> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Dismiss header recommendation

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Hides one security header recommendation from the app's security scan result, without changing the app's headers. Get the `flag` from `header_recommendations` in [Get security scan](/api-reference/get-security-scan).

The recommendation stays hidden until the next time the app is scanned with [Run security scan](/api-reference/run-security-scan). That scan judges the app's headers again, so the recommendation comes back if it still applies.

The call succeeds without changing anything when the app has never been scanned, when the recommendation is already dismissed, or when `flag` isn't one of the two recommendations. To act on the recommendation instead, turn the setting on with [Update security headers](/api-reference/update-security-headers).

This is limited to 30 requests a minute per app for each workspace's personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json delete /api/apps/{app_id}/security/scan/header-recommendations/{flag}
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/security/scan/header-recommendations/{flag}:
    delete:
      summary: Dismiss header recommendation
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Hides one security header recommendation from the app's security scan
        result, without changing the app's headers. Get the `flag` from
        `header_recommendations` in [Get security
        scan](/api-reference/get-security-scan).


        The recommendation stays hidden until the next time the app is scanned
        with [Run security scan](/api-reference/run-security-scan). That scan
        judges the app's headers again, so the recommendation comes back if it
        still applies.


        The call succeeds without changing anything when the app has never been
        scanned, when the recommendation is already dismissed, or when `flag`
        isn't one of the two recommendations. To act on the recommendation
        instead, turn the setting on with [Update security
        headers](/api-reference/update-security-headers).


        This is limited to 30 requests a minute per app for each workspace's
        personal API keys, so every key in a workspace shares one allowance.
        Some workspaces have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: >-
        dismiss_header_recommendation_api_apps__app_id__security_scan_header_recommendations__flag__delete
      parameters:
        - name: flag
          in: path
          required: true
          schema:
            type: string
            description: >-
              The recommendation to dismiss, as returned in
              `header_recommendations[].flag` by [Get security
              scan](/api-reference/get-security-scan). Either
              `prevent_iframe_embedding` or `restrict_browser_features`.
            title: Flag
          description: >-
            The recommendation to dismiss, as returned in
            `header_recommendations[].flag` by [Get security
            scan](/api-reference/get-security-scan). Either
            `prevent_iframe_embedding` or `restrict_browser_features`.
          example: prevent_iframe_embedding
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      responses:
        '200':
          description: The recommendation is dismissed, or there was nothing to dismiss.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityHeaderRecommendationDismissed'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have editor access to this app, your API key is read-only,
            or you used a workspace API key.
        '404':
          description: App not found.
        '429':
          description: Too many dismissals for this app in the last minute.
components:
  schemas:
    SecurityHeaderRecommendationDismissed:
      properties:
        status:
          type: string
          title: Status
          description: Always `ok`, including when there was nothing to dismiss.
          example: ok
      type: object
      required:
        - status
      title: SecurityHeaderRecommendationDismissed
      description: Confirms the header recommendation is dismissed.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````