Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

Explore

  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Tags index
  • Submit a server
  • Pricing

Learn

  • Guides hub
  • What is MCP?
  • Install guide
  • Troubleshooting
  • Security
  • Blog
  • Blog RSS

Tools

  • All tools
  • Config generator
  • Config validator
  • MCP playground
  • OpenAPI β†’ MCP
  • Badge generator

For agents

  • API docs
  • Trust & traffic
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
  • Remote MCP β†— (opens in a new tab)

Company

  • About
  • Contact
  • X (@AllMCPs) β†— (opens in a new tab)
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on Buildlist
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’¬ Communication
  3. OpenOSINT
O
Health: Not checked yetWe have not completed a health check for this listing yet.Last checked 8/11/2026, 12:09:43 AM

OpenOSINT

Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View RepositoryVisit Website

AI-powered OSINT agent & MCP server. 16 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Install Config Generator

Choose your client
claude_desktop_config.json
{
  "mcpServers": {
    "openosint": {
      "command": "npx",
      "args": [
        "-y",
        "openosint"
      ]
    }
  }
}

πŸ’‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)

Install Directory Badge Claim listing AlternativesπŸ’¬ More in Communication

Documentation Overview

mcp-name: io.github.OpenOSINT/openosint

OpenOSINT

OpenOSINT

OSINT agent for security researchers and analysts: 19 investigation tools behind a natural-language interface.

Use it as a REPL, CLI, MCP server, or browser Web UI.

The AI issues hard-stop tool calls; your code executes the real binary β€” hallucinated findings are structurally impossible.

Release PyPI PyPI downloads License MIT GitHub Stars MCP MCP Registry Sponsored by IP2Location Sponsored by RapidProxy

Featured Integrations

IP2Location.io logo

IP2Location.io β€” powers search_ip2location Β· Integration guide

Enhanced IP geolocation, ISP, VPN/Proxy/Tor, and datacenter detection

RapidProxy logo

RapidProxy Β· Integration guide

Reliable Residential Proxies for Data Collection & Automation β€” 90M+ IPs across 200+ countries. 10% off: RAPID10.

Open: Breach / Compromised-Credential Data Β· Email / Identity Lookup β€” see SPONSORSHIP.md.

OpenOSINT running a DNS lookup and returning records in under two seconds
Terminal
pip install openosint

Paid: Complete Kit β€” $55 (prompts + playbook, bundled) Β· Setup Sprint β€” $350 (done-for-you install) Β· Commercial License β€” from €300/yr (vendor contract, SLA, indemnification)

Quick Start

bash
# Interactive AI REPL (default)
openosint

# Web interface
openosint web

# Direct tool (no AI)
openosint email target@example.com

New to OSINT methodology? Grab the free 5-prompt starter set or the free Playbook edition before your first run.

πŸ“¬ Agents & OSINT β€” the newsletter

One AI-OSINT workflow you can run + a ruthless roundup of what's new, every week. Subscribe β†’

Run in the cloud (no install)

No Python, no holehe / sherlock / sublist3r / phoneinfoga binaries in PATH, no API keys β€” run OpenOSINT Email Recon from your browser, or as an MCP tool in Claude, Cursor, and Windsurf via the Apify MCP Server. Try for free.

Try OpenOSINT Email Recon on Apify β†’

Usage

Start the REPL and investigate any target β€” the agent decides which tools to run and chains them on findings:

text
openosint > investigate target@example.com

  -> generate_dorks('target@example.com')
  -> search_email('target@example.com')
  Found: Spotify, WordPress, Gravatar, Office365

  -> search_breach('target@example.com')
  Found in 2 breaches: LinkedIn (2016), Adobe (2013)

  -> search_username('johndoe99')   <- pivoted from email findings
  Found: GitHub, Reddit, Twitter

