API Docs

Wartiva GraphQL API

One GraphQL API for your entire security graph — the same API that powers the Wartiva product. Search all 102 operations and 1,035 types, or browse by area.

Every request needs an API token from the Wartiva dashboard, sent as Authorization: Bearer <token> to https://YOUR_DEPLOYMENT/graphql.

Searches names, descriptions, arguments, and fields.

Endpoints

Managed endpoints: the laptops, desktops, and servers running the Wartiva endpoint.

Operations

  • endpoint query: Retrieves an Endpoint by its graph object id: a Windows, macOS, or Linux computer running the Wartiva agent.

Types

  • Endpoint type A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
Supporting types, inputs, and enums (6)

    Endpoint configuration

    Operating system configuration collected from Windows, macOS, and Linux endpoints: accounts, Active Directory, policies, disks, services, and more.

    Operations

    • accountPolicy query: Retrieves an endpoint's AccountPolicy by its graph object id: the local account password and lockout policy in effect on a Windows or macOS…
    • activeDirectory query: Retrieves an endpoint's ActiveDirectory configuration by its graph object id: whether Active Directory is enabled, the domain and DNS forest, the…
    • administrativeTemplatesWindows query: Retrieves a Windows endpoint's AdministrativeTemplatesWindows by its graph object id: the Group Policy Administrative Templates (ADMX) settings…
    • auditPolicy query: Retrieves an endpoint's AuditPolicy by its graph object id: the security event auditing configuration, either the Windows Advanced Audit Policy…
    • disk query: Retrieves a Disk by its graph object id: a physical disk drive attached to an endpoint, with its partitions, volumes, and I/O statistics, on…
    • diskMount query: Retrieves a DiskMount by its graph object id: a mounted file system on an endpoint, with its file system type, mount options, and capacity and inode…
    • endpointGroup query: Retrieves an EndpointGroup by its graph object id: an operating system or domain group on an endpoint, identified by its SID on Windows or GID on…
    • endpointUser query: Retrieves an EndpointUser by its graph object id: an operating system or domain user account on an endpoint, identified by its SID on Windows or UID…
    • executable query: Retrieves an Executable by its graph object id: a unique executable file seen running on an endpoint, aggregating the peak resource use of its…
    • localPolicies query: Retrieves an endpoint's LocalPolicies by its graph object id: the local security policy, either Windows user rights assignments and security options…
    • logonSession query: Retrieves a LogonSession by its graph object id: a user logon session on an endpoint, with platform-specific detail such as the Windows logon type…
    • processes query: Lists the processes that were running on an Endpoint in its most recent process report, with the time of that report.
    • security query: Retrieves an endpoint's Security posture by its graph object id: firewall, antivirus, and antispyware products, Windows Firewall profiles, Linux…
    • systemService query: Retrieves a SystemService by its graph object id: a background service or daemon configured on an endpoint (a Windows service, macOS launchd job, or…
    • systemSettings query: Retrieves a macOS endpoint's SystemSettings by its graph object id: the machine-wide configuration, including System Integrity Protection,…
    • userSystemSettings query: Retrieves one macOS user's UserSystemSettings by its graph object id: screen saver locking, Universal Control, Siri and search data sharing,…

    Types

    • AccountPolicy type The local account password and lockout policy in effect on an Endpoint.
    • ActiveDirectory type The Active Directory (AD) domain membership and directory-binding configuration of an Endpoint.
    • AdministrativeTemplatesWindows type The Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.
    • AuditPolicy type The security event auditing configuration of an Endpoint.
    • Disk type A physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…
    • DiskMount type A file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).
    • EndpointGroup type An operating system or domain group observed on an Endpoint.
    • EndpointUser type An operating system or domain user account observed on an Endpoint.
    • Executable type A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.
    • LocalPolicies type The local security policy settings of an Endpoint.
    • LogonSession type A user logon session observed on an Endpoint, identified by the username and the time the session started.
    • Security type The security posture of an Endpoint: its firewall, anti-malware and disk encryption state, summarized as per-component health ratings in Health.
    • SystemService type A background service or daemon configured on an Endpoint.
    • SystemSettings type The machine-wide operating system configuration of an Endpoint.
    • UserSystemSettings type The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.
    Supporting types, inputs, and enums (395)

      Applications and updates

      Installed applications and packages, and the software updates available for them.

