> ## Documentation Index
> Fetch the complete documentation index at: https://docs.semgrep.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Search issues

> Search Semgrep Agentic Workflows issues with filtering, sorting, and cursor pagination.



## OpenAPI

````yaml /public_v2.openapi.yaml post /api/issues/{deploymentId}/search
openapi: 3.0.3
info:
  title: Semgrep API
  description: >-
    The API v2 is currently a work in progress as we expand and improve our
    platform capabilities. There are no current plans to deprecate the [v1
    API](/api/v1/docs) – we remain committed to supporting existing integrations
    and will ensure that all v1 use cases are fully supported in v2 before any
    deprecation occurs.

    ## API Maturity Levels


    Each endpoint in the v2 API is marked with a maturity badge to help you
    understand its current state:


    🚧 **Experimental** - Use at your own risk. This endpoint was not originally
    designed for third-party use or is under active development. Expect
    significant breaking changes.


    ⚠️ **Beta** - This endpoint is being refined. We will communicate breaking
    changes to Beta partners as we tweak the implementation.


    ✅ **Stable** - No breaking changes will be made to this API. You can
    confidently build production integrations against these endpoints.


    We recommend using Stable endpoints for production applications and treating
    Experimental/Beta endpoints as previews of upcoming functionality. This API
    is documented in the **OpenAPI format**.


    # Authentication


    The API supports authentication with an API token with the "Web API"
    permission, without limited scopes of access.


    You can provision an API token [from the Settings
    page](https://semgrep.dev/orgs/-/settings/tokens).


    # Terms of Use


    Please note, the materials made available herein are subject to the [Semgrep
    Terms of Use](https://semgrep.dev/resources/website-terms/), and your access
    or use of any of the same is your acknowledgment and acceptance of the such
    terms.


    <br>


    ___
  contact:
    email: support@semgrep.com
  version: v2.0.0.alpha
  x-logo:
    url: https://semgrep.dev/images/SemgrepLogoWithTextWithMargin.svg
    backgroundColor: '#fafafa'
    altText: Semgrep logo
servers: []
security: []
tags:
  - name: AiFixJobsService
    description: Manage AI fix jobs for automated security fixes
    x-displayName: AI Fix Jobs
    x-group: AI Fix Jobs
  - name: AiTasksService
    description: Manage AI tasks, such as triage, auto-triage, and issue tagging backfill
    x-displayName: Ai Tasks
    x-group: Ai Tasks
  - name: AutofixService
    description: Trigger automated fixes for SAST, AI SAST, and SCA issues.
    x-displayName: Autofix
    x-group: Autofix
  - name: AutomationsService
    description: >-
      Automations are a way to automatically take actions on findings based on
      certain conditions.
    x-displayName: Automations
    x-group: Automations
  - name: AutotriageFeedbackService
    description: Feedback for the quality of autotriage, guidance or autofix
    x-displayName: Autotriage Feedback
    x-group: Autotriage Feedback
  - name: ChecklistService
    description: Manage onboarding checklist
    x-displayName: Onboarding Checklist
    x-group: Onboarding Checklist
  - name: DeploymentProductsService
    description: Manage deployment product configurations.
    x-displayName: Deployment Products
    x-group: Deployment Products
  - name: DeploymentService
    description: Manage deployment and its resources.
    x-displayName: Deployment
    x-group: Deployment
  - name: DeploymentSsoProvidersService
    description: Manage Deployment SSO Providers
    x-displayName: Deployment SSO Providers
    x-group: Deployment SSO Providers
  - name: DeploymentTagService
    description: Assign tags to a deployment.
    x-displayName: Deployment Tags
    x-group: Deployment Tags
  - name: DeploymentsService
    description: >-
      Deployments encapsulate your organization's security organization, with
      multiple projects, policies, and integrations. As the root object of the
      organization, they're similarly the root object of the API.
    x-displayName: Deployments
    x-group: Deployments
  - name: EditorService
    description: Run Semgrep patterns against target code in the editor playground
    x-displayName: Editor
    x-group: Editor
  - name: ExternalTicketingService
    description: APIs that power the External Ticketing experience.
