Skip to main content

GraphQL API

The gateway exposes the whole platform at one GraphQL endpoint. Send a bearer token in Authorization and the workspace id in X-Tenant.

Endpoint
https://vulnara-gw.rso.dev/graphql
sh
curl https://vulnara-gw.rso.dev/graphql \
  -H "Authorization: Bearer $VULNARA_TOKEN" \
  -H "X-Tenant: $VULNARA_TENANT" \
  -H "Content-Type: application/json" \
  -d '{"query":"{ myUser { id } }"}'

acceptInvitationMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation AcceptInvitation($id: ID!) {
  acceptInvitation(id: $id)
}

associateGitTokenWithGitEntityMutation

Arguments

NameTypeDescription
inputGitTokenAssociationInput!

Returns GitToken!

Example
mutation AssociateGitTokenWithGitEntity($input: GitTokenAssociationInput!) {
  associateGitTokenWithGitEntity(input: $input) {
    id
    name
    value
    expiresAt
    flags
    status
    scopes
    createdAt
  }
}

Also available as: CLI command vulnara associate_git_token_with_git_entity

cancelTaskMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation CancelTask($id: ID!) {
  cancelTask(id: $id)
}

Also available as: CLI command vulnara cancel_task

checkGitTokenQuery

Probe the token against its provider, returning validity, the provider's error (when rejected) and the reported expiry. Used by the add-token form to surface why a token was rejected. When a workspace name is supplied and the token is valid, also returns how many repositories the token can see for it (public + private).

Arguments

NameTypeDescription
valueString!
gitTypeGitType!
nameString

Returns GitTokenCheck!

Example
query CheckGitToken($value: String!, $gitType: GitType!, $name: String) {
  checkGitToken(value: $value, gitType: $gitType, name: $name) {
    valid
    statusCode
    error
    expiresAt
    publicRepositoryCount
    privateRepositoryCount
  }
}

clearFindingTriageMutation

Arguments

NameTypeDescription
repositoryIdID!
matchKeyString!

Returns Boolean!

Example
mutation ClearFindingTriage($repositoryId: ID!, $matchKey: String!) {
  clearFindingTriage(repositoryId: $repositoryId, matchKey: $matchKey)
}

commitScansQuery

Arguments

NameTypeDescription
listList

Returns CommitScanListResult!

Example
query CommitScans($list: List) {
  commitScans(list: $list) {
    total
    items {
      id
      scanResultId
      commitHash
      createdAt
      updatedAt
    }
  }
}

Also available as: MCP tool commit_scans

confirmEmptyOrderMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation ConfirmEmptyOrder($id: ID!) {
  confirmEmptyOrder(id: $id)
}

createEmptyOrderMutation

Returns RevolutOrder!

Example
mutation CreateEmptyOrder {
  createEmptyOrder {
    id
  }
}

createGitEntityMutation

Arguments

NameTypeDescription
inputCreateGitEntityInput!

Returns GitEntity!

Example
mutation CreateGitEntity($input: CreateGitEntityInput!) {
  createGitEntity(input: $input) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

Also available as: CLI command vulnara create_git_entity

createGitTokenMutation

Arguments

NameTypeDescription
inputCreateGitTokenInput!

Returns GitToken!

Example
mutation CreateGitToken($input: CreateGitTokenInput!) {
  createGitToken(input: $input) {
    id
    name
    value
    expiresAt
    flags
    status
    scopes
    createdAt
  }
}

Also available as: CLI command vulnara create_git_token

createInvoiceDownloadUrlMutation

Arguments

NameTypeDescription
invoiceIdID!

Returns InvoiceDownload!

Example
mutation CreateInvoiceDownloadUrl($invoiceId: ID!) {
  createInvoiceDownloadUrl(invoiceId: $invoiceId) {
    url
    filename
    tenant
    contentType
  }
}

createNetworkMutation

Arguments

NameTypeDescription
inputCreateNetworkInput!

Returns Network!

Example
mutation CreateNetwork($input: CreateNetworkInput!) {
  createNetwork(input: $input) {
    id
    name
    network
    networkType
    tenant
    securityScore
    createdAt
    updatedAt
  }
}

Also available as: CLI command vulnara create_network

createNotificationScopeMutation

Arguments

NameTypeDescription
inputCreateNotificationScopeInput!

Returns NotificationScope!

Example
mutation CreateNotificationScope($input: CreateNotificationScopeInput!) {
  createNotificationScope(input: $input) {
    id
    channelIds
    channelType
    scopes
    isActive
    status
    headers {
      name
      value
    }
    template
  }
}

Also available as: CLI command vulnara create_notification_scope

createRepositoryMutation

Arguments

NameTypeDescription
inputCreateRepositoryInput!

Returns Repository!

Example
mutation CreateRepository($input: CreateRepositoryInput!) {
  createRepository(input: $input) {
    id
    gitEntityId
    repositoryName
    private
    securityScore
    programmingLanguage
    repositorySize
    numberOfBranches
  }
}

Also available as: CLI command vulnara create_repository

createScanScheduleMutation

Arguments

NameTypeDescription
inputCreateScanScheduleInput!

Returns ScanSchedule!

Example
mutation CreateScanSchedule($input: CreateScanScheduleInput!) {
  createScanSchedule(input: $input) {
    id
    action
    repositoryId
    gitEntityId
    branch
    dockerScanToolId
    frequency
    hourUtc
  }
}

createServiceAccountMutation

Arguments

NameTypeDescription
inputCreateServiceAccountInput!

Returns CreateServiceAccountPayload!

Example
mutation CreateServiceAccount($input: CreateServiceAccountInput!) {
  createServiceAccount(input: $input) {
    serviceAccount {
      id
      name
      isActive
      expiresAt
    }
  }
}

Also available as: CLI command vulnara create_service_account

createTenantMutation

Arguments

NameTypeDescription
inputCreateTenantInput!

Returns Tenant!

Example
mutation CreateTenant($input: CreateTenantInput!) {
  createTenant(input: $input) {
    id
    isPaying
    members {
      id
      roles
    }
  }
}

Also available as: CLI command vulnara create_tenant

dashboardAnalyticsQuery

Arguments

NameTypeDescription
daysInt

Returns DashboardAnalytics!

Example
query DashboardAnalytics($days: Int) {
  dashboardAnalytics(days: $days) {
    days
    generatedAt
    lastScanAt
    averageSecurityScore
    previousAverageSecurityScore
    severityCounts {
      severity
      count
    }
    previousSeverityCounts {
      severity
      count
    }
    exposure {
      total
      previousTotal
      newFindings
      resolvedFindings
      codeFindings
      dependencyFindings
      corroboratedFindings
      falsePositives
    }
  }
}

Also available as: MCP tool dashboard_analytics

declineInvitationMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeclineInvitation($id: ID!) {
  declineInvitation(id: $id)
}

deleteGitEntityMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteGitEntity($id: ID!) {
  deleteGitEntity(id: $id)
}

Also available as: CLI command vulnara delete_git_entity

deleteGitTokenMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteGitToken($id: ID!) {
  deleteGitToken(id: $id)
}

Also available as: CLI command vulnara delete_git_token

deleteInvitationMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteInvitation($id: ID!) {
  deleteInvitation(id: $id)
}

deleteNetworkMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteNetwork($id: ID!) {
  deleteNetwork(id: $id)
}

Also available as: CLI command vulnara delete_network

deleteNetworkScanResultMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteNetworkScanResult($id: ID!) {
  deleteNetworkScanResult(id: $id)
}

Also available as: CLI command vulnara delete_network_scan_result

deleteNotificationScopeMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteNotificationScope($id: ID!) {
  deleteNotificationScope(id: $id)
}

Also available as: CLI command vulnara delete_notification_scope

deletePaymentMethodMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeletePaymentMethod($id: ID!) {
  deletePaymentMethod(id: $id)
}

deleteRepositoryMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteRepository($id: ID!) {
  deleteRepository(id: $id)
}

Also available as: CLI command vulnara delete_repository

deleteScanResultMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteScanResult($id: ID!) {
  deleteScanResult(id: $id)
}

Also available as: CLI command vulnara delete_scan_result

deleteScanScheduleMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteScanSchedule($id: ID!) {
  deleteScanSchedule(id: $id)
}

deleteServiceAccountMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteServiceAccount($id: ID!) {
  deleteServiceAccount(id: $id)
}

Also available as: CLI command vulnara delete_service_account

deleteTenantMemberMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DeleteTenantMember($id: ID!) {
  deleteTenantMember(id: $id)
}

dismissTaskMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation DismissTask($id: ID!) {
  dismissTask(id: $id)
}

dissociateGitTokenWithGitEntityMutation

Arguments

NameTypeDescription
inputGitTokenAssociationInput!

