List security findings

GET/v1/security/findings

How to call this endpoint

Every ACP API request uses bearer authentication. The examples here show the actual request path, auth header, and body shape that the platform expects.

Path, query, and header parameters

These parameters control which ACP object the endpoint acts on and how the request is processed.

Path parameters
None.
Query parameters
NameLocationTypeRequiredDescription
repositoryIdquerystringNo
runIdquerystringNo
statusqueryopen | accepted | risk_accepted | false_positive | fixedNo
severityquerycritical | high | medium | low | informationalNo
limitqueryintegerNo
Header parameters
NameLocationTypeRequiredDescription
X-Computer-Agents-OrganizationheaderstringNoActive organization context. If omitted, the authenticated user's personal organization is used.

Body schema

This endpoint does not require a request body.

None.

What the API returns

Each response code below includes the documented payload shape for the ACP API.

200Security findingsapplication/json
FieldTypeRequiredDescription
objectlistYes
dataobject[]Yes
data[].idstringYesUnique identifier.
data[].repositoryIdstringYes
data[].repositoryFullNamestringNo
data[].fingerprintstringYes
data[].ruleIdstringNo
data[].titlestringYesDisplay title.
data[].summarystringYes
data[].severitycritical | high | medium | low | informationalYes
data[].confidencenumberYes
data[].exploitabilitystringNo
data[].cwestring[]No
data[].cvssnumberNo
data[].statusopen | accepted | risk_accepted | false_positive | fixedYesCurrent lifecycle status.
data[].firstSeenRunIdstringNo
data[].lastSeenRunIdstringNo
data[].assignedToUserIdstringNo
data[].resolutionReasonstringNo
data[].resolutionExpiresAtstringNo
data[].fixedAtstringNo
data[].metadataobjectNoFree-form metadata object.
data[].occurrenceCountintegerYes
data[].createdAtstringYesISO 8601 timestamp.
data[].updatedAtstringYesISO 8601 timestamp.
has_morebooleanYes
total_countintegerYes
List security findings
Loading...
Response 200
Loading...
See the ACP quickstart and SDK flow