For the complete documentation index, see llms.txt. This page is also available as Markdown.

REST API

Use the Panther REST API to interact with your Panther entities

Overview

Panther offers a REST API to interact with certain parts of your Panther instance. Currently, you can interact with the following entities through the REST API:

Additional operations are available in the GraphQL API.

Discover the Panther REST API schema

Discover the REST API schema by downloading the OpenAPI specification file:

Download panther-labs-api.yaml

You can discover the API schema by browsing the API Playground in your Panther Console. Learn more on API Playground.

How to use the Panther REST API

Step 1: Identify your Panther REST API URL

To locate your REST API URL:

  • At the bottom of the left-hand navigation bar in your Panther Console, click Settings, then navigate to Developer Tools > API Tokens. At the top of the page, see the API URL.

    • If you are running a SaaS deployment of Panther, your REST URL will be the portion shown below:

    An "API Tokens" section shows a blurred-out API URL
    • If you are running a Cloud Connected or self-hosted deployment of Panther, the URL will be the portion shown below (inclusive of /v1):

    An "API Tokens" section shows a blurred-out API URL

Step 2: Generate an API token

Step 3: Invoke the Panther REST API

In addition to testing with the API Playground in the Console, you can invoke the REST API using Swagger, Postman, or this documentation:

Using Swagger to access the REST API

  1. In a web browser, navigate to the Swagger Editor.

  2. In the code editor on the left-hand side, paste in the Panther REST OpenAPI specification file found above, in Discover the Panther REST API schema.

  3. On the right-hand side, under Server variables, in api_host, enter your Panther REST API URL without the protocol (i.e., excluding https://). A "Server variables" section shows an api_host

  4. Click Authorize. An Authorize button

  5. In the Available authorizations modal:

    1. Under Value, enter your API token value.

    2. Click Authorize.

    3. Click Close. An "Available authorizations" section shows "ApiKeyAuth" section, with a "Value" field. There are "Authorize" and "Close" buttons.

  6. You can now try invoking the API:

    1. Choose an endpoint, and expand it by clicking the arrow pointing down.

    2. Click Try it out. A  "GET /globals" section has a "Try it out" button

    3. Click Execute.

Using Postman to access the REST API

You will import the Panther Postman collection, create a new environment with URL and API variables, then try making a request.

  1. Download the Panther_REST_API_postman_collection.json file at the bottom of this tab.

  2. In your Postman application, click File > Import.

  3. Choose the Panther_REST_API_postman_collection.json file.

    • Under Collections, there will now be a Panther Rest API collection.

  4. Click Environments, then click the plus sign (+). A "My Workspace" section has a plus button with the tooltip "Create new environment"

  5. Enter a name for your environment—e.g., "Panther."

  6. In the table on the right-hand side, enter the following two variables:

    • restHost: For the Current value, enter your full Panther REST API URL.

    • restApiToken: For the Current value, enter your Panther API token. In the Type column, select secret.

      A table is shown with two rows filled in: one for restHost and one for restApiToken. There is a Type and Current value for each.
  7. In the upper-right corner, click Save.

  8. You can now try making a request:

    1. In the upper-right hand corner, click the environment dropdown, and select the one you created in the previous step. A drop-down field shows two options: "No Environment" and "Panther"

    2. Click Collections.

    3. Expand the Panther Rest API collection, then select a request.

    4. Click Send.

Using the Panther documentation to access the REST API

  1. Navigate to one of the REST API entity pages (nested under this page), and locate the operation you'd like to perform.

  2. In the bottom-right corner of the operation's Request tile, click â–¶Test it.

    A "Get an alert" section includes cards for "Path parameters," "Responses," and "Authorizations." The "Test it" button is circled.
  3. In the modal that pops up, in the endpoint displayed at the top, click {api_host}. In a URL value, the {api_host} section is circled.

  4. In the api_host field, enter the REST API URL you identified in Step 1, without the protocol (i.e., excluding https://). There is a circle around "api_host: my-REST-API-URL."

  5. In the Authentication section, click the Auth Type dropdown.

    1. Under Required authentication, check the box next to ApiKeyAuth. Under an "Authentication" header, an arrow is drawn from an "ApiKeyAuth" button to a value labeled "ApiKeyAuth."

    2. Under Authentication, Name and Value fields will populate. In Value, enter the API token you generated in Step 2.

  6. In the Variables section, if the operation has required path variables, such as {id}, provide value(s) in the VALUE column. Under a "Get an alert" title, there are sub-sections titled Authentication, Variables, and Cookies. The value of "id" within Variables is circled.

  7. If there are values in the Query Parameters section, if you would like them to apply to this invocation, click their checkboxes in the right-hand column. A "Query Parameters" header is over a table with columns for "KEY," "VALUE," and a three-lines icon. There are two rows filled in, and the third column is circled.

  8. If a request body is required for your request, add content within Body.

  9. Click Send Request.

Last updated

Was this helpful?