Developer Resources
Access OpenAPI specifications, automation tools, and integration resources for all DomainTools APIs.
Python SDK
Section titled “Python SDK”The official Python SDK is a fast way to integrate DomainTools APIs into your applications.
- Python SDK Documentation
- GitHub Repository ↗ - Source code and examples
- PyPI Package ↗ - Latest releases
Available APIs
Section titled “Available APIs”Quick links to get started:
- Iris Suite - Threat intelligence platform (investigation, enrichment, detection)
- Farsight DNSDB - Passive DNS database (300+ billion records)
- Farsight SIE - Real-time passive DNS feeds
- Lookups and Monitors - Domain research and monitoring tools
- Threat Feeds - Real-time and daily malicious infrastructure feeds
For complete API documentation, see individual product pages in the main navigation.
OpenAPI Specifications
Section titled “OpenAPI Specifications”View and interact with DomainTools API specifications using the interactive Scalar reference, raw OpenAPI files, or SwaggerHub.
Iris Suite
Section titled “Iris Suite”Complete threat intelligence platform for investigation, enrichment, and detection.
Interactive References:
- API Reference - Interactive reference (Scalar)
Specifications:
- OpenAPI Specification - YAML/JSON spec file
- View on SwaggerHub ↗ - SwaggerHub project page
Documentation:
- Developer Guide - Authentication, rate limits, and guides
Farsight DNSDB
Section titled “Farsight DNSDB”World’s largest passive DNS database for threat hunting and investigation.
Interactive References:
- API Reference - Interactive reference (Scalar)
Specifications:
- OpenAPI Specification - YAML/JSON spec file
- View on SwaggerHub ↗ - SwaggerHub project page
Documentation:
- Developer Guide - Setup and usage guides
Farsight SIE
Section titled “Farsight SIE”Real-time passive DNS feeds from the global sensor network.
Interactive References:
- API Reference - Interactive reference (Scalar)
Specifications:
- OpenAPI Specification - YAML/JSON spec file
- View on SwaggerHub ↗ - SwaggerHub project page
Documentation:
- Developer Guide - Access methods and configuration
Lookups and Monitors
Section titled “Lookups and Monitors”Classic domain research and monitoring tools.
Interactive References:
- API Reference - Interactive reference (Scalar)
Specifications:
- OpenAPI Specification - YAML/JSON spec file
- View on SwaggerHub ↗ - SwaggerHub project page
Documentation:
- Developer Guide - API basics and examples
Threat Feeds
Section titled “Threat Feeds”Real-time and daily feeds of malicious infrastructure.
Interactive References:
- API Reference - Interactive reference (Scalar)
Specifications:
- View on SwaggerHub ↗ - SwaggerHub project page
Documentation:
- API Reference and Resources - OpenAPI spec, guides, and SDK tips
- Developer Guide - Feed types and integration
Automation and integration
Section titled “Automation and integration”Playbooks
Section titled “Playbooks”Pre-built SOAR playbooks and workflow examples for automating threat intelligence tasks.
Platform integrations
Section titled “Platform integrations”Connect DomainTools to your security stack.
- All Integrations
- Splunk, Microsoft Sentinel, Palo Alto XSOAR, and more
PDF downloads
Section titled “PDF downloads”Complete API documentation compiled into single PDF files for offline reference.
- DomainTools Iris Investigate API
- DomainTools Iris Enrich API
- DomainTools Iris Detect API
- DomainTools Farsight DNSDB API
- DomainTools Threat Feeds API
- DomainTools Farsight SIE API
- DomainTools Lookups and Monitors API
- DomainTools Domain Risk Score
LLM resources
Section titled “LLM resources”Plain text API documentation optimized for large language models and RAG systems.
- llms.txt — Machine-readable index of LLM resources (llmstxt.org convention)
- DomainTools Iris Investigate API
- DomainTools Iris Enrich API
- DomainTools Iris Detect API
- DomainTools Farsight DNSDB API
- DomainTools Threat Feeds API
- DomainTools Farsight SIE API
- DomainTools Lookups and Monitors API
- DomainTools Domain Risk Score
Getting started
Section titled “Getting started”Authentication
Section titled “Authentication”All DomainTools APIs use API key authentication. Some APIs also support HMAC authentication for enhanced security.
Rate limits
Section titled “Rate limits”Monitor your API usage and understand rate limiting.
SDKs and tools
Section titled “SDKs and tools”- Python SDK - Official Python SDK for all DomainTools APIs
- DNSDB Tools - Command-line tools for DNSDB
- SIE Tools - Tools for SIE data access
Additional resources
Section titled “Additional resources”Support
Section titled “Support”Need help? Contact DomainTools Enterprise Support at enterprisesupport@domaintools.com.