The FalconFeeds API (dubbed Merlin) requires an active paid subscription. Ensure your account is active before making API requests.
Base URL
All API requests must be made to the following base URL:What You Can Access
The Merlin API gives you programmatic access to:- Threat Feeds - Posts from ransomware groups, data breach announcements, malware campaigns, and more
- Threat Actors - Detailed profiles of known threat actor groups and individuals
- CVEs - Common Vulnerabilities and Exposures data enriched with threat intelligence
- IOCs - Indicators of Compromise including IPs, domains, URLs, and file hashes
- Categories - Taxonomy of threat feed classifications
Next Steps
Authentication
Learn how to authenticate your API requests using Bearer tokens.
API Credits
Understand how API credits work and how to monitor your usage.
Response Codes
Reference for all HTTP response codes returned by the API.
API Reference
Browse all available endpoints and their parameters.