NetBird EDR SentinelOne Integrations API

Manage SentinelOne EDR integrations.

Operations 4

POST /api/integrations/edr/sentinelone Create EDR SentinelOne Integration #
GET /api/integrations/edr/sentinelone Get EDR SentinelOne Integration
PUT /api/integrations/edr/sentinelone Update EDR SentinelOne Integration #
DELETE /api/integrations/edr/sentinelone Delete EDR SentinelOne Integration

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/netbird-edr-sentinelone-integrations-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

netbird-edr-sentinelone-integrations-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: NetBird REST Accounts EDR SentinelOne Integrations API
  description: API to manipulate groups, rules, policies and retrieve information about peers and users
  version: 0.0.1
servers:
- url: https://api.netbird.io
  description: Default server
security:
- BearerAuth: []
- TokenAuth: []
tags:
- name: EDR SentinelOne Integrations
  description: Manage SentinelOne EDR integrations.
  x-cloud-only: true
paths:
  /api/integrations/edr/sentinelone:
    post:
      tags:
      - EDR SentinelOne Integrations
      summary: Create EDR SentinelOne Integration
      description: Creates a new EDR SentinelOne integration
      operationId: createSentinelOneEDRIntegration
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EDRSentinelOneRequest'
      responses:
        '200':
          description: Integration created successfully. Returns the created integration.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EDRSentinelOneResponse'
        '400':
          description: Bad Request (e.g., invalid JSON, missing required fields, validation error).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized (e.g., missing or invalid authentication token).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal Server Error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    get:
      tags:
      - EDR SentinelOne Integrations
      summary: Get EDR SentinelOne Integration
      description: Retrieves a specific EDR SentinelOne integration by its ID.
      responses:
        '200':
          description: Successfully retrieved the integration details.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EDRSentinelOneResponse'
        '400':
          description: Bad Request (e.g., invalid integration ID format).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Not Found (e.g., integration with the given ID does not exist).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal Server Error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    put:
      tags:
      - EDR SentinelOne Integrations
      summary: Update EDR SentinelOne Integration
      description: Updates an existing EDR SentinelOne Integration.
      operationId: updateSentinelOneEDRIntegration
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EDRSentinelOneRequest'
      responses:
        '200':
          description: Integration updated successfully. Returns the updated integration.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EDRSentinelOneResponse'
        '400':
          description: Bad Request (e.g., invalid JSON, validation error, invalid ID).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Not Found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal Server Error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    delete:
      tags:
      - EDR SentinelOne Integrations
      summary: Delete EDR SentinelOne Integration
      description: Deletes an EDR SentinelOne Integration by its ID.
      responses:
        '200':
          description: Integration deleted successfully. Returns an empty object.
          content:
            application/json:
              schema:
                type: object
                example: {}
        '400':
          description: Bad Request (e.g., invalid integration ID format).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Not Found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal Server Error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    Resource:
      type: object
      properties:
        id:
          description: ID of the resource
          type: string
          example: chacdk86lnnboviihd7g
        type:
          description: Type of the resource
          $ref: '#/components/schemas/ResourceType'
      required:
      - id
      - type
    PeerMinimum:
      type: object
      properties:
        id:
          description: Peer ID
          type: string
          example: chacbco6lnnbn6cg5s90
        name:
          description: Peer's hostname
          type: string
          example: stage-host-1
      required:
      - id
      - name
    Group:
      allOf:
      - $ref: '#/components/schemas/GroupMinimum'
      - type: object
        properties:
          peers:
            description: List of peers object
            type: array
            items:
              $ref: '#/components/schemas/PeerMinimum'
          resources:
            type: array
            items:
              $ref: '#/components/schemas/Resource'
        required:
        - peers
        - resources
    SentinelOneMatchAttributes:
      type: object
      description: Attribute conditions to match when approving agents
      additionalProperties: false
      properties:
        active_threats:
          description: The maximum allowed number of active threats on the agent
          type: integer
          example: 0
        encrypted_applications:
          description: Whether disk encryption is enabled on the agent
