This endpoint returns every AI model Cranium has discovered and tested in your tenant, so you can use it as a catalog when correlating model identifiers across other endpoints.
List Arena Models
Returns a paginated list of AI models discovered and tested by Cranium Arena across your tenant. Use it to resolve model names and metadata for the model identifier that appear on the Arena Model Vulnerabilities feed.
Request
GET /api/public/arena/models
Authentication
Bearer token. See Authentication & Generating Credentials.
Required Permission
Api_ArenaModels_Read
Query parameters

Response Fields

Sample Response
{
"data": [
{
"modelId": "d3e4f5a6-7b8c-4d9e-0f1a-2b3c4d5e6f7a",
"modelName": "llama-3-8b-instruct",
"modelFamilyId": "e4f5a6b7-8c9d-4e0f-1a2b-3c4d5e6f7a8b",
"modelFamilyName": "Llama 3",
"modelSource": "HuggingFace",
"modelType": "LLM",
"referenceUrl": "https://huggingface.co/meta-llama/Meta-Llama-3-8B-Instruct",
"modelStatus": "Tested",
"severity": "High",
"averageAttackSuccessRatio": 0.42,
"attackCategoriesVulnerableCount": 3,
"weaknessCount": 5,
"knownRisksCount": 2,
"automatedTestCount": 10,
"manualTestCount": 1,
"aiSystemCount": 2,
"penTestCompletedAt": "2026-03-15T00:00:00Z",
"discoveredAt": "2026-01-05T00:00:00Z",
"updatedAt": "2026-04-10T00:00:00Z"
}
],
"pagination": {
"limit": 100,
"nextCursor": "eyJ1cGRhdGVkQXQiOiIyMDI2LTA0LTEwVDAwOjAwOjAwWiIsImlkIjoiZDNlNGY1YTYifQ==",
"hasMore": false
},
"error": null,
"meta": {
"requestId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"timestamp": "2026-08-24T10:10:00Z"
}
}
modelId is the join key back to the Arena Model Vulnerabilities feed, where it appears alongside each attack category finding. severity and averageAttackSuccessRatio summarize risk across all of a model's pen test results; for the underlying per-attack-category detail, see the Arena Model Vulnerabilities endpoint. hasMore: false with a non-null nextCursor is the normal end-of-feed state; store the cursor and replay it on your next poll.
Error Responses
400 VALIDATION_FAILED: the cursor is invalid, orcursorandupdatedAfterwere supplied together.401 UNAUTHORIZED: the request is missing a token, or the token lacksApi_ArenaModels_Read.500 INTERNAL_ERROR: an unexpected server error.





