Getting started with the API
What the public API covers, how to call it, and what its responses look like.
The public API opens FirstSI's data to your other tools: ticketing, general monitoring, dashboards, scripts, AI assistants. It covers every module. It is read-only, apart from three specific write operations: acknowledging an alert, changing NetDiag settings, and starting a diagnostic action on a computer.
The essentials
The base address is https://<your-console>/api/v1. Every call carries a token from your customer account in the Authorization: Bearer <token> header (see API tokens). A token has scopes (read:netdiag, read:flows…); a route whose scope is missing answers 403.
Responses are JSON, shaped { data, meta }, with dates in UTC in ISO 8601 format. Each token is allowed 600 calls per minute; beyond that the server answers 429 with a Retry-After header.
The v1 contract only changes through backward-compatible additions. Any removal is announced 12 months in advance.
First call
The /me route checks a token. It returns the token's name, scopes and expiry date:
curl -s https://console.example.com/api/v1/me \
-H "Authorization: Bearer fsi_live_xxxxxxxxxxxx"Then, for example, the list of computers running the agent (scope read:machines):
curl -s "https://console.example.com/api/v1/machines?status=online&limit=50" \
-H "Authorization: Bearer fsi_live_xxxxxxxxxxxx"{
"data": [
{ "id": 21, "hostname": "pc-009", "ip": "10.20.0.9", "os": "Windows 11", "agent_version": "2026.10.7.0",
"status": "online", "last_seen_at": "2026-10-07T08:12:40Z", "modules": ["netflow", "netdiag"] }
],
"meta": { "limit": 50, "next_cursor": null }
}What the API covers
| Area | Example routes | Scope |
|---|---|---|
| Fleet | /machines, /machines/{hostname} | read:machines |
| Workstation network experience | /netdiag/machines, /netdiag/machines/{hostname}/summary | read:netdiag |
| Network flows | /flows, /flows/destinations, /flows/summary, /flows/explore | read:flows |
| Alerts and availability | /alerts, /monitors | read:alerts, read:monitors |
| Inventory and vulnerabilities | /inventory/… | read:inventory |
| Security (SIEM, Active Directory) | /security/… | read:security |
| Databases, DNS, files, network, firewall | /databases/…, /dns/…, /files/…, /network/…, /firewall/… | the matching read:* scope |
Every route and its parameters are listed in the API reference. Your console also serves the OpenAPI specification (/api/v1/openapi.json) and interactive documentation (/api/v1/docs).
For an AI assistant
The same data is available as MCP tools. Claude, ChatGPT, Copilot or any compatible client call them on their own to answer a question such as "which computer had a network problem this morning?". See MCP server.
Going further
Source: · FirstSI Docs · updated 2026-10-10