Know of an official OpenAPI document? Contribute it →
For Agents
Investigate and enrich domains with risk and infrastructure data, and monitor lookalike domains: create monitors, review newly discovered domains, escalate threats, and manage watchlists.
Use for: Investigate a suspicious domain's risk profile, Enrich a list of domains with threat data, Create a monitor for domains that look like my brand, List newly discovered lookalike domains
Not supported: Does not handle endpoint protection, email filtering, or SIEM alerting. Use for domain intelligence, lookalike-domain monitoring, and investigation only.
Jentic publishes the only available OpenAPI specification for the DomainTools Iris API, keeping it validated and agent-ready. The DomainTools Iris API delivers domain intelligence for threat investigation and brand protection. Its Iris Investigate and Iris Enrich operations return a domain's risk score, registration, and infrastructure data, while Iris Detect monitors track lookalike domains and surface newly discovered, watched, and ignored domains. Analysts can escalate suspicious domains and manage watchlists from the same API.
Install Jentic One Beta
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the DomainTools Iris API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.
Step 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fdomaintools.com%2Fdomaintools" | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fdomaintools.com%2Fdomaintools" | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with DomainTools Iris API.
Investigate a domain and pull its full Iris risk and infrastructure profile
Enrich a set of domains with DomainTools Iris data
Create and configure monitors that track lookalike domains for a brand
Retrieve newly discovered, watched, and ignored domains for active monitors
Add or remove domains from Watchlist or Ignored lists
Escalate suspicious domains internally and externally
Patterns agents use DomainTools Iris API for, with concrete tasks.
★ Agent Domain Threat Investigation
A security AI agent can send a suspicious domain to the DomainTools Iris API's investigate operation and receive its risk score, registration, and infrastructure data in one call. The agent can then enrich related domains to map an attacker's footprint.
Investigate a domain and return its risk score and associated infrastructure
Lookalike Domain Monitoring
Brand-protection workflows can create monitors for lookalike domains and poll newly discovered and watched domains with the DomainTools Iris API. When a confusingly similar domain appears, the agent can escalate it or add it to a watchlist.
Create a monitor for a brand term, then list the newly discovered domains it has found
Bulk Domain Enrichment
Analysts can enrich a batch of domains with DomainTools Iris data to add registration, hosting, and risk attributes to their records. The enrich operation accepts a set of domains and returns their attributes in one response.
Enrich a set of domains and record their risk scores and hosting attributes
14 endpoints — jentic publishes the only available openapi specification for the domaintools iris api, keeping it validated and agent-ready.
METHOD
PATH
DESCRIPTION
/v1/iris-detect/monitors/
Retrieve monitors and monitor IDs
/v1/iris-detect/monitors/
Create a monitor to track lookalike domains
/v1/iris-detect/domains/new/
List newly discovered domains for active monitors
/v1/iris-detect/domains/watched/
List recently changed or escalated domains
/v1/iris-detect/escalations/
Escalate domains internally and externally
/v1/iris-investigate/
Investigate domains
/v1/iris-enrich/
Enrich domains with Iris data
/v1/account/
Account information
/v1/iris-detect/monitors/
Retrieve monitors and monitor IDs
/v1/iris-detect/monitors/
Create a monitor to track lookalike domains
/v1/iris-detect/domains/new/
List newly discovered domains for active monitors
/v1/iris-detect/domains/watched/
List recently changed or escalated domains
/v1/iris-detect/escalations/
Escalate domains internally and externally
/v1/iris-investigate/
Investigate domains
/v1/iris-enrich/
Enrich domains with Iris data
/v1/account/
Account information
This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.
Base layer of spec validity and structural soundness.
Aggregated quality score from linter diagnostics, weighted by severity.
Percentage of `$ref` references that resolve successfully.
Checks whether the API description parses successfully and conforms to its declared specification (e.g., OpenAPI).
Structural correctness score based on schema issues using logarithmic dampening.
Clarity, completeness, and ingestion readiness for developers and tooling.
How richly the API is illustrated with examples.
Percentage of examples that conform to their schemas.
Percentage of operations with complete response definitions (success, client error, server error).
