Authentication

This section of the user guide describes how you can programmatically interact with the MetaDefender Software Supply Chain REST API. Below are some common tasks that can be done using the available REST APIs:

  • Authenticate to obtain a JSON Web Token(JWT)
  • Start or stop a process(scan)
  • Add / remove service units

About this REST API

The exposed endpoint is located by default at http(s)://mdssc-server/api/ (for example, the authentication endpoint is available at http(s)://mdssc-server/api/user/authenticate). All requests are handled by the NGINX web server before being proxied to the backend API Gateway service.

All endpoints perform authentication and authorization checks. For these checks to succeed, a valid token should be presented in the Authorization header in the form of Bearer.

Please note that all issued tokens have a timestamp and signature associated in order to prevent long-term usage without re - authentication. The lifespan of the token is currently set to 60 minutes, meaning you will have to request a new token before it expires in order to avoid error responses.

Server
http://localhost:8001
Server Variables
http Bearer
apiKey ApiKey
Fields
KeyIn
ApiKeyHeader

monitored-files

Auth
Request Body
objectobject
filefile
workflowIdstring
intervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
groupIdstring
groupNamestring
POST /api/v1/monitored-files
Responses
200

OK

objectobject
idstring
originalFileNamestring
sha256string
groupIdstring
groupNamestring
enabledboolean
rescanIntervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
newCveCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastRunAtdate-time
nextRunAtdate-time
createdAtdate-time
Response

monitored-files

Auth
GET /api/v1/monitored-files
Responses
200

OK

arrayarray[object]
idstring
originalFileNamestring
sha256string
groupIdstring
groupNamestring
enabledboolean
rescanIntervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
newCveCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastRunAtdate-time
nextRunAtdate-time
createdAtdate-time
Response

history

Auth
Path Params
idstring
GET /api/v1/monitored-files/{id}/history
Responses
200

OK

arrayarray[object]
idstring
scanIdstring
runAtdate-time
newCveIdsstring
Response

scan-now

Auth
Path Params
idstring
POST /api/v1/monitored-files/{id}/scan-now
Responses
200

OK

objectobject
idstring
originalFileNamestring
sha256string
groupIdstring
groupNamestring
enabledboolean
rescanIntervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
newCveCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastRunAtdate-time
nextRunAtdate-time
createdAtdate-time
Response

enabled

Auth
Path Params
idstring
Request Body
objectobject
enabledboolean
POST /api/v1/monitored-files/{id}/enabled
Responses
200

OK

objectobject
idstring
originalFileNamestring
sha256string
groupIdstring
groupNamestring
enabledboolean
rescanIntervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
newCveCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastRunAtdate-time
nextRunAtdate-time
createdAtdate-time
Response

interval

Auth
Path Params
idstring
Request Body
objectobject
intervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
POST /api/v1/monitored-files/{id}/interval
Responses
200

OK

objectobject
idstring
originalFileNamestring
sha256string
groupIdstring
groupNamestring
enabledboolean
rescanIntervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
newCveCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastRunAtdate-time
nextRunAtdate-time
createdAtdate-time
Response

{id}

Auth
Path Params
idstring
DELETE /api/v1/monitored-files/{id}
Responses
204

No Content

No response body
Response

Get Roles

Auth
Query String
includePermissionsboolean

Default: true

GET /api/v1/abac/roles
Responses
200

OK

objectobject
roles3 fieldsarray[object]
responseKeystring
responseMessagestring
Response

Create Role

Auth
Request Body
objectobject
namestring

maxLength: 100

minLength: 3

permissionIdsarray[string]
templateRoleIduuid
POST /api/v1/abac/roles
Responses
200

OK

objectobject
role
responseKeystring
responseMessagestring
Response

Get Role by ID

Auth
Path Params
roleIdstring
GET /api/v1/abac/roles/{roleId}
Responses
200

OK

objectobject
role
responseKeystring
responseMessagestring
Response

Update Role

Auth
Path Params
roleIdstring
Request Body
objectobject
namestring

maxLength: 100

minLength: 3

permissionIdsarray[string]
PUT /api/v1/abac/roles/{roleId}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Delete Role

Auth
Path Params
roleIdstring
DELETE /api/v1/abac/roles/{roleId}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Get Permissions

Auth
GET /api/v1/abac/permissions
Responses
200

OK

objectobject
permissions3 fieldsarray[object]
responseKeystring
responseMessagestring
Response

Create Permission

Auth
Request Body
objectobject
actionstring
resourcestring
POST /api/v1/abac/permissions
Responses
200

OK

objectobject
permission
responseKeystring
responseMessagestring
Response

Delete Permission

Auth
Path Params
permissionIdstring
DELETE /api/v1/abac/permissions/{permissionId}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Assign Permission to Role

Auth
Path Params
roleIdstring
Request Body
objectobject
permissionIduuid
POST /api/v1/abac/roles/{roleId}/permissions
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Remove Permission from Role

Auth
Path Params
roleIdstring
permissionIdstring
DELETE /api/v1/abac/roles/{roleId}/permissions/{permissionId}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Assign Role to User

Auth
Path Params
userIdstring
Request Body
objectobject
roleIduuid
expiresAtdate-time
POST /api/v1/abac/users/{userId}/roles
Responses
200

OK

objectobject
roleBindingIduuid
responseKeystring
responseMessagestring
Response

Replace User Roles

Auth
Path Params
userIdstring
Request Body
objectobject
roleIdsarray[string]
PUT /api/v1/abac/users/{userId}/roles
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Remove Role from User

Auth
Path Params
userIdstring
roleBindingIdstring
DELETE /api/v1/abac/users/{userId}/roles/{roleBindingId}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Assign Permission to User

Auth
Path Params
userIdstring
Request Body
objectobject
permissionIduuid
expiresAtdate-time
POST /api/v1/abac/users/{userId}/permissions
Responses
200

OK

objectobject
userPermissionIduuid
responseKeystring
responseMessagestring
Response

Remove Permission from User

Auth
Path Params
userIdstring
userPermissionIdstring
DELETE /api/v1/abac/users/{userId}/permissions/{userPermissionId}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Manage Audit

List audit events

Auth
Query String
Startstring

pattern: ^[0-9]*$

Countstring

pattern: ^[0-9]*$

LogTypearray
CategoryTypeinteger
LogLevelinteger
Searchstring
GET /api/v1/audit
Responses
200

OK

objectobject
entries4 fieldsarray[object]

Because it belongs to a response, if RetrieveLogs breaks, we won't have Entries and TotalCount.

totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response

Manage Password Encryption

Get the public key used to encrypt passwords

Auth
GET /api/v1/auth/public-key
Responses
200

OK

objectobject
modeinteger
serverTime

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
keys6 fieldsarray[object]
Response

Manage Configuration

Get application configuration

Auth
GET /api/v1
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Receive a full file as a single framed binary stream with manifest in headers

