# Censys Documentation Documentation > The Censys documentation site contains information about how to use the Censys Platform, Platform APIs, Attack Surface Management, Legacy Search, and Data Downloads. ## Guides - [Internet Scanning](https://docs.censys.com/docs/internet-scanning.md) - [Scanning FAQs](https://docs.censys.com/docs/scanning-faq.md) - [Release Notes](https://docs.censys.com/docs/release-notes.md) - [Research Access to Censys Data](https://docs.censys.com/docs/research-access-to-censys-data.md) - [Opt Out of Data Collection](https://docs.censys.com/docs/opt-out-of-data-collection.md) - [Policy for Enhancement Requests](https://docs.censys.com/docs/policy-for-enhancement-requests.md) - [Policy for Sharing Censys Rapid Response Queries](https://docs.censys.com/docs/policy-for-sharing-censys-rapid-response-queries.md) - [Get Started with the Censys Platform](https://docs.censys.com/docs/getting-started-1.md) - [Quick Start Guide](https://docs.censys.com/docs/platform-quickstart-guide.md) - [Feature and Data Access Tiers](https://docs.censys.com/docs/data-access-tiers-entitlements.md) - [Report Builder](https://docs.censys.com/docs/platform-report-builder.md) - [Transition to Censys Platform from Legacy Search](https://docs.censys.com/docs/transition-to-censys-platform.md) - [Platform Transition Guide for Legacy Search Enterprise Customers](https://docs.censys.com/docs/platform-transition-guide-enterprise.md) - [Transition Guides for Free Users, Solo, and Teams Subscribers](https://docs.censys.com/docs/transition-guides-for-free-solo-and-teams-subscribers.md) - [Platform API Transition Guide](https://docs.censys.com/docs/platform-api-transition-guide.md) - [Dataset Differences: Censys Platform vs. Legacy Search](https://docs.censys.com/docs/dataset-differences-legacy-search-censys-platform.md) - [Censys Platform Syntax Differences](https://docs.censys.com/docs/censys-platform-syntax-differences.md) - [Query Converter](https://docs.censys.com/docs/query-converter.md) - [Active DNS](https://docs.censys.com/docs/platform-active-dns.md) - [AI Features and Privacy Settings](https://docs.censys.com/docs/platform-privacy-ai-settings.md) - [Audit Log](https://docs.censys.com/docs/platform-audit-log.md) - [Delete Your Account ](https://docs.censys.com/docs/platform-delete-account.md) - [Multi-factor Authentication](https://docs.censys.com/docs/platform-mfa.md) - [Organization Management](https://docs.censys.com/docs/platform-org-management.md) - [Organization Switcher](https://docs.censys.com/docs/platform-organization-switcher.md) - [Role-based Access Control](https://docs.censys.com/docs/role-based-access-control.md) - [SAML Authentication](https://docs.censys.com/docs/platform-authentication.md) - [SCIM Configuration](https://docs.censys.com/docs/scim-configuration.md): Setup SAML/SCIM in OKTA IDP for the Censys Platform - [Adversary Investigation](https://docs.censys.com/docs/platform-threat-hunting.md) - [Adversary Investigation MCP Server](https://docs.censys.com/docs/platform-threat-hunting-mcp-server.md) - [CensEye](https://docs.censys.com/docs/platform-threat-hunting-use-censeye-to-build-detections.md) - [Certificate History](https://docs.censys.com/docs/platform-threat-hunting-use-cert-history-to-build-better-detections.md) - [Investigation Manager](https://docs.censys.com/docs/platform-investigation-manager.md) - [Live Discovery](https://docs.censys.com/docs/platform-threat-hunting-use-live-scan-and-rescan-to-validate-infrastructure.md) - [Open Directory Data and Threats](https://docs.censys.com/docs/platform-open-directory-data-threats.md) - [Threat Data](https://docs.censys.com/docs/platform-threat-hunting-threat-hunting-dataset.md) - [Tracked Threats](https://docs.censys.com/docs/platform-explore-threats.md) - [Browser Extension](https://docs.censys.com/docs/platform-browser-extension.md) - [Censys Assistant](https://docs.censys.com/docs/platform-censys-assistant.md) - [Censys Credits ](https://docs.censys.com/docs/censys-credits.md) - [Credits for Enterprise Organizations](https://docs.censys.com/docs/platform-credits-enterprise.md) - [Credits for Free and Starter Users](https://docs.censys.com/docs/platform-credits-free-starter.md) - [Manage and Monitor Censys Credits](https://docs.censys.com/docs/manage-and-monitor-censys-credits.md) - [Censys Query Language](https://docs.censys.com/docs/censys-query-language.md) - [Query Assistant](https://docs.censys.com/docs/platform-query-assistant.md) - [Relative Time in CenQL](https://docs.censys.com/docs/use-relative-time-in-queries.md) - [Regex in CenQL](https://docs.censys.com/docs/platform-regex-cenql.md) - [Collections](https://docs.censys.com/docs/platform-collections.md) - [Create, Delete, or Archive a Collection](https://docs.censys.com/docs/platform-create-a-collection.md) - [Collection Email Notifications](https://docs.censys.com/docs/platform-collection-emails.md) - [Collection Webhooks](https://docs.censys.com/docs/platform-collections-webhooks.md) - [Slack Collection Webhooks](https://docs.censys.com/docs/platform-collections-configure-webhooks-for-slack.md) - [Share a Collection](https://docs.censys.com/docs/platform-share-collection.md) - [Track and Monitor Collections](https://docs.censys.com/docs/platform-manage-and-monitor-collections.md) - [Troubleshooting Collection Issues](https://docs.censys.com/docs/platform-troubleshoot-collections.md) - [Critical Infrastructure](https://docs.censys.com/docs/platform-ics-protocols.md) - [Host Enrichment API](https://docs.censys.com/docs/host-enrichment.md) - [Live Rescan](https://docs.censys.com/docs/platform-live-rescan.md) - [Platform API and SDKs](https://docs.censys.com/docs/platform-api.md) - [Platform CLI Tool](https://docs.censys.com/docs/platform-cli.md) - [Platform Data](https://docs.censys.com/docs/platform-datasets.md) - [Platform Application and Endpoint Data](https://docs.censys.com/docs/platform-application-endpoint-data.md) - [Platform Certificate Dataset](https://docs.censys.com/docs/platform-certificate-dataset.md) - [Platform Historical Data](https://docs.censys.com/docs/platform-historical-data.md) - [Platform Host Dataset](https://docs.censys.com/docs/platform-host-dataset.md) - [Host Reputation](https://docs.censys.com/docs/platform-reputation-scores.md) - [Platform JARM Fingerprints and Context Hashes](https://docs.censys.com/docs/platform-jarm-fingerprints.md) - [Platform Web Property Dataset](https://docs.censys.com/docs/platform-web-property-dataset.md) - [Platform FAQs](https://docs.censys.com/docs/censys-platform-faq.md) - [Platform Integrations](https://docs.censys.com/docs/platform-integrations.md) - [Google SecOps SOAR Integration](https://docs.censys.com/docs/platform-google-secops-integration.md) - [Microsoft Sentinel Integration](https://docs.censys.com/docs/platform-microsoft-sentinel-integration.md) - [Palo Alto Cortex XSOAR/XSIAM Integration](https://docs.censys.com/docs/platform-palo-alto-cortex-xsoar-integration.md) - [Splunk Platform Integration](https://docs.censys.com/docs/platform-splunk-siem-integration.md) - [Splunk SOAR Integration](https://docs.censys.com/docs/platform-splunk-soar-integration.md) - [Platform MCP Server](https://docs.censys.com/docs/platform-mcp-server.md) - [Tags and Comments](https://docs.censys.com/docs/platform-tags-comments.md) - [Third-party Data Context](https://docs.censys.com/docs/platform-enrichment.md) - [Web Screenshots](https://docs.censys.com/docs/platform-web-screenshots.md) - [Get Started with Censys ASM](https://docs.censys.com/docs/asm-get-started.md) - [Quick Start Guide](https://docs.censys.com/docs/asm-quick-start-guide.md) - [ASM Overview Dashboard](https://docs.censys.com/docs/asm-dashboard.md) - [Trends & Benchmarks](https://docs.censys.com/docs/asm-trends-benchmarks.md) - [Ports & Protocols](https://docs.censys.com/docs/asm-ports-protocols-dashboard.md) - [Metrics](https://docs.censys.com/docs/asm-metrics.md) - [Reports](https://docs.censys.com/docs/asm-reports.md) - [Seed Your Attack Surface](https://docs.censys.com/docs/asm-seed-your-attack-surface.md) - [Use Censys to Find Seeds](https://docs.censys.com/docs/asm-use-censys-to-find-seeds.md) - [Understand and Investigate Your Attack Surface](https://docs.censys.com/docs/asm-understand-investigate-attack-surface.md) - [Build, Save, and Automate ASM Queries](https://docs.censys.com/docs/asm-build-save-automate-queries.md) - [Example ASM Queries](https://docs.censys.com/docs/asm-example-queries.md) - [ASM