Skip to main content
POST
Publish an audit

Authorizations

Authorization
string
header
required

Authorization: Bearer <key>.

For the project and card routes, the key is an API key belonging to an onboarded integrator or to an active audit provider. The publishing routes accept only an audit provider's credential. Sending no Authorization header produces 401; sending one that is not recognised produces 403.

Body

application/json
name
string
required
description
string
required
conductedAt
number
required

Milliseconds since the Unix epoch, of when the audit was conducted. Rejected if earlier than 2008-01-01 or later than the moment the request is handled.

reportType
enum<string>
required

file requires reportFileCid, obtained by uploading through the authorization route. web requires reportUrl, a link to the provider's own published report.

Available options:
file,
web
project
object
required
contracts
(On-chain contract · object | Public repository contract · object | Private repository contract · object)[]
required
Minimum array length: 1
issues
object[]
required
reportFileCid
string

Required when reportType is file.

reportUrl
string

Required when reportType is web.

aggregationId
string

Required for providers whose publishing mode is automatic or aggregated, and rejected for providers publishing manually.

Response

The audit was created.

id
string
required

The new audit's identifier.

extra
object
required

Present on every response, including errors.