> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cotool.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List the Cotool detection library

> Returns every library entry with eligibility derived at request time from the organization's connected tools, and the org detection created from it when already added. Never includes notebook source. Requires tool.read; added detection IDs are limited to detections the caller can read.



## OpenAPI

````yaml https://app.cotool.ai/api/docs/openapi.json get /api/detection-library
openapi: 3.1.0
info:
  title: Cotool API
  version: 1.0.0
  description: >-
    # Cotool API Documentation


    The Cotool API allows you to interact with the Cotool platform
    programmatically, enabling you to build powerful integrations and automate
    your workflows.


    ## Getting an API Key


    Follow these steps to generate your API key:


    1. **Log in** to the Cotool web interface

    2. **Navigate** to `/settings/api-keys`

    3. **Click** "Generate Key"

    4. **Copy and store** your API key securely ⚠️ *It won't be shown again*


    ## API Key Authentication


    For programmatic access and integrations, use your API key with the
    Authorization header:


    ```http

    Authorization: Bearer your_api_key_here

    ```


    ```bash

    curl -X GET "https://app.cotool.ai/api/endpoint" \
      -H "Authorization: Bearer your_api_key_here" \
      -H "Content-Type: application/json"
    ```
servers:
  - url: https://app.cotool.ai
    description: Production server
security:
  - ApiKeyAuth: []
paths:
  /api/detection-library:
    get:
      tags:
        - Detections
      summary: List the Cotool detection library
      description: >-
        Returns every library entry with eligibility derived at request time
        from the organization's connected tools, and the org detection created
        from it when already added. Never includes notebook source. Requires
        tool.read; added detection IDs are limited to detections the caller can
        read.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  entries:
                    type: array
                    items:
                      type: object
                      properties:
                        slug:
                          type: string
                          description: Kebab-case library entry identity
                        name:
                          type: string
                        summary:
                          type: string
                          description: >-
                            1–3 sentence plain-prose headline of what the
                            detection is meant to detect
                        description:
                          type: string
                          description: >-
                            Operational GitHub-flavored markdown covering the
                            signal and the fire condition
                        revision:
                          type: string
                          pattern: ^[0-9a-f]{64}$
                          description: SHA-256 of the entry notebook
                        toolNames:
                          type: array
                          items:
                            type: string
                          description: Tool actions the entry notebook calls
                        requiredLogSources:
                          type: array
                          items:
                            type: string
                          description: >-
                            Cotool Logs warehouse sources the notebook queries
                            (e.g. okta); eligibility requires the org to have
                            their log ingest enabled
                        missingLogSources:
                          type: array
                          items:
                            type: object
                            properties:
                              id:
                                type: string
                                description: Ingest source registry id
                              displayName:
                                type: string
                                description: Human-readable log source name
                            required:
                              - id
                              - displayName
                            additionalProperties: false
                          description: >-
                            Required log sources the organization is not
                            ingesting
                        missingTools:
                          type: array
                          items:
                            type: object
                            properties:
                              name:
                                type: string
                                description: Tool action called by the entry notebook
                              displayName:
                                type: string
                                description: >-
                                  Human-readable integration name from the tools
                                  registry
                            required:
                              - name
                              - displayName
                            additionalProperties: false
                          description: >-
                            Required integration tool actions the organization
                            cannot run
                        mitreTechniqueIds:
                          type: array
                          items:
                            type: string
                        defaultCronSchedule:
                          type: string
                          description: Schedule enabled when the entry is added
                        defaultMinSeverity:
                          type: string
                          enum:
                            - low
                            - medium
                            - high
                            - critical
                        eligible:
                          type: boolean
                          description: >-
                            Whether missingLogSources and missingTools are both
                            empty
                        addedDetectionId:
                          type:
                            - string
                            - 'null'
                          format: uuid
                          description: >-
                            The org detection created from this entry, when
                            already added
                      required:
                        - slug
                        - name
                        - summary
                        - description
                        - revision
                        - toolNames
                        - requiredLogSources
                        - mitreTechniqueIds
                        - defaultCronSchedule
                        - defaultMinSeverity
                        - eligible
                        - addedDetectionId
                      additionalProperties: false
                required:
                  - entries
                additionalProperties: false
        '400':
          description: Bad request — input validation failed or the request was malformed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationError'
        '401':
          description: Unauthorized — missing or invalid API key / session
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Caller lacks tool.read
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      x-codeSamples:
        - lang: shell
          label: cURL
          source: |-
            curl -X GET "https://app.cotool.ai/api/detection-library" \
              -H "Authorization: Bearer YOUR_API_KEY" \
              -H "Content-Type: application/json"
components:
  schemas:
    ValidationError:
      type: object
      properties:
        error:
          type: string
          description: Error message describing what went wrong
        issues:
          type: array
          description: >-
            Detailed validation issues, present when request or response schema
            validation fails
          items:
            type: object
            additionalProperties: true
      required:
        - error
    Error:
      type: object
      properties:
        error:
          type: string
          description: Error message describing what went wrong
      required:
        - error
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: >-
        API Key authentication for programmatic access. Include your API key in
        the Authorization header as: `Bearer your_api_key_here`

````