openapi: 3.2.0 info: contact: name: Kibana Team description: 'The Kibana REST APIs enable you to manage resources such as connectors, data views, and saved objects. The API calls are stateless. Each request that you make happens in isolation from other calls and must include all of the necessary information for Kibana to fulfill the request. API requests return JSON output, which is a format that is machine-readable and works well for automation. To interact with Kibana APIs, use the following operations: - GET: Fetches the information. - PATCH: Applies partial modifications to the existing information. - POST: Adds new information. - PUT: Updates the existing information. - DELETE: Removes the information. You can prepend any Kibana API endpoint with `kbn:` and run the request in **Dev Tools → Console**. For example: ``` GET kbn:/api/data_views ``` For more information about the console, refer to [Run API requests](https://www.elastic.co/docs/explore-analyze/query-filter/tools/console). NOTE: Access to internal Kibana API endpoints will be restricted in Kibana version 9.0. Please move any integrations to publicly documented APIs. ## Documentation source and versions This documentation is derived from the `main` branch of the [kibana](https://github.com/elastic/kibana) repository. It is provided under license [Attribution-NonCommercial-NoDerivatives 4.0 International](https://creativecommons.org/licenses/by-nc-nd/4.0/). This documentation contains work-in-progress information for future Elastic Stack releases. ' title: Kibana Workflows API version: '' x-doc-license: name: Attribution-NonCommercial-NoDerivatives 4.0 International url: https://creativecommons.org/licenses/by-nc-nd/4.0/ x-feedbackLink: label: Feedback url: https://github.com/elastic/docs-content/issues/new?assignees=&labels=feedback%2Ccommunity&projects=&template=api-feedback.yaml&title=%5BFeedback%5D%3A+ servers: - url: https://{kibana_url} variables: kibana_url: default: localhost:5601 security: - apiKeyAuth: [] - basicAuth: [] tags: - name: workflows description: 'Workflows enable you to automate multi-step processes directly in Kibana. Define sequences of steps in YAML to transform data insights into automated actions and outcomes, without needing external automation tools. Use the workflows APIs to create, manage, and run workflows programmatically. You can also search, export, import, and monitor workflow executions. ' externalDocs: description: Workflows documentation url: https://www.elastic.co/docs/explore-analyze/workflows x-displayName: Workflows paths: /api/workflows: delete: description: '**Spaces method and path for this operation:**
delete /s/{space_id}/api/workflows
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Delete multiple workflows by their IDs.

[Required authorization] Route required privileges: workflowsManagement:delete.' operationId: delete-workflows parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: When true, permanently deletes the workflows (hard delete) instead of soft-deleting them. The workflow IDs become available for reuse. in: query name: force required: false schema: default: false type: boolean requestBody: content: application/json: examples: bulkDeleteWorkflowsRequestExample: description: Example request for deleting multiple workflows value: ids: - workflow-c3d4e5f6-a7b8-9012-cdef-234567890123 - workflow-d4e5f6a7-b8c9-0123-defa-345678901234 schema: additionalProperties: false type: object properties: ids: description: Array of workflow IDs to delete. items: description: Workflow ID to delete. type: string maxItems: 1000 type: array required: - ids responses: '200': content: application/json: examples: bulkDeleteWorkflowsResponseExample: description: Example response after deleting multiple workflows value: deleted: 2 failures: [] total: 2 description: Indicates a successful response summary: Bulk delete workflows tags: - workflows x-codeSamples: - label: Soft delete (default) lang: curl source: "curl \\\n -X DELETE \"${KIBANA_URL}/api/workflows\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"ids\": [\"workflow-c3d4e5f6-a7b8-9012-cdef-234567890123\", \"workflow-d4e5f6a7-b8c9-0123-defa-345678901234\"]\n }'\n" - label: Hard delete (permanent) lang: curl source: "curl \\\n -X DELETE \"${KIBANA_URL}/api/workflows?force=true\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"ids\": [\"workflow-c3d4e5f6-a7b8-9012-cdef-234567890123\", \"workflow-d4e5f6a7-b8c9-0123-defa-345678901234\"]\n }'\n" - lang: Console source: "DELETE kbn://api/workflows\n{\n \"ids\": [\"workflow-c3d4e5f6-a7b8-9012-cdef-234567890123\", \"workflow-d4e5f6a7-b8c9-0123-defa-345678901234\"]\n}\n" x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve a paginated list of workflows with optional filtering.

[Required authorization] Route required privileges: workflowsManagement:read. Extended privileges (optional, expand functionality when granted): workflowsManagement:managed:read, workflowsManagement:readExecution, workflowsManagement:managed:readExecution.' operationId: get-workflows parameters: - description: Free-text search query. in: query name: query required: false schema: type: string - description: Number of results per page. in: query name: size required: false schema: minimum: 1 type: number - description: Page number. in: query name: page required: false schema: minimum: 1 type: number - description: Filter by enabled state. in: query name: enabled required: false schema: items: type: boolean maxItems: 2 type: array - description: Filter by creator. in: query name: createdBy required: false schema: items: type: string maxItems: 1000 type: array - description: Filter by tags. in: query name: tags required: false schema: items: type: string maxItems: 1000 type: array - description: Filter by managed status. Defaults to "unmanaged". in: query name: managed required: false schema: enum: - all - managed - unmanaged type: string - description: When managed workflows are included, only return managed workflows visible in these contexts. in: query name: visibilityContext required: false schema: items: maxLength: 128 type: string maxItems: 1000 type: array - description: Field to sort by. in: query name: sortField required: false schema: enum: - name - enabled type: string - description: Sort direction. in: query name: sortOrder required: false schema: enum: - asc - desc type: string responses: '200': content: application/json: examples: getWorkflowsResponseExample: description: Example response returning a paginated list of workflows value: page: 1 results: - createdAt: '2025-11-20T10:30:00.000Z' definition: description: This is a workflow example enabled: true inputs: - default: hello world name: message type: string name: Example definition steps: - name: hello_world_step type: console with: message: '{{ inputs.message }}' triggers: - type: manual description: This is a workflow example enabled: true history: - duration: 5000 finishedAt: '2025-11-20T12:00:05.000Z' id: exec-001 startedAt: '2025-11-20T12:00:00.000Z' status: completed workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 workflowName: Example definition id: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 name: Example definition tags: - example valid: true size: 20 total: 1 description: Indicates a successful response summary: Get workflows tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows?size=20&page=1&sortField=name&sortOrder=asc\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows?size=20&page=1&sortField=name&sortOrder=asc ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Create multiple workflows in a single request. Optionally overwrite existing workflows.

