Returns findings across campaigns of the target, newest first. Campaigns are ordered by creation time descending; findings within a campaign by execution order descending. Filter with type (failed, passed, or errors).
Campaign selection: by default only the latest finished campaign of each campaign group (an original campaign and its re-scans) is used, so a re-scan replaces the campaign it re-ran; running, errored or canceled re-scans are skipped in favor of the previous finished one. allCampaigns=true uses every campaign with results. lastNCampaigns keeps only the N newest campaigns of that selection. campaigns replaces the selection with an explicit list of campaign ids (cannot be combined with lastNCampaigns). lastN then caps the listing to the N newest findings. The next link carries every filter.
Comma-separated campaign ids to list findings for, used exactly as given (allCampaigns does not apply). Sent once as a single value; each id must be a UUID, with no empty items, whitespace or duplicates (case-insensitive), at most 100 ids. Any id that does not belong to the target returns 404. Cannot be combined with lastNCampaigns. Campaigns that have no results yet contribute no findings.
Optional caller-supplied correlation id. Must be a UUID when present. When omitted or blank, the API generates a UUID. A non-UUID value returns 400 CORRELATION.INVALID. If a write fails because a UUID is already in use, the API returns 409 UUID.DUPLICATE. The value used (caller or generated) is echoed as supportToken and in the X-Correlation-ID response header.
- Generated server urlhttps://baseUrl/api/v3.0/redteaming/orgs/{orgUuid}/applications/{applicationUuid}/projects/{projectUuid}/targets/{targetId}/findings
curl -i -X GET \
'https://baseUrl/api/v3.0/redteaming/orgs/{orgUuid}/applications/{applicationUuid}/projects/{projectUuid}/targets/{targetId}/findings?pretty=false&cursor=0&limit=50&type=failed&campaigns=497f6eca-6276-4993-bfeb-53cbbbba6f08&lastN=1&lastNCampaigns=1&allCampaigns=false' \
-H 'Authorization: Bearer <YOUR_JWT_HERE>' \
-H 'X-Correlation-ID: 497f6eca-6276-4993-bfeb-53cbbbba6f08'Finding collection. probeId and strategyId are human-readable probe and strategy names. gradingResult includes pass, score (finding risk score), and reason. Failed findings expose the explanation only under gradingResult.reason; top-level error appears only when type=errors. Suppressed findings count as passed. _links.suppress is present when the finding is not suppressed; _links.unsuppress when it is suppressed.
{ "supportToken": "5bac741e-3f1c-4cd4-ad0d-a1492df0a5cc", "additionalData": { "totalItems": "string", "cursor": 0, "next": "string" }, "response": [ { … } ] }