canonical: https://jentic.com/apis/bifrost.cyble.ai/bifrost

# Bifrost Cyble Alerts Management API

The Alerts Management API is part of Cyble's Bifrost threat-intelligence platform. An agent can fetch security alerts, filter them, update their status, and attach comments, as well as pull breach details for a given record and list the companies, users, and services an alert can be scoped to. It gives an agent a programmatic view of the alerts raised against monitored assets.

## For AI agents

Triage threat-intelligence alerts with the Cyble Bifrost Alerts Management API: fetch, filter, update, and comment on alerts, and pull breach details. Secured with a bearer token.

## Scope

Does not handle endpoint protection or firewall configuration - use it to manage threat-intelligence alerts and breach details only.

## Capabilities

- Fetch and filter security alerts
- Update alert status
- Add comments to an alert
- Retrieve breach details for a record
- List the companies, users, and services behind alerts

## Use cases

### Triage security alerts

Work through the alert queue automatically. The agent fetches alerts, applies the available filters, and updates the status of each one as it is reviewed.

Example prompt: Call POST `/ar-apollo-v2/api/v2/y/alerts`, then PUT `/ar-apollo-v2/api/v2/y/alerts` to update status

### Investigate a breach

Dig into the detail behind an alert. The agent retrieves breach details for a record so an analyst can see exactly what was exposed.

Example prompt: Call GET `/engine/api/v1/y/breach-details/{s3Key}` for the record under review

### Collaborate on an alert

Keep an audit trail on each alert. The agent adds comments so the handling of an alert is recorded for the rest of the security team.

Example prompt: Call POST `/ar-apollo-v2/api/v2/y/alerts/{alertId}/comments` with the note

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | `/ar-apollo-v2/api/v2/y/alerts` | Fetch alerts |
| PUT | `/ar-apollo-v2/api/v2/y/alerts` | Update alerts |
| POST | `/ar-apollo-v2/api/v2/y/alerts/filter/data` | Fetch available filter data |
| POST | `/ar-apollo-v2/api/v2/y/alerts/{alertId}/comments` | Add a comment to an alert |
| GET | `/engine/api/v1/y/breach-details/{s3Key}` | Get breach details by S3 key |
| GET | `/ar-apollo-v2/api/v2/y/services` | Fetch allowed services for alerts |
| GET | `/ar-apollo-v2/api/v2/y/companies` | Fetch companies |
| GET | `/ar-apollo-v2/api/v2/y/users` | Fetch users |

## Key resources

- **Alerts** — Security alerts raised against monitored assets
- **Breach Details** — The detailed record behind a breach alert
- **Companies** — Companies that alerts can be scoped to
- **Users** — Users associated with alerts
- **Services** — The services an alert can be filtered by

## AI readiness

This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.

- **Score:** 67 / 100
- **Maturity:** AI-Aware
- **Dimensions:**
  - Foundational Compliance: 87 / 100
  - Developer Experience & Jentic Compatibility: 65 / 100
  - AI-Readiness & Agent Experience: 47 / 100
  - Agent Usability: 94 / 100
  - Security: 75 / 100
  - AI Discoverability: 69 / 100
- **View full report:** https://jentic.com/apis/bifrost.cyble.ai/bifrost/scorecard
- **How the score is calculated:** https://docs.jentic.com/reference/api-readiness-framework/overview/
- **More about the dimensions:** https://docs.jentic.com/reference/api-readiness-framework/specification/#dimensional-model-overview

### Score it yourself

Every API in the directory is allowlisted, so you can re-score it with no key required.

- **Score your own API:** https://jentic.com/scorecard.md
- **Scoring CLI agent skill:** https://github.com/jentic/jentic-api-scorecard/blob/main/skills/jentic-api-scorecard/SKILL.md

```sh
npx @jentic/api-scorecard-cli score <openapi-url>
```

## Why Jentic

- **Setup:** Wiring the Alerts Management API by hand means obtaining a bearer token, pointing at the bifrost.cyble.ai host, and shaping the alert and breach-detail requests yourself. Through Jentic you install once, import Cyble Bifrost from the Jentic API Directory, store the token once, and your agent calls it.
- **Permission scoping:** Bifrost puts the alert id in the URL path (`/ar-apollo-v2/api/v2/y/alerts/{alertId}/comments`), so a rule can pin your agent to one alert and nothing else. You choose which operations it may call, so state-changing ones like updating an alert are not included unless you add them.
- **Credential handling:** Your Cyble Bifrost bearer token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'fetch open security alerts' or 'get breach details', and Jentic returns the matching Bifrost operation with its input schema so the agent calls the right endpoint without browsing the reference.

## Related APIs

- **Pulsedive** — Alternative threat intelligence API
- **Shodan** — Complementary attack-surface search API
- **Censys** — Complementary internet asset data API

## FAQ

### What authentication does the Alerts Management API use?

The Alerts Management API uses a bearer token in the Authorization header. Through Jentic, that token is stored encrypted in your Jentic One instance and injected at execution time, so the raw secret never enters the agent context.

### What can an agent do with the Alerts Management API?

It can fetch and filter security alerts, update their status, attach comments, pull breach details for a record, and list the companies, users, and services behind alerts. Responses are structured so an agent can act on them directly.

### Can I retrieve breach details through the Alerts Management API?

Yes. The API returns breach details for a given record key, so an agent can surface what was exposed when it works through an alert.

### What are the rate limits for the Alerts Management API?

Rate limits are not specified in the OpenAPI spec. Check the Cyble documentation for current limits. Through Jentic, retries are handled in the execution layer.

### How many endpoints does the Alerts Management API have?

The Alerts Management API exposes 8 endpoints covering alerts, breach details, companies, users, and services.

### Can I limit what my agent is allowed to do with the Alerts Management API?

Yes. Jentic One is self-hosted by you, so your own rules decide which Bifrost operations your agent may call. Because Bifrost puts the alert id in the URL path, such as `/ar-apollo-v2/api/v2/y/alerts/{alertId}/comments`, a rule can pin the agent to a single alert and nothing else. You also choose which operations it may call, so state-changing ones like PUT `/ar-apollo-v2/api/v2/y/alerts` to update an alert are excluded unless you add them.
