aid: airmdr name: AirMDR description: >- AirMDR is an AI-native managed detection and response (MDR) provider whose virtual security analyst, Darryl, automates alert triage, investigation and response across endpoint, cloud, SaaS, identity, email and network tools. The platform ingests alerts from 200+ integrations, runs automated or AI-generated investigation playbooks, and produces documented cases; it is sold as a full-service MDR for small security teams, an AI SOC platform for MSSPs and enterprise SOCs, and a free plan with 100 alert investigations. Programmatic access is a REST API on app.airmdr.com (Case Manager and User Management services, documented in Redoc), authenticated with an API token sent as a Session cookie, plus a webhook endpoint for pushing alerts into the platform. image: https://airmdr.com/hubfs/Favicon.png url: https://raw.githubusercontent.com/api-evangelist/airmdr/refs/heads/main/apis.yml x-type: company x-source: harvest:secondary-market x-tier: profiled x-tier-reason: harvest specificationVersion: '0.20' created: '2026-09-19' modified: '2026-09-19' x-docs-platform: mintlify x-docs-platform-confidence: medium x-docs-platform-checked: 2026-09-19 x-docs-hosting: vercel tags: - Security - Managed Detection and Response - Security Operations - Alert Triage - Incident Response - AI Agents - SOC Automation - Threat Detection - MCP - A2A apis: - name: AirMDR Documentation MCP Server description: >- Hosted, unauthenticated Streamable-HTTP MCP server on the AirMDR documentation host (Mintlify-operated) exposing three tools: search the AirMDR documentation, run read-only queries against a virtual filesystem of the docs pages, and submit documentation feedback. It documents the platform; it does not call the Case Manager or User Management APIs. humanURL: https://docs.airmdr.com/ baseURL: https://docs.airmdr.com/mcp tags: - MCP - Documentation - Security properties: - type: MCPServer url: mcp/airmdr-mcp.yml - type: MCPServer url: https://docs.airmdr.com/mcp - type: Documentation url: https://docs.airmdr.com/ - aid: airmdr:airmdr-alertcatalog-api name: AirMDR Alert Catalog API description: The AlertCatalog API from AirMDR — 8 operation(s) for alertcatalog. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - AlertCatalog properties: - type: OpenAPI url: openapi/airmdr-alertcatalog-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-alerts-api name: AirMDR Alerts API description: The Alerts API from AirMDR — 15 operation(s) for alerts. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Alerts properties: - type: OpenAPI url: openapi/airmdr-alerts-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-alerttypes-api name: AirMDR Alert Types API description: The AlertTypes API from AirMDR — 3 operation(s) for alerttypes. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - AlertTypes properties: - type: OpenAPI url: openapi/airmdr-alerttypes-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-case-manager-api name: AirMDR Case Manager API description: The Case Manager API from AirMDR — 32 operation(s) for case manager. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Case Manager properties: - type: OpenAPI url: openapi/airmdr-case-manager-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-case-manager-internal-api name: AirMDR Case Manager Internal API description: The Case Manager Internal API from AirMDR — 10 operation(s) for case manager internal. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Case Manager Internal properties: - type: OpenAPI url: openapi/airmdr-case-manager-internal-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-case-manager-v2-api name: AirMDR Case Manager V2 API description: The Case Manager V2 API from AirMDR — 43 operation(s) for case manager v2. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Case Manager V2 properties: - type: OpenAPI url: openapi/airmdr-case-manager-v2-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-casedecisionautomation-api name: AirMDR Case Decision Automation API description: The CaseDecisionAutomation API from AirMDR — 4 operation(s) for casedecisionautomation. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - CaseDecisionAutomation properties: - type: OpenAPI url: openapi/airmdr-casedecisionautomation-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-dashboard-api name: AirMDR Dashboard API description: The Dashboard API from AirMDR — 20 operation(s) for dashboard. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Dashboards tags_raw: - Dashboard properties: - type: OpenAPI url: openapi/airmdr-dashboard-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-internal-api name: AirMDR Internal API description: The Internal API from AirMDR — 8 operation(s) for internal. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Internal properties: - type: OpenAPI url: openapi/airmdr-internal-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-mitretactics-api name: AirMDR Mitre Tactics API description: The MitreTactics API from AirMDR — 1 operation(s) for mitretactics. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - MitreTactics properties: - type: OpenAPI url: openapi/airmdr-mitretactics-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-organization-api name: AirMDR Organization API description: Endpoints to manage organizations humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Organization properties: - type: OpenAPI url: openapi/airmdr-organization-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-password-api name: AirMDR Password API description: Endpoints to manage user password humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Password properties: - type: OpenAPI url: openapi/airmdr-password-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-permission-api name: AirMDR Permission API description: Endpoints to read system permissions humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Permission properties: - type: OpenAPI url: openapi/airmdr-permission-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-ping-api name: AirMDR Ping API description: The Ping API from AirMDR — 1 operation(s) for ping. