curl --request POST \
--url https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"repoId": "<string>",
"workflowName": "<string>",
"gitRef": "<string>",
"createPrs": true,
"baseBranch": "<string>",
"findingsAnalysisLimit": 123,
"prId": "<string>",
"sideEffects": true,
"inputs": {}
}
'import requests
url = "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger"
payload = {
"repoId": "<string>",
"workflowName": "<string>",
"gitRef": "<string>",
"createPrs": True,
"baseBranch": "<string>",
"findingsAnalysisLimit": 123,
"prId": "<string>",
"sideEffects": True,
"inputs": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
repoId: '<string>',
workflowName: '<string>',
gitRef: '<string>',
createPrs: true,
baseBranch: '<string>',
findingsAnalysisLimit: 123,
prId: '<string>',
sideEffects: true,
inputs: {}
})
};
fetch('https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'repoId' => '<string>',
'workflowName' => '<string>',
'gitRef' => '<string>',
'createPrs' => true,
'baseBranch' => '<string>',
'findingsAnalysisLimit' => 123,
'prId' => '<string>',
'sideEffects' => true,
'inputs' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger"
payload := strings.NewReader("{\n \"repoId\": \"<string>\",\n \"workflowName\": \"<string>\",\n \"gitRef\": \"<string>\",\n \"createPrs\": true,\n \"baseBranch\": \"<string>\",\n \"findingsAnalysisLimit\": 123,\n \"prId\": \"<string>\",\n \"sideEffects\": true,\n \"inputs\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"repoId\": \"<string>\",\n \"workflowName\": \"<string>\",\n \"gitRef\": \"<string>\",\n \"createPrs\": true,\n \"baseBranch\": \"<string>\",\n \"findingsAnalysisLimit\": 123,\n \"prId\": \"<string>\",\n \"sideEffects\": true,\n \"inputs\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"repoId\": \"<string>\",\n \"workflowName\": \"<string>\",\n \"gitRef\": \"<string>\",\n \"createPrs\": true,\n \"baseBranch\": \"<string>\",\n \"findingsAnalysisLimit\": 123,\n \"prId\": \"<string>\",\n \"sideEffects\": true,\n \"inputs\": {}\n}"
response = http.request(request)
puts response.read_body{
"jobId": "<string>"
}Trigger a workflow run
Submits a workflow job for a deployment.
curl --request POST \
--url https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"repoId": "<string>",
"workflowName": "<string>",
"gitRef": "<string>",
"createPrs": true,
"baseBranch": "<string>",
"findingsAnalysisLimit": 123,
"prId": "<string>",
"sideEffects": true,
"inputs": {}
}
'import requests
url = "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger"
payload = {
"repoId": "<string>",
"workflowName": "<string>",
"gitRef": "<string>",
"createPrs": True,
"baseBranch": "<string>",
"findingsAnalysisLimit": 123,
"prId": "<string>",
"sideEffects": True,
"inputs": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
repoId: '<string>',
workflowName: '<string>',
gitRef: '<string>',
createPrs: true,
baseBranch: '<string>',
findingsAnalysisLimit: 123,
prId: '<string>',
sideEffects: true,
inputs: {}
})
};
fetch('https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'repoId' => '<string>',
'workflowName' => '<string>',
'gitRef' => '<string>',
'createPrs' => true,
'baseBranch' => '<string>',
'findingsAnalysisLimit' => 123,
'prId' => '<string>',
'sideEffects' => true,
'inputs' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger"
payload := strings.NewReader("{\n \"repoId\": \"<string>\",\n \"workflowName\": \"<string>\",\n \"gitRef\": \"<string>\",\n \"createPrs\": true,\n \"baseBranch\": \"<string>\",\n \"findingsAnalysisLimit\": 123,\n \"prId\": \"<string>\",\n \"sideEffects\": true,\n \"inputs\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"repoId\": \"<string>\",\n \"workflowName\": \"<string>\",\n \"gitRef\": \"<string>\",\n \"createPrs\": true,\n \"baseBranch\": \"<string>\",\n \"findingsAnalysisLimit\": 123,\n \"prId\": \"<string>\",\n \"sideEffects\": true,\n \"inputs\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://semgrep.dev/api/workflows/v1/deployments/{deploymentId}/trigger")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"repoId\": \"<string>\",\n \"workflowName\": \"<string>\",\n \"gitRef\": \"<string>\",\n \"createPrs\": true,\n \"baseBranch\": \"<string>\",\n \"findingsAnalysisLimit\": 123,\n \"prId\": \"<string>\",\n \"sideEffects\": true,\n \"inputs\": {}\n}"
response = http.request(request)
puts response.read_body{
"jobId": "<string>"
}Authorizations
Get access to data with your API token. Example header:
Authorization: Bearer 2991e2fb4b540fe75b8f90677b0b892b6314e4961cb001fe6eb452eee248a628
The token can be provisioned from the Tokens section in your Settings, and requires explicitly enabling Web API access.
Path Parameters
The unique numerical identifier of the deployment. Can be found via the Deployments Service or in your Settings in the web UI.
"1234"
Body
The unique numerical identifier of the repository to analyze.
Workflow type to run (e.g., "c-buffer-overflow", "bola-detection", "msaas-dockerfile-fix")
Git reference to analyze (branch name, tag, or commit SHA)
Whether to create fix PRs for detected issues (defaults to true)
Base branch for fix PRs (defaults to "main")
Maximum number of findings to analyze (defaults to 50)
PR number to analyze. When provided, the backend resolves the head and base branches automatically.
Whether the workflow may perform side effects (PR comments, posting results back). Defaults to true; benchmark callers set false.
Arbitrary user-provided inputs for dynamic workflow fields. Keys correspond to WorkflowInputField.name values from the registry input schema. Only user/advanced visibility fields should be sent; system/secret fields are always supplied by the backend and any user-supplied values for those are ignored. When absent or empty, existing callers are unaffected.
Show child attributes
Show child attributes
Response
OK
Canonical job identifier. Use with the Workflow Jobs API to track status and retrieve results.
Was this page helpful?