Ellipse Gradient for Header

Rapid7 Integration Guide

Connect Rapid7 security data and selected event notifications with enterprise systems through REST APIs, webhooks, and Martini workflows.

Rapid7 integration options at a glance

Rapid7 primarily integrates through product-specific REST APIs across InsightVM, InsightIDR, InsightConnect, InsightCloudSec, and related Insight Platform products. Martini can consume these APIs to retrieve Assets, Vulnerabilities, Investigations, Reports, and other documented resources, then transform and route the results to enterprise applications. Selected Rapid7 products and workflows support webhook-style notifications, which Martini can receive through REST APIs or workflow triggers. Some product APIs may also provide bulk, export, or asynchronous operations for large datasets. Rapid7 API-key authentication, regional endpoints, product permissions, pagination, rate limits, and incremental synchronization should be configured per product and environment.

Integration pointSupported by Rapid7?Common use casesHow Martini supports it
REST APIsYesRapid7’s primary integration mechanism for retrieving product-specific Assets, Vulnerabilities, Investigations, Reports, and other documented resources across the Insight Platform.Martini can consume Rapid7 REST endpoints, configure regional hosts and API-key headers, paginate responses, transform payloads, and route results through workflows or exposed APIs.
Webhooks / outbound callbacksLimitedSelected Rapid7 products or workflows can send webhook-style notifications for supported events, particularly through InsightConnect-related capabilities.Martini can expose a REST API or use a workflow start trigger to receive notifications, validate requests, apply replay and idempotency controls, and invoke follow-up Rapid7 API calls.
Bulk / async / batch APIsLimitedSome product APIs, especially InsightVM-related APIs, may provide export, batch, or asynchronous operations for large vulnerability and asset datasets.Martini can orchestrate asynchronous polling, process batches incrementally, and fall back to paginated REST calls when a suitable bulk operation is unavailable.
AuthenticationYesRapid7 Insight Platform APIs commonly use an API key in the X-Api-Key header, with product-specific permissions, regions, and credentials potentially applying.Martini stores API keys and regional configuration as environment secrets and injects them into requests without placing credentials in workflow payloads or logs.
Scheduled synchronizationYesScheduled API retrieval is appropriate for Assets, Vulnerabilities, Reports, and other objects without universal event coverage.Martini can schedule workflows, maintain cursors or checkpoints, apply bounded concurrency, and perform incremental or reconciliation-based synchronization.
File / attachment APIsNot confirmedIndividual products may support report export or file delivery, but no general Rapid7 platform-wide file or attachment API was confirmed.Martini can process files when a selected Rapid7 product documents a supported delivery mechanism, but the interface must be verified before implementation.
Database / analytics accessNoDirect access to Rapid7-managed product databases is not a documented general integration path.Martini should consume supported Rapid7 APIs or notifications and can write transformed results to an approved external database or warehouse.
GraphQL APIsNot confirmedNo general Rapid7 GraphQL API was confirmed for current integrations.Martini can consume GraphQL when a provider documents it, but Rapid7 integrations should use the relevant REST API unless product documentation states otherwise.

How Rapid7 exposes data and business events

Rapid7 REST APIs

REST is Rapid7’s primary documented integration mechanism, but endpoint and object models vary by product such as InsightVM, InsightIDR, InsightConnect, and InsightCloudSec. The selected product API determines available resources, fields, permissions, pagination, and write operations.

Martini implementation pattern

Martini stores the Rapid7 regional base URL and API key in environment configuration, invokes the appropriate product endpoint, follows pagination or asynchronous status responses, validates the returned schema, and maps the result into a target or canonical model. Workflows can expose a normalized Martini API for downstream consumers.

Implementation sequence

Select the Rapid7 product and documented endpoint
Load the regional API host and API key from Martini secrets
Call the Rapid7 REST resource
Follow pagination or asynchronous status responses
Validate and map the product-specific payload
Apply business rules and write the target result

Rapid7 webhook-style notifications

Selected Rapid7 products or workflows support webhook-style outbound notifications, but event coverage is product-specific and should not be generalized to every Rapid7 object. The implementation must document the supported product and event types.

Martini implementation pattern

Martini exposes a REST API or starts a workflow from an inbound trigger. The workflow authenticates or validates the request, checks replay and idempotency controls, optionally retrieves current details from Rapid7, enriches the event, and routes it to an incident, notification, or analytics system.

