The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generating an API call

Prev Next

After you generate client credentials and the token, you can call a server API and keep track of its validity.

To call a server API and keep track of its validity:

  1. Extract the token from your token generation request.

  2. Make the API request to the server endpoint (https://xdr.trellix.com/helix/id/<HEX_ID>/api/v1/environment) with the access token included in the request header. In the cURL example below, replace <HEX_ID> with your instance's Helix ID.

    To obtain your HEX_ID, from the main menu, select your avatar and click API Documentation. In the page that opens, your HEX_ID is the part of the URL shown in bold in the following example: https://xdr.trellix.com/helix/id/hexabc123/api/documentation. Replace <ACCESS_TOKEN> with the token you generated in Generating a token. The following example sets the Authorization header with the access token value using the Bearer authentication scheme.

    curl --location 
    'https://xdr.trellix.com/helix/id/<HEX_ID>/api/v1/environment' \
    --header 'x-trellix-api-token: Bearer <ACCESS_TOKEN>'
  3. Handle the response from the server API and process the data as required. After you receive the response, you can parse the data and perform any required operation or validation.

    Note

    Make sure you handle and errors or exceptions that occur during the API call.

  4. Track the validity of the token life. Compare the current time with the token’s expiration time. The expiration time is typically included in the response from the token generation endpoint. If the token expires, you need to generate a new token. For more information, see Generating a token.

    Note

    You can use a programming language or framework to automate these steps and integrate them into your application’s code.

    Token expiration time and token renewal mechanisms may vary depending on the authorization server and its configuration. Consult the relevant server documentation or guidelines.