# Splunk SOAR > Splunk SOAR (Security Orchestration, Automation and Response) is the platform Splunk built on > Phantom, acquired in 2018, and now part of Cisco through the 2024 Splunk acquisition. It runs > playbooks across hundreds of connected security tools and exposes a REST API for containers, > artifacts, playbooks, actions, assets and case management. This file was GENERATED by API > Evangelist from the provider's published documentation on 2026-08-19 — Splunk does not serve an > llms.txt of its own (https://www.splunk.com/llms.txt returned 404). ## What an agent needs to know first - There is **no shared API host**. The SOAR REST API is served from each customer's own tenant: `https://{soar-host}/rest/`. Splunk SOAR (Cloud) gives each customer a dedicated host; SOAR (On-premises) runs on customer infrastructure. Nothing is callable without a tenant. - There is **no anonymously fetchable OpenAPI or Swagger document** for Splunk SOAR. The contract is human-readable HTML reference pages only. API Evangelist has not authored a substitute. - Authentication is HTTP Basic (username/password) or a `ph-auth-token` header issued to an automation user. **DELETE requires Basic auth** — the token is rejected for deletes. - Failures return `{"failed": true, "message": "..."}` with a non-200 status. There are no numbered error codes and no RFC 9457 problem+json. - No rate limits, quotas or rate-limit response headers are published. - Splunk ships no MCP server for SOAR. The official Splunk MCP Server targets Splunk Enterprise/Cloud Platform, not SOAR. ## APIs - [Splunk SOAR REST API](https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference): containers, artifacts, playbooks, actions, assets, indicators, evidence, notes, vault, workbooks, roles, multi-tenancy and system settings, at `https://{soar-host}/rest/`. ## Docs - [Splunk SOAR (Cloud) documentation](https://help.splunk.com/en/splunk-soar/soar-cloud) - [REST API reference](https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference) - [Using the REST API / authentication](https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/using-the-splunk-soar-rest-api/using-the-rest-api-reference-for-splunk-soar-cloud) - [Query for data — pagination, sorting, filtering](https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/using-the-splunk-soar-rest-api/query-for-data) - [Bulk create and update records](https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/using-the-splunk-soar-rest-api/bulk-create-and-update-records) - [Delete records](https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/using-the-splunk-soar-rest-api/delete-records) - [Release notes](https://help.splunk.com/en/splunk-soar/soar-cloud/release-notes) - [Splunk SOAR (Cloud) service description](https://help.splunk.com/en/splunk-soar/soar-cloud/soar-cloud-service-description/the-splunk-soar-service/splunk-soar-cloud-introduction) ## SDKs and tooling - [Splunk SOAR SDK (PyPI)](https://pypi.org/project/splunk-soar-sdk/) — official app/connector development framework; ships the `soarapps` CLI. v4.0.0, 2026-08-15. - [Splunk SOAR SDK docs](https://phantomcyber.github.io/splunk-soar-sdk/index.html) - [Splunk SOAR SDK source](https://github.com/phantomcyber/splunk-soar-sdk) - [Splunk SOAR VS Code extension](https://marketplace.visualstudio.com/items?itemName=Splunk.vscode-splunk-soar) — v0.0.33, 2026-07-20. - [phantomcyber GitHub organization](https://github.com/phantomcyber) - [splunk-soar-connectors GitHub organization](https://github.com/splunk-soar-connectors) — 529 public connector repos. ## Operations and trust - [Splunk status page](https://status.splunk.com) - [Splunk Cloud Service Level Schedule](https://www.splunk.com/en_us/legal/splunk-cloud-service-level-schedule.html) - [Compliance at Splunk](https://www.splunk.com/en_us/about-splunk/splunk-data-security-and-privacy/compliance-at-splunk.html) - [Splunk Customer Trust Portal](https://customertrust.splunk.com/) - [Report a vulnerability](https://advisory.splunk.com/report) - [security.txt](https://www.splunk.com/.well-known/security.txt) ## Commercial - [Product page](https://www.splunk.com/en_us/products/splunk-security-orchestration-and-automation.html) - [Pricing — quote only, no published SOAR tiers](https://www.splunk.com/en_us/products/pricing.html) - [Free trial](https://www.splunk.com/en_us/download/soar-free-trial.html) - [Splunk General Terms](https://www.splunk.com/en_us/legal/splunk-general-terms.html) - [Privacy policy](https://www.splunk.com/en_us/legal/privacy.html) ## API Evangelist artifacts - [apis.yml](https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/apis.yml) - authentication/splunk-soar-authentication.yml - conventions/splunk-soar-conventions.yml - errors/splunk-soar-problem-types.yml - lifecycle/splunk-soar-lifecycle.yml - changelog/splunk-soar-changelog.yml - conformance/splunk-soar-conformance.yml - data-model/splunk-soar-data-model.yml - packages/splunk-soar-packages.yml - cli/splunk-soar-cli.yml - rate-limits/splunk-soar-rate-limits.yml - plans/splunk-soar-plans-pricing.yml - mcp/splunk-soar-mcp.yml - well-known/splunk-soar-well-known.yml