--- title: "What Is the Best API for OSINT in 2026?" dek: "OSINT is not one API, it is a stack. The foundation is finding what is public on the live web, and that is a search problem. Keiro does it at $1/1k with 500 free credits a month and commercial use allowed. Then you bolt on specialists by axis: Shodan and Censys for infrastructure, SecurityTrails for DNS, HIBP for breaches, Nyne, Sixtyfour, and The Hog for people and companies. Proxycurl is gone. A real comparison with real prices, real mechanics, and a real investigation walkthrough." category: "comparisons" tags: [osint, comparison, api, security, keiro, ai-agents] author: "Manny" published: 2026-02-04T12:00:00+00:00 updated: 2026-07-16T00:00:00+00:00 url: https://keirolabs.cloud/blogs/comparisons/what-is-the-best-api-for-osint --- Here is the answer nobody gives you. There is no single best API for OSINT, because OSINT is not one job. It is a stack. Finding exposed infrastructure is Shodan. Certificate and asset discovery is Censys. DNS history and subdomain enumeration is SecurityTrails. Breach exposure is Have I Been Pwned. People and company enrichment is Nyne or Sixtyfour or The Hog. None of those does the thing that ties them together, which is finding what is public about a person, company, or event across the open web, as clean text your agent can reason over. That is a live web search problem, and Keiro does it at $1/1k with 500 free credits a month and commercial use allowed on the free tier. Build the stack on a fast web index, then bolt on the specialists by axis.
$1Keiro / 1k · 500 free
50B+Keiro page index
8tools that matter
~$120threat-intel stack / mo
2.4Bpeople in Nyne
10+yrSecurityTrails DNS
## TL;DR
TL;DR · the 8 category winners
- **Best for live web OSINT (the foundation layer):** Keiro. 50B+ index, ~100ms indexed, finds public info, news, mentions, and public records, $1/1k, free 500/mo, commercial use allowed. - **Best for exposed infrastructure and devices:** Shodan. Broadest banner and port coverage, $69/mo Freelancer, 1 req/sec. - **Best for certificate and asset discovery:** Censys. Certificate transparency, finds assets Shodan misses, free lookups. - **Best for DNS history and subdomain enumeration:** SecurityTrails. 10+ years of passive DNS, $50/mo Starter. - **Best for breach and credential exposure:** Have I Been Pwned. Industry standard, k-anonymity email search, free Pwned Passwords, 2026 overhaul. - **Best unified web-intelligence layer for agents:** The Hog. Search, people, enrichment, monitoring in one API, 500 free calls/mo. - **Best people data for agents:** Nyne. 2.4B people, 2,400+ attributes, MCP server, SOC 2. - **Best OSINT-grade company investigation:** Sixtyfour. Recursive open and dark web crawling, confidence scoring, org charts.
Cost per 1,000 OSINT lookups across Keiro, Shodan, SecurityTrails, Censys, HIBP, The Hog, Nyne, and Sixtyfour
Cost per 1,000 OSINT lookups. Keiro is the cheapest foundation layer; the specialists charge by axis, not by page.
## What is OSINT, actually OSINT, open-source intelligence, is the collection and analysis of publicly available information about people, organizations, domains, and infrastructure. You use it for due diligence, threat intelligence, fraud detection, investigative journalism, sales and recruiting enrichment, and brand or reputation monitoring. What people actually use it for, in practice: - **Threat intelligence** maps exposed assets, domains, and breach exposure, then watches for changes. - **Due diligence and risk** checks people and companies before deals, hires, or partnerships. - **Investigations** connect people, companies, and events across public sources, with provenance. - **Sales and recruiting enrichment** finds verified contacts, roles, and life events. - **Brand and reputation monitoring** tracks mentions across the open web, fast. The market splits into a **foundation** and **specialists**. The foundation is live web search: finding what is public across the open web, as clean text an agent can read and reason over. The specialists are single-axis tools that go deep on one surface: infrastructure (Shodan, Censys), domains and DNS (SecurityTrails), breaches (HIBP), people and companies (Nyne, Sixtyfour, The Hog). The foundation finds what is public. The specialists verify and go deep. You need both, and most teams build the stack backwards, starting with a specialist and then bolting on search when they realize they cannot answer "what is public about this company" from a port scanner.
OSINT stack: a live-web foundation with four specialist pillars and an agent reasoning layer on top
The OSINT stack. A live-web foundation carries four specialist pillars; the agent sits on top and routes by question. Build the stack on a fast index, not on a scraper.
## How the routing actually works The reason OSINT is a stack and not a vendor is that each question has a different cheapest, fastest answer. The agent's job is to route by question, not to call one endpoint for everything. The routing rule is simple. Start every investigation with the foundation, because "what is public about this" is the first question of every case. Then drop to a specialist when the question is a specific axis a specialist owns. - **What's public across the web?** Keiro. The start of every investigation. $1/1k, ~100ms, clean text plus optional embeddings in one call. - **Exposed devices or ports?** Shodan. Banner and port coverage, vuln filters, monitoring. - **Certificates or assets?** Censys. Certificate transparency, finds assets Shodan misses. - **DNS history or subdomains?** SecurityTrails. 10+ years of passive DNS, WHOIS change tracking. - **Breach exposure?** HIBP. k-anonymity email search, stealer logs, Pwned Passwords. - **A person?** Nyne for 2.4B people with 2,400+ attributes, or The Hog for people search plus LinkedIn in a unified API. - **A company, deep?** Sixtyfour. Recursive open and dark web crawl, org charts, confidence scoring. The foundation is not optional. If you skip it, you build an OSINT stack that can tell you a server has port 22 open but cannot tell you what the company said in public about that server. That is not intelligence, it is a scan.
OSINT routing tree: what are you investigating routes to seven tools, with Keiro as the start of every investigation
Routing tree. The Keiro branch is the start of every investigation. The other six fire only when the question is a specific axis a specialist owns.
## A comparison of the 8 | API | Layer | Pricing | Free tier | Best for | | --- | --- | --- | --- | --- | | **Keiro** | foundation (live web) | $1/1k | 500/mo (commercial OK) | Public info, news, mentions, clean text | | **Shodan** | infrastructure | $69/mo Freelancer | limited | Exposed devices, ports, banners | | **Censys** | certificates/assets | credit-based | free (lookups) | Certificate transparency, asset discovery | | **SecurityTrails** | DNS/domains | $50/mo Starter | 50 queries/mo | Historical DNS, subdomains, WHOIS | | **HIBP** | breaches | per-RPM plans | Pwned Passwords free | Breach and credential exposure | | **The Hog** | unified web intel | ~$3.29/1k web, $6.57/1k people | 500 calls/mo | Agent-native search + people + enrichment | | **Nyne** | people data | per-record | limited | Person enrichment, 2.4B people, MCP | | **Sixtyfour** | company intel | per-job | trial | OSINT-grade company investigation | Pricing is 2026 list. Keiro, The Hog, Nyne, and Sixtyfour are usage-based. Shodan, SecurityTrails, and HIBP are plan-based. Censys is credit-based. Verify on each provider's site before you model a budget, because the per-record and per-job prices move with volume. ## The foundation: live web OSINT with Keiro

