> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Internal links on these pages omit the .md extension. Append .md to a docs page URL, or send an Accept: text/markdown header, to get that page as markdown.

# Security

> Scan an app for security problems and act on the findings with the Base44 Apps API

<Note>
  The Apps API is in beta. Its endpoints and responses may change.
</Note>

These endpoints run a security scan on an app, read what it found, and act on the recommendations. See [Running a security scan](/Setting-up-your-app/running-a-security-scan) for the same feature in the Base44 online app editor.

## Run and read a scan

[Run security scan](/api-reference/run-security-scan) and [Get security scan](/api-reference/get-security-scan) return the same shape. Read `status` before `result`, because a `result` can be present on a stale scan and absent while one is in progress.

* Run returns the last scan straight away when it still matches the app. Otherwise it starts a scan in the background.
* Get never starts a scan. Poll it while `status` is `pending` or `scanning`.

A 200 from Run doesn't mean a scan ran, so check `status` and the `X-Scan-Source` response header.

## What a scan finds

Findings come in groups, by what the scan looked at.

* `rls_recommendations`: Entities whose row-level security is too open.
* `hardcoded_secrets` and `backend_functions`: Problems in the app's own code and functions.
* `dependency_vulnerabilities`: Vulnerabilities in its npm packages.
* `static_code_findings`: Problems found by reading the code.
* `header_recommendations`: Gaps in the published app's HTTP headers.

## Act on findings

Apply a recommended row-level security rule with [Fix RLS recommendations](/api-reference/fix-rls-recommendations), or change headers with [Update security headers](/api-reference/update-security-headers). To hide a finding instead, use [Ignore security finding](/api-reference/ignore-security-finding), and undo it with [Restore security finding](/api-reference/restore-security-finding).

## Endpoints

### Scan

* [Run security scan](/api-reference/run-security-scan): Scan the app, or return the last scan if it's still current.
* [Get security scan](/api-reference/get-security-scan): Read the latest scan and whether it still reflects the app.

### Recommendations

* [Fix RLS recommendations](/api-reference/fix-rls-recommendations): Apply the recommended row-level security rules to entities you name.
* [Dismiss RLS recommendation](/api-reference/dismiss-rls-recommendation): Remove one entity's recommendation from the scan result.
* [Update security headers](/api-reference/update-security-headers): Change the app's security header settings.
* [Dismiss header recommendation](/api-reference/dismiss-header-recommendation): Hide one header recommendation without changing the headers.
* [Enable core integration protection](/api-reference/enable-core-integration-protection): Require calls to Base44's built-in integrations to come from backend functions.

### Ignore findings

* [Ignore security finding](/api-reference/ignore-security-finding): Keep one finding hidden across rescans.
* [Restore security finding](/api-reference/restore-security-finding): Stop hiding an ignored finding.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.