Parameters shown without a default are required. Optional parameters show their server default where one exists.
Retrieval and account
Domains, hosts, and scanning
fullhunt_host is a passive lookup. It does not perform a live scan. The fullhunt_scan response confirms that a request was queued but does not expose a matching status tool.
Organizations and vulnerability intelligence
The feed accepts
days from 1 to 7, per_page from 1 to 100, and type values vulnerabilities, exploits, advisories, or all.
Data intelligence
Enterprise
Enterprise date filters use
DD/MM/YYYY. The two impersonation tools use the parameter q, not query.
Nexus
nexus_whois_search requires at least one filter. Its limit is constrained to 1 through 10.
OEM
oem_scan_status is the status operation for OEM scans. Poll no faster than the documented 10 requests per minute and stop when the scan reaches a terminal state.
Public archive
Error behavior
Tool errors preserve the status returned by the underlying API where possible:
For setup and caching issues, see MCP Integration and MCP Best Practices.
