Every API here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for apis
7 MCP tools reach this
find_apisBrowse and filter every API in the catalog.
get_api_artifactsOne API's artifacts, grouped by type.
get_openapiThe primary OpenAPI for this API.
find_similar_apisAPIs that look like this one.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools
Call it yourself
curl for this page
This API
curl "https://apis.io/api/v1/apis/securonix-object-relationship-comments-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no email required.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: ThreatQ Object Relationship Comments API
description: "© 2025<br/><br/><b>The API doc you are viewing is a BETA version that provides an early look at ThreatQ’s new API documentation format. At the moment, it does not cover the entire application program interface. Additional API resources, including the current standard format as well as previous versions, are available on the ThreatQ Help Center.</b><br/><br/>Last Updated: 07/11/2025\n## Introduction\n\nThe ThreatQ API is built on REST principles and uses JSON as a data interchange format.\n\n<script type=\"text/javascript\" src=\"ga.js\"></script>\n\n\n### Base URI\n\nAll URIs referenced in this document use the following base: https://**hostname**/api/, where **hostname** is replaced with the hostname or ip address of your ThreatQ instance.\n\n\n### Request Format\n\nThe ThreatQ API supports the following HTTP verbs:\n\n| Verb | Description |\n| :-------------| :----------------------------------|\n| GET | GET requests retrieve resources. |\n| POST | POST requests create resources. |\n| PUT | PUT requests update resources. |\n| DELETE | DELETE requests delete resources. |\n\n\n### Response Format\n\nAll responses are returned in JSON. The response is wrapped in a top level data envelope which is an object or array depending on whether a single item or a collection is returned. If a single item is returned, the data field will be an object. If a collection is returned, the field will be an array.\n\n\n### Response Codes\n\nThe ThreatQ API uses HTTP status codes to indicate the status of your request.\n\n| Code | Description |\n| :-------------| :-------------------------------------------------------------------------------------|\n| 200 | Object was retrieved successfully. |\n| 201 | Object was created successfully. |\n| 204 | Object(s) were successfully deleted. |\n| 400 | Validation failed (usually as the result of an incorrect request) |\n| 401 | Access denied (authorization access token in the header was incorrect / out of date) |\n| 403 | Access forbidden (usually as the result of a bad request) |\n| 404 | Object not found |\n\n<hr />\n\n### Authentication\n\nThreatQ uses OAuth 2.0 to authenticate end users. You must have a ThreatQ user account to retrieve an API token. The API token is required for all API requests. The token does time out; therefore, you must periodically refresh the token.\n\n\n#### Authorization workflow\n\n1. Run a GET request to retrieve your client ID using the following format:\n\thttps://**hostname**/assets/js/config.js\n2. Run a POST/token request to retrieve your authorization access token. See POST/token in the Authorization section of this reference for the correct format.\n\n Include the following parameters:\n\t * grant_type (password)\n\t * client-id (retrieved in step 1)\n\n **Example:** https://**hostname**/api/token?grant_type=password&client_id=ab20a55dd9ac779246210d7102a45ee37\n\n In the request body, include your ThreatQ credentials:\n\t * email\n\t * password\n\n3. Enter the access token as the authorization key in the header for all subsequent api requests."
license:
name: null
url: null
version: 1.0.0
x-logo:
url: null
backgroundColor: null
altText: ThreatQuotient
servers:
- description: SwaggerHub API Auto Mocking
url: https://virtserver.swaggerhub.com/securonix-b7a/ThreatQ/1.0.0
- url: https://threatq.com/api
description: ThreatQ Server
security:
- BearerAuth: []
tags:
- name: Object Relationship Comments
paths:
/{src_object_collection}/{src_object_id}/{dest_object_collection}/{object_link_id}/comments:
get:
tags:
- Object Relationship Comments
summary: List Relationship Comments for an Object Type
parameters:
- $ref: '#/components/parameters/SrcObject'
- $ref: '#/components/parameters/SrcObjectId'
- $ref: '#/components/parameters/DestObject'
- $ref: '#/components/parameters/ObjectLinkId'
- $ref: '#/components/parameters/Sort'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Offset'
responses:
'200':
description: Request Successful
content:
application/json:
schema:
allOf:
- properties:
data:
type: array
items:
allOf:
- properties:
sources:
type: array
items:
$ref: '#/components/schemas/ObjectLinkCommentSource'
type: object
- $ref: '#/components/schemas/ObjectLinkComment'
type: object
- $ref: '#/components/schemas/TotalResponse'
'401':
$ref: '#/components/responses/Unauthorized'
x-visibility: public
post:
tags:
- Object Relationship Comments