Keiro the foundation layer · $1/1k

This is our product, and the reason it is the foundation is that every OSINT investigation starts with "what is public about this." A fast web index that returns clean article text and structured page data is the layer you run first, before the specialists. Keiro's 50B+ page index returns indexed queries in about 100ms, with hot URLs refreshing in seconds and trending topics in minutes. It is an index, not a scraper, which is why it can answer a query like "Acme Corp SEC filing 2026 executives" in one call instead of crawling ten sites. `/api/v2/search/content` returns ranked pages plus their clean article text and optional chunked embeddings in one call, so an OSINT agent reads the page without a separate scrape step. `/api/v2/data` extracts structured data from a URL or an array of URLs in one call. $1/1k, 500 free credits a month, no card, and commercial use is allowed on the free tier, which matters because a lot of OSINT free tiers forbid commercial use. ```bash curl -X POST https://api.keirolabs.cloud/api/v2/search/content \ -H "Authorization: Bearer keiro_your_api_key_here" \ -H "Content-Type: application/json" \ -d '{"query": "Acme Corp SEC filing 2026 executives", "maxResults": 5, "mode": "ai"}' ``` That returns ranked public pages and their clean text in one call. For an OSINT agent, that is the discovery step done. If you then want a structured pull from a specific page you already found, `/api/v2/data` takes the URL array and returns structured fields, 2 credits. How the foundation actually works under the hood: - The index is a 50B+ page crawl of the open web, ranked by a Webrank signal that prioritizes authority and freshness, not a one-shot scrape of whatever Google returned. - `/search/content` runs the query against that index, returns ranked pages, and for each page returns the cleaned article text and optional chunked embeddings (384 to 1024 dims) in the same response. No second call to a scraper. - `/data` takes a URL or `urls` array and pulls structured fields, so when you already know the page (a court docket, an SEC filing, a news article), you skip search and go straight to extraction. - Hot URLs refresh in seconds, trending topics in minutes. For OSINT, that means a fresh breach disclosure or a new lawsuit filing surfaces fast, not on a 30-day crawl cadence.
Best for the foundation layer: finding what is public across the open web before any specialist database has it, ~100ms, clean text in one call.
Price $1/1k, 500 free credits a month, no card, commercial use allowed on free. No $499/mo minimum.
The catch it is an index, so a brand-new obscure source that is not yet indexed will lag. Bolt on a specialist for that.
Why it's here it leads the public QA benchmarks (SimpleQA 94, FreshQA 91, HotpotQA 82), so agents reading public sources through Keiro answer more accurately than through Perplexity or Tavily.

