Endor Labs Findings API

Detected problems requiring remediation.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/endor-labs-findings-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

endor-labs-findings-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Endor Labs REST Authentication Findings API
  description: The Endor Labs REST API is a uniform resource API over namespaces. Every resource kind (Project, PackageVersion, DependencyMetadata, Finding, Policy, ScanResult, Metric, and more) is addressed under /v1/namespaces/{namespace}/{resource}, with consistent list (GET), get (GET /{uuid}), create (POST), update (PATCH /{uuid}), and delete (DELETE /{uuid}) semantics. List endpoints share a common set of list_parameters (filter, mask, page_size, page_token, sort, count, group). Authentication is a bearer access token obtained by exchanging an API key and secret at POST /v1/auth/api-key.
  termsOfService: https://www.endorlabs.com/terms
  contact:
    name: Endor Labs Support
    url: https://docs.endorlabs.com/rest-api/
  version: '1.0'
servers:
- url: https://api.endorlabs.com/v1
security:
- bearerAuth: []
tags:
- name: Findings
  description: Detected problems requiring remediation.
paths:
  /namespaces/{namespace}/findings:
    get:
      operationId: listFindings
      tags:
      - Findings
      summary: List Finding resources in a namespace.
      parameters:
      - $ref: '#/components/parameters/Namespace'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Mask'
      - $ref: '#/components/parameters/PageSize'
      - $ref: '#/components/parameters/PageToken'
      - $ref: '#/components/parameters/SortPath'
      - $ref: '#/components/parameters/Count'
      responses:
        '200':
          description: A list of Finding resources.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FindingList'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /namespaces/{namespace}/findings/{uuid}:
    get:
      operationId: getFinding
      tags:
      - Findings
      summary: Get a Finding resource by UUID.
      parameters:
      - $ref: '#/components/parameters/Namespace'
      - $ref: '#/components/parameters/Uuid'
      responses:
        '200':
          description: The requested Finding resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Finding'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  parameters:
    Uuid:
      name: uuid
      in: path
      required: true
      description: The UUID of the resource.
      schema:
        type: string
    Filter:
      name: list_parameters.filter
      in: query
      required: false
      description: Endor query-language filter expression applied to the resource list.
      schema:
        type: string
    Count:
      name: list_parameters.count
      in: query
      required: false
      description: When true, return only the count of matching resources.
      schema:
        type: boolean
    Namespace:
      name: namespace
      in: path
      required: true
      description: The tenant namespace (tenant_meta.namespace) that scopes the resource.
      schema:
        type: string
    SortPath:
      name: list_parameters.sort.path
      in: query
      required: false
      description: Field path to sort the result set by.
      schema:
        type: string
    Mask:
      name: list_parameters.mask
      in: query
      required: false
      description: Comma-separated field mask selecting which fields to return.
      schema:
        type: string
    PageToken:
      name: list_parameters.page_token
      in: query
      required: false
      description: Opaque token to retrieve the next page of results.
      schema:
        type: string
    PageSize:
      name: list_parameters.page_size
      in: query
      required: false
      description: Maximum number of resources to return per page.
      schema:
        type: integer
        format: int32
  schemas:
    ListResponse:
      type: object
      properties:
        next_page_token:
          type: string
        count:
          type: integer
          format: int32
    TenantMeta:
      type: object
      properties:
        namespace:
          type: string
          description: The namespace the resource belongs to.
    ResourceMeta:
      type: object
      properties:
        name:
          type: string
        kind:
          type: string
        description:
          type: string
        version:
          type: string
        create_time:
          type: string
          format: date-time
        update_time:
          type: string
          format: date-time
    Error:
      type: object
      properties:
        code:
          type: integer
          format: int32
        message:
          type: string
    FindingList:
      type: object
      properties:
        list:
          type: object
          properties:
            objects:
              type: array
              items:
                $ref: '#/components/schemas/Finding'
            response:
              $ref: '#/components/schemas/ListResponse'
    Finding:
      type: object
      properties:
        uuid:
          type: string
        meta:
          $ref: '#/components/schemas/ResourceMeta'
        tenant_meta:
          $ref: '#/components/schemas/TenantMeta'
        spec:
          type: object
          properties:
            finding_categories:
              type: array
              items:
                type: string
            level:
              type: string
              description: Severity level, e.g. FINDING_LEVEL_CRITICAL.
            summary:
              type: string
            explanation:
              type: string
            target_uuid:
              type: string
            project_uuid:
              type: string
            finding_metadata:
              type: object
              properties:
                vulnerability:
                  type: object
                  description: Vulnerability detail when the finding is a vulnerability.
                reachability:
                  type: string
                  description: Reachability assessment for the finding.
  responses:
    Unauthorized:
      description: Missing or invalid bearer access token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: The requested resource was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Bearer access token obtained from POST /v1/auth/api-key by exchanging an Endor Labs API key and secret.