> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cotool.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Read one detection library entry

> Returns the entry with its notebook source and the globally cached logic summary, for review before adding. Requires tool.read.



## OpenAPI

````yaml https://app.cotool.ai/api/docs/openapi.json get /api/detection-library/{slug}
openapi: 3.1.0
info:
  title: Cotool API
  version: 1.0.0
  description: >-
    # Cotool API Documentation


    The Cotool API allows you to interact with the Cotool platform
    programmatically, enabling you to build powerful integrations and automate
    your workflows.


    ## Getting an API Key


    Follow these steps to generate your API key:


    1. **Log in** to the Cotool web interface

    2. **Navigate** to `/settings/api-keys`

    3. **Click** "Generate Key"

    4. **Copy and store** your API key securely ⚠️ *It won't be shown again*


    ## API Key Authentication


    For programmatic access and integrations, use your API key with the
    Authorization header:


    ```http

    Authorization: Bearer your_api_key_here

    ```


    ```bash

    curl -X GET "https://app.cotool.ai/api/endpoint" \
      -H "Authorization: Bearer your_api_key_here" \
      -H "Content-Type: application/json"
    ```
servers:
  - url: https://app.cotool.ai
    description: Production server
security:
  - ApiKeyAuth: []
paths:
  /api/detection-library/{slug}:
    get:
      tags:
        - Detections
      summary: Read one detection library entry
      description: >-
        Returns the entry with its notebook source and the globally cached logic
        summary, for review before adding. Requires tool.read.
      parameters:
        - in: path
          name: slug
          schema:
            type: string
            pattern: ^[a-z0-9]+(-[a-z0-9]+)*$
          required: true
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  slug:
                    type: string
                    description: Kebab-case library entry identity
                  name:
                    type: string
                  summary:
                    type: string
                    description: >-
                      1–3 sentence plain-prose headline of what the detection is
                      meant to detect
                  description:
                    type: string
                    description: >-
                      Operational GitHub-flavored markdown covering the signal
                      and the fire condition
                  revision:
                    type: string
                    pattern: ^[0-9a-f]{64}$
                    description: SHA-256 of the entry notebook
                  toolNames:
                    type: array
                    items:
                      type: string
                    description: Tool actions the entry notebook calls
                  requiredLogSources:
                    type: array
                    items:
                      type: string
                    description: >-
                      Cotool Logs warehouse sources the notebook queries (e.g.
                      okta); eligibility requires the org to have their log
                      ingest enabled
                  missingLogSources:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          description: Ingest source registry id
                        displayName:
                          type: string
                          description: Human-readable log source name
                      required:
                        - id
                        - displayName
                      additionalProperties: false
                    description: Required log sources the organization is not ingesting
                  missingTools:
                    type: array
                    items:
                      type: object
                      properties:
                        name:
                          type: string
                          description: Tool action called by the entry notebook
                        displayName:
                          type: string
                          description: >-
                            Human-readable integration name from the tools
                            registry
                      required:
                        - name
                        - displayName
                      additionalProperties: false
                    description: >-
                      Required integration tool actions the organization cannot
                      run
                  mitreTechniqueIds:
                    type: array
                    items:
                      type: string
                  defaultCronSchedule:
                    type: string
                    description: Schedule enabled when the entry is added
                  defaultMinSeverity:
                    type: string
                    enum:
                      - low
                      - medium
                      - high
                      - critical
                  eligible:
                    type: boolean
                    description: Whether missingLogSources and missingTools are both empty
                  addedDetectionId:
                    type:
                      - string
                      - 'null'
                    format: uuid
                    description: >-
                      The org detection created from this entry, when already
                      added
                  content:
                    type: string
                    description: The entry notebook source, for read-only preview
                  interpretation:
                    type:
                      - object
                      - 'null'
                    properties:
                      status:
                        type: string
                        enum:
                          - ready
                          - empty
                        description: >-
                          "empty" when the notebook has no interpretable cells
                          yet
                      interpretation:
                        type:
                          - object
                          - 'null'
                        properties:
                          notebookRevision:
                            type: string
                            description: Notebook revision this interpretation describes
                          lanes:
                            type: array
                            items:
                              type: object
                              properties:
                                id:
                                  type: string
                                steps:
                                  type: array
                                  items:
                                    type: object
                                    properties:
                                      id:
                                        type: string
                                        description: >-
                                          Stable step identifier carried across
                                          regenerations
                                      title:
                                        type: string
                                        description: 2-5 word verb-first objective
                                      summary:
                                        type: string
                                        description: >-
                                          Plain-language explanation of this step
                                          only
                                      kind:
                                        type: string
                                        enum:
                                          - source
                                          - transform
                                          - decision
                                          - output
                                      cellHashes:
                                        type: array
                                        items:
                                          type: string
