<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/huntress-api-update-new-endpoints-webhooks-and-automation-tvop3nnql" -->

---
title: Huntress API Update: New Endpoints, Webhooks, and Automation
description: Huntress has expanded its API from six read-only endpoints into a full integration and automation platform, adding write capabilities for managing agents,...
canonical: https://daily.dev/posts/huntress-api-update-new-endpoints-webhooks-and-automation-tvop3nnql
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Huntress API Update: New Endpoints, Webhooks, and Automation | daily.dev
og:description: Huntress has expanded its API from six read-only endpoints into a full integration and automation platform, adding write capabilities for managing agents,...
og:url: https://daily.dev/posts/huntress-api-update-new-endpoints-webhooks-and-automation-tvop3nnql
og:image: https://api.daily.dev/og/posts/TvoP3NnqL.png
og:image:alt: Huntress API Update: New Endpoints, Webhooks, and Automation
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Huntress API Update: New Endpoints, Webhooks, and Automation

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 5 min read · 1 upvotes · 0 comments

## Summary

Huntress has expanded its API from six read-only endpoints into a full integration and automation platform, adding write capabilities for managing agents, organizations, and user access programmatically. New read endpoints expose security workflow data (Signals API, SIEM Query API), richer per-product organization statistics, and external recon port scan data. API keys are now user-based rather than account-level, mirroring user permissions and updating automatically with role changes. Resellers get a new API for account CRUD, subscription management, and billing across all Huntress products. Full docs and an interactive testing widget are available at api.huntress.io/docs.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/huntress-api-automation-platform>

## Questions this post answers

### Does the Huntress API support write operations now, not just reading data?

Yes, the Huntress API now supports write operations in addition to read access. New write endpoints let partners uninstall agents, update tags, toggle tamper protection, isolate or release hosts, and programmatically create, update, or delete organizations and reseller accounts without logging into the portal.

_daily.dev helps developers track platform API changes like this before they touch production automation._

### How do Huntress API keys work now compared to before?

Huntress has deprecated the old account-level API key in favor of user-based API keys that mirror the permissions of the assigned user. Multiple keys can be created per user and per account, each scoped to only what it needs, and permissions update automatically whenever a user's role changes.

_developers migrating off deprecated API keys can follow changes like this on daily.dev._

### What new data can partners pull from the Huntress API besides basic account info?

New read endpoints expose security event data through the Signals API and SIEM Query API, incident report approval/rejection, ITDR unwanted access rules, per-product organization statistics (agent counts, SIEM storage, ITDR identity counts), and external recon port scan data including IP, port, protocol, and detected service.

_daily.dev keeps API-integration engineers current on new endpoints worth automating around._

## Similar posts on daily.dev

- [Introducing Huntress Webhooks. Get Real-Time Security Alerts.](https://daily.dev/posts/introducing-huntress-webhooks-get-real-time-security-alerts--33akh2jhw) · Huntress Blog · 0 upvotes · 0 comments
- [Huntress hits an inflection point](https://daily.dev/posts/huntress-hits-an-inflection-point-nxiqz9unm) · Huntress Blog · 0 upvotes · 0 comments
- [Huntress Widens Partner Programme to Reach Small Businesses Worldwide](https://daily.dev/posts/huntress-widens-partner-programme-to-reach-small-businesses-worldwide-qssviiuof) · IT Security Guru · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#architecture](https://daily.dev/tags/architecture), [#automation](https://daily.dev/tags/automation)

[View this post on daily.dev](https://daily.dev/posts/huntress-api-update-new-endpoints-webhooks-and-automation-tvop3nnql)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Huntress API Update: New Endpoints, Webhooks, and Automation","url":"https://daily.dev/posts/huntress-api-update-new-endpoints-webhooks-and-automation-tvop3nnql","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/huntress-api-update-new-endpoints-webhooks-and-automation-tvop3nnql"},"datePublished":"2026-09-01T15:04:26.250Z","dateModified":"2026-09-01T15:22:17.451Z","description":"Huntress has expanded its API from six read-only endpoints into a full integration and automation platform, adding write capabilities for managing agents,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6822a1508e435a12ce5957cf503e28f0?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6822a1508e435a12ce5957cf503e28f0?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Huntress Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Huntress Blog","logo":"https://media.daily.dev/image/upload/s--kDC1MDsj--/f_auto,q_auto/v1780213277/logos/huntress-blog?_a=BAMAMiWQ0","url":"https://daily.dev/sources/huntress-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/huntress-api-update-new-endpoints-webhooks-and-automation-tvop3nnql","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,architecture,automation","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Huntress Blog","item":"https://daily.dev/sources/huntress-blog"},{"@type":"ListItem","position":3,"name":"Huntress API Update: New Endpoints, Webhooks, and Automation"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/huntress-api-update-new-endpoints-webhooks-and-automation-tvop3nnql#faq","mainEntity":[{"@type":"Question","name":"Does the Huntress API support write operations now, not just reading data?","acceptedAnswer":{"@type":"Answer","text":"Yes, the Huntress API now supports write operations in addition to read access. New write endpoints let partners uninstall agents, update tags, toggle tamper protection, isolate or release hosts, and programmatically create, update, or delete organizations and reseller accounts without logging into the portal. daily.dev helps developers track platform API changes like this before they touch production automation."}},{"@type":"Question","name":"How do Huntress API keys work now compared to before?","acceptedAnswer":{"@type":"Answer","text":"Huntress has deprecated the old account-level API key in favor of user-based API keys that mirror the permissions of the assigned user. Multiple keys can be created per user and per account, each scoped to only what it needs, and permissions update automatically whenever a user's role changes. developers migrating off deprecated API keys can follow changes like this on daily.dev."}},{"@type":"Question","name":"What new data can partners pull from the Huntress API besides basic account info?","acceptedAnswer":{"@type":"Answer","text":"New read endpoints expose security event data through the Signals API and SIEM Query API, incident report approval/rejection, ITDR unwanted access rules, per-product organization statistics (agent counts, SIEM storage, ITDR identity counts), and external recon port scan data including IP, port, protocol, and detected service. daily.dev keeps API-integration engineers current on new endpoints worth automating around."}}]}
```

