AirMDR Case Manager Internal API

The Case Manager Internal API from AirMDR — 10 operation(s) for case manager internal.

Operations 10

POST /v2/case/reindex Reindex Cases V2 into Opensearch #
POST /case/reindex Reindex Cases into Opensearch #
POST /case/orgcode/migrate Add org code to to all cases #
POST /case/cache/purge Purge case related cache in redis #
POST /internal/investigation_credits/charge Charge investigation credits for an alert investigation #
POST /internal/investigation_credits/refund Refund a previously charged investigation #
POST /alerts/reindex Reindex Alerts into Opensearch #
PATCH /alerts/{alert_id}/mark_agent_investigated Mark alert as investigated with agent #
GET /investigation_quota Get investigation quota for an organization #
DELETE /case/delete_organization/{organization_code} Delete Cases and Alerts for an organization #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/airmdr:airmdr-case-manager-internal-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

airmdr-case-manager-internal-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Case Manager Internal API
  version: 1.0.0
servers:
- url: /airmdrapi
tags:
- name: Case Manager Internal
paths:
  /v2/case/reindex:
    post:
      tags:
      - Case Manager Internal
      operationId: reindexCasesV2API
      summary: Reindex Cases V2 into Opensearch
      description: Ollivander will be requested to reinsert every Case one by one via RabbitMQ queues
      parameters:
      - name: User-ID
        in: header
        description: The User ID of the requestor.
        required: true
        schema:
          type: string
      - name: Organization-ID
        in: header
        description: The Organization ID associated with the requestor.
        required: true
        schema:
          type: string
      - name: X-Request-ID
        in: header
        description: The ID associated with the request
        schema:
          type: string
      - name: Execution-ID
        in: header
        description: ID of the execution if action is perfomed through a darryl action
        schema:
          type: string
      - name: Organization-Hosturl
        in: header
        description: The host url of the organization
        schema:
          type: string
      - name: register
        in: query
        description: whether to register the entity again
        schema:
          type: boolean
          default: false
      - name: starting_time
        in: query
        description: Optional unix timestamp (seconds). If provided, only cases created at or after this time will be reindexed.
        schema:
          type: integer
          format: int64
      - name: end_time
        in: query
        description: Optional unix timestamp (seconds). If provided, only cases created at or before this time will be reindexed (inclusive).
        schema:
          type: integer
          format: int64
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CaseReindexRequest'
      security:
      - SessionCookie: []
      responses:
        '200':
          description: case created successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Success'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /case/reindex:
    post:
      tags:
      - Case Manager Internal
      operationId: reindexCasesAPI
      summary: Reindex Cases into Opensearch
      description: Ollivander will be requested to reinsert every Case one by one via RabbitMQ queues
      parameters:
      - name: User-ID
        in: header
        description: The User ID of the requestor.
        required: true
        schema:
          type: string
      - name: Organization-ID
        in: header
        description: The Organization ID associated with the requestor.
        required: true
        schema:
          type: string
      - name: X-Request-ID
        in: header
        description: The ID associated with the request
        schema:
          type: string
      - name: register
        in: query
        description: whether to register the entity again
        schema:
          type: boolean
          default: false
      security:
      - SessionCookie: []
      responses:
        '200':
          description: case created successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Success'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /case/orgcode/migrate:
    post:
      tags:
      - Case Manager Internal
      operationId: addOrgCodeAPI
      summary: Add org code to to all cases
      parameters:
      - name: User-ID
        in: header
        description: The User ID of the requestor.
        required: true
        schema:
          type: string
      - name: Organization-ID
        in: header
        description: The Organization ID associated with the requestor.
        required: true
        schema:
          type: string
      - name: X-Request-ID
        in: header
        description: The ID associated with the request
        schema:
          type: string
      security:
      - SessionCookie: []
      responses:
        '200':
          description: case created successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Success'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /case/cache/purge:
    post:
      tags:
      - Case Manager Internal
      operationId: purgeCacheAPI
      summary: Purge case related cache in redis
      description: Use this endpoint to purge a particular or all case related cache stored in redis
      parameters:
      - name: User-ID
        in: header
        description: The User ID of the requestor.
        required: true
        schema:
          type: string
      - name: Organization-ID
        in: header
        description: The Organization ID associated with the requestor.
        required: true
        schema:
          type: string
      - name: X-Request-ID
        in: header
        description: The ID associated with the request
        schema:
          type: string
      - name: cache_prefix
        in: query
        required: true
        description: Prefix to the cache that has to be purged.
        schema:
          type: string
          default: false
      security:
      - SessionCookie: []
      responses:
        '200':
          description: cache purged successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Success'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /internal/investigation_credits/charge:
    post:
      tags:
      - Case Manager Internal
      operationId: chargeInvestigationCredits
      summary: Charge investigation credits for an alert investigation
      description: 'Service-to-service endpoint used by the agentic investigation service to

