> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Joe Sandbox

## Overview

Joe Sandbox is a malware analysis platform for detonating and analyzing files and URLs. This guide walks through how to create a Joe Sandbox connection and the access it requires to be used in Blink's Automated Case Management, primarily for **Enrichment** workflows (file hash and related threat lookups).

<Note>
  Joe Sandbox does not use OAuth scopes. The connection authenticates with a single **API key**. See [Required Access](#required-access).
</Note>

***

## Creating a Connection

<Card title="Joe Sandbox Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/joe-sandbox">
  Follow this guide to create a Joe Sandbox connection
</Card>

***

## Required Access

Joe Sandbox has no OAuth scope selection. Access is granted by the **API key**, and available capabilities depend on your account tier.

| Setting | Value | Notes |
| - | - | - |
| Authentication | API key | Joe Sandbox does not use OAuth scopes |
| Endpoint access | Read/search access to analysis results | Required for file hash / indicator lookups |

<AccordionGroup>
  <Accordion title="Which stage of Alert Processing need this connection?" icon="table">
    | Source | Requires this connection? | Notes |
    | - | - | - |
    | Ingestion | ✗ No | Not applicable |
    | Enrichment | ✓ Yes | File hash and related threat lookups |
    | Response | ✗ No | Not applicable |
  </Accordion>
</AccordionGroup>

***


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.