      Operations

      • application query: Retrieves an Application by its graph object id: an organization-wide software product identity that ties together every install of that product…
      • applicationInstall query: Retrieves an ApplicationInstall by its graph object id: one installed copy of an application on one endpoint, with its version, size, code…
      • applicationInstallUserSettings query: Retrieves an ApplicationInstallUserSettings by its graph object id: one user's settings for a supported macOS application install (Safari, Terminal,…
      • softwareUpdatePreferences query: Retrieves an endpoint's SoftwareUpdatePreferences by its graph object id: the operating system update configuration and the updates currently…

      Types

      • Application type A software product as an identity shared across an organization, independent of any one computer.
      • ApplicationInstall type One installed copy of an application on one Endpoint.
      • ApplicationInstallUserSettings type The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
      • SoftwareUpdatePreferences type The operating system update configuration of an Endpoint and the updates currently available to it.
      Supporting types, inputs, and enums (29)

        File path sensors

        File paths collected from endpoints by path sensors, and their contents.

        Operations

        • endpointPath query: Retrieves an EndpointPath by its graph object id: the files a configured PathSensor found under its path on one endpoint, with each file's stat…
        • endpointPathEntryContents query: Retrieves the collected contents of one file path discovered by an EndpointPath — list discovered paths with its entries field.
        • endpointPathEntrySearch query: Checks whether an exact file path exists on an Endpoint, checking the collected paths of every PathSensor on the endpoint (every EndpointPath found…
        • endpointPathEntryStats query: Retrieves the stat record (mode, ownership, sizes, timestamps, and OS-specific attributes) of one file path discovered by an EndpointPath — list…

        Types

        • EndpointPath type The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…
        • EndpointPathEntryContents type The collected contents of one file a PathSensor discovered, retrieved with endpointPathEntryContents.
        • EndpointPathEntryStats type The stat record of one file a PathSensor discovered, stored as alternate data on the owning EndpointPath object and retrieved with…
        Supporting types, inputs, and enums (31)

          Networks, devices, and sensors

          Networks your endpoints connect to, the devices and services discovered on them, and the sensors that collect that data.

          Operations

          • arpTableEntry query: Retrieves an ArpTableEntry by its graph object id: one entry in an endpoint's neighbor cache (ARP for IPv4, NDP for IPv6 where the operating system…
          • device query: Retrieves a Device by its graph object id: an unmanaged device, such as a printer, camera, phone, or IoT appliance, that managed endpoints see on…
          • deviceManufacturer query: Retrieves a DeviceManufacturer by its graph object id: a hardware vendor of discovered devices, most often resolved from the MAC address OUI…
          • deviceModel query: Retrieves a DeviceModel by its graph object id: a specific product model of discovered devices, known only when a device identifies its exact…
          • interface query: Retrieves an Interface by its graph object id: a network interface on a Windows, macOS, or Linux endpoint, with its status, IP addresses, and…
          • network query: Retrieves a Network by its graph object id: an IP subnet that managed endpoints have joined, classified as PREMISE, REMOTE, or LINK_LOCAL, with…
          • networkPrefix query: Retrieves a NetworkPrefix by its graph object id: a host IP address with its subnet length, such as 192.168.1.23/24, on a specific Network.
          • openPort query: Retrieves an OpenPort by its graph object id: a TCP or UDP port on a discovered device, found by endpoint port scans of local devices or by…
          • route query: Retrieves a Route by its graph object id: one entry in a Windows, macOS, or Linux endpoint's IP routing table.
          • sensorRequest query: Retrieves a SensorRequest: a standing request to run one Sensor against one device IP address, and optionally one port, with its expiration and…
          • sensorRequestRun query: Retrieves a SensorRequestRun: the record of one attempt to run a SensorRequest, with its outcome, the endpoint that ran it when one did, and the…
          • sensors query: Lists the built-in network Sensor probes that discover ports and services on devices, such as HTTP, TLS, SSH, SMB, SNMP, UPnP, mDNS, DNS, and TCP…
          • sensorScopes query: Lists an organization's SensorScope rules, including disabled ones.
          • service query: Retrieves a Service by its graph object id: a network service identified on a discovered device, such as HTTP, TLS, SSH, SMB, SNMP, or DNS, in a…
          • wlanAccessPoint query: Retrieves a WlanAccessPoint by its graph object id: one Wi-Fi access point radio, identified by SSID and BSSID, heard by endpoint scans, with its…
          • wlanInterface query: Retrieves a WlanInterface by its graph object id: a Wi-Fi adapter on a Windows, macOS, or Linux endpoint, with its radio and connection state.
          • wlanInterfaceConnection query: Retrieves a WlanInterfaceConnection by its graph object id: an endpoint Wi-Fi adapter's association with one network and access point, with its…
          • wlanNetwork query: Retrieves a WlanNetwork by its graph object id: a Wi-Fi network (SSID) seen by endpoint Wi-Fi scans, with its advertised security and flags for…
          • sensorRequestReSubmit mutation: Re-runs a SensorRequest by resetting its request time, expiration, and completion state, so the sensor runs again as soon as an eligible endpoint is…
          • sensorRequestReSubmitForService mutation: Re-runs every sensor request that discovered the specified Service, as sensorRequestReSubmit does for one request.
          • sensorRequestSubmit mutation: Runs a Sensor against one device IP address, and optionally one port, by creating a SensorRequest.

