Last reviewed: 2026-07-28
CodeCleared API overview
Automate CodeCleared scans and project-unit results with Team+ API access, Bearer service tokens, and clear 401, 403, and 402 handling.
Automate scans and results
The CodeCleared API is available on Team and above. Authenticate every request with a Bearer service token, then operate only within the token’s organization and scopes.
Standard scan workflow
- Resolve the connected repository:
GET /v1/repositories/resolve?fullName=owner/repo. - Create a scan with the returned UUID
repositoryIdandcommitHash. - Wait or poll the scan status.
- Read vulnerabilities, SBOMs, licenses, secrets, source-code findings, and scores through the relevant project-unit result endpoints.
Use the project unit that matches the result you need. A repository can contain separate units for lockfiles, secrets, and source code, so a successful scan of one unit does not populate another unit’s results.
Finding triage (ignored findings)
List, create, and remove ignores with dedicated scopes. finding:read / finding:write are not implied by scan:all.
| Method | Path | Scope |
|---|---|---|
GET | /v1/project-units/:id/ignored-findings | finding:read or finding:write |
POST | /v1/project-units/:id/ignored-findings | finding:write — body scope: occurrence | rule | cve |
DELETE | /v1/project-units/:id/ignored-findings/:id | finding:write |
Prefer occurrence. rule and cve are broader and survive rescan. Grant only the scopes the integration needs.
Authentication and response semantics
401 means the token is missing, malformed, expired, or otherwise unauthenticated. 403 means the authenticated token lacks the needed organization, repository, role, or scope. 402 means the plan, eligible credit pool, or MAU license (seat_license_required) does not allow the operation. Do not retry a 402 until entitlement, credits, or licenses change. See Credits and 402.
Safe automation
Store service tokens in a secret manager, never in URLs or logs. Keep scan IDs after a wait timeout and retrieve status later. Resolve repositories before creating scans; scan creation accepts a UUID, not a repository full name.