How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Snyk Cloud API

The Cloud API from Snyk — 6 operation(s) for cloud.

Snyk Cloud API is one of 51 APIs that Snyk publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Cloud. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

This API exposes 9 operations across 6 paths, and defines 30 schemas. It is described by OpenAPI 3.2.0, at version REST.

Requests are made against a single base URL, https://api.snyk.io/rest.

9 operations 6 paths 30 schemas 1 DELETE4 GET1 PATCH3 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
REST
Base URL
https://api.snyk.io/rest
Authentication
API Key, HTTP Bearer
Resource Areas
1

Authentication & Security 2

Snyk Cloud API declares 2 security schemes for authenticating requests. An API key is passed in the header as Authorization (APIToken). It accepts HTTP bearer tokens (BearerAuth). By default, every request must be authenticated.

  • APIToken — API key value must be prefixed with \"Token \".

Paths & Operations 9

Across 6 paths, the API surfaces 9 operations — 1 DELETE, 4 GET, 1 PATCH, 3 POST. Each is listed below with its method, path, parameters, and response codes.

Cloud 9
GET
/orgs/{org_id}/cloud/environments
List Environments (Early Access)
listEnvironments 14 params → 200400401403404409500
POST
/orgs/{org_id}/cloud/environments
Create New Environment (Early Access)
createEnvironment 2 params body → 201400401403404409500
DELETE
/orgs/{org_id}/cloud/environments/{environment_id}
Delete Environment (Early Access)
deleteEnvironment 3 params → 204400401403404409500
PATCH
/orgs/{org_id}/cloud/environments/{environment_id}
Update Environment (Early Access)
updateEnvironment 3 params body → 200400401403404409500
POST
/orgs/{org_id}/cloud/permissions
Generate Cloud Provider Permissions (Early Access)
getPermissions 2 params body → 201400401403404409500
GET
/orgs/{org_id}/cloud/resources
List Resources (Early Access)
listResources 15 params → 200400401403404409500
GET
/orgs/{org_id}/cloud/scans
List Scans (Early Access)
listScan 5 params → 200400401403404409500
POST
/orgs/{org_id}/cloud/scans
Create Scan (Early Access)
createScan 2 params body → 201400401403404409500
GET
/orgs/{org_id}/cloud/scans/{scan_id}
Get scan (Early Access)
getScan 3 params → 200400401403404409500

Schemas 30

The contract defines 30 schemas that model the data the API accepts and returns. The most detailed are ResourceAttributes (20 properties), ScanAttributes (12 properties), EnvironmentAttributes (8 properties), PaginatedLinks (5 properties). Each schema is shown below with its type and property counts.

QueryVersion
string
Requested API version
ScanRelationships
object
Scan relationships
AzureOptions__0
object
Options for creating an Azure environment
3 properties 2 required
AzureOptions
object
Options for generating an Azure environment permissions script
2 properties 2 required
ErrorDocument
object
2 properties 2 required
ScanCreateAttributes
object
Scan create attributes
ResourceRelationships
object
Resource relationships
GoogleOptions
object
Options for creating a Google environment
3 properties 2 required
ActualVersion
string
Resolved API version
CreatePermissionsAttributes
object
3 properties 2 required
LinkProperty
EnvironmentKind
string
Environment kind: aws
PermissionsAttributes
object
2 properties 2 required
EnvironmentType
string
ResourceKind
string
Kind of resource: cloud
EnvironmentRelationships
object
Environment relationships
ScanAttributes
object
Scan attributes
12 properties 5 required
ScanType
string
EnvironmentAttributes
object
Environment attributes
8 properties 3 required
EnvironmentName
string
Environment name
PaginatedLinks
object
5 properties
ScanCreateRelationships
object
Scan create relationships
1 property
ResourceAttributes
object
20 properties 8 required
PermissionType
string
JsonApi
object
1 property 1 required
EnvironmentCreateAttributes
object
3 properties 2 required
EnvironmentOptions
AwsOptions
object
Options for creating an AWS environment
1 property 1 required
PlatformType
string
EnvironmentUpdateAttributes
object
Environment update attributes. Only the AWS role ARN can be updated; new ARN must have the same account ID as the old ARN.
2 properties 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

snyk-cloud-api-openapi.yml Raw ↑

Other APIs Snyk publishes across the network.

Snyk REST API - Apps (OAuth)
Snyk V1 API (Legacy)
Snyk OAuth2 API - Authorize
Snyk OAuth2 API - Token
Snyk MCP Server (Snyk Studio)
Snyk AccessRequests API
Snyk AiBom API
Snyk Apps API
Snyk Asset API
Snyk Audit Logs API
Snyk BrokerConnections API
Snyk BrokerContexts API
Where this information came from

This is an independent, third-party profile of Snyk Cloud API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.