          Types

          • ArpTableEntry type One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…
          • Device type A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
          • DeviceManufacturer type A hardware vendor that made one or more discovered Device objects in an organization.
          • DeviceModel type A specific product model, made by a DeviceManufacturer, that one or more discovered Device objects in an organization are instances of.
          • Interface type A network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…
          • Network type An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
          • NetworkPrefix type A specific IP address together with its subnet prefix length (e.g.
          • OpenPort type One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
          • Route type One entry in an Endpoint's IP routing table, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.
          • SensorRequest type A standing request to run one Sensor against one Device IP address, optionally on a specific protocol and port, in the SAE or PUBLIC zone.
          • SensorRequestRun type The record of one attempt to run a SensorRequest: when it ran, which sensor version ran it, which Endpoint ran it (none for PUBLIC-zone runs, which…
          • Service type A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
          • WlanAccessPoint type A Wi-Fi access point radio, identified by the network name (SSID) it broadcasts and its BSSID, as heard by managed endpoints scanning for nearby…
          • WlanInterface type A wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.
          • WlanNetwork type A Wi-Fi network identified by its network name (SSID), visible to managed endpoints when they scan for nearby networks on Windows, macOS, or Linux.
          Supporting types, inputs, and enums (168)

            Location

            Where endpoints and devices are, and where they have been.

            Operations

            • location query: Retrieves a Location by its graph object id: a physical place, identified by its global plus code and street address, that observed positions…
            • placeAutocomplete query: Suggests places that match partially typed text, such as a street address or business name, using the Google Maps Places service.
            • placeDetails query: Retrieves the address and coordinates of one Google Maps place, identified by a place id such as one returned by placeAutocomplete.
            • positionSeen query: Retrieves a PositionSeen by its graph object id: a geographic coordinate where endpoints, and the devices and networks they see, were observed, with…

            Types

            • Location type A physical place identified by its global plus code (Open Location Code), with a street address resolved by reverse geocoding.
            • PositionSeen type A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.
            Supporting types, inputs, and enums (27)

              Policies and findings

              Policy rules, security frameworks, and the findings and issues they raise.

              Operations

              • finding query: Retrieves a Finding by its graph object id: the record of a policy rule evaluating FAIL against one graph object, with its status history and the…
              • issue query: Retrieves an Issue by its graph object id: the triage record for a policy violation on one graph object, which users move between OPEN, IN_PROGRESS,…
              • policyFindingsList query: Returns every policy Finding recorded against one graph object, identified by objectId, in a single unpaginated list.
              • policyRulesList query: Lists a page of the organization's policy rules, sorted by name and then by creation time, optionally limited to one rule group.
              • securityFrameworks query: Retrieves the security frameworks policy rules are filed under, each with the products (SecurityCategory) and sections (SecuritySubCategory) its…
              • issueUpdate mutation: Moves an Issue to a new triage state and optionally records a note.
              • policyRulesAdd mutation: Adds between 1 and 500 policy rules to the organization.
              • policyRulesEdit mutation: Updates between 1 and 500 existing policy rules, identified by id, and returns their ids.
              • policyRulesExport mutation: Writes the group's rules to an export file in storage, overwriting any existing file.
              • policyRulesImport mutation: Loads the group's export file from storage and updates the group's rules to match it: rules are added, updated, or deleted as needed.
              • policyRulesPurgeGroup mutation: Deletes every policy rule in a group, including the rules Wartiva provides in that group; rules the organization has moved to another group are kept.
              • policyRulesRemove mutation: Deletes the identified policy rules so they are no longer listed or evaluated.

              Types

              • Finding type The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
              • Issue type The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
              Supporting types, inputs, and enums (102)

                Vulnerabilities

                Known vulnerabilities in the applications and packages on your endpoints.

                Operations

                • vulnerabilityCPEtoCVEIds query: Returns the ids of the CVEs that affect a product described by CPE 2.3 (Common Platform Enumeration) names.
                • vulnerabilityFetchCVE query: Retrieves one published CVE (Common Vulnerabilities and Exposures) record by its id, with its description, severity, and EPSS (Exploit Prediction…
                • vulnerabilityInputToCPE query: Uses AI to translate a free-text product description, such as "Chrome 120 on Windows 11", into CPE 2.3 (Common Platform Enumeration) names for the…
                • vulnerabilityInputToCVEIds query: Returns the ids of the CVEs that affect a product described in free text, such as "OpenSSL 3.0.1 on Ubuntu 22.04".
                • vulnerabilityStatus query: Reports whether the vulnerability service is available, how many CVE records it holds, and when its CVE data was last updated.

