canonical: https://jentic.com/apis/sysdig.com/sysdig

# Sysdig Secure API

Sysdig Secure REST API for cloud-native security. Provides programmatic access to runtime security, vulnerability management, compliance, posture management, identity and access management features. The API exposes 65 endpoints secured with bearer authentication.

## For AI agents

Programmatically create a runtime policy, list runtime policies. Covers 65 operations with bearer authentication.

## Scope

Does not handle payments, communications, or crm - use for security only.

## Capabilities

- Create a runtime policy
- List runtime policies
- Get policy by ID
- Update a runtime policy
- Delete a runtime policy

## Use cases

### Security Operations

Use the Sysdig Secure API to perform security operations programmatically. The API provides 65 endpoints covering core functionality including create a runtime policy, list runtime policies, get policy by id.

Example prompt: Call POST `/api/v1/secure/policies` to create a runtime policy

### Automated Policies Management

Automate policies operations by combining multiple Sysdig Secure API endpoints. Agents can list runtime policies and then get policy by id in a single workflow.

Example prompt: Call GET `/api/v1/secure/policies` to list runtime policies, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Sysdig Secure API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.

Example prompt: Search Jentic for 'create a runtime policy', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | `/api/v1/secure/policies` | Create a runtime policy |
| GET | `/api/v1/secure/policies` | List runtime policies |
| GET | `/api/v1/secure/policies/{id}` | Get policy by ID |
| PUT | `/api/v1/secure/policies/{id}` | Update a runtime policy |
| DELETE | `/api/v1/secure/policies/{id}` | Delete a runtime policy |
| POST | `/api/v1/secure/rules` | Create a rule |
| GET | `/api/v1/secure/rules` | List rules |
| GET | `/api/v1/secure/rules/{id}` | Get rule by ID |

## Key resources

- **Policies** — Operations related to Policies
- **Rules** — Operations related to Rules
- **Alerts** — Operations related to Alerts
- **Vulnerabilities** — Operations related to Vulnerabilities
- **Scanning** — Operations related to Scanning

## Why Jentic

- **Setup:** Wiring the Sysdig Secure API by hand means learning its bearer token scheme, choosing the right regional host from us1 through us4 or eu1 on sysdig.com, and shaping the policy and rule requests yourself. Through Jentic you install once, import Sysdig Secure from the API Directory, store the bearer token once, and your agent calls it.
- **Permission scoping:** Sysdig puts the policy and rule ids in the URL path (`/secure/policies/{id}`, `/secure/rules/{id}`), so a rule can pin your agent to one policy: it can read and update that policy and nothing else. You choose the operations it may call, so destructive ones like deleting a policy or rule are not included unless you add them.
- **Credential handling:** Your Sysdig bearer token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'create a runtime policy' or 'list secure rules', and Jentic returns the matching Sysdig operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Snyk** — Alternative security API
- **Crowdstrike** — Alternative security API

## FAQ

### What authentication does the Sysdig Secure API use?

The Sysdig Secure API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I create a runtime policy with the Sysdig Secure API?

Yes. Use the POST `/api/v1/secure/policies` endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Sysdig Secure API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I create a runtime policy through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'create a runtime policy'. Jentic returns the matching Sysdig Secure API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Sysdig Secure API have?

The Sysdig Secure API exposes 65 endpoints covering policies, rules, alerts operations.

### Can I limit what my agent is allowed to do with the Sysdig Secure API?

Yes. Jentic One is self-hosted by you, so your own rules decide which Sysdig Secure operations and credentials the agent may use. Because Sysdig puts policy and rule ids in the URL path, such as `/api/v1/secure/policies/{id}` and `/api/v1/secure/rules/{id}`, you can pin the agent to a single policy so it only reads and updates that one and nothing else. You also choose the operations it can call, so destructive ones like deleting a policy or rule stay out unless you explicitly add them.
