For Agents
Programmatically list workbench alerts, get alert details. Covers 52 operations with bearer authentication.
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Trend Vision One API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
# On the machine that will host your Jentic One instance:
curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | sh# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with Trend Vision One API API.
List Workbench Alerts
Get Alert Details
Update Alert Status
Add Suspicious Objects
Delete Suspicious Objects
GET STARTED
Use for: I need to workbench alerts, I want to alert details, Search for alert status, Find all add suspicious objects
Not supported: Does not handle payments, communications, or crm — use for security only.
Trend Micro Vision One (formerly XDR) REST API v3.0. Provides programmatic access to detection, response, threat intelligence, and security operations capabilities including alerts, suspicious objects, endpoint actions, email actions, network security, and workbench management. The API exposes 52 endpoints secured with bearer authentication.
Patterns agents use Trend Vision One API API for, with concrete tasks.
★ Security Operations
Use the Trend Vision One API to perform security operations programmatically. The API provides 52 endpoints covering core functionality including list workbench alerts, get alert details, update alert status.
Call GET /v3.0/workbench/alerts to list workbench alerts
Automated Alerts Management
Automate alerts operations by combining multiple Trend Vision One API endpoints. Agents can get alert details and then update alert status in a single workflow.
Call GET /v3.0/workbench/alerts/{alertId} to get alert details, then verify the result
AI Agent Integration via Jentic
AI agents discover and call Trend Vision One API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.
Search Jentic for 'list workbench alerts', load the operation schema, and execute with Jentic-managed credentials
52 endpoints — trend micro vision one (formerly xdr) rest api v3.
METHOD
PATH
DESCRIPTION
/v3.0/workbench/alerts
List Workbench Alerts
/v3.0/workbench/alerts/{alertId}
Get Alert Details
/v3.0/workbench/alerts/{alertId}
Update Alert Status
/v3.0/threatintel/suspiciousObjects
Add Suspicious Objects
/v3.0/threatintel/suspiciousObjects
List Suspicious Objects
/v3.0/threatintel/suspiciousObjects/delete
Delete Suspicious Objects
/v3.0/threatintel/suspiciousObjectExceptions
Add Suspicious Object Exceptions
/v3.0/threatintel/suspiciousObjectExceptions
List Suspicious Object Exceptions
/v3.0/workbench/alerts
List Workbench Alerts
/v3.0/workbench/alerts/{alertId}
Get Alert Details
/v3.0/workbench/alerts/{alertId}
Update Alert Status
/v3.0/threatintel/suspiciousObjects
Add Suspicious Objects
/v3.0/threatintel/suspiciousObjects
List Suspicious Objects
Three things that make agents converge on Jentic-routed access.
Credential isolation
Trend Vision One API bearer credentials are stored encrypted in the Jentic vault (MAXsystem). Agents receive scoped access tokens — raw secrets never enter the agent context.
Intent-based discovery
Agents search by intent (e.g., 'list workbench alerts') and Jentic returns the matching Trend Vision One API operation with its input schema, so the agent can call the right endpoint without browsing docs.
Time to first call
Direct Trend Vision One API integration: 1-3 days for auth handling, response parsing, and error cases. Through Jentic: under 1 hour — search, load schema, execute.
Alternatives and complements available in the Jentic catalogue.
Snyk
Alternative security API
Choose Snyk when you need a different approach to security operations
Crowdstrike
Alternative security API
Choose Crowdstrike when you need a different approach to security operations
Specific to using Trend Vision One API API through Jentic.
What authentication does the Trend Vision One API use?
The Trend Vision One API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in the MAXsystem vault and injected at execution time, so raw secrets never enter the agent context.
Can I list workbench alerts with the Trend Vision One API?
Yes. Use the GET /v3.0/workbench/alerts endpoint. The API returns structured JSON responses that agents can parse and act on directly.
What are the rate limits for the Trend Vision One API?
Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.
How do I list workbench alerts through Jentic?
Install the Jentic SDK with pip install jentic, authenticate at https://app.jentic.com/sign-up, then search for 'list workbench alerts'. Jentic returns the matching Trend Vision One API operation with its input schema. Load the schema and execute the call — credentials are injected automatically.
How many endpoints does the Trend Vision One API have?
The Trend Vision One API exposes 52 endpoints covering alerts, suspicious objects, suspicious object exceptions operations.
/v3.0/threatintel/suspiciousObjects/delete
Delete Suspicious Objects
/v3.0/threatintel/suspiciousObjectExceptions
Add Suspicious Object Exceptions
/v3.0/threatintel/suspiciousObjectExceptions
List Suspicious Object Exceptions