Skip to main content
PUT
Create or save a draft

Authorizations

Authorization
string
header
required

A Firebase ID token, or a Kalligator API key (kal_…).

Path Parameters

report_id
string<uuid4>
required

A UUIDv4 that you make for a new draft, or the ID of your draft.

Body

application/json
program_id
string
required

The program for the report. You cannot change it after you create the draft.

Pattern: ^[a-z0-9-]{1,80}$
title
string
required

A short title, at most 180 characters.

Maximum string length: 180
asset
string
required

The affected asset, for example a URL, host, app, or repository. At most 1000 characters.

Maximum string length: 1000
description
string
required

Markdown, at most 30000 characters. Use the headings for steps to reproduce, expected behavior, actual behavior, and security impact.

Maximum string length: 30000
revision
integer
required

0 for a new draft. Otherwise the current revision of the report.

Required range: x >= 0
cvss_vector
string
default:""

Optional. Your CVSS 3.1 base vector, for example CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Send an empty string for none.

Maximum string length: 100

Response

Successful Response

id
string
required
program_id
string
required
program_name
string
required
status
enum<string>
required

The report status. See the report lifecycle guide.

Available options:
draft,
triaging,
needs_info,
paused,
human_review,
accepted,
rejected,
duplicate,
insufficient_info,
withdrawn
display_status
string
required

The status text that the website shows.

title
string
required
revision
integer
required

Increases when you save the draft, upload or remove a file, submit, or withdraw. Send the latest value with your next change.

created_at
string | null
required
updated_at
string | null
required
submitted_at
string | null
required
withdrawn_at
string | null
required
asset
string
required
description
string
required
cvss_vector
string
required
attachments
Attachments · object
required

Files on the report, by file ID.

submission
Submission · object | null
required

The frozen copy of the report, files, and program policy at submission. null for a draft.

decision
Decision · object | null
required

The final decision and an optional message. null until a decision.

payout
Payout · object | null

Your reward payment. null until the Kalligator team approves the reward.