Cisco XDR Workflows API

The Workflows API from Cisco XDR — 20 operation(s) for workflows.

Operations 26

POST /v1.1/workflows Handler to get all workflows #
POST /v1.1/workflows/start Handler to start workflow execution #
POST /v1.2/workflows Handler to get all workflows #
GET /v1/workflows Handler to get all workflows #
POST /v1/workflows Handler to create a workflow definition #
POST /v1/workflows/batch_get # Handler to retrieve a list of workflows #
POST /v1/workflows/start Handler to start workflow execution #
GET /v1/workflows/start_config Handler to return required input parameters for the workflow #
GET /v1/workflows/summary Handler to get a summary of workflows #
GET /v1/workflows/{workflow_id} Handler to return workflow information using workflow ID #
PUT /v1/workflows/{workflow_id} Handler to update the workflow #
DELETE /v1/workflows/{workflow_id} Handler to delete workflow using ID #
POST /v1/workflows/{workflow_id}/actions Handler to add new action to workflow #
GET /v1/workflows/{workflow_id}/actions/{action_id} Handler to return Workflow's action information using action ID #
PUT /v1/workflows/{workflow_id}/actions/{action_id} Handler to update an Action #
DELETE /v1/workflows/{workflow_id}/actions/{action_id} Handler to delete an action from workflow byId #
PATCH /v1/workflows/{workflow_id}/actions/{action_id} Handler to move actions in workflow #
POST /v1/workflows/{workflow_id}/actions/{action_id}/duplicate Handler to duplicate action #
PUT /v1/workflows/{workflow_id}/lock Handler to Lock the workflow #
GET /v1/workflows/{workflow_id}/references Handler to return references for the workflow #
GET /v1/workflows/{workflow_id}/rules Handler to return rules for the workflow #
PUT /v1/workflows/{workflow_id}/unlock Handler to unlock a locked workflow. #
POST /v1/workflows/{workflow_id}/validate Handler to validate workflow #
DELETE /v1/{workflow_id}/uninstall Handler to unintsall a workflow installed through exchange #
POST /v2/workflows Handler to create a workflow definition from a given template #
PUT /v2/workflows/{workflow_id} Handler to update the workflow #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cisco-xdr-workflows-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cisco-xdr-workflows-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: REST API. Workflows API
  version: 1.0.0
  x-provenance:
    method: harvested
    authored_by: Cisco XDR
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: visibility.amp.cisco.com
    note: Anonymously fetchable Swagger 2.0 for nine IROH services plus the CTIA threat-intelligence API. The host returns real 404s on invented paths, so the 200s are genuine.
  x-evidence:
  - type: source
    url: https://visibility.amp.cisco.com/iroh/iroh-int/swagger.json
  - type: source
    url: https://private.intel.amp.cisco.com/swagger.json
servers:
- url: https://automate.us.security.cisco.com/{basePath}
  variables:
    basePath:
      default: api
security:
- oAuth2:
  - integration:read
  - private-intel:read
  - profile:read
  - inspect:read
  - users:read
  - invite:read
  - enrich:read
  - oauth:read
  - response:read
  - global-intel:read
  - ao:read
  - playbook:read
tags:


# --- truncated at 32 KB (121 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-xdr/refs/heads/main/openapi/cisco-xdr-workflows-api-openapi.yml