How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

ODIN API

REST API for ODIN, Cyble's internet-scanning search engine. Twenty-seven operations across five datasets — Hosts (IPv4 scan results, services, ASN/geo enrichment, CVEs and exploits), Exposed Buckets (AI/ML-labelled cloud storage across AWS/GCP/Azure/DigitalOcean/Akamai/Linode/Alibaba/IBM), Exposed Files (categorised and labelled files harvested from exposed buckets), Domains (search, subdomains, WHOIS current and historical, registration and expiry checks), and Fields (the queryable field registry per dataset) — plus a health check. Queries use Lucene syntax over 400+ fields. Authentication is a single X-API-Key request header issued from the ODIN search console; all calls must be made over HTTPS.

This API exposes 27 operations across 27 paths, organized into 6 resource areas, and defines 69 schemas. It is described by OpenAPI 3.0.1, at version 1.0.

Requests are made against a single base URL, https://api.odin.io/.

27 operations 27 paths 69 schemas 14 GET13 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.1
API Version
1.0
Base URL
https://api.odin.io/
Authentication
API Key
License
Resource Areas
6

Authentication & Security 1

ODIN API declares 1 security scheme for authenticating requests. An API key is passed in the header as X-API-Key (ApiKeyAuth).

Paths & Operations 27

Across 27 paths, the API surfaces 27 operations — 14 GET, 13 POST. They span 6 resource areas: Hosts, domain, ExposedBuckets, ExposedFiles, Fields, Health. Each is listed below with its method, path, parameters, and response codes.

Hosts 9
GET
/v1/cves/all/{ip}/{page}
Get cve details
2 params → 200400402408500
POST
/v1/hosts/count
Get the record count
body → 200400402408500
GET
/v1/hosts/cve/{ip}
Get ip cve details
1 param → 200400402408500
GET
/v1/hosts/cves/{ip}/{cve}
Get cve
2 params → 200400408500
GET
/v1/hosts/exploits/{ip}
Get exploits for ip
1 param → 200400402408500
GET
/v1/hosts/exploits/{ip}/{cve}
Get exploits for ip and cve
2 params → 200400408500
POST
/v1/hosts/search
Search hosts
body → 200400402408500
POST
/v1/hosts/summary
Get summary
body → 200400402408500
GET
/v1/hosts/{ip}
Get the latest ip details
1 param → 200400402408500
domain 8
POST
/v1/domain/count
Get domains count
body → 200400500
POST
/v1/domain/search
Search domains
body → 200400500
POST
/v1/domain/subdomain/count
Fetch the total no. of subdomain records
body → 200400500
POST
/v1/domain/subdomain/search
Fetch the subdomain record
body → 200400500
GET
/v1/domain/whois/{domain-name}
Fetch the domain whois record details
1 param → 200400402408500
GET
/v1/domain/whois/{domain-name}/historical
Fetch all the domain whois historical records
1 param → 200400402408500
GET
/v1/domain/whois/{domain-name}/is-expired
Get the expiry for a particular domain
1 param → 200400402408500
GET
/v1/domain/whois/{domain-name}/is-registered
Fetch all the domain whois historical records
1 param → 200400402408500
ExposedBuckets 3
POST
/v1/exposed/buckets/count
Get exposed bucket count
body → 200400500
POST
/v1/exposed/buckets/search
Search exposed buckets
searchExposedBuckets body → 200400500
POST
/v1/exposed/buckets/summary
Get exposed buckets summary
body → 200400500
ExposedFiles 3
POST
/v1/exposed/files/count
Get file count
body → 200400500
POST
/v1/exposed/files/search
Search exposed files
body → 200400402500
POST
/v1/exposed/files/summary
Get file summary
body → 200400500
Fields 3
GET
/v1/fields/exposed/buckets
Get the fields for exposed buckets
→ 200400402408500
GET
/v1/fields/exposed/files
Get the fields for exposed files
→ 200400402408500
GET
/v1/fields/hosts/{category}
Get the fields for hosts
1 param → 200400402408500
Health 1
GET
/v1/ping
Health check
→ 200

Schemas 69

The contract defines 69 schemas that model the data the API accepts and returns. The most detailed are service.Service (27 properties), exposed.Bucket (20 properties), exposed.File (18 properties), ipservices.IPSummaryData (18 properties). Each schema is shown below with its type and property counts.

Field
object
4 properties
APIResponse
object
4 properties
CertCount
object
1 property
CountRequest
object
1 property
Encoding
object
1 property
ErrorResponse
object
2 properties
IPASN
object
3 properties
IPCVE
object
9 properties
IPDomain
object
6 properties
IPExploitDetails
object
6 properties
IPHostname
object
2 properties
IPLocation
object
9 properties
IPService
object
13 properties
IPServiceMeta
object
4 properties
IPServiceSoftware
object
8 properties
IPTag
object
4 properties
IPWhois
object
5 properties
PaginationStruct
object
2 properties
SearchPagination
object
4 properties
SearchRequest
object
3 properties 1 required
SummaryRequest
object
3 properties 2 required
dns.APIResponse
object
3 properties
dns.DNSCountRequest
object
4 properties
dns.Data
object
1 property
dns.DomainRequest
object
6 properties 1 required
dns.ErrorResponse
object
2 properties
dns.SearchPagination
object
4 properties
eshandler.Aggregate
object
3 properties
eshandler.DNS
object
4 properties
eshandler.EXTDNSName
object
4 properties
exposed.APIResponse
object
3 properties
exposed.Aggregate
object
3 properties
exposed.Bucket
object
20 properties
exposed.BucketAPIResponse
object
3 properties
exposed.CountRequest
object
1 property
exposed.File
object
18 properties
exposed.FileAPIResponse
object
3 properties
exposed.SearchCount
object
1 property
exposed.SearchPagination
object
4 properties
exposed.SearchRequest
object
5 properties 1 required
exposed.SummaryRequest
object
3 properties 2 required
ipservices.HostsSummaryResponse
object
3 properties
ipservices.IPSummaryData
object
18 properties
ipservices.IpCveDetails
object
9 properties
ipservices.IpCveResponse
object
3 properties
schema.APIResponse
object
4 properties
schema.Audit
object
4 properties
schema.Contact
object
12 properties
schema.DomainWhoisResponse
object
14 properties
schema.PaginationMeta
object
2 properties
schema.Registrar
object
4 properties
service.Coordinates
object
2 properties
service.Encoding
object
1 property
service.FullCveData
object
3 properties
service.IPASN
object
3 properties
service.IPDomain
object
6 properties
service.IPHostname
object
2 properties
service.IPLocation
object
9 properties
service.IPServiceMeta
object
4 properties
service.IPServiceSoftware
object
8 properties
service.IPTag
object
4 properties
service.IPWhois
object
5 properties
service.Service
object
27 properties
tokens.DetailStat
object
3 properties
tokens.ErrorResponse
object
2 properties
tokens.FinalStats
object
2 properties
tokens.SearchStat
object
3 properties
tokens.UserTokenStats
object
3 properties
vision.ExploitDetails
object
6 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

cyble-odin-openapi.yml Raw ↑
Where this information came from

This is an independent, third-party profile of ODIN API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.