urlscan.io logo

urlscan.io

Submit and retrieve website scans, search urlscan.io data, and manage urlscan Pro resources for threat intelligence and security investigations.

50 actions Integration catalog
Request access
Connect urlscan.io once you're in Boring.
01 · WHAT THE AGENT CAN DO

Actions

Every capability is a discrete, logged action the agent calls by name — scoped to what you authorize and recorded in the run trace.

Close IncidentURLSCANIO_CLOSE_INCIDENT
Stop ongoing scans for an active urlscan Pro incident and transition it to the closed state. Closing does not delete the incident or its history, and the incident can later be restarted.
Copy IncidentURLSCANIO_COPY_INCIDENT
Create a separate urlscan Pro incident from an existing incident's configuration. This create operation can consume incident capacity and does not copy the source incident's stored state history; use the distinct fork operation when history must be preserved. The provider does not document whether the copied incident immediately activates ongoing scans or alerts.
Create Notification ChannelURLSCANIO_CREATE_CHANNEL
Create a Pro notification channel. This operation configures external effects: active webhook channels send requests to the supplied secret URL, and active email channels send messages to the supplied recipients. Confirm the destination and activation settings before calling.
Create IncidentURLSCANIO_CREATE_INCIDENT
Create a Pro incident that persistently monitors an observable. This high-impact operation starts ongoing external scans and can send alerts through every supplied notification channel; confirm the observable, visibility, channels, cadence, and expiration settings before calling. The operation is contract-only because the connected build account lacks the urlscan Pro Incidents entitlement.
Run Blocking Live ScanURLSCANIO_CREATE_LIVE_SCAN_BLOCKING
Run a temporary Live Scan synchronously and return only after the provider finishes the scan. This requires the separate Live Scanning product.
Create Live Scan TaskURLSCANIO_CREATE_LIVE_SCAN_TASK
Start a non-blocking temporary Live Scan on a selected scanner and return its UUID immediately without waiting for completion. This external scan side effect requires the separate urlscan.io Live Scanning entitlement; a generic Pro plan may not include it.
Create Saved SearchURLSCANIO_CREATE_SAVED_SEARCH
Create a reusable scans or hostnames search definition. This operation creates a persistent saved search and requires urlscan Pro; the hostnames datasource may require an additional product entitlement.
Create Alert SubscriptionURLSCANIO_CREATE_SUBSCRIPTION
Create a persistent scheduled or live alert subscription for saved searches. This Pro-only operation has external notification side effects: an active subscription can send email, invoke configured channels or webhooks, and create incidents. Confirm all recipients and channel or incident settings before calling.
Delete Scan ResultURLSCANIO_DELETE_RESULT
Permanently delete a scan owned by the connected user or team. This destructive operation cannot be reversed and requires urlscan Pro.
Delete Saved SearchURLSCANIO_DELETE_SAVED_SEARCH
Permanently delete a saved search by ID. This destructive operation cannot be undone and requires urlscan Pro saved-search access plus ownership or team write permission. Use it only for a saved search created or explicitly selected by the current workflow.
Delete Alert SubscriptionURLSCANIO_DELETE_SUBSCRIPTION
Permanently delete an alert subscription by ID. This destructive operation cannot be undone and requires urlscan Pro subscriptions access plus ownership or team write permission. Use it only for a subscription created or explicitly selected by the current workflow.
Download Captured FileURLSCANIO_DOWNLOAD_FILE
Retrieve a captured binary file by its SHA-256 hash as a password-encrypted ZIP archive. This operation requires urlscan Pro access.
Fork IncidentURLSCANIO_FORK_INCIDENT
Create a new Pro incident by copying an existing incident's configuration and complete stored state history. This creates a separate persistent incident; history volume and whether monitoring starts immediately are not documented.
