Skip to main content
AirMDR authenticates with Abnormal Security using a bearer API token.When AirMDR makes an API request, the token is submitted in the following HTTP header: Authorization: Bearer <API_TOKEN>
Enter only the generated token in the AirMDR API Token field. Do not add the Bearer prefix unless the AirMDR UI explicitly requests it.

Required role

The user creating the token must be able to:
  • Access Settings → Integrations.
  • Create and manage API tokens.
  • Select the tenant associated with the token.
  • Assign API endpoint permissions.
  • Configure token expiration and IP safelisting, when applicable.

Token access requirements

Use Custom Access and grant only the endpoints required by the AirMDR skills that will use this connection.For example:

Pre-requisites

Users must have Administrator access to the Abnormal Security UI with sufficient privileges to create an API key.
Permission to create and access the Abnormal Security API keys settings.
Some endpoints require an additional Abnormal Security license. For example, access to the Cases API requires an Account Takeover Protection license.

Setup Steps

1

Generate the API Token in Abnormal Security

  1. Sign in to the Abnormal Security portal.
  2. From the navigation menu, select Settings & Configuration → Integrations.
  3. Locate the API Token Management section.
  4. Click + Create New Token.
    Image
  5. For Integration Type, select REST API.
  6. Click Next.
  7. Continue with the applicable token-scope procedure, under Token Scope, select the appropriate scope.
    • Option 1: Tenant (Single Tenant)
    • Option 2: Customer (Multiple Tenants)
2

Option 1: Tenant (Single Tenant)

Use this scope when the AirMDR connection needs to access only one Abnormal Security tenant.
  1. Under Token Scope, select Tenant (Single Tenant).
  2. From the tenant list, select the organization that will connect to AirMDR.
  3. Click Next.
  4. Under Configure Access Type, select Custom Access.
  5. Select the API endpoints required by the supported AirMDR skills.
  6. Assign the minimum required access level to each selected endpoint. For example:
  7. Click Next.
  8. Continue to Configure the Token Details.
    Access to some endpoints may depend on the Abnormal Security products licensed for the selected tenant. For example, the Cases API requires an Account Takeover Protection entitlement.
3

Option 2: Customer (Multiple Tenants)

Use this scope only when the AirMDR connection is intended to access multiple Abnormal Security tenants managed under the same customer or partner account.
  1. Under Token Scope, select the applicable customer-level option, such as Customer (All Current and Future Tenants).
  2. Select the customer account associated with the tenants that AirMDR must access.
  3. Review the scope carefully. If All Current and Future Tenants is selected, the token may also apply to tenants added to the customer account after the token is created.
  4. Click Next.
  5. Under Configure Access Type, select Custom Access.
  6. Select only the API endpoints required by the supported AirMDR skills.
  7. Assign the minimum required access level for each endpoint.
  8. Verify that the selected endpoint permissions are appropriate for every tenant covered by the token.
  9. Click Next.
  10. Continue to Configure the Token Details.
    A customer-level token can provide access to data from multiple tenants. Use this scope only when multi-tenant access is required and approved by your organization.
    If different tenants require different permissions or access restrictions, create separate single-tenant tokens and AirMDR connections instead of using one broadly scoped customer token.
4

Configure the Token Details

Complete these steps after selecting either the single-tenant or multiple-tenant scope:
  1. Enter a recognizable Token Name.
    Single-tenant example: AirMDR-Abnormal-Production-Tenant
    Multiple-tenant example: AirMDR-Abnormal-Multi-Tenant
  2. Enter a description that identifies the connection’s purpose and scope.
    Example: Token used by AirMDR to execute approved Abnormal Security skills for the selected tenant scope.
  3. Select a Token Expiration Period that complies with your organization’s credential-rotation policy.
  4. In IP Safelist, enter the approved AirMDR outbound IPv4 or IPv6 addresses or CIDR ranges.
    Obtain the applicable outbound IP addresses from your AirMDR administrator or AirMDR Support. Requests may return 403 Forbidden if the AirMDR outbound IP addresses are not included in the safelist.
  5. Review the following token settings:
    • Integration type
    • Token scope
    • Included tenants
    • API endpoint permissions
    • Expiration period
    • IP safelist
  6. Click Create Token.
    Image
  7. Copy the generated API token immediately.
    Abnormal Security displays the token only once. Make sure to record the token before closing this modal, Abnormal Security will never again provide that token to you, this is your one and only chance to record it. 

