document, with every value traced to its XML line. - [ZUGFeRD / Factur-X validator](https://ironfang.com/tools/zugferd-validator): Check a ZUGFeRD or Factur-X PDF or XML: the PDF/A, the embedded invoice and its metadata, and the ZUGFeRD 2.5.2 profile rules. - [QR code generator](https://ironfang.com/tools/qr-code-generator): Generate a QR code as PNG. Every code is decoded to verify it before delivery. - [QR code decoder](https://ironfang.com/tools/qr-code-verifier): Decode a QR image or photo and see exactly what it contains, without opening the link. - [UUID generator & decoder](https://ironfang.com/tools/uuid-generator): Generate UUID v4 and time-ordered v7, or decode any UUID to see its version and embedded time. ## Company - [About Ironfang](https://ironfang.com/company): Who builds it and where it runs. - [Contact](https://ironfang.com/contact): Support, technical questions, billing. - [Status](https://status.ironfang.com) ## Optional - [Terms of Service](https://ironfang.com/legal/terms) - [Privacy Policy](https://ironfang.com/legal/privacy) - [Acceptable Use Policy](https://ironfang.com/legal/acceptable-use) - [Refunds and Cancellation](https://ironfang.com/legal/refunds) - [Licences and acknowledgements](https://ironfang.com/legal/open-source)