  Report saved -> reports/2026-05-11_14-32-11_report.md

Features

CapabilityDetails
AI tool chainingThe agent selects and chains tools based on findings; describe the target in plain language
19 modular toolsEmail, username, breach, WHOIS, IP, subdomain, dorks, paste, phone, Shodan, VirusTotal, Censys, IP2Location, AbuseIPDB, GitHub, DNS, live dork search, URL scraping, SERP footprint
Three AI backendsAnthropic Claude (default), local Ollama, or any OpenAI-compatible endpoint (LiteLLM, vLLM, LM Studio, ...)
Native MCP serverAll 19 tools exposed to Claude Code, Claude Desktop, and any MCP-compatible client β€” no extra config
Parallel execution--parallel runs complementary tools concurrently via asyncio.gather()
ReportsPDF + Markdown auto-saved after every investigation (reportlab optional)
Session historyAll REPL sessions saved to ~/.openosint/history/; browse with openosint history
Web UIBrowser-based AI chat with streaming output, tool cards, light/dark theme

Legal Disclaimer: OpenOSINT is intended for legal and authorized use only. Users are solely responsible for ensuring their use complies with all applicable laws and regulations. The authors accept no liability for misuse. See DISCLAIMER.md.

Custom Integrations

Need OpenOSINT wired into your SOC, fraud, threat-intel, or AI-agent stack? I build bespoke OSINT integrations for teams β€” you bring the data sources and compliance requirements, I deliver a working integration.

β†’ Get in touch


Tools

ToolPowered byWhat it investigates
search_emailholeheSocial accounts linked to an email address
search_usernamesherlockUsername presence across 300+ platforms
search_breachHaveIBeenPwned v3 APIData breach exposure
search_whoispython-whoisDomain registrant and DNS info
search_ipipinfo.ioGeolocation, ASN, hostname
search_domainsublist3rSubdomain enumeration
generate_dorksbuilt-in12 targeted Google dork URLs (no network calls)
search_pastepsbdmp.wsPastebin dump mentions
search_phonephoneinfogaCarrier, country, line type
search_shodanShodan APIOpen ports, banners, CVEs
search_virustotalVirusTotal API v3Verdict from 70+ antivirus engines
search_ip2locationIP2Location.io APIEnhanced IP intel: VPN/Proxy/Tor/datacenter flags (sponsored)
search_censysCensys Search APIInternet-facing infrastructure, certificates
search_abuseipdbAbuseIPDB v2 APIIP abuse reputation: confidence score, reports, country, ISP
search_githubGitHub REST APIProfile, repos, commit-discovered emails, username/keyword search
search_dnsdnspython (built-in)A/AAAA/MX/NS/TXT/CNAME/SOA records; SPF, DMARC, DKIM analysis
search_dorks_liveBright Data SERP APILive Google search results for dork queries (title, URL, snippet)
scrape_urlBright Data Web UnlockerFetch any URL bypassing Cloudflare/CAPTCHA β€” returns clean Markdown
search_footprintBright Data SERP APIEntity-type-aware public search-engine footprint: detects email/username/domain/phone/name and returns structured results + Entity Correlation Graph nodes/edges

Full per-tool documentation, CLI flags, and output formats: openosint.tech.

search_email

Enumerates online services linked to an email address using holehe.

bash
openosint email target@example.com
text
[+] Spotify        https://open.spotify.com/user/target
[+] WordPress      https://wordpress.com/target
[+] Gravatar       https://gravatar.com/target
[+] Office365      email used

search_username

Searches for a username across 300+ platforms using sherlock.

bash
openosint username johndoe99
text
[+] GitHub         https://github.com/johndoe99
[+] Twitter        https://twitter.com/johndoe99
[+] Reddit         https://reddit.com/user/johndoe99

search_breach

Checks data breach exposure via HaveIBeenPwned v3 API. Requires HIBP_API_KEY.

text
[+] LinkedIn (2016-05-05) β€” leaked: Email addresses, Passwords
[+] Adobe (2013-10-04) β€” leaked: Email addresses, Password hints

search_whois

Retrieves WHOIS data using python-whois.

text
[+] Registrar: ICANN
[+] Created: 1995-08-14
[+] Expires: 2024-08-13
[+] Name Servers: A.IANA-SERVERS.NET

search_ip

Retrieves geolocation and ASN data via ipinfo.io. Free tier: 50k/month.

text
[+] Hostname: dns.google
[+] Org: AS15169 Google LLC
[+] City: Mountain View, CA, US

search_domain

Enumerates subdomains using sublist3r.

text
[+] mail.example.com
[+] dev.example.com
[+] api.example.com

generate_dorks

Generates 12 targeted Google dork URLs for any target. No network calls.

