Rapid7 Vulnerability Comments API
A Vulnerability Comment is a resource that allows users to add context to the Vulnerability.
A Vulnerability Comment is a resource that allows users to add context to the Vulnerability.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/rapid7-vulnerability-comments-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: InsightAppSec Vulnerability Comments API
description: Welcome to the reference documentation for the public APIs available for InsightAppSec.
version: v1
servers:
- url: https://[region].api.insight.rapid7.com/ias/v1
tags:
- name: Vulnerability Comments
description: A Vulnerability Comment is a resource that allows users to add context to the Vulnerability.
paths:
/vulnerabilities/{vuln-id}/comments:
get:
tags:
- Vulnerability Comments
summary: Get Vulnerability Comments
description: Get the comments for a Vulnerability
operationId: get-vulnerability-comments
parameters:
- name: vuln-id
in: path
required: true
schema:
type: string
format: uuid
responses:
'415':
description: Unsupported Media Type
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/PageVulnerabilityComment'
'400':
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'401':
description: Unauthenticated
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Unauthorized
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'404':
description: Resource not found
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'500':
description: Internal error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
post:
tags:
- Vulnerability Comments
summary: Create Vulnerability Comment
description: Create a new Vulnerability Comment
operationId: create-vulnerability-comment
parameters:
- name: vuln-id
in: path
required: true
schema:
type: string
format: uuid
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/VulnerabilityComment'
required: true
responses:
'415':
description: Unsupported Media Type
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'201':
description: Created
'400':
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'401':
description: Unauthenticated
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Unauthorized
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'404':
description: Resource not found
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'500':
description: Internal error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'409':
description: Action conflict
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'422':
description: Resource validation error
content:
application/json:
schema:
$ref: '#/components/schemas/ValidationErrors'
/vulnerabilities/{vuln-id}/comments/{comment-id}:
get:
tags:
- Vulnerability Comments
summary: Get Vulnerability Comment
description: Get a Comment for a Vulnerability
operationId: get-vulnerability-comment
parameters:
- name: vuln-id
in: path
required: true
schema:
type: string
format: uuid
- name: comment-id
in: path
required: true
schema:
type: string
format: uuid
responses:
'415':
description: Unsupported Media Type
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/EntityModelVulnerabilityComment'
'400':
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'401':
description: Unauthenticated
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Unauthorized
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'404':
description: Resource not found
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'500':
description: Internal error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
put:
tags:
- Vulnerability Comments
summary: Update Vulnerability Comment
description: Update an existing Vulnerability Comment
operationId: update-vulnerability-comment
parameters:
- name: vuln-id
in: path
required: true
schema:
type: string
format: uuid
- name: comment-id
in: path
required: true
schema:
type: string
format: uuid
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/VulnerabilityComment'
required: true
responses:
'415':
description: Unsupported Media Type
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'200':
description: OK
'400':
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'401':
description: Unauthenticated
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Unauthorized
