Automation API
This reference is generated at build time from web/src/shared/api/openapi.json. There is no separately maintained endpoint list.
| Method | Path | Purpose | Access |
|---|---|---|---|
GET |
/api/health |
Health | Public |
GET |
/api/metrics |
Prometheus | Bearer: metrics token |
GET |
/api/cron |
Cron | Bearer: cron token |
POST |
/api/ci/sarif |
Ci Import | Bearer: import token |
GET /api/health
Section titled “GET /api/health”Health
Authentication: Public.
Responses
Section titled “Responses”| Status | Description |
|---|---|
200 |
Successful Response |
GET /api/metrics
Section titled “GET /api/metrics”Prometheus
Authentication: Bearer: metrics token.
Responses
Section titled “Responses”| Status | Description |
|---|---|
200 |
Prometheus text exposition format |
401 |
Missing or wrong bearer token |
404 |
Metrics are off (PITANGUS_METRICS_TOKEN is not set) |
GET /api/cron
Section titled “GET /api/cron”Cron
Authentication: Bearer: cron token.
Responses
Section titled “Responses”| Status | Description |
|---|---|
200 |
Successful Response |
401 |
Missing or wrong bearer token |
404 |
Off: not PITANGUS_PERIODIC=external, or no PITANGUS_CRON_TOKEN / CRON_SECRET |
POST /api/ci/sarif
Section titled “POST /api/ci/sarif”The same import for a pipeline, authenticated by PITANGUS_IMPORT_TOKEN instead of a session.
Authentication: Bearer: import token.
Parameters
Section titled “Parameters”| Name | In | Type | Required |
|---|---|---|---|
asset |
query | string |
No |
tool |
query | string |
No |
scope |
query | string |
No |
commit |
query | string |
No |
branch |
query | string |
No |
X-Pitangus-Actor |
header | string |
No |
Body: object.
Responses
Section titled “Responses”| Status | Description |
|---|---|
200 |
Successful Response |
401 |
Missing or wrong bearer token |
404 |
Off (no PITANGUS_IMPORT_TOKEN), or unknown asset |
409 |
The name matches several assets |