Build With Deepinfo Data, in Code or in the Platform

Look up and search Deepinfo's internet-wide domain, DNS, WHOIS, SSL, dark web and vulnerability data, and work with your External Attack Surface Management, Cyber Threat Intelligence and Brand Risk Protection findings, from your own code or in the Deepinfo Platform.

Your First Request

GET/lookup/whois

Reference: Domain WHOIS
curl 'https://api.deepinfo.com/v1/lookup/whois?domain=deepinfo.com' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'

Response: 200 OK · application/json

{
  "domain_name": "deepinfo.com",
  "parsed": {
    "create_date": "2001-06-05T02:57:08Z",
    "expiry_date": "2028-10-20T11:59:59Z",
    "registrar": "godaddy online services cayman islands ltd.",
    "name_servers": [
      "may.ns.cloudflare.com",
      "simon.ns.cloudflare.com"
    ],
    …
  },
  …
}

Your API key goes in the apikey header.Get an API key

Production or Demo?

Every account belongs to one environment: paid customer accounts use Production, demo accounts use Demo. Open the API reference in yours below. The code samples and platform links follow it, and the Environment switch at the top of the API Reference sidebar changes it.

Environments & Base URL

  • Production

    Paid (customer) account

    Platform
    platform.deepinfo.com
    API base URL
    https://api.deepinfo.com/v1

    API reference in Production

  • Demo

    Demo account

    Platform
    platform.deepinfodemo.com
    API base URL
    https://api.deepinfodemo.com/v1

    API reference in Demo

Getting Started

What every request has in common: your API key, the base URL, rate limits, pagination, search filters and errors.

  • Authentication

    Every Deepinfo API request is authenticated with your API key in the apikey header.

  • Environments & Base URL

    Paid accounts use the Production addresses and demo accounts the Demo addresses; the version is the first path segment, bodies are JSON and timestamps UTC.

  • Rate Limits

    Limits apply per API key and per endpoint; responses carry ratelimit headers that show where you stand.

  • Pagination

    Paginated endpoints take page and page_size and share one response envelope.

  • Search & Filters

    The filters body used by search endpoints, its operators, which operators each field accepts, the errors a filter returns, and query-parameter filters on list endpoints.

  • Errors

    The Deepinfo error formats, the status codes they use, the forms a search filter error takes, and an example request and response for each one.

  • Postman Collection

    Every Deepinfo API endpoint as a Postman collection. Download it with the Production environment, add your API key and send requests.

Deep Search & Insights (DSI)

Deepinfo's internet-wide dataset: look up and search domains, IP addresses, DNS, WHOIS and SSL records, dark web sources, vulnerabilities and domain registration statistics, or download it as data feeds.

  • Lookup

    Look up a single domain, host, IP address or website, either in real time or from Deepinfo's history.

  • Discovery

    Search Deepinfo's internet-wide domain dataset: find subdomains, associated domains, domains registered at the same time, and domains that share a WHOIS email, name server, IP or mail server.

  • Darkweb

    Search dark web sources (forums, markets, paste sites, chats, leaks).

  • Vulnerability

    Deepinfo's vulnerability (CVE) database: search, CVE details, EPSS history and global statistics.

  • Domain Intelligence

    Global domain registration statistics.

  • Feeds

    Download Deepinfo data feeds (all domains/subdomains, daily registered/updated/deleted domains, daily discovered subdomains).

Platform APIs

Your organization's data in the Deepinfo Platform: its EASM, CTI and BRP findings, notifications and reports.

  • EASMExternal Attack Surface Management

    Your monitored assets (domains, subdomains, IPs, websites), what Deepinfo discovers around them, and the issues, vulnerabilities and technologies found on them.

    • Assets
    • Asset Tags
    • Deleted Assets
    • Asset History
    • Open Ports
    • Asset Timelines
    • Snapshots
    • Dashboard
    • Discovery
    • Issues
    • Vulnerabilities
    • Technologies
  • CTICyber Threat Intelligence

    Email breaches, compromised employee/client/payment credentials, compromised devices, threat actors and security news relevant to your organization.

    • Email Breaches
    • Compromised Employee Accounts
    • Compromised Employee Credentials
    • Compromised Client Credentials
    • Compromised Payment Credentials
    • Compromised Devices
    • Threat Actors
    • Security News
  • BRPBrand Risk Protection

    Domains that imitate your brand.

    • Settings
    • Fraudulent Domains
    • Suspicious Domains
    • Fraudulent Rules
  • Platform

    Notifications and reports.

    • Notifications
    • Reports
    • Scheduled Reports

Latest Changes

    • API
    • Docs

    The New Deepinfo Documentation Site

    docs.deepinfo.com now documents every API endpoint, generated from the Deepinfo Postman collection, with Getting Started guides, search and a Markdown version of every page.

    • API
    • Docs

    Operator Support per Field

    Search endpoints now list their searchable fields grouped by the operators each field accepts, measured against the API, and the docs show the forms a filter error takes.

    • Platform
    • Guide

    A Guide to the Deepinfo Platform

    A new section of the documentation explains the Deepinfo Platform screen by screen, from your first sign-in to reports and notification rules.

Get Help From Deepinfo Support

Which endpoints you can call depends on your plan. For access, API keys and questions about a request, email Deepinfo support. About a specific request? Include its deepinfo-request-id response header.