Nord Security Subscription Management API

Endpoints for managing user subscriptions to data breach monitoring services. These operations enable administrators to create, update, and delete subscriptions for email addresses, phone numbers, domains, and sensitive data types. When a subscription is created, Serity automatically sends requests to the user’s webhook whenever new or updated data matches the subscription criteria. The webhook destination must be specified through the APIs user-management endpoints. ### Webhook Requirements To ensure reliable delivery under high load, user webhooks **must support very high request throughput** — at least `100 requests per second`. Serity operates at scale and will **not throttle outbound traffic** based on slow client responses. Frequent `429 Too Many Requests` responses are retried, but they can **clog internal delivery queues**, thus, it is strongly recommended that webhook endpoints are backed by a **message queue** or similar buffering system that can **acknowledge requests immediately** and **process them asynchronously** at the desired pace. This ensures resilience and prevents backpressure issues during high traffic periods. ### Delivery Semantics and Retry Policy - `2XX responses (200–299)` are treated as successful acknowledgements and are not retried. - `404 responses` trigger internal alerts and are **not retried**, as they typically indicate an invalid or deprecated endpoint. - `429 (Too Many Requests)` responses are retried with backoff, but can cause delivery delays if they persist. - `All other 4XX and 5XX responses` are **retried** with exponential backoff. - After prolonged retry failure, events are moved to a **DLQ**. In such cases, the platform team will contact the user. ### Webhook Payload ``` { "subscription_id": "string", "document_type": "email-sha256 | phone-sha256 | cc-argon2id | nin-argon2id | cc-sha1 | nin-sha1", "document_identifier": "string", "operation_type": "update | insert", "databases": [], "credential_lists": [], "malware_logs": [], } ``` By default, users receive only documents with the *insert* operation type. If the corresponding subscription has the dispatch_on_update option enabled, the webhook also sends update events.

Operations 14

GET /subscription Get user subscriptions #
POST /subscription/email-sha256 Create email subscription #
POST /subscription/phone-sha256 Create phone subscription #
POST /subscription/domain Create domain subscription #
POST /subscription/{cc-hash-type} Create zero knowledge credit card subscription #
POST /subscription/{nin-hash-type} Create zero knowledge national identification number subscription #
POST /subscription/email-sha256/bulk Create email subscriptions #
POST /subscription/phone-sha256/bulk Create phone subscriptions #
POST /subscription/domain/bulk Create domain subscriptions #
POST /subscription/{cc-hash-type}/bulk Create zero knowledge credit card subscriptions #
POST /subscription/{nin-hash-type}/bulk Create zero knowledge national identification number subscriptions #
DELETE /subscription/bulk Delete subscriptions #
GET /subscription/{id} Get subscription #
DELETE /subscription/{id} Delete subscription #

Documentation

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/nord-security-subscription-management-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

nord-security-subscription-management-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: NordStellar Enterprise Data Subscription Management API
  description: '## Overview

    The NordStellar Enterprise Data API provides comprehensive access to our data breach intelligence platform, enabling organizations to integrate real-time security monitoring and alerting capabilities directly into their existing infrastructure.'
  version: '3.1'
servers:
- url: /api/v3/data
security:
- ApiKeyAuth: []
- BasicAuth: []
tags:


# --- truncated at 32 KB (32 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/nord-security/refs/heads/main/openapi/nord-security-subscription-management-api-openapi.yml