AirMDR Case Manager V2 API

The Case Manager V2 API from AirMDR — 43 operation(s) for case manager v2.

Business capability
Threat Detection & Response Management BC-620.30

Operations 59

POST /v2/case create a new v2 case #
GET /v2/case/{case_uuid} get details of a v2 case #
PATCH /v2/case/{case_uuid} update details of a v2 case #
DELETE /v2/case/{case_uuid} archive a case #
DELETE /v2/case/{case_uuid}/hard_delete delete a case #
PATCH /v2/case/{case_uuid}/ignore_case_metric ignore/unignore the case from metrics #
POST /v2/case/{case_uuid}/finding add a new finding in case #
PATCH /v2/case/{case_uuid}/finding/{finding_uuid} update a finding in the case #
DELETE /v2/case/{case_uuid}/finding/{finding_uuid} delete a finding in a case #
POST /v2/case/{case_uuid}/finding/{finding_uuid}/email email details of a v2 case finding #
GET /v2/case/{case_uuid}/finding/{finding_uuid}/evidence/{evidence_uuid} get evidence data for a finding based on uuid #
POST /v2/case/{case_uuid}/attachment upload an image attachment for a case #
GET /v2/case/{case_uuid}/attachments list the image attachments for a case #
DELETE /v2/case/{case_uuid}/attachment/{attachment_uuid} delete a case image attachment #
GET /v2/case/{case_uuid}/attachment/{attachment_uuid}/content stream the bytes of a case image attachment #
POST /v2/case/{case_uuid}/email email details of a v2 case #
POST /v2/case/list get case list for an organization based on filter and sort #
POST /v2/case/{case_identifier}/chat_session/{chat_session_id}/link Link given chat session to case #
POST /v2/case/{case_identifier}/chat_session/{chat_session_id}/unlink Unlink given session from case #
GET /v2/case/chat_session/{chat_session_id} Get linked cases for given session uuid #
POST /v2/case/{case_identifier}/cases/link Link given cases in request to the case #
POST /v2/case/{primary_case_identifier}/secondary/case/{secondary_case_identifier}/unlink Unlink cases from one another #
POST /v2/case/{case_identifier}/alert/{alert_uuid}/unlink Unlink given alert from case #
POST /v2/case/{case_uuid}/comment add a new comment to the case #
PATCH /v2/case/{case_uuid}/comment/{comment_id} update a comment in the case #
DELETE /v2/case/{case_uuid}/comment/{comment_id} delete a comment in the case #
GET /v2/case/{case_uuid}/comments get paginated list of case comments #
GET /v2/case/{case_uuid}/history get paginated list of case history #
GET /v2/case/{case_uuid}/history/{change_log_id}/case get the case reconstructed as it was at a specific history entry, read-only #
GET /v2/case/{case_uuid}/versions list named versions for a case #
POST /v2/case/{case_uuid}/history/{change_log_id}/version name this history entry as a version #
PATCH /v2/case/{case_uuid}/history/{change_log_id}/version rename the named version pinned to this history entry #
DELETE /v2/case/{case_uuid}/history/{change_log_id}/version delete the named version pinned to this history entry #
GET /v2/case/{case_uuid}/watchers get list of case watchers #
POST /v2/case/{case_uuid}/watchers add list of users to case watchers #
DELETE /v2/case/{case_uuid}/watchers remove list of user from case watchers #
POST /v2/case/clone Clone a case #
POST /v2/case/{case_uuid}/reinvestigate Reinvestigate a case #
POST /v2/case/comments/list List case comments #
POST /v2/case/views Create a new saved view for case filters #
GET /v2/case/views Get list of saved views for the organization #
PATCH /v2/case/views/{view_id} Update an existing saved view #
DELETE /v2/case/views/{view_id} Delete a saved view #
GET /v2/case/views/preference Get user's current view preference and temporary filters #
PUT /v2/case/views/preference Update user's selected view preference #
PATCH /v2/case/views/preference/temp-filter Update user's temporary filters for current session #
DELETE /v2/case/views/preference/temp-filter Delete user's temporary filters for current session #
DELETE /v2/case/views/preference/selected-view Clear user's selected view preference #
POST /v2/case/custom/fields create a new custom field that can be used in cases #
POST /v2/case/custom/fields/list get custom case fields that the organization has access to #
DELETE /v2/case/custom/fields/{field_id} delete a custom field if its not used in any case #
PATCH /v2/case/custom/fields/{field_id} update a case custom field (title) #
GET /v2/case/custom/fields/values get custom case field values that are present in the cases available to the… #
GET /v2/case/configuration get case configuration for the organizations #
PATCH /v2/case/configuration Update case configuration fields (hidden_dashboard_widgets only) #
POST /v2/case/configuration create a new case configuration for the organization #
POST /v2/case/configuration/copy copy case configuration for the organizations #
GET /v2/case/dashboard/chart-config Get saved chart config (widget_id -> chart_type) for an OOB dashboard #
PATCH /v2/case/dashboard/chart-config Add or update chart types for widgets on an OOB dashboard #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/airmdr:airmdr-case-manager-v2-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

airmdr-case-manager-v2-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Case Manager V2 API
  version: 1.0.0
servers:
- url: /airmdrapi
tags:


# --- truncated at 32 KB (211 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/airmdr/refs/heads/main/openapi/airmdr-case-manager-v2-api-openapi.yml