Authentication

This section of the user guide describes how you can programmatically interact with the MetaDefender Software Supply Chain REST API. Below are some common tasks that can be done using the available REST APIs:

  • Authenticate to obtain a JSON Web Token(JWT)
  • Start or stop a process(scan)
  • Add / remove service units

About this REST API

The exposed endpoint is located by default at http(s)://mdssc-server/api/ (for example, the authentication endpoint is available at http(s)://mdssc-server/api/user/authenticate). All requests are handled by the NGINX web server before being proxied to the backend API Gateway service.

All endpoints perform authentication and authorization checks. For these checks to succeed, a valid token should be presented in the Authorization header in the form of Bearer.

Please note that all issued tokens have a timestamp and signature associated in order to prevent long-term usage without re - authentication. The lifespan of the token is currently set to 60 minutes, meaning you will have to request a new token before it expires in order to avoid error responses.

Server
http://localhost:8001
Server Variables
http Bearer
apiKey ApiKey
Fields
KeyIn
ApiKeyHeader

monitored-files

Auth
Request Body
objectobject
filefile
workflowIdstring
intervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
groupIdstring
groupNamestring
POST /api/v1/monitored-files
curl --request POST \
--url 'http://localhost:8001/api/v1/monitored-files' \
--form 'file=@{file}'
Copy
Responses
200

OK

objectobject
idstring
originalFileNamestring
sha256string
groupIdstring
groupNamestring
enabledboolean
rescanIntervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
newCveCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastRunAtdate-time
nextRunAtdate-time
createdAtdate-time
Response
{
"id": "{string}",
"originalFileName": "{string}",
"sha256": "{string}",
"groupId": "{string}",
"groupName": "{string}",
"enabled": "{boolean}",
"rescanIntervalMinutes": "{integer}",
"newCveCount": "{integer}",
"lastRunAt": "{date-time}",
"nextRunAt": "{date-time}",
"createdAt": "{date-time}"
}
Copy

monitored-files

Auth
GET /api/v1/monitored-files
curl --get \
--url 'http://localhost:8001/api/v1/monitored-files'
Copy
Responses
200

OK

arrayarray[object]
idstring
originalFileNamestring
sha256string
groupIdstring
groupNamestring
enabledboolean
rescanIntervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
newCveCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastRunAtdate-time
nextRunAtdate-time
createdAtdate-time
Response
[
{
"id": "{string}",
"originalFileName": "{string}",
"sha256": "{string}",
"groupId": "{string}",
"groupName": "{string}",
"enabled": "{boolean}",
"rescanIntervalMinutes": "{integer}",
"newCveCount": "{integer}",
"lastRunAt": "{date-time}",
"nextRunAt": "{date-time}",
"createdAt": "{date-time}"
}
]
Copy

history

Auth
Path Params
idstring
GET /api/v1/monitored-files/{id}/history
curl --get \
--url 'http://localhost:8001/api/v1/monitored-files/{id}/history'
Copy
Responses
200

OK

arrayarray[object]
idstring
scanIdstring
runAtdate-time
newCveIdsstring
Response
[
{
"id": "{string}",
"scanId": "{string}",
"runAt": "{date-time}",
"newCveIds": "{string}"
}
]
Copy

scan-now

Auth
Path Params
idstring
POST /api/v1/monitored-files/{id}/scan-now
curl --request POST \
--url 'http://localhost:8001/api/v1/monitored-files/{id}/scan-now'
Copy
Responses
200

OK

objectobject
idstring
originalFileNamestring
sha256string
groupIdstring
groupNamestring
enabledboolean
rescanIntervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
newCveCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastRunAtdate-time
nextRunAtdate-time
createdAtdate-time
Response
{
"id": "{string}",
"originalFileName": "{string}",
"sha256": "{string}",
"groupId": "{string}",
"groupName": "{string}",
"enabled": "{boolean}",
"rescanIntervalMinutes": "{integer}",
"newCveCount": "{integer}",
"lastRunAt": "{date-time}",
"nextRunAt": "{date-time}",
"createdAt": "{date-time}"
}
Copy

enabled

Auth
Path Params
idstring
Request Body
objectobject
enabledboolean
POST /api/v1/monitored-files/{id}/enabled
curl --request POST \
--url 'http://localhost:8001/api/v1/monitored-files/{id}/enabled' \
--data '{
"enabled": "{boolean}"
}'
Copy
Responses
200

OK

objectobject
idstring
originalFileNamestring
sha256string
groupIdstring
groupNamestring
enabledboolean
rescanIntervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
newCveCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastRunAtdate-time
nextRunAtdate-time
createdAtdate-time
Response
{
"id": "{string}",
"originalFileName": "{string}",
"sha256": "{string}",
"groupId": "{string}",
"groupName": "{string}",
"enabled": "{boolean}",
"rescanIntervalMinutes": "{integer}",
"newCveCount": "{integer}",
"lastRunAt": "{date-time}",
"nextRunAt": "{date-time}",
"createdAt": "{date-time}"
}
Copy

interval

Auth
Path Params
idstring
Request Body
objectobject
intervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
POST /api/v1/monitored-files/{id}/interval
curl --request POST \
--url 'http://localhost:8001/api/v1/monitored-files/{id}/interval' \
--data '{
"intervalMinutes": "{integer}"
}'
Copy
Responses
200

OK

objectobject
idstring
originalFileNamestring
sha256string
groupIdstring
groupNamestring
enabledboolean
rescanIntervalMinutes

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
newCveCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastRunAtdate-time
nextRunAtdate-time
createdAtdate-time
Response
{
"id": "{string}",
"originalFileName": "{string}",
"sha256": "{string}",
"groupId": "{string}",
"groupName": "{string}",
"enabled": "{boolean}",
"rescanIntervalMinutes": "{integer}",
"newCveCount": "{integer}",
"lastRunAt": "{date-time}",
"nextRunAt": "{date-time}",
"createdAt": "{date-time}"
}
Copy

{id}

Auth
Path Params
idstring
DELETE /api/v1/monitored-files/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/monitored-files/{id}'
Copy
Responses
204

No Content

No response body
Response
No response
Copy

Get Roles

Auth
Query String
includePermissionsboolean

Default: true

GET /api/v1/abac/roles
curl --get \
--url 'http://localhost:8001/api/v1/abac/roles' \
--data includePermissions=true
Copy
Responses
200

OK

objectobject
roles3 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"roles": [
{
"id": "{uuid}",
"name": "{string}",
"permissions": [
{
"id": "{uuid}",
"action": "{string}",
"resource": "{string}"
}
]
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Create Role

Auth
Request Body
objectobject
namestring

maxLength: 100

minLength: 3

permissionIdsarray[string]
templateRoleIduuid
POST /api/v1/abac/roles
curl --request POST \
--url 'http://localhost:8001/api/v1/abac/roles' \
--data '{
"name": "{string}",
"permissionIds": [
"{array[string]...}"
],
"templateRoleId": "{uuid}"
}'
Copy
Responses
200

OK

objectobject
role
responseKeystring
responseMessagestring
Response
{
"role": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get Role by ID

Auth
Path Params
roleIdstring
GET /api/v1/abac/roles/{roleId}
curl --get \
--url 'http://localhost:8001/api/v1/abac/roles/{roleId}'
Copy
Responses
200

OK

objectobject
role
responseKeystring
responseMessagestring
Response
{
"role": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Update Role

Auth
Path Params
roleIdstring
Request Body
objectobject
namestring

maxLength: 100

minLength: 3

permissionIdsarray[string]
PUT /api/v1/abac/roles/{roleId}
curl --request PUT \
--url 'http://localhost:8001/api/v1/abac/roles/{roleId}' \
--data '{
"name": "{string}",
"permissionIds": [
"{array[string]...}"
]
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Delete Role

Auth
Path Params
roleIdstring
DELETE /api/v1/abac/roles/{roleId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/abac/roles/{roleId}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get Permissions

Auth
GET /api/v1/abac/permissions
curl --get \
--url 'http://localhost:8001/api/v1/abac/permissions'
Copy
Responses
200

OK

objectobject
permissions3 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"permissions": [
{
"id": "{uuid}",
"action": "{string}",
"resource": "{string}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Create Permission

Auth
Request Body
objectobject
actionstring
resourcestring
POST /api/v1/abac/permissions
curl --request POST \
--url 'http://localhost:8001/api/v1/abac/permissions' \
--data '{
"action": "{string}",
"resource": "{string}"
}'
Copy
Responses
200

OK

objectobject
permission
responseKeystring
responseMessagestring
Response
{
"permission": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Delete Permission

Auth
Path Params
permissionIdstring
DELETE /api/v1/abac/permissions/{permissionId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/abac/permissions/{permissionId}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Assign Permission to Role

Auth
Path Params
roleIdstring
Request Body
objectobject
permissionIduuid
POST /api/v1/abac/roles/{roleId}/permissions
curl --request POST \
--url 'http://localhost:8001/api/v1/abac/roles/{roleId}/permissions' \
--data '{
"permissionId": "{uuid}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Remove Permission from Role

Auth
Path Params
roleIdstring
permissionIdstring
DELETE /api/v1/abac/roles/{roleId}/permissions/{permissionId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/abac/roles/{roleId}/permissions/{permissionId}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Assign Role to User

Auth
Path Params
userIdstring
Request Body
objectobject
roleIduuid
expiresAtdate-time
POST /api/v1/abac/users/{userId}/roles
curl --request POST \
--url 'http://localhost:8001/api/v1/abac/users/{userId}/roles' \
--data '{
"roleId": "{uuid}",
"expiresAt": "{date-time}"
}'
Copy
Responses
200

OK

objectobject
roleBindingIduuid
responseKeystring
responseMessagestring
Response
{
"roleBindingId": "{uuid}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Replace User Roles

Auth
Path Params
userIdstring
Request Body
objectobject
roleIdsarray[string]
PUT /api/v1/abac/users/{userId}/roles
curl --request PUT \
--url 'http://localhost:8001/api/v1/abac/users/{userId}/roles' \
--data '{
"roleIds": [
"{array[string]...}"
]
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Remove Role from User

Auth
Path Params
userIdstring
roleBindingIdstring
DELETE /api/v1/abac/users/{userId}/roles/{roleBindingId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/abac/users/{userId}/roles/{roleBindingId}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Assign Permission to User

Auth
Path Params
userIdstring
Request Body
objectobject
permissionIduuid
expiresAtdate-time
POST /api/v1/abac/users/{userId}/permissions
curl --request POST \
--url 'http://localhost:8001/api/v1/abac/users/{userId}/permissions' \
--data '{
"permissionId": "{uuid}",
"expiresAt": "{date-time}"
}'
Copy
Responses
200

OK

objectobject
userPermissionIduuid
responseKeystring
responseMessagestring
Response
{
"userPermissionId": "{uuid}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Remove Permission from User

Auth
Path Params
userIdstring
userPermissionIdstring
DELETE /api/v1/abac/users/{userId}/permissions/{userPermissionId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/abac/users/{userId}/permissions/{userPermissionId}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Manage Audit

List audit events

Auth
Query String
Startstring

pattern: ^[0-9]*$

Countstring

pattern: ^[0-9]*$

LogTypearray
CategoryTypeinteger
LogLevelinteger
Searchstring
GET /api/v1/audit
curl --get \
--url 'http://localhost:8001/api/v1/audit' \
--data Start={Start} \
--data Count={Count} \
--data LogType={LogType} \
--data CategoryType={CategoryType} \
--data LogLevel={LogLevel} \
--data Search={Search}
Copy
Responses
200

OK

objectobject
entries4 fieldsarray[object]

Because it belongs to a response, if RetrieveLogs breaks, we won't have Entries and TotalCount.

totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response
{
"entries": [
{
"id": "{string}",
"level": "{integer}",
"properties": {
"logType": "{integer}",
"category": "{integer}",
"eventTimestamp": "{date-time}",
"userId": "{string}",
"userName": "{string}"
},
"renderedMessage": "{string}"
}
],
"totalCount": "{integer}",
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Manage Password Encryption

Get the public key used to encrypt passwords

Auth
GET /api/v1/auth/public-key
curl --get \
--url 'http://localhost:8001/api/v1/auth/public-key'
Copy
Responses
200

OK

objectobject
modeinteger
serverTime

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
keys6 fieldsarray[object]
Response
{
"mode": "{integer}",
"serverTime": "{integer}",
"keys": [
{
"kty": "{string}",
"kid": "{string}",
"use": "{string}",
"alg": "{string}",
"n": "{string}",
"e": "{string}"
}
]
}
Copy

Manage Configuration

Get application configuration

Auth
GET /api/v1
curl --get \
--url 'http://localhost:8001/api/v1'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Receive a full file as a single framed binary stream with manifest in headers

Auth
Headers
receiveFileStreamDto11 fieldsobject
POST /api/v1/cross-domain/file-stream
curl --request POST \
--url 'http://localhost:8001/api/v1/cross-domain/file-stream' \
--header 'receiveFileStreamDto: {receiveFileStreamDto}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

500

Internal Server Error

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get the global cross-domain configuration for both sides

Auth
GET /api/v1/cross-domain/global-config
curl --get \
--url 'http://localhost:8001/api/v1/cross-domain/global-config'
Copy
Responses
200

OK

objectobject
lowside
highside
responseKeystring
responseMessagestring
Response
{
"lowside": "{}",
"highside": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Set global lowside configuration

Auth
Request Body
objectobject
highsideAddressstring
authorizationTokenstring
pairingSecretstring
enabledboolean
PUT /api/v1/cross-domain/global-config/lowside
curl --request PUT \
--url 'http://localhost:8001/api/v1/cross-domain/global-config/lowside' \
--data '{
"highsideAddress": "{string}",
"authorizationToken": "{string}",
"pairingSecret": "{string}",
"enabled": "{boolean}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Disable global lowside configuration

Auth
POST /api/v1/cross-domain/global-config/lowside/disable
curl --request POST \
--url 'http://localhost:8001/api/v1/cross-domain/global-config/lowside/disable'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Set global highside configuration

Auth
Request Body
objectobject
pushBehaviourinteger
enabledboolean
scanBeforeImportboolean
scanWorkflowIdstring
maxAllowedSeverity
blockOnSecretsboolean
scanTimeoutSeconds

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pollIntervalSeconds

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasPairingSecretboolean
pairingSecretIssuedAtdate-time
PUT /api/v1/cross-domain/global-config/highside
curl --request PUT \
--url 'http://localhost:8001/api/v1/cross-domain/global-config/highside' \
--data '{
"pushBehaviour": "{integer}",
"enabled": "{boolean}",
"scanBeforeImport": "{boolean}",
"scanWorkflowId": "{string}",
"maxAllowedSeverity": "{}",
"blockOnSecrets": "{boolean}",
"scanTimeoutSeconds": "{integer}",
"pollIntervalSeconds": "{integer}",
"hasPairingSecret": "{boolean}",
"pairingSecretIssuedAt": "{date-time}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Disable global highside configuration

Auth
POST /api/v1/cross-domain/global-config/highside/disable
curl --request POST \
--url 'http://localhost:8001/api/v1/cross-domain/global-config/highside/disable'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Generate a pairing secret for the global highside configuration

Auth
POST /api/v1/cross-domain/global-config/highside/pairing-secret
curl --request POST \
--url 'http://localhost:8001/api/v1/cross-domain/global-config/highside/pairing-secret'
Copy
Responses
200

OK

objectobject
pairingSecret
responseKeystring
responseMessagestring
400

Bad Request

404

Not Found

Response
{
"pairingSecret": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get cross-domain operation logs

Auth
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

sortBystring
sortOrderinteger
filterstring
searchstring
GET /api/v1/cross-domain/logs
curl --get \
--url 'http://localhost:8001/api/v1/cross-domain/logs' \
--data page={page} \
--data pageSize={pageSize} \
--data sortBy={sortBy} \
--data sortOrder={sortOrder} \
--data filter={filter} \
--data search={search}
Copy
Responses
200

