---
title: OpenPort type | Wartiva GraphQL API
description: One TCP or UDP port at one IP address on a discovered Device. Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/types/open-port.html
updated: 2026-10-07
---

Networks, devices, and sensors · GraphQL type

# `OpenPort` type

One TCP or UDP port at one IP address on a discovered [Device](https://wartiva.com/api-docs/types/device.html), found by managed endpoints port-scanning the devices on their local networks and by Wartiva's server-side sensors scanning public addresses. It keeps the port's open and closed history (when it was first and last seen open, and when last seen closed), the number of endpoints that currently observe it open, and whether it is exposed to the public Internet. Each open port links to the [Network](https://wartiva.com/api-docs/types/network.html) and [NetworkPrefix](https://wartiva.com/api-docs/types/network-prefix.html) where it was found and to the [Service](https://wartiva.com/api-docs/types/service.html) objects identified on it.

## Fields

| Field Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | Unique identifier for this graph object. |
| `orgId` - [`OrganizationId!`](https://wartiva.com/api-docs/types/organization-id.html) | Unique identifier for the owning organization. |
| `objectType` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | The type of this graph object. |
| `objectTypeLabel` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A localized label describing the object type. |
| `displayName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
| `firstSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was first seen. |
| `lastSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was last seen. |
| `seen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | When this graph object was seen. |
| `createdAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was created in the security graph. |
| `updatedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was last mutated in the security graph. |
| `snapshotInfo` - [`GraphObjectSnapshotInfo!`](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) | Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
| `device` - [`Device`](https://wartiva.com/api-docs/types/device.html) | The [Device](https://wartiva.com/api-docs/types/device.html) this open port belongs to. |
| `network` - [`Network`](https://wartiva.com/api-docs/types/network.html) | The [Network](https://wartiva.com/api-docs/types/network.html) this open port was found on if known. |
| `networkPrefix` - [`NetworkPrefix`](https://wartiva.com/api-docs/types/network-prefix.html) | The [NetworkPrefix](https://wartiva.com/api-docs/types/network-prefix.html) containing the IP this open port was found on if known. |
| `ip` - [`IpAddress!`](https://wartiva.com/api-docs/types/ip-address.html) | IP address where the port was found open. |
| `isOpen` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True if the last known state was open. |
| `public` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True if the port is on a public IP address and has been observed open from the public Internet. |
| `port` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | The IP port number, an unsigned 16-bit integer. |
| `protocol` - [`IpProtocol!`](https://wartiva.com/api-docs/types/ip-protocol.html) | The transport protocol of the port, TCP or UDP. |
| `state` - [`PortState!`](https://wartiva.com/api-docs/types/port-state.html) | Last known state e.g. open or closed. |
| `services` - [`ServiceConnection!`](https://wartiva.com/api-docs/types/service-connection.html) | Services found on this open port. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `endpoints` - [`EndpointConnection!`](https://wartiva.com/api-docs/types/endpoint-connection.html) | Endpoints that have seen this port open. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. `timeRange` - [`DateTimeRangeInput`](https://wartiva.com/api-docs/types/date-time-range-input.html) Optional time range filter. `includeSeen` - [`Boolean`](https://wartiva.com/api-docs/types/boolean.html) When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
| `firstSeenOpen` - [`Time`](https://wartiva.com/api-docs/types/time.html) | The time when the port was first detected as open. |
| `lastSeenOpen` - [`Time`](https://wartiva.com/api-docs/types/time.html) | The time the port was last seen open. |
| `lastSeenClosed` - [`Time`](https://wartiva.com/api-docs/types/time.html) | The time the port was last seen closed. Will be null if always seen open. |
| `seenOpen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | Describes when this port was seen open. |
| `openToEndpointCount` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | The number of Endpoints that currently observe this port as open. |
| `findings` - [`FindingsPayload!`](https://wartiva.com/api-docs/types/findings-payload.html) | Policy findings for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issues` - [`IssuesPayload!`](https://wartiva.com/api-docs/types/issues-payload.html) | Policy issues for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issuesSummary` - [`IssuesSummary!`](https://wartiva.com/api-docs/types/issues-summary.html) | Summary of the active policy issues currently open on this object, broken down by severity. |

## Returned by

- [`openPort`](https://wartiva.com/api-docs/queries/open-port.html) query: Retrieves an OpenPort by its graph object id: a TCP or UDP port on a discovered device, found by endpoint port scans of local devices or by…

## Used by

- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`Network`](https://wartiva.com/api-docs/types/network.html) type: An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
- [`NetworkPrefix`](https://wartiva.com/api-docs/types/network-prefix.html) type: A specific IP address together with its subnet prefix length (e.g.
- [`Service`](https://wartiva.com/api-docs/types/service.html) type: A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
- [`GraphObjectType`](https://wartiva.com/api-docs/types/graph-object-type.html) enum: An enumeration of the different types of security graph objects.
- [`GraphObjectTypeCategory`](https://wartiva.com/api-docs/types/graph-object-type-category.html) enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
- [`OpenPortConnection`](https://wartiva.com/api-docs/types/open-port-connection.html) type: Connection for OpenPort edges with total count.
- [`OpenPortEdge`](https://wartiva.com/api-docs/types/open-port-edge.html) type: Edge payload for an OpenPort with optional seen data.
- [`OpenPortPayload`](https://wartiva.com/api-docs/types/open-port-payload.html) type: Payload wrapper for a single OpenPort result.
- [`OpenPortSummary`](https://wartiva.com/api-docs/types/open-port-summary.html) type: An abbreviated summary of an OpenPort.
- [`RuleApplyToOptionKey`](https://wartiva.com/api-docs/types/rule-apply-to-option-key.html) enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.

## Related types

- [`Device`](https://wartiva.com/api-docs/types/device.html) A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
- [`Network`](https://wartiva.com/api-docs/types/network.html) An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
- [`NetworkPrefix`](https://wartiva.com/api-docs/types/network-prefix.html) A specific IP address together with its subnet prefix length (e.g.

## Example

### Example

```json
{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "device": Device,
  "network": Network,
  "networkPrefix": NetworkPrefix,
  "ip": IpAddress,
  "isOpen": true,
  "public": false,
  "port": 987,
  "protocol": "TCP",
  "state": "OPEN",
  "services": ServiceConnection,
  "endpoints": EndpointConnection,
  "firstSeenOpen": "2021-10-07T18:23:25.829Z",
  "lastSeenOpen": "2021-10-07T18:23:25.829Z",
  "lastSeenClosed": "2021-10-07T18:23:25.829Z",
  "seenOpen": SeenOnline,
  "openToEndpointCount": 123,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
