> For the complete documentation index, see [llms.txt](https://docs.ox.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ox.security/api-documentation/api-reference/api--api-security/queries/get-api-security-items.md).

# getApiSecurityItems

Retrieves a list of discovered API endpoints with their security information.

### Examples

{% tabs %}
{% tab title="GraphQL" %}

```graphql
query GetApiSecurityItems($getApiSecurityInput: GetApiSecurityInput) {
  getApiSecurityItems(getApiSecurityInput: $getApiSecurityInput) {
    apiSecurityItems {
      id
      scanId
      title
      description
      version
      methodDescription
      methodOperationId
      methodSummary
      openapi
      servers
      epName
      methodName
      methodResponses {
        description
        code
      }
      methodTags
      methodParameters {
        description
        in
        name
        required
      }
      appId
      appType
      appName
      fileName
      definitions {
        source
        fileName
        link
        llmTitle
        llmDescription
        functions {
          function
          line
          snippet
          filepath
          link
        }
      }
      framework
      language
      firstSeen
      uuid
      issuesBySeverity {
        info
        low
        medium
        high
        critical
        appox
      }
      codeLocations {
        link
        callBranch
      }
      commits {
        commitInfo {
          authorName
          authorEmail
          committerName
          committerEmail
          commitId
          message
          authorDate
          commitDate
        }
        match
        snippet
        snippetLineNumber
        startLineNumber
        fileName
        link
      }
      cfInfo {
        runtimeStatus
        requestCount
        lastSeen
        matchType
        wafBlockCount
        wafBotBlockCount
        wafTopAttackerIps
        wafTopCountries
        wafAttackSources
        wafLastAttackAt
        zone
        host
        allMatchedZones
      }
    }
    total
    totalFiltered
  }
}
```

#### Variables

This is an example input showing all available input fields. Only fields marked as required in the schema are mandatory.

```json
{
  "getApiSecurityInput": {
    "scanId": "c9da693d-8906-4a32-93c9-2ffdb1cebb99",
    "offset": 0,
    "limit": 100,
    "owners": ["example"],
    "tagIds": ["example"],
    "search": "/api/v2/",
    "filters": {
      "apps": ["repo-name"],
      "appIds": ["1234567890"],
      "titles": ["Kubernetes"],
      "endpoints": ["/api/v1/some/endpoint"],
      "methods": ["GET"],
      "framework": ["OpenAPI"],
      "languages": ["OpenAPI"],
      "issueIds": ["30966426-oxPolicy_securityCloudScan_100-example"],
      "apiId": ["ceb76dd8-7c11-448c-9056-17c5b5bfa361"],
      "source": ["OpenAPI"],
      "severities": ["2"],
      "reachability": ["Code"],
      "appTags": ["Private repo"]
    },
    "filterSearch": [
      {
        "fieldName": "example",
        "value": ["example"]
      }
    ],
    "openItems": ["digest"],
    "orderBy": {
      "field": "title",
      "direction": "ASC"
    }
  }
}
```

{% endtab %}

{% tab title="cURL" %}

```shell
curl -X POST \
https://api.cloud.ox.security/api/apollo-gateway \
-H 'Content-Type: application/json' \
-H 'Authorization: YOUR_API_TOKEN' \
-d '{
 "query": "query GetApiSecurityItems($getApiSecurityInput: GetApiSecurityInput) { getApiSecurityItems(getApiSecurityInput: $getApiSecurityInput) { apiSecurityItems { id scanId title description version methodDescription methodOperationId methodSummary openapi servers epName methodName methodResponses { description code } methodTags methodParameters { description in name required } appId appType appName fileName definitions { source fileName link llmTitle llmDescription functions { function line snippet filepath link } } framework language firstSeen uuid issuesBySeverity { info low medium high critical appox } codeLocations { link callBranch } commits { commitInfo { authorName authorEmail committerName committerEmail commitId message authorDate commitDate } match snippet snippetLineNumber startLineNumber fileName link } cfInfo { runtimeStatus requestCount lastSeen matchType wafBlockCount wafBotBlockCount wafTopAttackerIps wafTopCountries wafAttackSources wafLastAttackAt zone host allMatchedZones } } total totalFiltered } }",
 "variables": {
    "getApiSecurityInput": {
      "scanId": "c9da693d-8906-4a32-93c9-2ffdb1cebb99",
      "offset": 0,
      "limit": 100,
      "owners": ["example"],
      "tagIds": ["example"],
      "search": "/api/v2/",
      "filters": {
        "apps": ["repo-name"],
        "appIds": ["1234567890"],
        "titles": ["Kubernetes"],
        "endpoints": ["/api/v1/some/endpoint"],
        "methods": ["GET"],
        "framework": ["OpenAPI"],
        "languages": ["OpenAPI"],
        "issueIds": ["30966426-oxPolicy_securityCloudScan_100-example"],
        "apiId": ["ceb76dd8-7c11-448c-9056-17c5b5bfa361"],
        "source": ["OpenAPI"],
        "severities": ["2"],
        "reachability": ["Code"],
        "appTags": ["Private repo"]
      },
      "filterSearch": [
        {
          "fieldName": "example",
          "value": ["example"]
        }
      ],
      "openItems": ["digest"],
      "orderBy": {
        "field": "title",
        "direction": "ASC"
      }
    }
  }
}'
```

