Skip to main content
The Apps API is in beta. Its endpoints and responses may change.
These endpoints run a security scan on an app, read what it found, and act on the recommendations. See Running a security scan for the same feature in the Base44 online app editor.

Run and read a scan

Run security scan and Get security scan return the same shape. Read status before result, because a result can be present on a stale scan and absent while one is in progress.
  • Run returns the last scan straight away when it still matches the app. Otherwise it starts a scan in the background.
  • Get never starts a scan. Poll it while status is pending or scanning.
A 200 from Run doesn’t mean a scan ran, so check status and the X-Scan-Source response header.

What a scan finds

Findings come in groups, by what the scan looked at.
  • rls_recommendations: Entities whose row-level security is too open.
  • hardcoded_secrets and backend_functions: Problems in the app’s own code and functions.
  • dependency_vulnerabilities: Vulnerabilities in its npm packages.
  • static_code_findings: Problems found by reading the code.
  • header_recommendations: Gaps in the published app’s HTTP headers.

Act on findings

Apply a recommended row-level security rule with Fix RLS recommendations, or change headers with Update security headers. To hide a finding instead, use Ignore security finding, and undo it with Restore security finding.

Endpoints

Scan

Recommendations

Ignore findings