Scanning API
Use these endpoints to trigger repository static analysis and cloud infrastructure scans. Use theX-CLOUDGENI-API-KEY header for all examples here.
Repository Static Analysis
Create a Checkov-backed static analysis run for a repository:Repository IaC Scans
Create an IaC repository scan:iac-scans routes rather than the
Checkov-only static analysis flow.
Cloud Infra Scans
Create a cloud scan against an existing cloud integration:analysisEngine segment is part of the route. Supported values include:
prowler-ocsfaws-security-hubazure-defender
credentialId and regions when the route
supports them.
Cloud Scan Findings
Fetch findings for a specific cloud scan:limitoffsetsearchseveritystatusframeworkssummaryStatusCategoriesresourceTyperesourceIdsortBysortOrder
includeSummary=true to return severity totals for the same filtered result set;
summaryStatusCategories can further limit that summary to FAILED, SUPPRESSED, or PASSED.
For example, this request returns open high- or critical-severity findings mapped to SOC 2 or ISO
27001: