Skip to content
These docs describe staging.zkao.io and the @zksecurity/zkao-cli@next release. For production, see docs.zkao.io.

List scans (most recent first)

GET
/projects/{projectId}/scans
curl --request GET \
--url 'https://zkao.io/api/v1/projects/example/scans?page=1&limit=50' \
--header 'Authorization: Bearer <token>'

Requires scope: read.

projectId
required
string
page
integer
default: 1 >= 1
limit
integer
default: 50 >= 1 <= 100

OK

Media typeapplication/json
object
items
required
Array<object>
object
id
required
string
status
required
string
Allowed values: QUEUED PROCESSING COMPLETED FAILED CANCELLED
repositoryId
required
string
commitHash
string | null
baseCommit

A diff scan’s base, as the merge base SHA its change is measured from. Null for other scans.

string | null
commitMessage
string | null
presetName
string | null
createdAt
required
string format: date-time
startedAt
string | null format: date-time
completedAt
string | null format: date-time
progress
One of:

How far a running scan has got through its phases. Deliberately not a time estimate: a phase’s duration moves with the guidance it was given, the repository, and the model that ran it.

object
phasesCompleted
required

Phases that reached a terminal state (completed, failed, or skipped).

integer
phasesTotal
required

Phases this scan will run, fixed when it was dispatched.

integer
percent
required

Weighted completion. Each phase counts for its share of the scan budget, so this does not simply equal phasesCompleted / phasesTotal.

integer
<= 100
page
required
integer
limit
required
integer
total
required
integer
Example
{
"items": [
{
"status": "QUEUED"
}
]
}

Missing, malformed, expired, or revoked token

Media typeapplication/json
object
error
required
object
code
required
string
Allowed values: unauthorized forbidden not_found bad_request conflict insufficient_credits repository_initializing diff_base_required diff_base_not_allowed diff_base_invalid diff_empty rate_limited internal
message
required
string
Example
{
"error": {
"code": "unauthorized"
}
}

The token lacks the required scope

Media typeapplication/json
object
error
required
object
code
required
string
Allowed values: unauthorized forbidden not_found bad_request conflict insufficient_credits repository_initializing diff_base_required diff_base_not_allowed diff_base_invalid diff_empty rate_limited internal
message
required
string
Example
{
"error": {
"code": "unauthorized"
}
}

Resource not in this token’s project or repo allowlist

Media typeapplication/json
object
error
required
object
code
required
string
Allowed values: unauthorized forbidden not_found bad_request conflict insufficient_credits repository_initializing diff_base_required diff_base_not_allowed diff_base_invalid diff_empty rate_limited internal
message
required
string
Example
{
"error": {
"code": "unauthorized"
}
}