{"activeVersionTag":"latest","latestAvailableVersionTag":"latest","collection":{"info":{"_postman_id":"cb72ac78-9f59-4348-88a5-9296a535807c","name":"NopSec API Documentation v2 - Prod","description":"Welcome to the NopSec API!\n\nUsing the NopSec API, you can have visibility into your scanned targets and vulnerabilities, kick off remediation workflows by creating remediation plans, or submit exception requests to formally exclude vulnerabilities from remediation.\n\n# Quick start\n\n1. **Get an API key,** submit a Support Ticket or contact your Customer Success team.\n    \n2. **Pick the base URL**, `https://us2.nopsec.com/api`\n    \n3. **Send the key on every request**, as the `X-NOPSEC-API-KEY` header:\n    \n\n```\ncurl https://us2.nopsec.com/api/remediate/exceptionplan \\\n  -H \"X-NOPSEC-API-KEY: <your-api-key>\"\n\n ```\n\n# What you can do\n\n- **Prioritize** — pull saved column presets and saved queries for vulnerability triage\n    \n- **Exception Plans** — formally exclude vulnerabilities from remediation, with an approval workflow\n    \n- **Remediation Actions** — kick off remediation plans, track their progress, and push tickets to ITSM destinations like Jira\n    \n- **Reports** — generate and download CSV exports of your vulnerability data\n    \n- **Ingestion** — upload asset tags and other data into the platform\n    \n- **AuditLog** — query the audit trail of actions taken in your account\n    \n\n# Prerequisites\n\nTo begin using the NopSec API, you need an active NopSec Account that has been given API access, the API endpoint URL, and the correct credentials and permissions.\n\n## Active Account\n\nA NopSec Account is used to authenticate with the NopSec API.\n\nPlease submit a Service Request or contact your Customer Success team to receive your API Key.\n\n## Permissions\n\nEach user account within the NopSec platform is assigned to one or more Teams. Each Team is assigned a role which the user inherits. These roles dictate the permissions a user has within the platform. Your API Key will inherit the same permissions your user account has and will utilize the highest level of access for each API call.\n\nYou may create a new local user manually or ask your Customer Success team to do so with limited permissions if you prefer to use a service account for your API calls.\n\n## API Server\n\nThe NopSec API has a single endpoint:\n\n- [https://us2.nopsec.com/api](https://us2.nopsec.com/api)\n    \n\n## API Key\n\nPlease submit a Support Ticket or contact your Customer Success Team directly and request an API key.\n\nYou will need to provide this key with all of your API requests via the `X-NOPSEC-API-KEY` header.\n\n# Rate Limits\n\nThe API allows up to **5 requests per second**. Exceeding this returns a `429 Too Many Requests` — back off and retry rather than hammering the API.\n\n# Error Codes\n\nHTTP status codes will be returned in the response header in the event there is an error or unaccepted parameter in the api call. An error message (JSON formatted) will be returned in the response body to help guide you towards creating an acceptable request.\n\n| Code | Meaning |\n| --- | --- |\n| 102 | Processing |\n| 200 | OK |\n| 201 | Created |\n| 204 | No Content |\n| 400 | Bad Request |\n| 401 | Unauthorized |\n| 404 | Not Found |\n| 409 | Conflict |\n| 412 | Precondition Failed |\n| 422 | Unprocessable Entity |\n| 429 | Too Many Requests (more than 5 per second) |\n| 500 | Internal Server Error |\n\n# Limitations\n\nContact your Customer Success Team for details regarding your plan.\n\n# Troubleshooting\n\nBefore using NopSec APIs, we recommend that you familiarize yourself with [the user documentation](https://support.nopsec.com/knowledge). There is a strong correlation between the business logic of NopSec Platform UI and the API.