Home
Providers
HackNotice
HackNotice
HackNotice is an external threat-intelligence and cyber-risk platform founded in 2018 and headquartered in Austin, Texas. It continuously collects intelligence from ransomware groups, infostealer malware logs, data breaches, dark-web marketplaces, hacker forums and public disclosures, then matches that intelligence against the domains, employees, customers and vendors an organization asks it to watch. The product is organized around four monitoring services — first-party domain monitoring, third-party vendor risk monitoring, end-user credential monitoring, and threat research and investigations — plus AI-assisted vendor security assessments. HackNotice exposes this surface programmatically through a REST API documented as a public Postman collection at api-docs.hacknotice.com, a remote Model Context Protocol server at mcp.hacknotice.com whose tool catalogue answers anonymously, first-party n8n automation nodes on npm, and webhook, Splunk HEC and SIEM/SOAR alert delivery.
HackNotice publishes 8 APIs on the APIs.io network, including Alerts API, All Business Accounts API, Calc endpoints API, and 5 more. Tagged areas include Company, Security, Threat Intelligence, Cybersecurity, and Dark Web Monitoring.
The HackNotice catalog on APIs.io includes 1 event-driven AsyncAPI specification.
HackNotice’s developer surface includes documentation, API reference, getting-started guide, support, engineering blog, pricing, signup flow, and 28 more developer resources.
1 APIs
1 MCP Servers
On this page
Kin Score
APIs 9
MCP Servers 1
Pricing Plans 1
Rate Limits 1
Event Specs 1
Security Posture 2
Resources 35
apis.yml
32 Operational Transparency
0 Create-or-Update Ergonomics
Composite quality — 51.3/100 · developing
Agent readiness — 35/100 · agent ready
Individual APIs this provider publishes, each with its own machine-readable definition.
Scroll for all 9
Model Context Protocol servers that expose these APIs to AI agents.
Published pricing tiers and plan structures.
Documented rate limits and quota policies.
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Get Started 4
Portal, sign-up, and the first successful call
Documentation 3
Reference material describing how the API behaves
Agent Surfaces 3
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 5
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 5
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 1
Properties that don't map to a standard resource type
Source (apis.yml)
aid: hacknotice
name: HackNotice
description: HackNotice is an external threat-intelligence and cyber-risk platform founded in 2018 and headquartered in Austin,
Texas. It continuously collects intelligence from ransomware groups, infostealer malware logs, data breaches, dark-web marketplaces,
hacker forums and public disclosures, then matches that intelligence against the domains, employees, customers and vendors
an organization asks it to watch. The product is organized around four monitoring services — first-party domain monitoring,
third-party vendor risk monitoring, end-user credential monitoring, and threat research and investigations — plus AI-assisted
vendor security assessments. HackNotice exposes this surface programmatically through a REST API documented as a public
Postman collection at api-docs.hacknotice.com, a remote Model Context Protocol server at mcp.hacknotice.com whose tool catalogue
answers anonymously, first-party n8n automation nodes on npm, and webhook, Splunk HEC and SIEM/SOAR alert delivery.
deliveryModel:
model: unknown
open_source: unknown
commercial: true
callable_host: true
label: Delivery model not determined — needs a product licence on record
confidence: low
source:
- openapi
- pricing
- repository-unlicensed
generated: '2026-08-28'
method: derived
accessModel:
pricing: paid
onboarding: unknown
trial: false
try_now: false
public: false
label: Paid
confidence: high
source:
- plans
- authentication
- rate-limits
- security
generated: '2026-09-03'
method: derived
image: https://hacknotice.com/wp-content/uploads/2022/12/favicon.png
url: https://raw.githubusercontent.com/api-evangelist/hacknotice/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-08-22'
modified: '2026-08-22'
tags:
- Company
- Security
- Threat Intelligence
- Cybersecurity
- Dark Web Monitoring
- Data Breaches
- Credential Monitoring
- Third-Party Risk
- Vendor Risk Management
- Vulnerability Management
- Ransomware
- Security Assessments
- Alerts
- Monitoring
tags_raw:
- Company
- Security
- Threat Intelligence
- Cybersecurity
- Dark Web Monitoring
- Data Breaches
- Credential Monitoring
- Third Party Risk
- Vendor Risk Management
- Vulnerability Management
- Ransomware
- Security Assessments
- Alerts
- Monitoring
apis:
- aid: hacknotice:hacknotice-mcp
name: HackNotice MCP Server
description: Remote Model Context Protocol server operated by HackNotice, speaking JSON-RPC 2.0 over Streamable HTTP at
https://mcp.hacknotice.com:13330/mcp. It publishes 80 tools across third-party, first-party, end-user, research and assessment
groups, plus cross-cutting global-breach, exposure, chatter, credential-leak, leaked-file and correlated-leak search.