    x-displayName: External Ticketing
    x-group: External Ticketing
  - name: FeatureRolloutsService
    description: View feature flags rolled out to all deployments
    x-displayName: Feature Rollouts
    x-group: Feature Rollouts
  - name: IgnoresService
    description: >-
      API for managing global ignores. See
      https://semgrep.dev/docs/ignoring-files-folders-code
    x-displayName: Global Ignores
    x-group: Global Ignores
  - name: InfrastructureConfigurationsService
    description: Infrastructure configuration information.
    x-displayName: Infrastructure Configurations
    x-group: Infrastructure Configurations
  - name: IssuesService
    description: Manage findings found by Semgrep scans
    x-displayName: Issues
    x-group: Issues
  - name: ManagedScanSettingsService
    description: Settings that affect all of a deployment's managed scans
    x-displayName: Managed Scan Settings
    x-group: Managed Scan Settings
  - name: MemoriesService
    description: Memories help reduce noise from findings.
    x-displayName: Memories
    x-group: Memories
  - name: MiscService
    description: Miscellaneous endpoints
    x-displayName: Misc
    x-group: Misc
  - name: NotificationRulesService
    description: Setup rules to get notified about new findings
    x-displayName: Notification Rules
    x-group: Notification Rules
  - name: NotificationWebhooksService
    description: Manage webhook endpoints for deployment notifications.
    x-displayName: Notification Webhooks
    x-group: Notification Webhooks
  - name: NotificationsService
    description: Notifications show in-app toasts to users.
    x-displayName: Notifications
    x-group: Notifications
  - name: PoliciesService
    description: >-
      **Deprecated.** View and manage the Policies of your organization.


      This API is deprecated. Use the [Policies V2
      API](/api/v2/docs/#tag/PoliciesV2Service) instead. Deployments on the
      Unified Policies model must use Policies V2; this service stops working
      after the migration.
    x-displayName: Policies
    x-group: Policies
  - name: PoliciesV2Service
    description: >-
      Declarative management of detection and remediation policies for
      deployments on the Unified Policies model. Designed for GitOps-style
      reconciliation: read the current bundle, edit it, preview the diff with a
      dry run, then apply it strictly with optimistic concurrency control.
    x-displayName: Policies V2
    x-group: Policies V2
  - name: ProjectManagedScanSettingsService
    description: Settings that affect a specific project's managed scans
    x-displayName: Projects – Managed Scan Settings
    x-group: Projects – Managed Scan Settings
  - name: ProjectsService
    description: >-
      Projects are groups of files that are scanned by Semgrep. These normally
      correspond to repositories.
    x-displayName: Projects
    x-group: Projects
  - name: PublicIssuesService
    description: >-
      Search, inspect, and triage issues generated by Semgrep Agentic Workflows.
      This API does not include issues from other Semgrep products.
    x-displayName: Issues (Semgrep Agentic Workflows)
    x-group: Issues (Semgrep Agentic Workflows)
  - name: ReportsService
    description: APIs for Reporting Dashboards
    x-displayName: Reporting
    x-group: Reporting
  - name: ReviewCommentProductContentService
    description: >-
      Review comment product content is a way to add additional per-product
      information to a review comment.
    x-displayName: Review Comment Product Content
    x-group: Review Comment Product Content
  - name: RuleboardService
    description: >-
      The [Policies API](/api/v2/docs/#tag/PoliciesService) is *strongly*
      recommended. It is also newer than this Ruleboard service. Deployments on
      the Unified Policies model use the [Policies V2
      API](/api/v2/docs/#tag/PoliciesV2Service) instead; this service stops
      working after the migration.


      Manage Ruleboards (sets of policies).
    x-displayName: Ruleboards
    x-group: Ruleboards
  - name: ScansService
    description: View details of scans associated with projects in your organization.
    x-displayName: Scans
    x-group: Scans
  - name: ScmAppsService
    description: >-
      Manage connections to source code management systems (Github, Gitlab,
      etc.)
    x-displayName: Source Code Management (SCM) App
    x-group: Source Code Management (SCM) App
  - name: ScmService
    description: >-
      Manage connections to source code management systems (Github, Gitlab,
      etc.)
    x-displayName: Source Code Management (SCM) Configs
    x-group: Source Code Management (SCM) Configs
  - name: ScmSubscriptionsService
    description: Manage SCM Webhook Subscriptions
    x-displayName: Source Code Management (SCM) Webhooks
    x-group: Source Code Management (SCM) Webhooks
  - name: SlackService
  - name: SmsPackageManagerConfigService
    description: >-
      Manage authentication configurations for package managers used in Supply
      Chain Analysis (SCA) scans.