Pros

Cons

## The specialists

S Shodan infrastructure · $69/mo Freelancer

The exposed-infrastructure pick. Shodan is the search engine for internet-connected devices: servers, cameras, routers, ICS, anything with a banner. Broadest port and banner coverage, vulnerability filters like `vuln:heartbleed`, network monitoring and alerts. $49 one-time membership, $69/mo Freelancer (10,000 query credits), up to Corporate at $1,099/mo. Rate limit is 1 req/sec across plans. How Shodan actually works: a globally distributed crawler runs 24/7 on a randomized algorithm. It picks a random IPv4 address, picks a random port from the list of ports Shodan understands, connects, and grabs the banner. The banner is the fundamental unit of data, and it varies by service. An HTTP banner carries web server software and version. A Siemens S7 banner carries firmware and serial. The crawler auto-detects services on non-standard ports (SSH on port 80 gets an SSH banner grab, not an HTTP one), and it cascades: if a banner reveals peer IPs, like DHT nodes, the crawler launches follow-up grabs for those peers. The result is roughly one full-Internet pass per week, stored as searchable banners. The query syntax is the reason security teams stay on Shodan. Filters are `filtername:value`, no space. Values with spaces get quotes (`org:"SingTel Mobile"`). Comma-separated values OR (`product:MySQL,PostgreSQL`). Numeric filters take ranges (`port:>1024,<6000`). The `vuln:` filter is restricted to higher API plans, and it is the one that turns Shodan from a scanner into a threat-intel tool: `vuln:CVE-2019-19781 country:DE,CH,FR` returns Citrix devices in Germany, Switzerland, and France vulnerable to that CVE. Add `tag:ics` for industrial control systems, `ssl.version:tlsv1.3 HTTP` for TLS 1.3 services, `http.favicon.hash` to track the same site across IPs.
Best for exposed devices, ports, banners, and vuln filtering across the public internet.
Price $49 one-time or $69/mo Freelancer with 10k query credits. Enterprise up to $1,099/mo.
The catch 1 req/sec rate limit caps throughput, and credits do not roll over.
Why it's here it is the default everyone in security already knows, with mature query syntax and the broadest banner coverage.

Pros

Cons

C Censys certificates + assets · credit-based

The certificate and asset-discovery pick. Censys complements Shodan with certificate-transparency depth, finding assets Shodan may miss. Free tier for host, certificate, and web-property lookups; Starter, Search, and Core tiers add Global Data endpoints, concurrent actions, and an Adversary Investigation module. Credit-based, Personal Access Tokens. The reason Censys owns certificate transparency is that every TLS certificate issued by a trusted CA is logged in a CT log and searchable. That lets you find subdomains and infrastructure before DNS propagates, track certificate reuse across attacker infrastructure, and surface shadow IT presenting certs with your org's name in the Subject or SAN. Censys scans 1,400+ protocols and maintains a unified data model that makes pivoting cleaner than Shodan's banner-by-banner approach. Where Shodan is stronger on device and IoT/ICS banner coverage and cheaper, Censys is stronger on TLS and cert pivoting. One thing most comparisons miss: Censys Search and Censys ASM are different products. Censys Search is the internet-intelligence query engine (what you use for OSINT). Censys ASM is a separate enterprise attack-surface-management platform that seeds discovery from your own domains, does continuous monitoring, drift detection, and ticketing. ASM is enterprise sales. For an OSINT stack, you want Search, and you run it alongside Shodan, not instead of it. The 2026 consensus from red-team writeups is explicit: use at least two scan engines, because they catch different things. CT logs alone surface 30 to 60 percent more subdomains than DNS enumeration.
Best for certificate transparency and attack-surface management; finding assets Shodan misses.
Price free lookups, then credit-based Starter, Search, and Core tiers. Core is enterprise sales.
The catch credit-based consumption is hard to budget without modeling your real query volume.
Why it's here certificate transparency is the surface Shodan does not own, and Censys owns it.

