REST API
Automate scans and read results with the Webforta API.
The API is available on Pro and Business plans. Create keys under API keys. Keys are scoped (read, scan), can expire, and are shown only once.
Authentication
curl -H "Authorization: Bearer wf_xxxxxxxx_..." https://webforta.com/api/v1/websitesEndpoints
- GET /api/v1/websites - list websites (scope: read)
- GET /api/v1/websites/{id} - website detail with open finding counts (read)
- GET /api/v1/websites/{id}/scans - scan history, paginated with ?page= and ?per_page= (read)
- POST /api/v1/websites/{id}/scans - start a scan on a verified website; returns 202 (scan)
- GET /api/v1/scans/{id} - scan status, observations and findings (read)
Errors and limits
Errors use JSON: {"error": {"code": "...", "message": "..."}}. Each key is limited to 300 requests per 5 minutes; scan starts share your organization’s scan limits and monthly quota.