{% endtab %}

{% tab title="Node.js" %}

```javascript
const query = 'query GetApiSecurityItems($getApiSecurityInput: GetApiSecurityInput) { getApiSecurityItems(getApiSecurityInput: $getApiSecurityInput) { apiSecurityItems { id scanId title description version methodDescription methodOperationId methodSummary openapi servers epName methodName methodResponses { description code } methodTags methodParameters { description in name required } appId appType appName fileName definitions { source fileName link llmTitle llmDescription functions { function line snippet filepath link } } framework language firstSeen uuid issuesBySeverity { info low medium high critical appox } codeLocations { link callBranch } commits { commitInfo { authorName authorEmail committerName committerEmail commitId message authorDate commitDate } match snippet snippetLineNumber startLineNumber fileName link } cfInfo { runtimeStatus requestCount lastSeen matchType wafBlockCount wafBotBlockCount wafTopAttackerIps wafTopCountries wafAttackSources wafLastAttackAt zone host allMatchedZones } } total totalFiltered } }';

fetch("https://api.cloud.ox.security/api/apollo-gateway", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    "Authorization": "YOUR_API_TOKEN"
  },
  body: JSON.stringify({
    query: query,
    // This is an example input showing all available input fields. Only fields marked as required in the schema are mandatory.
    variables: {
      getApiSecurityInput: {
        scanId: "c9da693d-8906-4a32-93c9-2ffdb1cebb99",
        offset: 0,
        limit: 100,
        owners: ["example"],
        tagIds: ["example"],
        search: "/api/v2/",
        filters: {
          apps: ["repo-name"],
          appIds: ["1234567890"],
          titles: ["Kubernetes"],
          endpoints: ["/api/v1/some/endpoint"],
          methods: ["GET"],
          framework: ["OpenAPI"],
          languages: ["OpenAPI"],
          issueIds: ["30966426-oxPolicy_securityCloudScan_100-example"],
          apiId: ["ceb76dd8-7c11-448c-9056-17c5b5bfa361"],
          source: ["OpenAPI"],
          severities: ["2"],
          reachability: ["Code"],
          appTags: ["Private repo"]
        },
        filterSearch: [
          {
            fieldName: "example",
            value: ["example"]
          }
        ],
        openItems: ["digest"],
        orderBy: {
          field: "title",
          direction: "ASC"
        }
      }
    }
  })
})
.then(response => response.json())
.then(result => console.log(JSON.stringify(result, null, 2)))
.catch(error => console.error('Error:', error));
```

{% endtab %}

{% tab title="Python" %}

```python
import requests

query = 'query GetApiSecurityItems($getApiSecurityInput: GetApiSecurityInput) { getApiSecurityItems(getApiSecurityInput: $getApiSecurityInput) { apiSecurityItems { id scanId title description version methodDescription methodOperationId methodSummary openapi servers epName methodName methodResponses { description code } methodTags methodParameters { description in name required } appId appType appName fileName definitions { source fileName link llmTitle llmDescription functions { function line snippet filepath link } } framework language firstSeen uuid issuesBySeverity { info low medium high critical appox } codeLocations { link callBranch } commits { commitInfo { authorName authorEmail committerName committerEmail commitId message authorDate commitDate } match snippet snippetLineNumber startLineNumber fileName link } cfInfo { runtimeStatus requestCount lastSeen matchType wafBlockCount wafBotBlockCount wafTopAttackerIps wafTopCountries wafAttackSources wafLastAttackAt zone host allMatchedZones } } total totalFiltered } }'

response = requests.post(
  "https://api.cloud.ox.security/api/apollo-gateway",
  headers={
    "Content-Type": "application/json",
    "Authorization": "YOUR_API_TOKEN"
  },
  json={
    "query": query,
    # This is an example input showing all available input fields. Only fields marked as required in the schema are mandatory.
    "variables": {
      "getApiSecurityInput": {
        "scanId": "c9da693d-8906-4a32-93c9-2ffdb1cebb99",
        "offset": 0,
        "limit": 100,
        "owners": ["example"],
        "tagIds": ["example"],
        "search": "/api/v2/",
        "filters": {
          "apps": ["repo-name"],
          "appIds": ["1234567890"],
          "titles": ["Kubernetes"],
          "endpoints": ["/api/v1/some/endpoint"],
          "methods": ["GET"],
          "framework": ["OpenAPI"],
          "languages": ["OpenAPI"],
          "issueIds": ["30966426-oxPolicy_securityCloudScan_100-example"],
          "apiId": ["ceb76dd8-7c11-448c-9056-17c5b5bfa361"],
          "source": ["OpenAPI"],
          "severities": ["2"],
          "reachability": ["Code"],
          "appTags": ["Private repo"]
        },
        "filterSearch": [
          {
            "fieldName": "example",
            "value": ["example"]
          }
        ],
        "openItems": ["digest"],
        "orderBy": {
          "field": "title",
          "direction": "ASC"
        }
      }
    }
  }
)

if response.status_code == 200:
    result = response.json()
    print(result)
else:
    print(f"Error: {response.status_code}")
    print(response.text)
```