OK

objectobject
logs14 fieldsarray[object]
hasNextPageboolean
hasPreviousPageboolean
responseKeystring
responseMessagestring
Response
{
"logs": [
{
"id": "{string}",
"transmissionId": "{string}",
"storageId": "{string}",
"step": "{integer}",
"status": "{integer}",
"timestamp": "{date-time}",
"storageName": "{string}",
"storage": "{}",
"lowsideRepositoryName": "{string}",
"highsideRepositoryName": "{string}",
"reference": "{string}",
"scanId": "{string}",
"fileId": "{string}",
"errorMessage": "{string}"
}
],
"hasNextPage": "{boolean}",
"hasPreviousPage": "{boolean}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Delete a cross-domain activity-log entry by transmission id

Auth
Path Params
transmissionIdstring
DELETE /api/v1/cross-domain/logs/{transmissionId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/cross-domain/logs/{transmissionId}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Receive a lowside configuration change notification

Auth
Headers
X-Transfer-Timestamp

pattern: ^-?(?:0|[1-9]\d*)$

X-Transfer-Signaturestring
Request Body
objectobject
storageNamestring
protocolTypeinteger
changeTypeinteger
POST /api/v1/cross-domain/lowside-configuration-notifications
curl --request POST \
--url 'http://localhost:8001/api/v1/cross-domain/lowside-configuration-notifications' \
--header 'X-Transfer-Timestamp: {X-Transfer-Timestamp}' \
--header 'X-Transfer-Signature: {X-Transfer-Signature}' \
--data '{
"storageName": "{string}",
"protocolType": "{integer}",
"changeType": "{integer}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get all cross-domain notifications

Auth
GET /api/v1/cross-domain/notifications
curl --get \
--url 'http://localhost:8001/api/v1/cross-domain/notifications'
Copy
Responses
200

OK

objectobject
notifications6 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"notifications": [
{
"id": "{string}",
"storageName": "{string}",
"protocolType": "{integer}",
"changeType": "{integer}",
"receivedAt": "{date-time}",
"acknowledged": "{boolean}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get a lowside configuration by storage ID

Auth
GET /api/v1/cross-domain/storage-config/lowside
curl --get \
--url 'http://localhost:8001/api/v1/cross-domain/storage-config/lowside'
Copy
Responses
200

OK

objectobject
configurations5 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"configurations": [
{
"id": "{string}",
"storageId": "{string}",
"storageName": "{string}",
"protocolType": "{integer}",
"valid": "{boolean}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Add a lowside configuration

Auth
Request Body
objectobject
storageIdstring
POST /api/v1/cross-domain/storage-config/lowside
curl --request POST \
--url 'http://localhost:8001/api/v1/cross-domain/storage-config/lowside' \
--data '{
"storageId": "{string}"
}'
Copy
Responses
200

OK

objectobject
configurationIdstring
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"configurationId": "{string}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Update a lowside configuration by ID

Auth
Path Params
idstring
Request Body
objectobject
storageIdstring
PUT /api/v1/cross-domain/storage-config/lowside/{id}
curl --request PUT \
--url 'http://localhost:8001/api/v1/cross-domain/storage-config/lowside/{id}' \
--data '{
"storageId": "{string}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Delete a lowside configuration by ID

Auth
Path Params
idstring
DELETE /api/v1/cross-domain/storage-config/lowside/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/cross-domain/storage-config/lowside/{id}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get a highside storage configuration by storage ID

Auth
GET /api/v1/cross-domain/storage-config/highside
curl --get \
--url 'http://localhost:8001/api/v1/cross-domain/storage-config/highside'
Copy
Responses
200

OK

objectobject
configurations6 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"configurations": [
{
"id": "{string}",
"storageId": "{string}",
"storageName": "{string}",
"lowsideStorageName": "{string}",
"lowsideProtocolType": "{integer}",
"valid": "{boolean}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Add a highside configuration

Auth
Request Body
objectobject
storageIdstring
notificationIdstring
POST /api/v1/cross-domain/storage-config/highside
curl --request POST \
--url 'http://localhost:8001/api/v1/cross-domain/storage-config/highside' \
--data '{
"storageId": "{string}",
"notificationId": "{string}"
}'
Copy
Responses
200

OK

objectobject
configurationIdstring
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"configurationId": "{string}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Update a highside configuration by ID

Auth
Path Params
idstring
Request Body
objectobject
storageIdstring
storageNamestring
lowsideStorageNamestring
PUT /api/v1/cross-domain/storage-config/highside/{id}
curl --request PUT \
--url 'http://localhost:8001/api/v1/cross-domain/storage-config/highside/{id}' \
--data '{
"storageId": "{string}",
"storageName": "{string}",
"lowsideStorageName": "{string}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Delete a highside configuration by ID

Auth
Path Params
idstring
DELETE /api/v1/cross-domain/storage-config/highside/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/cross-domain/storage-config/highside/{id}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get top-risky repositories across all connections

Auth
Query String
windowstring
count

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/dashboard/top-risky
curl --get \
--url 'http://localhost:8001/api/v1/dashboard/top-risky' \
--data window={window} \
--data count={count}
Copy
Responses
200

OK

arrayarray[object]
connectionIdstring
connectionNamestring
repositoryIdstring
repositoryNamestring
riskScore

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
400

Bad Request

500

Internal Server Error

Response
[
{
"connectionId": "{string}",
"connectionName": "{string}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"riskScore": "{integer}"
}
]
Copy

Export a CycloneDX report for repository

Auth
Path Params
repoIdstring
Query String
Referencestring
GET /api/v1/export/cyclonedx/{repoId}
curl --get \
--url 'http://localhost:8001/api/v1/export/cyclonedx/{repoId}' \
--data Reference={Reference}
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export a CycloneDX report for a specific file scan

Auth
Path Params
fileIdstring
GET /api/v1/export/cyclonedx/file/{fileId}
curl --get \
--url 'http://localhost:8001/api/v1/export/cyclonedx/file/{fileId}'
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export an SPDX report for a specific scan

Auth
Path Params
scanIdstring
Query String
formatstring
versionstring
GET /api/v1/export/spdx/{scanId}
curl --get \
--url 'http://localhost:8001/api/v1/export/spdx/{scanId}' \
--data format={format} \
--data version={version}
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export an SPDX report for a specific file scan

Auth
Path Params
fileIdstring
Query String
formatstring
versionstring
GET /api/v1/export/spdx/file/{fileId}
curl --get \
--url 'http://localhost:8001/api/v1/export/spdx/file/{fileId}' \
--data format={format} \
--data version={version}
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export a PDF report for all scans

Auth
Query String
Typearray
TimeFrameinteger
Vulnerabilitiesarray
LicenseRisksarray
Statusarray
TriggerEventarray
Workflowstring
Connectionstring
Secretsboolean
Threatsboolean
Searchstring
ConnectionTypeinteger
RepositoryIdstring
Latestboolean
GET /api/v1/export/pdf/all-scans
curl --get \
--url 'http://localhost:8001/api/v1/export/pdf/all-scans' \
--data Type={Type} \
--data TimeFrame={TimeFrame} \
--data Vulnerabilities={Vulnerabilities} \
--data LicenseRisks={LicenseRisks} \
--data Status={Status} \
--data TriggerEvent={TriggerEvent} \
--data Workflow={Workflow} \
--data Connection={Connection} \
--data Secrets={Secrets} \
--data Threats={Threats} \
--data Search={Search} \
--data ConnectionType={ConnectionType} \
--data RepositoryId={RepositoryId} \
--data Latest={Latest}
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export a PDF overview report for repository

Auth
Path Params
scanIdstring
GET /api/v1/export/pdf/overview/{scanId}
curl --get \
--url 'http://localhost:8001/api/v1/export/pdf/overview/{scanId}'
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export a PDF SBOM report for repository

Auth
Path Params
scanIdstring
GET /api/v1/export/pdf/sbom/{scanId}
curl --get \
--url 'http://localhost:8001/api/v1/export/pdf/sbom/{scanId}'
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export a PDF SBOM report for a specific batch of files

Auth
Path Params
fileIdstring
GET /api/v1/export/pdf/sbom/file/{fileId}
curl --get \
--url 'http://localhost:8001/api/v1/export/pdf/sbom/file/{fileId}'
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export a PDF SBOM report for repository that lists every package dependency as its own package

Auth
Path Params
scanIdstring
GET /api/v1/export/pdf/sbom/dependencies/{scanId}
curl --get \
--url 'http://localhost:8001/api/v1/export/pdf/sbom/dependencies/{scanId}'
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export a CSV report for repository

Auth
Path Params
scanIdstring
GET /api/v1/export/csv/sbom/{scanId}
curl --get \
--url 'http://localhost:8001/api/v1/export/csv/sbom/{scanId}'
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export a CSV report for a specific batch of files

Auth
Path Params
fileIdstring
GET /api/v1/export/csv/sbom/file/{fileId}
curl --get \
--url 'http://localhost:8001/api/v1/export/csv/sbom/file/{fileId}'
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

404

Not Found

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export a CSV report of all CVEs from latest scans

Auth
Query String
Severityarray
GET /api/v1/export/csv/cves
curl --get \
--url 'http://localhost:8001/api/v1/export/csv/cves' \
--data Severity={Severity}
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Export a CSV report of all packages from latest scans

Auth
GET /api/v1/export/csv/packages
curl --get \
--url 'http://localhost:8001/api/v1/export/csv/packages'
Copy
Responses
200

OK

objectobject
fileStreamfile
contentTypestring
fileDownloadNamestring
lastModifieddate-time
entityTag
enableRangeProcessingboolean
400

Bad Request

Response
{
"fileStream": "{file}",
"contentType": "{string}",
"fileDownloadName": "{string}",
"lastModified": "{date-time}",
"entityTag": "{}",
"enableRangeProcessing": "{boolean}"
}
Copy

Get all external loggers

Auth
GET /api/v1/externallogger
curl --get \
--url 'http://localhost:8001/api/v1/externallogger'
Copy
Responses
200

OK

No response body
Response
No response
Copy

Add an external logger

Auth
Request Body
objectobject
connectionSettings4 fieldsobject
POST /api/v1/externallogger
curl --request POST \
--url 'http://localhost:8001/api/v1/externallogger' \
--data '{
"connectionSettings": {
"serverAddress": "{string}",
"port": "{integer}",
"facility": "{integer}",
"format": "{integer}"
}
}'
Copy
Responses
200

OK

No response body
Response
No response
Copy

Update an external logger

Auth
Path Params
idstring
Request Body
objectobject
connectionSettings4 fieldsobject
PUT /api/v1/externallogger/{id}
curl --request PUT \
--url 'http://localhost:8001/api/v1/externallogger/{id}' \
--data '{
"connectionSettings": {
"serverAddress": "{string}",
"port": "{integer}",
"facility": "{integer}",
"format": "{integer}"
}
}'
Copy
Responses
200

OK

No response body
Response
No response
Copy

Delete an external logger

Auth
Path Params
idstring
DELETE /api/v1/externallogger/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/externallogger/{id}'
Copy
Responses
200

OK

No response body
Response
No response
Copy

Returns all global label keys

Auth
GET /api/v1/global-label-keys
curl --get \
--url 'http://localhost:8001/api/v1/global-label-keys'
Copy
Responses
200

OK

objectobject
globalKeys10 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"globalKeys": [
{
"id": "{string}",
"name": "{string}",
"description": "{string}",
"valueType": "{string}",
"options": [
"{array[string]...}"
],
"created": "{date-time}",
"updated": "{date-time}",
"tenantId": "{string}",
"createdAt": "{date-time}",
"lastUpdated": "{date-time}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Adds a new global label key

Auth
Request Body
objectobject
namestring
descriptionstring
valueTypestring
optionsarray[string]
POST /api/v1/global-label-keys
curl --request POST \
--url 'http://localhost:8001/api/v1/global-label-keys' \
--data '{
"name": "{string}",
"description": "{string}",
"valueType": "{string}",
"options": [
"{array[string]...}"
]
}'
Copy
Responses
200

OK

objectobject
globalKey
responseKeystring
responseMessagestring
Response
{
"globalKey": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Updates an global label key

Auth
Path Params
idstring
Request Body
objectobject
namestring
descriptionstring
valueTypestring
optionsarray[string]
PUT /api/v1/global-label-keys/{id}
curl --request PUT \
--url 'http://localhost:8001/api/v1/global-label-keys/{id}' \
--data '{
"name": "{string}",
"description": "{string}",
"valueType": "{string}",
"options": [
"{array[string]...}"
]
}'
Copy
Responses
200

OK

objectobject
globalKey
responseKeystring
responseMessagestring
Response
{
"globalKey": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Deletes an global label key

Auth
Path Params
idstring
DELETE /api/v1/global-label-keys/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/global-label-keys/{id}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Start a Scan Now job over one or more targets (each target carries its own StorageId, so a single job may mix protocols)

Auth
Request Body
objectobject
namestring
priority
workflowIdstring
referenceSelectionMode
targets4 fieldsarray[object]
POST /api/v1/jobs
curl --request POST \
--url 'http://localhost:8001/api/v1/jobs' \
--data '{
"name": "{string}",
"priority": "{}",
"workflowId": "{string}",
"referenceSelectionMode": "{}",
"targets": [
{
"protocolType": "{integer}",
"storageId": "{string}",
"repositoryId": "{string}",
"repositoryName": "{string}"
}
]
}'
Copy
Responses
200

OK

objectobject
jobIdsarray[string]
priorityinteger
enabledRepositoriesarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
207

Multi-Status

400

Bad Request

Response
{
"jobIds": [
"{array[string]...}"
],
"triggerType": "{}",
"priority": "{integer}",
"enabledRepositories": [
"{array[string]...}"
],
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

List jobs (paginated, queryable by trigger type)

Auth
Query String
TriggerTypearray

Enum: ScanNow,Scheduled,RealTime,DirectFile

Priorityarray
Statusarray
WorkflowIdarray
Searchstring
TimeFrameinteger
Typearray
ConnectionTypeinteger
Repositorystring
Servicestring
Vulnerabilitiesarray
LicenseRisksarray
Threatsboolean
Secretsboolean
SortBystring
SortDirstring
Page

pattern: ^-?(?:0|[1-9]\d*)$

PageSize

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/jobs
curl --get \
--url 'http://localhost:8001/api/v1/jobs' \
--data TriggerType={TriggerType} \
--data Priority={Priority} \
--data Status={Status} \
--data WorkflowId={WorkflowId} \
--data Search={Search} \
--data TimeFrame={TimeFrame} \
--data Type={Type} \
--data ConnectionType={ConnectionType} \
--data Repository={Repository} \
--data Service={Service} \
--data Vulnerabilities={Vulnerabilities} \
--data LicenseRisks={LicenseRisks} \
--data Threats={Threats} \
--data Secrets={Secrets} \
--data SortBy={SortBy} \
--data SortDir={SortDir} \
--data Page={Page} \
--data PageSize={PageSize}
Copy
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
jobs9 fieldsarray[object]
Response
{
"page": "{integer}",
"pageSize": "{integer}",
"totalCount": "{integer}",
"hasMoreItems": "{boolean}",
"jobs": [
{
"jobId": "{string}",
"name": "{string}",
"priority": "{integer}",
"triggerType": "{}",
"storage": {
"storageId": "{string}",
"storageName": "{string}",
"vendorType": "{string}",
"protocolType": "{string}",
"connection": "{string}",
"packageType": "{string}",
"organization": "{string}"
},
"repository": {
"repositoryId": "{string}",
"repositoryName": "{string}",
"repositoryType": "{string}",
"repositoryUrl": "{string}",
"repositoryReference": "{string}",
"repositoryMetadata": "{string}"
},
"scanInformation": "{}",
"scanStatus": "{}",
"metadata": "{}"
}
]
}
Copy

Bulk delete jobs (trigger-agnostic)

Auth
Request Body
objectobject
jobIdsarray[string]
DELETE /api/v1/jobs
curl --request DELETE \
--url 'http://localhost:8001/api/v1/jobs' \
--data '{
"jobIds": [
"{array[string]...}"
]
}'
Copy
Responses
200

