StackHawk Scan Results API
Scan result reporting and findings
Scan result reporting and findings
openapi: 3.0.1
info:
title: StackHawk Api Authentication Scan Results API
description: The StackHawk Public API provides programmatic access to the StackHawk application and API security testing platform. Manage applications, environments, scan configurations, scan results, findings, repositories, teams, policies, and security reports. Authentication requires obtaining a JWT token via the /api/v1/auth/login endpoint using an API key from the StackHawk platform settings.
version: 0.0.1
contact:
url: https://www.stackhawk.com/
email: support@stackhawk.com
termsOfService: https://www.stackhawk.com/terms/
servers:
- url: https://api.stackhawk.com
description: StackHawk API
security:
- BearerAuth: []
tags:
- name: Scan Results
description: Scan result reporting and findings
paths:
/api/v1/app/{appId}/env/{envId}/scan:
get:
operationId: listScans
summary: List Scans
description: List all scans for an application environment.
tags:
- Scan Results
parameters:
- name: appId
in: path
required: true
schema:
type: string
- name: envId
in: path
required: true
schema:
type: string
- name: pageToken
in: query
schema:
type: string
- name: pageSize
in: query
schema:
type: integer
responses:
'200':
description: List of scans
content:
application/json:
schema:
$ref: '#/components/schemas/ScanListResponse'
/api/v1/app/{appId}/env/{envId}/scan/{scanId}:
get:
operationId: getScan
summary: Get Scan
description: Retrieve details for a specific scan.
tags:
- Scan Results
parameters:
- name: appId
in: path
required: true
schema:
type: string
- name: envId
in: path
required: true
schema:
type: string
- name: scanId
in: path
required: true
schema:
type: string
responses:
'200':
description: Scan details
content:
application/json:
schema:
$ref: '#/components/schemas/Scan'
delete:
operationId: deleteScan
summary: Delete Scan
description: Delete a scan and its associated findings.
tags:
- Scan Results
parameters:
- name: appId
in: path
required: true
schema:
type: string
- name: envId
in: path
required: true
schema:
type: string
- name: scanId
in: path
required: true
schema:
type: string
responses:
'204':
description: Scan deleted
/api/v1/app/{appId}/env/{envId}/scan/{scanId}/finding:
get:
operationId: listFindings
summary: List Findings
description: List all security findings from a specific scan.
tags:
- Scan Results
parameters:
- name: appId
in: path
required: true
schema:
type: string
- name: envId
in: path
required: true
schema:
type: string
- name: scanId
in: path
required: true
schema:
type: string
responses:
'200':
description: List of findings
content:
application/json:
schema:
$ref: '#/components/schemas/FindingListResponse'
/api/v1/app/{appId}/env/{envId}/scan/{scanId}/finding/{findingId}:
get:
operationId: getFinding
summary: Get Finding
description: Retrieve details for a specific security finding.
tags:
- Scan Results
parameters:
- name: appId
in: path
required: true
schema:
type: string
- name: envId
in: path
required: true
schema:
type: string
- name: scanId
in: path
required: true
schema:
type: string
- name: findingId
in: path
required: true
schema:
type: string
responses:
'200':
description: Finding details
content:
application/json:
schema:
$ref: '#/components/schemas/Finding'
components:
schemas:
ScanListResponse:
type: object
properties:
scans:
type: array
items:
$ref: '#/components/schemas/Scan'
nextPageToken:
type: string
Scan:
type: object
properties:
scanId:
type: string
appId:
type: string
envId:
type: string
status:
type: string
enum:
- RUNNING
- COMPLETED
- FAILED
startedAt:
type: string
format: date-time
completedAt:
type: string
format: date-time
findingCount:
type: integer
Finding:
type: object
properties:
findingId:
type: string
scanId:
type: string
severity:
type: string
enum:
- LOW
- MEDIUM
- HIGH
- CRITICAL
title:
type: string
description:
type: string
path:
type: string
method:
type: string
FindingListResponse:
type: object
properties:
findings:
type: array
items:
$ref: '#/components/schemas/Finding'
securitySchemes:
BearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
description: JWT token obtained via /api/v1/auth/login