Cisco XDR
Cisco XDR is Cisco's extended detection and response platform, the successor to SecureX. It correlates telemetry from Cisco Secure Endpoint, Secure Firewall, Umbrella, Duo, Secure Email and third-party sources into incidents, and exposes four distinct REST API families behind a single OAuth 2.0 authorization server: the IROH platform (inspect, enrich, response actions, integration modules, events, webhooks) at visibility.amp.cisco.com, the CTIA private-intelligence store at private.intel.amp.cisco.com, the Conure v2 incidents and investigations service at conure.us.security.cisco.com, and the Automation workflow engine at automate.us.security.cisco.com. All four publish anonymously fetchable machine-readable contracts — 52 documents, 581 operations, 1,176 schema definitions — and Cisco additionally ships a 27-tool MCP server through CiscoDevNet, stdio-only. There is no sandbox, no test mode and no idempotency key anywhere, including on the operation that blocks, isolates and quarantines.
Solid contracts, transparent operations, and an easy start — typically complete on four or five facets with one clear soft spot.
API Evangelist profiles Cisco XDR the way a machine reads it — 60 machine-readable artifacts across 50 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Cisco XDR scores 61.9/100 (strong), with a separate agent-readiness read of 49/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.
Put this on your own site. The badge is drawn live from Cisco XDR's current Kin Score — paste it once and it updates itself every time the score is recomputed. It follows your visitor's light or dark setting, and it links back here so anyone who sees it can read the full breakdown.
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/cisco-xdr/"
title="Cisco XDR on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/cisco-xdr.svg"
alt="Cisco XDR Kin Score — API readiness rating by API Evangelist" width="150" height="150" loading="lazy">
</a>
[](https://providers.apievangelist.com/providers/cisco-xdr/)
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/cisco-xdr/"
title="Cisco XDR on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/cisco-xdr/card.svg"
alt="Cisco XDR Kin Score — API readiness rating by API Evangelist" width="340" height="120" loading="lazy">
</a>
More shapes, themes and sizes → · Score as JSON · How badges work
How we profile Cisco XDR
Each block below is one kind of artifact we hold for Cisco XDR. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
APIs 50
Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.
Individual APIs this provider publishes, each with its own machine-readable definition.
Cisco XDR Actor API
Actor operations
Cisco XDR Asset API
Asset operations
Cisco XDR Asset Mapping API
Asset Mapping operations
Cisco XDR Asset Properties API
Asset Properties operations
Cisco XDR Attack Pattern API
Attack Pattern operations
Cisco XDR Bulk API
The Bulk API from Cisco XDR — 1 operation(s) for bulk.
Cisco XDR Bundle API
The Bundle API from Cisco XDR — 2 operation(s) for bundle.
Cisco XDR Campaign API
Campaign operations
Cisco XDR Casebook API
Casebook operations
Cisco XDR COA API
COA operations
Cisco XDR Deliberate API
This set of routes allow to quickly get answers from your integrations You might use them at the start of any investigation to quickly get answers from your modules if something...
Cisco XDR Event API
Events operations
Cisco XDR Feed API
Feed operations
Cisco XDR Feedback API
Feedback Routes
Cisco XDR Graph QL API
The GraphQL API from Cisco XDR — 1 operation(s) for graphql.
Cisco XDR Health API
This set of routes allow to check the health of your integrations setup Verify if your modules are setup correctly and if your credentials are correct.
Cisco XDR Incident API
Incident operations
Cisco XDR Indicator API
Indicator operations
Cisco XDR Inspect API
Inspect related routes
Cisco XDR Investigation API
The Investigation API from Cisco XDR — 8 operation(s) for investigation.
Cisco XDR INVITE API
The INVITE API from Cisco XDR — 2 operation(s) for invite.
Cisco XDR Iroh API
The Iroh API from Cisco XDR — 3 operation(s) for iroh.
Cisco XDR Judgement API
Judgement operations
Cisco XDR LOGIN API
The LOGIN API from Cisco XDR — 4 operation(s) for login.