text
[+] "johndoe" site:linkedin.com
    https://www.google.com/search?q=%22johndoe%22+site%3Alinkedin.com
[+] "johndoe" leaked OR breach OR dump
    https://www.google.com/search?q=%22johndoe%22+leaked+OR+breach+OR+dump

search_paste

Searches Pastebin dumps via psbdmp.ws.

text
[+] https://pastebin.com/aB1cD2eF (2023-04-12)
[+] https://pastebin.com/xY3zA4bC (2022-11-08)

search_phone

Gathers phone intelligence using phoneinfoga. Use E.164 format.

text
[+] Country: United States
[+] Carrier: AT&T
[+] Line type: Mobile

search_shodan

IPv4 input β†’ host lookup (open ports, org, CVEs). Any other query β†’ banner/keyword search. Requires SHODAN_API_KEY.

bash
openosint shodan 8.8.8.8
openosint shodan "apache port:80 country:DE"
text
[+] Org: Google LLC  |  Open ports: 53, 443

search_virustotal

Checks an IP, domain, URL, or file hash against VirusTotal's 70+ engines. Auto-detects input type. Requires VIRUSTOTAL_API_KEY.

bash
openosint virustotal 8.8.8.8
openosint virustotal example.com
openosint virustotal 44d88612fea8a8f36de82e1278abb02f
text
[VirusTotal] Malicious: 0 / Harmless: 72

search_ip2location

Queries IP2Location.io for enhanced IP intelligence: geolocation, ISP, ASN, and β€” on the Security Plan β€” VPN/Proxy/Tor/datacenter detection. Sponsored integration. Requires IP2LOCATION_API_KEY.

bash
openosint ip2location 8.8.8.8
text
[IP2Location] City: Mountain View, CA, US  |  ISP: Google LLC
[IP2Location] VPN: No  |  Proxy: No  |  TOR: No  |  Datacenter: Yes

search_censys

IPv4 β†’ host view (open ports, services, ASN). Domain β†’ certificate search (SANs, issuer). Requires CENSYS_API_ID and CENSYS_SECRET.

bash
openosint censys 8.8.8.8
openosint censys example.com
text
[Censys] Open Ports: 53, 443, 853  |  ASN: AS15169 Google LLC

search_abuseipdb

Checks an IP against AbuseIPDB v2. Returns abuse confidence score, total reports, country, ISP, and last reported timestamp. Requires ABUSEIPDB_API_KEY.

bash
openosint abuseipdb 198.51.100.1
text
[AbuseIPDB] Abuse Confidence Score: 87%  |  Total Reports: 143
⚠️  HIGH ABUSE CONFIDENCE β€” flagged by AbuseIPDB

Warning appears when abuseConfidenceScore exceeds 50%.

search_github

Queries GitHub REST API. Username β†’ profile, repos, commit-discovered emails. Keyword β†’ user/repo search. Optional GITHUB_TOKEN raises rate limit from 60 to 5000 req/h.

bash
openosint github johndoe99
text
[GitHub] Repos: 42  |  Followers: 128
[GitHub] Commit email: johndoe@example.com

search_dns

Queries A/AAAA/MX/NS/TXT/CNAME/SOA records and analyzes SPF, DMARC, and DKIM configuration using dnspython (no external API).

bash
openosint dns example.com
text
[DNS] A: 93.184.216.34
[DNS] MX: mail.example.com (priority 10)
[DNS] SPF: v=spf1 include:_spf.google.com ~all

search_dorks_live

Executes live Google dork queries through the Bright Data SERP APIΒΉ, returning structured results (title, URL, snippet). Defaults to 5 dorks per run; each is a separate billable API call. Requires BRIGHTDATA_API_KEY and BRIGHTDATA_SERP_ZONE.

bash
openosint search-dorks-live "john doe" --max-dorks 3
text
[+] Dork: "john doe" site:linkedin.com
    Title:   John Doe | LinkedIn
    URL:     https://www.linkedin.com/in/john-doe-12345

scrape_url

Fetches any public URL through Bright Data Web UnlockerΒΉ, bypassing Cloudflare/CAPTCHA. Returns clean Markdown. Requires BRIGHTDATA_API_KEY and BRIGHTDATA_UNLOCKER_ZONE.

