Sonatype Advanced Search API

Use the Advanced Search REST API to perform searches on Lifecycle application scan reports.

Operations 4

GET /api/v2/search/advanced Search index #
GET /api/v2/search/advanced/export/csv Get export results #
POST /api/v2/search/advanced/index Create search index async #
POST /api/v2/search/advanced/index/cancel Cancel search index rebuild #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sonatype-advanced-search-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sonatype-advanced-search-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Sonatype Advanced Search API
  version: '1.0'
  description: 'Operations tagged Advanced Search across 2 of this provider''s published API definitions: sonatype-lifecycle-openapi.yml, sonatype-iq-openapi.yml. Each path carries the servers of the definition it was published in.'
security:
- BasicAuth: []
  BearerAuth: []
tags:
- description: Use the Advanced Search REST API to perform searches on Lifecycle application scan reports.
  name: Advanced Search
paths:
  /api/v2/search/advanced:
    get:
      description: Use this method to perform an Advanced Search.
      operationId: searchIndex
      parameters:
      - description: Enter your search query here
        in: query
        name: query
        schema:
          type: string
      - description: Enter the no. of results that should be visible per page
        in: query
        name: pageSize
        schema:
          default: 10
          format: int32
          type: integer
      - description: Enter the page no. for the page containing results
        in: query
        name: page
        schema:
          format: int32
          type: integer
      - description: Set to `true` to retrieve results that include components with no violations
        in: query
        name: allComponents
        schema:
          default: false
          type: boolean
      - in: query
        name: mode
        schema:
          enum:
          - sbomManager
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SearchResultDTO'
          description: "Response JSON containing the search query sent in the API call, and other response fields as follows: \n1. searchQuery: search query sent in the request \n2. page: page number of search results requested \n3. pageSize: requested number of results per page \n4. totalNumberOfHits: total number of results returned \n5. isExactTotalNumberOfHits \n    * `true` indicates that the search results in the JSON is the same no. of search results that logically      match the search query. \n    * `false` indicates that the search results in the JSON are lower bound because fetching all results is     too expensive to compute. \n6. groupingByDTOS: array of search results grouped on a field name \n7. groupIdentifier: field name that the search results have been grouped by \n8. groupBy: field value that the search results have been grouped by \n9. additionalInfo: shared information between groups, e.g. info if grouped by a security vulnerability \n10. searchResultItemDTOS: array of search results with each element containing an itemType, field names and values \n11. resultIndex: indicating the relevance of the search result w.r.t. the query"
        '409':
          description: Search index not found. The Advanced Search index is unavailable or has not been created yet. Re-indexing is required before results can be returned.
      tags:
      - Advanced Search
      summary: Search index
      x-summary-source: derived
  /api/v2/search/advanced/export/csv:
    get:
      description: Use this method to generate a csv file containing your search results. The default delimiter in the generated file is comma. Use the advancedSearchCSVExportDelimiter property of the Configuration REST API to change the delimiter in the generated file.
      operationId: getExportResults
      parameters:
      - description: A well-formed search query.
        in: query
        name: query
        required: true
        schema:
          type: string
      - description: Enter the no. of results that should be visible per page, unset gives all results
        in: query
        name: pageSize
        schema:
          format: int32
          type: integer
      - description: Enter the page no. for the page containing results
        in: query
        name: page
        schema:
          format: int32
          type: integer
      - description: Set to `true` to retrieve results that include components with no violations.
        in: query
        name: allComponents
        schema:
          default: false
          type: boolean
      - in: query
        name: mode
        schema:
          enum:
          - sbomManager
          type: string
      responses:
        '200':
          description: Downloadable csv file generated successfully.
        '409':
          description: Search index does not exist or is unreadable.
      tags:
      - Advanced Search
      summary: Get export results
      x-summary-source: derived
  /api/v2/search/advanced/index:
    post:
      description: 'Use this method to create or rebuild the index for Advanced Search. This is a resource intensive operation. Avoid creating indexes during peak usage hours.


        Permissions required: Edit System Configuration and Users'
      operationId: createSearchIndexAsync
      responses:
        '204':
          description: Index created successfully.
      tags:
      - Advanced Search
      summary: Create search index async
      x-summary-source: derived
  /api/v2/search/advanced/index/cancel:
    post:
      tags:
      - Advanced Search
      description: 'Request cancellation of an in-flight Advanced Search index rebuild. On a Lucene-backed deployment the previous complete index continues to serve search results. Cancellation is not supported on OpenSearch-backed deployments, where the rebuild runs to completion. Use the status method to confirm whether a rebuild is still in progress.


