Install Jentic One Beta
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Alerts Management API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.
Step 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fbifrost.cyble.ai%2Fbifrost" | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fbifrost.cyble.ai%2Fbifrost" | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with Alerts Management API.
Fetch and filter security alerts
Update alert status
Add comments to an alert
Retrieve breach details for a record
List the companies, users, and services behind alerts
GET STARTED
Patterns agents use Alerts Management API for, with concrete tasks.
★ Triage security alerts
Work through the alert queue automatically. The agent fetches alerts, applies the available filters, and updates the status of each one as it is reviewed.
Call POST /ar-apollo-v2/api/v2/y/alerts, then PUT /ar-apollo-v2/api/v2/y/alerts to update status
Investigate a breach
Dig into the detail behind an alert. The agent retrieves breach details for a record so an analyst can see exactly what was exposed.
Call GET /engine/api/v1/y/breach-details/{s3Key} for the record under review
Collaborate on an alert
Keep an audit trail on each alert. The agent adds comments so the handling of an alert is recorded for the rest of the security team.
Call POST /ar-apollo-v2/api/v2/y/alerts/{alertId}/comments with the note
8 endpoints — the alerts management api is part of cyble's bifrost threat-intelligence platform.
METHOD
PATH
DESCRIPTION
/ar-apollo-v2/api/v2/y/alerts
Fetch alerts
/ar-apollo-v2/api/v2/y/alerts
Update alerts
/ar-apollo-v2/api/v2/y/alerts/filter/data
Fetch available filter data
/ar-apollo-v2/api/v2/y/alerts/{alertId}/comments
Add a comment to an alert
/engine/api/v1/y/breach-details/{s3Key}
Get breach details by S3 key
/ar-apollo-v2/api/v2/y/services
Fetch allowed services for alerts
/ar-apollo-v2/api/v2/y/companies
Fetch companies
/ar-apollo-v2/api/v2/y/users
Fetch users
/ar-apollo-v2/api/v2/y/alerts
Fetch alerts
/ar-apollo-v2/api/v2/y/alerts
Update alerts
/ar-apollo-v2/api/v2/y/alerts/filter/data
Fetch available filter data
/ar-apollo-v2/api/v2/y/alerts/{alertId}/comments
Add a comment to an alert
/engine/api/v1/y/breach-details/{s3Key}
Get breach details by S3 key
/ar-apollo-v2/api/v2/y/services
Fetch allowed services for alerts
/ar-apollo-v2/api/v2/y/companies
Fetch companies
/ar-apollo-v2/api/v2/y/users
Fetch users
What agents get from Jentic-routed access to this vendor.
Setup
Wiring the Alerts Management API by hand means obtaining a bearer token, pointing at the bifrost.cyble.ai host, and shaping the alert and breach-detail requests yourself. Through Jentic you install once, import Cyble Bifrost from the Jentic API Directory, store the token once, and your agent calls it.
Permission scoping
Bifrost puts the alert id in the URL path (/ar-apollo-v2/api/v2/y/alerts/{alertId}/comments), so a rule can pin your agent to one alert and nothing else. You choose which operations it may call, so state-changing ones like updating an alert are not included unless you add them.
Credential isolation
Your Cyble Bifrost bearer token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
Intent-based discovery
Agents search Jentic by intent such as 'fetch open security alerts' or 'get breach details', and Jentic returns the matching Bifrost operation with its input schema so the agent calls the right endpoint without browsing the reference.
Alternatives and complements available in the Jentic catalogue.
Specific to using Alerts Management API through Jentic.
What authentication does the Alerts Management API use?
The Alerts Management API uses a bearer token in the Authorization header. Through Jentic, that token is stored encrypted in your Jentic One instance and injected at execution time, so the raw secret never enters the agent context.
What can an agent do with the Alerts Management API?
It can fetch and filter security alerts, update their status, attach comments, pull breach details for a record, and list the companies, users, and services behind alerts. Responses are structured so an agent can act on them directly.
Can I retrieve breach details through the Alerts Management API?
Yes. The API returns breach details for a given record key, so an agent can surface what was exposed when it works through an alert.
What are the rate limits for the Alerts Management API?
Rate limits are not specified in the OpenAPI spec. Check the Cyble documentation for current limits. Through Jentic, retries are handled in the execution layer.
How many endpoints does the Alerts Management API have?
The Alerts Management API exposes 8 endpoints covering alerts, breach details, companies, users, and services.
Can I limit what my agent is allowed to do with the Alerts Management API?
Yes. Jentic One is self-hosted by you, so your own rules decide which Bifrost operations your agent may call. Because Bifrost puts the alert id in the URL path, such as /ar-apollo-v2/api/v2/y/alerts/{alertId}/comments, a rule can pin the agent to a single alert and nothing else. You also choose which operations it may call, so state-changing ones like PUT /ar-apollo-v2/api/v2/y/alerts to update an alert are excluded unless you add them.
Know of an official OpenAPI document? Contribute it →
For Agents
Triage threat-intelligence alerts with the Cyble Bifrost Alerts Management API: fetch, filter, update, and comment on alerts, and pull breach details. Secured with a bearer token.
Use for: Fetch open security alerts, Update the status of an alert, Add a comment to an alert, Get breach details for a record
Not supported: Does not handle endpoint protection or firewall configuration - use it to manage threat-intelligence alerts and breach details only.
The Alerts Management API is part of Cyble's Bifrost threat-intelligence platform. An agent can fetch security alerts, filter them, update their status, and attach comments, as well as pull breach details for a given record and list the companies, users, and services an alert can be scoped to. It gives an agent a programmatic view of the alerts raised against monitored assets.
This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.
Base layer of spec validity and structural soundness.
Aggregated quality score from linter diagnostics, weighted by severity.
Percentage of `$ref` references that resolve successfully.
Checks whether the API description parses successfully and conforms to its declared specification (e.g., OpenAPI).
Structural correctness score based on schema issues using logarithmic dampening.
Clarity, completeness, and ingestion readiness for developers and tooling.
How richly the API is illustrated with examples.
Percentage of examples that conform to their schemas.
Percentage of operations with complete response definitions (success, client error, server error).
Health of API ingestion, bundling, and resolution within Jentic pipelines.
Semantic breadth, depth, and agent comprehension for AI systems.
Coverage of descriptions across API elements.
Coverage of RFC 9457 Problem Details for error responses.
Coverage, uniqueness, and casing consistency of operationIds for AI inference.
Coverage of summaries across operations/tags/info.
Functional utility, complexity comfort, and AI orchestration readiness.
Agent comfort level based on API operational and structural complexity.
Trust, risk posture, and security compliance.
Average quality of security schemes based on authentication method strength (weakest link for OAuth2).
Findability, semantic richness, and reasoning readiness.
Clarity and depth of descriptions across API elements.
Score it yourself
Every API in the directory is allowlisted, so you can re-score it with no key required.
npx @jentic/api-scorecard-cli score <openapi-url>