# CybelAngel > External risk protection: CybelAngel scans the public internet, the deep and dark web, > unsecured file servers and databases, cloud drives, code- and paste-sharing sites, and DNS > and social platforms for a customer's exposed data and unmanaged assets. It publishes seven > documented REST APIs (52 operations, all OpenAPI 3.1.0) covering incident reports, real-time > alerts, external attack-surface inventory, monitored keywords, threat intelligence, audit > logs, and an MSSP partner surface. This file was GENERATED by API Evangelist from > CybelAngel's public developer portal and specifications — CybelAngel does not publish an > llms.txt of its own (probed 2026-08-17: /llms.txt is 404 on cybelangel.com, > api.cybelangel.com and developers.cybelangel.com). ## How to call it - Auth is OAuth 2.0 client-credentials. POST JSON `{"client_id":…,"client_secret":…,"audience":"https://platform.cybelangel.com/","grant_type":"client_credentials"}` to https://auth.cybelangel.com/oauth/token, then send `Authorization: Bearer `. - Credentials are self-activated by a platform admin at Platform > Settings > CybelAngel API. API access ships with the advanced package, is sold separately, or can be trialled free for 30 days. - Token TTL: assume 1 hour (the docs contradict themselves — see conventions). Tokens are capped at 2,000/month per client_id, so CACHE AND REUSE the token; do not mint one per request. - Request limits: 15 requests/second and 20 concurrent requests per client. No rate-limit response headers exist — self-throttle. - Two base URLs: https://platform.cybelangel.com/api (Reports API) and https://api.cybelangel.com (everything else). - Alerts responses are capped at 1,000 records; page with `cursor`. Alerts retain for a rolling 12 months and nothing exists before 2026-01-01. - Errors are `{"error":{"message":"…"}}` as application/json — not RFC 9457 problem+json. There is no idempotency key on any write. ## APIs - [CybelAngel Reports API](https://developers.cybelangel.com/docs/cybelangel-platform-api/39d4926befc14-what-can-i-do-with-this-api): 21 operations. Incident reports (v2 search + detail), mirror listings (JSON/CSV/zip), report PDF, attachments, threaded comments, remediation requests, leaked-credential watchlist + CSV export, malicious-domain watchlist, report assets, report volume stats, caller permissions. Base https://platform.cybelangel.com/api. The only API with declared OAuth scopes. - [CybelAngel Alerts API](https://developers.cybelangel.com/docs/alerts-api/72b66de24898e-cybel-angel-alerts-api-real-time-threat-intelligence): 9 operations. "Alerts in Feed" — search alerts by keyword/IP/hostname/date/ML score, fetch one alert, PATCH a customer assessment, list leak credentials and codeshare findings, DNS screenshot, and the same alerts as OASIS STIX bundles. Requires a `stream_id` issued by a CSM. - [CybelAngel ADM Inventory API](https://developers.cybelangel.com/docs/adm-inventory-api/7e88d945427a4-fetch-assets-details-from-adm-inventory): 5 operations. External attack-surface assets, their hostnames and open ports/services/CPEs, threats joined to the owning asset, plus asset and asset-threat status writes. - [CybelAngel Keywords API](https://developers.cybelangel.com/docs/keywords-api/c812fc6b544b0-manipulate-your-keywords): 5 operations. List, create, update and enable/disable the keywords that drive detection; list workspaces. Returns HTTP 207 partial success with created_keywords[] + failed_keywords[]. - [CybelAngel Threat Intelligence API](https://developers.cybelangel.com/docs/threat-intelligence-api/38e63ab3d5c42-fetch-threat-intelligence-claimed-attacks): 1 operation. Claimed attacks (ransomware/extortion claims) filterable by threat actor, country, industry, victim and domain. - [CybelAngel Audit Logs API](https://developers.cybelangel.com/docs/audit-logs-api/72b66de24898e-cybel-angel-audit-logs-api): 1 operation. Platform audit trail for an organization, scoped by `{organization_id}` in the path. - [CybelAngel Partner API](https://developers.cybelangel.com/docs/partner-api/72b66de24898e-cybel-angel-partners-api): 