Qwiet

Qwiet AI (formerly ShiftLeft, now part of Harness) is an application security testing platform delivering SAST, SCA, IaC, container, and secrets scanning in a single scan, with reachability and exploitability filtering to cut false positives and AI-generated code fixes (AutoFix) to speed remediation. The Qwiet API (OpenAPI 3.0.0, v4, Bearer-token auth) lets you programmatically manage applications, run and compare scans, retrieve and triage findings with data flow, request fixes, manage users and RBAC, and configure alerting webhooks. Qwiet also ships an official MCP server and a set of agent skills for the scan-triage-autofix workflow, plus the `sl` CLI.

Qwiet publishes 27 APIs on the APIs.io network, including alerting API, analyze API, app_groups API, and 24 more. Tagged areas include Company, Security, Application Security, SAST, and SCA.

The Qwiet catalog on APIs.io includes 1 event-driven AsyncAPI specification.

Qwiet’s developer surface includes documentation, API reference, engineering blog, pricing, support, authentication, CLI, and 21 more developer resources.

50.6/100 developing ▬ flat Agent 71/100 agent native Full breakdown ↓
scored 2026-07-27 · rubric v0.5
AccessSelf serve
27 APIs 1 MCP Servers
CompanySecurityApplication SecuritySASTSCAVulnerability ManagementDevSecOpsCode AnalysisMCP

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 50.6/100 · developing
Contract Quality 16.0 / 25
Developer Ergonomics 10.9 / 20
Commercial Clarity 8.9 / 20
Operational Transparency 4.8 / 13
Governance 0.0 / 12
Discoverability 10.0 / 10
Agent readiness — 71/100 · agent native
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 6 / 6
Agent Skills 5 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/qwiet: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 27

Individual APIs this provider publishes, each with its own machine-readable definition.

Qwiet alerting API

Notification and alerting related endpoints (such as webhooks)

Qwiet analyze API

The analyze API from Qwiet — 2 operation(s) for analyze.

Qwiet app_groups API

The user-created groups of applications. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-3251cbed-4ae3-4b06-8cad-c8748e49c...

Qwiet app_labels API

The user-created application labels. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/30743751-da3c929b-651f-414c-993c-ee2b2573b2f4...

Qwiet apps API

The applications submitted for analysis. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-e9d0bf19-30bd-46f4-b40c-9df03d2a4...

Qwiet autofix API

The AutoFix suggestions for findings in applications. Harness SAST and SCA AutoFix uses large language models (LLMs) to generate potential code fix suggestions for findings prod...

Qwiet azureboard API

The endpoints to manage the Azure Boards integration.

Qwiet branches API

The branch information for scans of applications.

Qwiet comments API

The text threads (with individual comments ordered by time) attached to findings. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/...

Qwiet compounds API

Multi-Language Apps are groups of applications that are scanned together as a single application. This is useful for applications that are a compound of various programming lang...

Qwiet findings API

The results of a scan (which can include vulnerabilities, secrets, or insights). [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9...

Qwiet org_backup API

The endpoints for downloading backups of an organization's data.

Qwiet orgs API

The logical grouping (e.g., tenant/account) within Qwiet that defines a set of users, teams, and applications. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.g...

Qwiet rbac API

Roles-based access control (RBAC) allows you to control the permissions users in an organization are granted. The permissions granted to a user are additive. The base level of a...

Qwiet reports API

The summaries of applications and their findings for a specific organization. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829...

Qwiet SAML API

The integration endpoints allowing orgs to configure Qwiet to act as a SAML service provider (SP) that uses the customer's identity provider (IdP) to log users in. [![Run in Pos...

Qwiet sarif API

The integration endpoints for generating and downloading SARIF reports for applications.

Qwiet saved_searches API

The saved searches endpoints allow users to save specific search queries for organization and app findings

Qwiet sca API

The summaries of software composition analysis (SCA) results for apps in an organization. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-col...

Qwiet scans API

The instances where Qwiet AI by Harness is invoked to identify findings in an application. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-co...

Qwiet scopes API

Scopes define the type of resource and the operation that you can perform with the access token you bear. For example, `scans:create` means that the bearer of the token with thi...

Qwiet slack API

The integration endpoints enabling users to set up a Slack integration.

Qwiet team_config API

The endpoints to manage team-level configuration.

Qwiet tokens API

Used to authenticate with the API. Can be issued by org admins. Each access token is owned by the org that issued it. [![Run in Postman](https://run.pstmn.io/button.svg)](https:...

Qwiet users API

Users pertains the users in general as qwiet.ai users and of each org as organization users.

