How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Elastic Stack (ELK Stack) Connectors API

Connectors provide a central place to store connection information for services and integrations with Elastic or third party systems. Alerting rules can use connectors to run actions when rule conditions are met.

Elastic Stack (ELK Stack) Connectors API is one of 132 APIs that Elastic Stack (ELK Stack) publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Connectors. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 9 operations across 6 paths, and defines 83 schemas. It is described by OpenAPI 3.2.0.

Requests are made against a single base URL, https://{kibana_url}.

9 operations 6 paths 83 schemas 1 DELETE5 GET2 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
Base URL
https://{elasticsearch_endpoint}
Authentication
API Key, HTTP Basic
Contact
Kibana Team
Resource Areas
1

Authentication & Security 2

Elastic Stack (ELK Stack) Connectors API declares 2 security schemes for authenticating requests. An API key is passed in the header as Authorization (apiKeyAuth). It accepts HTTP basic authentication (basicAuth). By default, every request must be authenticated.

  • apiKeyAuth — These APIs use key-based authentication. You must create an API key and use the encoded value in the request header. For example: Authorization: ApiKey base64A…

Paths & Operations 9

Across 6 paths, the API surfaces 9 operations — 1 DELETE, 5 GET, 2 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

connectors 9

Connectors provide a central place to store connection information for services and integrations with Elastic or third party systems. Alerting rules can use connectors to run acti…

GET
/api/actions/connector_types
Get connector types
get-actions-connector-types 1 param → 200403
GET
/api/actions/connector/_oauth_callback
Handle OAuth callback
get-actions-connector-oauth-callback 5 params → 200302401
GET
/api/actions/connector/{connectorId}/oauth/start
Start OAuth authorization (redirects to the identity provider)
get-actions-connector-connectorid-oauth-start 1 param → 302400401404
DELETE
/api/actions/connector/{id}
Delete a connector
delete-actions-connector-id 2 params → 204403
GET
/api/actions/connector/{id}
Get connector information
get-actions-connector-id 1 param → 200403
POST
/api/actions/connector/{id}
Create a connector
post-actions-connector-id 2 params body → 200403
PUT
/api/actions/connector/{id}
Update a connector
put-actions-connector-id 2 params body → 200403
POST
/api/actions/connector/{id}/_execute
Run a connector
post-actions-connector-id-execute 2 params body → 200403
GET
/api/actions/connectors
Get all connectors
get-actions-connectors → 200403

Schemas 83

The contract defines 83 schemas that model the data the API accepts and returns. The most detailed are cases_webhook_config (19 properties), Kibana_HTTP_APIs_connector_type_response (15 properties), webhook_config (12 properties), run_trigger_pagerduty (11 properties). Each schema is shown below with its type and property counts.

