openapi: 3.2.0 info: title: AppOmni AI Marlin AI API description: 'Marlin AI autonomous analysis plans and the AgentGuard prompt classification endpoint. Derived faithfully from the AppOmni public Postman collection published by AppOmni at https://api.appomni.com/ — every path, method, parameter, request body and example response below is taken verbatim from that collection. No operation was invented.' version: 1.0.0 contact: name: AppOmni url: https://appomni.com/support/ license: name: Proprietary url: https://appomni.com/terms-of-service/ x-generated-from: AppOmni public Postman collection (publishedId 2sBXc7Mjib) + AppOmni's published @appomni/n8n-nodes-agentguard source x-generated-source: https://api.appomni.com/api/collections/45135595/2sBXc7Mjib?segregateAuth=true&versionTag=latest x-generated-method: derived x-generated-date: '2026-09-04' servers: - url: https://{instance}.appomni.com description: AppOmni tenant. Replace {instance} with your AppOmni subdomain — e.g. `acme` if you log in at acme.appomni.com. variables: instance: default: example description: Your AppOmni tenant subdomain security: - bearerAuth: [] tags: - name: Marlin AI description: Marlin AI is an autonomous SaaS security AI that runs platform-wide deep analyses and correlations automatically across security observations in the AppOmni platform paths: /api/v1/ai/marlin/plans/analysis/latest/: get: operationId: marlinAIResults summary: Marlin AI results tags: - Marlin AI description: 'Returns a paginated list of the latest Marlin AI results in your environment. Each entry includes metadata such as playbook_id, playbook_name, playbook_description, created_at, risk_classification, ms_types, final_analysis, remediation_suggestions, summary Response Fields Field Data Type Description Example playbook_id String Unique identifier for the playbook. This is an AppOmni internal ID ms_errors playbook_name String Name of the playbook as seen in the UI Summary on monitored services disconnection issues playbook_description String Short description about what the playbook does This playbook runs once per day and summarizes connection issues found on up to 20 monitored services. The monitored services are chosen based on the largest posture coverage. created_at String (ISO datetime) Timestamp when the playbook run was created 2022-11-29T05:56:26.372253Z ms_types Array [String] List with type of service analyzed (e.g., box, github) [''smartsheet'', ''github'', ''asana'', ''sfdc'', ''confluence'', ''zendesk''] final_analysis String Text output of Marlin AI analysis These services have lost their connection to AppOmni, preventing continuous monitoring remediation_suggestions String Text output with remediation suggestions based on the data analyzed This suggests a missing permission set required for the Salesforce integration. Contact user@appomni.com to re-establish the connection summary String Text summary that shows on Marlin AI cards SaaS Monitoring Connection Issues.14 monitored services were analyzed, with 10 disconnected and 3 degraded risk_classification String risk set by Marlin AI based on what was found on its investigation high' responses: '200': description: Get Marlin AI results content: text/plain: schema: type: string example: "{\n \"results\": [\n {\n \"analysis_output\": {\n \"plan_id\": \"e73fe289-a451-44de-8e26-d7658b96fdf5\",\n \"final_analysis\": \"**Data analyzed:** 2651 occurrences and 20 findings related to inactive users were analyzed across your AppOmni environment. No specific links to the analyzed data are available in this output.\\n\\nThis analysis focused on identifying and reducing noise from overlapping insights related to inactive users within your production environment. The goal was to streamline your security posture by pinpointing redundant findings that can be safely closed, thereby improving operational efficiency for your SOC team. This process does not identify new cybersecurity threats but rather optimizes the management of existing observations.\\n\\n**Key findings:**\\n* **1311 occurrences** can be closed due to coverage overlap.\\n* **12 findings** can be closed due to coverage overlap.\\n\\nThis optimization applies to insights found across the following monitored services: **GSuite, iManage, O365, Okta, and SFMC**.\",\n \"remediation_suggestions\": \"To enhance your team's focus and reduce alert fatigue, prioritize the following actions:\\n\\n* **Review and Close Findings:** Access the Posture Findings interface in AppOmni and review the 12 identified findings and 1311 occurrences related to inactive users that have been marked for closure due to coverage overlap. Confirm their redundancy and proceed with dismissing or closing" '401': description: Unauthorized — missing or invalid AppOmni API token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden — the token lacks permission for this resource content: application/json: schema: $ref: '#/components/schemas/Error' components: schemas: Error: type: object title: Error description: Standard Django REST Framework error envelope returned by the AppOmni API. properties: detail: type: string description: Human readable error message securitySchemes: bearerAuth: type: http scheme: bearer description: 'AppOmni API access token, created and managed in the AppOmni platform under Settings > API Settings. Sent as `Authorization: Bearer `.' ingestToken: type: apiKey in: header name: X-AppOmni-Ingest-Token description: AppOmni-issued ingest token used by AgentGuard and the AODP ingest endpoint. Sent as the `X-AppOmni-Ingest-Token` request header.