Providers

Providers

Web archives and threat intel indexes behind one record shape. Pick a source to see its endpoint and its limits and the traps.

Every source answers the same call, discover(domain, options), and returns the same record. What differs is where it gets its URLs, whether it knows when it saw them, and how much it's willing to hand over in one go.

The archives with a CDX index (Wayback, Arquivo.pt, Vefsafn, Common Crawl) know capture dates, so from and to work on them. The security indexes (AlienVault OTX, URLScan, VirusTotal) know URLs people and scanners ran into, sometimes ones no archive bothered to keep.

providers()7 sources · table order
FormatWhat it knows
AlienVault OTXJSON pagesThreat intel URL lists. Keyless, but the public endpoint gets grumpy under load.no key
Arquivo.ptCDX NDJSONThe Portuguese web archive. CDX with dates, and a hard cap per request.no key
Common CrawlCDX textCrawl indexes, one per year for the last five. A broken index skips, the rest answer.no key
URLScanJSON search pagesPages people scanned. Answers without a key at small volumes, more with one.key optional
VefsafnCDX NDJSONThe Icelandic web archive. Ignores limit and sends everything, the collector stops it.no key
VirusTotalJSON v3 pagesURLs VirusTotal has seen for the domain. No key, no answer.key required
Wayback MachineCDX textThe Internet Archive's CDX index. One streamed answer with dates, subdomains included.no key
6 answer with nothing configured / no networkcreate("<key>") loads one module

Which one first?

For breadth on an old domain, Wayback. For what's been poked at recently, URLScan and AlienVault OTX. Not sure? provider: "all" asks everyone and shows who answered, which beats guessing.