Qwiet Ai

Qwiet AI (by Harness, formerly ShiftLeft) is an application security testing platform that unifies SAST, SCA, secrets, IaC, and container scanning with AI-assisted AutoFix remediation. The Qwiet AI API v4 (https://app.shiftleft.io/api/v4) lets teams programmatically manage applications, run and read code scans, work with findings and source-to-sink data flows, request and apply AutoFix recommendations, look up package CVEs (Intelligent SCA), manage RBAC/teams/tokens, and configure alerting webhooks and Slack notifications. Qwiet also ships a first-party CLI (`sl`), a published MCP server (harness-code-security-mcp), and packaged agent skills, making its code-security workflows agent-ready. Surfaced as a portfolio company of Mayfield and enriched from the provider's public developer surface.

Qwiet Ai publishes 27 APIs on the APIs.io network, including alerting API, analyze API, app_groups API, and 24 more. Tagged areas include Company, Security, Application Security, SAST, and SCA.

The Qwiet Ai catalog on APIs.io includes 1 event-driven AsyncAPI specification.

Qwiet Ai’s developer surface includes documentation, API reference, getting-started guide, support, pricing, authentication, CLI, and 20 more developer resources.

53.2/100 developing ▬ flat Agent 57/100 agent ready Full breakdown ↓
scored 2026-07-27 · rubric v0.5
AccessSelf serve
27 APIs 1 MCP Servers
CompanySecurityApplication SecuritySASTSCACode SecurityVulnerability ManagementDevSecOpsAutoFix

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 53.2/100 · developing
Contract Quality 16.0 / 25
Developer Ergonomics 16.5 / 20
Commercial Clarity 8.9 / 20
Operational Transparency 1.7 / 13
Governance 0.0 / 12
Discoverability 10.0 / 10
Agent readiness — 57/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 6 / 6
Agent Skills 5 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/qwiet-ai: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 27

Individual APIs this provider publishes, each with its own machine-readable definition.

Qwiet Ai alerting API

Notification and alerting related endpoints (such as webhooks)

Qwiet Ai analyze API

The analyze API from Qwiet Ai — 2 operation(s) for analyze.

Qwiet Ai app_groups API

The user-created groups of applications. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-3251cbed-4ae3-4b06-8cad-c8748e49c...

Qwiet Ai app_labels API

The user-created application labels. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/30743751-da3c929b-651f-414c-993c-ee2b2573b2f4...

Qwiet Ai apps API

The applications submitted for analysis. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-e9d0bf19-30bd-46f4-b40c-9df03d2a4...

Qwiet Ai autofix API

The AutoFix suggestions for findings in applications. Harness SAST and SCA AutoFix uses large language models (LLMs) to generate potential code fix suggestions for findings prod...

Qwiet Ai azureboard API

The endpoints to manage the Azure Boards integration.

Qwiet Ai branches API

The branch information for scans of applications.

Qwiet Ai comments API

The text threads (with individual comments ordered by time) attached to findings. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/...

Qwiet Ai compounds API

Multi-Language Apps are groups of applications that are scanned together as a single application. This is useful for applications that are a compound of various programming lang...

Qwiet Ai findings API

The results of a scan (which can include vulnerabilities, secrets, or insights). [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9...

Qwiet Ai org_backup API

The endpoints for downloading backups of an organization's data.

Qwiet Ai orgs API

The logical grouping (e.g., tenant/account) within Qwiet that defines a set of users, teams, and applications. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.g...

Qwiet Ai rbac API

Roles-based access control (RBAC) allows you to control the permissions users in an organization are granted. The permissions granted to a user are additive. The base level of a...

Qwiet Ai reports API

The summaries of applications and their findings for a specific organization. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829...

Qwiet Ai SAML API

The integration endpoints allowing orgs to configure Qwiet to act as a SAML service provider (SP) that uses the customer's identity provider (IdP) to log users in. [![Run in Pos...

Qwiet Ai sarif API

The integration endpoints for generating and downloading SARIF reports for applications.

Qwiet Ai saved_searches API

The saved searches endpoints allow users to save specific search queries for organization and app findings

Qwiet Ai sca API

The summaries of software composition analysis (SCA) results for apps in an organization. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-col...

Qwiet Ai scans API

The instances where Qwiet AI by Harness is invoked to identify findings in an application. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-co...

Qwiet Ai scopes API

Scopes define the type of resource and the operation that you can perform with the access token you bear. For example, `scans:create` means that the bearer of the token with thi...

