All integrations
UR
Catalogue metadata onlysecurity & identity toolsv00000000_00

URLSCANIO

urlscan.io

Submit and retrieve website scans, search urlscan.io data, and manage urlscan Pro resources for threat intelligence and security investigations.

Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.

Pakkawork boundary

Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.

No Pakkawork execution adapter is enabled. Hosted account-authorisation availability is workspace-specific and checked separately in the dashboard.Check workspace connection options
Attributed source

51

Action summaries

Display-only definitions

0

Trigger types

Not installed instances

1

Auth modes

Field names, never values

No

Execution

No runtime adapter

Authentication map

What setup is declared?

Only field names, types, and required markers are shown. Secret values, default auth URLs, credential material, and inferred OAuth scopes are excluded.
API_KEY

API_KEY

urlscanio_api_key

Provider setup

Developer setup

No fields declared in this snapshot.

User connection

  • API Keygeneric_api_key · stringRequired

Capability index

Actions and trigger definitions

Static summaries are available. Live schemas remain disabled until PROVIDER_HUB_API_KEY is configured server-side.

Showing 1–30 of 51 actions

Close Incident

URLSCANIO_CLOSE_INCIDENT

Stop ongoing scans for an active urlscan Pro incident and transition it to the closed state. Closing does not delete the incident or its history, and the incident can later be restarted.

Untrusted display-only summary

Copy Incident

URLSCANIO_COPY_INCIDENT

Create a separate urlscan Pro incident from an existing incident's configuration. This create operation can consume incident capacity and does not copy the source incident's stored state history; use the distinct fork operation when history must be preserved. The provider does not document whether the copied incident…

Untrusted display-only summary

Create Notification Channel

URLSCANIO_CREATE_CHANNEL

Create a Pro notification channel. This operation configures external effects: active webhook channels send requests to the supplied secret URL, and active email channels send messages to the supplied recipients. Confirm the destination and activation settings before calling.

Untrusted display-only summary

Create Incident

URLSCANIO_CREATE_INCIDENT

Create a Pro incident that persistently monitors an observable. This high-impact operation starts ongoing external scans and can send alerts through every supplied notification channel; confirm the observable, visibility, channels, cadence, and expiration settings before calling. The operation is contract-only because…

Untrusted display-only summary

Run Blocking Live Scan

URLSCANIO_CREATE_LIVE_SCAN_BLOCKING

Run a temporary Live Scan synchronously and return only after the provider finishes the scan. This requires the separate Live Scanning product.

Untrusted display-only summary

Create Live Scan Task

URLSCANIO_CREATE_LIVE_SCAN_TASK

Start a non-blocking temporary Live Scan on a selected scanner and return its UUID immediately without waiting for completion. This external scan side effect requires the separate urlscan.io Live Scanning entitlement; a generic Pro plan may not include it.

Untrusted display-only summary

Create Saved Search

URLSCANIO_CREATE_SAVED_SEARCH

Create a reusable scans or hostnames search definition. This operation creates a persistent saved search and requires urlscan Pro; the hostnames datasource may require an additional product entitlement.

Untrusted display-only summary

Create Alert Subscription

URLSCANIO_CREATE_SUBSCRIPTION

Create a persistent scheduled or live alert subscription for saved searches. This Pro-only operation has external notification side effects: an active subscription can send email, invoke configured channels or webhooks, and create incidents. Confirm all recipients and channel or incident settings before calling.

Untrusted display-only summary

Delete Scan Result

URLSCANIO_DELETE_RESULT

Permanently delete a scan owned by the connected user or team. This destructive operation cannot be reversed and requires urlscan Pro.

Untrusted display-only summary

Delete Saved Search

URLSCANIO_DELETE_SAVED_SEARCH

Permanently delete a saved search by ID. This destructive operation cannot be undone and requires urlscan Pro saved-search access plus ownership or team write permission. Use it only for a saved search created or explicitly selected by the current workflow.

Untrusted display-only summary

Delete Alert Subscription

URLSCANIO_DELETE_SUBSCRIPTION

Permanently delete an alert subscription by ID. This destructive operation cannot be undone and requires urlscan Pro subscriptions access plus ownership or team write permission. Use it only for a subscription created or explicitly selected by the current workflow.

