Create Azure DevOps SCM app (Service Principal)
curl --request POST \
--url https://semgrep.dev/api/scm/ado_app \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"deploymentId": "<string>",
"baseUrl": "<string>",
"tenantId": "<string>",
"clientId": "<string>",
"organizationName": "<string>",
"projectName": "<string>"
}
'import requests
url = "https://semgrep.dev/api/scm/ado_app"
payload = {
"deploymentId": "<string>",
"baseUrl": "<string>",
"tenantId": "<string>",
"clientId": "<string>",
"organizationName": "<string>",
"projectName": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
deploymentId: '<string>',
baseUrl: '<string>',
tenantId: '<string>',
clientId: '<string>',
organizationName: '<string>',
projectName: '<string>'
})
};
fetch('https://semgrep.dev/api/scm/ado_app', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://semgrep.dev/api/scm/ado_app",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'deploymentId' => '<string>',
'baseUrl' => '<string>',
'tenantId' => '<string>',
'clientId' => '<string>',
'organizationName' => '<string>',
'projectName' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://semgrep.dev/api/scm/ado_app"
payload := strings.NewReader("{\n \"deploymentId\": \"<string>\",\n \"baseUrl\": \"<string>\",\n \"tenantId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"organizationName\": \"<string>\",\n \"projectName\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://semgrep.dev/api/scm/ado_app")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"deploymentId\": \"<string>\",\n \"baseUrl\": \"<string>\",\n \"tenantId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"organizationName\": \"<string>\",\n \"projectName\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://semgrep.dev/api/scm/ado_app")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"deploymentId\": \"<string>\",\n \"baseUrl\": \"<string>\",\n \"tenantId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"organizationName\": \"<string>\",\n \"projectName\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"scmAppId": "<string>",
"publicCertificatePem": "<string>"
}Source Code Management (SCM) apps
Create Azure DevOps SCM app (Service Principal)
Create an ADO ScmApp using Entra ID Service Principal credentials. Generates a key pair server-side and returns the public certificate for the customer to upload to their Entra app registration. CompleteAdoScmAppInstall must be called to finish the install after the certificate is uploaded.
POST
/
api
/
scm
/
ado_app
Create Azure DevOps SCM app (Service Principal)
curl --request POST \
--url https://semgrep.dev/api/scm/ado_app \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"deploymentId": "<string>",
"baseUrl": "<string>",
"tenantId": "<string>",
"clientId": "<string>",
"organizationName": "<string>",
"projectName": "<string>"
}
'import requests
url = "https://semgrep.dev/api/scm/ado_app"
payload = {
"deploymentId": "<string>",
"baseUrl": "<string>",
"tenantId": "<string>",
"clientId": "<string>",
"organizationName": "<string>",
"projectName": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
deploymentId: '<string>',
baseUrl: '<string>',
tenantId: '<string>',
clientId: '<string>',
organizationName: '<string>',
projectName: '<string>'
})
};
fetch('https://semgrep.dev/api/scm/ado_app', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://semgrep.dev/api/scm/ado_app",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'deploymentId' => '<string>',
'baseUrl' => '<string>',
'tenantId' => '<string>',
'clientId' => '<string>',
'organizationName' => '<string>',
'projectName' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://semgrep.dev/api/scm/ado_app"
payload := strings.NewReader("{\n \"deploymentId\": \"<string>\",\n \"baseUrl\": \"<string>\",\n \"tenantId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"organizationName\": \"<string>\",\n \"projectName\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://semgrep.dev/api/scm/ado_app")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"deploymentId\": \"<string>\",\n \"baseUrl\": \"<string>\",\n \"tenantId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"organizationName\": \"<string>\",\n \"projectName\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://semgrep.dev/api/scm/ado_app")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"deploymentId\": \"<string>\",\n \"baseUrl\": \"<string>\",\n \"tenantId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"organizationName\": \"<string>\",\n \"projectName\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"scmAppId": "<string>",
"publicCertificatePem": "<string>"
}This endpoint is experimental. It may change or be removed without notice and is not covered by API stability guarantees.
Authorizations
SemgrepWebTokenSemgrepJWT
Get access to data with your API token. Example header:
Authorization: Bearer 2991e2fb4b540fe75b8f90677b0b892b6314e4961cb001fe6eb452eee248a628
The token can be provisioned from the Tokens section in your Settings, and requires explicitly enabling Web API access.
Body
application/json
Was this page helpful?
⌘I