Skip to main content

Product

Dark web monitoring API for leak-site and threat actor data

The DarkWebSonar API is a REST API that returns DarkWebSonar's dark web intelligence as JSON or CSV: ransomware and leak-site entries, event counts by country, industry, category or threat actor, and enriched threat-actor profiles with MITRE ATT&CK techniques. You can filter by victim organisation, victim domain, industry, country, region and time window. It authenticates with an X-API-Key header, comes with the Pro plan (1,000 requests a month) and Enterprise (5,000), and shares its credits with the DarkWebSonar MCP server.

On Pro, that is the intelligence feed and threat-actor data. Enterprise adds private credential lookup endpoints, documented for Enterprise customers. Twelve read-only GET endpoints. Parameters and schemas are in the API reference.

Base URL
https://api.darkwebsonar.io/v1
Auth
X-API-Key header
Formats
JSON, CSV
Plans
Pro, Enterprise

Example

Check a client list for new leak-site posts

Repeat victim_site once per domain. Up to 50 values, still one credit. A domain matches when the victim site contains that string. Store entry_hash and only act on hashes you have not seen. discovered_range=24h is when DarkWebSonar collected the entry, so a daily job also catches posts found after they were published.

Client leak-site check
GET/v1/entries/Up to 50 domains · 1 credit
curl -sG "https://api.darkwebsonar.io/v1/entries/" \
  -H "X-API-Key: $DWS_API_KEY" \
  --data-urlencode "victim_site=northwind.example" \
  --data-urlencode "victim_site=harborline.example" \
  --data-urlencode "discovered_range=24h" \
  --data-urlencode "include_total=false"
200 OKapplication/json · one entry, trimmed
{
  "skip": 0,
  "limit": 10,
  "data": [
    {
      "entry_hash": "15ec6efa9062…4504e6",
      "published_url": "http://shnyhnt…onion",
      "date": "2026-07-10T00:00:00Z",
      "category": "Ransomware",
      "title": "Northwind falls victim to ShinyHunters Ransomware",
      "content": "ShinyHunters claimed compromise of over 2.2 million records containing customer PII and internal corporate data from Northwind, threatening to leak the data by 18 June 2026 unless demands were met.",
      "threat_actors": "ShinyHunters",
      "victim_country": "United States",
      "victim_country_code": "USA",
      "victim_industry": "Technology & Telecom",
      "victim_organization": "Northwind",
      "victim_site": "northwind.example",
      "screenshots_full": "https://cdn.darkwebsonar.io/screenshots/full/15ec…_1.jpg",
      "screenshots_thumb": "",
      "network": "tor",
      "ingested_at": "2026-07-10T07:28:54.985089Z",
      "severity_score": 9.0,
      "technique_ids": ["T1486", "T1490", "T1027"],
      "has_extracted_content": false
    }
  ]
}

content summarises the leak-site post. Figures in it are the attacker's claims. Every field is described in the API reference. A scheduled pull, with pagination and retries, is in the integration guide.

Workflows

What you can build

The same feed supports a morning client check, a quarterly briefing, a SIEM pull, and an onboarding profile. The service around those jobs is in the MSP dark web monitoring guide.

  1. 01

    Daily client leak-site check

    The call above, once a day. A 50-domain roster is about 30 requests a month, inside Pro. A larger roster is one call per 50 domains. Open a ticket for each new entry_hash.

  2. 02

    Sector briefing

    GET /v1/entries/count_by_field?group_by=threat_actors&victim_industry=Healthcare&time_range=30d answers who hit healthcare this month. Industry values come from GET /v1/entries/facets. Healthcare matches Healthcare & Pharma.

  3. 03

    SIEM or data-lake pull

    Schedule discovered_range=2h or 24h, JSON or CSV, and dedupe on entry_hash. CSV through the API costs one credit per request, the same as JSON.

  4. 04

    Client onboarding profile

    GET /v1/threat_actor_profiles_enriched/?victim_country=US&activity_level=spiked, then /{id}?expand=techniques for MITRE techniques. US matches a stored USA.

Pricing

Plans, credits, and rate limits

Pro includes 1,000 API requests a month at up to 120 a minute. Enterprise includes 5,000 a month at up to 600 a minute. The rest of each plan is on pricing.

