API keys and the Verisight API
Create, use, rotate and revoke API keys to automate Verisight from scripts and pipelines.
API keys let scripts, CI pipelines and other tools call the Verisight API for one organization. Only owners and admins can manage keys.
Create a key
- Open Settings → API Keys and choose Create API key.
- Give it a descriptive name, such as
CI pipelineorSIEM export. - Pick a role. The key acts with exactly that role's permissions. Use the least privilege that works: viewer for read-only exports, analyst to create and run assessments.
- Copy the key (it starts with
vk_). It is shown only once. Verisight stores only a hash and can't show it again.
Use a key
Send it in the X-API-Key header. The key already identifies the organization and role, so no other headers are needed:
curl -H "X-API-Key: vk_..." https://api.sentinel-rsoc.com/v1/assessments
The full API reference is at api.sentinel-rsoc.com/v1/docs (OpenAPI: /v1/openapi.yaml).
Errors return a stable machine-readable error code plus a human-readable message. Build your logic on error; the message wording may change.
Rotate a key
Rotate replaces the secret and shows the new key once. The old key stops working immediately, so update your integration straight after.
Revoke a key
Revoke disables a key permanently. It stays in the list, marked revoked, for your audit trail. A revoked key can't be brought back; create a new one instead.
Every create, rotate and revoke is recorded in your organization's audit trail.
Treat keys like passwords
Store keys in your CI system's secret store, never in source code. If a key may have leaked, rotate or revoke it at once.
Integrations that authorise assessments
Authorising a domain assessment through the API requires accepting the current scan declaration (disclaimer_accepted and disclaimer_version). Your integration must show the declaration to a person and send their acceptance. Sending true automatically misrepresents consent.