Skip to content
Published

Last reviewed: 2026-07-28

CodeCleared API overview

Automate CodeCleared scans and project-unit results with Team+ API access, Bearer service tokens, and clear 401, 403, and 402 handling.

Automate scans and results

The CodeCleared API is available on Team and above. Authenticate every request with a Bearer service token, then operate only within the token’s organization and scopes.

Standard scan workflow

  1. Resolve the connected repository: GET /v1/repositories/resolve?fullName=owner/repo.
  2. Create a scan with the returned UUID repositoryId and commitHash.
  3. Wait or poll the scan status.
  4. Read vulnerabilities, SBOMs, licenses, secrets, source-code findings, and scores through the relevant project-unit result endpoints.

Use the project unit that matches the result you need. A repository can contain separate units for lockfiles, secrets, and source code, so a successful scan of one unit does not populate another unit’s results.

Finding triage (ignored findings)

List, create, and remove ignores with dedicated scopes. finding:read / finding:write are not implied by scan:all.

MethodPathScope
GET/v1/project-units/:id/ignored-findingsfinding:read or finding:write
POST/v1/project-units/:id/ignored-findingsfinding:write — body scope: occurrence | rule | cve
DELETE/v1/project-units/:id/ignored-findings/:idfinding:write

Prefer occurrence. rule and cve are broader and survive rescan. Grant only the scopes the integration needs.

Authentication and response semantics

401 means the token is missing, malformed, expired, or otherwise unauthenticated. 403 means the authenticated token lacks the needed organization, repository, role, or scope. 402 means the plan, eligible credit pool, or MAU license (seat_license_required) does not allow the operation. Do not retry a 402 until entitlement, credits, or licenses change. See Credits and 402.

Safe automation

Store service tokens in a secret manager, never in URLs or logs. Keep scan IDs after a wait timeout and retrieve status later. Resolve repositories before creating scans; scan creation accepts a UUID, not a repository full name.

API guides