{
  "openapi": "3.0.1",
  "info": {
    "title": "IaC Security Misconfiguration Scanner API",
    "description": "Scan Terraform, Kubernetes, Dockerfile, Helm, CloudFormation, and 15 more Infrastructure-as-Code formats for security misconfigurations. Submit a GitHub repository or ZIP and get normalized Checkov findings plus an automation-ready JSON summary. Start your first scan now. No runner to maintain.",
    "version": "0.1",
    "x-build-id": "b7zWd8yowoDOhgQD8"
  },
  "servers": [
    {
      "url": "https://api.apify.com/v2"
    }
  ],
  "paths": {
    "/acts/kazkn~hosted-iac-policy-scan-api/run-sync-get-dataset-items": {
      "post": {
        "operationId": "run-sync-get-dataset-items-kazkn-hosted-iac-policy-scan-api",
        "x-openai-isConsequential": false,
        "summary": "Executes an Actor, waits for its completion, and returns Actor's dataset items in response.",
        "tags": [
          "Run Actor"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/inputSchema"
              }
            }
          }
        },
        "parameters": [
          {
            "name": "token",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Enter your Apify token here"
          }
        ],
        "responses": {
          "200": {
            "description": "OK"
          }
        }
      }
    },
    "/acts/kazkn~hosted-iac-policy-scan-api/runs": {
      "post": {
        "operationId": "runs-sync-kazkn-hosted-iac-policy-scan-api",
        "x-openai-isConsequential": false,
        "summary": "Executes an Actor and returns information about the initiated run in response.",
        "tags": [
          "Run Actor"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/inputSchema"
              }
            }
          }
        },
        "parameters": [
          {
            "name": "token",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Enter your Apify token here"
          }
        ],
        "responses": {
          "200": {
            "description": "OK",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/runsResponseSchema"
                }
              }
            }
          }
        }
      }
    },
    "/acts/kazkn~hosted-iac-policy-scan-api/run-sync": {
      "post": {
        "operationId": "run-sync-kazkn-hosted-iac-policy-scan-api",
        "x-openai-isConsequential": false,
        "summary": "Executes an Actor, waits for completion, and returns the OUTPUT from Key-value store in response.",
        "tags": [
          "Run Actor"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/inputSchema"
              }
            }
          }
        },
        "parameters": [
          {
            "name": "token",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Enter your Apify token here"
          }
        ],
        "responses": {
          "200": {
            "description": "OK"
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "inputSchema": {
        "type": "object",
        "properties": {
          "sourceType": {
            "title": "Source",
            "enum": [
              "github",
              "zip_upload"
            ],
            "type": "string",
            "description": "Choose one source. GitHub fields and ZIP upload cannot be used together.",
            "default": "github"
          },
          "repositoryUrl": {
            "title": "GitHub repository",
            "type": "string",
            "description": "Paste https://github.com/{owner}/{repository}. Do not add a token, query, branch, or file path.",
            "default": "https://github.com/DataKazKN/iac-security-scan-examples"
          },
          "repositoryRef": {
            "title": "Git ref (optional)",
            "maxLength": 128,
            "type": "string",
            "description": "Enter a branch, tag, or commit. Public sources should use a full 40-character commit SHA so the same files are scanned again (maximum 128 characters).",
            "default": "ad600c04599f8a1d353639252ee12d2a5976a732"
          },
          "subdirectory": {
            "title": "Folder to scan (optional)",
            "type": "string",
            "description": "Scan only this relative POSIX path from the repository root, for example infra/production. Leave empty to scan the whole repository.",
            "default": "fixtures/terraform"
          },
          "archiveFile": {
            "title": "ZIP file",
            "type": "string",
            "description": "Switch to this only when your source is an uploaded ZIP. Select a ZIP up to 20 MiB; Console stores it as an authenticated Apify Key-Value Store record."
          },
          "githubToken": {
            "title": "Private repository token (optional)",
            "type": "string",
            "description": "Leave this empty for public repositories. For a private repository, use a fine-grained token with read-only Contents access to only that repository."
