{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/opentext-cybersecurity/main/json-schema/opentext-cybersecurity-get-dynamic-scan-setup-response-schema.json", "title": "GetDynamicScanSetupResponse", "description": "GetDynamicScanSetupResponse", "x-generated": "2026-10-03", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/opentext-cybersecurity-dynamic-scans-api-openapi.yml#/components/schemas/GetDynamicScanSetupResponse", "required": [ "geoLocationId", "timeZone", "entitlementFrequencyType" ], "type": "object", "properties": { "webServiceManifestFiles": { "description": "Collection of manifest files for web services", "type": "array", "items": { "$ref": "#/$defs/WebServiceManifestFile" } }, "scanDocument": { "description": "Collection of scan document and additional details files", "type": "array", "items": { "$ref": "#/$defs/ScanDocument" } }, "geoLocationId": { "format": "int32", "description": "Geo Location Id of the scan. Values can be obtained by calling GET /api/v3/lookup-items?type=GeoLocations", "type": "integer" }, "dynamicScanEnvironmentFacingType": { "description": "Type of environment the server is running in", "enum": [ "Internal", "External" ], "type": "string" }, "exclusions": { "description": "Deprecated", "type": "string" }, "includeUrls": { "description": "List of subdomains.", "type": "array", "items": { "$ref": "#/$defs/Subdomain" } }, "exclusionsList": { "description": "List of exclusions.", "type": "array", "items": { "$ref": "#/$defs/Exclusion" } }, "dynamicScanAuthenticationType": { "description": "This field is obsolete. Please use the hasFormsAuthentication field to indicate if Forms Authentication is required to scan the site", "enum": [ "NoAuthentication", "GenerateUniqueAuthentication", "AuthenticationRequired" ], "type": "string" }, "hasFormsAuthentication": { "description": "True if Forms Authentication is required to scan the site", "type": "boolean" }, "primaryUserName": { "description": "Primary username to login with", "type": "string" }, "primaryUserPassword": { "description": "Primary account password to login with", "type": "string" }, "secondaryUserName": { "description": "Secondary username to login with", "type": "string" }, "secondaryUserPassword": { "description": "Secondary account password to login with", "type": "string" }, "otherUserName": { "description": "Other username needed to operate the site", "type": "string" }, "otherUserPassword": { "description": "Other password needed to operate the site", "type": "string" }, "requiresNetworkAuthentication": { "description": "True if network connection is required to scan the site", "type": "boolean" }, "networkUserName": { "description": "Network account username", "type": "string" }, "networkPassword": { "description": "Network account password", "type": "string" }, "notes": { "description": "Additional notes that will help with running a scan", "type": "string" }, "dynamicSiteURL": { "description": "The dynamic site url", "type": "string" }, "timeZone": { "description": "The timezone. Values can be obtained by calling GET /api/v3/lookup-items?type=TimeZones", "type": "string" }, "blockout": { "description": "Blockout days list. All days and hours will default to checked unless otherwise specified.", "type": "array", "items": { "$ref": "#/$defs/BlackoutDay" } }, "repeatScheduleType": { "description": "For scans that are to be run at regular intervals, this specifies how often", "enum": [ "NoRepeat", "Biweekly", "Monthly", "Bimonthly", "Quarterly", "Triannually", "Semiannually", "Annually" ], "type": "string" }, "assessmentTypeId": { "format": "int32", "description": "Assessment type identifier of the scan. Values can be obtained by calling GET /api/v3/releases/{releaseId}/assessment-types", "type": "integer" }, "entitlementId": { "format": "int32", "description": "Entitlement identifier of the scan", "type": "integer" }, "allowFormSubmissions": { "description": "True to allow form submissions (default), otherwise false..", "type": "boolean" }, "restrictToDirectoryAndSubdirectories": { "description": "True to restrict to directory and subdirectories, otherwise false", "type": "boolean" }, "generateWAFVirtualPatch": { "description": "True to generate WAF virtual patch, otherwise false", "type": "boolean" }, "isWebService": { "description": "True if this a web service scan", "type": "boolean" }, "webServiceType": { "description": "The web service type", "enum": [ "SOAP", "REST", "PostmanCollectionFile", "PostmanCollectionURL", "OpenApiFile", "OpenApiUrl", "Grpc", "GraphQlFile", "GraphQlUrl", "PostmanAuthFile", "PostmanEnvironmentFile", "PostmanGlobalsFile" ], "type": "string" }, "webServiceDescriptorURL": { "description": "WSDL Location URL", "type": "string" }, "webServiceUserName": { "description": "The web service username", "type": "string" }, "webServicePassword": { "description": "The web service password", "type": "string" }, "webServiceAPIKey": { "description": "The web