AppOmni Marlin AI API

Marlin AI is an autonomous SaaS security AI that runs platform-wide deep analyses and correlations automatically across security observations in the AppOmni platform

Operations 1

GET /api/v1/ai/marlin/plans/analysis/latest/ Marlin AI results #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/appomni-marlin-ai-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

appomni-marlin-ai-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: AppOmni AI Marlin AI API
  description: 'Marlin AI autonomous analysis plans and the AgentGuard prompt classification endpoint.


    Derived faithfully from the AppOmni public Postman collection published by AppOmni at https://api.appomni.com/ — every path, method, parameter, request body and example response below is taken verbatim from that collection. No operation was invented.'
  version: 1.0.0
  contact:
    name: AppOmni
    url: https://appomni.com/support/
  license:
    name: Proprietary
    url: https://appomni.com/terms-of-service/
  x-generated-from: AppOmni public Postman collection (publishedId 2sBXc7Mjib) + AppOmni's published @appomni/n8n-nodes-agentguard source
  x-generated-source: https://api.appomni.com/api/collections/45135595/2sBXc7Mjib?segregateAuth=true&versionTag=latest
  x-generated-method: derived
  x-generated-date: '2026-09-04'
servers:
- url: https://{instance}.appomni.com
  description: AppOmni tenant. Replace {instance} with your AppOmni subdomain — e.g. `acme` if you log in at acme.appomni.com.
  variables:
    instance:
      default: example
      description: Your AppOmni tenant subdomain
security:
- bearerAuth: []
tags:
- name: Marlin AI
  description: Marlin AI is an autonomous SaaS security AI that runs platform-wide deep analyses and correlations automatically across security observations in the AppOmni platform
paths:
  /api/v1/ai/marlin/plans/analysis/latest/:
    get:
      operationId: marlinAIResults
      summary: Marlin AI results
      tags:
      - Marlin AI
      description: 'Returns a paginated list of the latest Marlin AI results in your environment.


        Each entry includes metadata such as playbook_id, playbook_name, playbook_description, created_at, risk_classification, ms_types, final_analysis, remediation_suggestions, summary


        Response Fields


        Field

        Data Type

        Description

        Example


        playbook_id

        String

        Unique identifier for the playbook. This is an AppOmni internal ID

        ms_errors


        playbook_name

        String

        Name of the playbook as seen in the UI

        Summary on monitored services disconnection issues


        playbook_description

        String

        Short description about what the playbook does

        This playbook runs once per day and summarizes connection issues found on up to 20 monitored services. The monitored services are chosen based on the largest posture coverage.


        created_at

        String (ISO datetime)

        Timestamp when the playbook run was created

        2022-11-29T05:56:26.372253Z


        ms_types

        Array [String]

        List with type of service analyzed (e.g., box, github)

        [''smartsheet'',

        ''github'',

        ''asana'',

        ''sfdc'',

        ''confluence'',

        ''zendesk'']


        final_analysis

        String

        Text output of Marlin AI analysis

        These services have lost their connection to AppOmni, preventing continuous monitoring


        remediation_suggestions

        String

        Text output with remediation suggestions based on the data analyzed

        This suggests a missing permission set required for the Salesforce integration. Contact user@appomni.com to re-establish the connection


        summary

        String

        Text summary that shows on Marlin AI cards

        SaaS Monitoring Connection Issues.14 monitored services were analyzed, with 10 disconnected and 3 degraded


        risk_classification

        String

        risk set by Marlin AI based on what was found on its investigation

        high'
      responses:
        '200':
          description: Get Marlin AI results
          content:
            text/plain:
              schema:
                type: string
              example: "{\n    \"results\": [\n        {\n            \"analysis_output\": {\n                \"plan_id\": \"e73fe289-a451-44de-8e26-d7658b96fdf5\",\n                \"final_analysis\": \"**Data analyzed:** 2651 occurrences and 20 findings related to inactive users were analyzed across your AppOmni environment. No specific links to the analyzed data are available in this output.\\n\\nThis analysis focused on identifying and reducing noise from overlapping insights related to inactive users within your production environment. The goal was to streamline your security posture by pinpointing redundant findings that can be safely closed, thereby improving operational efficiency for your SOC team. This process does not identify new cybersecurity threats but rather optimizes the management of existing observations.\\n\\n**Key findings:**\\n*   **1311 occurrences** can be closed due to coverage overlap.\\n*   **12 findings** can be closed due to coverage overlap.\\n\\nThis optimization applies to insights found across the following monitored services: **GSuite, iManage, O365, Okta, and SFMC**.\",\n                \"remediation_suggestions\": \"To enhance your team's focus and reduce alert fatigue, prioritize the following actions:\\n\\n*   **Review and Close Findings:** Access the Posture Findings interface in AppOmni and review the 12 identified findings and 1311 occurrences related to inactive users that have been marked for closure due to coverage overlap. Confirm their redundancy and proceed with dismissing or closing"
        '401':
          description: Unauthorized — missing or invalid AppOmni API token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden — the token lacks permission for this resource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      title: Error
      description: Standard Django REST Framework error envelope returned by the AppOmni API.
      properties:
        detail:
          type: string
          description: Human readable error message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'AppOmni API access token, created and managed in the AppOmni platform under Settings > API Settings. Sent as `Authorization: Bearer <token>`.'
    ingestToken:
      type: apiKey
      in: header
      name: X-AppOmni-Ingest-Token
      description: AppOmni-issued ingest token used by AgentGuard and the AODP ingest endpoint. Sent as the `X-AppOmni-Ingest-Token` request header.