OK

objectobject
deletedJobIdsarray[string]
failedJobIdsarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response
{
"deletedJobIds": [
"{array[string]...}"
],
"failedJobIds": [
"{array[string]...}"
],
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Start a Real-Time Protection job over one or more targets (each target carries its own StorageId)

Auth
Request Body
objectobject
namestring
priority
workflowIdstring
targets4 fieldsarray[object]
POST /api/v1/jobs/rtp
curl --request POST \
--url 'http://localhost:8001/api/v1/jobs/rtp' \
--data '{
"name": "{string}",
"priority": "{}",
"workflowId": "{string}",
"targets": [
{
"protocolType": "{integer}",
"storageId": "{string}",
"repositoryId": "{string}",
"repositoryName": "{string}"
}
]
}'
Copy
Responses
200

OK

objectobject
jobIdsarray[string]
priorityinteger
enabledRepositoriesarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
207

Multi-Status

400

Bad Request

Response
{
"jobIds": [
"{array[string]...}"
],
"triggerType": "{}",
"priority": "{integer}",
"enabledRepositories": [
"{array[string]...}"
],
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Create a scheduled job with a recurrence pattern

Auth
Request Body
objectobject
namestring
priority
workflowIdstring
referenceSelectionMode
recurrencePattern5 fieldsobject
targets4 fieldsarray[object]
POST /api/v1/jobs/scheduled
curl --request POST \
--url 'http://localhost:8001/api/v1/jobs/scheduled' \
--data '{
"name": "{string}",
"priority": "{}",
"workflowId": "{string}",
"referenceSelectionMode": "{}",
"recurrencePattern": {
"type": "{integer}",
"hourlyRecurrence": "{}",
"dailyRecurrence": "{}",
"weeklyRecurrence": "{}",
"monthlyRecurrence": "{}"
},
"targets": [
{
"protocolType": "{integer}",
"storageId": "{string}",
"repositoryId": "{string}",
"repositoryName": "{string}"
}
]
}'
Copy
Responses
200

OK

objectobject
jobIdsarray[string]
priorityinteger
nextRunTimedate-time
failedRepositoriesarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
207

Multi-Status

400

Bad Request

Response
{
"jobIds": [
"{array[string]...}"
],
"triggerType": "{}",
"priority": "{integer}",
"nextRunTime": "{date-time}",
"failedRepositories": [
"{array[string]...}"
],
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Delete all upcoming jobs

Auth
DELETE /api/v1/jobs/scheduled
curl --request DELETE \
--url 'http://localhost:8001/api/v1/jobs/scheduled'
Copy
Responses
200

OK

objectobject
deletedJobIdsarray[string]
failedJobIdsarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
207

Multi-Status

400

Bad Request

Response
{
"deletedJobIds": [
"{array[string]...}"
],
"failedJobIds": [
"{array[string]...}"
],
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Cancel a job (for RealTime jobs this disables RTP)

Auth
Path Params
idstring
POST /api/v1/jobs/{id}/cancel
curl --request POST \
--url 'http://localhost:8001/api/v1/jobs/{id}/cancel'
Copy
Responses
200

OK

objectobject
jobIdstring
statusstring
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
404

Not Found

Response
{
"jobId": "{string}",
"triggerType": "{}",
"status": "{string}",
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Get a single job by id

Auth
Path Params
idstring
GET /api/v1/jobs/{id}
curl --get \
--url 'http://localhost:8001/api/v1/jobs/{id}'
Copy
Responses
200

OK

objectobject
jobIdstring
namestring
priorityinteger
storage7 fieldsobject
repository6 fieldsobject
scanInformation
scanStatus
404

Not Found

Response
{
"jobId": "{string}",
"name": "{string}",
"priority": "{integer}",
"triggerType": "{}",
"storage": {
"storageId": "{string}",
"storageName": "{string}",
"vendorType": "{string}",
"protocolType": "{string}",
"connection": "{string}",
"packageType": "{string}",
"organization": "{string}"
},
"repository": {
"repositoryId": "{string}",
"repositoryName": "{string}",
"repositoryType": "{string}",
"repositoryUrl": "{string}",
"repositoryReference": "{string}",
"repositoryMetadata": "{string}"
},
"scanInformation": "{}",
"scanStatus": "{}",
"metadata": "{}"
}
Copy

Activate a license online

Auth
Request Body
objectobject
keystring
POST /api/v1/licenses/online
curl --request POST \
--url 'http://localhost:8001/api/v1/licenses/online' \
--data '{
"key": "{string}"
}'
Copy
Responses
200

OK

objectobject
resultinteger
responseMessagestring
400

Bad Request

Response
{
"result": "{integer}",
"responseMessage": "{string}"
}
Copy

Activate a license offline

Auth
Request Body
objectobject
LicenseContentfile
POST /api/v1/licenses/offline
curl --request POST \
--url 'http://localhost:8001/api/v1/licenses/offline' \
--form 'file=@{file}'
Copy
Responses
200

OK

objectobject
resultinteger
responseMessagestring
400

Bad Request

Response
{
"result": "{integer}",
"responseMessage": "{string}"
}
Copy

Remove licenses

Auth
DELETE /api/v1/licenses
curl --request DELETE \
--url 'http://localhost:8001/api/v1/licenses'
Copy
Responses
200

OK

objectobject
resultinteger
responseMessagestring
400

Bad Request

404

Not Found

Response
{
"result": "{integer}",
"responseMessage": "{string}"
}
Copy

Get licenses

Auth
GET /api/v1/licenses
curl --get \
--url 'http://localhost:8001/api/v1/licenses'
Copy
Responses
200

OK

objectobject
resultinteger
license
responseMessagestring
400

Bad Request

404

Not Found

Response
{
"result": "{integer}",
"license": "{}",
"responseMessage": "{string}"
}
Copy

Get current deployment Id for offline license activation

Auth
GET /api/v1/licenses/current-deployment-id
curl --get \
--url 'http://localhost:8001/api/v1/licenses/current-deployment-id'
Copy
Responses
200

OK

objectobject
resultinteger
currentDeploymentIdstring
responseMessagestring
400

Bad Request

Response
{
"result": "{integer}",
"currentDeploymentId": "{string}",
"responseMessage": "{string}"
}
Copy

Manage Opswat Central Management Ocm

Update an OCM instance

Auth
Request Body
objectobject
serverApistring
regCodestring
PUT /api/v1/ocm
curl --request PUT \
--url 'http://localhost:8001/api/v1/ocm' \
--data '{
"serverApi": "{string}",
"regCode": "{string}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Delete an OCM instance

Auth
DELETE /api/v1/ocm
curl --request DELETE \
--url 'http://localhost:8001/api/v1/ocm'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get an OCM instance

Auth
GET /api/v1/ocm
curl --get \
--url 'http://localhost:8001/api/v1/ocm'
Copy
Responses
200

OK

objectobject
ocmInformation
responseKeystring
responseMessagestring
Response
{
"ocmInformation": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get onboarding

Auth
GET /api/v1/onboarding
curl --get \
--url 'http://localhost:8001/api/v1/onboarding'
Copy
Responses
200

OK

objectobject
hasUserConfiguredboolean
hasLicenseConfiguredboolean
hasScanInstanceConfiguredboolean
hasConnectionConfiguredboolean
isCloudTypeboolean
isEulaAgreedboolean
isOnboardingDoneboolean
responseKeystring
responseMessagestring
Response
{
"hasUserConfigured": "{boolean}",
"hasLicenseConfigured": "{boolean}",
"hasScanInstanceConfigured": "{boolean}",
"hasConnectionConfigured": "{boolean}",
"isCloudType": "{boolean}",
"isEulaAgreed": "{boolean}",
"isOnboardingDone": "{boolean}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Complete onboarding

Auth
POST /api/v1/onboarding/complete
curl --request POST \
--url 'http://localhost:8001/api/v1/onboarding/complete'
Copy
Responses
200

OK

No response body
Response
No response
Copy

Agree to onboarding EULA

Auth
POST /api/v1/onboarding/accept-eula
curl --request POST \
--url 'http://localhost:8001/api/v1/onboarding/accept-eula'
Copy
Responses
200

OK

No response body
Response
No response
Copy

Retrieves a paginated, sortable list of packages

Auth
Query String
Namestring
Ecosystemstring
Versionstring
Vulnerabilitiesarray
LicenseRisksarray
Connectionstring
Repositorystring
Referencestring
ScanIdstring
StepSha256string
Searchstring
IncludeDirectFilesboolean
sortByinteger
sortDirinteger
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/packages
curl --get \
--url 'http://localhost:8001/api/v1/packages' \
--data Name={Name} \
--data Ecosystem={Ecosystem} \
--data Version={Version} \
--data Vulnerabilities={Vulnerabilities} \
--data LicenseRisks={LicenseRisks} \
--data Connection={Connection} \
--data Repository={Repository} \
--data Reference={Reference} \
--data ScanId={ScanId} \
--data StepSha256={StepSha256} \
--data Search={Search} \
--data IncludeDirectFiles={IncludeDirectFiles} \
--data sortBy={sortBy} \
--data sortDir={sortDir} \
--data page={page} \
--data pageSize={pageSize}
Copy
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
packages23 fieldsarray[object]
207

Multi-Status

401

Unauthorized

Response
{
"page": "{integer}",
"pageSize": "{integer}",
"totalCount": "{integer}",
"hasMoreItems": "{boolean}",
"packages": [
{
"id": "{string}",
"name": "{string}",
"version": "{string}",
"ecosystem": "{string}",
"archive": "{boolean}",
"executable": "{boolean}",
"uid": "{string}",
"packageType": "{string}",
"licenses": "{}",
"repositories": [
{
"connection": "{string}",
"repository": "{string}",
"repositoryId": "{string}",
"reference": "{string}",
"scanned": "{date-time}",
"scanIds": [
"{array[string]...}"
],
"stepSha256s": [
"{array[string]...}"
]
}
],
"directFiles": [
{
"fileName": "{string}",
"scanned": "{date-time}",
"scanResultId": "{string}"
}
],
"hashes": [
{
"sha256": "{string}",
"fileName": "{string}"
}
],
"vulnerabilities": [
{
"id": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"severity": "{integer}",
"source": "{string}",
"cwes": [
"{array[string]...}"
],
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"dependencies": [
{
"ecosystem": "{string}",
"group": "{string}",
"packageName": "{string}",
"packageVersion": "{string}",
"vulnerabilities": [
{
"id": "{string}",
"severity": "{string}",
"source": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"cwes": [
"{array[string]...}"
],
"type": "{string}",
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"vulnerabilityCounts": "{}"
}
],
"supplierName": "{string}",
"releaseDate": "{date-time}",
"labels": [
{
"key": "{string}",
"value": "{string}",
"valueType": "{string}",
"created": "{date-time}",
"updated": "{date-time}"
}
],
"latest": "{}",
"createdAt": "{date-time}",
"lastUpdated": "{date-time}",
"impact": "{integer}",
"dependencyImpact": "{integer}",
"recommendedVersion": "{string}"
}
]
}
Copy

Retrieves all versions of a specific package by its name and ecosystem

Auth
Query String
ecosystemstring
packageNamestring
GET /api/v1/packages/versions
curl --get \
--url 'http://localhost:8001/api/v1/packages/versions' \
--data ecosystem={ecosystem} \
--data packageName={packageName}
Copy
Responses
200

OK

objectobject
packageNamestring
ecosystemstring
versions6 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"packageName": "{string}",
"ecosystem": "{string}",
"versions": [
{
"version": "{string}",
"vulnerabilities": [
{
"id": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"severity": "{integer}",
"source": "{string}",
"cwes": [
"{array[string]...}"
],
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"supplierName": "{string}",
"releaseDate": "{date-time}",
"dependencies": [
{
"ecosystem": "{string}",
"group": "{string}",
"packageName": "{string}",
"packageVersion": "{string}",
"vulnerabilities": [
{
"id": "{string}",
"severity": "{string}",
"source": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"cwes": [
"{array[string]...}"
],
"type": "{string}",
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"vulnerabilityCounts": "{}"
}
],
"licenses": "{}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Retrieves a package by its internal database ID

Auth
Path Params
idstring
Query String
includeDirectFilesboolean

Default: false

GET /api/v1/packages/{id}
curl --get \
--url 'http://localhost:8001/api/v1/packages/{id}' \
--data includeDirectFiles={includeDirectFiles}
Copy
Responses
200

OK

objectobject
package
responseKeystring
responseMessagestring
Response
{
"package": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Retrieves a package by its universal package UID

Auth
Path Params
uidInB64string
GET /api/v1/packages/by-uid/{uidInB64}
curl --get \
--url 'http://localhost:8001/api/v1/packages/by-uid/{uidInB64}'
Copy
Responses
200

OK

objectobject
package
responseKeystring
responseMessagestring
Response
{
"package": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Retrieves CVEs associated with a specific package

Auth
Path Params
idstring
GET /api/v1/packages/{id}/cves
curl --get \
--url 'http://localhost:8001/api/v1/packages/{id}/cves'
Copy
Responses
200

OK

objectobject
cves8 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"cves": [
{
"id": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"severity": "{integer}",
"source": "{string}",
"cwes": [
"{array[string]...}"
],
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Retrieves the ecosystem-specific upgrade command for a package

Auth
Path Params
idstring
GET /api/v1/packages/{id}/update-instructions
curl --get \
--url 'http://localhost:8001/api/v1/packages/{id}/update-instructions'
Copy
Responses
200

OK

objectobject
packageIdstring
ecosystemstring
commandstring
messagestring
responseKeystring
responseMessagestring
401

Unauthorized

404

Not Found

500

Internal Server Error

Response
{
"packageId": "{string}",
"ecosystem": "{string}",
"command": "{string}",
"message": "{string}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Retrieves all labels for a specific package

Auth
Path Params
idstring
GET /api/v1/packages/{id}/labels
curl --get \
--url 'http://localhost:8001/api/v1/packages/{id}/labels'
Copy
Responses
200

OK

objectobject
labels5 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"labels": [
{
"Key": "{string}",
"Value": "{string}",
"ValueType": "{string}",
"Created": "{date-time}",
"Updated": "{date-time}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Adds a label to a package

Auth
Path Params
idstring
Request Body
objectobject
Keystring
Valuestring
ValueTypestring
Createddate-time
Updateddate-time
POST /api/v1/packages/{id}/labels
curl --request POST \
--url 'http://localhost:8001/api/v1/packages/{id}/labels' \
--data '{
"Key": "{string}",
"Value": "{string}",
"ValueType": "{string}",
"Created": "{date-time}",
"Updated": "{date-time}"
}'
Copy
Responses
200

OK

objectobject
label
responseKeystring
responseMessagestring
Response
{
"label": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Updates a label in a package

Auth
Path Params
idstring
keystring
Request Body
objectobject
valuestring
valueTypestring
PUT /api/v1/packages/{id}/labels/{key}
curl --request PUT \
--url 'http://localhost:8001/api/v1/packages/{id}/labels/{key}' \
--data '{
"value": "{string}",
"valueType": "{string}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Deletes a label from a package

Auth
Path Params
idstring
keystring
DELETE /api/v1/packages/{id}/labels/{key}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/packages/{id}/labels/{key}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Searches for packages by label key and optionally value

Auth
Query String
keystring
valuestring
GET /api/v1/packages/search/labels
curl --get \
--url 'http://localhost:8001/api/v1/packages/search/labels' \
--data key={key} \
--data value={value}
Copy
Responses
200