Returns Boolean!

Example
mutation DissociateGitTokenWithGitEntity($input: GitTokenAssociationInput!) {
  dissociateGitTokenWithGitEntity(input: $input)
}

Also available as: CLI command vulnara dissociate_git_token_with_git_entity

dockerScanToolQuery

Arguments

NameTypeDescription
idID!

Returns DockerScanTool!

Example
query DockerScanTool($id: ID!) {
  dockerScanTool(id: $id) {
    id
    name
  }
}

Also available as: MCP tool docker_scan_tool

dockerScanToolsQuery

Arguments

NameTypeDescription
listList

Returns DockerScanToolListResult!

Example
query DockerScanTools($list: List) {
  dockerScanTools(list: $list) {
    total
    items {
      id
      name
    }
  }
}

Also available as: MCP tool docker_scan_tools

downgradeToFreeMutation

Returns Boolean!

Example
mutation DowngradeToFree {
  downgradeToFree
}

fetchRepositoriesMutation

Arguments

NameTypeDescription
inputFetchRepositoriesInput!

Returns Boolean!

Example
mutation FetchRepositories($input: FetchRepositoriesInput!) {
  fetchRepositories(input: $input)
}

Also available as: CLI command vulnara fetch_repositories

findingCorroborationQuery

Cross-tool agreement for every secret found in a repository.

Arguments

NameTypeDescription
repositoryIdID!

Returns FindingCorroborationListResult!

Example
query FindingCorroboration($repositoryId: ID!) {
  findingCorroboration(repositoryId: $repositoryId) {
    total
    items {
      id
      matchHash
      toolCount
      severity
    }
  }
}

Also available as: MCP tool finding_corroboration

findingTriageQuery

Arguments

NameTypeDescription
repositoryIdID!

Returns [FindingTriage!]!

Example
query FindingTriage($repositoryId: ID!) {
  findingTriage(repositoryId: $repositoryId) {
    id
    repositoryId
    matchKey
    findingType
    state
    justification
    response
    priority
  }
}

Also available as: MCP tool finding_triage

findingTriageHistoryQuery

Every decision ever taken on this repository's findings, newest first.

Arguments

NameTypeDescription
repositoryIdID!
matchKeyString

Returns [FindingTriageEvent!]!

Example
query FindingTriageHistory($repositoryId: ID!, $matchKey: String) {
  findingTriageHistory(repositoryId: $repositoryId, matchKey: $matchKey) {
    id
    repositoryId
    matchKey
    action
    state
    justification
    response
    priority
  }
}

Also available as: MCP tool finding_triage_history

gitEntitiesQuery

Arguments

NameTypeDescription
listList

Returns GitEntityListResult!

Example
query GitEntities($list: List) {
  gitEntities(list: $list) {
    total
  }
}

Also available as: CLI command vulnara git_entities · MCP tool git_entities

gitEntityQuery

Arguments

NameTypeDescription
idID!

Returns GitEntity!

Example
query GitEntity($id: ID!) {
  gitEntity(id: $id) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

Also available as: CLI command vulnara get_git_entity · MCP tool git_entity

gitEntityProvidersQuery

Providers on which a bare handle resolves to an org/user/group. Lets the add-workspace form infer the provider automatically and only ask the user to choose when the same handle exists on more than one provider.

Arguments

NameTypeDescription
nameString!

Returns [GitType!]!

Example
query GitEntityProviders($name: String!) {
  gitEntityProviders(name: $name)
}

gitEntityRepositoryCountQuery

Arguments

NameTypeDescription
nameString!
gitTypeGitType!

Returns Int

Example
query GitEntityRepositoryCount($name: String!, $gitType: GitType!) {
  gitEntityRepositoryCount(name: $name, gitType: $gitType)
}

gitTokenQuery

Arguments

NameTypeDescription
idID!

Returns GitToken!

Example
query GitToken($id: ID!) {
  gitToken(id: $id) {
    id
    name
    value
    expiresAt
    flags
    status
    scopes
    createdAt
  }
}

Also available as: CLI command vulnara get_git_token

gitTokenExpirationQuery

The token's own expiry as reported by the provider (GitHub's token-expiration header / GitLab's PAT self endpoint), or null if the provider doesn't expose one or the token couldn't be checked. Lets the UI hide the manual "expires at" field when the token reports it itself.

Arguments

NameTypeDescription
valueString!
gitTypeGitType!

Returns DateTime

Example
query GitTokenExpiration($value: String!, $gitType: GitType!) {
  gitTokenExpiration(value: $value, gitType: $gitType)
}

gitTokensQuery

Arguments

NameTypeDescription
listList

Returns GitTokenListResult!

Example
query GitTokens($list: List) {
  gitTokens(list: $list) {
    total
    items {
      id
      name
      value
      expiresAt
      flags
      status
      scopes
      createdAt
    }
  }
}

Also available as: CLI command vulnara git_tokens

gitUserQuery

Arguments

NameTypeDescription
idID!

Returns GitEntity!

Example
query GitUser($id: ID!) {
  gitUser(id: $id) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

Also available as: MCP tool git_user

gitUsersQuery

Arguments

NameTypeDescription
listList

Returns GitEntityListResult!

Example
query GitUsers($list: List) {
  gitUsers(list: $list) {
    total
  }
}

Also available as: MCP tool git_users

invitationQuery

Arguments

NameTypeDescription
idID!

Returns Invitation

Example
query Invitation($id: ID!) {
  invitation(id: $id) {
    id
    email
    tenantName
  }
}

invitationsQuery

Returns [Invitation!]!

Example
query Invitations {
  invitations {
    id
    email
    tenantName
  }
}

inviteTenantMemberMutation

Arguments

NameTypeDescription
inputInviteTeamMemberInput!

Returns Boolean!

Example
mutation InviteTenantMember($input: InviteTeamMemberInput!) {
  inviteTenantMember(input: $input)
}

invoiceQuery

Arguments

NameTypeDescription
idID!

Returns Invoice!

Example
query Invoice($id: ID!) {
  invoice(id: $id) {
    id
    invoiceNumber
    date
    dueDate
    status
    total
    currency
  }
}

invoicesQuery

Arguments

NameTypeDescription
listList

Returns InvoiceListResult!

Example
query Invoices($list: List) {
  invoices(list: $list) {
    total
    items {
      id
      invoiceNumber
      date
      dueDate
      status
      total
      currency
    }
  }
}

markAllNotificationsReadMutation

Returns Boolean!

Example
mutation MarkAllNotificationsRead {
  markAllNotificationsRead
}

markNotificationDeliveredMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation MarkNotificationDelivered($id: ID!) {
  markNotificationDelivered(id: $id)
}

markNotificationsReadMutation

Arguments

NameTypeDescription
ids[ID!]!

Returns Boolean!

Example
mutation MarkNotificationsRead($ids: [ID!]!) {
  markNotificationsRead(ids: $ids)
}

myUserQuery

Returns MyUser

Example
query MyUser {
  myUser {
    id
    email
    name
    username
    tenants {
      id
      isPaying
    }
    preferences {
      theme
      dateTimeFormat
      repositoriesView
    }
  }
}

Also available as: MCP tool my_user

networkQuery

Arguments

NameTypeDescription
idID!

Returns Network!

Example
query Network($id: ID!) {
  network(id: $id) {
    id
    name
    network
    networkType
    tenant
    securityScore
    createdAt
    updatedAt
  }
}

Also available as: CLI command vulnara get_network · MCP tool network

networksQuery

Arguments

NameTypeDescription
listList

Returns NetworkListResult!

Example
query Networks($list: List) {
  networks(list: $list) {
    total
    items {
      id
      name
      network
      networkType
      tenant
      securityScore
      createdAt
      updatedAt
    }
  }
}

Also available as: CLI command vulnara networks · MCP tool networks

networkScanFindingQuery

Arguments

NameTypeDescription
idID!

Returns NetworkScanFinding!

Example
query NetworkScanFinding($id: ID!) {
  networkScanFinding(id: $id) {
    id
    scanResultId
    host
    hostname
    hostnameType
    protocol
    port
    serviceName
  }
}

Also available as: MCP tool network_scan_finding

networkScanFindingsQuery

Arguments

NameTypeDescription
listList

Returns NetworkScanFindingListResult!

Example
query NetworkScanFindings($list: List) {
  networkScanFindings(list: $list) {
    total
    items {
      id
      scanResultId
      host
      hostname
      hostnameType
      protocol
      port
      serviceName
    }
  }
}

Also available as: CLI command vulnara network_scan_findings · MCP tool network_scan_findings

networkScanResultQuery

Arguments

NameTypeDescription
idID!