Qwiet Ai slack API

The integration endpoints enabling users to set up a Slack integration.

Qwiet Ai team_config API

The endpoints to manage team-level configuration.

Qwiet Ai tokens API

Used to authenticate with the API. Can be issued by org admins. Each access token is owned by the org that issued it. [![Run in Postman](https://run.pstmn.io/button.svg)](https:...

Qwiet Ai users API

Users pertains the users in general as qwiet.ai users and of each org as organization users.

Qwiet Ai versions API

The specific instances of an application scanned using Qwiet AI by Harness. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/982931...

Qwiet Ai wiz API

The endpoints to manage the Wiz integration.

Scroll for all 27

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

qwiet-ai-mcp.yml

MCP SERVER

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Qwiet Ai Authentication

http · 1 scheme

SECURITY

Qwiet Ai Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 5

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: qwiet-ai
name: Qwiet Ai
description: Qwiet AI (by Harness, formerly ShiftLeft) is an application security testing platform that unifies SAST, SCA,
  secrets, IaC, and container scanning with AI-assisted AutoFix remediation. The Qwiet AI API v4 (https://app.shiftleft.io/api/v4)
  lets teams programmatically manage applications, run and read code scans, work with findings and source-to-sink data flows,
  request and apply AutoFix recommendations, look up package CVEs (Intelligent SCA), manage RBAC/teams/tokens, and configure
  alerting webhooks and Slack notifications. Qwiet also ships a first-party CLI (`sl`), a published MCP server (harness-code-security-mcp),
  and packaged agent skills, making its code-security workflows agent-ready. Surfaced as a portfolio company of Mayfield and
  enriched from the provider's public developer surface.
url: https://raw.githubusercontent.com/api-evangelist/qwiet-ai/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- mayfield
x-tier: stub
x-tier-reason: portfolio-lead
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-20'
tags:
- Company
- Security
- Application Security
- SAST
- SCA
- Code Security
- Vulnerability Management
- DevSecOps
- AutoFix
image: https://docs.shiftleft.io/img/sl-logo.svg
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
apis:
- aid: qwiet-ai:qwiet-ai-alerting-api
  name: Qwiet Ai alerting API
  description: Notification and alerting related endpoints (such as webhooks)
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - alerting
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-alerting-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-analyze-api
  name: Qwiet Ai analyze API
  description: The analyze API from Qwiet Ai — 2 operation(s) for analyze.
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - analyze
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-analyze-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-app-groups-api
  name: Qwiet Ai app_groups API
  description: 'The user-created groups of applications.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-3251cbed-4ae3-4b06-8cad-c8748e49c7ec?action=collection%2Ffork&collection-url=entityId%3D9829310-3251cbed-4ae3-4b06-8cad-c8748e49c7ec%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - app_groups
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-app-groups-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-app-labels-api
  name: Qwiet Ai app_labels API
  description: 'The user-created application labels.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/30743751-da3c929b-651f-414c-993c-ee2b2573b2f4?action=collection%2Ffork&collection-url=entityId%3D30743751-da3c929b-651f-414c-993c-ee2b2573b2f4%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - app_labels
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-app-labels-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-apps-api
  name: Qwiet Ai apps API
  description: 'The applications submitted for analysis.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-e9d0bf19-30bd-46f4-b40c-9df03d2a463a?action=collection%2Ffork&collection-url=entityId%3D9829310-e9d0bf19-30bd-46f4-b40c-9df03d2a463a%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - apps
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-apps-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-autofix-api
  name: Qwiet Ai autofix API
  description: 'The AutoFix suggestions for findings in applications. Harness SAST and SCA AutoFix uses large language models
    (LLMs) to generate potential code fix suggestions for findings produced by Qwiet AI by Harness analyses.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/30743751-b06912bf-f25e-46a3-92c1-c12ba2ef162a?action=collection%2Ffork&collection-url=entityId%3D30743751-b06912bf-f25e-46a3-92c1-c12ba2ef162a%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - autofix
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-autofix-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-azureboard-api
  name: Qwiet Ai azureboard API
  description: The endpoints to manage the Azure Boards integration.
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - azureboard
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-azureboard-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-branches-api
  name: Qwiet Ai branches API
  description: The branch information for scans of applications.
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - branches
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-branches-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-comments-api
  name: Qwiet Ai comments API
  description: 'The text threads (with individual comments ordered by time) attached to findings.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-49dbc330-9cb4-4dac-9257-a9cc79b1103c?action=collection%2Ffork&collection-url=entityId%3D9829310-49dbc330-9cb4-4dac-9257-a9cc79b1103c%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - comments
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-comments-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-compounds-api
  name: Qwiet Ai compounds API
  description: Multi-Language Apps are groups of applications that are scanned together as a single application. This is useful
    for applications that are a compound of various programming languages and configurations of frameworks.
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - compounds
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-compounds-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-findings-api
  name: Qwiet Ai findings API
  description: 'The results of a scan (which can include vulnerabilities, secrets, or insights).

