How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Cisco XDR

Cisco XDR is Cisco's extended detection and response platform, the successor to SecureX. It correlates telemetry from Cisco Secure Endpoint, Secure Firewall, Umbrella, Duo, Secure Email and third-party sources into incidents, and exposes four distinct REST API families behind a single OAuth 2.0 authorization server: the IROH platform (inspect, enrich, response actions, integration modules, events, webhooks) at visibility.amp.cisco.com, the CTIA private-intelligence store at private.intel.amp.cisco.com, the Conure v2 incidents and investigations service at conure.us.security.cisco.com, and the Automation workflow engine at automate.us.security.cisco.com. All four publish anonymously fetchable machine-readable contracts — 52 documents, 581 operations, 1,176 schema definitions — and Cisco additionally ships a 27-tool MCP server through CiscoDevNet, stdio-only. There is no sandbox, no test mode and no idempotency key anywhere, including on the operation that blocks, isolates and quarantines.

agent ready

Solid contracts, transparent operations, and an easy start — typically complete on four or five facets with one clear soft spot.

Kin Score

API Evangelist profiles Cisco XDR the way a machine reads it — 60 machine-readable artifacts across 50 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Cisco XDR scores 61.9/100 (strong), with a separate agent-readiness read of 49/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-08-24 · rubric v0.12.1
Composite quality — 61.9/100 · strong
Contract Quality 14.6 / 25
Developer Ergonomics 13.2 / 20
Access Clarity 15.0 / 20
Operational Transparency 8.9 / 13
Contract Governance 2.0 / 12
Discoverability 8.2 / 10
Agent readiness — 49/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 10
Documented Reversibility 0 / 6
MCP Server documented 4.8 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8.0 / 8
Request/Response Examples partial 3.5 / 7
Rate-Limit Signaling documented 3.5 / 7
Typed Event Surface derived 1.5 / 6
Agent Skills derived 1.3 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 3 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 4 / 4
Cisco XDR Kin Score — API readiness rating by API Evangelist

Put this on your own site. The badge is drawn live from Cisco XDR's current Kin Score — paste it once and it updates itself every time the score is recomputed. It follows your visitor's light or dark setting, and it links back here so anyone who sees it can read the full breakdown.

<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/cisco-xdr/"
   title="Cisco XDR on API Evangelist — API profile and Kin Score">
  <img src="https://apis.io/badge/cisco-xdr.svg"
       alt="Cisco XDR Kin Score — API readiness rating by API Evangelist" width="150" height="150" loading="lazy">
</a>

More shapes, themes and sizes → · Score as JSON · How badges work

How we profile Cisco XDR

Each block below is one kind of artifact we hold for Cisco XDR. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 50

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

Cisco XDR Actor API

Actor operations

Cisco XDR Asset API

Asset operations

Cisco XDR Asset Mapping API

Asset Mapping operations

Cisco XDR Asset Properties API

Asset Properties operations

Cisco XDR Attack Pattern API

Attack Pattern operations

Cisco XDR Bulk API

The Bulk API from Cisco XDR — 1 operation(s) for bulk.

Cisco XDR Bundle API

The Bundle API from Cisco XDR — 2 operation(s) for bundle.

Cisco XDR Campaign API

Campaign operations

Cisco XDR Casebook API

Casebook operations

Cisco XDR COA API

COA operations

Cisco XDR Deliberate API

This set of routes allow to quickly get answers from your integrations You might use them at the start of any investigation to quickly get answers from your modules if something...

Cisco XDR Event API

Events operations

Cisco XDR Feed API

Feed operations

Cisco XDR Feedback API

Feedback Routes

Cisco XDR Graph QL API

The GraphQL API from Cisco XDR — 1 operation(s) for graphql.

Cisco XDR Health API

This set of routes allow to check the health of your integrations setup Verify if your modules are setup correctly and if your credentials are correct.

Cisco XDR Incident API

Incident operations

Cisco XDR Indicator API

Indicator operations

Cisco XDR Inspect API

Inspect related routes

Cisco XDR Investigation API

The Investigation API from Cisco XDR — 8 operation(s) for investigation.

Cisco XDR INVITE API

The INVITE API from Cisco XDR — 2 operation(s) for invite.