Returns NetworkScanResult!

Example
query NetworkScanResult($id: ID!) {
  networkScanResult(id: $id) {
    id
    networkId
    status
    createdAt
    updatedAt
    scanTime
    network {
      id
      name
      network
      networkType
      tenant
      securityScore
      createdAt
      updatedAt
    }
  }
}

Also available as: CLI command vulnara get_network_scan_result · MCP tool network_scan_result

networkScanResultsQuery

Arguments

NameTypeDescription
listList

Returns NetworkScanResultListResult!

Example
query NetworkScanResults($list: List) {
  networkScanResults(list: $list) {
    total
    items {
      id
      networkId
      status
      createdAt
      updatedAt
      scanTime
    }
  }
}

Also available as: CLI command vulnara network_scan_results · MCP tool network_scan_results

notificationsQuery

Arguments

NameTypeDescription
listList

Returns NotificationList!

Example
query Notifications($list: List) {
  notifications(list: $list) {
    items {
      id
      type
      eventType
      data
      read
      createdAt
    }
    total
  }
}

Also available as: MCP tool notifications

notificationsSubscription

Returns Notification!

Example
subscription Notifications {
  notifications {
    id
    type
    eventType
    data
    read
    createdAt
  }
}

notificationScopeQuery

Arguments

NameTypeDescription
idID!

Returns NotificationScope!

Example
query NotificationScope($id: ID!) {
  notificationScope(id: $id) {
    id
    channelIds
    channelType
    scopes
    isActive
    status
    headers {
      name
      value
    }
    template
  }
}

Also available as: CLI command vulnara get_notification_scope · MCP tool notification_scope

notificationScopesQuery

Arguments

NameTypeDescription
listList

Returns NotificationScopeListResult!

Example
query NotificationScopes($list: List) {
  notificationScopes(list: $list) {
    total
    items {
      id
      channelIds
      channelType
      scopes
      isActive
      status
      template
    }
  }
}

Also available as: CLI command vulnara notification_scopes · MCP tool notification_scopes

organizationQuery

Arguments

NameTypeDescription
idID!

Returns GitEntity!

Example
query Organization($id: ID!) {
  organization(id: $id) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

Also available as: MCP tool organization

organizationsQuery

Arguments

NameTypeDescription
listList

Returns GitEntityListResult!

Example
query Organizations($list: List) {
  organizations(list: $list) {
    total
  }
}

Also available as: MCP tool organizations

paymentMethodQuery

Arguments

NameTypeDescription
idID!

Returns PaymentMethod!

Example
query PaymentMethod($id: ID!) {
  paymentMethod(id: $id) {
    id
    default
    lastFour
    brand
    expiryMonth
    expiryYear
    cardholderName
    expired
  }
}

paymentMethodsQuery

Arguments

NameTypeDescription
listList

Returns PaymentMethodListResult!

Example
query PaymentMethods($list: List) {
  paymentMethods(list: $list) {
    total
    items {
      id
      default
      lastFour
      brand
      expiryMonth
      expiryYear
      cardholderName
      expired
    }
  }
}

plansQuery

Returns [Plan!]!

Example
query Plans {
  plans {
    id
    availableGitScanMinutes
    availableNetworkScanMinutes
    maxRepositories
    maxNetworks
    maxEmails
    pricePerGitScanMinute
    pricePerNetworkScanMinute
  }
}

programmingLanguagesQuery

Returns [String!]

Example
query ProgrammingLanguages {
  programmingLanguages
}

Also available as: CLI command vulnara programming_languages · MCP tool programming_languages

promoGrantsQuery

Every grant this tenant holds, including ones that have run out.

Returns [PromoGrant!]!

Example
query PromoGrants {
  promoGrants {
    id
    code
    startsAt
    endsAt
    gitScanMinutes
    networkScanMinutes
    maxRepositories
    maxNetworks
  }
}

Also available as: MCP tool promo_grants

redeemPromoCodeMutation

Redeem a code for this tenant. ADMIN because redeeming changes what the tenant may spend, which is the same authority as changing the plan. A refusal arrives as PROMO_CODE_UNKNOWN, PROMO_CODE_INACTIVE, PROMO_CODE_EXPIRED, PROMO_CODE_FULLY_CLAIMED or PROMO_CODE_ALREADY_REDEEMED. They are distinct because each tells the person typing the code something different about what to do next.

Arguments

NameTypeDescription
codeString!

Returns PromoGrant!

Example
mutation RedeemPromoCode($code: String!) {
  redeemPromoCode(code: $code) {
    id
    code
    startsAt
    endsAt
    gitScanMinutes
    networkScanMinutes
    maxRepositories
    maxNetworks
  }
}

registerPushSubscriptionMutation

Arguments

NameTypeDescription
inputPushSubscriptionInput!

Returns Boolean!

Example
mutation RegisterPushSubscription($input: PushSubscriptionInput!) {
  registerPushSubscription(input: $input)
}

remediationTemplateQuery

Returns RemediationTemplate!

Example
query RemediationTemplate {
  remediationTemplate {
    codeIssueBody
    dependencyIssueBody
    pullRequestBody
  }
}

Also available as: MCP tool remediation_template

repositoriesQuery

Arguments

NameTypeDescription
listList

Returns RepositoryListResult!

Example
query Repositories($list: List) {
  repositories(list: $list) {
    total
    items {
      id
      gitEntityId
      repositoryName
      private
      securityScore
      programmingLanguage
      repositorySize
      numberOfBranches
    }
  }
}

Also available as: CLI command vulnara repositories · MCP tool repositories

repositoryQuery

Arguments

NameTypeDescription
idID!

Returns Repository!

Example
query Repository($id: ID!) {
  repository(id: $id) {
    id
    gitEntityId
    repositoryName
    private
    securityScore
    programmingLanguage
    repositorySize
    numberOfBranches
  }
}

Also available as: CLI command vulnara get_repository · MCP tool repository

repositoryBranchesQuery

Branch names for a repository, read from its git provider, so the scan form can offer real branches instead of free-text input.

Arguments

NameTypeDescription
repositoryIdID!

Returns [String!]!

Example
query RepositoryBranches($repositoryId: ID!) {
  repositoryBranches(repositoryId: $repositoryId)
}

Also available as: MCP tool repository_branches

repositoryDependencyScanFindingGroupsQuery

Arguments

NameTypeDescription
listList

Returns RepositoryDependencyScanFindingGroupListResult!

Example
query RepositoryDependencyScanFindingGroups($list: List) {
  repositoryDependencyScanFindingGroups(list: $list) {
    total
    items {
      id
      dependency
      repositoryId
      severity
      installedVersion
      occurrences
      issueUrl
      issueStatus
    }
  }
}

Also available as: MCP tool repository_dependency_scan_finding_groups

repositoryDependencyScanFindingsQuery

Arguments

NameTypeDescription
listList

Returns RepositoryDependencyScanFindingListResult!

Example
query RepositoryDependencyScanFindings($list: List) {
  repositoryDependencyScanFindings(list: $list) {
    total
    items {
      id
      commitScanId
      createdAt
      updatedAt
      severity
      vulnerability
      dependency
      installedVersion
    }
  }
}

Also available as: CLI command vulnara repository_dependency_scan_findings · MCP tool repository_dependency_scan_findings

requestNSFConsultationMutation

Arguments

NameTypeDescription
inputNSFConsultation!

Returns Boolean!

Example
mutation RequestNSFConsultation($input: NSFConsultation!) {
  requestNSFConsultation(input: $input)
}

Also available as: CLI command vulnara request_nsf_consultation

requestRSFConsultationMutation

Arguments

NameTypeDescription
inputRSFConsultation!

Returns Boolean!

Example
mutation RequestRSFConsultation($input: RSFConsultation!) {
  requestRSFConsultation(input: $input)
}

Also available as: CLI command vulnara request_rsf_consultation

retryPaymentMutation

Arguments

NameTypeDescription
invoiceIdID!
paymentMethodIdID!

Returns Invoice!

Example
mutation RetryPayment($invoiceId: ID!, $paymentMethodId: ID!) {
  retryPayment(invoiceId: $invoiceId, paymentMethodId: $paymentMethodId) {
    id
    invoiceNumber
    date
    dueDate
    status
    total
    currency
  }
}

revealScanFindingMatchMutation

The audited path to the raw secret behind a masked ScanFinding/ScanFindingGroup/ ScanFindingMatchGroup.match. Every call is logged with the caller, repository and match hash.

Arguments

NameTypeDescription
repositoryIdID!
matchHashString!

Returns String!

