Demisto Indicator API

The Indicator API from Demisto — 3 operation(s) for indicator.

Operations 3

POST /indicator/create Create Indicator #
POST /indicator/edit Edit Indicator #
POST /indicator/whitelist Whitelists or deletes Indicator #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/demisto-indicator-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

demisto-indicator-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: This is the public REST API to integrate with the demisto server.
  title: Demisto Indicator API
  version: 2.0.0
servers:
- url: https://hostname:443
security:
- api_key: []
- csrf_token: []
- x-xdr-auth-id: []
tags:
- name: Indicator
paths:
  /indicator/create:
    post:
      description: 'Create an indicator entity

        To update indicator custom fields you should lowercase them and remove all spaces. For example: Scan IP -> scanip'
      summary: Create Indicator
      operationId: indicatorsCreate
      responses:
        '200':
          description: IocObject
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IocObject'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/indicatorContext'
          application/xml:
            schema:
              $ref: '#/components/schemas/indicatorContext'
      tags:
      - Indicator
  /indicator/edit:
    post:
      description: 'Edit an indicator entity

        To update indicator custom fields you should lowercase them and remove all spaces. For example: Scan IP -> scanip'
      summary: Edit Indicator
      operationId: indicatorsEdit
      responses:
        '200':
          description: IocObject
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IocObject'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/IocObject'
          application/xml:
            schema:
              $ref: '#/components/schemas/IocObject'
      tags:
      - Indicator
  /indicator/whitelist:
    post:
      description: 'Whitelists or deletes an indicator entity

        In order to delete an indicator and not whitelist, set doNotWhitelist boolean field to true'
      summary: Whitelists or deletes Indicator
      operationId: indicatorWhitelist
      responses:
        '200':
          description: UpdateResponse
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UpdateResponse'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/updateIndicatorReputationData'
          application/xml:
            schema:
              $ref: '#/components/schemas/updateIndicatorReputationData'
      tags:
      - Indicator
components:
  schemas:
    indicatorContext:
      type: object
      properties:
        entryId:
          type: string
          x-go-name: EntryID
        indicator:
          $ref: '#/components/schemas/IocObject'
        investigationId:
          type: string
          x-go-name: InvestigationID
        seenNow:
          type: boolean
          x-go-name: SeenNow
      x-go-package: github.com/demisto/server/web
    InsightCache:
      description: InsightCache - map insight name to all its metadata, name will be case insensitive
      type: object
      properties:
        id:
          type: string
          x-go-name: ID
        modified:
          type: string
          format: date-time
          x-go-name: Modified
        scores:
          type: object
          additionalProperties:
            $ref: '#/components/schemas/DBotScore'
          x-go-name: Scores
        sequenceNumber:
          type: integer
          format: int64
          x-go-name: SeqNum
        sortValues:
          type: array
          items:
            type: string
          x-go-name: SortValues
        version:
          type: integer
          format: int64
          x-go-name: Versn
      x-go-package: github.com/demisto/server/domain
    CustomFields:
      description: 'The keys should be the field''s display name all lower and without spaces. For example: Scan IP -> scanip

        To get the actual key name you can also go to Demisto CLI and run /incident_add and look for the key that you would like to update'
      type: object
      title: CustomFields ...
      additionalProperties:
        type: object
      x-go-package: github.com/demisto/server/domain
    UpdateResponse:
      type: object
      title: UpdateResponse ...
      properties:
        notUpdated:
          type: integer
          format: int64
          x-go-name: NotUpdated
        updatedIds:
          type: array
          items:
            type: string
          x-go-name: UpdatedIds
      x-go-package: github.com/demisto/server/repo/entities
    IocObject:
      description: IocObject - represents an Ioc (or simply an indicator) object
      type: object
      properties:
        CustomFields:
          $ref: '#/components/schemas/CustomFields'
        account:
          type: string
          x-go-name: Account
        calculatedTime:
          description: Do not set the fields bellow this line
          type: string
          format: date-time
          x-go-name: CalculatedTime
        comment:
          type: string
          x-go-name: Comment
        firstSeen:
          type: string
          format: date-time
          x-go-name: FirstSeen
        firstSeenEntryID:
          type: string
          x-go-name: FirstSeenEntryID
        id:
          type: string
          x-go-name: ID
        indicator_type:
          type: string
          x-go-name: IndicatorType
        insightCache:
          $ref: '#/components/schemas/InsightCache'
        investigationIDs:
          type: array
          items:
            type: string
          x-go-name: InvestigationIDs
        lastReputationRun:
          type: string
          format: date-time
          x-go-name: LastReputationRun
        lastSeen:
          type: string
          format: date-time
          x-go-name: LastSeen
        lastSeenEntryID:
          type: string
          x-go-name: LastSeenEntryID
        manualScore:
          type: boolean
          x-go-name: ManualScore
        manualSetTime:
          type: string
          format: date-time
          x-go-name: ManualSetTime
        manuallyEditedFields:
          type: array
          items:
            type: string
          x-go-name: ManuallyEditedFields
        modified:
          type: string
          format: date-time
          x-go-name: Modified
        score:
          type: integer
          format: int64
          x-go-name: Score
        setBy:
          type: string
          x-go-name: SetBy
        sortValues:
          type: array
          items:
            type: string
          x-go-name: SortValues
        source:
          type: string
          x-go-name: Source
        timestamp:
          type: string
          format: date-time
          x-go-name: TimeStamp
        value:
          type: string
          x-go-name: Value
        version:
          type: integer
          format: int64
          x-go-name: Versn
      x-go-package: github.com/demisto/server/domain
    DBotScore:
      description: DBotScore - Contain the score of a specific brand for a specific insight
      type: object
      properties:
        content:
          type: string
          x-go-name: Content
        contentFormat:
          type: string
          x-go-name: ContentFormat
        context:
          type: object
          additionalProperties:
            type: object
          x-go-name: Context
        isTypedIndicator:
          type: boolean
          x-go-name: IsTypedIndicator
        score:
          type: integer
          format: int64
          x-go-name: Score
        scoreChangeTimestamp:
          description: We need to track when the score changes to know if we need to re-calculate the overall score
          type: string
          format: date-time
          x-go-name: ScoreChangeTimeStamp
        timestamp:
          type: string
          format: date-time
          x-go-name: TimeStamp
        type:
          type: string
          x-go-name: Type
      x-go-package: github.com/demisto/server/domain
    updateIndicatorReputationData:
      type: object
      properties:
        InvestigationId:
          type: string
          x-go-name: InvID
        doNotWhitelist:
          type: boolean
          x-go-name: DoNotWhitelist
        entryId:
          type: string
          x-go-name: EntryID
        manualScore:
          type: boolean
          x-go-name: ManualScore
        reason:
          type: string
          x-go-name: Reason
        reputation:
          type: integer
          format: int64
          x-go-name: Reputation
        reputations:
          type: array
          items:
            type: string
          x-go-name: Reputations
        value:
          type: string
          x-go-name: Value
      x-go-package: github.com/demisto/server/web
  securitySchemes:
    api_key:
      type: apiKey
      name: Authorization
      in: header
    csrf_token:
      type: apiKey
      name: X-XSRF-TOKEN
      in: header
    x-xdr-auth-id:
      type: apiKey
      name: x-xdr-auth-id
      in: header