mlab docs

API Reference

The mlab.sh REST API - authentication, endpoints, schemas and live examples.

GET
/api/v1/

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Response Body

application/json

application/json

curl -X GET "https://example.com/api/v1/"
{  "auth": "api_key",  "message": "Hello, Acme Corp!",  "organization": "Acme Corp",  "plan": "pro"}
{  "status": "error",  "message": "Invalid or missing API key."}
POST
/api/v1/scan/domain

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/scan/domain" \  -H "Content-Type: application/json" \  -d '{    "domain": "example.com"  }'
{  "status": "success",  "message": "Domain scan has been started."}

{  "status": "error",  "message": "Provided domain is invalid."}

{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/domain/status

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

domain*string

The domain in question.

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/domain/status?domain=example.com"

{  "status": "pending",  "message": "Domain scan is still pending."}

{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/domain/results

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

domain*string

The domain in question.

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/domain/results?domain=example.com"
{  "domain": "example.com",  "scan_date": "2026-07-05 16:13:00 UTC",  "status": "completed",  "results": {    "subdomains": [      "www.example.com",      "example.org",      "example.net"    ],    "subdomains_suspicious": [      {        "keyword": "admin",        "subdomain": "admin.example.com"      }    ],    "dns": {      "resolve": [        {          "domain": "www.example.com",          "a": [            "104.20.23.154",            "172.66.147.243"          ],          "aaaa": [            "2606:4700:10::6814:179a"          ],          "cname": null        }      ],      "txt": {        "raw": [          "v=spf1 -all"        ],        "spf": "v=spf1 -all",        "dmarc": null,        "dkim": []      }    },    "ssl": [      {        "domain": "example.com",        "id": 13769145126,        "issuer_ca_id": 0,        "issuer_name": "C=US, O=DigiCert Inc, CN=DigiCert Global CA G2",        "common_name": "www.example.com",        "name_value": "www.example.com",        "entry_timestamp": "2026-02-11T21:22:07Z",        "not_before": "2026-01-15T00:00:00",        "not_after": "2027-01-15T23:59:59",        "serial_number": "",        "result_count": 1      }    ],    "files": {      "robots_txt": "User-agent: *\nDisallow:",      "security_txt": ""    }  }}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/domain/loadnetworkrequest

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

url*string

Target URL to load. https:// is prepended if no scheme is present. Must be http or https.

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/domain/loadnetworkrequest?url=https%3A%2F%2Fexample.com"
{  "url": "https://example.com/",  "captureMs": 10000,  "count": 1,  "totalBytes": 632,  "requests": [    {      "requestId": "E51577303D719753FF104B65E699F860",      "url": "https://example.com/",      "method": "GET",      "resourceType": "Document",      "initiator": "other",      "status": 200,      "mimeType": "text/html",      "protocol": "http/1.1",      "remoteIP": "93.184.216.34",      "encodedBytes": 632,      "startMs": 0,      "endMs": 77,      "failed": false,      "errorText": null    }  ]}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/ip

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

ip*string

IPv4 or IPv6 address, or a CIDR range, to look up.

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/ip?ip=8.8.8.8"

{  "ip": "8.8.8.8",  "reserved": false,  "isp": "Google LLC",  "org": "Google Public DNS",  "as": "AS15169 Google LLC",  "city": "Ashburn",  "region": "Virginia",  "country": "United States",  "country_code": "US",  "continent": "North America",  "continent_code": "NA",  "timezone": "America/New_York",  "zip": "20149",  "lat": 39.03,  "lon": -77.5,  "currency": "USD",  "proxy": false,  "hosting": true,  "mobile": false,  "rdns": {    "ip": "8.8.8.8",    "found": true,    "names": [      "dns.google"    ],    "name": "dns.google",    "forward_confirmed": true,    "forward_addresses": [      "8.8.8.8"    ]  },  "rdap": {    "ip": "8.8.8.8",    "found": true,    "name": "GOGL",    "cidr": "8.8.8.0/24",    "country": "US",    "holder": "Google LLC",    "abuse_email": "[email protected]"  },  "tor": {    "available": true,    "ip": "8.8.8.8",    "is_tor": false  },  "status": "success"}

{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/crypto

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

address*string

The blockchain address to look up.

chain?string

Chain ID. Auto-detected for EVM (0x…), BTC (1…/3…/bc1…) and TRX (T…) addresses.

