Skip to content

Webhook Payload

Field-level reference for workflow webhook POST bodies. Unlisted: reachable by URL, not in the sidebar or search.

Setup and firewall: Webhook Notifications.

Payload Format

Setting Payload
Off (default) Current: see Default (current) payload
On Scoped: see Scoped payload

Organization → General → Enable scoped webhook export payload (organization admins).

Update your consumer before enabling the setting.

Both formats:

  • Root keys are always arrays (possibly empty): issues, assets, scans, profiles, locations, integrations.
  • Ignore unknown fields. New keys may appear without a version bump.

Differences (Current vs Scoped)

Area Current Scoped
Issue alertUid, customRule, full target objects with IDs No alertUid or customRule; narrower targets
Asset uri, nested scans, events, full schema, repository data No uri, scans, events, or repository data; schema contains only { id }
Integration parameters, valid Metadata only
Location target, enabled Name, type, region, IP only
Events Many events, full exchanges Latest event only, no attachments

Default (Current) Payload

Used when Enable scoped webhook export payload is off (default).

Full example and tables: Webhook Notifications: default example.

Summary:

  • Issues include alertUid, assetId, nested asset, targets, events, optional scan and application.
  • Assets include uri, scans, events, and type-specific nested objects (service, frontend, host, repository, schema).
  • Locations include target and enabled.
  • Integrations include valid and raw parameters, potentially including API tokens, PATs, client secrets, or other credentials.

Integration Credentials in Default Payloads

Default integration exports include raw configuration parameters. Send them only to receivers trusted to handle those credentials. Enable scoped payloads for receivers that don’t need them; scoped integration exports contain metadata only.


Scoped Payload

Used when Enable scoped webhook export payload is on.

Contract

  • Nullable issue-asset, root-asset, and profile relations use null when absent. Scan-application asset frontend and service keys are omitted when absent. Targets contain only the selected variant; unused variant keys are omitted.
  • Issue scan and application are included only when the workflow is associated with a scan. Otherwise, those keys are omitted. Targets and events come from that scan, or the issue’s last-seen scan when no scan is specified.

