# Cisco XDR

**Canonical:** https://apis.io/providers/cisco-xdr/  
**Website:** https://www.cisco.com/site/us/en/products/security/xdr/index.html  
**APIs profiled:** 50

Cisco XDR is Cisco's extended detection and response platform, the successor to SecureX. It correlates telemetry from Cisco Secure Endpoint, Secure Firewall, Umbrella, Duo, Secure Email and third-party sources into incidents, and exposes four distinct REST API families behind a single OAuth 2.0 authorization server: the IROH platform (inspect, enrich, response actions, integration modules, events, webhooks) at visibility.amp.cisco.com, the CTIA private-intelligence store at private.intel.amp.cisco.com, the Conure v2 incidents and investigations service at conure.us.security.cisco.com, and the Automation workflow engine at automate.us.security.cisco.com. All four publish anonymously fetchable machine-readable contracts — 52 documents, 581 operations, 1,176 schema definitions — and Cisco additionally ships a 27-tool MCP server through CiscoDevNet, stdio-only. There is no sandbox, no test mode and no idempotency key anywhere, including on the operation that blocks, isolates and quarantines.

## Kin Score — 65.6 / 100 (strong)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 65.6).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 58.4 |
| Governance | 16.7 |
| Contract Governance | 16.7 |
| Operational Transparency | 86.8 |
| Developer Ergonomics | 66.1 |
| Commercial Clarity | 81.6 |
| Access Clarity | 81.6 |

## Agent readiness — 49.2 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | derived |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | yes |

## APIs (50)

- **Cisco XDR Actor API** — Actor operations
- **Cisco XDR Asset API** — Asset operations
- **Cisco XDR Asset Mapping API** — Asset Mapping operations
- **Cisco XDR Asset Properties API** — Asset Properties operations
- **Cisco XDR Attack Pattern API** — Attack Pattern operations
- **Cisco XDR Bulk API** — The Bulk API from Cisco XDR — 1 operation(s) for bulk.
- **Cisco XDR Bundle API** — The Bundle API from Cisco XDR — 2 operation(s) for bundle.
- **Cisco XDR Campaign API** — Campaign operations
- **Cisco XDR Casebook API** — Casebook operations
- **Cisco XDR COA API** — COA operations
- **Cisco XDR Deliberate API** — This set of routes allow to quickly get answers from your integrations You might use them at the start of any investigation to quickly get answers from your modules if something...
- **Cisco XDR Event API** — Events operations
- **Cisco XDR Feed API** — Feed operations
- **Cisco XDR Feedback API** — Feedback Routes
- **Cisco XDR Graph QL API** — The GraphQL API from Cisco XDR — 1 operation(s) for graphql.
- **Cisco XDR Health API** — This set of routes allow to check the health of your integrations setup Verify if your modules are setup correctly and if your credentials are correct.
- **Cisco XDR Incident API** — Incident operations
- **Cisco XDR Indicator API** — Indicator operations
- **Cisco XDR Inspect API** — Inspect related routes
- **Cisco XDR Investigation API** — The Investigation API from Cisco XDR — 8 operation(s) for investigation.
- **Cisco XDR INVITE API** — The INVITE API from Cisco XDR — 2 operation(s) for invite.
- **Cisco XDR Iroh API** — The Iroh API from Cisco XDR — 3 operation(s) for iroh.
- **Cisco XDR Judgement API** — Judgement operations
- **Cisco XDR LOGIN API** — The LOGIN API from Cisco XDR — 4 operation(s) for login.
- **Cisco XDR Malware API** — Malware operations
- **Cisco XDR Metrics API** — The Metrics API from Cisco XDR — 1 operation(s) for metrics.
- **Cisco XDR Module Instance API** — ModuleInstance Routes
- **Cisco XDR Module Type API** — ModuleType Routes
- **Cisco XDR Module Type Patch API** — ModuleTypePatch Routes
- **Cisco XDR Note API** — The Note API from Cisco XDR — 8 operation(s) for note.
- **Cisco XDR Observe API** — This set of routes allow to get in depth investigation data about a threat You might use them at the start of any investigation to get the full picture and get to know if someth...
- **Cisco XDR One Click API** — One-click Routes
- **Cisco XDR Private Intel API** — Access private-intel
- **Cisco XDR Properties API** — The Properties API from Cisco XDR — 1 operation(s) for properties.
- **Cisco XDR Query API** — This set of routes allow to query for records related to observable events.Results are returned in OCSF format.
- **Cisco XDR Refer API** — This set of routes allow to get relevant Reference links and quickly pivot pursuing your investigation on a specific product interface.
- **Cisco XDR Relationship API** — Relationship operations
- **Cisco XDR Reputation API** — The Reputation API from Cisco XDR — 1 operation(s) for reputation.
- **Cisco XDR Response API** — IROH Response
- **Cisco XDR Session Cookie API** — Cookie-based session validation
- …and 10 more, listed in full on the page.

## MCP servers (2)

- **Cisco XDR MCP Server**
- **Cisco XDR MCP Server**

## Security (4)

- **Cisco Xdr Authentication** — apiKey/oauth2 · 4 schemes
- **Cisco Xdr Domain Security** — TLSv1.3 · HSTS · DMARC
- **Cisco Xdr Vulnerability Disclosure** — security.txt · contact published
- **Cisco Xdr Trust Center** — ISO 27001, FedRAMP, GDPR, SOC 2, BSI C5

## Plans (1)

- **Cisco Xdr Plans Pricing**

## Tags

Security, XDR, Threat Detection, Incident Response, SOC, Threat Intelligence, Extended Detection and Response, Authentication, Webhook, Automation, MCP

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/cisco-xdr/). Scores are computed from the provider's own public artifacts under a published rubric.
