Cisco XDR Workflow Instances API

The Workflow Instances API from Cisco XDR — 7 operation(s) for workflow instances.

Operations 9

POST /v1.1/instances Handler to get all Workflow Instances #
GET /v1/instances Handler to get all Workflow Instances #
POST /v1/instances/remove Handler to delete workflow instances in a batch #
GET /v1/instances/summary Handler to get a summary of workflows instances #
GET /v1/instances/{wf_instance_id} Handler returning workflow instance information #
POST /v1/instances/{wf_instance_id} Handler to manage(cancel/pause/resume) a specific workflow instance #
DELETE /v1/instances/{wf_instance_id} Handler for delete workflow instance #
GET /v1/instances/{wf_instance_id}/actions/{action_instance_id} Handler returning information about action's instance #
POST /v1/instances/{wf_instance_id}/cancel # Handler to cancel a specific workflow instance #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cisco-xdr-workflow-instances-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cisco-xdr-workflow-instances-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: REST API. Workflow Instances API
  version: 1.0.0
  x-provenance:
    method: harvested
    authored_by: Cisco XDR
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: visibility.amp.cisco.com
    note: Anonymously fetchable Swagger 2.0 for nine IROH services plus the CTIA threat-intelligence API. The host returns real 404s on invented paths, so the 200s are genuine.
  x-evidence:
  - type: source
    url: https://visibility.amp.cisco.com/iroh/iroh-int/swagger.json
  - type: source
    url: https://private.intel.amp.cisco.com/swagger.json
servers:
- url: https://automate.us.security.cisco.com/{basePath}
  variables:
    basePath:
      default: api
security:
- oAuth2:
  - integration:read
  - private-intel:read
  - profile:read
  - inspect:read
  - users:read
  - invite:read
  - enrich:read
  - oauth:read
  - response:read
  - global-intel:read
  - ao:read
  - playbook:read
tags:


# --- truncated at 32 KB (48 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-xdr/refs/heads/main/openapi/cisco-xdr-workflow-instances-api-openapi.yml