Ellipse Gradient for Header

Tines Integration Guide

Connect Tines Stories, webhook triggers, outbound HTTP actions, and REST APIs with enterprise systems through Martini workflows and APIs.

Tines integration options at a glance

Tines provides a REST API for retrieving and managing supported platform resources, including Stories, Story Actions, Story Records, Teams, and Users. Its Stories can receive webhook-style HTTP requests and send outbound HTTP requests to Martini or other endpoints. API-token authentication is the documented baseline for Tines API access, while OAuth may apply to selected third-party integrations configured within Tines. Martini can consume the Tines REST API, expose REST endpoints for Tines HTTP actions, orchestrate enrichment and routing workflows, and apply validation, transformation, idempotency, retry, and monitoring logic. A dedicated Tines bulk API, GraphQL API, SOAP API, or direct database interface was not confirmed.

Integration pointSupported by Tines?Common use casesHow Martini supports it
REST APIsYesRetrieve, create, or update supported Tines resources such as Stories, Story Actions, Story Records, Teams, and Users. Use the API for administration, reporting, inventory, and controlled downstream processing.Martini can consume the Tines REST API from workflows, map responses, paginate through results, expose a normalized façade, and persist synchronization state.
WebhooksYesTines Stories can receive HTTP requests through webhook triggers, allowing external systems such as Martini to start or continue configured automation.Martini can invoke Tines webhook endpoints and can expose REST APIs that accept Tines requests, validate payloads, and route them to workflows.
Outbound HTTP callbacksYesTines Story Actions can send HTTP requests to Martini or other endpoints after a configured trigger or action. Delivery depends on the Story and integration configuration.Martini can receive and authenticate callbacks, apply idempotency checks, transform payloads, and return processing or correlation results.
AuthenticationYesThe Tines REST API documents API-token authentication using an Authorization header with the Bearer scheme. OAuth may apply to selected third-party application integrations within Tines.Martini can store Tines tokens in secure environment configuration and attach them to outbound REST requests without embedding credentials in workflows.
Asynchronous workflowsLimitedTines Stories support asynchronous automation patterns, but a dedicated Tines bulk or batch REST API was not confirmed.Martini can schedule incremental processing, control concurrency, use queues where appropriate, and implement retry and checkpoint logic without assuming a bulk endpoint.
File and attachment APIsNot confirmedFile handling may be available through particular Tines actions or application integrations, but a general-purpose core Tines file API was not confirmed.Martini can process files or attachments only when the configured Tines action or documented endpoint explicitly exposes them.
Database and analytics accessNot confirmedDirect SQL database access to Tines was not confirmed. Reporting and analytics integrations should use the Tines API or documented export capabilities.Martini can write retrieved Tines data to an approved database or reporting target, but should not rely on direct Tines database access.

How Tines exposes data and business events

Tines REST APIs

Tines exposes a REST API for programmatic access to supported platform resources. The reviewed material confirms use cases including retrieving and managing Stories, Story Actions, Story Records, Teams, Users, and other supported resources; exact availability can vary by plan, tenant, and API version.

Martini implementation pattern

Martini implementation pattern: a workflow authenticates with a Tines API token, retrieves resources using the documented request and pagination behavior, validates the response, maps it to a canonical model, and writes or routes the result. Martini can also expose a controlled REST façade over selected Tines operations.

Implementation sequence

Authenticate with a Tines API token
Call the required Tines REST API operation
Process pagination or continuation state
Validate the response and preserve source identifiers
Map Tines data to the target model
Write the result and store synchronization state

Tines Webhook Triggers

Tines Stories can receive HTTP requests through configured webhook triggers. This provides event-driven intake, but it is not a universal event stream for every Tines object or lifecycle change; coverage depends on the Story, trigger, application, and plan.

Martini implementation pattern

Martini implementation pattern: a Martini REST API receives a Tines-originated or external request, authenticates and validates the payload, derives an idempotency key, applies business rules, and routes the event to a target workflow or application.

Implementation sequence

Receive the webhook request
Authenticate the caller and validate required fields
Derive an idempotency key from the event or source object
Map the payload to a canonical event model
Apply routing and business rules
Return a correlation identifier and processing status

Tines Outbound HTTP Actions

Tines Story Actions can send outbound HTTP requests after a configured trigger or action. This enables Tines-to-Martini callbacks for security alerts, workflow status, enrichment requests, and operational results.

Martini implementation pattern

Martini implementation pattern: Martini exposes a purpose-built endpoint, validates the Tines request, performs enrichment or orchestration, and returns a stable response structure that the Tines Story can use for subsequent decisions.

