Product
Dark web monitoring API for leak-site and threat actor data
The DarkWebSonar API is a REST API that returns DarkWebSonar's dark web intelligence as JSON or CSV: ransomware and leak-site entries, event counts by country, industry, category or threat actor, and enriched threat-actor profiles with MITRE ATT&CK techniques. You can filter by victim organisation, victim domain, industry, country, region and time window. It authenticates with an X-API-Key header, comes with the Pro plan (1,000 requests a month) and Enterprise (5,000), and shares its credits with the DarkWebSonar MCP server.
On Pro, that is the intelligence feed and threat-actor data. Enterprise adds private credential lookup endpoints, documented for Enterprise customers. Twelve read-only GET endpoints. Parameters and schemas are in the API reference.
- Base URL
- https://api.darkwebsonar.io/v1
- Auth
- X-API-Key header
- Formats
- JSON, CSV
- Plans
- Pro, Enterprise
Example
Check a client list for new leak-site posts
Repeat victim_site once per domain. Up to 50 values, still one credit. A domain matches when the victim site contains that string. Store entry_hash and only act on hashes you have not seen. discovered_range=24h is when DarkWebSonar collected the entry, so a daily job also catches posts found after they were published.
curl -sG "https://api.darkwebsonar.io/v1/entries/" \
-H "X-API-Key: $DWS_API_KEY" \
--data-urlencode "victim_site=northwind.example" \
--data-urlencode "victim_site=harborline.example" \
--data-urlencode "discovered_range=24h" \
--data-urlencode "include_total=false"{
"skip": 0,
"limit": 10,
"data": [
{
"entry_hash": "15ec6efa9062…4504e6",
"published_url": "http://shnyhnt…onion",
"date": "2026-07-10T00:00:00Z",
"category": "Ransomware",
"title": "Northwind falls victim to ShinyHunters Ransomware",
"content": "ShinyHunters claimed compromise of over 2.2 million records containing customer PII and internal corporate data from Northwind, threatening to leak the data by 18 June 2026 unless demands were met.",
"threat_actors": "ShinyHunters",
"victim_country": "United States",
"victim_country_code": "USA",
"victim_industry": "Technology & Telecom",
"victim_organization": "Northwind",
"victim_site": "northwind.example",
"screenshots_full": "https://cdn.darkwebsonar.io/screenshots/full/15ec…_1.jpg",
"screenshots_thumb": "",
"network": "tor",
"ingested_at": "2026-07-10T07:28:54.985089Z",
"severity_score": 9.0,
"technique_ids": ["T1486", "T1490", "T1027"],
"has_extracted_content": false
}
]
}content summarises the leak-site post. Figures in it are the attacker's claims. Every field is described in the API reference. A scheduled pull, with pagination and retries, is in the integration guide.
Workflows
What you can build
The same feed supports a morning client check, a quarterly briefing, a SIEM pull, and an onboarding profile. The service around those jobs is in the MSP dark web monitoring guide.
- 01
Daily client leak-site check
The call above, once a day. A 50-domain roster is about 30 requests a month, inside Pro. A larger roster is one call per 50 domains. Open a ticket for each new
entry_hash. - 02
Sector briefing
GET /v1/entries/count_by_field?answers who hit healthcare this month. Industry values come fromgroup_by=threat_actors& victim_industry=Healthcare& time_range=30d GET /v1/entries/facets. Healthcare matches Healthcare & Pharma. - 03
SIEM or data-lake pull
Schedule
discovered_range=2hor24h, JSON or CSV, and dedupe onentry_hash. CSV through the API costs one credit per request, the same as JSON. - 04
Client onboarding profile
GET /v1/threat_actor_profiles_enriched/?, thenvictim_country=US& activity_level=spiked /{id}?expand=techniquesfor MITRE techniques.USmatches a storedUSA.
Pricing
Plans, credits, and rate limits
Pro includes 1,000 API requests a month at up to 120 a minute. Enterprise includes 5,000 a month at up to 600 a minute. The rest of each plan is on pricing.