Activity Logbook](https://docs.censys.com/docs/asm-logbook.md) - [Logbook REST API Event Catalog](https://docs.censys.com/docs/asm-logbook-event-catalog-api.md) - [ASM Workspaces and User Access ](https://docs.censys.com/docs/asm-workspaces-user-access.md) - [ASM Integrations](https://docs.censys.com/docs/asm-integrations.md) - [Cloud Connectors](https://docs.censys.com/docs/asm-cloud-connectors.md) - [AWS Hosted Cloud Connector](https://docs.censys.com/docs/asm-aws-cloud-connector.md) - [Azure Hosted Cloud Connector](https://docs.censys.com/docs/asm-azure-cloud-connector.md) - [GCP Hosted Cloud Connector](https://docs.censys.com/docs/asm-gcp-cloud-connector.md) - [Atlassian Jira](https://docs.censys.com/docs/asm-atlassian-jira.md) - [Cisco Webex Teams](https://docs.censys.com/docs/asm-cisco-webex-teams.md) - [Google Security Operations](https://docs.censys.com/docs/asm-google-secops.md) - [Microsoft Sentinel](https://docs.censys.com/docs/asm-microsoft-sentinel.md) - [Microsoft Teams](https://docs.censys.com/docs/asm-microsoft-teams.md) - [Qualys VMDR](https://docs.censys.com/docs/asm-qualys-vmdr.md) - [Rapid Response Email Notifications](https://docs.censys.com/docs/asm-rapid-response-email-notifications.md) - [Risk Email Notifications](https://docs.censys.com/docs/asm-email-notifications.md) - [ServiceNow CMDB](https://docs.censys.com/docs/asm-servicenow-cmdb.md) - [ServiceNow ITSM](https://docs.censys.com/docs/asm-servicenow-itsm.md) - [ServiceNow VR](https://docs.censys.com/docs/asm-servicenow-vr.md) - [Slack](https://docs.censys.com/docs/asm-slack.md) - [Splunk](https://docs.censys.com/docs/asm-splunk.md) - [Tenable Vulnerability Management](https://docs.censys.com/docs/asm-tenable-vm.md) - [Webhook](https://docs.censys.com/docs/asm-webhook.md) - [Wiz](https://docs.censys.com/docs/asm-wiz.md) - [ASM MCP Server](https://docs.censys.com/docs/asm-mcp-server.md) - [Censys Assistant in ASM](https://docs.censys.com/docs/asm-censys-assistant.md) - [Insights](https://docs.censys.com/docs/asm-insights.md) - [Inventory Assets](https://docs.censys.com/docs/asm-inventory-assets.md) - [Cloud Asset Context](https://docs.censys.com/docs/asm-cloud-asset-context.md) - [Guide: Activate Cloud Asset Context in ASM](https://docs.censys.com/docs/asm-activate-cloud-asset-context.md) - [Certificates](https://docs.censys.com/docs/asm-certificate-assets.md) - [Certificate Data Definitions (ASM)](https://docs.censys.com/docs/asm-certificate-data-definitions.md) - [Domains](https://docs.censys.com/docs/asm-domain-assets.md) - [Domain Data Definitions (ASM)](https://docs.censys.com/docs/asm-domain-data-definitions.md) - [Exclude Assets](https://docs.censys.com/docs/asm-exclude-assets.md) - [Hosts](https://docs.censys.com/docs/asm-host-assets.md) - [Host Data Definitions (ASM)](https://docs.censys.com/docs/asm-host-data-definitions.md) - [Storage Buckets](https://docs.censys.com/docs/asm-storage-bucket-assets.md) - [Storage Bucket Data Definitions (ASM)](https://docs.censys.com/docs/asm-storage-bucket-data-definitions.md) - [Web Entities](https://docs.censys.com/docs/asm-web-entity-assets.md) - [Web Entity Data Definitions (ASM)](https://docs.censys.com/docs/asm-web-entity-data-definitions.md) - [Risks](https://docs.censys.com/docs/asm-risks.md) - [Configure Risks](https://docs.censys.com/docs/asm-configure-risks.md) - [CVE Risks](https://docs.censys.com/docs/asm-cve-risks.md) - [CVE Risks FAQ](https://docs.censys.com/docs/asm-cve-risks-faq.md) - [Risk Categories](https://docs.censys.com/docs/asm-risk-categories.md) - [Dangling DNS Risks](https://docs.censys.com/docs/asm-dangling-dns-risks.md) - [Shrink Your Attack Surface](https://docs.censys.com/docs/shrink-your-attack-surface.md) - [Secure Subsidiaries, Acquisitions, and Mergers](https://docs.censys.com/docs/asm-secure-subsidiaries-acquisitions-and-mergers.md) - [Eliminate Shadow IT](https://docs.censys.com/docs/asm-eliminate-shadow-it.md) - [Identify Unsanctioned Cloud Usage ](https://docs.censys.com/docs/asm-identify-unsanctioned-cloud-usage.md) - [ASM API](https://docs.censys.com/docs/asm-api.md) - [Inventory Aggregation API](https://docs.censys.com/docs/asm-inventory-aggregation-api.md) - [Get Started](https://docs.censys.com/docs/ls-get-started.md) - [Quick Start](https://docs.censys.com/docs/ls-quick-start.md) - [Introductory Use Cases](https://docs.censys.com/docs/ls-introductory-use-cases.md) - [Export Search Results](https://docs.censys.com/docs/ls-export-results.md) - [Censys Search Language](https://docs.censys.com/docs/ls-csl.md) - [Regular Expression (Regex) in Legacy Search](https://docs.censys.com/docs/ls-regex.md) - [Advanced Legacy Search Methods and Queries](https://docs.censys.com/docs/ls-advanced-methods-queries.md) - [Legacy Search and CSL FAQs](https://docs.censys.com/docs/ls-csl-faqs.md) - [Legacy Search Datasets](https://docs.censys.com/docs/ls-datasets-folder.md) - [Hosts](https://docs.censys.com/docs/ls-hosts.md) - [Virtual Hosts](https://docs.censys.com/docs/ls-intro-virtual-hosts.md) - [Autonomous System](https://docs.censys.com/docs/ls-host-autonomous-system.md) - [C2 Label](https://docs.censys.com/docs/ls-c2-label.md) - [DNS](https://docs.censys.com/docs/ls-dns.md) - [JARM](https://docs.censys.com/docs/ls-jarm.md) - [Labels](https://docs.censys.com/docs/ls-labels.md) - [Location](https://docs.censys.com/docs/ls-host-location.md) - [Operating System](https://docs.censys.com/docs/ls-host-os.md) - [Service Information](https://docs.censys.com/docs/ls-service-information.md) - [Software](https://docs.censys.com/docs/ls-software.md) - [TLS](https://docs.censys.com/docs/ls-tls.md) - [WHOIS](https://docs.censys.com/docs/ls-whois.md) - [Certificates](https://docs.censys.com/docs/ls-certificates.md) - [Certificate Transparency and Precertificates](https://docs.censys.com/docs/ls-ct-precerts.md) - [Lite Certificates](https://docs.censys.com/docs/ls-lite-certificates.md) - [CVE Context](https://docs.censys.com/docs/ls-cve-context.md) - [Legacy Search Administration and Authentication](https://docs.censys.com/docs/ls-identity-access.md) - [Manage a Team](https://docs.censys.com/docs/ls-manage-a-team.md) - [View Your Quota](https://docs.censys.com/docs/ls-view-quota.md) - [Enable and Configure SAML](https://docs.censys.com/docs/ls-saml-sso.md) - [Microsoft AD FS SSO](https://docs.censys.com/docs/ls-ms-ad-fs-sso.md) - [Azure Active Directory SSO](https://docs.censys.com/docs/ls-aad-sso.md) - [Okta SSO](https://docs.censys.com/docs/ls-okta-sso.md) - [Ping Identity SSO](https://docs.censys.com/docs/ls-ping-identity-sso.md) - [Delete Account or Cancel Subscription](https://docs.censys.com/docs/ls-delete-account-cancel-subscription.md) - [Legacy Search Video Walkthroughs](https://docs.censys.com/docs/ls-video-walkthroughs.md) - [Find Malicious Infrastructure Assets](https://docs.censys.com/docs/ls-find-malicious-infrastructure-video.md) - [Vendor Compliance](https://docs.censys.com/docs/ls-vendor-compliance-video.md) - [Monitor SSL TLS Certs](https://docs.censys.com/docs/ls-monitor-ssl-tls-certs-video.md) - [Find Rogue Assets](https://docs.censys.com/docs/ls-find-rogue-assets-video.md) - [Legacy Search API](https://docs.censys.com/docs/ls-api.md) - [Legacy Search and ASM Python CLI](https://docs.censys.com/docs/search-and-asm-python-cli.md) - [Censeye Automated Threat Hunting Tool](https://docs.censys.com/docs/censeye-automated-threat-hunting-tool.md) - [Legacy Search Integrations](https://docs.censys.com/docs/ls-integrations.md) - [Platform Data Downloads](https://docs.censys.com/docs/platform-data-downloads.md) - [Download Censys Universal Internet Dataset](https://docs.censys.com/docs/ls-download-censys-universal-internet-dataset.md) - [Download Certs 2.0 Data](https://docs.censys.com/docs/ls-download-certs-2-data.md) ## API Reference - [Get Started with Censys APIs](https://docs.censys.com/reference/get-started.md) - [Aggregate results for a search query](https://docs.censys.com/reference/v3-globaldata-search-aggregate.md): Aggregate results for a Platform search query. This functionality is equivalent to the [Report Builder](https://docs.censys.com/docs/platform-report-builder#/) in the Platform web UI. - [Convert Legacy Search queries to Platform queries](https://docs.censys.com/reference/v3-globaldata-search-convert.md): Convert Censys Search Language queries used in Legacy Search into Censys Query Language (CenQL) queries for use in the Platform.

