Projects and scope
All paths are relative to https://api.hashiro.ai/api/ and require X-HASHIRO-TOKEN.
Access
Reads require organization-wide project access or project membership. Creation requires organization-wide project permission. Writes require the corresponding permissions and either provider ownership or a client-managed project belonging to the caller. Provider-managed projects are read-only to their client through configuration-write routes.
Routes
| Method | Path | Operation |
|---|---|---|
| GET | /projects/metrics | List authorized projects with metrics |
| GET | /projects/:projectName | Read a project |
| PUT | /projects/:projectName | Create a project |
| PATCH | /projects/:projectName | Update project details |
| DELETE | /projects/:projectName | Request deletion of the project and its dependent data |
| GET | /projects/:projectName/:scope | Read inscope or outscope |
| POST | /projects/:projectName/:scope | Add scope entries |
| PATCH | /projects/:projectName/:scope/asset/:assetId | Update a scope entry |
| DELETE | /projects/:projectName/:scope/asset/:assetId | Delete a scope entry |
| PATCH | /projects/:projectName/members | Update membership |
| PATCH | /projects/:projectName/displayName | Update display name |
| POST | /projects/:projectName/report | Request PDF generation |
| GET | /projects/:projectName/report/status | Check generation status |
| GET | /projects/:projectName/report/download | Download the ready PDF |
| GET | /projects/:projectName/download/:fileFormat | Download a supported report format |
List projects
Use GET /projects/metrics?page=1&pageSize=10. This is the project-list route used by Galileo. GET /projects/ is not the documented list endpoint.
Create
Use a lowercase project identifier containing letters, numbers, and hyphens, with at most 50 characters. Keep the identifier separate from its display name. Example body for PUT /projects/my-project:
{
"platform": "pentest",
"type": "private",
"status": "active",
"definitions": {"category": "internal"}
}Providers can associate a project with an authorized linked client using customer_id. A client cannot select another organization. Available categories and project limits depend on organization settings and license.
Scope
:scope is inscope or outscope. Example body for POST /projects/my-project/inscope:
{
"assets": [
{"asset": "app.example.com", "asset_type": "domain"}
]
}Scope type values include wildcard, domain, ip_address, cdir, ios, android, source, and other. cdir is the existing API spelling for CIDR. Use the ID returned for an entry when updating or deleting it.
Reports
Report routes apply to supported provider-managed assessment projects. A client-managed project does not automatically have provider-report access. Request generation, check status, and download only after the PDF is ready. Download responses are files rather than JSON. Template availability is organization-specific.
Deletion
Deleting a project starts removal of its dependent data. Treat it as irreversible and do not reuse the identifier until deletion completes.