Findings
Create a finding
Create a finding. Regular human tokens and purposeless customer automation tokens may create drafts but cannot publish; platform-minted agent-run tokens, verified super-admins, and scoped pentesters may publish. Accepts optional sourceAgentName provenance for agent-authored drafts.
POST
Create a finding
Authorizations
A Tolmo API token, sent as Authorization: Bearer <token>. Either a user token (usr_tok.*, minted by tolmo auth login, scoped to your own permissions) or an org API token created in the Tolmo app, for CI and automation.
Path Parameters
Body
application/json
Required string length:
1 - 512Available options:
critical, high, medium, low, info Maximum string length:
512Maximum string length:
2048Maximum string length:
128Maximum string length:
2048Maximum string length:
2048Maximum string length:
48Maximum array length:
24Maximum string length:
48Maximum string length:
16Maximum string length:
128Maximum string length:
256Pattern:
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Available options:
draft, published Available options:
open, in_review, closed, acknowledged, false_positive, canceled Response
Default Response
Required range:
0 <= x <= 9007199254740991