API Access
Integrate Blue Lantern tools into your own workflows programmatically.
All marketplace tools are accessible via the REST API, allowing you to integrate security analysis into CI/CD pipelines, SOAR playbooks, or custom applications.
Getting Your API Key
- Navigate to API Access from your account.
- Click Generate API Key. Your key will be displayed once — copy it to a safe location.
- Include the key in the
Authorizationheader of every API request.
Authentication
Pass your API key in the Authorization header:
Authorization: YOUR_API_KEY
Account Scope (Organizations)
An API key is bound to the single account it was generated under — your personal account or a specific organization. Unlike the web app, an API key cannot switch accounts: it ignores the account switcher, and every request it makes runs against that one account and its Seat License coverage (API keys require an active seat plan on the account they belong to).
To use the API as a specific organization:
- Open the account switcher on the Organization page and switch into that organization.
- Go to API Access and generate a key while you're in that account. The key is now bound to that organization.
- Use that key for all requests that should run as the organization. Keep separate keys for separate accounts.
The same applies to monitor keys (browser/email extensions) — each is scoped to the account it was created in.
Postman Collection
A postman collection is provided for your convenience at this link: Postman Collection
Example: Analyze an Email via cURL
curl -X POST "$API_URL/runs" \
-H "Authorization: YOUR_API_KEY" \
-F "tool=EMAILANALYZER" \
-F "file=@/path/to/suspicious_email.eml"
Example: JavaScript (Fetch)
const formData = new FormData();
formData.append('tool', 'EMAILANALYZER');
formData.append('file', fileInput.files[0]);
const response = await fetch(API_URL + '/runs', {
method: 'POST',
headers: { 'Authorization': 'YOUR_API_KEY' },
body: formData
});
const data = await response.json();
console.log(data);
Seat License required — API keys can only be created and used on accounts with an active Seat License. Requests from a key on an account without one return 402; they resume automatically when a seat is added. Independently, APIs are limited to 600 requests in a 10 minute period.
Keep Keys Safe — Do not expose API keys in client-side code, public repos, or browser requests. Treat them like passwords.