Webhook Payload
Field-level reference for workflow webhook POST bodies. Unlisted: reachable by URL, not in the sidebar or search.
Setup and firewall: Webhook Notifications.
Payload Format¶
| Setting | Payload |
|---|---|
| Off (default) | Current: see Default (current) payload |
| On | Scoped: see Scoped payload |
Organization → General → Enable scoped webhook export payload (organization admins).
Update your consumer before enabling the setting.
Both formats:
- Root keys are always arrays (possibly empty):
issues,assets,scans,profiles,locations,integrations. - Ignore unknown fields. New keys may appear without a version bump.
Differences (Current vs Scoped)¶
| Area | Current | Scoped |
|---|---|---|
| Issue | alertUid, customRule, full target objects with IDs |
No alertUid or customRule; narrower targets |
| Asset | uri, nested scans, events, full schema, repository data |
No uri, scans, events, or repository data; schema contains only { id } |
| Integration | parameters, valid |
Metadata only |
| Location | target, enabled |
Name, type, region, IP only |
| Events | Many events, full exchanges | Latest event only, no attachments |
Default (Current) Payload¶
Used when Enable scoped webhook export payload is off (default).
Full example and tables: Webhook Notifications: default example.
Summary:
- Issues include
alertUid,assetId, nestedasset,targets,events, optionalscanandapplication. - Assets include
uri,scans,events, and type-specific nested objects (service,frontend,host,repository,schema). - Locations include
targetandenabled. - Integrations include
validand rawparameters, potentially including API tokens, PATs, client secrets, or other credentials.
Integration Credentials in Default Payloads
Default integration exports include raw configuration parameters. Send them only to receivers trusted to handle those credentials. Enable scoped payloads for receivers that don’t need them; scoped integration exports contain metadata only.
Scoped Payload¶
Used when Enable scoped webhook export payload is on.
Contract¶
- Nullable issue-asset, root-asset, and profile relations use
nullwhen absent. Scan-application assetfrontendandservicekeys are omitted when absent. Targets contain only the selected variant; unused variant keys are omitted. - Issue
scanandapplicationare included only when the workflow is associated with a scan. Otherwise, those keys are omitted. Targets and events come from that scan, or the issue’s last-seen scan when no scan is specified.
Example Payload¶
{
"issues": [
{
"id": "00000000-0000-0000-0000-000000000008",
"name": "SQL Injection",
"fullName": "SQL Injection - CRITICAL",
"createdAt": "2024-01-15T10:30:00.000Z",
"status": "OPEN",
"severity": "HIGH",
"category": "INJECTION",
"aiContext": null,
"risks": [],
"context": "The application is vulnerable to SQL injection.",
"aiRemediation": null,
"securityTestUid": "test-456",
"ticket": {
"id": "00000000-0000-0000-0000-000000000007",
"externalUrl": "https://jira.example.com/browse/SEC-12",
"createdAt": "2024-01-15T11:00:00.000Z",
"externalId": "SEC-12"
},
"asset": {
"id": "00000000-0000-0000-0000-000000000009",
"name": "https://api.example.com",
"externalUrl": "https://api.example.com",
"class": "API_SERVICE",
"type": "REST",
"tags": [{ "id": "00000000-0000-0000-0000-000000000003", "name": "production", "color": "112233" }],
"service": { "id": "00000000-0000-0000-0000-000000000010", "url": "https://api.example.com" },
"frontend": null,
"host": null,
"cloudComponent": null
},
"targets": [
{
"apiRoute": { "id": "00000000-0000-0000-0000-000000000013", "operation": "POST", "name": "/users" }
}
],
"events": [
{
"id": "00000000-0000-0000-0000-000000000025",
"createdAt": "2024-01-15T10:31:00.000Z",
"level": "INFO",
"stage": "EXECUTION"
}
],
"scan": {
"id": "00000000-0000-0000-0000-000000000012",
"createdAt": "2024-01-15T09:00:00.000Z",
"finishedAt": "2024-01-15T09:45:00.000Z",
"score": 0.42,
"coverage": 0.8,
"meanDuration": 12.5,
"totalDuration": 2700,
"status": "FINISHED",
"progressRatio": 1,
"initiator": "SCHEDULED",
"kind": "BLST_REST",
"application": {
"id": "00000000-0000-0000-0000-000000000014",
"name": "My Application",
"scannerKind": "BLST_REST",
"asset": {
"id": "00000000-0000-0000-0000-000000000009",
"name": "https://api.example.com",
"tags": [{ "id": "00000000-0000-0000-0000-000000000003", "name": "production", "color": "112233" }],
"service": { "url": "https://api.example.com" }
}
}
},
"application": {
"id": "00000000-0000-0000-0000-000000000014",
"name": "My Application",
"scannerKind": "BLST_REST",
"asset": {
"id": "00000000-0000-0000-0000-000000000009",
"name": "https://api.example.com",
"tags": [{ "id": "00000000-0000-0000-0000-000000000003", "name": "production", "color": "112233" }],
