How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Tenable Workbenches API

The Workbenches API from Tenable — 14 operation(s) for workbenches.

Tenable Workbenches API is one of 107 APIs that Tenable publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Workbenches. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 14 operations across 14 paths, and defines 18 schemas. It is described by OpenAPI 3.2.0, at version 1.0.0.

Requests are made against a single base URL, https://www.tenable.com/downloads/api/v2.

14 operations 14 paths 18 schemas 1 DELETE13 GET

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0.0
Base URL
https://cloud.tenable.com
Authentication
API Key
Resource Areas
1

Authentication & Security 1

Tenable Workbenches API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (Bearer). By default, every request must be authenticated.

  • Bearer — Example: Bearer {{token}}

Paths & Operations 14

Across 14 paths, the API surfaces 14 operations — 1 DELETE, 13 GET. Each is listed below with its method, path, parameters, and response codes.

Workbenches 14
GET
/workbenches/vulnerabilities
List vulnerabilities
workbenches-vulnerabilities 5 params → 200400401403429500
GET
/workbenches/vulnerabilities/{plugin_id}/info
Get plugin details
workbenches-vulnerability-info 6 params → 200401403429500
GET
/workbenches/vulnerabilities/{plugin_id}/outputs
List plugin outputs
workbenches-vulnerability-output 6 params → 200401403429500
GET
/workbenches/assets
List assets
workbenches-assets 6 params → 200401429500
GET
/workbenches/assets/vulnerabilities
List assets with vulnerabilities
workbenches-assets-vulnerabilities 5 params → 200401403429500
GET
/workbenches/assets/{asset_id}/info
Get asset information
workbenches-asset-info 2 params → 200401403429500
GET
/workbenches/assets/{asset_uuid}/activity
Get asset activity log
workbenches-assets-activity 1 param → 200401404429500
GET
/workbenches/assets/{asset_id}/vulnerabilities
List asset vulnerabilities
workbenches-asset-vulnerabilities 6 params → 200401403429500
GET
/workbenches/assets/{asset_id}/vulnerabilities/{plugin_id}/info
Get asset vulnerability details
workbenches-asset-vulnerability-info 7 params → 200401403429500
GET
/workbenches/assets/{asset_id}/vulnerabilities/{plugin_id}/outputs
List asset vulnerabilities for plugin
workbenches-asset-vulnerability-output 7 params → 200401403429500
DELETE
/workbenches/assets/{asset_uuid}deprecated
Delete asset
workbenches-assets-delete 1 param → 202401403404429500
GET
/workbenches/exportdeprecated
Export workbench
workbenches-export-request 12 params → 200400401403429500
GET
/workbenches/export/{file_id}/statusdeprecated
Check export status
workbenches-export-status 1 param → 200401429500
GET
/workbenches/export/{file_id}/downloaddeprecated
Download export file
workbenches-export-download 1 param → 200401429500

Schemas 18

The contract defines 18 schemas that model the data the API accepts and returns. The most detailed are workbenches_workbenches-asset-details (54 properties), workbenches_workbenches-asset (18 properties), workbenches_workbenches-vulnerability-info (13 properties), workbenches_workbenches-vulnerability (12 properties). Each schema is shown below with its type and property counts.

workbenches_workbenches-severity-object
object
3 properties
workbenches_exploit_framework
object
Information about the vulnerability in a specific exploit framework.
2 properties
workbenches_exploit
object
2 properties
workbenches_workbenches-asset
object
18 properties
workbenches_workbenches-asset-activity
object
7 properties
workbenches_AcrDriversObject
object
Asset characteristic that factored into the Asset Criticality Rating (ACR) calculation. For more details see [Lumin Metrics](https://docs.tenable.com/vulnerabi…
2 properties
workbenches_workbenches-assets-with-vulns
array
workbenches_AcrScanFrequencyObject
object
The interval, frequency, and licensing information for the scans of the asset.
3 properties
workbenches_workbenches-source-object
object
3 properties
workbenches_ErrorResponse
object
3 properties
workbenches_workbenches-vulnerability
object
12 properties
workbenches_workbenches-activity-source
object
3 properties
workbenches_workbenches-vulnerability-info
object
13 properties
workbenches_workbenches-plugin-outputs
array
A list of vulnerabilities discovered by the plugin.
workbenches_workbenches-assets
array
An array of asset objects.
workbenches_Error
object
1 property
workbenches_workbenches-asset-details
object
54 properties
workbenches_workbenches-tag-object
object
6 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

tenable-workbenches-api-openapi.yml Raw ↑

Other APIs Tenable publishes across the network.

Tenable About API
Tenable Access Control (API) API
Tenable Access Control (Groups) API
Tenable Access Control (Permissions) API
Tenable Access Control (Roles) API
Tenable Access Control (Users) API
Tenable Access Groups v1 API
Tenable Access Groups v2 API
Tenable Account Groups API
Tenable Accounts API
Tenable Activity Log API
Tenable AD object API
Where this information came from

This is an independent, third-party profile of Tenable Workbenches API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.