#163 · Asset Project IDs in the Escape Public API and CLI
Availability: General Availability. Discover project IDs on every asset response in Escape's public API and CLI: map findings to your portal without extra round trips.
You can already assign assets to projects on writes. Reads stayed silent: asset payloads came back without their project assignments, so anything round-tripping through the API or escape-cli had to call /v3/projects separately to place findings in the right product bucket. Asset payloads now carry projectIds on every read endpoint, and GET /v3/assets accepts a projectIds filter for parity with /v3/scans.
What's New¶
projectIdson every asset payload: returned byGET /v3/assets,GET /v3/assets/:assetId, and every endpoint that embeds an asset (issues, profiles, events, scan issues). Empty array when no project is assigned, nevernull.projectIdsfilter onGET /v3/assets:?projectIds=A,Bscopes a list to assets in any of those projects, mirroring the semantics already on/v3/scans.escape-cli assets list --project-id <uuid>: repeatable flag plumbed through to the same filter.PROJECTScount column inescape-cli assets listandescape-cli assets gettable output. JSON output is unchanged and now includes the fullprojectIdsarray.
Why It Matters¶
Customer AppSec teams plugging Escape into their internal product portals told us they were running extra /v3/projects lookups just to figure out which product each issue belonged to. That's a small tax that adds up across thousands of findings. Round-tripping is now lossless: write projectIds on an asset, read them straight back. Pipelines consuming issues, profiles, or events get the project context on the first response, so you can route findings into the right bucket without a second hop.
How to Get Started¶
- API: read
projectIdsfrom any asset response. Filter lists withGET /v3/assets?projectIds=<uuid>,<uuid>. - CLI:
escape-cli assets list --project-id <uuid> -o jsonscopes the list.escape-cli assets get <id> -o jsonincludesprojectIdson every detail payload. - SDKs: regenerate from
services/public-api/v3.openapi.jsonto pick up the new field and query parameter.
Compatibility¶
Hard-Breaking Changes¶
None.
Soft-Breaking Changes¶
- Public API and CLI
assets listandassets gettable columns: a newPROJECTScount column sits betweenOWNERSandNAME. Scripts that parse the human-readable table by tab-column index need to shift theirNAMEindex by one. JSON output (-o json) is unchanged and is the recommended target for automation.
Non-Breaking Changes¶
projectIds: string[]onAssetSummarizedandAssetDetailed: present on every asset returned by the public API, including embedded assets in issues, profiles, events, and scan issues. SDKs that ignore unknown response keys keep working unchanged.projectIdsquery parameter onGET /v3/assets: optional, comma-separated, OR semantics. Existing callers that don't pass it see no change.--project-idflag onescape-cli assets list: new optional flag, repeatable. Existing invocations are unaffected.
Questions?¶
Have a question? Reach out on your dedicated support channel (Slack, Microsoft Teams, or whichever channel we've set up with your team), or email us at support@escape.tech.