Cisco XDR Iroh API

The Iroh API from Cisco XDR — 3 operation(s) for iroh.

Cisco XDR Judgement API

Judgement operations

Cisco XDR LOGIN API

The LOGIN API from Cisco XDR — 4 operation(s) for login.

Cisco XDR Malware API

Malware operations

Cisco XDR Metrics API

The Metrics API from Cisco XDR — 1 operation(s) for metrics.

Cisco XDR Module Instance API

ModuleInstance Routes

Cisco XDR Module Type API

ModuleType Routes

Cisco XDR Module Type Patch API

ModuleTypePatch Routes

Cisco XDR Note API

The Note API from Cisco XDR — 8 operation(s) for note.

Cisco XDR Observe API

This set of routes allow to get in depth investigation data about a threat You might use them at the start of any investigation to get the full picture and get to know if someth...

Cisco XDR One Click API

One-click Routes

Cisco XDR Private Intel API

Access private-intel

Cisco XDR Properties API

The Properties API from Cisco XDR — 1 operation(s) for properties.

Cisco XDR Query API

This set of routes allow to query for records related to observable events.Results are returned in OCSF format.

Cisco XDR Refer API

This set of routes allow to get relevant Reference links and quickly pivot pursuing your investigation on a specific product interface.

Cisco XDR Relationship API

Relationship operations

Cisco XDR Reputation API

The Reputation API from Cisco XDR — 1 operation(s) for reputation.

Cisco XDR Response API

IROH Response

Cisco XDR Session Cookie API

Cookie-based session validation

Cisco XDR Sighting API

Sighting operations

Cisco XDR Status API

The Status API from Cisco XDR — 1 operation(s) for status.

Cisco XDR Target Record API

Target Record operations

Cisco XDR Tool API

Tool operations

Cisco XDR Verdict API

The Verdict API from Cisco XDR — 1 operation(s) for verdict.

Cisco XDR Version API

The Version API from Cisco XDR — 1 operation(s) for version.

Cisco XDR Vulnerability API

The Vulnerability API from Cisco XDR — 9 operation(s) for vulnerability.

Cisco XDR Webhook API

Webhook Routes

Cisco XDR Webhook Result API

The WebhookResult API from Cisco XDR — 2 operation(s) for webhookresult.

Cisco XDR MCP Server

Model Context Protocol server published by CiscoDevNet exposing 27 Cisco XDR tools across Inspect, Investigate, Incidents, Response Actions, Casebooks, Threat Intel, Workflows a...

Scroll within the panel for all 50 ·

MCP Servers 2

Model Context Protocol servers expose these APIs directly to AI agents. We profile them because agent-native access is the fastest-growing way this provider's capabilities actually get used.

Model Context Protocol servers that expose these APIs to AI agents.

Pricing Plans 1

Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the things the Kin Score reads for access clarity — renamed from commercial clarity in rubric 0.12, because a free statutory interface has access terms and no commercial ones.

Published pricing tiers and plan structures.

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Cisco Xdr Rate Limits

5 limits

RATE LIMITS

Event Specifications 1

Not every API is request/response. AsyncAPI describes the event-driven and streaming side — the webhooks and channels — so the asynchronous half of the interface is documented the same way the synchronous half is.

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Cisco Xdr Authentication

apiKey/oauth2 · 4 schemes

SECURITY

Cisco Xdr Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Cisco Xdr Vulnerability Disclosure

security.txt · contact published

SECURITY

Cisco Xdr Trust Center

ISO 27001, FedRAMP, GDPR, SOC 2, BSI C5

SECURITY

Scopes 1

OAuth scopes are the vocabulary of least-privilege access. Profiling them shows exactly what an integration — or an agent acting on a user's behalf — is allowed to do.

OAuth scopes governing access to this provider's APIs.

Cisco Xdr Scopes

41 scopes · authorizationCode/clientCredentials

41 scopes

SCOPES

Resources

Every other property we hold for Cisco XDR — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Documentation 4

Reference material describing how the API behaves

Agent Surfaces 5

MCP servers, agent skills, and machine-readable catalogs

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

← All providers · Data indexed from github.com/api-evangelist/cisco-xdr · machine-readable index on apis.io

Where this information came from

This is an independent, third-party profile of Cisco XDR, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.