    If it is lost, generate a new token.
    Image
  8. Store the token in an approved secrets manager or encrypted credential vault and share it securely with AirMDR.
  9. Click Done.
    Treat the API token as a password. Do not include it in documentation, screenshots, tickets, email, Slack messages, logs, or source-control repositories.
    If your tenant does not display API Token Management, navigate to Settings → Integrations → Additional Integrations → Abnormal REST API → Click Connect.

    Configure the required access and IP safelist to generate and copy the token.

Manage, Rotate, and Revoke Tokens

On the API Token Management dashboard, you can search, filter, rotate, revoke, and edit existing tokens. Use the search bar to filter by token name, scope, or access type.
Navigation Path: Settings → Integrations → API Token Management
Image
Rotating a token generates a new token value and immediately invalidates the existing value. The token scope, access permissions, and IP safelist remain unchanged.
Rotation immediately invalidates the API token currently stored in AirMDR. Until the AirMDR connection is updated, requests may fail with a 401 Unauthorized response.
To rotate an API token:
  1. Click the rotate icon (rotating arrow icon).
  2. Select a new token expiration date.
  3. Click Rotate Token.
    Image
  4. Copy the newly generated token immediately and store it temporarily in an approved secure location.
  5. Return to the AirMDR connection.
  6. Replace the existing value in API Token with the new token.
  7. In Expiry, select the new Abnormal Security token expiration date.
  8. Click Save.
To edit an existing token:
  1. Click the cog wheel icon to open a Token Details page.
    You can update any of the following:
    • Token name
    • Description
    • Safelisted IP addresses
      Image
  2. Save the changes.
    If the AirMDR connection uses a Remote Agent, ensure that the Remote Agent’s public outbound IP address is included in the token’s IP Safelist.

    Otherwise, Abnormal Security may reject AirMDR requests.
Revocation immediately and permanently invalidates a token. Unlike rotation, revocation does not generate a replacement token.Revoke a token when:
  • The AirMDR connection is being decommissioned.
  • The token is suspected to have been compromised.
  • A policy change requires removing the granted access.
  • A new token with a different scope or access level has replaced the existing token.
  • A legacy token has been successfully replaced.
    Revocation cannot be undone. If AirMDR continues using the revoked token, API requests will fail with a 401 Unauthorized response.
Before revoking a token that is still used by AirMDR:
  1. Create a replacement token.
  2. Update the AirMDR connection with the replacement token.
  3. Update the Expiry field.
  4. Save and validate the connection.
  5. Revoke the previous token only after successful validation.
To revoke the token:
  1. Sign in to the Abnormal Security portal.
  2. Navigate to Settings → Integrations → API Token Management.
  3. Find the token that you want to revoke.
  4. Click the trash icon.
  5. Review the permanent-action warning.
  6. Click Revoke Token.
    Image
  7. Confirm that the revoked token is no longer used by any AirMDR connection or other integration.
5

Determine the Base URL

The Base URL is not generated with the token. Select it based on the region in which your Abnormal Security tenant is hosted.
These regional endpoints are listed in the Abnormal Security API specification.
Enter the Base URL only. Do not append an individual resource path such as /threats or /cases.
If you are unsure of the tenant region:
  • Review your Abnormal Security onboarding information.
  • Check the region associated with your tenant.
  • Contact your Abnormal Security administrator or Abnormal Security Support.
For a FedRAMP/GovCloud environment, confirm the supported Base URL with Abnormal Security and AirMDR Support before creating the connection.

Abnormal Security Credential Reference Table

Validate Connectivity

The following example retrieves threat information from the US API endpoint:
curl —request GET \—url “https://eu.rest.abnormalsecurity.com/v1/threats” \—header “Authorization: Bearer <API_TOKEN>” \—header “Accept: application/json”
{“instance”: “Abnormal-Security-Production”,“base_url”: “https://api.abnormalplatform.com/v1”,“api_token”: “<stored-securely-in-airmdr>”}
Abnormal Security also documents a Mock-Data: True header for testing supported requests without relying on production threat data.
Run manual API tests only from an approved system. Do not expose the token in shared terminal history or logs.