Qwiet versions API

The specific instances of an application scanned using Qwiet AI by Harness. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/982931...

Qwiet wiz API

The endpoints to manage the Wiz integration.

Scroll for all 27

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

qwiet-mcp.yml

MCP SERVER

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Qwiet Authentication

http · 1 scheme

SECURITY

Qwiet Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Qwiet Agentic Access

145 operations · 59 acting · 2 human-in-the-loop

145 operations · 59 acting

AGENTIC

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 3

Reference material describing how the API behaves

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: qwiet
name: Qwiet
description: Qwiet AI (formerly ShiftLeft, now part of Harness) is an application security testing platform delivering SAST,
  SCA, IaC, container, and secrets scanning in a single scan, with reachability and exploitability filtering to cut false
  positives and AI-generated code fixes (AutoFix) to speed remediation. The Qwiet API (OpenAPI 3.0.0, v4, Bearer-token auth)
  lets you programmatically manage applications, run and compare scans, retrieve and triage findings with data flow, request
  fixes, manage users and RBAC, and configure alerting webhooks. Qwiet also ships an official MCP server and a set of agent
  skills for the scan-triage-autofix workflow, plus the `sl` CLI.
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://docs.shiftleft.io/img/sl-logo.svg
url: https://raw.githubusercontent.com/api-evangelist/qwiet/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- bain-capital-ventures
specificationVersion: '0.20'
tags:
- Company
- Security
- Application Security
- SAST
- SCA
- Vulnerability Management
- DevSecOps
- Code Analysis
- MCP
created: '2026-07-17'
modified: '2026-07-20'
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
apis:
- aid: qwiet:qwiet-alerting-api
  name: Qwiet alerting API
  description: Notification and alerting related endpoints (such as webhooks)
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - alerting
  properties:
  - type: OpenAPI
    url: openapi/qwiet-alerting-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-analyze-api
  name: Qwiet analyze API
  description: The analyze API from Qwiet — 2 operation(s) for analyze.
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - analyze
  properties:
  - type: OpenAPI
    url: openapi/qwiet-analyze-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-app-groups-api
  name: Qwiet app_groups API
  description: 'The user-created groups of applications.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-3251cbed-4ae3-4b06-8cad-c8748e49c7ec?action=collection%2Ffork&collection-url=entityId%3D9829310-3251cbed-4ae3-4b06-8cad-c8748e49c7ec%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - app_groups
  properties:
  - type: OpenAPI
    url: openapi/qwiet-app-groups-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-app-labels-api
  name: Qwiet app_labels API
  description: 'The user-created application labels.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/30743751-da3c929b-651f-414c-993c-ee2b2573b2f4?action=collection%2Ffork&collection-url=entityId%3D30743751-da3c929b-651f-414c-993c-ee2b2573b2f4%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - app_labels
  properties:
  - type: OpenAPI
    url: openapi/qwiet-app-labels-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-apps-api
  name: Qwiet apps API
  description: 'The applications submitted for analysis.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-e9d0bf19-30bd-46f4-b40c-9df03d2a463a?action=collection%2Ffork&collection-url=entityId%3D9829310-e9d0bf19-30bd-46f4-b40c-9df03d2a463a%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - apps
  properties:
  - type: OpenAPI
    url: openapi/qwiet-apps-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-autofix-api
  name: Qwiet autofix API
  description: 'The AutoFix suggestions for findings in applications. Harness SAST and SCA AutoFix uses large language models
    (LLMs) to generate potential code fix suggestions for findings produced by Qwiet AI by Harness analyses.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/30743751-b06912bf-f25e-46a3-92c1-c12ba2ef162a?action=collection%2Ffork&collection-url=entityId%3D30743751-b06912bf-f25e-46a3-92c1-c12ba2ef162a%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - autofix
  properties:
  - type: OpenAPI
    url: openapi/qwiet-autofix-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-azureboard-api
  name: Qwiet azureboard API
  description: The endpoints to manage the Azure Boards integration.
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - azureboard
  properties:
  - type: OpenAPI
    url: openapi/qwiet-azureboard-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-branches-api
  name: Qwiet branches API
  description: The branch information for scans of applications.
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - branches
  properties:
  - type: OpenAPI
    url: openapi/qwiet-branches-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-comments-api
  name: Qwiet comments API
  description: 'The text threads (with individual comments ordered by time) attached to findings.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-49dbc330-9cb4-4dac-9257-a9cc79b1103c?action=collection%2Ffork&collection-url=entityId%3D9829310-49dbc330-9cb4-4dac-9257-a9cc79b1103c%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - comments
  properties:
  - type: OpenAPI
    url: openapi/qwiet-comments-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-compounds-api
  name: Qwiet compounds API
  description: Multi-Language Apps are groups of applications that are scanned together as a single application. This is useful
    for applications that are a compound of various programming languages and configurations of frameworks.
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - compounds
  properties:
  - type: OpenAPI
    url: openapi/qwiet-compounds-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-findings-api
  name: Qwiet findings API
  description: 'The results of a scan (which can include vulnerabilities, secrets, or insights).