                                        description: >-
                                          Content hashes of the cells this step
                                          owns
                                      substeps:
                                        type: array
                                        items:
                                          type: object
                                          properties:
                                            id:
                                              type: string
                                            title:
                                              type: string
                                              description: Short plain-language action, a few words
                                            detail:
                                              type: string
                                              description: >-
                                                One or two sentences describing the
                                                concrete logic
                                            cellHash:
                                              type: string
                                              description: >-
                                                Content hash of the cell this substep
                                                describes
                                          required:
                                            - id
                                            - title
                                            - detail
                                            - cellHash
                                          additionalProperties: false
                                    required:
                                      - id
                                      - title
                                      - summary
                                      - kind
                                      - cellHashes
                                      - substeps
                                    additionalProperties: false
                                  description: Ordered steps; each step feeds the next
                              required:
                                - id
                                - steps
                              additionalProperties: false
                            description: Disjoint simple paths over the semantic steps
                        required:
                          - notebookRevision
                          - lanes
                        additionalProperties: false
                      cells:
                        type: array
                        items:
                          type: object
                          properties:
                            name:
                              type: string
                              description: Cell function name; "_" when anonymous
                            code:
                              type: string
                              description: >-
                                Cell body source without the def/return
                                scaffolding
                            refs:
                              type: array
                              items:
                                type: string
                              description: Variables the cell consumes from other cells
                            defs:
                              type: array
                              items:
                                type: string
                              description: Variables the cell defines for other cells
                            params:
                              type: array
                              items:
                                type: object
                                properties:
                                  name:
                                    type: string
                                    description: Constant name, e.g. LOOKBACK_HOURS
                                  value:
                                    anyOf:
                                      - type: number
                                      - type: string
                                      - type: boolean
                                  line:
                                    type: integer
                                    description: Absolute notebook line of the assignment
                                required:
                                  - name
                                  - value
                                  - line
                                additionalProperties: false
                              description: Tunable literal constants declared by this cell
                            lineStart:
                              type: integer
                              description: First line of the cell in the notebook file
                            lineEnd:
                              type: integer
                              description: Last line of the cell in the notebook file
                            contentHash:
                              type: string
                              description: SHA-256 of the cell body source
                          required:
                            - name
                            - code
                            - refs
                            - defs
                            - params
                            - lineStart
                            - lineEnd
                            - contentHash
                          additionalProperties: false
                        description: >-
                          Cells of the interpreted revision, for code display
                          and referencing
                    required:
                      - status
                      - interpretation
                      - cells
                    additionalProperties: false
                    description: >-
                      Logic summary computed once per notebook revision and
                      cached globally; null until the interpretation job
                      produces it
                required:
                  - slug
                  - name
                  - summary
                  - description
                  - revision
                  - toolNames
                  - requiredLogSources
                  - mitreTechniqueIds
                  - defaultCronSchedule
                  - defaultMinSeverity
                  - eligible
                  - addedDetectionId
                  - content
                  - interpretation
                additionalProperties: false
        '400':
          description: Bad request — input validation failed or the request was malformed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationError'
        '401':
          description: Unauthorized — missing or invalid API key / session
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Caller lacks tool.read
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Library entry not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      x-codeSamples:
        - lang: shell
          label: cURL
          source: |-
            curl -X GET "https://app.cotool.ai/api/detection-library/:slug" \
              -H "Authorization: Bearer YOUR_API_KEY" \
              -H "Content-Type: application/json"
components:
  schemas:
    ValidationError:
      type: object
      properties:
        error:
          type: string
          description: Error message describing what went wrong
        issues:
          type: array
          description: >-
            Detailed validation issues, present when request or response schema
            validation fails
          items:
            type: object
            additionalProperties: true
      required:
        - error
    Error:
      type: object
      properties:
        error:
          type: string
          description: Error message describing what went wrong
      required:
        - error
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: >-
        API Key authentication for programmatic access. Include your API key in
        the Authorization header as: `Bearer your_api_key_here`

````