summary: Create a Relationship Comment for an Object Type
description: 'This path can be used for any combination of objects installed on the system. <br><br>
Examples: <br><br> Comments for an Indicator / Adversary relationship:
<i>/adversaries/:adversary_id/indicators/:object_link_id/comments</i> <br><br> Comments for an
Indicator / Indicator relationship: <i>/indicators/:indicator_id/indicators/:object_link_id/comments</i>'
parameters:
- $ref: '#/components/parameters/SrcObject'
- $ref: '#/components/parameters/SrcObjectId'
- $ref: '#/components/parameters/DestObject'
- $ref: '#/components/parameters/ObjectLinkId'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectCommentFillable'
responses:
'201':
description: Created
content:
application/json:
schema:
properties:
data:
type: object
allOf:
- properties:
sources:
type: array
items:
$ref: '#/components/schemas/Source'
type: object
- $ref: '#/components/schemas/ObjectLinkComment'
type: object
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
x-visibility: public
/{src_object_collection}/{src_object_id}/{dest_object_collection}/{object_link_id}/comments/{object_link_comment_id}:
get:
tags:
- Object Relationship Comments
summary: Get a Single Relationship Comment for an Object Type
description: 'This path can be used for any combination of objects installed on the system. <br><br>
Examples: <br><br> A Comment for an Indicator / Adversary relationship:
<i>/adversaries/:adversary_id/indicators/:object_link_id/comments/:object_link_comment_id</i> <br><br>
An Comment for an Indicator / Indicator relationship:
<i>/indicators/:indicator_id/indicators/:object_link_id/comments/:object_link_comment_id</i>'
parameters:
- $ref: '#/components/parameters/SrcObject'
- $ref: '#/components/parameters/SrcObjectId'
- $ref: '#/components/parameters/DestObject'
- $ref: '#/components/parameters/ObjectLinkId'
- $ref: '#/components/parameters/ObjectLinkCommentId'
responses:
'200':
description: Request Successful
content:
application/json:
schema:
properties:
data:
type: object
allOf:
- properties:
sources:
type: array
items:
allOf:
- properties:
id:
description: Object Link Comment ID
type: integer
example: 2
type: object
- $ref: '#/components/schemas/SourceName'
type: object
- $ref: '#/components/schemas/ObjectLinkComment'
type: object
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
x-visibility: public
put:
tags:
- Object Relationship Comments
summary: Update a Relationship Comment for an Object Type
description: 'This path can be used for any combination of objects installed on the system. <br><br>
Examples: <br><br> A Comment for an Indicator / Adversary relationship:
<i>/adversaries/:adversary_id/indicators/:object_link_id/comments/:object_link_comment_id</i> <br><br>
An Attribute for an Indicator / Indicator relationship:
<i>/indicators/:indicator_id/indicators/:object_link_id/comments/:object_link_comment_id</i>'
parameters:
- $ref: '#/components/parameters/SrcObject'
- $ref: '#/components/parameters/SrcObjectId'
- $ref: '#/components/parameters/DestObject'
- $ref: '#/components/parameters/ObjectLinkId'
- $ref: '#/components/parameters/ObjectLinkCommentId'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectCommentFillable'
responses:
'200':
description: Request Successful
content:
application/json:
schema:
properties:
data:
type: object
allOf:
- properties:
sources:
type: array
items:
$ref: '#/components/schemas/ObjectLinkCommentSource'
type: object
- $ref: '#/components/schemas/ObjectLinkComment'
type: object
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
x-visibility: public
delete:
tags:
- Object Relationship Comments
summary: Remove a Relationship Comment for an Object Type
description: 'This path can be used for any combination of objects installed on the system. <br><br>
Examples: <br><br> A Comment for an Indicator / Adversary relationship:
<i>/adversaries/:adversary_id/indicators/:object_link_id/comments/:object_link_comment_id</i> <br><br>
A Comment for an Indicator / Indicator relationship:
<i>/indicators/:indicator_id/indicators/:object_link_id/comments/:object_link_comment_id</i>'
parameters:
- $ref: '#/components/parameters/SrcObject'
- $ref: '#/components/parameters/SrcObjectId'
- $ref: '#/components/parameters/DestObject'
- $ref: '#/components/parameters/ObjectLinkId'
- $ref: '#/components/parameters/ObjectLinkCommentId'
responses:
'204':
$ref: '#/components/responses/NoContent'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
x-visibility: public
components:
responses:
Unauthorized:
description: Unauthorized
NotFound:
description: Object Not Found
NoContent:
description: Object(s) were successfully deleted.
schemas:
ObjectLinkCommentBase:
allOf:
- properties:
id:
description: Object Link Comment ID
type: integer
example: 4
type: object
- $ref: '#/components/schemas/ObjectCommentFillable'
- $ref: '#/components/schemas/ThreatQTimestamps'
ObjectCommentFillable:
properties:
value:
description: Comment value
type: string
example: There's something odd happening...
