Integrations · Security

Shodan

What the internet can see of your infrastructure, checked by agents — free lookups first, credit-spending searches only when the question needs them.

8 actions · out of the box: Attack Surface Analyst, Threat Analyst

What your agents get done with it

What does the internet see of this host?

Paste an IP and get the outside view: open ports, service banners, product versions, known CVEs. The free snapshot runs first and the full record only when detail matters — neither costs query credits, so the routine check stays routine.

Runs on: shodan.quickhost · shodan.host

Size the search before you pay for it

"How many of our boxes answer on 3389?" A free count with facet breakdowns comes first; the credit-spending search runs only when the number is worth paying for. The answer arrives with its price tag attached.

Runs on: shodan.count · shodan.search · shodan.credits

The address in your logs, identified

An unfamiliar IP shows up in a log. Reverse DNS names it, the host record shows what it actually is — ports, products, organisation, known CVEs — and you get the one answer that matters: something, or nothing.

Runs on: shodan.dns_reverse · shodan.host

The domain footprint, mapped

One call returns a domain's subdomains and passive DNS — one query credit, spent knowingly. Known hostnames resolve to IPs for free, and each one feeds the free snapshot check. The result is a footprint list someone can act on.

Runs on: shodan.domain · shodan.dns_resolve · shodan.quickhost

Every action, honestly listed

The complete seeded set — what each one does and costs, stated before an agent may call it. Nothing hidden, nothing padded.

  • shodan.quickhostQuick host snapshot

    A free, no-credit port and CVE snapshot for one IP from Shodan's InternetDB (cached weekly). The first-pass triage read.

    read-onlyno vendor charge
  • shodan.hostHost detail

    The full Shodan record for one IP: open ports, service banners, products and versions, organisation, ISP, ASN, known CVEs, and location. Costs no query credits.

    read-onlyno vendor charge
  • shodan.dns_resolveResolve hostnames

    Resolves a comma-separated list of hostnames to IP addresses through Shodan DNS. Free, no credits.

    read-onlyno vendor charge
  • shodan.dns_reverseReverse DNS

    Reverse-DNS a list of IPs back to hostnames — who owns an address seen in logs or search results. Free, no credits.

    read-onlyno vendor charge
  • shodan.countSearch count + facets

    The result count and facet breakdown for a Shodan search query, with no host data returned. Free — the honest way to size a search before spending credits.

    read-onlyno vendor charge
  • shodan.searchSearch hosts

    Runs a Shodan search and returns matching hosts: IP, port, organisation, product, version, title. Spends 1 query credit per page whenever the query has a filter.

    read-onlyspends vendor credits
  • shodan.domainDomain + subdomains

    Subdomains and passive DNS records for one domain from Shodan. Spends 1 query credit.

    read-onlyspends vendor credits
  • shodan.creditsShodan credits

    Your Shodan plan plus remaining query and scan credits — called before any credit-spending action, and whenever you ask what recon is costing.

    read-onlyno vendor charge

Comes wired into these roles

Every Shodan action is a capability any agent in your workforce can hold. Out of the box it comes wired into the roles below — a starting point, not a boundary.

Attack Surface Analyst

What is exposed on a host or domain, and how large a footprint looks.

shodan.dns_resolve · shodan.quickhost · shodan.host · shodan.count · shodan.dns_reverse · shodan.credits · shodan.search · shodan.domain

Threat Analyst

An IP, domain, URL or file hash out of a log — is it known-bad, and what is it actually?

shodan.host

The full twelve-agent roster, with every action list, is in AI agent examples.

How connecting works

Connect Shodan once, in the Ahel desktop app, with your own key — stored by your runtime, not by us, removable at any time. From then on any agent whose job needs it can use it: hand over a job, get back a run with a receipt.

Shodan issues API keys with any account at account.shodan.io; query credits come with Shodan's own membership and plan tiers, at Shodan's prices. Ahel adds no markup.

Costs and limits, honestly

  • Six of the eight actions cost no query credits at all — the snapshot, the full host record, both DNS lookups, the search count, and the credits check.
  • Only shodan.search (one credit per page, when filtered) and shodan.domain (one credit) spend, and both are flagged in their own descriptions.
  • Agents call shodan.credits before anything that spends, and whenever you ask what recon is costing.

Questions people actually ask

Do I need a paid Shodan plan?

For most of the catalog, no: six of the eight actions — including the host snapshot and full host record — spend no query credits. The two that do (shodan.search and shodan.domain) draw on credits that come with Shodan's own membership and plan tiers, at Shodan's prices.

How do I get a Shodan API key?

From Shodan directly: create an account at account.shodan.io and the key is on your account page. Paste it once into the Ahel desktop app; it is stored by your own runtime and you can remove it whenever you like.

What does a Shodan query credit buy here?

One page of shodan.search results (when the query uses a filter), or one shodan.domain call for subdomains and passive DNS. Agents run the free shodan.count first to size a search, and shodan.credits to check the balance before spending.

Can agents scan my network with this?

No. Every seeded action is a read of Shodan's existing index — nothing here launches a scan or touches your hosts. Agents report what the internet already sees, which is exactly the point.

Put Shodan in your agents’ hands.

Ahel is invite-only while access opens in batches. Request yours, connect Shodan with your own key, and hand an agent its first real job.