Skip to content

Assets, URLs, and services ​

Use https://api.hashiro.ai/api/ with X-HASHIRO-TOKEN. IDs and project identifiers must belong to your authorized scope.

Routes ​

MethodPathOperation
GET/assets/List assets using project, asset, filter, page, pageSize
GET/assets/:assetIdRead asset by ID
POST/assets/:projectNameCreate assets from a JSON array
PUT/assets/:projectNameAlternative create route
POST/assets/searchSearch the authorized inventory
GET/assets/inventory/statsRead inventory filter statistics
GET/assets/pathsList paths with project and optional asset filters
GET/assets/:assetId/pathsList paths for an asset ID
GET/assets/paths/:pathIdRead a URL path
POST/assets/:projectName/pathsAdd paths, with asset as a query parameter
POST/assets/:projectName/servicesAdd service records, with asset as a query parameter
POST/assets/:projectName/restart-probeRequest refreshed probe data
DELETE/assets/Delete selected assets using the required filters
DELETE/assets/project/:projectNameDelete all project assets
DELETE/assets/pathsDelete selected paths
DELETE/assets/path/:pathIdDelete a path by ID

Read assets ​

bash
curl --fail-with-body -H "X-HASHIRO-TOKEN: $HASHIRO_TOKEN" \
  'https://api.hashiro.ai/api/assets/?project=my-project&filter=all&page=1&pageSize=100'

filter selects availability; use all when you need unavailable assets as well. Detail routes use the asset ID, while the asset query filter uses its name. An asset record includes fields such as id, asset, project, type, available, scope, probe, ip_address, and services.

Create assets ​

Send an array to POST /assets/my-project:

json
[
  {"asset":"app.example.com","type":"domain","available":true}
]

Creation accepts authorized project members where the license and project ownership allow it. Deletion and restart-probe routes have stricter provider/project permissions. Do not assume every read permission grants write access.

URL paths ​

POST /assets/my-project/paths?asset=app.example.com accepts an array of path records. Each record can include path, url, source, probe, and tags. Use full URLs in the Galileo CLI; the API stores the path and URL separately.

Services ​

POST /assets/my-project/services?asset=app.example.com accepts an array of service records:

json
[
  {"port":443,"protocol":"tcp","state":"open","service":"https"}
]

This records known observations; it does not itself launch a port scan. Reads expose recorded services through the asset details. States include open, filtered, closed, and unknown.

POST /assets/search searches the caller's authorized inventory. Provider network access is limited to linked clients; clients search their own organization only. The query is not a mechanism for selecting an unrelated tenant.

Hashiro. Continuous Threat Exposure Management.