API quickstart

Create an API key and make your first REST calls.

Create an API key, then use it to read who you are and list your open findings over REST.

Create a key

In the app, switch to the workspace you want the key to read. A key belongs to the workspace that is active when you create it, and it reads only that workspace.

Open Settings → Developer and click Create key.

Enter a key name, tick View account and members and View findings, and click Create.

Copy the key, which starts with v12p_. The dialog warns: "This secret is shown once. Copy it now." Then click Done.

Create an API key covers the dialog, and Scopes explains what each scope allows.

Call the API

Put the key in V12_API_TOKEN and ask the API who you are:

export V12_API_TOKEN=v12p_…   # from your secret store, never committed
curl -s -H "Authorization: Bearer $V12_API_TOKEN" https://v12.sh/api/v2/me
{
  "user": { "id": 2, "username": "you", "email": "[email protected]" },
  "organization": { "id": 2, "name": "Acme", "personal": false },
  "token": { "kind": "pat", "scopes": ["user:read", "findings:read"] },
  "credits": { "balanceCents": 0, "monthlyCapCents": null }
}
  • user is the person who created the key.
  • organization is the workspace the key reads; personal is true for a personal workspace.
  • token.kind is pat for an API key and oauth for a token an app got by signing in. token.scopes lists what the key may do.
  • credits holds the workspace's credit balance and its monthly spending limit, in cents.

Then list the five newest open findings across the workspace's repositories:

curl -s -H "Authorization: Bearer $V12_API_TOKEN" "https://v12.sh/api/v2/findings?status=open&limit=5"

The response has four parts you will use most:

  • items: the findings. Each has an id, a display key such as F-42, a title, severity, status, and a webUrl that opens it in the app.
  • nextCursor: send it back as cursor for the next page; it is null on the last page. See Pagination.
  • counts: how many findings are in each status and severity, before your filters and without dismissed findings.
  • total: how many findings match your filters, across all pages.

Keep the key safe

  • Keep the key in a secret manager or a CI secret, never in code or a repository.
  • A key made in Settings has no expiry. It stops working when you revoke it, and when you change or reset your password, which revokes all your keys. Revoke keys you no longer use.
  • To change a key's secret, follow Replace a key. To use it in a pipeline, see Use in CI.

Next

On this page