Reference the [documentation on CenQL](https://docs.censys.com/docs/censys-query-language) for more information about query syntax. - [Get a certificate](https://docs.censys.com/reference/v3-globaldata-asset-certificate.md): Retrieve information about a single certificate. A certificate ID is its SHA-256 fingerprint in the Censys dataset. - [Get a certificate in PEM format](https://docs.censys.com/reference/v3-globaldata-asset-certificate-raw.md): Retrieve the raw PEM-encoded format of a certificate. A certificate ID is its SHA-256 fingerprint in the Censys dataset. - [Get a host](https://docs.censys.com/reference/v3-globaldata-asset-host.md): Retrieve information about a single host. A host ID is its IP address. - [Get a web property](https://docs.censys.com/reference/v3-globaldata-asset-webproperty.md): Retrieve information about a single web property. Web properties are identified using a combination of a hostname and port joined with a colon, such as `platform.censys.io:80`. - [Get DNS names that resolved to an IP (aggregated bounds)](https://docs.censys.com/reference/v3-globaldata-dns-ip-resolution-bound.md): Retrieve the domain names that resolved to an IP during a time frame. You can narrow results with `record_types` (A or AAAA).

Results are aggregated per domain name and multiple distinct ranges for a name will be grouped into one row of results. For example, if `censys.com` resolved to `1.1.1.1` from January 1 to January 7 during two different ranges of January 1 to January 3 and January 5 to January 7, and you targeted January 1 through January 7 with your API call, then this endpoint will group those ranges into one entry for `censys.com` in the response.

