---
title: Create scan
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Vulnerability Scanner](https://developers.cloudflare.com/api/go/resources/vulnerability_scanner)

[Scans](https://developers.cloudflare.com/api/go/resources/vulnerability_scanner/subresources/scans)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Create scan

client.VulnerabilityScanner.Scans.New(ctx, params) (\*[ScanNewResponse](<https://developers.cloudflare.com/api/go/resources/vulnerability_scanner#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/vuln\_scanner/scans

Creates and starts a new vulnerability scan. The response may include non-fatal warnings in the `messages` array.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### ParametersExpand Collapse

<details>

<summary>

params ScanNewParams

</summary>

AccountID param.Field\[string]

Path param: Identifier.

maxLength32

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20account_id">Link to this property</a>

<details>

<summary>

CredentialSets param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/vulnerability_scanner/subresources/scans/methods/create#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20credential_sets%20%3E%20(schema)">ScanNewParamsCredentialSets</a>]

Body param: Credential set references for a BOLA scan. The scanner uses the <code>owner</code> credentials for legitimate requests and the <code>attacker</code> credentials to attempt unauthorized access.

</summary>

Attacker string

Credential set ID for the attacker.

formatuuid

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20credential_sets%20%3E%20(schema)%20%3E%20(property)%20attacker">Link to this property</a>

Owner string

Credential set ID for the resource owner.

formatuuid

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20credential_sets%20%3E%20(schema)%20%3E%20(property)%20owner">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20credential_sets">Link to this property</a>

OpenAPI param.Field\[string]

Body param: OpenAPI schema definition for the API under test. The scanner uses this to discover endpoints and construct requests.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20open_api">Link to this property</a>

<details>

<summary>

ScanType param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/vulnerability_scanner/subresources/scans/methods/create#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20scan_type%20%3E%20(schema)">ScanNewParamsScanType</a>]

Body param

</summary>

const ScanNewParamsScanTypeBOLA <a href="https://developers.cloudflare.com/api/go/resources/vulnerability_scanner/subresources/scans/methods/create#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20scan_type%20%3E%20(schema)">ScanNewParamsScanType</a> = "bola"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20scan_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20scan_type">Link to this property</a>

TargetEnvironmentID param.Field\[string]

Body param: The target environment to scan.

formatuuid

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20target_environment_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20create%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type ScanNewResponse struct{…}

</summary>

ID string

Scan identifier.

formatuuid

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

ScanType ScanNewResponseScanType

The type of vulnerability scan.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20scan_type">Link to this property</a>

<details>

<summary>

Status ScanNewResponseStatus

Current lifecycle status of the scan.

</summary>

One of the following:

const ScanNewResponseStatusCreated ScanNewResponseStatus = "created"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

const ScanNewResponseStatusScheduled ScanNewResponseStatus = "scheduled"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

const ScanNewResponseStatusPlanning ScanNewResponseStatus = "planning"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

const ScanNewResponseStatusRunning ScanNewResponseStatus = "running"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

const ScanNewResponseStatusFinished ScanNewResponseStatus = "finished"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

const ScanNewResponseStatusFailed ScanNewResponseStatus = "failed"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

TargetEnvironmentID string

The target environment this scan runs against.

formatuuid

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20target_environment_id">Link to this property</a>

<details>

<summary>

Report ScanNewResponseReportOptional

Vulnerability report produced after the scan completes. The shape depends on the scan type. Present only for finished scans.

</summary>

<details>

<summary>

Report ScanNewResponseReportReport

Version 1 of the BOLA vulnerability scan report.

</summary>

<details>

<summary>

Summary ScanNewResponseReportReportSummary

Summary of all steps and findings.

</summary>

<details>

<summary>

Verdict ScanNewResponseReportReportSummaryVerdict

Overall verdict of the vulnerability scan.

</summary>

One of the following:

const ScanNewResponseReportReportSummaryVerdictOk ScanNewResponseReportReportSummaryVerdict = "ok"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20summary%20%3E%20(property)%20verdict%20%3E%20(member)%200">Link to this property</a>

const ScanNewResponseReportReportSummaryVerdictWarning ScanNewResponseReportReportSummaryVerdict = "warning"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20summary%20%3E%20(property)%20verdict%20%3E%20(member)%201">Link to this property</a>

const ScanNewResponseReportReportSummaryVerdictInconclusive ScanNewResponseReportReportSummaryVerdict = "inconclusive"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20summary%20%3E%20(property)%20verdict%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20summary%20%3E%20(property)%20verdict">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20summary">Link to this property</a>

<details>

<summary>

Tests \[]ScanNewResponseReportReportTest

List of tests that were run.

