urlscan — osint terminal MCP Tool
urlscan
(urlscan) is one of 457 tools on the
osint terminal
MCP server. Connect the server and your client discovers it on the handshake.
by client
How to call urlscan from your client
- Claude Code osint terminal urlscan run in your project directory
- Claude Desktop osint terminal urlscan ~/Library/Application Support/Claude/claude_desktop_config.json
- Cursor osint terminal urlscan ~/.cursor/mcp.json
- VS Code osint terminal urlscan .vscode/mcp.json
- Zed osint terminal urlscan ~/.config/zed/settings.json
- Windsurf osint terminal urlscan ~/.codeium/windsurf/mcp_config.json
- Cline osint terminal urlscan ~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json
- Gemini CLI osint terminal urlscan ~/.gemini/settings.json
- Grok osint terminal urlscan .mcp.json (in your project root)
- ChatGPT osint terminal urlscan Settings → Connectors → Advanced → Developer mode
- Claude.ai osint terminal urlscan Settings → Connectors → Add custom connector
- LangChain osint terminal urlscan pip install langchain-mcp-adapters
Fastest route
claude mcp add --transport http osint-terminal https://osint-mcp.thetempleofdoom.com/mcp
Other tools on this server
- dns
- whois
- subdomains
- tls
- headers
- wayback
- ipgeo
- reversedns
- username
- github
- internetdb
- portscan
- camera
- ipwhois
- asn
- reverseip
- dnsbl
- tor
- cloud
- emailsec
- robots
- tech
- favicon
- redirects
- certhistory
- social
- mac
- crypto
- dorks
- greynoise
- typosquat
- securitytxt
- keybase
- phone
- decode
- jwt
- hashid
- cidr
- gitexposed
- cors
- cookies
- dnssec
- pgp
- hackernews
- gitlab
- dnsprop
- takeover
- sitemap
- waf
- cve
- npm
- peers
- urlparse
- epoch
- tlsscan
- revgeo
- suntimes
- iban
- bin
- uuid
- isbn
- txhash
- bluesky
- chesscom
- wikipedia
- httping
- links
- pwstrength
- entropy
- lobsters
- caa
- mtasts
- bimi
- domainage
- luhn
- pypi
- crates
- rubygems
- packagist
- npmpkg
- btcaddr
- ethaddr
- ghrepo
- ghgists
- ghorg
- mastodon
- geohash
- ipv6
- transform
- cpfcnpj
- color
- doh
- tlsa
- dnsverify
- subbrute
- hstspreload
- wpscan
- wellknown
- graphql
- swagger
- s3buckets
- httpmethods
- dirlisting
- adstxt
- feeds
- manifest
- wpplugin
- abusecontact
- asrank
- peeringdb
- rpki
- ens
- ethcontract
- osv
- depsdev
- gomod
- nuget
- maven
- hexpm
- cdnjs
- npmdl
- brew
- pypistats
- devto
- medium
- orcid
- codeberg
- wikidata
- musicbrainz
- stackoverflow
- hashnode
- gravatarfull
- osmuser
- feodo
- openphish
- kev
- epss
- circlhash
- weather
- elevation
- vin
- lei
- orgname
- cpe
- cvedetail
- port
- ssh
- hostsearch
- peeringnet
- nearbywiki
- doi
- crossrefauthor
- orcidworks
- isbnmeta
- sopostuser
- breachsearch
- feodoips
- urlscansearch
- commoncrawl
- ipfull
- geocode
- revgeocode
- macvendorlookup
- dnsmx
- fxrate
- country
- wikidatasearch
- spdxlicense
- gitignore
- ghcommits
- ghpubkeys
- ghkeysgpg
- npmdownloads
- pypiproject
- dockerhub
- httpstatus
- useragent
- asnprefixes
- ripewhois
- rdapip
- isotime
- nvdcve
- ghadvisory
- otxdomain
- otxip
- hosthunt
- ghlanguages
- githubsearch
- githubgists
- golangpkg
- rubygemrev
- cratedownloads
- openalexwork
- openalexauthor
- semanticscholar
- datacite
- restcountry
- wikisummary
- archiveorg
- hnsearch
- hnuser
- wikipv
- musicbrainzartist
- openfoodfacts
