Bounded relationship retrieval for canonical entities
curl --request POST \
--url https://api.example.com/v2/relationships \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"agent_context": {
"objective": "<string>",
"requested_outcome": "<string>",
"run_id": "<string>",
"step_id": "<string>",
"client": {
"agent_name": "<string>",
"agent_version": "<string>",
"framework": "<string>"
},
"constraints": {
"latency_budget_ms": 15025,
"max_results_budget": 100,
"min_resolution_confidence": 0.5,
"strict_mode": true
},
"parent_step_id": "<string>",
"tags": [
"<string>"
]
},
"context": {
"sector": "<string>"
},
"cursor": "<string>",
"expected_types": [
"<string>"
],
"max_results": 10,
"query": "<string>",
"relationship_types": [],
"resolution": {
"include_aliases": false,
"include_metadata": false,
"max_results": 5
},
"subject": {
"canonical_id": "<string>",
"entity_type": "<string>",
"canonical_name": "<string>"
}
}
'import requests
url = "https://api.example.com/v2/relationships"
payload = {
"agent_context": {
"objective": "<string>",
"requested_outcome": "<string>",
"run_id": "<string>",
"step_id": "<string>",
"client": {
"agent_name": "<string>",
"agent_version": "<string>",
"framework": "<string>"
},
"constraints": {
"latency_budget_ms": 15025,
"max_results_budget": 100,
"min_resolution_confidence": 0.5,
"strict_mode": True
},
"parent_step_id": "<string>",
"tags": ["<string>"]
},
"context": { "sector": "<string>" },
"cursor": "<string>",
"expected_types": ["<string>"],
"max_results": 10,
"query": "<string>",
"relationship_types": [],
"resolution": {
"include_aliases": False,
"include_metadata": False,
"max_results": 5
},
"subject": {
"canonical_id": "<string>",
"entity_type": "<string>",
"canonical_name": "<string>"
}
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
agent_context: {
objective: '<string>',
requested_outcome: '<string>',
run_id: '<string>',
step_id: '<string>',
client: {agent_name: '<string>', agent_version: '<string>', framework: '<string>'},
constraints: {
latency_budget_ms: 15025,
max_results_budget: 100,
min_resolution_confidence: 0.5,
strict_mode: true
},
parent_step_id: '<string>',
tags: ['<string>']
},
context: {sector: '<string>'},
cursor: '<string>',
expected_types: ['<string>'],
max_results: 10,
query: '<string>',
relationship_types: [],
resolution: {include_aliases: false, include_metadata: false, max_results: 5},
subject: {canonical_id: '<string>', entity_type: '<string>', canonical_name: '<string>'}
})
};
fetch('https://api.example.com/v2/relationships', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/v2/relationships",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'agent_context' => [
'objective' => '<string>',
'requested_outcome' => '<string>',
'run_id' => '<string>',
'step_id' => '<string>',
'client' => [
'agent_name' => '<string>',
'agent_version' => '<string>',
'framework' => '<string>'
],
'constraints' => [
'latency_budget_ms' => 15025,
'max_results_budget' => 100,
'min_resolution_confidence' => 0.5,
'strict_mode' => true
],
'parent_step_id' => '<string>',
'tags' => [
'<string>'
]
],
'context' => [
'sector' => '<string>'
],
'cursor' => '<string>',
'expected_types' => [
'<string>'
],
'max_results' => 10,
'query' => '<string>',
'relationship_types' => [
],
'resolution' => [
'include_aliases' => false,
'include_metadata' => false,
'max_results' => 5
],
'subject' => [
'canonical_id' => '<string>',
'entity_type' => '<string>',
'canonical_name' => '<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/v2/relationships"
payload := strings.NewReader("{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"sector\": \"<string>\"\n },\n \"cursor\": \"<string>\",\n \"expected_types\": [\n \"<string>\"\n ],\n \"max_results\": 10,\n \"query\": \"<string>\",\n \"relationship_types\": [],\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/v2/relationships")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"sector\": \"<string>\"\n },\n \"cursor\": \"<string>\",\n \"expected_types\": [\n \"<string>\"\n ],\n \"max_results\": 10,\n \"query\": \"<string>\",\n \"relationship_types\": [],\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/v2/relationships")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"sector\": \"<string>\"\n },\n \"cursor\": \"<string>\",\n \"expected_types\": [\n \"<string>\"\n ],\n \"max_results\": 10,\n \"query\": \"<string>\",\n \"relationship_types\": [],\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n }\n}"
