Skip to content
These docs describe staging.zkao.io and the @zksecurity/zkao-cli@next release. For production, see docs.zkao.io.

List a repository's audit areas

GET
/projects/{projectId}/repositories/{repositoryId}/audit-areas
curl --request GET \
--url https://zkao.io/api/v1/projects/example/repositories/example/audit-areas \
--header 'Authorization: Bearer <token>'

Requires scope: read. Audit areas are the named subsystems a scan can be scoped to (auditAreaKeys on launch). Each scan that maps the repository keeps the list current; sizes come from one branch’s map, so an area that map no longer names is returned without one.

projectId
required
string
repositoryId
required
string
branch
string

Branch whose map the sizes come from. Defaults to the repository’s default branch.

OK

Media typeapplication/json
object
repositoryId
required
string
branch
required

Branch the sizes were read from.

string | null
mapped
required

Whether that branch has a stored map at all.

boolean
totalFiles
required
integer | null
totalLines
required
integer | null
areas
required

The map’s own audit order first, then the areas it no longer names.

Array<object>
object
key
required

Stable slug, unique per repository. Pass it in auditAreaKeys when launching a scan.

string
name
required
string
description
required
string | null
source
required

discovered was named by a scan’s map of the repository; custom was added through this API or the app.

string
Allowed values: discovered custom
inLatestMap
required

Whether the branch’s latest map still names this area.

boolean
files
required

Files this area covers at that map. Null when the map does not name it.

integer | null
lines
required

Lines this area covers at that map. Null when the map does not name it.

integer | null
Example
{
"areas": [
{
"source": "discovered"
}
]
}

Missing, malformed, expired, or revoked token

Media typeapplication/json
object
error
required
object
code
required
string
Allowed values: unauthorized forbidden not_found bad_request conflict insufficient_credits repository_initializing diff_base_required diff_base_not_allowed diff_base_invalid diff_empty rate_limited internal
message
required
string
Example
{
"error": {
"code": "unauthorized"
}
}

The token lacks the required scope

Media typeapplication/json
object
error
required
object
code
required
string
Allowed values: unauthorized forbidden not_found bad_request conflict insufficient_credits repository_initializing diff_base_required diff_base_not_allowed diff_base_invalid diff_empty rate_limited internal
message
required
string
Example
{
"error": {
"code": "unauthorized"
}
}

Resource not in this token’s project or repo allowlist

Media typeapplication/json
object
error
required
object
code
required
string
Allowed values: unauthorized forbidden not_found bad_request conflict insufficient_credits repository_initializing diff_base_required diff_base_not_allowed diff_base_invalid diff_empty rate_limited internal
message
required
string
Example
{
"error": {
"code": "unauthorized"
}
}