GPSS ONE API v1.0.0

Multi-tenant security operations API. Every token is scoped to one organization and to a set of abilities. Base URL: https://app.gpssone.com/api/v1 · openapi.json

curl -H "Authorization: Bearer sntl_<org>_<token>" https://app.gpssone.com/api/v1/incidents?status=open
GET/healthHealth
Service health and API version.
Parameters: limit(query) cursor(query)
GET/posturePosture · scans.view
Security posture summary (score, vulnerabilities, incidents, SLA).
Parameters: limit(query) cursor(query)
GET/incidentsIncidents · scans.view
List incidents (cursor paginated). Filters: status, severity, category, source, q, since.
Parameters: limit(query) cursor(query)
POST/incidentsIncidents · scans.run
Open an incident manually.
{
    "type": "object",
    "required": [
        "title",
        "severity"
    ],
    "properties": {
        "title": {
            "type": "string"
        },
        "severity": {
            "type": "string",
            "enum": [
                "critical",
                "high",
                "medium",
                "low",
                "info"
            ]
        },
        "asset": {
            "type": "string"
        },
        "description": {
            "type": "string"
        },
        "category": {
            "type": "string"
        }
    }
}
GET/incidents/{id}Incidents · scans.view
Incident detail with linked alerts, IOCs, tasks and timeline. Supports ETag / If-None-Match.
Parameters: id(path)
PATCH/incidents/{id}/statusIncidents · scans.run
Transition incident status.
Parameters: id(path)
{
    "type": "object",
    "required": [
        "status"
    ],
    "properties": {
        "status": {
            "type": "string"
        },
        "note": {
            "type": "string"
        }
    }
}
POST/incidents/{id}/notesIncidents · scans.run
Append a timeline note.
Parameters: id(path)
{
    "type": "object",
    "required": [
        "message"
    ],
    "properties": {
        "message": {
            "type": "string"
        }
    }
}
GET/alertsAlerts · scans.view
Live SIEM alerts aggregated from the organization connectors. Filter: severity.
Parameters: limit(query) cursor(query)
GET/vulnerabilitiesVulnerabilities · scans.view
List findings (cursor paginated). Filters: status, severity, category, cve, target, priority_min, kev.
Parameters: limit(query) cursor(query)
GET/vulnerabilities/{id}Vulnerabilities · scans.view
Finding detail with evidence and validation. Supports ETag.
Parameters: id(path)
PATCH/vulnerabilities/{id}/statusVulnerabilities · scans.run
Set finding status (open, remediated, false_positive, accepted).
Parameters: id(path)
{
    "type": "object",
    "required": [
        "status"
    ],
    "properties": {
        "status": {
            "type": "string"
        },
        "note": {
            "type": "string"
        }
    }
}
GET/scansScans · scans.view
List scans (cursor paginated).
Parameters: limit(query) cursor(query)
POST/scansScans · scans.run
Queue a scan on a verified target.
{
    "type": "object",
    "required": [
        "runner",
        "target"
    ],
    "properties": {
        "runner": {
            "type": "string"
        },
        "target": {
            "type": "string"
        }
    }
}
GET/scans/{id}Scans · scans.view
Scan detail with result.
Parameters: id(path)
GET/targetsTargets · scans.view
List scan targets and their verification status.
Parameters: limit(query) cursor(query)
POST/targetsTargets · targets.manage
Register a target; it must be verified (DNS TXT or signed agreement) before scanning.
{
    "type": "object",
    "required": [
        "host"
    ],
    "properties": {
        "host": {
            "type": "string"
        },
        "label": {
            "type": "string"
        }
    }
}
GET/targets/{id}/verificationTargets · scans.view
Verification status and the DNS TXT challenge to publish.
Parameters: id(path)
GET/iocs/lookupIndicators · scans.view
Enrich an indicator (type: ip, domain, hash, cve) with local and intelligence context.
Parameters: limit(query) cursor(query) type(query) value(query)
GET/response/actionsResponse · scans.view
List containment actions. Approval is only possible from the UI with re-authentication.
Parameters: limit(query) cursor(query)
POST/response/actionsResponse · response.request
Request a containment action (pending human approval).
{
    "type": "object",
    "required": [
        "type",
        "target",
        "connector_id"
    ],
    "properties": {
        "type": {
            "type": "string"
        },
        "target": {
            "type": "string"
        },
        "connector_id": {
            "type": "integer"
        },
        "incident_id": {
            "type": "integer"
        },
        "reason": {
            "type": "string"
        },
        "ttl_minutes": {
            "type": "integer"
        }
    }
}
GET/reportsReports · scans.view
List generated reports.
Parameters: limit(query) cursor(query)
GET/reports/{id}/downloadReports · scans.view
Download a generated report (integrity verified).
Parameters: id(path)