OK

objectobject
packages23 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"packages": [
{
"id": "{string}",
"name": "{string}",
"version": "{string}",
"ecosystem": "{string}",
"archive": "{boolean}",
"executable": "{boolean}",
"uid": "{string}",
"packageType": "{string}",
"licenses": "{}",
"repositories": [
{
"connection": "{string}",
"repository": "{string}",
"repositoryId": "{string}",
"reference": "{string}",
"scanned": "{date-time}",
"scanIds": [
"{array[string]...}"
],
"stepSha256s": [
"{array[string]...}"
]
}
],
"directFiles": [
{
"fileName": "{string}",
"scanned": "{date-time}",
"scanResultId": "{string}"
}
],
"hashes": [
{
"sha256": "{string}",
"fileName": "{string}"
}
],
"vulnerabilities": [
{
"id": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"severity": "{integer}",
"source": "{string}",
"cwes": [
"{array[string]...}"
],
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"dependencies": [
{
"ecosystem": "{string}",
"group": "{string}",
"packageName": "{string}",
"packageVersion": "{string}",
"vulnerabilities": [
{
"id": "{string}",
"severity": "{string}",
"source": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"cwes": [
"{array[string]...}"
],
"type": "{string}",
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"vulnerabilityCounts": "{}"
}
],
"supplierName": "{string}",
"releaseDate": "{date-time}",
"labels": [
{
"key": "{string}",
"value": "{string}",
"valueType": "{string}",
"created": "{date-time}",
"updated": "{date-time}"
}
],
"latest": "{}",
"createdAt": "{date-time}",
"lastUpdated": "{date-time}",
"impact": "{integer}",
"dependencyImpact": "{integer}",
"recommendedVersion": "{string}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Create a project

Auth
Request Body
objectobject
namestring

maxLength: 50

workflowIdsarray[string]
storageIdsarray[string]
POST /api/v1/projects
curl --request POST \
--url 'http://localhost:8001/api/v1/projects' \
--data '{
"name": "{string}",
"workflowIds": [
"{array[string]...}"
],
"storageIds": [
"{array[string]...}"
]
}'
Copy
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"project": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

List projects

Auth
GET /api/v1/projects
curl --get \
--url 'http://localhost:8001/api/v1/projects'
Copy
Responses
200

OK

arrayarray[object]
idstring
namestring
workflowIdsarray[string]
storageIdsarray[string]
Response
[
{
"id": "{string}",
"name": "{string}",
"workflowIds": [
"{array[string]...}"
],
"storageIds": [
"{array[string]...}"
]
}
]
Copy

Get a project by ID

Auth
Path Params
idstring
GET /api/v1/projects/{id}
curl --get \
--url 'http://localhost:8001/api/v1/projects/{id}'
Copy
Responses
200

OK

objectobject
idstring
namestring
workflowIdsarray[string]
storageIdsarray[string]
404

Not Found

Response
{
"id": "{string}",
"name": "{string}",
"workflowIds": [
"{array[string]...}"
],
"storageIds": [
"{array[string]...}"
]
}
Copy

Update a project

Auth
Path Params
idstring
Request Body
objectobject
namestring

maxLength: 50

PUT /api/v1/projects/{id}
curl --request PUT \
--url 'http://localhost:8001/api/v1/projects/{id}' \
--data '{
"name": "{string}"
}'
Copy
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response
{
"project": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Delete a project

Auth
Path Params
idstring
DELETE /api/v1/projects/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/projects/{id}'
Copy
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response
{
"project": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Attach workflows to a project

Auth
Path Params
idstring
Request Body
objectobject
idsarray[string]
POST /api/v1/projects/{id}/workflows/attach
curl --request POST \
--url 'http://localhost:8001/api/v1/projects/{id}/workflows/attach' \
--data '{
"ids": [
"{array[string]...}"
]
}'
Copy
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response
{
"project": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Detach workflows from a project

Auth
Path Params
idstring
Request Body
objectobject
idsarray[string]
POST /api/v1/projects/{id}/workflows/detach
curl --request POST \
--url 'http://localhost:8001/api/v1/projects/{id}/workflows/detach' \
--data '{
"ids": [
"{array[string]...}"
]
}'
Copy
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response
{
"project": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Attach connections (services) to a project

Auth
Path Params
idstring
Request Body
objectobject
idsarray[string]
POST /api/v1/projects/{id}/storages/attach
curl --request POST \
--url 'http://localhost:8001/api/v1/projects/{id}/storages/attach' \
--data '{
"ids": [
"{array[string]...}"
]
}'
Copy
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response
{
"project": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Detach connections (services) from a project

Auth
Path Params
idstring
Request Body
objectobject
idsarray[string]
POST /api/v1/projects/{id}/storages/detach
curl --request POST \
--url 'http://localhost:8001/api/v1/projects/{id}/storages/detach' \
--data '{
"ids": [
"{array[string]...}"
]
}'
Copy
Responses
200

OK

objectobject
project
responseKeystring
responseMessagestring
404

Not Found

Response
{
"project": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Enable real-time protection for multiple repositories

Auth
Path Params
storageIdstring
Request Body
objectobject
repositoriesarray[object]
repositoryIdstring
repositoryNamestring
connectionstring
workflowIdstring
POST /api/v1/realtime/{storageId}/enable
curl --request POST \
--url 'http://localhost:8001/api/v1/realtime/{storageId}/enable' \
--data '{
"repositories": [
{
"repositoryId": "{string}",
"repositoryName": "{string}"
}
],
"connection": "{string}",
"workflowId": "{string}"
}'
Copy
Responses
207

Multi-Status

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

409

Conflict

Response
{
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Disable real-time protection for connection

Auth
Path Params
storageIdstring
PATCH /api/v1/realtime/{storageId}/disable
curl --request PATCH \
--url 'http://localhost:8001/api/v1/realtime/{storageId}/disable'
Copy
Responses
200

OK

No response body
Response
No response
Copy

Disable real-time protection for repository

Auth
Path Params
storageIdstring
repositoryIdstring
PATCH /api/v1/realtime/{storageId}/{repositoryId}/disable
curl --request PATCH \
--url 'http://localhost:8001/api/v1/realtime/{storageId}/{repositoryId}/disable'
Copy
Responses
200

OK

No response body
Response
No response
Copy

List connections with real-time protection enabled

Auth
GET /api/v1/realtime
curl --get \
--url 'http://localhost:8001/api/v1/realtime'
Copy
Responses
200

OK

objectobject
storages4 fieldsarray[object]
Response
{
"storages": [
{
"id": "{string}",
"name": "{string}",
"storageType": {
"name": "{string}",
"categoryType": "{integer}",
"protocolType": "{integer}",
"vendorType": "{integer}"
},
"storageStatus": {
"message": "{string}",
"statusType": "{integer}"
}
}
]
}
Copy

List ongoing real-time protection scans for connection

Auth
Path Params
storageIdstring
GET /api/v1/realtime/{storageId}
curl --get \
--url 'http://localhost:8001/api/v1/realtime/{storageId}'
Copy
Responses
200

OK

objectobject
storageIdstring
realTimeScans5 fieldsarray[object]
scanInformation
Response
{
"storageId": "{string}",
"realTimeScans": [
{
"scanId": "{string}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"scanningState": "{integer}",
"workflowId": "{string}"
}
],
"scanInformation": "{}"
}
Copy

Delete real-time scan protection for connection

Auth
Path Params
storageIdstring
Query String
forceDeleteboolean

Default: false

DELETE /api/v1/realtime/{storageId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/realtime/{storageId}' \
--data forceDelete={forceDelete}
Copy
Responses
200

OK

No response body
Response
No response
Copy

Delete real-time scan protection for repository

Auth
Path Params
storageIdstring
repositoryIdstring
Query String
forceDeleteboolean

Default: false

DELETE /api/v1/realtime/{storageId}/{repositoryId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/realtime/{storageId}/{repositoryId}' \
--data forceDelete={forceDelete}
Copy
Responses
200

OK

No response body
Response
No response
Copy

Add a scan configuration

Auth
Request Body
objectobject
namestring

maxLength: 50

minLength: 3

scanPoolIdstring
rulesarray[string]
userAgentstring
POST /api/v1/scan-configurations
curl --request POST \
--url 'http://localhost:8001/api/v1/scan-configurations' \
--data '{
"name": "{string}",
"scanPoolId": "{string}",
"rules": [
"{array[string]...}"
],
"userAgent": "{string}"
}'
Copy
Responses
200

OK

objectobject
idstring
scanPoolIdstring
rulesarray[string]
typeinteger
namestring
scanPool5 fieldsobject
userAgentstring
filters5 fieldsobject
400

Bad Request

502

Bad Gateway

Response
{
"id": "{string}",
"scanPoolId": "{string}",
"rules": [
"{array[string]...}"
],
"type": "{integer}",
"name": "{string}",
"scanPool": {
"id": "{string}",
"name": "{string}",
"scanPoolType": "{integer}",
"isDefault": "{boolean}",
"scanInstances": [
{
"id": "{string}",
"scanPoolId": "{string}",
"url": "{string}",
"apiKey": "{string}",
"timeout": "{string}"
}
]
},
"userAgent": "{string}",
"filters": {
"id": "{string}",
"minimumSize": "{integer}",
"maximumSize": "{integer}",
"minimumDateTime": "{date-time}",
"maximumDateTime": "{date-time}"
}
}
Copy

Get all scan configurations

Auth
GET /api/v1/scan-configurations
curl --get \
--url 'http://localhost:8001/api/v1/scan-configurations'
Copy
Responses
200

OK

objectobject
Workflows8 fieldsarray[object]

Because it belongs to a response, if GetMultipleScanConfiguration breaks, we won't have ScanConfigurations.

resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response
{
"Workflows": [
{
"id": "{string}",
"scanPoolId": "{string}",
"rules": [
"{array[string]...}"
],
"type": "{integer}",
"name": "{string}",
"scanPool": {
"id": "{string}",
"name": "{string}",
"scanPoolType": "{integer}",
"isDefault": "{boolean}",
"scanInstances": [
{
"id": "{string}",
"scanPoolId": "{string}",
"url": "{string}",
"apiKey": "{string}",
"timeout": "{string}"
}
]
},
"userAgent": "{string}",
"filters": {
"id": "{string}",
"minimumSize": "{integer}",
"maximumSize": "{integer}",
"minimumDateTime": "{date-time}",
"maximumDateTime": "{date-time}"
}
}
],
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Update a scan configuration

Auth
Path Params
idstring
Request Body
objectobject
namestring

maxLength: 50

minLength: 3

scanPoolIdstring
rulesarray[string]
userAgentstring
PUT /api/v1/scan-configurations/{id}
curl --request PUT \
--url 'http://localhost:8001/api/v1/scan-configurations/{id}' \
--data '{
"name": "{string}",
"scanPoolId": "{string}",
"rules": [
"{array[string]...}"
],
"userAgent": "{string}"
}'
Copy
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response
{
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Delete a scan configuration

Auth
Path Params
idstring
DELETE /api/v1/scan-configurations/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/scan-configurations/{id}'
Copy
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response
{
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Get a scan configuration by ID

Auth
Path Params
idstring
GET /api/v1/scan-configurations/{id}
curl --get \
--url 'http://localhost:8001/api/v1/scan-configurations/{id}'
Copy
Responses
200

OK

objectobject
Workflow
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response
{
"Workflow": "{}",
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Get all scan configurations by scan pool ID

Auth
Path Params
idstring
GET /api/v1/scan-configurations/scan-pools/{id}
curl --get \
--url 'http://localhost:8001/api/v1/scan-configurations/scan-pools/{id}'
Copy
Responses
200

OK

objectobject
Workflows8 fieldsarray[object]

Because it belongs to a response, if GetMultipleScanConfiguration breaks, we won't have ScanConfigurations.

resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response
{
"Workflows": [
{
"id": "{string}",
"scanPoolId": "{string}",
"rules": [
"{array[string]...}"
],
"type": "{integer}",
"name": "{string}",
"scanPool": {
"id": "{string}",
"name": "{string}",
"scanPoolType": "{integer}",
"isDefault": "{boolean}",
"scanInstances": [
{
"id": "{string}",
"scanPoolId": "{string}",
"url": "{string}",
"apiKey": "{string}",
"timeout": "{string}"
}
]
},
"userAgent": "{string}",
"filters": {
"id": "{string}",
"minimumSize": "{integer}",
"maximumSize": "{integer}",
"minimumDateTime": "{date-time}",
"maximumDateTime": "{date-time}"
}
}
],
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Add a new scan instance

Auth
Request Body
objectobject
scanPoolIdstring
urlstring
apiKeystring
timeoutstring

pattern: ^-?(\d+\.)?\d{2}:\d{2}:\d{2}(\.\d{1,7})?$

scanInstanceTypeinteger
POST /api/v1/scan-instances
curl --request POST \
--url 'http://localhost:8001/api/v1/scan-instances' \
--data '{
"scanPoolId": "{string}",
"url": "{string}",
"apiKey": "{string}",
"timeout": "{string}",
"scanInstanceType": "{integer}"
}'
Copy
Responses
200

OK

objectobject
scanInstanceIdstring
400

Bad Request

404

Not Found

500

Internal Server Error

Response
{
"scanInstanceId": "{string}"
}
Copy

Delete a scan instance

Auth
Path Params
idstring
DELETE /api/v1/scan-instances/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/scan-instances/{id}'
Copy
Responses
200

OK

No response body
400

Bad Request

404

Not Found

500

Internal Server Error

Response
No response
Copy

Get a scan instance by ID

Auth
Path Params
idstring
GET /api/v1/scan-instances/{id}
curl --get \
--url 'http://localhost:8001/api/v1/scan-instances/{id}'
Copy
Responses
200

OK

objectobject
idstring
scanPoolIdstring
urlstring
apiKeystring
timeoutstring

pattern: ^-?(\d+\.)?\d{2}:\d{2}:\d{2}(\.\d{1,7})?$

400

Bad Request

404

Not Found

500

Internal Server Error

Response
{
"id": "{string}",
"scanPoolId": "{string}",
"url": "{string}",
"apiKey": "{string}",
"timeout": "{string}"
}
Copy

Update a scan instance

Auth
Path Params
idstring
Request Body
objectobject
urlstring
apiKeystring
timeoutstring

pattern: ^-?(\d+\.)?\d{2}:\d{2}:\d{2}(\.\d{1,7})?$

PUT /api/v1/scan-instances/{id}
curl --request PUT \
--url 'http://localhost:8001/api/v1/scan-instances/{id}' \
--data '{
"url": "{string}",
"apiKey": "{string}",
"timeout": "{string}"
}'
Copy
Responses
200

OK

No response body
400

Bad Request

404

Not Found

500

Internal Server Error

Response
No response
Copy

Add a new scan pool

Auth
Request Body
objectobject
namestring
scanPoolTypeinteger
POST /api/v1/scan-pools
curl --request POST \
--url 'http://localhost:8001/api/v1/scan-pools' \
--data '{
"name": "{string}",
"scanPoolType": "{integer}"
}'
Copy
Responses
200

OK

objectobject
scanPoolIdstring
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response
{
"scanPoolId": "{string}",
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Get scan pools

Auth
GET /api/v1/scan-pools
curl --get \
--url 'http://localhost:8001/api/v1/scan-pools'
Copy
Responses
200

OK

objectobject
scanPools5 fieldsarray[object]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response
{
"scanPools": [
{
"id": "{string}",
"name": "{string}",
"scanPoolType": "{integer}",
"isDefault": "{boolean}",
"scanInstances": [
{
"id": "{string}",
"scanPoolId": "{string}",
"url": "{string}",
"apiKey": "{string}",
"timeout": "{string}"
}
]
}
],
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Delete a scan pool

Auth
Path Params
idstring
DELETE /api/v1/scan-pools/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/scan-pools/{id}'
Copy
Responses
200

OK

No response body
400

Bad Request

404

Not Found

500

Internal Server Error

Response
No response
Copy

Get a scan pool by ID

Auth
Path Params
idstring
GET /api/v1/scan-pools/{id}
curl --get \
--url 'http://localhost:8001/api/v1/scan-pools/{id}'
Copy
Responses
200

OK

objectobject
scanPool
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response
{
"scanPool": "{}",
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Update an existing scan pool

Auth
Path Params
idstring
Request Body
objectobject
namestring
PUT /api/v1/scan-pools/{id}
curl --request PUT \
--url 'http://localhost:8001/api/v1/scan-pools/{id}' \
--data '{
"name": "{string}"
}'
Copy
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

Response
{
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Get all rules from a scan pool

Auth
Path Params
idstring
GET /api/v1/scan-pools/{id}/rules
curl --get \
--url 'http://localhost:8001/api/v1/scan-pools/{id}/rules'
Copy
Responses
200

