Ingest a sensor scan report
const url = 'https://api.nextpki.com/v1/sensors/ingest';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"machine_id":"example","primary_ip":"example","results":[{"ip":"10.20.4.10","port":443,"hostname":"example","sni":"example","protocol":"PROTOCOL_HTTPS","certificates":["example"]}]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.nextpki.com/v1/sensors/ingest \ --header 'Content-Type: application/json' \ --data '{ "machine_id": "example", "primary_ip": "example", "results": [ { "ip": "10.20.4.10", "port": 443, "hostname": "example", "sni": "example", "protocol": "PROTOCOL_HTTPS", "certificates": [ "example" ] } ] }'Receives one scan report from a registered sensor and returns the configuration the control plane wants that sensor to run.
This endpoint is not called directly by API clients. A sensor reports
over HTTPS through the edge, which terminates TLS, verifies the sensor’s
client certificate against the internal sensor CA, and forwards the
verified identity as headers. The API trusts those headers only from
the loopback edge peer and only when X-Client-Cert-Verified: SUCCESS is
set; the tenant is resolved from the SPIFFE ID in X-Client-Cert-San-Uri.
A direct external call has neither and is rejected. See the sensor
network requirements.
Request Bodyrequired
Section titled “Request Bodyrequired”object
Stable machine identifier
Optional: the sensor’s own primary address
object
Example
10.20.4.10Example
443Example
PROTOCOL_HTTPSThe presented chain as base64-DER strings, leaf first
Responses
Section titled “Responses”Accepted - the response carries the config to apply
object
0 when the control plane has no config for this sensor yet
The scan configuration the control plane wants this sensor to run.
object
Examplegenerated
{ "ingest_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "accepted": 1, "rejected": 1, "warnings": [ "example" ], "config_version": 1, "config": { "targets": [ "example" ], "ports": [ 1 ], "include": [ "example" ], "exclude": [ "example" ], "scan_profile": "example", "scan_interval_secs": 1, "probe_timeout_ms": 1, "paused": true }}Malformed body, missing machine_id, unknown field, undecodable
certificate, or a body over the size limit. The reason is in error.
object
Examplegenerated
{ "error": "example"}No verified client-certificate identity: client_cert_required (the
edge did not set X-Client-Cert-Verified: SUCCESS) or bad_identity
(the forwarded SPIFFE ID was unusable).
object
Examplegenerated
{ "error": "example"}not_via_edge - the request did not come from the loopback edge peer,
so its client-certificate headers cannot be trusted.
object
Examplegenerated
{ "error": "example"}