service API key", "type": "string" }, "webServiceAPIPassword": { "description": "The web service API password", "type": "string" }, "entitlementFrequencyType": { "description": "The entitlement frequency type", "enum": [ "SingleScan", "Subscription" ], "type": "string" }, "concurrentRequestThreadsType": { "description": "The concurrent request threads type", "enum": [ "Standard", "Limited" ], "type": "string" }, "postmanCollectionURL": { "description": "URL for the remote Postman collection manifest", "type": "string" }, "openApiURL": { "description": "URL for the remote OpenApi manifest", "type": "string" }, "remoteManifestAuthorizationHeaderName": { "description": "Optional header name for downloading a remote manifest (e.g. Postman, OpenApi)", "type": "string" }, "remoteManifestAuthorizationHeaderValue": { "description": "Optional header value for downloading a remote manifest (e.g. Postman, OpenApi)", "type": "string" }, "networkName": { "description": "When set indicates that the scan should use the specified Fortify on Demand Connect\nnetwork when running the scan. Scans that use a Fortify on Demand Connect network\nwill automatically set dynamicScanEnvironmentFacingType to 'Internal'. Fortify on\nDemand Connect must be enabled for this tenant to use this feature.", "type": "string" }, "graphqlUrl": { "description": "URL for the remote GraphQL manifest", "type": "string" }, "apiSchemeType": { "description": "Api scheme type (e.g. Http or Https or HttpHttps)", "type": "string" }, "apiHost": { "description": "Api host name or Ip address with port number", "type": "string" }, "apiServicePath": { "description": "Directory path for the API service", "type": "string" }, "twoFactorAuthentication": { "$ref": "#/$defs/GetTwoFactor", "description": "Gets or sets the two-factor authentication settings for the GET response." } }, "$defs": { "BlackoutDay": { "description": "Blockout day option", "type": "object", "properties": { "day": { "description": "Day of week the hour blocks are associated with", "enum": [ "Sunday", "Monday", "Tuesday", "Wednesday", "Thursday", "Friday", "Saturday" ], "type": "string" }, "hourBlocks": { "description": "The list of hours and their blockout states", "type": "array", "items": { "$ref": "#/$defs/BlackoutHour" } } } }, "BlackoutHour": { "description": "Blockout hour option", "type": "object", "properties": { "hour": { "format": "int32", "description": "The 24 hour identifier (0-23)", "type": "integer" }, "checked": { "description": "Checked is true when this hour is blocked out. It is false when clear to scan", "type": "boolean" } } }, "Exclusion": { "type": "object", "properties": { "value": { "description": "URL fragment to exclude from scanning.", "type": "string" } } }, "GetOtherTwoFactorUser": { "type": "object", "properties": { "hasTotpConfigured": { "default": false, "type": "boolean" }, "userIndex": { "format": "int32", "default": 1, "type": "integer" }, "twoFactorEmail": { "type": "string" }, "userName": { "type": "string" } } }, "GetTwoFactor": { "type": "object", "properties": { "hasTwoFactorAuthentication": { "default": false, "type": "boolean" }, "twoFactorAuthenticationType": { "enum": [ "Email", "TOTP" ], "type": "string" }, "primaryUserTwoFactorEmail": { "type": "string" }, "secondaryUserTwoFactorEmail": { "type": "string" }, "otherUserTwoFactorEmail": { "type": "string" }, "primaryUserHasTotpConfigured": { "default": false, "type": "boolean" }, "secondaryUserHasTotpConfigured": { "default": false, "type": "boolean" }, "otherUserHasTotpConfigured": { "default": false, "type": "boolean" }, "otherTwoFactorUsers": { "type": "array", "items": { "$ref": "#/$defs/GetOtherTwoFactorUser" } } } }, "ScanDocument": { "type": "object", "properties": { "fileId": { "format": "int32", "description": "The id of the scan document and additional details files", "type": "integer" }, "fileName": { "description": "The name of the scan document and additional details files", "type": "string" }, "createdDate": { "description": "The creation date of the scan document and additional details files", "type": "string" } } }, "Subdomain": { "type": "object", "properties": { "value": { "description": "URL subdomain to include in scanning.", "type": "string" } } }, "WebServiceManifestFile": { "type": "object", "properties": { "webServiceFileType": { "description": "The web service type", "enum": [ "Postman", "OpenApi", "GraphQL", "Grpc", "WSDL" ], "type": "string" }, "filename": { "description": "The name of the manifest file", "type": "string" }, "dateCreated": { "format": "date-time", "description": "The creation date of the manifest file", "type": "string" }, "fileId": { "description": "The id of the manifest file", "type": "string" }, "postmanFileType": { "description": "The type of Postman file (Workflow, Auth, Environment, or Globals). \nNull for non-Postman web service types.", "enum": [ "Workflow", "Auth", "Environment", "Globals" ], "type": "string" } } } } }