Trigger a Whitebox Scan
Scans
Trigger a Whitebox Scan
Start a Whitebox Scan against one or more repositories.
POST
Trigger a Whitebox Scan
Starts a Whitebox Scan against the repositories attached to a completed or
partial cost estimation. Scans run asynchronously; the endpoint returns
immediately with a scan
id for polling.
Scope required:
writePrerequisites
- Create a cost estimation with
POST /cost-estimations. - Wait until the estimation reaches
completedorpartialstatus and has a positivetotal_creditsvalue. - Submit the same repositories and branches that were included in the estimation. Hacktron rejects scans whose repo, archive, or branch does not match the estimate.
- Ensure your organization has enough Whitebox Scan credits. Credits are
visible in Credits and billing in the
dashboard. Insufficient credits return
402 Payment Required.
Request
Body
Repo object
POST /scans accepts the REST API repo shape shown above. Cost estimations
use repo_url; scan creation uses url.Response
201 Created
Errors
400— missingrepos, invalid fields, cost estimate not ready, zero-credit estimate, repo not included in the estimate, branch mismatch, private target URL, or a scan that already claimed the estimate.401/403— authentication or scope failure.402— insufficient Whitebox Scan credits. Top up from Credits and billing in the dashboard.404— cost estimation not found or not visible to your organization.
Next steps
- Poll
GET /scans/{id}/statusuntil status iscompleted. - Fetch findings with
GET /scans/{id}/findingsor export them withGET /scans/{id}/findings/export.