openapi: 3.0.3 info: title: Trivy Server Health API description: The Trivy Server API exposes HTTP endpoints when running Trivy in client/server mode. In this mode, the server maintains a local vulnerability database and clients submit scan requests without needing to download the database themselves. The server listens on port 4954 by default and supports optional token-based authentication. version: 0.70.0 contact: url: https://trivy.dev/ license: name: Apache 2.0 url: https://github.com/aquasecurity/trivy/blob/main/LICENSE servers: - url: http://localhost:4954 description: Trivy server default endpoint - url: http://{host}:{port} description: Custom Trivy server endpoint variables: host: default: localhost description: Trivy server hostname port: default: '4954' description: Trivy server port tags: - name: Health description: Server health and liveness checks paths: /healthz: get: operationId: healthCheck summary: Health Check description: Check if the Trivy server is running and healthy. Returns 200 OK with "ok" body when the server is operational. Does not require authentication. tags: - Health responses: '200': description: Server is healthy content: text/plain: schema: type: string example: ok components: securitySchemes: TrivyToken: type: apiKey in: header name: Trivy-Token description: Optional token-based authentication. When the server is started with --token, all requests must include the token in the Trivy-Token header. externalDocs: description: Trivy Client/Server Documentation url: https://trivy.dev/latest/docs/references/modes/client-server/