Skip to main content
POST
URL Scan
URL Scan checks a URL against Encrata’s threat-detection signals and returns a verdict, risk score, and supporting indicators.

Authentication

Send your API key as Authorization: Bearer <key>.

Request

string
required
Set this value to url.
string
required
The URL to scan. Include the protocol, such as https://.
boolean
Set to true to include STIX 2.1 output when available. Defaults to false.

Example request

Example response

URL result fields

string
The normalized URL that Encrata scanned.
string[]
Security signals that contributed to the verdict.
object[]
Indicators of compromise found during the scan.
See Malware Scan for the complete response schema and shared fields.

Errors

The API returns 400 for an invalid URL, 401 for a missing or invalid API key, 402 when your account has insufficient credits, and 429 when you exceed a rate limit.

Credits

A successful scan costs 1 credit. Repeating the same scan kind and content is deduplicated for billing.