Trivy Health API

Server health and liveness checks

OpenAPI Specification

trivy-health-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Trivy Server Health API
  description: The Trivy Server API exposes HTTP endpoints when running Trivy in client/server mode. In this mode, the server maintains a local vulnerability database and clients submit scan requests without needing to download the database themselves. The server listens on port 4954 by default and supports optional token-based authentication.
  version: 0.70.0
  contact:
    url: https://trivy.dev/
  license:
    name: Apache 2.0
    url: https://github.com/aquasecurity/trivy/blob/main/LICENSE
servers:
- url: http://localhost:4954
  description: Trivy server default endpoint
- url: http://{host}:{port}
  description: Custom Trivy server endpoint
  variables:
    host:
      default: localhost
      description: Trivy server hostname
    port:
      default: '4954'
      description: Trivy server port
tags:
- name: Health
  description: Server health and liveness checks
paths:
  /healthz:
    get:
      operationId: healthCheck
      summary: Health Check
      description: Check if the Trivy server is running and healthy. Returns 200 OK with "ok" body when the server is operational. Does not require authentication.
      tags:
      - Health
      responses:
        '200':
          description: Server is healthy
          content:
            text/plain:
              schema:
                type: string
                example: ok
components:
  securitySchemes:
    TrivyToken:
      type: apiKey
      in: header
      name: Trivy-Token
      description: Optional token-based authentication. When the server is started with --token, all requests must include the token in the Trivy-Token header.
externalDocs:
  description: Trivy Client/Server Documentation
  url: https://trivy.dev/latest/docs/references/modes/client-server/