Skip to content

List findings for a specific campaign

Request

Returns findings for the campaign, newest first by execution order. Filter with type (failed, passed, or errors); use lastN to keep only the N newest findings.

Security
bearer-key
Path
orgUuidstring, (uuid)required
applicationUuidstring, (uuid)required
projectUuidstring, (uuid)required
targetIdstring, (uuid)required
campaignIdstring, (uuid)required
Query
prettyboolean

When true, indent the JSON body (2 spaces) and render multiline string fields (e.g. YAML config) with literal newlines for human readability. Default off (compact JSON). Intended for interactive use; omit for clients that parse the body as strict JSON.

Default:false
cursorinteger, >= 0
Default:0
limitinteger, [ 1 .. 200 ]
Default:50
typestring
Default:"failed"
Enum:"failed""passed""errors"
lastNinteger, [ 1 .. 10000 ]

Return only the N newest findings (after the other filters). totalItems is capped at N and cursor / limit page within those N findings. Must be sent once.

Headers
X-Correlation-IDstring, (uuid)

Optional caller-supplied correlation id. Must be a UUID when present. When omitted or blank, the API generates a UUID. A non-UUID value returns 400 CORRELATION.INVALID. If a write fails because a UUID is already in use, the API returns 409 UUID.DUPLICATE. The value used (caller or generated) is echoed as supportToken and in the X-Correlation-ID response header.

curl -i -X GET \
  'https://baseUrl/api/v3.0/redteaming/orgs/{orgUuid}/applications/{applicationUuid}/projects/{projectUuid}/targets/{targetId}/campaigns/{campaignId}/findings?pretty=false&cursor=0&limit=50&type=failed&lastN=1' \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'X-Correlation-ID: 497f6eca-6276-4993-bfeb-53cbbbba6f08'

Responses

Finding collection. probeId and strategyId are human-readable probe and strategy names. gradingResult includes pass, score (finding risk score), and reason. Failed findings expose the explanation only under gradingResult.reason; top-level error appears only when type=errors. _links.suppress is present when the finding is not suppressed; _links.unsuppress when it is suppressed.

Headers
X-Correlation-IDstring, (uuid)

Correlation id used for this request (caller-supplied UUID, or a UUID generated when the request omitted the header). Same value as supportToken.

Bodyapplication/json
supportTokenstring, (uuid)(SupportToken)required

Correlation id used for this request. Same value as the X-Correlation-ID response header.

additionalDataobject(AdditionalData)required
responseArray of objects(Finding)required
Response
{ "supportToken": "5bac741e-3f1c-4cd4-ad0d-a1492df0a5cc", "additionalData": { "totalItems": "string", "cursor": 0, "next": "string" }, "response": [ { … } ] }