Xbow Resources API

Upload and manage files used in assessments, such as source code archives. All endpoints require an _organization_ API key. ## Upload flow Resources use a multipart S3 upload. The full flow is: 1. **Create** — `POST /api/v1/organizations/:organizationId/resources` — initiates an upload and returns a resource ID. Status is `initiated`. 2. **Get part URLs** — `POST /api/v1/resources/:resourceId/parts` — provide a list of part numbers and receive a corresponding list of presigned S3 `PUT` URLs. 3. **Upload parts** — `PUT` each part directly to its presigned URL. Save the `ETag` header from each part response. 4. **Commit** — `POST /api/v1/resources/:resourceId/commit` — submit the part numbers and ETags. Optionally include a `sha256` checksum of the full file for server-side integrity verification. Status moves to `processing`. 5. **Poll** — `GET /api/v1/resources/:resourceId` — wait until status is `ready` (or `failed`). 6. **Delete** — `DELETE /api/v1/resources/:resourceId` — the resource can be manually deleted when required. Status moves to `deleted`. The maximum part size is 5 GiB. Parts must be at least 5 MiB each, except the final part which may be smaller. Breaking large files into multiple parts allows failed parts to be retried individually rather than restarting the entire upload. ## Resource statuses | Status | Meaning | |---|---| | `initiated` | Upload in progress — parts not yet committed | | `processing` | Commit received — server is validating and storing | | `ready` | Available to use in assessments | | `failed` | Processing failed — see `statusMessage` for details | | `deleted` | Deleted | ## Example This snippet shows how to upload an example file named `source.tar.gz` using the API multipart upload feature. It uses the `fetch` API and assumes a Node.js environment with `fs/promises` available. ```typescript import fs from "node:fs/promises"; import crypto from "node:crypto"; const BASE = "https://console.xbow.com"; const ORG_ID = "your-organization-id"; const API_KEY = "your-api-key"; const PART_SIZE = 5 * 1024 * 1024; // 5 MiB minimum const API_VERSION = "next"; const headers = { "Authorization": `Bearer ${API_KEY}`, "X-XBOW-API-Version": `${API_VERSION}` }; // 1. Create resource const created = await fetch(`${BASE}/api/v1/organizations/${ORG_ID}/resources`, { method: "POST", headers: { ...headers, "Content-Type": "application/json" }, body: JSON.stringify({ name: "My source", fileName: "source.tar.gz", type: "source" }), }).then(r => r.json()); const resourceId = created.id; // 2. Split file into parts and request presigned URLs const file = await fs.readFile("source.tar.gz"); const partCount = Math.ceil(file.length / PART_SIZE); const { parts: partUrls } = await fetch(`${BASE}/api/v1/resources/${resourceId}/parts`, { method: "POST", headers: { ...headers, "Content-Type": "application/json" }, body: JSON.stringify({ parts: Array.from({ length: partCount }, (_, i) => i + 1) }), }).then(r => r.json()); // 3. Upload each part to S3 directly, collect ETags const uploadedParts = await Promise.all(partUrls.map(async ({ partNumber, url }) => { const chunk = file.slice((partNumber - 1) * PART_SIZE, partNumber * PART_SIZE); const res = await fetch(url, { method: "PUT", body: chunk }); return { partNumber, eTag: res.headers.get("ETag").replaceAll('"', "") }; })); // 4. Commit (sha256 is optional but recommended for integrity verification) const sha256 = crypto.createHash("sha256").update(file).digest("hex"); await fetch(`${BASE}/api/v1/resources/${resourceId}/commit`, { method: "POST", headers: { ...headers, "Content-Type": "application/json" }, body: JSON.stringify({ parts: uploadedParts, sha256 }), }).then(r => r.json()); // 5. Poll until ready let resource; do { await new Promise(r => setTimeout(r, 5000)); resource = await fetch(`${BASE}/api/v1/resources/${resourceId}`, { headers }).then(r => r.json()); } while (resource.status === "processing" || resource.status === "initiated"); if (resource.status !== "ready") throw new Error(`Upload failed: ${resource.statusMessage}`); console.log("Resource ready:", resource.id); // 6. Delete when no longer required await fetch(`${BASE}/api/v1/resources/${resourceId}`, { method: "DELETE", headers, }); ```

Operations 6

GET /api/v1/organizations/{organizationId}/resources List resources #
POST /api/v1/organizations/{organizationId}/resources Create resource #
DELETE /api/v1/resources/{resourceId} Delete resource #
GET /api/v1/resources/{resourceId} Get resource #
POST /api/v1/resources/{resourceId}/commit Commit resource #
POST /api/v1/resources/{resourceId}/parts Get resource part upload URLs #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/xbow-resources-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

xbow-resources-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: '# Versioning


    The API is in public preview.'
