Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
Shodan website screenshot

Shodan

Shodan is the world's first search engine for Internet-connected devices. It continuously crawls the public Internet to build a searchable database of servers, IoT devices, industrial control systems, routers, webcams, databases, and any other host that exposes a service. Shodan provides REST, Streaming, and Trends APIs along with on-demand scanning, network alerts, notifiers, DNS lookups, the InternetDB API, and the CVEDB vulnerability database. It is widely used for attack-surface management, security research, threat intelligence, vulnerability discovery, market research, and academic study of the Internet itself.

agent ready

Reference-quality API operations across every facet — a rich contract, published governance, transparent operations, and machine-readable commercial terms.

Kin Score

API Evangelist profiles Shodan the way a machine reads it — 109 machine-readable artifacts across 15 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Shodan scores 75.3/100 (exemplar), with a separate agent-readiness read of 54/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 75.3/100 · exemplar
Contract Quality 20.0 / 25
Developer Ergonomics 17.0 / 20
Commercial Clarity 16.8 / 20
Operational Transparency 6.8 / 13
Governance 7.9 / 12
Discoverability 6.8 / 10
Agent readiness — 54/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 6 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3

How we profile Shodan

Each block below is one kind of artifact we hold for Shodan. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 15

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

Shodan Account API

Account, profile, and API plan information.

Shodan Bulk Data API

Enterprise bulk data exports.

Shodan CPE API

The CPE API from Shodan — 1 operation(s) for cpe.

Shodan CVE API

The CVE API from Shodan — 2 operation(s) for cve.

Shodan Directory API

Browse and search saved Shodan queries.

Shodan DNS API

Forward, reverse, and domain DNS lookups.

Shodan InternetDB API

The InternetDB API from Shodan — 1 operation(s) for internetdb.

Shodan Network Alerts API

Create and manage alerts on monitored IP ranges.

Shodan Notifiers API

Manage notification providers used by alerts.

Shodan On-Demand Scanning API

Request crawls of specific IPs, netblocks, or the entire Internet.

Shodan Organization API

Enterprise organization management.

Shodan Search Methods API

Search and lookup endpoints for indexed devices.

Shodan Streaming API

The Streaming API from Shodan — 5 operation(s) for streaming.

Shodan Trends API

The Trends API from Shodan — 1 operation(s) for trends.

Shodan Utility API

Helper endpoints for HTTP headers and IP detection.

Scroll within the panel for all 15 ·

Postman Collections 5

A runnable collection turns the contract into something a developer can execute in seconds. We profile them because the fastest way to trust an API is to make a real call against it.

Ready-to-run Postman collections for exercising this provider's APIs.

Open Collections 5

Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Shodan CVEDB API

OPEN COLLECTION

Shodan InternetDB API

OPEN COLLECTION

Shodan REST API

OPEN COLLECTION

Shodan Streaming API

OPEN COLLECTION

Shodan Trends API

OPEN COLLECTION

Arazzo Workflows 15

Real integrations are rarely a single call. Arazzo describes the multi-step sequences — auth, then create, then confirm — so both a human and an agent can follow the choreography, not just the endpoints.

Multi-step API workflows described with the Arazzo specification.

Shodan Account Overview

Pull the account profile, API plan limits, and the client's own IP.

ARAZZO

Shodan Alert With Notifier

Create a notifier, attach it via an alert, and arm a trigger for delivery.

ARAZZO

Shodan CVEDB Product Vulnerability Enrichment

Resolve a product to a CPE, search its CVEs, then pull full CVE details.

ARAZZO

Shodan Domain Reconnaissance

Enumerate a domain's DNS records, resolve a subdomain, and inspect the host.

ARAZZO

Shodan InternetDB Vulnerability Triage

Pull an IP's free InternetDB record, then detail one of its known CVEs.

ARAZZO

Shodan Network Alert Lifecycle

Create a network alert, enable a trigger, verify it, then update the IP set.

ARAZZO

Shodan Notifier Lifecycle

Create a notifier, read it back, update it, then delete it.

ARAZZO

Shodan Query Directory Explorer

Browse popular query tags, search the saved-query directory, then run a match.

ARAZZO

Shodan Resolve Hostname and Inspect Host

Resolve a hostname to an IP and pull the full Shodan host record for that IP.

