API_KEY
urlscanio_api_key
Developer setup
No fields declared in this snapshot.
User connection
- API Keygeneric_api_key · stringRequired
URLSCANIO
Submit and retrieve website scans, search urlscan.io data, and manage urlscan Pro resources for threat intelligence and security investigations.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
51
Action summaries
Display-only definitions
0
Trigger types
Not installed instances
1
Auth modes
Field names, never values
No
Execution
No runtime adapter
Authentication map
API_KEY
No fields declared in this snapshot.
Capability index
Showing 31–51 of 51 actions
URLSCANIO_LIST_AVAILABLE_BRANDS
List brand identifiers and metadata tracked by urlscan.io brand and phishing detection. Requires urlscan Pro brand/phishing access; the exact product and minimum plan are not documented.
Untrusted display-only summary
URLSCANIO_LIST_AVAILABLE_COUNTRIES
List scanner country codes currently accepted by the Scan API.
Untrusted display-only summary
URLSCANIO_LIST_CHANNELS
List email and webhook notification channels for the current user without returning webhook URLs or embedded credentials. This operation requires urlscan Pro channels access.
Untrusted display-only summary
URLSCANIO_LIST_DATA_DUMPS
List available urlscan.io data-dump files for a time window, file type, and date. Requires an Enterprise or Ultimate plan; availability can vary by window and file type.
Untrusted display-only summary
URLSCANIO_LIST_LIVE_SCANNERS
List Live Scanning nodes available to the connected account and their current metadata. This requires the separate urlscan.io Live Scanning product; a generic urlscan Pro plan may not include it.
Untrusted display-only summary
URLSCANIO_LIST_SAVED_SEARCHES
List saved searches owned by or shared with the current user. This operation requires urlscan Pro saved-search access.
Untrusted display-only summary
URLSCANIO_LIST_SUBSCRIPTIONS
List alert subscriptions configured for the current user. This operation requires urlscan Pro subscriptions access.
Untrusted display-only summary
URLSCANIO_LIST_USER_AGENTS
List grouped browser user-agent strings available for scan submission.
Untrusted display-only summary
URLSCANIO_LIST_WATCHABLE_ATTRIBUTES
List attribute values accepted when configuring incident change monitoring. Requires urlscan Pro Incidents capability; the exact minimum plan or product is not documented.
Untrusted display-only summary
URLSCANIO_LOOKUP_MALICIOUS_OBSERVABLE
Look up malicious-scan occurrence counts and first/last seen timestamps for an IP, hostname, domain, or exact URL. Requires urlscan Pro malicious-observable access.
Untrusted display-only summary
URLSCANIO_PURGE_LIVE_SCAN_RESULT
Permanently delete a temporary result from the separate urlscan.io Live Scanning product before its normal expiration. This destructive operation cannot be undone; only use it to clean up a temporary result created by the current workflow.
Untrusted display-only summary
URLSCANIO_RESET_RESULT_VISIBILITY
Remove an owned scan's visibility override and restore the visibility originally assigned at submission. This resets an override; it does not delete the scan. Requires urlscan Pro.
Untrusted display-only summary
URLSCANIO_RESTART_INCIDENT
Restart a closed urlscan Pro incident and extend its expiry. This resumes ongoing external monitoring, begins recording new incident states, and can resume alerts through the incident's configured notification channels; confirm the incident should become active again before calling. This operation is contract-only bec…
Untrusted display-only summary
URLSCANIO_SEARCH_SCANS
Search urlscan.io data with Elasticsearch Query String syntax and return one controllable page of results.
Untrusted display-only summary
URLSCANIO_STORE_LIVE_SCAN_RESULT
Permanently store an existing temporary Live Scan result with the selected visibility. This updates the temporary result into a durable snapshot and requires the separate urlscan.io Live Scanning entitlement; a generic urlscan Pro plan may not include it.
Untrusted display-only summary
URLSCANIO_SUBMIT_SCAN
Submit a URL for asynchronous external scanning, creating persistent result state and consuming quota. Visibility defaults to public, and free accounts have no cleanup operation. Returns the scan UUID for result and asset retrieval.
Untrusted display-only summary
URLSCANIO_UPDATE_CHANNEL
Replace the complete configuration of an existing Pro notification channel. This operation can redirect external effects: active webhook channels send requests to the supplied secret URL, and active email channels send messages to the supplied recipients. Confirm the complete destination and activation settings before…
Untrusted display-only summary
URLSCANIO_UPDATE_INCIDENT
Replace an existing incident's monitoring configuration and runtime options. This Pro-only PUT requires observable, visibility, and the complete channel set, not only changed values. Updating it changes ongoing external scanning and can redirect or trigger future channel alerts; confirm the complete replacement config…
Untrusted display-only summary
URLSCANIO_UPDATE_RESULT_VISIBILITY
Change the visibility of a scan owned by the connected user or team. This operation requires a paid urlscan Pro entitlement and is contract-only, not live verified. Use DELETE_RESULT for permanent deletion.
Untrusted display-only summary
URLSCANIO_UPDATE_SAVED_SEARCH
Replace the complete definition and metadata of an existing saved search. This PUT operation requires urlscan Pro saved-search access and write permission; the hostnames datasource may require an additional entitlement.
Untrusted display-only summary
URLSCANIO_UPDATE_SUBSCRIPTION
Replace the complete configuration of an existing alert subscription. This Pro-only PUT requires every mandatory field, not only changed values. It has external notification side effects: activating the subscription or changing recipients, channels, webhooks, or incident settings can send notifications or create incid…
Untrusted display-only summary
Provenance
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.
Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.