Skip to main content
POST
Image Scan
Image Scan analyzes a base64-encoded image for malware, suspicious content, and embedded indicators.

Authentication

Send your API key as Authorization: Bearer <key>.

Request

string
required
Set this value to image.
string
required
The base64-encoded image. Do not include a data URL prefix.
string
The original image file name.
boolean
Set to true to include STIX 2.1 output when available. Defaults to false.

Example request

Example response

Image result fields

string
The SHA-256 hash of the decoded image.
string[]
Security signals found during image analysis.
object[]
Indicators of compromise extracted from the image.
See Malware Scan for the complete response schema and shared fields.

Errors

The API returns 400 for invalid base64 content or an unsupported image, 401 for a missing or invalid API key, 402 when your account has insufficient credits, and 429 when you exceed a rate limit.

Credits

A successful scan costs 1 credit. Repeating the same scan kind and content is deduplicated for billing.