Providers

URLScan

The search API of urlscan.io. Works without a key at small volumes. Cursor pages up to 50 and more room with URLSCAN_API_KEY.
IDurlscan04 / 7urlscan.io
Source

URLScan

  • provider: "urlscan"
  • urlscan.io

Pages people scanned. Answers without a key at small volumes, more with one.

Format
JSON search pages
Paging
search_after cursor, at most 50 pages
Dates
none, from and to skip nothing
Key
optional

Access

Loadawait create("urlscan")
CLIurls discover example.com -p urlscan
KeyURLSCAN_API_KEY, optional, or apiKey in create()
Endpointhttps://urlscan.io/api/v1/search/

What it knows

Pages someone submitted to urlscan.io for a scan. People scan what they're suspicious of right now, so it leans recent. No dates come back.

How it asks

GET /api/v1/search/?q=domain:{domain}&size=10000, then the next page through the search_after cursor while has_more is true, 50 pages at most. With a key it goes in the API-Key header.

Traps

  • Without a key the public quota is small. Set URLSCAN_API_KEY or pass apiKey to create() for more.
  • The search can match scans of pages on other hosts. The default host scope drops the strangers, and noScope: true keeps them if that's what you want.
  • A 50-page walk stops with truncated when urlscan still advertises more.