# Getting Started

Authenticate with your API key, send your first Deepinfo API request and find your way around the reference.

Source: https://docs.deepinfo.com/getting-started/

Last updated: 2026-10-05

---
The Deepinfo API gives you programmatic access to Deepinfo's internet-wide domain, DNS, WHOIS, SSL and
vulnerability data, and to your Deepinfo Platform modules: External Attack Surface Management (EASM), Cyber Threat Intelligence (CTI), Brand Risk Protection (BRP) and Platform.

Every endpoint is served over HTTPS, and the API version is the first path segment:

```text
https://api.deepinfo.com/v1/<module>/<endpoint>
```

> [!NOTE]
> **Demo account?** The examples use the Production addresses. Choose **Demo** in the **Environment**
> switch at the top of the API Reference sidebar (or open the API reference from the **Demo** card on
> the home page) to show the Demo addresses. See
> [Environments & Base URL](/getting-started/environments-and-base-url/).

## Quick Start

**1. Get an API key.** Your key authenticates every request and decides which endpoints you can call.
Generate one in the Deepinfo Platform under **Settings → Organization Settings → API Keys** (see
[Get an API key](/getting-started/authentication/#get-an-api-key)). No platform access? Contact
[support@deepinfo.com](mailto:support@deepinfo.com).

**2. Send it in the `apikey` header.** Every request carries it. See
[Authentication](/getting-started/authentication/).

**3. Make your first call.** [Domain WHOIS](/reference/lookup/domain-whois/) returns the current WHOIS registration
record of a domain:

```bash
curl "https://api.deepinfo.com/v1/lookup/whois?domain=deepinfo.com" \
  -H "apikey: YOUR_API_KEY" \
  -H "Accept: application/json"
```

A successful response returns the parsed WHOIS record together with the raw WHOIS text:

```json
{
  "domain_name": "deepinfo.com",
  "raw": "Domain Name: DEEPINFO.COM\n   Registry Domain ID: 71858956_DOMAIN_COM-VRSN\n   ...",
  "parsed": {
    "create_date": "2001-06-05T02:57:08Z",
    "update_date": "2025-08-19T07:33:45Z",
    "expiry_date": "2028-10-20T11:59:59Z",
    "registrar": "godaddy online services cayman islands ltd.",
    "name_servers": ["may.ns.cloudflare.com", "simon.ns.cloudflare.com"],
    "whois_server": "whois.uniregistrar.com"
  },
  "check_date": "2026-09-22T12:25:50Z",
  "parse_code": null
}
```

> [!NOTE]
> The response above is shortened: `raw` is truncated, and `parsed.uid`, the registrant contact and the
> domain status codes are left out. The full field list and the complete saved example are on the
> [Domain WHOIS](/reference/lookup/domain-whois/) reference page.

## What to Read Next

| Page | What it covers |
|---|---|
| [Authentication](/getting-started/authentication/) | Getting and replacing a key, the `apikey` header, and what 401 and 403 mean |
| [Environments & base URL](/getting-started/environments-and-base-url/) | Host, version, content types, date format, expiring download links |
| [Rate limits](/getting-started/rate-limits/) | Per-key and per-endpoint limits, the `ratelimit-*` headers, quota |
| [Pagination](/getting-started/pagination/) | `page`, `page_size` and the list envelope |
| [Search & filters](/getting-started/search-and-filters/) | The `filters` body used by `search` endpoints, and query-parameter filters for list endpoints |
| [Errors](/getting-started/errors/) | The error formats, the status codes and example responses |

## The Modules

| Module | What it covers |
|---|---|
| Lookup | Real-time and historical lookups for a single domain, IP, host or website: WHOIS, DNS, IP WHOIS, SSL, port scan, technologies, screenshots, web data |
| Discovery | Search Deepinfo's domain dataset: subdomains, associated domains, reverse WHOIS/NS/IP/MX, TLDs |
| Darkweb | Search dark web sources |
| Vulnerability | Vulnerability (CVE) search, details and insights |
| Domain Intelligence | Domain registration statistics |
| Feeds | Download domain and subdomain data feeds |
| EASM | Your assets, discovery, issues, vulnerabilities and technologies |
| CTI | Email breaches, compromised credentials and devices, threat actors, security news |
| BRP | Fraudulent and suspicious domains, detection rules |
| Platform | Notification rules, reports and scheduled reports |

Which endpoints you can call depends on your plan. Browse them all in the
[API reference](/reference/).

## In Postman

Every endpoint of this reference is also in the Deepinfo Postman collection: download it with the
buttons above, and [Postman Collection](/getting-started/postman/) shows how to set it up in a few steps.

## Support

When you contact [support@deepinfo.com](mailto:support@deepinfo.com) about a request, include the value of
the `deepinfo-request-id` response header. It identifies that exact call.