Value in

  • "ETH"
  • "BSC"
  • "POLYGON"
  • "ARBITRUM"
  • "OPTIMISM"
  • "BASE"
  • "AVAX"
  • "BTC"
  • "TRX"
  • "SOL"
  • "TON"
  • "DOGE"

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/crypto?address=0x722122df12d4e14e13ac3b6895a86e84145b6967"
{  "address": "0x722122df12d4e14e13ac3b6895a86e84145b6967",  "chain": "ETH",  "chain_source": "default",  "chain_ambiguous": true,  "chain_candidates": [    "ETH",    "BSC",    "POLYGON",    "ARBITRUM",    "OPTIMISM",    "BASE",    "AVAX",    "BLAST",    "FLARE",    "LINEA",    "MANTA",    "MANTLE",    "SONIC"  ],  "address_info": {    "family": "evm",    "kind": "account",    "checksum": "absent",    "testnet": false  },  "intel": {    "type": "contract",    "categories": [      "contract",      "mixer"    ],    "labels": [      {        "name": "Tornado Cash: Proxy",        "source": "community"      }    ],    "sanctions": {      "is_sanctioned": false    },    "risk_score": 80,    "risk_level": "critical"  }}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
Empty
POST
/api/v1/scan/crypto

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

curl -X POST "https://example.com/api/v1/scan/crypto" \  -H "Content-Type: application/json" \  -d '{    "addresses": [      "string"    ]  }'
{  "count": 0,  "results": [    {      "address": "string",      "chain": "BTC",      "chain_source": "detected",      "chain_ambiguous": true,      "chain_candidates": [        "string"      ],      "address_info": {        "family": "evm",        "kind": "p2pkh",        "checksum": "valid",        "testnet": true      },      "note": "string",      "intel": {}    }  ],  "invalid": [    {}  ],  "deferred": [    {}  ]}
Empty
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/hash

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

hash*string

MD5, SHA-1, SHA-256 or SHA-512 hex digest.

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/hash?hash=44d88612fea8a8f36de82e1278abb02f"
{  "hash": "44d88612fea8a8f36de82e1278abb02f",  "algorithm": "MD5",  "verdict": "known_malicious",  "found": true,  "known_malicious": true,  "matched_on": "md5",  "enrichment_source": "circl-hashlookup",  "trust": 100,  "cached": true,  "sources_hit": 1,  "sources_answered": 1,  "sources_queried": 1}
Empty
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
POST
/api/v1/scan/hash

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/scan/hash" \  -H "Content-Type: application/json" \  -d '{    "hashes": [      "string"    ]  }'
{  "count": 0,  "cached": 0,  "summary": {    "property1": 0,    "property2": 0  },  "results": [    {      "hash": "string",      "algorithm": "MD5",      "verdict": "known_good",      "found": true,      "known_malicious": true,      "matched_on": "string",      "enrichment_source": "string",      "source": "string",      "product": "string",      "family": "string",      "file_name": "string",      "summary": "string",      "cached": true,      "checked_at": "string",      "sources_hit": 0,      "sources_answered": 0,      "sources_queried": 0,      "sources": {},      "mlab_sample": {},      "hint": "string"    }  ],  "invalid": [    {}  ]}
Empty
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/url

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

url*string

The URL to analyse (max 8192 chars). q is accepted as an alias.

resolve?string

Follow the link to its destination. Off by default.

Value in

  • "true"
  • "false"

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/url?url=https%3A%2F%2Fbit.ly%2F3xYz"
{  "url": "http://paypa1-secure.com/login?next=https://paypal.com",  "scheme": "http",  "host": "paypa1-secure.com",  "host_is_ip": false,  "path": "/login",  "query": [    {      "key": "next",      "value": "https://paypal.com"    }  ],  "has_userinfo": false,  "findings": [    {      "severity": "high",      "title": "Brand lookalike host",      "detail": "The host imitates paypal."    }  ],  "host_context": {    "scanned": false  },  "resolution": null}
Empty
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/email

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

email*string

The email address to analyse.

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/email?email=john.doe%2Bnews%40gmail.com"
{  "email": "[email protected]",  "local": "john.doe+news",  "domain": "gmail.com",  "tag": "news",  "canonical": "[email protected]",  "canonical_differs": true,  "mailbox_type": "Consumer provider",  "is_role": false,  "is_free_provider": true,  "is_disposable": false,  "score": {    "value": 10,    "band": "clean",    "conclusive": true,    "reasons": []  },  "domain_scan": {    "scanned": true,    "mail_source": "scan",    "spoofability": {      "verdict": "Spoofing rejected",      "summary": "DMARC p=reject is enforced."    },    "mx": {      "count": 5    },    "domain_age_days": 10950  },  "findings": []}
Empty
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/phone

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

number*string

Phone number in E.164 form. A missing leading + is added.