        spend credits for one investigation. The credit budget is charged

        atomically at the assigned tier; if the budget cannot afford it the tier

        is downgraded (ultimately to a free L1). Idempotent on idempotency_key so

        redelivered or retried requests never double-charge.'
      parameters:
      - $ref: '#/components/parameters/user-id'
      - $ref: '#/components/parameters/organization-id'
      - $ref: '#/components/parameters/x-request-id'
      security:
      - SessionCookie: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ChargeInvestigationCreditsRequest'
      responses:
        '200':
          description: Investigation credits charged successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ChargeInvestigationCreditsResponse'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /internal/investigation_credits/refund:
    post:
      tags:
      - Case Manager Internal
      operationId: refundInvestigationCredits
      summary: Refund a previously charged investigation
      description: 'Reverses a prior charge (e.g. when the investigation failed). Idempotent:

        refunding an unknown, free, or already-refunded charge is a no-op.'
      parameters:
      - $ref: '#/components/parameters/user-id'
      - $ref: '#/components/parameters/organization-id'
      - $ref: '#/components/parameters/x-request-id'
      security:
      - SessionCookie: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RefundInvestigationCreditsRequest'
      responses:
        '200':
          description: Refund processed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RefundInvestigationCreditsResponse'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /alerts/reindex:
    post:
      tags:
      - Case Manager Internal
      operationId: reindexAlertsAPI
      summary: Reindex Alerts into Opensearch
      description: Ollivander will be requested to reinsert every Alerts one by one via RabbitMQ queues
      parameters:
      - name: User-ID
        in: header
        description: The User ID of the requestor.
        required: true
        schema:
          type: string
      - name: Organization-ID
        in: header
        description: The Organization ID associated with the requestor.
        required: true
        schema:
          type: string
      - name: X-Request-ID
        in: header
        description: The ID associated with the request
        schema:
          type: string
      - name: Organization-Hosturl
        in: header
        description: The host url of the organization.
        schema:
          type: string
      - name: register
        in: query
        description: whether to register the entity again
        schema:
          type: boolean
          default: false
      - name: starting_time
        in: query
        description: Optional unix timestamp (seconds). If provided, only alerts created at or after this time will be reindexed.
        schema:
          type: integer
          format: int64
      - name: end_time
        in: query
        description: Optional unix timestamp (seconds). If provided, only alerts created at or before this time will be reindexed (inclusive).
        schema:
          type: integer
          format: int64
      security:
      - SessionCookie: []
      responses:
        '200':
          description: alerts reindexed successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Success'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /alerts/{alert_id}/mark_agent_investigated:
    patch:
      tags:
      - Case Manager Internal
      operationId: markAlertAgentInvestigatedAPI
      summary: Mark alert as investigated with agent
      description: Sets is_investigated_with_agent to true for the given alert. Internal endpoint for service-to-service use.
      parameters:
      - name: alert_id
        in: path
        required: true
        description: The ID of the alert to mark as investigated with agent.
        schema:
          type: string
      - $ref: '#/components/parameters/user-id'
      - $ref: '#/components/parameters/organization-id'
      - $ref: '#/components/parameters/x-request-id'
      security:
      - SessionCookie: []
      responses:
        '200':
          description: Alert marked as investigated with agent successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Success'
        '404':
          description: Alert not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /investigation_quota:
    get:
      tags:
      - Case Manager Internal
      operationId: getInvestigationQuotaAPI
      summary: Get investigation quota for an organization
      description: Returns the weekly investigation limit and current usage for an organization. Requires the caller to have access to the requested organization.
      parameters:
      - name: User-ID
        in: header
        description: The User ID of the requestor.
        required: true
        schema:
          type: string
      - name: Organization-ID
        in: header
        description: The Organization ID associated with the requestor.
        required: true
        schema:
          type: string
      - name: X-Request-ID
        in: header
        description: The ID associated with the request
        schema:
          type: string
      - name: organization_id
        in: query