    x-displayName: Supply Chain - SMS Package Manager Configurations
    x-group: Supply Chain - SMS Package Manager Configurations
  - name: SmsScaResolutionConfigService
    description: >-
      Retrieve custom dependency resolution configurations for lockfileless
      scans.
    x-displayName: Supply Chain - SMS SCA Resolution Configurations
    x-group: Supply Chain - SMS SCA Resolution Configurations
  - name: SupplyChain2Service
    description: >-
      The Supply Chain is all of the dependencies of code, rather than the code
      itself. This service gives information about the supply chain.
    x-displayName: Supply Chain
    x-group: Supply Chain
  - name: SupportService
    description: Create and List Support Cases
    x-displayName: Support Service
    x-group: Support Service
  - name: SurveysService
    description: Retrieve and submit company surveys
    x-displayName: Surveys
    x-group: Surveys
  - name: TasksService
    description: >-
      Many tasks are done asynchronously; this service deals with managing async
      tasks.
    x-displayName: Tasks
    x-group: Tasks
  - name: TeamsService
    description: >-
      Teams are used to manage access control for resources within a deployment.
      For more information visit https://semgrep.dev/docs/deployment/teams.
    x-displayName: Teams
    x-group: Teams
  - name: TokenService
    description: >-
      Tokens are used for programmatic access to the Semgrep Cloud Platform
      APIs.
    x-displayName: Tokens
    x-group: Tokens
  - name: UsersService
    description: Manage user accounts, settings, and organization memberships
    x-displayName: Users Auth Service
    x-group: Users Auth Service
  - name: VersionsService
    description: Semgrep version information
    x-displayName: Versions
    x-group: Versions
  - name: WizCredentialService
    description: Manage Wiz credentials
    x-displayName: Wiz Credentials
    x-group: Wiz Credentials
paths:
  /api/issues/{deploymentId}/search:
    post:
      tags:
        - PublicIssuesService
      summary: Search issues
      description: >-
        Search Semgrep Agentic Workflows issues with filtering, sorting, and
        cursor pagination.
      operationId: PublicIssuesService_SearchIssues
      parameters:
        - name: deploymentId
          in: path
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/protos.issues.api.SearchIssuesRequest'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/protos.issues.api.SearchIssuesResponse'
      security:
        - SemgrepWebToken: []
        - SemgrepJWT: []
components:
  schemas:
    protos.issues.api.SearchIssuesRequest:
      type: object
      properties:
        deploymentId:
          type: string
        filters:
          $ref: '#/components/schemas/protos.issues.api.IssueFilters'
        sortField:
          enum:
            - ISSUE_SORT_FIELD_SEVERITY
            - ISSUE_SORT_FIELD_LAST_DETECTED_AT
            - ISSUE_SORT_FIELD_CREATED_AT
            - ISSUE_SORT_FIELD_FILE_PATH
          type: string
          description: |+

            | value | description |
            |-------|---------------|
            | ISSUE_SORT_FIELD_SEVERITY |  |
            | ISSUE_SORT_FIELD_LAST_DETECTED_AT |  |
            | ISSUE_SORT_FIELD_CREATED_AT |  |
            | ISSUE_SORT_FIELD_FILE_PATH |  |

          format: enum
        sortDirection:
          enum:
            - SORT_DIRECTION_ASC
            - SORT_DIRECTION_DESC
          type: string
          description: |+

            | value | description |
            |-------|---------------|
            | SORT_DIRECTION_ASC |  |
            | SORT_DIRECTION_DESC |  |

          format: enum
        limit:
          type: integer
          format: int64
        cursor:
          type: string
    protos.issues.api.SearchIssuesResponse:
      type: object
      properties:
        issues:
          type: array
          items:
            $ref: '#/components/schemas/protos.issues.api.Issue'
        total:
          type: string
        cursor:
          type: string
    protos.issues.api.IssueFilters:
      title: Issue filters
      type: object
      properties:
        ids:
          type: array
          items:
            type: string
        titleQuery:
          type: string
        descriptionQuery:
          type: string
        reasoningQuery:
          type: string
        detectionStates:
          enum:
            - DETECTION_STATE_DETECTED
            - DETECTION_STATE_NOT_DETECTED
            - DETECTION_STATE_VERIFIED_ABSENT
            - DETECTION_STATE_VERIFIED_PRESENT
          type: array
          items:
            enum:
              - DETECTION_STATE_UNSPECIFIED
              - DETECTION_STATE_DETECTED
              - DETECTION_STATE_NOT_DETECTED
              - DETECTION_STATE_VERIFIED_ABSENT
              - DETECTION_STATE_VERIFIED_PRESENT
            type: string
            format: enum
          description: |+

            | value | description |
            |-------|---------------|
            | DETECTION_STATE_DETECTED |  |
            | DETECTION_STATE_NOT_DETECTED |  |
            | DETECTION_STATE_VERIFIED_ABSENT |  |
            | DETECTION_STATE_VERIFIED_PRESENT |  |

        severities:
          enum:
            - SEVERITY_INFO
            - SEVERITY_LOW
            - SEVERITY_MEDIUM
            - SEVERITY_HIGH
            - SEVERITY_CRITICAL
          type: array
          items:
            enum:
              - SEVERITY_UNSPECIFIED
              - SEVERITY_INFO
              - SEVERITY_LOW
              - SEVERITY_MEDIUM
              - SEVERITY_HIGH
              - SEVERITY_CRITICAL
            type: string
            format: enum
          description: |+

            | value | description |
            |-------|---------------|
            | SEVERITY_INFO |  |
            | SEVERITY_LOW |  |
            | SEVERITY_MEDIUM |  |
            | SEVERITY_HIGH |  |
            | SEVERITY_CRITICAL |  |

        triageStates:
          enum:
            - TRIAGE_STATE_IGNORED
            - TRIAGE_STATE_OPEN
            - TRIAGE_STATE_REOPENED
            - TRIAGE_STATE_REVIEWING
            - TRIAGE_STATE_FIXING
            - TRIAGE_STATE_PROVISIONALLY_IGNORED
            - TRIAGE_STATE_FIXED
          type: array
          items:
            enum:
              - TRIAGE_STATE_UNSPECIFIED
              - TRIAGE_STATE_IGNORED
              - TRIAGE_STATE_OPEN
              - TRIAGE_STATE_REOPENED
              - TRIAGE_STATE_REVIEWING
              - TRIAGE_STATE_FIXING
              - TRIAGE_STATE_PROVISIONALLY_IGNORED
              - TRIAGE_STATE_FIXED
            type: string
            format: enum
          description: |+

            | value | description |
            |-------|---------------|
            | TRIAGE_STATE_IGNORED |  |
            | TRIAGE_STATE_OPEN |  |
            | TRIAGE_STATE_REOPENED |  |
            | TRIAGE_STATE_REVIEWING |  |
            | TRIAGE_STATE_FIXING |  |
            | TRIAGE_STATE_PROVISIONALLY_IGNORED |  |
            | TRIAGE_STATE_FIXED |  |

        triageReasons:
          enum:
            - TRIAGE_REASON_FALSE_POSITIVE
            - TRIAGE_REASON_ACCEPTABLE_RISK
            - TRIAGE_REASON_NO_TIME
          type: array
          items:
            enum:
              - TRIAGE_REASON_UNSPECIFIED
              - TRIAGE_REASON_FALSE_POSITIVE
              - TRIAGE_REASON_ACCEPTABLE_RISK
              - TRIAGE_REASON_NO_TIME
            type: string
            format: enum
          description: |+

            | value | description |
            |-------|---------------|
            | TRIAGE_REASON_FALSE_POSITIVE |  |
            | TRIAGE_REASON_ACCEPTABLE_RISK |  |
            | TRIAGE_REASON_NO_TIME |  |

        actions:
          type: array
          items:
            type: string
        workflowIds:
          type: array
          items:
            type: string
        identities:
          type: array
          items:
            type: string
        triggerSources:
          type: array
          items:
            type: string
        projectIds:
          type: array
          items:
            type: string
        refIds:
          type: array
          items:
            type: string
        filePathQuery:
          type: string
        createdAt:
          $ref: '#/components/schemas/protos.issues.api.TimeRange'
        lastDetectedAt:
          $ref: '#/components/schemas/protos.issues.api.TimeRange'
        triagedAt:
          $ref: '#/components/schemas/protos.issues.api.TimeRange'
        workflowJobIds:
          type: array
          items:
            type: string
      description: >-
        Filters for narrowing issue search results. Fields are combined with
        AND; multiple values within a field are combined with OR.