    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-156075f8-c7cf-4e2c-95fa-0823a3313658?action=collection%2Ffork&collection-url=entityId%3D9829310-156075f8-c7cf-4e2c-95fa-0823a3313658%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - findings
  properties:
  - type: OpenAPI
    url: openapi/qwiet-findings-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-org-backup-api
  name: Qwiet org_backup API
  description: The endpoints for downloading backups of an organization's data.
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - org_backup
  properties:
  - type: OpenAPI
    url: openapi/qwiet-org-backup-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-orgs-api
  name: Qwiet orgs API
  description: 'The logical grouping (e.g., tenant/account) within Qwiet that defines a set of users, teams, and applications.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-f0ae38d5-6c27-41a9-a1c3-9721d39f5df0?action=collection%2Ffork&collection-url=entityId%3D9829310-f0ae38d5-6c27-41a9-a1c3-9721d39f5df0%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - orgs
  properties:
  - type: OpenAPI
    url: openapi/qwiet-orgs-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-rbac-api
  name: Qwiet rbac API
  description: 'Roles-based access control (RBAC) allows you to control the permissions users in an organization are granted.


    The permissions granted to a user are additive. The base level of a user''s permission is determined by their role in
    the organization.


    A team represents a group of users and the applications that group of users can access. Users are granted additional permissions
    based on their team role.


    Users can belong to multiple teams, but an application can only belong to one team.


    You can use the `TEAM_DEFINED` organization role to limit user access to only the apps assigned to their team.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-c002d05e-2fae-4914-8629-54cff59e1e6b?action=collection%2Ffork&collection-url=entityId%3D9829310-c002d05e-2fae-4914-8629-54cff59e1e6b%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - rbac
  properties:
  - type: OpenAPI
    url: openapi/qwiet-rbac-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-reports-api
  name: Qwiet reports API
  description: 'The summaries of applications and their findings for a specific organization.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-b675d7af-bdd5-49a4-982b-4e57c4f4a44c?action=collection%2Ffork&collection-url=entityId%3D9829310-b675d7af-bdd5-49a4-982b-4e57c4f4a44c%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - reports
  properties:
  - type: OpenAPI
    url: openapi/qwiet-reports-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-saml-api
  name: Qwiet SAML API
  description: 'The integration endpoints allowing orgs to configure Qwiet to act as a SAML service provider (SP) that uses
    the customer''s identity provider (IdP) to log users in.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-a411d1c3-c232-4843-a89d-b302df399d99?action=collection%2Ffork&collection-url=entityId%3D9829310-a411d1c3-c232-4843-a89d-b302df399d99%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - SAML
  properties:
  - type: OpenAPI
    url: openapi/qwiet-saml-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-sarif-api
  name: Qwiet sarif API
  description: The integration endpoints for generating and downloading SARIF reports for applications.
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - sarif
  properties:
  - type: OpenAPI
    url: openapi/qwiet-sarif-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-saved-searches-api
  name: Qwiet saved_searches API
  description: The saved searches endpoints allow users to save specific search queries for organization and app findings
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - saved_searches
  properties:
  - type: OpenAPI
    url: openapi/qwiet-saved-searches-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-sca-api
  name: Qwiet sca API
  description: 'The summaries of software composition analysis (SCA) results for apps in an organization.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/30743751-08a1d64d-5913-409a-ac8a-7074ce5a62d7?action=collection%2Ffork&collection-url=entityId%3D30743751-08a1d64d-5913-409a-ac8a-7074ce5a62d7%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - sca
  properties:
  - type: OpenAPI
    url: openapi/qwiet-sca-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-scans-api
  name: Qwiet scans API
  description: 'The instances where Qwiet AI by Harness is invoked to identify findings in an application.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-dc6a68d5-995d-4ba4-8098-e3b67773cf0e?action=collection%2Ffork&collection-url=entityId%3D9829310-dc6a68d5-995d-4ba4-8098-e3b67773cf0e%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - scans
  properties:
  - type: OpenAPI
    url: openapi/qwiet-scans-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-scopes-api
  name: Qwiet scopes API
  description: 'Scopes define the type of resource and the operation that you can perform with the access token you bear.
    For example, `scans:create` means that the bearer of the token with this scope can create scans via the API.


