---
title: List scans
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api)

[Vulnerability Scanner](https://developers.cloudflare.com/api/resources/vulnerability_scanner)

[Scans](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/scans)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# List scans

GET/accounts/{account\_id}/vuln\_scanner/scans

Returns all scans for the account.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### P ath ParametersExpand Collapse

account\_id: string

Identifier.

maxLength32

[Link to this property](<#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20account_id%20%3E%20(schema)>)

##### Q uery ParametersExpand Collapse

page: optional number

Page number of paginated results.

minimum1

[Link to this property](<#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page%20%3E%20(schema)>)

per\_page: optional number

Number of results per page.

maximum50

minimum5

[Link to this property](<#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20per_page%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

errors: array of object {code, message, documentation\_url, source }

</summary>

code: number

minimum1000

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: optional string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: optional object {pointer }

</summary>

pointer: optional string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

[Link to this property](<#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20errors>)

<details>

<summary>

messages: array of object {code, message, documentation\_url, source }

</summary>

code: number

minimum1000

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: optional string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: optional object {pointer }

</summary>

pointer: optional string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

[Link to this property](<#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20messages>)

success: true

Whether the API call was successful.

[Link to this property](<#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20success>)

<details>

<summary>

result: optional array of object {id, scan\_type, status, 2 more }

</summary>

id: string

Scan identifier.

formatuuid

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

scan\_type: "bola"

The type of vulnerability scan.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20scan_type">Link to this property</a>

<details>

<summary>

status: "created"or "scheduled"or "planning"or 3 more

Current lifecycle status of the scan.

</summary>

One of the following:

"created"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"scheduled"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"planning"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"running"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"finished"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

"failed"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

target\_environment\_id: string

The target environment this scan runs against.

formatuuid

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20target_environment_id">Link to this property</a>

<details>

<summary>

report: optional object {report, report\_schema\_version }

Vulnerability report produced after the scan completes. The shape depends on the scan type. Present only for finished scans.

</summary>

<details>

<summary>

report: object {summary, tests }

Version 1 of the BOLA vulnerability scan report.

</summary>

<details>

<summary>

summary: object {verdict }

Summary of all steps and findings.

</summary>

<details>

<summary>

verdict: "ok"or "warning"or "inconclusive"

Overall verdict of the vulnerability scan.

</summary>

One of the following:

"ok"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20summary%20%3E%20(property)%20verdict%20%3E%20(member)%200">Link to this property</a>

"warning"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20summary%20%3E%20(property)%20verdict%20%3E%20(member)%201">Link to this property</a>

"inconclusive"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20summary%20%3E%20(property)%20verdict%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20summary%20%3E%20(property)%20verdict">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20summary">Link to this property</a>

<details>

<summary>

tests: array of object {steps, verdict, preflight\_errors }

List of tests that were run.

</summary>

<details>

<summary>

steps: array of object {assertions, errors, request, response }

Steps that were executed.

</summary>

<details>

<summary>

assertions: array of object {description, kind, observed, outcome }

Assertions that were made against the received response.

</summary>

description: string

Human-readable description of the assertion, explaining what was checked.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

kind: object {parameters, type }

Kind of assertion.

</summary>

<details>

<summary>

parameters: object {max, min }

Range of HTTP status codes.

</summary>

max: number

Maximum (inclusive) status code of the range.

maximum65535

minimum0

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(property)%20parameters%20%3E%20(property)%20max">Link to this property</a>

min: number

Minimum (inclusive) status code of the range.

maximum65535

minimum0

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(property)%20parameters%20%3E%20(property)%20min">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(property)%20parameters">Link to this property</a>

type: "http\_status\_within\_range"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20kind">Link to this property</a>

observed: number

Observed value on which the assertion was made.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20observed">Link to this property</a>

<details>

<summary>

outcome: "ok"or "fail"or "inconclusive"

Outcome of the assertion.

</summary>

One of the following:

"ok"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20outcome%20%3E%20(member)%200">Link to this property</a>

"fail"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20outcome%20%3E%20(member)%201">Link to this property</a>

"inconclusive"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20outcome%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions%20%3E%20(items)%20%3E%20(property)%20outcome">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20assertions">Link to this property</a>

<details>

<summary>

errors: optional array of object {description, error\_code }

Errors the step encountered that may explain absent or incomplete fields.