Pros

Cons

S SecurityTrails DNS + domains · $50/mo Starter

The DNS and domain-intelligence pick. SecurityTrails has 10+ years of passive DNS (records back to 2015), WHOIS history, subdomain enumeration, and reverse IP, nameserver, and MX lookups, with native integration into recon tools like subfinder and amass. Free tier 50 queries a month, $50/mo Starter (500 queries), $250/mo Pro (5,000). How it works under the hood: passive DNS is aggregated from sensors that observe real DNS resolution traffic, so SecurityTrails sees what a domain actually resolved to at a point in time, not just what it resolves to now. That makes it the deepest accessible historical DNS layer. The DSL is SQL-like: query by `ipv4` (with CIDR masks), `mx`, `ns`, `cname`, `subdomain`, `apex_domain`, `tld`, WHOIS fields like `whois_email` and `whois_organization`, and `first_seen` / `dropped`. Reverse WHOIS is the pivot that turns a single domain into a cluster: search `whois_email:` for a registrant email and you get every domain they ever registered, which is how you surface shell-company clusters and infrastructure reuse. The recon-tool integration is the real moat for builders. SecurityTrails is the most widely integrated passive DNS source in open-source recon tooling. subfinder reads it from `provider-config.yaml`. amass reads it from `datasources` in `config.yaml`. You compose it with crt.sh for CT logs, Shodan for port discovery, and Censys for certificate and IP data, and that is the standard 2026 passive-recon stack. CT log analysis typically reveals 30 to 60 percent more subdomains than DNS enumeration alone, which is why everyone runs both.
Best for historical DNS, WHOIS change tracking, subdomain enumeration, and infrastructure pivoting.
Price free 50/mo, $50/mo Starter (500 queries), $250/mo Pro (5,000).
The catch passive collection only, no active scanning, and thin coverage for obscure low-traffic domains.
Why it's here 10+ years of passive DNS is the deepest accessible historical DNS layer, and it integrates with the recon tools you already run.

Pros

Cons

H Have I Been Pwned breaches · Pwned Passwords free

The breach and credential pick. HIBP is the industry standard for breach lookup by email or domain, stealer logs, and Pwned Passwords. The March 2026 overhaul replaced the old Pwned tiers with Core, Pro, High RPM, and Enterprise, and added k-anonymity email search, bulk domain verification by API, auto-subdomain verification, and unsmoothed burst rate limits. Pwned Passwords stays free with no key. The k-anonymity mechanic is the part worth understanding, because it is what made HIBP safe enough to run in a real product. To search an email without sending the email to HIBP, you SHA-1 hash it, send only the first 6 characters of the hash to `GET /breachedaccount/range/{first 6 chars}`, and HIBP responds with all hash suffixes matching that prefix (about 393 typical) plus the breaches each appears in. The client matches the suffix locally. HIBP never learns which email you searched. It is the same privacy model Pwned Passwords has used for years, extended to email. K-anonymity email search is available to Pro and High RPM subscribers at the same rate limit as direct searches. The tier restructure matters for budget. Core is direct email and domain search, no k-anon, no stealer logs. Pro adds k-anon email search, stealer logs, domain verification by API (DNS and email), auto-verifying subdomains, and MSP customer-domain monitoring. High RPM is the old Ultra tier: high-throughput API access for direct and k-anon email search, but no domain monitoring. Enterprise is enterprise sales. Old Pwned plans keep running until August 2, 2026, then roll over to a corresponding new plan at next renewal. If you are building on HIBP today, model against the new tiers, not the old ones.
Best for breach and credential exposure, stealer logs, and password safety checks.
Price Pwned Passwords free, no key. Email and domain search on Core, Pro, High RPM, Enterprise. Per-RPM plans.
The catch email and domain search require a paid plan, and plans restructure at renewal after August 2, 2026.
Why it's here it is the breach database. Everyone checks it. The 2026 k-anonymity overhaul made the API privacy-preserving enough to run in a real product.

