18 Threat Intelligence APIs

Threat Intelligence APIs let you add threat intelligence capabilities without building from scratch. Every entry below is profiled with trust signals — pricing model, authentication requirements, CORS support, rate limits, and live uptime checks — so you can compare options and pick production-safe choices instead of guessing from a link list.

malwarephishingiocreputationscanningthreats
APIPricingAuthCORSHealth
AbuseIPDB
IP/domain/URL reputation
FreeAPI KeyNoProfile
AlienVault Open Threat Exchange (OTX)
IP/domain/URL reputation
FreeAPI KeyYesProfile
CAPEsandbox
Malware execution and analysis
FreeAPI KeyYesProfile
Dymo API
Fraud & reputation detection
FreeAPI KeyNoProfile
FishFish
A volunteer cybersecurity project focused on providing resources and services that improve safety across Discord
FreeNoYesProfile
Google Safe Browsing
Google Link/Domain Flagging
FreeAPI KeyNoProfile
IPWhois.net Blacklist API
Community IP blacklist to check and report abusive IP addresses
UnknownAPI KeyUnknownProfile
MalDatabase
Provide malware datasets and threat intelligence feeds
FreeAPI KeyYesProfile
MalShare
Malware Archive / file sourcing
FreeAPI KeyNoProfile
MalwareBazaar
Collect and share malware samples
FreeAPI KeyNoProfile
Metacert
Metacert Link Flagging
FreeAPI KeyNoProfile
NoPhishy API
Check links to see if they're known phishing attempts
UnknownAPI KeyYesProfile
Scanii
Simple REST API that can scan submitted documents/files for the presence of threats
FreemiumAPI KeyNoProfile
URLScan.io
Scan and Analyse URLs
FreemiumAPI KeyYesProfile
URLhaus
Bulk queries and Download Malware Samples
FreeNoNoProfile
Verisys Antivirus API
Antivirus as a service - REST API that scans provided files for malware and NSFW content
FreemiumAPI KeyNoProfile
VirusTotal
VirusTotal File/URL Analysis
FreemiumAPI KeyNoProfile
Web of Trust
IP/domain/URL reputation
FreemiumAPI KeyNoProfile

How to choose a threat intelligence API

Start with pricing and auth: free tiers and no-auth APIs are fastest to prototype with. Then check CORS if your app calls the API from the browser, and health before you commit — a great API that's been down for a week will block your launch. Each profile below shows all of these signals plus rate limits where documented.