Auth
Headers
receiveFileStreamDto11 fieldsobject
POST /api/v1/cross-domain/file-stream
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

500

Internal Server Error

Response

Get the global cross-domain configuration for both sides

Auth
GET /api/v1/cross-domain/global-config
Responses
200

OK

objectobject
lowside
highside
responseKeystring
responseMessagestring
Response

Set global lowside configuration

Auth
Request Body
objectobject
highsideAddressstring
authorizationTokenstring
pairingSecretstring
enabledboolean
PUT /api/v1/cross-domain/global-config/lowside
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Disable global lowside configuration

Auth
POST /api/v1/cross-domain/global-config/lowside/disable
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

Set global highside configuration

Auth
Request Body
objectobject
pushBehaviourinteger
enabledboolean
scanBeforeImportboolean
scanWorkflowIdstring
maxAllowedSeverity
blockOnSecretsboolean
scanTimeoutSeconds

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pollIntervalSeconds

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasPairingSecretboolean
pairingSecretIssuedAtdate-time
PUT /api/v1/cross-domain/global-config/highside
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Disable global highside configuration

Auth
POST /api/v1/cross-domain/global-config/highside/disable
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

Generate a pairing secret for the global highside configuration

Auth
POST /api/v1/cross-domain/global-config/highside/pairing-secret
Responses
200

OK

objectobject
pairingSecret
responseKeystring
responseMessagestring
400

Bad Request

404

Not Found

Response

Get cross-domain operation logs

Auth
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

sortBystring
sortOrderinteger
filterstring
searchstring
GET /api/v1/cross-domain/logs
Responses
200

OK

objectobject
logs14 fieldsarray[object]
hasNextPageboolean
hasPreviousPageboolean
responseKeystring
responseMessagestring
Response

Delete a cross-domain activity-log entry by transmission id

Auth
Path Params
transmissionIdstring
DELETE /api/v1/cross-domain/logs/{transmissionId}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

Receive a lowside configuration change notification

Auth
Headers
X-Transfer-Timestamp

pattern: ^-?(?:0|[1-9]\d*)$

X-Transfer-Signaturestring
Request Body
objectobject
storageNamestring
protocolTypeinteger
changeTypeinteger
POST /api/v1/cross-domain/lowside-configuration-notifications
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Get all cross-domain notifications

Auth
GET /api/v1/cross-domain/notifications
Responses
200

OK

objectobject
notifications6 fieldsarray[object]
responseKeystring
responseMessagestring
Response

Get a lowside configuration by storage ID

Auth
GET /api/v1/cross-domain/storage-config/lowside
Responses
200

OK

objectobject
configurations5 fieldsarray[object]
responseKeystring
responseMessagestring
Response

Add a lowside configuration

Auth
Request Body
objectobject
storageIdstring
POST /api/v1/cross-domain/storage-config/lowside
Responses
200

OK

objectobject
configurationIdstring
responseKeystring
responseMessagestring
400

Bad Request

Response

Update a lowside configuration by ID

Auth
Path Params
idstring
Request Body
objectobject
storageIdstring
PUT /api/v1/cross-domain/storage-config/lowside/{id}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

Delete a lowside configuration by ID

Auth
Path Params
idstring
DELETE /api/v1/cross-domain/storage-config/lowside/{id}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

Get a highside storage configuration by storage ID

Auth
GET /api/v1/cross-domain/storage-config/highside
Responses
200

OK

objectobject
configurations6 fieldsarray[object]
responseKeystring
responseMessagestring
Response

Add a highside configuration

Auth
Request Body
objectobject
storageIdstring
notificationIdstring
POST /api/v1/cross-domain/storage-config/highside
Responses
200

OK

objectobject
configurationIdstring
responseKeystring
responseMessagestring
400

Bad Request

Response

Update a highside configuration by ID

Auth
Path Params
idstring
Request Body
objectobject
storageIdstring
storageNamestring
lowsideStorageNamestring
PUT /api/v1/cross-domain/storage-config/highside/{id}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

Delete a highside configuration by ID

Auth
Path Params
idstring
DELETE /api/v1/cross-domain/storage-config/highside/{id}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

Get top-risky repositories across all connections

Auth
Query String
windowstring
count

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/dashboard/top-risky
Responses
200

OK

arrayarray[object]
connectionIdstring
connectionNamestring
repositoryIdstring
repositoryNamestring
riskScore

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
400

Bad Request

500

Internal Server Error

Response

Export a CycloneDX report for repository

Auth
Path Params
repoIdstring
Query String
Referencestring
GET /api/v1/export/cyclonedx/{repoId}
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export a CycloneDX report for a specific file scan

Auth
Path Params
fileIdstring
GET /api/v1/export/cyclonedx/file/{fileId}
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export an SPDX report for a specific scan

Auth
Path Params
scanIdstring
Query String
formatstring
versionstring
GET /api/v1/export/spdx/{scanId}
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export an SPDX report for a specific file scan

Auth
Path Params
fileIdstring
Query String
formatstring
versionstring
GET /api/v1/export/spdx/file/{fileId}
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export a PDF report for all scans

Auth
Query String
Typearray
TimeFrameinteger
Vulnerabilitiesarray
LicenseRisksarray
Statusarray
TriggerEventarray
Workflowstring
Connectionstring
Secretsboolean
Threatsboolean
Searchstring
ConnectionTypeinteger
RepositoryIdstring
Latestboolean
GET /api/v1/export/pdf/all-scans
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export a PDF overview report for repository

Auth
Path Params
scanIdstring
GET /api/v1/export/pdf/overview/{scanId}
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export a PDF SBOM report for repository

Auth
Path Params
scanIdstring
GET /api/v1/export/pdf/sbom/{scanId}
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export a PDF SBOM report for a specific batch of files

Auth
Path Params
fileIdstring
GET /api/v1/export/pdf/sbom/file/{fileId}
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export a PDF SBOM report for repository that lists every package dependency as its own package

Auth
Path Params
scanIdstring
GET /api/v1/export/pdf/sbom/dependencies/{scanId}
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export a CSV report for repository

Auth
Path Params
scanIdstring
GET /api/v1/export/csv/sbom/{scanId}
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export a CSV report for a specific batch of files

Auth
Path Params
fileIdstring
GET /api/v1/export/csv/sbom/file/{fileId}
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response

Export a CSV report of all CVEs from latest scans

Auth
Query String
Severityarray
GET /api/v1/export/csv/cves
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

Response

Export a CSV report of all packages from latest scans

Auth
GET /api/v1/export/csv/packages
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

Response

Get all external loggers

Auth
GET /api/v1/externallogger
Responses
200

OK

No response body
Response

Add an external logger

Auth
Request Body
objectobject
connectionSettings4 fieldsobject
POST /api/v1/externallogger
Responses
200

OK

No response body
Response

Update an external logger

Auth
Path Params
idstring
Request Body
objectobject
connectionSettings4 fieldsobject
PUT /api/v1/externallogger/{id}
Responses
200