[Required authorization] Route required privileges: workflowsManagement:create AND workflowsManagement:update.' operationId: post-workflows parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: Whether to overwrite existing workflows. in: query name: overwrite required: false schema: default: false type: boolean - description: 'When true, performs a preflight conflict check only. Returns the subset of the supplied workflow IDs that already exist (including soft-deleted tombstones and cross-space documents) without writing anything. The response body is `{ existingIds: string[] }` instead of the normal `{ created, failed }` shape.' in: query name: dryRun required: false schema: default: false type: boolean requestBody: content: application/json: examples: bulkCreateWorkflowsRequestExample: description: Example request for creating multiple workflows at once value: workflows: - yaml: "name: Example definition\nenabled: true\ndescription: This is a workflow example\ntriggers:\n - type: manual\ninputs:\n - name: message\n type: string\n default: \"hello world\"\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"{{ inputs.message }}\"\n" - id: workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901 yaml: "name: Second workflow\nenabled: false\ndescription: Another workflow\ntriggers:\n - type: manual\nsteps:\n - name: log_step\n type: console\n with:\n message: \"Hello from second workflow\"\n" schema: additionalProperties: false type: object properties: workflows: items: type: object properties: id: maxLength: 255 minLength: 3 pattern: ^[a-z0-9]([a-z0-9-]*[a-z0-9])?$ type: string yaml: maxLength: 1048576 type: string required: - yaml maxItems: 500 type: array required: - workflows responses: '200': content: application/json: examples: bulkCreateWorkflowsResponseExample: description: Example response after creating multiple workflows value: created: - id: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 name: Example definition - id: workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901 name: Second workflow failures: [] total: 2 description: Indicates a successful response summary: Bulk create workflows tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows?overwrite=false\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"workflows\": [\n { \"yaml\": \"name: Example definition\\nenabled: true\\ndescription: This is a workflow example\\ntriggers:\\n - type: manual\\ninputs:\\n - name: message\\n type: string\\n default: \\\"hello world\\\"\\nsteps:\\n - name: hello_world_step\\n type: console\\n with:\\n message: \\\"{{ inputs.message }}\\\"\\n\" },\n { \"id\": \"workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901\", \"yaml\": \"name: Second workflow\\nenabled: false\\ndescription: Another workflow\\ntriggers:\\n - type: manual\\nsteps:\\n - name: log_step\\n type: console\\n with:\\n message: \\\"Hello from second workflow\\\"\\n\" }\n ]\n }'\n" - lang: Console source: "POST kbn://api/workflows?overwrite=false\n{\n \"workflows\": [\n { \"yaml\": \"name: Example definition\\nenabled: true\\ndescription: This is a workflow example\\ntriggers:\\n - type: manual\\ninputs:\\n - name: message\\n type: string\\n default: \\\"hello world\\\"\\nsteps:\\n - name: hello_world_step\\n type: console\\n with:\\n message: \\\"{{ inputs.message }}\\\"\\n\" },\n { \"id\": \"workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901\", \"yaml\": \"name: Second workflow\\nenabled: false\\ndescription: Another workflow\\ntriggers:\\n - type: manual\\nsteps:\\n - name: log_step\\n type: console\\n with:\\n message: \\\"Hello from second workflow\\\"\\n\" }\n ]\n}\n" x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/aggs: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/aggs
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve distinct values and their counts for the specified workflow fields. Useful for building filters such as lists of tags or creators.

[Required authorization] Route required privileges: workflowsManagement:read OR workflowsManagement:managed:read.' operationId: get-workflows-aggs parameters: - description: Field or fields to aggregate on. in: query name: fields required: true schema: description: Fields to aggregate on. items: description: Field name to aggregate. type: string maxItems: 25 minItems: 1 type: array - description: Filter aggregations by managed status. in: query name: managed required: false schema: enum: - all - managed - unmanaged type: string responses: '200': content: application/json: examples: getAggsResponseExample: description: Example response with tag and createdBy aggregations value: createdBy: - doc_count: 2 key: elastic tags: - doc_count: 1 key: reporting - doc_count: 1 key: security - doc_count: 1 key: triage description: Indicates a successful response summary: Get workflow aggregations tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/aggs?fields=tags&fields=createdBy\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/aggs?fields=tags&fields=createdBy ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/connectors: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/connectors
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve the Kibana action connectors that can be used in workflow steps, grouped by connector type. Each type includes its configured instances and availability status.

[Required authorization] Route required privileges: workflowsManagement:read.' operationId: get-workflows-connectors parameters: [] responses: '200': content: application/json: examples: getConnectorsResponseExample: description: Example response with available connector types and their instances value: connectorTypes: .email: actionTypeId: .email displayName: Email enabled: true enabledInConfig: true enabledInLicense: true instances: [] minimumLicenseRequired: gold subActions: - displayName: Send name: send .slack_api: actionTypeId: .slack_api displayName: Slack enabled: true enabledInConfig: true enabledInLicense: true instances: - id: slack-connector-1 isDeprecated: false isPreconfigured: false name: Team Notifications minimumLicenseRequired: gold subActions: - displayName: Post Message name: postMessage totalConnectors: 1 description: Indicates a successful response summary: Get available connectors tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/connectors\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/connectors ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/executions/{executionId}: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/executions/{executionId}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve details of a single workflow execution by its ID.

[Required authorization] Route required privileges: workflowsManagement:read AND workflowsManagement:readExecution. Extended privileges (optional, expand functionality when granted): workflowsManagement:managed:readExecution.' operationId: get-workflows-executions-executionid parameters: - description: Workflow execution ID in: path name: executionId required: true schema: type: string - description: Include execution input data. in: query name: includeInput required: false schema: default: false type: boolean - description: Include execution output data. in: query name: includeOutput required: false schema: default: false type: boolean responses: '200': content: application/json: examples: getExecutionResponseExample: description: Example response returning a workflow execution with step details value: duration: 3000 executedBy: elastic finishedAt: '2025-11-20T12:00:03.000Z' id: exec-a1b2c3d4-e5f6-7890 input: message: hello world isTestRun: false output: hello world spaceId: default startedAt: '2025-11-20T12:00:00.000Z' status: completed stepExecutions: - executionTimeMs: 1000 finishedAt: '2025-11-20T12:00:02.000Z' globalExecutionIndex: 0 id: step-exec-001 isTestRun: false scopeStack: [] spaceId: default startedAt: '2025-11-20T12:00:01.000Z' status: completed stepExecutionIndex: 0 stepId: hello_world_step stepType: console topologicalIndex: 0 workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 workflowRunId: exec-a1b2c3d4-e5f6-7890 triggeredBy: manual workflowDefinition: description: This is a workflow example enabled: true inputs: - default: hello world name: message type: string name: Example definition steps: - name: hello_world_step type: console with: message: '{{ inputs.message }}' triggers: - type: manual workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 yaml: "name: Example definition\nenabled: true\ndescription: This is a workflow example\ntriggers:\n - type: manual\ninputs:\n - name: message\n type: string\n default: \"hello world\"\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"{{ inputs.message }}\"\n" description: Indicates a successful response summary: Get a workflow execution tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/executions/{executionId}?includeInput=true&includeOutput=true\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/executions/{executionId}?includeInput=true&includeOutput=true ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/executions/{executionId}/cancel: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/executions/{executionId}/cancel
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Cancel a running workflow execution by its ID.

