> For the complete documentation index, see [llms.txt](https://docs.nullify.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.nullify.ai/configuration/configuration-api.md).

# API Configuration

## Overview

API findings are produced by Dynamic Application Security Testing (DAST) against your running applications and are configured from the Nullify dashboard — there is no checked-in config file.

A pentest runs against an application's resolved context. Start one with `POST /dast/pentest/start` (body `{"applicationId":"<id>","configOverrides":{...}}`; `applicationId` is required) and review results with `GET /dast/pentest/scans/{scanId}/findings`. Lighter bug-hunt scans run at `low`, `medium`, or `high` intensity via `GET,POST /dast/bughunt/scans`.

## Ignore findings

Suppress an API finding by allowlisting it per-finding from the dashboard or via the API, e.g. for a pentest finding:

```
POST /dast/pentest/findings/{findingId}/allowlist
```

Request body:

```json
{
  "allowlistReason": "Endpoint is internal-only and not reachable in production",
  "allowlistType": "UserAssumeRisk"
}
```

`allowlistType` is one of `AI`, `UserFixed`, `UserAssumeRisk`, `UserFalsePositive`, or `UserOther`.

## Pull request gate and notifications

Whether findings fail CI and where alerts are delivered is managed centrally — see [Configuration – General](/configuration/configuration-general.md) for the **Configure → Pull Requests** and **Configure → Notifications** settings.
