How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Qwiet Ai findings API

The results of a scan (which can include vulnerabilities, secrets, or insights).[![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-156075f8-c7cf-4e2c-95fa-0823a3313658?action=collection%2Ffork&collection-url=entityId%3D9829310-156075f8-c7cf-4e2c-95fa-0823a3313658%26entityType%3Dcollection%26workspaceId%3Da63f69cc-5c31-4f2b-8d28-b647f83b9e97)

Qwiet Ai findings API is one of 27 APIs that Qwiet Ai publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Findings. The published artifact set on APIs.io includes an OpenAPI specification and authentication docs.

This API exposes 12 operations across 12 paths, and defines 22 schemas. It is described by OpenAPI 3.2.0, at version 4.0.0.

Requests are made against a single base URL, https://app.shiftleft.io/api/v4.

12 operations 12 paths 22 schemas 8 GET4 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
4.0.0
Base URL
https://app.shiftleft.io/api/v4
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Qwiet Ai findings API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (BearerToken).

  • BearerToken — Use of the Qwiet API requires an access token, which is available via the Qwiet Dashboard (either under [Account Settings](https://app.shiftleft.io/user/profil…

Paths & Operations 12

Across 12 paths, the API surfaces 12 operations — 8 GET, 4 PUT. Each is listed below with its method, path, parameters, and response codes.

findings 12

The results of a scan (which can include vulnerabilities, secrets, or insights). [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/982…

GET
/orgs/{orgID}/apps/{appID}/findings
List app findings
ListAppFindings 21 params → 200default
GET
/orgs/{orgID}/compounds/named/{compoundName}/findingsdeprecated
List compound findings
ListCompoundFindingsDEPRECATED 21 params → 200default
GET
/orgs/{orgID}/compounds/byname/{compoundName}/findings
List compound findings
ListCompoundFindings 23 params → 200default
GET
/orgs/{orgID}/apps/{appID}/findings/{findingID}
Read app finding detail
ReadAppFinding 3 params → 200default
PUT
/orgs/{orgID}/apps/{appID}/findings/{findingID}/status
Set finding status
SetAppFindingStatus 3 params body → 200default
PUT
/orgs/{orgID}/apps/{appID}/findings/{findingID}/assignment
Set finding assignee
SetAppFindingAssignee 3 params body → 200default
PUT
/orgs/{orgID}/apps/{appID}/findings_status
Set multiple findings status
SetAppMultipleFindingsStatus 2 params body → 200default
PUT
/orgs/{orgID}/apps/{appID}/findings_assignment
Set multiple findings assignee
SetAppMultipleFindingsAssignee 2 params body → 200default
GET
/orgs/{orgID}/compounds/named/{compoundName}/sca/packages
Read the SCA packages of a compound scan
ReadCompoundSCAPackages 14 params → 200default
GET
/orgs/{orgID}/apps/{appID}/sca/packages
Read the count of multiple tags of an app.
ReadAppSCAPackages 10 params → 200default
GET
/orgs/{orgID}/findings
List org findings
ListOrgFindings 15 params → 200default
GET
/orgs/{orgID}/findings/summary
Read org findings summary
ReadOrgFindingsSummary 4 params → 200default

Schemas 22

The contract defines 22 schemas that model the data the API accepts and returns. The most detailed are SCAPackage (17 properties), Scan (16 properties), Finding (14 properties), FindingsSummary (8 properties). Each schema is shown below with its type and property counts.

TagWithNumber
object
2 properties 2 required
Status
string
Scan
object
16 properties 4 required
MultipleFindingsAssigneeUpdate
object
2 properties
ScanPlatform
string
The analysis platform identifier.
SuccessResponse
object
1 property 1 required
OSSScan
object
3 properties 1 required
TagWithString
object
2 properties 2 required
Severity
string
The severity of a finding
Assignment
string
Finding
object
14 properties 4 required
ScanLanguage
string
The analysis language identifier.
Error
object
4 properties 3 required
FindingAssigneeUpdate
object
1 property
SCAPackage
object
Information about an SCA package
17 properties 13 required
MultipleFindingsStatusUpdate
object
2 properties
FindingsSummary
object
8 properties 1 required
FindingStatusUpdate
object
2 properties
NextPage
string
URL for the next page of results
TagCount
Diff
string
Tag

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

qwiet-ai-findings-api-openapi.yml Raw ↑

Other APIs Qwiet Ai publishes across the network.

Qwiet Ai alerting API
Qwiet Ai analyze API
Qwiet Ai app_groups API
Qwiet Ai app_labels API
Qwiet Ai apps API
Qwiet Ai autofix API
Qwiet Ai azureboard API
Qwiet Ai branches API
Qwiet Ai comments API
Qwiet Ai compounds API
Qwiet Ai org_backup API
Qwiet Ai orgs API
Where this information came from

This is an independent, third-party profile of Qwiet Ai findings API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.