Skip to content

Public endpoints

These routes respond without an API key. They are informational. Do not send customer content to them.

They are not part of the machine contract at https://api.vulnify.io/openapi.json. The payloads below are what the server returned when these pages were checked.

https://api.vulnify.io/health

{
"ready": true,
"status": "ok",
"version": "0.3.0",
"apiVersion": "v1",
"timestamp": "2026-10-02T19:00:46.973Z"
}

The live payload also includes database and uptime fields (db, dbLatencyMs, uptimeSec). version and apiVersion above are what the server reported when these docs were written.

https://api.vulnify.io/public/plans

{
"plans": [
{ "name": "DEVELOPER", "agents": 2, "eventsPerMonth": 10000, "retentionDays": 7 },
{ "name": "TEAM", "agents": 10, "eventsPerMonth": 250000, "retentionDays": 30 },
{ "name": "BUSINESS", "agents": 50, "eventsPerMonth": 2000000, "retentionDays": 365 },
{ "name": "ENTERPRISE", "agents": null, "eventsPerMonth": null, "retentionDays": null }
]
}

retentionDays is the plan window for decision events. null means the public payload does not publish a fixed limit. Prices are not on this endpoint.

Decision events are deleted automatically after your plan’s retention window (Developer 7 days, Team 30 days, Business 365 days). The deletion job runs regularly. Enterprise retention follows your contract; there is no automatic deletion unless agreed. When an event is deleted, its audit-log entry (the decision, risk score and related metadata) is kept for as long as the organization exists, because the audit log is append-only. Deleted data can remain in encrypted backups for up to 30 days. See Plans.

https://api.vulnify.io/public/dlp-types

Returns { "types": [ ... ] }. Each item has type, category, personalData, sensitive, and a detection string. The table in Risk engine lists the types returned when these docs were written.

https://api.vulnify.io/public/config

Returns booleans that describe the deployment, including demoEnabled, emailConfigured, planChangeEnabled, and billingEnabled. Read this endpoint for the current flags. When these docs were written, billingEnabled was true and planChangeEnabled was false, so the prices on Plans were published while changing plan inside the app was not enabled on that deployment.

Landing site only. This is the contact form on vulnify.io and www.vulnify.io. It is listed in the public OpenAPI document so that document matches the server. It is not a customer API, and it is not in the API reference navigation. Do not call it from an agent or an integration.