openapi: 3.0.1 info: title: StackHawk Api Authentication Scan Results API description: The StackHawk Public API provides programmatic access to the StackHawk application and API security testing platform. Manage applications, environments, scan configurations, scan results, findings, repositories, teams, policies, and security reports. Authentication requires obtaining a JWT token via the /api/v1/auth/login endpoint using an API key from the StackHawk platform settings. version: 0.0.1 contact: url: https://www.stackhawk.com/ email: support@stackhawk.com termsOfService: https://www.stackhawk.com/terms/ servers: - url: https://api.stackhawk.com description: StackHawk API security: - BearerAuth: [] tags: - name: Scan Results description: Scan result reporting and findings paths: /api/v1/app/{appId}/env/{envId}/scan: get: operationId: listScans summary: List Scans description: List all scans for an application environment. tags: - Scan Results parameters: - name: appId in: path required: true schema: type: string - name: envId in: path required: true schema: type: string - name: pageToken in: query schema: type: string - name: pageSize in: query schema: type: integer responses: '200': description: List of scans content: application/json: schema: $ref: '#/components/schemas/ScanListResponse' /api/v1/app/{appId}/env/{envId}/scan/{scanId}: get: operationId: getScan summary: Get Scan description: Retrieve details for a specific scan. tags: - Scan Results parameters: - name: appId in: path required: true schema: type: string - name: envId in: path required: true schema: type: string - name: scanId in: path required: true schema: type: string responses: '200': description: Scan details content: application/json: schema: $ref: '#/components/schemas/Scan' delete: operationId: deleteScan summary: Delete Scan description: Delete a scan and its associated findings. tags: - Scan Results parameters: - name: appId in: path required: true schema: type: string - name: envId in: path required: true schema: type: string - name: scanId in: path required: true schema: type: string responses: '204': description: Scan deleted /api/v1/app/{appId}/env/{envId}/scan/{scanId}/finding: get: operationId: listFindings summary: List Findings description: List all security findings from a specific scan. tags: - Scan Results parameters: - name: appId in: path required: true schema: type: string - name: envId in: path required: true schema: type: string - name: scanId in: path required: true schema: type: string responses: '200': description: List of findings content: application/json: schema: $ref: '#/components/schemas/FindingListResponse' /api/v1/app/{appId}/env/{envId}/scan/{scanId}/finding/{findingId}: get: operationId: getFinding summary: Get Finding description: Retrieve details for a specific security finding. tags: - Scan Results parameters: - name: appId in: path required: true schema: type: string - name: envId in: path required: true schema: type: string - name: scanId in: path required: true schema: type: string - name: findingId in: path required: true schema: type: string responses: '200': description: Finding details content: application/json: schema: $ref: '#/components/schemas/Finding' components: schemas: ScanListResponse: type: object properties: scans: type: array items: $ref: '#/components/schemas/Scan' nextPageToken: type: string Scan: type: object properties: scanId: type: string appId: type: string envId: type: string status: type: string enum: - RUNNING - COMPLETED - FAILED startedAt: type: string format: date-time completedAt: type: string format: date-time findingCount: type: integer Finding: type: object properties: findingId: type: string scanId: type: string severity: type: string enum: - LOW - MEDIUM - HIGH - CRITICAL title: type: string description: type: string path: type: string method: type: string FindingListResponse: type: object properties: findings: type: array items: $ref: '#/components/schemas/Finding' securitySchemes: BearerAuth: type: http scheme: bearer bearerFormat: JWT description: JWT token obtained via /api/v1/auth/login