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/phone?number=%2B33612345678"
{  "input": "+33612345678",  "valid": true,  "possible": true,  "verdict": "Nothing notable",  "country_code": 33,  "region": "FR",  "line_type": "Mobile",  "allocated_operator": "Orange",  "allocated_operator_may_have_changed": true,  "formats": {    "e164": "+33612345678",    "international": "+33 6 12 34 56 78",    "national": "06 12 34 56 78",    "rfc3966": "tel:+33-6-12-34-56-78"  },  "findings": []}
Empty
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/mac

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

mac*string

MAC address in any common notation.

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/mac?mac=00%3A1A%3A2B%3A3C%3A4D%3A5E"
{  "mac": "00:1a:2b:3c:4d:5e",  "verdict": "Vendor assigned",  "cast": "Unicast",  "administration": "Universal",  "randomized": false,  "oui": "00:1a:2b",  "vendor": "Ayecom Technology",  "virtualization": null,  "special": null,  "eui64_ipv6": "fe80::21a:2bff:fe3c:4d5e",  "formats": {    "colon": "00:1a:2b:3c:4d:5e",    "hyphen": "00-1a-2b-3c-4d-5e",    "cisco": "001a.2b3c.4d5e",    "bare": "001a2b3c4d5e"  }}
Empty
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
POST
/api/v1/scan/ioc

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

risk?string

Add SMS threat scoring: true/fast (offline) or deep (network).

Value in

  • "true"
  • "fast"
  • "deep"
country?string

Keyword and brand pack for the scorer. pays is accepted as an alias.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/scan/ioc" \  -H "Content-Type: application/json" \  -d '{    "text": "string"  }'
{  "status": "ok",  "ioc_total": 1,  "truncated": false,  "iocs": {    "url": [      {        "value": "https://colis-livraison.top/suivi",        "link": "https://mlab.sh/url?q=https://colis-livraison.top/suivi"      }    ]  },  "risk": {    "score": 85,    "band": "critical",    "action": "drop",    "mode": "fast",    "country": "fr",    "reasons": [      {        "code": "parcel_lure",        "weight": 30,        "label": "Parcel delivery lure"      }    ]  }}
Empty
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
POST
/upload/file

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

multipart/form-data

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/upload/file" \  -F file="string"
{  "success": true,  "filename": "0c2c2762-4c33-4b49-8771-be36675c8a58.png",  "sha256": "5f31de7b7059acf773ba2fafcd318a2f46883d58deb9b323e74dfb20453ed3d0",  "job_launched": true,  "existingData": [],  "existingJobs": []}
{  "success": false,  "error": {    "code": 400,    "message": "invalid_content_type"  }}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "success": false,  "error": {    "code": 413,    "message": "file_too_large"  }}
{  "success": false,  "error": {    "code": 429,    "message": "rate_limited"  }}
GET
/api/v1/scan/file/results

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

sha256*string

The sha256 returned by the upload endpoint.

Response Body

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/file/results?sha256=5f31de7b7059acf773ba2fafcd318a2f46883d58deb9b323e74dfb20453ed3d0"
{  "status": "completed",  "jobs_total": 3,  "jobs_completed": 3,  "file": {    "sha256": "5f31de7b7059acf773ba2fafcd318a2f46883d58deb9b323e74dfb20453ed3d0",    "md5": "d41d8cd98f00b204e9800998ecf8427e",    "ssdeep": "3:tk:tk",    "filename": "0c2c2762-4c33-4b49-8771-be36675c8a58.png",    "size": 70,    "mime_type": "image/png",    "created_at": "2026-07-05T16:13:54Z"  },  "analysis": [    {      "job_name": "binwalk",      "end_date": "2026-07-05T16:14:04+00:00",      "data": "Analyzed 1 file for 111 file signatures (251 magic patterns) in 405.0 milliseconds"    },    {      "job_name": "exiftool",      "end_date": "2026-07-05T16:14:04+00:00",      "data": "File Type : PNG\nMIME Type : image/png\nImage Width : 1\nImage Height : 1"    },    {      "job_name": "strings",      "end_date": "2026-07-05T16:14:05+00:00",      "data": "IHDR\nIDAT\nIEND"    }  ]}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "error": "Not found"}
GET
/api/v1/scan/file/output

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

sha256*string

SHA-256 of the analysed file.

tool*string

Tool name, as listed in the file results.

