Your fleet.
Queryable.
Bring endpoint evidence into the tools you already use. Build with the API. Investigate with MCP. Keep every customer’s data inside its own boundary.
“What operating system are you running?”
Architecture illustration · not a live fleet
A place to start
Choose your integration.
From your first request to a connected investigation workflow.
Build on endpoint evidence.
Discover your fleet, submit questions, and bring attributed answers into your existing security workflows.
Make your first query ↗Give your AI a view of the fleet.
Connect an MCP client to six read-only investigation tools, using the same customer-scoped access.
Connect an MCP client ↗Start with the right boundaries.
Understand customer isolation, API scopes, credential handling, and the access model ahead.
Explore authentication ↗Small request. Useful context.
Start with the endpoints
you can access.
One customer key. An explicit list of endpoints. A clear path from a question to its source.
Explore the integration examples →API keys and read-only queries are live. OAuth sign-in, site roles, and invitations are planned.
See release capabilities ↗curl --fail-with-body "https://api.recursift.app/v1/agents?limit=20" \
-H "Authorization: Bearer $RECURSIFT_API_KEY"