# Rapid7 Scan Configs API

**Canonical:** https://apis.io/apis/rapid7/rapid7-scan-configs-api/  
**Provider:** Rapid7 — https://apis.io/providers/rapid7/  
**Base URL:** https://us.api.insight.rapid7.com/vm/v4  
**Documentation:** https://help.rapid7.com/insightvm/en-us/api/api.html

Rapid7 Scan Configs API is one of 50 APIs that [Rapid7](https://apis.io/providers/rapid7/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. Tagged areas include Scan Configs. The published artifact set on APIs.io includes an OpenAPI specification.

A Scan Config defines all the necessary information required to perform a Scan of an App. An App <i>must</i> be created prior to creating a Scan Config. It is the main document that describes <i>what</i> and <i>how</i> web resources should be discovered and Scanned, and can be tailored from Scan to Scan in order to refine the results gathered. It must define which Attack Template to use during the attacking phase of the Scan. Currently, all Scan Configs created via the API will by default specify that Scans will be executed on Cloud engines; support for On-Premise engines is available by specifying appropriate assignment ID (a known engine group ID), type (<code>ENGINE_GROUP</code>) and environment (<code>ON_PREMISE</code>) values. A Scan Config <i>must</i> define a minimum set of Options that specify the following:<ul><li>At least one Seed URL</li><li>At least one Crawling Scope Constraint</li></ul>If any of the Options defined for a Scan Config are considered invalid, an explanatory message should be included in the "errors" property of the owning Scan Config response body. All Seed URLs and Scope Constraint URLs provided must have a valid Target.

## Machine-readable artifacts (1)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/rapid7/refs/heads/main/openapi/rapid7-scan-configs-api-openapi.yml

## Other Rapid7 APIs (12)

- [Rapid7 InsightVM Cloud API](https://apis.io/apis/rapid7/insightvm-api/)
- [Rapid7 Insight Platform API](https://apis.io/apis/rapid7/insight-platform-api/)
- [Rapid7 InsightIDR API](https://apis.io/apis/rapid7/insightidr-api/)
- [Rapid7 Accounts API](https://apis.io/apis/rapid7/rapid7-accounts-api/)
- [Rapid7 Administration API](https://apis.io/apis/rapid7/rapid7-administration-api/)
- [Rapid7 Apps API](https://apis.io/apis/rapid7/rapid7-apps-api/)
- [Rapid7 Asset API](https://apis.io/apis/rapid7/rapid7-asset-api/)
- [Rapid7 Asset Discovery API](https://apis.io/apis/rapid7/rapid7-asset-discovery-api/)
- [Rapid7 Asset Group API](https://apis.io/apis/rapid7/rapid7-asset-group-api/)
- [Rapid7 Assets API](https://apis.io/apis/rapid7/rapid7-assets-api/)
- [Rapid7 Attachments API](https://apis.io/apis/rapid7/rapid7-attachments-api/)
- [Rapid7 Attack Templates API](https://apis.io/apis/rapid7/rapid7-attack-templates-api/)

## Tags

Scan Configs

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/rapid7/rapid7-scan-configs-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/rapid7/.