    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-156075f8-c7cf-4e2c-95fa-0823a3313658?action=collection%2Ffork&collection-url=entityId%3D9829310-156075f8-c7cf-4e2c-95fa-0823a3313658%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - findings
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-findings-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-org-backup-api
  name: Qwiet Ai org_backup API
  description: The endpoints for downloading backups of an organization's data.
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - org_backup
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-org-backup-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-orgs-api
  name: Qwiet Ai orgs API
  description: 'The logical grouping (e.g., tenant/account) within Qwiet that defines a set of users, teams, and applications.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-f0ae38d5-6c27-41a9-a1c3-9721d39f5df0?action=collection%2Ffork&collection-url=entityId%3D9829310-f0ae38d5-6c27-41a9-a1c3-9721d39f5df0%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - orgs
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-orgs-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-rbac-api
  name: Qwiet Ai rbac API
  description: 'Roles-based access control (RBAC) allows you to control the permissions users in an organization are granted.


    The permissions granted to a user are additive. The base level of a user''s permission is determined by their role in
    the organization.


    A team represents a group of users and the applications that group of users can access. Users are granted additional permissions
    based on their team role.


    Users can belong to multiple teams, but an application can only belong to one team.


    You can use the `TEAM_DEFINED` organization role to limit user access to only the apps assigned to their team.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-c002d05e-2fae-4914-8629-54cff59e1e6b?action=collection%2Ffork&collection-url=entityId%3D9829310-c002d05e-2fae-4914-8629-54cff59e1e6b%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - rbac
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-rbac-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-reports-api
  name: Qwiet Ai reports API
  description: 'The summaries of applications and their findings for a specific organization.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-b675d7af-bdd5-49a4-982b-4e57c4f4a44c?action=collection%2Ffork&collection-url=entityId%3D9829310-b675d7af-bdd5-49a4-982b-4e57c4f4a44c%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - reports
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-reports-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-saml-api
  name: Qwiet Ai SAML API
  description: 'The integration endpoints allowing orgs to configure Qwiet to act as a SAML service provider (SP) that uses
    the customer''s identity provider (IdP) to log users in.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-a411d1c3-c232-4843-a89d-b302df399d99?action=collection%2Ffork&collection-url=entityId%3D9829310-a411d1c3-c232-4843-a89d-b302df399d99%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - SAML
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-saml-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-sarif-api
  name: Qwiet Ai sarif API
  description: The integration endpoints for generating and downloading SARIF reports for applications.
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - sarif
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-sarif-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-saved-searches-api
  name: Qwiet Ai saved_searches API
  description: The saved searches endpoints allow users to save specific search queries for organization and app findings
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - saved_searches
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-saved-searches-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-sca-api
  name: Qwiet Ai sca API
  description: 'The summaries of software composition analysis (SCA) results for apps in an organization.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/30743751-08a1d64d-5913-409a-ac8a-7074ce5a62d7?action=collection%2Ffork&collection-url=entityId%3D30743751-08a1d64d-5913-409a-ac8a-7074ce5a62d7%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - sca
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-sca-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-scans-api
  name: Qwiet Ai scans API
  description: 'The instances where Qwiet AI by Harness is invoked to identify findings in an application.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-dc6a68d5-995d-4ba4-8098-e3b67773cf0e?action=collection%2Ffork&collection-url=entityId%3D9829310-dc6a68d5-995d-4ba4-8098-e3b67773cf0e%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - scans
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-scans-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-scopes-api
  name: Qwiet Ai scopes API
  description: 'Scopes define the type of resource and the operation that you can perform with the access token you bear.
    For example, `scans:create` means that the bearer of the token with this scope can create scans via the API.


    For each endpoint, we indicate the scope required to perform an operation under **Authorizations**.


