API & MCP Access & Usage
Summary
- Access to Recorded Future Integrations, Recorded Future Integration Center, Recorded Future APIs and Recorded Future MCP may be included in your subscriptions.
- Across all features, a single unified usage quota applies, defined by the “Daily API Call Limit” and measured across both API calls and MCP tool calls.
- This article describes access limitations, usage quota and enforcement details.
- This article is provided for informational purposes only and is subject to change. If there is any conflict between this article and your subscription Order Form or the agreement between you and Recorded Future, such document controls.
Integrations And API Access
- Depending on offerings included in your subscription, access may include all the integrations listed here.
- The list of available integrations is subject to change, and the availability of any individual integration may depend on the continued availability and support of the applicable third-party product.
- If integrations are included in your licensing, they are limited to the default Recorded Future configuration settings. The Integration Center may enable you to generate your own API token, with instructions available to assist with the setup process.
- If you require changes to these default settings, or additional configuration support or customization, a Professional Services engagement may be required, and is not included in your licensing unless purchased separately.
- Output available in the APIs or Recorded Future MCP is limited to the data included in capabilities aligned to your package subscription. The APIs that count against the Daily API Call Limit as of the date of this article, including any successor, renamed, or replacement APIs, are listed below:
- Alert API
- Analyst Note API
- Attack Surface Intelligence API
- Connect API
- Detection Rule API
- Detection Rule Relation API
- Entity Match API
- Links API
- List API
- Malware Intelligence API
- Playbook Alert API
- SOAR API
- Threat API
MCP Access
- Recorded Future MCP is available to customers whose subscriptions include unlimited integrations. Within it, each tool is designed to authenticate individually against your organization’s and the applicable user’s entitlements.
- For Integration Users (i.e. when creating an enterprise-wide MCP OAuth credential from the Integration Center), the customer is responsible for selecting which entitlements may be accessed by that Integration User.
- For customers whose subscriptions do not include unlimited integrations - Recorded Future is extending access to Recorded Future MCP pilot through December 31st 2026. Access will be available via portal users only, with entitlements applied from that user’s existing entitlements. Following the pilot period, continued access will require an upgrade to the latest packages as available at that time.
Pilot access is provided on an as-is basis without any service level commitment or support obligation, and may be modified, suspended or discontinued by Recorded Future at any time.
Usage Quota
- The Daily API Call Limit is 5,000 calls per day by default, unless a different limit is specified in your subscription Order Form, in which case the Order Form controls.
- Additional calls can be purchased separately.
- When specified in your order form and multiple packages or products are purchased, the highest applicable Daily API Call Limit among the purchased offerings shall apply, and such limits are not cumulative.
- For API Usage:
- An API Call is a single request sent from, or on behalf of, a Customer to a Recorded Future API, whether or not the request returns results, and including requests that return an error or are retried.
- Integrations may use one or more of the above APIs, and each API Call (regardless of API used) shall apply towards the Daily API Call Limit.
- For MCP Usage:
- Recorded Future MCP counts against your Daily API Call Limit at a ratio of one tool call to one API call.
- When making an MCP tool call, the underlying API calls executed by MCP to retrieve information are not separately counted.
Usage Visibility And Enforcement
- Customers can view their daily usage within the Recorded Future Platform. Usage data is provided for informational purposes only and may be subject to reporting delays.
- Recorded Future reserves the right to apply rate limiting or throttling, and to suspend or limit access, where usage is excessive or sustained above the Daily API Call Limit, threatens the security, integrity, or availability of the Recorded Future Platform, or violates the applicable agreement.
- Recorded Future’s current practice is not to suspend access to Integrations or Recorded Future MCP solely because a customer exceeds its Daily API Call Limit on a given day.
- Example: You have a breaking incident that requires rapid, high-volume triage of indicators via both API and MCP. Executives are also leveraging Recorded Future MCP through your organization's in-house AI assistant to understand the situation. You exceed your Daily API Call Limit by several thousand calls. This example is illustrative only and does not create an entitlement to usage above your Daily API Call Limit.
- If a customer is repeatedly over its Daily API Call Limit, Recorded Future will generally reach out through its account teams to discuss options, which may include purchasing additional calls or upgrading the subscription.