To retrieve domain names for an IP with each record broken down by time range, use the [ranges endpoint](https://docs.censys.com/reference/v3-globaldata-dns-ip-resolution-ranges)

This endpoint is only available to organizations on the Censys Search and Censys Core plans.

[Learn more about Censys Active DNS](https://docs.censys.com/docs/platform-active-dns). - [Get DNS names that resolved to an IP (ranges)](https://docs.censys.com/reference/v3-globaldata-dns-ip-resolution-ranges.md): Retrieve the domain names that resolved to an IP during a time frame. You can narrow results with `record_types` (A or AAAA).

Record results are broken down based on time range. For example, if `censys.com` resolved to `1.1.1.1` from January 1 to January 7 during two different ranges of January 1 to January 3 and January 5 to January 7, and you targeted January 1 through January 7 with your API call, then this endpoint will return one row for each of those distinct ranges.

To retrieve domain names for an IP with each result aggregated by name, use the [bounds endpoint endpoint](https://docs.censys.com/reference/v3-globaldata-dns-ip-resolution-bound).

This endpoint is only available to organizations on the Censys Search and Censys Core plans.

[Learn more about Censys Active DNS](https://docs.censys.com/docs/platform-active-dns). - [Get DNS resolution records for a name (aggregated bounds)](https://docs.censys.com/reference/v3-globaldata-dns-name-resolution-bound.md): Retrieve the DNS resolution records for a name. This endpoint returns observed A, AAAA, MX, NS, SOA, and TXT records for the name you provide. You can filter by one or more record types using record_types.

Results are aggregated per record distinct ranges for a record will be grouped into one row of results. For example, if `censys.com` resolved to `1.1.1.1` from January 1 to January 7 during two different ranges of January 1 to January 3 and January 5 to January 7, and you targeted January 1 through January 7 with your API call, then this endpoint will group those ranges into one entry for the `1.1.1.1` A record in the response.

To retrieve records for a name with each record broken down by time range, use the [ranges endpoint](https://docs.censys.com/reference/v3-globaldata-dns-name-resolution-ranges).

This endpoint is only available to organizations on the Censys Search and Censys Core plans.

[Learn more about Censys Active DNS](https://docs.censys.com/docs/platform-active-dns). - [Get DNS resolution records for a name (ranges)](https://docs.censys.com/reference/v3-globaldata-dns-name-resolution-ranges.md): Retrieve the records that resolved for a name during a time frame. This endpoint returns observed A, AAAA, MX, NS, SOA, and TXT records for the name you provide. You can filter by one or more record types using `record_types`.