response = http.request(request)
puts response.read_body{
"items": [
{
"canonical_id": "<string>",
"canonical_name": "<string>",
"evidence_count": 123,
"score": 123,
"target_entity_type": "<string>",
"last_seen": "<string>",
"metadata": {}
}
],
"max_results": 123,
"metadata": {},
"relationship_types": [],
"resolution": {
"candidates": [
{
"canonical_id": "<string>",
"canonical_name": "<string>",
"entity_type": "<string>",
"match_type": "<string>",
"score": 123,
"aliases": [
"<string>"
],
"matched_on": "<string>",
"metadata": {}
}
],
"canonical_id": "<string>",
"canonical_name": "<string>",
"entity_type": "<string>",
"resolution_confidence": 123
},
"next_cursor": "<string>",
"subject": {
"canonical_id": "<string>",
"entity_type": "<string>",
"canonical_name": "<string>"
}
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"ctx": {},
"input": "<unknown>"
}
]
}Relationships
Retrieve relationships
POST
/
v2
/
relationships
Bounded relationship retrieval for canonical entities
curl --request POST \
--url https://api.example.com/v2/relationships \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"agent_context": {
"objective": "<string>",
"requested_outcome": "<string>",
"run_id": "<string>",
"step_id": "<string>",
"client": {
"agent_name": "<string>",
"agent_version": "<string>",
"framework": "<string>"
},
"constraints": {
"latency_budget_ms": 15025,
"max_results_budget": 100,
"min_resolution_confidence": 0.5,
"strict_mode": true
},
"parent_step_id": "<string>",
"tags": [
"<string>"
]
},
"context": {
"sector": "<string>"
},
"cursor": "<string>",
"expected_types": [
"<string>"
],
"max_results": 10,
"query": "<string>",
"relationship_types": [],
"resolution": {
"include_aliases": false,
"include_metadata": false,
"max_results": 5
},
"subject": {
"canonical_id": "<string>",
"entity_type": "<string>",
"canonical_name": "<string>"
}
}
'import requests
url = "https://api.example.com/v2/relationships"
payload = {
"agent_context": {
"objective": "<string>",
"requested_outcome": "<string>",
"run_id": "<string>",
"step_id": "<string>",
"client": {
"agent_name": "<string>",
"agent_version": "<string>",
"framework": "<string>"
},
"constraints": {
"latency_budget_ms": 15025,
"max_results_budget": 100,
"min_resolution_confidence": 0.5,
"strict_mode": True
},
"parent_step_id": "<string>",
"tags": ["<string>"]
},
"context": { "sector": "<string>" },
"cursor": "<string>",
"expected_types": ["<string>"],
"max_results": 10,
"query": "<string>",
"relationship_types": [],
"resolution": {
"include_aliases": False,
"include_metadata": False,
"max_results": 5
},
"subject": {
"canonical_id": "<string>",
"entity_type": "<string>",
"canonical_name": "<string>"
}
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
agent_context: {
objective: '<string>',
requested_outcome: '<string>',
run_id: '<string>',
step_id: '<string>',
client: {agent_name: '<string>', agent_version: '<string>', framework: '<string>'},
constraints: {
latency_budget_ms: 15025,
max_results_budget: 100,
min_resolution_confidence: 0.5,
strict_mode: true
},
parent_step_id: '<string>',
tags: ['<string>']
},
context: {sector: '<string>'},
cursor: '<string>',
expected_types: ['<string>'],
max_results: 10,
query: '<string>',
relationship_types: [],
resolution: {include_aliases: false, include_metadata: false, max_results: 5},
subject: {canonical_id: '<string>', entity_type: '<string>', canonical_name: '<string>'}
})
};
fetch('https://api.example.com/v2/relationships', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/v2/relationships",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'agent_context' => [
'objective' => '<string>',
'requested_outcome' => '<string>',
'run_id' => '<string>',
'step_id' => '<string>',
'client' => [
'agent_name' => '<string>',
'agent_version' => '<string>',
'framework' => '<string>'
],
'constraints' => [
'latency_budget_ms' => 15025,
'max_results_budget' => 100,
'min_resolution_confidence' => 0.5,
'strict_mode' => true
],
'parent_step_id' => '<string>',
'tags' => [
'<string>'
]
],
'context' => [
'sector' => '<string>'
],
'cursor' => '<string>',
