---
title: "ESPY Integration"
description: "Connect AI agents to the ESPY IRBIS OSINT API for people, data, and compliance lookups. Agents run people searches, check breach and deep web exposure, analyze images, and screen subjects against compliance lists."
url: https://flowrunner.ai/integrations/espy
date_modified: 2026-08-11T09:36:14-07:00
---

# ESPY

[Identity & Security](https://flowrunner.ai/integrations/category/identity-security)

Connect AI agents to the ESPY IRBIS OSINT API for people, data, and compliance lookups. Agents run people searches, check breach and deep web exposure, analyze images, and screen subjects against compliance lists.

[Verified](https://flowrunner.ai/integrations/verified "What does verified mean?") · 25 actions · API key · available

[ESPY website](https://irbis.espysys.com/) · [Platform Documentation](https://irbis.espysys.com/developer) · Capability data verified 2026-08-12

1.  A new counterparty is added to the onboarding queue and needs a screening file
2.  Agent starts Watchlist And PEP Screening for the subject and keeps the returned request id
3.  Agent waits out the 30 second enrichment interval before retrieving anything
4.  Agent calls Get Lookup Result with the request id and reads the returned matches
5.  Agent compares each match on date of birth, aliases, and jurisdiction rather than name alone
6.  Compliance analyst receives the subject, the matched entries, and the strength of each match
7.  Any screening hit goes to the named compliance owner for the accept, reject, or escalate call

## What This Integration Enables

ESPY is not a risk score. It is an evidence gathering surface, and that distinction shapes how it should be used. The IRBIS API returns what it found and where, and the judgment about what that means stays with you. Agents run people enrichment from a phone number, an email address, a full name, or an Instagram ID, search social posts by keyword with Leads Search, and verify whether a number belongs to a real person or a scammer with Real Phone Check. They check exposure with Breach Scan across leaks and deep web sources, using an email, phone, password, full name, or platform ID as the search value. They analyze images with Face WebScan for facial matches across social networks and Scene Check for location and scene context. They validate and enrich company and financial data through KYC Validator, geolocate an address with IP Geolocation, cross check a phone against an IP or a name, capture a page with Web Scraper, and produce AI analysis of text and subjects through Sentiment Analysis, Psychological Portrait, and Psycho Profile By Text. Three actions sit in a different weight class: SSN Trace, National Criminal Screening, and Watchlist And PEP Screening return findings about a named person that carry consequences for that person.

Every lookup in this connector is asynchronous and there are no triggers. Nothing in ESPY starts a FlowRunner flow, and the connector does not receive events. A start action submits the request and immediately returns a request id with a status of progress. The flow then waits at least 30 seconds, because a shorter interval returns an insufficient enrichment timeout error, and calls Get Lookup Result with that id to collect the enriched data. This start-then-collect shape is the pattern to build around: agents hold the request id, poll on their own schedule, and use List Requests to reconcile across a batch rather than blocking on any single lookup. Get Credits Status reports the account balance and expiration, and Delete Record removes a lookup request record permanently. Most start actions also take a Lookup ID that selects the endpoint and package, and the available values differ by subscription.

### Without FlowRunner

**Screening spread across portals**: An analyst opens several vendor sites per subject and copies findings into a spreadsheet

**No record of what was searched**: The file shows the conclusion but not the query, the sources, or the date it ran

**Hits resolved by whoever is free**: Match adjudication depends on which analyst picked up the case that morning

### With FlowRunner

**One screening surface**: Watchlist, criminal, and identity checks all start and return through the same flow

**Request id on every result**: Each finding traces back to a specific lookup request that can be listed and re-read

**Hits routed to a named owner**: No screening match resolves without a person on the record who resolved it

## Use Case Scenarios

### Counterparty Screening at Onboarding

A new vendor or client reaches the onboarding stage. The agent starts Watchlist And PEP Screening with the subject name, any known aliases, and the category refinements the policy calls for, then holds the request id. After the enrichment interval it collects the result with Get Lookup Result. A clean return moves the counterparty forward with the request id recorded against the file, so the screening can be evidenced later by its own reference rather than by a screenshot. A return with matches does not move forward at all until a person has looked at it. The flow produces a documented search, not a verdict.

### Verifying a Contact Before Outreach

An outbound flow is about to spend real effort on a lead list of unknown provenance. Before anything sends, the agent runs Real Phone Check on each number and Phone Vs Name Validator to confirm the number corresponds to the name on the record. Numbers that return a scammer indication or a name mismatch are pulled out of the send. The agent also runs Breach Scan on the email addresses so the team knows which contacts are appearing in leak corpora and may be receiving fraudulent messages that look like yours. The list that survives is smaller and worth working.

### Building the Evidence File for an Investigation

An investigator opens a case on a subject and needs a file that holds up. The agent starts several lookups in parallel: Name Lookup for social presence, Email Lookup and Phone Lookup for associated data, Face WebScan against a supplied image, and Scene Check on any images tied to the case. It collects each with Get Lookup Result and assembles them into one packet with the request ids preserved. The investigator reads the packet. The agent has done the collection work across sources and formats, and every claim in the packet points back to a request that can be pulled again from List Requests.

## Human-in-Loop Highlight

A hit on Watchlist And PEP Screening, National Criminal Screening, or SSN Trace is not a number to threshold. It is an assertion about a specific named human being, matched largely on name, which means common names generate matches that belong to somebody else entirely. Acting on one carries obligations in both directions: obligations to act, and obligations not to act against a person on the strength of a partial match. Neither of those belongs to an agent. So when a screening returns any match, the agent assembles the case and stops. It posts to the compliance owner: "Watchlist And PEP Screening on \[subject\] returned \[n\] matches. Closest entry: \[name\], \[DOB\], \[jurisdiction\], \[category\]. Aliases searched: \[list\]. Request id \[id\]. Clear as false positive, escalate for enhanced review, or reject?" The named compliance owner decides, and the agent records who decided and on what evidence. The second irreversibility is quieter and worth naming: Delete Record permanently removes a lookup request from the account, so a flow that tidies up after itself can erase the very record that evidences a decision. That deletion is gated on the same person, never on a retention rule an agent applies by itself.