    protos.issues.api.Issue:
      title: Issue
      type: object
      properties:
        id:
          type: string
        deploymentId:
          type: string
        title:
          type: string
        description:
          type: string
        reasoning:
          type: string
        createdAt:
          type: string
          format: date-time
        lastDetectedAt:
          type: string
          format: date-time
        detectionState:
          enum:
            - DETECTION_STATE_DETECTED
            - DETECTION_STATE_NOT_DETECTED
            - DETECTION_STATE_VERIFIED_ABSENT
            - DETECTION_STATE_VERIFIED_PRESENT
          type: string
          description: |+

            | value | description |
            |-------|---------------|
            | DETECTION_STATE_DETECTED |  |
            | DETECTION_STATE_NOT_DETECTED |  |
            | DETECTION_STATE_VERIFIED_ABSENT |  |
            | DETECTION_STATE_VERIFIED_PRESENT |  |

          format: enum
        severity:
          enum:
            - SEVERITY_INFO
            - SEVERITY_LOW
            - SEVERITY_MEDIUM
            - SEVERITY_HIGH
            - SEVERITY_CRITICAL
          type: string
          description: |+

            | value | description |
            |-------|---------------|
            | SEVERITY_INFO |  |
            | SEVERITY_LOW |  |
            | SEVERITY_MEDIUM |  |
            | SEVERITY_HIGH |  |
            | SEVERITY_CRITICAL |  |

          format: enum
        triageState:
          enum:
            - TRIAGE_STATE_IGNORED
            - TRIAGE_STATE_OPEN
            - TRIAGE_STATE_REOPENED
            - TRIAGE_STATE_REVIEWING
            - TRIAGE_STATE_FIXING
            - TRIAGE_STATE_PROVISIONALLY_IGNORED
            - TRIAGE_STATE_FIXED
          type: string
          description: |+

            | value | description |
            |-------|---------------|
            | TRIAGE_STATE_IGNORED |  |
            | TRIAGE_STATE_OPEN |  |
            | TRIAGE_STATE_REOPENED |  |
            | TRIAGE_STATE_REVIEWING |  |
            | TRIAGE_STATE_FIXING |  |
            | TRIAGE_STATE_PROVISIONALLY_IGNORED |  |
            | TRIAGE_STATE_FIXED |  |

          format: enum
        triageReason:
          enum:
            - TRIAGE_REASON_FALSE_POSITIVE
            - TRIAGE_REASON_ACCEPTABLE_RISK
            - TRIAGE_REASON_NO_TIME
          type: string
          description: |+

            | value | description |
            |-------|---------------|
            | TRIAGE_REASON_FALSE_POSITIVE |  |
            | TRIAGE_REASON_ACCEPTABLE_RISK |  |
            | TRIAGE_REASON_NO_TIME |  |

          format: enum
        triagedAt:
          type: string
          format: date-time
        actions:
          type: array
          items:
            type: string
        workflowIds:
          type: array
          items:
            type: string
        identities:
          type: array
          items:
            type: string
        triggerSources:
          type: array
          items:
            type: string
        projectIds:
          type: array
          items:
            type: string
        refIds:
          type: array
          items:
            type: string
        filePaths:
          type: array
          items:
            type: string
        dependencyPaths:
          type: array
          items:
            type: string
        directDependencies:
          type: array
          items:
            type: string
        domains:
          type: array
          items:
            type: string
        cwes:
          type: array
          items:
            type: string
        owasps:
          type: array
          items:
            type: string
      description: An issue generated by a Semgrep Agentic Workflow.
    protos.issues.api.TimeRange:
      type: object
      properties:
        startAt:
          type: string
          format: date-time
        endAt:
          type: string
          format: date-time
  securitySchemes:
    SemgrepWebToken:
      type: http
      description: >-
        Get access to data with your API token. Example header:


        `Authorization: Bearer
        2991e2fb4b540fe75b8f90677b0b892b6314e4961cb001fe6eb452eee248a628`


        The token can be provisioned from the Tokens section in your Settings,
        and requires explicitly enabling `Web API` access.
      scheme: bearer
      bearerFormat: string
    SemgrepJWT:
      type: http
      description: Get access to data with your user's JSON Web Token.
      scheme: bearer
      bearerFormat: string

````