Update a custom API source
Update only the supplied fields of a custom source. Team admins only. A change of documentation, request template (authentication included), pagination or mapping increments configuration_version, marks the previous test stale, and pauses synchronization until the new configuration passes a test. A change of the request URL’s origin (scheme, host, port), the OAuth token URL’s origin, or the authentication type, header name or query parameter name also revokes the stored credential (credential_configured becomes false): send the credential again with the test action. enabled false disables the source, stops its schedule and cancels its queued synchronizations; enabled true re-enables a source whose current configuration passed a test (409 source_not_tested otherwise) and makes it due at once.
Authorizations
JWT authentication token
Path Parameters
Source id
Body
Only supplied fields change.
Reference to the API documentation. Give a public https URL, or paste the document as JSON or YAML text (at most 1 MiB). Never include a credential.
false disables the source and stops its schedule; true re-enables a source whose current configuration passed a test.
Dot paths from each provider record to the normalized finding fields. external_key identifies a record inside the source.
1 - 80How a synchronization walks the listing.
The request a synchronization sends. Header and query values are stored and returned as typed, so never put a credential in them.
Interval between scheduled synchronizations.
1h, 6h, 12h, 24h documentation reads an OpenAPI 3 or Swagger 2 document to propose the configuration; manual takes the configuration as entered.
documentation, manual Response
The updated source
A Triage source of your team. Credentials are never returned: credential_configured shows whether one is stored.
Incremented by every change of documentation, request template, pagination or mapping.
Documentation reference of a source. Pasted documents are not returned.
True when scheduled synchronization is on.
hackerone, github and gmail are built-in connections; custom_api is a source you configure.
hackerone, github, gmail, custom_api Interval between scheduled synchronizations.
1h, 6h, 12h, 24h documentation reads an OpenAPI 3 or Swagger 2 document to propose the configuration; manual takes the configuration as entered.
documentation, manual Server-controlled lifecycle state of a source. A failed scheduled or manual synchronization sets failed and backs the next one off (the schedule interval times 2^min(failures, 4), at most 24 hours later). After 10 failed synchronizations in a row the source is paused: disabled, enabled false, last_error_code kept. A successful synchronization or re-enabling the source resets the count.
draft, analyzing, configuration_required, testing, setting_up, ready, syncing, failed, disabled, removed Configuration version that last passed a test (0 when none). Synchronization needs it to equal configuration_version.
Stable code of the last failure, such as target_not_public or upstream_status. On a ready source it is a warning from the last synchronization, such as record_limit or page_limit when the listing was longer than one synchronization reads.
Dot paths from each provider record to the normalized finding fields. external_key identifies a record inside the source.
How a synchronization walks the listing.
The request a synchronization sends. Header and query values are stored and returned as typed, so never put a credential in them.