</summary>

<details>

<summary>

Steps \[]ScanNewResponseReportReportTestsStep

Steps that were executed.

</summary>

<details>

<summary>

Assertions \[]ScanNewResponseReportReportTestsStepsAssertion

Assertions that were made against the received response.

</summary>

Description string

Human-readable description of the assertion, explaining what was checked.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

Kind ScanNewResponseReportReportTestsStepsAssertionsKind

Kind of assertion.

</summary>

<details>

<summary>

Parameters ScanNewResponseReportReportTestsStepsAssertionsKindParameters

Range of HTTP status codes.

</summary>

Max int64

Maximum (inclusive) status code of the range.

maximum65535

minimum0

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(property)%20parameters%20%3E%20(property)%20max">Link to this property</a>

Min int64

Minimum (inclusive) status code of the range.

maximum65535

minimum0

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(property)%20parameters%20%3E%20(property)%20min">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(property)%20parameters">Link to this property</a>

Type ScanNewResponseReportReportTestsStepsAssertionsKindType

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20kind">Link to this property</a>

Observed int64

Observed value on which the assertion was made.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20observed">Link to this property</a>

<details>

<summary>

Outcome ScanNewResponseReportReportTestsStepsAssertionsOutcome

Outcome of the assertion.

</summary>

One of the following:

const ScanNewResponseReportReportTestsStepsAssertionsOutcomeOk ScanNewResponseReportReportTestsStepsAssertionsOutcome = "ok"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20outcome%20%3E%20(member)%200">Link to this property</a>

const ScanNewResponseReportReportTestsStepsAssertionsOutcomeFail ScanNewResponseReportReportTestsStepsAssertionsOutcome = "fail"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20outcome%20%3E%20(member)%201">Link to this property</a>

const ScanNewResponseReportReportTestsStepsAssertionsOutcomeInconclusive ScanNewResponseReportReportTestsStepsAssertionsOutcome = "inconclusive"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20outcome%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20outcome">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions">Link to this property</a>

<details>

<summary>

Errors \[]ScanNewResponseReportReportTestsStepsErrorOptional

Errors the step encountered that may explain absent or incomplete fields.

</summary>

Description string

Human-readable error description.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

ErrorCode int64Optional

Numeric error code identifying the class of error, if available.

formatuint32

minimum0

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20error_code">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20errors">Link to this property</a>

<details>

<summary>

Request ScanNewResponseReportReportTestsStepsRequestOptional

HTTP request that was made, if any.

</summary>

<details>

<summary>

CredentialSet ScanNewResponseReportReportTestsStepsRequestCredentialSet

Credential set that was used.

</summary>

ID string

ID of the credential set.

formatuuid

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20credential_set%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Role ScanNewResponseReportReportTestsStepsRequestCredentialSetRole

Role of the credential set.

</summary>

One of the following:

const ScanNewResponseReportReportTestsStepsRequestCredentialSetRoleOwner ScanNewResponseReportReportTestsStepsRequestCredentialSetRole = "owner"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20credential_set%20%3E%20(property)%20role%20%3E%20(member)%200">Link to this property</a>

const ScanNewResponseReportReportTestsStepsRequestCredentialSetRoleAttacker ScanNewResponseReportReportTestsStepsRequestCredentialSetRole = "attacker"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20credential_set%20%3E%20(property)%20role%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20credential_set%20%3E%20(property)%20role">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20credential_set">Link to this property</a>

HeaderNames \[]string

Names of headers that were sent.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20header_names">Link to this property</a>

<details>

<summary>

Method ScanNewResponseReportReportTestsStepsRequestMethod

HTTP method.