bash
openosint scrape https://example.com
text
[Web Unlocker] Remote status: 200
# Example Domain
This domain is for use in illustrative examples in documents.

search_footprint

Collects a target's public search-engine footprint via Bright Data SERP APIΒΉ. Detects entity type (email, username, domain, phone, or full name) and runs entity-type-aware Google queries, returning structured results plus Entity Correlation Graph nodes/edges for discovered domains and profiles. Requires BRIGHTDATA_API_KEY and BRIGHTDATA_SERP_ZONE.

bash
openosint footprint johndoe99

Interfaces

Web UI

Terminal
pip install "openosint[web]"
openosint web
# Opens http://localhost:8080 automatically

Browser-based AI chat with streaming tool output, inline result cards, light/dark theme toggle. Supports local inference via Ollama or any OpenAI-compatible endpoint β€” no Anthropic API key required.

OpenOSINT Web UI β€” live entity correlation graph demo: investigating openosint.tech

Try the live demo β†’ β€” bring your own Anthropic / OpenRouter / Ollama key, no signup.

server.ts
# Fully local (no API key) β€” requires Ollama runtime: https://ollama.com
ollama pull llama3.2
openosint web
# Settings -> Ollama (local) -> model: llama3.2

# OpenAI-compatible endpoint (LiteLLM, vLLM, LM Studio, ...)
export OPENAI_BASE_URL="http://localhost:4000/v1"
openosint web
# Settings -> OpenAI API

Interactive REPL

Run openosint with no arguments to start the AI-powered REPL:

OpenOSINT terminal REPL demo

REPL commands:

CommandDescription
<target>Investigate any target β€” email, username, domain, IP, name
clearReset conversation memory
saveSave last report to reports/
toolsList available tools and their status
configShow current configuration
historyBrowse saved sessions
helpShow all commands
exit / Ctrl-DExit

All sessions are auto-saved to ~/.openosint/history/. Browse with openosint history.

For the REPL/CLI with an OpenAI-compatible backend:

Terminal
pip install "openosint[openai]"
openosint --provider openai \
  --openai-base-url http://localhost:4000/v1 \
  --openai-model gpt-4o-mini

Live Documentation

Full per-tool reference, CLI flags, and configuration options at openosint.tech.

openosint.tech documentation tour

MCP Server

Expose all 19 OpenOSINT tools to any MCP-compatible AI client. Once connected, Claude can natively invoke all 19 tools during conversations.

Claude Code:

Terminal
claude mcp add openosint python /absolute/path/to/OpenOSINT/openosint/mcp_server.py
claude mcp list

Claude Desktop β€” add to ~/Library/Application Support/Claude/claude_desktop_config.json:

config.json
{
  "mcpServers": {
    "openosint": {
      "command": "python",
      "args": ["/absolute/path/to/OpenOSINT/openosint/mcp_server.py"]
    }
  }
}

Prefer zero setup? The OpenOSINT Email Recon Actor is also available as a hosted MCP tool via the Apify MCP Server β€” no server to run, no config file to edit. Try for free.

Agentic use via Claude Code:

text
$ claude
> Investigate target@example.com. Trace any username found
  across other platforms and compile a full report.

Installation

bash
# From PyPI (recommended)
pip install openosint

# From source
git clone https://github.com/OpenOSINT/OpenOSINT.git
cd OpenOSINT
pip install -e .

External binaries (must be in PATH):

BinaryPurposeInstall
holeheEmail account enumerationpip install holehe
sherlockUsername enumeration (300+ platforms)pip install sherlock-project
sublist3rSubdomain enumerationpip install sublist3r
phoneinfogaPhone number intelligenceDownload binary

If a binary is absent, the corresponding tool returns a descriptive error. All other tools remain operational.

Don't want to install these locally? The OpenOSINT Email Recon Actor runs email recon in Apify's cloud β€” zero dependencies, zero local setup.

Optional Python packages:

PackagePurposeInstall
ollamaLocal LLM backend (no API key)pip install ollama (also requires Ollama runtime)
openaiOpenAI-compatible backendpip install "openosint[openai]"
shodanShodan API clientpip install shodan
reportlabPDF report exportpip install reportlab
censysCensys API clientpip install censys

Configuration

Store keys in a .env file at the project root (copy .env.example). python-dotenv loads it automatically at startup.