          type: boolean
        firewall_enabled:
          description: Whether the agent firewall is enabled
          type: boolean
        infected:
          description: Whether the agent is currently flagged as infected
          type: boolean
        is_active:
          description: Whether the agent has been recently active and reporting
          type: boolean
        is_up_to_date:
          description: Whether the agent is running the latest available version
          type: boolean
        network_status:
          description: The current network connectivity status of the device
          type: string
          enum:
          - connected
          - disconnected
          - quarantined
        operational_state:
          description: The current operational state of the agent
          type: string
    EDRSentinelOneRequest:
      type: object
      description: Request payload for creating or updating a EDR SentinelOne integration
      properties:
        api_token:
          type: string
          description: SentinelOne API token
        api_url:
          type: string
          description: The Base URL of SentinelOne API
        groups:
          type: array
          description: The Groups this integrations applies to
          items:
            type: string
        last_synced_interval:
          type: integer
          description: The devices last sync requirement interval in hours. Minimum value is 24 hours.
          minimum: 24
        enabled:
          type: boolean
          description: Indicates whether the integration is enabled
          default: true
        match_attributes:
          $ref: '#/components/schemas/SentinelOneMatchAttributes'
      required:
      - api_token
      - api_url
      - groups
      - last_synced_interval
      - match_attributes
    ErrorResponse:
      type: object
      description: 'Standard error response. Note: The exact structure of this error response is inferred from `util.WriteErrorResponse` and `util.WriteError` usage in the provided Go code, as a specific Go struct for errors was not provided.'
      properties:
        message:
          type: string
          description: A human-readable error message.
          example: couldn't parse JSON request
    ResourceType:
      allOf:
      - $ref: '#/components/schemas/NetworkResourceType'
      - type: string
        enum:
        - peer
        example: peer
    NetworkResourceType:
      description: Network resource type based of the address
      type: string
      enum:
      - host
      - subnet
      - domain
      example: host
    GroupMinimum:
      type: object
      properties:
        id:
          description: Group ID
          type: string
          example: ch8i4ug6lnn4g9hqv7m0
        name:
          description: Group Name identifier
          type: string
          example: devs
        peers_count:
          description: Count of peers associated to the group
          type: integer
          example: 2
        resources_count:
          description: Count of resources associated to the group
          type: integer
          example: 5
        issued:
          description: How the group was issued (api, integration, jwt)
          type: string
          enum:
          - api
          - integration
          - jwt
          example: api
      required:
      - id
      - name
      - peers_count
      - resources_count
    EDRSentinelOneResponse:
      type: object
      description: Represents a SentinelOne EDR integration configuration
      required:
      - id
      - account_id
      - created_by
      - last_synced_at
      - created_at
      - updated_at
      - api_url
      - groups
      - last_synced_interval
      - match_attributes
      - enabled
      properties:
        id:
          type: integer
          format: int64
          description: The unique numeric identifier for the integration.
          example: 123
        account_id:
          type: string
          description: The identifier of the account this integration belongs to.
          example: ch8i4ug6lnn4g9hqv7l0
        last_synced_at:
          type: string
          format: date-time
          description: Timestamp of when the integration was last synced.
          example: '2023-05-15T10:30:00Z'
        created_by:
          type: string
          description: The user id that created the integration
        created_at:
          type: string
          format: date-time
          description: Timestamp of when the integration was created.
          example: '2023-05-15T10:30:00Z'
        updated_at:
          type: string
          format: date-time
          description: Timestamp of when the integration was last updated.
          example: '2023-05-16T11:45:00Z'
        api_url:
          type: string
          description: The Base URL of SentinelOne API
        groups:
          type: array
          description: List of groups
          items:
            $ref: '#/components/schemas/Group'
        last_synced_interval:
          type: integer
          description: The devices last sync requirement interval in hours.
        match_attributes:
          $ref: '#/components/schemas/SentinelOneMatchAttributes'
        enabled:
          type: boolean
          description: Indicates whether the integration is enabled
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
    TokenAuth:
      type: apiKey
      in: header
      name: Authorization
      description: Enter the token with the `Token` prefix, e.g. "Token nbp_F3f0d.....".