canonical: https://jentic.com/apis/pulsedive.com/pulsedive

# Pulsedive API

Pulsedive is a free threat intelligence platform that provides community-powered indicator of compromise (IOC) data. The API allows searching, scanning, and analyzing indicators (IPs, domains, URLs), threats, and feeds for threat intelligence enrichment. The API exposes 8 endpoints secured with apiKey authentication.

## For AI agents

Programmatically get indicator by id, get indicator by value. Covers 8 operations with apiKey authentication.

## Scope

Does not handle payments, communications, or crm - use for security only.

## Capabilities

- Get indicator by ID
- Explore indicators
- Submit indicator for scanning

## Use cases

### Security Operations

Use the Pulsedive API to perform security operations programmatically. The API provides 8 endpoints covering core functionality including get indicator by id, get indicator by value, get threat by id.

Example prompt: Call GET /info.php to get indicator by id

### Automated Indicators Management

Automate indicators operations by combining multiple Pulsedive API endpoints. Agents can get indicator by value and then get threat by id in a single workflow.

Example prompt: Call GET /info.php#indicator-by-value to get indicator by value, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Pulsedive API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle apiKey tokens manually.

Example prompt: Search Jentic for 'get indicator by id', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | `/info.php` | Get indicator by ID |
| GET | `/info.php#indicator-by-value` | Get indicator by value |
| GET | `/info.php#threat` | Get threat by ID |
| GET | `/info.php#threat-by-name` | Get threat by name |
| GET | `/info.php#feed` | Get feed by ID |
| GET | `/explore.php` | Explore indicators |
| POST | `/analyze.php` | Submit indicator for scanning |
| GET | `/analyze.php` | Get scan results |

## Key resources

- **Indicators** — Retrieve and manage threat indicators (IPs, domains, URLs, artifacts)
- **Threats** — Retrieve and manage threat entries (malware families, campaigns, actors)
- **Explore** — Explore and query the Pulsedive dataset
- **Scan** — Submit indicators for on-demand scanning and analysis
- **Feeds** — Retrieve threat intelligence feed data

## Why Jentic

- **Setup:** Wiring Pulsedive by hand means passing its API key on every query string and parsing the .php threat and indicator endpoints yourself. Through Jentic you install once, import the Pulsedive API from the API Directory, store the key once, and your agent calls it.
- **Permission scoping:** Pulsedive takes its lookup targets in query and body parameters rather than as path resources, so scope the agent to the operations it needs, such as fetching indicator or threat info and analyzing a value. You choose that allowed set, so submission or bulk analyze operations are not included unless you add them.
- **Credential handling:** Your Pulsedive key is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'look up an indicator by value' or 'analyze a URL for threats', and Jentic returns the matching Pulsedive operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Snyk** — Alternative security API
- **Crowdstrike** — Alternative security API

## FAQ

### What authentication does the Pulsedive API use?

The Pulsedive API uses an API key passed in the `key` query. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I get indicator by id with the Pulsedive API?

Yes. Use the GET /info.php endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Pulsedive API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I get indicator by id through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'get indicator by id'. Jentic returns the matching Pulsedive API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Pulsedive API have?

The Pulsedive API exposes 8 endpoints covering indicators, threats, explore operations.

### Can I limit what my agent is allowed to do with the Pulsedive API?

Yes. Because you run Jentic One yourself, you decide which Pulsedive operations your agent may call and which stored API key it uses. Since Pulsedive takes its lookup targets in query and body parameters rather than as path resources, you can allow only read operations such as getting an indicator by ID or value, getting a threat, or exploring indicators, while withholding the analyze submission and scan-result endpoints unless you explicitly add them. The operations you do not grant simply are not available to the agent.
