openapi: 3.1.0 info: title: Fortify on Demand Alert Definitions System API description: REST API for Fortify on Demand (FoD), the cloud-based application security testing service from OpenText. Provides programmatic access to manage applications, releases, initiate static, dynamic, and mobile scans, retrieve vulnerability results, and manage tenant-level settings. Supports OAuth2 client credentials and resource owner password grant flows for authentication. version: v3 contact: name: OpenText Fortify Support url: https://www.opentext.com/support email: fortify-support@microfocus.com license: name: Proprietary url: https://www.opentext.com/about/legal/website-terms-of-use x-logo: url: https://www.microfocus.com/brand/fortify-logo.png servers: - url: https://api.ams.fortify.com description: Fortify on Demand - Americas - url: https://api.emea.fortify.com description: Fortify on Demand - EMEA - url: https://api.apac.fortify.com description: Fortify on Demand - APAC security: - bearerAuth: [] tags: - name: System description: System health and configuration paths: /health: get: operationId: getHealth summary: Fortify Get system health description: Returns the health status of the ScanCentral DAST system, including database connectivity and service availability. tags: - System security: [] responses: '200': description: System is healthy content: application/json: schema: $ref: '#/components/schemas/HealthResponse' '503': description: System is unhealthy content: application/json: schema: $ref: '#/components/schemas/HealthResponse' components: schemas: HealthResponse: type: object description: System health status properties: status: type: string description: Overall health status enum: - Healthy - Degraded - Unhealthy checks: type: array items: type: object properties: name: type: string description: Health check name status: type: string description: Check status description: type: string description: Check description securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: OAuth2 Bearer token obtained from POST /oauth/token using either client_credentials or password grant type. externalDocs: description: Fortify on Demand API Reference url: https://api.ams.fortify.com/swagger/ui/index