Browse the API reference

Domains

List a domain's hosts

Paged hosts for one root domain, newest first. Handles 100k+ hosts.

GEThttps://chaos.thescope.top/api/v1/domains/{domain}/subdomainsscope: read

Path parameters

domainstringrequired

Root domain.

Query parameters

filterstringoptionaldefault all

Subset of hosts to return.

allnewinactive
searchstringoptional

Substring match on the host.

limitintegeroptionaldefault 100

Rows to return (max 1000).

offsetintegeroptionaldefault 0

Rows to skip.

Example response

200 application/json
{ "data": [ { "host": "www.lovable.app", "first_seen_at": "2026-07-02T10:00:00Z", "is_active": true } ], "meta": { "total": 9948 } }

Errors

400invalid_bodyA POST body was missing or was not valid JSON.
400invalid_domainThe supplied domain is not a valid root domain.
400invalid_queryA required query parameter was missing or too short.
400invalid_idA path id was not a UUID.
401missing_tokenNo Authorization or X-API-Key header was sent.
401invalid_tokenThe token is malformed or unknown.
401revoked_tokenThe token was revoked by its owner.
404not_foundThe domain, platform, scan or endpoint does not exist.
405method_not_allowedThe HTTP verb is not supported on that path.
500query_failedA database query failed while serving the request.
500server_errorAn unexpected error occurred.

Full catalogue with fixes on the errors page.

GETTry it

Kept in this browser tab only and sent straight to this API.

https://chaos.thescope.top/api/v1/domains/lovable.app/subdomains?filter=all&limit=100&offset=0
curl "https://chaos.thescope.top/api/v1/domains/lovable.app/subdomains?filter=all&limit=100&offset=0" \
  -H "Authorization: Bearer chs_live_xxxxxxxxxxxx"