| Plan | Price | API access | Requests / month | Standard | CSV | History |
|---|---|---|---|---|---|---|
| Starter | $49/mo | No | None | None | None | 3 months |
| Growth | $99/mo | No | None | None | None | 6 months |
| ProMost popular | $199/mo | Yes, including MCP: intel feed and threat actors | 1,000 | 120/min | 50/min | 12 months |
| Enterprise | from $499/mo | Yes, including MCP, plus private credential lookup endpoints | 5,000 | 600/min | 200/min | Full |
Starter$49/moNo API requests
- API access
- No
- Standard
- None
- CSV
- None
- History
- 3 months
Growth$99/moNo API requests
- API access
- No
- Standard
- None
- CSV
- None
- History
- 6 months
ProMost popular$199/mo1,000 requests/month
- API access
- Yes, including MCP: intel feed and threat actors
- Standard
- 120/min
- CSV
- 50/min
- History
- 12 months
Enterprisefrom $499/mo5,000 requests/month
- API access
- Yes, including MCP, plus private credential lookup endpoints
- Standard
- 600/min
- CSV
- 200/min
- History
- Full
One request is one credit, REST or MCP, and unused credits do not roll over. Rate limits are per account, shared by every key. The 14-day trial does not include the API, and there is no free key.
CSV through the API (format=csv) costs one credit and uses the CSV limit. CSV downloads inside the platform do not. Enterprise “Full” history means omit time_range. Domain packs add monitored domains, not requests. Higher volume is Enterprise.
Delivery
Alerts, pulls, or a question
Pick the path that matches the job. Alert setup is on Integrations. The MCP server is on the MCP page.
| You want | Use | Notes |
|---|---|---|
| An alert when a monitored domain, keyword, or actor gets a hit | Integrations | Slack, Microsoft Teams, PagerDuty, ServiceNow, email, or a signed custom webhook. Set up in the app. Starter includes 1, Growth 3, Pro 5, Enterprise unlimited. |
| Feed data on a schedule, in a SIEM, dashboard, or client report | REST API | Pull with discovered_range and keep new rows by entry_hash. |
| An ad-hoc question in Claude, Cursor, or another MCP client | MCP server | Same monthly credits. One answer can spend several calls. |
Custom webhooks are signed and created in the app, not through the API. Route one into a PSA such as HaloPSA, ConnectWise, or Autotask. DarkWebSonar does not ship native connectors for those products. Credential lookups stay off Pro; monitor client domains for leaked credentials in breach credential monitoring.
Common questions
Frequently asked questions
Is there an API for dark web monitoring?
Yes. DarkWebSonar has a REST API at https://api.darkwebsonar.io/v1 that returns dark web and ransomware leak-site entries, event counts, and enriched threat-actor profiles as JSON or CSV. You can filter by victim organisation, victim domain, industry, country, region, category, threat actor and time window. It authenticates with an X-API-Key header and comes with the Pro and Enterprise plans.
How many API requests do I get on each plan?
Pro ($199/month) includes 1,000 API requests a month, at up to 120 requests a minute (50 a minute for CSV exports). Enterprise (from $499/month) includes 5,000 a month, at up to 600 a minute (200 for CSV). Those ceilings are per account, shared by every key. One request uses one credit, whether it comes from REST or the MCP server, and unused credits do not roll over. Starter and Growth do not include API access.
Can I check whether a client's domain appeared on a ransomware leak site?
Yes. Call GET /v1/entries/ with victim_site set to the client domain (or victim_organization set to its name) and discovered_range=24h. The match is a substring, so the victim site only has to contain that domain. Repeat victim_site to check up to 50 domains in one call; that is still one credit. Store each entry_hash so you only act on new entries.
Should I use webhooks or poll the API?
Use webhooks and the built-in integrations (Slack, Microsoft Teams, PagerDuty, ServiceNow, email, or a custom webhook) when you want an alert as soon as a monitored domain, keyword, or threat actor gets a hit. Use the REST API for scheduled pulls into a SIEM, data lake, dashboard, or client report. Use the MCP server for ad-hoc questions in Claude or Cursor.
Is there a free tier or trial for the API?
No. API access, including the MCP server, starts on the Pro plan ($199/month, 1,000 requests a month). The 14-day free trial covers the DarkWebSonar platform and does not include REST or MCP access, and there is no free API key. For higher volumes, Enterprise starts at $499/month with 5,000 requests a month.
Can I look up leaked credentials through the API?
Not on Pro. The Pro API covers the intelligence feed and threat-actor data. Enterprise adds private credential lookup endpoints, and their documentation is shared with Enterprise customers. Credential monitoring for client domains stays in the platform.
Is there an SDK?
There is no official SDK. The API is plain REST with JSON, so any HTTP client works. The integration guide has curl and Python examples.
API access starts on Pro
1,000 requests a month, the intelligence feed, and threat-actor profiles. Need 5,000 or more requests a month, or credential lookup endpoints? Contact sales.