Create an access key
A verified organisation administrator opens Feed API (/feed) and creates a key. The secret is shown on creation: store it securely in the integration. Revoke a lost or compromised key and create another. The key does not grant private case access.
Choose delivery
Use object lookup, a list snapshot or changes as described in Feed API. TAXII 2.1 provides read access to published STIX objects. Discovery on the application domain is /taxii2/. Use HTTP Basic with username feed and your API key as password; Accept is application/taxii+json;version=2.1. Read discovery and collections first, then objects and subsequent pages.
Process changes
Preserve continuation cursors and honour entry validity. Revocation, exclusion or expiry must update local state. Presence in an older export does not mean a current block. Private files, personal case material and internal graphs are excluded from the public feed.