> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tolmo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Import third-party findings

> Import findings under a provider and stable source name. Reusing the same provider, source, and external ID updates the existing record. Returns the imported finding IDs.



## OpenAPI

````yaml /api-reference/openapi.json post /api/v1/orgs/{orgSlug}/external-findings
openapi: 3.0.3
info:
  title: Tolmo API
  version: 1.0.0
  description: >-
    The Tolmo REST API. Use an organization API key for automation or a CLI user
    token for user-authenticated operations. Most endpoints are scoped to one
    organization.
servers:
  - url: https://api.tolmo.com
    description: Production
security: []
paths:
  /api/v1/orgs/{orgSlug}/external-findings:
    post:
      tags:
        - external-findings
      summary: Import third-party findings
      description: >-
        Import findings under a provider and stable source name. Reusing the
        same provider, source, and external ID updates the existing record.
        Returns the imported finding IDs.
      operationId: uploadExternalFindings
      parameters:
        - schema:
            type: string
          in: path
          name: orgSlug
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                provider:
                  type: string
                  minLength: 1
                  maxLength: 64
                  pattern: ^[a-z0-9][a-z0-9._-]*$
                source:
                  type: string
                  minLength: 1
                  maxLength: 128
                findings:
                  minItems: 1
                  maxItems: 100
                  type: array
                  items:
                    type: object
                    properties:
                      externalId:
                        type: string
                        minLength: 1
                        maxLength: 512
                      title:
                        type: string
                        minLength: 1
                        maxLength: 10000
                      severity:
                        type: string
                        minLength: 1
                        maxLength: 64
                      status:
                        default: open
                        type: string
                        minLength: 1
                        maxLength: 64
                      kind:
                        default: security_finding
                        type: string
                        minLength: 1
                        maxLength: 128
                      body:
                        nullable: true
                        type: string
                        maxLength: 1000000
                      resourceKey:
                        nullable: true
                        type: string
                        maxLength: 10000
                      ruleId:
                        nullable: true
                        type: string
                        maxLength: 2000
                      ruleName:
                        nullable: true
                        type: string
                        maxLength: 2000
                      originalUrl:
                        nullable: true
                        type: string
                        format: uri
                      firstSeenAt:
                        nullable: true
                        type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
                      lastSeenAt:
                        nullable: true
                        type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
                      raw:
                        default: {}
                        type: object
                        additionalProperties: {}
                    required:
                      - externalId
                      - title
                      - severity
                    additionalProperties: false
              required:
                - provider
                - source
                - findings
              additionalProperties: false
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  sourceId:
                    type: string
                    format: uuid
                    pattern: >-
                      ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                  upserted:
                    type: integer
                    minimum: 0
                    maximum: 9007199254740991
                  items:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        externalId:
                          type: string
                      required:
                        - id
                        - externalId
                      additionalProperties: false
                required:
                  - sourceId
                  - upserted
                  - items
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HttpError'
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HttpError'
      security:
        - bearerAuth: []
components:
  schemas:
    HttpError:
      type: object
      properties:
        statusCode:
          type: number
        code:
          type: string
        error:
          type: string
        message:
          type: string
      title: HttpError
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        A Tolmo API token, sent as `Authorization: Bearer <token>`. Either a
        user token (`usr_tok.*`, minted by `tolmo auth login`, scoped to your
        own permissions) or an org API token created in the Tolmo app, for CI
        and automation.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.