mirror of
https://github.com/j3ssie/osmedeus.git
synced 2026-08-17 21:25:49 +02:00
Osmedeus API Documentation
Overview
The Osmedeus API provides a RESTful interface for managing security automation workflows, runs, and distributed task execution.
Base URL: http://localhost:8002
Default Port: 8002
Authentication
Most API endpoints require JWT authentication. First, obtain a token via the login endpoint, then include it in subsequent requests using the Authorization: Bearer <token> header.
See Authentication for details.
API Reference
| Category | Description |
|---|---|
| Public Endpoints | Server info, health checks, Swagger docs |
| Authentication | Login and JWT token management |
| Workflows | List, view, and refresh workflows |
| Runs | Create and manage workflow executions |
| File Uploads | Upload target files and workflows |
| Snapshots | Download workspace snapshots |
| Workspaces | List and manage workspaces |
| Assets | View discovered assets |
| Vulnerabilities | View and manage vulnerabilities |
| Event Logs | View execution event logs |
| Functions | Execute and list utility functions |
| System Statistics | Get aggregated system stats |
| Settings | Manage server configuration |
| Installation | Install binaries and workflows |
| Schedules | Manage scheduled workflows |
| Distributed Mode | Worker and task management |
| LLM API | Large Language Model API |
| Reference | Error codes, pagination, cron expressions, step types |
Quick Start
# Get server info (no auth required)
curl http://localhost:8002/server-info
# Login and get token
export TOKEN=$(curl -s -X POST http://localhost:8002/osm/api/login \
-H "Content-Type: application/json" \
-d '{"username": "osmedeus", "password": "admin"}' | jq -r '.token')
# List workflows
curl http://localhost:8002/osm/api/workflows \
-H "Authorization: Bearer $TOKEN"
# Start a scan
curl -X POST http://localhost:8002/osm/api/runs \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"flow": "subdomain-enum", "target": "example.com"}'