openapi: 3.0.3 info: title: Stellar Cyber Open XDR Alerts Reports API description: The Stellar Cyber REST API provides programmatic access to the Open XDR platform, enabling automation of security operations including case management, tenant administration, connector management, alert handling, query operations, user management, watchlists, sensors, and security event management. version: '6.3' contact: name: Stellar Cyber Support url: https://stellarcyber.zendesk.com license: name: Proprietary url: https://stellarcyber.ai/terms/ servers: - url: https://{platformHostname}/connect/api/v1 description: Stellar Cyber Platform API variables: platformHostname: description: Your Stellar Cyber platform hostname default: your-platform.stellarcyber.ai security: - bearerAuth: [] tags: - name: Reports description: Security report generation and retrieval paths: /reports: get: operationId: listReports summary: List Reports description: Retrieve all available security reports. tags: - Reports responses: '200': description: List of reports content: application/json: schema: $ref: '#/components/schemas/ReportsListResponse' '401': $ref: '#/components/responses/Unauthorized' post: operationId: createReport summary: Create Report description: Generate a new security report. tags: - Reports requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateReportRequest' responses: '201': description: Report created successfully content: application/json: schema: $ref: '#/components/schemas/Report' '401': $ref: '#/components/responses/Unauthorized' /reports/{reportId}: delete: operationId: deleteReport summary: Delete Report description: Delete a security report. tags: - Reports parameters: - $ref: '#/components/parameters/ReportId' responses: '204': description: Report deleted successfully '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' components: schemas: CreateReportRequest: type: object required: - name - type properties: name: type: string type: type: string parameters: type: object ReportsListResponse: type: object properties: data: type: array items: $ref: '#/components/schemas/Report' total: type: integer Report: type: object properties: id: type: string name: type: string type: type: string status: type: string enum: - pending - completed - failed created_at: type: string format: date-time url: type: string Error: type: object properties: error: type: string message: type: string code: type: integer responses: Unauthorized: description: Authentication required or token expired content: application/json: schema: $ref: '#/components/schemas/Error' NotFound: description: Resource not found content: application/json: schema: $ref: '#/components/schemas/Error' parameters: ReportId: name: reportId in: path required: true description: Unique identifier for the report schema: type: string securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: JWT token obtained from /access_token endpoint. Tokens expire after 10 minutes. API keys can also be used as Bearer tokens for the /access_token call.