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'404':
description: Resource not found
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'500':
description: Internal error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'409':
description: Action conflict
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'422':
description: Resource validation error
content:
application/json:
schema:
$ref: '#/components/schemas/ValidationErrors'
delete:
tags:
- Vulnerability Comments
summary: Delete Vulnerability Comment
description: Delete an existing Vulnerability Comment
operationId: delete-vulnerability-comment
parameters:
- name: vuln-id
in: path
required: true
schema:
type: string
format: uuid
- name: comment-id
in: path
required: true
schema:
type: string
format: uuid
responses:
'415':
description: Unsupported Media Type
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'204':
description: No Content
'400':
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'401':
description: Unauthenticated
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Unauthorized
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'404':
description: Resource not found
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'500':
description: Internal error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'409':
description: Action conflict
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
components:
schemas:
VulnerabilityComment:
properties:
id:
type: string
format: uuid
description: The ID of the Vulnerability Comment
readOnly: true
vulnerability:
$ref: '#/components/schemas/ReferenceResource'
author:
$ref: '#/components/schemas/ReferenceResource'
last_update_author:
$ref: '#/components/schemas/ReferenceResource'
content:
type: string
description: The content of the Vulnerability Comment
maxLength: 5000
minLength: 1
create_time:
type: string
description: The time when the Vulnerability Comment was created
example: '2021-08-03T14:07:37'
readOnly: true
update_time:
type: string
description: The time when the Vulnerability Comment was last edited
example: '2021-08-03T14:07:37'
readOnly: true
required:
- content
title: VulnerabilityComment
PageMetadata:
properties:
index:
type: integer
format: int64
size:
type: integer
format: int64
sort:
type: string
total_data:
type: integer
format: int64
total_pages:
type: integer
format: int64
page_token:
type: string
EntityModelVulnerabilityComment:
properties:
id:
type: string
format: uuid
description: The ID of the Vulnerability Comment
readOnly: true
vulnerability:
$ref: '#/components/schemas/ReferenceResource'
author:
$ref: '#/components/schemas/ReferenceResource'
last_update_author:
$ref: '#/components/schemas/ReferenceResource'
content:
type: string
description: The content of the Vulnerability Comment
maxLength: 5000
minLength: 1
create_time:
type: string
description: The time when the Vulnerability Comment was created
example: '2021-08-03T14:07:37'
readOnly: true
update_time:
type: string
description: The time when the Vulnerability Comment was last edited
example: '2021-08-03T14:07:37'
readOnly: true
links:
type: array
items:
$ref: '#/components/schemas/Link'
readOnly: true
required:
- content
ValidationError:
properties:
type:
type: string
description: The type of the validation error
enum:
- OBJECT
- PROPERTY
readOnly: true
context:
type: string
description: An optional contextual indicator of a part of the request which failed validation
readOnly: true
explanation:
type: string
description: Details of the validation error
readOnly: true
PageVulnerabilityComment:
properties:
data:
type: array
items:
$ref: '#/components/schemas/EntityModelVulnerabilityComment'
metadata:
$ref: '#/components/schemas/PageMetadata'
links:
type: array
items:
$ref: '#/components/schemas/Link'
readOnly: true
Link:
properties:
rel:
type: string
href:
type: string
profile:
type: string
name:
type: string
readOnly: true
Error:
properties:
status:
type: string
description: A description of the type of error based on HTTP status code
enum:
- 100 CONTINUE
- 101 SWITCHING_PROTOCOLS
- 102 PROCESSING
- 103 EARLY_HINTS
- 103 CHECKPOINT
- 200 OK
- 201 CREATED
- 202 ACCEPTED
- 203 NON_AUTHORITATIVE_INFORMATION
