ARMO Runtime API

Runtime incidents (CADR), network and runtime policies.

Business capability
Threat Detection & Response Management BC-620.30

Operations 12

GET /runtime/incidents List runtime incidents #
GET /runtime/incidents/severity Get runtime incidents grouped by severity #
GET /runtime/incidents/{incidentGUID}/alerts Get alerts for an incident #
POST /runtime/incidents/{incidentGUID}/explain Explain a runtime incident #
POST /runtime/incidents/{incidentGUID}/resolve Resolve a runtime incident #
POST /runtime/incidents/{incidentGUID}/unresolve Unresolve a runtime incident #
GET /network/policies List network policies #
POST /network/policies/generate Generate network policies #
GET /runtime/seccomp/list List seccomp resources #
POST /runtime/seccomp/generate Generate seccomp profiles #
POST /runtime/policy/create Create a runtime policy #
POST /runtime/policy/exception/create Create a runtime policy exception #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/armosec-runtime-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

armosec-runtime-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: ARMO Platform Runtime API
  description: The ARMO Platform API exposes ARMO's cloud-native and Kubernetes security data over REST.
  version: '1.0'
  contact:
    name: ARMO
    url: https://www.armosec.io
  license:
    name: ARMO Platform Terms
    url: https://www.armosec.io/terms-of-service/
servers:
- url: https://api.armosec.io/api/v1
  description: EU region
- url: https://api.us.armosec.io/api/v1
  description: US region
security:
- apiKeyAuth: []
tags:
- name: Runtime
  description: Runtime incidents (CADR), network and runtime policies.
paths:
  /runtime/incidents:
    get:
      operationId: listRuntimeIncidents
      tags:
      - Runtime
      summary: List runtime incidents
      description: Retrieves all runtime incidents detected by ARMO's runtime sensor.
      responses:
        '200':
          description: A list of runtime incidents.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /runtime/incidents/severity:
    get:
      operationId: getRuntimeIncidentsSeverity
      tags:
      - Runtime
      summary: Get runtime incidents grouped by severity
      responses:
        '200':
          description: Incidents grouped by severity.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /runtime/incidents/{incidentGUID}/alerts:
    parameters:
    - $ref: '#/components/parameters/IncidentGUID'
    get:
      operationId: getRuntimeIncidentAlerts
      tags:
      - Runtime
      summary: Get alerts for an incident
      responses:
        '200':
          description: Incident alerts.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
  /runtime/incidents/{incidentGUID}/explain:
    parameters:
    - $ref: '#/components/parameters/IncidentGUID'
    post:
      operationId: explainRuntimeIncident
      tags:
      - Runtime
      summary: Explain a runtime incident
      description: Returns a detailed explanation for the specified incident.
      responses:
        '200':
          description: Incident explanation.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
  /runtime/incidents/{incidentGUID}/resolve:
    parameters:
    - $ref: '#/components/parameters/IncidentGUID'
    post:
      operationId: resolveRuntimeIncident
      tags:
      - Runtime
      summary: Resolve a runtime incident
      responses:
        '200':
          description: Resolved.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
  /runtime/incidents/{incidentGUID}/unresolve:
    parameters:
    - $ref: '#/components/parameters/IncidentGUID'
    post:
      operationId: unresolveRuntimeIncident
      tags:
      - Runtime
      summary: Unresolve a runtime incident
      responses:
        '200':
          description: Unresolved.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
  /network/policies:
    get:
      operationId: listNetworkPolicies
      tags:
      - Runtime
      summary: List network policies
      description: Retrieves generated Kubernetes network policies.
      responses:
        '200':
          description: Network policies.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /network/policies/generate:
    post:
      operationId: generateNetworkPolicies
      tags:
      - Runtime
      summary: Generate network policies
      description: Generates Kubernetes network policies for the specified workloads from observed traffic.
      requestBody:
        $ref: '#/components/requestBodies/GenericBody'
      responses:
        '200':
          description: Generated network policies.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /runtime/seccomp/list:
    get:
      operationId: listSeccompProfiles
      tags:
      - Runtime
      summary: List seccomp resources
      responses:
        '200':
          description: Seccomp resources.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /runtime/seccomp/generate:
    post:
      operationId: generateSeccompProfiles
      tags:
      - Runtime
      summary: Generate seccomp profiles
      requestBody:
        $ref: '#/components/requestBodies/GenericBody'
      responses:
        '200':
          description: Generated seccomp profiles.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /runtime/policy/create:
    post:
      operationId: createRuntimePolicy
      tags:
      - Runtime
      summary: Create a runtime policy
      requestBody:
        $ref: '#/components/requestBodies/GenericBody'
      responses:
        '200':
          description: Created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /runtime/policy/exception/create:
    post:
      operationId: createRuntimePolicyException
      tags:
      - Runtime
      summary: Create a runtime policy exception
      requestBody:
        $ref: '#/components/requestBodies/GenericBody'
      responses:
        '200':
          description: Created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  responses:
    NotFound:
      description: The requested resource was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Missing or invalid X-API-KEY.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  requestBodies:
    GenericBody:
      required: true
      content:
        application/json:
          schema:
            type: object
            additionalProperties: true
  parameters:
    IncidentGUID:
      name: incidentGUID
      in: path
      required: true
      description: The GUID of the runtime incident.
      schema:
        type: string
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
    ListResponse:
      type: object
      properties:
        total:
          type: object
          properties:
            value:
              type: integer
        response:
          type: array
          items:
            type: object
            additionalProperties: true
      additionalProperties: true
    GenericResponse:
      type: object
      additionalProperties: true
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: Account access key (Agent Access Key) generated in ARMO Platform under Settings, sent in the X-API-KEY header.