VirusTotal IoC Investigation - URLs API

IoC Investigation - URLs

Business capability
Threat Detection & Response Management BC-620.30

Operations 9

POST /urls VirusTotal Scan URL #
GET /urls/{id} VirusTotal Get a URL Report #
POST /urls/{id}/analyse VirusTotal Request a URL Rescan (re-analyze) #
GET /urls/{id}/comments VirusTotal Get Comments on a URL #
POST /urls/{id}/comments VirusTotal Add a Comment on a URL #
GET /urls/{id}/relationships/{relationship} VirusTotal Get Object Descriptors Related to a URL #
GET /urls/{id}/votes VirusTotal Get Votes on a URL #
POST /urls/{id}/votes VirusTotal Add a Vote on a URL #
GET /urls/{id}/{relationship} VirusTotal Get Objects Related to a URL #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/virustotal-ioc-investigation-urls-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

virustotal-ioc-investigation-urls-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: VirusTotal API v3 - IoC Investigation IoC Investigation…
  version: '3.0'
  description: Investigate files, URLs, IP addresses, and domains. Submit and analyse samples, retrieve reports, get comments and votes, view sandbox behaviour, traverse the relationships graph.
  contact:
    name: VirusTotal / Google Threat Intelligence
    url: https://docs.virustotal.com/reference/overview
  license:
    name: VirusTotal Terms of Service
    url: https://www.virustotal.com/gui/terms-of-service
  x-generated-from: https://storage.googleapis.com/gtidocresources/guides/GTI_API_v3_openapi_spec_10022025.json
  x-last-validated: '2026-05-29'
servers:
- url: https://www.virustotal.com/api/v3
  description: VirusTotal / GTI API v3 production.
security:
- VTApiKey: []
tags:
- name: IoC Investigation - URLs
  description: IoC Investigation - URLs
paths:
  /urls:
    post:
      summary: VirusTotal Scan URL
      description: This returns an Analysis ID. The analysis can be retrieved by using the Analysis endpoint.
      operationId: scanUrl
      parameters: []
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              required:
              - url
              properties:
                url:
                  type: string
                  description: URL to scan
      responses:
        '200':
          description: '200'
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                type: object
                properties: {}
        '400':
          description: '400'
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                type: object
                properties: {}
      deprecated: false
      security:
      - VTApiKey: []
      tags:
      - IoC Investigation - URLs
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /urls/{id}:
    get:
      tags:
      - IoC Investigation - URLs
      deprecated: false
      description: '> 📘

        >

        > See URL identifiers from more information about how to generate a valid URL identifier for a URL.


        Returns a URL object.'
      operationId: urlInfo
      parameters:
      - description: URL identifier or base64 representation of URL to scan (w/o padding)
        in: path
        name: id
        required: true
        schema:
          type: string
      - description: The name of your tool or service. This is required to obtain the gti_assesment data
        in: header
        name: x-tool
        required: false
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Get a URL Report
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /urls/{id}/analyse:
    post:
      tags:
      - IoC Investigation - URLs
      deprecated: false
      description: '> 📘 See URL identifiers from more information about how to generate a valid URL identifier for a URL.


        Returns a Analysis object descriptor which can be used in the GET/analyses/{id} API endpoint to get further information about the analysis status.


        ```json Example response

        {

        "data": {

        "id": "u-a354494a73382ea0b4bc47f4c9e8d6c578027cd4598196dc88f05a22b5817293-1604933101",

        "type": "analysis"

        }

        }

        ```'
      operationId: urlsAnalyse
      parameters:
      - description: URL identifier
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Request a URL Rescan (re-analyze)
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /urls/{id}/comments:
    get:
      tags:
      - IoC Investigation - URLs
      deprecated: false
      description: 'Returns a list of Comment objects.

        Check comments done in VT Community regarding a specific URL.


        > 📘 See URL identifiers from more information about how to generate a valid URL identifier for a URL.


        - `data`: list of ("comment" objects)[ref:comment-object].

        - `links`: contains "self" with a reference to this group of comments and "next", with a reference to the next group.

        - `cursor`: contains the cursor token used to access the next group of comments.'
      operationId: urlsCommentsGet
      parameters:
      - description: URL identifier
        in: path
        name: id
        required: true
        schema:
          type: string
      - description: Maximum number of comments to retrieve
        in: query
        name: limit
        schema:
          default: 10
          format: int32
          type: integer
      - description: Continuation cursor
        in: query
        name: cursor
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Get Comments on a URL
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
    post:
      tags:
      - IoC Investigation - URLs
      deprecated: false
      description: '> 📘 See URL identifiers from more information about how to generate a valid URL identifier for a URL.


