HTTP API
The REST endpoint in one screen: POST Cypher as JSON, send your key in a header, read the response envelope.
In this chapter
On this page (3)
HTTP API Documentation
The Whisper API is one HTTP endpoint. POST a read-only Cypher query as JSON to https://graph.whisper.security/api/query and you get back columns and rows. There is no SDK to install and no session to manage; curl, fetch, or any HTTP client works as is. If you would rather stay in a terminal, the CLI sends the same request.
The same endpoint serves every request, and every runnable example in these docs goes through it. A GET variant and a /api/query/stats endpoint exist for quick checks and graph-wide counts. Every successful query answers with the same three fields — columns, rows and statistics — and every failed one with an application/problem+json body keyed on a stable type slug; the API Reference and Errors carry the detail.
Try it
One request end to end: resolve google.com to its IP addresses over the RESOLVES_TO edge. Running it here needs an account, so sign in.
curl -s -X POST https://graph.whisper.security/api/query \
-H "Content-Type: application/json" \
-H "X-API-Key: $WHISPER_API_KEY" \
-d "{\"query\":\"MATCH (h:HOSTNAME {name: \\\"google.com\\\"})-[:RESOLVES_TO]->(ip:IPV4) RETURN ip.name AS ip LIMIT 5\"}"The Raw tab shows the exact JSON envelope the API returns: columns, rows, and statistics.get an API key →
Authentication
Send your key in the X-API-Key header. A request with no key still runs, with reduced access, so confirm the key was accepted before you debug a query. The other accepted header formats and that check are in the API Reference; the response headers are on Errors.
Where next
The query language itself — its clauses, its functions and the rules that keep a query fast — is the Cypher chapter.