Developers
API v1
Read your programs and reports from your tooling. Personal keys, limited scopes, instant revocation.
01
Create a key
From your company dashboard: name, scopes, expiry. The secret shows once.
02
Call the API
Authorization: Bearer dk_… header. Your keys only see your programs.
03
Revoke anytime
A compromised key revokes in one click; later calls get 401.
Endpoints
Your programs (admin: all).
GET /api/v1/programs
curl https://defenz.org/api/v1/programs \ -H "Authorization: Bearer dk_xxx"
Reports on your programs, filterable by status and severity, paginated.
GET /api/v1/reports
curl "https://defenz.org/api/v1/reports?status=TRIAGED&pageSize=20" \ -H "Authorization: Bearer dk_xxx"
- → Scopes: programs:read, reports:read. Out of scope: 403.
- → Limit: 120 requests/minute per key.
- → Never commit a secret. Store it in a vault.
Outbound webhooks
Receive report.created, report.status_changed and payout.status_changed on your HTTPS URL, signed with HMAC-SHA256.
Events: report.created · report.status_changed · payout.status_changed.
Verify X-Defenz-Signature (hex sha256 of timestamp.body), tolerating ±5 minutes on X-Defenz-Timestamp.
import hmac
def valid(secret: str, ts: str, body: bytes, sig: str) -> bool:
mac = "sha256=" + hmac.new(secret.encode(), f"{ts}.".encode() + body, "sha256").hexdigest()
return hmac.compare_digest(mac, sig)Roadmap
Upcoming integrations
These integrations are committed but not shipped. Nothing here is dated: a date is published only once the integration is in production.
- JiraPlanned
- GitHubPlanned
- SlackPlanned
- ServiceNowPlanned
- SIEM exportPlanned
- OpenAPI / Postman specPlanned
Need a sandbox key to try the API without production scopes?
Get a sandbox keyNeed writes or outbound webhooks?
Talk integration