Example
mutation RevealScanFindingMatch($repositoryId: ID!, $matchHash: String!) {
  revealScanFindingMatch(repositoryId: $repositoryId, matchHash: $matchHash)
}

scanFindingGroupsQuery

Arguments

NameTypeDescription
listList

Returns ScanFindingGroupListResult!

Example
query ScanFindingGroups($list: List) {
  scanFindingGroups(list: $list) {
    total
    items {
      id
      fingerprint
      matchHash
      matchedByToolCount
      file
      severity
      confidence
      match
    }
  }
}

Also available as: MCP tool scan_finding_groups

scanFindingMatchGroupsQuery

Findings grouped by cross-tool identity, one row per real secret.

Arguments

NameTypeDescription
listList

Returns ScanFindingMatchGroupListResult!

Example
query ScanFindingMatchGroups($list: List) {
  scanFindingMatchGroups(list: $list) {
    total
    items {
      id
      matchHash
      file
      line
      severity
      confidence
      match
      occurrences
    }
  }
}

Also available as: MCP tool scan_finding_match_groups

scanFindingsQuery

Arguments

NameTypeDescription
listList

Returns ScanFindingListResult!

Example
query ScanFindings($list: List) {
  scanFindings(list: $list) {
    total
    items {
      id
      commitScanId
      createdAt
      updatedAt
      line
      file
      severity
      confidence
    }
  }
}

Also available as: CLI command vulnara scan_findings · MCP tool scan_findings

scanResultQuery

Arguments

NameTypeDescription
idID!

Returns ScanResult!

Example
query ScanResult($id: ID!) {
  scanResult(id: $id) {
    id
    repositoryId
    scanType
    scanner
    dockerScanToolId
    status
    createdAt
    updatedAt
  }
}

Also available as: CLI command vulnara get_scan_result · MCP tool scan_result

scanResultsQuery

Arguments

NameTypeDescription
listList

Returns ScanResultListResult!

Example
query ScanResults($list: List) {
  scanResults(list: $list) {
    total
    items {
      id
      repositoryId
      scanType
      scanner
      dockerScanToolId
      status
      createdAt
      updatedAt
    }
  }
}

Also available as: CLI command vulnara scan_results · MCP tool scan_results

scanScheduleQuery

Arguments

NameTypeDescription
idID!

Returns ScanSchedule!

Example
query ScanSchedule($id: ID!) {
  scanSchedule(id: $id) {
    id
    action
    repositoryId
    gitEntityId
    branch
    dockerScanToolId
    frequency
    hourUtc
  }
}

Also available as: MCP tool scan_schedule

scanSchedulesQuery

Arguments

NameTypeDescription
listList

Returns ScanScheduleListResult!

Example
query ScanSchedules($list: List) {
  scanSchedules(list: $list) {
    total
    items {
      id
      action
      repositoryId
      gitEntityId
      branch
      dockerScanToolId
      frequency
      hourUtc
    }
  }
}

Also available as: MCP tool scan_schedules

serviceAccountsQuery

Returns [ServiceAccount!]!

Example
query ServiceAccounts {
  serviceAccounts {
    id
    name
    isActive
    expiresAt
    createdBy {
      id
      email
      username
      name
    }
  }
}

Also available as: CLI command vulnara service_accounts

setDefaultPaymentMethodMutation

Arguments

NameTypeDescription
idID!

Returns Boolean!

Example
mutation SetDefaultPaymentMethod($id: ID!) {
  setDefaultPaymentMethod(id: $id)
}

setFindingTriageMutation

Arguments

NameTypeDescription
inputSetFindingTriageInput!

Returns FindingTriage!

Example
mutation SetFindingTriage($input: SetFindingTriageInput!) {
  setFindingTriage(input: $input) {
    id
    repositoryId
    matchKey
    findingType
    state
    justification
    response
    priority
  }
}

setGitEntityIgnorePathsMutation

Arguments

NameTypeDescription
inputSetGitEntityIgnorePathsInput!

Returns GitEntity!

Example
mutation SetGitEntityIgnorePaths($input: SetGitEntityIgnorePathsInput!) {
  setGitEntityIgnorePaths(input: $input) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

setRemediationTemplateMutation

Arguments

NameTypeDescription
inputRemediationTemplateInput!

Returns RemediationTemplate!

Example
mutation SetRemediationTemplate($input: RemediationTemplateInput!) {
  setRemediationTemplate(input: $input) {
    codeIssueBody
    dependencyIssueBody
    pullRequestBody
  }
}

setRepositoryEnabledMutation

Arguments

NameTypeDescription
inputSetRepositoryEnabledInput!

Returns Boolean!

Example
mutation SetRepositoryEnabled($input: SetRepositoryEnabledInput!) {
  setRepositoryEnabled(input: $input)
}

setRepositoryIgnorePathsMutation

Arguments

NameTypeDescription
inputSetRepositoryIgnorePathsInput!

Returns Repository!

Example
mutation SetRepositoryIgnorePaths($input: SetRepositoryIgnorePathsInput!) {
  setRepositoryIgnorePaths(input: $input) {
    id
    gitEntityId
    repositoryName
    private
    securityScore
    programmingLanguage
    repositorySize
    numberOfBranches
  }
}

setServiceAccountActiveMutation

Arguments

NameTypeDescription
inputSetServiceAccountActiveInput!

Returns ServiceAccount!

Example
mutation SetServiceAccountActive($input: SetServiceAccountActiveInput!) {
  setServiceAccountActive(input: $input) {
    id
    name
    isActive
    expiresAt
    createdBy {
      id
      email
      username
      name
    }
  }
}

Also available as: CLI command vulnara set_service_account_active

startNetworkScanMutation

Arguments

NameTypeDescription
inputStartNetworkScanInput!

Returns Boolean!

Example
mutation StartNetworkScan($input: StartNetworkScanInput!) {
  startNetworkScan(input: $input)
}

Also available as: CLI command vulnara start_network_scan

startRepositoryScanMutation

Arguments

NameTypeDescription
inputStartRepositoryScanInput!

Returns RepositoryScanTask!

Example
mutation StartRepositoryScan($input: StartRepositoryScanInput!) {
  startRepositoryScan(input: $input) {
    id
    objectId
    status
    state {
      totalCommits
      scheduled
      scanned
      failed
      parsed
    }
    createdAt
    scanResult {
      id
      repositoryId
      scanType
      scanner
      dockerScanToolId
      status
      createdAt
      updatedAt
    }
  }
}

Also available as: CLI command vulnara start_repository_scan

statisticsQuery

Returns TenantStatistics!

Example
query Statistics {
  statistics {
    tenant
    totalUsers
    totalGitEntities
    totalRepositories
    totalNetworks
  }
}

Also available as: MCP tool statistics

taskQuery

Arguments

NameTypeDescription
idID!

Returns Task!

Example
query Task($id: ID!) {
  task(id: $id) {
    __typename
    ... on RepositoryScanTask {
      id
      objectId
      status
      createdAt
    }
    ... on NetworkScanTask {
      id
      objectId
      status
      createdAt
    }
  }
}

Also available as: MCP tool task

taskEventsSubscription

Returns TaskEvent!

Example
subscription TaskEvents {
  taskEvents {
    type
    taskId
  }
}

tasksQuery

Returns [Task!]!

Example
query Tasks {
  tasks {
    __typename
    ... on RepositoryScanTask {
      id
      objectId
      status
      createdAt
    }
    ... on NetworkScanTask {
      id
      objectId
      status
      createdAt
    }
  }
}

Also available as: CLI command vulnara tasks · MCP tool tasks

testNotificationScopeMutation

Send a test notification to the rule's channel and record its reachability as the channel status.

Arguments

NameTypeDescription
idID!

Returns NotificationScope!

Example
mutation TestNotificationScope($id: ID!) {
  testNotificationScope(id: $id) {
    id
    channelIds
    channelType
    scopes
    isActive
    status
    headers {
      name
      value
    }
    template
  }
}

transferGitEntityMutation

Arguments

NameTypeDescription
inputTransferGitEntityInput!

Returns Boolean!

Example
mutation TransferGitEntity($input: TransferGitEntityInput!) {
  transferGitEntity(input: $input)
}

Also available as: CLI command vulnara transfer_git_entity

transferNetworkMutation

Arguments

NameTypeDescription
inputTransferNetworkInput!

Returns Boolean!

Example
mutation TransferNetwork($input: TransferNetworkInput!) {
  transferNetwork(input: $input)
}

Also available as: CLI command vulnara transfer_network

unreadNotificationCountQuery

Returns Int!

Example
query UnreadNotificationCount {
  unreadNotificationCount
}

Also available as: MCP tool unread_notification_count

unregisterPushSubscriptionMutation

Arguments

NameTypeDescription
endpointString!

Returns Boolean!

