Malwarebytes Account API

The Account API from Malwarebytes — 2 operation(s) for account.

Operations 2

GET /nebula/v1/account/ad/structure Get account AD structure #
GET /nebula/v1/account Get account details #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/malwarebytes-account-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

malwarebytes-account-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: ThreatDown Account API
  description: '# Introduction

    ThreatDown Nebula API lets you remotely manage the security of your `Endpoints`, analyze their `assets`, perform advanced analysis on `Detections` of `Malware`, `Ransomware`, `Exploits` and other threats found by the `ThreatDown Endpoint Agent`, and issue jobs like `Scan`, `Isolate`, `Remediate` or `Reboot`.'
  version: 1.0.0
  x-logo:
    altText: ThreatDown logo
    url: https://assets.threatdown.com/hermes/ThreatDown_Horizontal_Navy.png
    backgroundColor: '#FFFFFF'
servers:
- url: https://api.threatdown.com
tags:
- name: Account
paths:
  /nebula/v1/account/ad/structure:
    get:
      description: Get the Active Directory structure of an account
      summary: Get account AD structure
      security:
      - client_credentials:
        - read
      - user_permissions:
        - account.view
      status:
        outage:
        - auth
      parameters:
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      responses:
        '200':
          description: response schema
          content:
            application/json:
              schema:
                type: object
                additionalProperties:
                  type: object
                  properties:
                    filter:
                      type: string
                      description: Filter string
                    nodes:
                      type: object
                      additionalProperties: true
      tags:
      - Account
      operationId: api.nebula.get.account.ad.structure
  /nebula/v1/account:
    get:
      description: Get details of the current account
      summary: Get account details
      security:
      - client_credentials:
        - read
      - user_permissions:
        - account.view
      status:
        outage:
        - auth
      parameters:
      - name: authorization
        required: true
        in: header
        description: Authorization token
        schema:
          type: string
      - name: accountid
        required: true
        in: header
        description: Your Nebula account id (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
        schema:
          type: string
          pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
      responses:
        '200':
          description: response schema
          content:
            application/json:
              schema:
                type: object
                title: Your license key
                properties:
                  license_key:
                    type: string
                    title: The license key associated with the account
                  id:
                    type: string
                    title: The id of the account (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
                    pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
                    examples:
                    - 9256034b-7967-4253-a5d9-260663e4fa4f
                  name:
                    type: string
                    title: The Name of the account
                  options:
                    type: object
                    title: Optional field options. Information for MSP.
                    properties:
                      msp:
                        type: object
                        title: MSP
                        properties:
                          name:
                            type: string
                            title: Name
                          redirect_url:
                            type: string
                            title: Redirect URL
                  account_token:
                    type: string
                    title: the account token of this account for registering endpoints
                  client_id:
                    type: string
                    title: The default client_id for this account, if any
                  default_policy_id:
                    type: string
                    title: The policy ID associated with this account (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
                    pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
                    examples:
                    - 9256034b-7967-4253-a5d9-260663e4fa4f
                  default_group_id:
                    type: string
                    title: The group ID associated with this account (Ex. "9256034b-7967-4253-a5d9-260663e4fa4f")
                    pattern: '[\da-fA-F]{8}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{4}-?[\da-fA-F]{12}$'
                    examples:
                    - 9256034b-7967-4253-a5d9-260663e4fa4f
                  owner_id:
                    type: string
                    format: uuid
                    title: The nebula account owner user ID
                  created_at:
                    type: string
                    title: When this account has been created (Ex. "2020-03-23T17:23:17.860482Z")
                    pattern: ^\d{4}-[0-1]\d-[0-3]\d[(t|T)\s](?:[0-2]\d:[0-5]\d:[0-5]\d|23:59:60)(?:\.\d+)?(?:(z|Z)|[+-]\d{2}:\d{2})$
                    examples:
                    - '2020-03-23T17:23:17.860482Z'
                  updated_at:
                    type: string
                    title: When the account has been updated the last time (Ex. "2020-03-23T17:23:17.860482Z")
                    pattern: ^\d{4}-[0-1]\d-[0-3]\d[(t|T)\s](?:[0-2]\d:[0-5]\d:[0-5]\d|23:59:60)(?:\.\d+)?(?:(z|Z)|[+-]\d{2}:\d{2})$
                    examples:
                    - '2020-03-23T17:23:17.860482Z'
                  product_license_info:
                    type: array
                    title: Product license information
                    items:
                      type: object
                      properties:
                        licensed_product:
                          type: string
                          title: Licensed product
                          description: The licensed products
                          default: ''
                          examples:
                          - MBAE-B,MBAM-B,MBBR-B,MBFT-B,MBRX-B,NCCA-B,NCEP-B,NCRM-B
                        combo_code:
                          type: string
                          title: Combo code
                          examples:
                          - NEBULA-EP-COMBO
                        catalog_code:
                          type: string
                          title: Catalog code
                          default: ''
                          examples:
                          - BUS-CLOUD-EPP-01
                        licensed_seats:
                          type: integer
                          title: The number of seats licensed
                          default: 0
                          examples:
                          - 5
                        license_expires_at:
                          type: string
                          title: When the license expires
                          default: ''
                          examples:
                          - '2021-03-18T00:00:00Z'
                        license_term_type:
                          type: string
                          title: The License_term_type Schema
                          default: ''
                          examples:
                          - utility
                        licensed_ir_remediations:
                          type: integer
                          title: Licensed ir remediations
                          default: 0
                          examples:
                          - 0
                        license_status:
                          type: string
                          title: License status
                          default: ''
                          examples:
                          - active
                        ir_remediations_count:
                          type: integer
                          title: Ir remediations count
                          default: 0
                          examples:
                          - 0
                        machine_counts:
                          type: array
                          title: Endpoints linked to products
                          items:
                            type: object
                            title: Items
                            properties:
                              product_type:
                                type: string
                                title: Product type
                                examples:
                                - EDR
                                - EPP
                                - IR
                              os_type:
                                type: string
                                title: OS type
                                examples:
                                - WORKSTATION
                                - SERVER
                              os_platform:
                                type: string
                                title: Operation system platform
                                examples:
                                - Windows
                              machine_count:
                                type: integer
                                title: Count of machines having this product
      tags:
      - Account
      operationId: api.nebula.get.account
components:
  securitySchemes:
    client_credentials:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: /token
          scopes:
            read: Read data of your Nebula account
            write: Write data, such as groups, policies, exclusions. Create Webhook subscriptions
            execute: Issue jobs on your endpoints, like Scan, Reboot or Isolate.
    user_permissions:
      type: http
      scheme: bearer