How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Synack Suspected Vulnerabilities API

Operations related to suspected vulnerabilities

Synack Suspected Vulnerabilities API is one of 22 APIs that Synack publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Suspected Vulnerabilities. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 5 operations across 4 paths, and defines 23 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 6 base URLs: https://api.synack.com, https://api.synack.us, https://client.synack.com/api/streaming, https://client.synack.us/api/streaming, https://client.synack.com/api/vulnerability, https://client.synack.us/api/vulnerability.

5 operations 4 paths 23 schemas 3 GET1 PATCH1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://api.synack.com
Authentication
HTTP Bearer, HTTP Basic, API Key, HTTP Bearer, OAuth 2.0
Resource Areas
1

Authentication & Security 5

Synack Suspected Vulnerabilities API declares 5 security schemes for authenticating requests. It accepts HTTP bearer tokens (JWT) (BearerAuth). It accepts HTTP basic authentication (BasicAuth). An API key is passed in the header as X-Auth (ApiKeyAuth). It accepts HTTP bearer tokens (JWT) (bearerAuth). It supports OAuth 2.0 (OAuth2) using the implicit flow, exposing 11 scopes.

Paths & Operations 5

Across 4 paths, the API surfaces 5 operations — 3 GET, 1 PATCH, 1 POST. Each is listed below with its method, path, parameters, and response codes.

Suspected Vulnerabilities 5

Operations related to suspected vulnerabilities

PATCH
/v1/suspected_vulnerabilities/{id}
Update a suspected vulnerability
updateSuspectedVulnerability 1 param body → 200400404
GET
/v1/{org_uid}/assets/{asset_uid}/suspected_vulns
Returns list of suspected vulnerabilities on a given organization and asset uid
getAssetSuspectedVulnerabilities 10 params → 200400401500
GET
/v1/organizations/{organizationUid}/suspected-vulnerabilities
Retrieve suspected vulnerabilities for an organization
getSuspectedVulnerabilities 17 params → 200400401403422500
POST
/v1/organizations/{organizationUid}/suspected-vulnerabilities
Add suspected vulnerabilities for an organization
postSuspectedVulnerabilities 1 param body → 201400401403422500
GET
/v1/organizations/{organizationUid}/suspected-vulnerabilities/{id}
Retrieve a specific suspected vulnerability
getSuspectedVulnerability 2 params → 200400401403404422500default

Schemas 23

The contract defines 23 schemas that model the data the API accepts and returns. The most detailed are SuspectedVulnerability_2 (35 properties), SuspectedVulnerability (20 properties), NewSuspectedVulnerability (20 properties), SuspectedVulnerabilitiesSummaries_SummaryStatus (11 properties). Each schema is shown below with its type and property counts.

SuspectedVulnerability
object
20 properties
Relationship
object
2 properties
Data
object
6 properties
Links
object
2 properties
Error
object
5 properties
Document
object
5 properties
ResourceType
string
SuspectedVulnerabilitiesSummaries_Counts
object
Numerical counts of vulnerabilities grouped by various attributes
2 properties
Error_2
object
Standard error response format following RFC 7807 Problem Details specification
5 properties 2 required
Metadata
object
Additional metadata accompanying API responses
2 properties
SuspectedVulnerabilitiesSummaries_SummarySeverity
object
Summary severity of the vulnerabilities
6 properties
ExternalJobTriageAgentThought
object
Thought data for a vulnerability triage, including analysis and reporting
8 properties
StringMap
object
Pagination
object
Pagination metadata for navigating through large result sets
9 properties 4 required
SuspectedVulnerabilityTriage
object
Triage assessment data for a vulnerability, including analysis and reporting
2 properties
SuspectedVulnerabilityWithTriages
Extended suspected vulnerability schema that includes embedded triage assessments. Used specifically for single vulnerability responses where triage data is in…
SuspectedVulnerability_2
object
35 properties
SuspectedVulnerabilitiesSummaries_SummaryStatus
object
Summary status of the vulnerabilities
11 properties
ExternalJobTriageAgentBlock
object
Block data for a vulnerability triage, including analysis and reporting
2 properties
ExternalJobTriageAgentToolExecution
object
Tool execution data for a vulnerability triage, including analysis and reporting
4 properties
SuspectedVulnerabilitiesCreateRequest
array
List of objects, describing the properties of suspected vulnerabilities to create
NewSuspectedVulnerability
object
Object, describing properties of a new suspected vulnerability to create
20 properties 6 required
SuspectedVulnerabilitiesSummaries
object
Statistical summary information about the vulnerabilities in the result set
1 property

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

synack-suspected-vulnerabilities-api-openapi.yml Raw ↑

Other APIs Synack publishes across the network.

Synack Assessment Groups API
Synack Assessment Lifecycle API
Synack Assessments API
Synack asset-relationships API
Synack assetproviders API
Synack Assets API
Synack Comments API
Synack credentials API
Synack external-relationships API
Synack health API
Synack Hosts API
Synack Missions API
Where this information came from

This is an independent, third-party profile of Synack Suspected Vulnerabilities API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.