                Types

                • CVE type Type CVE represents a Common Vulnerabilities and Exposures entry with comprehensive security information
                Supporting types, inputs, and enums (64)

                  AI

                  Ask Wartiva's AI about your environment and generate search and GraphQL queries.

                  Operations

                  • aiGenerateGraphQLQuery query: Asks the AI assistant to write a Wartiva GraphQL query from a natural-language request, for the object type the thread was created with (see…
                  • aiGenerateSearchQuery query: Asks the AI assistant to turn a natural-language request into a graph search query, such as "Windows endpoints with an unencrypted disk", that can…
                  • aiQueryObject query: Asks the AI assistant a natural-language question about the specific graph object the thread was created for (see aiThreadCreate with an object id).
                  • aiQuerySearch query: Asks the AI assistant a natural-language question that it answers by searching the security graph, for example "which endpoints have not reported in…
                  • aiStatus query: Reports whether the AI service is ready to answer requests.
                  • aiThread query: Retrieves one of the caller's AI chat threads with its messages.
                  • aiThreadClear query: Removes every message from one of the caller's AI chat threads and returns the now-empty thread.
                  • aiThreadCreate query: Creates an AI chat thread of the requested type, or returns the existing one: a thread id is derived from the user, organization, thread type,…
                  • aiThreadDelete query: Deletes one of the caller's AI chat threads and its messages.
                  • aiThreadDeleteAll query: Deletes all of the caller's AI chat threads in an organization.
                  • aiThreadMessage query: Sends a message to an AI chat thread and returns the assistant's reply.
                  • aiThreads query: Lists the caller's AI chat threads in an organization that contain at least one message, most recently updated first.

                  Types

                  • AiThread type Type AiThread represents a conversation thread between a user and the AI system, containing metadata about the thread's purpose, associated object,…
                  • AiThreadEntry type Type AiThreadEntry represents an individual message in an AI thread, acting as a base interface for different types of thread entries with common…
                  Supporting types, inputs, and enums (15)

                    Organizations and users

                    Your organization, its users, and organization-wide settings.

                    Operations

                    • endpointDeployToken query: Returns the deployment token and secret that enroll newly installed Wartiva agents into an Organization.
                    • organization query: Retrieves an Organization: the customer tenant that owns every endpoint, graph object, policy rule, and user in its account, and sets their data…
                    • pathSensor query: Retrieves a PathSensor configuration: an organization-wide instruction for endpoints to collect file metadata, and optionally checksums, ACLs, or…
                    • pathSensors query: Lists a page of the enabled PathSensor configurations in an organization, including the default sensors Wartiva provides; total counts enabled…
                    • userGetMetadata query: Reads one value from the caller's own key-value metadata store, which clients use to keep per-user preferences and UI state on the server.
                    • userSetMetadata query: Stores a value under a key in the caller's own key-value metadata store, replacing any existing value, and returns the stored key and value.
                    • whoami query: Returns the authenticated user and how the server interprets time zones for the caller's requests: the effective time zone and its short name, the…
                    • createPathSensor mutation: Creates a new PathSensor for the given organization.
                    • deletePathSensor mutation: Soft-deletes a user-defined PathSensor (marks it as deleted and disables it).
                    • updatePathSensor mutation: Updates an existing user-defined PathSensor.

                    Types

                    • Organization type A customer account: the tenant boundary for every endpoint, graph object, policy rule, and user.
                    • PathSensor type An organization-wide instruction telling endpoints to collect file metadata under one filesystem path.
                    Supporting types, inputs, and enums (20)

                      Releases

                      Wartiva endpoint and platform releases.

                      Operations

                      • endpointAutoUpdates query: Lists the newest Wartiva agent build available for automatic update on each release channel, operating system platform, and CPU architecture.
                      • endpointInstallers query: Lists the Wartiva agent installers available to an organization, with a download URL for each.
                      • endpointPackageRepos query: Returns the Linux package repositories (APT and RPM) that distribute the Wartiva agent: for each, the package manager, the repository download URL,…
                      Supporting types, inputs, and enums (8)

                        General

                        Shared types and operations used across the API.

                        Supporting types, inputs, and enums (32)

                          Want to try the API on your environment?

                          Wartiva is in early access. Request your spot and get an API token for your deployment.

                          Request Early Access