Xbow Reports API
Endpoints for downloading and viewing reports. All endpoints require an _organization_ API key.
Endpoints for downloading and viewing reports. All endpoints require an _organization_ API key.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/xbow-reports-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
description: '# Versioning
The API is in public preview.'
title: XBOW Reports API
version: '2026-07-01'
servers:
- description: Default
url: https://console.xbow.com/
- description: Multi SAAS - Europe data resident instance
url: https://console.eu.xbow.com/
- description: Multi SAAS - Asia Pacific data resident instance
url: https://console.sg.xbow.com/
tags:
- description: 'Endpoints for downloading and viewing reports.
All endpoints require an _organization_ API key.'
name: Reports
paths:
/api/v1/assets/{assetId}/reports:
get:
description: 'Lists all available report versions for an asset.
Supports pagination via `limit` and `after` query parameters.'
parameters:
- in: query
name: limit
required: false
schema:
default: 20
maximum: 100
minimum: 1
type: integer
- in: query
name: after
required: false
schema:
type: string
- in: path
name: assetId
required: true
schema:
type: string
- description: API version to use for this request
in: header
name: X-XBOW-API-Version
required: true
schema:
enum:
- '2026-07-01'
example: '2026-07-01'
type: string
responses:
'200':
content:
application/json:
schema:
example:
items:
- createdAt: '2025-01-15T00:00:00Z'
id: 123e4567-e89b-12d3-a456-426614174000
version: 3
nextCursor: eyJjcmVhdGVkQXQiOiIyMDI1LTAxLTAxVDAwOjAwOjAwWiIsImlkIjoiMTIzZTQ1NjctZTg5Yi0xMmQzLWE0NTYtNDI2NjE0MTc0MDAwIn0=
properties:
items:
items:
properties:
createdAt:
format: date-time
type: string
id:
type: string
version:
exclusiveMinimum: 0
maximum: 9007199254740991
type: integer
required:
- createdAt
- id
- version
type: object
type: array
nextCursor:
type: string
required:
- items
type: object
description: Default Response
'400':
content:
application/json:
schema:
properties:
code:
description: A constant for machines
enum:
- FST_ERR_VALIDATION
type: string
error:
description: A human readable string for the constant
enum:
- Bad Request
type: string
message:
description: A human readable message
type: string
requestId:
description: A unique identifier for the request
type: string
required:
- code
- error
- message
- requestId
type: object
description: Default Response
'404':
content:
application/json:
schema:
properties:
code:
description: A constant for machines
enum:
- ERR_NOT_FOUND
type: string
error:
description: A human readable string for the constant
enum:
- Not Found
type: string
message:
description: A human readable message
type: string
requestId:
description: A unique identifier for the request
type: string
required:
- code
- error
- message
- requestId
type: object
description: The requested resource was not found
security:
- Authorization: []
summary: List asset reports
tags:
- Reports
operationId: getApiV1AssetsByAssetIdReports
x-operation-id-source: derived
/api/v1/reports/{reportId}:
get:
description: Downloads a report version as a PDF file using its UUID.
parameters:
- in: path
name: reportId
required: true
schema:
type: string
- description: API version to use for this request
in: header
name: X-XBOW-API-Version
required: true
schema:
enum:
- '2026-07-01'
example: '2026-07-01'
type: string
responses:
'200':
content:
application/pdf:
schema: {}
description: PDF file content
'400':
content:
application/json:
schema:
properties:
code:
description: A constant for machines
enum:
- FST_ERR_VALIDATION
type: string
error:
description: A human readable string for the constant
enum:
- Bad Request
type: string
message:
description: A human readable message
type: string
requestId:
description: A unique identifier for the request
type: string
required:
- code
- error
- message
- requestId
type: object
description: Default Response
'404':
content:
application/json:
schema:
properties:
code:
description: A constant for machines
enum:
- ERR_NOT_FOUND
type: string
error:
description: A human readable string for the constant
enum:
- Not Found
type: string
message:
description: A human readable message
type: string
requestId:
description: A unique identifier for the request
type: string
required:
- code
- error
- message
- requestId
type: object
description: The requested resource was not found
security:
- Authorization: []
summary: Get report
tags:
- Reports
operationId: getApiV1ReportsByReportId
x-operation-id-source: derived
/api/v1/reports/{reportId}/summary:
get:
description: Gets a summary of a report version using its UUID.
parameters:
- in: path
name: reportId
required: true
schema:
type: string
- description: API version to use for this request
in: header
name: X-XBOW-API-Version
required: true
schema:
enum:
- '2026-07-01'
example: '2026-07-01'
type: string
responses:
'200':
content:
application/json:
schema:
example:
markdown: XBOW identified 5 critical findings.
properties:
markdown:
type: string
required:
- markdown
type: object
description: Markdown summary of the report, suitable for display in the UI
'400':
content:
application/json:
schema:
properties:
code:
description: A constant for machines
enum:
- FST_ERR_VALIDATION
type: string
error:
description: A human readable string for the constant
enum:
- Bad Request
type: string
message:
description: A human readable message
type: string
requestId:
description: A unique identifier for the request
type: string
required:
- code
- error
- message
- requestId
type: object
description: Default Response
'404':
content:
application/json:
schema:
properties:
code:
description: A constant for machines
enum:
- ERR_NOT_FOUND
type: string
error:
description: A human readable string for the constant
enum:
- Not Found
type: string
message:
description: A human readable message
type: string
requestId:
description: A unique identifier for the request
type: string
required:
- code
- error
- message
- requestId
type: object
description: The requested resource was not found
security:
- Authorization: []
summary: Get report summary
tags:
- Reports
operationId: getApiV1ReportsByReportIdSummary
x-operation-id-source: derived
components:
securitySchemes:
Authorization:
bearerFormat: API Key
description: Authorization header with Bearer token
scheme: bearer
type: http