API upgrade guide
When upgrading from Invicti Enterprise to Invicti Platform, the API changes completely. This document explains what's incompatible, where to find the new API, and what actions to take before your integrations can run again.
Any existing automation scripts, CI/CD integrations, custom tooling, and API-based reporting or orchestration must be reviewed and updated to work with the new API.
For a high-level overview of all upgrade areas, refer to the Moving from Invicti Enterprise to Invicti Platform document.
Why this matters
The Invicti Platform API isn't backward-compatible with the Invicti Enterprise API. If your team relies on API-based automation (such as triggering scans from CI/CD pipelines, importing findings into external tools, or managing targets programmatically), those integrations stop working after the upgrade and require manual updates before they can run again.
API compatibility
Existing API calls don't work as-is after the upgrade. Update integrations to use the Invicti Platform API endpoints, request models, and authentication scheme.
Invicti Platform API uses completely different endpoints and request schemas. Any existing automation built on the Invicti Enterprise API needs to be rebuilt regardless. Before updating your integrations, confirm your API key is available in Invicti Platform and has the permissions your integrations need.
Refer to the Get started with the Invicti Platform API document for steps on managing API keys and permissions.
Accessing the Invicti Platform API
The Invicti Platform API is documented via Swagger:
- US region: https://platform.invicti.com/swagger/
- EU region: https://platform-eu.invicti.com/swagger/
- Canada region: https://platform-ca.invicti.com/swagger/
Use the Swagger UI to explore available endpoints, review request and response schemas, and test API calls interactively.
Required actions
After upgrading to Invicti Platform:
- Review all existing automation scripts and API integrations.
- Identify API calls that reference the Invicti Enterprise API.
- Confirm your API key is available in Invicti Platform and has the permissions your integrations need.
- Update integrations to use the Invicti Platform API endpoints.
- Validate integrations using the Swagger interface.
Troubleshooting
An existing integration returns errors after the upgrade
The Invicti Platform API uses different endpoints, request models, and authentication schemes from the Invicti Enterprise API. Calls that worked before the upgrade are likely hitting the wrong endpoint or sending an incompatible request format. Use the Swagger interface for your region to review the current endpoint structure and update your integration accordingly.
An API key is rejected after the upgrade
Your API key from Invicti Enterprise is carried over to Invicti Platform, but the API uses a completely different authentication scheme and endpoint structure. If a key is rejected, confirm that it's present in Invicti Platform under your account settings and that it has the permissions required for the integration. Update your integration or CI/CD configuration to use the Invicti Platform API endpoints. Refer to the Get started with the Invicti Platform API document for steps.
A CI/CD pipeline fails after the upgrade
Pipeline failures are usually caused by one of three things: the API endpoint URL has changed, the request schema has changed, or the API key is invalid. Check each in order. Use the Swagger interface to confirm the correct endpoint and request format, and confirm the pipeline uses an API key created in Invicti Platform.
Need help?
Invicti Support team is ready to provide you with technical help. Go to Help Center