OK

arrayarray[object]
namestring
user_agentsarray[string]
400

Bad Request

Response
[
{
"name": "{string}",
"user_agents": [
"{array[string]...}"
]
}
]
Copy

Add or start a scan

Auth
Request Body
objectobject
storageIdstring
storageNamestring
scanTypeinteger
workflowIdstring
repositoryIdstring
repositoryNamestring
protocolType
repositoryReferencesarray[string]
organizationstring
connectionstring
packageTypestring
repositoryTypestring
POST /api/v1/scans
curl --request POST \
--url 'http://localhost:8001/api/v1/scans' \
--data '{
"storageId": "{string}",
"storageName": "{string}",
"scanType": "{integer}",
"workflowId": "{string}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"protocolType": "{}",
"repositoryReferences": [
"{array[string]...}"
],
"organization": "{string}",
"connection": "{string}",
"packageType": "{string}",
"repositoryType": "{string}"
}'
Copy
Responses
200

OK

objectobject
scanIdsarray[string]
referencesUsedForScanningarray[string]
protocolType
repositoryIdstring
repositoryNamestring
serviceIdstring
storageNamestring
workflowIdstring
workflowNamestring
triggerEventstring
triggerBystring
responseKeystring
responseMessagestring
Response
{
"scanIds": [
"{array[string]...}"
],
"referencesUsedForScanning": [
"{array[string]...}"
],
"protocolType": "{}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"serviceId": "{string}",
"storageName": "{string}",
"workflowId": "{string}",
"workflowName": "{string}",
"triggerEvent": "{string}",
"triggerBy": "{string}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Enumerate scan results

Auth
Query String
Typearray
TimeFrameinteger
Vulnerabilitiesarray
LicenseRisksarray
Statusarray
TriggerEventarray
Workflowstring
Connectionstring
Secretsboolean
Threatsboolean
Searchstring
ConnectionTypeinteger
RepositoryIdstring
Latestboolean
GET /api/v1/scans
curl --get \
--url 'http://localhost:8001/api/v1/scans' \
--data Type={Type} \
--data TimeFrame={TimeFrame} \
--data Vulnerabilities={Vulnerabilities} \
--data LicenseRisks={LicenseRisks} \
--data Status={Status} \
--data TriggerEvent={TriggerEvent} \
--data Workflow={Workflow} \
--data Connection={Connection} \
--data Secrets={Secrets} \
--data Threats={Threats} \
--data Search={Search} \
--data ConnectionType={ConnectionType} \
--data RepositoryId={RepositoryId} \
--data Latest={Latest}
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Delete multiple scans by their scan IDs

Auth
Request Body
arrayarray[string]
DELETE /api/v1/scans
curl --request DELETE \
--url 'http://localhost:8001/api/v1/scans' \
--data '[
"{array[string]...}"
]'
Copy
Responses
200

OK

objectobject
notFoundScanIdsarray[string]
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
207

Multi-Status

400

Bad Request

404

Not Found

500

Internal Server Error

Response
{
"notFoundScanIds": [
"{array[string]...}"
],
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Upload and scan a file immediately

Uploads and scans files immediately. Optional 'jobName' labels the scan; if omitted, a name is generated automatically.

Auth
Request Body
objectobject
filesarray[string]
workflowIdstring
metadatastring
jobNamestring
POST /api/v1/scans/direct
curl --request POST \
--url 'http://localhost:8001/api/v1/scans/direct' \
--form 'file=@{file}'
Copy
Responses
200

OK

objectobject
scanIdsarray[string]
referencesUsedForScanningarray[string]
protocolType
repositoryIdstring
repositoryNamestring
serviceIdstring
storageNamestring
workflowIdstring
workflowNamestring
triggerEventstring
triggerBystring
responseKeystring
responseMessagestring
Response
{
"scanIds": [
"{array[string]...}"
],
"referencesUsedForScanning": [
"{array[string]...}"
],
"protocolType": "{}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"serviceId": "{string}",
"storageName": "{string}",
"workflowId": "{string}",
"workflowName": "{string}",
"triggerEvent": "{string}",
"triggerBy": "{string}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Stop a scan

Auth
Path Params
idstring
POST /api/v1/scans/{id}
curl --request POST \
--url 'http://localhost:8001/api/v1/scans/{id}'
Copy
Responses
200

OK

objectobject
statusCode

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
Response
{
"statusCode": "{integer}"
}
Copy

Get scan results by scan ID

Auth
Path Params
idstring
GET /api/v1/scans/{id}
curl --get \
--url 'http://localhost:8001/api/v1/scans/{id}'
Copy
Responses
200

OK

objectobject
serviceIdstring
repositoryIdstring
repositoryNamestring
repositoryTypestring
referenceUsedForScanningstring
scanIdstring
protocolTypeinteger
connectionstring
packageTypestring
organizationstring
startTimedate-time
stopTimedate-time
durationstring

pattern: ^-?(\d+\.)?\d{2}:\d{2}:\d{2}(\.\d{1,7})?$

vulnerabilityIssues5 fieldsobject
scanStatusinteger
discoveryStatusinteger
errorsarray[string]
blockedLicensesCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
infectedFiles

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
filesWithSecrets

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
404

Not Found

Response
{
"serviceId": "{string}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"repositoryType": "{string}",
"referenceUsedForScanning": "{string}",
"scanId": "{string}",
"protocolType": "{integer}",
"connection": "{string}",
"packageType": "{string}",
"organization": "{string}",
"startTime": "{date-time}",
"stopTime": "{date-time}",
"duration": "{string}",
"vulnerabilityIssues": {
"critical": "{integer}",
"high": "{integer}",
"medium": "{integer}",
"low": "{integer}",
"unknown": "{integer}"
},
"scanStatus": "{integer}",
"discoveryStatus": "{integer}",
"errors": [
"{array[string]...}"
],
"blockedLicensesCount": "{integer}",
"infectedFiles": "{integer}",
"filesWithSecrets": "{integer}"
}
Copy

Enumerate all latest scan results

Auth
Query String
Typearray
TimeFrameinteger
Vulnerabilitiesarray
LicenseRisksarray
Statusarray
TriggerEventarray
Workflowstring
Connectionstring
Secretsboolean
Threatsboolean
Searchstring
ConnectionTypeinteger
RepositoryIdstring
Latestboolean
GET /api/v1/scans/latest
curl --get \
--url 'http://localhost:8001/api/v1/scans/latest' \
--data Type={Type} \
--data TimeFrame={TimeFrame} \
--data Vulnerabilities={Vulnerabilities} \
--data LicenseRisks={LicenseRisks} \
--data Status={Status} \
--data TriggerEvent={TriggerEvent} \
--data Workflow={Workflow} \
--data Connection={Connection} \
--data Secrets={Secrets} \
--data Threats={Threats} \
--data Search={Search} \
--data ConnectionType={ConnectionType} \
--data RepositoryId={RepositoryId} \
--data Latest={Latest}
Copy
Responses
200

OK

arrayarray[object]
scanIdstring
repository7 fieldsobject
scanInformation12 fieldsobject
scanStatus3 fieldsobject
metadatastring
404

Not Found

Response
[
{
"scanId": "{string}",
"repository": {
"connectionId": "{string}",
"connectionName": "{string}",
"protocolType": "{integer}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"repositoryReference": "{string}",
"repositoryMetadata": "{string}"
},
"scanInformation": {
"malware": "{boolean}",
"secret": "{boolean}",
"vulnerabilityIssues": {
"critical": "{integer}",
"high": "{integer}",
"medium": "{integer}",
"low": "{integer}",
"unknown": "{integer}"
},
"licenses": {
"blockedLicensesCount": "{integer}",
"allowed": [
{
"id": "{string}",
"url": "{string}",
"category": "{string}",
"usageRestriction": "{}"
}
],
"blocked": [
{
"id": "{string}",
"url": "{string}",
"category": "{string}",
"usageRestriction": "{}"
}
]
},
"workflow": {
"workflowId": "{string}",
"workflowName": "{string}",
"workflowIsDeleted": "{boolean}",
"remediations": [
{
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
}
]
},
"package": {
"totalPackages": "{integer}",
"vulnerablePackages": "{integer}"
},
"riskScore": "{integer}",
"riskBreakdown": "{}",
"scannedOn": "{date-time}",
"stopTime": "{date-time}",
"triggerEvent": "{string}",
"errors": [
"{array[string]...}"
]
},
"scanStatus": {
"scanningState": "{string}",
"uploadProgress": "{integer}",
"scanProgress": "{integer}"
},
"metadata": "{string}"
}
]
Copy

Enumerate all latest scan results by service ID

Auth
Path Params
serviceIdstring
Query String
Typearray
TimeFrameinteger
Vulnerabilitiesarray
LicenseRisksarray
Statusarray
TriggerEventarray
Workflowstring
Connectionstring
Secretsboolean
Threatsboolean
Searchstring
ConnectionTypeinteger
RepositoryIdstring
Latestboolean
GET /api/v1/scans/{serviceId}/latest
curl --get \
--url 'http://localhost:8001/api/v1/scans/{serviceId}/latest' \
--data Type={Type} \
--data TimeFrame={TimeFrame} \
--data Vulnerabilities={Vulnerabilities} \
--data LicenseRisks={LicenseRisks} \
--data Status={Status} \
--data TriggerEvent={TriggerEvent} \
--data Workflow={Workflow} \
--data Connection={Connection} \
--data Secrets={Secrets} \
--data Threats={Threats} \
--data Search={Search} \
--data ConnectionType={ConnectionType} \
--data RepositoryId={RepositoryId} \
--data Latest={Latest}
Copy
Responses
200

OK

objectobject
scanIdstring
repository7 fieldsobject
scanInformation12 fieldsobject
scanStatus3 fieldsobject
metadatastring
Response
{
"scanId": "{string}",
"repository": {
"connectionId": "{string}",
"connectionName": "{string}",
"protocolType": "{integer}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"repositoryReference": "{string}",
"repositoryMetadata": "{string}"
},
"scanInformation": {
"malware": "{boolean}",
"secret": "{boolean}",
"vulnerabilityIssues": {
"critical": "{integer}",
"high": "{integer}",
"medium": "{integer}",
"low": "{integer}",
"unknown": "{integer}"
},
"licenses": {
"blockedLicensesCount": "{integer}",
"allowed": [
{
"id": "{string}",
"url": "{string}",
"category": "{string}",
"usageRestriction": "{}"
}
],
"blocked": [
{
"id": "{string}",
"url": "{string}",
"category": "{string}",
"usageRestriction": "{}"
}
]
},
"workflow": {
"workflowId": "{string}",
"workflowName": "{string}",
"workflowIsDeleted": "{boolean}",
"remediations": [
{
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
}
]
},
"package": {
"totalPackages": "{integer}",
"vulnerablePackages": "{integer}"
},
"riskScore": "{integer}",
"riskBreakdown": "{}",
"scannedOn": "{date-time}",
"stopTime": "{date-time}",
"triggerEvent": "{string}",
"errors": [
"{array[string]...}"
]
},
"scanStatus": {
"scanningState": "{string}",
"uploadProgress": "{integer}",
"scanProgress": "{integer}"
},
"metadata": "{string}"
}
Copy

Get scan overview by scan ID

Auth
Path Params
idstring
GET /api/v1/scans/{id}/overview
curl --get \
--url 'http://localhost:8001/api/v1/scans/{id}/overview'
Copy
Responses
200

OK

arrayarray[object]
scanIdstring
repository7 fieldsobject
scanInformation12 fieldsobject
scanStatus3 fieldsobject
metadatastring
Response
[
{
"scanId": "{string}",
"repository": {
"connectionId": "{string}",
"connectionName": "{string}",
"protocolType": "{integer}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"repositoryReference": "{string}",
"repositoryMetadata": "{string}"
},
"scanInformation": {
"malware": "{boolean}",
"secret": "{boolean}",
"vulnerabilityIssues": {
"critical": "{integer}",
"high": "{integer}",
"medium": "{integer}",
"low": "{integer}",
"unknown": "{integer}"
},
"licenses": {
"blockedLicensesCount": "{integer}",
"allowed": [
{
"id": "{string}",
"url": "{string}",
"category": "{string}",
"usageRestriction": "{}"
}
],
"blocked": [
{
"id": "{string}",
"url": "{string}",
"category": "{string}",
"usageRestriction": "{}"
}
]
},
"workflow": {
"workflowId": "{string}",
"workflowName": "{string}",
"workflowIsDeleted": "{boolean}",
"remediations": [
{
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
}
]
},
"package": {
"totalPackages": "{integer}",
"vulnerablePackages": "{integer}"
},
"riskScore": "{integer}",
"riskBreakdown": "{}",
"scannedOn": "{date-time}",
"stopTime": "{date-time}",
"triggerEvent": "{string}",
"errors": [
"{array[string]...}"
]
},
"scanStatus": {
"scanningState": "{string}",
"uploadProgress": "{integer}",
"scanProgress": "{integer}"
},
"metadata": "{string}"
}
]
Copy

Enumerate all scan results by repository ID

Auth
Path Params
serviceIdstring
repositoryIdstring
GET /api/v1/scans/{serviceId}/{repositoryId}
curl --get \
--url 'http://localhost:8001/api/v1/scans/{serviceId}/{repositoryId}'
Copy
Responses
200

OK

arrayarray[object]
scanIdstring
repository7 fieldsobject
scanInformation12 fieldsobject
scanStatus3 fieldsobject
metadatastring
Response
[
{
"scanId": "{string}",
"repository": {
"connectionId": "{string}",
"connectionName": "{string}",
"protocolType": "{integer}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"repositoryReference": "{string}",
"repositoryMetadata": "{string}"
},
"scanInformation": {
"malware": "{boolean}",
"secret": "{boolean}",
"vulnerabilityIssues": {
"critical": "{integer}",
"high": "{integer}",
"medium": "{integer}",
"low": "{integer}",
"unknown": "{integer}"
},
"licenses": {
"blockedLicensesCount": "{integer}",
"allowed": [
{
"id": "{string}",
"url": "{string}",
"category": "{string}",
"usageRestriction": "{}"
}
],
"blocked": [
{
"id": "{string}",
"url": "{string}",
"category": "{string}",
"usageRestriction": "{}"
}
]
},
"workflow": {
"workflowId": "{string}",
"workflowName": "{string}",
"workflowIsDeleted": "{boolean}",
"remediations": [
{
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
}
]
},
"package": {
"totalPackages": "{integer}",
"vulnerablePackages": "{integer}"
},
"riskScore": "{integer}",
"riskBreakdown": "{}",
"scannedOn": "{date-time}",
"stopTime": "{date-time}",
"triggerEvent": "{string}",
"errors": [
"{array[string]...}"
]
},
"scanStatus": {
"scanningState": "{string}",
"uploadProgress": "{integer}",
"scanProgress": "{integer}"
},
"metadata": "{string}"
}
]
Copy

Enumerate all scan schedules

Auth
GET /api/v1/scans/schedules
curl --get \
--url 'http://localhost:8001/api/v1/scans/schedules'
Copy
Responses
200

OK

arrayarray[object]
idstring
workflowIdstring
storageIdstring
userIdstring
namestring
priorityinteger
createdAtdate-time
lastUpdateddate-time
lastScanTimedate-time
nextScanTimedate-time
recurrenceTypeinteger
startDatedate-time
timeToStartdate-time
everyNumberOfHours

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
everyNumberOfDays

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
everyNumberOfWeeks

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
everyNumberOfMonths

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
daysOfWeekarray[integer]
dayOfMonth

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
workflow
scansarray[object]
Response
[
{
"id": "{string}",
"workflowId": "{string}",
"storageId": "{string}",
"userId": "{string}",
"name": "{string}",
"priority": "{integer}",
"createdAt": "{date-time}",
"lastUpdated": "{date-time}",
"lastScanTime": "{date-time}",
"nextScanTime": "{date-time}",
"recurrenceType": "{integer}",
"startDate": "{date-time}",
"timeToStart": "{date-time}",
"everyNumberOfHours": "{integer}",
"everyNumberOfDays": "{integer}",
"everyNumberOfWeeks": "{integer}",
"everyNumberOfMonths": "{integer}",
"daysOfWeek": [
"{array[integer]...}"
],
"dayOfMonth": "{integer}",
"workflow": "{}",
"scans": [
{}
]
}
]
Copy

