ZeroFlaw

Documentation

API & CI/CD

Overview

The ZeroFlaw API lets you start scans automatically from your development environment – for example on every push, in GitHub Actions, GitLab CI or Jenkins. This ensures security checks become part of your workflow.

Create an API key

  1. In the dashboard go to "API & Integration".
  2. Click "Create new key".
  3. Give the key a name (e.g. "GitHub Actions").
  4. Copy the key immediately – it's only shown once!
Security Never share your API key publicly. Store it as a secret in your CI system (e.g. GitHub Secrets).

Start a scan (REST API)

Send a POST request with your code as a ZIP file:

curl -X POST https://zeroflaw.net/api/v1/scans \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -F "file=@project.zip"

The response contains the scan ID:

{
  "id": 42,
  "status": "queued",
  "kind": "code"
}

Check scan status

curl https://zeroflaw.net/api/v1/scans/42 \
  -H "Authorization: Bearer YOUR_API_KEY"

Possible status values: queued → running → done (or error).

Get results

curl https://zeroflaw.net/api/v1/scans/42/findings \
  -H "Authorization: Bearer YOUR_API_KEY"

GitHub Actions example

name: Security Scan
on: [push]
jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Create ZIP
        run: zip -r code.zip . -x '.git/*'
      - name: Run ZeroFlaw Scan
        run: |
          RESULT=$(curl -s -X POST https://zeroflaw.net/api/v1/scans \
            -H "Authorization: Bearer ${{ secrets.ZEROFLAW_KEY }}" \
            -F "file=@code.zip")
          echo "$RESULT"

Rate limits

API rate limits depend on your plan:

PlanScans per dayConcurrent scans
Free51
Pro503
Team2005

FAQ

Can I use the API for domain scans?

Yes, send a POST to /api/v1/scans with {"target": "example.com", "kind": "live"} instead of a file.

Is there an SDK?

We currently don't offer an SDK. The REST API is simple enough to use directly with curl or any HTTP library of your choice.