Get started with the ThreatCluster API

Pick your stack, make one call, watch it run. Incidents, CVEs, threat actors, IOCs and leak-site victims over REST, from a free key with 100 credits a day and no card.

Six paths, three steps each. The page keeps its place in the URL, so you can hand a link to a colleague at the step you are on.

What the API returns

Pick a stack above to see the three steps for it: install or configure, one call, and what the response means.

The same request, sent from this page. Signed in, it runs on your own key and budget. Not signed in, a demo key covers the threats endpoints so you can see real records before you sign up. The snippets under the form always use $THREATCLUSTER_API_KEY; nothing about your key is put in a URL or in this browser's storage.

Three recipes that run on the free key, each shown with the output it produced, and the full guide for your stack.

Pick a stack above.

All ten recipes are under What you can build; every integration guide is under Integrations.

  • Key created
    Generate it under Settings, API & Feeds. Shown once.
  • First call
    From your terminal or code, or from the playground above.
  • First recipe
    Open one of the next moves and run it.
  • Done
    Tick this when the API is wired into whatever you were building.

One key, every path on this page

The key you make now works from curl, Python, Node, an MCP client, an editor, a SIEM and the CLI, with the same 100 credits a day. Upgrade when you need the history.

OpenAPI reference