Kondukto Scanners API

The Scanners API from Kondukto — 1 operation(s) for scanners.

OpenAPI Specification

kondukto-scanners-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Invicti ASPM (Kondukto) REST API v2 Authorization Managers Scanners API
  version: '2.0'
  description: Public REST API v2 for the Invicti ASPM platform (formerly Kondukto), an Application Security Posture Management platform that centralizes SAST, DAST, SCA, container and pentest findings from more than eighty scanners. The API manages projects, products, teams, labels, scans and vulnerabilities, and is the same public API the open-source KDT command-line client uses. Assembled by API Evangelist from the per-operation OpenAPI 3.1 definitions Kondukto publishes on each page of its API reference.
  contact:
    name: Kondukto Support
    email: support@kondukto.io
    url: https://docs.kondukto.io/reference/starting-with-kondukto-api
  x-origin:
  - format: openapi
    version: '3.1'
    url: https://docs.kondukto.io/reference/starting-with-kondukto-api
servers:
- url: https://{hostname}
  description: 'Invicti ASPM deployment host. The platform is deployed per customer (self-hosted or dedicated tenant), so there is no single shared public endpoint: set this to your own instance, the same value KDT reads from INVICTI_ASPM_HOST. The provider''s own published definitions leave this variable with the literal placeholder default "hostname"; api.kondukto.io is used here as a real, provider-owned default. It resolves but answers 403 to unauthenticated requests.'
  variables:
    hostname:
      default: api.kondukto.io
      description: Hostname of your Invicti ASPM instance.
security:
- apiToken: []
tags:
- name: Scanners
paths:
  /api/v2/scanners/active/:
    get:
      summary: Get Active Scanners
      description: Return active scanners
      operationId: get-active-scanners
      parameters:
      - name: name
        in: query
        description: Scanner Name (Contains)
        schema:
          type: string
      - name: X-Cookie
        in: header
        description: Personal Access Token
        required: true
        schema:
          type: string
      - name: types
        in: query
        description: Comma separated scanner types
        schema:
          type: array
          items:
            type: string
      - name: labels
        in: query
        description: Comma separated scanner labels
        schema:
          type: array
          items:
            type: string
      responses:
        '200':
          description: '200'
          content:
            application/json:
              examples:
                Result:
                  value: "{\n    \"active_scanners\": [\n        {\n            \"id\": \"{scannerID}\",\n            \"type\": \"{scannerType}\",\n            \"slug\": \"{scannerName}\",\n            \"display_name\": \"{scannerDisplayName}\",\n            \"labels\": [\n                \"{scannerLabel}\",\n                \"{scannerLabel}\",\n                \"{scannerLabel}\"\n            ],\n            \"image_tags\": [\n                \"{scannerImageTag}\"\n            ],\n            \"disabled\": false,\n            \"global_configurations\": {\n                \"custom_registry\": false,\n                \"scanner_image\": \"{scannerImageName}\"\n            },\n            \"params\": {},\n        }\n    ],\n    \"total\": 1\n}"
        '401':
          description: '401'
          content:
            application/json:
              examples:
                Result:
                  value:
                    error: failed to authorize
              schema:
                type: object
                properties:
                  error:
                    type: string
                    example: failed to authorize
      deprecated: false
      tags:
      - Scanners
components:
  securitySchemes:
    apiToken:
      type: apiKey
      in: header
      name: X-Cookie
      description: Kondukto-issued API token. Generate it in the UI under Integrations > Personal Access Token (shown once). Sent on every request in the X-Cookie header.