Skip to main content
When you first evaluate ChainPatrol over the API, the questions are usually counts: how many confirmed threats, how many detections, how many watched, how many above a confidence cut-off. Each one below is a single request with includeTotal: true, so you get the number without paging through every result.
Don’t add a date window unless you mean one. Every date filter cuts off older history, and each endpoint filters on a different timestamp:
Throughout, exclude deleted detections with { "property": "deleted", "operator": "notIn", "value": ["deleted"] }, because /detection/list includes them by default.

How many confirmed threats do we have?

A confirmed threat is an asset ChainPatrol reviewed and blocked. If protection is not active for your organization, confirmed threats are held as Pending Blocked instead of being enforced, but they are still confirmed. Include both.
metrics.newThreats is the all-time count, with domainThreats, twitterThreats, telegramThreats and otherThreats as the breakdown. To list them from your detections:
The two numbers can differ: newThreats also counts threats you reported yourself that no detector produced. To list every confirmed threat regardless of source, use /threats/list with includePending: true and an early startDate.

How many detections for domains do we have?

total counts detections. Several detections can point at the same domain, so de-duplicate by asset.id if you need unique domains.

How many watchlisted domains are there?

Leave out assetType for the whole watchlist. That total matches threatsWatchlisted in /metrics/summary. Each item’s reason says why it is being watched (DEAD, PARKING, NOT_ENOUGH_EVIDENCE, …).

How many detections are over 80% (or 90%) confidence?

Use the raw score cut-off, not the confidence filter. Confidence levels are bucketed from the score with your organization’s own thresholds, so "high" is not a fixed percentage.
minScore is inclusive. Change it to 0.9 for the 90% question, and page with nextCursor to list every match.

From the CLI or an AI agent

The same questions with the ChainPatrol CLI:
The CLI has no flag to exclude deleted detections, so its detections list totals include them. Use the API requests above when the exact number matters. The ChainPatrol MCP server includes a detection_evaluation prompt that runs all of these for an organization and reports the counts.