        Permissions required: Edit System Configuration and Users'
      operationId: cancelSearchIndexRebuild
      responses:
        '204':
          description: Cancel requested.
      summary: Cancel search index rebuild
      x-summary-source: derived
components:
  schemas:
    GroupingByDTO:
      properties:
        additionalInfo:
          type: string
        groupBy:
          type: string
        groupIdentifier:
          enum:
          - itemType
          - organizationId
          - organizationName
          - applicationId
          - applicationName
          - applicationPublicId
          - policyEvaluationStage
          - applicationVersion
          - reportId
          - componentHash
          - componentFormat
          - componentName
          - componentCoordinate
          - vulnerabilityId
          - vulnerabilitySeverity
          - vulnerabilityStatus
          - vulnerabilityDescription
          - applicationCategoryId
          - applicationCategoryName
          - applicationCategoryColor
          - applicationCategoryDescription
          - componentLabelId
          - componentLabelName
          - componentLabelColor
          - componentLabelDescription
          - policyId
          - policyName
          - policyThreatCategory
          - policyThreatLevel
          - parentOrganizationName
          - parentOrganizationId
          - sbomSpecification
          type: string
        searchResultItemDTOS:
          items:
            $ref: '#/components/schemas/SearchResultItemDTO'
          type: array
      type: object
    ApiComponentIdentifierDTOV2:
      properties:
        coordinates:
          additionalProperties:
            type: string
          type: object
        format:
          type: string
      type: object
    SearchResultDTO:
      properties:
        groupingByDTOS:
          items:
            $ref: '#/components/schemas/GroupingByDTO'
          type: array
        isExactTotalNumberOfHits:
          type: boolean
        page:
          format: int32
          type: integer
        pageSize:
          format: int32
          type: integer
        searchAfter:
          items:
            type: string
          type: array
        searchQuery:
          type: string
        totalNumberOfHits:
          format: int64
          type: integer
      type: object
    SearchResultItemDTO:
      properties:
        applicationCategoryColor:
          type: string
        applicationCategoryDescription:
          type: string
        applicationCategoryId:
          type: string
        applicationCategoryName:
          type: string
        applicationId:
          type: string
        applicationName:
          type: string
        applicationPublicId:
          type: string
        applicationVersion:
          type: string
        componentHash:
          type: string
        componentIdentifier:
          $ref: '#/components/schemas/ApiComponentIdentifierDTOV2'
        componentLabelColor:
          type: string
        componentLabelDescription:
          type: string
        componentLabelId:
          type: string
        componentLabelName:
          type: string
        componentName:
          type: string
        itemType:
          type: string
        organizationId:
          type: string
        organizationName:
          type: string
        policyEvaluationStage:
          type: string
        policyId:
          type: string
        policyName:
          type: string
        policyThreatCategory:
          type: string
        policyThreatLevel:
          format: int32
          type: integer
        reportId:
          type: string
        resultIndex:
          format: int32
          type: integer
        sbomSpecification:
          type: string
        vulnerabilityDescription:
          type: string
        vulnerabilityId:
          type: string
        vulnerabilityStatus:
          type: string
      type: object
    GroupingByDTO_2:
      type: object
      properties:
        groupIdentifier:
          type: string
          enum:
          - itemType
          - organizationId
          - organizationName
          - applicationId
          - applicationName
          - applicationPublicId
          - policyEvaluationStage
          - applicationVersion
          - reportId
          - componentHash
          - componentFormat
          - componentName
          - componentCoordinate
          - componentCoordinateArtifactId
          - componentCoordinateGroupId
          - componentCoordinateName
          - componentCoordinateExtension
          - componentCoordinateArchitecture
          - componentCoordinatePlatform
          - componentCoordinateVersion
          - componentCoordinateClassifier
          - componentCoordinateQualifier
          - componentCoordinatePackageId
          - vulnerabilityId
          - vulnerabilitySeverity
          - vulnerabilityStatus
          - vulnerabilityDescription
          - applicationCategoryId
          - applicationCategoryName
          - applicationCategoryColor
          - applicationCategoryDescription
          - componentLabelId
          - componentLabelName
          - componentLabelColor
          - componentLabelDescription
          - policyId
          - policyName
          - policyThreatCategory
          - policyThreatLevel
          - parentOrganizationName
          - parentOrganizationId
          - sbomSpecification
          - policyViolationId
          - policyViolationThreatCategory
          - policyViolationThreatLevel
          - policyViolationPolicyName
          - policyViolationPolicyId
          - policyViolationWaiverStatus
          - policyViolationConstraintName
          - componentEffectiveLicenseId
          - componentEffectiveLicenseName
          - componentLicenseThreatGroupName
          - componentLicenseThreatLevel
          - allowedContextIds
          - documentKey
          - policyWaiverId
          - policyWaiverPolicyName
          - policyWaiverPolicyId
