Get started with Cortex XDR 5.x APIs
Using the Cortex XDR APIs, you can integrate Cortex XDR with third-party apps or services to ingest alerts, manage incidents, and perform response actions programmatically. The APIs let you build integrations that extend Cortex XDR across your detection and response workflows.
Before you can begin using Cortex XDR APIs, you must generate the following items in Cortex XDR:
API Key
The API Key is your unique identifier used as the Authorization:{key} header required for authenticating API calls. Depending on your desired security level, you can generate two types of API keys, Advanced or Standard, from Cortex XDR.
API Key ID
The API Key ID is your unique token used to authenticate the API Key. The header used when running an API call is x-xdr-auth-id:{key_id}.
FQDN
The FQDN is a unique host and domain name associated with each tenant.
Cortex XDR API URIs are made up of your tenant's FQDN, the API name, and endpoint path. For example, https://api-{fqdn}/XDR/public/v1/{endpoint_path}/.
The following steps describe how to generate the necessary key values and run your first API call:
Last updated
Was this helpful?
