How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Synack webapps API

Web application assets.

Synack webapps API is one of 22 APIs that Synack publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Web App. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 5 operations across 4 paths, and defines 25 schemas. It is described by OpenAPI 3.2.0, at version 2.1.020.

Requests are made against 2 base URLs: https://client.synack.com/api/asset, https://client.synack.us/api/asset.

5 operations 4 paths 25 schemas 4 GET1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
2.1.020
Base URL
https://api.synack.com
Authentication
OAuth 2.0
Resource Areas
1

Authentication & Security 1

Synack webapps API declares 1 security scheme for authenticating requests. It supports OAuth 2.0 (OAuth2) using the implicit flow, exposing 11 scopes.

Paths & Operations 5

Across 4 paths, the API surfaces 5 operations — 4 GET, 1 POST. Each is listed below with its method, path, parameters, and response codes.

webapps 5

Web application assets.

GET
/v2/assets/{assetUid}/scripts
Gets all scripts owned by the mobile or web application asset. Returns 409 status if the asset is not of one of these types.
getAssetScripts 5 params → 200401403404409500503
POST
/v2/assets/{assetUid}/scripts
Adds a script to a mobile or web application asset. Returns 409 status if the asset is of any other type..
postAssetScript 1 param body → 201401403404409412500503
GET
/v2/assets/{assetUid}/credentials
Gets all credentials owned by web application asset. Returns 409 status if the asset is not of this type.
getAssetCredentials 5 params → 200401403404409500503
GET
/v2/listing-webapps/{listingUid}
Gets a list of active webapps with all their HTTPing settings, scope rules, session handling scripts, SRT credentials and credential user UIDs for the given listing. Used to generate input for Tarant…
getWebApps 1 param → 200400401403500503
GET
/v2/webapps/{assetUid}
Gets a webapp with all assigned HTTPing settings, scope rules, session handling scripts, SRT credentials and credential user UIDs. Used to generate input for TarantulaBurp and TarantulaBurpValidator…
getWebApp 1 param → 200400401403500503

Schemas 25

The contract defines 25 schemas that model the data the API accepts and returns. The most detailed are HTTPingSettings (10 properties), ProblemDetails (9 properties), FailedValidation (3 properties), IndexedFailedValidations (2 properties). Each schema is shown below with its type and property counts.

AssetScript
Updatable
CheckerStatus
string
Status reported by automated checkers.
FailedValidation
object
3 properties 1 required
HTTPingSettings_Headers
object
1 property
WebAppScopeRule
Auxiliary type for WebApp struct. It is a simplified object describing scope rule for a web application.
Base64Data
string
Base64 encoding of data.
WebApp
Simplified object describing web asset, used by TarantulaBurp and TarantulaBurpValidator plugins. Contains HTTPing settings, scope rules, session handling scri…
ArrayOfAssetCredentials
array
CredentialSharing
string
Determines the limits on users that may be assigned; "one" permits only one user to be assigned, "many" places no limit, and "all" prevents any users to explic…
ListingUID
string
Unique identifier for an listing.
IndexedFailedValidations
object
2 properties
AssetCredential
Credential used by an application in context of a user role.
ScriptRole
string
ArrayOfWebApps
array
List of simplified web assets, used by listing scanner workflows for TarantulaBurp and TarantulaBurpValidator plugins.
ProblemDetails
object
See [RFC 7807: Problem Details for HTTP APIs](https://tools.ietf.org/html/rfc7807)
9 properties
OperationUserUID
string
Automatically set by the server to the requesting user whenever the resource is updated. May be a user account or a service account if the action is performed…
ArrayOfAssetScripts
array
UID
string
Unique Identifier.
WebAppCredential
Auxiliary type for WebApp struct. It is a simplified object describing SRT credential for a session handling script of web application.
Creatable
object
2 properties 2 required
WebAppScript
Auxiliary type for WebApp struct. It is a simplified object describing session handling script for a web application.
UserUID
string
Unique identifier for a user.
AssetUID
string
Unique identifier for an asset.
HTTPingSettings
object
HTTPingSettings represents custom settings for webapp reachability checks. All fields are optional.
10 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

synack-webapps-api-openapi.yml Raw ↑

Other APIs Synack publishes across the network.

Synack Assessment Groups API
Synack Assessment Lifecycle API
Synack Assessments API
Synack asset-relationships API
Synack assetproviders API
Synack Assets API
Synack Comments API
Synack credentials API
Synack external-relationships API
Synack health API
Synack Hosts API
Synack Missions API
Where this information came from

This is an independent, third-party profile of Synack webapps API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.