Create a project
Create a project in an organization where the account has the necessary role.
curl -X POST "https://app.aegisrunner.com/api/v1/projects" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN" \
-d '{
"name": "John Doe",
"description": "example_string",
"base_url": "example_string",
"orgId": "123e4567-e89b-12d3-a456-426614174000",
"testingAuthorized": true
}'
import requests
import json
url = "https://app.aegisrunner.com/api/v1/projects"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
data = {
"name": "John Doe",
"description": "example_string",
"base_url": "example_string",
"orgId": "123e4567-e89b-12d3-a456-426614174000",
"testingAuthorized": true
}
response = requests.post(url, headers=headers, json=data)
print(response.json())
const response = await fetch("https://app.aegisrunner.com/api/v1/projects", {
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
},
body: JSON.stringify({
"name": "John Doe",
"description": "example_string",
"base_url": "example_string",
"orgId": "123e4567-e89b-12d3-a456-426614174000",
"testingAuthorized": true
})
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
"bytes"
"encoding/json"
)
func main() {
data := []byte(`{
"name": "John Doe",
"description": "example_string",
"base_url": "example_string",
"orgId": "123e4567-e89b-12d3-a456-426614174000",
"testingAuthorized": true
}`)
req, err := http.NewRequest("POST", "https://app.aegisrunner.com/api/v1/projects", bytes.NewBuffer(data))
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://app.aegisrunner.com/api/v1/projects')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Post.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
request.body = '{
"name": "John Doe",
"description": "example_string",
"base_url": "example_string",
"orgId": "123e4567-e89b-12d3-a456-426614174000",
"testingAuthorized": true
}'
response = http.request(request)
puts response.body
{
"id": "123e4567-e89b-12d3-a456-426614174000",
"name": "John Doe",
"status": "example_string"
}
{
"error": "Bad Request",
"message": "The request contains invalid parameters or malformed data",
"code": 400,
"details": [
{
"field": "email",
"message": "Invalid email format"
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Error",
"message": "Plan or usage entitlement prevents the operation.",
"code": 402
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
/projects
Target server for requests. Edit to use your own host.
AegisRunner account session access token. Complete the supported sign-in, security verification, and two-factor flow as required.
The media type of the request body
Project name.
Configured target website.
Organization you can administer.
Attest that the target may be tested. This does not bypass per-scan write controls.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. AegisRunner account session access token. Complete the supported sign-in, security verification, and two-factor flow as required.
Body
Project name.
Configured target website.
Organization you can administer.
Attest that the target may be tested. This does not bypass per-scan write controls.
Responses
Create a project in an organization where the account has the necessary role. The website field is base_url; account creation and testing authorization are separate steps.
Authenticate with an account session as described in Project and testing API. Use resource IDs available to the same organization and project.
For unattended pipelines, use the separately authenticated CI endpoints.