Cisco XDR Malware API
Malware operations
Cisco XDR Metrics API
The Metrics API from Cisco XDR — 1 operation(s) for metrics.
Cisco XDR Module Instance API
ModuleInstance Routes
Cisco XDR Module Type API
ModuleType Routes
Cisco XDR Module Type Patch API
ModuleTypePatch Routes
Cisco XDR Note API
The Note API from Cisco XDR — 8 operation(s) for note.
Cisco XDR Observe API
This set of routes allow to get in depth investigation data about a threat You might use them at the start of any investigation to get the full picture and get to know if someth...
Cisco XDR One Click API
One-click Routes
Cisco XDR Private Intel API
Access private-intel
Cisco XDR Properties API
The Properties API from Cisco XDR — 1 operation(s) for properties.
Cisco XDR Query API
This set of routes allow to query for records related to observable events.Results are returned in OCSF format.
Cisco XDR Refer API
This set of routes allow to get relevant Reference links and quickly pivot pursuing your investigation on a specific product interface.
Cisco XDR Relationship API
Relationship operations
Cisco XDR Reputation API
The Reputation API from Cisco XDR — 1 operation(s) for reputation.
Cisco XDR Response API
IROH Response
Cisco XDR Session Cookie API
Cookie-based session validation
Cisco XDR Sighting API
Sighting operations
Cisco XDR Status API
The Status API from Cisco XDR — 1 operation(s) for status.
Cisco XDR Target Record API
Target Record operations
Cisco XDR Tool API
Tool operations
Cisco XDR Verdict API
The Verdict API from Cisco XDR — 1 operation(s) for verdict.
Cisco XDR Version API
The Version API from Cisco XDR — 1 operation(s) for version.
Cisco XDR Vulnerability API
The Vulnerability API from Cisco XDR — 9 operation(s) for vulnerability.
Cisco XDR Webhook API
Webhook Routes
Cisco XDR Webhook Result API
The WebhookResult API from Cisco XDR — 2 operation(s) for webhookresult.
Cisco XDR MCP Server
Model Context Protocol server published by CiscoDevNet exposing 27 Cisco XDR tools across Inspect, Investigate, Incidents, Response Actions, Casebooks, Threat Intel, Workflows a...
Scroll within the panel for all 50 ·
MCP Servers 2
Model Context Protocol servers expose these APIs directly to AI agents. We profile them because agent-native access is the fastest-growing way this provider's capabilities actually get used.
Model Context Protocol servers that expose these APIs to AI agents.
Cisco XDR MCP Server
MCP SERVERCisco XDR MCP Server
MCP SERVERPricing Plans 1
Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the things the Kin Score reads for access clarity — renamed from commercial clarity in rubric 0.12, because a free statutory interface has access terms and no commercial ones.
Published pricing tiers and plan structures.
Rate Limits 1
Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.
Documented rate limits and quota policies.
Cisco Xdr Rate Limits
RATE LIMITSEvent Specifications 1
Not every API is request/response. AsyncAPI describes the event-driven and streaming side — the webhooks and channels — so the asynchronous half of the interface is documented the same way the synchronous half is.
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Cisco Xdr Webhooks
ASYNCAPISecurity Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Scopes 1
OAuth scopes are the vocabulary of least-privilege access. Profiling them shows exactly what an integration — or an agent acting on a user's behalf — is allowed to do.
OAuth scopes governing access to this provider's APIs.
Resources
Every other property we hold for Cisco XDR — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 5
Portal, sign-up, and the first successful call
Documentation 4
Reference material describing how the API behaves
Agent Surfaces 5
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 8
Authentication, authorization, and security posture
Scroll within the panel for all 8 ·
Operate 6
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 5
Properties that don't map to a standard resource type
← All providers · Data indexed from github.com/api-evangelist/cisco-xdr · machine-readable index on apis.io
This is an independent, third-party profile of Cisco XDR, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.