Implementation sequence

Expose a Martini REST endpoint for the callback
Receive the Tines HTTP request
Validate authentication, schema, and authorization
Enrich or transform the received data
Invoke downstream systems or Tines operations
Return the result and record the correlation outcome

Common Tines integration patterns

Pattern 1: Send Tines security alerts to an incident system

When to use this pattern

Use this pattern when a Tines Story receives a security alert and an enterprise incident or case system must be created or updated. The flow supports severity-based routing, enrichment, correlation, and duplicate prevention.

Integration direction
Tines
Martini
ServiceNow
Example Mapping
Tines FieldCanonical FieldTarget Field
Story Record.idsourceEventIdu_external_reference
severityprioritypriority
descriptionsummaryshort_description
sourceoriginu_detection_source
Martini implementation pattern

Tines sends the normalized alert to a Martini API. Martini validates the payload, enriches it with asset or ownership data, applies severity and routing rules, and performs an idempotent create or update in ServiceNow. Transient failures are retried with backoff; non-retryable failures are routed to an exception workflow with the original payload and correlation data.

Martini capabilities used
  • APIs
  • workflows
  • data mapping
  • business rules
  • error handling
  • secure environment configuration

Pattern 2: Provide an enrichment API for Tines

When to use this pattern

Use this pattern when a Tines Story needs a consistent response for an indicator, user, domain, IP address, or other operational input before deciding whether to notify, isolate, escalate, or create a ticket.

Integration direction
Tines
Martini
Security and internal APIs
Example Mapping
Tines FieldCanonical FieldTarget Field
indicator.valuelookupValuequery
indicator.typelookupTypeindicatorType
Story Record.idcorrelationIdrequestId
requestedAtrequestTimestamptimestamp
Martini implementation pattern

A Tines HTTP Action calls a Martini endpoint. Martini validates the request, calls multiple enrichment or internal APIs, normalizes their responses, applies confidence and policy rules, and returns a consistent result. Martini isolates failures by source, applies controlled retries to transient calls, and includes correlation data for Tines logging.

Martini capabilities used
  • API exposure
  • workflow orchestration
  • API consumption
  • data transformation
  • conditional routing
  • error handling

Pattern 3: Synchronize Tines Story inventory

When to use this pattern

Use this pattern for governance, reporting, or configuration inventory when an organization needs scheduled visibility into Stories, Story Actions, Teams, or Users. It is appropriate when no dedicated bulk API is available and processing must be incremental.

Integration direction
Tines
Martini
Database
Example Mapping
Tines FieldCanonical FieldTarget Field
Story.idworkflowIdexternal_workflow_id
Story.nameworkflowNamename
Team.idteamIdteam_external_id
updatedAtlastChangedAtsource_updated_at
Martini implementation pattern

A scheduled Martini workflow calls the Tines REST API, follows documented pagination, maps each object into an inventory model, and upserts it into a database. The workflow stores page or object state, compares previously observed values, limits concurrency, and retries temporary throttling without restarting the entire synchronization.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • pagination control
  • data mapping
  • SQL database access
  • retry handling

Pattern 4: Orchestrate an IT or security request through Tines

When to use this pattern

Use this pattern when an enterprise application submits a normalized request to Martini and Tines should execute the operational automation across connected tools, with status returned to the originating system.

Integration direction
Enterprise application
Martini
Tines
Example Mapping
Tines FieldCanonical FieldTarget Field
request.idcorrelationIdStory input.correlationId
request.typecommandTypeStory input.command
request.subjectsubjectIdentifierStory input.subject
request.requesterrequesterIdStory input.requester
Martini implementation pattern

Martini receives and authorizes the request, applies business rules, and invokes a configured Tines webhook. Tines executes the Story and can post status updates back to Martini through an outbound HTTP Action. Martini maintains the correlation state, prevents duplicate commands, and updates the originating system when completion or failure is reported.

Martini capabilities used
  • REST APIs
  • webhook consumption
  • workflow orchestration
  • authorization
  • business rules
  • idempotency

Applications commonly integrated with Tines

Tines commonly participates in security, identity, IT operations, and collaboration workflows. Martini can sit between Tines and these named applications to provide consistent APIs, data mapping, authorization, enrichment, retry handling, and operational monitoring. Specific Tines actions, scopes, and event coverage should be verified for each tenant and application.