OK

No response body
Response

Delete an external logger

Auth
Path Params
idstring
DELETE /api/v1/externallogger/{id}
Responses
200

OK

No response body
Response

Returns all global label keys

Auth
GET /api/v1/global-label-keys
Responses
200

OK

objectobject
globalKeys10 fieldsarray[object]
responseKeystring
responseMessagestring
Response

Adds a new global label key

Auth
Request Body
objectobject
namestring
descriptionstring
valueTypestring
optionsarray[string]
POST /api/v1/global-label-keys
Responses
200

OK

objectobject
globalKey
responseKeystring
responseMessagestring
Response

Updates an global label key

Auth
Path Params
idstring
Request Body
objectobject
namestring
descriptionstring
valueTypestring
optionsarray[string]
PUT /api/v1/global-label-keys/{id}
Responses
200

OK

objectobject
globalKey
responseKeystring
responseMessagestring
Response

Deletes an global label key

Auth
Path Params
idstring
DELETE /api/v1/global-label-keys/{id}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Start a Scan Now job over one or more targets (each target carries its own StorageId, so a single job may mix protocols)

Auth
Request Body
objectobject
namestring
priority
workflowIdstring
referenceSelectionMode
targets4 fieldsarray[object]
POST /api/v1/jobs
Responses
200

OK

objectobject
jobIdsarray[string]
priorityinteger
enabledRepositoriesarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
207

Multi-Status

400

Bad Request

Response

List jobs (paginated, queryable by trigger type)

Auth
Query String
TriggerTypearray

Enum: ScanNow,Scheduled,RealTime,DirectFile

Priorityarray
Statusarray
WorkflowIdarray
Searchstring
TimeFrameinteger
Typearray
ConnectionTypeinteger
Repositorystring
Servicestring
Vulnerabilitiesarray
LicenseRisksarray
Threatsboolean
Secretsboolean
SortBystring
SortDirstring
Page

pattern: ^-?(?:0|[1-9]\d*)$

PageSize

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/jobs
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
jobs9 fieldsarray[object]
Response

Bulk delete jobs (trigger-agnostic)

Auth
Request Body
objectobject
jobIdsarray[string]
DELETE /api/v1/jobs
Responses
200

OK

objectobject
deletedJobIdsarray[string]
failedJobIdsarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response

Start a Real-Time Protection job over one or more targets (each target carries its own StorageId)

Auth
Request Body
objectobject
namestring
priority
workflowIdstring
targets4 fieldsarray[object]
POST /api/v1/jobs/rtp
Responses
200

OK

objectobject
jobIdsarray[string]
priorityinteger
enabledRepositoriesarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
207

Multi-Status

400

Bad Request

Response

Create a scheduled job with a recurrence pattern

Auth
Request Body
objectobject
namestring
priority
workflowIdstring
referenceSelectionMode
recurrencePattern5 fieldsobject
targets4 fieldsarray[object]
POST /api/v1/jobs/scheduled
Responses
200

OK

objectobject
jobIdsarray[string]
priorityinteger
nextRunTimedate-time
failedRepositoriesarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
207

Multi-Status

400

Bad Request

Response

Delete all upcoming jobs

Auth
DELETE /api/v1/jobs/scheduled
Responses
200

OK

objectobject
deletedJobIdsarray[string]
failedJobIdsarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
207

Multi-Status

400

Bad Request

Response

Cancel a job (for RealTime jobs this disables RTP)

Auth
Path Params
idstring
POST /api/v1/jobs/{id}/cancel
Responses
200

OK

objectobject
jobIdstring
statusstring
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
404

Not Found

Response

Get a single job by id

Auth
Path Params
idstring
GET /api/v1/jobs/{id}
Responses
200

OK

objectobject
jobIdstring
namestring
priorityinteger
storage7 fieldsobject
repository6 fieldsobject
scanInformation
scanStatus
404

Not Found

Response

Activate a license online

Auth
Request Body
objectobject
keystring
POST /api/v1/licenses/online
Responses
200

OK

objectobject
resultinteger
responseMessagestring
400

Bad Request

Response

Activate a license offline

Auth
Request Body
objectobject
LicenseContentfile
POST /api/v1/licenses/offline
Responses
200

OK

objectobject
resultinteger
responseMessagestring
400

Bad Request

Response

Remove licenses

Auth
DELETE /api/v1/licenses
Responses
200

OK

objectobject
resultinteger
responseMessagestring
400

Bad Request

404

Not Found

Response

Get licenses

Auth
GET /api/v1/licenses
Responses
200

OK

objectobject
resultinteger
license
responseMessagestring
400

Bad Request

404

Not Found

Response

Get current deployment Id for offline license activation

Auth
GET /api/v1/licenses/current-deployment-id
Responses
200

OK

objectobject
resultinteger
currentDeploymentIdstring
responseMessagestring
400

Bad Request

Response

Manage Opswat Central Management Ocm

Update an OCM instance

Auth
Request Body
objectobject
serverApistring
regCodestring
PUT /api/v1/ocm
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Delete an OCM instance

Auth
DELETE /api/v1/ocm
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Get an OCM instance

Auth
GET /api/v1/ocm
Responses
200

OK

objectobject
ocmInformation
responseKeystring
responseMessagestring
Response

Get onboarding

Auth
GET /api/v1/onboarding
Responses
200

OK

objectobject
hasUserConfiguredboolean
hasLicenseConfiguredboolean
hasScanInstanceConfiguredboolean
hasConnectionConfiguredboolean
isCloudTypeboolean
isEulaAgreedboolean
isOnboardingDoneboolean
responseKeystring
responseMessagestring
Response

Complete onboarding

Auth
POST /api/v1/onboarding/complete
Responses
200

OK

No response body
Response

Agree to onboarding EULA

Auth
POST /api/v1/onboarding/accept-eula
Responses
200

OK

No response body
Response

Retrieves a paginated, sortable list of packages

Auth
Query String
Namestring
Ecosystemstring
Versionstring
Vulnerabilitiesarray
LicenseRisksarray
Connectionstring
Repositorystring
Referencestring
ScanIdstring
StepSha256string
Searchstring
IncludeDirectFilesboolean
sortByinteger
sortDirinteger
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/packages
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
packages23 fieldsarray[object]
207

Multi-Status

401

Unauthorized

Response

Retrieves all versions of a specific package by its name and ecosystem

Auth
Query String
ecosystemstring
packageNamestring
GET /api/v1/packages/versions
Responses
200

OK

objectobject
packageNamestring
ecosystemstring
versions6 fieldsarray[object]
responseKeystring
responseMessagestring
Response

Retrieves a package by its internal database ID

Auth
Path Params
idstring
Query String
includeDirectFilesboolean

Default: false

GET /api/v1/packages/{id}
Responses
200

OK

objectobject
package
responseKeystring
responseMessagestring
Response

Retrieves a package by its universal package UID

Auth
Path Params
uidInB64string
GET /api/v1/packages/by-uid/{uidInB64}
Responses
200