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Ping properties: - type: OpenAPI url: openapi/airmdr-ping-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-query-dsl-api name: AirMDR Query DSL API description: The Query DSL API from AirMDR — 3 operation(s) for query dsl. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Query DSL properties: - type: OpenAPI url: openapi/airmdr-query-dsl-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-security-review-api name: AirMDR Security Review API description: The Security Review API from AirMDR — 5 operation(s) for security review. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Security Review properties: - type: OpenAPI url: openapi/airmdr-security-review-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-session-api name: AirMDR Session API description: Endpoints to manage sessions humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Sessions tags_raw: - Session properties: - type: OpenAPI url: openapi/airmdr-session-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-token-api name: AirMDR Token API description: Endpoints to manage tokens humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Tokens tags_raw: - Token properties: - type: OpenAPI url: openapi/airmdr-token-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-trial-api name: AirMDR Trial API description: The Trial API from AirMDR — 1 operation(s) for trial. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Trial properties: - type: OpenAPI url: openapi/airmdr-trial-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-user-api name: AirMDR User API description: Endpoints to manager users humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - User properties: - type: OpenAPI url: openapi/airmdr-user-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-user-group-api name: AirMDR User Group API description: Endpoints to manage user groups humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - UserGroup tags_raw: - User Group properties: - type: OpenAPI url: openapi/airmdr-user-group-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html - aid: airmdr:airmdr-webhooks-api name: AirMDR Webhooks API description: The Webhooks API from AirMDR — 3 operation(s) for webhooks. humanURL: https://app.airmdr.com/docs/api/case_manager.html baseURL: https://app.airmdr.com/airmdrapi tags: - Webhook tags_raw: - Webhooks properties: - type: OpenAPI url: openapi/airmdr-webhooks-api-openapi.yml - type: Documentation url: https://docs.airmdr.com/api-reference/apilandingpage - type: APIReference url: https://app.airmdr.com/docs/api/case_manager.html - type: Documentation url: https://docs.airmdr.com/api-reference/apitoken - type: APIReference url: https://app.airmdr.com/docs/api/user_management_service.html maintainers: - FN: Kin Lane email: kin@apievangelist.com - FN: APIs.json email: info@apis.io common: - type: CapabilityMap url: capabilities/airmdr-capability-edges.yml name: AirMDR Business Capability Map - type: DomainSecurity url: security/airmdr-domain-security.yml - type: Authentication url: authentication/airmdr-authentication.yml - type: Website url: https://airmdr.com/ - type: DeveloperPortal url: https://docs.airmdr.com/ - type: Documentation url: https://docs.airmdr.com/essentials/Landingpage - type: APIReference url: https://docs.airmdr.com/api-reference/apilandingpage - type: GettingStarted url: https://docs.airmdr.com/api-reference/apitoken - type: Blog url: https://airmdr.com/blog - type: BlogRSS url: https://airmdr.com/blog/rss.xml - type: Newsroom url: https://airmdr.com/newsroom - type: Leadership url: https://airmdr.com/about-us - type: GitHubOrganization url: https://github.com/AirMDR - type: Pricing url: https://airmdr.com/pricing - type: Login url: https://app.airmdr.com/auth/login - type: PrivacyPolicy url: https://airmdr.com/privacy - type: Support url: https://airmdr.com/contact-us - type: ChangeLog url: https://docs.airmdr.com/changelog/changelog - type: LinkedIn url: https://www.linkedin.com/company/airmdr/ - type: Twitter url: https://twitter.com/AirMDR_Company - type: YouTube url: https://www.youtube.com/channel/UC_qHwQAACG8K20-X3JaB-yA - type: Packages url: packages/airmdr-packages.yml - type: WellKnown url: well-known/airmdr-well-known.yml - type: AgentCard url: a2a/airmdr-a2a.yml - type: MCPServer url: mcp/airmdr-mcp.yml - type: ToolCrosswalk url: mcp/airmdr-tool-crosswalk.yml - type: LLMsTxt url: llms/airmdr-llms.txt - type: LLMsTxt url: https://docs.airmdr.com/llms.txt - type: Overlay url: overlays/airmdr-case-manager-overlay.yaml - type: Overlay url: overlays/airmdr-user-management-service-overlay.yaml - type: Conformance url: conformance/airmdr-conformance.yml - type: ErrorCatalog url: errors/airmdr-problem-types.yml - type: Lifecycle url: lifecycle/airmdr-lifecycle.yml - type: Conventions url: conventions/airmdr-conventions.yml - type: DataModel url: data-model/airmdr-data-model.yml - type: ChangeLog url: changelog/airmdr-changelog.yml - type: Plans url: plans/airmdr-plans-pricing.yml - type: RateLimits url: rate-limits/airmdr-rate-limits.yml - type: Webhooks url: asyncapi/airmdr-webhooks.yml - type: AgentSkill url: skills/_index.yml - type: RegulatoryPosture url: regulatory/airmdr-regulatory-posture.yml x-enrichment: date: '2026-09-19' status: enriched artifacts_added: 27 pass: local-v3 x-a2a: verified: true probed: '2026-09-26' url: "https://docs.airmdr.com/.well-known/agent-card.json" grade: "conformant" protocol_version: "0.3" control: 404