Shodan
Shodan is the world's first search engine for Internet-connected devices. It continuously crawls the public Internet to build a searchable database of servers, IoT devices, industrial control systems, routers, webcams, databases, and any other host that exposes a service. Shodan provides REST, Streaming, and Trends APIs along with on-demand scanning, network alerts, notifiers, DNS lookups, the InternetDB API, and the CVEDB vulnerability database. It is widely used for attack-surface management, security research, threat intelligence, vulnerability discovery, market research, and academic study of the Internet itself.
Reference-quality API operations across every facet — a rich contract, published governance, transparent operations, and machine-readable commercial terms.
API Evangelist profiles Shodan the way a machine reads it — 109 machine-readable artifacts across 15 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Shodan scores 75.3/100 (exemplar), with a separate agent-readiness read of 54/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.
How we profile Shodan
Each block below is one kind of artifact we hold for Shodan. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
APIs 15
Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.
Individual APIs this provider publishes, each with its own machine-readable definition.
Shodan Account API
Account, profile, and API plan information.
Shodan Bulk Data API
Enterprise bulk data exports.
Shodan CPE API
The CPE API from Shodan — 1 operation(s) for cpe.
Shodan CVE API
The CVE API from Shodan — 2 operation(s) for cve.
Shodan Directory API
Browse and search saved Shodan queries.
Shodan DNS API
Forward, reverse, and domain DNS lookups.
Shodan InternetDB API
The InternetDB API from Shodan — 1 operation(s) for internetdb.
Shodan Network Alerts API
Create and manage alerts on monitored IP ranges.
Shodan Notifiers API
Manage notification providers used by alerts.
Shodan On-Demand Scanning API
Request crawls of specific IPs, netblocks, or the entire Internet.
Shodan Organization API
Enterprise organization management.
Shodan Search Methods API
Search and lookup endpoints for indexed devices.
Shodan Streaming API
The Streaming API from Shodan — 5 operation(s) for streaming.
Shodan Trends API
The Trends API from Shodan — 1 operation(s) for trends.
Shodan Utility API
Helper endpoints for HTTP headers and IP detection.
Scroll within the panel for all 15 ·
Postman Collections 5
A runnable collection turns the contract into something a developer can execute in seconds. We profile them because the fastest way to trust an API is to make a real call against it.
Ready-to-run Postman collections for exercising this provider's APIs.
Shodan CVEDB API
POSTMANShodan InternetDB API
POSTMANShodan REST API
POSTMANShodan Streaming API
POSTMANShodan Trends API
POSTMANOpen Collections 5
Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Shodan CVEDB API
OPEN COLLECTIONShodan InternetDB API
OPEN COLLECTIONShodan REST API
OPEN COLLECTIONShodan Streaming API
OPEN COLLECTIONShodan Trends API
OPEN COLLECTIONArazzo Workflows 15
Real integrations are rarely a single call. Arazzo describes the multi-step sequences — auth, then create, then confirm — so both a human and an agent can follow the choreography, not just the endpoints.
Multi-step API workflows described with the Arazzo specification.
Shodan Alert With Notifier
Create a notifier, attach it via an alert, and arm a trigger for delivery.
ARAZZOShodan CVEDB Product Vulnerability Enrichment
Resolve a product to a CPE, search its CVEs, then pull full CVE details.
ARAZZOShodan Domain Reconnaissance
Enumerate a domain's DNS records, resolve a subdomain, and inspect the host.
ARAZZOShodan InternetDB Vulnerability Triage
Pull an IP's free InternetDB record, then detail one of its known CVEs.
ARAZZOShodan Network Alert Lifecycle
Create a network alert, enable a trigger, verify it, then update the IP set.
ARAZZOShodan Query Directory Explorer
Browse popular query tags, search the saved-query directory, then run a match.
ARAZZOShodan Resolve Hostname and Inspect Host
Resolve a hostname to an IP and pull the full Shodan host record for that IP.
ARAZZOShodan Reverse DNS to Host Info
Reverse-resolve an IP to its hostnames, then pull the full host record.
