Skip to main content

API upgrade guide

When upgrading from Invicti Enterprise to Invicti Platform, the API changes completely. This document explains what's incompatible, where to find the new API, and what actions to take before your integrations can run again.

Any existing automation scripts, CI/CD integrations, custom tooling, and API-based reporting or orchestration must be reviewed and updated to work with the new API.

For a high-level overview of all upgrade areas, refer to the Moving from Invicti Enterprise to Invicti Platform document.

Why this matters​

The Invicti Platform API isn't backward-compatible with the Invicti Enterprise API. If your team relies on API-based automation (such as triggering scans from CI/CD pipelines, importing findings into external tools, or managing targets programmatically), those integrations stop working after the upgrade and require manual updates before they can run again.

API compatibility​

Existing API calls don't work as-is after the upgrade. Update integrations to use the Invicti Platform API endpoints, request models, and authentication scheme.

Invicti Platform API uses completely different endpoints and request schemas. Any existing automation built on the Invicti Enterprise API needs to be rebuilt regardless. Before updating your integrations, confirm your API key is available in Invicti Platform and has the permissions your integrations need.

Refer to the Get started with the Invicti Platform API document for steps on managing API keys and permissions.

Accessing the Invicti Platform API​

The Invicti Platform API is documented via Swagger:

Use the Swagger UI to explore available endpoints, review request and response schemas, and test API calls interactively.

Required actions​

After upgrading to Invicti Platform:

  1. Review all existing automation scripts and API integrations.
  2. Identify API calls that reference the Invicti Enterprise API.
  3. Confirm your API key is available in Invicti Platform and has the permissions your integrations need.
  4. Update integrations to use the Invicti Platform API endpoints.
  5. Validate integrations using the Swagger interface.

Troubleshooting​

An existing integration returns errors after the upgrade

The Invicti Platform API uses different endpoints, request models, and authentication schemes from the Invicti Enterprise API. Calls that worked before the upgrade are likely hitting the wrong endpoint or sending an incompatible request format. Use the Swagger interface for your region to review the current endpoint structure and update your integration accordingly.

An API key is rejected after the upgrade

Your API key from Invicti Enterprise is carried over to Invicti Platform, but the API uses a completely different authentication scheme and endpoint structure. If a key is rejected, confirm that it's present in Invicti Platform under your account settings and that it has the permissions required for the integration. Update your integration or CI/CD configuration to use the Invicti Platform API endpoints. Refer to the Get started with the Invicti Platform API document for steps.

A CI/CD pipeline fails after the upgrade

Pipeline failures are usually caused by one of three things: the API endpoint URL has changed, the request schema has changed, or the API key is invalid. Check each in order. Use the Swagger interface to confirm the correct endpoint and request format, and confirm the pipeline uses an API key created in Invicti Platform.


Need help?​

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?