How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Fortify Applications API

Manage applications and their configurations

Fortify Applications API is one of 42 APIs that Fortify publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Application. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, authentication docs, and a getting-started guide.

This API exposes 14 operations across 10 paths, and defines 23 schemas. It is described by OpenAPI 3.1.0, at version v3.

Requests are made against 3 base URLs: https://api.ams.fortify.com, https://api.emea.fortify.com, https://api.apac.fortify.com.

14 operations 10 paths 23 schemas 1 DELETE10 GET2 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
v3
Base URL
https://api.ams.fortify.com
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Fortify Applications API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (JWT) (bearerAuth). By default, every request must be authenticated.

  • bearerAuth — OAuth2 Bearer token obtained from POST /oauth/token using either clientcredentials or password grant type.

Paths & Operations 14

Across 10 paths, the API surfaces 14 operations — 1 DELETE, 10 GET, 2 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Applications 14

Manage applications and their configurations

GET
/api/v3/applications
Fortify List applications
listApplications 7 params → 200401403429
POST
/api/v3/applications
Fortify Create application
createApplication body → 201400401403429
GET
/api/v3/applications/{applicationId}
Fortify Get application
getApplication 1 param → 200401403404429
PUT
/api/v3/applications/{applicationId}
Fortify Update application
updateApplication 1 param body → 200400401403404429
DELETE
/api/v3/applications/{applicationId}
Fortify Delete application
deleteApplication 1 param → 200401403404429
GET
/api/v3/applications/{applicationId}/releases
Fortify List application releases
listApplicationReleases 8 params → 200401403404429
GET
/api/v3/applications/{applicationId}/scans
Fortify List application scans
listApplicationScans 6 params → 200401403404429
GET
/api/v3/applications/{applicationId}/issue-count-by-severity
Fortify Get issue count by severity
getApplicationIssueCountBySeverity 1 param → 200401403404429
GET
/api/v3/applications/{applicationId}/users
Fortify List application users
listApplicationUsers 1 param → 200401403404429
GET
/api/v3/applications/{applicationId}/microservices
Fortify List application microservices
listApplicationMicroservices 2 params → 200401403404429
POST
/api/v3/applications/{applicationId}/microservices
Fortify Create application microservice
createApplicationMicroservice 1 param body → 201400401403404429
GET
/api/v3/applications/{applicationId}/vulnerabilities/{vulnerabilityId}
Fortify Get application vulnerability
getApplicationVulnerability 11 params → 200401403404429
GET
/api/v3/applications/owners
Fortify List application owners
listApplicationOwners → 200401403429
GET
/api/v3/fortify-on-demand-connect-networks
List Fortify Connect networks
listFortifyConnectNetworks → 200401403429

Schemas 23

The contract defines 23 schemas that model the data the API accepts and returns. The most detailed are Release (17 properties), Vulnerability (15 properties), Scan (12 properties), PostApplicationRequest (9 properties). Each schema is shown below with its type and property counts.

Release
object
Represents a release within an application
17 properties
PostMicroserviceRequest
object
Request body for creating a microservice
1 property 1 required
Scan
object
Represents a security scan
12 properties
ApplicationUserListResponse
object
List of users associated with an application
2 properties
ScanListResponse
object
Paginated list of scans
2 properties
User
object
Represents a user in the system
5 properties
ReleaseListResponse
object
Paginated list of releases
2 properties
Application
object
Represents an application in Fortify on Demand
8 properties
PostApplicationRequest
object
Request body for creating an application
9 properties 5 required
PostApplicationResponse
object
Response after creating an application
3 properties
ApplicationIssueCountListResponse
object
Issue counts grouped by severity for an application
1 property
Microservice
object
Represents a microservice within an application
3 properties
PostMicroserviceResponse
object
Response after creating a microservice
2 properties
Vulnerability
object
Represents a vulnerability finding
15 properties
DeleteResponse
object
Generic delete response
1 property
PutApplicationRequest
object
Request body for updating an application
5 properties
ErrorResponse
object
Error response
1 property
VulnerabilityListResponse
object
Paginated list of vulnerabilities
2 properties
ApplicationListResponse
object
Paginated list of applications
2 properties
PutApplicationResponse
object
Response after updating an application
1 property
MicroserviceListResponse
object
List of microservices
2 properties
ApplicationAttribute
object
An attribute value assigned to an application
3 properties
FortifyConnectNetworkListResponse
object
List of Fortify Connect networks
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

fortify-applications-api-openapi.yml Raw ↑

Other APIs Fortify publishes across the network.

Fortify Alert Definitions API
Fortify API Keys API
Fortify Artifacts API
Fortify Attributes API
Fortify Audit Templates API
Fortify Auth Entities API
Fortify Authentication API
Fortify CI/CD API
Fortify Cloud Pools API
Fortify Custom Tags API
Fortify DAST Automated Scans API
Fortify Dynamic Scans API
Where this information came from

This is an independent, third-party profile of Fortify Applications API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.