Application Scenario Direction Martini Pattern
Splunk Send security findings or notable events into Tines for enrichment and response, or return remediation status to Splunk. Splunk → Tines → Martini Martini receives or retrieves normalized Tines and Splunk payloads, maps alert fields to a canonical security-event model, applies severity and deduplication rules, and routes results to the required target.
Microsoft Sentinel Automate response to incidents and alerts, enrich entities, and update incident status across security operations. Microsoft Sentinel → Tines → Martini A Martini API receives Tines callbacks or a scheduled workflow consumes supported APIs, validates incident data, enriches entities, and writes status updates with controlled retries.
CrowdStrike Falcon Trigger workflows from detections, hosts, or indicators and return containment or remediation outcomes. CrowdStrike Falcon → Tines → Martini Martini normalizes detection and host data from the participating APIs, applies response policies, records correlation identifiers, and coordinates downstream actions through Tines or other systems.
ServiceNow Create or update incidents, requests, and change-related records from Tines security and operations workflows. Tines → Martini → ServiceNow Martini receives a Tines Story callback, validates and maps the payload to ServiceNow fields, performs an idempotent create or update, and returns the resulting correlation identifier.
Jira Create and update issues for security findings, operational tasks, and remediation work. Tines → Martini → Jira A Martini workflow transforms Tines Story Records into Jira issue fields, applies project and priority rules, prevents duplicate issues, and routes failures to an exception path.
Slack Send operational notifications, approval requests, and response updates to channels or users. Tines → Martini → Slack Martini maps normalized Tines events to notification templates, applies recipient and severity rules, calls the supported Slack interface, and records delivery outcomes.
Okta Automate identity response actions such as user or session handling in response to security events. Okta → Tines → Martini Martini validates identity-event payloads, enriches them with organizational policy data, invokes the required API or Tines Story, and tracks action status with idempotency controls.

How to build a Tines integration in Martini

Objective

Establish secure access to the Tines REST API and any webhook endpoints used by the integration.

Instructions in Martini

  • Store the Tines API token in Martini secure environment configuration.
  • Attach the token using the required Bearer authorization header.
  • Treat webhook authentication and shared-secret requirements as endpoint-specific.
  • Limit credentials to the required Tines team and operations.

Objective

Select an event-driven or scheduled entry point based on the required integration behavior.

Instructions in Martini

  • Expose a Martini REST API when Tines must call Martini.
  • Invoke a configured Tines webhook when Martini must start a Story.
  • Use a scheduler for inventory or reporting synchronization.
  • Do not assume every Tines object or event produces a webhook.

Objective

Obtain Tines data through the appropriate REST operation, webhook request, or outbound HTTP callback.

Instructions in Martini

  • Validate the request method, authentication, and required fields.
  • Use documented pagination for collection retrieval.
  • Preserve source identifiers and the original payload when auditability is needed.
  • Record synchronization state so interrupted runs can resume.

Objective

Coordinate Tines, Martini, and downstream calls as a maintainable integration workflow.

Instructions in Martini

  • Separate vendor-specific intake from canonical business processing.
  • Call enrichment and target APIs through controlled workflow steps.
  • Apply concurrency limits for large result sets.
  • Use correlation identifiers across all participating systems.

Objective

Transform Tines Stories, Story Records, and related resources into target-specific models.

Instructions in Martini

  • Map source fields to a canonical model before target mapping.
  • Validate required fields and treat trigger-specific fields as optional unless confirmed.
  • Normalize timestamps, identifiers, severity, and status values where needed.
  • Keep Tines-specific mappings isolated from downstream business logic.

Objective

Use policy, routing, authorization, and deduplication rules to determine the correct outcome.

Instructions in Martini

  • Route based on severity, source, team, ownership, or request type.
  • Derive a stable idempotency key from the event or source object.
  • Use upsert or conditional updates where the target supports them.
  • Reject unauthorized or incomplete requests before invoking downstream actions.

Common Tines data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
StoriesRepresent Tines automation workflows containing triggers, events, actions, and control logic.Governance repositories, configuration databases, reporting platforms, and operational dashboardsMartini retrieves or receives supported Story data, maps it to an inventory model, and synchronizes changes using pagination and checkpoints.
Story ActionsRepresent individual HTTP requests, transformations, notifications, or application calls inside a Story.Governance databases, audit repositories, reporting platforms, and configuration management systemsMartini extracts action metadata, preserves source identifiers, and applies schema-aware mappings rather than assuming every Story has the same action fields.
Story RecordsRepresent data items processed by a Story and passed between actions.Case systems, security platforms, databases, reporting platforms, and audit storesMartini validates incoming records, derives idempotency keys, transforms payloads, and routes them to downstream workflows.
TeamsDefine organizational boundaries for Stories, users, resources, and permissions.Identity governance systems, configuration repositories, and reporting platformsMartini can synchronize Team metadata through the REST API and apply tenant, ownership, and authorization mapping rules.
UsersRepresent Tines users whose ownership and permissions can affect API access and Story administration.Identity governance, access review, HR-adjacent directories, and audit repositoriesMartini retrieves supported user data, maps identities to a canonical model, and handles permission-sensitive fields conservatively.
ResourcesProvide reusable values or configuration objects used by Stories, including shared integration assets or credentials.Configuration repositories, governance systems, and audit storesMartini should synchronize only permitted metadata, keep secrets out of payloads and logs, and preserve references to protected resources.