Record results are broken down based on time range. For example, if `censys.com` resolved to `1.1.1.1` from January 1 to January 7 during two different ranges of January 1 to January 3 and January 5 to January 7, and you targeted January 1 through January 7 with your API call, then this endpoint will return one row for each of those distinct ranges for the `1.1.1.1` A record.

To retrieve records for a name with each result aggregated per record, use the [bounds endpoint endpoint](https://docs.censys.com/reference/v3-globaldata-dns-name-resolution-bound).

This endpoint is only available to organizations on the Censys Search and Censys Core plans.

[Learn more about Censys Active DNS](https://docs.censys.com/docs/platform-active-dns). - [Get host enrichment](https://docs.censys.com/reference/v3-globaldata-asset-host-enrichment.md): Retrieve enrichment data for a single host. This endpoint is optimized for high-volume SOC enrichment use cases.

This endpoint does not consume standard Censys credits. Core organizations may perform up to 20,000 enrichment calls per day. Core + Unlimited Enrichment organizations may perform an unlimited amount of enrichment calls per day.

[Learn more about the enrichment API here](https://docs.censys.com/docs/host-enrichment). - [Get host event history](https://docs.censys.com/reference/v3-globaldata-asset-host-timeline.md): Retrieve event history for a host. A host ID is its IP address.

Note that when a service protocol changes after a new scan (for example, from `UNKNOWN` to `NETBIOS`), this information will be reflected in the `scan` object. - [Get scan status](https://docs.censys.com/reference/v3-globaldata-scans-get.md): Retrieve the current status of a scan by its ID. This endpoint works for both [Live Discovery scans](https://docs.censys.com/reference/v3-threathunting-scans-discovery#/) and [Live Rescans](https://docs.censys.com/reference/v3-globaldata-scans-rescan#/).

If the scan was successful, perform a lookup on the target asset to retrieve detailed scan information.

This endpoint is available to all Enterprise customers. This endpoint does not cost any credits to execute. - [Get service history for a host](https://docs.censys.com/reference/v3-globaldata-service-on-host.md): Retrieve historical service observations for a host. This endpoint returns time ranges during which services were detected on the host.

You can define a specific time frame of interest. If you do not specify a time frame, this endpoint will search the historical dataset that is available to your account.

You can filter by port number, protocol, and transport protocol. - [Live Rescan: Initiate a new rescan](https://docs.censys.com/reference/v3-globaldata-scans-rescan.md): Initiate a rescan for a known host service at a specific IP and port (`ip:port`) or hostname and port (`hostname:port`). This is equivalent to the [Live Rescan](https://docs.censys.com/docs/platform-live-rescan#/) feature available in the UI, but you can also target web properties in addition to hosts.

The scan may take several minutes to complete. The response will contain a scan ID that you can use to [monitor the scan's status](https://docs.censys.com/reference/v3-globaldata-scans-get#/). After the scan completes, perform a lookup on the target asset to retrieve detailed scan information.

This endpoint is available to all Enterprise customers. It costs 10 credits to execute. - [Retrieve multiple certificates](https://docs.censys.com/reference/v3-globaldata-asset-certificate-list-post.md): Retrieve information about multiple certificates. You can retrieve up to 1,000 certificates per call. A certificate ID is its SHA-256 fingerprint in the Censys dataset. - [Retrieve multiple certificates](https://docs.censys.com/reference/v3-globaldata-asset-certificate-list.md): Retrieve information about multiple certificates. A certificate ID is its SHA-256 fingerprint in the Censys dataset.

The GET method of this endpoint is deprecated, but will continue to be supported for backwards compatibility. Please use the [POST variant](https://docs.censys.com/reference/v3-globaldata-asset-certificate-list-post#/) of this endpoint instead. - [Retrieve multiple certificates in PEM format](https://docs.censys.com/reference/v3-globaldata-asset-certificate-list-raw-post.md): Retrieve the raw PEM-encoded format for multiple certificates. You can retrieve up to 1,000 certificates per call. A certificate ID is its SHA-256 fingerprint in the Censys dataset. - [Retrieve multiple certificates in PEM format](https://docs.censys.com/reference/v3-globaldata-asset-certificate-list-raw.md): Retrieve the raw PEM-encoded format for multiple certificates. A certificate ID is its SHA-256 fingerprint in the Censys dataset.

The GET method of this endpoint is deprecated, but will continue to be supported for backwards compatibility. Please use the [POST variant](https://docs.censys.com/reference/v3-globaldata-asset-certificate-list-raw-post#/) of this endpoint instead. - [Retrieve multiple hosts](https://docs.censys.com/reference/v3-globaldata-asset-host-list-post.md): Retrieve information about multiple hosts. You can retrieve up to 100 hosts per call. A host ID is its IP address. - [Retrieve multiple hosts](https://docs.censys.com/reference/v3-globaldata-asset-host-list.md): Retrieve information about multiple hosts. A host ID is its IP address.

The GET method of this endpoint is deprecated, but will continue to be supported for backwards compatibility. Please use the [POST variant](https://docs.censys.com/reference/v3-globaldata-asset-host-list-post#/) of this endpoint instead. - [Retrieve multiple web properties](https://docs.censys.com/reference/v3-globaldata-asset-webproperty-list-post.md): Retrieve information about multiple web properties. You can retrieve up to 100 web properties per call. Web properties are identified using a combination of a hostname and port joined with a colon, such as `platform.censys.io:80`. - [Retrieve multiple web properties](https://docs.censys.com/reference/v3-globaldata-asset-webproperty-list.md): Retrieve information about multiple web properties. Web properties are identified using a combination of a hostname and port joined with a colon, such as `platform.censys.io:80`.