"service": { "url": "https://api.example.com" }
}
}
}
],
"assets": [
{
"id": "00000000-0000-0000-0000-000000000015",
"class": "FRONTEND",
"type": "WEBAPP",
"rootFQDN": "app.example.com",
"externalUrl": "https://app.example.com",
"name": "https://app.example.com",
"manuallySetName": null,
"faviconUrl": null,
"description": "",
"manuallySetDescription": null,
"createdAt": "2024-01-15T08:00:00.000Z",
"lastSeenAt": "2024-01-15T10:00:00.000Z",
"scheduledForDeletionAt": null,
"status": "MONITORED",
"risks": [],
"owners": [{ "email": "owner@example.com" }],
"tags": [{ "id": "00000000-0000-0000-0000-000000000003", "name": "production", "color": "112233" }],
"projects": [{ "id": "00000000-0000-0000-0000-000000000004" }],
"firstSeenScan": { "id": "00000000-0000-0000-0000-000000000024", "createdAt": "2024-01-15T09:00:00.000Z" },
"lastSeenScan": { "id": "00000000-0000-0000-0000-000000000024", "createdAt": "2024-01-15T09:00:00.000Z" },
"service": null,
"frontend": {
"type": "WEBAPP",
"url": "https://app.example.com",
"framework": null,
"APIFramework": null,
"authProtocol": null,
"authTechnology": null,
"cloudProvider": null,
"wafProvider": null,
"environment": null,
"ips": ["192.0.2.2"],
"tls": true
},
"schema": { "id": "00000000-0000-0000-0000-000000000005" },
"host": null,
"technology": null
}
],
"scans": [
{
"id": "00000000-0000-0000-0000-000000000024",
"createdAt": "2024-01-15T09:00:00.000Z",
"finishedAt": "2024-01-15T10:00:00.000Z",
"score": 0.42,
"coverage": 0.8,
"meanDuration": 12.5,
"totalDuration": 3600,
"status": "FINISHED",
"progressRatio": 1,
"initiator": "SCHEDULED",
"kind": "FRONTEND_DAST",
"application": {
"id": "00000000-0000-0000-0000-000000000026",
"name": "My Application",
"scannerKind": "FRONTEND_DAST",
"asset": {
"id": "00000000-0000-0000-0000-000000000015",
"name": "https://app.example.com",
"tags": [],
"frontend": { "url": "https://app.example.com" }
}
}
}
],
"profiles": [
{
"id": "00000000-0000-0000-0000-000000000027",
"name": "My Application",
"createdAt": "2024-01-15T07:00:00.000Z",
"updatedAt": "2024-01-15T07:00:00.000Z",
"asset": { "id": "00000000-0000-0000-0000-000000000015", "name": "https://app.example.com" },
"lastResourceScan": { "id": "00000000-0000-0000-0000-000000000024", "createdAt": "2024-01-15T09:00:00.000Z" },
"lastSuccessfulResourceScan": { "id": "00000000-0000-0000-0000-000000000024", "createdAt": "2024-01-15T09:00:00.000Z" }
}
],
"locations": [
{
"id": "00000000-0000-0000-0000-000000000001",
"name": "US East",
"type": "PRIVATE",
"createdAt": "2024-01-15T06:00:00.000Z",
"ip": "192.0.2.1",
"region": "UnitedStates"
}
],
"integrations": [
{
"id": "00000000-0000-0000-0000-000000000002",
"name": "GitHub Org Integration",
"kind": "GITHUB_API_KEY",
"createdAt": "2024-01-15T06:00:00.000Z",
"updatedAt": "2024-01-15T06:00:00.000Z",
"organizationId": "00000000-0000-0000-0000-000000000006"
}
]
}
Numeric examples (score, coverage, durations) are illustrative.
Scoped Field Reference¶
Root Object¶
| Field | Type | Description |
|---|---|---|
issues |
array<Issue> |
Issues that matched the workflow. |
assets |
array<Asset> |
Assets that matched the workflow. Not scan-scoped. |
scans |
array<ResourceScan> |
Scans that matched the workflow. |
profiles |
array<Profile> |
Profiles (applications) that matched the workflow. |
locations |
array<Proxy> |
Locations (proxies) that matched the workflow. |
integrations |
array<Integration> |
Integrations that matched the workflow. No credentials. |
Issue¶
| Field | Type | Description |
|---|---|---|
id |
string (UUID) |
Issue id |
name |
string |
Short name |
fullName |
string |
Display name including risks |
createdAt |
string (ISO 8601) |
Created at |
status |
string |
OPEN, RESOLVED, MANUAL_REVIEW, IGNORED, FALSE_POSITIVE |
severity |
string |
INFO, LOW, MEDIUM, HIGH, CRITICAL |
category |
string |
ACCESS_CONTROL, CONFIGURATION, INFORMATION_DISCLOSURE, SENSITIVE_DATA, INJECTION, PROTOCOL, REQUEST_FORGERY, RESOURCE_LIMITATION, SCHEMA, CUSTOM |
aiContext |
string or null |
AI context |
risks |
array<string> |
Risk kinds |
context |
string |
Issue context |
aiRemediation |
string or null |
AI remediation text |
securityTestUid |
string |
Security test uid |
ticket |
object or null |
id, externalUrl, createdAt, externalId |
asset |
object | Nested issue asset (narrower than root assets[]) |
targets |
array |
Scan-scoped (or last-seen). Nested kinds below. No target id, targetUid, or scanId. |
events |
array |
Latest one event. Same scan filter as targets. |
scan |
object | Present when the item has scan context. Same shape as root Scan. |
application |
object | scan.application when scan is present |
Not included: alertUid, customRule, assetId.