Example
mutation UnregisterPushSubscription($endpoint: String!) {
  unregisterPushSubscription(endpoint: $endpoint)
}

updateGitEntityMutation

Arguments

NameTypeDescription
inputUpdateGitEntityInput!

Returns GitEntity!

Example
mutation UpdateGitEntity($input: UpdateGitEntityInput!) {
  updateGitEntity(input: $input) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

updateGitTokenMutation

Arguments

NameTypeDescription
inputUpdateGitTokenInput!

Returns GitToken!

Example
mutation UpdateGitToken($input: UpdateGitTokenInput!) {
  updateGitToken(input: $input) {
    id
    name
    value
    expiresAt
    flags
    status
    scopes
    createdAt
  }
}

Also available as: CLI command vulnara update_git_token

updateMyUserPreferencesMutation

Arguments

NameTypeDescription
inputUpdateUserPreferencesInput!

Returns UserPreferences!

Example
mutation UpdateMyUserPreferences($input: UpdateUserPreferencesInput!) {
  updateMyUserPreferences(input: $input) {
    theme
    dateTimeFormat
    repositoriesView
  }
}

updateNotificationScopeMutation

Arguments

NameTypeDescription
inputUpdateNotificationScopeInput!

Returns NotificationScope!

Example
mutation UpdateNotificationScope($input: UpdateNotificationScopeInput!) {
  updateNotificationScope(input: $input) {
    id
    channelIds
    channelType
    scopes
    isActive
    status
    headers {
      name
      value
    }
    template
  }
}

Also available as: CLI command vulnara update_notification_scope

updateScanScheduleMutation

Arguments

NameTypeDescription
inputUpdateScanScheduleInput!

Returns ScanSchedule!

Example
mutation UpdateScanSchedule($input: UpdateScanScheduleInput!) {
  updateScanSchedule(input: $input) {
    id
    action
    repositoryId
    gitEntityId
    branch
    dockerScanToolId
    frequency
    hourUtc
  }
}

updateUserRolesMutation

Arguments

NameTypeDescription
inputUpdateUserRolesInput!

Returns TenantUser!

Example
mutation UpdateUserRoles($input: UpdateUserRolesInput!) {
  updateUserRoles(input: $input) {
    id
    roles
    user {
      id
      email
      username
      name
    }
  }
}

upgradeToPayingMutation

Returns Boolean!

Example
mutation UpgradeToPaying {
  upgradeToPaying
}

usageQuery

Arguments

NameTypeDescription
startDateDateTime!
endDateDateTime!

Returns Usage!

Example
query Usage($startDate: DateTime!, $endDate: DateTime!) {
  usage(startDate: $startDate, endDate: $endDate) {
    accountTier
    usedGitScanTimeMinutes
    repositoryScanLimited
    usedNetworkScanTimeMinutes
    networkScanLimited
    parallelScans
    availableGitScanMinutes
    availableNetworkScanMinutes
  }
}

workspaceOverviewQuery

Arguments

NameTypeDescription
gitEntityIdID!

Returns WorkspaceOverview!

Example
query WorkspaceOverview($gitEntityId: ID!) {
  workspaceOverview(gitEntityId: $gitEntityId) {
    severityCounts {
      severity
      count
    }
    totalFindings
    totalRepositories
    scanned
    unscanned
  }
}

Also available as: MCP tool workspace_overview

Types

AgingBucket object
NameTypeDescription
bucketString!Age range in days, such as 8-30 or 91+.
countInt!
ChannelStatus enum
NameDescription
operational
degraded
unknown
error
ChannelType enum
NameDescription
email
slack
webhook
telegram
discord
CommitScan object
NameTypeDescription
idID!
scanResultIdID!
commitHashString!
createdAtDateTime
updatedAtDateTime
scanResultScanResult!
CommitScanListResult object
NameTypeDescription
totalInt!
items[CommitScan!]!
CorroboratedFinding object

One finding that more than one scanner reported. Carries no matched value on purpose: a corroborated finding is very often a leaked secret, and the dashboard is the most widely viewed screen in the product. The repository and file identify it, and the view behind the link masks what it shows.

NameTypeDescription
kindString!Either code or dependency.
repositoryIdID!
repositoryNameString!
labelStringThe file for a code finding, the library for a dependency finding.
severityString!
scanners[String!]!The scanners that agreed, by name.
toolCountInt!
findingKeyString!The identity the vulnerabilities explorer addresses this finding by, usable directly as its matchHash filter.
CreateGitEntityInput input
NameTypeDescription
nameString!
gitTypeGitType!
externalIdFloat
webUrlString
ignorePaths[String!]Gitignore-style glob patterns applied to every repo under this entity.
ownershipConsentBoolean!Attests that the caller's tenant owns this organisation/user, or is authorized to scan it. No default: the client must decide explicitly. Rejected unless true; the actor and statement version are added server-side, not taken from client input.
CreateGitTokenInput input
NameTypeDescription
nameString!
valueString!
flags[GitTokenFlag!]!
gitTokenTypeGitType!
expiresAtDateTime
CreateNetworkInput input
NameTypeDescription
nameString!
networkString!
networkTypeNetworkType!
ownershipConsentBoolean!
CreateNotificationScopeInput input
NameTypeDescription
channelIds[String!]!
channelTypeChannelType!
scopes[String!]!
isActiveBoolean!
headers[HttpHeaderInput!]
templates[NotificationTemplateInput!]
CreateRepositoryInput input
NameTypeDescription
gitEntityIdID!
repositoryNameString!
cloneUrlString
ignorePaths[String!]Gitignore-style glob patterns to exclude from scans.
CreateScanScheduleInput input
NameTypeDescription
actionScanScheduleActionDefaults to SCAN. SYNC requires gitEntityId.
repositoryIdIDSupply exactly one of repositoryId or gitEntityId.
gitEntityIdID
branchString
dockerScanToolIdID
frequencyScanScheduleFrequency!
hourUtcInt!
minuteUtcIntDefaults to 0 upstream, which is the minute every schedule fired at before this field existed.
dayOfWeekInt
isActiveBoolean
recipients[String!]Required for a REPORT, refused for anything else. The address shape is checked here because this is the trust boundary; vulnara-api forwards it and vulnara-notification-api refuses a malformed one at the far end.
CreateServiceAccountInput input
NameTypeDescription
nameString!
expiresAtDateTime!
CreateServiceAccountPayload object
NameTypeDescription
serviceAccountServiceAccount!
tokenString!
CreateTenantInput input
NameTypeDescription
nameString!
Currency enum
NameDescription
USD
EUR
BGN
DashboardAnalytics object
NameTypeDescription
daysInt!The window the deltas and activity are measured over.
generatedAtDateTime!
lastScanAtDateTime
averageSecurityScoreFloat!
previousAverageSecurityScoreFloat!The same score as it stood at the start of the period.
severityCounts[SeverityCount!]!
previousSeverityCounts[SeverityCount!]!
exposureExposure!
scanActivity[ScanActivityPoint!]!
scoreTrend[ScoreTrendPoint!]!
topRiskRepositories[RepositoryRisk!]!
remediationRemediationFunnel!
dependencyFixesDependencyFixes!
aging[AgingBucket!]!
oldestFindingDaysInt
oldestCriticalDaysInt
coverageScanCoverage!
scanHealthScanHealth!
staleWorkspaces[StaleWorkspace!]!
DependencyFixes object
NameTypeDescription
totalInt!
fixableInt!Dependency findings whose advisory names a fixed version.
DockerScanTool object

A scanner, named. The image, tag and arguments are deliberately not exposed: they identify our scanners and their private registry paths, and every screen in the product only ever needs to label a scan with the tool that produced it. Managed in vulnara-backoffice, not through this API.

NameTypeDescription
idID!
nameString!
DockerScanToolListResult object
NameTypeDescription
totalInt!
items[DockerScanTool!]!
Exposure object

Findings currently exposed, and how that moved over the period. Deduplicated by match hash within a repository and read from the latest scan per tool, so this is what is open now - not every row ever written.