  title: XBOW Resources API
  version: '2026-07-01'
servers:
- description: Default
  url: https://console.xbow.com/
- description: Multi SAAS - Europe data resident instance
  url: https://console.eu.xbow.com/
- description: Multi SAAS - Asia Pacific data resident instance
  url: https://console.sg.xbow.com/
tags:
- description: Upload and manage files used in assessments, such as source code archives.
  name: Resources
paths:
  /api/v1/organizations/{organizationId}/resources:
    get:
      description: List resources in an organization.
      parameters:
      - in: query
        name: limit
        required: false
        schema:
          default: 20
          maximum: 100
          minimum: 1
          type: integer
      - in: query
        name: after
        required: false
        schema:
          type: string
      - in: path
        name: organizationId
        required: true
        schema:
          type: string
      - description: API version to use for this request
        in: header
        name: X-XBOW-API-Version
        required: true
        schema:
          enum:
          - '2026-07-01'
          example: '2026-07-01'
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  items:
                    items:
                      properties:
                        createdAt:
                          format: date-time
                          type: string
                        fileName:
                          type: string
                        id:
                          type: string
                        name:
                          type: string
                        sha256:
                          anyOf:
                          - type: string
                          - type: 'null'
                        sizeBytes:
                          anyOf:
                          - type: number
                          - type: 'null'
                        status:
                          enum:
                          - deleted
                          - failed
                          - initiated
                          - processing
                          - ready
                          type: string
                        statusMessage:
                          anyOf:
                          - type: string
                          - type: 'null'
                        type:
                          enum:
                          - documentation
                          - report
                          - source
                          type: string
                        updatedAt:
                          format: date-time
                          type: string
                      required:
                      - createdAt
                      - fileName
                      - id
                      - name
                      - sha256
                      - sizeBytes
                      - status
                      - statusMessage
                      - type
                      - updatedAt
                      type: object
                    type: array
                  nextCursor:
                    type: string
                required:
                - items
                type: object
          description: Default Response
      security:
      - Authorization: []
      summary: List resources
      tags:
      - Resources
      operationId: getApiV1OrganizationsByOrganizationIdResources
      x-operation-id-source: derived
    post:
      description: Create a new resource in an organization. For example, source code to be used in an assessment.
