Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

ARMO Runtime API

Runtime incidents (CADR), network and runtime policies.

ARMO Runtime API is one of 8 APIs that ARMO publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Runtime. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 12 operations across 12 paths, and defines 3 schemas. It is described by OpenAPI 3.0.3, at version 1.0.

Requests are made against 2 base URLs: https://api.armosec.io/api/v1, https://api.us.armosec.io/api/v1.

12 operations 12 paths 3 schemas 5 GET7 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.3
API Version
1.0
Base URL
https://api.armosec.io/api/v1
Authentication
API Key
Contact
Resource Areas
1

Authentication & Security 1

ARMO Runtime API declares 1 security scheme for authenticating requests. An API key is passed in the header as X-API-KEY (apiKeyAuth). By default, every request must be authenticated.

  • apiKeyAuth — Account access key (Agent Access Key) generated in ARMO Platform under Settings, sent in the X-API-KEY header.

Paths & Operations 12

Across 12 paths, the API surfaces 12 operations — 5 GET, 7 POST. Each is listed below with its method, path, parameters, and response codes.

Runtime 12

Runtime incidents (CADR), network and runtime policies.

GET
/runtime/incidents
List runtime incidents
listRuntimeIncidents → 200401
GET
/runtime/incidents/severity
Get runtime incidents grouped by severity
getRuntimeIncidentsSeverity → 200401
GET
/runtime/incidents/{incidentGUID}/alerts
Get alerts for an incident
getRuntimeIncidentAlerts 1 param → 200401404
POST
/runtime/incidents/{incidentGUID}/explain
Explain a runtime incident
explainRuntimeIncident 1 param → 200401404
POST
/runtime/incidents/{incidentGUID}/resolve
Resolve a runtime incident
resolveRuntimeIncident 1 param → 200401404
POST
/runtime/incidents/{incidentGUID}/unresolve
Unresolve a runtime incident
unresolveRuntimeIncident 1 param → 200401404
GET
/network/policies
List network policies
listNetworkPolicies → 200401
POST
/network/policies/generate
Generate network policies
generateNetworkPolicies body → 200401
GET
/runtime/seccomp/list
List seccomp resources
listSeccompProfiles → 200401
POST
/runtime/seccomp/generate
Generate seccomp profiles
generateSeccompProfiles body → 200401
POST
/runtime/policy/create
Create a runtime policy
createRuntimePolicy body → 200401
POST
/runtime/policy/exception/create
Create a runtime policy exception
createRuntimePolicyException body → 200401

Schemas 3

The contract defines 3 schemas that model the data the API accepts and returns. The most detailed are ListResponse (2 properties), Error (2 properties). Each schema is shown below with its type and property counts.

GenericResponse
object
Error
object
2 properties
ListResponse
object
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

armosec-runtime-api-openapi.yml Raw ↑

Other APIs ARMO publishes across the network.

ARMO Access Keys API
ARMO Clusters API
ARMO Integrations API
ARMO Posture API
ARMO Registry API
ARMO Security Risks API
ARMO Vulnerabilities API