Track takedown requests

Track takedown requests

Use GET /v2/alert/takedown-requests to read what Doppel filed with each
platform for one alert. An alert can have several requests because each request
targets one platform.

Prerequisite

Get an OAuth access token (see Authentication).

List requests for an alert

Pass the public alert ID as alert_id:

curl --request GET \
  --url "https://api.doppel.com/v2/alert/takedown-requests?alert_id=ACM-1234&limit=25&offset=0" \
  --header "Authorization: Bearer <YOUR_ACCESS_TOKEN>"

Requests are returned newest first. limit defaults to 25 and accepts 1–100;
offset defaults to 0.

Read the response

{
  "data": [
    {
      "id": "44444444-4444-4444-4444-444444444444",
      "platform": "registrar",
      "argument": "phishing",
      "status": "reported",
      "created_at": "2026-08-24T12:00:00",
      "updated_at": "2026-08-24T12:30:00",
      "submitted_at": "2026-08-24T12:05:00",
      "external_case_id": "CASE-1",
      "latest_platform_response": {
        "matched_at": "2026-08-24T12:30:00",
        "email_type": "confirmation"
      }
    }
  ],
  "count": 1
}

Each item reports its current status, the argument Doppel filed under, the
platform's case identifier, and the latest matched platform response when one
is available. count is the total number of requests for the alert, before
pagination.

Get one request

Use the request id with GET /v2/alert/takedown-request.

curl --request GET \
  --url "https://api.doppel.com/v2/alert/takedown-request?id=44444444-4444-4444-4444-444444444444" \
  --header "Authorization: Bearer <YOUR_ACCESS_TOKEN>"

The response contains all fields from the list item. It also contains the
alert_id, activity, and activity_truncated fields.

The activity array contains status changes and platform email events. Events
are in oldest-first order. The response contains the newest 100 events. The
activity_truncated value is true when older events are not in the response.

These endpoints are read-only.

Status codes

StatusMeaning
200 OKDoppel returned the request page or request detail.
401 UnauthorizedThe access token is missing or invalid.
403 ForbiddenThe token is not mapped to a Doppel organization.
404 Not FoundDoppel cannot find the alert or request for your organization.
422 Unprocessable EntityA page value or request ID is invalid.
429 Too Many RequestsRate limit exceeded.

Next steps


Did this page help you?