    We also offer helper endpoints that allow you to determine what the allowed scopes for your access token are in the context
    of a specific API resource.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-54d0d8f3-0cc0-42c3-8eee-2eb66e1ea835?action=collection%2Ffork&collection-url=entityId%3D9829310-54d0d8f3-0cc0-42c3-8eee-2eb66e1ea835%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - scopes
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-scopes-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-slack-api
  name: Qwiet Ai slack API
  description: The integration endpoints enabling users to set up a Slack integration.
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - slack
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-slack-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-team-config-api
  name: Qwiet Ai team_config API
  description: The endpoints to manage team-level configuration.
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - team_config
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-team-config-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-tokens-api
  name: Qwiet Ai tokens API
  description: 'Used to authenticate with the API.


    Can be issued by org admins. Each access token is owned by the org that issued it.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-0a2fce9d-f679-41e8-a438-bcf13ddec403?action=collection%2Ffork&collection-url=entityId%3D9829310-0a2fce9d-f679-41e8-a438-bcf13ddec403%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - tokens
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-tokens-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-users-api
  name: Qwiet Ai users API
  description: Users pertains the users in general as qwiet.ai users and of each org as organization users.
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - users
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-users-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-versions-api
  name: Qwiet Ai versions API
  description: 'The specific instances of an application scanned using Qwiet AI by Harness.

    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-d8e4a6f2-bdce-4807-a8ca-74fc00dbc089?action=collection%2Ffork&collection-url=entityId%3D9829310-d8e4a6f2-bdce-4807-a8ca-74fc00dbc089%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - versions
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-versions-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
- aid: qwiet-ai:qwiet-ai-wiz-api
  name: Qwiet Ai wiz API
  description: The endpoints to manage the Wiz integration.
  humanURL: https://docs.shiftleft.io/api/
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - wiz
  properties:
  - type: OpenAPI
    url: openapi/qwiet-ai-wiz-api-openapi.yml
  - type: Authentication
    url: authentication/qwiet-ai-authentication.yml
  - type: Conventions
    url: conventions/qwiet-ai-conventions.yml
  - type: ErrorCatalog
    url: errors/qwiet-ai-problem-types.yml
  - type: DataModel
    url: data-model/qwiet-ai-data-model.yml
  - type: Conformance
    url: conformance/qwiet-ai-conformance.yml
  - type: Webhooks
    url: asyncapi/qwiet-ai-alerting-webhooks.yml
common:
- type: Website
  url: https://qwiet.ai
- type: DeveloperPortal
  url: https://developer.harness.io/docs/sast-and-sca/
- type: Documentation
  url: https://docs.shiftleft.io/
- type: APIReference
  url: https://docs.shiftleft.io/api/
- type: GettingStarted
  url: https://docs.shiftleft.io/inspect/getting-started/quickstart
- type: Login
  url: https://app.shiftleft.io/login
- type: GitHubOrganization
  url: https://github.com/ShiftLeftSecurity
- type: Support
  url: https://www.harness.io/support
- type: Pricing
  url: https://www.harness.io/pricing
- type: TermsOfService
  url: https://www.harness.io/legal
- type: PrivacyPolicy
  url: https://www.harness.io/legal/privacy
- type: Authentication
  url: authentication/qwiet-ai-authentication.yml
- type: DomainSecurity
  url: security/qwiet-ai-domain-security.yml
- type: Lifecycle
  url: lifecycle/qwiet-ai-lifecycle.yml
- type: Conventions
  url: conventions/qwiet-ai-conventions.yml
- type: ErrorCatalog
  url: errors/qwiet-ai-problem-types.yml
- type: DataModel
  url: data-model/qwiet-ai-data-model.yml
- type: Conformance
  url: conformance/qwiet-ai-conformance.yml
- type: Overlay
  url: overlays/qwiet-ai-openapi-overlay.yaml
- type: Packages
  url: packages/qwiet-ai-packages.yml
- type: SDKs
  url: packages/qwiet-ai-packages.yml
- type: CLI
  url: cli/qwiet-ai-cli.yml
- type: MCPServer
  url: mcp/qwiet-ai-mcp.yml
- type: AgentSkill
  url: skills/_index.yml
- type: Webhooks
  url: asyncapi/qwiet-ai-alerting-webhooks.yml
- type: LLMsTxt
  url: llms/qwiet-ai-llms.txt
- type: Postman
  url: https://god.gw.postman.com/run-collection/9829310-3251cbed-4ae3-4b06-8cad-c8748e49c7ec
x-enrichment:
  date: '2026-07-20'
  status: enriched
  artifacts_added: 15
  pass: local-v1