ARMO Vulnerabilities API

Image and workload vulnerability scanning and results.

Business capability
Vulnerability Management BC-620.40

Operations 12

POST /vulnerability/scan Issue a vulnerability scan #
POST /vulnerability/scanResults/summary Get vulnerability scan summary #
POST /vulnerability/scanResults/details Get vulnerability scan details #
POST /vulnerability/severity Get vulnerability severity roll-up #
POST /vulnerability/topVulnerabilities Get top vulnerabilities #
POST /vulnerabilities/list List vulnerabilities #
POST /vulnerabilities/components/list List vulnerabilities by component #
POST /vulnerabilities/images/list List vulnerabilities by image #
GET /vulnerability/exception List vulnerability exceptions #
POST /vulnerability/exception Create a vulnerability exception #
PUT /vulnerability/exception Update a vulnerability exception #
DELETE /vulnerability/exception Delete a vulnerability exception #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/armosec-vulnerabilities-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

armosec-vulnerabilities-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: ARMO Platform Vulnerabilities API
  description: The ARMO Platform API exposes ARMO's cloud-native and Kubernetes security data over REST.
  version: '1.0'
  contact:
    name: ARMO
    url: https://www.armosec.io
  license:
    name: ARMO Platform Terms
    url: https://www.armosec.io/terms-of-service/
servers:
- url: https://api.armosec.io/api/v1
  description: EU region
- url: https://api.us.armosec.io/api/v1
  description: US region
security:
- apiKeyAuth: []
tags:
- name: Vulnerabilities
  description: Image and workload vulnerability scanning and results.
paths:
  /vulnerability/scan:
    post:
      operationId: issueVulnerabilityScan
      tags:
      - Vulnerabilities
      summary: Issue a vulnerability scan
      description: Issues a vulnerability scan for a specific context or workload.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ScanRequest'
      responses:
        '200':
          description: Scan accepted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /vulnerability/scanResults/summary:
    post:
      operationId: getVulnerabilityScanSummary
      tags:
      - Vulnerabilities
      summary: Get vulnerability scan summary
      description: Returns a summary of a vulnerability scan.
      requestBody:
        $ref: '#/components/requestBodies/ListQuery'
      responses:
        '200':
          description: Scan summary.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /vulnerability/scanResults/details:
    post:
      operationId: getVulnerabilityScanDetails
      tags:
      - Vulnerabilities
      summary: Get vulnerability scan details
      description: Returns a detailed list of vulnerabilities from a scan.
      requestBody:
        $ref: '#/components/requestBodies/ListQuery'
      responses:
        '200':
          description: Detailed vulnerability list.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /vulnerability/severity:
    post:
      operationId: getVulnerabilitySeverity
      tags:
      - Vulnerabilities
      summary: Get vulnerability severity roll-up
      description: Returns severity "big numbers" from the latest scan.
      requestBody:
        $ref: '#/components/requestBodies/ListQuery'
      responses:
        '200':
          description: Severity roll-up.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /vulnerability/topVulnerabilities:
    post:
      operationId: getTopVulnerabilities
      tags:
      - Vulnerabilities
      summary: Get top vulnerabilities
      description: Returns the list of top vulnerabilities.
      requestBody:
        $ref: '#/components/requestBodies/ListQuery'
      responses:
        '200':
          description: Top vulnerabilities.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /vulnerabilities/list:
    post:
      operationId: listVulnerabilities
      tags:
      - Vulnerabilities
      summary: List vulnerabilities
      description: Retrieves a filtered, paginated list of vulnerabilities (CVEs).
      requestBody:
        $ref: '#/components/requestBodies/ListQuery'
      responses:
        '200':
          description: A list of vulnerabilities.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /vulnerabilities/components/list:
    post:
      operationId: listVulnerabilitiesByComponent
      tags:
      - Vulnerabilities
      summary: List vulnerabilities by component
      description: Retrieves vulnerabilities scoped to software components/packages.
      requestBody:
        $ref: '#/components/requestBodies/ListQuery'
      responses:
        '200':
          description: A list of vulnerabilities by component.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /vulnerabilities/images/list:
    post:
      operationId: listVulnerabilitiesByImage
      tags:
      - Vulnerabilities
      summary: List vulnerabilities by image
      description: Retrieves vulnerabilities scoped to container images.
      requestBody:
        $ref: '#/components/requestBodies/ListQuery'
      responses:
        '200':
          description: A list of vulnerabilities by image.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /vulnerability/exception:
    get:
      operationId: listVulnerabilityExceptions
      tags:
      - Vulnerabilities
      summary: List vulnerability exceptions
      responses:
        '200':
          description: Vulnerability exceptions.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: createVulnerabilityException
      tags:
      - Vulnerabilities
      summary: Create a vulnerability exception
      requestBody:
        $ref: '#/components/requestBodies/GenericBody'
      responses:
        '200':
          description: Created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
    put:
      operationId: updateVulnerabilityException
      tags:
      - Vulnerabilities
      summary: Update a vulnerability exception
      requestBody:
        $ref: '#/components/requestBodies/GenericBody'
      responses:
        '200':
          description: Updated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
    delete:
      operationId: deleteVulnerabilityException
      tags:
      - Vulnerabilities
      summary: Delete a vulnerability exception
      responses:
        '200':
          description: Deleted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenericResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  requestBodies:
    GenericBody:
      required: true
      content:
        application/json:
          schema:
            type: object
            additionalProperties: true
    ListQuery:
      required: false
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ListQuery'
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
    ListQuery:
      type: object
      description: ARMO's list endpoints accept a common query body with pagination, sorting, and field filters. Exact filter keys vary per resource.
      properties:
        pageSize:
          type: integer
          default: 50
        pageNum:
          type: integer
          default: 1
        orderBy:
          type: string
        innerFilters:
          type: array
          items:
            type: object
            additionalProperties: true
        since:
          type: string
          format: date-time
    ListResponse:
      type: object
      properties:
        total:
          type: object
          properties:
            value:
              type: integer
        response:
          type: array
          items:
            type: object
            additionalProperties: true
      additionalProperties: true
    GenericResponse:
      type: object
      additionalProperties: true
  responses:
    Unauthorized:
      description: Missing or invalid X-API-KEY.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: Account access key (Agent Access Key) generated in ARMO Platform under Settings, sent in the X-API-KEY header.