API Reference

Complete REST API reference for taco-api, taco-inbound, and taco-auth endpoints.

This documents the REST API served by taco-api on port 8090. All endpoints return JSON.

Authentication

Public Endpoints (no auth required)

MethodEndpointDescription
POST/api/v1/auth/registerRegister a new user account
POST/api/v1/auth/loginLogin with email/password
POST/api/v1/auth/refreshRefresh an access token
POST/api/v1/auth/logoutLogout (invalidate refresh token)
GET/api/v1/auth/githubInitiate GitHub OAuth flow
GET/api/v1/auth/github/callbackGitHub OAuth callback
GET/api/v1/auth/googleInitiate Google OAuth flow
GET/api/v1/auth/google/callbackGoogle OAuth callback
POST/api/v1/billing/webhookStripe webhook (uses Stripe signature verification)
GET/healthzHealth check

Protected Endpoints

All other endpoints require Authorization: Bearer <jwt_access_token>.


Users

MethodEndpointDescription
GET/api/v1/users/meGet current user profile
PUT/api/v1/users/meUpdate current user profile
PUT/api/v1/users/me/slack-webhookUpdate user-level Slack webhook URL

Subscriptions

MethodEndpointRolesDescription
GET/api/v1/subscriptionsanyList user's subscriptions
POST/api/v1/subscriptionsanyCreate a new subscription
GET/api/v1/subscriptions/:subscription_idowner, admin, memberGet subscription details
PUT/api/v1/subscriptions/:subscription_idowner, adminUpdate subscription
DELETE/api/v1/subscriptions/:subscription_idowner, adminDelete subscription
GET/api/v1/subscriptions/:subscription_id/components/usageowner, admin, memberGet component usage stats
GET/api/v1/subscriptions/:subscription_id/membersowner, admin, memberList subscription members
POST/api/v1/subscriptions/:subscription_id/membersowner, adminInvite a member
PUT/api/v1/subscriptions/:subscription_id/members/:user_idowner, adminUpdate member role
DELETE/api/v1/subscriptions/:subscription_id/members/:user_idowner, adminRemove a member
GET/api/v1/subscriptions/:subscription_id/statsowner, admin, memberGet subscription statistics
PUT/api/v1/subscriptions/:subscription_id/slack-webhookowner, adminUpdate subscription Slack webhook
GET/api/v1/subscriptions/:subscription_id/dashboardowner, admin, memberGet subscription dashboard data

Billing

MethodEndpointRolesDescription
GET/api/v1/subscriptions/:subscription_id/billingowner, admin, memberGet billing status
POST/api/v1/subscriptions/:subscription_id/billing/checkoutowner, adminCreate Stripe checkout session
POST/api/v1/subscriptions/:subscription_id/billing/portalowner, adminCreate Stripe customer portal session

Projects

MethodEndpointRolesDescription
GET/api/v1/subscriptions/:subscription_id/projectsowner, admin, memberList projects in subscription
POST/api/v1/subscriptions/:subscription_id/projectsowner, adminCreate a project
GET/api/v1/projects/:project_idowner, admin, memberGet project details
PUT/api/v1/projects/:project_idowner, adminUpdate project
DELETE/api/v1/projects/:project_idowner, adminDelete project
GET/api/v1/projects/:project_id/statsowner, admin, memberGet project statistics
GET/api/v1/projects/:project_id/dashboardowner, admin, memberGet project dashboard data

Project Members

MethodEndpointRolesDescription
GET/api/v1/projects/:project_id/membersowner, admin, memberList project members
POST/api/v1/projects/:project_id/membersowner, adminAdd a project member
PUT/api/v1/projects/:project_id/members/:user_idowner, adminUpdate member role
DELETE/api/v1/projects/:project_id/members/:user_idowner, adminRemove a member

SBOMs

MethodEndpointRolesDescription
GET/api/v1/projects/:project_id/sbomsowner, admin, memberList SBOMs for a project
GET/api/v1/projects/:project_id/sboms/:sbom_idowner, admin, memberGet SBOM details
GET/api/v1/projects/:project_id/sboms/:sbom_id/findingsowner, admin, memberList findings for a specific SBOM
GET/api/v1/projects/:project_id/sboms/diff/:sbom_a/:sbom_bowner, admin, memberDiff two SBOMs
GET/api/v1/projects/:project_id/sboms/aggregateowner, admin, memberAggregate SBOM statistics

