Rapid7 Vulnerability Check API
Resources and operations for view vulnerability checks that can be run as a part of vulnerability content.
Resources and operations for view vulnerability checks that can be run as a part of vulnerability content.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/rapid7-vulnerability-check-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
description: '# Overview
This guide documents the InsightVM Application Programming Interface (API) Version 3.'
version: '3'
title: InsightVM Vulnerability Check API
contact:
name: Rapid7
email: support@rapid7.com
servers:
- url: https://localhost:3780/
tags:
- name: Vulnerability Check
description: Resources and operations for view vulnerability checks that can be run as a part of vulnerability content.
paths:
/api/3/vulnerabilities/{id}/checks:
get:
tags:
- Vulnerability Check
summary: Vulnerability Checks
description: Returns the vulnerability checks that assess for a specific vulnerability during a scan.
operationId: getVulnerabilityChecksForVulnerability
parameters:
- name: id
in: path
description: The identifier of the vulnerability.
required: true
schema:
type: string
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ReferencesWith_VulnerabilityCheckID_Link'
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'404':
description: Not Found
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/NotFoundError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
/api/3/vulnerability_checks:
get:
tags:
- Vulnerability Check
summary: Checks
description: Returns vulnerability checks. Optional search and filtering parameters may be supplied to refine the results. Searching allows full text search of the vulnerability details a check is related to.
operationId: getVulnerabilityChecks
parameters:
- name: search
in: query
description: Vulnerability search term to find vulnerability checks for. e.g. `"ssh"`.
required: false
schema:
type: string
- name: safe
in: query
description: Whether to return vulnerability checks that are considered "safe" to run. Defaults to return safe and unsafe checks.
required: false
schema:
type: boolean
- name: potential
in: query
description: Whether to only return checks that result in potentially vulnerable results. Defaults to return all checks.
required: false
schema:
type: boolean
- name: requiresCredentials
in: query
description: Whether to only return checks that require credentials in order to successfully execute. Defaults to return all checks.
required: false
schema:
type: boolean
- name: unique
in: query
description: Whether to only return checks that guarantee to be executed once-and-only once on a host resulting in a unique result. False returns checks that can result in multiple occurrences of the same vulnerability on a host.
required: false
schema:
type: boolean
- name: type
in: query
description: The type of vulnerability checks to return. See <a href="#operation/vulnerabilityCheckTypesUsingGET">Check Types</a> for all available types.
required: false
schema:
type: string
- name: page
in: query
description: The index of the page (zero-based) to retrieve.
required: false
schema:
type: integer
format: int32
default: 0
- name: size
in: query
description: The number of records per page to retrieve.
required: false
schema:
type: integer
format: int32
default: 10
- name: sort
in: query
description: 'The criteria to sort the records by, in the format: `property[,ASC|DESC]`. The default sort order is ascending. Multiple sort criteria can be specified using multiple sort query parameters.'
required: false
style: form
explode: true
schema:
type: array
items:
type: string
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/PageOf_VulnerabilityCheck'
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'404':
description: Not Found
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/NotFoundError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
/api/3/vulnerability_checks/{id}:
get:
tags:
- Vulnerability Check
summary: Check
description: Returns the vulnerability check.
operationId: vulnerabilityCheck
parameters:
- name: id
in: path
description: The identifier of the vulnerability check.
required: true
schema:
type: string
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/VulnerabilityCheck'
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'404':
description: Not Found
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/NotFoundError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
/api/3/vulnerability_checks_types:
get:
tags:
- Vulnerability Check
summary: Check Types
description: Returns the vulnerability check types. The type groups related vulnerability checks by their purpose, property, or related characteristic.
operationId: getVulnerabilityCheckTypes
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ReferencesWith_VulnerabilityCheckTypeID_Link'
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'404':
description: Not Found
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/NotFoundError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
components:
schemas:
InternalServerError:
type: object
required:
- status
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
message:
type: string
example: An error has occurred.