ARAZZO

Shodan Reverse DNS to Host Info

Reverse-resolve an IP to its hostnames, then pull the full host record.

ARAZZO

Shodan Scan Then Inspect Host

Submit a single-IP scan, poll until done, then pull the fresh host record.

ARAZZO

Shodan Search Builder

Discover available filters and facets, validate a query, then count its results.

ARAZZO

Shodan Search to Host Detail

Estimate a search, run it, then drill into the first matching host.

ARAZZO

Shodan Submit On-Demand Scan and Poll

Submit an on-demand scan and poll its status until the crawl completes.

ARAZZO

Shodan Historical Trends vs Live Exposure

Pull historical monthly trends for a query, then compare to the live count.

ARAZZO

Scroll within the panel for all 15 ·

Pricing Plans 1

Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.

Published pricing tiers and plan structures.

Shodan Plans Pricing

6 plans

PLANS

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Shodan Rate Limits

17 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.

Cost, billing, and metering signals for API financial operations.

Features 13

The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.

Notable capabilities this provider offers.

Internet-Wide Device Search

Search billions of indexed banners from servers, routers, webcams, industrial control systems, and IoT devices using a powerful query language with facets and filters.

Host Information Lookup

Retrieve all known information for an IP including open ports, service banners, geolocation, ASN/ISP, hostnames, vulnerabilities, SSL/TLS certificates, and detected technologies.

On-Demand Scanning

Submit IPs, CIDR ranges, or netblocks for an on-demand crawl using scan credits. Enterprise plans can request Internet-wide scans for a specific port or protocol.

Network Alerts and Notifiers

Create alerts on monitored IP ranges that fire when new services, changes, vulnerabilities, or expirations are detected, with delivery via Slack, email, webhook, and other notif...

DNS Lookup Suite

Forward, reverse, and full-domain DNS lookups including subdomain enumeration backed by Shodan's passive DNS database.

Streaming Firehose

Subscribe to real-time banner data filtered by ASN, country, port, or CVE for SIEMs, data lakes, and bespoke analytics pipelines.

Trends Analytics

Run faceted queries against the full historical scan database to analyze product adoption, regional exposure, and changes over time.

InternetDB Free Lookup

Open, key-free lookup that returns the open ports, CPEs, tags, and CVEs for any IPv4 address; refreshed weekly.

CVEDB Vulnerability Database

Open vulnerability lookup with CPE search, KEV filter, EPSS sorting, and date-range queries.

Bulk Data Exports

Enterprise-tier daily and on-demand bulk exports of Shodan's underlying datasets for offline analysis and warehousing.

Organization Management

Enterprise organization support for sharing credits and managing members through the API.

Saved Query Directory

Browse, search, and tag community-contributed Shodan queries covering common technologies, exposures, and devices.

Notifier Providers

Built-in notification provider integrations for Slack, email, Discord, Telegram, webhook, and more.

Scroll within the panel for all 13 ·

Event Specifications 1

Not every API is request/response. AsyncAPI describes the event-driven and streaming side — the webhooks and channels — so the asynchronous half of the interface is documented the same way the synchronous half is.

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Shodan Streaming API

Real-time streaming firehose of banner data collected by Shodan, delivered as newline-separated JSON or Server-Sent Events. Subscribers can consume the full firehose or filter b...

ASYNCAPI

Semantic Vocabularies 1

JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.

JSON-LD contexts and semantic vocabularies used across these APIs.

Shodan Context

8 classes · 46 properties

JSON-LD

Spectral Rules 3

Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.

Shodan API Rules

7 rules · 1 errors · 6 warnings

SPECTRAL

Shodan API Rules

5 rules · 4 warnings

SPECTRAL

Shodan API Rules

11 rules · 6 errors · 5 warnings

SPECTRAL

JSON Schema 11

Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.

Standalone JSON Schema definitions for this provider's data models.

Shodan CVEDB CPE

4 properties

JSON SCHEMA

Shodan CVEDB CVE

14 properties

JSON SCHEMA

Shodan InternetDB Host

6 properties

JSON SCHEMA

Shodan Network Alert

8 properties

JSON SCHEMA

Shodan Banner

19 properties

JSON SCHEMA

Shodan Host

20 properties

JSON SCHEMA

Shodan Notifier

4 properties

JSON SCHEMA

Shodan On-Demand Scan

5 properties

JSON SCHEMA

Shodan Search Result

3 properties

JSON SCHEMA

Shodan Streaming Banner

19 properties

JSON SCHEMA

Shodan Trends Result

3 properties

JSON SCHEMA

Scroll within the panel for all 11 ·

JSON Structure 3

JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.