Components

MethodEndpointRolesDescription
GET/api/v1/projects/:project_id/componentsowner, admin, memberList components in a project
GET/api/v1/projects/:project_id/components/summaryowner, admin, memberGet component summary stats
GET/api/v1/projects/:project_id/components/:component_idowner, admin, memberGet component details
GET/api/v1/projects/:project_id/components/:component_id/dependenciesowner, admin, memberGet component dependency tree
PUT/api/v1/projects/:project_id/components/:component_id/statusowner, admin, memberSet component triage status
DELETE/api/v1/projects/:project_id/components/:component_id/statusowner, admin, memberClear component triage status
POST/api/v1/projects/:project_id/components/bulk-statusowner, admin, memberBulk set component statuses

Findings

MethodEndpointRolesDescription
GET/api/v1/findings/recentany (JWT)Get recent findings across all user's projects
GET/api/v1/projects/:project_id/findingsowner, admin, memberList findings for a project
GET/api/v1/projects/:project_id/findings/summaryowner, admin, memberGet findings summary (counts by severity)
GET/api/v1/projects/:project_id/findings/trendsowner, admin, memberGet finding trends over time
GET/api/v1/projects/:project_id/findings/cve/:cve_idowner, admin, memberGet details for a specific CVE

Secrets

MethodEndpointRolesDescription
GET/api/v1/projects/:project_id/secretsowner, admin, memberList detected secrets
GET/api/v1/projects/:project_id/secrets/summaryowner, admin, memberGet secrets summary
GET/api/v1/projects/:project_id/secrets/:secret_idowner, admin, memberGet secret details
PUT/api/v1/projects/:project_id/secrets/:secret_id/statusowner, admin, memberSet secret triage status
DELETE/api/v1/projects/:project_id/secrets/:secret_id/statusowner, admin, memberClear secret triage status

Tokens

MethodEndpointRolesDescription
GET/api/v1/projects/:project_id/tokensowner, admin, memberList project tokens
POST/api/v1/projects/:project_id/tokensowner, adminCreate a project token
DELETE/api/v1/projects/:project_id/tokens/:token_idowner, adminRevoke a project token

Alerts

MethodEndpointRolesDescription
GET/api/v1/projects/:project_id/alertsowner, admin, memberGet alert configuration
PUT/api/v1/projects/:project_id/alertsowner, adminUpdate alert configuration
GET/api/v1/projects/:project_id/alerts/webhookowner, admin, memberGet effective webhook URL

Scan Requests

MethodEndpointRolesDescription
GET/api/v1/projects/:project_id/scan-requestsowner, admin, memberGet scan request status
POST/api/v1/projects/:project_id/sboms/:sbom_id/scanowner, admin, memberRequest an on-demand scan

Image Scans

MethodEndpointRolesDescription
GET/api/v1/projects/:project_id/image-scansowner, admin, memberList image scan requests
POST/api/v1/projects/:project_id/image-scansowner, admin, memberRequest a container image scan

Risk Configuration

MethodEndpointRolesDescription
GET/api/v1/projects/:project_id/risk-configowner, admin, memberGet risk scoring configuration
PUT/api/v1/projects/:project_id/risk-configowner, adminUpdate risk scoring configuration

Audit Log

MethodEndpointRolesDescription
GET/api/v1/projects/:project_id/audit-logowner, admin, memberList audit log entries

Inbound API (taco-inbound)

These endpoints are served by taco-inbound at taco-inbound.taco-sec.com.

MethodEndpointAuthDescription
POST/api/v1/sbomBearer project-tokenSubmit an SBOM for processing
POST/api/v1/secretsBearer project-tokenSubmit secret scan results
GET/healthznoneHealth check
GET/swagger/*noneSwagger UI

Auth Service API (taco-auth, internal)

MethodEndpointDescription
GET/api/v1/token/validate?token=<token>Validate a project token
GET/healthzHealth check
GET/swagger/*Swagger UI