Skip to main content
PATCH
Update a custom API source

Authorizations

Authorization
string
header
required

JWT authentication token

Path Parameters

id
string<uuid>
required

Source id

Body

application/json

Only supplied fields change.

documentation
object

Reference to the API documentation. Give a public https URL, or paste the document as JSON or YAML text (at most 1 MiB). Never include a credential.

enabled
boolean

false disables the source and stops its schedule; true re-enables a source whose current configuration passed a test.

mapping
object

Dot paths from each provider record to the normalized finding fields. external_key identifies a record inside the source.

name
string
Required string length: 1 - 80
pagination
object

How a synchronization walks the listing.

request_template
object

The request a synchronization sends. Header and query values are stored and returned as typed, so never put a credential in them.

schedule
enum<string>

Interval between scheduled synchronizations.

Available options:
1h,
6h,
12h,
24h
setup_mode
enum<string>

documentation reads an OpenAPI 3 or Swagger 2 document to propose the configuration; manual takes the configuration as entered.

Available options:
documentation,
manual

Response

The updated source

A Triage source of your team. Credentials are never returned: credential_configured shows whether one is stored.

configuration_version
integer
required

Incremented by every change of documentation, request template, pagination or mapping.

created_at
string<date-time>
required
credential_configured
boolean
required
documentation
object
required

Documentation reference of a source. Pasted documents are not returned.

enabled
boolean
required

True when scheduled synchronization is on.

id
string<uuid>
required
kind
enum<string>
required

hackerone, github and gmail are built-in connections; custom_api is a source you configure.

Available options:
hackerone,
github,
gmail,
custom_api
name
string
required
schedule
enum<string>
required

Interval between scheduled synchronizations.

Available options:
1h,
6h,
12h,
24h
setup_mode
enum<string>
required

documentation reads an OpenAPI 3 or Swagger 2 document to propose the configuration; manual takes the configuration as entered.

Available options:
documentation,
manual
status
enum<string>
required

Server-controlled lifecycle state of a source. A failed scheduled or manual synchronization sets failed and backs the next one off (the schedule interval times 2^min(failures, 4), at most 24 hours later). After 10 failed synchronizations in a row the source is paused: disabled, enabled false, last_error_code kept. A successful synchronization or re-enabling the source resets the count.

Available options:
draft,
analyzing,
configuration_required,
testing,
setting_up,
ready,
syncing,
failed,
disabled,
removed
team_id
string<uuid>
required
tested_configuration_version
integer
required

Configuration version that last passed a test (0 when none). Synchronization needs it to equal configuration_version.

updated_at
string<date-time>
required
last_error_code
string

Stable code of the last failure, such as target_not_public or upstream_status. On a ready source it is a warning from the last synchronization, such as record_limit or page_limit when the listing was longer than one synchronization reads.

last_synced_at
string<date-time>
mapping
object

Dot paths from each provider record to the normalized finding fields. external_key identifies a record inside the source.

next_sync_at
string<date-time>
pagination
object

How a synchronization walks the listing.

request_template
object

The request a synchronization sends. Header and query values are stored and returned as typed, so never put a credential in them.