- cidrinfo
- passwordcheck
- base64
- hashtext
- qrcode
- dnsptrrange
- jwtdecode
- reddit_user
- reddit_sub
- huggingface
- steam_user
- codeforces
- leetcode_user
- npmorg
- emailrep
- arxiv
- pubmed
- zenodo
- dblp
- unpaywall
- ltcaddr
- dogeaddr
- xrpaddr
- soladdr
- opencorp
- gleif_name
- fccid
- smtpbanner
- disposable
- zonetransfer
- ctlogsearch
- webfinger
- srvlookup
- nstrace
- rdap_domain
- csp_parse
- sri_check
- clickjacking
- referrer_pol
- permissions_pol
- ipv4classify
- dnsrecon
- portlookup
- mimetype
- httpcode
- unixperm
- unicode_lookup
- timezone_info
- base_convert
- ip_math
- latlonformat
- regdomain
- tldinfo
- emailformat
- teamcymru
- whoisserver
- robotsmeta
- numlookup
- phonefmt
- phonenanp
- phonecc
- phonepivot
- phoneapps
- phonespam
- phonevcard
- imageexif
- imagegps
- imagemeta
- imagehash
- imagecolors
- imagerev
- imagephash
- imagethumb
- imageicc
- imagechunks
- imagexmp
- imagelsb
- quakes
- iss
- spacepeople
- airquality
- marineweather
- flightsnear
- whatsnearby
- maidenhead
- pluscode
- antipode
- geodist
- moonphase
- morse
- nato
- roman
- caesar
- snowflake
- ulid
- cron
- hexdump
- numwords
- jsonfmt
- passentropy
- cryptoprice
- agify
- genderize
- nationalize
- randomuser
- holidays
- binarytext
- rot47
- ascii85
- emoji
- slug
- wordcount
- ipint
- tempconv
- disasters
- spaceweather
- weatheralerts
- onthisday
- trendingwiki
- btcfees
- blockheight
- cryptomarket
- coininfo
- jslibs
- htmlcomments
- formaudit
- metatags
- telegram_channel
- linktree
- imei
- creditcard
- ean
- punycode
- homoglyph
- base58
- vatid
- swiftbic
- utm
- mgrs
- bearing
- passgen
- casify
- leet
- atbash
- railfence
- rdap
- ghevents
- cratestats
- isin
- barcode
- macvendor
- vigenere
- base36
- goproxy
- checksum
- sha256lookup
- crc32
- rot13
- spamhauslookup
- isexitnode
- asnlookup
- hostname
- portquick
- dnsquery
- creditcardtest
- htmlencode
- disposablecheck
- quoted_printable
- base32
- uuencode
- semver
- macvalid
- uuid_validate
- datauri
- stringmetrics
- whois_check
- hibp
- hibp_email
- leakcheck
- hudsonrock
- paste_email
- paste_domain
- gh_dorking
- gh_secret_scan
- intelx_email
- dehashed_domain
- breachdirectory
- snusbase_hash
- wayback_leaks
- trufflehog_url
- comb_search
- leaklookup
- cdxwayback
- cfradar
- bgphistory
- dnsgraph
- github_code
- pageinfo
- jarm
- threatcrowd
- apileak
- hibp_breaches
- breachdb
- password_dumps
- ssn_check
- phone_leak
- api_key_scan
- robotstxt_history
- exploit_cve
- cve_timeline
- cve_poc_checker
- mitre_technique
- cisa_alerts
- ransomware_tracker
- threat_actor
- malware_family
- ioc_reputation
- zerodday_timeline
- apt_track
- botnet_tracker
- c2_infrastructure
- breach_aggregator
- darkweb_monitor
- credential_stuffing
- supply_chain_risk
- vuln_feed
- cve_severity
- threat_pattern
- emerging_threats
- phishing_intel
- infra_fingerprint
- attack_surface
- youtube
- soundcloud
- vimeo
- deviantart
- sec_edgar
- binlookup
- github_trending
- hackernews_front
- apod
- random_fact
- tempmail
- urban
- ddg_instant
- gdelt
- tiktok
- revimg
- correlate_sweep
- person_sweep
- agent_manifest
This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what
the server actually exposes, not what its listing claims.
Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.