VariableToolRequiredPurpose
ANTHROPIC_API_KEYAI agentYes (or Ollama / OpenAI)Anthropic API key
OPENAI_BASE_URLAI agentOptionalBase URL of an OpenAI-compatible endpoint (e.g. http://localhost:4000/v1)
OPENAI_API_KEYAI agentOptionalAPI key for the endpoint (local servers may ignore it)
OPENAI_MODELAI agentOptionalModel name to request (default: gpt-4o-mini)
HIBP_API_KEYsearch_breachOptionalHaveIBeenPwned v3 β€” get one
IPINFO_TOKENsearch_ipOptionalipinfo.io higher rate limits
SHODAN_API_KEYsearch_shodanOptionalShodan API β€” get one
VIRUSTOTAL_API_KEYsearch_virustotalOptionalVirusTotal API v3 β€” get one
IP2LOCATION_API_KEYsearch_ip2locationOptionalIP2Location.io β€” get one (sponsored)
CENSYS_API_ID + CENSYS_SECRETsearch_censysOptionalCensys β€” get one
ABUSEIPDB_API_KEYsearch_abuseipdbOptionalAbuseIPDB v2 β€” get one
GITHUB_TOKENsearch_githubOptionalGitHub API β€” raises rate limit 60 β†’ 5000 req/h β€” get one
BRIGHTDATA_API_KEYsearch_dorks_live, scrape_url, search_footprintOptionalBright Data β€” get oneΒΉ (free tier: 5,000 req/month)
BRIGHTDATA_SERP_ZONEsearch_dorks_live, search_footprintOptionalYour Bright Data SERP zone name (e.g. serp_api1)
BRIGHTDATA_UNLOCKER_ZONEscrape_urlOptionalYour Bright Data Web Unlocker zone name (e.g. web_unlocker1)

CLI Reference

Flag / SubcommandDescription
openosintInteractive AI REPL (default)
openosint web [--port N] [--no-browser]Launch browser UI
openosint email ADDRESS [-t N]Direct email scan
openosint username HANDLE [-t N]Direct username scan
openosint shodan QUERY [-t N]Shodan lookup
openosint virustotal TARGET [-t N]VirusTotal lookup
openosint censys TARGET [-t N]Censys lookup
openosint ip2location IP [-t N]IP2Location lookup
openosint abuseipdb IP [-t N]AbuseIPDB reputation check
openosint github QUERY [-t N]GitHub profile/repo/email discovery
openosint dns DOMAIN [-t N]DNS records + email security analysis
openosint multi TARGETSParallel multi-target investigation (max 10)
openosint history [--all] [open N] [clear]View/manage REPL session history
-v, --verboseEnable debug logging to stderr
-t, --timeout NOverride subprocess timeout (seconds)
--api-key KEYAnthropic API key (overrides env var)
--parallelRun complementary tools concurrently
--jsonOutput results as structured JSON
--provider {anthropic,ollama,openai}AI provider (default: anthropic)
--ollama-model MODELOllama model name (default: llama3.2)
--ollama-host URLOllama server URL (default: http://localhost:11434)
--openai-base-url URLOpenAI-compatible endpoint base URL (env: OPENAI_BASE_URL)
--openai-model MODELModel to request from the endpoint (default: gpt-4o-mini; env: OPENAI_MODEL)
--openai-api-key KEYAPI key for the endpoint (env: OPENAI_API_KEY)
--no-pdfDisable automatic PDF generation

Docker

bash
# Build and run
docker compose up --build

# One-off command
docker compose run --rm openosint email target@example.com --json

Set ANTHROPIC_API_KEY (and optionally HIBP_API_KEY, IPINFO_TOKEN) in a .env file or export them before running docker compose. Reports are persisted to ./reports/ via a volume mount.

DigitalOcean App Platform: see .do/app.yaml for App Platform configuration.

