Tenable Attachments API

With the Attachments API, you can download auxiliary files generated by plugins during a scan. These attachments provide forensic evidence and deeper context for identified vulnerabilities. For more information, see the [Tenable Web App Scanning User Guide](https://docs.tenable.com/web-app-scanning/).

Operations 1

GET /was/v2/attachments/{attachment_id} Download attachment #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/tenable-attachments-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

tenable-attachments-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: 1.0.0
  title: Web Application Scanning v2 Attachments API
  license:
    name: Web App Scanning
  description: The Tenable Web App Scanning v2 API serves as a gateway for you to interact with the Tenable Web App Scanning application and enables users to automate the security management of web applications.
servers:
- url: https://cloud.tenable.com
security:
- cloud: []
tags:
- name: Attachments
  description: 'With the Attachments API, you can download auxiliary files generated by plugins during a scan. These attachments provide forensic evidence and deeper context for identified vulnerabilities.


    For more information, see the Tenable Web App Scanning User Guide.'
paths:
  /was/v2/attachments/{attachment_id}:
    get:
      summary: Download attachment
      description: 'Returns the specified attachment file for a vulnerability detected by a Tenable Web App Scanning scan. Attachments provide additional details for a detected vulnerability.


        **Note:** The `transfer-encoding` header value of the response stream is set to `chunked`.

        Requires the Basic [16] user role or the `WAS.TOGGLE_WAS.USE` custom role privilege. Additionally, requires the Can View [16] scan permission. See Roles and Permissions.'
      operationId: was-v2-attachments-download
      tags:
      - Attachments
      parameters:
      - in: path
        name: attachment_id
        required: true
        schema:
          type: string
          format: uuid
        description: The UUID of the attachment to download. To determine the UUID of an attachment, use either the [GET /was/v2/vulnerabilities](ref:was-v2-vulns-list) or [GET /was/v2/scans/{scan_id}/vulnerabilities](ref:was-v2-scans-details-vulns) endpoint.
      responses:
        '200':
          description: Returns the specified attachment file as a chunked transfer-encoded stream.
          content:
            text/plain:
              schema:
                type: string
              examples:
                response:
                  value: 'PUT /tenable-wasscan-9a3511f8-7852-4096-a7c0-6065ff8ebad3 HTTP/1.1

                    Host: testfire.net

                    Accept-Encoding: gzip, deflate

                    User-Agent: Nessus WAS/%v

                    X-Tenable-Wasscan-Id: 9a3511f8-7852-4096-a7c0-6065ff8ebad3

                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8

                    Accept-Language: en-US,en;q=0.5

                    Cookie: JSESSIONID=76893A2AF20FA28774258A1FF4877A86

                    Content-Length: 68

                    Created by Tenable WAS scan. PUT9a3511f8-7852-4096-a7c0-6065ff8ebad3'
            image/png:
              schema:
                type: string
                format: binary
        '400':
          description: Returned if your request specifies an invalid attachment ID.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                response:
                  value:
                    reasons:
                    - code: INVALID_ID_FORMAT
                      reason: The provided ID of '1234567' must be UUID type
        '401':
          description: Returned if the API keys specified in your request are invalid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                response:
                  value:
                    statusCode: 401
                    error: Unauthorized
                    message: Invalid credentials.
        '404':
          description: Returned if Tenable Web App Scanning cannot find the specified attachment file.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                response:
                  value:
                    reasons:
                    - code: NOT_FOUND
                      reason: Resource with ID 'b29f198c-eac6-4107-b046-c621f542cd39' not found
        '429':
          description: Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](doc:rate-limiting).
          content:
            text/html:
              examples:
                response:
                  value: "<html>\n\n<head>\n    <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n    <center>\n        <h1>429 Too Many Requests</h1>\n    </center>\n    <hr>\n    <center>nginx</center>\n</body>\n\n</html>"
        '500':
          description: Returned if an internal error occurred.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                response:
                  value:
                    statusCode: 500
                    error: Internal Server Error
                    message: An internal server error occurred. Please wait a moment and try your request again.
components:
  schemas:
    ErrorResponse:
      type: object
      required:
      - reasons
      description: Tenable Web App Scanning error response.
      properties:
        reasons:
          type: array
          description: A list of reasons for the Tenable Web App Scanning error.
          items:
            type: object
            description: A reason for the Tenable Web App Scanning error, including a code and an extended description.
            minItems: 1
            required:
            - code
            - reason
            properties:
              code:
                type: string
                description: "The Tenable Web App Scanning error code. Error code values include:\n - `NOT_FOUND`—Returned if Tenable Web App Scanning could not find the resource you specified.\n - `INVALID_ID_FORMAT`—Returned if you specify a resource ID in an invalid format.\n - `INVALID_PARAMETER`—Returned if you specify an invalid URL parameter.\n- `INVALID_JSON_BODY`—Returned if you specify invalid JSON in request payload.\n - `DUPLICATE_ENTITY`—Returned if you attempt to create a duplicate resource.\n - `NOT_ALLOWED`—Returned if Tenable Web App Scanning encounters a stateful conflict, for example, if you attempt to start a scan that is already in progress.\n - `OPERATION_FORBIDDEN`—Returned if you do not have sufficient permissions to access a resource or complete a task."
              reason:
                type: string
                description: The extended description of the cause of the Tenable Web App Scanning error.
  securitySchemes:
    cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
x-readme:
  proxy-enabled: false
  samples-languages:
  - python
  - curl
  - node
  - powershell
  - ruby
  - javascript
  - objectivec
  - java
  - php
  - csharp
  - go
  - swift
  - kotlin