curl --request GET \
--url https://api.leen.dev/v1/tprm/findings \
--header 'Authorization: Bearer <token>' \
--header 'X-API-KEY: <api-key>'import requests
url = "https://api.leen.dev/v1/tprm/findings"
headers = {
"X-API-KEY": "<api-key>",
"Authorization": "Bearer <token>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'X-API-KEY': '<api-key>', Authorization: 'Bearer <token>'}
};
fetch('https://api.leen.dev/v1/tprm/findings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.leen.dev/v1/tprm/findings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"X-API-KEY: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.leen.dev/v1/tprm/findings"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-KEY", "<api-key>")
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.leen.dev/v1/tprm/findings")
.header("X-API-KEY", "<api-key>")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.leen.dev/v1/tprm/findings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-KEY"] = '<api-key>'
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"items": [
{
"asset_id": "<string>",
"asset_type": "<string>",
"company": {
"compliance_claimed": [
{
"standard": "<string>",
"last_updated_at": "2023-11-07T05:31:56Z"
}
],
"created_at": "2023-11-07T05:31:56Z",
"date_added": "2023-11-07T05:31:56Z",
"domain": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"industry": "<string>",
"name": "<string>",
"related_portfolios": [
{
"id": "<string>",
"name": "<string>"
}
],
"score": {
"factors": [],
"grade": "<string>",
"rating": 123
},
"size": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"vendor_attributes": {
"id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"data": {
"dashboard_link": "<string>",
"strategy_report_url": "<string>",
"type": "<string>"
},
"updated_at": "2023-11-07T05:31:56Z"
}
},
"connection_attributes": {
"country": "<string>",
"geo_ip_location": "<string>",
"hostnames": [
"<string>"
],
"observed_ips": [
"<string>"
],
"ports": [
123
],
"protocol": "<string>"
},
"created_at": "2023-11-07T05:31:56Z",
"description": "<string>",
"domain": "<string>",
"evidence": {},
"first_seen": "2023-11-07T05:31:56Z",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"last_seen": "2023-11-07T05:31:56Z",
"provider_name": "<string>",
"remediation": "<string>",
"severity": "CRITICAL",
"status": "OPEN",
"status_updated_at": "2023-11-07T05:31:56Z",
"ticket": {
"owner": "<string>",
"status": "<string>",
"ticket_id": "<string>"
},
"title": "<string>",
"type": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"vendor_attributes": {
"id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"data": {
"finding_data": {
"control_id": "<string>",
"detail": "<string>",
"output": "<string>",
"title": "<string>"
}
},
"severity": "<string>",
"status": "<string>",
"type": "<string>",
"updated_at": "2023-11-07T05:31:56Z"
},
"vulnerability_id": "<string>"
}
],
"next_cursor": "<string>",
"previous_cursor": "<string>"
}{
"code": "<string>",
"detail": [
{}
],
"message": "<string>",
"type": "<string>"
}List TPRM Findings
Supports authentication via Bearer token (from /identity/token) or API key + connection ID
curl --request GET \
--url https://api.leen.dev/v1/tprm/findings \
--header 'Authorization: Bearer <token>' \
--header 'X-API-KEY: <api-key>'import requests
url = "https://api.leen.dev/v1/tprm/findings"
headers = {
"X-API-KEY": "<api-key>",
"Authorization": "Bearer <token>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'X-API-KEY': '<api-key>', Authorization: 'Bearer <token>'}
};
fetch('https://api.leen.dev/v1/tprm/findings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.leen.dev/v1/tprm/findings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"X-API-KEY: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.leen.dev/v1/tprm/findings"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-KEY", "<api-key>")
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.leen.dev/v1/tprm/findings")
.header("X-API-KEY", "<api-key>")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.leen.dev/v1/tprm/findings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-KEY"] = '<api-key>'
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"items": [
{
"asset_id": "<string>",
"asset_type": "<string>",
"company": {
"compliance_claimed": [
{
"standard": "<string>",
"last_updated_at": "2023-11-07T05:31:56Z"
}
],
"created_at": "2023-11-07T05:31:56Z",
"date_added": "2023-11-07T05:31:56Z",
"domain": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"industry": "<string>",
"name": "<string>",
"related_portfolios": [
{
"id": "<string>",
"name": "<string>"
}
],
"score": {
"factors": [],
"grade": "<string>",
"rating": 123
},
"size": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"vendor_attributes": {
"id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"data": {
"dashboard_link": "<string>",
"strategy_report_url": "<string>",
"type": "<string>"
},
"updated_at": "2023-11-07T05:31:56Z"
}
},
"connection_attributes": {
"country": "<string>",
"geo_ip_location": "<string>",
"hostnames": [
"<string>"
],
"observed_ips": [
"<string>"
],
"ports": [
123
],
"protocol": "<string>"
},
"created_at": "2023-11-07T05:31:56Z",
"description": "<string>",
"domain": "<string>",
"evidence": {},
"first_seen": "2023-11-07T05:31:56Z",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"last_seen": "2023-11-07T05:31:56Z",
"provider_name": "<string>",
"remediation": "<string>",
"severity": "CRITICAL",
"status": "OPEN",
"status_updated_at": "2023-11-07T05:31:56Z",
"ticket": {
"owner": "<string>",
"status": "<string>",
"ticket_id": "<string>"
},
"title": "<string>",
"type": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"vendor_attributes": {
"id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"data": {
"finding_data": {
"control_id": "<string>",
"detail": "<string>",
"output": "<string>",
"title": "<string>"
}
},
"severity": "<string>",
"status": "<string>",
"type": "<string>",
"updated_at": "2023-11-07T05:31:56Z"
},
"vulnerability_id": "<string>"
}
],
"next_cursor": "<string>",
"previous_cursor": "<string>"
}{
"code": "<string>",
"detail": [
{}
],
"message": "<string>",
"type": "<string>"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
Query Parameters
Company Filter, comma separated
"123e4567-e89b-12d3-a456-426614174000, 123e4567-e89b-12d3-a456-426614174001"
Filter by severity (comma-separated list, e.g., 'CRITICAL,HIGH')
Filter by status (comma-separated list, e.g., 'OPEN,REOPENED')
Filter by type (comma-separated list)
Filter by vendor finding type (comma-separated list, e.g., 'websitesecurity')
Filter findings by vulnerability ID presence. True=with CVE, False=without CVE
Filter by findings first seen after this date
Filter by findings state updated after this date
Filter by findings last seen after this date
Only records whose updated_at is at or after this time. Leen bumps updated_at whenever any field on a record changes, so this is the filter for an incremental sync: it returns records that are new and records that changed, and nothing that has stood still. Example: 2021-01-01T00:00:00+00:00.
"2021-01-01T00:00:00+00:00"
Opaque position of the next page, taken from the previous response. Ignore its contents; it encodes where the walk had reached.
How many records to return per page. The walk is the same either way; a larger page means fewer round trips and more memory per response.
1 <= x <= 500Response
Successful Response
The records on this page.
Show child attributes
Show child attributes
Opaque position of the next page. Pass it back as cursor to continue; null when this is the last page.
Opaque position of the previous page, for walking backwards. Null on the first page.