Fortify CI/CD API

CI/CD pipeline integration endpoints

Operations 3

POST /scans/start-scan-cicd Fortify Start scan from CI/CD #
GET /scan-settings/{scanSettingsId}/cicd-token Fortify Get CI/CD token #
POST /scan-settings/{scanSettingsId}/cicd-token Fortify Regenerate CI/CD token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/fortify-ci-cd-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

fortify-ci-cd-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Fortify ScanCentral DAST CI/CD API
  description: REST API for Fortify ScanCentral DAST, which provides centralized dynamic application security testing management. Enables orchestration of DAST scans across distributed WebInspect sensors, management of scan settings and policies, sensor pool configuration, and CI/CD pipeline integration. Authentication uses FortifyToken obtained from Fortify Software Security Center.
  version: v2
  contact:
    name: OpenText Fortify Support
    url: https://www.opentext.com/support
    email: fortify-support@microfocus.com
  license:
    name: Proprietary
    url: https://www.opentext.com/about/legal/website-terms-of-use
  x-logo:
    url: https://www.microfocus.com/brand/fortify-logo.png
servers:
- url: '{protocol}://{host}/api'
  description: ScanCentral DAST API Server
  variables:
    protocol:
      default: https
      enum:
      - https
      - http
    host:
      default: localhost:8500
      description: Your ScanCentral DAST server hostname and port
security:
- fortifyToken: []
tags:
- name: CI/CD
  description: CI/CD pipeline integration endpoints
paths:
  /scans/start-scan-cicd:
    post:
      operationId: startScanCicd
      summary: Fortify Start scan from CI/CD
      description: Starts a new DAST scan from a CI/CD pipeline using a pre-configured CI/CD token that references the scan settings. This is the primary endpoint for CI/CD integration.
      tags:
      - CI/CD
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/StartScanCicdRequest'
      responses:
        '200':
          description: Scan started successfully from CI/CD
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StartScanResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
  /scan-settings/{scanSettingsId}/cicd-token:
    get:
      operationId: getScanSettingsCicdToken
      summary: Fortify Get CI/CD token
      description: Retrieves the CI/CD token for a scan settings configuration, used to trigger scans from CI/CD pipelines.
      tags:
      - CI/CD
      parameters:
      - name: scanSettingsId
        in: path
        required: true
        description: Unique identifier of the scan settings
        schema:
          type: string
          format: uuid
      responses:
        '200':
          description: Successful response with CI/CD token
          content:
            application/json:
              schema:
                type: object
                properties:
                  cicdToken:
                    type: string
                    format: uuid
                    description: CI/CD token for triggering scans
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
    post:
      operationId: regenerateScanSettingsCicdToken
      summary: Fortify Regenerate CI/CD token
      description: Regenerates the CI/CD token for a scan settings configuration, invalidating the previous token.
      tags:
      - CI/CD
      parameters:
      - name: scanSettingsId
        in: path
        required: true
        description: Unique identifier of the scan settings
        schema:
          type: string
          format: uuid
      responses:
        '200':
          description: CI/CD token regenerated successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  cicdToken:
                    type: string
                    format: uuid
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  schemas:
    StartScanCicdRequest:
      type: object
      description: Request to start a scan from CI/CD pipeline
      required:
      - cicdToken
      properties:
        cicdToken:
          type: string
          format: uuid
          description: CI/CD token that references scan settings
        name:
          type: string
          description: Optional name for the scan
    ErrorResponse:
      type: object
      description: Error response
      properties:
        errorCode:
          type: integer
          format: int32
        message:
          type: string
        details:
          type: string
    StartScanResponse:
      type: object
      description: Response after starting a scan
      properties:
        scanId:
          type: string
          format: uuid
          description: Identifier of the newly created scan
        status:
          type: string
          description: Initial scan status
  responses:
    NotFound:
      description: Not found - the specified resource does not exist
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Unauthorized:
      description: Unauthorized - authentication required or token invalid
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Forbidden:
      description: Forbidden - insufficient permissions
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    BadRequest:
      description: Bad request - invalid parameters or request body
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    fortifyToken:
      type: apiKey
      in: header
      name: Authorization
      description: 'Fortify token-based authentication. Pass as: FORTIFYTOKEN <token_value>. Obtain a CI token from SSC Administration or use an SSC auth token.'
externalDocs:
  description: Fortify ScanCentral DAST Documentation
  url: https://www.microfocus.com/documentation/fortify-ScanCentral-DAST/