Response Body

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/file/output?sha256=275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f&tool=yara"
{  "sha256": "string",  "tool": "string",  "is_json": true,  "output": "string"}
Empty
{  "status": "error",  "message": "Invalid or missing API key."}
Empty
GET
/api/v1/domain/ssl

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

domain*string

The domain in question.

Response Body

application/json

application/json

curl -X GET "https://example.com/api/v1/domain/ssl?domain=example.com"
[  {    "domain": "google.com",    "id": 13769145126,    "issuer_ca_id": 0,    "issuer_name": "C=US, O=Google Trust Services, CN=WR4",    "common_name": "da-twd-8.da.ext.google.com",    "name_value": "da-twd-8.da.ext.google.com",    "entry_timestamp": "2026-02-11T21:22:07Z",    "not_before": "2026-02-11T21:22:07Z",    "not_after": "2026-05-12T21:22:06Z",    "serial_number": "",    "result_count": 1  }]
{  "status": "error",  "message": "Invalid or missing API key."}
GET
/api/v1/limit/{scan_type}

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Path Parameters

scan_type*string

The scan type to check.

Value in

  • "domain"
  • "ip"
  • "file"
  • "crypto"

Response Body

application/json

application/json

curl -X GET "https://example.com/api/v1/limit/domain"
{  "scan_type": "domain",  "remaining": 98,  "total": 100}
{  "status": "error",  "message": "Invalid or missing API key."}
POST
/api/v1/scan/batch

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/scan/batch" \  -H "Content-Type: application/json" \  -d '{    "indicators": "string"  }'
{  "count": 1,  "truncated": false,  "indicators": [    {      "kind": "ip",      "value": "8.8.8.8",      "link": "https://mlab.sh/ip/8.8.8.8",      "known": true    }  ],  "skipped": []}
{  "status": "error",  "message": "Description of what went wrong."}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
POST
/api/v1/scan/file/bash/ai

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

sha256*string

SHA-256 of the submitted script.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/scan/file/bash/ai?sha256=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
Empty
{  "status": "error",  "message": "Description of what went wrong."}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
POST
/api/v1/scan/redkit

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/scan/redkit" \  -H "Content-Type: application/json" \  -d '{    "domain": "example.com",    "plugins": [      "headers",      "ssl",      "dns"    ]  }'
{  "status": "success",  "scan_uuid": "2f1c0000-0000-4000-8000-000000000000",  "job_id": "7d2e0000-0000-4000-8000-000000000000"}
{  "status": "error",  "message": "Description of what went wrong."}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/redkit/status

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

uuid*string

The scan_uuid returned at launch.

Response Body

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/redkit/status?uuid=2f1c0000-0000-4000-8000-000000000000"
{  "status": "completed",  "raw_json": "{...}"}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "status": "error",  "message": "Description of what went wrong."}
GET
/api/v1/scan/redkit/quota

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/redkit/quota"
{  "plan": "team",  "used": 3,  "limit": 20,  "remaining": 17}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/watchdog/list

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Response Body

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/watchdog/list"
{  "schedules": [    {      "uuid": "…",      "scan_type": "domain",      "domain": "example.com",      "plugins": [],      "frequency": "weekly",      "day_of_week": 1,      "day_of_month": null,      "hour": 3,      "minute": 0,      "enabled": true,      "next_run_at": "2026-10-05 03:00:00",      "last_run_at": "",      "created_at": "2026-10-01 17:53:03"    }  ]}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
POST
/api/v1/scan/watchdog/create

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/scan/watchdog/create" \  -H "Content-Type: application/json" \  -d '{    "domain": "string",    "frequency": "weekly"  }'
{  "status": "success",  "uuid": "…"}
{  "status": "error",  "message": "Description of what went wrong."}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
POST
/api/v1/scan/watchdog/update

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/scan/watchdog/update" \  -H "Content-Type: application/json" \  -d '{    "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f"  }'
{  "status": "success",  "message": "Schedule updated."}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "status": "error",  "message": "Description of what went wrong."}
POST
/api/v1/scan/watchdog/delete

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/scan/watchdog/delete" \  -H "Content-Type: application/json" \  -d '{    "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f"  }'
{  "status": "success"}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "status": "error",  "message": "Description of what went wrong."}
GET
/api/v1/cases

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Response Body

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/cases"
{  "cases": [    {      "uuid": "…",      "title": "Phishing wave",      "summary": "",      "status": "open",      "indicators": 4,      "comments": 2,      "created_at": "2026-10-01 17:53:03",      "updated_at": "2026-10-01 17:55:10"    }  ]}
{  "status": "error",  "message": "Description of what went wrong."}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
POST
/api/v1/cases/detail

