Initiates export of threat data objects to a CSV file based on the CQL input. This API returns a file ID to retrieve the export file download link. You can export a maximum of 100,000 threat data objects in one API request.
The Column Object
Each column object includes the key and value of a column. You can include the following columns in the export file:
name
Value
type
Type
tlp
TLP
tags
Tags
sources
Source
source_collections
Source Collection
published_collections
Published Collections
ctix_created
System Created Date
ctix_modified
System Modified Date
country
Country
analyst_score
Analyst Score
source_confidence
Source ConfidenceBody Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| format | string | required | Pass the export file format. Currently, Intel Exchange supports only the CSV format. |
| component | string | required | Pass the component you want to export. |
| query | string | required | Pass the CQL query to filter threat data objects. |
| columns | array | required | Pass the list of columns you want to export. For the allowed list of columns, see The Column Object. |
Run it
Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).
Playground
Request parameters
Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.
Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.
Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.
Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.
curl --request POST \
--url "https://cs-testv2.cyware.com/ctixapi/ingestion/export/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
--data '{
"format": "csv",
"component": "threat_data",
"query": "type = \"tool\"",
"columns": [
{}
]
}'View-only example — running live API calls requires a role with snippet testing access.
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/export/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";
const response = await fetch(url, {
method: "POST",
headers: {},
body: JSON.stringify({
"format": "csv",
"component": "threat_data",
"query": "type = \"tool\"",
"columns": [
{}
]
}),
});
const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);View-only example — running live API calls requires a role with snippet testing access.
import requests
url = "https://cs-testv2.cyware.com/ctixapi/ingestion/export/"
params = {
"AccessID": "<your access id>",
"Signature": "<your signature>",
"Expires": "<your expires>"
}
headers = {}
payload = {
"format": "csv",
"component": "threat_data",
"query": "type = \"tool\"",
"columns": [
{}
]
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)View-only example — running live API calls requires a role with snippet testing access.
{
"format": "csv",
"component": "threat_data",
"query": "type = \"tool\"",
"columns": [
{}
]
}View-only example — running live API calls requires a role with snippet testing access.
{
"details": "Export is in progress. You will receive a notification once the export is complete.",
"file_id": "48294eb5-ad7a-439e-83e4-d99da6921076"
}View-only example — running live API calls requires a role with snippet testing access.