Pros

Cons

T The Hog unified web intel · 500 free/mo

The unified web-intelligence pick for agents. The Hog (YC F25) is the closest thing to a single OSINT API for agents: web search, people search, social search (X, Reddit, TikTok), verified email and mobile enrichment, LinkedIn scraping, deep multi-hop research, and monitoring, returning structured JSON with ranked signals, source attribution, freshness, and confidence scores. Metered per call, 500 free a month, web search about $3.29/1k and people search about $6.57/1k. The mechanic that differentiates The Hog from a stitched stack is multi-provider waterfall logic. Each call routes to the best source for that question and falls back automatically, so you do not write the fallback code yourself. People search is async: `POST /api/v1/people/search` accepts natural-language queries and structured filters (title, seniority, location, industry, employee count, signals, company nesting), returns an `operationId`, and you poll `GET /api/v1/operations/:id` for results. Deep research jobs return structured data conforming to your JSON Schema, which is the part that matters for agents: you define the dossier shape, The Hog fills it. Monitoring covers Reddit, LinkedIn, X, forums, and review sites.
Best for one API replacing a stitched stack of search, enrichment, and monitoring for an agent.
Price 500 free calls/mo, web ~$3.29/1k, people ~$6.57/1k, transparent per-call metering.
The catch ~3x to 6x Keiro on the web-search foundation layer, and newer so reliability at very high scale is less proven.
Why it's here if you refuse to stitch a stack and want one intelligence endpoint, this is the one. Agent-ready structured output with provenance and confidence.

Pros

Cons

N Nyne people data · 2.4B people · MCP

The people-data pick for agents. Nyne is a people data API built for agents, with 2.4 billion people and 2,400+ attributes across demographics, wealth, life events, public filings, contact, social, and career. It ships an MCP server, an `llms.txt` index, and an agent manifest, plus life-event webhooks for real-time CRM signals. CCPA-ready, SOC 2, every field sourced and time-stamped. Recently raised $5.3M. How Nyne works under the hood: autonomous AI agents continuously source and verify data across the open web and public records, including state, county, and national filings. The API surfaces Person Search, Person Enrichment, Email and Phone Finder, social intelligence (profiles, newsfeed, interactions), and AI research (Deep Research, Ask, Simulation, Personal Interests, Article Search). Auth is `X-API-Key` plus `X-API-Secret`. The async pattern is explicit: submit returns `202 Accepted` with a `request_id`, you poll until `completed` or use a webhook callback. Rate limits are 100 req/min and 1,000 req/hour. Credits charge only on meaningful results, so empty results do not burn credits, which is the detail that makes per-record pricing survivable at scale. The MCP server is the reason Nyne is the agent-native people layer. You expose it as a tool and the agent calls it for person enrichment without you writing glue. The `llms.txt` index and agent manifest mean an agent can discover the endpoints at runtime. Life-event webhooks push real-time signals (new job, new filing, role change) into CRMs and CDPs, which is the OSINT-to-workflow bridge that Proxycurl used to pretend to offer.
Best for person enrichment at scale, with an MCP server so an agent can call it as a tool.
Price per-record enrichment pricing. Free tier limited.
The catch people data only, and per-record pricing adds up at high volume.
Why it's here 2.4B people, 2,400+ attributes, MCP server, SOC 2, life-event webhooks. The agent-native people layer Proxycurl used to pretend to be.

Pros

Cons

S Sixtyfour company intel · OSINT-grade

The OSINT-grade company-investigation pick. Sixtyfour (YC S25) does company research and enrichment at tiered depth, from a lightweight `micro` lookup to a `high` OSINT-grade investigation with recursive crawling across the open web, dark web, directories, and proprietary sources. Custom structured output, people discovery with full org charts, confidence and relevance scoring 0 to 10, and an async job pattern for production. How it works under the hood: starting from a single identifier (name, email, phone, username, or company name), Sixtyfour deploys agents that recursively search the open web, dark web, social platforms (LinkedIn, GitHub, Reddit, Telegram), court records, and regulatory filings. Every signal is cross-referenced across thousands of sources and every data point is cited. The `high` tier is the one that does OSINT-grade depth: deeply recursive crawling across open and dark web, directories, proprietary sources, designed for high-stakes accounts, sensitive diligence, and investigative workflows. Access is granted case-by-case by sales. The scoring model is the part worth understanding. `confidence_score` (0 to 10) is the global quality score: overall quality, consistency, and correctness of the returned data. `score` (0 to 10) is the relevance score: likelihood a returned person matches the prompt. The async pattern is `/company-intelligence-async` with polling on `/job-status/{task_id}`, which fits a production workflow instead of blocking on a 30-second recursive crawl. The output is a mapped graph of connected accounts, confidence scores per edge, and the exact surfaced identifiers linking them, which is what AML and shell-company investigations actually need.
Best for deep company investigation: dark web, proprietary sources, org charts, confidence scoring.
Price per-job, tiered by depth (micro to high). Trial available.
The catch per-job pricing means you have to model your investigation volume, not your query volume, and `high` depth access is sales-gated.
Why it's here it is the only tool in this list that does true OSINT-grade company depth, including dark web and proprietary sources, with a production async pattern.