Implementation sequence

Configure the supported Rapid7 notification event
Receive the HTTP notification in Martini
Validate request authenticity and required fields
Check the source identifier for replay or duplication
Retrieve related Rapid7 details when enrichment is required
Map and route the normalized event to the target system

Rapid7 bulk and asynchronous operations

Some Rapid7 product APIs provide export, batch, or asynchronous processing capabilities, particularly for large InsightVM asset and vulnerability datasets. Availability, limits, and response behavior depend on the selected endpoint.

Martini implementation pattern

Martini starts the documented operation, stores the operation identifier, polls its status with controlled delays, retrieves the completed result, and processes pages or batches without retaining the full dataset in one execution. If no bulk operation exists, the workflow uses paginated incremental retrieval.

Implementation sequence

Start the documented Rapid7 bulk or asynchronous operation
Store the returned operation identifier
Poll status with bounded retries and backoff
Retrieve the completed result or next batch
Transform and write each batch independently
Persist a checkpoint for restart and reconciliation

Rapid7 scheduled synchronization

Scheduled synchronization provides a fallback or primary pattern for Assets, Vulnerabilities, Reports, Investigations, and other objects without universal event support. It is also useful for reconciliation after event delivery gaps.

Martini implementation pattern

Martini schedules a workflow that uses product-supported updated-time or status filters where available. Otherwise, it maintains a cursor, checkpoint, or comparison state, processes pages incrementally, applies idempotent upserts, and records the last successful synchronization boundary.

Implementation sequence

Schedule the Rapid7 synchronization workflow
Load the last successful cursor or checkpoint
Retrieve filtered or paginated Rapid7 data
Map and validate each object
Upsert using stable Rapid7 identifiers
Persist the new checkpoint and synchronization metrics

Common Rapid7 integration patterns

Pattern 1: Create remediation tasks from Rapid7 vulnerabilities

When to use this pattern

Use this pattern when security teams need Rapid7 Vulnerabilities and related Assets converted into actionable work in ServiceNow or Jira. It supports scheduled or incremental synchronization and avoids duplicate tasks when the same finding is returned repeatedly.

Integration direction
Rapid7 InsightVM
Martini
ServiceNow
Example Mapping
Rapid7 FieldCanonical FieldTarget Field
Vulnerability identifierfinding.externalIdServiceNow vulnerability reference
Severity or risk scorefinding.priorityServiceNow priority
Asset identifier and hostnameasset.externalId and asset.nameServiceNow configuration item
Remediation statusfinding.statusServiceNow task state
Martini implementation pattern

A scheduled Martini workflow retrieves changed Vulnerabilities and related Assets, validates required identifiers, maps Rapid7 severity to the target priority model, and applies ownership and due-date rules. It upserts by a composite vulnerability and asset key, retries transient target failures, and routes authorization or validation failures to an operational error flow.

Martini capabilities used
  • workflows
  • scheduled triggers
  • API consumption
  • pagination
  • data mapping
  • business rules
  • idempotency
  • error handling

Pattern 2: Synchronize Rapid7 assets to a CMDB or warehouse

When to use this pattern

Use this pattern to maintain an approved inventory of Rapid7 Assets in ServiceNow CMDB, Snowflake, or another repository. It is suitable for large inventories where incremental filters, checkpoints, or batch processing are needed.

Integration direction
Rapid7 InsightVM
Martini
Snowflake
Example Mapping
Rapid7 FieldCanonical FieldTarget Field
Asset identifierasset.externalIdasset_id
Hostnameasset.namehostname
Operating systemasset.operatingSystemoperating_system
Last scan timestampasset.lastObservedAtlast_scanned_at
Martini implementation pattern

Martini retrieves paginated Assets using documented filters where available, transforms product-specific fields into a versioned warehouse model, and upserts by the stable Rapid7 identifier. The workflow persists checkpoints, limits concurrency, and performs periodic reconciliation when incremental filtering is unavailable.

Martini capabilities used
  • workflows
  • scheduler triggers
  • API consumption
  • data transformation
  • database or warehouse writes
  • checkpointing
  • monitoring

Pattern 3: Route Rapid7 detections to incident response

When to use this pattern

Use this pattern when selected Rapid7 products can send webhook-style notifications or expose detection endpoints and response teams need normalized incidents in Microsoft Sentinel, Splunk, PagerDuty, Slack, or Microsoft Teams.

Integration direction
Rapid7
Martini
PagerDuty
Example Mapping
Rapid7 FieldCanonical FieldTarget Field
Detection or alert identifierevent.externalIdPagerDuty deduplication key
Severityevent.priorityPagerDuty urgency
Asset or identity contextevent.subjectPagerDuty incident details
Detection timestampevent.occurredAtPagerDuty incident timestamp
Martini implementation pattern

Martini receives a supported Rapid7 notification, validates the event type and source identifier, optionally calls the Rapid7 API for asset or identity enrichment, and applies severity-based routing. It uses the Rapid7 identifier for deduplication and retries transient downstream failures without replaying permanent validation errors.

