Create a custom API source
Create a custom API source for your team in the draft state. Team admins only. The request takes a name, a setup mode, a schedule, a documentation reference and an optional request template, pagination and mapping. None of these may contain a credential: send credentials only to the test action. Names are unique in a team, ignoring case. A team can have at most 25 custom sources.
Authorizations
JWT authentication token
Body
1 - 80Reference to the API documentation. Give a public https URL, or paste the document as JSON or YAML text (at most 1 MiB). Never include a credential.
Dot paths from each provider record to the normalized finding fields. external_key identifies a record inside the source.
How a synchronization walks the listing.
The request a synchronization sends. Header and query values are stored and returned as typed, so never put a credential in them.
Interval between scheduled synchronizations.
1h, 6h, 12h, 24h documentation reads an OpenAPI 3 or Swagger 2 document to propose the configuration; manual takes the configuration as entered.
documentation, manual Response
Source created
A Triage source of your team. Credentials are never returned: credential_configured shows whether one is stored.
Incremented by every change of documentation, request template, pagination or mapping.
Documentation reference of a source. Pasted documents are not returned.
True when scheduled synchronization is on.
hackerone, github and gmail are built-in connections; custom_api is a source you configure.
hackerone, github, gmail, custom_api Interval between scheduled synchronizations.
1h, 6h, 12h, 24h documentation reads an OpenAPI 3 or Swagger 2 document to propose the configuration; manual takes the configuration as entered.
documentation, manual Server-controlled lifecycle state of a source. A failed scheduled or manual synchronization sets failed and backs the next one off (the schedule interval times 2^min(failures, 4), at most 24 hours later). After 10 failed synchronizations in a row the source is paused: disabled, enabled false, last_error_code kept. A successful synchronization or re-enabling the source resets the count.
draft, analyzing, configuration_required, testing, setting_up, ready, syncing, failed, disabled, removed Configuration version that last passed a test (0 when none). Synchronization needs it to equal configuration_version.
Stable code of the last failure, such as target_not_public or upstream_status. On a ready source it is a warning from the last synchronization, such as record_limit or page_limit when the listing was longer than one synchronization reads.
Dot paths from each provider record to the normalized finding fields. external_key identifies a record inside the source.
How a synchronization walks the listing.
The request a synchronization sends. Header and query values are stored and returned as typed, so never put a credential in them.