Pros

Cons

## The Proxycurl situation This matters more than people admit. Half the "best OSINT API" posts still ranking were written when Proxycurl was the default LinkedIn layer. If you copy that stack today, you build on a discontinued product. The replacement is not one vendor, it is the same stack logic: Keiro for the public-web picture, then Nyne, The Hog, or Sixtyfour for the people and company axis depending on whether you want attributes, a unified agent API, or OSINT-grade depth. NinjaPear itself is worth a note. It is the same founder, building the legally cleaner version of the same idea. Canonical entity key is the company website, not a LinkedIn URL. API surfaces are Customer, Company, Employee, Monitor, Competitor. Credit-based, 3-day free trial with 10 credits. It is a B2B GTM platform more than an OSINT tool, but if you were a Proxycurl customer, it is the spiritual successor. For OSINT specifically, Nyne and The Hog are the better fits. ## A concrete investigation: "is this vendor safe to sign with?" Say you are running due diligence on a vendor called Acme Corp before signing a multi-year contract. Here is how the stack actually fires, in order.
OSINT investigation flow: foundation Keiro discovers, then five specialist layers verify by axis, then an agent reasons and scores confidence
One vendor check, six layers. The foundation discovers. The specialists verify by axis. The agent scores confidence and returns a dossier.
1. **Foundation.** Run Keiro `/api/v2/search/content` with `"query": "Acme Corp SEC filing 2026 executives lawsuit"`, `maxResults: 5`, `mode: ai`. You get ranked public pages and their clean text in one call, ~100ms. If Acme was named in a lawsuit or filed an SEC document this quarter, you see it here, with the article text. Cost: 3 credits (one `/search/content` call). At $1/1k that is fractions of a cent. 2. **People.** The article names a CFO, "Jane Doe." Run Nyne for her 2,400+ attributes: career history, public filings, life events, social intelligence. If Nyne does not have her, run The Hog's people search. Cost: per-record, model it. Nyne charges only on meaningful results, so a miss does not burn credits. 3. **Company, deep.** Run Sixtyfour at `high` depth for Acme itself: recursive open and dark web crawl, org chart, confidence and relevance scoring 0 to 10, every data point cited. You want the dark-web mention and the shell-company signal if they exist. Cost: per-job, one job. 4. **Domains.** Run SecurityTrails for `acme.com`: 10+ years of passive DNS, WHOIS changes, subdomain enumeration, reverse WHOIS on the registrant email. If the domain was registered two months ago and the WHOIS flipped three times, that is a flag. Cost: 1 of 500 Starter queries. 5. **Breaches.** Run HIBP for the Acme email domain. With k-anonymity on Pro, you send only the first 6 chars of the SHA-1 hash of each email, HIBP responds with suffixes and breaches, and you match locally. If the domain appears in a recent stealer log, that is a supply-chain risk signal. Cost: paid plan, per RPM. 6. **Infrastructure.** If Acme hosts their own infrastructure, run Shodan for their IP range: exposed ports, vuln filters, banners. Add Censys for certificates and assets Shodan misses, including shadow IT on third-party hosting. Cost: Shodan 1 of 10k Freelancer credits, Censys credit-based. Total spend for one vendor check: roughly cents on Keiro, plus a handful of specialist queries. The foundation did the discovery. The specialists did the verification and the deep axis work. The agent layer cross-references all six, cites every source, flags contradictions, and scores confidence per edge. That is the stack. Skip the foundation and you might sign with a company that has a public lawsuit you never found, because Shodan cannot read the news. ## How to build an OSINT stack **Start with the foundation.** A live web search layer (Keiro) finds what is public across the open web: mentions, news, public records, company pages, people's public profiles. Run it first, on every investigation. $1/1k, free 500/mo, commercial use allowed. This is the layer that answers the question every case starts with. **Add specialists by axis.** Infrastructure questions, add Shodan and Censys for certificates. Domain and DNS questions, add SecurityTrails. Breach exposure, add HIBP. People and company enrichment, add Nyne or Sixtyfour or The Hog. The mistake is bolting on five specialists and skipping the foundation, because then you have five deep tools that cannot tell you what is public about the target this morning. **Use the unified layer if you want one API.