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/cases/detail" \  -H "Content-Type: application/json" \  -d '{    "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f"  }'
{  "uuid": "…",  "title": "Phishing wave",  "summary": "",  "status": "open",  "indicators": [    {      "uuid": "…",      "kind": "domain",      "value": "evil.example",      "link": "https://mlab.sh/domain/evil.example",      "added_at": "…"    }  ],  "comments": [    {      "uuid": "…",      "author": "API key · SOAR prod",      "body": "Seen in 12 mailboxes",      "indicator_uuid": ""    }  ]}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "status": "error",  "message": "Description of what went wrong."}
POST
/api/v1/cases/create

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/cases/create" \  -H "Content-Type: application/json" \  -d '{    "title": "string"  }'
{  "status": "success",  "uuid": "…"}
{  "status": "error",  "message": "Description of what went wrong."}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
POST
/api/v1/cases/update

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/cases/update" \  -H "Content-Type: application/json" \  -d '{    "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f"  }'
{  "status": "success"}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "status": "error",  "message": "Description of what went wrong."}
POST
/api/v1/cases/delete

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/cases/delete" \  -H "Content-Type: application/json" \  -d '{    "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f"  }'
{  "status": "success"}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "status": "error",  "message": "Description of what went wrong."}
POST
/api/v1/cases/indicator/add

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/cases/indicator/add" \  -H "Content-Type: application/json" \  -d '{    "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",    "indicators": "string"  }'
{  "status": "success",  "added": 2,  "skipped": [    {      "value": "not-an-ioc",      "reason": "not an indicator"    }  ]}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "status": "error",  "message": "Description of what went wrong."}
POST
/api/v1/cases/indicator/delete

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/cases/indicator/delete" \  -H "Content-Type: application/json" \  -d '{    "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",    "indicator_uuid": "697456c0-194b-4346-a052-59671c6d36dc"  }'
{  "status": "success"}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "status": "error",  "message": "Description of what went wrong."}
POST
/api/v1/cases/comment/add

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/cases/comment/add" \  -H "Content-Type: application/json" \  -d '{    "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",    "body": "string"  }'
{  "status": "success"}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "status": "error",  "message": "Description of what went wrong."}
POST
/api/v1/cases/comment/delete

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/cases/comment/delete" \  -H "Content-Type: application/json" \  -d '{    "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",    "comment_uuid": "419e4a20-fd36-4fda-bf75-52fba5ddc192"  }'
{  "status": "success"}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
{  "status": "error",  "message": "Description of what went wrong."}
GET
/api/v1/scan/finding-tags

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

scan_uuid*string

The RedKit audit.

Response Body

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/finding-tags?scan_uuid=2f1c0000-0000-4000-8000-000000000000"
{  "tags": [    {      "finding_id": "9f3b2c1a7d4e5f60",      "tag": "false-positive",      "user_uuid": "…"    }  ]}
{  "status": "error",  "message": "Description of what went wrong."}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/finding-tags/add

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

scan_uuid*string

The RedKit audit.

finding_id*string

The finding, as shown on the result page.

tag*string

Value in

  • "false-positive"
  • "accepted-risk"
  • "fixed"

Response Body

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/finding-tags/add?scan_uuid=2f1c0000-0000-4000-8000-000000000000&finding_id=9f3b2c1a7d4e5f60&tag=false-positive"
{  "status": "success"}
{  "status": "error",  "message": "Description of what went wrong."}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}
GET
/api/v1/scan/finding-tags/remove

Authorization

ApiKeyAuth
Authorization<token>

Your API key, prefixed with token . Example: Authorization: token mlab_your_api_key_here. Each key only reaches the endpoints its permissions allow.

In: header

Query Parameters

scan_uuid*string

The RedKit audit.

finding_id*string

The finding, as shown on the result page.

tag*string

Value in

  • "false-positive"
  • "accepted-risk"
  • "fixed"

Response Body

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/scan/finding-tags/remove?scan_uuid=2f1c0000-0000-4000-8000-000000000000&finding_id=9f3b2c1a7d4e5f60&tag=false-positive"
{  "status": "success"}
{  "status": "error",  "message": "Description of what went wrong."}
{  "status": "error",  "message": "Invalid or missing API key."}
{  "error": "This API key does not have the 'cases.write' permission (Write cases). An owner or admin can add it in the organization settings."}