Xbow Meta API

Instance metadata endpoints.

Operations 3

GET /api/v1/meta/addresses Get addresses #
GET /api/v1/meta/openapi.json Get OpenAPI specification #
GET /api/v1/meta/webhooks-signing-keys Get webhook signing keys #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/xbow-meta-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

xbow-meta-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: '# Versioning


    The API is in public preview.'
  title: XBOW Meta API
  version: '2026-07-01'
servers:
- description: Default
  url: https://console.xbow.com/
- description: Multi SAAS - Europe data resident instance
  url: https://console.eu.xbow.com/
- description: Multi SAAS - Asia Pacific data resident instance
  url: https://console.sg.xbow.com/
tags:
- description: Instance metadata endpoints.
  name: Meta
paths:
  /api/v1/meta/addresses:
    get:
      description: 'Returns the public IP addresses used by XBOW. Allowlist these IPs to allow XBOW traffic.

        `agents` are the IPs used by XBOW agents when performing an assessment.'
      parameters:
      - description: API version to use for this request
        in: header
        name: X-XBOW-API-Version
        required: true
        schema:
          enum:
          - '2026-07-01'
          example: '2026-07-01'
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                example:
                  agents:
                  - 1.2.3.4
                  - 5.6.7.8
                properties:
                  agents:
                    items:
                      format: ipv4
                      pattern: ^(?:(?:25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9][0-9]|[0-9])\.){3}(?:25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9][0-9]|[0-9])$
                      type: string
                    type: array
                required:
                - agents
                type: object
          description: Default Response
      security:
      - Authorization: []
      summary: Get addresses
      tags:
      - Meta
      operationId: getApiV1MetaAddresses
      x-operation-id-source: derived
  /api/v1/meta/openapi.json:
    get:
      description: 'Returns the OpenAPI specification in JSON format for the API version specified in the X-XBOW-API-Version header.


        Requires an organization API key. This may be made public in the future.'
      parameters:
      - description: API version to use for this request
        in: header
        name: X-XBOW-API-Version
        required: true
        schema:
          enum:
          - '2026-07-01'
          example: '2026-07-01'
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                example:
                  info:
                    title: XBOW API
                    version: next
                  openapi: 3.0.0
          description: Default Response
        '400':
          content:
            application/json:
              schema:
                properties:
                  code:
                    type: string
                  error:
                    type: string
                  message:
                    type: string
                required:
                - code
                - error
                - message
                type: object
          description: Default Response
        '404':
          content:
            application/json:
              schema:
                properties:
                  code:
                    type: string
                  error:
                    type: string
                  message:
                    type: string
                required:
                - code
                - error
                - message
                type: object
          description: Default Response
      security:
      - Authorization: []
      summary: Get OpenAPI specification
      tags:
      - Meta
      operationId: getApiV1MetaOpenapiJson
      x-operation-id-source: derived
  /api/v1/meta/webhooks-signing-keys:
    get:
      description: 'Returns the public keys used to sign webhook requests. Use these keys to verify webhook signatures.


        The array supports key rotation - during rotation, multiple keys may be active.'
      parameters:
      - description: API version to use for this request
        in: header
        name: X-XBOW-API-Version
        required: true
        schema:
          enum:
          - '2026-07-01'
          example: '2026-07-01'
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                example:
                - publicKey: MCowBQYDK2VwAyEA...
                items:
                  properties:
                    publicKey:
                      description: Base64-encoded Ed25519 public key in SPKI format
                      type: string
                  required:
                  - publicKey
                  type: object
                type: array
          description: Default Response
      security:
      - Authorization: []
      summary: Get webhook signing keys
      tags:
      - Meta
      operationId: getApiV1MetaWebhooksSigningKeys
      x-operation-id-source: derived
components:
  securitySchemes:
    Authorization:
      bearerFormat: API Key
      description: Authorization header with Bearer token
      scheme: bearer
      type: http