Skip to main content
GET
Get a Triage finding

Authorizations

Authorization
string
header
required

JWT authentication token

Path Parameters

id
string<uuid>
required

Finding id

Response

The finding

A normalized report of one source (HackerOne report, GitHub security advisory, Security Inbox thread or custom API source record). Its id is opaque; (source, external_key) is its identity at the source.

context
string
required

Scope at the source: HackerOne program handle, GitHub owner/repo, or Security Inbox mailbox email. Empty for custom API sources.

description
string
required
external_key
string
required

The record's identity at the source: HackerOne report id, GitHub security advisory id, Gmail thread id, or the mapped key of a custom API source record.

first_seen_at
string<date-time>
required
id
string<uuid>
required
last_seen_at
string<date-time>
required
reporter
string
required
revision
integer
required

Increases when the source record's content changes.

severity
enum<string>
required
Available options:
none,
low,
medium,
high,
critical,
unknown
source_id
string<uuid>
required
source_kind
enum<string>
required

hackerone, github and gmail are built-in connections; custom_api is a source you configure.

Available options:
hackerone,
github,
gmail,
custom_api
source_name
string
required
source_status
string
required

The record's status at the source, as the source reports it.

title
string
required
url
string
required
archived_at
string<date-time> | null
latest_run
object | null

The newest triage run of this finding. Null when none exists.

raw
object | null

The bounded source record (at most 64 KiB) as stored. Only returned by the single-finding read. Never contains credentials.