The GET method of this endpoint is deprecated, but will continue to be supported for backwards compatibility. Please use the [POST variant](https://docs.censys.com/reference/v3-globaldata-asset-webproperty-list-post#/) of this endpoint instead. - [Run a search query](https://docs.censys.com/reference/v3-globaldata-search-query.md): Run a search query across Censys data. Reference the [documentation on Censys Query Language](https://docs.censys.com/docs/censys-query-language#/) for information about query syntax. Host services that match your search criteria will be returned in a `matched_services` object. - [Aggregate results for a search query within a collection](https://docs.censys.com/reference/v3-collections-search-aggregate.md): Aggregate results for a Platform search query that targets a collection's assets. This functionality is equivalent to the [Report Builder](https://docs.censys.com/docs/platform-report-builder#/) in the Platform web UI. - [Create a collection](https://docs.censys.com/reference/v3-collections-crud-create.md): Create a new collection.

This endpoint does not cost credits to execute. - [Delete a collection](https://docs.censys.com/reference/v3-collections-crud-delete.md): Delete a collection.

This endpoint does not cost credits to execute. - [Get a collection](https://docs.censys.com/reference/v3-collections-crud-get.md): Retrieve information about a collection. Retrieved information includes its name, query, description, status, and asset count.

This endpoint does not cost credits to execute. - [Get a collection's events](https://docs.censys.com/reference/v3-collections-list-events.md): Retrieve the event history for a collection. This includes the addition or removal of assets as well as collection status changes.

This endpoint does not cost credits to execute. - [List collections](https://docs.censys.com/reference/v3-collections-crud-list.md): List all collections for an organization. Retrieved information includes collection ID, name, query, description, status, and asset count.

This endpoint does not cost credits to execute. - [Run a search query within a collection](https://docs.censys.com/reference/v3-collections-search-query.md): Run a search query across a collection's assets. Reference the [documentation on Censys Query Language](https://docs.censys.com/docs/censys-query-language#/) for information about query syntax. Host services that match your search criteria will be returned in a `matched_services` object. - [Update a collection](https://docs.censys.com/reference/v3-collections-crud-update.md): Update a collection's name, description, and/or query.

This endpoint does not cost credits to execute. - [CensEye: Create a pivot analysis job](https://docs.censys.com/reference/v3-threathunting-censeye-jobs-create.md): Create an asynchronous CensEye pivot analysis job for a host, web property, or certificate. The job extracts [default pivot fields](https://docs.censys.com/docs/platform-threat-hunting-use-censeye-to-build-detections#default-pivot-fields) from the target asset and counts matching documents for each field-value pair. Poll the job status endpoint to track progress, then retrieve results when complete.

To use this endpoint, your organization must have access to the Adversary Investigation module.

This endpoint costs 44 credits to execute for a host, 28 credits to execute for a web property, and 7 credits to execute for a certificate. - [CensEye: Get job results](https://docs.censys.com/reference/v3-threathunting-censeye-job-results.md): Retrieve the results of a completed CensEye pivot analysis job. Each result contains a count and the field-value pairs that were analyzed. Results may be empty if the job is still running.

Results are paginated. Use the `next_page_token` from the response to fetch subsequent pages.

To use this endpoint, your organization must have access to the Adversary Investigation module. - [CensEye: Get job status](https://docs.censys.com/reference/v3-threathunting-censeye-jobs-get.md): Retrieve the current status of a CensEye pivot analysis job. Use this to poll for completion before fetching results.

To use this endpoint, your organization must have access to the Adversary Investigation module. - [CensEye: List jobs](https://docs.censys.com/reference/v3-threathunting-censeye-jobs-list.md): List CensEye pivot analysis jobs for the current organization. Results are paginated. Optionally filter by asset (host, web property, or certificate). - [CensEye: Retrieve value counts to discover pivots](https://docs.censys.com/reference/v3-threathunting-value-counts.md): Get counts of web assets for specific field-value pairs and combinations of field-value pairs. This is similar to the [CensEye functionality](https://docs.censys.com/docs/platform-threat-hunting-use-censeye-to-build-detections#/) available in the Platform web UI, but it allows you to define specific fields of interest rather than the [default fields](https://docs.censys.com/docs/platform-threat-hunting-use-censeye-to-build-detections#default-pivot-fields) leveraged by the tool in the UI.

Each array can only target fields within the same nested object and may contain at most 5 field-value pairs. For example, you can combine `host.services.port=80` and `host.services.protocol=SSH` in the same array, but you cannot combine `host.services.port=80` and `host.location.country="United States"` in the same array. You can input multiple arrays of objects in each API call.

To use this endpoint, your organization must have access to the Adversary Investigation module. This endpoint costs 1 credit per count condition (array of objects) included in the API call. - [Get endpoint observation history for a host](https://docs.censys.com/reference/v3-threathunting-endpoint-observations-on-host.md): Retrieve historical endpoint-level hash observations for a host. This action returns time frames during which Censys observed host service endpoint body, favicon, and banner hash values. You must provide an `observation_type` and can optionally filter by a specific value using the `observation_value` parameter. You may also filter by port number.

To use this endpoint, your organization must have access to the Adversary Investigation module. - [Get host history for a certificate](https://docs.censys.com/reference/v3-threathunting-get-host-observations-with-certificate.md): Retrieve the historical observations of hosts associated with a certificate. This is useful for threat hunting, detection engineering, and timeline generation. Certificate history is also visible to Adversary Investigation users in the Platform UI on the [certificate timeline](https://docs.censys.com/docs/platform-threat-hunting-use-cert-history-to-build-better-detections#/).

You can define a specific time frame of interest. If you do not specify a time frame, this endpoint will search the historical dataset that is available to your account. You may also filter results by port and transport protocol.

This endpoint is available to organizations that have access to the Adversary Investigation module. It costs 5 credits per page of results. - [Get scan status](https://docs.censys.com/reference/v3-threathunting-scans-get.md): Retrieve the current status of a scan by its ID. This endpoint works for both [Live Discovery scans](https://docs.censys.com/reference/v3-threathunting-scans-discovery#/) and [Live Rescans](https://docs.censys.com/reference/v3-globaldata-scans-rescan#/).