Integrations

ServiceURLToolTierAuth
IP2Location.iohttps://www.ip2location.iosearch_ip2locationFeatured (sponsored)API key β€” free tier
RapidProxyhttps://www.rapidproxy.io/?ref=openosintβ€”Featured (sponsored)β€”
AbuseIPDBhttps://www.abuseipdb.comsearch_abuseipdbCommunityAPI key β€” free tier
Censyshttps://censys.iosearch_censysCommunityAPI key β€” free tier
GitHubhttps://github.comsearch_githubCommunityToken optional
HaveIBeenPwnedhttps://haveibeenpwned.comsearch_breachCommunityAPI key β€” paid
holehehttps://github.com/megadose/holehesearch_emailCommunityNone β€” local binary
ipinfo.iohttps://ipinfo.iosearch_ipCommunityToken optional
phoneinfogahttps://github.com/sundowndev/phoneinfogasearch_phoneCommunityNone β€” local binary
psbdmp.wshttps://psbdmp.wssearch_pasteCommunityNone
sherlockhttps://github.com/sherlock-project/sherlocksearch_usernameCommunityNone β€” local binary
Shodanhttps://shodan.iosearch_shodanCommunityAPI key β€” free tier
sublist3rhttps://github.com/aboul3la/Sublist3rsearch_domainCommunityNone β€” local binary
VirusTotalhttps://www.virustotal.comsearch_virustotalCommunityAPI key β€” free tier
WHOIS (IANA)https://www.iana.org/whoissearch_whoisCommunityNone
DNS (system resolver)β€”search_dnsCommunityNone
Google Searchhttps://www.google.comgenerate_dorksCommunityNone

Get the Method

OpenOSINT is the tool. The AI OSINT Complete Kit ($55) is the method: the Prompt Pack and the Operator's Playbook, bundled.

β†’ Get the Complete Kit ($55)

AI OSINT Prompt Pack

OpenOSINT gives you the tooling. The AI OSINT Prompt Pack gives you the method: 30+ tested prompts across 8 target types, with one repeatable collect β†’ pivot β†’ verify β†’ document flow for running OpenOSINT investigations.

  • Email, username, domain, IP, phone, company due-diligence, image & reporting prompts
  • One repeatable investigation flow + an ethics & legal primer
  • Instant download Β· pairs directly with OpenOSINT

β†’ Get the Prompt Pack ($29)

AI OSINT Operator's Playbook

Step-by-step workflows for running investigations with ChatGPT, Claude, and OpenOSINT.

β†’ Get the Playbook ($39)

Buying directly funds OpenOSINT's development.

AI OSINT Prompts β€” Free Starter Set

New to AI-assisted OSINT? The free starter set gives you 5 structured prompts β€” one per stage of a real investigation β€” that make ChatGPT and Claude collect real public data instead of hallucinating it.

  • Scope β†’ Collect β†’ Pivot β†’ Verify β†’ Document
  • Works with any AI assistant (Claude, ChatGPT, Gemini)
  • Instant PDF, no card required

β†’ Get the free starter set

AI OSINT Operator's Playbook β€” Free Edition

The free edition walks the 5-phase method once, end to end, on a single worked case: scope β†’ collect β†’ pivot β†’ verify β†’ document. Includes one sample prompt and the confidence rubric used to grade findings.

  • Free edition: the method + one worked investigation
  • Full edition ($39): 12 complete workflows, per-tool playbooks, reporting templates, and the legal/ethics primer

β†’ Get the free edition Β· Full Playbook ($39) β†’

Sponsor this project

OpenOSINT is used by OSINT practitioners, security researchers, and developers actively evaluating intelligence APIs. Every time a user configures an integration, the docs route them to that provider's sign-up page β€” high-intent exposure at the moment of adoption.

Featured Integration ($2,000/year or $220/month): recommended/default provider for one tool category, exclusive. Logo + badge across README, docs, CLI banner, and Web UI. One vendor per category.

Current sponsors and open categories are listed in the sponsor block at the top of this README. Full media kit, pricing, and the referral funnel: SPONSORSHIP.md.

Open Collective Β· commercial@openosint.tech Β· SPONSORSHIP.md

SERVICES

The framework is free and MIT-licensed. This is an optional paid setup service offered by the maintainer.

OSINT-MCP Setup Sprint β€” done-for-you installation and configuration of an autonomous OSINT-MCP pipeline on your environment. Fully async, no calls required.