NameTypeDescription
totalInt!
previousTotalInt!
newFindingsInt!
resolvedFindingsInt!
codeFindingsInt!
dependencyFindingsInt!
corroboratedFindingsInt!Findings more than one scanner reported - the least likely to be noise.
corroborated[CorroboratedFinding!]!The findings behind corroboratedFindings, worst first. They come from the same query as the count, so the two cannot disagree - which is why this is here rather than the client deep-linking into the explorer, whose finding list is a different population (every scan, code only, triaged included). Capped, while the count stays exact: a tenant over the cap reads as "some of many" rather than seeing a list that looks complete.
falsePositivesInt!Held back by a decision rather than by a fix. Reported beside the open total, never folded into it - a number that shrinks when somebody dismisses something is what this endpoint exists to avoid.
notAffectedInt!
hiddenButScoredInt!Real findings a decision keeps out of the working list - deferred, or will-not-fix. They still count against the score, so they are named here rather than being quietly absent from both numbers.
resolvedFindingsTriagedInt!Everything a decision took out of the score entirely.
FetchGitEntityTask object
NameTypeDescription
idID!
objectIdID!
statusTaskStatus!
stateFetchGitEntityTaskState!
createdAtInt!
gitEntityGitEntity!
FetchGitEntityTaskState object
NameTypeDescription
processedInt!
totalInt!
FetchRepositoriesInput input
NameTypeDescription
gitEntityIdID!
gitTokenIdID
Filter input
NameTypeDescription
fieldString!
minFloat
maxFloat
stringEqualsString
idEqualsID
FindingCorroboration object

One real-world issue and how many independent scanners found it. toolCount > 1 is the "confirmed by N tools" signal.

NameTypeDescription
idID!
matchHashString!
toolCountInt!
severitySeverityReconciled across the tools that reported it (highest severity wins).
FindingCorroborationListResult object
NameTypeDescription
totalInt!
items[FindingCorroboration!]!
FindingTriage object

A decision taken about a finding. Keyed on the finding's identity rather than its row, so it survives rescans and applies to every scanner that reported the same thing. The three axes are separate on purpose. state decides whether the finding still counts against the security score - only states asserting no live risk take it out. response and a defer priority clear it from the working list while leaving the score alone, because deciding not to act on something does not make it safe.

NameTypeDescription
idID!
repositoryIdID!
matchKeyString!
findingTypeString!
stateTriageState!
justificationTriageJustification
responseTriageResponse
priorityTriagePriority
reasonString!
createdByString
createdAtDateTime!
expiresAtDateTimeRequired whenever the decision hides a finding that is still exposed.
FindingTriageEvent object

One entry in a finding's decision history. Append-only.

NameTypeDescription
idID!
repositoryIdID!
matchKeyString!
actionString!set or reopen.
stateTriageState
justificationTriageJustification
responseTriageResponse
priorityTriagePriority
reasonString
expiresAtDateTime
actorString
createdAtDateTime!
GitEntity union

One of: Organization, GitUser

GitEntityListResult object
NameTypeDescription
totalInt!
items[GitEntity!]!
GitEntityType enum
NameDescription
organization
user
GitToken object
NameTypeDescription
idID!
nameString
valueString!
expiresAtDateTime
flags[GitTokenFlag!]!
statusGitTokenStatus!
scopes[String!]!
createdAtDateTime
updatedAtDateTime
gitTokenTypeGitType!
tenantString!
gitEntitiesGitEntityListResult!
GitTokenAssociationInput input
NameTypeDescription
gitEntityIdID!
gitTokenIdID!
GitTokenCheck object

Result of probing a git token against its provider so the UI can pre-fill the expiry and explain what's wrong when the token is rejected.

NameTypeDescription
validBoolean!Whether the provider accepted the token.
statusCodeIntHTTP status the provider returned (e.g. 401 for bad credentials), if any.
errorStringProvider error message/code (e.g. "Bad credentials"), if the check failed.
expiresAtDateTimeThe token's own expiry as reported by the provider, if it exposes one.
publicRepositoryCountIntPublic repositories the token can see for the given workspace name, or null when no name was supplied, the token is invalid, or the provider couldn't be reached.
privateRepositoryCountIntPrivate repositories the token can see for the given workspace name, or null when no name was supplied, the token is invalid, or the provider couldn't be reached.
GitTokenFlag enum
NameDescription
default
GitTokenListResult object
NameTypeDescription
totalInt!
items[GitToken!]!
GitTokenStatus enum
NameDescription
valid
invalid
unknown
error
GitType enum
NameDescription
github
gitlab
GitUser object
NameTypeDescription
idID!
nameString!
gitTypeGitType!
externalIdFloat
webUrlString
htmlUrlString
avatarUrlStringPresigned URL of the entity's avatar (re-hosted from the provider), null if none.
colorStringRepresentative, always-vivid colour (hex) derived from the avatar or seeded from the name.
averageSecurityScoreFloat!
lastImportDateDateTime
repositoryCountInt
typeGitEntityType!
createdAtDateTime!
updatedAtDateTime
ignorePaths[String!]
tags[Tag!]!
HttpHeader object
NameTypeDescription
nameString!
valueString!
HttpHeaderInput input
NameTypeDescription
nameString!
valueString!
Invitation object
NameTypeDescription
idID!
emailString!
tenantNameString!
InviteTeamMemberInput input
NameTypeDescription
emailString!
languageString
Invoice object
NameTypeDescription
idID!
invoiceNumberString
dateDateTime!
dueDateDateTime!
statusString!
totalFloat!
currencyCurrency!
InvoiceDownload object
NameTypeDescription
urlString!
filenameString!
tenantString!
contentTypeString!
InvoiceListResult object
NameTypeDescription
totalInt!
items[Invoice!]!
IssueStatus enum

Normalized issue state across providers (GitHub open/closed, GitLab opened/closed).

NameDescription
open
closed
List input
NameTypeDescription
limitInt
skipInt
filters[Filter!]
sortString
orderOrder
searchString
MyUser object
NameTypeDescription
idID!
emailString!
nameString!
usernameString!
tenants[Tenant!]!
preferencesUserPreferences!
Network object
NameTypeDescription
idID!
nameString!
networkString!
networkTypeNetworkType!
tenantString!
securityScoreFloat!
createdAtDateTime!
updatedAtDateTime
tags[Tag!]!
NetworkListResult object
NameTypeDescription
totalInt!
items[Network!]!
NetworkScanFinding object
NameTypeDescription
idID!
scanResultIdID!
hostString!
hostnameString!
hostnameTypeString
protocolString!
portInt!
serviceNameString!
stateString!
productString!
versionString!
extraInfoString!
reasonString!
confidenceInt!
cpeString!
tags[Tag!]!
createdAtDateTime!
updatedAtDateTime
networkScanResultNetworkScanResult!
NetworkScanFindingListResult object
NameTypeDescription
totalInt!
items[NetworkScanFinding!]!
NetworkScanResult object
NameTypeDescription
idID!
networkIdID!
statusScanStatus!
createdAtDateTime!
updatedAtDateTime
scanTimeInt
networkNetwork!
NetworkScanResultListResult object
NameTypeDescription
totalInt!
items[NetworkScanResult!]!
NetworkScanTask object
NameTypeDescription
idID!
objectIdID!
statusTaskStatus!
stateNetworkScanTaskState!
createdAtInt!
scanResultNetworkScanResult!
NetworkScanTaskState object
NameTypeDescription
totalHostsInt!
processedHostsInt!
currentHostString
NetworkType enum
NameDescription
public
private
vpn
internal
external
dmz
unknown
Notification object
NameTypeDescription
idID!
typeNotificationType!
eventTypeString!
dataJSON
readBoolean!
createdAtDateTime!
NotificationList object
NameTypeDescription
items[Notification!]!
totalInt!
NotificationScope object
NameTypeDescription
idID!
channelIds[String!]!
channelTypeChannelType!
scopes[String!]!
isActiveBoolean!
statusChannelStatus!
headers[HttpHeader!]Custom HTTP headers sent with webhook deliveries (webhook channel only).
templateStringDeprecated: superseded by templates.
templates[NotificationTemplate!]Per-event message templates (eventType '*' is the default for all events).
NotificationScopeListResult object
NameTypeDescription
totalInt!
items[NotificationScope!]!
NotificationTemplate object

A message template for one event type ('*' = every event).

NameTypeDescription
eventTypeString!
templateString!
NotificationTemplateInput input
NameTypeDescription
eventTypeString!
templateString!
NotificationType enum
NameDescription
SCAN_FINISHED
REPOSITORY_FETCH_FINISHED
NSFConsultation input
NameTypeDescription
findingIdID!
Order enum
NameDescription
ASC
DESC
Organization object
NameTypeDescription
idID!
nameString!
gitTypeGitType!
externalIdFloat
webUrlString
htmlUrlString
avatarUrlStringPresigned URL of the entity's avatar (re-hosted from the provider), null if none.
colorStringRepresentative, always-vivid colour (hex) derived from the avatar or seeded from the name.
averageSecurityScoreFloat!
lastImportDateDateTime
repositoryCountInt
typeGitEntityType!
createdAtDateTime!
updatedAtDateTime
ignorePaths[String!]
tags[Tag!]!
PaymentMethod object
NameTypeDescription
idID!
defaultBoolean!
lastFourString!
brandString!
expiryMonthInt!
expiryYearInt!
cardholderNameString!
expiredBoolean!
PaymentMethodListResult object
NameTypeDescription
totalInt!
items[PaymentMethod!]!
Plan object
NameTypeDescription
idID!
availableGitScanMinutesInt
availableNetworkScanMinutesInt
maxRepositoriesInt
maxNetworksInt
maxEmailsInt
pricePerGitScanMinuteFloat
pricePerNetworkScanMinuteFloat
currencyCurrency
PreferredDateTimeFormat enum
NameDescription
localized
iso
us
eu
PreferredRepositoriesView enum
NameDescription
board
table
PreferredTheme enum
NameDescription
Light
Dark
System
PromoGrant object

A promotion a tenant holds. The limits are the ones granted when the code was redeemed, not the ones the code names today: vulnara-api copies them at redemption so that editing a code cannot change a grant already made.

