2.1STIX & TAXII version
3Live collections
50Objects per push request
FreeDiscovery calls
Why We Built It

We adapted to the standard everyone else already built for

Most of the Alliance's data has always been reachable through our own REST endpoints, and honestly that's still the fastest way to get a Crime Score for a single IP. But if you already run a threat intel platform — MISP, OpenCTI, Anomali, ThreatConnect, whatever your team standardised on — those tools expect to speak STIX 2.1 over TAXII 2.1, not a bespoke JSON schema. Writing and maintaining a custom parser for every member's platform doesn't scale. The server sits alongside the existing REST API and the older STIX 2.0 endpoint — nothing was ripped out, we just added the plumbing most CTI tooling already expects.

What's Actually There

Standard TAXII 2.1 discovery-to-object walk

If your client already talks TAXII, this should just work — that was the point.

GET /taxii2/Discovery — server metadata and the API root. No auth required.
GET /taxii2/onefirewall/API root — version and capability info for the OneFirewall root.
GET /taxii2/onefirewall/collections/Lists the three live collections: IP, domain, and URL indicators.
GET /collections/{id}/objects/Paginated STIX 2.1 Indicators. Supports added_after, limit, next.
POST /collections/{id}/objects/Push — submit up to 50 STIX 2.1 Indicators. New this release.
GET /collections/{id}/manifest/Lightweight change-detection metadata, without pulling full objects.

Point your TAXII client at the alliance.

JWT or Basic Auth — the same credentials you already have.

Get API Access