Rapid7 Vulnerability Exception API
Vulnerability Exception Resource Controller
Vulnerability Exception Resource Controller
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/rapid7-vulnerability-exception-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
description: '# Overview
This guide documents the InsightVM Application Programming Interface (API) Version 3.'
version: '3'
title: InsightVM Vulnerability Exception API
contact:
name: Rapid7
email: support@rapid7.com
servers:
- url: https://localhost:3780/
tags:
- name: Vulnerability Exception
description: Vulnerability Exception Resource Controller
paths:
/api/3/vulnerability_exceptions:
get:
tags:
- Vulnerability Exception
summary: Exceptions
description: Returns all exceptions defined on vulnerabilities.
operationId: getVulnerabilityExceptions
parameters:
- name: page
in: query
description: The index of the page (zero-based) to retrieve.
required: false
schema:
type: integer
format: int32
default: 0
- name: size
in: query
description: The number of records per page to retrieve.
required: false
schema:
type: integer
format: int32
default: 10
- name: sort
in: query
description: 'The criteria to sort the records by, in the format: `property[,ASC|DESC]`. The default sort order is ascending. Multiple sort criteria can be specified using multiple sort query parameters.'
required: false
style: form
explode: true
schema:
type: array
items:
type: string
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/PageOf_VulnerabilityException'
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'404':
description: Not Found
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/NotFoundError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
post:
tags:
- Vulnerability Exception
summary: Exceptions
description: Creates a vulnerability exception.
operationId: createVulnerabilityException
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/CreatedReference_VulnerabilityExceptionID_Link'
'400':
description: Bad Request
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/BadRequestError'
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/VulnerabilityException'
description: The vulnerability exception to create.
/api/3/vulnerability_exceptions/{id}:
get:
tags:
- Vulnerability Exception
summary: Exception
description: Returns an exception made on a vulnerability.
operationId: getVulnerabilityException
parameters:
- name: id
in: path
description: The identifier of the vulnerability exception.
required: true
schema:
type: integer
format: int32
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/VulnerabilityException'
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'404':
description: Not Found
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/NotFoundError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
delete:
tags:
- Vulnerability Exception
summary: Exception
description: Removes an exception made on a vulnerability.
operationId: removeVulnerabilityException
parameters:
- name: id
in: path
description: id
required: true
schema:
type: integer
format: int32
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/Links'
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'404':
description: Not Found
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/NotFoundError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
/api/3/vulnerability_exceptions/{id}/expires:
get:
tags:
- Vulnerability Exception
summary: Exception Expiration
description: Get the expiration date for a vulnerability exception.
operationId: getVulnerabilityExceptionExpiration
parameters:
- name: id
in: path
description: id
required: true
schema:
type: integer
format: int32
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
type: string
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'404':
description: Not Found
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/NotFoundError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
put:
tags:
- Vulnerability Exception
summary: Exception Expiration
description: Set the expiration date for a vulnerability exception. This must be a valid date in the future.
operationId: updateVulnerabilityExceptionExpiration
parameters:
- name: id
in: path
description: id
required: true
schema:
type: integer
format: int32
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/Links'
'400':
description: Bad Request
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/BadRequestError'
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'404':
description: Not Found
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/NotFoundError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
requestBody:
content:
application/json:
schema:
type: string
description: param1
required: true
/api/3/vulnerability_exceptions/{id}/{status}:
post:
tags:
- Vulnerability Exception
summary: Exception Status
description: 'Update the status of the vulnerability exception. The status can be one of: `"recall"`, `"approve"`, or `"reject"`.'
operationId: updateVulnerabilityExceptionStatus
parameters:
- name: id
in: path
description: id
required: true
schema:
type: integer
format: int32
- name: status
in: path
description: Exception Status
required: true
schema:
type: string
enum:
- recall
- approve
- reject
responses:
'200':
description: OK
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/Links'
'400':
description: Bad Request
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/BadRequestError'
'401':
description: Unauthorized
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/UnauthorizedError'
'500':
description: Internal Server Error
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/InternalServerError'
'503':
description: Service Unavailable
headers: {}
content:
application/json;charset=UTF-8:
schema:
$ref: '#/components/schemas/ServiceUnavailableError'
security: []
requestBody:
content:
application/json:
schema:
type: string
description: param2
components:
schemas:
InternalServerError:
type: object
required:
- status
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
message:
type: string
example: An error has occurred.
description: The messages indicating the cause or reason for failure.
status:
type: string
example: '500'
description: The HTTP status code for the error (same as in the HTTP response).
enum:
- '500'
description: ''
CreatedReference_VulnerabilityExceptionID_Link:
type: object
properties:
id:
type: integer
format: int32
example: 1
description: The identifier of the resource created.
