Skip to main content

1. Get your API key

Sign up at validate.al and copy your API key from the portal dashboard.

2. Request a scan

Send a POST request with your target:
Response:
The scan is queued and will be picked up by an available scanner.

Scan types

See Scan Types for details.

3. Check scan status

List your scans:
Response:
Status values: pending → in_progress → completed / failed

4. Get the full report

Returns the full JSON report with raw tool output, findings summary, and scan metadata.

Notes

  • Scans run on isolated infrastructure, never on the origin
  • A single request queue per plan; scans run one at a time
  • Typical scan time for a webapp scan: 30s–3min