API Entitlements

Core APIs

APIIncluded Modules
AlertsAll except SecOps Intelligence
Analyst NotesAll modules
Attack Surface IntelligenceAttack Surface Intelligence
Autonomous Threat OperationsThreat Intelligence or SecOps Intelligence, & Autonomous Threat Operations add-on
Collective InsightsSecOps Intelligence, Threat Intelligence
Detection RulesSecOps Intelligence, Threat Intelligence
Entity MatchAll modules
FusionFusion access granted by Support as needed
Identity IntelligenceIdentity Intelligence
LinksSecOps Intelligence, Threat Intelligence
ListsAll modules
Malware IntelligenceSecOps Intelligence, Threat Intelligence
Payment Fraud IntelligencePayment Fraud Intelligence
RiskAll modules with the addition:
Integration user - "Risk History Read API Access" enabled
User privilege - RiskApiRead
SandboxSecOps Intelligence, Threat Intelligence
TakedownsBrand Intelligence
Threat MapsThreat Intelligence

Enrichment & Risk Lists

APIIncluded Modules
Company EnrichmentThird Party Intelligence
IP / Domain / URL EnrichmentSecOps Intelligence, Threat Intelligence, Brand Intelligence
Hash / File EnrichmentSecOps Intelligence, Threat Intelligence
IOC Risk ListsSecOps Intelligence, Threat Intelligence
Malware EnrichmentSecOps Intelligence, Threat Intelligence
SOARSecOps Intelligence, Threat Intelligence
Vulnerability EnrichmentVulnerability Intelligence
Vulnerability Risk ListsVulnerability Intelligence

Troubleshooting 403 Errors

A 403 Forbidden response from the Recorded Future API can indicate one of two distinct issues:

"Missing API privileges" — Your API token does not have the module entitlement required for the endpoint you are calling. Check the tables above to verify your module includes the API. If it does not, contact your Recorded Future account team to discuss adding the required module. If your module was recently added, you may need to regenerate your API token for the new entitlements to take effect.

"Missing Data permissions" — Your API token has the correct module entitlement, but your account lacks access to the specific data group referenced in the request. This is a data-scope restriction, not a licensing issue. Contact your Recorded Future administrator to review your data-group ACL configuration.

Read the error.message field in the JSON response to determine which type of 403 you received.