Authentication

Every request to these APIs needs either an access key or an OAuth token. Generate one from the Atlas Platform:

  1. Sign in to Atlas and go to Settings → Organization Settings → API Access.
  2. Click New API Credentials.
  3. Choose the Endpoint this credential is for: Threat Intelligence and GenAI each use their own separate credentials, but every other API (Tickets, Findings, MVS, etc.) shares one Atlas credential.
  4. Choose an Auth Type: Token for a long-lived access key, or OAuth for a client ID/secret you exchange for short-lived tokens.
  5. If you chose Token, give it a nickname, then submit. Your new credential is shown once — copy it before closing the confirmation.

Using a credential:

Partner on-behalf-of access

If your organization is a partner managing one or more tenant customers, your existing credential also works to access data for any tenant you are the direct parent of — no separate credential per tenant is needed. Pass an optional tenant_code query parameter on the Tickets, Findings, and MVS APIs to scope a request to that tenant instead of your own organization; omit it to act on your own organization as before.

See the Tickets API docs for the full behavior, scoping rules, and curl examples. The Findings and MVS APIs support the same tenant_code parameter (see each API's Swagger UI for its per-endpoint reference).