Skip to content

Projects and scope ​

All paths are relative to https://api.hashiro.ai/api/ and require X-HASHIRO-TOKEN.

Access ​

Reads require organization-wide project access or project membership. Creation requires organization-wide project permission. Writes require the corresponding permissions and either provider ownership or a client-managed project belonging to the caller. Provider-managed projects are read-only to their client through configuration-write routes.

Routes ​

MethodPathOperation
GET/projects/metricsList authorized projects with metrics
GET/projects/:projectNameRead a project
PUT/projects/:projectNameCreate a project
PATCH/projects/:projectNameUpdate project details
DELETE/projects/:projectNameRequest deletion of the project and its dependent data
GET/projects/:projectName/:scopeRead inscope or outscope
POST/projects/:projectName/:scopeAdd scope entries
PATCH/projects/:projectName/:scope/asset/:assetIdUpdate a scope entry
DELETE/projects/:projectName/:scope/asset/:assetIdDelete a scope entry
PATCH/projects/:projectName/membersUpdate membership
PATCH/projects/:projectName/displayNameUpdate display name
POST/projects/:projectName/reportRequest PDF generation
GET/projects/:projectName/report/statusCheck generation status
GET/projects/:projectName/report/downloadDownload the ready PDF
GET/projects/:projectName/download/:fileFormatDownload a supported report format

List projects ​

Use GET /projects/metrics?page=1&pageSize=10. This is the project-list route used by Galileo. GET /projects/ is not the documented list endpoint.

Create ​

Use a lowercase project identifier containing letters, numbers, and hyphens, with at most 50 characters. Keep the identifier separate from its display name. Example body for PUT /projects/my-project:

json
{
  "platform": "pentest",
  "type": "private",
  "status": "active",
  "definitions": {"category": "internal"}
}

Providers can associate a project with an authorized linked client using customer_id. A client cannot select another organization. Available categories and project limits depend on organization settings and license.

Scope ​

:scope is inscope or outscope. Example body for POST /projects/my-project/inscope:

json
{
  "assets": [
    {"asset": "app.example.com", "asset_type": "domain"}
  ]
}

Scope type values include wildcard, domain, ip_address, cdir, ios, android, source, and other. cdir is the existing API spelling for CIDR. Use the ID returned for an entry when updating or deleting it.

Reports ​

Report routes apply to supported provider-managed assessment projects. A client-managed project does not automatically have provider-report access. Request generation, check status, and download only after the PDF is ready. Download responses are files rather than JSON. Template availability is organization-specific.

Deletion ​

Deleting a project starts removal of its dependent data. Treat it as irreversible and do not reuse the identifier until deletion completes.

Hashiro. Continuous Threat Exposure Management.