Enumerate all CVEs across scanned packages

Auth
Query String
severitiesstring
searchstring
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/scans/cves
curl --get \
--url 'http://localhost:8001/api/v1/scans/cves' \
--data severities={severities} \
--data search={search} \
--data page={page} \
--data pageSize={pageSize}
Copy
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
cves6 fieldsarray[object]
400

Bad Request

401

Unauthorized

500

Internal Server Error

Response
{
"page": "{integer}",
"pageSize": "{integer}",
"totalCount": "{integer}",
"hasMoreItems": "{boolean}",
"cves": [
{
"cve": {
"id": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"severity": "{integer}",
"source": "{string}",
"cwes": [
"{array[string]...}"
],
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
},
"packageId": "{string}",
"packageName": "{string}",
"packageVersion": "{string}",
"ecosystem": "{string}",
"repositories": [
{
"connection": "{string}",
"repository": "{string}",
"repositoryId": "{string}",
"reference": "{string}",
"scanned": "{date-time}",
"scanIds": [
"{array[string]...}"
],
"stepSha256s": [
"{array[string]...}"
]
}
]
}
]
}
Copy

Clean up historical scan results older than the specified time frame

Auth
Request Body
objectobject
timeFrameinteger
POST /api/v1/scans/cleanup
curl --request POST \
--url 'http://localhost:8001/api/v1/scans/cleanup' \
--data '{
"timeFrame": "{integer}"
}'
Copy
Responses
200

OK

objectobject
deletedScansCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalScansFound

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
responseKeystring
responseMessagestring
207

Multi-Status

400

Bad Request

500

Internal Server Error

Response
{
"deletedScansCount": "{integer}",
"totalScansFound": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Enumerate files by scan ID

Auth
Path Params
scanIdstring
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

searchstring
includeArchivesboolean
includePackagesboolean
GET /api/v1/scans/{scanId}/files
curl --get \
--url 'http://localhost:8001/api/v1/scans/{scanId}/files' \
--data page={page} \
--data pageSize={pageSize} \
--data search={search} \
--data includeArchives={includeArchives} \
--data includePackages={includePackages}
Copy
Responses
200

OK

arrayarray[object]
objectIdentityIdstring
objectIdentityHashstring
scanResultIdstring
progressUpload

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
progressScan

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
processingStateinteger
exceptionDetailsstring
createddate-time
discoveryStarteddate-time
discoveryStartedDaySec

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
streamingStartedTimedate-time
streamingCompletedTimedate-time
streamingTimeSpanMs

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
scanCompletedTimedate-time
processingTimeSpanMs

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
processingFailedTimedate-time
processingRetryCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
objectTriggeredActionsarray[object]
actionStatusinteger
triggeredActionTypeinteger
skippedScanboolean
hasAppliedRemediationboolean
hasAppliedSanitizationboolean
hasFailedSanitizationboolean
createdAtdate-time
lastUpdateddate-time
tenantIdstring
objectRemediationActionsarray[object]
scanResult
objectIdentity
versionsarray[object]
idstring
scanIdstring
storageIdstring
scanWorkflowSnapshotIdstring
metaDefenderCoreUrlstring
namestring
pathstring
hashstring
objectStorageMetadatastring
size

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
lastModifieddate-time
storageLocationstring
fileTypeCategory
pathForDisplaystring
extensionstring
404

Not Found

Response
[
{
"objectIdentityId": "{string}",
"objectIdentityHash": "{string}",
"scanResultId": "{string}",
"progressUpload": "{integer}",
"progressScan": "{integer}",
"processingState": "{integer}",
"exceptionDetails": "{string}",
"created": "{date-time}",
"discoveryStarted": "{date-time}",
"discoveryStartedDaySec": "{integer}",
"streamingStartedTime": "{date-time}",
"streamingCompletedTime": "{date-time}",
"streamingTimeSpanMs": "{integer}",
"scanCompletedTime": "{date-time}",
"processingTimeSpanMs": "{integer}",
"processingFailedTime": "{date-time}",
"processingRetryCount": "{integer}",
"objectTriggeredActions": [
{
"actionStatus": "{integer}",
"triggeredActionType": "{integer}"
}
],
"skippedScan": "{boolean}",
"hasAppliedRemediation": "{boolean}",
"hasAppliedSanitization": "{boolean}",
"hasFailedSanitization": "{boolean}",
"createdAt": "{date-time}",
"lastUpdated": "{date-time}",
"tenantId": "{string}",
"objectRemediationActions": [
{}
],
"scanResult": "{}",
"objectIdentity": "{}",
"versions": [
{}
],
"id": "{string}",
"scanId": "{string}",
"storageId": "{string}",
"scanWorkflowSnapshotId": "{string}",
"metaDefenderCoreUrl": "{string}",
"name": "{string}",
"path": "{string}",
"hash": "{string}",
"objectStorageMetadata": "{string}",
"size": "{integer}",
"lastModified": "{date-time}",
"storageLocation": "{string}",
"fileTypeCategory": "{}",
"pathForDisplay": "{string}",
"extension": "{string}"
}
]
Copy

Get the file details view of a file by its scan result ID

Auth
Path Params
scanResultIdstring
GET /api/v1/scans/{scanResultId}/details
curl --get \
--url 'http://localhost:8001/api/v1/scans/{scanResultId}/details'
Copy
Responses
200

OK

objectobject
fileIdstring
scanResultIdstring
parentIdstring
displayNamestring
filePathstring
fileTypestring
size

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
scannedOnstring
startTimedate-time
isArchiveboolean
isBlockedboolean
blockedReasonstring
isMalwareboolean
hasSecretsboolean
isVulnerableboolean
dlp
metascan
sbom5 fieldsobject
Response
{
"fileId": "{string}",
"scanResultId": "{string}",
"parentId": "{string}",
"displayName": "{string}",
"filePath": "{string}",
"fileType": "{string}",
"size": "{integer}",
"scannedOn": "{string}",
"startTime": "{date-time}",
"isArchive": "{boolean}",
"isBlocked": "{boolean}",
"blockedReason": "{string}",
"isMalware": "{boolean}",
"hasSecrets": "{boolean}",
"isVulnerable": "{boolean}",
"dlp": "{}",
"metascan": "{}",
"sbom": {
"vulnerabilityCounts": {
"critical": "{integer}",
"high": "{integer}",
"medium": "{integer}",
"low": "{integer}",
"unknown": "{integer}"
},
"dependencyVulnerabilityCounts": {
"critical": "{integer}",
"high": "{integer}",
"medium": "{integer}",
"low": "{integer}",
"unknown": "{integer}"
},
"licenses": "{}",
"packages": [
{
"packageId": "{string}",
"ecosystem": "{string}",
"group": "{string}",
"packageName": "{string}",
"packageVersion": "{string}",
"target": "{string}",
"licenses": "{}",
"vulnerabilities": [
{
"id": "{string}",
"severity": "{string}",
"source": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"cwes": [
"{array[string]...}"
],
"type": "{string}",
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"vulnerabilityCounts": "{}",
"dependencies": [
{
"ecosystem": "{string}",
"group": "{string}",
"packageName": "{string}",
"packageVersion": "{string}",
"vulnerabilities": [
{
"id": "{string}",
"severity": "{string}",
"source": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"cwes": [
"{array[string]...}"
],
"type": "{string}",
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"vulnerabilityCounts": "{}"
}
],
"labels": [
{
"key": "{string}",
"value": "{string}",
"valueType": "{string}",
"created": "{date-time}",
"updated": "{date-time}"
}
],
"latest": "{}"
}
],
"steps": [
{
"step": "{integer}",
"command": "{string}",
"sha256": "{string}"
}
]
}
}
Copy

Get the archive entries of a file by its scan result ID

Auth
Path Params
scanResultIdstring
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/scans/{scanResultId}/children
curl --get \
--url 'http://localhost:8001/api/v1/scans/{scanResultId}/children' \
--data page={page} \
--data pageSize={pageSize}
Copy
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
children18 fieldsarray[object]
Response
{
"page": "{integer}",
"pageSize": "{integer}",
"totalCount": "{integer}",
"hasMoreItems": "{boolean}",
"children": [
{
"fileId": "{string}",
"scanResultId": "{string}",
"parentId": "{string}",
"displayName": "{string}",
"filePath": "{string}",
"fileType": "{string}",
"size": "{integer}",
"scannedOn": "{string}",
"startTime": "{date-time}",
"isArchive": "{boolean}",
"isBlocked": "{boolean}",
"blockedReason": "{string}",
"isMalware": "{boolean}",
"hasSecrets": "{boolean}",
"isVulnerable": "{boolean}",
"dlp": "{}",
"metascan": "{}",
"sbom": {
"vulnerabilityCounts": {
"critical": "{integer}",
"high": "{integer}",
"medium": "{integer}",
"low": "{integer}",
"unknown": "{integer}"
},
"dependencyVulnerabilityCounts": {
"critical": "{integer}",
"high": "{integer}",
"medium": "{integer}",
"low": "{integer}",
"unknown": "{integer}"
},
"licenses": "{}",
"packages": [
{
"packageId": "{string}",
"ecosystem": "{string}",
"group": "{string}",
"packageName": "{string}",
"packageVersion": "{string}",
"target": "{string}",
"licenses": "{}",
"vulnerabilities": [
{
"id": "{string}",
"severity": "{string}",
"source": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"cwes": [
"{array[string]...}"
],
"type": "{string}",
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"vulnerabilityCounts": "{}",
"dependencies": [
{
"ecosystem": "{string}",
"group": "{string}",
"packageName": "{string}",
"packageVersion": "{string}",
"vulnerabilities": [
{
"id": "{string}",
"severity": "{string}",
"source": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"cwes": [
"{array[string]...}"
],
"type": "{string}",
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"vulnerabilityCounts": "{}"
}
],
"labels": [
{
"key": "{string}",
"value": "{string}",
"valueType": "{string}",
"created": "{date-time}",
"updated": "{date-time}"
}
],
"latest": "{}"
}
],
"steps": [
{
"step": "{integer}",
"command": "{string}",
"sha256": "{string}"
}
]
}
}
]
}
Copy

Get the dependencies of a file and its archive entries by its scan result ID

Rolls up the transitive dependencies reported for a file and every entry inside it when it is an archive. ReportedDependencyCount is what the scan engine reported; ItemizedDependencyCount is how many it itemized and therefore how many rows this endpoint can return.

Auth
Path Params
scanResultIdstring
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

searchstring
GET /api/v1/scans/{scanResultId}/dependencies
curl --get \
--url 'http://localhost:8001/api/v1/scans/{scanResultId}/dependencies' \
--data page={page} \
--data pageSize={pageSize} \
--data search={search}
Copy
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
directPackageCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalPackageCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
reportedDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
itemizedDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
distinctDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
vulnerabilityCounts
dependencies9 fieldsarray[object]
Response
{
"page": "{integer}",
"pageSize": "{integer}",
"hasMoreItems": "{boolean}",
"directPackageCount": "{integer}",
"totalPackageCount": "{integer}",
"reportedDependencyCount": "{integer}",
"itemizedDependencyCount": "{integer}",
"distinctDependencyCount": "{integer}",
"vulnerabilityCounts": "{}",
"dependencies": [
{
"uid": "{string}",
"ecosystem": "{string}",
"group": "{string}",
"packageName": "{string}",
"packageVersion": "{string}",
"parentPackageName": "{string}",
"parentPackageVersion": "{string}",
"vulnerabilities": [
{
"id": "{string}",
"severity": "{string}",
"source": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"cwes": [
"{array[string]...}"
],
"type": "{string}",
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"vulnerabilityCounts": "{}"
}
]
}
Copy

Get the dependencies of one archive entry, including nested entries, by its child data ID

Same rollup as the file dependencies endpoint, scoped to one extracted file and any archive entries nested under it. ReportedDependencyCount is what the scan engine reported; ItemizedDependencyCount is how many it itemized and therefore how many rows this endpoint can return.

Auth
Path Params
scanResultIdstring
childDataIdstring
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

searchstring
GET /api/v1/scans/{scanResultId}/archive/{childDataId}/dependencies
curl --get \
--url 'http://localhost:8001/api/v1/scans/{scanResultId}/archive/{childDataId}/dependencies' \
--data page={page} \
--data pageSize={pageSize} \
--data search={search}
Copy
Responses
200

OK

objectobject
page

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
pageSize

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
hasMoreItemsboolean
directPackageCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
totalPackageCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
reportedDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
itemizedDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
distinctDependencyCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
vulnerabilityCounts
dependencies9 fieldsarray[object]
Response
{
"page": "{integer}",
"pageSize": "{integer}",
"hasMoreItems": "{boolean}",
"directPackageCount": "{integer}",
"totalPackageCount": "{integer}",
"reportedDependencyCount": "{integer}",
"itemizedDependencyCount": "{integer}",
"distinctDependencyCount": "{integer}",
"vulnerabilityCounts": "{}",
"dependencies": [
{
"uid": "{string}",
"ecosystem": "{string}",
"group": "{string}",
"packageName": "{string}",
"packageVersion": "{string}",
"parentPackageName": "{string}",
"parentPackageVersion": "{string}",
"vulnerabilities": [
{
"id": "{string}",
"severity": "{string}",
"source": "{string}",
"fixedVersions": [
"{array[string]...}"
],
"cwes": [
"{array[string]...}"
],
"type": "{string}",
"aliases": [
"{array[string]...}"
],
"epss": "{}",
"ratings": [
{
"method": "{string}",
"score": "{number}",
"severity": "{string}",
"source": "{}"
}
]
}
],
"vulnerabilityCounts": "{}"
}
]
}
Copy

Get per-CVE new/fixed details for each trend period

Auth
Query String
intervalinteger
periods

pattern: ^-?(?:0|[1-9]\d*)$

Default: 4

GET /api/v1/scans/vulnerability-trends/details
curl --get \
--url 'http://localhost:8001/api/v1/scans/vulnerability-trends/details' \
--data interval={interval} \
--data periods=4
Copy
Responses
200

OK

arrayarray[object]
periodStartdate
periodEnddate
newCves6 fieldsarray[object]
fixedCves6 fieldsarray[object]
500

Internal Server Error

Response
[
{
"periodStart": "{date}",
"periodEnd": "{date}",
"newCves": [
{
"cveId": "{string}",
"severity": "{integer}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"packageName": "{string}",
"packageVersion": "{string}"
}
],
"fixedCves": [
{
"cveId": "{string}",
"severity": "{integer}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"packageName": "{string}",
"packageVersion": "{string}"
}
]
}
]
Copy

Get service references by service ID

Auth
Path Params
serviceIdstring
GET /api/v1/services/{serviceId}/references
curl --get \
--url 'http://localhost:8001/api/v1/services/{serviceId}/references'
Copy
Responses
200

OK

objectobject
serviceIdstring
serviceNamestring
repositoryReferenceInfoArray3 fieldsarray[object]
404

Not Found

Response
{
"serviceId": "{string}",
"serviceName": "{string}",
"repositoryReferenceInfoArray": [
{
"repositoryId": "{string}",
"defaultReference": "{string}",
"references": [
"{array[string]...}"
]
}
]
}
Copy

Get service references by service ID and repository ID

Auth
Path Params
serviceIdstring
repositoryIdstring
Query String
Page

pattern: ^-?(?:0|[1-9]\d*)$

PageSize

pattern: ^-?(?:0|[1-9]\d*)$

FilterValuestring
Cursorstring
Searchstring

maxLength: 256

minLength: 0

GET /api/v1/services/{serviceId}/{repositoryId}/references
curl --get \
--url 'http://localhost:8001/api/v1/services/{serviceId}/{repositoryId}/references' \
--data Page={Page} \
--data PageSize={PageSize} \
--data FilterValue={FilterValue} \
--data Cursor={Cursor} \
--data Search={Search}
Copy
Responses
200