If the scan was successful, perform a lookup on the target asset to retrieve detailed scan information.

This endpoint is available to all Enterprise customers. This endpoint does not cost any credits to execute. - [Get threat history for a host](https://docs.censys.com/reference/v3-threathunting-threats-on-host.md): Retrieve historical threat observations for a host. This endpoint returns time ranges during which threats were detected on the host.

You can define a specific time frame of interest. If you do not specify a time frame, this endpoint will search the historical dataset that is available to your account.

You can filter by port number, protocol, threat name, and transport protocol.

This endpoint is available to organizations that have access to the Adversary Investigation module. - [Get threat history for a web property](https://docs.censys.com/reference/v3-threathunting-threats-on-web.md): Retrieve historical threat observations for a web property. This endpoint returns time ranges during which threats were detected on the host.

You can define a specific time frame of interest. If you do not specify a time frame, this endpoint will search the historical dataset that is available to your account.

You can filter by threat name.

This endpoint is available to organizations that have access to the Adversary Investigation module. - [List active threats](https://docs.censys.com/reference/v3-threathunting-threats-list.md): Retrieve a list of active threats observed by Censys by aggregating threat IDs across hosts and web properties. Threats are active if their fingerprint has been identified on hosts or web properties by Censys scans. This information is also available on the [Explore Threats page in the Platform web UI](https://platform.censys.io/threats).

This endpoint is available to organizations that have access to the Adversary Investigation module. - [Live Discovery: Initiate a new scan](https://docs.censys.com/reference/v3-threathunting-scans-discovery.md): Initiate a scan to look for a currently unobserved service at a specific IP and port (`ip:port`) or hostname and port (`hostname:port`). This is equivalent to the [Live Discovery](https://docs.censys.com/docs/platform-threat-hunting-use-live-scan-and-rescan-to-validate-infrastructure#/) feature available in the UI, but you can also target web properties in addition to hosts.

The scan may take several minutes to complete. The response will contain a scan ID that you can use to [monitor the scan's status](https://docs.censys.com/reference/v3-threathunting-scans-get#/). After the scan completes, perform a lookup on the target asset to retrieve detailed scan information.

This endpoint is available to organizations that have access to the Adversary Investigation module. It costs 15 credits to execute this endpoint. - [Get Free user credit balance](https://docs.censys.com/reference/v3-accountmanagement-user-credits.md): Retrieve your Free user account credit balance and refresh information. To retrieve the credit balance for a Starter or Enterprise account, use the [get organization credit balance endpoint](https://docs.censys.com/reference/v3-accountmanagement-org-credits).

This endpoint does not cost any credits to execute. - [Get Free user credit usage](https://docs.censys.com/reference/v3-accountmanagement-user-credits-usage.md): Retrieve your Free user account credit consumption information over a specific date range. You must include a start date in your request.

This endpoint does not cost any credits to execute. - [Get organization member credit usage](https://docs.censys.com/reference/v3-accountmanagement-member-credits-usage.md): Retrieve credit consumption information for an organization member over a specific date range. You must include a start date in your request.

This endpoint does not cost any credits to execute. - [Get organization details](https://docs.censys.com/reference/v3-accountmanagement-org-details.md): Retrieve an organization's details, including the count of organization members broken down by role and organization settings such as AI training and MFA requirements.

This endpoint does not cost any credits to execute. - [Get organization credit balance](https://docs.censys.com/reference/v3-accountmanagement-org-credits.md): Retrieve credit balance and expiration information for an organization.

Credits expire 12 months after they are acquired.

This endpoint does not cost any credits to execute. - [Get organization credit usage](https://docs.censys.com/reference/v3-accountmanagement-org-credits-usage.md): Retrieve credit information for an organization over a specific date range. You must include a start date in your request.

Admins can obtain credit usage information for all users in their organization. Members may only retrieve usage information for their own account.

This endpoint does not cost any credits to execute. - [Invite user to organization](https://docs.censys.com/reference/v3-accountmanagement-invite-user-to-org.md): Invite a user to an organization. The user will receive an email to join the organization. This is equivalent to [adding a new member via the UI](https://docs.censys.com/docs/platform-org-management#invite-members).

Only users with the Admin role in the provided organization can perform this operation.

This endpoint does not cost any credits to execute. - [List audit log events](https://docs.censys.com/reference/v3-accountmanagement-org-audit-log-events.md): Retrieve audit log events for an organization. Use query parameters to filter events by time range, user, and event type.

This endpoint does not cost any credits to execute. - [List organization members](https://docs.censys.com/reference/v3-accountmanagement-list-org-members.md): Retrieve a paginated list of an organization's members and their user details, including their user ID, email, name, creation time, and roles.

This endpoint does not cost any credits to execute. - [Remove member from organization](https://docs.censys.com/reference/v3-accountmanagement-remove-org-member.md): Remove a user from an organization. This is equivalent to [removing a member via the UI](https://docs.censys.com/docs/platform-org-management#remove-members).

Only users with the Admin role in the provided organization can perform this operation.

This endpoint does not cost any credits to execute. - [Update a member's roles in an organization](https://docs.censys.com/reference/v3-accountmanagement-update-org-member.md): Update the roles assigned to an organization member. This operation replaces a member's roles with the list provided in the request body. To remove all roles from a member, provide an empty list. To completely remove a member from an organization, use the [remove member endpoint](https://docs.censys.com/reference/v3-accountmanagement-remove-org-member).

Only users with the Admin role in the provided organization can perform this operation.

This endpoint does not cost any credits to execute. - [SDKs](https://docs.censys.com/reference/sdks.md) - [Current API Version](https://docs.censys.com/reference/current-api-version.md) - [Create a tag](https://docs.censys.com/reference/v3-tags-create-tag.md): Create a new tag in your organization. Tags can be used to label and organize assets.

