Get workflow job findings
curl --request GET \
--url https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings \
--header 'Authorization: Bearer <token>'import requests
url = "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"findings": [
{
"package": {
"ecosystem": "<string>",
"name": "<string>",
"version": "<string>"
},
"domain": "<string>",
"cwe": [
"<string>"
],
"owasp": [
"<string>"
],
"severity": "SEVERITY_CRITICAL",
"reasoning": "<string>",
"evidence": [
{
"trace": {
"steps": [
{
"path": "<string>",
"startLine": 123,
"startColumn": 123,
"endLine": 123,
"endColumn": 123
}
]
},
"snippet": {
"location": {
"path": "<string>",
"startLine": 123,
"startColumn": 123,
"endLine": 123,
"endColumn": 123
},
"text": "<string>"
},
"depPath": {
"chain": [
{
"ecosystem": "<string>",
"name": "<string>",
"version": "<string>"
}
]
},
"rule": {
"id": "<string>",
"name": "<string>"
}
}
],
"extra": {},
"title": "<string>",
"description": "<string>",
"identity": {}
}
]
}Semgrep Agentic Workflows
Get workflow job findings
Returns the findings produced by a completed workflow job.
GET
/
api
/
workflows
/
v1
/
deployments
/
{deploymentId}
/
jobs
/
id
/
{jobId}
/
findings
Get workflow job findings
curl --request GET \
--url https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings \
--header 'Authorization: Bearer <token>'import requests
url = "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/jobs/id/{jobId}/findings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"findings": [
{
"package": {
"ecosystem": "<string>",
"name": "<string>",
"version": "<string>"
},
"domain": "<string>",
"cwe": [
"<string>"
],
"owasp": [
"<string>"
],
"severity": "SEVERITY_CRITICAL",
"reasoning": "<string>",
"evidence": [
{
"trace": {
"steps": [
{
"path": "<string>",
"startLine": 123,
"startColumn": 123,
"endLine": 123,
"endColumn": 123
}
]
},
"snippet": {
"location": {
"path": "<string>",
"startLine": 123,
"startColumn": 123,
"endLine": 123,
"endColumn": 123
},
"text": "<string>"
},
"depPath": {
"chain": [
{
"ecosystem": "<string>",
"name": "<string>",
"version": "<string>"
}
]
},
"rule": {
"id": "<string>",
"name": "<string>"
}
}
],
"extra": {},
"title": "<string>",
"description": "<string>",
"identity": {}
}
]
}This endpoint is experimental. It may change or be removed without notice and is not covered by API stability guarantees.
Authorizations
SemgrepWebTokenSemgrepJWT
Get access to data with your API token. Example header:
Authorization: Bearer 2991e2fb4b540fe75b8f90677b0b892b6314e4961cb001fe6eb452eee248a628
The token can be provisioned from the Tokens section in your Settings, and requires explicitly enabling Web API access.
Path Parameters
The unique numerical identifier of the deployment. Can be found via the Deployments Service or in your Settings in the web UI.
Example:
"1234"
The unique identifier of the workflow job.
Response
200 - application/json
OK
Findings produced by the workflow run, taken from the FindingsReport in the WorkflowResult result.json artifact.
Show child attributes
Show child attributes
Was this page helpful?