Queue an exact-commit security run
POST
/v1/security/repositories/{repositoryId}/runsIf headSha is omitted, the API resolves the selected branch through a repository-scoped, short-lived GitHub App installation token before enqueueing. The resulting run is always pinned to the returned full commit SHA.
How to call this endpoint
Every ACP API request uses bearer authentication. The examples here show the actual request path, auth header, and body shape that the platform expects.
Path, query, and header parameters
These parameters control which ACP object the endpoint acts on and how the request is processed.
Path parameters
| Name | Location | Type | Required | Description |
|---|---|---|---|---|
| repositoryId | path | string | Yes | Monitored security repository ID |
Query parameters
None.
Header parameters
| Name | Location | Type | Required | Description |
|---|---|---|---|---|
| X-Computer-Agents-Organization | header | string | No | Active organization context. If omitted, the authenticated user's personal organization is used. |
| Idempotency-Key | header | string | No | — |
Body schema
Content type: application/json · Optional
| Field | Type | Required | Description |
|---|---|---|---|
| headSha | string | No | — |
| baseSha | string | No | — |
| ref | string | No | Branch name or refs/heads path |
What the API returns
Each response code below includes the documented payload shape for the ACP API.
202Run queuedapplication/json
| Field | Type | Required | Description |
|---|---|---|---|
| id | string | Yes | Unique identifier. |
| repositoryId | string | Yes | — |
| repositoryFullName | string | No | — |
| triggerType | manual | schedule | pull_request | push | retry | Yes | — |
| triggerEventId | string | No | — |
| baseSha | string | No | — |
| headSha | string | No | — |
| ref | string | No | — |
| status | queued | running | waiting_approval | succeeded | partial | failed | cancelled | Yes | Current lifecycle status. |
| stage | ingest | checkout | inventory | scan | validate | triage | remediate | verify | publish | complete | Yes | — |
| policyVersionId | string | No | — |
| threatModelVersionId | string | No | — |
| promptVersion | string | No | — |
| modelVersion | string | No | — |
| scannerVersions | object | No | — |
| coverage | object | No | — |
| summary | object | No | — |
| error | object | No | — |
| findingCount | integer | Yes | — |
| checkRunUrl | string | No | — |
| pullRequestUrl | string | No | — |
| queuedAt | string | Yes | — |
| startedAt | string | No | ISO 8601 timestamp. |
| completedAt | string | No | ISO 8601 timestamp. |
| createdAt | string | Yes | ISO 8601 timestamp. |
| updatedAt | string | Yes | ISO 8601 timestamp. |
402Insufficient budgetapplication/json
| Field | Type | Required | Description |
|---|---|---|---|
| error | string | No | — |
| message | string | No | Message text. |
| currentBudget | number | No | — |
Queue an exact-commit security run
Loading...
Response 202
Loading...