API Key Credentials
Most investigation endpoints accept API key credentials:Short-lived Bearer Tokens
Mint a bearer token from API key credentials:Scopes
Different endpoints require different scopes. Common examples:
A missing scope returns
403 with error_code="insufficient_scope" and required_scopes.
Agent Context
All investigationPOST calls should include agent_context.
resolve, evidence, relationships, assessment, hunt, hydrate, batch, finalize, and other.
Hydration Headers
GET /v2/entities/{canonical_id} and GET /v2/evidence/{evidence_id} use headers for agent context:
Request Correlation
SendX-Request-ID when you need cross-system tracing. Kyberis responses include X-Request-ID; error bodies also include request_id..png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)