urlscan.io for AI agents
urlscan.io scans and analyzes websites for threat intelligence, used by security teams investigating suspicious URLs and tracking phishing infrastructure. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in urlscan.io.
Scan a URL
Submit a URL for a live scan and get back its behavior and screenshot.
Get a scan result
Pull a prior scan's findings as a read-only lookup.
Confirm before deleting a saved search
Check with the user before deleting a saved search, since it may be used by an ongoing investigation.
51 urlscan.io actions, graded by risk.
Every urlscan.io action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
29Look things up. Allowed by default.
- urlscan_io.get_domGet Scan DOM
- urlscan_io.get_quotasGet API Quotas
- urlscan_io.get_resultGet Scan Result
- urlscan_io.get_channelGet Notification Channel
- urlscan_io.get_incidentGet Incident
- urlscan_io.search_scansSearch Scans
- urlscan_io.get_phishfeedGet Deprecated Phishing Feed
- urlscan_io.list_channelsList Notification Channels
- urlscan_io.get_screenshotGet Scan Screenshot
- urlscan_io.list_data_dumpsList Data Dumps
- urlscan_io.list_user_agentsGet Scan User Agents
- urlscan_io.get_brand_summaryGet Brand Summary
- urlscan_io.get_data_dump_linkGet Data Dump Download Link
- urlscan_io.list_live_scannersList Live Scanners
- urlscan_io.list_subscriptionsList Alert Subscriptions
- urlscan_io.get_incident_statesGet Incident States
write
16Create and change things. Allow, or ask the user first.
- urlscan_io.create_channelCreate Notification Channel
- urlscan_io.update_channelUpdate Notification Channel
- urlscan_io.create_incidentCreate Incident
- urlscan_io.update_incidentUpdate Incident
- urlscan_io.create_saved_searchCreate Saved Search
- urlscan_io.create_subscriptionCreate Alert Subscription
- urlscan_io.update_saved_searchUpdate Saved Search
- urlscan_io.update_subscriptionUpdate Alert Subscription
- urlscan_io.create_live_scan_taskCreate Live Scan Task
- urlscan_io.update_result_visibilityUpdate Scan Visibility
- urlscan_io.create_live_scan_blockingRun Blocking Live Scan
- urlscan_io.submit_scanSubmit Scan
- urlscan_io.copy_incidentCopy Incident
- urlscan_io.fork_incidentFork Incident
- urlscan_io.restart_incidentRestart Incident
- urlscan_io.store_live_scan_resultStore Live Scan Result
destructive
6Delete, cancel or archive. Ask first, or deny outright.
- urlscan_io.delete_resultDelete Scan Result
- urlscan_io.delete_saved_searchDelete Saved Search
- urlscan_io.delete_subscriptionDelete Alert Subscription
- urlscan_io.close_incidentClose Incident
- urlscan_io.purge_live_scan_resultPurge Live Scan Result
- urlscan_io.reset_result_visibilityReset Scan Visibility
urlscan.io in three steps.
- 01Your users connect urlscan.ioThey add their urlscan.io api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Notification Channel” can wait for the user, and “delete Scan Result” can be denied outright.
- 03Any agent can actYour agent calls urlscan.io through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('urlscan_io', { read: 'allow', write: 'ask', // create_channel destructive: 'deny', // delete_result }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How urlscan.io connects.
Users add their urlscan.io api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same urlscan.io connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use urlscan.io from any agent.
More security and identity apps.
urlscan.io and Arc0, answered.
Can I use urlscan.io with Claude, ChatGPT or Cursor?
Yes. Connect urlscan.io to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the urlscan.io actions you allow.
How do users connect urlscan.io?
Users add their urlscan.io api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which urlscan.io actions can my agent take?
51 in total: 29 read, 16 write and 6 destructive, such as “create Notification Channel”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in urlscan.io?
Yes. Actions like “delete Scan Result” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call urlscan.io too?
Yes. The same urlscan.io connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug urlscan.io into your agent.
Your users connect urlscan.io once, under your brand. Your agent gets 51 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan