Skip to content

APIs

Every published Sophos API, with a guide for the narrative and a reference for every operation. Type to filter.

  • Account Account Management API

    Manage account settings, including access tokens for package-manager authentication.

    Guide API reference

  • Endpoint Endpoint API

    Query computers and servers belonging to a tenant, and perform routine actions on them.

    Guide API reference

  • SIEM SIEM Integration API

    Pull Sophos Central events and alerts into a SIEM.

    Guide API reference

  • Legacy APIs XDR Query API

    Run XDR queries against the Sophos Data Lake.

    Guide API reference

  • Partner Partner API

    Enumerate and provision MSP-managed tenants, manage admin access, and fetch billing reports.

    Guide API reference

  • Admin & IAM Common API

    Routine administrative actions across Sophos Central alerts, users and user groups.

    API reference

  • Legacy APIs Live Discover API

    Run osquery against endpoints connected to Sophos Central.

    Guide API reference

  • Organization Organization API

    Enumerate tenants that are part of your organization and managed via Enterprise Admin.

    Guide API reference

  • Account Who-am-I API

    Look up your business entity's unique ID and the API host for your data region.

    API reference

  • Admin & IAM User Activity Verification API

    Ask a user or admin to confirm whether they performed some action.

    Guide API reference

  • Firewall Firewall Management API

    Manage firewalls, check their status, and manage groups of firewalls.

    Guide API reference

  • Account Account Health Check API

    Run an account health check across a tenant's endpoint estate.

    Guide API reference

  • Email Email Management API

    Manage mailboxes and quarantined messages, and clawback messages from M365 inboxes.

    Guide API reference

  • Cloud Security Cloud Security API

    Manage security for cloud resources covered by Sophos Workload Protection and Cloud Optix.

    Guide API reference

  • Legacy APIs Detections API

    Query detections from endpoints, servers, and third-party integrations.

    Guide API reference

  • Network Switch Management API

    Manage network switch configuration.

    Guide API reference

  • Network Wi-Fi Management API

    Manage Wi-Fi access point configuration.

    Guide API reference

  • Account Licensing API

    Manage Sophos licenses.

    Guide API reference

  • Legacy APIs Cases API

    Manage cases.

    Guide API reference

  • Mobile Mobile API

    Query mobile devices belonging to a tenant, and perform routine actions on them.

    Guide API reference

  • Network DNS Protection API

    Manage DNS Protection configuration.

    Guide API reference

  • Partner Business Automation API

    Business automation for distributors.

    Guide API reference

  • Admin & IAM Audit Events API

    Retrieve audit events.

    Guide API reference

  • Network Web Filtering API

    Manage web filtering configuration.

    API reference

  • Detections Detections GraphQL API

    Query alerts — the detections raised from endpoints, network sensors, and other data sources — over GraphQL.

    Guide API reference

  • Cases Cases GraphQL API

    Query and manage cases — opened around related alerts, events, and other evidence — over GraphQL.

    Guide API reference

  • Threat Timeline Threat Timeline GraphQL API

    Search process lineage — the ancestry tree around a suspicious process, with its detections, key activities, child processes, and related events — over GraphQL.

    Guide API reference

  • Events Events GraphQL API

    Retrieve details for events referenced by cases and detections.

    Guide API reference

  • Live Endpoint Search Live Endpoint Search GraphQL API

    Run osquery-style queries against endpoints, replacing the legacy Live Discover REST API.

    API reference

  • Cloud Security Cloud Optix APIs

    Query cloud security posture: inventory, alerts, benchmarks, and compliance results from Cloud Optix. Hosted in the Cloud Optix console today.

    Cloud Optix API documentation