demisto-py
"A Python library for the Demisto API"
Decision gist · record as of 2026-08-14
Yes. The package is actively maintained, has no known vulnerabilities, uses a permissive Apache-2.0 license, and offers low-friction installation. It is the official client for Demisto API integration and is suitable for any Python-based security automation or integration project targeting Demisto or Cortex XSIAM platforms.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires valid Demisto API key (generated from Demisto Settings > API Keys) and network access to a Demisto or Cortex XSIAM server.
- Low friction install with standard dependencies.
- Actively maintained with last commit on 2026-07-29; supports Python 3.10 through 3.14.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use without restriction; suitable for proprietary integrations.
last release 2026-05-11 (95 days) · last repo commit 2026-07-29 · 73 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 104,596 downloads/mo, #12,745 on PyPI
Alternatives
Verify before relying
pip install demisto-py
import demisto_client
api_key = 'YOUR_API_KEY'
host = 'https://YOUR_DEMISTO_HOST'
api_instance = demisto_client.configure(base_url=host, api_key=api_key)- Whether the library supports Demisto server versions prior to 4.5 or only 4.5 and later as stated.
- Performance characteristics when handling large incident batches or high-frequency API calls.
- Whether generated code is kept in sync with newer Demisto server versions automatically.
What it is and what it does
demisto-py is a Python wrapper around the Demisto REST API, generated from the Demisto Server 4.5.0 Swagger definition. It provides a structured interface for authenticating to Demisto or Cortex XSIAM platforms and performing operations like creating incidents and querying data. The library supports multiple authentication methods: API key, username/password (XSOAR only), and Cortex XSIAM's auth_id scheme. Configuration can be passed directly or via environment variables, making it suitable for both interactive scripts and automated deployments.
The package depends on standard HTTP and date/time utilities (urllib3, certifi, python-dateutil, tzlocal, six, setuptools) and is designed for developers building integrations, incident response automation, or security operations workflows. It is actively maintained and supports Python 3.10 through 3.14.
Use it for
- Automate incident creation and enrichment from external security tools into Demisto.
- Build custom reporting tools that query incident and alert data from Demisto via API.
- Integrate Demisto with third-party ticketing systems to synchronize security events.
- Develop security automation that programmatically triggers Demisto operations based on external events.
- Bulk-import historical incidents or test data into Demisto for training purposes.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is actively maintained, has no known vulnerabilities, uses a permissive Apache-2.0 license, and offers low-friction installation. It is the official client for Demisto API integration and is suitable for any Python-based security automation or integration project targeting Demisto or Cortex XSIAM platforms.
Install
demisto-py on PyPI
Before you install
Low friction install with standard dependencies. Actively maintained with last commit on 2026-07-29; supports Python 3.10 through 3.14.
Requires valid Demisto API key (generated from Demisto Settings > API Keys) and network access to a Demisto or Cortex XSIAM server.
License in practice
Apache-2.0 permissive license allows commercial and private use without restriction; suitable for proprietary integrations.
Quickstart
pip install demisto-py
import demisto_client
api_key = 'YOUR_API_KEY'
host = 'https://YOUR_DEMISTO_HOST'
api_instance = demisto_client.configure(base_url=host, api_key=api_key)
Verify before relying
- Whether the library supports Demisto server versions prior to 4.5 or only 4.5 and later as stated.
- Performance characteristics when handling large incident batches or high-frequency API calls.
- Whether generated code is kept in sync with newer Demisto server versions automatically.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release <3.15,>=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 6 packagescertifisixpython-dateutilurllib3tzlocalsetuptools |
| Maintenance | Actively maintained 95 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 104,596 / month, #12,745 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Intended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseNatural Language :: EnglishProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPython |
Evidence: demisto_py-3.3.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “demisto api client”
- demisto-pyA Python client library for the Demisto API, enabling programmatic…
- demisto-sdkA command-line SDK and Python library for developing, validating, and…
- codewords-clientA Python client library for the Codewords API with built-in FastAPI…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also demisto-sdk · python-incidentio-client · datadog-api-client · athenaintel · dataforseo-client · tiktok-business-api-sdk-official · simile · assisted-service-client · brevo-python · xdk