- 204 NO_CONTENT
- 205 RESET_CONTENT
- 206 PARTIAL_CONTENT
- 207 MULTI_STATUS
- 208 ALREADY_REPORTED
- 226 IM_USED
- 300 MULTIPLE_CHOICES
- 301 MOVED_PERMANENTLY
- 302 FOUND
- 302 MOVED_TEMPORARILY
- 303 SEE_OTHER
- 304 NOT_MODIFIED
- 305 USE_PROXY
- 307 TEMPORARY_REDIRECT
- 308 PERMANENT_REDIRECT
- 400 BAD_REQUEST
- 401 UNAUTHORIZED
- 402 PAYMENT_REQUIRED
- 403 FORBIDDEN
- 404 NOT_FOUND
- 405 METHOD_NOT_ALLOWED
- 406 NOT_ACCEPTABLE
- 407 PROXY_AUTHENTICATION_REQUIRED
- 408 REQUEST_TIMEOUT
- 409 CONFLICT
- 410 GONE
- 411 LENGTH_REQUIRED
- 412 PRECONDITION_FAILED
- 413 PAYLOAD_TOO_LARGE
- 413 REQUEST_ENTITY_TOO_LARGE
- 414 URI_TOO_LONG
- 414 REQUEST_URI_TOO_LONG
- 415 UNSUPPORTED_MEDIA_TYPE
- 416 REQUESTED_RANGE_NOT_SATISFIABLE
- 417 EXPECTATION_FAILED
- 418 I_AM_A_TEAPOT
- 419 INSUFFICIENT_SPACE_ON_RESOURCE
- 420 METHOD_FAILURE
- 421 DESTINATION_LOCKED
- 422 UNPROCESSABLE_ENTITY
- 423 LOCKED
- 424 FAILED_DEPENDENCY
- 425 TOO_EARLY
- 426 UPGRADE_REQUIRED
- 428 PRECONDITION_REQUIRED
- 429 TOO_MANY_REQUESTS
- 431 REQUEST_HEADER_FIELDS_TOO_LARGE
- 451 UNAVAILABLE_FOR_LEGAL_REASONS
- 500 INTERNAL_SERVER_ERROR
- 501 NOT_IMPLEMENTED
- 502 BAD_GATEWAY
- 503 SERVICE_UNAVAILABLE
- 504 GATEWAY_TIMEOUT
- 505 HTTP_VERSION_NOT_SUPPORTED
- 506 VARIANT_ALSO_NEGOTIATES
- 507 INSUFFICIENT_STORAGE
- 508 LOOP_DETECTED
- 509 BANDWIDTH_LIMIT_EXCEEDED
- 510 NOT_EXTENDED
- 511 NETWORK_AUTHENTICATION_REQUIRED
readOnly: true
message:
type: string
description: A description of the error
readOnly: true
errorCode:
type: string
description: An optional code which may help support indicate the underlying cause of the error
enum:
- E1
- E2
- E3
- E4
- E5
- E6
- E7
- E8
- E9
- E10
- E11
- E12
- E13
- E14
- E15
- E16
- E17
- E18
- E19
- E20
- E22
- E23
- E24
- E25
- E26
- E27
- E28
- E999
readOnly: true
title: Error
ReferenceResource:
description: The last editor of the comment
properties:
id:
type: string
format: uuid
readOnly: true
required:
- id
ValidationErrors:
properties:
status:
type: string
description: A description of the type of error based on HTTP status code
enum:
- 100 CONTINUE
- 101 SWITCHING_PROTOCOLS
- 102 PROCESSING
- 103 EARLY_HINTS
- 103 CHECKPOINT
- 200 OK
- 201 CREATED
- 202 ACCEPTED
- 203 NON_AUTHORITATIVE_INFORMATION
- 204 NO_CONTENT
- 205 RESET_CONTENT
- 206 PARTIAL_CONTENT
- 207 MULTI_STATUS
- 208 ALREADY_REPORTED
- 226 IM_USED
- 300 MULTIPLE_CHOICES
- 301 MOVED_PERMANENTLY
- 302 FOUND
- 302 MOVED_TEMPORARILY
- 303 SEE_OTHER
- 304 NOT_MODIFIED
- 305 USE_PROXY
- 307 TEMPORARY_REDIRECT
- 308 PERMANENT_REDIRECT
- 400 BAD_REQUEST
- 401 UNAUTHORIZED
- 402 PAYMENT_REQUIRED
- 403 FORBIDDEN
- 404 NOT_FOUND
- 405 METHOD_NOT_ALLOWED
- 406 NOT_ACCEPTABLE
- 407 PROXY_AUTHENTICATION_REQUIRED
- 408 REQUEST_TIMEOUT
- 409 CONFLICT
- 410 GONE
- 411 LENGTH_REQUIRED
- 412 PRECONDITION_FAILED
- 413 PAYLOAD_TOO_LARGE
- 413 REQUEST_ENTITY_TOO_LARGE
- 414 URI_TOO_LONG
- 414 REQUEST_URI_TOO_LONG
- 415 UNSUPPORTED_MEDIA_TYPE
- 416 REQUESTED_RANGE_NOT_SATISFIABLE
- 417 EXPECTATION_FAILED
- 418 I_AM_A_TEAPOT
- 419 INSUFFICIENT_SPACE_ON_RESOURCE
- 420 METHOD_FAILURE
- 421 DESTINATION_LOCKED
- 422 UNPROCESSABLE_ENTITY
- 423 LOCKED
- 424 FAILED_DEPENDENCY
- 425 TOO_EARLY
- 426 UPGRADE_REQUIRED
- 428 PRECONDITION_REQUIRED
- 429 TOO_MANY_REQUESTS
- 431 REQUEST_HEADER_FIELDS_TOO_LARGE
- 451 UNAVAILABLE_FOR_LEGAL_REASONS
- 500 INTERNAL_SERVER_ERROR
- 501 NOT_IMPLEMENTED
- 502 BAD_GATEWAY
- 503 SERVICE_UNAVAILABLE
- 504 GATEWAY_TIMEOUT
- 505 HTTP_VERSION_NOT_SUPPORTED
- 506 VARIANT_ALSO_NEGOTIATES
- 507 INSUFFICIENT_STORAGE
- 508 LOOP_DETECTED
- 509 BANDWIDTH_LIMIT_EXCEEDED
- 510 NOT_EXTENDED
- 511 NETWORK_AUTHENTICATION_REQUIRED
readOnly: true
message:
type: string
description: A description of the error
readOnly: true
errorCode:
type: string
description: An optional code which may help support indicate the underlying cause of the error
enum:
- E1
- E2
- E3
- E4
- E5
- E6
- E7
- E8
- E9
- E10
- E11
- E12
- E13
- E14
- E15
- E16
- E17
- E18
- E19
- E20
- E22
- E23
- E24
- E25
- E26
- E27
- E28
- E999
readOnly: true
errors:
type: array
description: A list of validation errors, when the HTTP status code is 422
items:
$ref: '#/components/schemas/ValidationError'
readOnly: true
title: ValidationErrors