📡 API Reference

AI Security Hub API Docs

Complete reference for all REST API endpoints. Secure, versioned, enterprise-ready. Build, integrate, automate.

BASE URL https://cyberdudebivash.in
Authentication
🔑
JWT Bearer Token
Obtain via POST /api/auth/login — include as Authorization: Bearer <token>
🗝
API Key (cdb_*)
Generated in the API Keys tab of your dashboard — include as X-API-Key: cdb_your_key. POST /api/developer/keys below is the same key system under a developer-portal-branded URL — same key, same limits, same account, either path works.
👤
Anonymous / IP Fallback
Free-tier read endpoints are available without auth. Rate-limited per IP.
POST /api/auth/login FREE Obtain JWT token
Request Body
{
  "email": "user@example.com",
  "password": "your-password"
}
Response
{
  "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
  "expires_in": 86400,
  "user": { "id": "usr_...", "tier": "FREE" }
}
Status Codes
200 OK 400 Invalid credentials
Developer API Keys

Create and manage keys programmatically. Session auth required (log in first) — these endpoints manage the same keys shown in your dashboard's API Keys tab, just reachable under a developer-portal-branded URL.

POST /api/developer/keys SESSION Generate a new API key
Request Body
{
  "label": "My Integration"
}
Response
{
  "success": true,
  "key": "cdb_...",
  "prefix": "cdb_ab12",
  "label": "My Integration",
  "tier": "FREE",
  "warning": "Store this key securely. It cannot be retrieved after this response."
}
Status Codes
201 Created 401 Authentication required 409 Key limit reached for your tier
GET /api/developer/keys SESSION List your active API keys
Response
{
  "keys": [ { "key_prefix": "cdb_ab12", "label": "My Integration", "active": true } ],
  "count": 1,
  "max_keys": 1
}
DELETE /api/developer/keys/{id} SESSION Revoke a key
POST /api/developer/keys/{id}/rotate SESSION Revoke and reissue a key, same label and tier
Rate Limits
FREE
50
requests / hour
STARTER
500
requests / hour
PRO
5,000
requests / hour
ENTERPRISE
Unlimited
custom SLA

Exceeded limits return HTTP 429 with header Retry-After: <seconds>.

Pillar 1 — AI Security Posture Management
POST /api/ai-security/assets/register STARTER+ Register AI asset
Request Body
{
  "name": "My GPT-4 Agent",
  "type": "agent",       // model | agent | rag | api | pipeline
  "provider": "openai",
  "endpoint": "https://api.openai.com/v1/chat/completions",
  "env": "production"
}
Response
{
  "asset_id": "ast_01JX...",
  "security_score": 74,
  "risk_level": "MEDIUM",
  "created_at": "2025-06-09T14:30:00Z"
}
GET /api/ai-security/assets STARTER+ List all AI assets
Query Parameters
ParamTypeRequiredDescription
typestringoptionalFilter: model | agent | rag | api
riskstringoptionalFilter: CRITICAL | HIGH | MEDIUM | LOW
limitnumberoptionalDefault 20, max 100
POST /api/ai-security/assets/:id/scan PRO+ Run security scan
Path Parameters
ParamTypeRequiredDescription
idstringrequiredAsset ID from register
Response
{
  "scan_id": "scn_01JX...",
  "findings": [
    { "id": "F001", "severity": "HIGH", "title": "Prompt Injection Vector" }
  ],
  "score": 62,
  "owasp_llm_hits": ["LLM01","LLM02"]
}
Pillar 2 — AI Governance Center
GET /api/ai-security/governance/frameworks FREE List compliance frameworks
Response
{
  "frameworks": [
    { "id": "nist-ai-rmf", "name": "NIST AI RMF 1.0", "controls": 72 },
    { "id": "iso-42001",   "name": "ISO/IEC 42001:2023", "controls": 38 },
    { "id": "eu-ai-act",   "name": "EU AI Act", "controls": 44 },
    { "id": "owasp-llm",  "name": "OWASP LLM Top 10", "controls": 10 }
  ]
}
POST /api/ai-security/governance/assess STARTER+ Start governance assessment
Request Body
{
  "framework_id": "nist-ai-rmf",
  "org_context": "Financial services, 500 employees",
  "ai_use_cases": ["fraud detection", "customer chatbot"]
}
Pillar 3 — AI Red Team Platform
POST /api/ai-security/redteam/engage PRO+ Initiate red team engagement
Request Body
{
  "target_asset_id": "ast_01JX...",
  "attack_categories": ["prompt_injection","jailbreak","rag_poisoning"],
  "intensity": "standard"  // light | standard | full
}
Response
{
  "engagement_id": "eng_01JX...",
  "status": "running",
  "attack_count": 247,
  "eta_seconds": 120
}
GET /api/ai-security/redteam/:id/report PRO+ Get engagement report
Response
{
  "engagement_id": "eng_01JX...",
  "overall_risk": "HIGH",
  "attacks_succeeded": 14,
  "attacks_total": 247,
  "critical_findings": [ /* ... */ ],
  "remediation_plan": { /* ... */ }
}
Pillar 4 — AI Agent Security
POST /api/ai-security/agents/scan STARTER+ Scan AI agent configuration
Request Body
{
  "agent_type": "langchain",  // openai | langchain | crewai | autogen | mcp
  "tools": ["web_search","code_exec","file_write"],
  "system_prompt": "You are a helpful assistant..."
}
Response
{
  "risk_score": 83,
  "risk_level": "HIGH",
  "issues": [
    { "type": "OVER_PRIVILEGED_TOOL", "tool": "file_write", "severity": "CRITICAL" },
    { "type": "SYSTEM_PROMPT_INJECTION_RISK", "severity": "HIGH" }
  ]
}
Pillar 5 — AI Threat Intelligence
GET /api/ai-security/threat-feed FREE Live AI threat intelligence feed
Query Parameters
ParamTypeRequiredDescription
typestringoptionalprompt_attacks | agent_threats | ai_cves | model_advisories
severitystringoptionalCRITICAL | HIGH | MEDIUM | LOW
limitnumberoptionalDefault 20, max 100
Response
{
  "feed": [
    {
      "id": "ATI-2025-0047",
      "type": "prompt_attack",
      "title": "Multi-turn Jailbreak via Role Persistence",
      "severity": "HIGH",
      "published": "2025-06-09T08:00:00Z"
    }
  ],
  "total": 847,
  "updated_at": "2025-06-09T14:00:00Z"
}
GET /api/threat-intel/:id/playbook FREE Mitigation & response playbook for a CVE/threat-intel item
Description

