Skip to content

Live Endpoint Search GraphQL API

Run osquery-style queries against endpoints, replacing the legacy Live Discover REST API.

This is a GraphQL API: every request is a POST carrying a query (or mutation) document, rather than one endpoint per operation. See the guide above for the request shape and authentication.

Queries

Mutations

Types

Download