      parameters:
      - in: path
        name: organizationId
        required: true
        schema:
          type: string
      - description: API version to use for this request
        in: header
        name: X-XBOW-API-Version
        required: true
        schema:
          enum:
          - '2026-07-01'
          example: '2026-07-01'
          type: string
      requestBody:
        content:
          application/json:
            schema:
              example:
                fileName: source.tar.gz
                name: Source code for upcoming release
                type: source
              properties:
                fileName:
                  type: string
                name:
                  type: string
                type:
                  enum:
                  - documentation
                  - report
                  - source
                  type: string
              required:
              - fileName
              - name
              - type
              type: object
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                properties:
                  createdAt:
                    format: date-time
                    type: string
                  fileName:
                    type: string
                  id:
                    type: string
                  name:
                    type: string
                  organizationId:
                    type: string
                  type:
                    enum:
                    - documentation
                    - report
                    - source
                    type: string
                  updatedAt:
                    format: date-time
                    type: string
                required:
                - createdAt
                - fileName
                - id
                - name
                - organizationId
                - type
                - updatedAt
                type: object
          description: Default Response
        '400':
          content:
            application/json:
              schema:
                properties:
                  code:
                    description: A constant for machines
                    enum:
                    - FST_ERR_VALIDATION
                    type: string
                  error:
                    description: A human readable string for the constant
                    enum:
                    - Bad Request
                    type: string
                  message:
                    description: A human readable message
                    type: string
                  requestId:
                    description: A unique identifier for the request
                    type: string
                required:
                - code
                - error
                - message
                - requestId
                type: object
          description: Default Response
      security:
      - Authorization: []
      summary: Create resource
      tags:
      - Resources
      operationId: postApiV1OrganizationsByOrganizationIdResources
      x-operation-id-source: derived
  /api/v1/resources/{resourceId}:
    delete:
      description: Delete a resource by ID.
      parameters:
      - in: path
        name: resourceId
        required: true
        schema:
          type: string
      - description: API version to use for this request
        in: header
        name: X-XBOW-API-Version
        required: true
        schema:
          enum:
          - '2026-07-01'
          example: '2026-07-01'
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  createdAt:
                    format: date-time
                    type: string
                  fileName:
                    type: string
                  id:
                    type: string
                  name:
                    type: string
                  organizationId:
                    type: string
                  sha256:
                    anyOf:
                    - type: string
                    - type: 'null'
                  sizeBytes:
                    anyOf:
                    - type: number
                    - type: 'null'
                  status:
                    enum:
                    - deleted
                    - failed
                    - initiated
                    - processing
                    - ready
                    type: string
                  statusMessage:
                    anyOf:
                    - type: string
                    - type: 'null'
                  type:
                    enum:
                    - documentation
                    - report
                    - source
                    type: string
                  updatedAt:
                    format: date-time
                    type: string
                required:
                - createdAt
                - fileName
                - id
                - name
                - organizationId
                - sha256
                - sizeBytes
                - status
                - statusMessage
                - type
                - updatedAt
                type: object
          description: Default Response
        '404':
          content:
            application/json:
              schema:
                properties:
                  code:
                    description: A constant for machines
                    enum:
                    - ERR_NOT_FOUND
                    type: string
                  error:
                    description: A human readable string for the constant
                    enum:
                    - Not Found
                    type: string
                  message:
                    description: A human readable message
                    type: string
                  requestId:
                    description: A unique identifier for the request
                    type: string
                required:
                - code
                - error
                - message
                - requestId
                type: object
          description: The requested resource was not found
      security:
      - Authorization: []
      summary: Delete resource
      tags:
      - Resources
      operationId: deleteApiV1ResourcesByResourceId
      x-operation-id-source: derived
    get:
      description: Get a resource by ID.