OK

objectobject
package
responseKeystring
responseMessagestring
Response

Retrieves CVEs associated with a specific package

Auth
Path Params
idstring
GET /api/v1/packages/{id}/cves
Responses
200

OK

objectobject
cves8 fieldsarray[object]
responseKeystring
responseMessagestring
Response

Retrieves the ecosystem-specific upgrade command for a package

Auth
Path Params
idstring
GET /api/v1/packages/{id}/update-instructions
Responses
200

OK

objectobject
packageIdstring
ecosystemstring
commandstring
messagestring
responseKeystring
responseMessagestring
401

Unauthorized

404

Not Found

500

Internal Server Error

Response

Retrieves all labels for a specific package

Auth
Path Params
idstring
GET /api/v1/packages/{id}/labels
Responses
200

OK

objectobject
labels5 fieldsarray[object]
responseKeystring
responseMessagestring
Response

Adds a label to a package

Auth
Path Params
idstring
Request Body
objectobject
Keystring
Valuestring
ValueTypestring
Createddate-time
Updateddate-time
POST /api/v1/packages/{id}/labels
Responses
200

OK

objectobject
label
responseKeystring
responseMessagestring
Response

Updates a label in a package

Auth
Path Params
idstring
keystring
Request Body
objectobject
valuestring
valueTypestring
PUT /api/v1/packages/{id}/labels/{key}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Deletes a label from a package

Auth
Path Params
idstring
keystring
DELETE /api/v1/packages/{id}/labels/{key}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Searches for packages by label key and optionally value

Auth
Query String
keystring
valuestring
GET /api/v1/packages/search/labels
Responses
200

OK

objectobject
packages23 fieldsarray[object]
responseKeystring
responseMessagestring
Response

Create a project

Auth
Request Body
objectobject
namestring

maxLength: 50

workflowIdsarray[string]
storageIdsarray[string]
POST /api/v1/projects
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
400

Bad Request

Response

List projects

Auth
GET /api/v1/projects
Responses
200

OK

arrayarray[object]
idstring
namestring
workflowIdsarray[string]
storageIdsarray[string]
Response

Get a project by ID

Auth
Path Params
idstring
GET /api/v1/projects/{id}
Responses
200

OK

objectobject
idstring
namestring
workflowIdsarray[string]
storageIdsarray[string]
404

Not Found

Response

Update a project

Auth
Path Params
idstring
Request Body
objectobject
namestring

maxLength: 50

PUT /api/v1/projects/{id}
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response

Delete a project

Auth
Path Params
idstring
DELETE /api/v1/projects/{id}
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response

Attach workflows to a project

Auth
Path Params
idstring
Request Body
objectobject
idsarray[string]
POST /api/v1/projects/{id}/workflows/attach
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response

Detach workflows from a project

Auth
Path Params
idstring
Request Body
objectobject
idsarray[string]
POST /api/v1/projects/{id}/workflows/detach
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response

Attach connections (services) to a project

Auth
Path Params
idstring
Request Body
objectobject
idsarray[string]
POST /api/v1/projects/{id}/storages/attach
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response

Detach connections (services) from a project

Auth
Path Params
idstring
Request Body
objectobject
idsarray[string]
POST /api/v1/projects/{id}/storages/detach
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response

Enable real-time protection for multiple repositories

Auth
Path Params
storageIdstring
Request Body
objectobject
repositoriesarray[object]
repositoryIdstring
repositoryNamestring
connectionstring
workflowIdstring
POST /api/v1/realtime/{storageId}/enable
Responses
207

Multi-Status

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

409

Conflict

Response

Disable real-time protection for connection

Auth
Path Params
storageIdstring
PATCH /api/v1/realtime/{storageId}/disable
Responses
200

OK

No response body
Response

Disable real-time protection for repository

Auth
Path Params
storageIdstring
repositoryIdstring
PATCH /api/v1/realtime/{storageId}/{repositoryId}/disable
Responses
200

OK

No response body
Response

List connections with real-time protection enabled

Auth
GET /api/v1/realtime
Responses
200

OK

objectobject
storages4 fieldsarray[object]
Response

List ongoing real-time protection scans for connection

Auth
Path Params
storageIdstring
GET /api/v1/realtime/{storageId}
Responses
200

OK

objectobject
storageIdstring
realTimeScans5 fieldsarray[object]
scanInformation
Response

Delete real-time scan protection for connection

Auth
Path Params
storageIdstring
Query String
forceDeleteboolean

Default: false

DELETE /api/v1/realtime/{storageId}
Responses
200

OK

No response body
Response

Delete real-time scan protection for repository

Auth
Path Params
storageIdstring
repositoryIdstring
Query String
forceDeleteboolean

Default: false

DELETE /api/v1/realtime/{storageId}/{repositoryId}
Responses
200

OK

No response body
Response

Add a scan configuration

Auth
Request Body
objectobject
namestring

maxLength: 50

minLength: 3

scanPoolIdstring
rulesarray[string]
userAgentstring
POST /api/v1/scan-configurations
Responses
200

OK

objectobject
idstring
scanPoolIdstring
rulesarray[string]
typeinteger
namestring
scanPool5 fieldsobject
userAgentstring
filters5 fieldsobject
400

Bad Request

502

Bad Gateway

Response

Get all scan configurations

Auth
GET /api/v1/scan-configurations
Responses
200

OK

objectobject
Workflows8 fieldsarray[object]

Because it belongs to a response, if GetMultipleScanConfiguration breaks, we won't have ScanConfigurations.

resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response

Update a scan configuration

Auth
Path Params
idstring
Request Body
objectobject
namestring

maxLength: 50

minLength: 3

scanPoolIdstring
rulesarray[string]
userAgentstring
PUT /api/v1/scan-configurations/{id}
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response

Delete a scan configuration

Auth
Path Params
idstring
DELETE /api/v1/scan-configurations/{id}
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response

Get a scan configuration by ID

Auth
Path Params
idstring
GET /api/v1/scan-configurations/{id}
Responses
200

OK

objectobject
Workflow
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response

Get all scan configurations by scan pool ID

Auth
Path Params
idstring
GET /api/v1/scan-configurations/scan-pools/{id}
Responses
200

OK

objectobject
Workflows8 fieldsarray[object]

Because it belongs to a response, if GetMultipleScanConfiguration breaks, we won't have ScanConfigurations.

resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response

Add a new scan instance

Auth
Request Body
objectobject
scanPoolIdstring
urlstring
apiKeystring
timeoutstring

pattern: ^-?(\d+\.)?\d{2}:\d{2}:\d{2}(\.\d{1,7})?$

scanInstanceTypeinteger
POST /api/v1/scan-instances
Responses
200

OK

objectobject
scanInstanceIdstring
400

Bad Request

404

Not Found

500

Internal Server Error

Response

Delete a scan instance

Auth
Path Params
idstring
DELETE /api/v1/scan-instances/{id}
Responses
200

OK

No response body
400

Bad Request

404

Not Found

500

Internal Server Error

Response

Get a scan instance by ID

Auth
Path Params
idstring
GET /api/v1/scan-instances/{id}
Responses
200

OK

objectobject
idstring
scanPoolIdstring
urlstring
apiKeystring
timeoutstring

pattern: ^-?(\d+\.)?\d{2}:\d{2}:\d{2}(\.\d{1,7})?$

400

Bad Request

404

Not Found

500

Internal Server Error

Response

Update a scan instance

Auth
Path Params
idstring
Request Body
objectobject
urlstring
apiKeystring
timeoutstring

pattern: ^-?(\d+\.)?\d{2}:\d{2}:\d{2}(\.\d{1,7})?$

PUT /api/v1/scan-instances/{id}
Responses
200

OK

No response body
400

Bad Request

404

Not Found

500

Internal Server Error

Response

Add a new scan pool

Auth
Request Body
objectobject
namestring
scanPoolTypeinteger
POST /api/v1/scan-pools
Responses
200

OK

objectobject
scanPoolIdstring
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response

Get scan pools

Auth
GET /api/v1/scan-pools
Responses
200

OK

objectobject
scanPools5 fieldsarray[object]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response

Delete a scan pool

Auth
Path Params
idstring
DELETE /api/v1/scan-pools/{id}
Responses
200

OK

No response body
400

Bad Request

404

Not Found

500

Internal Server Error

Response

Get a scan pool by ID

Auth
Path Params
idstring
GET /api/v1/scan-pools/{id}
Responses
200

OK

objectobject
scanPool
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response

Update an existing scan pool

Auth
Path Params
idstring
Request Body
objectobject
namestring
PUT /api/v1/scan-pools/{id}
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response

Get all rules from a scan pool

Auth
Path Params
idstring
GET /api/v1/scan-pools/{id}/rules
Responses
200

OK

arrayarray[object]
namestring
user_agentsarray[string]
400

Bad Request

Response

Add or start a scan

Auth
Request Body
objectobject
storageIdstring
storageNamestring
scanTypeinteger
workflowIdstring
repositoryIdstring
repositoryNamestring
protocolType
repositoryReferencesarray[string]
organizationstring
connectionstring
packageTypestring
repositoryTypestring
POST /api/v1/scans
Responses
200

OK

objectobject
scanIdsarray[string]
referencesUsedForScanningarray[string]
protocolType
repositoryIdstring
repositoryNamestring
serviceIdstring
storageNamestring
workflowIdstring
workflowNamestring
triggerEventstring
triggerBystring
responseKeystring
responseMessagestring
Response

Enumerate scan results

Auth
Query String
Typearray
TimeFrameinteger
Vulnerabilitiesarray
LicenseRisksarray
Statusarray
TriggerEventarray
Workflowstring
Connectionstring
Secretsboolean
Threatsboolean
Searchstring
ConnectionTypeinteger
RepositoryIdstring
Latestboolean
GET /api/v1/scans
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Delete multiple scans by their scan IDs

Auth
Request Body
arrayarray[string]
DELETE /api/v1/scans
Responses
200

OK

objectobject
notFoundScanIdsarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
207

Multi-Status

400

Bad Request

404

Not Found

500

Internal Server Error

Response

Upload and scan a file immediately

Uploads and scans files immediately. Optional 'jobName' labels the scan; if omitted, a name is generated automatically.

Auth
Request Body
objectobject
filesarray[string]
workflowIdstring
metadatastring
jobNamestring
POST /api/v1/scans/direct
Responses
200

OK

objectobject
scanIdsarray[string]
referencesUsedForScanningarray[string]
protocolType
repositoryIdstring
repositoryNamestring
serviceIdstring
storageNamestring
workflowIdstring
workflowNamestring
triggerEventstring
triggerBystring
responseKeystring
responseMessagestring
Response

Stop a scan

Auth
Path Params
idstring
POST /api/v1/scans/{id}
Responses
200

OK

objectobject
statusCode

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
Response

Get scan results by scan ID

Auth
Path Params
idstring
GET /api/v1/scans/{id}
Responses
200

OK

objectobject
serviceIdstring
repositoryIdstring
repositoryNamestring
repositoryTypestring
referenceUsedForScanningstring
scanIdstring
protocolTypeinteger
connectionstring
packageTypestring
organizationstring
startTimedate-time
stopTimedate-time
durationstring

pattern: ^-?(\d+\.)?\d{2}:\d{2}:\d{2}(\.\d{1,7})?$

vulnerabilityIssues5 fieldsobject
scanStatusinteger
discoveryStatusinteger
errorsarray[string]
blockedLicensesCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
infectedFiles

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
filesWithSecrets

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
404

Not Found

Response

Enumerate all latest scan results

Auth
Query String
Typearray
TimeFrameinteger
Vulnerabilitiesarray
LicenseRisksarray
Statusarray
TriggerEventarray
Workflowstring
Connectionstring
Secretsboolean
Threatsboolean
Searchstring
ConnectionTypeinteger
RepositoryIdstring
Latestboolean
GET /api/v1/scans/latest
Responses
200

OK

arrayarray[object]
scanIdstring
repository7 fieldsobject
scanInformation12 fieldsobject
scanStatus3 fieldsobject
metadatastring
404

Not Found

Response

Enumerate all latest scan results by service ID

Auth
Path Params
serviceIdstring
Query String
Typearray
TimeFrameinteger
Vulnerabilitiesarray
LicenseRisksarray
Statusarray
TriggerEventarray
Workflowstring
Connectionstring
Secretsboolean
Threatsboolean
Searchstring
ConnectionTypeinteger
RepositoryIdstring
Latestboolean
GET /api/v1/scans/{serviceId}/latest
Responses
200

OK

objectobject
scanIdstring
repository7 fieldsobject
scanInformation12 fieldsobject
scanStatus3 fieldsobject
metadatastring
Response

Get scan overview by scan ID

Auth
Path Params
idstring
GET /api/v1/scans/{id}/overview
Responses
200

OK

arrayarray[object]
scanIdstring
repository7 fieldsobject
scanInformation12 fieldsobject
scanStatus3 fieldsobject
metadatastring
Response

Enumerate all scan results by repository ID

Auth
Path Params
serviceIdstring
repositoryIdstring
GET /api/v1/scans/{serviceId}/{repositoryId}
Responses
200

OK

arrayarray[object]
scanIdstring
repository7 fieldsobject
scanInformation12 fieldsobject
scanStatus3 fieldsobject
metadatastring
Response

