Skip to content

Download a remediations report as PDF or CSV

Request

Downloads the remediation report for the target's selected campaigns as PDF or CSV. Uses the same campaign ids and filters (severity, category, sort) as GET remediations. Campaign selection and the 20-id sorted cap match GET remediations (lastNCampaigns 1–20, default 20). Errors return the JSON error envelope, not a report file.

Security
bearer-key
Path
orgUuidstring, (uuid)required
applicationUuidstring, (uuid)required
projectUuidstring, (uuid)required
targetIdstring, (uuid)required
Query
prettyboolean

When true, indent the JSON body (2 spaces) and render multiline string fields (e.g. YAML config) with literal newlines for human readability. Default off (compact JSON). Intended for interactive use; omit for clients that parse the body as strict JSON.

Default:false
formatstringrequired
Enum:"pdf""csv"
campaignsArray of strings, (uuid), [ 1 .. 20 ] items

Comma-separated campaign ids to aggregate remediations for (at most 20 UUIDs). Sent once as a single value; each id must be a UUID, with no empty items, whitespace or duplicates (case-insensitive). Any id that does not belong to the target returns 404. Cannot be combined with lastNCampaigns.

lastNCampaignsinteger, [ 1 .. 20 ]

Use only the N newest campaigns of the latest-finished-per-group selection (1–20). Defaults to 20 when omitted. Cannot be combined with campaigns. Must be sent once.

Default:20
severitystring^(critical|high|medium|low)(,(critical|high|m...

Optional. Comma-separated severities: critical, high, medium, low. Sent once as a single value. Any other value returns 400 REMEDIATIONS.SEVERITY_INVALID.

categorystring

Optional. Comma-separated category names. Sent once as a single value. At most 20 names of at most 100 characters each; otherwise 400 REMEDIATIONS.CATEGORY_INVALID.

sortstring

Optional. asr sorts by attack success rate, highest first. Omit for the default order (worst severity first, then name). Sent once. Any other value returns 400 REMEDIATIONS.SORT_INVALID.

Value:"asr"
Headers
X-Correlation-IDstring, (uuid)

Optional caller-supplied correlation id. Must be a UUID when present. When omitted or blank, the API generates a UUID. A non-UUID value returns 400 CORRELATION.INVALID. If a write fails because a UUID is already in use, the API returns 409 UUID.DUPLICATE. The value used (caller or generated) is echoed as supportToken and in the X-Correlation-ID response header.

curl -i -X GET \
  'https://baseUrl/api/v3.0/redteaming/orgs/{orgUuid}/applications/{applicationUuid}/projects/{projectUuid}/targets/{targetId}/remediations/report?pretty=false&format=pdf&campaigns=497f6eca-6276-4993-bfeb-53cbbbba6f08&lastNCampaigns=20&severity=string&category=string&sort=asr' \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'X-Correlation-ID: 497f6eca-6276-4993-bfeb-53cbbbba6f08'

Responses

Remediation report file bytes (PDF or CSV).

Headers
X-Correlation-IDstring, (uuid)

Correlation id used for this request (caller-supplied UUID, or a UUID generated when the request omitted the header). Same value as supportToken.

Content-Dispositionstring

attachment; filename="Mend Red-Teaming Remediation Report - YYYY-MM-DD.<pdf|csv>" (same naming as the UI export)

Body
string, (binary)(BinaryReport)

Report bytes. application/pdf when format=pdf, text/csv when format=csv.

Response
string