How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Snyk Findings API

The Findings API from Snyk — 1 operation(s) for findings.

Snyk Findings API is one of 51 APIs that Snyk publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Findings. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

This API exposes 1 operation across 1 path, and defines 42 schemas. It is described by OpenAPI 3.2.0, at version REST.

Requests are made against a single base URL, https://api.snyk.io/rest.

1 operations 1 paths 42 schemas 1 GET

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
REST
Base URL
https://api.snyk.io/rest
Authentication
API Key, HTTP Bearer
Resource Areas
1

Authentication & Security 2

Snyk Findings API declares 2 security schemes for authenticating requests. An API key is passed in the header as Authorization (APIToken). It accepts HTTP bearer tokens (BearerAuth). By default, every request must be authenticated.

  • APIToken — API key value must be prefixed with \"Token \".

Paths & Operations 1

Across 1 path, the API surfaces 1 operation — 1 GET. Each is listed below with its method, path, parameters, and response codes.

Findings 1
GET
/orgs/{org_id}/tests/{test_id}/findings
List findings for a test. (Early Access)
listFindings 8 params → 200400

Schemas 42

The contract defines 42 schemas that model the data the API accepts and returns. The most detailed are FindingAttributes (13 properties), io.snyk.api.common.Error (8 properties), Suppression (7 properties), io.snyk.api.common.PaginatedLinks (5 properties). Each schema is shown below with its type and property counts.

DiffSuggestion
object
A suggestion in unified diff format representing the code changes to fix the vulnerability.
3 properties 1 required
FindingLocation
Location within an Subject's contents where the finding was discovered.
SuppressionStatus
string
Status of a suppression on a finding.
io.snyk.api.common.RelatedLink
object
1 property
UpgradePath
object
Upgrade path model all known dependency paths that will change when applying an upgrade action.
2 properties 2 required
FindingType
string
Type of Finding which was discovered.
io.snyk.api.common.ErrorDocument
object
2 properties 2 required
io.snyk.api.common.LinkObject
object
2 properties 1 required
ManagedPolicyRef
object
Reference to a managed policy.
1 property 1 required
FileRegion
object
FileRegion models a location where vulnerable code is found.
5 properties 2 required
Evidence
Supporting evidence for (rather than representative of) the finding in other security domains and systems, lacking a well-known identifier. More detailed attri…
ReachabilityType
string
Reachability enum for reachability signal.
ExecutionFlowEvidence
object
Indicate a program flow of execution as additional evidence for the finding.
2 properties 2 required
FindingAttributes
object
FindingAttributes represent the attributes of a Finding resource.
13 properties 10 required
DependencyPathEvidence
object
Dependency path to a software component within an SBOM dependency graph. Finding types: SCA
2 properties 2 required
Package
object
Dependency models a package dependency.
2 properties 2 required
io.snyk.api.common.JsonApi
object
1 property 1 required
PolicyRef
Reference to a single policy.
OtherLocation
object
Finding locations which this API version is not capable of expressing. This location may be available in a newer version of this API.
1 property 1 required
ReachabilityEvidence
object
Indicate the reachability signals as additional evidence for the finding.
3 properties 2 required
Diff
object
Fix suggestions in the unified diff format that introduce code changes to remediate the vulnerability.
2 properties 2 required
UpgradePackageAdvice
object
Upgrade a package from one version to another.
3 properties 3 required
io.snyk.api.common.PaginatedLinks
object
5 properties
io.snyk.api.common.ErrorLink
object
A link that leads to further details about this particular occurrance of the problem.
1 property
io.snyk.api.common.Meta
object
Free-form object that may contain non-standard information.
io.snyk.api.common.LinkString
string
String256
string
FindingData
object
FindingData represents a Finding resource object.
5 properties 3 required
FixAction
Different fix formats in which the fix action is represented. We distinguish between advice and diff formats. Advice - Fix advice in a display only / informati…
PinPackageAdvice
object
Pin a package at a specific version. Pinning is a capability not supported by all ecosystems, which causes a transitive dependency to be pinned at a specific v…
3 properties 3 required
Severity
string
Indicate the severity of a finding discovered by a Test.
PackageLocation
object
Package dependency version. Finding type: SCA
2 properties 2 required
Suppression
object
Details about a finding's suppression in test results. Suppressed findings do not contribute to the test outcome, but they are still provided in the results.
7 properties 1 required
Uuid
string
FixAppliedOutcome
string
Indicates the outcome of a fix in terms of resolving the finding at hand
ReachablePath
object
ReachablePath represents the paths to a vulnerable function.
3 properties 2 required
PolicyModification
object
Prior attribute values and the reason they were modified.
4 properties 2 required
FixAttributes
object
FixAttributes is the main payload modelling a fix
2 properties 1 required
io.snyk.api.common.Error
object
8 properties 2 required
io.snyk.api.common.LinkProperty
Rating
object
Rating represents qualitative metrics on a finding.
1 property 1 required
OtherEvidence
object
Evidence which this API version is not capable of expressing. More information may be available in a newer version of this API.
1 property 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

snyk-findings-api-openapi.yml Raw ↑

Other APIs Snyk publishes across the network.

Snyk REST API - Apps (OAuth)
Snyk V1 API (Legacy)
Snyk OAuth2 API - Authorize
Snyk OAuth2 API - Token
Snyk MCP Server (Snyk Studio)
Snyk AccessRequests API
Snyk AiBom API
Snyk Apps API
Snyk Asset API
Snyk Audit Logs API
Snyk BrokerConnections API
Snyk BrokerContexts API
Where this information came from

This is an independent, third-party profile of Snyk Findings API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.