Authentication and security considerations

API-token authentication

Tines documents API-token authentication for its REST API, generally using a Bearer token in the Authorization header. Martini can store the token in secure environment configuration and add it to outbound requests.

Secret handling

Keep tokens and webhook credentials out of workflow definitions, source control, URLs, and operational logs. Limit permissions to the required Tines team and operations, and rotate credentials according to organizational policy.

Endpoint protection

Protect Martini APIs that receive Tines callbacks with appropriate authentication, authorization, validation, and rate controls. OAuth may apply to selected third-party applications configured in Tines, but it should not be assumed for Tines REST API access.

Operational considerations for Tines integrations

Rate limits and pagination

Confirm tenant and plan limits, treat HTTP 429 responses as potentially retryable, and use controlled concurrency. Do not assume a collection response contains all Stories, Actions, Records, Teams, or Users.

Idempotency and duplicates

Webhook retries and workflow retries can repeat delivery. Derive stable idempotency keys, check prior processing, and use upsert or conditional operations to avoid duplicate incidents, issues, or notifications.

Schema and event coverage

Story payloads can differ by trigger and application integration. Validate required fields, isolate vendor-specific mappings, preserve source payloads where appropriate, and monitor changes to response fields and pagination behavior.

Testing and operations

Test authentication failures, authorization failures, validation errors, throttling, transient outages, and duplicate delivery. Capture response bodies and correlation identifiers, retry transient failures only, and route permanent failures to an operational exception path.

Why use Martini instead of scripts or point-to-point integrations?

Reusable orchestration

Martini separates Tines-specific API and webhook handling from canonical business logic, allowing the same validation, enrichment, routing, and target-writing workflows to be reused across security and operations use cases.

Controlled integration behavior

Instead of embedding point-to-point logic in individual Stories or scripts, Martini can expose governed APIs, apply authorization and business rules, manage idempotency, and coordinate multiple downstream systems.

Maintainability and operations

Workflows provide explicit mapping, retry, error, logging, and synchronization behavior. Secure environment configuration keeps credentials separate from implementation, while monitoring and structured exception paths support production troubleshooting.

Frequently asked questions

How can Tines be integrated with enterprise systems?

Tines can integrate through its REST API, configured webhook triggers, and outbound HTTP requests from Story Actions. These mechanisms support platform administration, security and operations automation, callbacks, enrichment, and synchronization with enterprise applications.

Can Martini integrate with Tines?

Yes. Martini can consume the Tines REST API using API-token authentication, receive requests from Tines webhook triggers or HTTP Actions, expose REST endpoints for Tines to call, and orchestrate mapping, enrichment, routing, and error handling.

Do I need a connector to integrate Tines with Martini?

No. A dedicated Tines connector is not required. Martini can integrate with Tines using its confirmed native REST API, webhook, outbound HTTP, and API-token mechanisms.

Is there any extra Lonti cost to integrate Tines with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate Tines. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Tines, cloud infrastructure, or other third-party systems based on subscription, usage, and deployment model.

Which Tines integration methods should architects use?

Use the Tines REST API for supported resource retrieval and management, and use webhook triggers or outbound HTTP Actions for event-driven workflows. A dedicated Tines GraphQL API, SOAP API, bulk API, and direct database interface were not confirmed.

Are Tines events and webhooks available for every object?

No. Tines supports webhook-style triggers and outbound HTTP requests, but event coverage depends on the configured Story, trigger, application integration, action, and plan. It should not be treated as a universal event stream for every Tines object or change.

How should Tines data synchronization work?

Martini can run scheduled workflows that use the Tines REST API, follow documented pagination, process resources incrementally, and store checkpoints or synchronization state. Rate limits, changing schemas, and tenant-specific object availability should be considered.

How does Martini handle Tines mapping, retries, and API façades?

Martini can validate and transform Tines payloads, apply business rules, derive idempotency keys, retry transient failures, and route non-retryable failures for review. It can also expose a normalized REST API that hides Tines-specific structures and orchestrates calls to Tines and other systems.