Developer Tools50 toolsPaste one API key
urlscan.io integration for AI agents
Submit and retrieve website scans, search urlscan.io data, and manage urlscan Pro resources for threat intelligence and security investigations.
Use it from your agent
One ClawLink account serves every agent you run. Pick the guide for yours, or connect urlscan.io once and call the same tools from all of them.
Setup
Connect urlscan.io through ClawLink's hosted setup.
- Auth: Paste one API key. The credential stays on the ClawLink server; your agent holds only a ClawLink key you can revoke.
- Where: the ClawLink dashboard, or ask your agent to connect it.
What your agent can do
urlscan.io exposes 50 tools through ClawLink. The 30 most used are listed here; your agent sees all of them.
| Tool | What it does | Kind |
|---|---|---|
urlscanio_download_file | Retrieve a captured binary file by its SHA-256 hash as a password-encrypted ZIP archive | Read |
urlscanio_get_account_capabilities | Get non-sensitive plan, product, feature, visibility, submission, and limit information for the | Read |
urlscanio_get_brand_summary | Return detectable brands with detected-page totals and latest hits | Read |
urlscanio_get_channel | Get one urlscan Pro notification channel by ID while preserving provider-specific metadata and | Read |
urlscanio_get_data_dump_link | Generate a temporary download URL for a path returned by LIST_DATA_DUMPS | Read |
urlscanio_get_dom | Return the plain-text DOM snapshot captured for a completed scan | Read |
urlscanio_get_hostname_history | Return one page of historical Pro Hostnames observations for a hostname | Read |
urlscanio_get_incident | Get one incident's configuration, source, runtime state, and timestamps | Read |
urlscanio_get_incident_states | Retrieve the stored state history for an incident | Read |
urlscanio_get_live_scan_resource | Retrieve one temporary result, DOM, screenshot, captured response, or download from the | Read |
urlscanio_get_quotas | Get current products, features, query capabilities, and per-action minute, hour, and day quota | Read |
urlscanio_get_response_content | Return textual content captured in a scan response, addressed by its SHA-256 hash | Read |
urlscanio_get_result | Retrieve the complete metadata and captured request data for a completed scan UUID | Read |
urlscanio_get_saved_search_results | Run a urlscan Pro saved search and return its current Search API results | Read |
urlscanio_get_screenshot | Retrieve a completed urlscan.io scan screenshot as a downloadable PNG file reference | Read |
urlscanio_get_similar_results | Find one page of scan results structurally similar to a specified scan | Read |
urlscanio_get_subscription_results | Resolve a urlscan Pro alert subscription and datasource to its current Search API results | Read |
urlscanio_list_available_brands | List brand identifiers and metadata tracked by urlscan.io brand and phishing detection | Read |
urlscanio_list_available_countries | List scanner country codes currently accepted by the Scan API | Read |
urlscanio_list_channels | List email and webhook notification channels for the current user without returning webhook | Read |
urlscanio_list_data_dumps | List available urlscan.io data-dump files for a time window, file type, and date | Read |
urlscanio_list_live_scanners | List Live Scanning nodes available to the connected account and their current metadata | Read |
urlscanio_list_saved_searches | List saved searches owned by or shared with the current user | Read |
urlscanio_list_subscriptions | List alert subscriptions configured for the current user | Read |
urlscanio_list_user_agents | List grouped browser user-agent strings available for scan submission | Read |
urlscanio_list_watchable_attributes | List attribute values accepted when configuring incident change monitoring | Read |
urlscanio_lookup_malicious_observable | Look up malicious-scan occurrence counts and first/last seen timestamps for an IP, hostname | Read |
urlscanio_search_scans | Search urlscan.io data with Elasticsearch Query String syntax and return one controllable page | Read |
urlscanio_close_incident | Stop ongoing scans for an active urlscan Pro incident and transition it to the closed state | Write |
urlscanio_copy_incident | Create a separate urlscan Pro incident from an existing incident's configuration | Read |