Filigran · AsyncAPI Specification
Filigran Opencti Webhooks
Version
View Spec
View on GitHub
CompanyCybersecurityThreat IntelligenceOpenCTIOpenAEVSTIXGraphQLBreach and Attack SimulationOpen-SourceSecurityAsyncAPIEvents
AsyncAPI Specification
generated: '2026-07-19'
method: searched
type: Webhooks
source: https://docs.opencti.io/latest/administration/notifiers/ ; https://docs.opencti.io/latest/reference/streaming/
summary: >-
OpenCTI exposes a real-time event surface. It is not published as an AsyncAPI
document, so this artifact captures the webhook + streaming catalog rather than
a spec. NEVER fabricated — derived from Filigran's documented event surfaces.
event_surfaces:
- kind: webhook
name: Notifier connector (webhooks)
since: OpenCTI 5.10
docs: https://docs.opencti.io/latest/administration/notifiers/
description: >-
The notifier connector sends notifications to external services via HTTP.
Configurable verb (GET/POST/PUT/DELETE), destination URL, and a message
template. Webhooks are triggered from triggers and digests.
- kind: sse-stream
name: Live streams (Server-Sent Events)
endpoint: /stream
docs: https://docs.opencti.io/latest/reference/streaming/
description: >-
SSE connection delivering a real-time pure STIX 2.1 event stream; live
streams resolve relationships/dependencies beyond plain TAXII.
- kind: taxii
name: TAXII 2.1 server
docs: https://docs.opencti.io/latest/reference/streaming/
description: >-
OpenCTI implements a TAXII 2.1 server with as many collections as needed for
STIX 2.1 bundle sharing.
asyncapi_spec:
published: false
note: No provider-published AsyncAPI document found; webhook/stream catalog captured instead.
Work with this as data
Every AsyncAPI spec here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for asyncapi
4 MCP tools reach this
find_asyncapisBrowse and filter every AsyncAPI spec in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This AsyncAPI spec
curl "https://apis.io/api/v1/asyncapis/filigran-opencti-webhooks"
All asyncapi
curl "https://apis.io/api/v1/asyncapis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.