Skip to main content
The FalconFeeds API (dubbed Merlin) requires an active paid subscription. Ensure your account is active before making API requests.

Base URL

All API requests must be made to the following base URL:

What You Can Access

The Merlin API gives you programmatic access to:
  • Threat Feeds - Posts from ransomware groups, data breach announcements, malware campaigns, and more
  • Threat Actors - Detailed profiles of known threat actor groups and individuals
  • CVEs - Common Vulnerabilities and Exposures data enriched with threat intelligence
  • IOCs - Indicators of Compromise including IPs, domains, URLs, and file hashes
  • Categories - Taxonomy of threat feed classifications

Next Steps

Authentication

Learn how to authenticate your API requests using Bearer tokens.

API Credits

Understand how API credits work and how to monitor your usage.

Response Codes

Reference for all HTTP response codes returned by the API.

API Reference

Browse all available endpoints and their parameters.