    For each endpoint, we indicate the scope required to perform an operation under **Authorizations**.


    We also offer helper endpoints that allow you to determine what the allowed scopes for your access token are in the context
    of a specific API resource.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-54d0d8f3-0cc0-42c3-8eee-2eb66e1ea835?action=collection%2Ffork&collection-url=entityId%3D9829310-54d0d8f3-0cc0-42c3-8eee-2eb66e1ea835%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - scopes
  properties:
  - type: OpenAPI
    url: openapi/qwiet-scopes-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-slack-api
  name: Qwiet slack API
  description: The integration endpoints enabling users to set up a Slack integration.
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - slack
  properties:
  - type: OpenAPI
    url: openapi/qwiet-slack-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-team-config-api
  name: Qwiet team_config API
  description: The endpoints to manage team-level configuration.
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - team_config
  properties:
  - type: OpenAPI
    url: openapi/qwiet-team-config-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-tokens-api
  name: Qwiet tokens API
  description: 'Used to authenticate with the API.


    Can be issued by org admins. Each access token is owned by the org that issued it.


    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-0a2fce9d-f679-41e8-a438-bcf13ddec403?action=collection%2Ffork&collection-url=entityId%3D9829310-0a2fce9d-f679-41e8-a438-bcf13ddec403%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - tokens
  properties:
  - type: OpenAPI
    url: openapi/qwiet-tokens-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-users-api
  name: Qwiet users API
  description: Users pertains the users in general as qwiet.ai users and of each org as organization users.
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - users
  properties:
  - type: OpenAPI
    url: openapi/qwiet-users-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-versions-api
  name: Qwiet versions API
  description: 'The specific instances of an application scanned using Qwiet AI by Harness.

    [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-d8e4a6f2-bdce-4807-a8ca-74fc00dbc089?action=collection%2Ffork&collection-url=entityId%3D9829310-d8e4a6f2-bdce-4807-a8ca-74fc00dbc089%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)'
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - versions
  properties:
  - type: OpenAPI
    url: openapi/qwiet-versions-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
- aid: qwiet:qwiet-wiz-api
  name: Qwiet wiz API
  description: The endpoints to manage the Wiz integration.
  humanURL: https://docs.shiftleft.io/api
  baseURL: https://app.shiftleft.io/api/v4
  tags:
  - wiz
  properties:
  - type: OpenAPI
    url: openapi/qwiet-wiz-api-openapi.yml
  - type: APIReference
    url: https://docs.shiftleft.io/api
common:
- type: Website
  url: https://qwiet.ai/
- type: Documentation
  url: https://docs.shiftleft.io/
- type: APIReference
  url: https://docs.shiftleft.io/api
- type: GitHubOrganization
  url: https://github.com/ShiftLeftSecurity
- type: Blog
  url: https://qwiet.ai/blog/
- type: Login
  url: https://app.shiftleft.io/login
- type: Pricing
  url: https://www.harness.io/pricing
- type: TermsOfService
  url: https://www.harness.io/legal
- type: PrivacyPolicy
  url: https://www.harness.io/legal/privacy
- type: Support
  url: https://www.harness.io/support
- type: StatusPage
  url: https://status.shiftleft.io
- type: OpenAPI
  url: openapi/qwiet-api-original.yml
- type: Overlay
  url: overlays/qwiet-api-overlay.yaml
- type: Authentication
  url: authentication/qwiet-authentication.yml
- type: Conventions
  url: conventions/qwiet-conventions.yml
- type: ErrorCatalog
  url: errors/qwiet-error-codes.yml
- type: Lifecycle
  url: lifecycle/qwiet-lifecycle.yml
- type: Deprecation
  url: lifecycle/qwiet-lifecycle.yml
- type: DataModel
  url: data-model/qwiet-data-model.yml
- type: Conformance
  url: conformance/qwiet-conformance.yml
- type: Webhooks
  url: asyncapi/qwiet-alerting-webhooks.yml
- type: Packages
  url: packages/qwiet-packages.yml
- type: CLI
  url: cli/qwiet-cli.yml
- type: MCPServer
  url: mcp/qwiet-mcp.yml
- type: AgentSkill
  url: skills/_index.yml
- type: LLMsTxt
  url: llms/qwiet-llms.txt
- type: AgenticAccess
  url: agentic-access/qwiet-agentic-access.yml
- type: DomainSecurity
  url: security/qwiet-domain-security.yml
x-enrichment:
  date: '2026-07-20'
  status: enriched
  artifacts_added: 16
  pass: local-v1