# Rapid7 Engines API

**Canonical:** https://apis.io/apis/rapid7/rapid7-engines-api/  
**Provider:** Rapid7 — https://apis.io/providers/rapid7/  
**Base URL:** https://us.api.insight.rapid7.com/vm/v4  
**Documentation:** https://help.rapid7.com/insightvm/en-us/api/api.html

Rapid7 Engines API is one of 50 APIs that [Rapid7](https://apis.io/providers/rapid7/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. Tagged areas include Engines. The published artifact set on APIs.io includes an OpenAPI specification.

An Engine encapsulates the state and high-level attributes of the components which may be installed and running on a specific On-Premise host. The status of an Engine is not mutable via the API; it reflects the platform state of the components installed on the host, and can change at any given time. These states are: <ul><li>INITIALIZING : Engine is starting </li> <li>IDLE : Engine is waiting for scans</li> <li>LICENSING : Engine is checking a License has been assigned</li> <li>SCANNING : Engine is currently scanning</li> <li>UPGRADING : Engine is in the process of upgrading </li> <li>FAILED : Engine has failed in a process, with the reason shown in failure reason</li> <li>OFFLINE : Engine is not available</li> <li>TERMINATING : Engine is in the process of being deleted</li> </ul> It should be noted that deleting an Engine resource is an asynchronous process, and actioning the request to delete the Engine occurs at the earliest convenience and is state-dependant. Creating a new Engine resource implicitly creates a Credential sub-resource, which is an alpha-numeric API key required for the successful installation and operation of an Engine in an On-Premise environment. An Engine API key can be retrieved by executing a <code>get-engine-credential</code> request, as documented below.<p> <strong> CAUTION: regenerating an API key should only be performed when there is suspicion that the security of the API key has been compromised; regenerating will prevent any communication between any client using the revoked API key and the InsightAppSec Platform. Any manual Engine maintenance exercise which involves running the InsightAppSec Engine installer, should result in the creation of a NEW Engine; an API key should never be used across installations to prevent data loss/pollution and runtime issues. </strong> </p> Please refer to <TODO insert link here> help documentation which describes the process required to update the API for an existing installation.

## Machine-readable artifacts (1)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/rapid7/refs/heads/main/openapi/rapid7-engines-api-openapi.yml

## Other Rapid7 APIs (12)

- [Rapid7 InsightVM Cloud API](https://apis.io/apis/rapid7/insightvm-api/)
- [Rapid7 Insight Platform API](https://apis.io/apis/rapid7/insight-platform-api/)
- [Rapid7 InsightIDR API](https://apis.io/apis/rapid7/insightidr-api/)
- [Rapid7 Accounts API](https://apis.io/apis/rapid7/rapid7-accounts-api/)
- [Rapid7 Administration API](https://apis.io/apis/rapid7/rapid7-administration-api/)
- [Rapid7 Apps API](https://apis.io/apis/rapid7/rapid7-apps-api/)
- [Rapid7 Asset API](https://apis.io/apis/rapid7/rapid7-asset-api/)
- [Rapid7 Asset Discovery API](https://apis.io/apis/rapid7/rapid7-asset-discovery-api/)
- [Rapid7 Asset Group API](https://apis.io/apis/rapid7/rapid7-asset-group-api/)
- [Rapid7 Assets API](https://apis.io/apis/rapid7/rapid7-assets-api/)
- [Rapid7 Attachments API](https://apis.io/apis/rapid7/rapid7-attachments-api/)
- [Rapid7 Attack Templates API](https://apis.io/apis/rapid7/rapid7-attack-templates-api/)

## Tags

Engines

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/rapid7/rapid7-engines-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/rapid7/.