ARAZZOShodan Scan Then Inspect Host
Submit a single-IP scan, poll until done, then pull the fresh host record.
ARAZZOShodan Search Builder
Discover available filters and facets, validate a query, then count its results.
ARAZZOShodan Search to Host Detail
Estimate a search, run it, then drill into the first matching host.
ARAZZOShodan Submit On-Demand Scan and Poll
Submit an on-demand scan and poll its status until the crawl completes.
ARAZZOShodan Historical Trends vs Live Exposure
Pull historical monthly trends for a query, then compare to the live count.
ARAZZOScroll within the panel for all 15 ·
Pricing Plans 1
Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.
Published pricing tiers and plan structures.
Shodan Plans Pricing
PLANSRate Limits 1
Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.
Documented rate limits and quota policies.
Shodan Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.
Cost, billing, and metering signals for API financial operations.
Shodan Finops
FINOPSFeatures 13
The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.
Notable capabilities this provider offers.
Internet-Wide Device Search
Search billions of indexed banners from servers, routers, webcams, industrial control systems, and IoT devices using a powerful query language with facets and filters.
Host Information Lookup
Retrieve all known information for an IP including open ports, service banners, geolocation, ASN/ISP, hostnames, vulnerabilities, SSL/TLS certificates, and detected technologies.
On-Demand Scanning
Submit IPs, CIDR ranges, or netblocks for an on-demand crawl using scan credits. Enterprise plans can request Internet-wide scans for a specific port or protocol.
Network Alerts and Notifiers
Create alerts on monitored IP ranges that fire when new services, changes, vulnerabilities, or expirations are detected, with delivery via Slack, email, webhook, and other notif...
DNS Lookup Suite
Forward, reverse, and full-domain DNS lookups including subdomain enumeration backed by Shodan's passive DNS database.
Streaming Firehose
Subscribe to real-time banner data filtered by ASN, country, port, or CVE for SIEMs, data lakes, and bespoke analytics pipelines.
Trends Analytics
Run faceted queries against the full historical scan database to analyze product adoption, regional exposure, and changes over time.
InternetDB Free Lookup
Open, key-free lookup that returns the open ports, CPEs, tags, and CVEs for any IPv4 address; refreshed weekly.
CVEDB Vulnerability Database
Open vulnerability lookup with CPE search, KEV filter, EPSS sorting, and date-range queries.
Bulk Data Exports
Enterprise-tier daily and on-demand bulk exports of Shodan's underlying datasets for offline analysis and warehousing.
Organization Management
Enterprise organization support for sharing credits and managing members through the API.
Saved Query Directory
Browse, search, and tag community-contributed Shodan queries covering common technologies, exposures, and devices.
Notifier Providers
Built-in notification provider integrations for Slack, email, Discord, Telegram, webhook, and more.
Scroll within the panel for all 13 ·
Event Specifications 1
Not every API is request/response. AsyncAPI describes the event-driven and streaming side — the webhooks and channels — so the asynchronous half of the interface is documented the same way the synchronous half is.
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Shodan Streaming API
Real-time streaming firehose of banner data collected by Shodan, delivered as newline-separated JSON or Server-Sent Events. Subscribers can consume the full firehose or filter b...
ASYNCAPISemantic Vocabularies 1
JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.
JSON-LD contexts and semantic vocabularies used across these APIs.
Shodan Context
JSON-LDSpectral Rules 3
Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.
JSON Schema 11
Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.
Standalone JSON Schema definitions for this provider's data models.
Shodan CVEDB CPE
JSON SCHEMAShodan CVEDB CVE
JSON SCHEMAShodan InternetDB Host
JSON SCHEMAShodan Network Alert
JSON SCHEMAShodan Banner
JSON SCHEMAShodan Host
JSON SCHEMAShodan Notifier
JSON SCHEMAShodan On-Demand Scan
JSON SCHEMAShodan Search Result
JSON SCHEMAShodan Streaming Banner
JSON SCHEMAShodan Trends Result
JSON SCHEMAScroll within the panel for all 11 ·
JSON Structure 3
JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.