Untrusted display-only summary

Download Captured File

URLSCANIO_DOWNLOAD_FILE

Retrieve a captured binary file by its SHA-256 hash as a password-encrypted ZIP archive. This operation requires urlscan Pro access.

Untrusted display-only summary

Fork Incident

URLSCANIO_FORK_INCIDENT

Create a new Pro incident by copying an existing incident's configuration and complete stored state history. This creates a separate persistent incident; history volume and whether monitoring starts immediately are not documented.

Untrusted display-only summary

Get Account Capabilities

URLSCANIO_GET_ACCOUNT_CAPABILITIES

Get non-sensitive plan, product, feature, visibility, submission, and limit information for the connected urlscan.io API key.

Untrusted display-only summary

Get Brand Summary

URLSCANIO_GET_BRAND_SUMMARY

Return detectable brands with detected-page totals and latest hits. This operation requires urlscan Pro access and uses the official contract only; the provider does not document its response fields.

Untrusted display-only summary

Get Notification Channel

URLSCANIO_GET_CHANNEL

Get one urlscan Pro notification channel by ID while preserving provider-specific metadata and removing webhook destinations or credentials.

Untrusted display-only summary

Get Data Dump Download Link

URLSCANIO_GET_DATA_DUMP_LINK

Generate a temporary download URL for a path returned by LIST_DATA_DUMPS. Data Dumps require an Enterprise or Ultimate urlscan.io plan.

Untrusted display-only summary

Get Scan DOM

URLSCANIO_GET_DOM

Return the plain-text DOM snapshot captured for a completed scan.

Untrusted display-only summary

Get Hostname History

URLSCANIO_GET_HOSTNAME_HISTORY

Return one page of historical Pro Hostnames observations for a hostname.

Untrusted display-only summary

Get Incident

URLSCANIO_GET_INCIDENT

Get one incident's configuration, source, runtime state, and timestamps.

Untrusted display-only summary

Get Incident States

URLSCANIO_GET_INCIDENT_STATES

Retrieve the stored state history for an incident.

Untrusted display-only summary

Get Live Scan Resource

URLSCANIO_GET_LIVE_SCAN_RESOURCE

Retrieve one temporary result, DOM, screenshot, captured response, or download from the separate urlscan.io Live Scanning product. JSON and text are returned inline; binary content is offloaded as a downloadable file.

Untrusted display-only summary

Get Deprecated Phishing Feed

URLSCANIO_GET_PHISHFEED

Retrieve the deprecated urlscan Pro phishing feed in JSON, CSV, or TSV. Prefer SEARCH_SCANS for new workflows, as recommended by urlscan.io.

Untrusted display-only summary

Get API Quotas

URLSCANIO_GET_QUOTAS

Get current products, features, query capabilities, and per-action minute, hour, and day quota usage.

Untrusted display-only summary

Get Captured Response Content

URLSCANIO_GET_RESPONSE_CONTENT

Return textual content captured in a scan response, addressed by its SHA-256 hash.

Untrusted display-only summary

Get Scan Result

URLSCANIO_GET_RESULT

Retrieve the complete metadata and captured request data for a completed scan UUID.

Untrusted display-only summary

Get Saved Search Results

URLSCANIO_GET_SAVED_SEARCH_RESULTS

Run a urlscan Pro saved search and return its current Search API results. The provider redirect is followed automatically; this operation does not expose pagination controls.

Untrusted display-only summary

Get Scan Screenshot

URLSCANIO_GET_SCREENSHOT

Retrieve a completed urlscan.io scan screenshot as a downloadable PNG file reference.

Untrusted display-only summary

Get Similar Scan Results

URLSCANIO_GET_SIMILAR_RESULTS

Find one page of scan results structurally similar to a specified scan. Requires urlscan Pro access.

Untrusted display-only summary

Get Subscription Results

URLSCANIO_GET_SUBSCRIPTION_RESULTS

Resolve a urlscan Pro alert subscription and datasource to its current Search API results. The provider redirect is followed automatically; this operation does not expose pagination controls.

Untrusted display-only summary

Provenance

Versioned facts, explicit trust.

The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.

Repository
https://github.com/provider-directoryHQ/provider-directory
Commit
85e33f6a81dfe987f6fc3637d48d45052cea8ca5
Generated
2026-09-12
Trust policy
untrusted_display_only

Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.