Overview
The ZeroFlaw API lets you start scans automatically from your development environment – for example on every push, in GitHub Actions, GitLab CI or Jenkins. This ensures security checks become part of your workflow.
Create an API key
- In the dashboard go to "API & Integration".
- Click "Create new key".
- Give the key a name (e.g. "GitHub Actions").
- Copy the key immediately – it's only shown once!
Security
Never share your API key publicly. Store it as a secret in your CI system (e.g. GitHub Secrets).
Start a scan (REST API)
Send a POST request with your code as a ZIP file:
curl -X POST https://zeroflaw.net/api/v1/scans \
-H "Authorization: Bearer YOUR_API_KEY" \
-F "file=@project.zip"
The response contains the scan ID:
{
"id": 42,
"status": "queued",
"kind": "code"
}
Check scan status
curl https://zeroflaw.net/api/v1/scans/42 \
-H "Authorization: Bearer YOUR_API_KEY"
Possible status values: queued → running → done (or error).
Get results
curl https://zeroflaw.net/api/v1/scans/42/findings \
-H "Authorization: Bearer YOUR_API_KEY"
GitHub Actions example
name: Security Scan
on: [push]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Create ZIP
run: zip -r code.zip . -x '.git/*'
- name: Run ZeroFlaw Scan
run: |
RESULT=$(curl -s -X POST https://zeroflaw.net/api/v1/scans \
-H "Authorization: Bearer ${{ secrets.ZEROFLAW_KEY }}" \
-F "file=@code.zip")
echo "$RESULT"
Rate limits
API rate limits depend on your plan:
| Plan | Scans per day | Concurrent scans |
|---|---|---|
| Free | 5 | 1 |
| Pro | 50 | 3 |
| Team | 200 | 5 |
FAQ
Can I use the API for domain scans?
Yes, send a POST to /api/v1/scans with {"target": "example.com", "kind": "live"} instead of a file.
Is there an SDK?
We currently don't offer an SDK. The REST API is simple enough to use directly with curl or any HTTP library of your choice.