.png)
Rapid7 Integration Guide
Connect Rapid7 security data and selected event notifications with enterprise systems through REST APIs, webhooks, and Martini workflows.
Rapid7 integration options at a glance
Rapid7 primarily integrates through product-specific REST APIs across InsightVM, InsightIDR, InsightConnect, InsightCloudSec, and related Insight Platform products. Martini can consume these APIs to retrieve Assets, Vulnerabilities, Investigations, Reports, and other documented resources, then transform and route the results to enterprise applications. Selected Rapid7 products and workflows support webhook-style notifications, which Martini can receive through REST APIs or workflow triggers. Some product APIs may also provide bulk, export, or asynchronous operations for large datasets. Rapid7 API-key authentication, regional endpoints, product permissions, pagination, rate limits, and incremental synchronization should be configured per product and environment.
Common Rapid7 integration patterns
Common Rapid7 data objects used in integrations
Authentication and security considerations
API keys and product permissions
Rapid7 Insight Platform APIs commonly use an API key in the X-Api-Key header. Product-specific credentials, roles, organization access, and regional endpoints may also apply.
Secure configuration
Store Rapid7 API keys, regional base URLs, and target credentials in Martini environment configuration and secrets. Do not place credentials in workflow payloads, source-controlled mappings, or diagnostic messages.
Least privilege and validation
- Use separate credentials for development, testing, and production where practical.
- Grant only the product and operations required by the workflow.
- Validate inbound webhook-style requests and implement replay and idempotency controls.
- Do not assume OAuth 2.0 is the general Rapid7 authentication method; verify product-specific requirements.
Operational considerations for Rapid7 integrations
Product-specific schemas
Rapid7 APIs are organized by product, so fields, identifiers, lifecycle values, permissions, and write operations can differ between InsightVM, InsightIDR, InsightConnect, and InsightCloudSec.
Rate limits and pagination
Use bounded concurrency, pagination, and exponential backoff for transient failures. Large inventories should be processed incrementally or through documented bulk and asynchronous operations.
Checkpoints and idempotency
Persist cursors or synchronization checkpoints where appropriate. Use stable Rapid7 identifiers, or composite keys for vulnerability and asset relationships, so retries do not create duplicate incidents or remediation tasks.
Events and schema changes
Webhook-style coverage is product-specific. Document supported event types, retain scheduled polling as a fallback, validate response fields, and monitor changes to pagination fields, enum values, severity, and lifecycle statuses.
Testing and monitoring
Test each product endpoint, region, permission set, pagination path, and failure class before production deployment. Monitor workflow execution, rate-limit responses, rejected mappings, retries, and checkpoint progression.
Why use Martini instead of scripts or point-to-point integrations?
Orchestrate more than one API call
Rapid7 integrations often require product-specific retrieval, pagination, enrichment, target writes, and reconciliation. Martini coordinates these steps in workflows instead of embedding them in a single script.
Maintainable mappings and rules
Martini separates data mapping, validation, business rules, and error handling from endpoint calls. This makes severity mappings, ownership rules, deduplication, and product-specific transformations easier to maintain.
Reusable integration assets
Martini can consume documented Rapid7 REST APIs, expose normalized APIs for downstream consumers, and reuse common workflow logic across products and environments without requiring a dedicated Rapid7 connector.
Operational reliability
- Use environment-specific secrets and regional configuration.
- Process large datasets with pagination, checkpoints, and controlled concurrency.
- Retry transient failures while routing permanent errors for review.
- Monitor workflows and preserve source identifiers for traceability.