Skip to content

API Reference Overview

Base URL

https://breachspider.com/api/v1
https://breachspider.com/api/v2   (Windows patch level only)

Endpoint Categories

Category Base Path Description
Health /health System status and pipeline health
CVEs /cves CVE search, detail, KEV, vendor, protocol
Dashboard /dashboard Personal posture dashboard
Environments /environments Site management and asset matching
Watchlist /watchlist Vendor and protocol watch subscriptions
Reports /reports PDF and compliance report generation
AI Assistant Chat /chat AI-powered vulnerability Q&A
Integrations /integrations API keys, connections, alert rules
Webhooks /webhooks Event delivery configuration
Training /training Platform training modules
Account /account User profile and billing
Catalog /catalog Vendor and protocol catalog
Correlate CVEs /assets/correlate-cves Stateless: resolve a vendor/product/version list and return affected CVEs, plus a staleness check. See Correlate CVEs
Windows Patch Level (v2) /api/v2/assets Submit Windows build and KB facts; per-CVE confirmed open / cleared / needs review. See Windows Patch Level

Authentication

Most endpoints require authentication, with these public exceptions:

  • The CVE read endpoints (/cves, /cves/{id}, /cves/kev, /cves/vendor/{slug}, /cves/protocol/{name}, /cves/stats/*) are public with optional auth. Anonymous callers are capped at 10 results per page; authenticated paid tiers get up to 100 per page (with no pagination depth cap), plus AI assistant and watchlist ranking where applicable.
  • /health/ping is fully public.
  • The browser status page at /health shows a public banner and service badges; detailed metrics and the JSON payload require a session.

See Authentication for details.

Response Format

All endpoints return the BreachSpider envelope. See Response Format for the full schema.

Versioning

The current API version is 1.0.0. The version is included in every response under api.version. Breaking changes will increment the major version and be announced at least 90 days in advance.

API v2 (/api/v2/assets/...) adds Windows patch-level results alongside v1. v2 success responses report meta.api_version: "2". See Windows Patch Level.

Additive changes (new fields, options and warning codes) ship in v1 without a version change; ignore fields you do not recognise. 2026-09-26: the correlation endpoints (v1 correlate and API v2) now return each asset's CVEs in exposure-priority order by default, with new ranking, fix and filter fields; pass sort: "score" for the previous order. Details are in the change logs on Correlate CVEs and Windows Patch Level.