OK

objectobject
referencesarray[string]
totalReferences

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
404

Not Found

Response
{
"references": [
"{array[string]...}"
],
"totalReferences": "{integer}"
}
Copy

Add service references

Auth
Request Body
arrayarray[object]
serviceIdstring
repositoryIdsarray[string]
POST /api/v1/services/references
curl --request POST \
--url 'http://localhost:8001/api/v1/services/references' \
--data '[
{
"serviceId": "{string}",
"repositoryIds": [
"{array[string]...}"
]
}
]'
Copy
Responses
200

OK

arrayarray[object]
serviceIdstring
serviceNamestring
repositoryReferenceInfoArray3 fieldsarray[object]
204

No Content

404

Not Found

Response
[
{
"serviceId": "{string}",
"serviceName": "{string}",
"repositoryReferenceInfoArray": [
{
"repositoryId": "{string}",
"defaultReference": "{string}",
"references": [
"{array[string]...}"
]
}
]
}
]
Copy

Get service resources by service ID

Auth
Path Params
serviceIdstring
GET /api/v1/services/{serviceId}/resources
curl --get \
--url 'http://localhost:8001/api/v1/services/{serviceId}/resources'
Copy
Responses
200

OK

objectobject
resourcesarray[string]
404

Not Found

Response
{
"resources": [
"{array[string]...}"
]
}
Copy

Add a service

Auth
Request Body
objectobject
credentialsstring
namestring
vendorTypeinteger
protocolTypeinteger
POST /api/v1/services
curl --request POST \
--url 'http://localhost:8001/api/v1/services' \
--data '{
"credentials": "{string}",
"name": "{string}",
"source": "{}",
"vendorType": "{integer}",
"protocolType": "{integer}"
}'
Copy
Responses
200

OK

objectobject
idstring
namestring
type
details
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

409

Conflict

500

Internal Server Error

503

Service Unavailable

Response
{
"id": "{string}",
"name": "{string}",
"type": "{}",
"details": "{}",
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Get all services

Auth
Query String
contentboolean
typearray
GET /api/v1/services
curl --get \
--url 'http://localhost:8001/api/v1/services' \
--data content={content} \
--data type={type}
Copy
Responses
200

OK

objectobject
serviceDtos9 fieldsarray[object]
statusMessagestring
206

Partial Content

400

Bad Request

Response
{
"serviceDtos": [
{
"id": "{string}",
"credentialsType": "{integer}",
"scanWorkflowId": "{string}",
"domain": "{string}",
"realTimeStatus": "{integer}",
"name": "{string}",
"source": "{}",
"vendorType": "{integer}",
"protocolType": "{integer}"
}
],
"statusMessage": "{string}"
}
Copy

Update a service by ID

Auth
Path Params
serviceIdstring
Request Body
objectobject
namestring
credentialsstring
hasNewCredentialsboolean
PUT /api/v1/services/{serviceId}
curl --request PUT \
--url 'http://localhost:8001/api/v1/services/{serviceId}' \
--data '{
"name": "{string}",
"credentials": "{string}",
"hasNewCredentials": "{boolean}"
}'
Copy
Responses
200

OK

objectobject
idstring
namestring
type
details
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

404

Not Found

409

Conflict

500

Internal Server Error

503

Service Unavailable

Response
{
"id": "{string}",
"name": "{string}",
"type": "{}",
"details": "{}",
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Get a service by ID

Auth
Path Params
serviceIdstring
Query String
contentboolean
Searchstring
Page

pattern: ^-?(?:0|[1-9]\d*)$

PageSize

pattern: ^-?(?:0|[1-9]\d*)$

FilterValuestring
Cursorstring
Searchstring

maxLength: 256

minLength: 0

PrioritizedRepositoriesReferencestring
GET /api/v1/services/{serviceId}
curl --get \
--url 'http://localhost:8001/api/v1/services/{serviceId}' \
--data content={content} \
--data Search={Search} \
--data Page={Page} \
--data PageSize={PageSize} \
--data FilterValue={FilterValue} \
--data Cursor={Cursor} \
--data Search={Search} \
--data PrioritizedRepositoriesReference={PrioritizedRepositoriesReference}
Copy
Responses
200

OK

objectobject
idstring
credentialsType

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
scanWorkflowIdstring
domainstring
realTimeStatusinteger
namestring
vendorTypeinteger
protocolTypeinteger
400

Bad Request

404

Not Found

500

Internal Server Error

Response
{
"id": "{string}",
"credentialsType": "{integer}",
"scanWorkflowId": "{string}",
"domain": "{string}",
"realTimeStatus": "{integer}",
"name": "{string}",
"source": "{}",
"vendorType": "{integer}",
"protocolType": "{integer}"
}
Copy

Delete a service by ID

Auth
Path Params
serviceIdstring
DELETE /api/v1/services/{serviceId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/services/{serviceId}'
Copy
Responses
200

OK

No response body
400

Bad Request

404

Not Found

500

Internal Server Error

Response
No response
Copy

Get top-risky repositories for a service

Auth
Path Params
serviceIdstring
Query String
windowstring
count

pattern: ^-?(?:0|[1-9]\d*)$

GET /api/v1/services/{serviceId}/top-risky
curl --get \
--url 'http://localhost:8001/api/v1/services/{serviceId}/top-risky' \
--data window={window} \
--data count={count}
Copy
Responses
200

OK

arrayarray[object]
connectionIdstring
connectionNamestring
repositoryIdstring
repositoryNamestring
riskScore

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
400

Bad Request

500

Internal Server Error

Response
[
{
"connectionId": "{string}",
"connectionName": "{string}",
"repositoryId": "{string}",
"repositoryName": "{string}",
"riskScore": "{integer}"
}
]
Copy

Get the base URL

Auth
GET /api/v1/network
curl --get \
--url 'http://localhost:8001/api/v1/network'
Copy
Responses
200

OK

objectobject
baseUrlstring
500

Internal Server Error

Response
{
"baseUrl": "{string}"
}
Copy

Set the base URL

Auth
Request Body
objectobject
baseUrlstring
PUT /api/v1/network
curl --request PUT \
--url 'http://localhost:8001/api/v1/network' \
--data '{
"baseUrl": "{string}"
}'
Copy
Responses
200

OK

No response body
400

Bad Request

409

Conflict

500

Internal Server Error

Response
No response
Copy

Add a SMTP configuration

Auth
Request Body
objectobject
hoststring
port

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
senderAddressstring
senderNamestring
domainstring
usernamestring
passwordstring
secureSocketOptioninteger
ignoreCertWarningsboolean
isEnabledboolean
POST /api/v1/smtp
curl --request POST \
--url 'http://localhost:8001/api/v1/smtp' \
--data '{
"host": "{string}",
"port": "{integer}",
"senderAddress": "{string}",
"senderName": "{string}",
"domain": "{string}",
"username": "{string}",
"password": "{string}",
"secureSocketOption": "{integer}",
"ignoreCertWarnings": "{boolean}",
"isEnabled": "{boolean}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Partially update SMTP configuration

Auth
Request Body
objectobject
hoststring
port

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
senderAddressstring
senderNamestring
domainstring
usernamestring
passwordstring
secureSocketOption
ignoreCertWarningsboolean
isEnabledboolean
PATCH /api/v1/smtp
curl --request PATCH \
--url 'http://localhost:8001/api/v1/smtp' \
--data '{
"host": "{string}",
"port": "{integer}",
"senderAddress": "{string}",
"senderName": "{string}",
"domain": "{string}",
"username": "{string}",
"password": "{string}",
"secureSocketOption": "{}",
"ignoreCertWarnings": "{boolean}",
"isEnabled": "{boolean}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get a SMTP configuration

Auth
GET /api/v1/smtp
curl --get \
--url 'http://localhost:8001/api/v1/smtp'
Copy
Responses
200

OK

objectobject
smtp
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"smtp": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Add a Jira configuration

Auth
Request Body
objectobject
namestring
apiKeystring
baseAddressstring
usernamestring
POST /api/v1/jira
curl --request POST \
--url 'http://localhost:8001/api/v1/jira' \
--data '{
"name": "{string}",
"apiKey": "{string}",
"baseAddress": "{string}",
"username": "{string}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get all Jira configurations

Auth
GET /api/v1/jira
curl --get \
--url 'http://localhost:8001/api/v1/jira'
Copy
Responses
200

OK

objectobject
jiraEntries8 fieldsarray[object]
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"jiraEntries": [
{
"id": "{string}",
"name": "{string}",
"apiKey": "{string}",
"baseAddress": "{string}",
"username": "{string}",
"tenantId": "{string}",
"createdAt": "{date-time}",
"lastUpdated": "{date-time}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get a Jira configuration by ID

Auth
Path Params
idstring
GET /api/v1/jira/{id}
curl --get \
--url 'http://localhost:8001/api/v1/jira/{id}'
Copy
Responses
200

OK

objectobject
jira
responseKeystring
responseMessagestring
404

Not Found

Response
{
"jira": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Update a Jira configuration by ID

Auth
Path Params
idstring
Request Body
objectobject
namestring
apiKeystring
baseAddressstring
usernamestring
PUT /api/v1/jira/{id}
curl --request PUT \
--url 'http://localhost:8001/api/v1/jira/{id}' \
--data '{
"name": "{string}",
"apiKey": "{string}",
"baseAddress": "{string}",
"username": "{string}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Delete a Jira configuration by ID

Auth
Path Params
idstring
DELETE /api/v1/jira/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/jira/{id}'
Copy
Responses
200

OK

objectobject
jiraIdstring
responseKeystring
responseMessagestring
404

Not Found

Response
{
"jiraId": "{string}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get Jira projects

Auth
Path Params
idstring
GET /api/v1/jira/{id}/projects
curl --get \
--url 'http://localhost:8001/api/v1/jira/{id}/projects'
Copy
Responses
200

OK

objectobject
projectsarray[object]
idstring
namestring
responseKeystring
responseMessagestring
404

Not Found

Response
{
"projects": [
{
"id": "{string}",
"name": "{string}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Add a Teams configuration

Auth
Request Body
objectobject
namestring
apiKeystring
webhookUrlstring
POST /api/v1/teams
curl --request POST \
--url 'http://localhost:8001/api/v1/teams' \
--data '{
"name": "{string}",
"apiKey": "{string}",
"webhookUrl": "{string}"
}'
Copy
Responses
201

Created

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get all Teams configurations

Auth
GET /api/v1/teams
curl --get \
--url 'http://localhost:8001/api/v1/teams'
Copy
Responses
200

OK

objectobject
teamsConnections7 fieldsarray[object]
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"teamsConnections": [
{
"name": "{string}",
"apiKey": "{string}",
"webhookUrl": "{string}",
"createdAt": "{date-time}",
"lastUpdated": "{date-time}",
"id": "{string}",
"tenantId": "{string}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get a Teams configuration by ID

Auth
Path Params
idstring
GET /api/v1/teams/{id}
curl --get \
--url 'http://localhost:8001/api/v1/teams/{id}'
Copy
Responses
200

OK

objectobject
teams
responseKeystring
responseMessagestring
404

Not Found

Response
{
"teams": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Update a Teams configuration by ID

Auth
Path Params
idstring
Request Body
objectobject
namestring
apiKeystring
webhookUrlstring
PUT /api/v1/teams/{id}
curl --request PUT \
--url 'http://localhost:8001/api/v1/teams/{id}' \
--data '{
"name": "{string}",
"apiKey": "{string}",
"webhookUrl": "{string}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Delete a Teams configuration by ID

Auth
Path Params
idstring
DELETE /api/v1/teams/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/teams/{id}'
Copy
Responses
200

OK

objectobject
teamsIdstring
responseKeystring
responseMessagestring
404

Not Found

Response
{
"teamsId": "{string}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get the SSO configuration

Auth
GET /api/v1/sso
curl --get \
--url 'http://localhost:8001/api/v1/sso'
Copy
Responses
200

OK

objectobject
isEnabledboolean
ssoTypeinteger
ssoProviderinteger
baseUrlstring
clientIdstring
authoritystring
identityProviderIssuerstring
identityProviderLoginUrlstring
identityProviderLogoutUrlstring
administratorRoleNamestring
readonlyRoleNamestring
roleMappingsarray[object]
roleIduuid
idpRoleNamestring
hasClientSecretboolean
hasIdentityProviderCertificateboolean
404

Not Found

500

Internal Server Error

Response
{
"isEnabled": "{boolean}",
"ssoType": "{integer}",
"ssoProvider": "{integer}",
"baseUrl": "{string}",
"clientId": "{string}",
"authority": "{string}",
"identityProviderIssuer": "{string}",
"identityProviderLoginUrl": "{string}",
"identityProviderLogoutUrl": "{string}",
"administratorRoleName": "{string}",
"readonlyRoleName": "{string}",
"roleMappings": [
{
"roleId": "{uuid}",
"idpRoleName": "{string}"
}
],
"hasClientSecret": "{boolean}",
"hasIdentityProviderCertificate": "{boolean}"
}
Copy

Create or update the SSO configuration

Auth
Request Body
objectobject
isEnabledboolean
ssoTypeinteger
ssoProviderinteger
baseUrlstring
clientIdstring
clientSecretstring
authoritystring
identityProviderCertificatestring
identityProviderIssuerstring
identityProviderLoginUrlstring
identityProviderLogoutUrlstring
administratorRoleNamestring
readonlyRoleNamestring
roleMappingsarray[object]
roleIduuid
idpRoleNamestring
PUT /api/v1/sso
curl --request PUT \
--url 'http://localhost:8001/api/v1/sso' \
--data '{
"isEnabled": "{boolean}",
"ssoType": "{integer}",
"ssoProvider": "{integer}",
"baseUrl": "{string}",
"clientId": "{string}",
"clientSecret": "{string}",
"authority": "{string}",
"identityProviderCertificate": "{string}",
"identityProviderIssuer": "{string}",
"identityProviderLoginUrl": "{string}",
"identityProviderLogoutUrl": "{string}",
"administratorRoleName": "{string}",
"readonlyRoleName": "{string}",
"roleMappings": [
{
"roleId": "{uuid}",
"idpRoleName": "{string}"
}
]
}'
Copy
Responses
200

OK

No response body
400

Bad Request

404

Not Found

500

Internal Server Error

Response
No response
Copy

Anonymous by design: the login page must decide whether to offer the SSO button before a session exists. It returns only a boolean — never provider, authority, or secret presence.

Auth
GET /api/v1/sso/enabled
curl --get \
--url 'http://localhost:8001/api/v1/sso/enabled'
Copy
Responses
200

OK

objectobject
isEnabledboolean
Response
{
"isEnabled": "{boolean}"
}
Copy

telemetry

Auth
GET /api/v1/telemetry
curl --get \
--url 'http://localhost:8001/api/v1/telemetry'
Copy
Responses
200

OK

objectobject
enabledboolean
sendToOpswatEnabledboolean
collectors4 fieldsarray[object]
responseKeystring
responseMessagestring
Response
{
"enabled": "{boolean}",
"sendToOpswatEnabled": "{boolean}",
"collectors": [
{
"type": "{}",
"endpointUrl": "{string}",
"metricProtocol": "{string}",
"hasApiKey": "{boolean}"
}
],
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

enabled

Auth
Request Body
objectobject
enabledboolean
PUT /api/v1/telemetry/enabled
curl --request PUT \
--url 'http://localhost:8001/api/v1/telemetry/enabled' \
--data '{
"enabled": "{boolean}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

opswat

Auth
Request Body
objectobject
sendToOpswatEnabledboolean
PUT /api/v1/telemetry/opswat
curl --request PUT \
--url 'http://localhost:8001/api/v1/telemetry/opswat' \
--data '{
"sendToOpswatEnabled": "{boolean}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

collectors

Auth
Request Body
objectobject
endpointUrlstring
metricProtocolstring
apiKeystring
POST /api/v1/telemetry/collectors
curl --request POST \
--url 'http://localhost:8001/api/v1/telemetry/collectors' \
--data '{
"endpointUrl": "{string}",
"metricProtocol": "{string}",
"apiKey": "{string}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

collectors

Auth
Request Body
objectobject
endpointUrlstring
metricProtocolstring
apiKeystring
PUT /api/v1/telemetry/collectors
curl --request PUT \
--url 'http://localhost:8001/api/v1/telemetry/collectors' \
--data '{
"endpointUrl": "{string}",
"metricProtocol": "{string}",
"apiKey": "{string}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

collectors

Auth
Query String
endpointUrlstring
DELETE /api/v1/telemetry/collectors
curl --request DELETE \
--url 'http://localhost:8001/api/v1/telemetry/collectors' \
--data endpointUrl={endpointUrl}
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
404

Not Found

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Add a new user

The new password must meet the password policy. A rejected password returns 400 stating the exact limit.

