Find the insights and best practices about our product.
Arena Models

This endpoint returns every AI model Cranium has discovered and tested in your tenant, so you can use it as a catalog when correlating model identifiers across other endpoints.

List Arena Models

Returns a paginated list of AI models discovered and tested by Cranium Arena across your tenant. Use it to resolve model names and metadata for the model identifier that appear on the Arena Model Vulnerabilities feed.

Request

GET /api/public/arena/models

Authentication

Bearer token. See Authentication & Generating Credentials.

Required Permission

Api_ArenaModels_Read

Query parameters

Response Fields

Sample Response

{
"data": [
{
"modelId": "d3e4f5a6-7b8c-4d9e-0f1a-2b3c4d5e6f7a",
"modelName": "llama-3-8b-instruct",
"modelFamilyId": "e4f5a6b7-8c9d-4e0f-1a2b-3c4d5e6f7a8b",
"modelFamilyName": "Llama 3",
"modelSource": "HuggingFace",
"modelType": "LLM",
"referenceUrl": "https://huggingface.co/meta-llama/Meta-Llama-3-8B-Instruct",
"modelStatus": "Tested",
"severity": "High",
"averageAttackSuccessRatio": 0.42,
"attackCategoriesVulnerableCount": 3,
"weaknessCount": 5,
"knownRisksCount": 2,
"automatedTestCount": 10,
"manualTestCount": 1,
"aiSystemCount": 2,
"penTestCompletedAt": "2026-03-15T00:00:00Z",
"discoveredAt": "2026-01-05T00:00:00Z",
"updatedAt": "2026-04-10T00:00:00Z"
}
],
"pagination": {
"limit": 100,
"nextCursor": "eyJ1cGRhdGVkQXQiOiIyMDI2LTA0LTEwVDAwOjAwOjAwWiIsImlkIjoiZDNlNGY1YTYifQ==",
"hasMore": false
},
"error": null,
"meta": {
"requestId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"timestamp": "2026-08-24T10:10:00Z"
}
}


modelId is the join key back to the Arena Model Vulnerabilities feed, where it appears alongside each attack category finding. severity and averageAttackSuccessRatio summarize risk across all of a model's pen test results; for the underlying per-attack-category detail, see the Arena Model Vulnerabilities endpoint. hasMore: false with a non-null nextCursor is the normal end-of-feed state; store the cursor and replay it on your next poll.

Error Responses

  • 400 VALIDATION_FAILED: the cursor is invalid, or cursor and updatedAfter were supplied together.
  • 401 UNAUTHORIZED: the request is missing a token, or the token lacks Api_ArenaModels_Read.
  • 500 INTERNAL_ERROR: an unexpected server error.
Did this answer your question?