Skip to main content

REST endpoints

A handful of plain HTTP endpoints sit next to GraphQL: the browser sign-in flow, health probes and PDF report downloads. Everything else is GraphQL.

Base URL
https://vulnara-gw.rso.dev

Sign-in

GET/auth/oauth2

Start browser sign-in

Redirects the browser to the Vulnara sign-in page. After sign-in the browser comes back to the callback below.

Responses

NameDescription
302Redirect to the sign-in page.
Request
curl "https://vulnara-gw.rso.dev/auth/oauth2"

GET/auth/oauth2/callback

Finish browser sign-in

The sign-in page redirects here. The gateway exchanges the code for tokens and hands them to the web app. You do not call this yourself.

Parameters

NameTypeDescription
codeRequiredquery
stateRequiredquery

Responses

NameDescription
302Redirect to the web app, signed in, or to the sign-in failure page.
Request
curl "https://vulnara-gw.rso.dev/auth/oauth2/callback"

POST/auth/oauth2/refresh

Refresh an access token

Swap a refresh token for a new access token and refresh token.

Responses

NameDescription
200New tokens.
400The refresh token is missing, expired or revoked. Sign in again.
Request
curl -X POST "https://vulnara-gw.rso.dev/auth/oauth2/refresh" \
  -H "Content-Type: application/json" \
  -d '{"refreshToken":"<refresh token>"}'

Health

GET/health/live

Liveness

Answers while the gateway process is running.

Responses

NameDescription
200Running.
Request
curl "https://vulnara-gw.rso.dev/health/live"

GET/health/ready

Readiness

Answers 200 when the gateway can serve requests.

Responses

NameDescription
200Ready.
503Not ready yet.
Request
curl "https://vulnara-gw.rso.dev/health/ready"

Reports

GET/reports/summary

Security summary report

A PDF summary of the security posture of the whole workspace.

Parameters

NameTypeDescription
X-TenantheaderWorkspace id. Optional when you belong to one workspace only.

Responses

NameDescription
200The report as a PDF download.
401Missing or invalid bearer token.
403You are not a member of the requested workspace.
404The item does not exist in this workspace.
502The report could not be generated. Try again.
Request
curl "https://vulnara-gw.rso.dev/reports/summary" \
  -H "Authorization: Bearer $VULNARA_TOKEN" \
  -H "X-Tenant: $VULNARA_TENANT" \
  -o report.pdf

GET/reports/scan/{id}

Scan report

A PDF report for one scan result.

Parameters

NameTypeDescription
idRequiredpathId of the scan result.
X-TenantheaderWorkspace id. Optional when you belong to one workspace only.

Responses

NameDescription
200The report as a PDF download.
401Missing or invalid bearer token.
403You are not a member of the requested workspace.
404The item does not exist in this workspace.
502The report could not be generated. Try again.
Request
curl "https://vulnara-gw.rso.dev/reports/scan/<id>" \
  -H "Authorization: Bearer $VULNARA_TOKEN" \
  -H "X-Tenant: $VULNARA_TENANT" \
  -o report.pdf

GET/reports/workspace/{id}

Git workspace report

A PDF report for one GitHub or GitLab organisation or user.

Parameters

NameTypeDescription
idRequiredpathId of the git workspace.
X-TenantheaderWorkspace id. Optional when you belong to one workspace only.

Responses

NameDescription
200The report as a PDF download.
401Missing or invalid bearer token.
403You are not a member of the requested workspace.
404The item does not exist in this workspace.
502The report could not be generated. Try again.
Request
curl "https://vulnara-gw.rso.dev/reports/workspace/<id>" \
  -H "Authorization: Bearer $VULNARA_TOKEN" \
  -H "X-Tenant: $VULNARA_TENANT" \
  -o report.pdf

GET/reports/repository/{id}

Repository report

A PDF report for one repository.

Parameters

NameTypeDescription
idRequiredpathId of the repository.
X-TenantheaderWorkspace id. Optional when you belong to one workspace only.

Responses

NameDescription
200The report as a PDF download.
401Missing or invalid bearer token.
403You are not a member of the requested workspace.
404The item does not exist in this workspace.
502The report could not be generated. Try again.
Request
curl "https://vulnara-gw.rso.dev/reports/repository/<id>" \
  -H "Authorization: Bearer $VULNARA_TOKEN" \
  -H "X-Tenant: $VULNARA_TENANT" \
  -o report.pdf

Manage Your Cookie Preferences

We use cookies to enhance your experience. You can accept all cookies, decline non-essential cookies, or manage preferences below. Privacy Policy