openapi: 3.1.0 info: contact: email: support@censys.io name: Censys Support description: '# Asset Graph API The Asset Graph API provides comprehensive visibility into your Internet-facing assets. Use this API to build and manage attack surfaces by creating asset graphs, configuring seeds and exclusions, running discovery executions, and retrieving discovered assets and risk metadata. ### Authentication All requests must include a valid Censys personal access token (PAT) in the `Authorization` header: ``` Authorization: Bearer ``` An `X-Organization-ID` header must also be present on every request. This identifies the Censys organization that owns the resources being accessed. ``` X-Organization-ID: ``` ### Core Concepts - **Asset Graph**: The parent resource representing an attack surface. Each asset graph contains seeds, excluded assets, and executions. - **Seeds**: Persistent starting points used to discover additional assets. Supported types include IP addresses, domains, CIDRs, ASNs, certificates, and web properties. - **Excluded Assets**: Assets explicitly excluded from the graph. Excluded assets will not appear in execution results and will not be used to discover additional assets. - **Executions**: A discovery process that uses the graph''s configured seeds and excluded assets to generate a complete snapshot of the attack surface. Censys periodically runs executions in the background, or they can be triggered on-demand. - **Assets**: Internet-facing resources discovered during an execution, including hosts, domains, certificates, and web properties. Each asset includes discovery paths showing how it was found from your seeds. - **Risks**: Vulnerabilities, exposures, misconfigurations, and threats identified on discovered assets. ### Getting Started 1. **Create an asset graph** to represent your attack surface. 2. **Add seeds** — the known assets that Censys will use as starting points for discovery. 3. **Optionally add excluded assets** to omit specific assets from results. 4. **Create an execution** to trigger the discovery process, or wait for Censys to run one automatically. 5. **List assets** from a completed execution to view your discovered attack surface. 6. **Look up risk metadata** for any risk IDs found on your assets. ' title: Asset Graph Account Management Risks API version: 1.0.12 servers: - description: Asset Graph API url: https://graph.data.censys.io tags: - name: Risks paths: /api/v1/risks/{risk_id}: get: description: Retrieve additional metadata for a risk, such as long-form descriptions and references. Risk IDs can be found on asset data in vulnerabilities, exposures, misconfigurations, and threats. operationId: get-risk-metadata parameters: - description: Censys organization ID in: header name: X-Organization-ID required: true schema: description: Censys organization ID format: uuid type: string - description: A Censys risk ID (e.g. CENSYS-2025-1), threat ID (e.g. THREAT-1) or an external risk identifier (e.g. CVE-2025-00001) in: path name: risk_id required: true schema: description: A Censys risk ID (e.g. CENSYS-2025-1), threat ID (e.g. THREAT-1) or an external risk identifier (e.g. CVE-2025-00001) type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/RiskMetadata' description: OK default: content: application/problem+json: schema: $ref: '#/components/schemas/ErrorModel' description: Error security: - PersonalAccessToken: [] summary: Censys Get Static Risk Metadata tags: - Risks x-microcks-operation: delay: 0 dispatcher: FALLBACK components: schemas: ErrorDetail: additionalProperties: false properties: location: description: Where the error occurred, e.g. 'body.items[3].tags' or 'path.thing-id' type: string message: description: Error message text type: string value: description: The value at the given location type: object RiskMetadata: additionalProperties: false properties: $schema: description: A URL to the JSON Schema for this object. examples: - https://graph.data.censys.io/schemas/RiskMetadata.json format: uri readOnly: true type: string added_at: description: Time data was ingested format: date-time type: string description: description: Description of the risk type: string name: description: Name of the risk type: string references: description: Reference information for data returned items: $ref: '#/components/schemas/Reference' type: - array - 'null' required: - description - references - name - added_at type: object ErrorModel: additionalProperties: false properties: $schema: description: A URL to the JSON Schema for this object. examples: - https://graph.data.censys.io/schemas/ErrorModel.json format: uri readOnly: true type: string detail: description: A human-readable explanation specific to this occurrence of the problem. examples: - Property foo is required but is missing. type: string errors: description: Optional list of individual error details items: $ref: '#/components/schemas/ErrorDetail' type: - array - 'null' instance: description: A URI reference that identifies the specific occurrence of the problem. examples: - https://example.com/error-log/abc123 format: uri type: string status: description: HTTP status code examples: - 400 format: int64 type: integer title: description: A short, human-readable summary of the problem type. This value should not change between occurrences of the error. examples: - Bad Request type: string type: default: about:blank description: A URI reference to human-readable documentation for the error. examples: - https://example.com/errors/example format: uri type: string type: object Reference: additionalProperties: false properties: link: type: string required: - link type: object securitySchemes: PersonalAccessToken: description: Your Censys personal access token. scheme: bearer type: http x-speakeasy-globals: parameters: - in: header name: X-Organization-ID schema: type: string x-speakeasy-globals-hidden: true