ThreatMap aggregates Shodan, Censys, VirusTotal, AbuseIPDB, GreyNoise, and dozens more into one normalised API with a unified score. One auth. One data model. One MCP endpoint.
Copy the config. Paste into Claude. Ask a question. ThreatMap handles the rest.
Yes, you could call Shodan + VT + GreyNoise directly. Here's what that actually costs.
| DIY (10+ vendor APIs) | ThreatMap | |
|---|---|---|
| Time to first API call | 2+ weeks | 60 seconds |
| Procurement cycle | 6-12 months (per vendor) | None — self-serve |
| Schema normalisation | Months of engineering | Built-in, one schema |
| MCP server for AI agents | Build it yourself | Native, day one |
| Vendor API maintenance | Forever — your problem | Zero — we handle it |
| Monthly bills | 10+ separate invoices | One bill |
| Failed call cost | You still pay upstream | 0 credits |
If you'd otherwise wire up 10+ vendor APIs, use ThreatMap instead.
Give Claude, Cursor, or Copilot a tool that enriches any IOC, looks up any CVE, scans any asset. Native MCP.
Auto-enrich every URL, domain, attachment hash, and sender IP in one batch call.
Chain /v1/ioc to /v1/dns to /v1/certificates to /v1/trackers — map an attacker's footprint in 4 calls.
Scan assets before deploy, check dependencies against KEV + EPSS, block on critical exposure.
The Free tier is a real product — not a trial. Stay on it forever if that's all you need.
You'll never be charged on Free. No card on file. No trial timer. No "upgrade to continue" popups. 1,000 credits land on the 1st of every month — use them or lose them, no catch.
These capabilities are served by partners — we feed intelligence into their workflows.
No credit card. No trial timer. Failed calls are free. Sign up and make your first API call in 60 seconds.
Get API key