# Demisto (Cortex XSOAR) > Demisto is a Security Orchestration, Automation, and Response (SOAR) platform, acquired by Palo Alto Networks in 2019 and rebranded as Cortex XSOAR. It unifies case management, playbook-driven automation, real-time collaboration (the "War Room"), and threat-intelligence management. The Demisto REST API exposes incidents, war-room entries, evidence, indicators, and automation scripts programmatically. This is an API Evangelist profile generated by the enrichment pipeline. ## APIs - [Demisto REST API (reference)](https://xsoar.pan.dev/docs/reference/api/demisto-class): Incidents, entries, evidence, indicators, and automation via the Cortex XSOAR server API. ## Specs - [OpenAPI (Swagger 2.0)](openapi/demisto-openapi-original.json): 72 paths / 75 operations, API-key auth. - [Authentication profile](authentication/demisto-authentication.yml): API key in the Authorization header (XSOAR 8+ adds API-Key-ID + X-XSRF-TOKEN). - [Conventions](conventions/demisto-conventions.yml): pagination, error envelope, versioning. - [Error catalog](errors/demisto-problem-types.yml): HTTP status codes and JSON error body. - [Data model](data-model/demisto-data-model.yml): incident / entry / evidence / indicator / automation entities. - [Conformance](conformance/demisto-conformance.yml): standards posture. - [MCP (candidate)](mcp/demisto-mcp.yml): one candidate tool per REST operation. - [Agentic access](agentic-access/demisto-agentic-access.yml): recommended x-agentic-access contracts. ## Docs - [Cortex XSOAR for Developers](https://xsoar.pan.dev/): Developer portal (formerly Demisto). - [Get Started with APIs](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Administrator-Guide/Get-Started-with-APIs): API key setup. - [demisto-py](https://github.com/demisto/demisto-py): Official Python REST client. - [demisto-sdk](https://github.com/demisto/demisto-sdk): Content-development toolkit and CLI. - [GitHub organization](https://github.com/demisto): Content repository and tooling.