User Tools

Site Tools


api

This is an old revision of the document!


API & Webhook

Introduction

Kaduu consists of two plattforms:

Deepweb is used for live queries that can take up to 3 hours. Control is mainly DB driven. API access is currently only available for "Control". Control uses a REST API which you can reach via SSL.

API Documentation

Please find the API documentation here kaduu-2.2-swagger_3_.zip. The PDF documentation has some more details about authentication and filters.

Please note that Kaduu SaaS API is based on a REST/HTTPS protocol with JSON format. All endpoints except the authentication expect the JSON input and Content-Type: application/json header provided with the request. All endpoint results are in JSON format. Before using any other API calls, you should obtain an authentication token – it is required for all subsequent API calls. In order to obtain the token, you should send a POST request to the

https://app.leak.center/uaa/oauth/token URL with the following data: Headers Content-Type application/x-www-form-urlencoded Form client_id client-api client_secret comfy-litigate-embargo-forelimb grant_type password username <your username> password <your password>

All fields in form should be URL-encoded.

The server responds with a token in JSON format: {

"access_token": "<your token>",
"token_type": "bearer",
"expires_in": 43199,
"scope": "svc-saas",
"jti": "fcea19dc-091c-4b58-901e-3e9bb8df162f"

}

The API consumer should copy the resulting access_token value from the response and use it in Authorization header with Bearer scheme for all other requests:

Authorization: Bearer <your token>

Webhook

Please define your webhook under your account settings. You need to define "http" as a alerting method. The system will POST all new findings to that URL as a JSON list of alert objects. You may leave this field blank in order to disable alert notifications.

API Script

The customer has various options in Kaduu for accessing the query data:

  • Via dashboard: data can be displayed and then exported (CSV, XML, DOCX etc)
  • Via webhook
  • Via REST API
  • Via alerting (email)

The REST API allows you great flexibility in automation and integration into your existing processes and applications. In this chapter we illustrate how the API can be used with a customizable Python script which could assist you with few business use cases:

  • White labeled alerts: You use Kaduu to regularly provide end customers or specific people with email alerts on certain topics (e.g. leaked data). To do this, you want to use an email with your design, company name and structure and also send this via your infrastructure.
  • Ticketing System Integration: You want to integrate Kaduu into your existing environment and create tickets or incidents automatically in Splunk, Jira, Slack or similar systems.
  • Automated Output Parsing: You want to store all results for certain search queries daily in an easy-to-process format (CSV, XLS, etc.) locally in a folder of your choice for analysis and further processing.
  • Reduce Workload in Alerting: You want to save time when using Kaduu's email alerts: Instead of logging into the system for email alerts and researching the cause of the alerts, you want to receive the specific raw data of the alerts via email.

You can learn more in the readme.docx or download the python files.

api.1700996392.txt.gz · Last modified: 2023/11/26 11:59 by kaduuwikiadmin