      parameters:
      - in: path
        name: resourceId
        required: true
        schema:
          type: string
      - description: API version to use for this request
        in: header
        name: X-XBOW-API-Version
        required: true
        schema:
          enum:
          - '2026-07-01'
          example: '2026-07-01'
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  createdAt:
                    format: date-time
                    type: string
                  fileName:
                    type: string
                  id:
                    type: string
                  name:
                    type: string
                  organizationId:
                    type: string
                  sha256:
                    anyOf:
                    - type: string
                    - type: 'null'
                  sizeBytes:
                    anyOf:
                    - type: number
                    - type: 'null'
                  status:
                    enum:
                    - deleted
                    - failed
                    - initiated
                    - processing
                    - ready
                    type: string
                  statusMessage:
                    anyOf:
                    - type: string
                    - type: 'null'
                  type:
                    enum:
                    - documentation
                    - report
                    - source
                    type: string
                  updatedAt:
                    format: date-time
                    type: string
                required:
                - createdAt
                - fileName
                - id
                - name
                - organizationId
                - sha256
                - sizeBytes
                - status
                - statusMessage
                - type
                - updatedAt
                type: object
          description: Default Response
        '404':
          content:
            application/json:
              schema:
                properties:
                  code:
                    description: A constant for machines
                    enum:
                    - ERR_NOT_FOUND
                    type: string
                  error:
                    description: A human readable string for the constant
                    enum:
                    - Not Found
                    type: string
                  message:
                    description: A human readable message
                    type: string
                  requestId:
                    description: A unique identifier for the request
                    type: string
                required:
                - code
                - error
                - message
                - requestId
                type: object
          description: The requested resource was not found
      security:
      - Authorization: []
      summary: Get resource
      tags:
      - Resources
      operationId: getApiV1ResourcesByResourceId
      x-operation-id-source: derived
  /api/v1/resources/{resourceId}/commit:
    post:
      description: Commit a resource after all parts are uploaded.
      parameters:
      - in: path
        name: resourceId
        required: true
        schema:
          type: string
      - description: API version to use for this request
        in: header
        name: X-XBOW-API-Version
        required: true
        schema:
          enum:
          - '2026-07-01'
          example: '2026-07-01'
          type: string
      requestBody:
        content:
          application/json:
            schema:
              example:
                parts:
                - eTag: 9b2cf535f27731c974343645a3985328-1
                  partNumber: 1
                - eTag: 1b2cf535f27731c974343645a39853aa-2
                  partNumber: 2
                sha256: 3a7bd3e2360a3d80d1c8b456426655440c5fbc1bdb1c9aafbf71e913d93
              properties:
                parts:
                  items:
                    properties:
                      eTag:
                        type: string
                      partNumber:
                        maximum: 9007199254740991
                        minimum: -9007199254740991
                        type: integer
                    required:
                    - eTag
                    - partNumber
                    type: object
                  type: array
                sha256:
                  type: string
              required:
              - parts
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  createdAt:
                    format: date-time
                    type: string
                  fileName:
                    type: string
                  id:
                    type: string
                  name:
                    type: string
                  organizationId:
                    type: string
                  sha256:
                    anyOf:
                    - type: string
                    - type: 'null'
                  sizeBytes:
                    anyOf:
                    - type: number
                    - type: 'null'
                  status:
                    enum:
                    - deleted
                    - failed
                    - initiated
                    - processing
                    - ready
                    type: string
                  statusMessage:
                    anyOf:
                    - type: string
                    - type: 'null'
                  type:
                    enum:
                    - documentation
                    - report
                    - source
                    type: string
                  updatedAt:
                    format: date-time
                    type: string
                required:
                - createdAt
                - fileName
                - id
                - name
                - organizationId
                - sha256
                - sizeBytes
                - status
                - statusMessage
                - type
                - updatedAt
                type: object
          description: Default Response
        '400':
          content:
            application/json:
              schema:
                properties:
                  code:
                    description: A constant for machines
                    enum:
                    - FST_ERR_VALIDATION
                    type: string
                  error:
                    description: A human readable string for the constant
                    enum:
                    - Bad Request
                    type: string
                  message:
                    description: A human readable message
                    type: string
                  requestId:
                    description: A unique identifier for the request
                    type: string
                required:
                - code
                - error
                - message
                - requestId
                type: object
          description: Default Response
        '404':
          content:
            application/json:
              schema:
                properties:
                  code:
                    description: A constant for machines
                    enum:
                    - ERR_NOT_FOUND
                    type: string
                  error:
                    description: A human readable string for the constant
                    enum:
                    - Not Found
                    type: string
                  message:
                    description: A human readable message
                    type: string
                  requestId:
                    description: A unique identifier for the request
                    type: string
                required:
                - code
                - error
                - message
                - requestId
                type: object
          description: The requested resource was not found
        '409':
          content:
            application/json:
              schema:
                properties:
                  code:
                    description: A constant for machines
                    enum:
                    - ERR_CONFLICT
                    type: string
                  error:
                    description: A human readable string for the constant
                    enum:
                    - Conflict
                    type: string
                  message:
                    description: A human readable message
                    type: string
                  requestId:
                    description: A unique identifier for the request
                    type: string
                required:
                - code
                - error
                - message
                - requestId
                type: object
          description: The resource already exists
      security:
      - Authorization: []
      summary: Commit resource
      tags:
      - Resources
      operationId: postApiV1ResourcesByResourceIdCommit
      x-operation-id-source: derived
  /api/v1/resources/{resourceId}/parts:
    post:
      description: Get presigned upload URLs for specific parts of a multipart upload.
