Core APIs
| API | Included Modules |
|---|---|
| Alerts | All except SecOps Intelligence |
| Analyst Notes | All modules |
| Attack Surface Intelligence | Attack Surface Intelligence |
| Autonomous Threat Operations | Threat Intelligence or SecOps Intelligence, & Autonomous Threat Operations add-on |
| Collective Insights | SecOps Intelligence, Threat Intelligence |
| Detection Rules | SecOps Intelligence, Threat Intelligence |
| Entity Match | All modules |
| Fusion | Fusion access granted by Support as needed |
| Identity Intelligence | Identity Intelligence |
| Links | SecOps Intelligence, Threat Intelligence |
| Lists | All modules |
| Malware Intelligence | SecOps Intelligence, Threat Intelligence |
| Payment Fraud Intelligence | Payment Fraud Intelligence |
| Risk | All modules with the addition: Integration user - "Risk History Read API Access" enabled User privilege - RiskApiRead |
| Sandbox | SecOps Intelligence, Threat Intelligence |
| Takedowns | Brand Intelligence |
| Threat Maps | Threat Intelligence |
Enrichment & Risk Lists
| API | Included Modules |
|---|---|
| Company Enrichment | Third Party Intelligence |
| IP / Domain / URL Enrichment | SecOps Intelligence, Threat Intelligence, Brand Intelligence |
| Hash / File Enrichment | SecOps Intelligence, Threat Intelligence |
| IOC Risk Lists | SecOps Intelligence, Threat Intelligence |
| Malware Enrichment | SecOps Intelligence, Threat Intelligence |
| SOAR | SecOps Intelligence, Threat Intelligence |
| Vulnerability Enrichment | Vulnerability Intelligence |
| Vulnerability Risk Lists | Vulnerability Intelligence |
Troubleshooting 403 Errors
A 403 Forbidden response from the Recorded Future API can indicate one of two distinct issues:
"Missing API privileges" — Your API token does not have the module entitlement required for the endpoint you are calling. Check the tables above to verify your module includes the API. If it does not, contact your Recorded Future account team to discuss adding the required module. If your module was recently added, you may need to regenerate your API token for the new entitlements to take effect.
"Missing Data permissions" — Your API token has the correct module entitlement, but your account lacks access to the specific data group referenced in the request. This is a data-scope restriction, not a licensing issue. Contact your Recorded Future administrator to review your data-group ACL configuration.
Read the error.message field in the JSON response to determine which type of 403 you received.