Deterministically generates immediate mitigation actions, detection guidance, a threat hunting guide, a SOC playbook, an incident response playbook (NIST SP 800-61), an executive advisory, security architecture guidance, an operational checklist, and references — grounded entirely in the real threat_intel record plus the live MITRE ATT&CK mapping and composite risk score. Anonymous callers get the full playbook computed on demand; sign in to persist it and get staleness tracking if the underlying intelligence is later re-enriched.

Response (abridged)
{
  "success": true,
  "playbook_id": "pbk_mr4z...",
  "persisted": true,
  "stale": false,
  "playbook": {
    "risk_tier": "CRITICAL",
    "immediate_actions": [ "..." ],
    "detection_guidance": [ "..." ],
    "threat_hunting_guide": { "suggested_query": "..." },
    "soc_playbook": [ { "stage": "Triage", "action": "..." } ],
    "incident_response_playbook": [ /* NIST SP 800-61 phases */ ],
    "executive_advisory": "...",
    "security_architecture_guidance": [ /* per ATT&CK tactic */ ],
    "operational_checklist": [ /* checkbox items */ ],
    "references": [ { "label": "NVD — CVE-...", "url": "https://nvd.nist.gov/..." } ],
    "supporting_evidence": { /* every real field the playbook was built from */ }
  }
}
Related

POST /api/threat-intel/:id/playbook — force regeneration from current intelligence. GET /api/threat-intel/playbooks/history — your saved generation history (sign-in required).

Vibe Code Security Scanner
POST /api/vibe-code/scan FREE (gated) Scan AI-generated code
Request Body
{
  "code": "const query = `SELECT * FROM users WHERE id = ${req.params.id}`",
  "language": "javascript",  // js | ts | py | go | java | php | rb | cs | rs
  "context": "express api route"
}
Response (FREE)
{
  "ok": true,
  "risk_grade": "F",
  "risk_score": 94,
  "findings": [ /* top 3 findings visible */ ],
  "locked_count": 7,
  "gated": true,
  "upgrade": { "price": "₹499", "url": "https://cyberdudebivash.in/pricing" }
}
Response (STARTER+)
{
  "ok": true,
  "risk_grade": "F",
  "risk_score": 94,
  "tier": "starter",
  "gated": false,
  "findings": [
    {
      "rule_id": "CDB-SQL-001",
      "title": "SQL Injection via String Interpolation",
      "severity": "CRITICAL",
      "cwe": "CWE-89",
      "line": 1,
      "remediation": "Use parameterized queries..."
    }
  ]
}
GET /api/vibe-code/patterns FREE Get rule catalog
Response
{
  "total_rules": 47,
  "categories": ["injection","auth","secrets","crypto","ssrf","ai_llm"],
  "patterns": [ /* full rule catalog */ ]
}
MCP Security Scanner
POST /api/mcp-security/scan STARTER+ Scan MCP server configuration
Request Body
{
  "mcp_config": {
    "server_url": "https://mcp.example.com/sse",
    "tools": ["read_file", "execute_code"],
    "auth_method": "oauth2"
  }
}
MYTHOS God Mode API — Autonomous Orchestration

