How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

UpGuard risks API

The risks API from UpGuard — 13 operation(s) for risks.

UpGuard risks API is one of 18 APIs that UpGuard publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Risks. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 13 operations across 13 paths, and defines 37 schemas. It is described by OpenAPI 2.0, at version 1.13.2.

Requests are made against the base URL https://cyber-risk.upguard.com/api/public.

13 operations 13 paths 37 schemas 13 GET

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 2.0
API Version
1.13.2
Base URL
https://cyber-risk.upguard.com/api/public
Authentication
API Key
Resource Areas
1

Authentication & Security 1

UpGuard risks API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (API key in header). By default, every request must be authenticated.

Paths & Operations 13

Across 13 paths, the API surfaces 13 operations — 13 GET. Each is listed below with its method, path, parameters, and response codes.

risks 13
GET
/available_risksdeprecated
Get a list of available risks in the platform
available_risks → 200422429500
GET
/available_risks/risk
Get details for a risk in the platform
risk 1 param → 200422429500
GET
/available_risks/v2
Get a list of available risks in the platform
available_risks_v2 2 params → 200422429500
GET
/risks
Get a list of active risks for your account
risks 3 params → 200422429500
GET
/risks/diff
Get a list of risk changes for your account
org_risks_diff 3 params → 200422429500
GET
/risks/vendors
Get a list of active risks for a vendor
vendor_risks 5 params → 200422429500
GET
/risks/vendors/all
Get portfolio risk profile overview
vendor_risk_overview_params 18 params → 200403422429500
GET
/risks/vendors/diff
Get a list of risk changes for a vendor
vendor_risks_diff 4 params → 200403404422429500
GET
/risks/vendors/diffs
Get a list of risk changes for monitored vendors
vendors_risks_diff 4 params → 200403404422429500
GET
/risks/vendors/hostnames
Get vendor hostnames affected by a risk
get_vendor_hostnames_with_risk_params 3 params → 200403422429500
GET
/risks/vendors/questionnairesdeprecated
Get a list of questionnaire risks for one or more watched vendors or a specific questionnaire
vendor_questionnaire_risks 5 params → 200403422429500
GET
/risks/vendors/questionnaires/v2
(V2) Get a list of questionnaire risks for one or more watched vendors or a specific questionnaire
vendor_questionnaire_risks_v2 6 params → 200403422429500
GET
/risks/vendors_with_risk
Get vendors affected by a risk
get_vendors_with_risk_params 17 params → 200403404422429500

Schemas 37

The contract defines 37 schemas that model the data the API accepts and returns. The most detailed are Risk (15 properties), SummaryDiff (14 properties), QuestionnaireRiskV2 (14 properties), RiskDiff (13 properties). Each schema is shown below with its type and property counts.

Diff
object
12 properties
ExternalVendorsWithRiskResponse
object
5 properties
SummaryDiff
object
14 properties
endpointError
object
Error details coming from an endpoint
1 property
VendorRiskOverviewV1ResponsePayload
object
2 properties
VendorsRiskDiffs
object
5 properties
DiffStatus
string
AvailableRisk
object
9 properties
Diffs
array
QuestionnaireRisksResponsePayloadBody
object
3 properties
RiskDiffGroup
object
5 properties
externalVendorWithRisk
object
13 properties
ValueMetadataURL
object
2 properties
QuestionnaireRisksResponsePayloadBodyV2
object
3 properties
StringSlice
array
SummaryDiffGroup
object
5 properties
VendorDiff
object
6 properties
ScanDiff
object
5 properties
externalSurveyMini
object
3 properties
externalVendorRisk
object
13 properties
externalEvidence
object
3 properties
RiskDiff
object
13 properties
externalHostnameRisk
object
6 properties
AvailableRiskV2
object
12 properties
QuestionnaireRisk
object
13 properties
QuestionnaireRiskWaiver
object
5 properties
QuestionnaireRiskV2
object
14 properties
ExternalVendorHostnamesWithRiskResponse
object
2 properties
externalLabel
object
2 properties
GetRisksV1RespBody
object
1 property
VendorsRisksDiffResponsePayloadBody
object
3 properties
ScanResult
object
3 properties
Risk
object
15 properties
RiskWaiver
object
7 properties
Severity
integer
RisksDiffResponsePayloadBody
object
2 properties
ValueMetadata
object
4 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

upguard-risks-api-openapi.yml Raw ↑

Other APIs UpGuard publishes across the network.

UpGuard breaches API
UpGuard bulk API
UpGuard dataleaks API
UpGuard domains API
UpGuard ips API
UpGuard labels API
UpGuard notifications API
UpGuard organisation API
UpGuard reports API
UpGuard subsidiaries API
UpGuard threatmonitoring API
UpGuard trust_exchange API
Where this information came from

This is an independent, third-party profile of UpGuard risks API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.