** If you would rather not stitch specialists, The Hog covers web, people, social, enrichment, and monitoring in one API, at 3 to 6x the foundation-layer cost. Good for agents that want one intelligence endpoint and will pay for it. You trade cost for not writing fallback glue. **Wire it into an agent with MCP.** Keiro, Nyne, and The Hog all ship MCP servers. Sixtyfour ships an MCP server plus an async job pattern. Expose each layer as a tool and let the agent call the right one per question. Keep the toolset lean, because tool definitions consume context and the 2026-07-28 MCP RC spec makes tool descriptions a primary attack surface. Treat every MCP server like an npm dependency. Do not wire six MCP servers into one agent context unless you actually need all six axes, because every tool definition costs tokens and widens the prompt-injection surface. **Budget the stack.** A threat-intel stack of Shodan Freelancer ($69) plus SecurityTrails Starter ($50) plus HIBP plus Keiro (usage) covers most infrastructure, domain, breach, and web OSINT at around $120/mo plus Keiro usage. An agent-enrichment stack of Keiro plus Nyne or The Hog covers people and company OSINT on usage-based pricing. Model your real query volume, not the headline. Censys is credit-based, so model it separately or it will surprise you. **Budget realistically by stack shape:** | Stack | Tools | Fixed / mo | Variable | | --- | --- | --- | --- | | Threat intel | Keiro + Shodan + SecurityTrails + HIBP | ~$120 | Keiro usage, Censys credits | | Agent enrichment | Keiro + Nyne (or The Hog) | $0 fixed | per-record / per-call | | Company deep-dive | Keiro + Sixtyfour | $0 fixed | per-job | | One-API team | The Hog only | $0 fixed | per-call (3 to 6x Keiro on web) | ## How to choose Pick by what your agent actually does, not by what the vendor's homepage leads with. - **Your agent does live discovery on the open web.** Start with Keiro. It is the foundation layer, $1/1k, and the only one that returns clean article text plus embeddings in one call. Add specialists only when you hit an axis Keiro does not own. - **Your agent does infrastructure and attack-surface work.** Start with Shodan, add Censys for certificate transparency. Run both, because they catch different things. Add Keiro for the public-web picture of the same targets. - **Your agent does due diligence and AML.** Start with Keiro for discovery, then Sixtyfour at `high` depth for the company, Nyne for the people, SecurityTrails for the domain history, HIBP for breach exposure. That is the vendor-check stack above. - **Your agent does people enrichment at scale.** Start with Nyne (MCP, 2.4B people, life-event webhooks). Add The Hog if you need LinkedIn and social in the same API. Add Keiro for public-web context on the same people. - **You want one API, not a stack.** The Hog. You pay 3 to 6x Keiro on the web layer, but you do not write fallback glue and you get one structured endpoint with provenance and confidence. - **You are budget-constrained.** Keiro (500 free/mo, commercial OK) plus Censys free lookups plus HIBP Pwned Passwords (free, no key) plus SecurityTrails free 50/mo covers a surprising amount of OSINT before you spend anything. ## Takeaways OSINT is a stack, and the foundation of the stack is live web search, because every investigation starts with "what is public about this." Keiro does that at $1/1k with 500 free credits a month, commercial use allowed, and clean article text plus optional embeddings in one call. Then bolt on the specialists: Shodan and Censys for infrastructure, SecurityTrails for DNS, HIBP for breaches, Nyne, Sixtyfour, or The Hog for people and companies. If you want one API instead of a stack, The Hog is the unified agent-native layer, at 3 to 6x the foundation cost. And forget Proxycurl. It is gone, shut down July 4, 2025 after LinkedIn's lawsuit settled. Any guide still routing LinkedIn people data to it is stale. Start free with 500 Keiro credits on the [pricing page](/pricing), or see the [best AI search API guide](/best-ai-search-api) and the [Exa alternatives breakdown](/firecrawl-alternative). ## FAQ ### Is there one best API for OSINT? No. OSINT is a stack. The foundation is live web search (Keiro) to find what is public, then specialists by axis: Shodan and Censys for infrastructure, SecurityTrails for DNS, HIBP for