  • Starter$49/moNo API requests
    API access
    No
    Standard
    None
    CSV
    None
    History
    3 months
  • Growth$99/moNo API requests
    API access
    No
    Standard
    None
    CSV
    None
    History
    6 months
  • ProMost popular$199/mo1,000 requests/month
    API access
    Yes, including MCP: intel feed and threat actors
    Standard
    120/min
    CSV
    50/min
    History
    12 months
  • Enterprisefrom $499/mo5,000 requests/month
    API access
    Yes, including MCP, plus private credential lookup endpoints
    Standard
    600/min
    CSV
    200/min
    History
    Full

One request is one credit, REST or MCP, and unused credits do not roll over. Rate limits are per account, shared by every key. The 14-day trial does not include the API, and there is no free key.

CSV through the API (format=csv) costs one credit and uses the CSV limit. CSV downloads inside the platform do not. Enterprise “Full” history means omit time_range. Domain packs add monitored domains, not requests. Higher volume is Enterprise.

Delivery

Alerts, pulls, or a question

Pick the path that matches the job. Alert setup is on Integrations. The MCP server is on the MCP page.

When to use integrations, the REST API, or MCP
You wantUseNotes
An alert when a monitored domain, keyword, or actor gets a hitIntegrationsSlack, Microsoft Teams, PagerDuty, ServiceNow, email, or a signed custom webhook. Set up in the app. Starter includes 1, Growth 3, Pro 5, Enterprise unlimited.
Feed data on a schedule, in a SIEM, dashboard, or client reportREST APIPull with discovered_range and keep new rows by entry_hash.
An ad-hoc question in Claude, Cursor, or another MCP clientMCP serverSame monthly credits. One answer can spend several calls.

Custom webhooks are signed and created in the app, not through the API. Route one into a PSA such as HaloPSA, ConnectWise, or Autotask. DarkWebSonar does not ship native connectors for those products. Credential lookups stay off Pro; monitor client domains for leaked credentials in breach credential monitoring.

Common questions

Frequently asked questions

Is there an API for dark web monitoring?

Yes. DarkWebSonar has a REST API at https://api.darkwebsonar.io/v1 that returns dark web and ransomware leak-site entries, event counts, and enriched threat-actor profiles as JSON or CSV. You can filter by victim organisation, victim domain, industry, country, region, category, threat actor and time window. It authenticates with an X-API-Key header and comes with the Pro and Enterprise plans.

How many API requests do I get on each plan?

Pro ($199/month) includes 1,000 API requests a month, at up to 120 requests a minute (50 a minute for CSV exports). Enterprise (from $499/month) includes 5,000 a month, at up to 600 a minute (200 for CSV). Those ceilings are per account, shared by every key. One request uses one credit, whether it comes from REST or the MCP server, and unused credits do not roll over. Starter and Growth do not include API access.

Can I check whether a client's domain appeared on a ransomware leak site?

Yes. Call GET /v1/entries/ with victim_site set to the client domain (or victim_organization set to its name) and discovered_range=24h. The match is a substring, so the victim site only has to contain that domain. Repeat victim_site to check up to 50 domains in one call; that is still one credit. Store each entry_hash so you only act on new entries.

Should I use webhooks or poll the API?

Use webhooks and the built-in integrations (Slack, Microsoft Teams, PagerDuty, ServiceNow, email, or a custom webhook) when you want an alert as soon as a monitored domain, keyword, or threat actor gets a hit. Use the REST API for scheduled pulls into a SIEM, data lake, dashboard, or client report. Use the MCP server for ad-hoc questions in Claude or Cursor.

Is there a free tier or trial for the API?

No. API access, including the MCP server, starts on the Pro plan ($199/month, 1,000 requests a month). The 14-day free trial covers the DarkWebSonar platform and does not include REST or MCP access, and there is no free API key. For higher volumes, Enterprise starts at $499/month with 5,000 requests a month.

Can I look up leaked credentials through the API?

Not on Pro. The Pro API covers the intelligence feed and threat-actor data. Enterprise adds private credential lookup endpoints, and their documentation is shared with Enterprise customers. Credential monitoring for client domains stays in the platform.

Is there an SDK?

There is no official SDK. The API is plain REST with JSON, so any HTTP client works. The integration guide has curl and Python examples.

API access starts on Pro

1,000 requests a month, the intelligence feed, and threat-actor profiles. Need 5,000 or more requests a month, or credential lookup endpoints? Contact sales.

We use cookies to improve your experience

Help us understand how visitors interact with our website by collecting anonymous information (Google Analytics, Ahrefs, PostHog).