10 operations. The MSSP surface — ADM Inventory, Keywords and Workspaces scoped to a client organization by `{organization_id}`. Its keyword model exposes four detection-tuning fields (rule, sources, active_search, infostealer_search) the customer-facing Keywords API does not. ## Specifications - [Reports OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/cybelangel/refs/heads/main/openapi/cybelangel-platform-reports-openapi.yml) - [Alerts OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/cybelangel/refs/heads/main/openapi/cybelangel-alerts-openapi.yml) - [ADM Inventory OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/cybelangel/refs/heads/main/openapi/cybelangel-adm-inventory-openapi.yml) - [Keywords OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/cybelangel/refs/heads/main/openapi/cybelangel-keywords-openapi.yml) - [Partner OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/cybelangel/refs/heads/main/openapi/cybelangel-partner-openapi.yml) - [Threat Intelligence OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/cybelangel/refs/heads/main/openapi/cybelangel-threat-intelligence-openapi.yml) - [Audit Logs OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/cybelangel/refs/heads/main/openapi/cybelangel-audit-logs-openapi.yml) - [OpenID Connect discovery](https://auth.cybelangel.com/.well-known/openid-configuration) and [JWKS](https://auth.cybelangel.com/.well-known/jwks.json) — the Auth0 tenant that mints every token. ## Docs - [Developer portal](https://developers.cybelangel.com/) - [Get your API credentials](https://developers.cybelangel.com/docs/cybelangel-platform-api/05d245301ecc5-get-your-api-credentials) - [Authentication](https://developers.cybelangel.com/docs/cybelangel-platform-api/b6b6c2d4906e9-authentication) - [Make authenticated requests](https://developers.cybelangel.com/docs/cybelangel-platform-api/8ba3b4bfd2344-make-authenticated-requests) - [API calls and base URL (Alerts)](https://developers.cybelangel.com/docs/alerts-api/fbe89213b575d-api-calls) - [Limitations — rate limits, token caps, retention](https://developers.cybelangel.com/docs/alerts-api/304dab003eb13-limitations) - [Alerts in STIX format, with a schema per alert category](https://developers.cybelangel.com/docs/alerts-api/3d22245755b86-alerts-in-stix-format) - [Getting started with Alerts](https://developers.cybelangel.com/docs/alerts-api/c53add3c8b16f-getting-started) - [Audit Logs getting-started guide](https://developers.cybelangel.com/docs/audit-logs-api/f9723159f94ff-getting-started-guide-audit-logs-api) - [API Toolbox tutorial (Python script that pages past the 1,000-alert cap)](https://developers.cybelangel.com/docs/alerts-api/6e548d500150e-cybel-angel-api-toolbox-tutorial) - [Fetch reports with Postman](https://developers.cybelangel.com/docs/cybelangel-platform-api/wkg6n6pod3pt8-fetch-reports-using-cybel-angel-api-and-postman) - [Fetch alerts with Insomnia](https://developers.cybelangel.com/docs/alerts-api/884d6a784fabe-fetch-alerts-with-insomnia) - [CybelAngel Connect — no-code integrations](https://developers.cybelangel.com/docs/connectors-apps/141b1fbcacfd2-welcome-to-cybel-angel-connect-docs) - [Changelog and quarterly roadmap](https://cybelangel.com/changelog/) ## Integrations - CybelAngel Connect (no-code automation studio): ServiceNow, Jira, Splunk Enterprise Security, Slack, Palo Alto Cortex XSOAR, IBM Security SOAR, Azure Sentinel, FortiSOAR, Splunk Phantom. - [CybelAngel EASM Splunk technical add-on (TA-cybelangel 1.1.6, 2025-09-10)](https://splunkbase.splunk.com/app/7287/) — the only official installable distribution. ## Not available CybelAngel publishes none of the following as of 2026-08-17, and API Evangelist did not manufacture them: no client SDK in any language (npm/PyPI/RubyGems/NuGet/crates.io all empty), no CLI, no MCP server, no A2A agent card, no GraphQL endpoint, no webhooks or AsyncAPI (Alerts in Feed is polled, not pushed), no status page (status.cybelangel.com does not resolve), no published prices, no deprecation policy or Sunset headers, no rate-limit response headers, and no idempotency keys.