tools/list and initialize answer anonymously, so every tool inputSchema is public; tools/call is gated on a per-user X-HackNotice-Integration-Key.
humanURL: https://github.com/HackNotice/n8n-nodes-hacknotice-mcp
baseURL: https://mcp.hacknotice.com:13330/mcp
tags:
- MCP
- Agents
- Threat Intelligence
- Security
properties:
- type: MCPServer
url: mcp/hacknotice-mcp.yml
- type: ToolCrosswalk
url: mcp/hacknotice-tool-crosswalk.yml
- type: SourceCode
url: https://github.com/HackNotice/n8n-nodes-hacknotice-mcp
- aid: hacknotice:hacknotice-alerts-api
name: HackNotice Alerts API
description: Cross-service alert retrieval.
humanURL: https://api-docs.hacknotice.com
baseURL: https://extensionapi.hacknotice.com
tags:
- Alerts
properties:
- type: OpenAPI
url: openapi/hacknotice-alerts-api-openapi.yml
- type: Documentation
url: https://api-docs.hacknotice.com
- type: APIReference
url: https://api-docs.hacknotice.com
- type: Postman
url: https://api-docs.hacknotice.com
- type: Authentication
url: authentication/hacknotice-authentication.yml
- type: RateLimits
url: rate-limits/hacknotice-rate-limits.yml
- type: ErrorCatalog
url: errors/hacknotice-problem-types.yml
- type: DataModel
url: data-model/hacknotice-data-model.yml
- type: Conventions
url: conventions/hacknotice-conventions.yml
- aid: hacknotice:hacknotice-all-business-accounts-api
name: HackNotice All Business Accounts API
description: Authentication, leak/leakfile search, customer records, metrics, habits, downloads, utilities and item notes
shared by every business account.
humanURL: https://api-docs.hacknotice.com
baseURL: https://extensionapi.hacknotice.com
tags:
- All Business Accounts
properties:
- type: OpenAPI
url: openapi/hacknotice-all-business-accounts-api-openapi.yml
- type: Documentation
url: https://api-docs.hacknotice.com
- type: APIReference
url: https://api-docs.hacknotice.com
- type: Postman
url: https://api-docs.hacknotice.com
- type: Authentication
url: authentication/hacknotice-authentication.yml
- type: RateLimits
url: rate-limits/hacknotice-rate-limits.yml
- type: ErrorCatalog
url: errors/hacknotice-problem-types.yml
- type: DataModel
url: data-model/hacknotice-data-model.yml
- type: Conventions
url: conventions/hacknotice-conventions.yml
- aid: hacknotice:hacknotice-calc-endpoints-api
name: HackNotice Calc endpoints API
description: Aggregate/rollup calculation endpoints for breaches, threat actors and per-service alerts.
humanURL: https://api-docs.hacknotice.com
baseURL: https://extensionapi.hacknotice.com
tags:
- Calc endpoints
properties:
- type: OpenAPI
url: openapi/hacknotice-calc-endpoints-api-openapi.yml
- type: Documentation
url: https://api-docs.hacknotice.com
- type: APIReference
url: https://api-docs.hacknotice.com
- type: Postman
url: https://api-docs.hacknotice.com
- type: Authentication
url: authentication/hacknotice-authentication.yml
- type: RateLimits
url: rate-limits/hacknotice-rate-limits.yml
- type: ErrorCatalog
url: errors/hacknotice-problem-types.yml
- type: DataModel
url: data-model/hacknotice-data-model.yml
- type: Conventions
url: conventions/hacknotice-conventions.yml
- aid: hacknotice:hacknotice-deprecated-api
name: HackNotice Deprecated API
description: Endpoints HackNotice groups as deprecated in its published collection (dark hash alerts, Teams accounts).
