Find related alerts
Find alerts that share threat infrastructure
GET /v2/alert/related returns the alerts connected to one alert through
observed threat infrastructure, such as a shared name server, registrant, or
hosting provider. This endpoint is available only in V2 and requires Threat
Graph Insights.
Identify the alert
Provide exactly one query parameter:
alert_id— the alert ID, such asACM-1234entity— the alert's URL, phone number, or email address
Passing both parameters, or neither, returns 400 Bad Request.
curl --request GET \
--url "https://api.doppel.com/v2/alert/related?alert_id=ACM-1234" \
--header "Authorization: Bearer <YOUR_ACCESS_TOKEN>"To look up by entity, URL-encode the value:
curl --request GET \
--url "https://api.doppel.com/v2/alert/related?entity=https%3A%2F%2Fsuspicious-site.example.com" \
--header "Authorization: Bearer <YOUR_ACCESS_TOKEN>"Read the response
The response contains a thin summary of each related alert:
{
"related": [
{
"id": "ACM-5678",
"queue_state": "actioned",
"entity_state": "active",
"created_at": "2026-08-10T17:04:31.221+00:00"
}
],
"truncated": false
}Results are newest first and exclude the alert from the request. The list
contains at most 100 alerts and is not paginated. When more than 100 alerts are
connected, truncated is true and the oldest results are omitted.
The endpoint returns only alerts that the caller can open with
GET /v2/alert, so visibility follows the products available to the account.
Use a returned id with GET /v2/alert to retrieve the full alert.
This response does not expose Threat Graph nodes, edges, or observations.
Status codes
| Status | Meaning |
|---|---|
200 OK | Related-alert summaries were returned. |
400 Bad Request | The request did not provide exactly one of alert_id or entity. |
401 Unauthorized | The OAuth access token is missing or invalid. |
404 Not Found | Threat Graph Insights is unavailable or the alert cannot be read. |
429 Too Many Requests | The rate limit was exceeded. |
502 Bad Gateway | The related-alert data could not be read. |
Next steps
- Check an alert's status — read the current workflow
state of a returned alert. - Request a takedown — move a confirmed alert to
actioned.
Updated about 1 month ago
