HTTP API
Base URL: https://app.dagsec.net. These endpoints authenticate with an API key:
Authorization: Bearer dgs_...Errors are JSON: {"error": "message"}.
Download the scanner
GET /api/action/binaryReturns the dagsec binary for Linux x86-64 (application/octet-stream). Used by the GitHub Action, GitLab CI and the CLI. Each successful download counts as one CI run.
The repository is identified by, in order of preference:
| How | Header or parameter | Plans |
|---|---|---|
GitHub Actions OIDC token, audience dagsec | X-GitHub-OIDC: <token> | All; proves the repository and whether it's public |
gitlab.com CI ID token, audience dagsec | X-GitLab-OIDC: <token> | All; proves the project, whose visibility dagsec then asks GitLab |
| Self-reported GitLab project | ?gitlab_project=group/project | Paid plans |
| Self-reported GitHub repository | ?repo=owner/name | Paid plans |
| Status | Meaning |
|---|---|
| 200 | The binary |
| 400 | Missing or malformed repository, or no identity token on the Free plan |
| 401 | Bad API key or identity token |
| 402 | Private repository on the Free plan |
| 429 | Monthly CI runs used up, or rate limited |
| 503 | The binary isn't published on this server |
MCP
POST /mcpJSON-RPC 2.0 over Streamable HTTP, with JSON responses. See MCP server for the tools.
Agent hooks
POST /api/hooks/cursor
POST /api/hooks/geminiTake the agent's hook input as the request body (--data-binary @-) and answer in that agent's hook format. Add ?mode=warn or the header X-Dagsec-Mode: warn to ask instead of block. Errors of any kind allow the command. See Cursor and Gemini CLI.
Rate limits
Per IP address, per minute:
| Requests | Limit |
|---|---|
| All API, MCP and hook requests | 300 |
Sign-in (/auth/...) | 20 |
| Starting dashboard scans | 5 |
Over the limit, the answer is 429 with a Retry-After header in seconds. Monthly plan limits are separate: see Plans and limits.