\n\nYou will also find detailed step-by-step instructions for specific use cases, for example, importing asset data and importing scan data.\n\nIf you experience any errors please submit a support ticket in your [customer portal](https://support.nopsec.com/customer-portal).","schema":"https://schema.getpostman.com/json/collection/v2.0.0/collection.json","isPublicCollection":false,"owner":"56962595","team":424191,"collectionId":"cb72ac78-9f59-4348-88a5-9296a535807c","publishedId":"2sBY4Wpca4","public":true,"publicUrl":"https://developer.nopsec.com","privateUrl":"https://go.postman.co/documentation/56962595-cb72ac78-9f59-4348-88a5-9296a535807c","customColor":{"top-bar":"FFFFFF","right-sidebar":"303030","highlight":"FF6C37"},"documentationLayout":"classic-double-column","customisation":{"metaTags":[{"name":"description","value":"This is the official NopSec public API"},{"name":"title","value":"NopSec Public API"}],"appearance":{"default":"system_default","themes":[{"name":"dark","logo":null,"colors":{"top-bar":"212121","right-sidebar":"303030","highlight":"FF6C37"}},{"name":"light","logo":null,"colors":{"top-bar":"FFFFFF","right-sidebar":"303030","highlight":"FF6C37"}}]}},"version":"8.12.5","publishDate":"2026-08-12T16:00:04.000Z","activeVersionTag":"latest","documentationTheme":"light","metaTags":{"title":"NopSec Public API","description":"This is the official NopSec public API"},"logos":{"logoLight":null,"logoDark":null}},"statusCode":200},"environments":[],"user":{"authenticated":false,"permissions":{"publish":false}},"run":{"button":{"js":"https://run.pstmn.io/button.js","css":"https://run.pstmn.io/button.css"}},"web":"https://www.getpostman.com/","team":{"logo":"https://res.cloudinary.com/postman/image/upload/t_team_logo_pubdoc/v1/team/4073408444ad10fed905f75341ab882a6511303f1c476934de051f830032c08a","favicon":"https://res.cloudinary.com/postman/image/upload/v1563221159/team/scu4dqgrpdewscft2fap.ico"},"isEnvFetchError":false,"languages":"[{\"key\":\"csharp\",\"label\":\"C#\",\"variant\":\"HttpClient\"},{\"key\":\"csharp\",\"label\":\"C#\",\"variant\":\"RestSharp\"},{\"key\":\"curl\",\"label\":\"cURL\",\"variant\":\"cURL\"},{\"key\":\"dart\",\"label\":\"Dart\",\"variant\":\"http\"},{\"key\":\"go\",\"label\":\"Go\",\"variant\":\"Native\"},{\"key\":\"http\",\"label\":\"HTTP\",\"variant\":\"HTTP\"},{\"key\":\"java\",\"label\":\"Java\",\"variant\":\"OkHttp\"},{\"key\":\"java\",\"label\":\"Java\",\"variant\":\"Unirest\"},{\"key\":\"javascript\",\"label\":\"JavaScript\",\"variant\":\"Fetch\"},{\"key\":\"javascript\",\"label\":\"JavaScript\",\"variant\":\"jQuery\"},{\"key\":\"javascript\",\"label\":\"JavaScript\",\"variant\":\"XHR\"},{\"key\":\"c\",\"label\":\"C\",\"variant\":\"libcurl\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Axios\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Native\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Request\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Unirest\"},{\"key\":\"objective-c\",\"label\":\"Objective-C\",\"variant\":\"NSURLSession\"},{\"key\":\"ocaml\",\"label\":\"OCaml\",\"variant\":\"Cohttp\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"cURL\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"Guzzle\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"HTTP_Request2\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"pecl_http\"},{\"key\":\"powershell\",\"label\":\"PowerShell\",\"variant\":\"RestMethod\"},{\"key\":\"python\",\"label\":\"Python\",\"variant\":\"http.client\"},{\"key\":\"python\",\"label\":\"Python\",\"variant\":\"Requests\"},{\"key\":\"r\",\"label\":\"R\",\"variant\":\"httr\"},{\"key\":\"r\",\"label\":\"R\",\"variant\":\"RCurl\"},{\"key\":\"ruby\",\"label\":\"Ruby\",\"variant\":\"Net::HTTP\"},{\"key\":\"shell\",\"label\":\"Shell\",\"variant\":\"Httpie\"},{\"key\":\"shell\",\"label\":\"Shell\",\"variant\":\"wget\"},{\"key\":\"swift\",\"label\":\"Swift\",\"variant