/status is public only as a coarse availability signal. Detailed run state, job identifiers, metrics, pipeline metadata and all operational intelligence endpoints require privileged authority: an authenticated ENTERPRISE/MSSP principal, a valid ADMIN_KEY, or an approved administrative RBAC principal.

GET /api/mythos/god-mode/status Availability status — detailed operational telemetry is authority-gated ▾
Anonymous requests return only a coarse availability envelope. ENTERPRISE/MSSP/admin-authorized requests receive detailed run state and operational telemetry.
curl https://cyberdudebivash.in/api/mythos/god-mode/status
GET /api/mythos/god-mode/ciso ENTERPRISE / MSSP / ADMIN CISO executive intel pack — posture gauge, threat highlights, recommendations ▾
Returns the full CISO intelligence package: executive summary with posture grade (A–F), critical CVE counts, CISA KEV entries, MITRE TTPs detected, and prioritized remediation recommendations. Privileged authentication required: real ENTERPRISE/MSSP principal, ADMIN_KEY, or administrative RBAC authority.
curl https://cyberdudebivash.in/api/mythos/god-mode/ciso \
  -H "Authorization: Bearer <ENTERPRISE_OR_MSSP_TOKEN>"
GET /api/mythos/god-mode/aspm ENTERPRISE / MSSP / ADMIN AI Security Posture Management snapshot — ASPM score, findings, zero-trust anomalies ▾
Returns the ASPM snapshot: assets scanned, overall posture, critical findings, open risks, and zero-trust anomalies including API abuse detections. Privileged authentication required: real ENTERPRISE/MSSP principal, ADMIN_KEY, or administrative RBAC authority.
curl https://cyberdudebivash.in/api/mythos/god-mode/aspm \
  -H "Authorization: Bearer <ENTERPRISE_OR_MSSP_TOKEN>"
GET /api/mythos/god-mode/compliance ENTERPRISE / MSSP / ADMIN Compliance posture — ISO 27001, SOC 2, NIST CSF, GDPR, DPDP 2023, OWASP LLM ▾
Returns compliance posture mapping active CVEs to control gaps across six frameworks. Privileged authentication required: real ENTERPRISE/MSSP principal, ADMIN_KEY, or administrative RBAC authority.
curl https://cyberdudebivash.in/api/mythos/god-mode/compliance \
  -H "Authorization: Bearer <ENTERPRISE_OR_MSSP_TOKEN>"
GET /api/mythos/god-mode/hunt-pack ENTERPRISE / MSSP / ADMIN SOAR hunt pack — auto-generated Sigma, KQL, YARA detection rules ▾
Returns Sigma rules, KQL hunt queries, and YARA signatures auto-generated for each active CVE. Privileged authentication required: real ENTERPRISE/MSSP principal, ADMIN_KEY, or administrative RBAC authority.
curl https://cyberdudebivash.in/api/mythos/god-mode/hunt-pack \
  -H "Authorization: Bearer <ENTERPRISE_OR_MSSP_TOKEN>"
POST /api/mythos/god-mode/run Trigger a full 16-phase God Mode run — admin only ▾
Triggers an asynchronous 16-phase autonomous security orchestration run. Returns immediately with a job ID. Privileged authority required: valid ADMIN_KEY, authenticated ENTERPRISE/MSSP principal, or administrative RBAC authority.
curl -X POST https://cyberdudebivash.in/api/mythos/god-mode/run \
  -H "Content-Type: application/json" \
  -H "x-api-key: <YOUR_ADMIN_KEY>" \
  -d '{"max_items": 20}'
Error Codes
CodeStatusMeaning
AUTH_REQUIRED401JWT or API key required for this endpoint
TIER_REQUIRED403Current plan insufficient — upgrade required
RATE_LIMITED429Too many requests — check Retry-After header
VALIDATION_ERROR400Request body failed validation — check the errors array
NOT_FOUND404Resource does not exist or belongs to another account
INTERNAL_ERROR500Platform error — contact support with x-request-id