        With this endpoint you can post a comment for a given URL. The body for the POST request must be the JSON representation of a comment object. Notice however that you don''t need to provide an ID for the object, as they are automatically generated for new comments.


        Any word starting with # in your comment''s text will be considered a tag, and added to the comment''s tag attribute.


        ```json Example request

        {

        "data": {

        "type": "comment",

        "attributes": {

        "text": "Lorem #ipsum dolor sit ..."

        }

        }

        }

        ```


        Returns a Comment object.'
      operationId: urlsCommentsPost
      parameters:
      - description: URL identifier
        in: path
        name: id
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              properties:
                data:
                  default: '{"type": "comment", "attributes": {"text": "Lorem ipsum dolor sit ..."}}'
                  description: A comment object
                  format: json
                  type: string
              required:
              - data
              type: object
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Add a Comment on a URL
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /urls/{id}/relationships/{relationship}:
    get:
      tags:
      - IoC Investigation - URLs
      deprecated: false
      description: This endpoint is the same as /urls/{id}/{relationship} except it returns just the related object's IDs (and context attributes, if any) instead of returning all attributes.
      operationId: urlsRelationshipsIds
      parameters:
      - description: URL ID
        in: path
        name: id
        required: true
        schema:
          type: string
      - description: Relationship name (see [table](ref:url-object#relationships))
        in: path
        name: relationship
        required: true
        schema:
          type: string
      - description: Maximum number of related objects to retrieve
        in: query
        name: limit
        schema:
          default: '10'
          type: string
      - description: Continuation cursor
        in: query
        name: cursor
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      summary: VirusTotal Get Object Descriptors Related to a URL
      security:
      - VTApiKey: []
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /urls/{id}/votes:
    get:
      tags:
      - IoC Investigation - URLs
      deprecated: false
      description: '> 📘 See URL identifiers from more information about how to generate a valid URL identifier for a URL.


        Returns a list of Vote objects.'
      operationId: urlsVotesGet
      parameters:
      - description: URL identifier
        in: path
        name: id
        required: true
        schema:
          type: string
      - description: Maximum number of votes to retrieve
        in: query
        name: limit
        schema:
          default: 10
          format: int32
          type: integer
      - description: Continuation cursor
        in: query
        name: cursor
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Get Votes on a URL
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
    post:
      tags:
      - IoC Investigation - URLs
      deprecated: false
      description: '> 📘 See URL identifiers from more information about how to generate a valid URL identifier for a URL.


        With this endpoint you can post a vote for a given URL. The body for the `POST` request must be the JSON representation of a vote object. Notice however that you don''t need to provide an ID for the object, as they are automatically generated for new votes.


        The verdict attribute must have be either `harmless` or `malicious`.


        ```json Example request

        {

        "data": {

        "type": "vote",

        "attributes": {

        "verdict": "harmless"

        }

        }

        }

        ```


        Returns a Vote object.'
      operationId: urlsVotesPost
      parameters:
      - description: URL identifier
        in: path
        name: id
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              properties:
                data:
                  default: '{"type": "vote", "attributes": {"verdict": "malicious"}}'
                  description: Vote object
                  format: json
                  type: string
              required:
              - data
              type: object
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
        '409':
          content:
            application/json:
              examples:
                Result:
                  value: "{\n  \"error\": {\n    \"code\": \"AlreadyExistsError\",\n    \"message\": \"User \\\"username\\\" already voted \\\"malicious\\\" for this url\"\n  }\n}"
              schema:
                properties:
                  error:
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                    type: object
                type: object
          description: '409'
      security:
      - VTApiKey: []
      summary: VirusTotal Add a Vote on a URL
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /urls/{id}/{relationship}:
    get:
      tags:
      - IoC Investigation - URLs
      deprecated: false
      description: '> 📘 See URL identifiers from more information about how to generate a valid URL identifier for a URL.


        URL objects have number of relationships to other URLs and objects. As mentioned in the Relationships section, those related objects can be retrieved by sending `GET` requests to the relationship URL.


        The relationships supported by URL objects are documented in the URL API object page.'
      operationId: urlsRelationships
      parameters:
      - description: URL identifier
        in: path
        name: id
        required: true
        schema:
          type: string
      - description: Relationship name (see [table](ref:url-object#relationships))
        in: path
        name: relationship
        required: true
        schema:
          type: string
      - description: Maximum number of related objects to retrieve
        in: query
        name: limit
        schema:
          default: 10
          format: int32
          type: integer
      - description: Continuation cursor
        in: query
        name: cursor
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Get Objects Related to a URL
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
components:
  securitySchemes:
    VTApiKey:
      type: apiKey
      in: header
      name: x-apikey
      description: Personal VirusTotal / GTI API key. Found in the user menu of your VirusTotal account.