
Remote MCP Server
Hunt.io now has a remote MCP server at mcp.hunt.io with OAuth support, so you can connect AI tools like Claude directly to Hunt data without building a custom integration.
PKCE S256 is supported for browser-based clients
Authentication uses your existing API key, and dedicated MCP API keys can be created with fixed scopes
18 tools available out of the box
Organizations can manage MCP activation and access gating at the org level


Threat Enrichment Data Included
Instead of simple reputation scores, it delivers infrastructure-level context built from live scanning, validation, and ongoing monitoring. Each response combines multiple intelligence layers into a single, automation-ready result.
Certificates & Cryptography
TLS certificates, serial numbers, issuers, fingerprints, and observed usage patterns.
Malware & Tooling Signals
Malware families, tooling indicators, and infrastructure linked to known threats.
Network & Protocol Fingerprinting
JA4 and protocol-level fingerprints revealing behavioral patterns.
Exposed Infrastructure
Open directories, exposed services, and misconfigured assets observed in the wild.
Honeypots & Deception Signals
Indicators showing interaction with honeypots or research infrastructure.
Phishing & Abuse Indicators
Infrastructure associated with phishing or abuse campaigns when observed.

Why it's different
Built From Live Scanning
All enrichment is powered by Hunt's own internet-wide scanning and validation.
Designed for Automation
Consistent schemas, timestamps, and structured fields designed for pipelines and integrations.
Infrastructure Context Over Raw IOCs
Understand how an IP fits into attacker's infrastructure, not just whether it appeared in a list.

Get your API key and start enriching IP addresses immediately.

What does the IP Enrichment API return for an IP?
Structured enrichment blocks including certificates, malware signals, network and protocol fingerprints, exposed directories, phishing indicators, and timestamps showing observed activity.
How is this different from reputation or blacklist APIs?
The API focuses on infrastructure behavior and attacker tooling rather than static reputation scores.
How do I access the IP Enrichment API ?
Access is provided via API key and standard REST requests.
What formats are supported?
Responses are available in JSON and GZ formats.
