v2

latestOpenAPI 3.0.1private2026-07-2667209320.4 KB
Scan Results

Bulk add notes to findings by hash

Bulk add notes to findings by their finding hash within a single application environment. Unlike the full triage endpoint, this endpoint adds notes only — it does not change finding statuses.

Finding Hashes

Finding hashes are SHA-256 identifiers that uniquely identify a finding across scans. You can discover finding hashes from:

  • GET /api/v1/reports/org/{orgId}/findings — the findingHash field on each finding
  • GET /api/v1/scan/{scanId}/alert/{pluginId} — the findingHash field on each alert URI

Behavior

  • The status field in each action is silently ignored — only the note is applied. No triage status is changed by this endpoint.
  • Each action must include a non-blank note.
  • This endpoint is available to all authenticated org members without any feature flag requirement.

Limits

  • Maximum 100 actions per request
  • One request per organization/application/environment combination

Partial Success

The endpoint always returns HTTP 200 for valid requests. Individual action failures (e.g., finding hash not found) are reported per-result with success: false and an error message. Successful actions are still applied even if some fail.

🧾 Audited This is recorded as ALERT_RULE_TRIAGED User Activity.

post/api/v1/org/{orgId}/app/{appId}/env/{envId}/findings/triage/notes

Path parameters

orgIdstring uuid required

UUID identifier for this StackHawk Organization.

appIdstring uuid required

UUID identifier for this StackHawk Application.

envIdstring uuid required

UUID identifier for this StackHawk Environment.

Request body

applicationIdstring

The application containing the findings.

environmentIdstring

The environment where the findings were detected.

organizationIdstring

The organization that owns the application.

userIdstring

The user performing the triage actions (inferred from API key, not user-supplied).

Response

Response from bulk triage — echoes the result of each requested action.

applicationIdstring

The application ID.

environmentIdstring

The environment ID.

organizationIdstring

The organization ID.