NameTypeDescription
idID!
codeString!
startsAtDateTime!
endsAtDateTime!
gitScanMinutesInt
networkScanMinutesInt
maxRepositoriesInt
maxNetworksInt
maxEmailsInt
PrStatus enum

Normalized remediation pull/merge request state.

NameDescription
open
merged
closed
PushSubscriptionInput input
NameTypeDescription
endpointString!
p256dhString!
authString!
RemediationFunnel object

Findings to opened issues to merged remediation PRs.

NameTypeDescription
findingsInt!
issuesOpenedInt!
issuesClosedInt!
prsOpenedInt!
prsMergedInt!
RemediationTemplate object
NameTypeDescription
codeIssueBodyString
dependencyIssueBodyString
pullRequestBodyString
RemediationTemplateInput input
NameTypeDescription
codeIssueBodyString
dependencyIssueBodyString
pullRequestBodyString
Repository object
NameTypeDescription
idID!
gitEntityIdID!
repositoryNameString!
privateBoolean
securityScoreFloat
programmingLanguage[String!]
repositorySizeFloatRepository size in bytes. Float, not Int, so large repos (>2GB) don't overflow GraphQL's 32-bit Int.
numberOfBranchesInt
cloneUrlString
createdAtDateTime!
updatedAtDateTime
isBlacklistedBoolean
enabledBoolean
isStandaloneBoolean
avatarUrlStringPresigned URL of the repo's own avatar (GitLab project image or GitHub custom social-preview image); null otherwise - fall back to gitEntity.avatarUrl.
colorStringVivid colour derived from the repo's avatar; null when it has no colourful image - fall back to a hash of the id.
ignorePaths[String!]
tags[Tag!]!
gitEntityGitEntity!
severityCounts[SeverityCount!]
latestScanRepositoryScanMost recent scan's status and time (null if never scanned).
scoreHistory[Float!]Recent security scores oldest→newest, for the list trend sparkline.
RepositoryDependencyScanFinding object
NameTypeDescription
idID!
commitScanIdID!
createdAtDateTime!
updatedAtDateTime
severitySeverity
vulnerabilityString
dependencyString
installedVersionString
fixedVersionString
purlStringPackage URL, e.g. pkg:npm/[email protected].
vulnerabilityAliases[String!]Other identifiers for the same advisory (GHSA, vendor ids).
matchHashStringCross-tool identity: two scanners reporting the same vulnerable package share this value, even when one leads with a CVE and the other a GHSA.
issueUrlStringURL of the GitHub/GitLab issue opened for this dependency, if any.
issueStatusIssueStatus
prUrlStringURL of the remediation PR opened for this dependency, if any.
prStatusPrStatus
commitScanCommitScan!
tags[Tag!]!
RepositoryDependencyScanFindingGroup object

One vulnerable library, aggregating all its advisories (CVEs). Queried with a scanResultId filter it covers that scan; without one it covers the tenant, one row per repository the library is vulnerable in.

NameTypeDescription
idID!
dependencyString!
repositoryIdIDWhich repository the library is vulnerable in. Null within a single scan result, where the caller already named the repository.
severitySeverity
installedVersionString
occurrencesInt!
issueUrlString
issueStatusIssueStatus
prUrlString
prStatusPrStatus
RepositoryDependencyScanFindingGroupListResult object
NameTypeDescription
totalInt!
items[RepositoryDependencyScanFindingGroup!]!
RepositoryDependencyScanFindingListResult object
NameTypeDescription
totalInt!
items[RepositoryDependencyScanFinding!]!
RepositoryListResult object
NameTypeDescription
totalInt!
items[Repository!]!
RepositoryRisk object
NameTypeDescription
idID!
nameString!
securityScoreFloat!
criticalCountInt!
highCountInt!
findingCountInt!
RepositoryScan object
NameTypeDescription
statusScanStatus
scannedAtDateTime
RepositoryScanTask object
NameTypeDescription
idID!
objectIdID!
statusTaskStatus!
stateRepositoryScanTaskState!
createdAtInt!
scanResultScanResult!
RepositoryScanTaskState object
NameTypeDescription
totalCommitsInt!
scheduledInt!
scannedInt!
failedInt!
parsedInt!
RevolutOrder object
NameTypeDescription
idID!
tokenString!
RSFConsultation input
NameTypeDescription
findingIdID!
ScanActivityPoint object
NameTypeDescription
dateString!
countInt!Every scan started that day, failed ones included.
succeededInt!
failedInt!Failed and cancelled scans - activity that produced no coverage.
ScanCoverage object
NameTypeDescription
totalRepositoriesInt!
scannedInt!
unscannedInt!Repositories never scanned - unknown risk, and excluded from the score.
ScanFinding object
NameTypeDescription
idID!
commitScanIdID!
createdAtDateTime!
updatedAtDateTime
lineInt
fileString
severitySeverity
confidenceString
matchStringMasked (first/last few characters only) - see revealScanFindingMatch for the raw value.
fingerprintString
matchHashStringCross-tool identity: two different scanners that found the same secret share this value. Null when the secret could not be resolved (older scans). Distinct from fingerprint, which is per-tool.
matchedByToolCountIntHow many distinct scanners reported this finding. Greater than 1 means two tools independently agreed, which is the strongest cheap signal that it is not a false positive. Null when the finding has no cross-tool identity.
issueUrlStringURL of the GitHub/GitLab issue opened for this finding, if any.
issueStatusIssueStatus
prUrlStringURL of the remediation PR opened for this finding, if any.
prStatusPrStatus
commitScanCommitScan!
tags[Tag!]!
ScanFindingGroup object
NameTypeDescription
idID!
fingerprintString!
matchHashStringCross-tool identity of this group.
matchedByToolCountIntHow many distinct scanners reported this finding. A fingerprint group is one tool's view; this says whether anyone else found the same thing.
fileString
severitySeverity
confidenceString
matchStringMasked (first/last few characters only) - see revealScanFindingMatch for the raw value.
occurrencesInt!
issueUrlStringURL of the GitHub/GitLab issue opened for this finding, if any.
issueStatusIssueStatus
prUrlStringURL of the remediation PR opened for this finding, if any.
prStatusPrStatus
ScanFindingGroupListResult object
NameTypeDescription
totalInt!
items[ScanFindingGroup!]!
ScanFindingListResult object
NameTypeDescription
totalInt!
items[ScanFinding!]!
ScanFindingMatchGroup object

One real secret, collapsed across every commit and tool that saw it. The explorer listed raw findings, so a token committed once appeared per commit per tool - 26 commits scanned by 2 tools meant 52 rows for one secret.

NameTypeDescription
idID!
matchHashString!
fileString
lineInt
severitySeverity
confidenceStringHighest confidence any contributing tool assigned.
matchStringMasked (first/last few characters only) - see revealScanFindingMatch for the raw value.
occurrencesInt!How many raw findings collapsed into this group.
toolCountInt!How many distinct scanners agreed. Greater than 1 is the corroboration signal.
scanners[String!]!Which scanners reported it. toolCount answers "is this corroborated"; this answers "who says so", which is what you need to judge a finding you disagree with.
repositoryIdID
triageKeyStringThe identity a triage decision is filed under - the match hash, or the fingerprint when there is none. Distinct from matchHash above, which falls back to the finding id: filing a decision under that key stored it somewhere nothing ever looks up.
triageStateTriageStateThe decision in force, carried on the row so the explorer can show and filter it without a call per finding. Null when nothing has been decided.
triageResponseTriageResponse
triagePriorityTriagePriority
ScanFindingMatchGroupListResult object
NameTypeDescription
totalInt!
items[ScanFindingMatchGroup!]!
ScanHealth object
NameTypeDescription
totalScansInt!
succeededScansInt!
failedScansInt!
runningScansInt!
invalidTokensInt!Tokens the provider rejected; every scan under their workspaces is blocked.
expiringTokensInt!
ScanResult object
NameTypeDescription
idID!
repositoryIdID!
scanTypeString!
scannerString!
dockerScanToolIdID!
statusScanStatus!
createdAtDateTime!
updatedAtDateTime
scanTimeInt
securityScoreFloat
createIssueBoolean!
autoRemediateBoolean!
branches[String!]
repositoryRepository!
dockerScanToolDockerScanTool!
severityCounts[SeverityCount!]!
ScanResultListResult object
NameTypeDescription
totalInt!
items[ScanResult!]!
ScanSchedule object

A standing instruction to run on a fixed cadence. Deliberately a frequency plus an hour rather than a cron expression: the whole space of valid values is enumerable, so it validates here and renders as two selects. Exactly one of repositoryId or gitEntityId is set. A workspace SCAN fans out over the repositories the workspace holds when it fires, so one imported after the schedule was made is included and one disabled since is not.

