urlscan.io
for LuumenAI

Scan suspicious URLs, search urlscan data, and run Pro incidents from the terminal

Connect urlscan.io and your agent can pull scan evidence while you work — DOM snapshots, captured response content, hostname history, brand detections, and current API quota. When an investigation needs a new scan or a monitored incident, the agent writes to urlscan as a previewed step you approve. Luumen authenticates with an API key.

The urlscan.io toolbox

50 tools: 28 read, 22 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadDownload Captured FileRetrieve a captured binary file by its SHA-256 hash as a password-encrypted ZIP archive.
  • ReadGet Account CapabilitiesGet non-sensitive plan, product, feature, visibility, submission, and limit information for the connected urlscan.io API key.
  • ReadGet Brand SummaryReturn detectable brands with detected-page totals and latest hits.
  • ReadGet Notification ChannelGet one urlscan Pro notification channel by ID while preserving provider-specific metadata and removing webhook destinations or credentials.
  • ReadGet Data Dump Download LinkGenerate a temporary download URL for a path returned by LIST_DATA_DUMPS.
  • ReadGet Scan DOMReturn the plain-text DOM snapshot captured for a completed scan.
  • ReadGet Hostname HistoryReturn one page of historical Pro Hostnames observations for a hostname.
  • ReadGet IncidentGet one incident's configuration, source, runtime state, and timestamps.
  • ReadGet Incident StatesRetrieve the stored state history for an incident.
  • ReadGet Live Scan ResourceRetrieve one temporary result, DOM, screenshot, captured response, or download from the separate urlscan.io Live Scanning product.
  • ReadGet API QuotasGet current products, features, query capabilities, and per-action minute, hour, and day quota usage.
  • ReadGet Captured Response ContentReturn textual content captured in a scan response, addressed by its SHA-256 hash.
  • ReadGet Scan ResultRetrieve the complete metadata and captured request data for a completed scan UUID.
  • ReadGet Saved Search ResultsRun a urlscan Pro saved search and return its current Search API results.
  • ReadGet Scan ScreenshotRetrieve a completed urlscan.io scan screenshot as a downloadable PNG file reference.
  • ReadGet Similar Scan ResultsFind one page of scan results structurally similar to a specified scan.
  • ReadGet Subscription ResultsResolve a urlscan Pro alert subscription and datasource to its current Search API results.
  • ReadGet Available BrandsList brand identifiers and metadata tracked by urlscan.io brand and phishing detection.
  • ReadGet Available Scan CountriesList scanner country codes currently accepted by the Scan API.
  • ReadList Notification ChannelsList email and webhook notification channels for the current user without returning webhook URLs or embedded credentials.
  • ReadList Data DumpsList available urlscan.io data-dump files for a time window, file type, and date.
  • ReadList Live ScannersList Live Scanning nodes available to the connected account and their current metadata.
  • ReadList Saved SearchesList saved searches owned by or shared with the current user.
  • ReadList Alert SubscriptionsList alert subscriptions configured for the current user.
  • ReadGet Scan User AgentsList grouped browser user-agent strings available for scan submission.
  • ReadGet Watchable Incident AttributesList attribute values accepted when configuring incident change monitoring.
  • ReadLookup Malicious ObservableLook up malicious-scan occurrence counts and first/last seen timestamps for an IP, hostname, domain, or exact URL.
  • ReadSearch ScansSearch urlscan.io data with Elasticsearch Query String syntax and return one controllable page of results.
  • WriteClose IncidentStop ongoing scans for an active urlscan Pro incident and transition it to the closed state. Approval by default
  • WriteCopy IncidentCreate a separate urlscan Pro incident from an existing incident's configuration. Approval by default
  • WriteCreate Notification ChannelCreate a Pro notification channel. Approval by default
  • WriteCreate IncidentCreate a Pro incident that persistently monitors an observable. Approval by default
  • WriteRun Blocking Live ScanRun a temporary Live Scan synchronously and return only after the provider finishes the scan. Approval by default
  • WriteCreate Live Scan TaskStart a non-blocking temporary Live Scan on a selected scanner and return its UUID immediately without waiting for completion. Approval by default
  • WriteCreate Saved SearchCreate a reusable scans or hostnames search definition. Approval by default
  • WriteCreate Alert SubscriptionCreate a persistent scheduled or live alert subscription for saved searches. Approval by default
  • WriteDelete Scan ResultPermanently delete a scan owned by the connected user or team. Approval by default
  • WriteDelete Saved SearchPermanently delete a saved search by ID. Approval by default
  • WriteDelete Alert SubscriptionPermanently delete an alert subscription by ID. Approval by default
  • WriteFork IncidentCreate a new Pro incident by copying an existing incident's configuration and complete stored state history. Approval by default
  • WritePurge Live Scan ResultPermanently delete a temporary result from the separate urlscan.io Live Scanning product before its normal expiration. Approval by default
  • WriteReset Scan VisibilityRemove an owned scan's visibility override and restore the visibility originally assigned at submission. Approval by default
  • WriteRestart IncidentRestart a closed urlscan Pro incident and extend its expiry. Approval by default
  • WriteStore Live Scan ResultPermanently store an existing temporary Live Scan result with the selected visibility. Approval by default
  • WriteSubmit ScanSubmit a URL for asynchronous external scanning, creating persistent result state and consuming quota. Approval by default
  • WriteUpdate Notification ChannelReplace the complete configuration of an existing Pro notification channel. Approval by default
  • WriteUpdate IncidentReplace an existing incident's monitoring configuration and runtime options. Approval by default
  • WriteUpdate Scan VisibilityChange the visibility of a scan owned by the connected user or team. Approval by default
  • WriteUpdate Saved SearchReplace the complete definition and metadata of an existing saved search. Approval by default
  • WriteUpdate Alert SubscriptionReplace the complete configuration of an existing alert subscription. Approval by default

One prompt, start to finish

What a governed urlscan.io run looks like inside Luumen.

Questions

How does LuumenAI connect to urlscan.io?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in urlscan.io on its own?

Read actions answer immediately. Anything that writes — close incident, copy incident, create notification channel, create incident, and more — is shown as a plan and requires approval by default, including the 5 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to urlscan.io — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put urlscan.io to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.