urlscan.io, worked by an AI employee
Not another app for your team to learn, and not a set of rules for you to build. You hire an AI employee, you give it access to your urlscan.io account, and you ask it for things in Slack or Teams the way you would ask anyone else on the team. There is nothing to map and nothing to maintain.
- Security & Identity Tools
- Connects with a key
- 50 ready-made tools
- Asked in Slack or Teams
An illustration of how the conversation reads, not a transcript from a client account.
What urlscan.io is
Submit and retrieve website scans, search urlscan.io data, and manage urlscan Pro resources for threat intelligence and security investigations.
You paste in a key from your own urlscan.io account. It is kept encrypted, and you can withdraw it from inside urlscan.io whenever you like.
One message in, the work done in urlscan.io.
- 01
You ask
You message your AI employee in the chat your team already has open, in one sentence, in your own words.
- 02
It works out the step
It decides what the job needs in urlscan.io. You do not pick anything from a menu or wire anything together.
- 03
It does the work
Signed in to your own urlscan.io account, inside the access you granted it, doing the thing you asked for.
- 04
It reports back
It tells you what it did, in the same thread. If it could not do something, it says so rather than guessing.
What it can do in urlscan.io
These are the ready-made tools your AI employee already has in urlscan.io. It is not limited to them, but it never has to be taught these.
- Close IncidentStop ongoing scans for an active urlscan Pro incident and transition it to the closed state. Closing does not delete the incident or its history, and the incident can later be rest
- Copy IncidentCreate a separate urlscan Pro incident from an existing incident's configuration. This create operation can consume incident capacity and does not copy the source incident's stored
- Create Alert SubscriptionCreate a persistent scheduled or live alert subscription for saved searches. This Pro-only operation has external notification side effects: an active subscription can send email,
- Create IncidentCreate a Pro incident that persistently monitors an observable. This high-impact operation starts ongoing external scans and can send alerts through every supplied notification cha
- Create Live Scan TaskStart a non-blocking temporary Live Scan on a selected scanner and return its UUID immediately without waiting for completion. This external scan side effect requires the separate
- Create Notification ChannelCreate a Pro notification channel. This operation configures external effects: active webhook channels send requests to the supplied secret URL, and active email channels send mess
- Create Saved SearchCreate a reusable scans or hostnames search definition. This operation creates a persistent saved search and requires urlscan Pro; the hostnames datasource may require an additiona
- Delete Alert SubscriptionPermanently delete an alert subscription by ID. This destructive operation cannot be undone and requires urlscan Pro subscriptions access plus ownership or team write permission. U
- Delete Saved SearchPermanently delete a saved search by ID. This destructive operation cannot be undone and requires urlscan Pro saved-search access plus ownership or team write permission. Use it on
- Delete Scan ResultPermanently delete a scan owned by the connected user or team. This destructive operation cannot be reversed and requires urlscan Pro.
- Download Captured FileRetrieve a captured binary file by its SHA-256 hash as a password-encrypted ZIP archive. This operation requires urlscan Pro access.
- Fork IncidentCreate a new Pro incident by copying an existing incident's configuration and complete stored state history. This creates a separate persistent incident; history volume and whether
- Get Account CapabilitiesGet non-sensitive plan, product, feature, visibility, submission, and limit information for the connected urlscan.io API key.
- Get API QuotasGet current products, features, query capabilities, and per-action minute, hour, and day quota usage.
- Get Available BrandsList brand identifiers and metadata tracked by urlscan.io brand and phishing detection. Requires urlscan Pro brand/phishing access; the exact product and minimum plan are not docum
- Get Available Scan CountriesList scanner country codes currently accepted by the Scan API.
- Get Brand SummaryReturn detectable brands with detected-page totals and latest hits. This operation requires urlscan Pro access and uses the official contract only; the provider does not document i
- Get Captured Response ContentReturn textual content captured in a scan response, addressed by its SHA-256 hash.
- Get Data Dump Download LinkGenerate a temporary download URL for a path returned by LISTDATADUMPS. Data Dumps require an Enterprise or Ultimate urlscan.io plan.
- Get Hostname HistoryReturn one page of historical Pro Hostnames observations for a hostname.
- Get IncidentGet one incident's configuration, source, runtime state, and timestamps.
- Get Incident StatesRetrieve the stored state history for an incident.
- Get Live Scan ResourceRetrieve one temporary result, DOM, screenshot, captured response, or download from the separate urlscan.io Live Scanning product. JSON and text are returned inline; binary content
- Get Notification ChannelGet one urlscan Pro notification channel by ID while preserving provider-specific metadata and removing webhook destinations or credentials.
- Get Saved Search ResultsRun a urlscan Pro saved search and return its current Search API results. The provider redirect is followed automatically; this operation does not expose pagination controls.
- Get Scan DOMReturn the plain-text DOM snapshot captured for a completed scan.
- Get Scan ResultRetrieve the complete metadata and captured request data for a completed scan UUID.
- Get Scan ScreenshotRetrieve a completed urlscan.io scan screenshot as a downloadable PNG file reference.
- Get Scan User AgentsList grouped browser user-agent strings available for scan submission.