Includes:

  • Pre-configured OpenOSINT setup tailored to your stack (Claude Code, Claude Desktop, or any MCP client)
  • API keys wired in (Shodan, VirusTotal, IP2Location, HaveIBeenPwned, and others as needed)
  • One investigation workflow built around your use case
  • Written step-by-step setup guide + screen-recorded walkthrough

Delivery: 3–5 days, fully async.

For: SOC analysts Β· threat-intel teams Β· fraud/AML Β· pentesters Β· OSINT investigators

Need it set up for you?

Get OpenOSINT wired into your stack in 3–5 days β€” done-for-you, fully async, no calls.

Book the Setup Sprint β†’ $350 (founding price, first 5 teams)

β†’ Or email commercial@openosint.tech Β· LinkedIn

For authorized use only. See DISCLAIMER.md.

Commercial License & Support

OpenOSINT is free and MIT-licensed for everyone β€” personal projects, commercial products, SaaS, and closed-source are all covered with no purchase required. Organizations that additionally need a vendor contract, written warranty, indemnification, SLA, or priority support for procurement and compliance can purchase a commercial plan. Three tiers available from €300/year β€” see COMMERCIAL.md for full details and pricing. Contact: commercial@openosint.tech.

Contributing

Issues and pull requests are welcome. See CONTRIBUTING.md for the development workflow, integration registration checklist, and coding conventions. Please read DISCLAIMER.md before contributing.

Regenerating the demo GIF/MP4

server.ts
export OPENOSINT_DEMO_KEY=sk-ant-...   # your Anthropic key β€” never committed
openosint --web &                      # start the web server on :8080
make demo                              # record -> encode -> write docs/assets/demo-web-graph.*
git add docs/assets/demo-web-graph.*

See scripts/record-demo/README.md for full prerequisites and pipeline details.

Maintainer

Tommaso Bertocchi

  • X (personal): https://x.com/SonoTommy_
  • X (OpenOSINT): https://x.com/openosint_oss
  • LinkedIn: https://www.linkedin.com/company/openosintoss
  • Email: commercial@openosint.tech

Contributors

ContributorContribution
@consociovenv/uv-tool binary resolution fix β€” co-installed tools are now found without a separate activation step (#6)

License

OpenOSINT is open source under the MIT License β€” free for any use, including personal, commercial, academic, and closed-source.


ΒΉ Bright Data links in this README are affiliate/referral links β€” OpenOSINT earns a commission if you sign up through them, at no extra cost to you.

For authorized security research only. See DISCLAIMER.md.

OpenOSINT v2.25.0 β€” July 2026

Star History

Star History Chart

Related MCP Servers

View all in Communication View all alternatives
  • Slack Mcp Server logoSlack Mcp Server

    The most powerful MCP server for Slack Workspaces.

    πŸ’¬ Communication1 views
    Compare vs Slack Mcp Server β†’
  • V
    Validator Ai Mcp

    AI-powered validator ai MCP server for agents. Supports validate json, validate email, validate

    πŸ’¬ Communication0 views
    Compare vs Validator Ai Mcp β†’
  • Mcp logoMcp

    Email validation and SMTP verification for Claude Desktop, Cursor, and Claude Code.

    πŸ’¬ Communication0 views
    Compare vs Mcp β†’
  • A
    Agent Tools

    9 utility tools for agents: DNS, WHOIS, email, IP, URL, headers, QR, text, tech. x402 on Base.

    πŸ’¬ Communication0 views
    Compare vs Agent Tools β†’

Frequently Asked Questions about OpenOSINT

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "openosint": { "command": "npx", "args": ["-y", "OpenOSINT"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewOpenOSINT AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/openosint?style=directory)](https://allmcps.com/mcp/openosint)
HTML Embed
<a href="https://allmcps.com/mcp/openosint"><img src="https://allmcps.com/api/badge/openosint?style=directory" alt="OpenOSINT on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’¬Communication
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
28Quality signal: Emerging Β· 28/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools12/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge.

Free dofollow backlink: after claiming, verify your product site and place a dofollow AllMCPs badge β€” we recheck it stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’¬ Communication β†’Best MCP servers for Slack & Communication β†’Alternatives to OpenOSINT β†’Install in Claude DesktopInstall in CursorInstall in VS Code