Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

API token obtained from the Tokens endpoint or CLI device login. Include as Authorization: Bearer <token>. Requests made with a managed CLI session also include X-Strix-Workspace: <organization_id> to pin a process to the workspace it started in; recovery endpoints report the current workspace after a concurrent switch.

Body

application/json
domain
string
required

Hostname to add, for example app.example.com. Do not include a scheme or path.

asset_type
enum<string>
required

Kind of asset the domain is. Use web_app for browser applications, api for HTTP APIs, and attack_surface for external discovery.

Available options:
web_app,
api,
attack_surface
context
string | null

Free-text background about the domain that the agent uses on every scan. Send null to clear it.

tags
string[]

Enterprise asset labels for RBAC scoping. Requires the Enterprise plan.

business_unit
string | null

Enterprise asset label for RBAC scoping. Requires the Enterprise plan.

Response

Domain already exists.

domain
object
required
status
enum<string>
required
Available options:
added,
exists
reachable
boolean
required
verification
object
required