---
title: "URLs by Keyword"
method: POST
path: "/search-by-keyword/urls"
tags: ["Keyword Search"]
---

# URLs by Keyword

`POST /search-by-keyword/urls`

Search for URLs based on keywords.

## Request body

- object
  - `keyword` string, required — Keyword to search for in URLs. Case-insensitive. Examples include 'rdweb', 'citrix', 'webmail', etc.
  - `cursor` string — Base64 encoded pagination cursor for retrieving the next set of results. Obtained from the 'nextCursor' field in the previous response. Enables efficient pagination through large result sets without data loss.
  - `sort_direction` 'asc' | 'desc' — Direction to sort results. 'desc' returns newest file exposures first (recommended for threat monitoring), while 'asc' returns oldest exposures first (useful for forensic analysis and incident timelines).

## Response `200`

Successful keyword URLs search

- KeywordUrlsResponse
  - `data` KeywordUrlsData[]
    - `domain` string
    - `urls` string[]
    - `occurrence` integer
  - `nextCursor` string — Cursor for the next page of results

## Other responses

- `400` — Validation error - the request or request body was invalid
- `401` — Unauthorized - the server could not authenticate the request
- `403` — Forbidden - the server authenticated the request but refuses to process it because of insufficient permissions
- `404` — Not found - the server could not find the requested resource
- `408` — Timeout - the server timed out while waiting for a response (90 seconds)
- `429` — Rate limit exceeded - the server has received too many requests in a short period of time
- `500` — Internal server error - the server encountered an unexpected condition that prevented it from fulfilling the request

---

[API](https://skmtc.net/hudsonrock/apis/cavalier-api.md) · [All operations](https://skmtc.net/hudsonrock/apis/cavalier-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/hudsonrock/cavalier-api/revisions/5ba0142eec4d/schema)
