Skip to content

Authentication

Every API entry point into the Anantis platform authenticates with an API key. One key works for both the REST API and the MCP server.


  1. Log in to the Anantis Console.

  2. Navigate to Settings → Configuration → API Keys.

  3. Click Create API Key.

  4. Give the key a name that identifies where it will be used.

  5. Select the scopes the key requires. Grant only what the integration actually calls. See Scopes below.

  6. Click Create, then copy the key.

Anantis API keys are prefixed so they are recognisable in logs, code review, and secret scanners:

anantis_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Treat the whole string as a secret. Never commit it to a repository, or paste it into a support ticket.

Pass the key as a bearer token in the Authorization header:

Terminal window
curl https://api.anantis.io/v1/me \
-H "Authorization: Bearer anantis_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"

The base URL for every REST endpoint is:

https://api.anantis.io/v1

GET /me enables you to confirm a key works and to inspect what it can reach. It requires no scope:

Terminal window
curl https://api.anantis.io/v1/me \
-H "Authorization: Bearer $ANANTIS_API_KEY"
{
"entity_uuid": "22222222-2222-2222-2222-222222222220",
"key_id": "019fdde2-9021-74b9-8eae-e42eae2fdb58",
"scopes": ["threats:read", "interactions:read", "reports:read"],
"accessible_entities": ["22222222-2222-2222-2222-222222222220"]
}
FieldMeaning
entity_uuidThe organization the key belongs to.
key_idIdentifier of the key. Safe to log, useful for support and audit.
scopesPermissions actually granted at creation.
accessible_entitiesEvery organization uuid this key can address.

Scopes are selected per key at creation and cannot be changed after creation.

ScopeGrants
threats:readList and read threats.
threats:writeUpdate a threat’s triage status and notes.
interactions:readList and read interactions captured by decoys.
decoys:readList and read decoys, including their breadcrumbs.
decoys:updateTrigger a decoy software update.
decoys:deleteDecommission a decoy.
canaries:readList and read canaries.
canaries:writeCreate and update canaries.
canaries:deleteDecommission a canary.
reports:readExport the executive report.
users:readList and read console users.
users:writeCreate console users.
users:deleteDelete console users.