          },
          "frameworks": {
            "title": "IaC formats",
            "minItems": 1,
            "uniqueItems": true,
            "type": "array",
            "description": "Select the file formats Checkov should scan. Remote configuration and application-code SAST modes are excluded.",
            "items": {
              "type": "string",
              "enum": [
                "ansible",
                "argo_workflows",
                "arm",
                "azure_pipelines",
                "bicep",
                "bitbucket_pipelines",
                "cdk",
                "circleci_pipelines",
                "cloudformation",
                "dockerfile",
                "github_actions",
                "gitlab_ci",
                "helm",
                "kubernetes",
                "kustomize",
                "openapi",
                "serverless",
                "terraform",
                "terraform_json",
                "terraform_plan"
              ],
              "enumTitles": [
                "Ansible",
                "Argo Workflows",
                "Azure Resource Manager (ARM)",
                "Azure Pipelines",
                "Bicep",
                "Bitbucket Pipelines",
                "AWS CDK",
                "CircleCI Pipelines",
                "AWS CloudFormation",
                "Dockerfile",
                "GitHub Actions",
                "GitLab CI",
                "Helm",
                "Kubernetes",
                "Kustomize",
                "OpenAPI",
                "Serverless Framework",
                "Terraform",
                "Terraform JSON",
                "Terraform Plan"
              ]
            },
            "default": [
              "terraform"
            ]
          },
          "policyProfile": {
            "title": "Policy set",
            "enum": [
              "security",
              "all_iac"
            ],
            "type": "string",
            "description": "Keep Security misconfigurations for the normal scan. All IaC policies also includes Checkov CONVENTION checks. Specific Checkov IDs must belong to the selected policy set.",
            "default": "security"
          },
          "checkIds": {
            "title": "Specific Checkov IDs (optional)",
            "maxItems": 100,
            "uniqueItems": true,
            "type": "array",
            "description": "Leave empty to run every matching policy. To narrow the scan, enter up to 100 unique Checkov IDs valid for the selected frameworks and policy set.",
            "items": {
              "type": "string"
            },
            "default": []
          },
          "maxFindings": {
            "title": "Dataset row limit",
            "minimum": 1,
            "maximum": 500,
            "type": "integer",
            "description": "Choose how many failed checks to write to the Dataset. OUTPUT always reports the complete normalized count.",
            "default": 25
          }
        }
      },
      "runsResponseSchema": {
        "type": "object",
        "properties": {
          "data": {
            "type": "object",
            "properties": {
              "id": {
                "type": "string"
              },
              "actId": {
                "type": "string"
              },
              "userId": {
                "type": "string"
              },
              "startedAt": {
                "type": "string",
                "format": "date-time",
                "example": "2025-01-08T00:00:00.000Z"
              },
              "finishedAt": {
                "type": "string",
                "format": "date-time",
                "example": "2025-01-08T00:00:00.000Z"
              },
              "status": {
                "type": "string",
                "example": "READY"
              },
              "meta": {
                "type": "object",
                "properties": {
                  "origin": {
                    "type": "string",
                    "example": "API"
                  },
                  "userAgent": {
                    "type": "string"
                  }
                }
              },
              "stats": {
                "type": "object",
                "properties": {
                  "inputBodyLen": {
                    "type": "integer",
                    "example": 2000
                  },
                  "rebootCount": {
                    "type": "integer",
                    "example": 0
                  },
                  "restartCount": {
                    "type": "integer",
                    "example": 0
                  },
                  "resurrectCount": {
                    "type": "integer",
                    "example": 0
                  },
                  "computeUnits": {
                    "type": "integer",
                    "example": 0
                  }
                }
              },
              "options": {
                "type": "object",
                "properties": {
                  "build": {
                    "type": "string",
                    "example": "latest"
                  },
                  "timeoutSecs": {
                    "type": "integer",
                    "example": 300
                  },
                  "memoryMbytes": {
                    "type": "integer",
                    "example": 1024
                  },
                  "diskMbytes": {
                    "type": "integer",
                    "example": 2048
                  }
                }
              },
              "buildId": {
                "type": "string"
              },
              "defaultKeyValueStoreId": {
                "type": "string"
              },
              "defaultDatasetId": {
                "type": "string"
              },
              "defaultRequestQueueId": {
                "type": "string"
              },
              "buildNumber": {
                "type": "string",
                "example": "1.0.0"
              },
              "containerUrl": {
                "type": "string"
              },
              "usage": {
                "type": "object",
                "properties": {
                  "ACTOR_COMPUTE_UNITS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_WRITES": {
                    "type": "integer",
                    "example": 1
                  },
                  "KEY_VALUE_STORE_LISTS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_INTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_EXTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_SERPS": {
                    "type": "integer",
                    "example": 0
                  }
                }
              },
              "usageTotalUsd": {
                "type": "number",
                "example": 0.00005
              },
              "usageUsd": {
                "type": "object",
                "properties": {
                  "ACTOR_COMPUTE_UNITS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_WRITES": {
                    "type": "number",
                    "example": 0.00005
                  },
                  "KEY_VALUE_STORE_LISTS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_INTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_EXTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_SERPS": {
                    "type": "integer",
                    "example": 0
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}