Auth
Request Body
objectobject
role
fullNamestring
userNamestring
passwordstring
emailstring
POST /api/v1/users
curl --request POST \
--url 'http://localhost:8001/api/v1/users' \
--data '{
"role": "{}",
"fullName": "{string}",
"userName": "{string}",
"password": "{string}",
"email": "{string}"
}'
Copy
Responses
200

OK

objectobject
createUserParameters5 fieldsobject
currentUserIdstring
400

Bad Request

Response
{
"createUserParameters": {
"role": "{}",
"fullName": "{string}",
"userName": "{string}",
"password": "{string}",
"email": "{string}"
},
"currentUserId": "{string}"
}
Copy

Get users

Auth
Query String
Typeinteger
StartIndex

pattern: ^-?(?:0|[1-9]\d*)$

Count

pattern: ^-?(?:0|[1-9]\d*)$

SearchTermstring
GET /api/v1/users
curl --get \
--url 'http://localhost:8001/api/v1/users' \
--data Type={Type} \
--data StartIndex={StartIndex} \
--data Count={Count} \
--data SearchTerm={SearchTerm}
Copy
Responses
200

OK

objectobject
enumerateUsersDto2 fieldsobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"enumerateUsersDto": {
"entries": [
{
"userId": "{string}",
"username": "{string}",
"fullName": "{string}",
"email": "{string}",
"role": "{}",
"showTutorial": "{boolean}",
"tablePreferences": [
{
"tableId": "{string}",
"columns": [
{
"columnKey": "{string}",
"isVisible": "{boolean}",
"order": "{integer}"
}
]
}
]
}
],
"totalCount": "{integer}"
},
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Update a user

Auth
Request Body
objectobject
userIdstring
role
userNamestring
fullNamestring
emailstring
currentPasswordstring
newPasswordstring
showTutorialboolean
PUT /api/v1/users
curl --request PUT \
--url 'http://localhost:8001/api/v1/users' \
--data '{
"userId": "{string}",
"role": "{}",
"userName": "{string}",
"fullName": "{string}",
"email": "{string}",
"currentPassword": "{string}",
"newPassword": "{string}",
"showTutorial": "{boolean}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Register a new pending user

The new password must meet the password policy. A rejected password returns 400 stating the exact limit.

Auth
Request Body
objectobject
fullNamestring
userNamestring
passwordstring
emailstring
POST /api/v1/users/register
curl --request POST \
--url 'http://localhost:8001/api/v1/users/register' \
--data '{
"fullName": "{string}",
"userName": "{string}",
"password": "{string}",
"email": "{string}"
}'
Copy
Responses
200

OK

objectobject
userDto
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"userDto": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Approve a pending user

Auth
Path Params
userIdstring
Request Body
objectobject
roleinteger
POST /api/v1/users/{userId}/approve
curl --request POST \
--url 'http://localhost:8001/api/v1/users/{userId}/approve' \
--data '{
"role": "{integer}"
}'
Copy
Responses
200

OK

No response body
400

Bad Request

403

Forbidden

404

Not Found

409

Conflict

Response
No response
Copy

Reject a pending user

Auth
Path Params
userIdstring
POST /api/v1/users/{userId}/reject
curl --request POST \
--url 'http://localhost:8001/api/v1/users/{userId}/reject'
Copy
Responses
200

OK

No response body
400

Bad Request

404

Not Found

409

Conflict

Response
No response
Copy

Get current user

Auth
GET /api/v1/user
curl --get \
--url 'http://localhost:8001/api/v1/user'
Copy
Responses
200

OK

objectobject
userDto
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"userDto": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Update the current user's own profile

The new password must meet the password policy. A rejected password returns 400 stating the exact limit.

Auth
Request Body
objectobject
fullNamestring
emailstring
currentPasswordstring
newPasswordstring
showTutorialboolean
tablePreferences2 fieldsarray[object]
PUT /api/v1/user
curl --request PUT \
--url 'http://localhost:8001/api/v1/user' \
--data '{
"fullName": "{string}",
"email": "{string}",
"currentPassword": "{string}",
"newPassword": "{string}",
"showTutorial": "{boolean}",
"tablePreferences": [
{
"tableId": "{string}",
"columns": [
{
"columnKey": "{string}",
"isVisible": "{boolean}",
"order": "{integer}"
}
]
}
]
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get the calling principal's permission claims

Auth
GET /api/v1/user/permissions
curl --get \
--url 'http://localhost:8001/api/v1/user/permissions'
Copy
Responses
200

OK

arrayarray[string]
Response
[
"{array[string]...}"
]
Copy

Delete a user

Auth
Path Params
userIdstring
DELETE /api/v1/users/{userId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/users/{userId}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Login user

Auth
Request Body
objectobject
usernamestring
passwordstring
POST /api/v1/user/login
curl --request POST \
--url 'http://localhost:8001/api/v1/user/login' \
--data '{
"username": "{string}",
"password": "{string}"
}'
Copy
Responses
200

OK

objectobject
jwtToken
responseKeystring
responseMessagestring
400

Bad Request

429

Too Many Requests

Response
{
"jwtToken": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Turns an identity-service session into an MDSSC one. The SSO callback leaves the platform token readable by the page, but MDSSC's own session lives in an HttpOnly cookie that script cannot write, so the exchange has to happen here.

Auth
Request Body
objectobject
accessTokenstring
POST /api/v1/user/sso/session
curl --request POST \
--url 'http://localhost:8001/api/v1/user/sso/session' \
--data '{
"accessToken": "{string}"
}'
Copy
Responses
200

OK

No response body
403

Forbidden

404

Not Found

Response
No response
Copy

Remove all tokens for an user

Auth
Path Params
userIdstring
DELETE /api/v1/user/login/{userId}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/user/login/{userId}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get a new Access Token

Auth
PUT /api/v1/user/token
curl --request PUT \
--url 'http://localhost:8001/api/v1/user/token'
Copy
Responses
200

OK

objectobject
jwtToken
responseKeystring
responseMessagestring
400

Bad Request

Response
{
"jwtToken": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Request a password reset

Auth
Request Body
objectobject
emailInputstring
POST /api/v1/user/password/request-reset
curl --request POST \
--url 'http://localhost:8001/api/v1/user/password/request-reset' \
--data '{
"emailInput": "{string}"
}'
Copy
Responses
200

OK

objectobject
responseKeystring
responseMessagestring
Response
{
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Reset a user password

The new password must meet the password policy. A rejected password returns 400 stating the exact limit.

Auth
Request Body
objectobject
newPasswordstring
newPasswordConfirmationstring
secureTokenstring
userIdstring
POST /api/v1/user/password/new-password
curl --request POST \
--url 'http://localhost:8001/api/v1/user/password/new-password' \
--data '{
"newPassword": "{string}",
"newPasswordConfirmation": "{string}",
"secureToken": "{string}",
"userId": "{string}"
}'
Copy
Responses
200

OK

objectobject
user
responseKeystring
responseMessagestring
Response
{
"user": "{}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

List the current user's active sessions

Auth
GET /api/v1/user/sessions
curl --get \
--url 'http://localhost:8001/api/v1/user/sessions'
Copy
Responses
200

OK

arrayarray[object]
idstring
signedInAtdate-time
lastActiveAtdate-time
expiresAtdate-time
isCurrentboolean
403

Forbidden

Response
[
{
"id": "{string}",
"signedInAt": "{date-time}",
"lastActiveAt": "{date-time}",
"expiresAt": "{date-time}",
"isCurrent": "{boolean}"
}
]
Copy

Terminate the current user's sessions

Supply CurrentPassword to confirm the request.

Auth
Request Body
objectobject
sessionIdstring
includeCurrentboolean
currentPasswordstring
POST /api/v1/user/sessions/terminate
curl --request POST \
--url 'http://localhost:8001/api/v1/user/sessions/terminate' \
--data '{
"sessionId": "{string}",
"includeCurrent": "{boolean}",
"currentPassword": "{string}"
}'
Copy
Responses
200

OK

objectobject
terminatedCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
currentSessionEndedboolean
400

Bad Request

403

Forbidden

404

Not Found

429

Too Many Requests

Response
{
"terminatedCount": "{integer}",
"currentSessionEnded": "{boolean}"
}
Copy

Manage Versions

Get application version

Auth
Query String
api-versionstring
GET /api/version
curl --get \
--url 'http://localhost:8001/api/version' \
--data api-version={api-version}
Copy
Responses
200

OK

objectobject
versionstring
responseKeystring
responseMessagestring
Response
{
"version": "{string}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Get application version

Auth
GET /api/v1/version
curl --get \
--url 'http://localhost:8001/api/v1/version'
Copy
Responses
200

OK

objectobject
versionstring
responseKeystring
responseMessagestring
Response
{
"version": "{string}",
"responseKey": "{string}",
"responseMessage": "{string}"
}
Copy

Handles a scan event triggered by a webhook. Requires a custom header and a body.

Auth
Path Params
routeParameterstring
Request Body
No request body
POST /api/v1/webhook/hmac/{routeParameter}
curl --request POST \
--url 'http://localhost:8001/api/v1/webhook/hmac/{routeParameter}'
Copy
Responses
200

OK

No response body
400

Bad Request

500

Internal Server Error

Response
No response
Copy

Handles a scan event triggered by a webhook. Requires a custom body.

Auth
Path Params
routeParameterstring
Request Body
No request body
POST /api/v1/webhook/{routeParameter}
curl --request POST \
--url 'http://localhost:8001/api/v1/webhook/{routeParameter}'
Copy
Responses
200

OK

No response body
400

Bad Request

500

Internal Server Error

Response
No response
Copy

Create a workflow

Auth
Request Body
objectobject
namestring
descriptionstring
scanConfigurationIdstring
blockedFileDefinitionobject
modestring
configuration
fileRemediations3 fieldsobject
fileDiscoveryFilterConfiguration
remediations3 fieldsarray[object]
crossDomainTransfer
POST /api/v1/workflows
curl --request POST \
--url 'http://localhost:8001/api/v1/workflows' \
--data '{
"name": "{string}",
"description": "{string}",
"scanConfigurationId": "{string}",
"blockedFileDefinition": {
"mode": "{string}",
"configuration": "{}"
},
"fileRemediations": {
"sourceCode": {
"allowed": {
"softDelete": "{boolean}",
"keep": "{boolean}"
},
"blocked": {
"softDelete": "{boolean}",
"keep": "{boolean}"
}
},
"container": {
"allowed": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
},
"blocked": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
}
},
"binary": {
"allowed": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
},
"blocked": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"packageDelete": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
}
}
},
"fileDiscoveryFilterConfiguration": "{}",
"remediations": [
{
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
}
],
"crossDomainTransfer": "{}"
}'
Copy
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response
{
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

List workflows (paginated)

Auth
Query String
page

pattern: ^-?(?:0|[1-9]\d*)$

Default: 1

pageSize

pattern: ^-?(?:0|[1-9]\d*)$

Default: 10

includeDeletedboolean

Default: false

GET /api/v1/workflows
curl --get \
--url 'http://localhost:8001/api/v1/workflows' \
--data page=1 \
--data pageSize=10 \
--data includeDeleted={includeDeleted}
Copy
Responses
200

OK

objectobject
entries13 fieldsarray[object]
totalCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
Response
{
"entries": [
{
"id": "{string}",
"name": "{string}",
"description": "{string}",
"userId": "{string}",
"scanConfigurationId": "{string}",
"deleted": "{boolean}",
"blockedFileDefinition": {
"mode": "{string}",
"configuration": "{}"
},
"fileRemediations": {
"sourceCode": {
"allowed": {
"softDelete": "{boolean}",
"keep": "{boolean}"
},
"blocked": {
"softDelete": "{boolean}",
"keep": "{boolean}"
}
},
"container": {
"allowed": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
},
"blocked": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
}
},
"binary": {
"allowed": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
},
"blocked": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"packageDelete": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
}
}
},
"fileDiscoveryFilterConfiguration": "{}",
"remediations": [
{
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
}
],
"crossDomainTransfer": "{}",
"security": "{integer}",
"scanPool": "{string}"
}
],
"totalCount": "{integer}"
}
Copy

Partially update a workflow

Auth
Path Params
idstring
Request Body
objectobject
namestring
descriptionstring
scanConfigurationIdstring
blockedFileDefinition
fileRemediations
fileDiscoveryFilterConfiguration
remediations3 fieldsarray[object]
crossDomainTransfer
PATCH /api/v1/workflows/{id}
curl --request PATCH \
--url 'http://localhost:8001/api/v1/workflows/{id}' \
--data '{
"name": "{string}",
"description": "{string}",
"scanConfigurationId": "{string}",
"blockedFileDefinition": "{}",
"fileRemediations": "{}",
"fileDiscoveryFilterConfiguration": "{}",
"remediations": [
{
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
}
],
"crossDomainTransfer": "{}"
}'
Copy
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response
{
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Get a workflow by ID

Auth
Path Params
idstring
GET /api/v1/workflows/{id}
curl --get \
--url 'http://localhost:8001/api/v1/workflows/{id}'
Copy
Responses
200

OK

objectobject
idstring
namestring
descriptionstring
userIdstring
scanConfigurationIdstring
deletedboolean
blockedFileDefinitionobject
modestring
configuration
fileRemediations3 fieldsobject
fileDiscoveryFilterConfiguration
remediations3 fieldsarray[object]
crossDomainTransfer
security

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
scanPoolstring
Response
{
"id": "{string}",
"name": "{string}",
"description": "{string}",
"userId": "{string}",
"scanConfigurationId": "{string}",
"deleted": "{boolean}",
"blockedFileDefinition": {
"mode": "{string}",
"configuration": "{}"
},
"fileRemediations": {
"sourceCode": {
"allowed": {
"softDelete": "{boolean}",
"keep": "{boolean}"
},
"blocked": {
"softDelete": "{boolean}",
"keep": "{boolean}"
}
},
"container": {
"allowed": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
},
"blocked": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
}
},
"binary": {
"allowed": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
},
"blocked": {
"copy": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"packageDelete": {
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
},
"keep": "{boolean}"
}
}
},
"fileDiscoveryFilterConfiguration": "{}",
"remediations": [
{
"isEnabled": "{boolean}",
"type": "{string}",
"config": "{}"
}
],
"crossDomainTransfer": "{}",
"security": "{integer}",
"scanPool": "{string}"
}
Copy

Delete a workflow by ID

Auth
Path Params
idstring
DELETE /api/v1/workflows/{id}
curl --request DELETE \
--url 'http://localhost:8001/api/v1/workflows/{id}'
Copy
Responses
200

OK

objectobject
resultinteger
responseKeystring
responseMessagestring
responseMessageParamsobject
*string
400

Bad Request

Response
{
"result": "{integer}",
"responseKey": "{string}",
"responseMessage": "{string}",
"responseMessageParams": {}
}
Copy

Retrieve MetaDefender Core technology states for a workflow

Auth
Path Params
idstring
GET /api/v1/workflows/{id}/technologies
curl --get \
--url 'http://localhost:8001/api/v1/workflows/{id}/technologies'
Copy
Responses
200

OK

objectobject
sbominteger
metaScaninteger
dlpinteger
enabledCount

pattern: ^-?(?:0|[1-9]\d*)$

integerinteger
404

Not Found

500

Internal Server Error

Response
{
"sbom": "{integer}",
"metaScan": "{integer}",
"dlp": "{integer}",
"enabledCount": "{integer}"
}
Copy