d3security_config
object
Defines properties for connectors when type is .d3security.
1 property 1 required
email_config
object
Defines properties for connectors when type is .email.
10 properties 1 required
run_issues
object
The issues subaction for Jira connectors.
2 properties 2 required
thehive_config
object
Defines configuration properties for connectors when type is .thehive.
2 properties 1 required
thehive_secrets
object
Defines secrets for connectors when type is .thehive.
1 property 1 required
verification_mode
string
Controls the verification of certificates. Use full to validate that the certificate has an issue date within the notbefore and notafter dates, chains to a tru…
run_issue
object
The issue subaction for Jira connectors.
2 properties 1 required
tines_config
object
Defines properties for connectors when type is .tines.
1 property 1 required
sentinelone_secrets
object
Defines secrets for connectors when type is .sentinelone.
1 property 1 required
run_message_slack
object
Test an action that sends a message to Slack. It is applicable only when the connector type is .slack.
1 property 1 required
torq_config
object
Defines properties for connectors when type is .torq.
1 property 1 required
run_closealert
object
The closeAlert subaction for Opsgenie connectors.
2 properties 2 required
d3security_secrets
object
Defines secrets for connectors when type is .d3security.
1 property 1 required
run_acknowledge_resolve_pagerduty
object
Test an action that acknowledges or resolves a PagerDuty alert.
2 properties 2 required
bedrock_config
object
Defines properties for connectors when type is .bedrock.
3 properties 1 required
cases_webhook_config
object
Defines properties for connectors when type is .cases-webhook.
19 properties 8 required
run_getincident
object
The getIncident subaction for Jira, ServiceNow ITSM, and ServiceNow SecOps connectors.
2 properties 2 required
run_getchoices
object
The getChoices subaction for ServiceNow ITOM, ServiceNow ITSM, and ServiceNow SecOps connectors.
2 properties 2 required
servicenow_config
object
Defines properties for connectors when type is .servicenow.
6 properties 1 required
genai_secrets
object
Defines secrets for connectors when type is .gen-ai. Supports both API key authentication (OpenAI, Azure OpenAI, and Other) and PKI authentication (Other provi…
4 properties
Kibana_HTTP_APIs_connector_execute_request
object
1 property 1 required
pagerduty_config
object
Defines properties for connectors when type is .pagerduty.
1 property
run_closeincident
object
The closeIncident subaction for ServiceNow ITSM connectors.
2 properties 2 required
run_validchannelid
object
Retrieves information about a valid Slack channel identifier. It is applicable only when the connector type is .slackapi.
2 properties 2 required
run_trigger_pagerduty
object
Test an action that triggers a PagerDuty alert.
11 properties 1 required
jira_secrets
object
Defines secrets for connectors when type is .jira.
2 properties 2 required
Kibana_HTTP_APIs_connector_response
object
10 properties 7 required
webhook_config
object
Defines properties for connectors when type is .webhook.
12 properties
xmatters_config
object
Defines properties for connectors when type is .xmatters.
2 properties
email_secrets
object
Defines secrets for connectors when type is .email.
3 properties
resilient_config
object
Defines properties for connectors when type is .resilient.
2 properties 2 required
run_documents
object
Test an action that indexes a document into Elasticsearch.
1 property 1 required
crowdstrike_secrets
object
Defines secrets for connectors when type is .crowdstrike.
2 properties 2 required
key
string
If authType is webhook-authentication-ssl and certType is ssl-crt-key, it is a base64 encoded version of the KEY file.
Kibana_HTTP_APIs_connector_response_with_references_count
object
11 properties 8 required
xmatters_secrets
object
Defines secrets for connectors when type is .xmatters.
3 properties
defender_secrets
object
Defines secrets for connectors when type is ..microsoftdefenderendpoint.
1 property 1 required
Kibana_HTTP_APIs_connector_type_response
object
15 properties 11 required
pfx
string
If authType is webhook-authentication-ssl and certType is ssl-pfx, it is a base64 encoded version of the PFX or P12 file.
run_message_email
object
Test an action that sends an email message. There must be at least one recipient in to, cc, or bcc.
5 properties 2 required
run_createalert
object
The createAlert subaction for Opsgenie and TheHive connectors.
2 properties 2 required
opsgenie_config
object
Defines properties for connectors when type is .opsgenie.
1 property 1 required
gemini_config
object
Defines properties for connectors when type is .gemini.
4 properties 3 required
bedrock_secrets
object
Defines secrets for connectors when type is .bedrock.
2 properties 2 required
run_fieldsbyissuetype
object
The fieldsByIssueType subaction for Jira connectors.
2 properties 2 required
run_postmessage
object