Enumerate all scan schedules

Auth
GET /api/v1/scans/schedules
Responses
200

OK

arrayarray[object]
idstring
workflowIdstring
storageIdstring
userIdstring
namestring
priorityinteger
createdAtdate-time
lastUpdateddate-time
lastScanTimedate-time
nextScanTimedate-time
recurrenceTypeinteger
startDatedate-time
timeToStartdate-time
everyNumberOfHours

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
everyNumberOfDays

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
everyNumberOfWeeks

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
everyNumberOfMonths

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
daysOfWeekarray[integer]
dayOfMonth

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
workflow
scansarray[object]
Response

Enumerate all CVEs across scanned packages

Auth
Query String
severitiesstring
searchstring
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/scans/cves
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
cves6 fieldsarray[object]
400

Bad Request

401

Unauthorized

500

Internal Server Error

Response

Clean up historical scan results older than the specified time frame

Auth
Request Body
objectobject
timeFrameinteger
POST /api/v1/scans/cleanup
Responses
200

OK

objectobject
deletedScansCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalScansFound

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
responseKeystring
responseMessagestring
207

Multi-Status

400

Bad Request

500

Internal Server Error

Response

Enumerate files by scan ID

Auth
Path Params
scanIdstring
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

searchstring
includeArchivesboolean
includePackagesboolean
GET /api/v1/scans/{scanId}/files
Responses
200

OK

arrayarray[object]
objectIdentityIdstring
objectIdentityHashstring
scanResultIdstring
progressUpload

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
progressScan

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
processingStateinteger
exceptionDetailsstring
createddate-time
discoveryStarteddate-time
discoveryStartedDaySec

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
streamingStartedTimedate-time
streamingCompletedTimedate-time
streamingTimeSpanMs

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
scanCompletedTimedate-time
processingTimeSpanMs

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
processingFailedTimedate-time
processingRetryCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
objectTriggeredActionsarray[object]
actionStatusinteger
triggeredActionTypeinteger
skippedScanboolean
hasAppliedRemediationboolean
hasAppliedSanitizationboolean
hasFailedSanitizationboolean
createdAtdate-time
lastUpdateddate-time
tenantIdstring
objectRemediationActionsarray[object]
scanResult
objectIdentity
versionsarray[object]
idstring
scanIdstring
storageIdstring
scanWorkflowSnapshotIdstring
metaDefenderCoreUrlstring
namestring
pathstring
hashstring
objectStorageMetadatastring
size

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastModifieddate-time
storageLocationstring
fileTypeCategory
pathForDisplaystring
extensionstring
404

Not Found

Response

Get the file details view of a file by its scan result ID

Auth
Path Params
scanResultIdstring
GET /api/v1/scans/{scanResultId}/details
Responses
200

OK

objectobject
fileIdstring
scanResultIdstring
parentIdstring
displayNamestring
filePathstring
fileTypestring
size

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
scannedOnstring
startTimedate-time
isArchiveboolean
isBlockedboolean
blockedReasonstring
isMalwareboolean
hasSecretsboolean
isVulnerableboolean
dlp
metascan
sbom5 fieldsobject
Response

Get the archive entries of a file by its scan result ID

Auth
Path Params
scanResultIdstring
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/scans/{scanResultId}/children
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
children18 fieldsarray[object]
Response

Get the dependencies of a file and its archive entries by its scan result ID

Rolls up the transitive dependencies reported for a file and every entry inside it when it is an archive. ReportedDependencyCount is what the scan engine reported; ItemizedDependencyCount is how many it itemized and therefore how many rows this endpoint can return.

Auth
Path Params
scanResultIdstring
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

searchstring
GET /api/v1/scans/{scanResultId}/dependencies
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
directPackageCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalPackageCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
reportedDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
itemizedDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
distinctDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
vulnerabilityCounts
dependencies9 fieldsarray[object]
Response

Get the dependencies of one archive entry, including nested entries, by its child data ID

Same rollup as the file dependencies endpoint, scoped to one extracted file and any archive entries nested under it. ReportedDependencyCount is what the scan engine reported; ItemizedDependencyCount is how many it itemized and therefore how many rows this endpoint can return.

Auth
Path Params
scanResultIdstring
childDataIdstring
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

searchstring
GET /api/v1/scans/{scanResultId}/archive/{childDataId}/dependencies
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
directPackageCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalPackageCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
reportedDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
itemizedDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
distinctDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
vulnerabilityCounts
dependencies9 fieldsarray[object]
Response

Get per-CVE new/fixed details for each trend period

Auth
Query String
intervalinteger
periods

pattern: ^-?(?:0|[1-9]\d*)$

Default: 4

GET /api/v1/scans/vulnerability-trends/details
Responses
200

OK

arrayarray[object]
periodStartdate
periodEnddate
newCves6 fieldsarray[object]
fixedCves6 fieldsarray[object]
500

Internal Server Error

Response

Get service references by service ID

Auth
Path Params
serviceIdstring
GET /api/v1/services/{serviceId}/references
Responses
200

OK

objectobject
serviceIdstring
serviceNamestring
repositoryReferenceInfoArray3 fieldsarray[object]
404

Not Found

Response

Get service references by service ID and repository ID

Auth
Path Params
serviceIdstring
repositoryIdstring
Query String
Page

pattern: ^-?(?:0|[1-9]\d*)$

PageSize

pattern: ^-?(?:0|[1-9]\d*)$

FilterValuestring
Cursorstring
Searchstring

maxLength: 256

minLength: 0

GET /api/v1/services/{serviceId}/{repositoryId}/references
Responses
200

OK

objectobject
referencesarray[string]
totalReferences

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
404

Not Found

Response

Add service references

Auth
Request Body
arrayarray[object]
serviceIdstring
repositoryIdsarray[string]
POST /api/v1/services/references
Responses
200

OK

arrayarray[object]
serviceIdstring
serviceNamestring
repositoryReferenceInfoArray3 fieldsarray[object]
204

No Content

404

Not Found

Response

Get service resources by service ID

Auth
Path Params
serviceIdstring
GET /api/v1/services/{serviceId}/resources
Responses
200

OK

objectobject
resourcesarray[string]
404

Not Found

Response

Add a service

Auth
Request Body
objectobject
credentialsstring
namestring
vendorTypeinteger
protocolTypeinteger
POST /api/v1/services
Responses
200

OK

objectobject
idstring
namestring
type
details
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

409

Conflict

500

Internal Server Error

503

Service Unavailable

Response

Get all services

Auth
Query String
contentboolean
typearray
GET /api/v1/services
Responses
200

OK

objectobject
serviceDtos9 fieldsarray[object]
statusMessagestring
206

Partial Content

400

Bad Request

Response

Update a service by ID

Auth
Path Params
serviceIdstring
Request Body
objectobject
namestring
credentialsstring
hasNewCredentialsboolean
PUT /api/v1/services/{serviceId}
Responses
200

OK

objectobject
idstring
namestring
type
details
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

