Create or save a draft
Creates a draft or saves changes to a draft. You choose the report ID: make a new UUIDv4. Because the ID is yours, a retry never makes a duplicate report.
Send revision: 0 for a new draft. After that, send the revision from the last response. If the draft changed in a different session, the API returns 409 revision_conflict with the stored report in current.
You can only edit a report in draft status. You cannot change program_id after you create the draft. Your email must be verified.
Authorizations
A Firebase ID token, or a Kalligator API key (kal_…).
Path Parameters
A UUIDv4 that you make for a new draft, or the ID of your draft.
Body
The program for the report. You cannot change it after you create the draft.
^[a-z0-9-]{1,80}$A short title, at most 180 characters.
180The affected asset, for example a URL, host, app, or repository. At most 1000 characters.
1000Markdown, at most 30000 characters. Use the headings for steps to reproduce, expected behavior, actual behavior, and security impact.
300000 for a new draft. Otherwise the current revision of the report.
x >= 0Optional. Your CVSS 3.1 base vector, for example CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Send an empty string for none.
100Response
Successful Response
The report status. See the report lifecycle guide.
draft, triaging, needs_info, paused, human_review, accepted, rejected, duplicate, insufficient_info, withdrawn The status text that the website shows.
Increases when you save the draft, upload or remove a file, submit, or withdraw. Send the latest value with your next change.
Files on the report, by file ID.
The frozen copy of the report, files, and program policy at submission. null for a draft.
The final decision and an optional message. null until a decision.
Your reward payment. null until the Kalligator team approves the reward.