Add a custom audit area
const url = 'https://zkao.io/api/v1/projects/example/repositories/example/audit-areas';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"name":"example","description":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://zkao.io/api/v1/projects/example/repositories/example/audit-areas \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "name": "example", "description": "example" }'Requires scope: guidance:write. An area is a name and a description, never a file list: a scan resolves it against the code at the commit it runs on. The key is derived from the name and disambiguated on collision.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”Request Bodyrequired
Section titled “Request Bodyrequired”object
What this part of the code does.
Examplegenerated
{ "name": "example", "description": "example"}Responses
Section titled “ Responses ”Created
object
object
Stable slug, unique per repository. Pass it in auditAreaKeys when launching a scan.
discovered was named by a scan’s map of the repository; custom was added through this API or the app.
Whether the branch’s latest map still names this area.
Files this area covers at that map. Null when the map does not name it.
Lines this area covers at that map. Null when the map does not name it.
Example
{ "area": { "source": "discovered" }}Invalid request
object
object
Example
{ "error": { "code": "unauthorized" }}Missing, malformed, expired, or revoked token
object
object
Example
{ "error": { "code": "unauthorized" }}The token lacks the required scope
object
object
Example
{ "error": { "code": "unauthorized" }}Resource not in this token’s project or repo allowlist
object
object
Example
{ "error": { "code": "unauthorized" }}A compare-and-set (expectedContent) missed: the guidance changed since it was read. Re-read the current guidance and retry.
object
object
Example
{ "error": { "code": "unauthorized" }}
