Publish results
Publishing creates a public page on zkao for one finding or one scan. Anyone with the link can read it. Nothing else in the project becomes visible.
Publishing needs the publish scope. zkao login does not request it by default. Ask for it when you log in:
zkao login --scope read scans:launch findings:write publishPublish a finding
Section titled “Publish a finding”A published finding shows its title, severity, repository, commit, description, impact, and recommendation. You can also attach one of its comments as the team’s public response. Pass that comment’s id as the note.
zkao findings publish <findingId>zkao findings publish <findingId> --note <noteId> --passwordconst { publicId, accessPassword } = await zkao.publishFinding(findingId, { noteId, withPassword: true,});curl -X POST -H "Authorization: Bearer $ZKAO_API_TOKEN" -H "Content-Type: application/json" \ -d '{"noteId":"<noteId>","withPassword":true}' \ https://zkao.io/api/v1/projects/$ZKAO_PROJECT_ID/findings/<findingId>/publishThe note must belong to the finding. Another finding’s note returns 400. The finding id also accepts a ZK- label.
Publish a scan
Section titled “Publish a scan”A published scan lists the scan’s reported findings, most severe first. It covers the findings zkao confirmed, and those it marked as needing review. Only a COMPLETED scan can be published.
zkao scans publish <scanId>zkao scans publish <scanId> --passwordconst { publicId, accessPassword } = await zkao.publishScan(scanId, { withPassword: true });curl -X POST -H "Authorization: Bearer $ZKAO_API_TOKEN" -H "Content-Type: application/json" \ -d '{"withPassword":true}' \ https://zkao.io/api/v1/projects/$ZKAO_PROJECT_ID/scans/<scanId>/publishThe result
Section titled “The result”Both calls return the same shape.
{ "artifactId": "…", "publicId": "…", "accessPassword": null}The public page lives at one of these URLs.
https://zkao.io/public/findings/<publicId>https://zkao.io/public/scans/<publicId>
Password protection
Section titled “Password protection”With withPassword, zkao generates a password and returns it as accessPassword. Visitors must enter it to read the page. Share it separately from the link.
Unpublishing
Section titled “Unpublishing”The API publishes but does not unpublish. Unpublish a page from the finding or scan on zkao.
See Publish a finding and Publish a scan for the full schemas.