description: The messages indicating the cause or reason for failure.
status:
type: string
example: '500'
description: The HTTP status code for the error (same as in the HTTP response).
enum:
- '500'
description: ''
VulnerabilityCheck:
type: object
properties:
id:
type: string
example: WINDOWS-HOTFIX-MS14-009-01123281-bac0-44d8-a729-cd31c19d6bd1
description: The identifier of the vulnerability check.
links:
type: array
description: Hypermedia links to corresponding or related resources.
readOnly: true
items:
$ref: '#/components/schemas/Link'
plugin:
type: string
example: WindowsHotfixScanner
description: The name of the plugin (module) the check belongs to.
potential:
type: boolean
example: false
description: Whether the check results in potential vulnerabilities.
requiresCredentials:
type: boolean
example: true
description: Whether the check requires credentials in order to run.
safe:
type: boolean
example: true
description: Whether the checked is deemed to be "safe" to run. A safe check is one that can be run without negatively impacting the host it is run against.
service:
type: boolean
example: false
description: Whether the check operates against a service, or false it it is a local check.
unique:
type: boolean
example: false
description: Whether the check may only register a result once during a scan of host. Otherwise, the tests in the check can run multiple times, possibly registering multiple results.
vulnerability:
type: string
example: windows-hotfix-ms14-009
description: The identifier of the vulnerability the check results in.
description: ''
PageOf_VulnerabilityCheck:
type: object
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
page:
example: ''
description: The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.
$ref: '#/components/schemas/PageInfo'
resources:
type: array
description: The page of resources returned.
items:
$ref: '#/components/schemas/VulnerabilityCheck'
description: ''
ReferencesWith_VulnerabilityCheckID_Link:
type: object
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
resources:
type: array
description: The identifiers of the associated resources.
items:
type: string
description: ''
Link:
type: object
properties:
href:
type: string
example: https://hostname:3780/api/3/...
description: 'A hypertext reference, which is either a URI (see <a target="_blank" rel="noopener noreferrer" href="https://tools.ietf.org/html/rfc3986">RFC 3986</a>) or URI template (see <a target="_blank" rel="noopener noreferrer" href="https://tools.ietf.org/html/rfc6570">RFC 6570</a>). '
rel:
type: string
example: self
description: The link relation type. This value is one from the <a target="_blank" rel="noopener noreferrer" href="https://tools.ietf.org/html/rfc5988#section-6.2">Link Relation Type Registry</a> or is the type of resource being linked to.
description: ''
UnauthorizedError:
type: object
required:
- status
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
message:
type: string
example: An error has occurred.
description: The messages indicating the cause or reason for failure.
status:
type: string
example: '401'
description: The HTTP status code for the error (same as in the HTTP response).
enum:
- '401'
description: ''
NotFoundError:
type: object
required:
- status
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
message:
type: string
example: An error has occurred.
description: The messages indicating the cause or reason for failure.
status:
type: string
example: '404'
description: The HTTP status code for the error (same as in the HTTP response).
enum:
- '404'
description: ''
PageInfo:
type: object
properties:
number:
type: integer
format: int64
example: 6
description: The index (zero-based) of the current page returned.
size:
type: integer
format: int64
example: 10
description: The maximum size of the page returned.
totalPages:
type: integer
format: int64
example: 13
description: The total number of pages available.
totalResources:
type: integer
format: int64
example: 123
description: The total number of resources available across all pages.
description: ''
ReferencesWith_VulnerabilityCheckTypeID_Link:
type: object
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
resources:
type: array
description: The identifiers of the associated resources.
items:
type: string
description: ''
ServiceUnavailableError:
type: object
required:
- status
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
message:
type: string
example: An error has occurred.
description: The messages indicating the cause or reason for failure.
status:
type: string
example: '503'
description: The HTTP status code for the error (same as in the HTTP response).
enum:
- '503'
description: ''
securitySchemes:
Basic:
type: http
scheme: basic