cipher387/API-s-for-OSINT: a curated index of OSINT APIs, not a toolkit
List of API's for gathering information about phone numbers, addresses, domains etc
At a glance
- What is it?
- The repository is a markdown catalogue of APIs for phone numbers, domains, IPs, leaks and more, with pricing columns and a beginner tutorial link. It ships no code, so its value depends on how you read the tables and what you verify yourself.
- Who is it for?
- Use cipher387/API-s-for-OSINT if you already know which category of lookup you need and want a starting shortlist of providers with rough pricing, then verify current terms and quotas on each vendor's own page before you build against them. Do not use it as a runtime dependency, as a self-hosted service, or as a source of code: the repository contains only README.md, CONTRIBUTING.md, LICENSE.md and logo.png, so there is nothing to install and no library to import.
- Can I use it commercially?
- Yes. CC0-1.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 58 days ago.
- What is it written in?
- GitHub does not report a main language for this repository.
Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What the API-s-for-OSINT repository actually is
This is an awesome-list style index, not a program. The README opens by describing itself as "a Collection of APIs that will be useful for automating various tasks in OSINT", and the repository layout backs that up: the top level holds README.md, CONTRIBUTING.md, LICENSE.md and logo.png. There is no package manifest, no source directory, no Dockerfile. Nothing runs when you clone it.
The target reader is someone who already has an OSINT task and needs to pick an endpoint for it. The table of contents spans roughly thirty categories, from IOT/IP search engines and universal OSINT APIs through phone number lookup, address and ZIP codes, domain and DNS, Whois, GEO IP, email, pastebin and leaks, archives, hashes, crypto, malware, face search, reverse image search, AI geolocation, social media, unofficial APIs, search engines, news analysis, darknet, torrents, vulnerabilities, flights, webcams, regex, and finally API testing tools, curl converters, and sections on creating, distributing and storing API keys. Each entry is a row with Name, Link, Description and Price.
That breadth is the point. A single engineer investigating a domain does not want to open twelve vendor pages to learn which of them publish a JSON API at all. The list answers that first question cheaply. It does not answer the second question, which is whether the endpoint still works the way the row implies.
How the tables encode price, and where that breaks down
The Price column is the most useful and the most fragile part of the list. It uses a small set of informal labels: FREE, Partly FREE, PAID, and concrete figures. In the IOT/IP search engines section, IPQuery.io is marked FREE, Netlas.io, Censys.io, Hunter.how and Fullhunt.io are marked Partly FREE, Shodan is listed as "from $59/month", and Fofa.so is marked "???". Hunt.io is listed as "Free demo".
Those labels are not a schema. "Partly FREE" does not say how many requests you get, whether a credit card is required, or whether the free tier covers the endpoint you want. In the Phone Number Lookup and Verification section the numbers are sharper: Numverify is listed as "250 requests FREE", Veriphone as "1000 requests/month FREE", Twilio as "Free or $0.01 per request (for caller lookup)", Plivo as "from $0.04 per request", and GetContact as "from $6,89 in months/100 requests". Even there, the units differ between rows, which makes sorting by cost across categories impossible without going to the vendors.
The "???" entry is honest and worth noting. A curated list that leaves a price unknown is more trustworthy than one that guesses. Treat every figure as a lead to confirm, not as a budget input.
Using it without installing anything: the beginner path
There is nothing to install and no code in the repository to copy. The README gives one instruction aimed at non-programmers: a link titled "Instruction for total beginners: OSINT automation: using custom functions for working with API requests in Google Sheets", which points to a Medium article by the same author. That is the project's own suggested starting path if you do not write code.
If you do write code, the repository's contribution to your workflow is the shortlist, not the request. Suppose you need to validate a phone number and learn its carrier. The table points at Numverify, Twilio Lookup, Plivo, Veriphone and GetContact. You then open the vendor's own documentation, obtain a key, and construct the call against the shape that vendor publishes. The README's API Keys Info section is an index of where keys are managed, not a place that issues them.
A second helper category in the table of contents is curl converters, described as "tools that help to write code using API queries". Those are external tools, listed for convenience; the repository does not host them. If you prefer spreadsheets, the beginner article describes writing custom functions that call these endpoints from Google Sheets cells, which is the lowest-friction path for an analyst who is not building an application. Either way, the repository supplies the address list and the vendor supplies the contract.
The unofficial APIs section is the sharpest edge in the list
The table of contents includes a section called UNOFFICIAL APIs, and the presence of GetContact under Phone Number Lookup, linked to a third-party GitHub repository rather than a vendor domain, shows the pattern. Rows in this category point at endpoints that were reverse engineered from a mobile app or website, not published by the operator.
