> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Ignore security finding

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Ignores one finding in the app's security scan, so it stays hidden across rescans for as long as it doesn't change. Get the finding's `fingerprint` from [Get security scan](/api-reference/get-security-scan), and send the list it came from as `finding_type`.

Ignoring doesn't change the app, and it doesn't remove the finding from the scan result. The finding stays in its list, and its fingerprint is added to `ignored_fingerprints`. The Base44 editor hides findings whose fingerprint is there.

A finding gets a new `fingerprint` when what it flags changes, for example when the file it points at is edited. It then shows up again, and the next scan drops the old ignore.

A successful call doesn't confirm that anything was recorded. Nothing changes when the finding is already ignored, when the app has never been scanned, or when `finding_type` isn't one of the five lists. Base44 doesn't check `fingerprint` against the scan result either, so read `ignored_fingerprints` to confirm. Undo it with [Restore security finding](/api-reference/restore-security-finding).

This is limited to 60 requests a minute per app for each workspace's personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json post /api/apps/{app_id}/security/scan/ignore
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/security/scan/ignore:
    post:
      summary: Ignore security finding
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Ignores one finding in the app's security scan, so it stays hidden
        across rescans for as long as it doesn't change. Get the finding's
        `fingerprint` from [Get security
        scan](/api-reference/get-security-scan), and send the list it came from
        as `finding_type`.


        Ignoring doesn't change the app, and it doesn't remove the finding from
        the scan result. The finding stays in its list, and its fingerprint is
        added to `ignored_fingerprints`. The Base44 editor hides findings whose
        fingerprint is there.


        A finding gets a new `fingerprint` when what it flags changes, for
        example when the file it points at is edited. It then shows up again,
        and the next scan drops the old ignore.


        A successful call doesn't confirm that anything was recorded. Nothing
        changes when the finding is already ignored, when the app has never been
        scanned, or when `finding_type` isn't one of the five lists. Base44
        doesn't check `fingerprint` against the scan result either, so read
        `ignored_fingerprints` to confirm. Undo it with [Restore security
        finding](/api-reference/restore-security-finding).


        This is limited to 60 requests a minute per app for each workspace's
        personal API keys, so every key in a workspace shares one allowance.
        Some workspaces have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: ignore_finding_api_apps__app_id__security_scan_ignore_post
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/IgnoreFindingPayload'
      responses:
        '200':
          description: The call was accepted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityFindingIgnoreStatus'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have editor access to this app, your API key is read-only,
            or you used a workspace API key.
        '404':
          description: App not found.
        '422':
          description: >-
            The body is missing or isn't a JSON object, has fields other than
            `fingerprint`, `finding_type`, `file_path`, and `title`, or leaves
            out `fingerprint` or `finding_type`. Also returned when a value
            isn't a string, is longer than its limit, or is empty for
            `fingerprint` or `finding_type`.
        '429':
          description: Too many ignores for this app in the last minute.
components:
  schemas:
    IgnoreFindingPayload:
      properties:
        fingerprint:
          type: string
          maxLength: 128
          minLength: 1
          title: Fingerprint
          description: >-
            The finding's `fingerprint`, as returned by [Get security
            scan](/api-reference/get-security-scan). Up to 128 characters.
          example: 3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e
        finding_type:
          type: string
          maxLength: 64
          minLength: 1
          title: Finding Type
          description: >-
            Which list in [Get security scan](/api-reference/get-security-scan)
            the finding came from. Send `rls` for `rls_recommendations`,
            `secret` for `hardcoded_secrets`, `backend_function` for
            `backend_functions`, `dependency` for `dependency_vulnerabilities`,
            or `static_code` for `static_code_findings`. Any other value is
            accepted and nothing is recorded.
          example: static_code
        file_path:
          type: string
          maxLength: 1024
          title: File Path
          description: >-
            Path of the file the finding points at, kept with the ignore as a
            record of what was ignored. Up to 1,024 characters. Defaults to an
            empty string.
          default: ''
          example: src/pages/Orders.jsx
        title:
          type: string
          maxLength: 2000
          title: Title
          description: >-
            Short name for the finding, kept with the ignore as a record of what
            was ignored. Up to 2,000 characters. Defaults to an empty string.
          default: ''
          example: Order lookup trusts a client-supplied ID
      additionalProperties: false
      type: object
      required:
        - fingerprint
        - finding_type
      title: IgnoreFindingPayload
      description: The security finding to ignore.
    SecurityFindingIgnoreStatus:
      properties:
        status:
          type: string
          title: Status
          description: Always `ok`, including when nothing changed.
          example: ok
      type: object
      required:
        - status
      title: SecurityFindingIgnoreStatus
      description: Confirms the call was accepted.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````