{% endtab %}
{% endtabs %}

### Arguments

You can use the following argument(s) to customize your `getApiSecurityItems` query.

| Argument                                                                                                                               | Description                                                     | Supported fields                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| -------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| getApiSecurityInput [`GetApiSecurityInput`](/api-documentation/api-reference/api--api-security/types/inputs/get-api-security-input.md) | Parameters for filtering and paginating the API security items. | <p>scanId <code>String</code><br>offset <code>Int</code><br>limit <code>Int</code><br>owners <code>\[String]</code><br>tagIds <code>\[String]</code><br>search <code>String</code><br>filters <a href="/pages/TDjeO8EVDPM5KceB4FJJ"><code>ApiSecFilters</code></a><br>filterSearch <a href="/pages/501RBby5Vj4iETTOR8n2"><code>\[AutoCompleteSearch]</code></a><br>openItems <a href="/pages/43jgm6P5kcKgBM8FmTho"><code>\[FilterTypes]</code></a><br>orderBy <a href="/pages/6rwm4OZ9MFEQrLRtaZgZ"><code>ApiSecurityOrderBy</code></a></p> |

### Fields

Return type: [`ApiSecurityItemsResponse`](/api-documentation/api-reference/api--api-security/types/objects/api-security-items-response.md)

You can use the following field(s) to specify what information your `getApiSecurityItems` query will return. Please note that some fields may have their own subfields.

| Field                                                                                                                         | Description                                               | Supported fields                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ----------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| apiSecurityItems [`[ApiSecurityItem]`](/api-documentation/api-reference/api--api-security/types/objects/api-security-item.md) | List of API security items found in the scan              | <p>id <code>String</code><br>scanId <code>String</code><br>title <code>String</code><br>description <code>String</code><br>version <code>String</code><br>methodDescription <code>String</code><br>methodOperationId <code>String</code><br>methodSummary <code>String</code><br>openapi <code>String</code><br>servers <code>\[String]</code><br>epName <code>String</code><br>methodName <code>String</code><br>methodResponses <a href="/pages/Js9j74jBgLGT5AtFgMgU"><code>\[MethodResponse]</code></a><br>methodTags <code>\[String]</code><br>methodParameters <a href="/pages/aII2kfJB1D9u6yY2lrjc"><code>\[MethodParameter]</code></a><br>appId <code>String</code><br>appType <code>String</code><br>appName <code>String</code><br>fileName <code>\[String]</code><br>definitions <a href="/pages/4v1VhNxezfFEG1SjkRN6"><code>\[APIDefinitions]</code></a><br>framework <code>String</code><br>language <code>String</code><br>firstSeen <code>Date</code><br>uuid <code>String</code><br>issuesBySeverity <a href="/pages/slO1MlaqzcbcMdp3yvLW"><code>Severities</code></a><br>codeLocations <a href="/pages/u8ALaEg8q8NFcL8tE7wy"><code>\[CodeLocation]</code></a><br>commits <a href="/pages/hwVPhlkWdE4ZgNU59vfA"><code>\[ApiInventoryCommit]</code></a><br>cfInfo <a href="/pages/U0gSFZ9iVtVmcFLuVyzM"><code>CfInfo</code></a></p> |
| total `Int`                                                                                                                   | Total number of API security items available              |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| totalFiltered `Int`                                                                                                           | Total number of API security items after applying filters |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.ox.security/api-documentation/api-reference/api--api-security/queries/get-api-security-items.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