      parameters:
      - in: path
        name: resourceId
        required: true
        schema:
          type: string
      - description: API version to use for this request
        in: header
        name: X-XBOW-API-Version
        required: true
        schema:
          enum:
          - '2026-07-01'
          example: '2026-07-01'
          type: string
      requestBody:
        content:
          application/json:
            schema:
              example:
                parts:
                - 1
                - 2
                - 3
              properties:
                parts:
                  items:
                    maximum: 9007199254740991
                    minimum: 1
                    type: integer
                  type: array
              required:
              - parts
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                example:
                  parts:
                  - expiresAt: '2026-05-11T08:14:23.976Z'
                    partNumber: 1
                    url: https://presignedurl.amazonaws.com/upload?partNumber=1&uploadId=abc123
                  storageProtocol: S3
                properties:
                  parts:
                    items:
                      properties:
                        expiresAt:
                          format: date-time
                          type: string
                        partNumber:
                          maximum: 9007199254740991
                          minimum: -9007199254740991
                          type: integer
                        url:
                          type: string
                      required:
                      - expiresAt
                      - partNumber
                      - url
                      type: object
                    type: array
                  storageProtocol:
                    enum:
                    - S3
                    type: string
                required:
                - parts
                - storageProtocol
                type: object
          description: Default Response
        '400':
          content:
            application/json:
              schema:
                properties:
                  code:
                    description: A constant for machines
                    enum:
                    - FST_ERR_VALIDATION
                    type: string
                  error:
                    description: A human readable string for the constant
                    enum:
                    - Bad Request
                    type: string
                  message:
                    description: A human readable message
                    type: string
                  requestId:
                    description: A unique identifier for the request
                    type: string
                required:
                - code
                - error
                - message
                - requestId
                type: object
          description: Default Response
        '404':
          content:
            application/json:
              schema:
                properties:
                  code:
                    description: A constant for machines
                    enum:
                    - ERR_NOT_FOUND
                    type: string
                  error:
                    description: A human readable string for the constant
                    enum:
                    - Not Found
                    type: string
                  message:
                    description: A human readable message
                    type: string
                  requestId:
                    description: A unique identifier for the request
                    type: string
                required:
                - code
                - error
                - message
                - requestId
                type: object
          description: The requested resource was not found
        '409':
          content:
            application/json:
              schema:
                properties:
                  code:
                    description: A constant for machines
                    enum:
                    - ERR_CONFLICT
                    type: string
                  error:
                    description: A human readable string for the constant
                    enum:
                    - Conflict
                    type: string
                  message:
                    description: A human readable message
                    type: string
                  requestId:
                    description: A unique identifier for the request
                    type: string
                required:
                - code
                - error
                - message
                - requestId
                type: object
          description: The resource already exists
      security:
      - Authorization: []
      summary: Get resource part upload URLs
      tags:
      - Resources
      operationId: postApiV1ResourcesByResourceIdParts
      x-operation-id-source: derived
components:
  securitySchemes:
    Authorization:
      bearerFormat: API Key
      description: Authorization header with Bearer token
      scheme: bearer
      type: http