          - policyWaiverReason
          - policyWaiverComment
          - policyWaiverCreatedAt
          - policyWaiverCreatedAtEpochMs
          - policyWaiverExpiresAt
          - policyWaiverExpiresAtEpochMs
          - policyWaiverScopeOwnerId
          - policyWaiverScopeOwnerType
          - policyWaiverThreatLevel
          - policyWaiverWaivedBy
          - policyWaiverAuto
          - policyWaiverIsAuto
          - policyWaiverExpiryStatus
          - policyWaiverPolicyType
          - policyWaiverScope
          - policyWaiverRequestStatus
          - requesterName
          - reviewerName
          - reviewTime
          - rejectionReason
          - noteToReviewer
          - applicationLastEvaluationTimeEpochMs
          - applicationStageSeverityCount
          - componentViolationPolicyType
          - componentViolationState
          - componentMaxPolicyThreatLevel
          - vulnerabilityFirstSeenEpochMs
          - applicationMaxPolicyThreatLevel
          - applicationViolationStage
          - applicationViolationPolicyType
          - applicationViolationState
          - applicationViolationStateSortOrdinal
        groupBy:
          type: string
        additionalInfo:
          type: string
        searchResultItemDTOS:
          type: array
          items:
            $ref: '#/components/schemas/SearchResultItemDTO_2'
    SearchResultItemDTO_2:
      type: object
      properties:
        itemType:
          type: string
        organizationId:
          type: string
        organizationName:
          type: string
        applicationId:
          type: string
        applicationPublicId:
          type: string
        applicationName:
          type: string
        applicationVersion:
          type: string
        sbomSpecification:
          type: string
        policyEvaluationStage:
          type: string
        reportId:
          type: string
        componentHash:
          type: string
        componentIdentifier:
          $ref: '#/components/schemas/ApiComponentIdentifierDTOV2'
        componentName:
          type: string
        vulnerabilityId:
          type: string
        vulnerabilityDescription:
          type: string
        vulnerabilitySeverity:
          type: number
          format: float
        vulnerabilityStatus:
          type: string
        vulnerabilityFirstSeenEpochMs:
          type: integer
          format: int64
        applicationCategoryId:
          type: string
        applicationCategoryName:
          type: string
        applicationCategoryNames:
          type: array
          items:
            type: string
        applicationViolationStages:
          type: array
          items:
            type: string
        applicationViolationPolicyTypes:
          type: array
          items:
            type: string
        applicationViolationStates:
          type: array
          items:
            type: string
        componentViolationPolicyTypes:
          type: array
          items:
            type: string
        componentViolationStates:
          type: array
          items:
            type: string
        applicationLastEvaluationTimeEpochMs:
          type: integer
          format: int64
        applicationStageSeverityCounts:
          type: array
          items:
            type: string
        applicationCategoryColor:
          type: string
        applicationCategoryDescription:
          type: string
        componentLabelId:
          type: string
        componentLabelName:
          type: string
        componentLabelColor:
          type: string
        componentLabelDescription:
          type: string
        policyId:
          type: string
        policyName:
          type: string
        policyThreatCategory:
          type: string
        policyThreatLevel:
          type: integer
          format: int32
        policyViolationId:
          type: string
        policyViolationThreatCategory:
          type: string
        policyViolationThreatLevel:
          type: integer
          format: int32
        policyViolationPolicyName:
          type: string
        policyViolationPolicyId:
          type: string
        policyViolationWaiverStatus:
          type: string
        policyViolationConstraintName:
          type: string
        componentEffectiveLicenseId:
          type: string
        componentEffectiveLicenseName:
          type: string
        componentLicenseThreatGroupName:
          type: string
        componentLicenseThreatLevel:
          type: integer
          format: int32
        policyWaiverId:
          type: string
        policyWaiverPolicyName:
          type: string
        policyWaiverPolicyId:
          type: string
        policyWaiverReason:
          type: string
        policyWaiverComment:
          type: string
        policyWaiverCreatedAt:
          type: string
        policyWaiverExpiresAt:
          type: string
        policyWaiverScopeOwnerId:
          type: string
        policyWaiverScopeOwnerType:
          type: string
        policyWaiverThreatLevel:
          type: integer
          format: int32
        policyWaiverWaivedBy:
          type: string
        policyWaiverAuto:
          type: boolean
        policyWaiverIsAuto:
          type: boolean
        policyWaiverExpiryStatus:
          type: string
        policyWaiverPolicyType:
          type: string
        policyWaiverScope:
          type: string
        policyWaiverRequestStatus:
          type: string
        requesterName:
          type: string
        reviewerName:
          type: string
        reviewTime:
          type: string
        rejectionReason:
          type: string
        noteToReviewer:
          type: string
        resultIndex:
          type: integer
          format: int32
  securitySchemes:
    BasicAuth:
      scheme: basic
      type: http
    BearerAuth:
      bearerFormat: JWT
      scheme: bearer
      type: http
x-refined-from:
- sonatype-lifecycle-openapi.yml
- sonatype-iq-openapi.yml