# How to Configure TAXII Feed Ingestion in OpenCTI: A Complete Guide

> Learn to configure TAXII feed ingestion in OpenCTI with our complete guide. Set up a TAXII feed easily using server URL, collection UUID, and Bearer token authentication.

- Repository: [OpenCTI Platform/opencti](https://github.com/opencti-platform/opencti)
- Tags: how-to-guide
- Published: 2026-02-19

---

**To configure TAXII feed ingestion in OpenCTI, create a dedicated source user, navigate to Data ▶ Ingestion, add a TAXII feed with the server URL and collection UUID, and set authentication to Bearer token.**

OpenCTI supports automated ingestion of threat intelligence via TAXII (Trusted Automated Exchange of Intelligence Information) feeds, allowing the platform to pull collections from external servers or other OpenCTI instances. This guide explains how to configure TAXII feed ingestion using the web interface and programmatic APIs, referencing the actual implementation in the [OpenCTI-Platform/opencti](https://github.com/OpenCTI-Platform/opencti) repository.

## Prerequisites for TAXII Feed Configuration

Before configuring TAXII feed ingestion, you must prepare the user context and optional organizational attribution to ensure proper data provenance.

### Create a Dedicated Source User

Create a user named `[F] Source Name` and add it to the **Connectors** group. This user becomes the *User responsible for data creation* for the feed, ensuring all imported objects have clear attribution in the knowledge graph.

Source: [docs/docs/usage/import/taxii-feed.md](https://github.com/OpenCTI-Platform/opencti/blob/master/docs/docs/usage/import/taxii-feed.md#L12-L14)

### (Optional) Create a Dedicated Organization

Create an organization matching the source name and set it as the *Default author* for the ingestion. This attribution helps track the origin of intelligence within your threat knowledge base.

Source: [docs/docs/usage/import/taxii-feed.md](https://github.com/OpenCTI-Platform/opencti/blob/master/docs/docs/usage/import/taxii-feed.md#L13-L15)

## Configuring TAXII Feed Ingestion via the UI

Once prerequisites are met, configure the feed through the OpenCTI web interface by mapping connection parameters to the internal schema.

### Open the TAXII Ingestion Wizard

Navigate to **Data ▶ Ingestion**, click **Add TAXII feed**, and complete the form. The form fields map directly to attributes defined in [`ingestion-taxii.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/ingestion-taxii.ts).

### Fill the Core Connection Fields

Enter the following required parameters:

1. **TAXII server URL** – The root API URL (e.g., `https://example.com/taxii2/root`).
2. **TAXII collection** – The collection UUID (e.g., `426e3acb-db50-4118-be7e-648fab67c16c`).
3. **Authentication type** – Select *Bearer token* for private collections.
4. **Authentication value** – Provide the token of a user with access to the collection.

Source: [docs/docs/usage/import/taxii-feed.md](https://github.com/OpenCTI-Platform/opencti/blob/master/docs/docs/usage/import/taxii-feed.md#L19-L24)

### Configure Additional Options

Set the following optional fields:

- **User responsible for data creation** – Select the dedicated source user created earlier.
- **Import from date** – Specify the earliest `added after` date; leave empty to import all available objects.

Source: [docs/docs/usage/import/taxii-feed.md](https://github.com/OpenCTI-Platform/opencti/blob/master/docs/docs/usage/import/taxii-feed.md#L29-L33)

### Save and Activate

Clicking **Save** creates an `IngestionTaxii` entity, registers a TAXII connector via `registerConnectorForIngestion`, and starts polling according to the platform scheduler.

Source: [ingestion-taxii-domain.ts](https://github.com/OpenCTI-Platform/opencti/blob/master/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-domain.ts#L51-L57)

## Understanding the IngestionTaxii Schema

The `IngestionTaxii` object schema is defined in [`opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii.ts). Key attributes include:

```typescript
// Attribute definitions (excerpt)
{ name: 'uri', label: 'URI', type: 'string', format: 'short', mandatoryType: 'customizable', editDefault: true, upsert: true, isFilterable: true },
{ name: 'collection', label: 'Collection', type: 'string', format: 'short', mandatoryType: 'internal', editDefault: false, upsert: true, isFilterable: true },
{ name: 'authentication_type', label: 'Authentication type', type: 'string', format: 'short', mandatoryType: 'no', editDefault: false, upsert: true, isFilterable: true },
{ name: 'added_after_start', label: 'Added after', type: 'date', mandatoryType: 'no', editDefault: true, upsert: true, isFilterable: true },

```

Source: [ingestion-taxii.ts](https://github.com/OpenCTI-Platform/opencti/blob/master/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii.ts#L26-L50)

## Managing TAXII Feeds Programmatically

For automation and CI/CD pipelines, use the GraphQL API to manage feeds.

### Adding a Feed via GraphQL

Use the `ingestionTaxiiAdd` mutation:

```graphql
mutation AddTaxiiIngestion {
  ingestionTaxiiAdd(
    input: {
      name: "ISAC TAXII Feed"
      uri: "https://isac.example.com/taxii2/root"
      collection: "426e3acb-db50-4118-be7e-648fab67c16c"
      authentication_type: "Bearer token"
      authentication_value: "eyJhbGciOiJIUzI1NiIsIn..."
      added_after_start: "2024-01-01T00:00:00Z"
      user_id: "c0d4f3b2-9a6e-4a1e-8b6f-123456789abc"
    }
  ) {
    id
    name
    ingestion_running
  }
}

```

*This mutation triggers `addIngestion` in [`ingestion-taxii-domain.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/ingestion-taxii-domain.ts).*