Agent processes routinely

Detects on Watchlist And PEP Screening

Clear match Continues automatically

Ambiguous Routes to human via preferred channel

Human decides

Agent resumes with decision

## Agent Capabilities

25 actions

### People Lookup

6

-   **Phone Lookup** Starts a phone number enrichment that gathers associated data from mobile applications and exposed data sources. Returns the request id used with Get Lookup Result. Which underlying lookup runs is determined by the Lookup ID chosen from your subscription.
-   **Email Lookup** Starts an email address enrichment that uncovers associated data from mobile applications and exposed data sources. Returns the request id used with Get Lookup Result.
-   **Name Lookup** Starts a full name enrichment across social networks including Facebook, Twitter, LinkedIn, Instagram, OK and VK, plus exposed data sources. Returns the request id used with Get Lookup Result.
-   **Instagram ID WebScan** Starts an Instagram profile enrichment by Instagram ID, returning current profile statistics and archived profile data.
-   **Leads Search** Starts a keyword based leads search across social network posts from Facebook, Twitter, LinkedIn, Instagram and VK.
-   **Real Phone Check** Starts a real phone verification that combines a phone number lookup with AI analysis and returns a report and score indicating whether the number belongs to a scammer or a real person.

### Breach and Deep Web

1

-   **Breach Scan** Starts a BreachScan that checks whether the supplied value appears in data leaks and breaches across deep web sources. The Value Type selects whether the value is read as an email, phone, password, full name, or platform ID.

### Image Intelligence

2

-   **Face WebScan** Starts a facial recognition image search that looks for the person in the supplied image across social networks, returning matches with relevance scores. The image is downloaded from the provided URL and submitted as base64.
-   **Scene Check** Starts a Scene Check that analyses an image to reveal location, time context and scene insights, and performs an automated threat assessment.

### Analysis and Verification

9

-   **Sentiment Analysis** Starts an AI sentiment analysis of the supplied text, evaluating its emotional tone.
-   **KYC Validator** Starts a KYC check that validates and enriches company and financial data. The Check Type selects between validating a VAT number, validating an IBAN, or enriching a company by its domain.
-   **Web Scraper** Starts a web collection task that captures a webpage as a screenshot image or scrapes its content, selected by the Mode field.
-   **IP Geolocation** Starts an IP geolocation lookup that pinpoints the city, region, country and coordinates of the supplied IP address.
-   **Phone Vs IP / Email Validator** Starts a validation that checks the connection between a phone number and an IP address, or validates an email domain. Supply the phone and IP for the first check, or the email address for the second.
-   **Psychological Portrait** Starts an AI psychological profile or summary of a person identified by their Facebook ID. The Output field selects between a full portrait and a concise summary.
-   **Psycho Profile By Text** Starts an AI psychological profile or summary built from a person's name and associated text. The Output field selects between a full portrait and a concise summary.
-   **Phone Validation Request** Starts a phone validation that verifies the results of an earlier Phone Lookup, referenced by its search result id.
-   **Phone Vs Name Validator** Starts a validation that checks whether a phone number corresponds to an expected name.

### Compliance Screening

3

-   **SSN Trace** Starts a US SSN Trace that verifies an applicant's identity and returns details associated with the Social Security Number, such as reported names, dates and locations. Findings are routed to a compliance owner rather than applied automatically.
-   **National Criminal Screening** Starts a US National Criminal Screening across records collected from federal, state, county and local sources. The subject name is required, and date of birth fields plus a list of state codes narrow the search. Findings are routed for human adjudication.
-   **Watchlist And PEP Screening** Starts an international Watchlist and Politically Exposed Persons screening sourced from global sanctions, watchlists and government databases. Optional categories and aliases refine the match. Any match is routed to a named compliance owner.

### Results and Account

4

-   **Get Lookup Result** Retrieves the data for a single lookup request by its id. This is the collection half of every lookup in this connector: start actions return a request id with a status of progress, and this returns the enriched results once processing completes. Allow at least 30 seconds after the start action.
-   **List Requests** Retrieves a paginated list of lookup requests made on the account, using offset and limit. Used to reconcile a batch of in flight lookups and to re-read the evidence behind an earlier decision.
-   **Get Credits Status** Retrieves the account's current credit balance, including balance details, currency, expiration date and account status. Used before a batch to confirm the run can complete.
-   **Delete Record** Deletes a single lookup request record from the account by its id. This is permanent and removes the record that evidences a lookup, so it is gated on a human rather than applied by a retention rule.

## Frequently Asked Questions

### What can FlowRunner do with ESPY?

FlowRunner agents can run Phone Lookup, Email Lookup, and Name Lookup in ESPY, plus 22 more actions.

### Does connecting ESPY to FlowRunner require OAuth?

No. ESPY connects to FlowRunner with an API key, no OAuth flow required.

### Can ESPY trigger a FlowRunner workflow automatically?

ESPY doesn't currently expose triggers in FlowRunner. It connects as an action step inside workflows started by another trigger.

**Work at ESPY?** This integration exposes ESPY to AI agents on every FlowRunner plan, including through MCP, at no cost to you. [See what FlowRunner offers integration partners](https://flowrunner.ai/integrations/partners), including how to keep this page current.

---
Markdown version of https://flowrunner.ai/integrations/espy. Site index: https://flowrunner.ai/llms.txt
