API Overview¶
The Sable Integration API lets external systems create and manage projects, sessions, findings, and documents. Contract: OpenAPI 3.1.0, API version 1.0.0, all endpoints under /api/v1.
Warning
The Integration API is currently in beta.
Beta access is limited to Team and Enterprise subscribers.
Prerequisites¶
- A Vulnetic account with available balance
- A Team or Enterprise subscription with beta API access
- An API key. See Create an API key
- An integration client with the scopes you need
- Use base URL
https://app.vulnetic.ai/api/v1
What the API covers¶
| Resource | Purpose |
|---|---|
GET /api/v1/me |
Identity and scopes |
| Projects | Organize engagements |
| Sessions | Create and track pentests / retests |
| Findings | Read, update, and transition findings |
| Documents | Notes and report PDFs |
Common use cases¶
- Create projects and sessions from your own systems when a new asset or engagement needs tracking
- Poll sessions and events into dashboards or approval workflows
- Sync findings into Jira, Linear, ServiceNow, Slack, or internal vuln tools
- Run remediation and retest flows (
IN_RETEST→REMEDIATED) - Pull rendered PDFs into client portals or GRC systems
- Build internal dashboards without requiring every stakeholder to log into Sable
Read in this order¶
- Quickstart: shortest path to a tracked session
- Authentication
- Environments
- Pagination and Filters
- Errors
- Resource pages: Projects, Sessions, Findings, Documents
Core workflow¶
- Verify identity with
GET /api/v1/me - Create or select a project
- Create a pentest or retest session
- Poll session state and events
- Review and manage findings
- Create or update documents
Key endpoints¶
Identity¶
GET /api/v1/me: account, API client, delegated user, roles, and scopes
Projects¶
GET /api/v1/projectsPOST /api/v1/projectsGET /api/v1/projects/{project_id}PATCH /api/v1/projects/{project_id}
Sessions¶
GET /api/v1/sessionsPOST /api/v1/sessionsGET /api/v1/sessions/{session_id}PATCH /api/v1/sessions/{session_id}GET /api/v1/sessions/{session_id}/eventsPATCH /api/v1/sessions/{session_id}/statusPATCH /api/v1/sessions/{session_id}/project
Findings¶
GET /api/v1/findings/{finding_id}PATCH /api/v1/findings/{finding_id}GET /api/v1/sessions/{session_id}/findingsGET /api/v1/findings/{finding_id}/historyPOST /api/v1/findings/{finding_id}/transition
Documents¶
GET /api/v1/documentsPOST /api/v1/documentsGET /api/v1/documents/{document_id}PATCH /api/v1/documents/{document_id}GET /api/v1/documents/{document_id}/view-pdf
Important enums¶
| Enum | Values |
|---|---|
| Session status | active, active_auto, complete, queued, failed, halted |
| Finding status | OPEN, FALSE_POSITIVE, IN_RETEST, REMEDIATED, ACCEPTED_RISK |
| Document type | note, report |
| Session type | pentest, retest |
Beta notes¶
Warning
The Integration API is still evolving during beta. Confirm environment, authentication, and response expectations against the reference pages before rolling an integration into production.
Handle auth, permission, not-found, validation, and server errors defensively even when examples currently focus on the most common success and validation flows.
Next¶
Start with the shortest working path: API Quickstart