Assets, URLs, and services
Use https://api.hashiro.ai/api/ with X-HASHIRO-TOKEN. IDs and project identifiers must belong to your authorized scope.
Routes
| Method | Path | Operation |
|---|---|---|
| GET | /assets/ | List assets using project, asset, filter, page, pageSize |
| GET | /assets/:assetId | Read asset by ID |
| POST | /assets/:projectName | Create assets from a JSON array |
| PUT | /assets/:projectName | Alternative create route |
| POST | /assets/search | Search the authorized inventory |
| GET | /assets/inventory/stats | Read inventory filter statistics |
| GET | /assets/paths | List paths with project and optional asset filters |
| GET | /assets/:assetId/paths | List paths for an asset ID |
| GET | /assets/paths/:pathId | Read a URL path |
| POST | /assets/:projectName/paths | Add paths, with asset as a query parameter |
| POST | /assets/:projectName/services | Add service records, with asset as a query parameter |
| POST | /assets/:projectName/restart-probe | Request refreshed probe data |
| DELETE | /assets/ | Delete selected assets using the required filters |
| DELETE | /assets/project/:projectName | Delete all project assets |
| DELETE | /assets/paths | Delete selected paths |
| DELETE | /assets/path/:pathId | Delete a path by ID |
Read assets
curl --fail-with-body -H "X-HASHIRO-TOKEN: $HASHIRO_TOKEN" \
'https://api.hashiro.ai/api/assets/?project=my-project&filter=all&page=1&pageSize=100'filter selects availability; use all when you need unavailable assets as well. Detail routes use the asset ID, while the asset query filter uses its name. An asset record includes fields such as id, asset, project, type, available, scope, probe, ip_address, and services.
Create assets
Send an array to POST /assets/my-project:
[
{"asset":"app.example.com","type":"domain","available":true}
]Creation accepts authorized project members where the license and project ownership allow it. Deletion and restart-probe routes have stricter provider/project permissions. Do not assume every read permission grants write access.
URL paths
POST /assets/my-project/paths?asset=app.example.com accepts an array of path records. Each record can include path, url, source, probe, and tags. Use full URLs in the Galileo CLI; the API stores the path and URL separately.
Services
POST /assets/my-project/services?asset=app.example.com accepts an array of service records:
[
{"port":443,"protocol":"tcp","state":"open","service":"https"}
]This records known observations; it does not itself launch a port scan. Reads expose recorded services through the asset details. States include open, filtered, closed, and unknown.
Inventory search
POST /assets/search searches the caller's authorized inventory. Provider network access is limited to linked clients; clients search their own organization only. The query is not a mechanism for selecting an unrelated tenant.