humanURL: https://api-docs.hacknotice.com
baseURL: https://extensionapi.hacknotice.com
tags:
- Deprecated
properties:
- type: OpenAPI
url: openapi/hacknotice-deprecated-api-openapi.yml
- type: Documentation
url: https://api-docs.hacknotice.com
- type: APIReference
url: https://api-docs.hacknotice.com
- type: Postman
url: https://api-docs.hacknotice.com
- type: Authentication
url: authentication/hacknotice-authentication.yml
- type: RateLimits
url: rate-limits/hacknotice-rate-limits.yml
- type: ErrorCatalog
url: errors/hacknotice-problem-types.yml
- type: DataModel
url: data-model/hacknotice-data-model.yml
- type: Conventions
url: conventions/hacknotice-conventions.yml
- aid: hacknotice:hacknotice-domain-business-accounts-api
name: HackNotice Domain Business Accounts API
description: 'First-party domain monitoring: domain watchlists, domain leaks, domain alerts and downloads.'
humanURL: https://api-docs.hacknotice.com
baseURL: https://extensionapi.hacknotice.com
tags:
- Domain Business Accounts
properties:
- type: OpenAPI
url: openapi/hacknotice-domain-business-accounts-api-openapi.yml
- type: Documentation
url: https://api-docs.hacknotice.com
- type: APIReference
url: https://api-docs.hacknotice.com
- type: Postman
url: https://api-docs.hacknotice.com
- type: Authentication
url: authentication/hacknotice-authentication.yml
- type: RateLimits
url: rate-limits/hacknotice-rate-limits.yml
- type: ErrorCatalog
url: errors/hacknotice-problem-types.yml
- type: DataModel
url: data-model/hacknotice-data-model.yml
- type: Conventions
url: conventions/hacknotice-conventions.yml
- aid: hacknotice:hacknotice-enduser-business-accounts-api
name: HackNotice Enduser Business Accounts API
description: 'End-user monitoring: end-user watchlists, end-user leaks and end-user alerts.'
humanURL: https://api-docs.hacknotice.com
baseURL: https://extensionapi.hacknotice.com
tags:
- Enduser Business Accounts
properties:
- type: OpenAPI
url: openapi/hacknotice-enduser-business-accounts-api-openapi.yml
- type: Documentation
url: https://api-docs.hacknotice.com
- type: APIReference
url: https://api-docs.hacknotice.com
- type: Postman
url: https://api-docs.hacknotice.com
- type: Authentication
url: authentication/hacknotice-authentication.yml
- type: RateLimits
url: rate-limits/hacknotice-rate-limits.yml
- type: ErrorCatalog
url: errors/hacknotice-problem-types.yml
- type: DataModel
url: data-model/hacknotice-data-model.yml
- type: Conventions
url: conventions/hacknotice-conventions.yml
- aid: hacknotice:hacknotice-research-service-accounts-api
name: HackNotice Research Service Accounts API
description: Threat-research search over terms, filenames and word pools, plus saved searches.
humanURL: https://api-docs.hacknotice.com
baseURL: https://extensionapi.hacknotice.com
tags:
- Research Service Accounts
properties:
- type: OpenAPI
url: openapi/hacknotice-research-service-accounts-api-openapi.yml
- type: Documentation
url: https://api-docs.hacknotice.com
- type: APIReference
url: https://api-docs.hacknotice.com
- type: Postman
url: https://api-docs.hacknotice.com
- type: Authentication
url: authentication/hacknotice-authentication.yml
- type: RateLimits
url: rate-limits/hacknotice-rate-limits.yml
- type: ErrorCatalog
url: errors/hacknotice-problem-types.yml
- type: DataModel
url: data-model/hacknotice-data-model.yml
- type: Conventions
url: conventions/hacknotice-conventions.yml
- aid: hacknotice:hacknotice-third-party-accounts-api
name: HackNotice Third Party Accounts API
description: 'Third-party vendor monitoring: hacks, hack updates, watchlists, alerts and vendor security assessments.'