Martini capabilities used
  • REST APIs
  • webhook consumption
  • workflow triggers
  • validation
  • enrichment
  • business rules
  • deduplication
  • retry handling

Pattern 4: Distribute Rapid7 security reports

When to use this pattern

Use this pattern when security or executive teams need scheduled Rapid7 report summaries delivered to SharePoint, email, Snowflake, or a reporting API. It is useful for recurring vulnerability and risk reporting across products.

Integration direction
Rapid7
Martini
SharePoint
Example Mapping
Rapid7 FieldCanonical FieldTarget Field
Report identifierreport.externalIdSharePoint document metadata
Report statusreport.statusprocessing status
Risk or vulnerability summaryreport.summaryreport content
Generated timestampreport.generatedAtcreated date
Martini implementation pattern

A Martini workflow invokes documented Rapid7 report or vulnerability endpoints, waits for asynchronous completion where required, transforms the returned summary, and distributes it to the target repository. Large results are processed in pages or batches, with failed deliveries recorded for retry and audit.

Martini capabilities used
  • scheduled workflows
  • API orchestration
  • asynchronous polling
  • data mapping
  • file or content handling when documented
  • error handling
  • monitoring

Applications commonly integrated with Rapid7

Rapid7 data can be routed to named enterprise applications for remediation, incident response, security analytics, collaboration, notification, and historical reporting. The exact flow depends on the Rapid7 product, available API operations, and supported event types; Martini provides the orchestration, transformation, validation, and retry handling between systems.

Application Scenario Direction Martini Pattern
ServiceNow Create vulnerability remediation tasks and incidents from Rapid7 findings, update CMDB information, and optionally return remediation status or ticket identifiers. Rapid7 → Martini → ServiceNow A scheduled Martini workflow retrieves paginated Rapid7 Vulnerabilities and Assets, applies severity and ownership rules, deduplicates using Rapid7 identifiers, and creates or updates ServiceNow tasks. Status changes can be reconciled through a separate documented API flow.
Jira Create engineering or infrastructure remediation issues from Rapid7 vulnerabilities and track work assigned to delivery teams. Rapid7 → Martini → Jira Martini retrieves changed vulnerabilities, maps severity, asset, remediation status, and due dates to Jira fields, and uses a composite Rapid7 vulnerability and asset key to prevent duplicate issues. Transient API failures are retried with controlled backoff.
Splunk Forward Rapid7 findings, detections, or normalized security events for search, correlation, and broader security operations analysis. Rapid7 → Martini → Splunk Martini receives supported Rapid7 notifications or polls product APIs, normalizes the event envelope, enriches selected events with Rapid7 asset data, and sends the result to Splunk through its documented ingestion interface.
Microsoft Sentinel Send Rapid7 security events and findings into a central SIEM and automation environment for correlation and response. Rapid7 → Martini → Microsoft Sentinel A Martini workflow validates selected Rapid7 events, maps product-specific fields to a common security-event model, and submits them to the approved Microsoft Sentinel ingestion endpoint while preserving source identifiers for deduplication.
Slack Publish selected high-priority detections, remediation failures, and workflow outcomes to security response channels. Rapid7 → Martini → Slack Martini receives a supported Rapid7 notification or scheduled result, applies severity and routing rules, formats a concise message, and sends it to the appropriate Slack destination. Failed notifications are captured for retry or operational review.
PagerDuty Create or update on-call incidents for high-priority Rapid7 detections or failed remediation workflows. Rapid7 → Martini → PagerDuty Martini maps Rapid7 alert severity and investigation identifiers to PagerDuty incident fields, applies deduplication keys, and routes only qualifying events to the on-call service. Repeated notifications update an existing incident instead of creating duplicates.
Microsoft Teams Distribute security notifications, investigation summaries, and remediation updates to operational teams. Rapid7 → Martini → Microsoft Teams A Martini workflow transforms selected Rapid7 events or scheduled summaries into Teams-compatible messages, applies channel-routing rules, and records the Rapid7 source identifier for traceability.
Snowflake Store historical Assets, Vulnerabilities, investigations, and remediation data for trend analysis, reporting, and governance. Rapid7 → Martini → Snowflake Martini pages through Rapid7 API results, converts product-specific responses into versioned analytical tables, upserts by stable Rapid7 identifiers, and stores synchronization checkpoints for incremental loads.

