Skip to content

#163 · Asset Project IDs in the Escape Public API and CLI

Availability: General Availability. Discover project IDs on every asset response in Escape's public API and CLI: map findings to your portal without extra round trips.

You can already assign assets to projects on writes. Reads stayed silent: asset payloads came back without their project assignments, so anything round-tripping through the API or escape-cli had to call /v3/projects separately to place findings in the right product bucket. Asset payloads now carry projectIds on every read endpoint, and GET /v3/assets accepts a projectIds filter for parity with /v3/scans.

What's New

  • projectIds on every asset payload: returned by GET /v3/assets, GET /v3/assets/:assetId, and every endpoint that embeds an asset (issues, profiles, events, scan issues). Empty array when no project is assigned, never null.
  • projectIds filter on GET /v3/assets: ?projectIds=A,B scopes a list to assets in any of those projects, mirroring the semantics already on /v3/scans.
  • escape-cli assets list --project-id <uuid>: repeatable flag plumbed through to the same filter.
  • PROJECTS count column in escape-cli assets list and escape-cli assets get table output. JSON output is unchanged and now includes the full projectIds array.

Why It Matters

Customer AppSec teams plugging Escape into their internal product portals told us they were running extra /v3/projects lookups just to figure out which product each issue belonged to. That's a small tax that adds up across thousands of findings. Round-tripping is now lossless: write projectIds on an asset, read them straight back. Pipelines consuming issues, profiles, or events get the project context on the first response, so you can route findings into the right bucket without a second hop.

How to Get Started

  • API: read projectIds from any asset response. Filter lists with GET /v3/assets?projectIds=<uuid>,<uuid>.
  • CLI: escape-cli assets list --project-id <uuid> -o json scopes the list. escape-cli assets get <id> -o json includes projectIds on every detail payload.
  • SDKs: regenerate from services/public-api/v3.openapi.json to pick up the new field and query parameter.

Compatibility

Hard-Breaking Changes

None.

Soft-Breaking Changes

  • Public API and CLI assets list and assets get table columns: a new PROJECTS count column sits between OWNERS and NAME. Scripts that parse the human-readable table by tab-column index need to shift their NAME index by one. JSON output (-o json) is unchanged and is the recommended target for automation.

Non-Breaking Changes

  • projectIds: string[] on AssetSummarized and AssetDetailed: present on every asset returned by the public API, including embedded assets in issues, profiles, events, and scan issues. SDKs that ignore unknown response keys keep working unchanged.
  • projectIds query parameter on GET /v3/assets: optional, comma-separated, OR semantics. Existing callers that don't pass it see no change.
  • --project-id flag on escape-cli assets list: new optional flag, repeatable. Existing invocations are unaffected.

Questions?

Have a question? Reach out on your dedicated support channel (Slack, Microsoft Teams, or whichever channel we've set up with your team), or email us at support@escape.tech.