Cisco XDR · OpenAPI Overlay 1.0.0

API Evangelist enhancements for Cisco XDR Inspect

2 actions 2 updates update extends openapi/cisco-xdr-inspect-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Cisco XDR's API. It is a proposal applied on top of the contract, not a document Cisco XDR publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-familyx-apievangelist-base-urlx-apievangelist-error-envelopex-apievangelist-notex-agentic-access

Targets 2

$.info
$.paths['/iroh/iroh-inspect/inspect'].post

OpenAPI Overlay

Raw ↑
overlay: 1.0.0
info:
  title: API Evangelist enhancements for Cisco XDR Inspect
  version: 1.0.0
x-generated: '2026-08-19'
x-method: generated
x-source: openapi/cisco-xdr-inspect-api-openapi.yml
extends: openapi/cisco-xdr-inspect-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-family: IROH platform
    x-apievangelist-base-url: https://visibility.amp.cisco.com/iroh
    x-apievangelist-error-envelope: iroh-normalized-error
    x-apievangelist-note: >-
      findObservables is the only operation in the entire IROH/CTIA/Conure surface that declares an
      operationId. Recorded here so downstream tooling does not assume operationIds are available.
- target: $.paths['/iroh/iroh-inspect/inspect'].post
  update:
    x-agentic-access:
      action_class: read
      consequence: none
      idempotent: true
      scope: inspect:read