Get Account CapabilitiesURLSCANIO_GET_ACCOUNT_CAPABILITIES
Get non-sensitive plan, product, feature, visibility, submission, and limit information for the connected urlscan.io API key.
Get Brand SummaryURLSCANIO_GET_BRAND_SUMMARY
Return detectable brands with detected-page totals and latest hits. This operation requires urlscan Pro access and uses the official contract only; the provider does not document its response fields.
Get Notification ChannelURLSCANIO_GET_CHANNEL
Get one urlscan Pro notification channel by ID while preserving provider-specific metadata and removing webhook destinations or credentials.
Get Data Dump Download LinkURLSCANIO_GET_DATA_DUMP_LINK
Generate a temporary download URL for a path returned by LIST_DATA_DUMPS. Data Dumps require an Enterprise or Ultimate urlscan.io plan.
Get Scan DOMURLSCANIO_GET_DOM
Return the plain-text DOM snapshot captured for a completed scan.
Get Hostname HistoryURLSCANIO_GET_HOSTNAME_HISTORY
Return one page of historical Pro Hostnames observations for a hostname.
Get IncidentURLSCANIO_GET_INCIDENT
Get one incident's configuration, source, runtime state, and timestamps.
Get Incident StatesURLSCANIO_GET_INCIDENT_STATES
Retrieve the stored state history for an incident.
Get Live Scan ResourceURLSCANIO_GET_LIVE_SCAN_RESOURCE
Retrieve one temporary result, DOM, screenshot, captured response, or download from the separate urlscan.io Live Scanning product. JSON and text are returned inline; binary content is offloaded as a downloadable file.
Get Deprecated Phishing FeedURLSCANIO_GET_PHISHFEED
Retrieve the deprecated urlscan Pro phishing feed in JSON, CSV, or TSV. Prefer SEARCH_SCANS for new workflows, as recommended by urlscan.io.
Get API QuotasURLSCANIO_GET_QUOTAS
Get current products, features, query capabilities, and per-action minute, hour, and day quota usage.
Get Captured Response ContentURLSCANIO_GET_RESPONSE_CONTENT
Return textual content captured in a scan response, addressed by its SHA-256 hash.
Get Scan ResultURLSCANIO_GET_RESULT
Retrieve the complete metadata and captured request data for a completed scan UUID.
Get Saved Search ResultsURLSCANIO_GET_SAVED_SEARCH_RESULTS
Run a urlscan Pro saved search and return its current Search API results. The provider redirect is followed automatically; this operation does not expose pagination controls.
Get Scan ScreenshotURLSCANIO_GET_SCREENSHOT
Retrieve a completed urlscan.io scan screenshot as a downloadable PNG file reference.
Get Similar Scan ResultsURLSCANIO_GET_SIMILAR_RESULTS
Find one page of scan results structurally similar to a specified scan. Requires urlscan Pro access.
Get Subscription ResultsURLSCANIO_GET_SUBSCRIPTION_RESULTS
Resolve a urlscan Pro alert subscription and datasource to its current Search API results. The provider redirect is followed automatically; this operation does not expose pagination controls.
Get Available BrandsURLSCANIO_LIST_AVAILABLE_BRANDS
List brand identifiers and metadata tracked by urlscan.io brand and phishing detection. Requires urlscan Pro brand/phishing access; the exact product and minimum plan are not documented.
Get Available Scan CountriesURLSCANIO_LIST_AVAILABLE_COUNTRIES
List scanner country codes currently accepted by the Scan API.
List Notification ChannelsURLSCANIO_LIST_CHANNELS
List email and webhook notification channels for the current user without returning webhook URLs or embedded credentials. This operation requires urlscan Pro channels access.
List Data DumpsURLSCANIO_LIST_DATA_DUMPS
List available urlscan.io data-dump files for a time window, file type, and date. Requires an Enterprise or Ultimate plan; availability can vary by window and file type.
List Live ScannersURLSCANIO_LIST_LIVE_SCANNERS
List Live Scanning nodes available to the connected account and their current metadata. This requires the separate urlscan.io Live Scanning product; a generic urlscan Pro plan may not include it.
List Saved SearchesURLSCANIO_LIST_SAVED_SEARCHES
List saved searches owned by or shared with the current user. This operation requires urlscan Pro saved-search access.
