Skip to main content
GET
Read the IoC feed (enterprise-only)
Enterprise-only. Kyberis must explicitly enable feed access for your account. A standard plan or an API key alone does not grant access. Contact [email protected] to arrange access.
Use the feed to maintain a local set of indicators of compromise for matching and investigation. Start with a paginated snapshot, then retrieve additions, updates, and removals using a saved cursor. The feed is published daily; it is not a live stream or a record of every change between publications.

Access and credits

Use Authorization: ApiKey <key_id>:<secret> or Authorization: Bearer <access_token>. See authentication. This endpoint does not require an agent_context body or agent-context headers. Normal account and credential rate limits apply. The exact charge is ceil(upserts / 100): 5 or 100 upserts cost 1 credit, 101 cost 2, and 1,000 cost 10. Removals count toward page size but not the charge. A mixed page of 100 upserts and 900 removals costs 1 credit. Smaller pages can increase rounding costs. A 500,000-record snapshot retrieved in full pages costs 5,000 credits.

Retrieve the first page

Set KYBERIS_API_KEY to your API key credential (<key_id>:<secret>):
Omit cursor for the initial snapshot. There is no request that returns the entire dataset without pagination. Dataset size changes as indicators become eligible or are removed.

Continue pages and daily polling

Use the previous response’s next_cursor as the cursor query parameter:
  1. Apply each record to your local dataset using id as the key. Replace or insert on upsert; delete on remove, even if the ID is already absent.
  2. Save next_cursor atomically with those local changes.
  3. While has_more is true, fetch the next page immediately.
  4. When has_more is false, keep the returned cursor and resume with it at your next poll, typically 24 hours later. Save the returned cursor even on an empty page.
The snapshot remains consistent while you page through it. After its last page, the cursor continues into incremental changes. A poll returns changes published since your checkpoint, potentially across several pages. Do not restart a snapshot for each daily poll or run parallel pagination chains against the same local dataset. Treat cursors as opaque strings and URL-encode them.

Select a confidence interval

The default feed includes all eligible indicators, including those with unknown source confidence. You can select a confidence interval on the first request: For example, ?min_confidence=40&max_confidence=65 selects [40,65). ?min_confidence=65 includes scores from 65 through 100. An explicit max_confidence=100 excludes 100; omit the maximum to include it. Fractional bounds are supported. Unknown confidence is excluded whenever either bound is specified, including min_confidence=0. Confidence describes source threat confidence, not freshness. The selected bounds are fixed in the cursor. Subsequent requests should send only cursor and optional limit, or repeat identical bounds. Changing a bound returns 400 cursor_filter_mismatch. Start a new snapshot to change selection. An indicator entering your interval produces an upsert; one leaving it produces a free removal. For example, a score falling from 70 to 50 produces a removal for a consumer using min_confidence=65, but an update for one using min_confidence=40. Each consumer should keep its own dataset and cursor. Cursors belong to the account, not a particular API key. Overlapping downloads by separate consumers are each billable. Unsupported or duplicate query parameters are rejected. Type, country, industry, not_older_than, and verbose filters are not supported.

Read the response

This illustrative incremental page contains one upsert and one removal. Cursor strings in examples are placeholders.
Upserts include id, operation, type, value, changed_at, freshness_at, and freshness_basis. confidence is omitted when unknown. last_seen is actual source observation time and is omitted when unavailable. freshness_basis is last_seen or last_feed_occurrence; a feed occurrence describes source feed recency, not a confirmed malicious sighting. changed_at indicates when the feed detected the change, not when malicious activity occurred. Removals contain only id, operation, and changed_at. They include withdrawals, indicators aging out, and indicators leaving a selected confidence interval. A quiet poll returns records: [], has_more: false, a new checkpoint, and zero credits. The feed contains minimal indicators, not enriched investigation results or internal lifecycle fields. Use IoC assessment for a separate, billable investigation of an indicator.

Cursor expiry and recovery

Feed history is retained for seven days from each publication’s evaluation cutoff. A cursor expires with its retained base publication; each page does not reset that clock. Catching up to a newer publication advances the checkpoint. Complete initial snapshots promptly and poll regularly. On 410 snapshot_required, build a replacement snapshot without a cursor and replace your local dataset after completing all its pages. Reapply your confidence bounds when starting it. The replacement snapshot is billable. A cursor invalidated by signing-key rotation also requires a fresh snapshot.

Errors and retries

Replaying a cursor lets you apply records idempotently, but every successful response is charged again for its upserts. Request IDs do not deduplicate charges. A connection failure after a debit commits may leave you charged without receiving the response; retrying is a new retrieval. Validation and access errors before a debit do not charge. Keep your last successfully applied cursor on errors.

Authorizations

Authorization
string
header
required

ApiKey <key_id>:

Query Parameters

cursor
string | null
Required string length: 1 - 4096
limit
integer
default:1000
Required range: 1 <= x <= 1000
min_confidence
number | null

Inclusive source-confidence minimum. Fixed for this cursor chain.

Required range: 0 <= x <= 100
max_confidence
number | null

Exclusive source-confidence maximum. Omit to include 100. Must exceed the minimum (or zero).

Required range: 0 <= x <= 100

Response

Successful Response

as_of
string<date-time>
required
credits_charged
integer
required
has_more
boolean
required
mode
enum<string>
required
Available options:
snapshot,
incremental
next_cursor
string
required
records
FeedRecord · object[]
required