</summary>

One of the following:

const ScanNewResponseReportReportTestsStepsRequestMethodGet ScanNewResponseReportReportTestsStepsRequestMethod = "GET"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method%20%3E%20(member)%200">Link to this property</a>

const ScanNewResponseReportReportTestsStepsRequestMethodDelete ScanNewResponseReportReportTestsStepsRequestMethod = "DELETE"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method%20%3E%20(member)%201">Link to this property</a>

const ScanNewResponseReportReportTestsStepsRequestMethodPatch ScanNewResponseReportReportTestsStepsRequestMethod = "PATCH"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method%20%3E%20(member)%202">Link to this property</a>

const ScanNewResponseReportReportTestsStepsRequestMethodPost ScanNewResponseReportReportTestsStepsRequestMethod = "POST"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method%20%3E%20(member)%203">Link to this property</a>

const ScanNewResponseReportReportTestsStepsRequestMethodPut ScanNewResponseReportReportTestsStepsRequestMethod = "PUT"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method">Link to this property</a>

URL string

Exact and full URL (including host, query parameters) that was requested.

formaturi

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20url">Link to this property</a>

<details>

<summary>

VariableCaptures \[]ScanNewResponseReportReportTestsStepsRequestVariableCapture

Variable captures requested for this step.

</summary>

JsonPath string

JSONPath expression used for capture, e.g. <code>"$.id"</code>.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20variable_captures%20%3E%20(items)%20%3E%20(property)%20json_path">Link to this property</a>

Name string

Variable name, e.g. <code>"resource_id"</code>.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20variable_captures%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20variable_captures">Link to this property</a>

Body unknownOptional

Request body, if any.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20body">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request">Link to this property</a>

<details>

<summary>

Response ScanNewResponseReportReportTestsStepsResponseOptional

HTTP response that was received, if any.

</summary>

<details>

<summary>

Body ScanNewResponseReportReportTestsStepsResponseBody

HTTP response body.

</summary>

One of the following:

<details>

<summary>

type ScanNewResponseReportReportTestsStepsResponseBodyVulnScannerBOLABodyResponseNotFound struct{…}

No body was received.

</summary>

Kind ScanNewResponseReportReportTestsStepsResponseBodyVulnScannerBOLABodyResponseNotFoundKind

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%200%20%3E%20(property)%20kind">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

type ScanNewResponseReportReportTestsStepsResponseBodyVulnScannerBOLABodyResponseBytes struct{…}

Body received but unable to read as UTF-8. Raw bytes, base64-encoded.

</summary>

Contents string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%201%20%3E%20(property)%20contents">Link to this property</a>

Kind ScanNewResponseReportReportTestsStepsResponseBodyVulnScannerBOLABodyResponseBytesKind

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%201%20%3E%20(property)%20kind">Link to this property</a>

Truncated bool

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%201%20%3E%20(property)%20truncated">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type ScanNewResponseReportReportTestsStepsResponseBodyVulnScannerBOLABodyResponseText struct{…}

Body received as valid UTF-8 text but not valid JSON.

</summary>

Contents string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%202%20%3E%20(property)%20contents">Link to this property</a>

Kind ScanNewResponseReportReportTestsStepsResponseBodyVulnScannerBOLABodyResponseTextKind

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%202%20%3E%20(property)%20kind">Link to this property</a>

Truncated bool

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%202%20%3E%20(property)%20truncated">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type ScanNewResponseReportReportTestsStepsResponseBodyVulnScannerBOLABodyResponseJson struct{…}

Body received as valid JSON.

</summary>

Contents string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%203%20%3E%20(property)%20contents">Link to this property</a>

Kind ScanNewResponseReportReportTestsStepsResponseBodyVulnScannerBOLABodyResponseJsonKind

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%203%20%3E%20(property)%20kind">Link to this property</a>

Truncated bool

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%203%20%3E%20(property)%20truncated">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body">Link to this property</a>

HeaderNames \[]string

Names of headers that were received.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20header_names">Link to this property</a>

Status int64

HTTP status code.

maximum65535

minimum0

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20status">Link to this property</a>

StatusText stringOptional

HTTP status text, if available for the status code.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20status_text">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps">Link to this property</a>

<details>

<summary>

Verdict ScanNewResponseReportReportTestsVerdict

Verdict of this single test.

</summary>

One of the following:

const ScanNewResponseReportReportTestsVerdictOk ScanNewResponseReportReportTestsVerdict = "ok"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20verdict%20%3E%20(member)%200">Link to this property</a>

const ScanNewResponseReportReportTestsVerdictWarning ScanNewResponseReportReportTestsVerdict = "warning"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20verdict%20%3E%20(member)%201">Link to this property</a>

const ScanNewResponseReportReportTestsVerdictInconclusive ScanNewResponseReportReportTestsVerdict = "inconclusive"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20verdict%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20verdict">Link to this property</a>

<details>

<summary>

PreflightErrors \[]ScanNewResponseReportReportTestsPreflightErrorOptional

Errors that prevented step execution.