List Alert SubscriptionsURLSCANIO_LIST_SUBSCRIPTIONS
List alert subscriptions configured for the current user. This operation requires urlscan Pro subscriptions access.
Get Scan User AgentsURLSCANIO_LIST_USER_AGENTS
List grouped browser user-agent strings available for scan submission.
Get Watchable Incident AttributesURLSCANIO_LIST_WATCHABLE_ATTRIBUTES
List attribute values accepted when configuring incident change monitoring. Requires urlscan Pro Incidents capability; the exact minimum plan or product is not documented.
Lookup Malicious ObservableURLSCANIO_LOOKUP_MALICIOUS_OBSERVABLE
Look up malicious-scan occurrence counts and first/last seen timestamps for an IP, hostname, domain, or exact URL. Requires urlscan Pro malicious-observable access.
Purge Live Scan ResultURLSCANIO_PURGE_LIVE_SCAN_RESULT
Permanently delete a temporary result from the separate urlscan.io Live Scanning product before its normal expiration. This destructive operation cannot be undone; only use it to clean up a temporary result created by the current workflow.
Reset Scan VisibilityURLSCANIO_RESET_RESULT_VISIBILITY
Remove an owned scan's visibility override and restore the visibility originally assigned at submission. This resets an override; it does not delete the scan. Requires urlscan Pro.
Restart IncidentURLSCANIO_RESTART_INCIDENT
Restart a closed urlscan Pro incident and extend its expiry. This resumes ongoing external monitoring, begins recording new incident states, and can resume alerts through the incident's configured notification channels; confirm the incident should become active again before calling. This operation is contract-only because the connected build account lacks Pro Incidents access.
Search ScansURLSCANIO_SEARCH_SCANS
Search urlscan.io data with Elasticsearch Query String syntax and return one controllable page of results.
Store Live Scan ResultURLSCANIO_STORE_LIVE_SCAN_RESULT
Permanently store an existing temporary Live Scan result with the selected visibility. This updates the temporary result into a durable snapshot and requires the separate urlscan.io Live Scanning entitlement; a generic urlscan Pro plan may not include it.
Submit ScanURLSCANIO_SUBMIT_SCAN
Submit a URL for asynchronous external scanning, creating persistent result state and consuming quota. Visibility defaults to public, and free accounts have no cleanup operation. Returns the scan UUID for result and asset retrieval.
Update Notification ChannelURLSCANIO_UPDATE_CHANNEL
Replace the complete configuration of an existing Pro notification channel. This operation can redirect external effects: active webhook channels send requests to the supplied secret URL, and active email channels send messages to the supplied recipients. Confirm the complete destination and activation settings before calling.
Update IncidentURLSCANIO_UPDATE_INCIDENT
Replace an existing incident's monitoring configuration and runtime options. This Pro-only PUT requires observable, visibility, and the complete channel set, not only changed values. Updating it changes ongoing external scanning and can redirect or trigger future channel alerts; confirm the complete replacement configuration before calling.
Update Scan VisibilityURLSCANIO_UPDATE_RESULT_VISIBILITY
Change the visibility of a scan owned by the connected user or team. This operation requires a paid urlscan Pro entitlement and is contract-only, not live verified. Use DELETE_RESULT for permanent deletion.
Update Saved SearchURLSCANIO_UPDATE_SAVED_SEARCH
Replace the complete definition and metadata of an existing saved search. This PUT operation requires urlscan Pro saved-search access and write permission; the hostnames datasource may require an additional entitlement.
Update Alert SubscriptionURLSCANIO_UPDATE_SUBSCRIPTION
Replace the complete configuration of an existing alert subscription. This Pro-only PUT requires every mandatory field, not only changed values. It has external notification side effects: activating the subscription or changing recipients, channels, webhooks, or incident settings can send notifications or create incidents. Confirm the complete replacement configuration before calling.