How to build a Rapid7 integration in Martini

Objective

Establish the Rapid7 product, region, endpoint family, and credentials required for the integration.

Instructions in Martini

  • Select the Rapid7 product and documented API resources
  • Store the regional base URL and API key as Martini environment configuration
  • Restrict the Rapid7 key to the minimum required product permissions
  • Test authentication without exposing the key in payloads or logs

Objective

Select an event-driven or scheduled initiation method based on the Rapid7 product and object coverage.

Instructions in Martini

  • Use a Rapid7 webhook-style notification only for documented product and event combinations
  • Expose a Martini API or use a workflow start trigger for supported inbound notifications
  • Use a scheduler for Assets, Vulnerabilities, Reports, or events without notification coverage
  • Define the synchronization interval and checkpoint strategy

Objective

Retrieve current Rapid7 data reliably across product-specific endpoints and response formats.

Instructions in Martini

  • Call the relevant Rapid7 REST endpoint
  • Follow pagination until the API indicates completion
  • Poll documented asynchronous operations with bounded retries
  • Use incremental filters or a Martini-side cursor when supported

Objective

Coordinate enrichment, validation, routing, and target writes in a maintainable Martini workflow.

Instructions in Martini

  • Separate notification intake from follow-up Rapid7 API retrieval when appropriate
  • Validate required identifiers and product-specific fields
  • Enrich detections with Assets or other resources only when needed
  • Route permanent failures to an operational error path

Objective

Transform Rapid7 product-specific schemas into canonical and target-specific models.

Instructions in Martini

  • Map actual Rapid7 object names and identifiers to target fields
  • Normalize severity, lifecycle status, timestamps, and ownership values
  • Preserve source identifiers and product context for traceability
  • Version mappings when Rapid7 product schemas or enum values change

Objective

Apply security, routing, deduplication, and synchronization rules before writing downstream data.

Instructions in Martini

  • Use stable Rapid7 identifiers as external keys
  • Apply severity thresholds and ownership rules
  • Prevent duplicate incidents or remediation tasks with composite keys where necessary
  • Limit concurrency and apply rate-limit-aware backoff

Common Rapid7 data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
AssetsRepresent hosts, devices, cloud resources, or other infrastructure observed by Rapid7 security products.ServiceNow CMDB, Snowflake, Microsoft Sentinel, SplunkMartini retrieves Assets through the selected product API, handles pagination or incremental filters, maps stable identifiers and ownership fields, and upserts the canonical asset model.
VulnerabilitiesRepresent vulnerability findings associated with Assets, including identifiers, risk information, severity, and remediation status.ServiceNow, Jira, Snowflake, Microsoft SentinelMartini maps product-specific severity and lifecycle values, builds deduplication keys from vulnerability and asset identifiers, applies remediation rules, and routes permanent mapping failures for review.
SitesRepresent logical collections of InsightVM Assets used for scanning, reporting, and access control.ServiceNow, Snowflake, governance repositoriesMartini retrieves documented Site fields, preserves Rapid7 identifiers and regional context, and relates Sites to synchronized Assets where the product API exposes that relationship.
ReportsRepresent security assessment or vulnerability reports generated from Rapid7 data.SharePoint, Snowflake, email platforms, executive reporting APIsMartini invokes documented report or vulnerability endpoints, coordinates asynchronous or paginated processing where available, transforms summaries, and distributes them to approved targets.
InvestigationsRepresent InsightIDR analysis of suspicious activity or security incidents.ServiceNow, Splunk, Microsoft Sentinel, PagerDutyMartini retrieves or receives supported investigation data, enriches it with related Rapid7 information when available, normalizes the event model, and preserves the investigation identifier for traceability.
Detections or alertsRepresent security events or detection results generated by Rapid7 monitoring and detection products.ServiceNow, Microsoft Sentinel, Splunk, Slack, PagerDuty, Microsoft TeamsMartini accepts selected webhook-style notifications or polls documented endpoints, validates event types, applies routing and severity rules, and suppresses duplicate downstream notifications.

Authentication and security considerations

API keys and product permissions

Rapid7 Insight Platform APIs commonly use an API key in the X-Api-Key header. Product-specific credentials, roles, organization access, and regional endpoints may also apply.

Secure configuration

Store Rapid7 API keys, regional base URLs, and target credentials in Martini environment configuration and secrets. Do not place credentials in workflow payloads, source-controlled mappings, or diagnostic messages.

