API Capabilities
The API covers alert ingestion, incident and event updates, historical state, bulk jobs, and MCP access.
Two-Way Integration
Pull alerts into your tools. Send incident and event status, assignees, comments, and remediation results back to CloudSEK.
Current and Historic Alerts
Read current or historic alerts from XVigil, BeVigil, and SVigil. Filter results by severity, category, or time range.
Changelog and Snapshots
Resume changelog polling from your last cursor. Use snapshots to reconcile the current incident or event state.
Bulk Operations
Submit one action for many incidents or events. Poll the returned job ID for per-record results.
API Explorer
Set your token, enter the request fields, and call an endpoint from its reference page. The response appears beside the request.
Bearer Token Authentication
Send the token in the Authorization header. One Alerts API token covers reads and writes; tokens issued from 30 July 2026 include write access.
Model Context Protocol
Investigate and act with CloudSEK MCP
Ask your AI client to inspect live CloudSEK data, correlate it with Global Threat Intelligence, and make controlled updates. CloudSEK MCP uses the hosted endpoint at https://api.cloudsek.com/mcp.
Account data and threat intelligence
Investigate CloudSEK alerts, incidents, events, evidence, and audit history alongside GTI actors, feeds, CVEs, and IOCs.
Read and write operations
Triage records, add comments, change status or ownership, remediate events, and submit bulk updates under the client’s configured approval policy.
Traceable changes
Single-record writes return operation IDs. Bulk jobs return per-record success, skipped, and failed results.
Your choice of MCP client
Connect Claude Desktop, Claude Code, Gemini CLI, Codex CLI, Kiro, Cursor, or a custom MCP client to one hosted endpoint.
Common MCP workflows
Start with a tested prompt, inspect the returned records, and approve writes only after checking the proposed change.