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
description: ''
Review:
type: object
properties:
comment:
type: string
example: ''
description: 'A comment from the reviewer detailing the review. '
readOnly: true
date:
type: string
example: ''
description: The date and time the review took place.
readOnly: true
links:
type: array
items:
$ref: '#/components/schemas/Link'
name:
type: string
example: ''
description: The identifier of the user that reviewed the vulnerability exception.
readOnly: true
user:
type: integer
format: int32
example: ''
description: The login name of the user that reviewed the vulnerability exception.
readOnly: true
description: ''
Submission:
type: object
properties:
comment:
type: string
example: ''
description: A comment from the submitter as to why the exception was submitted.
date:
type: string
example: ''
description: The date and time the vulnerability exception was submitted.
readOnly: true
links:
type: array
items:
$ref: '#/components/schemas/Link'
name:
type: string
example: ''
description: The login name of the user that submitted the vulnerability exception.
readOnly: true
reason:
type: string
example: ''
description: 'The reason the vulnerability exception was submitted. One of: `"False Positive"`, `"Compensating Control"`, `"Acceptable Use"`, `"Acceptable Risk"`, `"Other"`'
user:
type: integer
format: int32
example: ''
description: The identifier of the user that submitted the vulnerability exception.
readOnly: true
description: ''
Link:
type: object
properties:
href:
type: string
example: https://hostname:3780/api/3/...
description: 'A hypertext reference, which is either a URI (see <a target="_blank" rel="noopener noreferrer" href="https://tools.ietf.org/html/rfc3986">RFC 3986</a>) or URI template (see <a target="_blank" rel="noopener noreferrer" href="https://tools.ietf.org/html/rfc6570">RFC 6570</a>). '
rel:
type: string
example: self
description: The link relation type. This value is one from the <a target="_blank" rel="noopener noreferrer" href="https://tools.ietf.org/html/rfc5988#section-6.2">Link Relation Type Registry</a> or is the type of resource being linked to.
description: ''
VulnerabilityException:
type: object
properties:
expires:
type: string
example: ''
description: The date and time the vulnerability exception is set to expire.
id:
type: integer
format: int32
example: ''
description: The identifier of the vulnerability exception.
readOnly: true
links:
type: array
items:
$ref: '#/components/schemas/Link'
review:
example: ''
description: Details regarding the review and/or approval of the exception.
readOnly: true
$ref: '#/components/schemas/Review'
scope:
example: ''
description: The scope of the vulnerability exception, indicating the results it applies to.
$ref: '#/components/schemas/ExceptionScope'
state:
type: string
example: ''
description: 'The state of the vulnerability exception. One of: `"Deleted"`, `"Expired"`, `"Approved"`, `"Rejected"`, `"Under Review".'
submit:
example: ''
description: Details regarding the submission of the exception.
readOnly: true
$ref: '#/components/schemas/Submission'
description: ''
NotFoundError:
type: object
required:
- status
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
message:
type: string
example: An error has occurred.
description: The messages indicating the cause or reason for failure.
status:
type: string
example: '404'
description: The HTTP status code for the error (same as in the HTTP response).
enum:
- '404'
description: ''
PageInfo:
type: object
properties:
number:
type: integer
format: int64
example: 6
description: The index (zero-based) of the current page returned.
size:
type: integer
format: int64
example: 10
description: The maximum size of the page returned.
totalPages:
type: integer
format: int64
example: 13
description: The total number of pages available.
totalResources:
type: integer
format: int64
example: 123
description: The total number of resources available across all pages.
description: ''
UnauthorizedError:
type: object
required:
- status
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
message:
type: string
example: An error has occurred.
description: The messages indicating the cause or reason for failure.
status:
type: string
example: '401'
description: The HTTP status code for the error (same as in the HTTP response).
enum:
- '401'
description: ''
BadRequestError:
type: object
required:
- status
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
message:
type: string
example: An error has occurred.
description: The messages indicating the cause or reason for failure.
status:
type: string
example: '400'
description: The HTTP status code for the error (same as in the HTTP response).
enum:
- '400'
description: ''
ExceptionScope:
type: object
properties:
id:
type: integer
format: int64
example: ''
description: The identifier of the scope type to which the exception applies. For example in a site scoped vulnerability exception this is the site id, in an asset group vulnerability exception this is the asset group id.
key:
type: string
example: ''
description: If the scope type is `"Instance"`, an optional key to discriminate the instance the exception applies to.
links:
type: array
items:
$ref: '#/components/schemas/Link'
port:
type: integer
format: int32
example: ''
description: If the scope type is `"Instance"` and the vulnerability is detected on a service, the port on which the exception applies.
type:
type: string
example: ''
description: 'The type of the exception scope. One of: `"Global"`, `"Site"`, `"Asset"`, `"Asset Group"`, `"Instance"`'
vulnerability:
type: string
example: ''
description: The identifier of the vulnerability to which the exception applies.
description: ''
Links:
type: object
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
description: ''
PageOf_VulnerabilityException:
type: object
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
page:
example: ''
description: The details of pagination indicating which page was returned, and how the remaining pages can be retrieved.
$ref: '#/components/schemas/PageInfo'
resources:
type: array
description: The page of resources returned.
items:
$ref: '#/components/schemas/VulnerabilityException'
description: ''
ServiceUnavailableError:
type: object
required:
- status
properties:
links:
type: array
description: Hypermedia links to corresponding or related resources.
items:
$ref: '#/components/schemas/Link'
message:
type: string
example: An error has occurred.
description: The messages indicating the cause or reason for failure.
status:
type: string
example: '503'
description: The HTTP status code for the error (same as in the HTTP response).
enum:
- '503'
description: ''
securitySchemes:
Basic:
type: http
scheme: basic