</summary>

Description string

Human-readable error description.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20preflight_errors%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

ErrorCode int64Optional

Numeric error code identifying the class of error, if available.

formatuint32

minimum0

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20preflight_errors%20%3E%20(items)%20%3E%20(property)%20error_code">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20preflight_errors">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report">Link to this property</a>

ReportSchemaVersion ScanNewResponseReportReportSchemaVersion

Version of the report schema.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report_schema_version">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)%20%3E%20(property)%20report">Link to this property</a>

</details>

[Link to this property](<#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20ScanNewResponse%20%3E%20(schema)>)

### Create scan

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/option"
  "github.com/cloudflare/cloudflare-go/vulnerability_scanner"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  scan, err := client.VulnerabilityScanner.Scans.New(context.TODO(), vulnerability_scanner.ScanNewParams{
    AccountID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
    CredentialSets: cloudflare.F(vulnerability_scanner.ScanNewParamsCredentialSets{
      Attacker: cloudflare.F("182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e"),
      Owner: cloudflare.F("182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e"),
    }),
    OpenAPI: cloudflare.F("open_api"),
    ScanType: cloudflare.F(vulnerability_scanner.ScanNewParamsScanTypeBOLA),
    TargetEnvironmentID: cloudflare.F("182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", scan.ID)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "scan_type": "bola",
    "status": "created",
    "target_environment_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "report": {
      "report": {
        "summary": {
          "verdict": "ok"
        },
        "tests": [
          {
            "steps": [
              {
                "assertions": [
                  {
                    "description": "description",
                    "kind": {
                      "parameters": {
                        "max": 0,
                        "min": 0
                      },
                      "type": "http_status_within_range"
                    },
                    "observed": 0,
                    "outcome": "ok"
                  }
                ],
                "errors": [
                  {
                    "description": "description",
                    "error_code": 0
                  }
                ],
                "request": {
                  "credential_set": {
                    "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
                    "role": "owner"
                  },
                  "header_names": [
                    "string"
                  ],
                  "method": "GET",
                  "url": "https://example.com",
                  "variable_captures": [
                    {
                      "json_path": "json_path",
                      "name": "name"
                    }
                  ],
                  "body": {}
                },
                "response": {
                  "body": {
                    "kind": "not_found"
                  },
                  "header_names": [
                    "string"
                  ],
                  "status": 0,
                  "status_text": "status_text"
                }
              }
            ],
            "verdict": "ok",
            "preflight_errors": [
              {
                "description": "description",
                "error_code": 0
              }
            ]
          }
        ]
      },
      "report_schema_version": "v1"
    }
  },
  "result_info": {}
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "scan_type": "bola",
    "status": "created",
    "target_environment_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "report": {
      "report": {
        "summary": {
          "verdict": "ok"
        },
        "tests": [
          {
            "steps": [
              {
                "assertions": [
                  {
                    "description": "description",
                    "kind": {
                      "parameters": {
                        "max": 0,
                        "min": 0
                      },
                      "type": "http_status_within_range"
                    },
                    "observed": 0,
                    "outcome": "ok"
                  }
                ],
                "errors": [
                  {
                    "description": "description",
                    "error_code": 0
                  }
                ],
                "request": {
                  "credential_set": {
                    "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
                    "role": "owner"
                  },
                  "header_names": [
                    "string"
                  ],
                  "method": "GET",
                  "url": "https://example.com",
                  "variable_captures": [
                    {
                      "json_path": "json_path",
                      "name": "name"
                    }
                  ],
                  "body": {}
                },
                "response": {
                  "body": {
                    "kind": "not_found"
                  },
                  "header_names": [
                    "string"
                  ],
                  "status": 0,
                  "status_text": "status_text"
                }
              }
            ],
            "verdict": "ok",
            "preflight_errors": [
              {
                "description": "description",
                "error_code": 0
              }
            ]
          }
        ]
      },
      "report_schema_version": "v1"
    }
  },
  "result_info": {}
}
```