Security graph console
The API embeds a static console at / and /ui/. After
docker compose up and a scan, open
http://localhost:8080. The page loads stats, findings, and
a vis-network graph of the snapshot.
What you can do
- Read node and edge counts in the stats strip. Those numbers come from
GET /v1/graph/stats. - Scan the findings list from
GET /v1/findings. Each card shows severity, title, and the affected resource. An attack-path card also prints thepathnode ids. Choosing a card highlights the affected resource when it is in the current snapshot. - The dropdown loads every named query. On first paint it selects
internet-to-datastorewhen that query exists, then draws those paths. Choose Full graph snapshot to callGET /v1/graph/snapshotinstead (500 nodes and 2000 edges). - A named query still uses the snapshot’s edge list to label each hop. If the connecting edge is past that 2000-edge cap, the hop is drawn as type
PATHand anyreasonproperty is missing. The nodes themselves come from the query, not from the snapshot cap. Audit events returned inauditsare listed under that path. - Select an identity node to load
GET /v1/identity/blast-radius. The panel shows the summary and the reachable nodes. See Blast radius. Other node types do not open that panel. - Refresh reloads stats, findings, and the current view after you ingest from the CLI. The page does not poll.
Choosing a finding calls selectNodes on the canvas. That highlight only lands
when the affected resource is in the view you have open. A finding about a node that is not
on the current path, and not in the snapshot when you are on the full graph, stays in the
list and is not drawn.
Run CSPM rules from the browser
The Run CSPM rules button calls POST /v1/rules/run. That route
requires the API secret. Enter it in the API key field and choose
Save API key. The page stores it in localStorage.om_api_key and
sends X-API-Key on /v1 calls. The key is not written into the graph.
Clearing the field and saving removes it. The HTML page loads without a key. Stats, findings,
and the graph need the secret. GET /v1/health does not.
Use the value of OM_API_SECRET from the environment the API process actually
has. Running om rules run on the CLI does the same work without the browser key,
because the CLI uses Postgres directly.
Graph script
The graph canvas loads vis-network from /ui/vis-network.min.js, served with the
rest of the console. The API does not fetch that script from a CDN.
Copyright © 2026 OpenSourceOM. Licensed under Apache-2.0.