> ## Documentation Index
> Fetch the complete documentation index at: https://docs.encrata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Image Scan

> Inspect an image for malware and suspicious content.

Image Scan analyzes a base64-encoded image for malware, suspicious content, and embedded indicators.

## Authentication

Send your API key as `Authorization: Bearer <key>`.

## Request

<ParamField body="kind" type="string" required>
  Set this value to `image`.
</ParamField>

<ParamField body="content_base64" type="string" required>
  The base64-encoded image. Do not include a data URL prefix.
</ParamField>

<ParamField body="filename" type="string">
  The original image file name.
</ParamField>

<ParamField body="stix" type="boolean">
  Set to `true` to include STIX 2.1 output when available. Defaults to `false`.
</ParamField>

## Example request

```bash theme={"theme":{"light":"github-light","dark":"vesper"}}
IMAGE_BASE64=$(base64 < screenshot.png | tr -d '\n')

curl --request POST \
  --url https://api.encrata.com/api/lookup/malware/scan \
  --header "Content-Type: application/json" \
  --header "Authorization: Bearer $ENCRATA_API_KEY" \
  --data "{\"kind\":\"image\",\"content_base64\":\"$IMAGE_BASE64\",\"filename\":\"screenshot.png\"}"
```

## Example response

```json theme={"theme":{"light":"github-light","dark":"vesper"}}
{
  "success": true,
  "result": {
    "scan_id": "scan_01J9W6Q9E8PW4V9N7T3K2M1R5D",
    "kind": "image",
    "status": "completed",
    "verdict": "clean",
    "score": 2,
    "sha256": "f2ca1bb6c7e907d06dafe4687e579fce76b37e4e93b7605022da52e6ccc26fd2",
    "signals": [],
    "data_residency": "us",
    "scanned_at": "2026-10-07T09:30:00Z"
  },
  "message": "Scan completed"
}
```

## Image result fields

<ResponseField name="sha256" type="string">
  The SHA-256 hash of the decoded image.
</ResponseField>

<ResponseField name="signals" type="string[]">
  Security signals found during image analysis.
</ResponseField>

<ResponseField name="iocs" type="object[]">
  Indicators of compromise extracted from the image.
</ResponseField>

See [Malware Scan](/api-reference/endpoint/malware-scan) for the complete response schema and shared fields.

## Errors

The API returns `400` for invalid base64 content or an unsupported image, `401` for a missing or invalid API key, `402` when your account has insufficient credits, and `429` when you exceed a rate limit.

## Credits

A successful scan costs 1 credit. Repeating the same scan kind and content is deduplicated for billing.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.