From an empty account to a confirmed finding in under five minutes. This guide uses the REST API — if you'd rather use the dashboard, see the UI walkthrough instead.
Every request to the Orithos API is authenticated with a bearer token scoped to your organisation. Generate one from Settings → API Keys in the dashboard, or via the CLI:
$ orithos auth login
# Opens a browser window for OAuth — the key is stored in
# ~/.orithos/credentials, never printed to stdoutPrefer the API? POST /v1/api-keys creates a key programmatically — response includes the plaintext once; we only store a bcrypt hash.
An agent is the unit Orithos scans — your system prompt, tool manifest, RAG sources, and guardrail declarations, described once and reused across every scan.
/v1/agentscurl https://api.orithos.com/v1/agents \
-H "Authorization: Bearer $ORITHOS_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "Support Assistant",
"endpoint_url": "https://api.openai.com/v1/chat/completions",
"system_prompt": "You are a helpful support assistant...",
"tools_config": [
{
"name": "order_lookup",
"description": "Look up an order by ID",
"parameters": {"order_id": {"type": "string", "required": true}}
}
]
}'The response includes an id (e.g. agt_8f2a1c) — save it, you'll need it for every subsequent call. See Agents for the full schema (provider presets, headers, memory_config, guardrails).
Orithos sends probes to your agent's actual running deployment. A connection is a URL and an auth method — no SDK installed on your side, no code changes to your agent. You can set endpoint_url directly on the agent (step 2), or manage a dedicated connection:
| Field | Type | Description |
|---|---|---|
| endpoint_url required | string | Your agent's chat completion endpoint |
| auth_type optional | enum | bearer · api_key · none |
| format optional | enum | openai_compatible · anthropic |
Credentials are Fernet-encrypted at rest. Health checks run every 6 hours — or hit POST /v1/agents/:id/verify for an immediate check.
/v1/scanscurl https://api.orithos.com/v1/scans \
-H "Authorization: Bearer $ORITHOS_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"agent_id": "agt_8f2a1c",
"connection_id": "cxn_44e01b",
"intensity": "deep"
}'
# Response — 202 Accepted
{
"scan_id": "scn_a3f9c21",
"status": "running"
}intensity is quick (1 probe/category) or deep (full catalog + permutations). Add connection_id when the same agent has multiple endpoints (staging vs production).
/v1/scans/:scan_idA typical deep scan completes in under 5 minutes. Poll every 5–10 seconds, or subscribe to the WebSocket stream (see Running a scan) to avoid polling entirely.
{
"scan_id": "scn_a3f9c21",
"status": "complete",
"risk_score": 6.4,
"findings": {
"critical": 0, "high": 1, "medium": 2, "low": 0
},
"findings_url": "https://api.orithos.com/v1/findings?scan_id=scn_a3f9c21"
}Fetch full evidence at GET /v1/findings?scan_id=scn_a3f9c21 or export HTML / PDF / SARIF from the dashboard.
orithos skill scan for vetting skills and plugins offline.Keep these in mind as you move beyond the quickstart.