ReliaQuest · Postman Collection

GreyMatter API

Introduction

The GreyMatter API provides access to select GreyMatter capabilities through a GraphQL interface. All API interactions occur over a secure HTTPS connection to a single endpoint. Requests are made using the POST HTTPS method with JSON-encoded bodies, and the API returns JSON-encoded responses. We use standard

64
Folders
View on GitHub Raw JSON CybersecuritySecurity OperationsThreat DetectionIncident ResponseThreat IntelligenceDigital Risk ProtectionAgentic AIGraphQLPostman Collection

Overview

GreyMatter API is a Postman Collection published by ReliaQuest on the APIs.io network.

Introduction

The GreyMatter API provides access to select GreyMatter capabilities through a GraphQL interface. All API interactions occur over a secure HTTPS connection to a single endpoint. Requests are made using the POST HTTPS method with JSON-encoded bodies, and the API returns JSON-encoded responses. We use standard <a href=" The collection contains 153 requests organised into 64 folders. Tagged areas include Cybersecurity, Security Operations, Threat Detection, Incident Response, and Threat Intelligence.

Requests & Folders

Access Groups

Permission

Represents a permission

<
API Keys

ApiKey

Represents an API Key with associated metadata.

Field Description Type
Field Description T
Assets

Asset

Details of Asset

<
Cases

CaseBy

Search for a Case by one and only one of the below

Field Description Type
Change Control

DetectionChangeRequest

A request to change a customer detection — to create, enable, disable, or tune it — awaiting or having completed customer review.

Customer

Customer

Customer schema.

Field Description
Data

TimeBucketsFilter

Represents Time bucket filter schema

Field Description Type
Field Description
Detections

DetectionRuleConnection

Represents a paginated list of detection rules.

Fie
Discover Tasks

DiscoverTaskBy

Retreive a Discover Task by one and only one of the below

DRP Access Control

AccessControlPolicy

Schema for an Access Control Policy.

Field
Field Descrip
DRP Alerts

AddDrpAlertCommentResponse

DrpAlertCommentResponse schema.

<
Emergency Contacts

EmergencyContactOrderBy

OrderBy ENUM for Emergency Contacts

Field
Value
Fields

GreyMatterFieldBy

Input type to get GreyMatterField by either field ID or field name. This input is annotated with @oneOf directive so only one field should be prov

Identities

Identity

Details of Identity

Incidents

IncidentFilter

Incident Filter input type to filter out Incidents. If not set, defaults will be used. Defaults: state = NEW

Indicators

Indicator

Represents an Indicator type.

Field Description Type
Memory

AiContext

Context injected into AI prompts and tools. Used to provide memories or guidance to AI operations.

Playbooks

RecommendedPlaybooks

Type representing recommended playbooks response

Field Description Type
Field
Query Management

IntegrationFilter

Input type used to filter integrations based on specific criteria.

Reference Lists

ReferenceList

Represents a Reference List type.

Field Description T

Related API Specs

Work with this as data

Every collection here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for collections

4 MCP tools reach this
  • find_collectionsBrowse and filter every collection in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This collection
curl "https://apis.io/api/v1/collections/postman-reliaquest-greymatter-api"
All collections
curl "https://apis.io/api/v1/collections?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.