Secureworks GraphQL API

The GraphQL API from Secureworks — 1 operation(s) for graphql.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/secureworks-graphql-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

secureworks-graphql-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Secureworks Taegis XDR Authentication GraphQL API
  description: The Secureworks Taegis XDR API provides programmatic access to the Taegis extended detection and response platform via GraphQL. This OpenAPI document describes the REST authentication endpoints and the primary GraphQL endpoint used to access alerts, investigations, endpoint assets, identities, threat intelligence, collectors, connectors, playbooks, audits, and users. Authentication uses OAuth2 client credentials flow with bearer token authorization across multiple regions.
  version: 1.0.0
  contact:
    url: https://docs.taegis.secureworks.com/apis/using_xdr_apis/
servers:
- url: https://api.ctpx.secureworks.com
  description: Taegis XDR API - US1 (Primary)
- url: https://api.delta.taegis.secureworks.com
  description: Taegis XDR API - US2
- url: https://api.foxtrot.taegis.secureworks.com
  description: Taegis XDR API - US3
- url: https://api.echo.taegis.secureworks.com
  description: Taegis XDR API - EU1
- url: https://api.golf.taegis.secureworks.com
  description: Taegis XDR API - EU2
security:
- bearerAuth: []
tags:
- name: GraphQL
paths:
  /graphql:
    post:
      operationId: executeGraphQLQuery
      summary: Execute GraphQL Query
      description: 'Execute a GraphQL query or mutation against the Taegis XDR platform. The Taegis XDR API is primarily a GraphQL API supporting the following domains: Alerts, Audits, Collectors, Connectors, Endpoint Assets, Identities, Investigations, Playbooks, Threat Intelligence, BYOTI, Countermeasures, File Upload, Notifications, Tenants, and Users.'
      tags:
      - GraphQL
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GraphQLRequest'
      responses:
        '200':
          description: GraphQL response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GraphQLResponse'
        '400':
          description: Invalid GraphQL query
        '401':
          description: Unauthorized - invalid or expired bearer token
        '429':
          description: Rate limit exceeded
components:
  schemas:
    GraphQLRequest:
      type: object
      required:
      - query
      properties:
        query:
          type: string
          description: GraphQL query or mutation string
          example: "query {\n  alerts(input: { limit: 10, offset: 0 }) {\n    alerts {\n      id\n      severity\n      status\n      message\n      createdAt\n    }\n    totalCount\n  }\n}\n"
        variables:
          type: object
          description: GraphQL variables for parameterized queries
          additionalProperties: true
        operationName:
          type: string
          description: Name of the GraphQL operation (for multi-operation documents)
    GraphQLResponse:
      type: object
      properties:
        data:
          type: object
          description: GraphQL response data (shape varies by query)
          additionalProperties: true
        errors:
          type: array
          description: GraphQL errors if any
          items:
            type: object
            properties:
              message:
                type: string
              locations:
                type: array
                items:
                  type: object
                  properties:
                    line:
                      type: integer
                    column:
                      type: integer
              path:
                type: array
                items:
                  type: string
              extensions:
                type: object
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: OAuth2 bearer access token from /auth/api/v2/auth/token
    basicAuth:
      type: http
      scheme: basic
      description: HTTP Basic auth with client_id as username and client_secret as password