NameTypeDescription
idID!
actionScanScheduleAction!
repositoryIdIDSet when this schedule targets one repository. Null for a workspace schedule.
gitEntityIdIDSet when this schedule targets a whole workspace. Null for a repository schedule.
branchStringBranch to scan. Null means the default branch. Never set on a workspace schedule - a branch is a repository-level idea and a workspace's repositories do not share one - nor on a SYNC.
dockerScanToolIdIDScanner to run. Null means the tenant's default scanner.
frequencyScanScheduleFrequency!
hourUtcInt!Hour of day in UTC, 0-23. Clients render it in the viewer's own zone.
minuteUtcInt!Minute of the hour in UTC, 0-59. Zero for a schedule created before minutes existed.
dayOfWeekIntDay of week, 0-6, Monday is 0. Only read when frequency is WEEKLY.
isActiveBoolean!
nextRunAtDateTimeWhen the next run is due, in UTC. Computed by vulnara-api, never written by a client.
lastRunAtDateTimeWhen the schedule last dispatched a scan, in UTC. Read only.
recipients[String!]!Where a REPORT is mailed. Empty for a SCAN or a SYNC. Not restricted to tenant members, matching the destinations alert rules already accept.
createdByString
createdAtDateTime
updatedAtDateTime
repositoryRepositoryNull for a workspace schedule.
gitEntityGitEntityNull for a repository schedule.
dockerScanToolDockerScanTool
ScanScheduleAction enum

What a due schedule does. SCAN queues a scan; SYNC re-imports a workspace's repositories, the same job the workspace sync button runs. A SYNC only ever targets a workspace: there is nothing to re-import for a single repository.

NameDescription
SCAN
SYNC
REPORT
ScanScheduleFrequency enum
NameDescription
DAILY
WEEKLY
ScanScheduleListResult object
NameTypeDescription
totalInt!
items[ScanSchedule!]!
ScanStatus enum
NameDescription
PENDING
SUCCESS
FAILED
CANCELLED
ScoreTrendPoint object
NameTypeDescription
dateString!
scoreFloat!
ServiceAccount object
NameTypeDescription
idID!
nameString!
isActiveBoolean!
expiresAtDateTime
createdByUser!
SetFindingTriageInput input
NameTypeDescription
repositoryIdID!
matchKeyString!The finding's matchHash, or its per-tool fallback when it has none.
findingTypeString!
stateTriageState!
justificationTriageJustification
responseTriageResponse
priorityTriagePriority
reasonString!
expiresAtDateTime
SetGitEntityIgnorePathsInput input
NameTypeDescription
gitEntityIdID!
ignorePaths[String!]!
SetRepositoryEnabledInput input
NameTypeDescription
repositoryIds[ID!]!
enabledBoolean!
SetRepositoryIgnorePathsInput input
NameTypeDescription
repositoryIdID!
ignorePaths[String!]!
SetServiceAccountActiveInput input
NameTypeDescription
idID!
isActiveBoolean!
Severity enum
NameDescription
info
low
medium
high
critical
SeverityCount object
NameTypeDescription
severityString!
countInt!
StaleWorkspace object
NameTypeDescription
idID!
nameString!
lastImportDateDateTime
StartNetworkScanInput input
NameTypeDescription
networkIdID!
StartRepositoryScanInput input
NameTypeDescription
repositoryIdID!
dockerScanToolIdID!
branchString
gitTokenIdID
createIssueBoolean
autoRemediateBoolean
Tag object
NameTypeDescription
keyString!
valueString!
Task union

One of: RepositoryScanTask, NetworkScanTask, FetchGitEntityTask

TaskEvent object
NameTypeDescription
typeTaskEventType!
taskIdID!
taskTask
TaskEventType enum
NameDescription
STATE_UPDATED
TASK_CANCELLED
TaskStatus enum
NameDescription
QUEUED
STARTED
CANCELLED
PROCESSING
COMPLETED
FAILED
Tenant object
NameTypeDescription
idID!
isPayingBoolean!
members[TenantUser!]!
TenantStatistics object
NameTypeDescription
tenantString!
totalUsersInt!
totalGitEntitiesInt!
totalRepositoriesInt!
totalNetworksInt!
TenantUser object
NameTypeDescription
idID!
roles[TenantUserRole!]!
userUser!
TenantUserRole enum
NameDescription
VIEWER
EDITOR
ADMIN
TransferGitEntityInput input
NameTypeDescription
gitEntityIdID!
newTenantString!
TransferNetworkInput input
NameTypeDescription
networkIdID!
newTenantString!
TriageJustification enum

CycloneDX VEX justification. Required when the state is not_affected.

NameDescription
code_not_present
code_not_reachable
requires_configuration
requires_dependency
requires_environment
protected_by_compiler
protected_at_runtime
protected_at_perimeter
protected_by_mitigating_control
TriagePriority enum

SSVC decision outcome. Only defer hides the finding from the working list.

NameDescription
defer
scheduled
out_of_cycle
immediate
TriageResponse enum

CycloneDX VEX analysis.response - what will be done about it.

NameDescription
can_not_fix
rollback
update
will_not_fix
workaround_available
TriageState enum

CycloneDX VEX analysis.state - what is true about the finding.

NameDescription
resolved
resolved_with_pedigree
exploitable
in_triage
false_positive
not_affected
UpdateGitEntityInput input
NameTypeDescription
gitEntityIdID!
nameString
gitTypeGitType
ignorePaths[String!]
UpdateGitTokenInput input
NameTypeDescription
idID!
nameString
valueString
UpdateNotificationScopeInput input
NameTypeDescription
idID!
channelIds[String!]
channelTypeChannelType
scopes[String!]
isActiveBoolean
headers[HttpHeaderInput!]
templates[NotificationTemplateInput!]
UpdateScanScheduleInput input
NameTypeDescription
idID!
branchString
dockerScanToolIdID
frequencyScanScheduleFrequency
hourUtcInt
minuteUtcInt
dayOfWeekInt
isActiveBoolean
recipients[String!]
UpdateUserPreferencesInput input
NameTypeDescription
themePreferredTheme
dateTimeFormatPreferredDateTimeFormat
repositoriesViewPreferredRepositoriesView
UpdateUserRolesInput input
NameTypeDescription
userIdID!
roles[TenantUserRole!]!
Usage object
NameTypeDescription
accountTierString!
usedGitScanTimeMinutesInt!
repositoryScanLimitedBoolean!
usedNetworkScanTimeMinutesInt!
networkScanLimitedBoolean!
parallelScansInt!
availableGitScanMinutesInt!
availableNetworkScanMinutesInt!
maxParallelScansInt!
usedRepositoriesInt!
maxRepositoriesInt!
repositoryLimitReachedBoolean!
usedNetworksInt!
maxNetworksInt!
networkLimitReachedBoolean!
usedEmailsInt!
maxEmailsInt!
emailLimitReachedBoolean!
User object
NameTypeDescription
idID!
emailStringNull unless the caller may read it: their own address, or any address in a tenant they hold EDITOR or ADMIN in. Nullable rather than guarded by @tenantRole because the directive throws, and a thrown error on a non-null field takes the whole myUser query down for every VIEWER instead of hiding one field.
usernameString!
nameString!
UserPreferences object
NameTypeDescription
themePreferredTheme
dateTimeFormatPreferredDateTimeFormat
repositoriesViewPreferredRepositoriesView
WorkspaceOverview object

Security aggregate for one workspace, counted on the server with the same latest-scan + deduplicated policy as the dashboard.

NameTypeDescription
severityCounts[SeverityCount!]!
totalFindingsInt!
totalRepositoriesInt!
scannedInt!
unscannedInt!

Manage Your Cookie Preferences

We use cookies to enhance your experience. You can accept all cookies, decline non-essential cookies, or manage preferences below. Privacy Policy