Every API here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for apis
7 MCP tools reach this
find_apisBrowse and filter every API in the catalog.
get_api_artifactsOne API's artifacts, grouped by type.
get_openapiThe primary OpenAPI for this API.
find_similar_apisAPIs that look like this one.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This API
curl "https://apis.io/api/v1/apis/securonix-indicators-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: ThreatQ Indicators API
description: '© 2025
The API doc you are viewing is a BETA version that provides an early look at ThreatQ’s new API documentation format.'
license:
name: null
url: null
version: 1.0.0
x-logo:
url: null
backgroundColor: null
altText: ThreatQuotient
servers:
- description: SwaggerHub API Auto Mocking
url: https://virtserver.swaggerhub.com/securonix-b7a/ThreatQ/1.0.0
- url: https://threatq.com/api
description: ThreatQ Server
security:
- BearerAuth: []
tags:
- name: Indicators
paths:
/indicators:
get:
tags:
- Indicators
summary: List Indicators
parameters:
- $ref: '#/components/parameters/IndicatorWith'
- $ref: '#/components/parameters/Sort'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Offset'
responses:
'200':
description: Request Successful
content:
application/json:
schema:
allOf:
- properties:
data:
type: array
items:
$ref: '#/components/schemas/Indicator'
type: object
- $ref: '#/components/schemas/TotalResponse'
'401':
$ref: '#/components/responses/Unauthorized'
x-visibility: public
operationId: getIndicators
x-operation-id-source: derived
post:
tags:
- Indicators
summary: Create a(n) Indicator
requestBody:
content:
application/json:
schema:
type: array
items:
allOf:
- properties:
attributes:
type: array
items:
$ref: '#/components/schemas/AttributeBasics'
sources:
type: array
items:
$ref: '#/components/schemas/SourceBasics'
type: object
- $ref: '#/components/schemas/IndicatorFillable'
responses:
'200':
description: Request Successful
content:
application/json:
schema:
allOf:
- properties:
data:
type: array
items:
allOf:
- properties:
attributes:
type: array
items:
$ref: '#/components/schemas/AttributeBasics'
sources:
type: array
items:
$ref: '#/components/schemas/SourceBasics'
type: object
- $ref: '#/components/schemas/Indicator'
type: object
- $ref: '#/components/schemas/TotalResponse'
'401':
$ref: '#/components/responses/Unauthorized'
x-visibility: public
operationId: postIndicators
x-operation-id-source: derived
/indicators/consume:
post:
tags:
- Indicators
summary: Indicator Consume
requestBody:
content:
application/json:
schema:
type: array
items:
allOf:
- properties:
indicators:
description: Related Indicators
type: array
items:
$ref: '#/components/schemas/IndicatorFillable'
type: object
- $ref: '#/components/schemas/IndicatorFillable'
- $ref: '#/components/schemas/CommonObjectConsumeRequest'
responses:
'201':
description: Ingestion Completed Successfully
content:
application/json:
schema:
allOf:
- properties:
data:
type: array
items:
allOf:
- properties:
id:
description: Indicator ID
type: integer
default: 1
type: object
- $ref: '#/components/schemas/IndicatorFillable'
type: object
- $ref: '#/components/schemas/TotalResponse'
'401':
$ref: '#/components/responses/Unauthorized'
x-visibility: public
operationId: postIndicatorsConsume
x-operation-id-source: derived
/indicators/{indicator_id}:
get:
tags:
- Indicators
summary: Get Single Indicator
parameters:
- $ref: '#/components/parameters/IndicatorId'
- $ref: '#/components/parameters/IndicatorWith'
responses:
'200':
description: Request Successful
content:
application/json:
schema:
properties:
data:
$ref: '#/components/schemas/Indicator'
type: object
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
x-visibility: public
operationId: getIndicatorsByIndicatorId
x-operation-id-source: derived
put:
tags:
- Indicators
summary: Update a(n) Indicator
parameters:
- $ref: '#/components/parameters/IndicatorId'
- $ref: '#/components/parameters/IndicatorWith'
requestBody:
content:
application/json:
schema:
type: array
items:
allOf:
- properties:
attributes:
type: array
items:
$ref: '#/components/schemas/AttributeBasics'
sources:
type: array
items:
$ref: '#/components/schemas/SourceBasics'
type: object
- $ref: '#/components/schemas/IndicatorFillable'
responses:
'200':
description: Request Successful
content:
application/json:
schema:
allOf:
- properties:
data:
type: array
items:
allOf:
- properties:
attributes:
type: array
items:
$ref: '#/components/schemas/AttributeBasics'
sources:
type: array
items:
$ref: '#/components/schemas/SourceBasics'
type: object
- $ref: '#/components/schemas/Indicator'
type: object
- $ref: '#/components/schemas/TotalResponse'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
x-visibility: public
operationId: putIndicatorsByIndicatorId
x-operation-id-source: derived
delete:
tags:
- Indicators
summary: Delete Indicator
parameters:
- $ref: '#/components/parameters/IndicatorId'
responses:
'204':
$ref: '#/components/responses/NoContent'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
x-visibility: public
operationId: deleteIndicatorsByIndicatorId
x-operation-id-source: derived
components:
parameters:
IndicatorId:
name: indicator_id
in: path
description: Indicator ID
required: true
schema:
type: integer
Limit:
name: limit
in: query
description: <br>The number of objects included in the response.