[Required authorization] Route required privileges: workflowsManagement:cancelExecution.' operationId: post-workflows-executions-executionid-cancel parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: Workflow execution ID in: path name: executionId required: true schema: type: string responses: '200': description: Indicates a successful response summary: Cancel a workflow execution tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/executions/{executionId}/cancel\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\"\n" - lang: Console source: 'POST kbn://api/workflows/executions/{executionId}/cancel ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/executions/{executionId}/children: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/executions/{executionId}/children
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve child workflow executions spawned by sub-workflow steps within a parent execution.

[Required authorization] Route required privileges: workflowsManagement:read AND workflowsManagement:readExecution. Extended privileges (optional, expand functionality when granted): workflowsManagement:managed:readExecution.' operationId: get-workflows-executions-executionid-children parameters: - description: Workflow execution ID in: path name: executionId required: true schema: type: string responses: '200': content: application/json: examples: getChildrenExecutionsResponseExample: description: Example response returning child workflow executions spawned by sub-workflow steps value: - executionId: child-exec-001 parentStepExecutionId: step-exec-003 status: completed stepExecutions: - executionTimeMs: 1000 finishedAt: '2025-11-20T12:00:07.000Z' globalExecutionIndex: 0 id: child-step-001 isTestRun: false scopeStack: [] startedAt: '2025-11-20T12:00:06.000Z' status: completed stepExecutionIndex: 0 stepId: hello_world_step stepType: console topologicalIndex: 0 workflowId: workflow-e5f6a7b8-c9d0-1234-efab-456789012345 workflowRunId: child-exec-001 workflowId: workflow-e5f6a7b8-c9d0-1234-efab-456789012345 workflowName: Child Workflow description: Indicates a successful response summary: Get child executions tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/executions/{executionId}/children\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/executions/{executionId}/children ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/executions/{executionId}/logs: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/executions/{executionId}/logs
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve paginated logs for a workflow execution. Optionally filter by a specific step execution.

[Required authorization] Route required privileges: workflowsManagement:read AND workflowsManagement:readExecution. Extended privileges (optional, expand functionality when granted): workflowsManagement:managed:readExecution.' operationId: get-workflows-executions-executionid-logs parameters: - description: Workflow execution ID in: path name: executionId required: true schema: type: string - description: Filter logs by a specific step execution ID. in: query name: stepExecutionId required: false schema: type: string - description: Number of log entries per page. in: query name: size required: false schema: default: 100 maximum: 100 minimum: 1 type: number - description: Page number. in: query name: page required: false schema: default: 1 minimum: 1 type: number - description: Field to sort by. in: query name: sortField required: false schema: type: string - description: Sort order. in: query name: sortOrder required: false schema: enum: - asc - desc type: string responses: '200': content: application/json: examples: getExecutionLogsResponseExample: description: Example response returning paginated execution logs value: logs: - additionalData: executionId: exec-a1b2c3d4-e5f6-7890 workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 connectorType: console duration: 150 id: log-001 level: info message: Workflow execution started stepId: hello_world_step stepName: Hello World timestamp: '2025-11-20T12:00:01.000Z' - additionalData: executionId: exec-a1b2c3d4-e5f6-7890 workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 connectorType: console duration: 200 id: log-002 level: info message: Step completed successfully stepId: hello_world_step stepName: Hello World timestamp: '2025-11-20T12:00:02.000Z' page: 1 size: 100 total: 2 description: Indicates a successful response summary: Get execution logs tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/executions/{executionId}/logs?size=100&page=1\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/executions/{executionId}/logs?size=100&page=1 ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/executions/{executionId}/resume: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/executions/{executionId}/resume
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Resume a paused workflow execution with the provided input.

[Required authorization] Route required privileges: workflowsManagement:execute.' operationId: post-workflows-executions-executionid-resume parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: Workflow execution ID in: path name: executionId required: true schema: type: string requestBody: content: application/json: examples: resumeExecutionRequestExample: description: Example request to resume a paused workflow execution value: input: approved: true comment: Approved by analyst schema: additionalProperties: false type: object properties: input: additionalProperties: {} description: Input data to resume the execution with. type: object required: - input responses: '200': content: application/json: examples: resumeExecutionResponseExample: description: Example response confirming the resume was scheduled value: executionId: exec-a1b2c3d4-e5f6-7890 message: Workflow resume scheduled success: true description: Indicates a successful response summary: Resume a workflow execution tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/executions/{executionId}/resume\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"input\": {\n \"approved\": true,\n \"comment\": \"Approved by analyst\"\n }\n }'\n" - lang: Console source: "POST kbn://api/workflows/executions/{executionId}/resume\n{\n \"input\": {\n \"approved\": true,\n \"comment\": \"Approved by analyst\"\n }\n}\n" x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/executions/{executionId}/step/{stepExecutionId}: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/executions/{executionId}/step/{stepExecutionId}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve details of a single step execution within a workflow execution.

[Required authorization] Route required privileges: workflowsManagement:read AND workflowsManagement:readExecution. Extended privileges (optional, expand functionality when granted): workflowsManagement:managed:readExecution.' operationId: get-workflows-executions-executionid-step-stepexecutionid parameters: - description: Workflow execution ID. in: path name: executionId required: true schema: type: string - description: Step execution ID. in: path name: stepExecutionId required: true schema: type: string responses: '200': content: application/json: examples: getStepExecutionResponseExample: description: Example response returning a single step execution value: error: null executionTimeMs: 1000 finishedAt: '2025-11-20T12:00:02.000Z' globalExecutionIndex: 0 id: step-exec-001 input: message: hello world isTestRun: false output: hello world scopeStack: [] spaceId: default startedAt: '2025-11-20T12:00:01.000Z' state: null status: completed stepExecutionIndex: 0 stepId: hello_world_step stepType: console topologicalIndex: 0 workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 workflowRunId: exec-a1b2c3d4-e5f6-7890 getWaitForInputStepExecutionResponseExample: description: Example response for a Human-In-The-Loop `wait_for_input` step. Once a responder submits via any client (Kibana Inbox UI, Slack, Agent Builder, raw API/MCP), the `hitl` envelope is populated synchronously — before Task Manager runs the resume — so every reader can detect the "responded but not yet resumed" state from this single doc. value: error: null executionTimeMs: 329000 finishedAt: '2025-11-20T12:05:30.000Z' globalExecutionIndex: 1 hitl: channel: kibana-ui respondedAt: '2025-11-20T12:05:29.000Z' respondedBy: alice id: step-exec-002 input: message: Approve change to production? isTestRun: false output: respondedBy: alice response: approved: true reason: looks good scopeStack: [] spaceId: default startedAt: '2025-11-20T12:00:01.000Z' state: null status: completed stepExecutionIndex: 0 stepId: approve_change stepType: wait_for_input topologicalIndex: 1 workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 workflowRunId: exec-a1b2c3d4-e5f6-7890 description: Indicates a successful response summary: Get a step execution tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/executions/{executionId}/step/{stepExecutionId}\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/executions/{executionId}/step/{stepExecutionId} ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/executions/{executionId}/steps/{stepId}/resume/external: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/executions/{executionId}/steps/{stepId}/resume/external
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Resume a paused `waitForApproval` step (pauses the workflow and waits for a human to approve/decline before execution continues) or `waitForInput` step (passes the expected input values as query parameters in the URL). Returns an HTML confirmation page.' operationId: get-workflows-executions-executionid-steps-stepid-resume-external parameters: - description: Workflow execution ID in: path name: executionId required: true schema: maxLength: 128 type: string - description: Workflow step execution ID in: path name: stepId required: true schema: maxLength: 128 type: string - description: The token created when the workflow execution was paused. Authenticates the request to resume execution. in: query name: token required: true schema: maxLength: 128 type: string - description: Indicates whether a human reviewer approved the paused step. Required for `waitForApproval` when resuming an approval step. in: query name: approved required: false schema: anyOf: - type: boolean - enum: - 'true' type: string - enum: - 'false' type: string responses: '200': content: text/html: examples: externalResumeSuccessExample: description: Success page confirming the response was received value:

Thank you

Your response was received. You can close this window.

schema: type: string description: An HTML confirmation page confirming that the response was received and the workflow execution was resumed. summary: Resume a workflow execution from an external link tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/executions/{executionId}/steps/{stepId}/resume/external?token=${RESUME_TOKEN}&approved=true\"\n" - lang: Console source: 'GET kbn://api/workflows/executions/{executionId}/steps/{stepId}/resume/external?token={resumeToken}&approved=true ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/executions/{executionId}/steps/{stepId}/resume/external
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Resume a workflow execution that is paused and waiting for external input. Submit input values as a JSON request body, authenticated with a token query parameter. Returns an HTML confirmation page.' operationId: post-workflows-executions-executionid-steps-stepid-resume-external parameters: - description: Workflow execution ID in: path name: executionId required: true schema: maxLength: 128 type: string - description: Workflow step execution ID in: path name: stepId required: true schema: maxLength: 128 type: string - description: The resume token authenticating this request. in: query name: token required: true schema: maxLength: 128 type: string requestBody: content: application/json: examples: externalResumeInputRequestExample: description: Example external input payload for a waitForInput step value: description: Escalated from Slack triage severity: high schema: {} responses: '200': content: text/html: examples: externalResumeInputSuccessExample: description: Success page confirming the input was received value:

Thank you

Your response was received. You can close this window.

schema: type: string description: An HTML confirmation page confirming that the input was received and the workflow execution was resumed. summary: Submit external input for a paused workflow execution tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/executions/{executionId}/steps/{stepId}/resume/external?token=${RESUME_TOKEN}\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\"severity\":\"high\"}'\n" - lang: Console source: 'POST kbn://api/workflows/executions/{executionId}/steps/{stepId}/resume/external?token={resumeToken} Content-Type: application/json {"severity":"high"} ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/executions/{executionId}/steps/{stepId}/resume/external/form: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/executions/{executionId}/steps/{stepId}/resume/external/form
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Returns an HTML form for submitting external input to a paused waitForInput step. Does not resume the execution.' operationId: get-workflows-executions-executionid-steps-stepid-resume-external-form parameters: - description: Workflow execution ID in: path name: executionId required: true schema: maxLength: 128 type: string - description: Workflow step execution ID in: path name: stepId required: true schema: maxLength: 128 type: string - description: The resume token authenticating this request. in: query name: token required: true schema: maxLength: 128 type: string responses: '200': content: text/html: examples: externalResumeFormExample: description: Form page for external input submission value:

Submit your response

schema: type: string description: HTML form page for submitting external input to a paused waitForInput step summary: Get the external input form for a paused workflow execution tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/executions/{executionId}/steps/{stepId}/resume/external/form?token=${RESUME_TOKEN}\"\n" - lang: Console source: 'GET kbn://api/workflows/executions/{executionId}/steps/{stepId}/resume/external/form?token={resumeToken} ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/export: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/export
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Export one or more workflows as JSON with YAML content and metadata.

[Required authorization] Route required privileges: workflowsManagement:read OR workflowsManagement:managed:read.' operationId: post-workflows-export parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string requestBody: content: application/json: examples: exportWorkflowsRequestExample: description: Example request to export workflows value: ids: - workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 - workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901 schema: additionalProperties: false type: object properties: ids: description: Array of workflow IDs to export. items: description: Workflow ID to export. maxLength: 255 type: string maxItems: 500 minItems: 1 type: array required: - ids responses: '200': content: application/json: examples: exportWorkflowsResponseExample: description: Workflow entries with YAML content and export manifest value: entries: - id: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 yaml: "name: My Workflow\nsteps:\n - type: http.request\n with:\n url: https://example.com" - id: workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901 yaml: "name: Another Workflow\nsteps:\n - type: http.request\n with:\n url: https://example.com" manifest: exportedAt: '2026-03-26T12:00:00.000Z' exportedCount: 2 version: '1' description: JSON containing exported workflow YAML entries and manifest metadata summary: Export workflows tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/export\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"ids\": [\"workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890\", \"workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901\"]\n }'\n" - lang: Console source: "POST kbn://api/workflows/export\n{\n \"ids\": [\"workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890\", \"workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901\"]\n}\n" x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/managed/workflow/{id}: put: description: '**Spaces method and path for this operation:**
put /s/{space_id}/api/workflows/managed/workflow/{id}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Partially update an existing managed workflow. This elevated route can update fields beyond the enabled state.

[Required authorization] Route required privileges: workflowsManagement:update AND workflowsManagement:managed:update.' operationId: put-workflows-managed-workflow-id parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: Workflow ID in: path name: id required: true schema: type: string requestBody: content: application/json: examples: updateManagedWorkflowExample: description: Example request to update a managed workflow value: description: Updated managed workflow description enabled: true name: Updated managed workflow tags: - managed - updated yaml: "name: Updated managed workflow\nenabled: true\ndescription: Updated managed workflow description\ntriggers:\n - type: manual\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"hello world\"\n" schema: additionalProperties: false type: object properties: description: type: string enabled: type: boolean name: type: string tags: items: type: string type: array yaml: type: string responses: '200': content: application/json: examples: updateManagedWorkflowResponseExample: description: Example response returning the updated managed workflow value: enabled: true id: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 lastUpdatedAt: '2026-03-23T13:38:59.568Z' lastUpdatedBy: elastic valid: true validationErrors: [] description: Indicates a successful response summary: Update a managed workflow tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X PUT \"${KIBANA_URL}/api/workflows/managed/workflow/{id}\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"name\": \"Updated managed workflow\",\n \"enabled\": true,\n \"tags\": [\"managed\", \"updated\"]\n }'\n" - lang: Console source: "PUT kbn://api/workflows/managed/workflow/{id}\n{\n \"name\": \"Updated managed workflow\",\n \"enabled\": true,\n \"tags\": [\"managed\", \"updated\"]\n}\n" x-state: Generally available; added in 9.5.0 x-metaTags: - content: Kibana name: product_name /api/workflows/mget: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/mget
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve multiple workflows by their IDs in a single request. Optionally use the `source` parameter to return only specific fields from each workflow document.