Least privilege and validation

  • Use separate credentials for development, testing, and production where practical.
  • Grant only the product and operations required by the workflow.
  • Validate inbound webhook-style requests and implement replay and idempotency controls.
  • Do not assume OAuth 2.0 is the general Rapid7 authentication method; verify product-specific requirements.

Operational considerations for Rapid7 integrations

Product-specific schemas

Rapid7 APIs are organized by product, so fields, identifiers, lifecycle values, permissions, and write operations can differ between InsightVM, InsightIDR, InsightConnect, and InsightCloudSec.

Rate limits and pagination

Use bounded concurrency, pagination, and exponential backoff for transient failures. Large inventories should be processed incrementally or through documented bulk and asynchronous operations.

Checkpoints and idempotency

Persist cursors or synchronization checkpoints where appropriate. Use stable Rapid7 identifiers, or composite keys for vulnerability and asset relationships, so retries do not create duplicate incidents or remediation tasks.

Events and schema changes

Webhook-style coverage is product-specific. Document supported event types, retain scheduled polling as a fallback, validate response fields, and monitor changes to pagination fields, enum values, severity, and lifecycle statuses.

Testing and monitoring

Test each product endpoint, region, permission set, pagination path, and failure class before production deployment. Monitor workflow execution, rate-limit responses, rejected mappings, retries, and checkpoint progression.

Why use Martini instead of scripts or point-to-point integrations?

Orchestrate more than one API call

Rapid7 integrations often require product-specific retrieval, pagination, enrichment, target writes, and reconciliation. Martini coordinates these steps in workflows instead of embedding them in a single script.

Maintainable mappings and rules

Martini separates data mapping, validation, business rules, and error handling from endpoint calls. This makes severity mappings, ownership rules, deduplication, and product-specific transformations easier to maintain.

Reusable integration assets

Martini can consume documented Rapid7 REST APIs, expose normalized APIs for downstream consumers, and reuse common workflow logic across products and environments without requiring a dedicated Rapid7 connector.

Operational reliability

  • Use environment-specific secrets and regional configuration.
  • Process large datasets with pagination, checkpoints, and controlled concurrency.
  • Retry transient failures while routing permanent errors for review.
  • Monitor workflows and preserve source identifiers for traceability.

Frequently asked questions

How can Rapid7 be integrated with enterprise systems?

Rapid7 is primarily integrated through product-specific REST APIs across the Insight Platform. Selected products or workflows also support webhook-style notifications, while some APIs may provide bulk or asynchronous operations. Enterprise workflows commonly retrieve Assets, Vulnerabilities, Investigations, Reports, and detections, then route normalized data to ITSM, SIEM, incident response, collaboration, or analytics systems.

Can Martini integrate with Rapid7?

Yes. Martini can consume Rapid7 REST APIs, receive supported webhook-style notifications, paginate and transform product data, and orchestrate writes to downstream applications. The exact implementation depends on whether the target product is InsightVM, InsightIDR, InsightConnect, InsightCloudSec, or another Rapid7 product.

Do I need a connector to integrate Rapid7 with Martini?

No. A dedicated Rapid7 connector is not required. Martini can use Rapid7’s documented REST APIs, supported webhook-style notifications, API-key authentication, and any product-specific export or asynchronous endpoints that are confirmed for the selected integration.

Is there any extra Lonti cost to integrate Rapid7 with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate Rapid7. Integration use is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Rapid7, cloud infrastructure, or other third-party systems based on subscription, usage, and deployment model.

Which Rapid7 integration methods should be used?

REST APIs are the recommended primary method for new Rapid7 integrations. Use webhook-style notifications for supported product and event combinations, and use bulk or asynchronous operations where the selected product documents them for large datasets. A general Rapid7 GraphQL or SOAP API was not confirmed.

Can Martini receive Rapid7 alerts or detections in real time?

Martini can receive HTTP notifications when the selected Rapid7 product and event type support webhook-style delivery. Coverage is product-specific and should be documented explicitly. For unsupported objects or events, a scheduled REST API workflow can provide polling and reconciliation.

How does synchronization of Rapid7 Assets and Vulnerabilities work?

A Martini workflow retrieves paginated Assets and Vulnerabilities using product-supported filters where available, or maintains a cursor and checkpoint when they are not. It maps the objects into a target model, upserts using stable Rapid7 identifiers, and periodically reconciles data to detect missed or changed items.

How does Martini handle Rapid7 errors, retries, and duplicates?

Martini can distinguish authentication, authorization, rate-limit, validation, missing-resource, and transient server failures. Workflows can retry transient failures with bounded exponential backoff, route permanent failures for review, and use stable Rapid7 identifiers or composite keys to prevent duplicate downstream records.