</summary>

description: string

Human-readable error description.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

error\_code: optional number

Numeric error code identifying the class of error, if available.

formatuint32

minimum0

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20error_code">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20errors">Link to this property</a>

<details>

<summary>

request: optional object {credential\_set, header\_names, method, 3 more }

HTTP request that was made, if any.

</summary>

<details>

<summary>

credential\_set: object {id, role }

Credential set that was used.

</summary>

id: string

ID of the credential set.

formatuuid

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20credential_set%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

role: "owner"or "attacker"

Role of the credential set.

</summary>

One of the following:

"owner"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20credential_set%20%3E%20(property)%20role%20%3E%20(member)%200">Link to this property</a>

"attacker"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20credential_set%20%3E%20(property)%20role%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20credential_set%20%3E%20(property)%20role">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20credential_set">Link to this property</a>

header\_names: array of string

Names of headers that were sent.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20header_names">Link to this property</a>

<details>

<summary>

method: "GET"or "DELETE"or "PATCH"or 2 more

HTTP method.

</summary>

One of the following:

"GET"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method%20%3E%20(member)%200">Link to this property</a>

"DELETE"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method%20%3E%20(member)%201">Link to this property</a>

"PATCH"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method%20%3E%20(member)%202">Link to this property</a>

"POST"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method%20%3E%20(member)%203">Link to this property</a>

"PUT"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20method">Link to this property</a>

url: string

Exact and full URL (including host, query parameters) that was requested.

formaturi

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20url">Link to this property</a>

<details>

<summary>

variable\_captures: array of object {json\_path, name }

Variable captures requested for this step.

</summary>

json\_path: string

JSONPath expression used for capture, e.g. <code>"$.id"</code>.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20variable_captures%20%3E%20(items)%20%3E%20(property)%20json_path">Link to this property</a>

name: string

Variable name, e.g. <code>"resource_id"</code>.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20variable_captures%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20variable_captures">Link to this property</a>

body: optional unknown

Request body, if any.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request%20%3E%20(property)%20body">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20request">Link to this property</a>

<details>

<summary>

response: optional object {body, header\_names, status, status\_text }

HTTP response that was received, if any.

</summary>

<details>

<summary>

body: object {kind } or object {contents, kind, truncated } or object {contents, kind, truncated } or object {contents, kind, truncated }

HTTP response body.

</summary>

One of the following:

<details>

<summary>

NotFound object {kind }

No body was received.

</summary>

kind: "not\_found"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%200%20%3E%20(property)%20kind">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

Bytes object {contents, kind, truncated }

Body received but unable to read as UTF-8. Raw bytes, base64-encoded.

</summary>

contents: string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%201%20%3E%20(property)%20contents">Link to this property</a>

kind: "bytes"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%201%20%3E%20(property)%20kind">Link to this property</a>

truncated: boolean

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%201%20%3E%20(property)%20truncated">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

Text object {contents, kind, truncated }

Body received as valid UTF-8 text but not valid JSON.

</summary>

contents: string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%202%20%3E%20(property)%20contents">Link to this property</a>

kind: "text"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%202%20%3E%20(property)%20kind">Link to this property</a>

truncated: boolean

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%202%20%3E%20(property)%20truncated">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

Json object {contents, kind, truncated }

Body received as valid JSON.

</summary>

contents: string

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%203%20%3E%20(property)%20contents">Link to this property</a>

kind: "json"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%203%20%3E%20(property)%20kind">Link to this property</a>

truncated: boolean

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%203%20%3E%20(property)%20truncated">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20body">Link to this property</a>

header\_names: array of string

Names of headers that were received.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20header_names">Link to this property</a>

status: number

HTTP status code.

maximum65535

minimum0

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20status">Link to this property</a>

status\_text: optional string

HTTP status text, if available for the status code.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response%20%3E%20(property)%20status_text">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps%20%3E%20(items)%20%3E%20(property)%20response">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20steps">Link to this property</a>

<details>

<summary>

verdict: "ok"or "warning"or "inconclusive"

Verdict of this single test.

</summary>

One of the following:

"ok"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20verdict%20%3E%20(member)%200">Link to this property</a>

"warning"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20verdict%20%3E%20(member)%201">Link to this property</a>

"inconclusive"

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20verdict%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20verdict">Link to this property</a>

<details>

<summary>

preflight\_errors: optional array of object {description, error\_code }

Errors that prevented step execution.

