The Apps API is in beta. Its endpoints and responses may change.
Run and read a scan
Run security scan and Get security scan return the same shape. Readstatus before result, because a result can be present on a stale scan and absent while one is in progress.
- Run returns the last scan straight away when it still matches the app. Otherwise it starts a scan in the background.
- Get never starts a scan. Poll it while
statusispendingorscanning.
status and the X-Scan-Source response header.
What a scan finds
Findings come in groups, by what the scan looked at.rls_recommendations: Entities whose row-level security is too open.hardcoded_secretsandbackend_functions: Problems in the app’s own code and functions.dependency_vulnerabilities: Vulnerabilities in its npm packages.static_code_findings: Problems found by reading the code.header_recommendations: Gaps in the published app’s HTTP headers.
Act on findings
Apply a recommended row-level security rule with Fix RLS recommendations, or change headers with Update security headers. To hide a finding instead, use Ignore security finding, and undo it with Restore security finding.Endpoints
Scan
- Run security scan: Scan the app, or return the last scan if it’s still current.
- Get security scan: Read the latest scan and whether it still reflects the app.
Recommendations
- Fix RLS recommendations: Apply the recommended row-level security rules to entities you name.
- Dismiss RLS recommendation: Remove one entity’s recommendation from the scan result.
- Update security headers: Change the app’s security header settings.
- Dismiss header recommendation: Hide one header recommendation without changing the headers.
- Enable core integration protection: Require calls to Base44’s built-in integrations to come from backend functions.
Ignore findings
- Ignore security finding: Keep one finding hidden across rescans.
- Restore security finding: Stop hiding an ignored finding.