type: object
SourceReferenceId:
properties:
reference_id:
description: Source Reference ID - points to related Client, Connector (Feed), Other Source, Plugin, or User
type: integer
example: 2
type: object
SourceName:
properties:
name:
description: Source Name
type: string
example: ThreatQ
type: object
SourceType:
properties:
type:
description: 'Source Type - Options include: clients, connectors (Feeds), other_sources, plugins, or users'
type: string
example: other_sources
type: object
ObjectLinkComment:
allOf:
- properties:
object_link_id:
description: Object Link ID - ID for the relationship record
type: integer
example: 4
type: object
- $ref: '#/components/schemas/CreatorSource'
- $ref: '#/components/schemas/ObjectLinkCommentBase'
CreatorSource:
properties:
creator_source_id:
description: Creator Source ID - Source ID of User, Feed, or other means that brought the object into the system
type: integer
example: 2
type: object
Source:
allOf:
- properties:
id:
description: Source ID
type: integer
example: 1
expire_days:
description: Number of days after which Objects with this Source will expire
type: integer
example: 12
expires_needs_calc:
description: Determines whether expiration for Objects with this Source needs recalculating
type: string
example: N
type: object
- $ref: '#/components/schemas/SourceFillable'
- $ref: '#/components/schemas/ThreatQTimestamps'
SourceFillable:
allOf:
- properties:
score:
description: Source Score - Ranges from -10 to 10
type: integer
example: 6
default_tlp_id:
description: Source Default TLP ID - the TLP that should be assigned for the Source if none is provided
type: integer
example: 3
type: object
- $ref: '#/components/schemas/SourceType'
- $ref: '#/components/schemas/SourceReferenceId'
- $ref: '#/components/schemas/SourceName'
TotalResponse:
properties:
total:
description: Total Number of Objects Processed
type: integer
example: 1
type: object
ThreatQTimestamps:
properties:
created_at:
description: Creation Date
type: string
example: '2021-07-29 13:58:03'
updated_at:
description: Update Date
type: string
example: '2022-04-12 08:32:16'
type: object
ObjectLinkCommentSource:
allOf:
- properties:
pivot:
type: object
allOf:
- properties:
id:
description: Object Link Comment ID
type: integer
example: 21
type: object
- $ref: '#/components/schemas/CreatorSource'
type: object
- $ref: '#/components/schemas/Source'
parameters:
ObjectLinkCommentId:
name: object_link_comment_id
in: path
description: Object Link Comment ID
required: true
schema:
type: integer
example: 4
Limit:
name: limit
in: query
description: <br>The number of objects included in the response.
required: false
style: form
explode: false
schema:
type: integer
example: 10
ObjectLinkId:
name: object_link_id
in: path
description: Object Link ID - the ID of the relationship record
required: true
schema:
type: integer
example: 3
Offset:
name: offset
in: query
description: <br>The number of result set records that should be ignored.
required: false
style: form
explode: false
schema:
type: integer
example: 50
Sort:
name: sort
in: query
description: "<br>Designate the field(s) you want to use to sort the retrieved list. You can prepend each field \n with a minus sign (-) to reverse the sorting order. This string can be a list of comma-separated values."
required: false
style: form
explode: false
schema:
type: string
example: id,created_at
SrcObject:
name: src_object_collection
in: path
description: "Source Object collection - the object type collection whose relationships you would like\n to retrieve. Options include: adversaries, attachments, attack_pattern, campaign, course_of_action, event,\n exploit_target, identity, incident, indicators, intrustion_set, malware, report, signature, tool, ttp,\n and vulnerability. If you have any additional custom objects installed on your system, use the `object_code`\n associated with the object definition."
required: true
schema:
type: string
example: indicators
SrcObjectId:
name: src_object_id
in: path
description: Source Object ID - the ID of the object whose relationships you would like to retrieve
required: true
schema:
type: integer
example: 2
DestObject:
name: dest_object_collection
in: path
description: "Destination Object collection - the collection for an object type that may have relationships\n associated with the Source Object collection. Options include: adversaries, attachments, attack_pattern,\n campaign, course_of_action, event, exploit_target, identity, incident, indicators, intrustion_set, malware,\n report, signature, tool, ttp, and vulnerability. If you have any additional custom objects installed on your\n system, use the `object_code` associated with the object definition."
required: true
schema:
type: string
example: adversaries
securitySchemes:
BearerAuth:
type: http
description: "Once authorized, all subsequent requests must include an `Authorization` header\n with the granted `access_token`. See the OAuth2 Authentication path for more information on how to authorize a User.<br><br>\n Example Header: `Authorization: Bearer <access_token>`"
name: Authorization
in: header
bearerFormat: Bearer `<access_token>`
scheme: bearer