</summary>

description: string

Human-readable error description.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20preflight_errors%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

error\_code: optional number

Numeric error code identifying the class of error, if available.

formatuint32

minimum0

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20preflight_errors%20%3E%20(items)%20%3E%20(property)%20error_code">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests%20%3E%20(items)%20%3E%20(property)%20preflight_errors">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report%20%3E%20(property)%20tests">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report">Link to this property</a>

report\_schema\_version: "v1"

Version of the report schema.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report%20%3E%20(property)%20report_schema_version">Link to this property</a>

</details>

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(model)%20scan_list_response%20%3E%20(schema)%20%3E%20(property)%20report">Link to this property</a>

</details>

[Link to this property](<#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result>)

<details>

<summary>

result\_info: optional object {count, page, per\_page, 2 more }

</summary>

count: optional number

Total number of results for the requested service.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20count">Link to this property</a>

page: optional number

Current page within paginated list of results.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20page">Link to this property</a>

per\_page: optional number

Number of results per page of results.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20per_page">Link to this property</a>

total\_count: optional number

Total results available without any search parameters.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20total_count">Link to this property</a>

total\_pages: optional number

The number of total pages in the entire result set.

<a href="#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20total_pages">Link to this property</a>

</details>

[Link to this property](<#(resource)%20vulnerability_scanner.scans%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info>)

### List scans

HTTP

HTTPTypeScriptPythonGoTerraform

```
curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/vuln_scanner/scans \
    -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": [
    {
      "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "scan_type": "bola",
      "status": "created",
      "target_environment_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "report": {
        "report": {
          "summary": {
            "verdict": "ok"
          },
          "tests": [
            {
              "steps": [
                {
                  "assertions": [
                    {
                      "description": "description",
                      "kind": {
                        "parameters": {
                          "max": 0,
                          "min": 0
                        },
                        "type": "http_status_within_range"
                      },
                      "observed": 0,
                      "outcome": "ok"
                    }
                  ],
                  "errors": [
                    {
                      "description": "description",
                      "error_code": 0
                    }
                  ],
                  "request": {
                    "credential_set": {
                      "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
                      "role": "owner"
                    },
                    "header_names": [
                      "string"
                    ],
                    "method": "GET",
                    "url": "https://example.com",
                    "variable_captures": [
                      {
                        "json_path": "json_path",
                        "name": "name"
                      }
                    ],
                    "body": {}
                  },
                  "response": {
                    "body": {
                      "kind": "not_found"
                    },
                    "header_names": [
                      "string"
                    ],
                    "status": 0,
                    "status_text": "status_text"
                  }
                }
              ],
              "verdict": "ok",
              "preflight_errors": [
                {
                  "description": "description",
                  "error_code": 0
                }
              ]
            }
          ]
        },
        "report_schema_version": "v1"
      }
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": [
    {
      "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "scan_type": "bola",
      "status": "created",
      "target_environment_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "report": {
        "report": {
          "summary": {
            "verdict": "ok"
          },
          "tests": [
            {
              "steps": [
                {
                  "assertions": [
                    {
                      "description": "description",
                      "kind": {
                        "parameters": {
                          "max": 0,
                          "min": 0
                        },
                        "type": "http_status_within_range"
                      },
                      "observed": 0,
                      "outcome": "ok"
                    }
                  ],
                  "errors": [
                    {
                      "description": "description",
                      "error_code": 0
                    }
                  ],
                  "request": {
                    "credential_set": {
                      "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
                      "role": "owner"
                    },
                    "header_names": [
                      "string"
                    ],
                    "method": "GET",
                    "url": "https://example.com",
                    "variable_captures": [
                      {
                        "json_path": "json_path",
                        "name": "name"
                      }
                    ],
                    "body": {}
                  },
                  "response": {
                    "body": {
                      "kind": "not_found"
                    },
                    "header_names": [
                      "string"
                    ],
                    "status": 0,
                    "status_text": "status_text"
                  }
                }
              ],
              "verdict": "ok",
              "preflight_errors": [
                {
                  "description": "description",
                  "error_code": 0
                }
              ]
            }
          ]
        },
        "report_schema_version": "v1"
      }
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  }
}
```