409

Conflict

500

Internal Server Error

503

Service Unavailable

Response

Get a service by ID

Auth
Path Params
serviceIdstring
Query String
contentboolean
Searchstring
Page

pattern: ^-?(?:0|[1-9]\d*)$

PageSize

pattern: ^-?(?:0|[1-9]\d*)$

FilterValuestring
Cursorstring
Searchstring

maxLength: 256

minLength: 0

PrioritizedRepositoriesReferencestring
GET /api/v1/services/{serviceId}
Responses
200

OK

objectobject
idstring
credentialsType

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
scanWorkflowIdstring
domainstring
realTimeStatusinteger
namestring
vendorTypeinteger
protocolTypeinteger
400

Bad Request

404

Not Found

500

Internal Server Error

Response

Delete a service by ID

Auth
Path Params
serviceIdstring
DELETE /api/v1/services/{serviceId}
Responses
200

OK

No response body
400

Bad Request

404

Not Found

500

Internal Server Error

Response

Get top-risky repositories for a service

Auth
Path Params
serviceIdstring
Query String
windowstring
count

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/services/{serviceId}/top-risky
Responses
200

OK

arrayarray[object]
connectionIdstring
connectionNamestring
repositoryIdstring
repositoryNamestring
riskScore

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
400

Bad Request

500

Internal Server Error

Response

Get the base URL

Auth
GET /api/v1/network
Responses
200

OK

objectobject
baseUrlstring
500

Internal Server Error

Response

Set the base URL

Auth
Request Body
objectobject
baseUrlstring
PUT /api/v1/network
Responses
200

OK

No response body
400

Bad Request

409

Conflict

500

Internal Server Error

Response

Add a SMTP configuration

Auth
Request Body
objectobject
hoststring
port

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
senderAddressstring
senderNamestring
domainstring
usernamestring
passwordstring
secureSocketOptioninteger
ignoreCertWarningsboolean
isEnabledboolean
POST /api/v1/smtp
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Partially update SMTP configuration

Auth
Request Body
objectobject
hoststring
port

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
senderAddressstring
senderNamestring
domainstring
usernamestring
passwordstring
secureSocketOption
ignoreCertWarningsboolean
isEnabledboolean
PATCH /api/v1/smtp
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Get a SMTP configuration

Auth
GET /api/v1/smtp
Responses
200

OK

objectobject
smtp
responseKeystring
responseMessagestring
400

Bad Request

Response

Add a Jira configuration

Auth
Request Body
objectobject
namestring
apiKeystring
baseAddressstring
usernamestring
POST /api/v1/jira
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Get all Jira configurations

Auth
GET /api/v1/jira
Responses
200

OK

objectobject
jiraEntries8 fieldsarray[object]
responseKeystring
responseMessagestring
400

Bad Request

Response

Get a Jira configuration by ID

Auth
Path Params
idstring
GET /api/v1/jira/{id}
Responses
200

OK

objectobject
jira
responseKeystring
responseMessagestring
404

Not Found

Response

Update a Jira configuration by ID

Auth
Path Params
idstring
Request Body
objectobject
namestring
apiKeystring
baseAddressstring
usernamestring
PUT /api/v1/jira/{id}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

Delete a Jira configuration by ID

Auth
Path Params
idstring
DELETE /api/v1/jira/{id}
Responses
200

OK

objectobject
jiraIdstring
responseKeystring
responseMessagestring
404

Not Found

Response

Get Jira projects

Auth
Path Params
idstring
GET /api/v1/jira/{id}/projects
Responses
200

OK

objectobject
projectsarray[object]
idstring
namestring
responseKeystring
responseMessagestring
404

Not Found

Response

Add a Teams configuration

Auth
Request Body
objectobject
namestring
apiKeystring
webhookUrlstring
POST /api/v1/teams
Responses
201

Created

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Get all Teams configurations

Auth
GET /api/v1/teams
Responses
200

OK

objectobject
teamsConnections7 fieldsarray[object]
responseKeystring
responseMessagestring
400

Bad Request

Response

Get a Teams configuration by ID

Auth
Path Params
idstring
GET /api/v1/teams/{id}
Responses
200

OK

objectobject
teams
responseKeystring
responseMessagestring
404

Not Found

Response

Update a Teams configuration by ID

Auth
Path Params
idstring
Request Body
objectobject
namestring
apiKeystring
webhookUrlstring
PUT /api/v1/teams/{id}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

Delete a Teams configuration by ID

Auth
Path Params
idstring
DELETE /api/v1/teams/{id}
Responses
200

OK

objectobject
teamsIdstring
responseKeystring
responseMessagestring
404

Not Found

Response

Get the SSO configuration

Auth
GET /api/v1/sso
Responses
200

OK

objectobject
isEnabledboolean
ssoTypeinteger
ssoProviderinteger
baseUrlstring
clientIdstring
authoritystring
identityProviderIssuerstring
identityProviderLoginUrlstring
identityProviderLogoutUrlstring
administratorRoleNamestring
readonlyRoleNamestring
roleMappingsarray[object]
roleIduuid
idpRoleNamestring
hasClientSecretboolean
hasIdentityProviderCertificateboolean
404

Not Found

500

Internal Server Error

Response

Create or update the SSO configuration

Auth
Request Body
objectobject
isEnabledboolean
ssoTypeinteger
ssoProviderinteger
baseUrlstring
clientIdstring
clientSecretstring
authoritystring
identityProviderCertificatestring
identityProviderIssuerstring
identityProviderLoginUrlstring
identityProviderLogoutUrlstring
administratorRoleNamestring
readonlyRoleNamestring
roleMappingsarray[object]
roleIduuid
idpRoleNamestring
PUT /api/v1/sso
Responses
200

OK

No response body
400

Bad Request

404

Not Found

500

Internal Server Error

Response

Anonymous by design: the login page must decide whether to offer the SSO button before a session exists. It returns only a boolean — never provider, authority, or secret presence.

Auth
GET /api/v1/sso/enabled
Responses
200

OK

objectobject
isEnabledboolean
Response

telemetry

Auth
GET /api/v1/telemetry
Responses
200

OK

objectobject
enabledboolean
sendToOpswatEnabledboolean
collectors4 fieldsarray[object]
responseKeystring
responseMessagestring
Response

enabled

Auth
Request Body
objectobject
enabledboolean
PUT /api/v1/telemetry/enabled
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

opswat

Auth
Request Body
objectobject
sendToOpswatEnabledboolean
PUT /api/v1/telemetry/opswat
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

collectors

Auth
Request Body
objectobject
endpointUrlstring
metricProtocolstring
apiKeystring
POST /api/v1/telemetry/collectors
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

collectors

Auth
Request Body
objectobject
endpointUrlstring
metricProtocolstring
apiKeystring
PUT /api/v1/telemetry/collectors
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

collectors

Auth
Query String
endpointUrlstring
DELETE /api/v1/telemetry/collectors
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response

Add a new user

The new password must meet the password policy. A rejected password returns 400 stating the exact limit.