[Required authorization] Route required privileges: workflowsManagement:read OR workflowsManagement:managed:read.' operationId: post-workflows-mget parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string requestBody: content: application/json: examples: mgetWorkflowsRequestExample: description: Example request to retrieve multiple workflows by their IDs value: ids: - workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 - workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901 source: - name - enabled schema: additionalProperties: false type: object properties: ids: description: Array of workflow IDs to look up. items: description: Workflow ID. maxLength: 255 type: string maxItems: 500 minItems: 1 type: array source: description: Array of source fields to include. items: description: Source field. maxLength: 255 type: string maxItems: 10 minItems: 1 type: array required: - ids responses: '200': content: application/json: examples: mgetWorkflowsResponseExample: description: Example response returning the requested workflows with projected fields value: - enabled: true id: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 name: Example definition - enabled: false id: workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901 name: Second workflow description: Indicates a successful response summary: Get workflows by IDs tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/mget\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"ids\": [\"workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890\", \"workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901\"],\n \"source\": [\"name\", \"enabled\"]\n }'\n" - lang: Console source: "POST kbn://api/workflows/mget\n{\n \"ids\": [\"workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890\", \"workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901\"],\n \"source\": [\"name\", \"enabled\"]\n}\n" x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/schema: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/schema
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve the JSON schema used to validate workflow YAML definitions. The schema includes available step types based on the configured connectors in the current space.

[Required authorization] Route required privileges: workflowsManagement:read.' operationId: get-workflows-schema parameters: - description: When true, returns a permissive schema that allows additional properties. When false, returns a strict schema for full validation. in: query name: loose required: true schema: type: boolean responses: '200': content: application/json: examples: getSchemaResponseExample: description: Example response returning the workflow JSON schema (truncated) value: $schema: http://json-schema.org/draft-07/schema# type: object properties: description: type: string enabled: default: true type: boolean name: minLength: 1 type: string tags: items: type: string type: array version: const: '1' default: '1' description: The version of the workflow schema type: string required: - name - triggers - steps description: Indicates a successful response summary: Get workflow JSON schema tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/schema?loose=false\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/schema?loose=false ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/stats: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/stats
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve summary statistics about workflows, including total, enabled, and disabled counts; execution history metrics for the last 30 days are included only when the caller has execution read privilege.

[Required authorization] Route required privileges: workflowsManagement:read. Extended privileges (optional, expand functionality when granted): workflowsManagement:managed:read, workflowsManagement:readExecution, workflowsManagement:managed:readExecution.' operationId: get-workflows-stats parameters: [] responses: '200': content: application/json: examples: getStatsResponseExample: description: Example response with workflow counts and 30-day execution history value: executions: - cancelled: 1 completed: 45 date: '2025-11-20' failed: 2 timestamp: '2025-11-20T00:00:00.000Z' - cancelled: 0 completed: 50 date: '2025-11-21' failed: 0 timestamp: '2025-11-21T00:00:00.000Z' workflows: disabled: 3 enabled: 12 description: Indicates a successful response summary: Get workflow statistics tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/stats\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/stats ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/step/test: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/step/test
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Execute a single step from a workflow definition in test mode.

[Required authorization] Route required privileges: workflowsManagement:execute.' operationId: post-workflows-step-test parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string requestBody: content: application/json: examples: testStepRequestExample: description: Example request to test a single workflow step value: contextOverride: inputs: message: override message stepId: hello_world_step workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 workflowYaml: "name: Example definition\nenabled: true\ndescription: This is a workflow example\ntriggers:\n - type: manual\ninputs:\n - name: message\n type: string\n default: \"hello world\"\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"{{ inputs.message }}\"\n" schema: additionalProperties: false type: object properties: contextOverride: additionalProperties: {} description: Context overrides for the step execution. type: object executionContext: additionalProperties: {} description: Execution context for the step execution. type: object stepId: description: ID of the step to test. type: string workflowId: description: ID of the workflow containing the step. type: string workflowYaml: description: YAML definition of the workflow containing the step. type: string required: - stepId - contextOverride - workflowYaml responses: '200': content: application/json: examples: testStepResponseExample: description: Example response returning the step test execution ID value: workflowExecutionId: step-test-exec-a1b2c3d4 description: Indicates a successful response summary: Test a workflow step tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/step/test\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"stepId\": \"hello_world_step\",\n \"workflowId\": \"workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890\",\n \"workflowYaml\": \"name: Example definition\\nenabled: true\\ntriggers:\\n - type: manual\\ninputs:\\n - name: message\\n type: string\\n default: \\\"hello world\\\"\\nsteps:\\n - name: hello_world_step\\n type: console\\n with:\\n message: \\\"{{ inputs.message }}\\\"\",\n \"contextOverride\": { \"inputs\": { \"message\": \"override message\" } }\n }'\n" - lang: Console source: "POST kbn://api/workflows/step/test\n{\n \"stepId\": \"hello_world_step\",\n \"workflowId\": \"workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890\",\n \"workflowYaml\": \"name: Example definition\\nenabled: true\\ntriggers:\\n - type: manual\\ninputs:\\n - name: message\\n type: string\\n default: \\\"hello world\\\"\\nsteps:\\n - name: hello_world_step\\n type: console\\n with:\\n message: \\\"{{ inputs.message }}\\\"\",\n \"contextOverride\": { \"inputs\": { \"message\": \"override message\" } }\n}\n" x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/test: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/test
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Execute a workflow in test mode without requiring it to be saved or enabled. Provide either a workflow ID to test a saved workflow, a YAML definition to test an unsaved draft, or both to test a modified version of an existing workflow.

[Required authorization] Route required privileges: workflowsManagement:execute.' operationId: post-workflows-test parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string requestBody: content: application/json: examples: testWorkflowByIdRequestExample: description: Example request to test a saved workflow by its ID value: inputs: message: test message workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 testWorkflowByYamlRequestExample: description: Example request to test an unsaved workflow YAML draft value: inputs: message: test message workflowYaml: "name: Example definition\nenabled: true\ndescription: This is a workflow example\ntriggers:\n - type: manual\ninputs:\n - name: message\n type: string\n default: \"hello world\"\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"{{ inputs.message }}\"\n" schema: additionalProperties: false type: object properties: inputs: additionalProperties: {} description: Key-value inputs for the test execution. type: object workflowId: description: ID of an existing workflow to test. type: string workflowYaml: description: YAML definition to test. type: string required: - inputs responses: '200': content: application/json: examples: testWorkflowResponseExample: description: Example response returning the test execution ID value: workflowExecutionId: test-exec-a1b2c3d4-e5f6 description: Indicates a successful response summary: Test a workflow tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/test\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"workflowId\": \"workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890\",\n \"inputs\": { \"message\": \"test message\" }\n }'\n" - lang: Console source: "POST kbn://api/workflows/test\n{\n \"workflowId\": \"workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890\",\n \"inputs\": { \"message\": \"test message\" }\n}\n" x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/workflow: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/workflow
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Create a new workflow from a YAML definition. The YAML is validated and parsed before the workflow is saved. An optional custom ID can be provided.