JSON Structure definitions describing this provider's data shapes.

Shodan Rest Alert Structure

0 properties

JSON STRUCTURE

Shodan Rest Host Structure

0 properties

JSON STRUCTURE

Shodan Stream Banner Structure

0 properties

JSON STRUCTURE

Examples 8

Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.

Example request and response payloads for these APIs.

Scroll within the panel for all 8 ·

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Shodan Authentication

apiKey · 1 scheme

SECURITY

Shodan Domain Security

TLSv1.3 · DNSSEC · DMARC

SECURITY

Agentic Access 1

An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.

Recommended x-agentic-access execution contracts for AI agents.

Shodan Agentic Access

51 operations · 12 acting · 1 human-in-the-loop

51 operations · 12 acting

AGENTIC

Use Cases 8

What developers actually build with this provider — captured so the catalogue answers 'what is this for', not just 'what does this expose'.

What developers build with this provider.

Attack Surface Management

Continuously monitor an organization's external attack surface for new services, configuration drift, and vulnerable software.

Vulnerability Intelligence

Quantify exposure to specific CVEs across the Internet or a defined customer footprint using CVEDB and the search/trends APIs.

Threat Hunting and OSINT

Pivot from IPs, certificates, banners, and ASNs to map adversary infrastructure and discover related hosts.

Security Research

Study the distribution of misconfigured services, exposed databases, and emerging IoT ecosystems across the public Internet.

Competitive and Market Research

Track adoption of products, web servers, cloud providers, and frameworks across regions and industries using Trends.

Regulatory and Compliance Reporting

Demonstrate visibility into externally exposed assets for frameworks that require attack-surface inventories.

Insurance Underwriting

Inform cyber-insurance scoring with externally observable evidence of exposed services, vulnerabilities, and hygiene.

Incident Response

Triage IPs observed in alerts against Shodan history to determine who they are and what services they expose.

Scroll within the panel for all 8 ·

Integrations 10

Pre-built integrations with other platforms tell you where this provider already fits in a stack.

Pre-built integrations with other platforms and tools.

Splunk

Shodan data is widely ingested into Splunk for security analytics via the streaming API and the Splunk add-on ecosystem.

Maltego

Shodan transforms for Maltego enable graph-based pivoting on banners, certificates, and IPs.

Slack

Notifier integration delivers alert events to Slack channels.

Email

Notifier integration delivers alert events to mailboxes.

Webhook

Notifier integration posts alert events to arbitrary HTTPS endpoints.

Discord

Notifier integration delivers alert events to Discord servers.

Telegram

Notifier integration delivers alert events to Telegram chats.

Steampipe

Official Steampipe plugin lets you query Shodan host, DNS, and exploit data using standard SQL.

Model Context Protocol

Multiple community MCP servers expose Shodan tools to AI assistants including Claude, Cursor, and VS Code.

Nmap

Shodan's CLI ships helpers to enrich Nmap scan output with Shodan-derived banner context.

Scroll within the panel for all 10 ·

Solutions 5

Packaged solutions the provider offers on top of the raw API surface.

Packaged solutions this provider offers.

Shodan Monitor

Hosted attack-surface monitoring product built on the network alerts and notifiers APIs.

Enterprise Data Feed

Real-time firehose and daily bulk data exports for SOCs, threat intelligence platforms, and academic researchers.

InternetDB

Free, unauthenticated host lookup designed for embedding into security tools and dashboards.

CVEDB

Free vulnerability database with KEV and EPSS metadata for prioritization workflows.

Internet-Wide Scanning

Enterprise-only capability to request a scan of the entire Internet for a specific port or protocol.

Resources

Every other property we hold for Shodan — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Access & Security 3

Authentication, authorization, and security posture

Learn 2

Tutorials, courses, talks, and written guidance

Operate 3

Status, limits, changes, and where to get help

Company 3

The organization behind the API

Other 3

Properties that don't map to a standard resource type

← All providers · Data indexed from github.com/api-evangelist/shodan · machine-readable index on apis.io