required: false
style: form
explode: false
schema:
type: integer
example: 10
Sort:
name: sort
in: query
description: "<br>Designate the field(s) you want to use to sort the retrieved list. You can prepend each field \n with a minus sign (-) to reverse the sorting order. This string can be a list of comma-separated values."
required: false
style: form
explode: false
schema:
type: string
example: id,created_at
IndicatorWith:
name: with
in: query
description: '<br>Object Relationships that can be included in the response.<br><br>Options include: adversaries,
attachments, attack_pattern, attributes, campaign, comments, course_of_action, events, exploit_target, identity,
incident, indicators, intrusion_set, malware, recipient, report, plugins, pluginActions, score, signatures, sources,
status, tags, tool, ttp, type, and watchlist.'
required: false
style: form
explode: false
schema:
type: array
items:
type: string
example: adversaries,comments,description
Offset:
name: offset
in: query
description: <br>The number of result set records that should be ignored.
required: false
style: form
explode: false
schema:
type: integer
example: 50
schemas:
TLPName:
properties:
name:
description: TLP Name
type: string
example: WHITE
type: object
ObjectAttributeValue:
properties:
value:
description: Attribute Value
type: string
example: High
type: object
ObjectLinkAttributeFillable:
allOf:
- $ref: '#/components/schemas/AttributeFillable'
- $ref: '#/components/schemas/ObjectAttributeValue'
TotalResponse:
properties:
total:
description: Total Number of Objects Processed
type: integer
example: 1
type: object
IndicatorFillable:
properties:
type_id:
description: Indicator Type ID
type: integer
example: 11
status_id:
description: Indicator Status ID
type: integer
example: 2
class:
description: 'Indicator Class - Options include: host, network'
type: string
example: network
value:
description: Indicator Value
type: string
example: www.danger-doom.com
description:
description: Indicator Description
type: string
example: Website encountered during incident investigation.
type: object
AttributeBasics:
allOf:
- properties:
sources:
type: array
items:
$ref: '#/components/schemas/SourceBasics'
type: object
- $ref: '#/components/schemas/ObjectLinkAttributeFillable'
AttributeFillable:
properties:
name:
description: Attribute Name
type: string
example: Confidence
type: object
ThreatQTimestamps:
properties:
created_at:
description: Creation Date
type: string
example: '2021-07-29 13:58:03'
updated_at:
description: Update Date
type: string
example: '2022-04-12 08:32:16'
type: object
SourceName:
properties:
name:
description: Source Name
type: string
example: ThreatQ
type: object
Indicator:
allOf:
- properties:
id:
description: Indicator ID
type: integer
example: 54
type: object
- properties:
hash:
description: Indicator Hash
type: string
example: 4aba5ab07a3bda558d5d725a09d93ba6
last_detected_at:
description: Date the Indicator was last encountered
type: string
example: '2020-02-28 13:42:51'
expires_at:
description: Date the Indicator will expire
type: string
example: '2020-04-01 03:17:23'
expired_at:
description: Date the Indicator expired
type: string
example: null
expired_needs_calc:
description: Determines whether the Indicator's expiration date needs updating
type: string
example: N
expires_calculated_at:
description: Date the Indicator's expiration date was calculated
type: string
example: '2020-02-28 18:36:24'
type: object
- $ref: '#/components/schemas/IndicatorFillable'
- $ref: '#/components/schemas/ThreatQTimestamps'
- $ref: '#/components/schemas/TouchedAtTimestamp'
CommonObjectConsumeRequest:
properties:
attributes:
type: array
items:
$ref: '#/components/schemas/AttributeBasics'
sources:
type: array
items:
$ref: '#/components/schemas/SourceBasics'
tlp:
$ref: '#/components/schemas/TLPName'
<object_code>:
description: 'Relate objects of other types by providing a list of IDs. Replace the `<object_code>` property key with
one of the options to relate objects of that type. <br><br> NOTE: Objects must be created separately before IDs can be
used in request. <br><br>Options include: adversaries, attachments, attack_pattern, campaign, course_of_action, events,
exploit_target, identity, incident, indicators, intrusion_set, malware, recipient, report, signatures, tool, ttp.'
type: array
items:
type: integer
example: 2
type: object
TouchedAtTimestamp:
properties:
touched_at:
description: Update Date for Object Context (Attributes, Comments, Sources, Relationships)
type: string
example: '2021-11-13 15:28:17'
type: object
SourceBasics:
oneOf:
- allOf:
- properties:
tlp_id:
description: Source TLP ID
type: integer
example: 3
type: object
- $ref: '#/components/schemas/SourceName'
- allOf:
- properties:
tlp:
$ref: '#/components/schemas/TLPName'
type: object
- $ref: '#/components/schemas/SourceName'
responses:
Unauthorized:
description: Unauthorized
NotFound:
description: Object Not Found
NoContent:
description: Object(s) were successfully deleted.
securitySchemes:
BearerAuth:
type: http
description: "Once authorized, all subsequent requests must include an `Authorization` header\n with the granted `access_token`. See the OAuth2 Authentication path for more information on how to authorize a User.<br><br>\n Example Header: `Authorization: Bearer <access_token>`"
name: Authorization
in: header
bearerFormat: Bearer `<access_token>`
scheme: bearer