Skip to main content
DEFENZ

Developers

API v1

Read your programs and reports from your tooling. Personal keys, limited scopes, instant revocation.

  1. 01

    Create a key

    From your company dashboard: name, scopes, expiry. The secret shows once.

  2. 02

    Call the API

    Authorization: Bearer dk_… header. Your keys only see your programs.

  3. 03

    Revoke anytime

    A compromised key revokes in one click; later calls get 401.

Endpoints

Your programs (admin: all).

GET /api/v1/programs

curl https://defenz.org/api/v1/programs \
  -H "Authorization: Bearer dk_xxx"

Reports on your programs, filterable by status and severity, paginated.

GET /api/v1/reports

curl "https://defenz.org/api/v1/reports?status=TRIAGED&pageSize=20" \
  -H "Authorization: Bearer dk_xxx"
  • → Scopes: programs:read, reports:read. Out of scope: 403.
  • → Limit: 120 requests/minute per key.
  • → Never commit a secret. Store it in a vault.

Outbound webhooks

Receive report.created, report.status_changed and payout.status_changed on your HTTPS URL, signed with HMAC-SHA256.

Events: report.created · report.status_changed · payout.status_changed.

Verify X-Defenz-Signature (hex sha256 of timestamp.body), tolerating ±5 minutes on X-Defenz-Timestamp.

import hmac

def valid(secret: str, ts: str, body: bytes, sig: str) -> bool:
    mac = "sha256=" + hmac.new(secret.encode(), f"{ts}.".encode() + body, "sha256").hexdigest()
    return hmac.compare_digest(mac, sig)

Roadmap

Upcoming integrations

These integrations are committed but not shipped. Nothing here is dated: a date is published only once the integration is in production.

  • JiraPlanned
  • GitHubPlanned
  • SlackPlanned
  • ServiceNowPlanned
  • SIEM exportPlanned
  • OpenAPI / Postman specPlanned

Need a sandbox key to try the API without production scopes?

Get a sandbox key

Need writes or outbound webhooks?

Talk integration