[Required authorization] Route required privileges: workflowsManagement:create.' operationId: post-workflows-workflow parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string requestBody: content: application/json: examples: createWorkflowRequestExample: description: Example request for creating a workflow from a YAML definition value: yaml: "name: Example definition\nenabled: true\ndescription: This is a workflow example\ntriggers:\n - type: manual\ninputs:\n - name: message\n type: string\n default: \"hello world\"\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"{{ inputs.message }}\"\n" createWorkflowWithIdRequestExample: description: Example request for creating a workflow with a custom ID value: id: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 yaml: "name: Example definition\nenabled: true\ndescription: This is a workflow example\ntriggers:\n - type: manual\ninputs:\n - name: message\n type: string\n default: \"hello world\"\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"{{ inputs.message }}\"\n" schema: additionalProperties: false type: object properties: id: maxLength: 255 minLength: 3 pattern: ^[a-z0-9]([a-z0-9-]*[a-z0-9])?$ type: string yaml: maxLength: 1048576 type: string required: - yaml responses: '200': content: application/json: examples: createWorkflowResponseExample: description: Example response returning the created workflow value: createdAt: '2025-11-20T10:30:00.000Z' createdBy: elastic definition: description: This is a workflow example enabled: true inputs: - default: hello world name: message type: string name: Example definition steps: - name: hello_world_step type: console with: message: '{{ inputs.message }}' triggers: - type: manual description: This is a workflow example enabled: true id: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 lastUpdatedAt: '2025-11-20T10:30:00.000Z' lastUpdatedBy: elastic name: Example definition valid: true yaml: "name: Example definition\nenabled: true\ndescription: This is a workflow example\ntriggers:\n - type: manual\ninputs:\n - name: message\n type: string\n default: \"hello world\"\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"{{ inputs.message }}\"\n" description: Indicates a successful response summary: Create a workflow tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/workflow\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"yaml\": \"name: Example definition\\nenabled: true\\ndescription: This is a workflow example\\ntriggers:\\n - type: manual\\ninputs:\\n - name: message\\n type: string\\n default: \\\"hello world\\\"\\nsteps:\\n - name: hello_world_step\\n type: console\\n with:\\n message: \\\"{{ inputs.message }}\\\"\\n\"\n }'\n" - lang: Console source: "POST kbn://api/workflows/workflow\n{\n \"yaml\": \"name: Example definition\\nenabled: true\\ndescription: This is a workflow example\\ntriggers:\\n - type: manual\\ninputs:\\n - name: message\\n type: string\\n default: \\\"hello world\\\"\\nsteps:\\n - name: hello_world_step\\n type: console\\n with:\\n message: \\\"{{ inputs.message }}\\\"\\n\"\n}\n" x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/workflow/{id}: delete: description: '**Spaces method and path for this operation:**
delete /s/{space_id}/api/workflows/workflow/{id}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Delete a single workflow by its ID.

[Required authorization] Route required privileges: workflowsManagement:delete.' operationId: delete-workflows-workflow-id parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: Workflow ID in: path name: id required: true schema: type: string - description: When true, permanently deletes the workflow (hard delete) instead of soft-deleting it. The workflow ID becomes available for reuse. in: query name: force required: false schema: default: false type: boolean responses: '200': description: Indicates a successful response summary: Delete a workflow tags: - workflows x-codeSamples: - label: Soft delete (default) lang: curl source: "curl \\\n -X DELETE \"${KIBANA_URL}/api/workflows/workflow/{id}\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\"\n" - label: Hard delete (permanent) lang: curl source: "curl \\\n -X DELETE \"${KIBANA_URL}/api/workflows/workflow/{id}?force=true\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\"\n" - lang: Console source: 'DELETE kbn://api/workflows/workflow/{id} ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/workflow/{id}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve a single workflow by its ID.

[Required authorization] Route required privileges: workflowsManagement:read OR workflowsManagement:managed:read.' operationId: get-workflows-workflow-id parameters: - description: Workflow ID in: path name: id required: true schema: type: string responses: '200': content: application/json: examples: getWorkflowResponseExample: description: Example response returning a single workflow value: createdAt: '2025-11-20T10:30:00.000Z' createdBy: elastic definition: description: This is a workflow example enabled: true inputs: - default: hello world name: message type: string name: Example definition steps: - name: hello_world_step type: console with: message: '{{ inputs.message }}' triggers: - type: manual description: This is a workflow example enabled: true id: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 lastUpdatedAt: '2025-11-21T14:00:00.000Z' lastUpdatedBy: elastic name: Example definition valid: true yaml: "name: Example definition\nenabled: true\ndescription: This is a workflow example\ntriggers:\n - type: manual\ninputs:\n - name: message\n type: string\n default: \"hello world\"\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"{{ inputs.message }}\"\n" description: Indicates a successful response summary: Get a workflow tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/workflow/{id}\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/workflow/{id} ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name put: description: '**Spaces method and path for this operation:**
put /s/{space_id}/api/workflows/workflow/{id}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Partially update an existing workflow. You can update individual fields such as name, description, enabled state, tags, or the YAML definition without providing all fields.

[Required authorization] Route required privileges: workflowsManagement:update.' operationId: put-workflows-workflow-id parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: Workflow ID in: path name: id required: true schema: type: string requestBody: content: application/json: examples: updateWorkflowEnableExample: description: Example request to enable a workflow and update its tags value: enabled: true tags: - production updateWorkflowFullExample: description: Example request to update multiple workflow fields value: description: Updated workflow description enabled: true name: Updated example tags: - example - updated yaml: "name: Updated example\nenabled: true\ndescription: Updated workflow description\ntriggers:\n - type: manual\ninputs:\n - name: message\n type: string\n default: \"hello world\"\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"{{ inputs.message }}\"\n" schema: additionalProperties: false type: object properties: description: type: string enabled: type: boolean name: type: string tags: items: type: string type: array yaml: type: string responses: '200': content: application/json: examples: updateWorkflowResponseExample: description: Example response returning the updated workflow value: enabled: false id: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 lastUpdatedAt: '2026-03-23T13:38:59.568Z' lastUpdatedBy: elastic valid: true validationErrors: [] description: Indicates a successful response summary: Update a workflow tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X PUT \"${KIBANA_URL}/api/workflows/workflow/{id}\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"enabled\": true,\n \"tags\": [\"production\"]\n }'\n" - lang: Console source: "PUT kbn://api/workflows/workflow/{id}\n{\n \"enabled\": true,\n \"tags\": [\"production\"]\n}\n" x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/workflow/{id}/clone: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/workflow/{id}/clone
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Create a copy of an existing workflow.

