How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

HackNotice All Business Accounts API

Authentication, leak/leakfile search, customer records, metrics, habits, downloads, utilities and item notes shared by every business account.

HackNotice All Business Accounts API is one of 9 APIs that HackNotice publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include All Business Accounts. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, authentication docs, and rate-limit docs.

This API exposes 36 operations across 31 paths, and defines 1 schema. It is described by OpenAPI 3.2.0, at version 2026-08-22.

Requests are made against a single base URL, https://extensionapi.hacknotice.com.

36 operations 31 paths 1 schemas 2 DELETE20 GET12 POST2 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
2026-08-22
Base URL
https://extensionapi.hacknotice.com
Authentication
API Key, API Key, API Key
Terms of Service
Resource Areas
1

Authentication & Security 3

HackNotice All Business Accounts API declares 3 security schemes for authenticating requests. An API key is passed in the header as Authorization (jwtAuth). An API key is passed in the header as apikey (apiKeyAuth). An API key is passed in the header as X-HackNotice-Integration-Key (integrationKeyAuth). By default, every request must be authenticated.

  • jwtAuth — Session token from POST /auth/signin, sent as the literal prefix "JWT " followed by the token — e.g. Authorization: JWT . Note this is HackNotice's own scheme,…
  • apiKeyAuth — Per-account API key issued by HackNotice, sent in the lower-case "apikey" header alongside the JWT on most operations.
  • integrationKeyAuth — Per-user HackNotice integration secret (hnik prefix). Single-header alternative to apikey + email + password; also the credential used by the HackNotice MCP se…

Paths & Operations 36

Across 31 paths, the API surfaces 36 operations — 2 DELETE, 20 GET, 12 POST, 2 PUT. Each is listed below with its method, path, parameters, and response codes.

All Business Accounts 36

Authentication, leak/leakfile search, customer records, metrics, habits, downloads, utilities and item notes shared by every business account.

POST
/auth/sign_in
Sign In
postSignIn body → 200401
GET
/auth/sign_out
Sign out
getSignOut → 200401
GET
/auth/sign_out_all
Sign out all sessions
getSignOutAllSessions → 200401
POST
/auth/twofa_sign_in
2FA Sign In
post2FaSignIn 1 param body → 200401
GET
/customerHabits
Read a document
getReadADocument5 1 param → 200401
PUT
/customerHabits
Update habits
putUpdateHabits 1 param body → 200401
GET
/customers
Read a document
getReadADocument3 1 param → 200401
POST
/customers
Update a document
postUpdateADocument body → 200401
GET
/customers/accounts
Read accounts
getReadAccounts 1 param → 200401
GET
/customerstats
Read a document
getReadADocument4 1 param → 200401
GET
/downloads
Read downloads to see if file is ready
getReadDownloadsToSeeIfFileIsReady 1 param → 200401
GET
/downloads/{documentId}
download file
getDownloadFile 2 params → 200401
GET
/itemnotes/count
Get the count of documents
getTheCountOfDocuments2 1 param → 200401
POST
/itemnotes/create
Create a doc
postCreateADoc 1 param body → 200401
GET
/itemnotes/customer/count
Get the count of documents
getTheCountOfDocuments 1 param → 200401
POST
/itemnotes/customer/itemdoc
Search for a note for an item
postSearchForANoteForAnItem 1 param body → 200401
GET
/itemnotes/customer/page/{pageNum}
Read a page of documents
getReadAPageOfDocuments 2 params → 200401
GET
/itemnotes/customer/{customerId}
Read a doc
getReadADoc 2 params → 200401
DELETE
/itemnotes/customer/{customerId}
Delete a doc
deleteADoc 2 params → 200401
POST
/itemnotes/itemdoc
Search for a note for an item
postSearchForANoteForAnItem2 1 param body → 200401
GET
/itemnotes/page/{pageNum}
Read a page of documents
getReadAPageOfDocuments2 2 params → 200401
GET
/itemnotes/{noteId}
Read a doc
getReadADoc2 2 params → 200401
PUT
/itemnotes/{noteId}
Update a doc
putUpdateADoc 2 params body → 200401
DELETE
/itemnotes/{noteId}
Delete a doc
deleteADoc2 2 params → 200401
GET
/leakReportsv2/count
Read a count of documents
getReadACountOfDocuments 1 param → 200401
POST
/leakReportsv2/search
Search all
postSearchAll 1 param body → 200401
GET
/leakReportsv2/{documentId}
Read a document
getReadADocument 2 params → 200401
POST
/leakfile/filename
Get by filename
postGetByFilename 1 param body → 200401
POST
/leakfile/search
Search all
postSearchAll2 1 param body → 200401
GET
/leakfile/{documentId}
Read a document
getReadADocument2 2 params → 200401
GET
/leakfilestats/count
Read count
getReadCount 1 param → 200401
POST
/leakfilestats/find
Find one
postFindOne body → 200401
GET
/leakfilestats/latest
Read latest
getReadLatest → 200401
GET
/leakfilestats/page/{pageNum}
Read page
getReadPage 2 params → 200401
POST
/utils/sha512
Create a SHA512 hash
postCreateASha512Hash 1 param body → 200401
POST
/utils/sha512half
Create a SHA512 half hash
postCreateASha512HalfHash 1 param body → 200401

Schemas 1

The contract defines 1 schema that model the data the API accepts and returns. The most detailed is Error (1 property). Each schema is shown below with its type and property counts.

Error
object
HackNotice error envelope observed on the live API hosts.
1 property

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

hacknotice-all-business-accounts-api-openapi.yml Raw ↑

Other APIs HackNotice publishes across the network.

HackNotice MCP Server
HackNotice Alerts API
HackNotice Calc endpoints API
HackNotice Deprecated API
HackNotice Domain Business Accounts API
HackNotice Enduser Business Accounts API
HackNotice Research Service Accounts API
HackNotice Third Party Accounts API
Where this information came from

This is an independent, third-party profile of HackNotice All Business Accounts API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.