Skip to content

HTTP API ​

Base URL: https://app.dagsec.net. These endpoints authenticate with an API key:

Authorization: Bearer dgs_...

Errors are JSON: {"error": "message"}.

Download the scanner ​

GET /api/action/binary

Returns the dagsec binary for Linux x86-64 (application/octet-stream). Used by the GitHub Action, GitLab CI and the CLI. Each successful download counts as one CI run.

The repository is identified by, in order of preference:

HowHeader or parameterPlans
GitHub Actions OIDC token, audience dagsecX-GitHub-OIDC: <token>All; proves the repository and whether it's public
gitlab.com CI ID token, audience dagsecX-GitLab-OIDC: <token>All; proves the project, whose visibility dagsec then asks GitLab
Self-reported GitLab project?gitlab_project=group/projectPaid plans
Self-reported GitHub repository?repo=owner/namePaid plans
StatusMeaning
200The binary
400Missing or malformed repository, or no identity token on the Free plan
401Bad API key or identity token
402Private repository on the Free plan
429Monthly CI runs used up, or rate limited
503The binary isn't published on this server

MCP ​

POST /mcp

JSON-RPC 2.0 over Streamable HTTP, with JSON responses. See MCP server for the tools.

Agent hooks ​

POST /api/hooks/cursor
POST /api/hooks/gemini

Take the agent's hook input as the request body (--data-binary @-) and answer in that agent's hook format. Add ?mode=warn or the header X-Dagsec-Mode: warn to ask instead of block. Errors of any kind allow the command. See Cursor and Gemini CLI.

Rate limits ​

Per IP address, per minute:

RequestsLimit
All API, MCP and hook requests300
Sign-in (/auth/...)20
Starting dashboard scans5

Over the limit, the answer is 429 with a Retry-After header in seconds. Monthly plan limits are separate: see Plans and limits.