Configure Abnormal Security in AirMDR Integrations Dashboard

  1. Navigate to AirMDR, provide the credentials and click Login
  2. Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select ADMIN → Integrations.
  3. Use the search option, enter the keyword “Abnormal Security”, select the Connections tab, and click + New Connection button.
    Image
  4. Use the following values in the AirMDR integration configuration screen:
    Enter only the token value in API Token. Do not include the Bearer prefix. Enter the Base URL without appending endpoints such as /threats or /cases.
    1. In Remote Agent, leave the field unselected for a standard cloud connection. Select an AirMDR Remote Agent only when your organisation requires Abnormal Security API requests to pass through an approved private network route or a specific outbound IP address.
      When using a Remote Agent, add the Remote Agent’s public outbound IP address to the IP Safelist configured for the Abnormal Security API token. Otherwise, Abnormal Security may reject requests with a 403 Forbidden response.
    2. In Expiry, select the date on which AirMDR should treat the stored connection credentials as expired, according to your organisation’s credential-rotation policy.
      The AirMDR Expiry setting is a connection-management control. It does not automatically configure or rotate the API key in Abnormal Security.
  5. Click Save.

Skills provided by this Integration

Case-related skills may require the applicable Abnormal Security product entitlement. Confirm that the selected tenant supports the Cases API.
To view the details of Input Parameters and Output for the respective skills
To view a skill’s input parameters and outputs:

Additional Information

AirMDR monitoring

Monitor:
  • Connection status.
  • Skill-execution status.
  • Playbook execution history.
  • Authentication and authorization failures.
  • API timeouts and network errors.
When reviewing failures, verify:
  • Connection instance used by the skill.
  • Execution timestamp.
  • HTTP status code.
  • Requested operation.
  • Error response, excluding credentials.

Abnormal Security monitoring

In Abnormal Security:
  1. Navigate to Settings > Integrations.
  2. Open API Token Management.
  3. Confirm that the AirMDR token is active.
  4. Verify its expiration date.
  5. Confirm the selected tenant and endpoint access.
  6. Verify the IP safelist.
  7. Rotate or revoke the token if suspicious usage is detected.

Example sanitized log entries

Successful request:
Authentication failure:
Authorization failure:
Never record the API token or complete Authorization header in logs.

✅ Do

  • Use Custom Access and assign the minimum endpoint permissions required.
  • Use a dedicated token for the AirMDR integration.
  • Configure an expiration period.
  • Safelist only approved AirMDR outbound IP addresses.
  • Store the token in the AirMDR credential field or an approved secrets manager.
  • Rotate the token according to your organization’s credential policy.
  • Use separate read-only and response-action tokens when operational separation is required.
  • Revoke unused, expired, or potentially compromised tokens.
  • Verify the tenant region before entering the Base URL.

❌ Don’t

  • Granting full access when read-only access is sufficient.
  • Reusing a personal or unrelated integration token.
  • Adding /threats, /cases, or another resource path to the Base URL.
  • Entering the EU Base URL for a US tenant, or vice versa.
  • Including Bearer in the AirMDR token field unless explicitly required.
  • Sharing the token through email, chat, documentation, screenshots, or tickets.
  • Logging the token or Authorization header.
  • Disabling certificate validation.
  • 📧 Contact AirMDR Support through your designated support channel.
  • 🔁 Rotate credentials regularly. Recommended cadence: As per your internal security policy
  • 🔄 Reconnect with AirMDR immediately when secrets are changed.

Data flow

  1. An AirMDR playbook or analyst initiates an Abnormal Security skill.
  2. AirMDR retrieves the stored connection credentials.
  3. AirMDR sends an HTTPS request to the configured regional Base URL.
  4. Abnormal Security validates the API token, endpoint permission, token scope, expiration, and IP safelist.
  5. Abnormal Security returns the permitted response.
  6. AirMDR makes the results available to the playbook or analyst.

Data exchanged

The data exchanged depends on the skill and permissions assigned to the token. It may include:
  • Threat identifiers and threat details.
  • Sender and recipient information.
  • Attack type and remediation status.
  • Message and attachment metadata.
  • Case information and status.
  • Employee or user information.
  • Action identifiers and action-status information.

Network and encryption

All network communication must use the HTTPS endpoint. Do not replace https:// with http://.