[Required authorization] Route required privileges: workflowsManagement:create AND workflowsManagement:read.' operationId: post-workflows-workflow-id-clone parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: Workflow ID in: path name: id required: true schema: type: string responses: '200': content: application/json: examples: cloneWorkflowResponseExample: description: Example response returning the cloned workflow with a new ID value: createdAt: '2025-11-22T11:00:00.000Z' createdBy: elastic definition: description: This is a workflow example enabled: false inputs: - default: hello world name: message type: string name: Example definition (copy) steps: - name: hello_world_step type: console with: message: '{{ inputs.message }}' triggers: - type: manual description: This is a workflow example enabled: false id: workflow-b2c3d4e5-f6a7-8901-bcde-f12345678901 lastUpdatedAt: '2025-11-22T11:00:00.000Z' lastUpdatedBy: elastic name: Example definition (copy) valid: true yaml: "name: Example definition (copy)\nenabled: false\ndescription: This is a workflow example\ntriggers:\n - type: manual\ninputs:\n - name: message\n type: string\n default: \"hello world\"\nsteps:\n - name: hello_world_step\n type: console\n with:\n message: \"{{ inputs.message }}\"\n" description: Indicates a successful response summary: Clone a workflow tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/workflow/{id}/clone\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\"\n" - lang: Console source: 'POST kbn://api/workflows/workflow/{id}/clone ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/workflow/{id}/run: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/workflow/{id}/run
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Execute a workflow by its ID with the provided inputs. The workflow must be enabled and have a valid definition. Returns an execution ID that can be used to monitor progress.

[Required authorization] Route required privileges: workflowsManagement:execute.' operationId: post-workflows-workflow-id-run parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: Workflow ID in: path name: id required: true schema: type: string requestBody: content: application/json: examples: runWorkflowRequestExample: description: Example request to execute a workflow with inputs value: inputs: message: hello from the API schema: additionalProperties: false type: object properties: inputs: additionalProperties: {} description: Key-value inputs for the workflow execution. type: object metadata: additionalProperties: {} description: Optional metadata for the execution. type: object required: - inputs responses: '200': content: application/json: examples: runWorkflowResponseExample: description: Example response returning the execution ID value: workflowExecutionId: exec-a1b2c3d4-e5f6-7890 description: Indicates a successful response summary: Run a workflow tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/workflow/{id}/run\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"inputs\": {\n \"message\": \"hello from the API\"\n }\n }'\n" - lang: Console source: "POST kbn://api/workflows/workflow/{id}/run\n{\n \"inputs\": {\n \"message\": \"hello from the API\"\n }\n}\n" x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/workflow/{workflowId}/executions: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/workflow/{workflowId}/executions
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve a paginated list of executions for a specific workflow.

[Required authorization] Route required privileges: workflowsManagement:read AND workflowsManagement:readExecution. Extended privileges (optional, expand functionality when granted): workflowsManagement:managed:readExecution.' operationId: get-workflows-workflow-workflowid-executions parameters: - description: Workflow ID in: path name: workflowId required: true schema: type: string - description: Filter by execution status. in: query name: statuses required: false schema: items: enum: - pending - waiting - waiting_for_input - waiting_for_child - running - queued - completed - failed - cancelled - timed_out - skipped type: string maxItems: 11 type: array - description: Filter by execution type. in: query name: executionTypes required: false schema: items: enum: - test - production type: string maxItems: 2 type: array - description: Filter by the user who triggered the execution. in: query name: executedBy required: false schema: items: type: string maxItems: 100 type: array - description: Filter by evaluated concurrency group key. in: query name: concurrencyGroupKey required: false schema: type: string x-state: Generally available; added in 9.5.0 - description: Whether to exclude step-level execution data. in: query name: omitStepRuns required: false schema: type: boolean - description: Datemath lower bound for filtering executions by finishedAt (inclusive when parsed). in: query name: finishedAfter required: false schema: type: string x-state: Generally available; added in 9.5.0 - description: Datemath upper bound for filtering executions by finishedAt (inclusive when parsed with roundUp). in: query name: finishedBefore required: false schema: type: string x-state: Generally available; added in 9.5.0 - description: Field to collapse execution results by. in: query name: collapse required: false schema: enum: - concurrencyGroupKey - status - executedBy - triggeredBy type: string x-state: Generally available; added in 9.5.0 - description: Field to sort executions by. in: query name: sortField required: false schema: enum: - createdAt - finishedAt type: string x-state: Generally available; added in 9.5.0 - description: Sort order. in: query name: sortOrder required: false schema: enum: - asc - desc type: string x-state: Generally available; added in 9.5.0 - description: Page number. in: query name: page required: false schema: minimum: 1 type: number - description: Number of results per page. in: query name: size required: false schema: maximum: 100 minimum: 1 type: number - description: Datemath lower bound for filtering executions by startedAt (inclusive when parsed). in: query name: startedAfter required: false schema: type: string x-state: Generally available; added in 9.5.0 - description: Datemath upper bound for filtering executions by startedAt (inclusive when parsed with roundUp). in: query name: startedBefore required: false schema: type: string x-state: Generally available; added in 9.5.0 responses: '200': content: application/json: examples: getWorkflowExecutionsResponseExample: description: Example response returning a paginated list of executions for a workflow value: page: 1 results: - duration: 3000 error: null executedBy: elastic finishedAt: '2025-11-20T12:00:03.000Z' id: exec-001 isTestRun: false spaceId: default startedAt: '2025-11-20T12:00:00.000Z' status: completed triggeredBy: manual workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 - duration: 2000 error: message: Step 'hello_world_step' failed executedBy: elastic finishedAt: '2025-11-20T13:00:02.000Z' id: exec-002 isTestRun: false spaceId: default startedAt: '2025-11-20T13:00:00.000Z' status: failed triggeredBy: manual workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 size: 20 total: 2 description: Indicates a successful response summary: Get workflow executions tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/workflow/{workflowId}/executions?page=1&size=20\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/workflow/{workflowId}/executions?page=1&size=20&startedAfter=now-1d&startedBefore=now ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/workflow/{workflowId}/executions/cancel: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/workflows/workflow/{workflowId}/executions/cancel
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Request cancellation for all non-terminal executions of the given workflow in the current space.

[Required authorization] Route required privileges: workflowsManagement:cancelExecution.' operationId: post-workflows-workflow-workflowid-executions-cancel parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: Workflow ID in: path name: workflowId required: true schema: type: string responses: '200': description: Indicates a successful response summary: Cancel all active workflow executions tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X POST \"${KIBANA_URL}/api/workflows/workflow/{workflowId}/executions/cancel\" \\\n -H \"Authorization: ApiKey ${API_KEY}\" \\\n -H \"kbn-xsrf: true\"\n" - lang: Console source: 'POST kbn://api/workflows/workflow/{workflowId}/executions/cancel ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/workflow/{workflowId}/executions/steps: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/workflow/{workflowId}/executions/steps
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Retrieve a paginated list of step-level execution records for a specific workflow. Optionally filter by step ID and include input or output data.

