CTIX
Network live
CTIXPOST

With Source and Collection Name

Source docs
POSThttps://cs-testv2.cyware.com/ctixapi/ingestion/ingestion-api/ingest_bundle/

Use this API to ingest a STIX bundle into Intel Exchange by specifying the source and collection name. A STIX bundle can include any combination of STIX Domain Objects (SDOs). For more information on supported objects, see the STIX documentation.

NOTE If you pass an invalid or missing source_name or collection_name, the bundle is ingested with the source set to Import and the collection set to STIX2.

Body Parameters

NameTypeRequiredDescription
bundleobjectrequired

Pass the STIX bundle that contains one or more STIX objects to ingest.

collection_namestringrequired

Pass the name of the collection that should receive the bundle.

source_namestringrequired

Pass the name of the source from which the bundle originates.

source_typestringrequired

Pass the type of the source. For example, CUSTOM_STIX_SOURCES.

Run it

Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).

Playground

Request parameters

Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.

CTIXConnect to Intel ExchangeRequired to change data
Credentials required for POST

Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.

Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.

Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.

Request body (JSON)Valid JSON
cURL
curl --request POST \
  --url "https://cs-testv2.cyware.com/ctixapi/ingestion/ingestion-api/ingest_bundle/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
  --data '{
  "bundle": {},
  "collection_name": "Compromised Credentials",
  "source_name": "Cyware CCM",
  "source_type": "CUSTOM_STIX_SOURCES"
}'

View-only example — running live API calls requires a role with snippet testing access.

JavaScript
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/ingestion-api/ingest_bundle/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";

const response = await fetch(url, {
  method: "POST",
  headers: {},
  body: JSON.stringify({
    "bundle": {},
    "collection_name": "Compromised Credentials",
    "source_name": "Cyware CCM",
    "source_type": "CUSTOM_STIX_SOURCES"
  }),
});

const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);

View-only example — running live API calls requires a role with snippet testing access.

Python
import requests

url = "https://cs-testv2.cyware.com/ctixapi/ingestion/ingestion-api/ingest_bundle/"
params = {
    "AccessID": "<your access id>",
    "Signature": "<your signature>",
    "Expires": "<your expires>"
}
headers = {}
payload = {
  "bundle": {},
  "collection_name": "Compromised Credentials",
  "source_name": "Cyware CCM",
  "source_type": "CUSTOM_STIX_SOURCES"
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)

View-only example — running live API calls requires a role with snippet testing access.

Request Body
{
  "bundle": {},
  "collection_name": "Compromised Credentials",
  "source_name": "Cyware CCM",
  "source_type": "CUSTOM_STIX_SOURCES"
}

View-only example — running live API calls requires a role with snippet testing access.

Example Response
{
  "success": true,
  "message": "Successfully sent bundle to ingestion."
}

View-only example — running live API calls requires a role with snippet testing access.