API reference
API reference
Call the Kissaki API - base URL, how it is generated, and the resource groups.
The Kissaki API is a JSON HTTP API. The base URL is https://api.kissaki.io.
This reference is generated from the API's own OpenAPI spec and filtered to the customer-facing surface - staff, agent-plane and webhook routes are removed before publishing. Each endpoint page below shows its parameters, request and response schemas, and an interactive request builder.
Authentication
Requests are made in the context of a workspace and authenticated with your workspace credentials from the dashboard. Each endpoint page states the parameters it needs; send requests over HTTPS only.
Resource groups
- Assets - onboard and manage the inventory (repositories, domains, containers, clouds, VMs), verify ownership, and start scans.
- Findings - read normalised, proven findings and record suppressions.
- Reports - generate an asset report as Markdown, PDF or SARIF.
- Campaigns - drive the agentic pentest pipeline.
- Integrations, GitHub, GitLab, Bitbucket - connect git providers and configure PR gating.
- Registry - connect a container registry.
- Workspace - workspace settings, KPIs and the scan identity.
- Blog - the public blog feed.
Pick a group in the sidebar to browse its endpoints.