Skip to content

Trigger a discovery scan

POST
/api/v1/scans
curl --request POST \
--url https://api.aletheia-ops.com/api/v1/scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "aws_account_id": "example" }'
Media typeapplication/json

POST /scans body

object
aws_account_id
string
Examplegenerated
{
"aws_account_id": "example"
}

Accepted

Media typeapplication/json

Public shape of a discovery run

object
id
string
aws_account_id
string
trigger
string
triggered_by
string
status
string
stats

Are the aggregated counters on a scan

object
seen
integer
created
integer
updated
integer
deleted
integer
api_calls
integer
started_at
string format: date-time
finished_at
string format: date-time
created_at
string format: date-time
Examplegenerated
{
"id": "example",
"aws_account_id": "example",
"trigger": "example",
"triggered_by": "example",
"status": "example",
"stats": {
"seen": 1,
"created": 1,
"updated": 1,
"deleted": 1,
"api_calls": 1
},
"started_at": "2026-04-15T12:00:00Z",
"finished_at": "2026-04-15T12:00:00Z",
"created_at": "2026-04-15T12:00:00Z"
}

The request is malformed or fails validation.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "validation_failed",
"message": "name: must not be blank"
}

No valid credential was presented, or it has expired.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "unauthorized",
"message": "authentication required"
}

Authenticated, but not permitted to perform this action.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "forbidden",
"message": "you do not have permission to perform this action"
}

The request conflicts with the current state.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "email_taken",
"message": "an account with this email already exists"
}

An unexpected failure. Diagnostic detail is logged server-side and deliberately not returned. Quote the X-Request-Id response header when reporting one.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
Exampleinternal_error
{
"code": "internal_error",
"message": "internal server error"
}