VirusTotal Private Scanning - URLs API

Private Scanning - URLs

Business capability
Threat Detection & Response Management BC-620.30

Operations 4

POST /private/urls VirusTotal Private Scan URL #
GET /private/urls/{id} VirusTotal Get a URL Analysis Report #
GET /private/urls/{id}/{relationship} VirusTotal Get Objects Related to a Private URL #
GET /private/urls/{id}/relationships/{relationship} VirusTotal Get Object Descriptors Related to a Private URL #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/virustotal-private-scanning-urls-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

virustotal-private-scanning-urls-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: VirusTotal API v3 - Private Scanning Private Scanning…
  version: '3.0'
  description: Submit files and URLs for analysis without sharing the artefact with the VirusTotal community. Mirrors the public scanning surface (Files / URLs / Analyses / Behaviours / Zip Files).
  contact:
    name: VirusTotal / Google Threat Intelligence
    url: https://docs.virustotal.com/reference/overview
  license:
    name: VirusTotal Terms of Service
    url: https://www.virustotal.com/gui/terms-of-service
  x-generated-from: https://storage.googleapis.com/gtidocresources/guides/GTI_API_v3_openapi_spec_10022025.json
  x-last-validated: '2026-05-29'
servers:
- url: https://www.virustotal.com/api/v3
  description: VirusTotal / GTI API v3 production.
security:
- VTApiKey: []
tags:
- name: Private Scanning - URLs
  description: Private Scanning - URLs
paths:
  /private/urls:
    post:
      tags:
      - Private Scanning - URLs
      summary: VirusTotal Private Scan URL
      description: This returns an Analysis ID. The analysis can be retrieved by using the Analysis endpoint.
      operationId: privateScanUrl
      parameters: []
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              required:
              - url
              properties:
                url:
                  type: string
                  description: URL to scan
      responses:
        '200':
          description: '200'
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                type: object
                properties: {}
        '400':
          description: '400'
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                type: object
                properties: {}
      deprecated: false
      security:
      - VTApiKey: []
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /private/urls/{id}:
    get:
      tags:
      - Private Scanning - URLs
      summary: VirusTotal Get a URL Analysis Report
      description: '> 📘

        >

        > See URL identifiers from more information about how to generate a valid URL identifier for a URL.


        Returns a URL object.'
      operationId: getAPrivateUrlAnalysisReport
      parameters:
      - name: id
        in: path
        description: URL identifier or base64 representation of URL to scan (w/o padding)
        schema:
          type: string
        required: true
      responses:
        '200':
          description: '200'
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                type: object
                properties: {}
        '400':
          description: '400'
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                type: object
                properties: {}
      deprecated: false
      security:
      - VTApiKey: []
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /private/urls/{id}/{relationship}:
    get:
      tags:
      - Private Scanning - URLs
      summary: VirusTotal Get Objects Related to a Private URL
      description: '> 📘

        >

        > See URL identifiers from more information about how to generate a valid URL identifier for a URL.


        URL objects have number of relationships to other URLs and objects. As mentioned in the Relationships section, those related objects can be retrieved by sending `GET` requests to the relationship URL.


        Some relationships are accessible only to users who have access to VirusTotal Enterprise package.


        The relationships supported by URL objects are documented in the URL API object page.'
      operationId: privateGetObjectsRelatedToAUrl
      parameters:
      - name: id
        in: path
        description: URL identifier
        schema:
          type: string
        required: true
      - name: relationship
        in: path
        description: Relationship name (see [table](ref:private-urls-object#relationships))
        schema:
          type: string
        required: true
      - name: limit
        in: query
        description: Maximum number of related objects to retrieve
        schema:
          type: integer
          format: int32
          default: 10
      - name: cursor
        in: query
        description: Continuation cursor
        schema:
          type: string
      responses:
        '200':
          description: '200'
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                type: object
                properties: {}
        '400':
          description: '400'
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                type: object
                properties: {}
      deprecated: false
      security:
      - VTApiKey: []
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /private/urls/{id}/relationships/{relationship}:
    get:
      tags:
      - Private Scanning - URLs
      summary: VirusTotal Get Object Descriptors Related to a Private URL
      description: This endpoint is the same as /private/urls/{id}/{relationship} except it returns just the related object's IDs (and context attributes, if any) instead of returning all attributes.
      operationId: privateGetObjectDescriptorsRelatedToAUrl
      parameters:
      - name: id
        in: path
        description: URL ID
        schema:
          type: string
        required: true
      - name: relationship
        in: path
        description: Relationship name (see [table](ref:private-urls-object#relationships))
        schema:
          type: string
        required: true
      - name: limit
        in: query
        description: Maximum number of related objects to retrieve
        schema:
          type: string
          default: '10'
      - name: cursor
        in: query
        description: Continuation cursor
        schema:
          type: string
      responses:
        '200':
          description: '200'
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                type: object
                properties: {}
        '400':
          description: '400'
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                type: object
                properties: {}
      deprecated: false
      security:
      - VTApiKey: []
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
components:
  securitySchemes:
    VTApiKey:
      type: apiKey
      in: header
      name: x-apikey
      description: Personal VirusTotal / GTI API key. Found in the user menu of your VirusTotal account.