Specify a privacy setting to control visibility: `private` tags are only visible to you and organization admins, while `shared` tags are visible and manageable by all organization members.

Tag names must be unique within your organization.

This endpoint does not cost any credits to execute. - [Create a tag assignment](https://docs.censys.com/reference/v3-tags-create-assignment.md): Assign a tag to an asset. Tag assignments are only visible to members of your organization, depending on the tag's privacy settings. You must have access to the tag to assign it to an asset.

This endpoint does not cost any credits to execute. - [Delete a tag](https://docs.censys.com/reference/v3-tags-delete-tag.md): Delete a tag and all of its assignments from your organization. This action is permanent and cannot be undone.

Only the tag's creator or an organization admin can delete a `private` tag. Tags that are `shared` can be deleted by any organization member.

This endpoint does not cost any credits to execute. - [Delete a tag assignment](https://docs.censys.com/reference/v3-tags-delete-assignment.md): Remove a tag assignment from an asset. This action is permanent and cannot be undone. Removing an assignment only detaches the tag from the specified asset; the tag itself is not deleted. Only the tag's creator or an organization admin can delete an assignment for a `private` tag. Assignments for `shared` tags can be deleted by any organization member.

This endpoint does not cost any credits to execute. - [Get a tag](https://docs.censys.com/reference/v3-tags-get-tag.md): Retrieve a tag by its ID or name. Tag names are unique within an organization and can be used interchangeably with the tag ID in the path parameter.

Only tags that are visible to the caller are returned: private tags created by other users are not accessible unless your account is an organization admin.

This endpoint does not cost any credits to execute. - [List tag assignments](https://docs.censys.com/reference/v3-tags-list-assignments.md): Retrieve a paginated list of assignments for a tag in your organization. Use query parameters to filter results by asset, created_by, or creation time. Only assignments for tags visible to your account are returned.

This endpoint does not cost any credits to execute. - [List tags](https://docs.censys.com/reference/v3-tags-list-tags.md): Retrieve a paginated list of tags in your organization. Private tags created by other users are not included in the results unless your account is an organization admin.

This endpoint does not cost any credits to execute. - [Update a tag](https://docs.censys.com/reference/v3-tags-update-tag.md): Update an existing tag in your organization. Only the fields provided in the request body will be updated; omitted fields are left unchanged.

Only the tag's creator or an organization admin can update a `private` tag. Tags with the `shared` setting can be updated by any organization member.

This endpoint does not cost any credits to execute. - [List comments](https://docs.censys.com/reference/v3-comments-list-comments.md): Retrieve a paginated list of comments in your organization. Use query parameters to filter by asset, creator, or creation time.

This endpoint does not cost any credits to execute. - [Create a comment](https://docs.censys.com/reference/v3-comments-create-comment.md): Add a comment on an asset in your organization.

This endpoint does not cost any credits to execute. - [Delete a comment](https://docs.censys.com/reference/v3-comments-delete-comment.md): Delete a comment. Only the comment's creator or an organization admin can delete a comment. This action is permanent and cannot be undone.

This endpoint does not cost any credits to execute. - [Update a comment](https://docs.censys.com/reference/v3-comments-update-comment.md): Update the body of an existing comment. Only the comment's creator can update it.

This endpoint does not cost any credits to execute. - [Bulk create tag assignments](https://docs.censys.com/reference/v3-tags-bulk-create-assignments.md): Start a long-running operation that assigns a tag to every asset matching a CenQL query. The operation runs asynchronously; use the returned operation to track its progress.

A tag can hold a limited number of asset assignments, and the limit depends on your plan. If the operation reaches that limit before every matching asset is tagged, it finishes with status `limit_reached`.

This endpoint does not cost any credits to execute. - [Bulk delete tag assignments](https://docs.censys.com/reference/v3-tags-bulk-delete-assignments.md): Start a long-running operation that removes a tag from its assigned assets, optionally restricted to a creation-time window. The operation runs asynchronously; use the returned operation to track its progress.

This endpoint does not cost any credits to execute. - [List tag operations](https://docs.censys.com/reference/v3-tags-list-operations.md): Retrieve a paginated list of bulk tag operations. Provide a tag ID in the path to scope the listing to a single tag, or `-` to list operations across all tags in your organization. Use query parameters to filter by type or status.

This endpoint does not cost any credits to execute. - [Cancel a tag operation](https://docs.censys.com/reference/v3-tags-cancel-operation.md): Request cancellation of an in-progress bulk tag operation. Cancellation is cooperative: the operation finishes the page it is currently processing, then stops. Work already committed before cancellation is preserved.

Cancellation is not a rollback — it stops further work but does not remove assignments the operation already created. To remove assignments, use the bulk-delete endpoint. An operation that has already finished cannot be cancelled.

This endpoint does not cost any credits to execute. - [Get Started with Data Downloads](https://docs.censys.com/reference/get-started-downloads.md) - [Fetch the list of available datasets](https://docs.censys.com/reference/get-datasets.md): Fetch the list of available datasets - [Fetch the list of snapshots for a dataset](https://docs.censys.com/reference/get-snapshots.md): Fetch the list of snapshots for a dataset - [Fetch the list of files for a snapshot](https://docs.censys.com/reference/get-files.md): Fetch the list of files for a snapshot ## Changelog - [July 13, 2026](https://docs.censys.com/changelog/july-13-2026.md) - [July 6, 2026](https://docs.censys.com/changelog/july-6-2026.md) - [June 29, 2026](https://docs.censys.com/changelog/june-29-2026.md) - [June 22, 2026](https://docs.censys.com/changelog/june-22-2026.md) - [June 15, 2026](https://docs.censys.com/changelog/june-15-2026.md)