# OpenCTI GraphQL API

**Canonical:** https://apis.io/apis/filigran/opencti-graphql-api/  
**Provider:** Filigran — https://apis.io/providers/filigran/  
**Base URL:** https://demo.opencti.io/graphql  
**Documentation:** https://docs.opencti.io/latest/reference/api/

OpenCTI GraphQL API is one of 2 APIs that [Filigran](https://apis.io/providers/filigran/) publishes on the [APIs.io](https://apis.io/) network. Tagged areas include Threat Intelligence, GraphQL, STIX, and OpenCTI. The published artifact set on APIs.io includes API documentation, an API reference, and a getting-started guide.

The OpenCTI platform exposes a full GraphQL API on the /graphql endpoint for programmatic access to cyber threat intelligence knowledge modeled on STIX 2.1. Authentication uses a per-user bearer API token. A GraphiQL-based playground is available on /public/graphql, and a native embedded MCP server is exposed for AI agents.

## Machine-readable artifacts (5)

- **Documentation** — https://docs.opencti.io/latest/
- **APIReference** — https://docs.opencti.io/latest/reference/api/
- **GettingStarted** — https://docs.opencti.io/latest/usage/getting-started/
- **Webhooks** — https://docs.opencti.io/latest/administration/notifiers/
- **APIsJSON** — https://raw.githubusercontent.com/api-evangelist/filigran/refs/heads/main/apis.yml

## Other Filigran APIs (1)

- [OpenAEV REST API](https://apis.io/apis/filigran/openaev-rest-api/)

## Tags

Threat Intelligence, GraphQL, STIX, OpenCTI

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/filigran/opencti-graphql-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/filigran/.
