reyhford.com/api).
TAXII 2.1 (machine clients)
TAXII collection and object endpoints require an API key:Scopes
Indicators REST API (application clients)
The/v1/indicators/* endpoints accept:
- WorkOS JWT — for dashboard and SaaS integrations (
indicators:readscope) - API key — for machine-to-machine access
Rate limiting
Rate limits apply per API key. TAXII polling should use incrementaladded_after cursors rather than full feed pulls.
Errors
See the Quickstart for a working curl example.