humanURL: https://api-docs.hacknotice.com
baseURL: https://extensionapi.hacknotice.com
tags:
- Third Party Accounts
properties:
- type: OpenAPI
url: openapi/hacknotice-third-party-accounts-api-openapi.yml
- type: Documentation
url: https://api-docs.hacknotice.com
- type: APIReference
url: https://api-docs.hacknotice.com
- type: Postman
url: https://api-docs.hacknotice.com
- type: Authentication
url: authentication/hacknotice-authentication.yml
- type: RateLimits
url: rate-limits/hacknotice-rate-limits.yml
- type: ErrorCatalog
url: errors/hacknotice-problem-types.yml
- type: DataModel
url: data-model/hacknotice-data-model.yml
- type: Conventions
url: conventions/hacknotice-conventions.yml
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
- FN: APIs.json
email: info@apis.io
common:
- type: License
name: MIT
url: https://github.com/HackNotice/n8n-nodes-hacknotice-mcp/blob/main/LICENSE
- type: DomainSecurity
url: security/hacknotice-domain-security.yml
- type: Website
url: https://hacknotice.com/
- type: DeveloperPortal
url: https://api-docs.hacknotice.com
- type: Documentation
url: https://hacknotice.zendesk.com/hc/en-us
- type: APIReference
url: https://api-docs.hacknotice.com
- type: GettingStarted
url: https://hacknotice.zendesk.com/hc/en-us/articles/13771563959828-Overview-Getting-Started-for-Sec-Teams
- type: Support
url: https://hacknotice.zendesk.com/hc/en-us
- type: HelpCenter
url: https://hacknotice.zendesk.com/hc/en-us
- type: Blog
url: https://hacknotice.com/category/blog/
- type: BlogRSS
url: https://hacknotice.com/feed/
- type: GitHubOrganization
url: https://github.com/HackNotice
- type: Pricing
url: https://hacknotice.com/pricing/
- type: SignUp
url: https://hacknotice.com/free-account/
- type: Login
url: https://app.hacknotice.com/
- type: TermsOfService
url: https://hacknotice.com/businesstandc/
- type: PrivacyPolicy
url: https://hacknotice.com/privacy/
- type: Postman
url: https://api-docs.hacknotice.com
- type: OpenAPI
url: openapi/hacknotice-openapi.yml
- type: MCPServer
url: mcp/hacknotice-mcp.yml
- type: ToolCrosswalk
url: mcp/hacknotice-tool-crosswalk.yml
- type: Packages
url: packages/hacknotice-packages.yml
- type: SDKs
url: packages/hacknotice-packages.yml
- type: Authentication
url: authentication/hacknotice-authentication.yml
- type: RateLimits
url: rate-limits/hacknotice-rate-limits.yml
- type: Plans
url: plans/hacknotice-plans-pricing.yml
- type: Conventions
url: conventions/hacknotice-conventions.yml
- type: ErrorCatalog
url: errors/hacknotice-problem-types.yml
- type: Lifecycle
url: lifecycle/hacknotice-lifecycle.yml
- type: Conformance
url: conformance/hacknotice-conformance.yml
- type: DataModel
url: data-model/hacknotice-data-model.yml
- type: Overlay
url: overlays/hacknotice-openapi-overlay.yaml
- type: Webhooks
url: asyncapi/hacknotice-webhooks.yml
- type: AgentSkill
url: skills/_index.yml
- type: LLMsTxt
url: llms/hacknotice-llms.txt
x-enrichment:
date: '2026-08-22'
status: enriched
artifacts_added: 25
pass: local-v1
Every provider here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for providers
9 MCP tools reach this
find_providersBrowse and filter every provider in the catalog.
get_provider_artifactsEvery artifact this provider publishes, grouped by type.
get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
get_provider_ratingPRO — composite, band, trend and facet scores.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This provider
curl "https://apis.io/api/v1/providers/hacknotice"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/hacknotice/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/hacknotice/evidence"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms .
A second provider on the same verified email joins the account you already have.