Add a comment (note) to a finding
POST
/projects/{projectId}/findings/{findingId}/notes
const url = 'https://zkao.io/api/v1/projects/example/findings/example/notes';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"content":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://zkao.io/api/v1/projects/example/findings/example/notes \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "content": "example" }'Requires scope: findings:write.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”projectId
required
string
findingId
required
string
The finding id, or the ZK- label shown on the finding page (the id’s last eight characters, prefix optional). A label that matches more than one finding in the project is refused with 409 conflict; use the full id.
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
content
required
The comment body (markdown).
string
Examplegenerated
{ "content": "example"}Responses
Section titled “ Responses ”Note created
Media typeapplication/json
object
noteId
required
string
findingId
required
string
Examplegenerated
{ "noteId": "example", "findingId": "example"}Invalid request
Media typeapplication/json
object
error
required
object
code
required
string
message
required
string
Example
{ "error": { "code": "unauthorized" }}Missing, malformed, expired, or revoked token
Media typeapplication/json
object
error
required
object
code
required
string
message
required
string
Example
{ "error": { "code": "unauthorized" }}The token lacks the required scope
Media typeapplication/json
object
error
required
object
code
required
string
message
required
string
Example
{ "error": { "code": "unauthorized" }}Resource not in this token’s project or repo allowlist
Media typeapplication/json
object
error
required
object
code
required
string
message
required
string
Example
{ "error": { "code": "unauthorized" }}A compare-and-set (expectedContent) missed: the guidance changed since it was read. Re-read the current guidance and retry.
Media typeapplication/json
object
error
required
object
code
required
string
message
required
string
Example
{ "error": { "code": "unauthorized" }}