JSON Structure definitions describing this provider's data shapes.
Shodan Rest Alert Structure
JSON STRUCTUREShodan Rest Host Structure
JSON STRUCTUREShodan Stream Banner Structure
JSON STRUCTUREExamples 8
Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.
Example request and response payloads for these APIs.
Shodan Rest Search Example
EXAMPLEShodan Stream Banner Example
EXAMPLEShodan Trends Search Example
EXAMPLEScroll within the panel for all 8 ·
Security Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 8
What developers actually build with this provider — captured so the catalogue answers 'what is this for', not just 'what does this expose'.
What developers build with this provider.
Attack Surface Management
Continuously monitor an organization's external attack surface for new services, configuration drift, and vulnerable software.
Vulnerability Intelligence
Quantify exposure to specific CVEs across the Internet or a defined customer footprint using CVEDB and the search/trends APIs.
Threat Hunting and OSINT
Pivot from IPs, certificates, banners, and ASNs to map adversary infrastructure and discover related hosts.
Security Research
Study the distribution of misconfigured services, exposed databases, and emerging IoT ecosystems across the public Internet.
Competitive and Market Research
Track adoption of products, web servers, cloud providers, and frameworks across regions and industries using Trends.
Regulatory and Compliance Reporting
Demonstrate visibility into externally exposed assets for frameworks that require attack-surface inventories.
Insurance Underwriting
Inform cyber-insurance scoring with externally observable evidence of exposed services, vulnerabilities, and hygiene.
Incident Response
Triage IPs observed in alerts against Shodan history to determine who they are and what services they expose.
Scroll within the panel for all 8 ·
Integrations 10
Pre-built integrations with other platforms tell you where this provider already fits in a stack.
Pre-built integrations with other platforms and tools.
Splunk
Shodan data is widely ingested into Splunk for security analytics via the streaming API and the Splunk add-on ecosystem.
Maltego
Shodan transforms for Maltego enable graph-based pivoting on banners, certificates, and IPs.
Slack
Notifier integration delivers alert events to Slack channels.
Notifier integration delivers alert events to mailboxes.
Webhook
Notifier integration posts alert events to arbitrary HTTPS endpoints.
Discord
Notifier integration delivers alert events to Discord servers.
Telegram
Notifier integration delivers alert events to Telegram chats.
Steampipe
Official Steampipe plugin lets you query Shodan host, DNS, and exploit data using standard SQL.
Model Context Protocol
Multiple community MCP servers expose Shodan tools to AI assistants including Claude, Cursor, and VS Code.
Nmap
Shodan's CLI ships helpers to enrich Nmap scan output with Shodan-derived banner context.
Scroll within the panel for all 10 ·
Solutions 5
Packaged solutions the provider offers on top of the raw API surface.
Packaged solutions this provider offers.
Shodan Monitor
Hosted attack-surface monitoring product built on the network alerts and notifiers APIs.
Enterprise Data Feed
Real-time firehose and daily bulk data exports for SOCs, threat intelligence platforms, and academic researchers.
InternetDB
Free, unauthenticated host lookup designed for embedding into security tools and dashboards.
CVEDB
Free vulnerability database with KEV and EPSS metadata for prioritization workflows.
Internet-Wide Scanning
Enterprise-only capability to request a scan of the entire Internet for a specific port or protocol.
Resources
Every other property we hold for Shodan — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 6
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 17
Pagination, idempotency, versioning, errors, and events
Scroll within the panel for all 17 ·
Build 35
SDKs, sample code, and the tooling you integrate with
Scroll within the panel for all 35 ·
Access & Security 3
Authentication, authorization, and security posture
Learn 2
Tutorials, courses, talks, and written guidance
Operate 3
Status, limits, changes, and where to get help
Commercial 6
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 3
Properties that don't map to a standard resource type
← All providers · Data indexed from github.com/api-evangelist/shodan · machine-readable index on apis.io