> ## Documentation Index
> Fetch the complete documentation index at: https://docs.encrata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# URL Scan

> Scan a URL for phishing, malware, and other security threats.

URL Scan checks a URL against Encrata's threat-detection signals and returns a verdict, risk score, and supporting indicators.

## Authentication

Send your API key as `Authorization: Bearer <key>`.

## Request

<ParamField body="kind" type="string" required>
  Set this value to `url`.
</ParamField>

<ParamField body="url" type="string" required>
  The URL to scan. Include the protocol, such as `https://`.
</ParamField>

<ParamField body="stix" type="boolean">
  Set to `true` to include STIX 2.1 output when available. Defaults to `false`.
</ParamField>

## Example request

```bash theme={"theme":{"light":"github-light","dark":"vesper"}}
curl --request POST \
  --url https://api.encrata.com/api/lookup/malware/scan \
  --header "Content-Type: application/json" \
  --header "Authorization: Bearer $ENCRATA_API_KEY" \
  --data '{
    "kind": "url",
    "url": "https://example.com/login"
  }'
```

## Example response

```json theme={"theme":{"light":"github-light","dark":"vesper"}}
{
  "success": true,
  "result": {
    "scan_id": "scan_01J9W6Q9E8PW4V9N7T3K2M1R5A",
    "kind": "url",
    "status": "completed",
    "verdict": "suspicious",
    "score": 72,
    "url": "https://example.com/login",
    "signals": ["credential-harvesting-pattern"],
    "iocs": [],
    "data_residency": "us",
    "scanned_at": "2026-10-07T09:30:00Z"
  },
  "message": "Scan completed"
}
```

## URL result fields

<ResponseField name="url" type="string">
  The normalized URL that Encrata scanned.
</ResponseField>

<ResponseField name="signals" type="string[]">
  Security signals that contributed to the verdict.
</ResponseField>

<ResponseField name="iocs" type="object[]">
  Indicators of compromise found during the scan.
</ResponseField>

See [Malware Scan](/api-reference/endpoint/malware-scan) for the complete response schema and shared fields.

## Errors

The API returns `400` for an invalid URL, `401` for a missing or invalid API key, `402` when your account has insufficient credits, and `429` when you exceed a rate limit.

## Credits

A successful scan costs 1 credit. Repeating the same scan kind and content is deduplicated for billing.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.