- Get Similar Scan ResultsFind one page of scan results structurally similar to a specified scan. Requires urlscan Pro access.
- Get Subscription ResultsResolve a urlscan Pro alert subscription and datasource to its current Search API results. The provider redirect is followed automatically; this operation does not expose paginatio
- Get Watchable Incident AttributesList attribute values accepted when configuring incident change monitoring. Requires urlscan Pro Incidents capability; the exact minimum plan or product is not documented.
- List Alert SubscriptionsList alert subscriptions configured for the current user. This operation requires urlscan Pro subscriptions access.
- List Data DumpsList available urlscan.io data-dump files for a time window, file type, and date. Requires an Enterprise or Ultimate plan; availability can vary by window and file type.
- List Live ScannersList Live Scanning nodes available to the connected account and their current metadata. This requires the separate urlscan.io Live Scanning product; a generic urlscan Pro plan may
- List Notification ChannelsList email and webhook notification channels for the current user without returning webhook URLs or embedded credentials. This operation requires urlscan Pro channels access.
- List Saved SearchesList saved searches owned by or shared with the current user. This operation requires urlscan Pro saved-search access.
- Lookup Malicious ObservableLook up malicious-scan occurrence counts and first/last seen timestamps for an IP, hostname, domain, or exact URL. Requires urlscan Pro malicious-observable access.
- Purge Live Scan ResultPermanently delete a temporary result from the separate urlscan.io Live Scanning product before its normal expiration. This destructive operation cannot be undone; only use it to c
- Reset Scan VisibilityRemove an owned scan's visibility override and restore the visibility originally assigned at submission. This resets an override; it does not delete the scan. Requires urlscan Pro.
- Restart IncidentRestart a closed urlscan Pro incident and extend its expiry. This resumes ongoing external monitoring, begins recording new incident states, and can resume alerts through the incid
- Run Blocking Live ScanRun a temporary Live Scan synchronously and return only after the provider finishes the scan. This requires the separate Live Scanning product.
- Search ScansSearch urlscan.io data with Elasticsearch Query String syntax and return one controllable page of results.
- Store Live Scan ResultPermanently store an existing temporary Live Scan result with the selected visibility. This updates the temporary result into a durable snapshot and requires the separate urlscan.i
- Submit ScanSubmit a URL for asynchronous external scanning, creating persistent result state and consuming quota. Visibility defaults to public, and free accounts have no cleanup operation. R
- Update Alert SubscriptionReplace the complete configuration of an existing alert subscription. This Pro-only PUT requires every mandatory field, not only changed values. It has external notification side e
- Update IncidentReplace an existing incident's monitoring configuration and runtime options. This Pro-only PUT requires observable, visibility, and the complete channel set, not only changed value
- Update Notification ChannelReplace the complete configuration of an existing Pro notification channel. This operation can redirect external effects: active webhook channels send requests to the supplied secr
- Update Saved SearchReplace the complete definition and metadata of an existing saved search. This PUT operation requires urlscan Pro saved-search access and write permission; the hostnames datasource
- Update Scan VisibilityChange the visibility of a scan owned by the connected user or team. This operation requires a paid urlscan Pro entitlement and is contract-only, not live verified. Use DELETERESUL
You stay the boss of your urlscan.io account.
Nothing connects until you approve it. You grant access one app at a time, you can take it back the same way, and everything your AI employee does in there is written down where you can see it.
How we handle your data- It signs in to your own urlscan.io account. You are not moving anything into ours.
- You grant access one app at a time, and you can take it back the same way.
- Everything it does in urlscan.io is written down, with what it did and when.
- Anything you tell it to check with you first, it checks with you first.
It works in urlscan.io and the rest of your software in the same job
A real job rarely stays in one place. Reading a message in one app, checking a record in another and writing the result in a third is one request to your AI employee, not three.
Questions people ask about urlscan.io
- Can an AI employee really work inside urlscan.io?
- Yes. It signs in to your own urlscan.io account and works in it the way a new hire would, from the chat your team already has open. Nobody installs anything, and nobody learns a new screen.
- Do I have to move anything out of urlscan.io?
- No. Nothing moves and nothing is replaced. Your records stay in urlscan.io, your team carries on in the same screens they used yesterday, and your AI employee works alongside them in there.
- How does it get into my urlscan.io account?
- You paste in a key from your own urlscan.io account. It is kept encrypted, and you can withdraw it from inside urlscan.io whenever you like. You approve it before anything connects, and you can take the access back the same way you gave it.
- What can it actually do in urlscan.io?
- It has 50 ready-made tools in urlscan.io today, among them Close Incident, Copy Incident and Create Alert Subscription. The full list is on this page. It is not limited to those, but it never has to be taught them.
- Can it use urlscan.io and the rest of my software in the same job?
- Yes, and that is usually the point. Reading a message in one app, checking a record in urlscan.io and writing the result somewhere else is one request to your AI employee, not three separate ones you stitch together.
- Who decides what it is allowed to do in urlscan.io?
- You do. You grant access one app at a time and can withdraw it at any time, anything you ask it to check with you first it checks with you first, and everything it does in urlscan.io is written down with what it did and when.