Live Data API

All systems operational

Programmatic access to ThreatOps SOC telemetry, compliance posture, and pre-computed analytics. Integrate with PowerBI, Tableau, Splunk, or any REST-capable platform.

21Endpoints
BearerAuth
JSONFormat
Base URLhttps://api.threatops.io
Authentication required — Pass Authorization: Bearer <api_key> and X-Tenant-ID: <tenant_uuid> on every request.

Core Data Endpoints

Raw SOC and compliance data with pagination and filtering

7 endpoints

SOC Analytics Endpoints

Pre-computed, BI-ready metrics — click Run to call any endpoint live

14 endpoints
Time window
days
Every response returns metadata.generated_atmetadata.record_countmetadata.daysvalid range: 1 – 3650
GET/api/v1/reports/live-data/summary
GET/api/v1/reports/live-data/alerts-by-response-type
GET/api/v1/reports/live-data/escalated-incidents-by-severity
GET/api/v1/reports/live-data/escalated-incidents-weekly-trend
GET/api/v1/reports/live-data/escalated-incidents-by-category
GET/api/v1/reports/live-data/top-categories
GET/api/v1/reports/live-data/benign-false-positive-alerts
GET/api/v1/reports/live-data/non-escalated-alerts-by-severity
GET/api/v1/reports/live-data/alerts-resolved-by-automation
GET/api/v1/reports/live-data/alert-types-by-hour
GET/api/v1/reports/live-data/mean-times
GET/api/v1/reports/live-data/mean-times-by-disposition
GET/api/v1/reports/live-data/incidents-by-severity
GET/api/v1/reports/live-data/incidents-by-disposition

Works with

PowerBITableauGrafanaSplunkElasticPythonNode.jscurl