Snyk Inventory Assets API is one of 51 APIs that Snyk publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Inventory Assets. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.
This API exposes
36 operations
across 30 paths,
and defines 53 schemas.
It is described by OpenAPI 3.2.0, at version REST.
Requests are made against a single base URL, https://api.snyk.io/rest.
36 operations30 paths53 schemas27 GET6 PATCH3 POST
Metadata
The identity and technical contract details declared by the specification.
Specification
OpenAPI 3.2.0
API Version
REST
Base URL
https://api.snyk.io/rest
Authentication
API Key, HTTP Bearer
Resource Areas
1
Authentication & Security 2
Snyk Inventory Assets API declares
2 security schemes
for authenticating requests.
An API key is passed in the header as Authorization (APIToken).
It accepts HTTP bearer tokens (BearerAuth).
By default, every request must be authenticated.
APIToken — API key value must be prefixed with \"Token \".
Paths & Operations 36
Across 30 paths, the API surfaces 36 operations — 27 GET, 6 PATCH, 3 POST. Each is listed below with its method, path, parameters, and response codes.
Inventory Assets 36
GET
/groups/{group_id}/inventory/assets
List or search all assets (synchronous) - Group scope (Early Access)
listAssetsGroup9 params→ 200400401403500
PATCH
/groups/{group_id}/inventory/assets
Bulk update asset attributes - Group scope (Early Access)
The contract defines 53 schemas that model the data the API accepts and returns. The most detailed are ProjectRelationshipAttributes (14 properties), AssetBaseAttributes (12 properties), ImageConfig (10 properties), GroupValueMeta (8 properties). Each schema is shown below with its type and property counts.
LabelsReplace
array
Full replacement of all labels on the asset. All existing labels will be removed and replaced with the provided labels.
QueryVersion
string
Requested API version
GroupValueMeta
object
Computed aggregations across all assets within this group value. Fields are only present when explicitly requested via the metafields query parameter. If metaf…
8 properties
CreateSearchRequestBody
object
1 property
GroupValuesResponse
object
2 properties2 required
ScanEngine
object
Scan engine information associated with an asset
5 properties4 required
ImageConfig
object
Runtime configuration for the container (OCI image config). Contains entrypoint, environment, exposed ports, volumes, labels, etc.
10 properties
TargetRelationshipData
object
Full target resource with attributes
3 properties2 required
ClassResponse
object
Asset classification in response
3 properties2 required
Architecture
string
CPU architecture for container images (Go GOARCH conventions)
ProjectRelationshipData
object
Full project resource with attributes
3 properties2 required
IssueCounts
object
Issue counts by severity
4 properties4 required
ProjectRelationshipAttributes
object
Attributes of the project resource
14 properties
GroupValueData
object
4 properties3 required
BaseImageRemediation
object
Base image upgrade recommendation data from container scanning
6 properties2 required
RsqlFilterString
string
RSQL filter expression for filtering results. Supported operators: - == (equal), != (not equal) - or =gt= (greater than) - = or =ge= (greater than or equal) -…
ErrorDocument
object
2 properties2 required
FilterValueAttributes
object
2 properties
GroupFieldData
object
4 properties2 required
TargetRelationshipAttributes
object
Attributes of the target resource
5 properties
ContainerImageAttributesResponse
GroupValueIssuesAggregation
object
Aggregated issue counts from discovery sources across all assets in this group. Counts are summed from all project-type discovery sources.
5 properties
History
object
A single entry in the container image build history
5 properties
ProjectRelationshipListResponse
object
Response containing linked projects with full attributes
3 properties3 required
GroupValueAttributes
object
1 property1 required
FilterFieldAttributes
object
3 properties3 required
RelationshipLinks
Links for relationship endpoint responses (combines relationship + pagination links)
AssetBaseAttributes
object
Asset-level fields shared across all asset types.
12 properties
ActualVersion
string
Resolved API version
OperatingSystem
string
Operating system for container images (Go GOOS conventions)
ImageInfo
object
Container image with vulnerability summary
5 properties4 required
TargetRelationshipListResponse
object
Response containing linked targets with full attributes
3 properties3 required
PolymorphicAssetData
object
JSON:API data for any asset type (polymorphic)
5 properties2 required
TagsUpdate
object
Updates the asset's tags by adding or removing key-value pairs. Both add and remove can be specified in the same request. If a tag key appears in both add and…
2 properties
GroupFieldAttributes
object
2 properties2 required
FilterValuesResponse
object
2 properties2 required
JsonApiLinks
object
Links for relationship objects within a resource
2 properties
FilterFieldsResponse
object
2 properties2 required
AssetBulkPatchRequestBody
object
1 property1 required
AssetPatchAttributes
object
Attributes that can be updated via PATCH. At least one attribute must be provided. Labels and tags support add/remove operations for atomic modifications.
3 properties
AssetPatchData
object
3 properties3 required
ProposedBaseImages
object
Categorized base image upgrade recommendations
3 properties
AssetPatchRequestBody
object
1 property1 required
AssetListResponse
object
3 properties
FilterValueData
object
3 properties2 required
PaginationLinks
object
Cursor-based pagination links
4 properties
JsonApiVersion
object
1 property1 required
FilterFieldData
object
4 properties2 required
RootFs
object
Root filesystem information with ordered layer diff IDs. Each diffid is a SHA256 digest of the uncompressed layer content.
2 properties2 required
DistributionDigest
object
Distribution digest information for a container image
2 properties
TagsReplace
object
Full replacement of all tags on the asset. All existing tags will be removed and replaced with the provided tags.
GroupFieldsResponse
object
2 properties2 required
LabelsUpdate
object
Updates the asset's labels by adding or removing label values. At least one of 'add' or 'remove' must be provided.
2 properties
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of Snyk Inventory Assets API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.