Example Payload

{
  "issues": [
    {
      "id": "00000000-0000-0000-0000-000000000008",
      "name": "SQL Injection",
      "fullName": "SQL Injection - CRITICAL",
      "createdAt": "2024-01-15T10:30:00.000Z",
      "status": "OPEN",
      "severity": "HIGH",
      "category": "INJECTION",
      "aiContext": null,
      "risks": [],
      "context": "The application is vulnerable to SQL injection.",
      "aiRemediation": null,
      "securityTestUid": "test-456",
      "ticket": {
        "id": "00000000-0000-0000-0000-000000000007",
        "externalUrl": "https://jira.example.com/browse/SEC-12",
        "createdAt": "2024-01-15T11:00:00.000Z",
        "externalId": "SEC-12"
      },
      "asset": {
        "id": "00000000-0000-0000-0000-000000000009",
        "name": "https://api.example.com",
        "externalUrl": "https://api.example.com",
        "class": "API_SERVICE",
        "type": "REST",
        "tags": [{ "id": "00000000-0000-0000-0000-000000000003", "name": "production", "color": "112233" }],
        "service": { "id": "00000000-0000-0000-0000-000000000010", "url": "https://api.example.com" },
        "frontend": null,
        "host": null,
        "cloudComponent": null
      },
      "targets": [
        {
          "apiRoute": { "id": "00000000-0000-0000-0000-000000000013", "operation": "POST", "name": "/users" }
        }
      ],
      "events": [
        {
          "id": "00000000-0000-0000-0000-000000000025",
          "createdAt": "2024-01-15T10:31:00.000Z",
          "level": "INFO",
          "stage": "EXECUTION"
        }
      ],
      "scan": {
        "id": "00000000-0000-0000-0000-000000000012",
        "createdAt": "2024-01-15T09:00:00.000Z",
        "finishedAt": "2024-01-15T09:45:00.000Z",
        "score": 0.42,
        "coverage": 0.8,
        "meanDuration": 12.5,
        "totalDuration": 2700,
        "status": "FINISHED",
        "progressRatio": 1,
        "initiator": "SCHEDULED",
        "kind": "BLST_REST",
        "application": {
          "id": "00000000-0000-0000-0000-000000000014",
          "name": "My Application",
          "scannerKind": "BLST_REST",
          "asset": {
            "id": "00000000-0000-0000-0000-000000000009",
            "name": "https://api.example.com",
            "tags": [{ "id": "00000000-0000-0000-0000-000000000003", "name": "production", "color": "112233" }],
            "service": { "url": "https://api.example.com" }
          }
        }
      },
      "application": {
        "id": "00000000-0000-0000-0000-000000000014",
        "name": "My Application",
        "scannerKind": "BLST_REST",
        "asset": {
          "id": "00000000-0000-0000-0000-000000000009",
          "name": "https://api.example.com",
          "tags": [{ "id": "00000000-0000-0000-0000-000000000003", "name": "production", "color": "112233" }],
          "service": { "url": "https://api.example.com" }
        }
      }
    }
  ],
  "assets": [
    {
      "id": "00000000-0000-0000-0000-000000000015",
      "class": "FRONTEND",
      "type": "WEBAPP",
      "rootFQDN": "app.example.com",
      "externalUrl": "https://app.example.com",
      "name": "https://app.example.com",
      "manuallySetName": null,
      "faviconUrl": null,
      "description": "",
      "manuallySetDescription": null,
      "createdAt": "2024-01-15T08:00:00.000Z",
      "lastSeenAt": "2024-01-15T10:00:00.000Z",
      "scheduledForDeletionAt": null,
      "status": "MONITORED",
      "risks": [],
      "owners": [{ "email": "owner@example.com" }],
      "tags": [{ "id": "00000000-0000-0000-0000-000000000003", "name": "production", "color": "112233" }],
      "projects": [{ "id": "00000000-0000-0000-0000-000000000004" }],
      "firstSeenScan": { "id": "00000000-0000-0000-0000-000000000024", "createdAt": "2024-01-15T09:00:00.000Z" },
      "lastSeenScan": { "id": "00000000-0000-0000-0000-000000000024", "createdAt": "2024-01-15T09:00:00.000Z" },
      "service": null,
      "frontend": {
        "type": "WEBAPP",
        "url": "https://app.example.com",
        "framework": null,
        "APIFramework": null,
        "authProtocol": null,
        "authTechnology": null,
        "cloudProvider": null,
        "wafProvider": null,
        "environment": null,
        "ips": ["192.0.2.2"],
        "tls": true
      },
      "schema": { "id": "00000000-0000-0000-0000-000000000005" },
      "host": null,
      "technology": null
    }
  ],
  "scans": [
    {
      "id": "00000000-0000-0000-0000-000000000024",
      "createdAt": "2024-01-15T09:00:00.000Z",
      "finishedAt": "2024-01-15T10:00:00.000Z",
      "score": 0.42,
      "coverage": 0.8,
      "meanDuration": 12.5,
      "totalDuration": 3600,
      "status": "FINISHED",
      "progressRatio": 1,
      "initiator": "SCHEDULED",
      "kind": "FRONTEND_DAST",
      "application": {
        "id": "00000000-0000-0000-0000-000000000026",
        "name": "My Application",
        "scannerKind": "FRONTEND_DAST",
        "asset": {
          "id": "00000000-0000-0000-0000-000000000015",
          "name": "https://app.example.com",
          "tags": [],
          "frontend": { "url": "https://app.example.com" }
        }
      }
    }
  ],
  "profiles": [
    {
      "id": "00000000-0000-0000-0000-000000000027",
      "name": "My Application",
      "createdAt": "2024-01-15T07:00:00.000Z",
      "updatedAt": "2024-01-15T07:00:00.000Z",
      "asset": { "id": "00000000-0000-0000-0000-000000000015", "name": "https://app.example.com" },
      "lastResourceScan": { "id": "00000000-0000-0000-0000-000000000024", "createdAt": "2024-01-15T09:00:00.000Z" },
      "lastSuccessfulResourceScan": { "id": "00000000-0000-0000-0000-000000000024", "createdAt": "2024-01-15T09:00:00.000Z" }
    }
  ],
  "locations": [
    {
      "id": "00000000-0000-0000-0000-000000000001",
      "name": "US East",
      "type": "PRIVATE",
      "createdAt": "2024-01-15T06:00:00.000Z",
      "ip": "192.0.2.1",
      "region": "UnitedStates"
    }
  ],
  "integrations": [
    {
      "id": "00000000-0000-0000-0000-000000000002",
      "name": "GitHub Org Integration",
      "kind": "GITHUB_API_KEY",
      "createdAt": "2024-01-15T06:00:00.000Z",
      "updatedAt": "2024-01-15T06:00:00.000Z",
      "organizationId": "00000000-0000-0000-0000-000000000006"
    }
  ]
}

Numeric examples (score, coverage, durations) are illustrative.

Scoped Field Reference

Root Object

Field Type Description
issues array<Issue> Issues that matched the workflow.
assets array<Asset> Assets that matched the workflow. Not scan-scoped.
scans array<ResourceScan> Scans that matched the workflow.
profiles array<Profile> Profiles (applications) that matched the workflow.
locations array<Proxy> Locations (proxies) that matched the workflow.
integrations array<Integration> Integrations that matched the workflow. No credentials.

