---
title: Using the Public API
slug: asm/using-the-public-api
description: FractalScan Surface provides a public HTTP API, built using the OpenAPI framework, that allows you to programmatically access and interact with your FractalScan data. 
docTags: 
createdAt: 2023-11-10T14:07:48.667Z
---

:::hint{type="info"}
Please note that the public API is not available in all Hexiosec ASM tiers. If you would like access to the API, please contact us at [support@hexiosec.com](mailto\:support@hexiosec.com)
:::

Hexiosec ASM provides a public HTTP API, built using the OpenAPI framework, that allows you to programmatically access and interact with your Hexiosec ASM data. The following page details the steps to generate your personal API key and start using the API.

The main documentation page for the API can be found at [https://asm.hexiosec.com/api/ui#overview](https://asm.hexiosec.com/api/ui#overview).

The OpenAPI specification for the API can be downloaded from  [https://asm.hexiosec.com/api/openapi.yml](https://asm.hexiosec.com/api/openapi.yml)

You can also find out more about[ creating a scan using the API](https://docs.hexiosec.com/asm/creating-a-scan-using-the-api) and [paginating API requests](https://docs.hexiosec.com/asm/paginating-the-api-requests).

# Generate your API key

From within the Hexiosec ASM app:

- Via the account icon, select 'account & preferences'
- Give the API key a description and lifetime and then click 'Create API key'

From a browser where you are logged into Hexiosec ASM:

- Navigate to: [https://asm.hexiosec.com/api/ui#get-/auth](https://asm.hexiosec.com/api/ui#get-/auth)
- Click 'Try'
- From the 'Response' copy the value for `crsf`
- Navigate or scroll to: [https://asm.hexiosec.com/api/ui#post-/users/api\_key](https://asm.hexiosec.com/api/ui#post-/users/api_key)
- In the example, update the 'description' and 'lifetime' as appropriate
- Add the copied `crsf` to the request header `X-CRSF-Token`
- Click 'Try'
- You API key is the value under `api_key`

# Use your API key

Both examples below get the organisations for the logged in user.

In the browser:

- Navigate to: [https://asm.hexiosec.com/api/ui#auth](https://asm.hexiosec.com/api/ui#auth)
- Add the API key to the value for the 'API Key'
- Navigate or scroll to: [https://asm.hexiosec.com/api/ui#get-/v1/orgs](https://asm.hexiosec.com/api/ui#get-/v1/orgs)
- Click 'Try'
- The result of the request can be seen in the 'Response' tab

In a terminal (via the steps above in a browser):

- Do the steps above
- Copy the value under the 'Curl' tab
- Paste the command and run it