Issue Asset¶
| Field | Type |
|---|---|
id, name, externalUrl, class, type |
scalars |
tags |
id, name, color (6-char hex, no #) |
service, frontend |
id, url or null |
host, cloudComponent |
{ id } or null |
Issue Target (One Nested Object Is Set)¶
| Nested | Fields |
|---|---|
apiRoute |
id, operation, name |
codeFile |
id, path |
graphqlResolver |
id, parent, name |
webPage |
id, url |
webCrawledUrl |
id, url |
cve |
id, cveId |
Issue Event¶
| Field | Type | Description |
|---|---|---|
id |
string (UUID) |
Event id |
createdAt |
string (ISO 8601) |
Created at |
level |
string |
DEBUG, INFO, WARNING, ERROR |
stage |
string |
CONFIGURATION, EXECUTION, AGENT_REASONING, AGENT_ACTION |
Not included: attachments, title, description.
Asset (Root assets[])¶
| Field | Type | Description |
|---|---|---|
id |
string (UUID) |
Asset id |
class |
string |
Asset class |
type |
string |
Asset type |
rootFQDN |
string or null |
Root FQDN |
externalUrl |
string or null |
External URL |
name |
string |
Display name |
manuallySetName |
string or null |
Manual name override |
faviconUrl |
string or null |
Favicon URL |
description |
string |
Description. Empty string when unset. |
manuallySetDescription |
string or null |
Manual description override |
createdAt |
string (ISO 8601) |
Created at |
lastSeenAt |
string (ISO 8601) |
Last seen |
scheduledForDeletionAt |
string (ISO 8601) or null |
Scheduled deletion |
status |
string |
Asset status |
risks |
array<string> |
Asset risk kinds |
owners |
array |
{ email } |
tags |
array |
id, name, color (6-char hex, no #) |
projects |
array |
{ id } |
firstSeenScan, lastSeenScan |
object or null |
id, createdAt |
schema |
object or null |
{ id } only |
service |
object or null |
type, url, framework, authProtocol, authTechnology, cloudProvider, wafProvider, environment, tls, ips |
frontend |
object or null |
type, url, framework, APIFramework, authProtocol, authTechnology, cloudProvider, wafProvider, environment, ips, tls |
host |
object or null |
type, address, ips; ports: { port }; records: { type, value } |
technology |
object or null |
type, technologyKey, version, cpe, referenceUrl, purl, packageType, wellKnownTechnology |
Not included: uri, nested scans, events, repository.
Scan¶
| Field | Type | Description |
|---|---|---|
id |
string (UUID) |
Scan id |
createdAt |
string (ISO 8601) |
Created at |
finishedAt |
string (ISO 8601) or null |
Finished at |
score |
number or null |
Security Score as a number from 0 to 1 (the platform shows it as 0 to 100%) |
coverage |
number or null |
Coverage |
meanDuration |
number or null |
Mean duration |
totalDuration |
number or null |
Total duration |
status |
string |
STARTING, RUNNING, CANCELED, FINISHED, FAILED |
progressRatio |
number or null |
Progress 0 to 1 |
initiator |
string or null |
Initiator |
kind |
string |
Scan kind (for example FRONTEND_DAST, BLST_REST, ASM_REST) |
application |
object | Profile on the scan |
Scan Application¶
| Field | Type |
|---|---|
id, name, scannerKind |
scalars |
asset.id, asset.name |
scalars |
asset.tags |
id, name, color (6-char hex, no #) |
asset.frontend.url, asset.service.url |
when those relations exist |
Profile¶
| Field | Type |
|---|---|
id, name, createdAt, updatedAt |
scalars |
asset |
id, name |
lastResourceScan, lastSuccessfulResourceScan |
id, createdAt or null |
No scannerKind or type on the profile object itself.
Location¶
| Field | Type | Description |
|---|---|---|
id |
string (UUID) |
Location id |
name |
string |
Display name |
type |
string |
ESCAPE, PRIVATE |
createdAt |
string (ISO 8601) |
Created at |
ip |
string or null |
IP |
region |
string or null |
Europe, UnitedStates, Canada, Asia |
Not included: target, enabled.
Integration¶
| Field | Type | Description |
|---|---|---|
id |
string (UUID) |
Integration id |
name |
string |
Display name |
kind |
string |
Integration kind enum |
createdAt |
string (ISO 8601) |
Created at |
updatedAt |
string (ISO 8601) |
Updated at |
organizationId |
string (UUID) |
Organization id |
Not included: parameters, valid, credentials.
Related¶
- Webhook Notifications: setup, firewall, default payload example