Health of API ingestion, bundling, and resolution within Jentic pipelines.
Semantic breadth, depth, and agent comprehension for AI systems.
Coverage of descriptions across API elements.
Coverage of RFC 9457 Problem Details for error responses.
Coverage, uniqueness, and casing consistency of operationIds for AI inference.
Coverage of summaries across operations/tags/info.
Functional utility, complexity comfort, and AI orchestration readiness.
Agent comfort level based on API operational and structural complexity.
Trust, risk posture, and security compliance.
Average quality of security schemes based on authentication method strength (weakest link for OAuth2).
Findability, semantic richness, and reasoning readiness.
Clarity and depth of descriptions across API elements.
Score it yourself
Every API in the directory is allowlisted, so you can re-score it with no key required.
npx @jentic/api-scorecard-cli score <openapi-url>What agents get from Jentic-routed access to this vendor.
Setup
Wiring the DomainTools Iris API by hand means choosing among three authentication schemes, an X-Api-Key header, HTTP basic, or an HMAC signature, and building the signature yourself for HMAC. Through Jentic you install once, import the DomainTools Iris API from the API Directory, store the credentials once, and your agent calls it.
Permission scoping
The DomainTools Iris API identifies domains and monitors by parameters in the query or body rather than the URL path, so rules bound which operations your agent may call. Limit it to the investigate and enrich read operations, and leave monitor creation, updates, and deletion out unless you add them.
Credential isolation
Your DomainTools credentials are stored once, encrypted, by your own Jentic One instance and injected at execution time. They never enter the agent's prompt, logs, or context.
Intent-based discovery
Agents search Jentic by intent such as 'investigate a suspicious domain' or 'monitor lookalike domains', and Jentic returns the matching DomainTools operation with its input schema so the agent calls the right endpoint without reading the reference docs.
Alternatives and complements available in the Jentic catalogue.
Specific to using DomainTools Iris API through Jentic.
Why is there no official OpenAPI spec for the DomainTools Iris API?
DomainTools does not publish an OpenAPI specification for its Iris API. Jentic generates and maintains this spec so that AI agents and developers can call the DomainTools Iris API via structured tooling. It is validated against the live API and kept up to date. To run it on your own infrastructure, install Jentic One from its GitHub repo.
What authentication does the DomainTools Iris API use?
The DomainTools Iris API supports three schemes per its OpenAPI spec: an API key in the `X-Api-Key` header, HTTP basic authentication with your API username and key, and an HMAC `signature` passed as a query parameter. DomainTools recommends the header or HMAC method. Through Jentic the credentials are stored encrypted by your own Jentic One instance and injected at call time, so they never enter the agent's prompt or logs.
Can I investigate a domain with the DomainTools Iris API?
Yes. The Iris Investigate operation returns a domain's risk and infrastructure profile, and the Iris Enrich operation adds attributes to a set of domains. For monitoring, you can create monitors that track lookalike domains and review the newly discovered ones.
What are the rate limits for the DomainTools Iris API?
The OpenAPI spec does not specify rate limits for the DomainTools Iris API. Check the provider's documentation at https://docs.domaintools.com for the limits that apply to your plan.
Can I limit what my agent is allowed to do with the DomainTools Iris API?
Yes. Domains and monitors are identified by parameters in the query or body rather than the URL path, so a rule bounds which operations your agent may call. Write a rule that allows only the investigate and enrich read operations, and leave monitor creation, updates, and deletion out unless the agent needs them, and every call it makes is logged.
How do I investigate a domain with the DomainTools Iris API through Jentic?
Search Jentic for 'investigate a suspicious domain' and it returns the Iris Investigate operation with its input schema. Import the DomainTools Iris API from the Jentic API Directory, store your credentials once, and your agent can investigate and enrich domains without hand-wiring the authentication on each request.
Is there a DomainTools Iris API MCP server?
You don't need an MCP server to give your agent the DomainTools Iris API. Jentic connects it directly from the API Directory: import it, store your credentials once, and your agent calls the investigate, enrich, and monitor operations. Nothing extra loads into the agent's context until an operation is actually used.
GET STARTED