# Splunk Observability Cloud > Splunk Observability Cloud is the observability platform Splunk built on SignalFx and now runs as > part of Cisco: infrastructure monitoring, APM, real user monitoring, synthetics, log observer and > incident response over OpenTelemetry-native ingest. Its control plane is a large REST API — 48 > OpenAPI documents and 242 operations covering charts, dashboards, detectors, incidents, metrics > metadata, SignalFlow, SLOs, org tokens, teams and twenty synthetics services — plus a SignalFlow > WebSocket/SSE streaming surface and a hosted MCP server. ## What an agent most needs to know - Authentication is a single header, `X-SF-TOKEN`, carrying either a long-lived org token or a short-lived session token. No OAuth, no OIDC, no scopes. - The realm is part of the HOSTNAME: `https://api..observability.splunkcloud.com/v2`. Ingest, backfill and SignalFlow live on `ingest.`, `backfill.` and `stream.` hosts respectively. - There is NO idempotency key. A retried POST creates a second real object; there is no sandbox. - There are NO rate-limit response headers. Exhaustion is a bare 429. - Errors are not RFC 9457. Five vendor JSON envelopes plus a bare-string form are in use. - Any query returns at most 10,000 objects, however you page. - Splunk publishes no downloadable OpenAPI file. The specs below were reconstructed from the OpenAPI object Splunk embeds in its own reference pages. ## APIs - [API reference (48 specifications)](https://dev.splunk.com/observability/reference/) - [Endpoint overview](https://dev.splunk.com/observability/docs/apibasics/api_list/) - [Authentication](https://dev.splunk.com/observability/docs/apibasics/authentication_basics/) - [Realms in endpoints](https://dev.splunk.com/observability/docs/realms_in_endpoints/) - [SignalFlow](https://dev.splunk.com/observability/docs/signalflow/) - [MCP server](https://help.splunk.com/en/splunk-observability-cloud/splunk-ai-assistant/interact-with-your-observability-data-using-the-splunk-mcp-server) ## Specifications - [OpenAPI directory (48 documents)](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/openapi/) - [Charts](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/openapi/splunk-observability-charts-openapi.yml) - [Dashboards](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/openapi/splunk-observability-dashboards-openapi.yml) - [Detectors](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/openapi/splunk-observability-detectors-openapi.yml) - [Incidents and alerts](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/openapi/splunk-observability-incidents-openapi.yml) - [Metrics metadata](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/openapi/splunk-observability-metrics-metadata-openapi.yml) - [SignalFlow](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/openapi/splunk-observability-signalflow-openapi.yml) - [SLOs](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/openapi/splunk-observability-slo-openapi.yml) - [Org tokens](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/openapi/splunk-observability-org-tokens-openapi.yml) - [Teams](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/openapi/splunk-observability-teams-openapi.yml) - [SignalFlow AsyncAPI (derived)](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/asyncapi/splunk-observability-signalflow-asyncapi.yml) ## Runtime semantics - [Conventions](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/conventions/splunk-observability-conventions.yml) - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/authentication/splunk-observability-authentication.yml) - [Error catalogue](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/errors/splunk-observability-problem-types.yml) - [Rate limits](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/rate-limits/splunk-observability-rate-limits.yml) - [Lifecycle and versioning](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/lifecycle/splunk-observability-lifecycle.yml) - [Data model](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/data-model/splunk-observability-data-model.yml) - [Webhooks](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/asyncapi/splunk-observability-webhooks.yml) ## Agent surfaces - [MCP server manifest](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/mcp/splunk-observability-mcp.yml) - [MCP tool to REST crosswalk](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/mcp/splunk-observability-tool-crosswalk.yml) - [Agent skills](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/skills/_index.yml) ## Commercial - [Pricing](https://www.splunk.com/en_us/products/pricing/observability.html) - [Plans artifact](https://raw.githubusercontent.com/api-evangelist/splunk-observability/refs/heads/main/plans/splunk-observability-plans-pricing.yml) - [Status](https://status.signalfx.com) - [Release notes](https://help.splunk.com/en/splunk-observability-cloud/release-notes) - [Compliance](https://www.splunk.com/en_us/about-splunk/splunk-data-security-and-privacy/compliance-at-splunk.html) - [Security policy](https://advisory.splunk.com/report) ## Notes Generated by API Evangelist on 2026-08-19. Splunk serves no /llms.txt of its own — dev.splunk.com answers HTTP 200 with an identical SPA shell for every path, including /llms.txt.