ClawLink
Developer Tools50 toolsPaste one API key

urlscan.io integration for AI agents

Submit and retrieve website scans, search urlscan.io data, and manage urlscan Pro resources for threat intelligence and security investigations.

Use it from your agent

One ClawLink account serves every agent you run. Pick the guide for yours, or connect urlscan.io once and call the same tools from all of them.

Setup

Connect urlscan.io through ClawLink's hosted setup.

  • Auth: Paste one API key. The credential stays on the ClawLink server; your agent holds only a ClawLink key you can revoke.
  • Where: the ClawLink dashboard, or ask your agent to connect it.

What your agent can do

urlscan.io exposes 50 tools through ClawLink. The 30 most used are listed here; your agent sees all of them.

ToolWhat it doesKind
urlscanio_download_fileRetrieve a captured binary file by its SHA-256 hash as a password-encrypted ZIP archiveRead
urlscanio_get_account_capabilitiesGet non-sensitive plan, product, feature, visibility, submission, and limit information for theRead
urlscanio_get_brand_summaryReturn detectable brands with detected-page totals and latest hitsRead
urlscanio_get_channelGet one urlscan Pro notification channel by ID while preserving provider-specific metadata andRead
urlscanio_get_data_dump_linkGenerate a temporary download URL for a path returned by LIST_DATA_DUMPSRead
urlscanio_get_domReturn the plain-text DOM snapshot captured for a completed scanRead
urlscanio_get_hostname_historyReturn one page of historical Pro Hostnames observations for a hostnameRead
urlscanio_get_incidentGet one incident's configuration, source, runtime state, and timestampsRead
urlscanio_get_incident_statesRetrieve the stored state history for an incidentRead
urlscanio_get_live_scan_resourceRetrieve one temporary result, DOM, screenshot, captured response, or download from theRead
urlscanio_get_quotasGet current products, features, query capabilities, and per-action minute, hour, and day quotaRead
urlscanio_get_response_contentReturn textual content captured in a scan response, addressed by its SHA-256 hashRead
urlscanio_get_resultRetrieve the complete metadata and captured request data for a completed scan UUIDRead
urlscanio_get_saved_search_resultsRun a urlscan Pro saved search and return its current Search API resultsRead
urlscanio_get_screenshotRetrieve a completed urlscan.io scan screenshot as a downloadable PNG file referenceRead
urlscanio_get_similar_resultsFind one page of scan results structurally similar to a specified scanRead
urlscanio_get_subscription_resultsResolve a urlscan Pro alert subscription and datasource to its current Search API resultsRead
urlscanio_list_available_brandsList brand identifiers and metadata tracked by urlscan.io brand and phishing detectionRead
urlscanio_list_available_countriesList scanner country codes currently accepted by the Scan APIRead
urlscanio_list_channelsList email and webhook notification channels for the current user without returning webhookRead
urlscanio_list_data_dumpsList available urlscan.io data-dump files for a time window, file type, and dateRead
urlscanio_list_live_scannersList Live Scanning nodes available to the connected account and their current metadataRead
urlscanio_list_saved_searchesList saved searches owned by or shared with the current userRead
urlscanio_list_subscriptionsList alert subscriptions configured for the current userRead
urlscanio_list_user_agentsList grouped browser user-agent strings available for scan submissionRead
urlscanio_list_watchable_attributesList attribute values accepted when configuring incident change monitoringRead
urlscanio_lookup_malicious_observableLook up malicious-scan occurrence counts and first/last seen timestamps for an IP, hostnameRead
urlscanio_search_scansSearch urlscan.io data with Elasticsearch Query String syntax and return one controllable pageRead
urlscanio_close_incidentStop ongoing scans for an active urlscan Pro incident and transition it to the closed stateWrite
urlscanio_copy_incidentCreate a separate urlscan Pro incident from an existing incident's configurationRead