Get a single finding (full detail)
const url = 'https://zkao.io/api/v1/projects/example/findings/example';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://zkao.io/api/v1/projects/example/findings/example \ --header 'Authorization: Bearer <token>'Requires scope: read. Includes description, PoC, recommended fix, and notes.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”The finding id, or the ZK- label shown on the finding page (the id’s last eight characters, prefix optional). A label that matches more than one finding in the project is refused with 409 conflict; use the full id.
Responses
Section titled “ Responses ”OK
object
object
Effective severity (user override if set, else AI severity).
What backs a CONFIRMED verdict. POC means a proof of concept ran and demonstrated the issue. ANALYSIS means it was confirmed by code analysis alone. Null for other statuses or when not recorded.
object
object
object
Example
{ "finding": { "severity": "CRITICAL", "triageStatus": "PENDING", "confirmationEvidence": "POC", "resolutionStatus": "NOT_STARTED" }}Missing, malformed, expired, or revoked token
object
object
Example
{ "error": { "code": "unauthorized" }}The token lacks the required scope
object
object
Example
{ "error": { "code": "unauthorized" }}Resource not in this token’s project or repo allowlist
object
object
Example
{ "error": { "code": "unauthorized" }}A compare-and-set (expectedContent) missed: the guidance changed since it was read. Re-read the current guidance and retry.
object
object
Example
{ "error": { "code": "unauthorized" }}