Nothing in the README warns about this. There is no column for authentication type, no column for terms of service, no column for whether the endpoint requires a session token that expires. A reader scanning the table sees a Name, a Link, a Description and a Price, and the Price column does not capture legal or operational risk.
For an engineer, the practical consequence is that unofficial endpoints break without notice and cannot be depended on in a pipeline. They are reasonable for one-off manual research and unreasonable for anything scheduled. The list does not make that distinction for you, so you have to make it yourself by looking at whether the Link points to a vendor's documentation domain or to a community repository.
Why the README's own gaps matter more than they look
The README does not document rollback, retries, error codes, rate-limit headers or authentication flows, because it is not describing one API. It is describing many, and the contract for each lives elsewhere. That is a structural limit, not an oversight, but it changes how you should use the page.
A concrete example: the IOT/IP search engines section lists Shodan, Netlas, Fofa, Censys, Hunter.how, Fullhunt, IPQuery and Hunt.io as if they were interchangeable. They are not. Some are search engines over internet-connected hosts, some are enrichment APIs, and the rows do not separate query-style access from lookup-style access. If your task is "given an IP, return ASN and geolocation", you want the enrichment rows; if it is "find hosts matching a banner string", you want the search rows. The Description column gestures at this but does not enforce it.
There is also no freshness signal per row. The repository's last push was on 2026-08-05, which tells you when the file was last edited, not when each vendor's pricing page was last checked. Rows can be individually stale inside a recently touched file.
What to use instead when you need a runnable tool
If you need code rather than a catalogue, this repository is the wrong artifact. Two alternatives with genuinely different approaches:
A framework such as the one the README links as "OSINT Framework" in the related tooling ecosystem takes the opposite approach: instead of listing APIs to call, it presents a navigable tree of sources and tools, organized by the type of information you are chasing. It is a research aid for a human, closer in spirit to this list but interactive rather than a markdown file.
A vendor SDK or CLI, such as the Netlas CookBook the README points to for Netlas.io, gives you working code against one provider. The difference in approach is decisive: a cookbook shows you the request shape, the response fields and the failure modes for a single API, so you can build against it today. cipher387/API-s-for-OSINT tells you that Netlas.io exists and is partly free; the cookbook tells you how to call it.
Neither replaces the other. The list is for choosing. The cookbook is for building.
Licence, contributions and the cost of keeping a list current
The repository is licensed CC0-1.0, which places it in the public domain: you can copy the tables into your own documentation, fork the list, or republish it without attribution requirements. For an internal runbook, that is unusually permissive and removes the usual licence review step. It does not extend to the APIs listed, which carry their own terms, and it does not cover the logo.
CONTRIBUTING.md exists at the top level, and the README carries a contributions-welcome badge, so the maintenance model is pull requests from the community. That model has a known cost: entries are added faster than they are re-verified, and there is no visible mechanism in the README for marking a row as dead or stale. If you depend on this list for a recurring workflow, the upkeep is on you. Pin the specific vendor documentation pages you actually use, and re-check them on your own schedule rather than trusting the table's Price column to stay accurate.
The last push was on 2026-08-05, so the file is being touched, but a recent edit to one section says nothing about the accuracy of the other twenty-nine.
Editorial conclusion
Use cipher387/API-s-for-OSINT if you already know which category of lookup you need and want a starting shortlist of providers with rough pricing, then verify current terms and quotas on each vendor's own page before you build against them. Do not use it as a runtime dependency, as a self-hosted service, or as a source of code: the repository contains only README.md, CONTRIBUTING.md, LICENSE.md and logo.png, so there is nothing to install and no library to import. Before adopting any listed API, check the vendor's live documentation for authentication method, rate limits and current price, because the table's Price column is a snapshot and the README does not state when each row was last reviewed.
Frequently asked questions
Is cipher387/API-s-for-OSINT free to use?
The repository itself is licensed CC0-1.0, so the list can be copied and reused without attribution. The APIs it points to are separate services with their own pricing, ranging from FREE to PAID per the Price column.
Do I need to install anything to use cipher387/API-s-for-OSINT?
No. The repository contains only README.md, CONTRIBUTING.md, LICENSE.md and logo.png, so there is no package, binary or service to install. You read the tables and then call the vendor APIs directly.
Where do the API keys come from for the APIs in this list?
From each provider, not from the repository. The README has a section called API Keys Info that indexes where keys are managed, and it also links a beginner tutorial on calling APIs from Google Sheets custom functions.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/cipher387-api-s-for-osint)