### Exporting Feed Configuration

Export configurations for backup or migration:

```typescript
import { taxiiFeedExport } from './ingestion-taxii-domain';

// Assuming `taxiiIngestion` is a fetched StoreEntityIngestionTaxii
const jsonExport = await taxiiFeedExport(taxiiIngestion);
console.log(jsonExport);
// Result (pretty-printed):
/*
{
  "openCTI_version": "6.10.0",
  "type": "taxiiFeeds",
  "configuration": {
    "name": "ISAC TAXII Feed",
    "description": "Official ISAC indicator feed",
    "uri": "https://isac.example.com/taxii2/root",
    "version": "2.0",
    "collection": "426e3acb-db50-4118-be7e-648fab67c16c",
    "authentication_type": "Bearer token",
    "added_after_start": "2024-01-01T00:00:00Z"
  }
}
*/

```

Source: [`taxiiFeedExport` implementation](https://github.com/OpenCTI-Platform/opencti/blob/master/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-domain.ts#L5-L27)

### Importing Feed Configuration

Import previously exported feeds:

```graphql
mutation ImportTaxiiFeed($file: Upload!) {
  taxiiFeedAddInputFromImport(file: $file) {
    name
    uri
    collection
    authentication_type
  }
}

```

*The resolver `taxiiFeedAddInputFromImport` reads the JSON file, validates the platform version (minimum `6.9.4`), and returns the `configuration` object that can be fed into `ingestionTaxiiAdd`.*

Source: [`taxiiFeedAddInputFromImport` resolver](https://github.com/OpenCTI-Platform/opencti/blob/master/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-resolver.ts#L19-L20) and domain logic (lines 91-103)

### Resetting Ingestion State

Clear the cursor to force a fresh pull:

```graphql
mutation ResetTaxiiState($id: ID!) {
  ingestionTaxiiResetState(id: $id) {
    id
    name
    current_state_cursor
    added_after_start
  }
}

```

*Calls `ingestionTaxiiResetState`, which clears the cursor via `patchTaxiiIngestion` in [`ingestion-taxii-domain.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/ingestion-taxii-domain.ts).*

Source: [`ingestionTaxiiResetState`](https://github.com/OpenCTI-Platform/opencti/blob/master/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-domain.ts#L69-L82)

## Key Source Files and Implementation Details

| File | Role | Link |
|------|------|------|
| [`docs/docs/usage/import/taxii-feed.md`](https://github.com/OpenCTI-Platform/opencti/blob/main/docs/docs/usage/import/taxii-feed.md) | End-user documentation for configuring TAXII feeds | [View](https://github.com/OpenCTI-Platform/opencti/blob/master/docs/docs/usage/import/taxii-feed.md) |
| [`ingestion-taxii.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/ingestion-taxii.ts) | Schema definition for the `IngestionTaxii` internal object (attributes, identifiers) | [View](https://github.com/OpenCTI-Platform/opencti/blob/master/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii.ts) |
| [`ingestion-taxii-domain.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/ingestion-taxii-domain.ts) | Business logic: create, edit, delete, reset, export, import, and connector registration | [View](https://github.com/OpenCTI-Platform/opencti/blob/master/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-domain.ts) |
| [`ingestion-taxii-resolver.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/ingestion-taxii-resolver.ts) | GraphQL resolvers that expose the domain functions to the API | [View](https://github.com/OpenCTI-Platform/opencti/blob/master/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-resolver.ts) |
| `ingestion-taxii-collection.graphql` | GraphQL schema for the TAXII collection UI (queries, mutations) | [View](https://github.com/OpenCTI-Platform/opencti/blob/master/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-collection.graphql) |

## Summary

- **Create dedicated users and organizations** before configuring feeds to ensure proper data attribution and access control.
- **Configure TAXII feed ingestion** via **Data ▶ Ingestion** in the UI by providing the server URL, collection UUID, and Bearer token authentication.
- **Understand the schema** defined in [`ingestion-taxii.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/ingestion-taxii.ts), which controls mandatory fields like `uri` and `collection` and optional fields like `added_after_start`.
- **Manage feeds programmatically** using GraphQL mutations for adding (`ingestionTaxiiAdd`), exporting (`taxiiFeedExport`), importing (`taxiiFeedAddInputFromImport`), and resetting state (`ingestionTaxiiResetState`).
- **Reset state** when you need to force a fresh pull by clearing the `current_state_cursor` via the reset mutation.

## Frequently Asked Questions

### What authentication types does OpenCTI support for TAXII feeds?

OpenCTI supports **Bearer token** authentication for private TAXII collections, as defined in the `authentication_type` field of the `IngestionTaxii` schema. You provide the token in the `authentication_value` field when configuring the feed via the UI or GraphQL API.

### How do I force a TAXII feed to re-import all data from the beginning?

Use the **Reset** button in the UI or call the `ingestionTaxiiResetState` GraphQL mutation. This clears the `current_state_cursor` via `patchTaxiiIngestion` in [`ingestion-taxii-domain.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/ingestion-taxii-domain.ts), forcing the connector to poll the collection from the start date or from the beginning if no date is specified.

### Can I migrate TAXII feed configurations between OpenCTI instances?

Yes. Use the `taxiiFeedExport` function to generate a JSON file containing the feed configuration and platform version. Then use the `taxiiFeedAddInputFromImport` mutation to import it into another instance. The import logic validates platform version compatibility (minimum version `6.9.4`) before processing.

### Where is the TAXII ingestion logic implemented in the OpenCTI codebase?

The core logic resides in [`opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-domain.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-domain.ts), which handles creation, updates, resets, exports, and imports. The schema definition is in [`ingestion-taxii.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/ingestion-taxii.ts), and GraphQL resolvers are in [`ingestion-taxii-resolver.ts`](https://github.com/OpenCTI-Platform/opencti/blob/main/ingestion-taxii-resolver.ts).