# Cisco XDR > Cisco's extended detection and response platform, successor to SecureX. It correlates telemetry > from Cisco Secure Endpoint, Secure Firewall, Umbrella, Duo, Secure Email and third-party sources > into incidents, and exposes four distinct REST API families for investigation, threat > intelligence, incident management and automation. Generated by API Evangelist from the provider's > own published specifications, 2026-08-19. Read this first: Cisco XDR is not one API. It is four API families on four different hosts, sharing one OAuth 2.0 authorization server. Mixing the hosts returns 404 — Cisco says so in its own MCP server documentation. There is no sandbox, no test mode, and no idempotency key anywhere, including on the operation that blocks, isolates and quarantines. ## Authentication - Token endpoint (US): https://visibility.amp.cisco.com/iroh/oauth2/token - Grant: client_credentials, HTTP Basic with client_id:client_password - Header: `Authorization: Bearer `; tokens expire in ~600 seconds - Create credentials in the XDR console under Administration > API Clients - Authorization server metadata: https://visibility.amp.cisco.com/.well-known/oauth-authorization-server - OIDC discovery: https://visibility.amp.cisco.com/.well-known/openid-configuration - 41 scopes are declared in the specs; 32 are advertised by the authorization server; 34 finer-grained scope strings (for example `response/trigger:write`, `webhook/management:read`) gate individual operations. See scopes/cisco-xdr-scopes.yml. - Docs: https://developer.cisco.com/docs/cisco-xdr/authentication/ ## API families and base URLs - IROH platform (inspect, enrich, response, integrations, events, webhooks, feedback, auth) — https://visibility.amp.cisco.com/iroh — also .eu. and .apjc. - Private intelligence, CTIA (indicators, judgements, sightings, feeds, incidents, casebooks, assets, the whole CTIM entity model) — https://private.intel.amp.cisco.com/ctia - Incidents and investigations, Conure v2 (high-priority incident search) — https://conure.us.security.cisco.com - Automation (workflows and workflow instances) — https://automate.us.security.cisco.com/api ## Specifications - IROH services (Swagger 2.0, anonymously fetchable): https://visibility.amp.cisco.com/iroh/{iroh-auth,iroh-enrich,iroh-inspect,iroh-response,iroh-int,iroh-event,iroh-feedback,iroh-webhook}/swagger.json - CTIA private intelligence (Swagger 2.0, 188 paths): https://private.intel.amp.cisco.com/swagger.json - Conure v2 incidents and investigations (Swagger 2.0, 89 paths): https://conure.us.security.cisco.com/swagger.json - Automation (OpenAPI 3.0.1, 90 paths): https://pubhub.devnetcloud.com/media/cisco-xdr-api-docs/docs/reference/automation/rest_api_1_0_0.json - Harvested and split by resource into 52 documents under openapi/ in this repository. ## Docs - Introduction: https://developer.cisco.com/docs/cisco-xdr/ - Getting started: https://developer.cisco.com/docs/cisco-xdr/getting-started/ - Rate limits: https://developer.cisco.com/docs/cisco-xdr/rate-limits/ - API changelog: https://developer.cisco.com/docs/cisco-xdr/api-changelog/ - Developer support: https://developer.cisco.com/docs/cisco-xdr/developer-support/ - API clients (console help): https://docs.xdr.security.cisco.com/Content/Administration/api-clients.htm - Product release notes: https://docs.xdr.security.cisco.com/Content/release-notes.htm - Service status: https://status.tdr.cisco.com/ - Community: https://community.cisco.com/t5/cisco-xdr/bd-p/developer-xdr ## Agent surfaces - MCP server: https://github.com/CiscoDevNet/xdr-mcp-community — 27 tools, 5 resources, 6 prompts, Apache-2.0. **stdio only.** There is no hosted endpoint and the package is not on npm; a human must clone and build it before any agent can use it. - A2A agent card: none. /.well-known/agent-card.json and /.well-known/agent.json 404 on every host. - llms.txt: Cisco publishes none; this file is generated by API Evangelist. ## Runtime behaviour an agent must know - Rate limit: 8000 requests/hour per organization, rolling window, shared by every API client in the tenant. Workflow Run is 10/minute. On 429 read `Retry-After`, `X-Ratelimit-Org-Limit` and `X-Ratelimit-Org-Remaining`. - Errors: no RFC 9457. Three envelopes — IROH `{error, error_description, error_code, error_uri, trace_id}`, Conure `{message}`, and per-module `ErrorMessage` objects that can appear inside a 200. - Pagination: `search_after` cursor plus `X-Sort` / `X-Next` / `X-Total-Hits` headers on CTIA; `limit`/`offset` elsewhere; `start`/`limit` on Automation. - Content types: JSON, YAML, EDN and Transit are all negotiated; 406 is a real response. - Idempotency: none. Use `external_id` and the `/ctia//external_id/{external_id}` lookup to reconcile before retrying a write. - Versioning: four schemes. CTIA v2.71.0 in the document, Conure in the path (/v1, /v2), Automation with three live majors (/v1, /v1.1, /v1.2), IROH not versioned in the path at all. No deprecation policy is published and no Sunset header is sent. ## Artifacts in this repository - openapi/ — 52 specifications, harvested verbatim, plus _original/ - authentication/, scopes/ — the OAuth model and the full scope map - conventions/, errors/, data-model/, rate-limits/, lifecycle/, changelog/, conformance/ - mcp/ — the MCP manifest and the tool-to-REST crosswalk - asyncapi/ — the webhook subscription catalogue: 30 event types, 17 record types - skills/ — three packaged agent skills split along the consequence boundary - security/, well-known/, plans/, packages/, sandbox/