Auth
Request Body
objectobject
role
fullNamestring
userNamestring
passwordstring
emailstring
POST /api/v1/users
Responses
200

OK

objectobject
createUserParameters5 fieldsobject
currentUserIdstring
400

Bad Request

Response

Get users

Auth
Query String
Typeinteger
StartIndex

pattern: ^-?(?:0|[1-9]\d*)$

Count

pattern: ^-?(?:0|[1-9]\d*)$

SearchTermstring
GET /api/v1/users
Responses
200

OK

objectobject
enumerateUsersDto2 fieldsobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Update a user

Auth
Request Body
objectobject
userIdstring
role
userNamestring
fullNamestring
emailstring
currentPasswordstring
newPasswordstring
showTutorialboolean
PUT /api/v1/users
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Register a new pending user

The new password must meet the password policy. A rejected password returns 400 stating the exact limit.

Auth
Request Body
objectobject
fullNamestring
userNamestring
passwordstring
emailstring
POST /api/v1/users/register
Responses
200

OK

objectobject
userDto
responseKeystring
responseMessagestring
400

Bad Request

Response

Approve a pending user

Auth
Path Params
userIdstring
Request Body
objectobject
roleinteger
POST /api/v1/users/{userId}/approve
Responses
200

OK

No response body
400

Bad Request

403

Forbidden

404

Not Found

409

Conflict

Response

Reject a pending user

Auth
Path Params
userIdstring
POST /api/v1/users/{userId}/reject
Responses
200

OK

No response body
400

Bad Request

404

Not Found

409

Conflict

Response

Get current user

Auth
GET /api/v1/user
Responses
200

OK

objectobject
userDto
responseKeystring
responseMessagestring
400

Bad Request

Response

Update the current user's own profile

The new password must meet the password policy. A rejected password returns 400 stating the exact limit.

Auth
Request Body
objectobject
fullNamestring
emailstring
currentPasswordstring
newPasswordstring
showTutorialboolean
tablePreferences2 fieldsarray[object]
PUT /api/v1/user
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Get the calling principal's permission claims

Auth
GET /api/v1/user/permissions
Responses
200

OK

arrayarray[string]
Response

Delete a user

Auth
Path Params
userIdstring
DELETE /api/v1/users/{userId}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Login user

Auth
Request Body
objectobject
usernamestring
passwordstring
POST /api/v1/user/login
Responses
200

OK

objectobject
jwtToken
responseKeystring
responseMessagestring
400

Bad Request

429

Too Many Requests

Response

Turns an identity-service session into an MDSSC one. The SSO callback leaves the platform token readable by the page, but MDSSC's own session lives in an HttpOnly cookie that script cannot write, so the exchange has to happen here.

Auth
Request Body
objectobject
accessTokenstring
POST /api/v1/user/sso/session
Responses
200

OK

No response body
403

Forbidden

404

Not Found

Response

Remove all tokens for an user

Auth
Path Params
userIdstring
DELETE /api/v1/user/login/{userId}
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response

Get a new Access Token

Auth
PUT /api/v1/user/token
Responses
200

OK

objectobject
jwtToken
responseKeystring
responseMessagestring
400

Bad Request

Response

Request a password reset

Auth
Request Body
objectobject
emailInputstring
POST /api/v1/user/password/request-reset
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response

Reset a user password

The new password must meet the password policy. A rejected password returns 400 stating the exact limit.

Auth
Request Body
objectobject
newPasswordstring
newPasswordConfirmationstring
secureTokenstring
userIdstring
POST /api/v1/user/password/new-password
Responses
200

OK

objectobject
user
responseKeystring
responseMessagestring
Response

List the current user's active sessions

Auth
GET /api/v1/user/sessions
Responses
200

OK

arrayarray[object]
idstring
signedInAtdate-time
lastActiveAtdate-time
expiresAtdate-time
isCurrentboolean
403

Forbidden

Response

Terminate the current user's sessions

Supply CurrentPassword to confirm the request.

Auth
Request Body
objectobject
sessionIdstring
includeCurrentboolean
currentPasswordstring
POST /api/v1/user/sessions/terminate
Responses
200

OK

objectobject
terminatedCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
currentSessionEndedboolean
400

Bad Request

403

Forbidden

404

Not Found

429

Too Many Requests

Response

Manage Versions

Get application version

Auth
Query String
api-versionstring
GET /api/version
Responses
200

OK

objectobject
versionstring
responseKeystring
responseMessagestring
Response

Get application version

Auth
GET /api/v1/version
Responses
200

OK

objectobject
versionstring
responseKeystring
responseMessagestring
Response

Handles a scan event triggered by a webhook. Requires a custom header and a body.

Auth
Path Params
routeParameterstring
Request Body
No request body
POST /api/v1/webhook/hmac/{routeParameter}
Responses
200

OK

No response body
400

Bad Request

500

Internal Server Error

Response

Handles a scan event triggered by a webhook. Requires a custom body.

Auth
Path Params
routeParameterstring
Request Body
No request body
POST /api/v1/webhook/{routeParameter}
Responses
200

OK

No response body
400

Bad Request

500

Internal Server Error

Response

Create a workflow

Auth
Request Body
objectobject
namestring
descriptionstring
scanConfigurationIdstring
blockedFileDefinitionobject
modestring
configuration
fileRemediations3 fieldsobject
fileDiscoveryFilterConfiguration
remediations3 fieldsarray[object]
crossDomainTransfer
POST /api/v1/workflows
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response

List workflows (paginated)

Auth
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

Default: 1

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

Default: 10

includeDeletedboolean

Default: false

GET /api/v1/workflows
Responses
200

OK

objectobject
entries13 fieldsarray[object]
totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
Response

Partially update a workflow

Auth
Path Params
idstring
Request Body
objectobject
namestring
descriptionstring
scanConfigurationIdstring
blockedFileDefinition
fileRemediations
fileDiscoveryFilterConfiguration
remediations3 fieldsarray[object]
crossDomainTransfer
PATCH /api/v1/workflows/{id}
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response

Get a workflow by ID

Auth
Path Params
idstring
GET /api/v1/workflows/{id}
Responses
200

OK

objectobject
idstring
namestring
descriptionstring
userIdstring
scanConfigurationIdstring
deletedboolean
blockedFileDefinitionobject
modestring
configuration
fileRemediations3 fieldsobject
fileDiscoveryFilterConfiguration
remediations3 fieldsarray[object]
crossDomainTransfer
security

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
scanPoolstring
Response

Delete a workflow by ID

Auth
Path Params
idstring
DELETE /api/v1/workflows/{id}
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response

Retrieve MetaDefender Core technology states for a workflow

Auth
Path Params
idstring
GET /api/v1/workflows/{id}/technologies
Responses
200

OK

objectobject
sbominteger
metaScaninteger
dlpinteger
enabledCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
404

Not Found

500

Internal Server Error

Response