        required: true
        description: The ID of the organization to fetch the investigation quota for.
        schema:
          type: string
      security:
      - SessionCookie: []
      responses:
        '200':
          description: Investigation quota fetched successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvestigationQuotaResponse'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /case/delete_organization/{organization_code}:
    delete:
      tags:
      - Case Manager Internal
      operationId: deleteOrganizationAPI
      summary: Delete Cases and Alerts for an organization
      description: Use this endpoint to delete all cases and alerts for an organization
      parameters:
      - name: User-ID
        in: header
        description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
        required: true
        schema:
          type: string
      - name: Organization-ID
        in: header
        description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
        required: true
        schema:
          type: string
      - name: X-Request-ID
        in: header
        description: The ID associated with the request
        schema:
          type: string
      - name: organization_code
        in: path
        description: The code of the organization to be deleted
        schema:
          type: string
      responses:
        '200':
          description: Organization deleted successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Success'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    RefundInvestigationCreditsRequest:
      type: object
      required:
      - idempotency_key
      properties:
        idempotency_key:
          type: string
    RefundInvestigationCreditsResponse:
      type: object
      required:
      - refunded
      properties:
        refunded:
          type: boolean
    InvestigationQuotaResponse:
      type: object
      required:
      - limit_set
      properties:
        limit_set:
          type: boolean
          description: Whether a weekly investigation limit is configured for this organization
        weekly_limit:
          type: integer
          description: The configured weekly investigation limit (only present when limit_set is true)
        investigations_used:
          type: integer
          description: Number of investigations consumed this week (only present when limit_set is true)
        investigations_remaining:
          type: integer
          description: Number of investigations remaining this week (only present when limit_set is true)
    ChargeInvestigationCreditsResponse:
      type: object
      required:
      - granted_tier
      - model
      - credits_charged
      - downgraded
      - floored
      - duplicate
      properties:
        granted_tier:
          type: string
          description: the tier the caller should actually run at
        model:
          type: string
        credits_charged:
          type: number
          format: double
        downgraded:
          type: boolean
          description: granted tier is cheaper than the requested/assigned tier
        floored:
          type: boolean
          description: budget could not afford even L1; granted a free L1
        duplicate:
          type: boolean
          description: idempotent replay of a prior charge
        balance_after:
          type: number
          format: double
    Error:
      type: object
      required:
      - message
      properties:
        message:
          type: string
          description: user friendly error message
    CaseReindexRequest:
      type: object
      required:
      - case_uuids
      properties:
        case_uuids:
          type: array
          items:
            type: string
          description: The list of case uuids to reindex. If this non empty list is provided, only the cases in this list will be reindexed else all cases will be reindexed.
    ChargeInvestigationCreditsRequest:
      type: object
      required:
      - organization_code
      - alert_id
      - alert_provider
      - alert_type
      - idempotency_key
      properties:
        organization_code:
          type: string
        alert_id:
          type: string
        alert_provider:
          type: string
        alert_type:
          type: string
        idempotency_key:
          type: string
          description: unique per investigation attempt; dedupes retries/redeliveries
    Success:
      type: object
      required:
      - message
      properties:
        message:
          type: string
          description: user friendly message
  parameters:
    x-request-id:
      name: X-Request-ID
      in: header
      description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
      schema:
        type: string
    user-id:
      name: User-ID
      in: header
      description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
      schema:
        type: string
    organization-id:
      name: Organization-ID
      in: header
      description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
      schema:
        type: string
  securitySchemes:
    SessionCookie:
      type: apiKey
      in: cookie
      name: Session
x-tagGroups:
- name: Included APIs
  tags:
  - Case Manager V2
  - Dashboard
  - Alerts
  - Webhooks
  - Query DSL