CentralCSP
APIAlerts

List alert rules

Lists what this website notifies about. A rule pairs an event type with the channels to notify and a cooldown that batches findings, so a burst of similar events becomes one message instead of many.

Requires the viewer role on the website and the alerting plan feature.

GET
/v1/workspaces/{workspaceId}/websites/{websiteId}/alerts/rules

Authorization

AuthorizationBearer <token>

An OpenID Connect access token issued by Keycloak, acting as the signed-in user.

In: header

Path Parameters

workspaceId*string
websiteId*string

Query Parameters

cursor?string

The nextCursor of the previous page. Omit it to start from the beginning. A cursor encodes a position and is not meant to be built by hand.

limit*|

How many items to return, from 1 to 200.

Range1 <= value <= 200
Default50
q?string

Match part of the rule name.

Lengthlength <= 255
enabled?boolean

Only enabled or only disabled rules.

eventType?AlertEventType

What to notify about. new-* types fire the first time something appears in a website's reports: a CSP directive and blocked origin pair, a script origin, a failing network origin, a COOP or COEP violation type, a Permissions Policy violation, a deprecated API, a browser intervention, or a blocked connection origin. compliance:unjustified-script fires when a payment-page script needs review. *:spike types fire when an hour's report volume reaches at least 50 reports and three times the trailing 24-hour average, both adjustable per rule with config. sbom:new-cve fires when a technology on the website gains a known vulnerability at or above the rule's minimum severity; sbom:version-status fires when a technology is detected as, or becomes, outdated or deprecated, per the rule's statuses.

Value in

  • "csp-violation:new-type"
  • "csp-violation:spike"
  • "csp-hash:new-script-origin"
  • "integrity-violation:spike"
  • "compliance:unjustified-script"
  • "network-error:new-failing-origin"
  • "network-error:spike"
  • "crash:spike"
  • "coop:new-violation"
  • "coep:new-violation"
  • "permissions-policy:new-violation"
  • "deprecation:new-api"
  • "intervention:new-type"
  • "connection-allowlist:new-blocked-origin"
  • "sbom:new-cve"
  • "sbom:version-status"

Response Body

application/json

curl -X GET "https://example.com/v1/workspaces/string/websites/string/alerts/rules?limit=50"
{  "data": [    {      "id": "string",      "workspaceId": "string",      "websiteId": "string",      "name": "New third-party script",      "eventType": "csp-violation:new-type",      "cooldownSeconds": 0,      "config": {        "multiplier": 3,        "floor": 50,        "minSeverity": "medium",        "statuses": [          "deprecated"        ]      },      "enabled": true,      "channelIds": [        "string"      ],      "createdAt": "2019-08-24T14:15:22Z",      "updatedAt": "2019-08-24T14:15:22Z"    }  ],  "pagination": {    "nextCursor": "string",    "hasMore": true,    "total": 0  }}