Reports
Get a report
Returns the report’s summary, scope, methodology, and captured vulnerability and evidence metadata. Reports can cover more than one run. See Reports for creating and reviewing reports in the platform.
GET
/
reports
/
{id}
Get a report
curl --request GET \
--url https://api.antigen.sh/v1/reports/{id} \
--header 'x-api-key: <api-key>'import requests
url = "https://api.antigen.sh/v1/reports/{id}"
headers = {"x-api-key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.antigen.sh/v1/reports/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/reports/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/reports/{id}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("x-api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.antigen.sh/v1/reports/{id}")
.header("x-api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/reports/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["x-api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"id": "report_123",
"title": "Production API assessment",
"summary": "Testing identified a cross-account authorization weakness.",
"scope": "api.example.com",
"methodology": "Authenticated testing of invoice ownership checks.",
"runIds": [
"run_123"
],
"vulnerabilities": [
{
"vulnerability": {
"id": "vuln_123",
"title": "Cross-account invoice access",
"description": "An authenticated account can retrieve another account’s invoice by changing its ID.",
"severity": "high",
"target": "api.example.com",
"runId": "run_123",
"remediation": "Check that the authenticated account owns the invoice before returning it.",
"status": "open",
"assignee": null,
"riskAcceptance": null,
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z"
},
"evidence": [
{
"id": "ev_123",
"vulnerabilityId": "vuln_123",
"runId": "run_123",
"filename": "reproduction.py",
"sizeBytes": 2048,
"contentType": "text/x-python",
"createdAt": "2026-09-13T10:00:00.000Z"
}
]
}
],
"createdAt": "2026-09-13T10:00:00.000Z"
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in this organization."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}Authorizations
API key from your organization. Supply the value directly, without a Bearer prefix.
Path Parameters
Opaque resource identifier.
Minimum string length:
1Response
Successful response.
Minimum string length:
1Minimum string length:
1Vulnerability and evidence metadata captured when the report was written. Later updates do not change these values.
Show child attributes
Show child attributes
Get a report
curl --request GET \
--url https://api.antigen.sh/v1/reports/{id} \
--header 'x-api-key: <api-key>'import requests
url = "https://api.antigen.sh/v1/reports/{id}"
headers = {"x-api-key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.antigen.sh/v1/reports/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/reports/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/reports/{id}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("x-api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.antigen.sh/v1/reports/{id}")
.header("x-api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/reports/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["x-api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"id": "report_123",
"title": "Production API assessment",
"summary": "Testing identified a cross-account authorization weakness.",
"scope": "api.example.com",
"methodology": "Authenticated testing of invoice ownership checks.",
"runIds": [
"run_123"
],
"vulnerabilities": [
{
"vulnerability": {
"id": "vuln_123",
"title": "Cross-account invoice access",
"description": "An authenticated account can retrieve another account’s invoice by changing its ID.",
"severity": "high",
"target": "api.example.com",
"runId": "run_123",
"remediation": "Check that the authenticated account owns the invoice before returning it.",
"status": "open",
"assignee": null,
"riskAcceptance": null,
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z"
},
"evidence": [
{
"id": "ev_123",
"vulnerabilityId": "vuln_123",
"runId": "run_123",
"filename": "reproduction.py",
"sizeBytes": 2048,
"contentType": "text/x-python",
"createdAt": "2026-09-13T10:00:00.000Z"
}
]
}
],
"createdAt": "2026-09-13T10:00:00.000Z"
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in this organization."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}