'expected_types' => [
'<string>'
],
'max_results' => 10,
'query' => '<string>',
'relationship_types' => [
],
'resolution' => [
'include_aliases' => false,
'include_metadata' => false,
'max_results' => 5
],
'subject' => [
'canonical_id' => '<string>',
'entity_type' => '<string>',
'canonical_name' => '<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/v2/relationships"
payload := strings.NewReader("{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"sector\": \"<string>\"\n },\n \"cursor\": \"<string>\",\n \"expected_types\": [\n \"<string>\"\n ],\n \"max_results\": 10,\n \"query\": \"<string>\",\n \"relationship_types\": [],\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/v2/relationships")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"sector\": \"<string>\"\n },\n \"cursor\": \"<string>\",\n \"expected_types\": [\n \"<string>\"\n ],\n \"max_results\": 10,\n \"query\": \"<string>\",\n \"relationship_types\": [],\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/v2/relationships")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"agent_context\": {\n \"objective\": \"<string>\",\n \"requested_outcome\": \"<string>\",\n \"run_id\": \"<string>\",\n \"step_id\": \"<string>\",\n \"client\": {\n \"agent_name\": \"<string>\",\n \"agent_version\": \"<string>\",\n \"framework\": \"<string>\"\n },\n \"constraints\": {\n \"latency_budget_ms\": 15025,\n \"max_results_budget\": 100,\n \"min_resolution_confidence\": 0.5,\n \"strict_mode\": true\n },\n \"parent_step_id\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"context\": {\n \"sector\": \"<string>\"\n },\n \"cursor\": \"<string>\",\n \"expected_types\": [\n \"<string>\"\n ],\n \"max_results\": 10,\n \"query\": \"<string>\",\n \"relationship_types\": [],\n \"resolution\": {\n \"include_aliases\": false,\n \"include_metadata\": false,\n \"max_results\": 5\n },\n \"subject\": {\n \"canonical_id\": \"<string>\",\n \"entity_type\": \"<string>\",\n \"canonical_name\": \"<string>\"\n }\n}"
response = http.request(request)
puts response.read_body{
"items": [
{
"canonical_id": "<string>",
"canonical_name": "<string>",
"evidence_count": 123,
"score": 123,
"target_entity_type": "<string>",
"last_seen": "<string>",
"metadata": {}
}
],
"max_results": 123,
"metadata": {},
"relationship_types": [],
"resolution": {
"candidates": [
{
"canonical_id": "<string>",
"canonical_name": "<string>",
"entity_type": "<string>",
"match_type": "<string>",
"score": 123,
"aliases": [
"<string>"
],
"matched_on": "<string>",
"metadata": {}
}
],
"canonical_id": "<string>",
"canonical_name": "<string>",
"entity_type": "<string>",
"resolution_confidence": 123
},
"next_cursor": "<string>",
"subject": {
"canonical_id": "<string>",
"entity_type": "<string>",
"canonical_name": "<string>"
}
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"ctx": {},
"input": "<unknown>"
}
]
}Scope and credits
| Requirement | Value |
|---|---|
| Required scopes | read:relationships |
| Credits | 3 credits per request |
IOC relationship behavior
/v2/relationships accepts IOC subjects with concrete entity_type values: ip, domain, url, hash, or email.
For IOC subjects, request relationship_types: ["ioc"] to retrieve related indicators from event-correlation context. You may also request actor, campaign, or malware relationships for attribution-style context, sector relationships for targeted industries, and country relationships for targeted countries when available.
Do not use ioc as a subject entity_type; use the concrete observable type.Authorizations
ApiKey <key_id>:
Body
application/json
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Maximum string length:
512Required range:
1 <= x <= 50Maximum string length:
1024Available options:
actor, campaign, malware, sector, country, ioc, technique Show child attributes
Show child attributes
Show child attributes
Show child attributes
Response
Successful Response
Available options:
subject, query Show child attributes
Show child attributes
Available options:
actor, campaign, malware, sector, country, ioc, technique Show child attributes
Show child attributes
Available options:
ok, no_relationships Show child attributes
Show child attributes
Was this page helpful?
⌘I
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)