Snyk Findings API is one of 51 APIs that Snyk publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Findings. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.
This API exposes
1 operation
across 1 path,
and defines 42 schemas.
It is described by OpenAPI 3.2.0, at version REST.
Requests are made against a single base URL, https://api.snyk.io/rest.
1 operations1 paths42 schemas1 GET
Metadata
The identity and technical contract details declared by the specification.
Specification
OpenAPI 3.2.0
API Version
REST
Base URL
https://api.snyk.io/rest
Authentication
API Key, HTTP Bearer
Resource Areas
1
Authentication & Security 2
Snyk Findings API declares
2 security schemes
for authenticating requests.
An API key is passed in the header as Authorization (APIToken).
It accepts HTTP bearer tokens (BearerAuth).
By default, every request must be authenticated.
APIToken — API key value must be prefixed with \"Token \".
Paths & Operations 1
Across 1 path, the API surfaces 1 operation — 1 GET. Each is listed below with its method, path, parameters, and response codes.
Findings 1
GET
/orgs/{org_id}/tests/{test_id}/findings
List findings for a test. (Early Access)
listFindings8 params→ 200400
Schemas 42
The contract defines 42 schemas that model the data the API accepts and returns. The most detailed are FindingAttributes (13 properties), io.snyk.api.common.Error (8 properties), Suppression (7 properties), io.snyk.api.common.PaginatedLinks (5 properties). Each schema is shown below with its type and property counts.
DiffSuggestion
object
A suggestion in unified diff format representing the code changes to fix the vulnerability.
3 properties1 required
FindingLocation
Location within an Subject's contents where the finding was discovered.
SuppressionStatus
string
Status of a suppression on a finding.
io.snyk.api.common.RelatedLink
object
1 property
UpgradePath
object
Upgrade path model all known dependency paths that will change when applying an upgrade action.
2 properties2 required
FindingType
string
Type of Finding which was discovered.
io.snyk.api.common.ErrorDocument
object
2 properties2 required
io.snyk.api.common.LinkObject
object
2 properties1 required
ManagedPolicyRef
object
Reference to a managed policy.
1 property1 required
FileRegion
object
FileRegion models a location where vulnerable code is found.
5 properties2 required
Evidence
Supporting evidence for (rather than representative of) the finding in other security domains and systems, lacking a well-known identifier. More detailed attri…
ReachabilityType
string
Reachability enum for reachability signal.
ExecutionFlowEvidence
object
Indicate a program flow of execution as additional evidence for the finding.
2 properties2 required
FindingAttributes
object
FindingAttributes represent the attributes of a Finding resource.
13 properties10 required
DependencyPathEvidence
object
Dependency path to a software component within an SBOM dependency graph. Finding types: SCA
2 properties2 required
Package
object
Dependency models a package dependency.
2 properties2 required
io.snyk.api.common.JsonApi
object
1 property1 required
PolicyRef
Reference to a single policy.
OtherLocation
object
Finding locations which this API version is not capable of expressing. This location may be available in a newer version of this API.
1 property1 required
ReachabilityEvidence
object
Indicate the reachability signals as additional evidence for the finding.
3 properties2 required
Diff
object
Fix suggestions in the unified diff format that introduce code changes to remediate the vulnerability.
2 properties2 required
UpgradePackageAdvice
object
Upgrade a package from one version to another.
3 properties3 required
io.snyk.api.common.PaginatedLinks
object
5 properties
io.snyk.api.common.ErrorLink
object
A link that leads to further details about this particular occurrance of the problem.
1 property
io.snyk.api.common.Meta
object
Free-form object that may contain non-standard information.
io.snyk.api.common.LinkString
string
String256
string
FindingData
object
FindingData represents a Finding resource object.
5 properties3 required
FixAction
Different fix formats in which the fix action is represented. We distinguish between advice and diff formats. Advice - Fix advice in a display only / informati…
PinPackageAdvice
object
Pin a package at a specific version. Pinning is a capability not supported by all ecosystems, which causes a transitive dependency to be pinned at a specific v…
3 properties3 required
Severity
string
Indicate the severity of a finding discovered by a Test.
PackageLocation
object
Package dependency version. Finding type: SCA
2 properties2 required
Suppression
object
Details about a finding's suppression in test results. Suppressed findings do not contribute to the test outcome, but they are still provided in the results.
7 properties1 required
Uuid
string
FixAppliedOutcome
string
Indicates the outcome of a fix in terms of resolving the finding at hand
ReachablePath
object
ReachablePath represents the paths to a vulnerable function.
3 properties2 required
PolicyModification
object
Prior attribute values and the reason they were modified.
4 properties2 required
FixAttributes
object
FixAttributes is the main payload modelling a fix
2 properties1 required
io.snyk.api.common.Error
object
8 properties2 required
io.snyk.api.common.LinkProperty
Rating
object
Rating represents qualitative metrics on a finding.
1 property1 required
OtherEvidence
object
Evidence which this API version is not capable of expressing. More information may be available in a newer version of this API.
1 property1 required
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of Snyk Findings API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.