# LevelBlue Open Threat Exchange (OTX) DirectConnect API

**Canonical:** https://apis.io/apis/levelblue/levelblue-open-threat-exchange-otx-directconnect-api/  
**Provider:** LevelBlue — https://apis.io/providers/levelblue/  
**Base URL:** https://otx.alienvault.com/api/v1  
**Documentation:** https://otx.alienvault.com/assets/static/external_api.html

LevelBlue Open Threat Exchange (OTX) DirectConnect API is one of 4 APIs that [LevelBlue](https://apis.io/providers/levelblue/) publishes on the [APIs.io](https://apis.io/) network. Tagged areas include Threat Intelligence, Indicators of Compromise, and Security. The published artifact set on APIs.io includes API documentation.

The OTX DirectConnect API provides programmatic access to the LevelBlue Open Threat Exchange, an open community threat-intelligence platform. It exposes indicators (IPs, domains, hostnames, file hashes, URLs, CVEs, NIDS), pulses (curated collections of related indicators with tags, TLP levels and targeted countries), keyword search over users and pulses, and user subscription management. Access is by API key, validated against the users/me endpoint.

## Machine-readable artifacts (3)

- **Documentation** — https://otx.alienvault.com/assets/static/external_api.html
- **Portal** — https://otx.alienvault.com/
- **APIsJSON** — https://raw.githubusercontent.com/api-evangelist/levelblue/refs/heads/main/apis.yml

## Other LevelBlue APIs (3)

- [LevelBlue Alarms API](https://apis.io/apis/levelblue/levelblue-alarms-api/)
- [LevelBlue Events API](https://apis.io/apis/levelblue/levelblue-events-api/)
- [LevelBlue OAuth API](https://apis.io/apis/levelblue/levelblue-oauth-api/)

## Tags

Threat Intelligence, Indicators of Compromise, Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/levelblue/levelblue-open-threat-exchange-otx-directconnect-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/levelblue/.
