Skip to content

Findings and review ​

Finding endpoints use /scans, the existing API resource name. Use X-HASHIRO-TOKEN with https://api.hashiro.ai/api/.

Access ​

Read access follows project membership or organization-wide project access. Creation, update, and deletion require pentester/project-management permission and a permitted provider or client-owned project. Clients can review eligible public AI candidates, but cannot access private provider drafts or unrelated findings.

Routes ​

MethodPathOperation
GET/scans/List findings with project, page, pageSize
GET/scans/:scanIdRead a finding
PUT/scans/:projectNameCreate a finding
POST/scans/:projectNameUpdate a finding using its ID in the body
DELETE/scans/:projectName/:scanIdDelete a finding
POST/scans/:projectName/bulk-statusChange selected findings status
POST/scans/:projectName/bulk-deleteDelete selected findings
POST/scans/:projectName/:scanId/reviewReview a candidate with its expected version
POST/scans/:projectName/:scanId/ai/demonstrationGenerate a draft demonstration for review
POST/scans/:projectName/:scanId/ai/demonstration/applyApply a reviewed draft
POST/scans/:projectName/:scanId/ai/mergePropose a merge for review

Create a finding ​

Send this body to PUT /scans/my-project:

json
{
  "title":"Missing security header",
  "asset":["app.example.com"],
  "severity":"low",
  "description":"Observed during the assessment",
  "remediation":"Configure the required header"
}

asset is an array, even for one host. Optional fields include observation, demonstration, remediation, references, requests, CVSS, and tags. References must be HTTP or HTTPS URLs. cwe and owasp, when supplied, are also URLs.

Creation returns a result containing success and Ids; preserve those identifiers. Clients' new findings are opened according to the server's policy; do not assume a requested draft status is accepted for every caller.

Update ​

POST /scans/my-project requires id, title, and a nonempty asset array. Read the current finding first, preserve these required fields, and submit the permitted changes. Pending AI candidates must use the candidate-review route for status decisions.

Bulk status ​

json
{
  "ids":["FINDING_ID"],
  "status":"pending_retest"
}

Send to POST /scans/my-project/bulk-status. Bulk requests are limited to 500 IDs. bulk-delete accepts the ids array without status and permanently removes authorized findings.

Candidate review ​

Use the review version returned by the candidate and submit the decision with expected_review_version. A conflict requires reading the latest record before deciding again. Review and merge options are constrained by the caller's role, project, and candidate visibility. AI draft generation can consume credits; review the draft before applying it.

See the issue lifecycle and AI review guide for the interface workflow.

Hashiro. Continuous Threat Exposure Management.