Subdomains Lookup

Domain Intelligence and Analysis
POST /api/v1/domain/subdomains Bearer

Subdomains Lookup API — discovers subdomains observed for a domain, each with first_seen and last_seen dates so you can tell live infrastructure from historical records. Results are paginated: read total_pages and total_records from the first response, then pass page to walk the rest. Pass status to return only active or only inactive hosts. Built for attack-surface mapping, asset inventory and shadow-IT discovery. Each page is one billable call.

Availability

🌍 Global — Available worldwide

What Subdomains Lookup Is Used For

Attack surface mapping

Discover subdomains exposed for a domain, with first_seen and last_seen dates to separate live from historical.

Shadow IT discovery

Find hosts standing up under your domain that never went through IT.

Asset inventory

Build and refresh a list of everything published under a domain you own.

Acquisition due diligence

Survey the infrastructure footprint of a company before you buy it.

Quick Start

1. Copy your API key from Dashboard → API Keys
2. Send a POST request to /api/v1/domain/subdomains
3. Pass the key as Authorization: Bearer <key>
4. Read the result from the data object in the JSON response

cURL

curl -X POST https://app.way2api.com/api/v1/domain/subdomains \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"domain_name":"way2api.com"}'
🚀 Send Request
✓ Key saved

🔑 Remember API Key

One-click convenience for testing & troubleshooting — no account needed.

1

What it doesSaves your API key in this browser only using localStorage. Next time you open a docs page, the Try It panel is pre-filled automatically.

2

Auto-updatesIf you type a different key into any Try It field, the saved key is replaced instantly — only the most recent key is ever stored.

3

Uncheck to forgetUnchecking “Remember API Key” immediately deletes the stored key and clears the field. While unchecked, nothing is saved even if you type a new key.

4

Re-check to save againChecking the box again saves whatever key is currently in the Try It field.

⚠ Security note: Your key is stored only in your browser and is never sent to any server except as part of the actual API call you send. Do not use this feature on shared or public computers.