Skip to content

API Overview

The Sable Integration API lets external systems create and manage projects, sessions, findings, and documents. Contract: OpenAPI 3.1.0, API version 1.0.0, all endpoints under /api/v1.

Warning

The Integration API is currently in beta.

Beta access is limited to Team and Enterprise subscribers.

Prerequisites

  1. A Vulnetic account with available balance
  2. A Team or Enterprise subscription with beta API access
  3. An API key. See Create an API key
  4. An integration client with the scopes you need
  5. Use base URL https://app.vulnetic.ai/api/v1

What the API covers

Resource Purpose
GET /api/v1/me Identity and scopes
Projects Organize engagements
Sessions Create and track pentests / retests
Findings Read, update, and transition findings
Documents Notes and report PDFs

Common use cases

  • Create projects and sessions from your own systems when a new asset or engagement needs tracking
  • Poll sessions and events into dashboards or approval workflows
  • Sync findings into Jira, Linear, ServiceNow, Slack, or internal vuln tools
  • Run remediation and retest flows (IN_RETEST → REMEDIATED)
  • Pull rendered PDFs into client portals or GRC systems
  • Build internal dashboards without requiring every stakeholder to log into Sable

Read in this order

  1. Quickstart: shortest path to a tracked session
  2. Authentication
  3. Environments
  4. Pagination and Filters
  5. Errors
  6. Resource pages: Projects, Sessions, Findings, Documents

Core workflow

  1. Verify identity with GET /api/v1/me
  2. Create or select a project
  3. Create a pentest or retest session
  4. Poll session state and events
  5. Review and manage findings
  6. Create or update documents

Key endpoints

Identity

  • GET /api/v1/me: account, API client, delegated user, roles, and scopes

Projects

  • GET /api/v1/projects
  • POST /api/v1/projects
  • GET /api/v1/projects/{project_id}
  • PATCH /api/v1/projects/{project_id}

Sessions

  • GET /api/v1/sessions
  • POST /api/v1/sessions
  • GET /api/v1/sessions/{session_id}
  • PATCH /api/v1/sessions/{session_id}
  • GET /api/v1/sessions/{session_id}/events
  • PATCH /api/v1/sessions/{session_id}/status
  • PATCH /api/v1/sessions/{session_id}/project

Findings

  • GET /api/v1/findings/{finding_id}
  • PATCH /api/v1/findings/{finding_id}
  • GET /api/v1/sessions/{session_id}/findings
  • GET /api/v1/findings/{finding_id}/history
  • POST /api/v1/findings/{finding_id}/transition

Documents

  • GET /api/v1/documents
  • POST /api/v1/documents
  • GET /api/v1/documents/{document_id}
  • PATCH /api/v1/documents/{document_id}
  • GET /api/v1/documents/{document_id}/view-pdf

Important enums

Enum Values
Session status active, active_auto, complete, queued, failed, halted
Finding status OPEN, FALSE_POSITIVE, IN_RETEST, REMEDIATED, ACCEPTED_RISK
Document type note, report
Session type pentest, retest

Beta notes

Warning

The Integration API is still evolving during beta. Confirm environment, authentication, and response expectations against the reference pages before rolling an integration into production.

Handle auth, permission, not-found, validation, and server errors defensively even when examples currently focus on the most common success and validation flows.

Next

Start with the shortest working path: API Quickstart