\":\"URLSession\"}]","languageSettings":[{"key":"csharp","label":"C#","variant":"HttpClient"},{"key":"csharp","label":"C#","variant":"RestSharp"},{"key":"curl","label":"cURL","variant":"cURL"},{"key":"dart","label":"Dart","variant":"http"},{"key":"go","label":"Go","variant":"Native"},{"key":"http","label":"HTTP","variant":"HTTP"},{"key":"java","label":"Java","variant":"OkHttp"},{"key":"java","label":"Java","variant":"Unirest"},{"key":"javascript","label":"JavaScript","variant":"Fetch"},{"key":"javascript","label":"JavaScript","variant":"jQuery"},{"key":"javascript","label":"JavaScript","variant":"XHR"},{"key":"c","label":"C","variant":"libcurl"},{"key":"nodejs","label":"NodeJs","variant":"Axios"},{"key":"nodejs","label":"NodeJs","variant":"Native"},{"key":"nodejs","label":"NodeJs","variant":"Request"},{"key":"nodejs","label":"NodeJs","variant":"Unirest"},{"key":"objective-c","label":"Objective-C","variant":"NSURLSession"},{"key":"ocaml","label":"OCaml","variant":"Cohttp"},{"key":"php","label":"PHP","variant":"cURL"},{"key":"php","label":"PHP","variant":"Guzzle"},{"key":"php","label":"PHP","variant":"HTTP_Request2"},{"key":"php","label":"PHP","variant":"pecl_http"},{"key":"powershell","label":"PowerShell","variant":"RestMethod"},{"key":"python","label":"Python","variant":"http.client"},{"key":"python","label":"Python","variant":"Requests"},{"key":"r","label":"R","variant":"httr"},{"key":"r","label":"R","variant":"RCurl"},{"key":"ruby","label":"Ruby","variant":"Net::HTTP"},{"key":"shell","label":"Shell","variant":"Httpie"},{"key":"shell","label":"Shell","variant":"wget"},{"key":"swift","label":"Swift","variant":"URLSession"}],"languageOptions":[{"label":"C# - HttpClient","value":"csharp - HttpClient - C#"},{"label":"C# - RestSharp","value":"csharp - RestSharp - C#"},{"label":"cURL - cURL","value":"curl - cURL - cURL"},{"label":"Dart - http","value":"dart - http - Dart"},{"label":"Go - Native","value":"go - Native - Go"},{"label":"HTTP - HTTP","value":"http - HTTP - HTTP"},{"label":"Java - OkHttp","value":"java - OkHttp - Java"},{"label":"Java - Unirest","value":"java - Unirest - Java"},{"label":"JavaScript - Fetch","value":"javascript - Fetch - JavaScript"},{"label":"JavaScript - jQuery","value":"javascript - jQuery - JavaScript"},{"label":"JavaScript - XHR","value":"javascript - XHR - JavaScript"},{"label":"C - libcurl","value":"c - libcurl - C"},{"label":"NodeJs - Axios","value":"nodejs - Axios - NodeJs"},{"label":"NodeJs - Native","value":"nodejs - Native - NodeJs"},{"label":"NodeJs - Request","value":"nodejs - Request - NodeJs"},{"label":"NodeJs - Unirest","value":"nodejs - Unirest - NodeJs"},{"label":"Objective-C - NSURLSession","value":"objective-c - NSURLSession - Objective-C"},{"label":"OCaml - Cohttp","value":"ocaml - Cohttp - OCaml"},{"label":"PHP - cURL","value":"php - cURL - PHP"},{"label":"PHP - Guzzle","value":"php - Guzzle - PHP"},{"label":"PHP - HTTP_Request2","value":"php - HTTP_Request2 - PHP"},{"label":"PHP - pecl_http","value":"php - pecl_http - PHP"},{"label":"PowerShell - RestMethod","value":"powershell - RestMethod - PowerShell"},{"label":"Python - http.client","value":"python - http.client - Python"},{"label":"Python - Requests","value":"python - Requests - Python"},{"label":"R - httr","value":"r - httr - R"},{"label":"R - RCurl","value":"r - RCurl - R"},{"label":"Ruby - Net::HTTP","value":"ruby - Net::HTTP - Ruby"},{"label":"Shell - Httpie","value":"shell - Httpie - Shell"},{"label":"Shell - wget","value":"shell - wget - Shell"},{"label":"Swift - URLSession","value":"swift - URLSession - Swift"}],"layoutOptions":[{"value":"classic-single-column","label":"Single Column"},{"value":"classic-double-column","label":"Double Column"}],"versionOptions":[],"environmentOptions":[{"value":"0","label":"No Environment"}],"canonicalUrl":"https://developer.nopsec.com/view/metadata/2sBY4Wpca4"}