[Required authorization] Route required privileges: workflowsManagement:read AND workflowsManagement:readExecution. Extended privileges (optional, expand functionality when granted): workflowsManagement:managed:readExecution.' operationId: get-workflows-workflow-workflowid-executions-steps parameters: - description: Workflow ID in: path name: workflowId required: true schema: type: string - description: Filter by step ID. in: query name: stepId required: false schema: type: string - description: Include step input data. in: query name: includeInput required: false schema: type: boolean - description: Include step output data. in: query name: includeOutput required: false schema: type: boolean - description: Page number for pagination. in: query name: page required: false schema: minimum: 1 type: number - description: Number of results per page. in: query name: size required: false schema: maximum: 100 minimum: 1 type: number - description: Datemath lower bound for filtering step executions by startedAt (inclusive when parsed). in: query name: startedAfter required: false schema: type: string - description: Datemath upper bound for filtering step executions by startedAt (inclusive when parsed with roundUp). in: query name: startedBefore required: false schema: type: string responses: '200': content: application/json: examples: getWorkflowStepExecutionsResponseExample: description: 'Example response returning step execution records for a workflow. The second entry shows a Human-In-The-Loop `wait_for_input` step that has been responded to: the `hitl` envelope is populated synchronously by the inbox respond path so every reader (Kibana Inbox UI, Slack, Agent Builder, raw API/MCP) sees a single canonical responder for the step.' value: results: - executionTimeMs: 1000 finishedAt: '2025-11-20T12:00:02.000Z' globalExecutionIndex: 0 id: step-exec-001 input: message: hello world isTestRun: false scopeStack: [] spaceId: default startedAt: '2025-11-20T12:00:01.000Z' status: completed stepExecutionIndex: 0 stepId: hello_world_step stepType: console topologicalIndex: 0 workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 workflowRunId: exec-001 - executionTimeMs: 329000 finishedAt: '2025-11-20T12:05:31.000Z' globalExecutionIndex: 1 hitl: channel: kibana-ui respondedAt: '2025-11-20T12:05:29.000Z' respondedBy: alice id: step-exec-002 input: message: Approve change to production? isTestRun: false output: respondedBy: alice response: approved: true scopeStack: [] spaceId: default startedAt: '2025-11-20T12:00:02.000Z' status: completed stepExecutionIndex: 0 stepId: approve_change stepType: wait_for_input topologicalIndex: 1 workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 workflowRunId: exec-001 total: 2 description: Indicates a successful response summary: Get workflow step executions tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/workflow/{workflowId}/executions/steps?includeInput=true\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/workflow/{workflowId}/executions/steps?includeInput=true ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name /api/workflows/workflow/executions: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/workflows/workflow/executions
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Search across all workflow executions.

[Required authorization] Route required privileges: workflowsManagement:read AND workflowsManagement:readExecution. Extended privileges (optional, expand functionality when granted): workflowsManagement:managed:readExecution.' operationId: get-workflows-workflow-executions parameters: - description: KQL query string to filter executions. in: query name: kql required: false schema: maxLength: 4096 type: string - description: Filter by execution status. in: query name: statuses required: false schema: items: enum: - pending - waiting - waiting_for_input - waiting_for_child - running - queued - completed - failed - cancelled - timed_out - skipped type: string maxItems: 11 type: array - description: Filter by execution type. in: query name: executionTypes required: false schema: items: enum: - test - production type: string maxItems: 2 type: array - description: Filter by the user who triggered the execution. in: query name: executedBy required: false schema: items: type: string maxItems: 100 type: array - description: Filter by evaluated concurrency group key. in: query name: concurrencyGroupKey required: false schema: type: string - description: Datemath lower bound for filtering executions by startedAt. in: query name: startedAfter required: false schema: type: string - description: Datemath upper bound for filtering executions by startedAt. in: query name: startedBefore required: false schema: type: string - description: Datemath lower bound for filtering executions by finishedAt. in: query name: finishedAfter required: false schema: type: string - description: Datemath upper bound for filtering executions by finishedAt. in: query name: finishedBefore required: false schema: type: string - description: Field to collapse execution results by. in: query name: collapse required: false schema: enum: - concurrencyGroupKey - status - executedBy - triggeredBy type: string - description: 'Field to sort by. One of: startedAt, duration, workflowId, triggeredBy.' in: query name: sortField required: false schema: enum: - startedAt - duration - workflowId - triggeredBy type: string - description: Sort direction. in: query name: sortOrder required: false schema: enum: - asc - desc type: string - description: Page number. in: query name: page required: false schema: minimum: 1 type: number - description: Number of results to return. in: query name: size required: false schema: maximum: 100 minimum: 1 type: number - description: Whether to track total hit count. in: query name: trackTotalHits required: false schema: type: boolean responses: '200': content: application/json: examples: searchExecutionsResponseExample: description: Example paginated list of workflow-level executions value: page: 1 results: - duration: 3000 error: null executedBy: elastic finishedAt: '2025-11-20T12:00:03.000Z' id: exec-a1b2c3d4-e5f6-7890 isTestRun: false managed: false spaceId: default startedAt: '2025-11-20T12:00:00.000Z' status: completed tags: - reporting triggeredBy: manual workflowId: workflow-a1b2c3d4-e5f6-7890-abcd-ef1234567890 workflowName: Example Workflow size: 25 total: 1 description: Indicates a successful response '400': content: application/json: examples: searchExecutionsBadRequestExample: description: Example response when the kql parameter contains invalid syntax value: message: 'Invalid KQL: Expected AND, OR, or end of input but "f" found.' description: Indicates a bad request, such as invalid KQL syntax summary: Search workflow executions tags: - workflows x-codeSamples: - lang: curl source: "curl \\\n -X GET \"${KIBANA_URL}/api/workflows/workflow/executions?page=1&size=25&trackTotalHits=true&kql=startedAt%20%3E%3D%20%22now-15m%22&sortField=startedAt&sortOrder=desc\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n" - lang: Console source: 'GET kbn://api/workflows/workflow/executions?from=0&size=25&trackTotalHits=true&kql=startedAt >= "now-15m"&sortField=startedAt&sortOrder=desc ' x-state: Generally available; added in 9.4.0 x-metaTags: - content: Kibana name: product_name components: securitySchemes: apiKeyAuth: description: 'These APIs use key-based authentication. You must create an API key and use the encoded value in the request header. For example: `Authorization: ApiKey base64AccessApiKey` ' in: header name: Authorization type: apiKey basicAuth: scheme: basic type: http x-topics: - title: Kibana spaces content: "Spaces enable you to organize your dashboards and other saved objects into meaningful categories.\nYou can use the default space or create your own spaces.\n\nTo run APIs in non-default spaces, you must add `s/{space_id}/` to the path.\nFor example:\n\n```bash\ncurl -X GET \"http://${KIBANA_URL}/s/marketing/api/data_views\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n```\n\nIf you use the Kibana console to send API requests, it automatically adds the appropriate space identifier.\n\nTo learn more, check out [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces).\n"