Issue

Field Type Description
id string (UUID) Issue id
name string Short name
fullName string Display name including risks
createdAt string (ISO 8601) Created at
status string OPEN, RESOLVED, MANUAL_REVIEW, IGNORED, FALSE_POSITIVE
severity string INFO, LOW, MEDIUM, HIGH, CRITICAL
category string ACCESS_CONTROL, CONFIGURATION, INFORMATION_DISCLOSURE, SENSITIVE_DATA, INJECTION, PROTOCOL, REQUEST_FORGERY, RESOURCE_LIMITATION, SCHEMA, CUSTOM
aiContext string or null AI context
risks array<string> Risk kinds
context string Issue context
aiRemediation string or null AI remediation text
securityTestUid string Security test uid
ticket object or null id, externalUrl, createdAt, externalId
asset object Nested issue asset (narrower than root assets[])
targets array Scan-scoped (or last-seen). Nested kinds below. No target id, targetUid, or scanId.
events array Latest one event. Same scan filter as targets.
scan object Present when the item has scan context. Same shape as root Scan.
application object scan.application when scan is present

Not included: alertUid, customRule, assetId.

Issue Asset
Field Type
id, name, externalUrl, class, type scalars
tags id, name, color (6-char hex, no #)
service, frontend id, url or null
host, cloudComponent { id } or null
Issue Target (One Nested Object Is Set)
Nested Fields
apiRoute id, operation, name
codeFile id, path
graphqlResolver id, parent, name
webPage id, url
webCrawledUrl id, url
cve id, cveId
Issue Event
Field Type Description
id string (UUID) Event id
createdAt string (ISO 8601) Created at
level string DEBUG, INFO, WARNING, ERROR
stage string CONFIGURATION, EXECUTION, AGENT_REASONING, AGENT_ACTION

Not included: attachments, title, description.

Asset (Root assets[])

Field Type Description
id string (UUID) Asset id
class string Asset class
type string Asset type
rootFQDN string or null Root FQDN
externalUrl string or null External URL
name string Display name
manuallySetName string or null Manual name override
faviconUrl string or null Favicon URL
description string Description. Empty string when unset.
manuallySetDescription string or null Manual description override
createdAt string (ISO 8601) Created at
lastSeenAt string (ISO 8601) Last seen
scheduledForDeletionAt string (ISO 8601) or null Scheduled deletion
status string Asset status
risks array<string> Asset risk kinds
owners array { email }
tags array id, name, color (6-char hex, no #)
projects array { id }
firstSeenScan, lastSeenScan object or null id, createdAt
schema object or null { id } only
service object or null type, url, framework, authProtocol, authTechnology, cloudProvider, wafProvider, environment, tls, ips
frontend object or null type, url, framework, APIFramework, authProtocol, authTechnology, cloudProvider, wafProvider, environment, ips, tls
host object or null type, address, ips; ports: { port }; records: { type, value }
technology object or null type, technologyKey, version, cpe, referenceUrl, purl, packageType, wellKnownTechnology

Not included: uri, nested scans, events, repository.

Scan

Field Type Description
id string (UUID) Scan id
createdAt string (ISO 8601) Created at
finishedAt string (ISO 8601) or null Finished at
score number or null Security Score as a number from 0 to 1 (the platform shows it as 0 to 100%)
coverage number or null Coverage
meanDuration number or null Mean duration
totalDuration number or null Total duration
status string STARTING, RUNNING, CANCELED, FINISHED, FAILED
progressRatio number or null Progress 0 to 1
initiator string or null Initiator
kind string Scan kind (for example FRONTEND_DAST, BLST_REST, ASM_REST)
application object Profile on the scan
Scan Application
Field Type
id, name, scannerKind scalars
asset.id, asset.name scalars
asset.tags id, name, color (6-char hex, no #)
asset.frontend.url, asset.service.url when those relations exist

Profile

Field Type
id, name, createdAt, updatedAt scalars
asset id, name
lastResourceScan, lastSuccessfulResourceScan id, createdAt or null

No scannerKind or type on the profile object itself.

Location

Field Type Description
id string (UUID) Location id
name string Display name
type string ESCAPE, PRIVATE
createdAt string (ISO 8601) Created at
ip string or null IP
region string or null Europe, UnitedStates, Canada, Asia

Not included: target, enabled.

Integration

Field Type Description
id string (UUID) Integration id
name string Display name
kind string Integration kind enum
createdAt string (ISO 8601) Created at
updatedAt string (ISO 8601) Updated at
organizationId string (UUID) Organization id

Not included: parameters, valid, credentials.