Test an action that sends a message to Slack. It is applicable only when the connector type is .slackapi.
2 properties 2 required
cases_webhook_secrets
object
5 properties
auth_type
stringnull
The type of authentication to use: basic, SSL, OAuth2 client credentials, or none.
run_getfields
object
The getFields subaction for Jira, ServiceNow ITSM, and ServiceNow SecOps connectors.
1 property 1 required
run_getagentdetails
object
The getAgentDetails subaction for CrowdStrike connectors.
2 properties 2 required
genai_openai_other_config
object
Defines properties for connectors when type is .gen-ai and the API provider is Other (OpenAI-compatible service), including optional PKI authentication.
8 properties 3 required
jira_config
object
Defines properties for connectors when type is .jira.
2 properties 2 required
defender_config
object
Defines properties for connectors when type is .microsoftdefenderendpoint.
5 properties 2 required
opsgenie_secrets
object
Defines secrets for connectors when type is .opsgenie.
1 property 1 required
pagerduty_secrets
object
Defines secrets for connectors when type is .pagerduty.
1 property 1 required
torq_secrets
object
Defines secrets for connectors when type is .torq.
1 property 1 required
run_message_serverlog
object
Test an action that writes an entry to the Kibana server log.
2 properties 1 required
servicenow_secrets
object
Defines secrets for connectors when type is .servicenow, .servicenow-sir, or .servicenow-itom.
5 properties
index_config
object
Defines properties for connectors when type is .index.
3 properties 1 required
swimlane_config
object
Defines properties for connectors when type is .swimlane.
4 properties 3 required
swimlane_secrets
object
Defines secrets for connectors when type is .swimlane.
1 property
run_issuetypes
object
The issueTypes subaction for Jira connectors.
1 property 1 required
run_addevent
object
The addEvent subaction for ServiceNow ITOM connectors.
2 properties 1 required
teams_secrets
object
Defines secrets for connectors when type is .teams.
1 property 1 required
genai_openai_config
object
Defines properties for connectors when type is .gen-ai and the API provider is OpenAI.
3 properties 2 required
Kibana_HTTP_APIs_new_connector
object
4 properties 2 required
webhook_secrets
object
Defines secrets for connectors when type is .webhook.
6 properties
cert_type
string
If the authType is webhook-authentication-ssl, specifies whether the certificate authentication data is in a CRT and key file format or a PFX file format.
crowdstrike_config
object
Defines config properties for connectors when type is .crowdstrike.
1 property 1 required
servicenow_itom_config
object
Defines properties for connectors when type is .servicenow-itom.
5 properties 1 required
has_auth
boolean
If true, a username and password for login type authentication must be provided.
tines_secrets
object
Defines secrets for connectors when type is .tines.
2 properties 2 required
Kibana_HTTP_APIs_update_connector
object
3 properties 1 required
genai_azure_config
object
Defines properties for connectors when type is .gen-ai and the API provider is Azure OpenAI.
2 properties 2 required
resilient_secrets
object
Defines secrets for connectors when type is .resilient.
2 properties 2 required
slack_api_secrets
object
Defines secrets for connectors when type is .slack.
1 property 1 required
sentinelone_config
object
Defines properties for connectors when type is .sentinelone.
1 property 1 required
slack_api_config
object
Defines properties for connectors when type is .slackapi.
1 property
run_pushtoservice
object
The pushToService subaction for Jira, ServiceNow ITSM, ServiceNow SecOps, Swimlane, TheHive, and Webhook - Case Management connectors.
2 properties 2 required
ca
string
A base64 encoded version of the certificate authority file that the connector can trust to sign and validate certificates. This option is available for all aut…
run_getagents
object
The getAgents subaction for SentinelOne connectors.
1 property 1 required
crt
string
If authType is webhook-authentication-ssl and certType is ssl-crt-key, it is a base64 encoded version of the CRT or CERT file.
gemini_secrets
object
Defines secrets for connectors when type is .gemini.
1 property 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

elk-stack-connectors-api-openapi.yml Raw ↑

Other APIs Elastic Stack (ELK Stack) publishes across the network.

Elastic Cloud API
Elastic Stack (ELK Stack) Accounts API
Elastic Stack (ELK Stack) Actions API
Elastic Stack (ELK Stack) agent builder API
Elastic Stack (ELK Stack) Alerting API
Elastic Stack (ELK Stack) Alerting V2 API
Elastic Stack (ELK Stack) Analytics API
Elastic Stack (ELK Stack) APM agent configuration API
Elastic Stack (ELK Stack) APM agent keys API
Elastic Stack (ELK Stack) APM annotations API
Elastic Stack (ELK Stack) APM server schema API
Elastic Stack (ELK Stack) APM sourcemaps API
Where this information came from

This is an independent, third-party profile of Elastic Stack (ELK Stack) Connectors API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.