breaches, Nyne, Sixtyfour, or The Hog for people and companies. If you want one API, The Hog is the closest to a unified agent-native OSINT layer, at 3 to 6x the foundation-layer cost. ### What replaced Proxycurl for LinkedIn OSINT? Proxycurl (Nubela) is discontinued. LinkedIn sued Nubela in January 2025, the case settled with a permanent injunction, and Proxycurl shut down July 4, 2025. The founder moved to NinjaPear, a B2B customer-data platform that does not scrape LinkedIn. For LinkedIn people and company OSINT, use Nyne (people data, agent-native, MCP), The Hog (people search and LinkedIn scraping in a unified API), Sixtyfour (company investigation with people discovery), or direct LinkedIn Sales Navigator for manual work. Any guide still recommending Proxycurl is stale. ### What is the cheapest way to do OSINT? The web-search foundation is cheapest with Keiro at $1/1k and 500 free credits a month, commercial use allowed. For free specialists, Censys (free lookups) and HIBP Pwned Passwords (free, no key) cover a lot, and SecurityTrails gives 50 free queries a month. A budget threat-intel stack of Shodan Freelancer ($69) plus SecurityTrails Starter ($50) plus Keiro is around $120/mo plus usage. ### Which OSINT API is best for AI agents? The Hog for a unified agent-native layer (search, people, enrichment, monitoring, MCP). Keiro for the live web foundation at $1/1k with clean text and embeddings. Nyne for people data with an MCP server and life-event webhooks. Sixtyfour for OSINT-grade company investigation with an MCP server and async jobs. The agent answer depends on whether your agent does live discovery (Keiro), unified intelligence (The Hog), people enrichment (Nyne), or deep company investigation (Sixtyfour). ### How is OSINT different from general web search? OSINT is web search plus specialists plus provenance. You search the open web (the foundation), then verify and go deep with single-axis tools (infrastructure, DNS, breaches, people), and you track source attribution, freshness, and confidence so an agent or analyst can trust the result. General web search is the foundation layer. OSINT is the stack built on it. ### Can I use these OSINT APIs in a commercial product? Read each license. Keiro's free tier (500 credits/mo), SecurityTrails's free tier (50 queries/mo), and HIBP Pwned Passwords allow commercial use. Some specialist free tiers are for personal or research use only. For people data (Nyne, The Hog), check CCPA and consent compliance for your jurisdiction. If you are shipping a product, verify commercial use before you build on a free tier. ### How much does an OSINT pipeline cost? It depends on the stack. Foundation: Keiro at $1/1k (100k investigations about $100, 1M about $1,000, 500 free a month). Specialists: Shodan $69/mo, SecurityTrails $50/mo, Censys credit-based, HIBP per-RPM. People and company: Nyne and Sixtyfour per-record or per-job, The Hog $3.29 to $6.57/1k. A typical threat-intel stack runs about $120/mo plus Keiro usage. Model your real query volume against each model. ### Which OSINT API has the best coverage? It depends on the axis. Infrastructure: Shodan (broadest banners) and Censys (certificates, all 65,535 ports). DNS: SecurityTrails (10+ years back to 2015). People: Nyne (2.4B people). Unified: The Hog (web, people, social). Live web: Keiro (50B+ page open-web index, which is why it catches sources the licensed databases do not). No single API wins every axis, which is the point of building a stack. ### Should I build the stack with MCP servers? Yes, if your agent runtime supports it. Keiro, Nyne, The Hog, and Sixtyfour ship MCP servers, and the 2026-07-28 MCP RC spec makes remote stateless servers the norm. Expose each layer as one tool, keep the toolset lean, and treat tool descriptions as attack surface. Do not wire six MCP servers into one agent context unless you actually need all six axes, because every tool definition costs tokens and widens the prompt-injection surface. ### How does HIBP k-anonymity email search work? You SHA-1 hash the email, send only the first 6 characters of the hash to `GET /breachedaccount/range/{first 6 chars}`, and HIBP responds with all hash suffixes matching that prefix (about 393 typical) plus the breaches each appears in. You match the suffix locally, so HIBP never learns which email you searched. It is available to Pro and High RPM subscribers at the same rate limit as direct searches. Core and Enterprise do not get k-anon access.