API_KEY
urlscanio_api_key
Developer setup
No fields declared in this snapshot.
User connection
- API Keygeneric_api_key · stringRequired
URLSCANIO
Submit and retrieve website scans, search urlscan.io data, and manage urlscan Pro resources for threat intelligence and security investigations.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
51
Action summaries
Display-only definitions
0
Trigger types
Not installed instances
1
Auth modes
Field names, never values
No
Execution
No runtime adapter
Authentication map
API_KEY
No fields declared in this snapshot.
Capability index
Showing 1–30 of 51 actions
URLSCANIO_CLOSE_INCIDENT
Stop ongoing scans for an active urlscan Pro incident and transition it to the closed state. Closing does not delete the incident or its history, and the incident can later be restarted.
Untrusted display-only summary
URLSCANIO_COPY_INCIDENT
Create a separate urlscan Pro incident from an existing incident's configuration. This create operation can consume incident capacity and does not copy the source incident's stored state history; use the distinct fork operation when history must be preserved. The provider does not document whether the copied incident…
Untrusted display-only summary
URLSCANIO_CREATE_CHANNEL
Create a Pro notification channel. This operation configures external effects: active webhook channels send requests to the supplied secret URL, and active email channels send messages to the supplied recipients. Confirm the destination and activation settings before calling.
Untrusted display-only summary
URLSCANIO_CREATE_INCIDENT
Create a Pro incident that persistently monitors an observable. This high-impact operation starts ongoing external scans and can send alerts through every supplied notification channel; confirm the observable, visibility, channels, cadence, and expiration settings before calling. The operation is contract-only because…
Untrusted display-only summary
URLSCANIO_CREATE_LIVE_SCAN_BLOCKING
Run a temporary Live Scan synchronously and return only after the provider finishes the scan. This requires the separate Live Scanning product.
Untrusted display-only summary
URLSCANIO_CREATE_LIVE_SCAN_TASK
Start a non-blocking temporary Live Scan on a selected scanner and return its UUID immediately without waiting for completion. This external scan side effect requires the separate urlscan.io Live Scanning entitlement; a generic Pro plan may not include it.
Untrusted display-only summary
URLSCANIO_CREATE_SAVED_SEARCH
Create a reusable scans or hostnames search definition. This operation creates a persistent saved search and requires urlscan Pro; the hostnames datasource may require an additional product entitlement.
Untrusted display-only summary
URLSCANIO_CREATE_SUBSCRIPTION
Create a persistent scheduled or live alert subscription for saved searches. This Pro-only operation has external notification side effects: an active subscription can send email, invoke configured channels or webhooks, and create incidents. Confirm all recipients and channel or incident settings before calling.
Untrusted display-only summary
URLSCANIO_DELETE_RESULT
Permanently delete a scan owned by the connected user or team. This destructive operation cannot be reversed and requires urlscan Pro.
Untrusted display-only summary
URLSCANIO_DELETE_SAVED_SEARCH
Permanently delete a saved search by ID. This destructive operation cannot be undone and requires urlscan Pro saved-search access plus ownership or team write permission. Use it only for a saved search created or explicitly selected by the current workflow.
Untrusted display-only summary
URLSCANIO_DELETE_SUBSCRIPTION
Permanently delete an alert subscription by ID. This destructive operation cannot be undone and requires urlscan Pro subscriptions access plus ownership or team write permission. Use it only for a subscription created or explicitly selected by the current workflow.
Untrusted display-only summary
URLSCANIO_DOWNLOAD_FILE
Retrieve a captured binary file by its SHA-256 hash as a password-encrypted ZIP archive. This operation requires urlscan Pro access.
Untrusted display-only summary
URLSCANIO_FORK_INCIDENT
Create a new Pro incident by copying an existing incident's configuration and complete stored state history. This creates a separate persistent incident; history volume and whether monitoring starts immediately are not documented.
Untrusted display-only summary
URLSCANIO_GET_ACCOUNT_CAPABILITIES
Get non-sensitive plan, product, feature, visibility, submission, and limit information for the connected urlscan.io API key.
Untrusted display-only summary
URLSCANIO_GET_BRAND_SUMMARY
Return detectable brands with detected-page totals and latest hits. This operation requires urlscan Pro access and uses the official contract only; the provider does not document its response fields.
Untrusted display-only summary
URLSCANIO_GET_CHANNEL
Get one urlscan Pro notification channel by ID while preserving provider-specific metadata and removing webhook destinations or credentials.
Untrusted display-only summary
URLSCANIO_GET_DATA_DUMP_LINK
Generate a temporary download URL for a path returned by LIST_DATA_DUMPS. Data Dumps require an Enterprise or Ultimate urlscan.io plan.
Untrusted display-only summary
URLSCANIO_GET_DOM
Return the plain-text DOM snapshot captured for a completed scan.
Untrusted display-only summary
URLSCANIO_GET_HOSTNAME_HISTORY
Return one page of historical Pro Hostnames observations for a hostname.
Untrusted display-only summary
URLSCANIO_GET_INCIDENT
Get one incident's configuration, source, runtime state, and timestamps.
Untrusted display-only summary
URLSCANIO_GET_INCIDENT_STATES
Retrieve the stored state history for an incident.
Untrusted display-only summary
URLSCANIO_GET_LIVE_SCAN_RESOURCE
Retrieve one temporary result, DOM, screenshot, captured response, or download from the separate urlscan.io Live Scanning product. JSON and text are returned inline; binary content is offloaded as a downloadable file.
Untrusted display-only summary
URLSCANIO_GET_PHISHFEED
Retrieve the deprecated urlscan Pro phishing feed in JSON, CSV, or TSV. Prefer SEARCH_SCANS for new workflows, as recommended by urlscan.io.
Untrusted display-only summary
URLSCANIO_GET_QUOTAS
Get current products, features, query capabilities, and per-action minute, hour, and day quota usage.
Untrusted display-only summary
URLSCANIO_GET_RESPONSE_CONTENT
Return textual content captured in a scan response, addressed by its SHA-256 hash.
Untrusted display-only summary
URLSCANIO_GET_RESULT
Retrieve the complete metadata and captured request data for a completed scan UUID.
Untrusted display-only summary
URLSCANIO_GET_SAVED_SEARCH_RESULTS
Run a urlscan Pro saved search and return its current Search API results. The provider redirect is followed automatically; this operation does not expose pagination controls.
Untrusted display-only summary
URLSCANIO_GET_SCREENSHOT
Retrieve a completed urlscan.io scan screenshot as a downloadable PNG file reference.
Untrusted display-only summary
URLSCANIO_GET_SIMILAR_RESULTS
Find one page of scan results structurally similar to a specified scan. Requires urlscan Pro access.
Untrusted display-only summary
URLSCANIO_GET_SUBSCRIPTION_RESULTS
Resolve a urlscan Pro alert subscription and datasource to its current Search API results. The provider redirect is followed automatically; this operation does not expose pagination controls.
Untrusted display-only summary
Provenance
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.
Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.