Skip to content
RejectModders edited this page Aug 25, 2026 · 3 revisions

API

Everything the UI can do is available over a REST API (bearer / API-key auth), plus webhooks and scheduled scans. Full reference with a live "Try It": https://vulnradar.dev/docs/api

Basics

  • Base URL: https://vulnradar.dev/api/v3
  • Auth: Authorization: Bearer <your_api_key> (create keys in your profile; scopes: scan:read, scan:write, scan:delete)

Reports: pull a completed scan in several formats for CI / automation:

GET /api/v3/history/{id}/report?format=sarif        # GitHub code scanning
GET /api/v3/history/{id}/report?format=pdf
GET /api/v3/history/{id}/report?format=md
GET /api/v3/history/{id}/report?format=compliance   # PCI/SOC2/ISO/ASVS/HIPAA/GDPR crosswalk

CI: a GitHub Action can fail a build on new findings. See https://vulnradar.dev/docs/api and the repo's .github/actions/. There is also a GitLab CI template and a command-line tool: CLI docs (installable from the repo until it is on npm).

Try it in the browser: the API Playground sends real requests against your account and shows the same call as ready-to-run code in cURL, JavaScript, Python, Go, PHP, Java, Ruby, or C#. It is driven by the OpenAPI spec.

Clone this wiki locally