Skip to content

Preview integration resources as risks

GET
/v1/integrations/{name}/risks/import
name
required
string

Integration vendor short name (e.g. ‘jira’, ‘wiz’, ‘bugcrowd’)

Preview Integration resources as Risks before importing

Paginated list envelope: { "results": [...], "pagination": {...} }.

object
pagination
required

Pagination metadata for external-integration responses. The continuation is a single opaque next_page_token — a base64(JSON) blob the producer round-trips through [crate::views::cursor] — so the page/offset/cursor schemes of the underlying APIs are invisible to the SDK/frontend, which only read total_items for the “X of Y” display.

object
next_page_token

Opaque continuation token. Absent means there are no further pages — the sole end-of-collection signal.

string | null
total_items

Total matching items, when the upstream API reports it. Informational only — never used for loop control. Absent when the API reports no total (e.g. HackerOne, GitHub Dependabot).

integer | null format: int64
results
required

The items on this page.

Array<object>

The core view of an Organization Risk (RSK).

Relational data — threat objectives, comments, incident associations, and tags — is exposed on RiskRegisterEntry, not here.

object
assigned_to
One of:
null
closed_date
string | null format: date-time
control_statement
string | null
created_date
required
string format: date-time
deleted_date
string | null format: date-time
description
required
string
discovered_date
required
string format: date-time
due_date
string | null format: date-time
expected_date
string | null format: date-time
id
required
string
Example
RSK-00001
impact
One of:
null
impact_reasoning
string | null
initially_reported_urgency
One of:
null
likelihood
One of:
null
likelihood_reasoning
string | null
opened_by
required

A User as returned by the API.

Profile images are not embedded — clients fetch them from GET /api/v1/{icon} when icon is Some.

object
email
required
string
first_name
required
string
icon

Relative path to the user’s avatar endpoint, e.g. "users/{id}/avatar?v={hash}". None when the user has no avatar.

string | null
id
required
string format: uuid
last_name
required
string
parent_id

When set, this risk is linked under the named parent risk.

string | null
Example
RSK-00001
remediation_task
string | null
source
string | null
status
required

The status of a risk

string
Allowed values: New Urgency Proposed Remediation Closure Proposed Closed
title
required
string
type
required
string
Allowed values: Code Configuration Control Deficiency Policy Procedural Vulnerability Third-party
updated_by
required

A User as returned by the API.

Profile images are not embedded — clients fetch them from GET /api/v1/{icon} when icon is Some.

object
email
required
string
first_name
required
string
icon

Relative path to the user’s avatar endpoint, e.g. "users/{id}/avatar?v={hash}". None when the user has no avatar.

string | null
id
required
string format: uuid
last_name
required
string
updated_date
required
string format: date-time
urgency
One of:
null