> ## Documentation Index
> Fetch the complete documentation index at: https://docs.attaxr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a resource

> Creates a row owned by the calling user; `userId` is injected server-side and never taken from the body.



## OpenAPI

````yaml /api/openapi.json post /api/leads
openapi: 3.1.0
info:
  title: Aquila API
  version: 1.0.0
  description: >-
    Event-driven reconnaissance platform API. All /api/* routes except
    /api/public/* require an authenticated session (cookie), an X-Api-Key
    header, or a bearer token. Auth endpoints under /api/auth/* are generated by
    Better Auth.
servers:
  - url: https://aquila.attaxr.com
  - url: http://localhost
security: []
tags:
  - name: AI
  - name: Agents
  - name: Bulk Delete
  - name: Chat
  - name: Constraints
  - name: Dashboard
  - name: Events
  - name: JS
  - name: JS Analysis
  - name: JS Monitoring
  - name: Leads
  - name: MCP Key
  - name: Models
  - name: Notification Channels
  - name: Notification Event Preferences
  - name: Notifications
  - name: OOB
  - name: Provider Keys
  - name: Public Shares
  - name: Reinforcements
  - name: Reports
  - name: Scans
  - name: Schedules
  - name: Shares
  - name: Tools
  - name: User Profiles
  - name: V1
  - name: Vulnerabilities
  - name: Workflows
paths:
  /api/leads:
    post:
      tags:
        - Leads
      summary: Create a resource
      description: >-
        Creates a row owned by the calling user; `userId` is injected
        server-side and never taken from the body.
      operationId: postApiLeads
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $schema: https://json-schema.org/draft/2020-12/schema
              type: object
              properties:
                _id:
                  type: string
                userId:
                  type: string
                assetKey:
                  type: string
                assetType:
                  type: string
                assetValue:
                  type: string
                scanId:
                  type: string
                metadata:
                  default: {}
                  type: object
                  propertyNames:
                    type: string
                  additionalProperties: {}
                category:
                  type: string
                interestScore:
                  type: number
                  minimum: 0
                  maximum: 1
                confidence:
                  type: number
                  minimum: 0
                  maximum: 1
                recommendedAction:
                  type: string
                analysis:
                  type: string
                technologies:
                  type: array
                  items:
                    type: object
                    propertyNames:
                      type: string
                    additionalProperties: {}
                notableObservations:
                  type: array
                  items:
                    type: string
                relationships:
                  type: array
                  items:
                    type: string
                whyInteresting:
                  type: string
                potentialVulnerabilities:
                  type: array
                  items:
                    type: object
                    propertyNames:
                      type: string
                    additionalProperties: {}
                recommendedTools:
                  type: array
                  items:
                    type: object
                    propertyNames:
                      type: string
                    additionalProperties: {}
                architectureMermaid:
                  type: string
                chainingOpportunities:
                  type: array
                  items:
                    type: object
                    propertyNames:
                      type: string
                    additionalProperties: {}
                endpoints:
                  type: array
                  items:
                    type: object
                    propertyNames:
                      type: string
                    additionalProperties: {}
                insights:
                  type: array
                  items:
                    type: object
                    propertyNames:
                      type: string
                    additionalProperties: {}
                cves:
                  type: array
                  items:
                    type: object
                    properties:
                      id:
                        type: string
                        minLength: 1
                      technology:
                        type: string
                      version:
                        type: string
                      description:
                        type: string
                      cvssScore:
                        type: number
                      cvssSeverity:
                        type: string
                        enum:
                          - CRITICAL
                          - HIGH
                          - MEDIUM
                          - LOW
                      publishedAt:
                        type: string
                      references:
                        type: array
                        items:
                          type: string
                    required:
                      - id
                      - technology
                classifiedAt: {}
                lastAnalysisAt: {}
                reconVersion:
                  type: integer
                  minimum: 0
                  maximum: 9007199254740991
                response:
                  type: string
                changedResponse:
                  type: string
                lastFetchedAt: {}
                jsRecon:
                  type: object
                  propertyNames:
                    type: string
                  additionalProperties: {}
                jsReconAnalyzedAt: {}
                lastNotifiedJsBodyHash:
                  type: string
                lastNotifiedJsAt: {}
                type:
                  default: other
                  type: string
                  enum:
                    - authorization_issue
                    - api_endpoint
                    - auth_workflow
                    - sensitive_functionality
                    - business_logic_concern
                    - other
                title:
                  type: string
                description:
                  default: ''
                  type: string
                priority:
                  default: medium
                  type: string
                  enum:
                    - low
                    - medium
                    - high
                    - critical
                status:
                  default: new
                  type: string
                  enum:
                    - new
                    - analyzing
                    - investigating
                    - validating
                    - closed
                createdAt:
                  default: '2026-09-18T11:34:11.692Z'
                updatedAt:
                  default: '2026-09-18T11:34:11.692Z'
              required:
                - userId
                - assetKey
                - title
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema: {}
        '201':
          description: The created resource.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  _id:
                    type: string
                  userId:
                    type: string
                  assetKey:
                    type: string
                  assetType:
                    type: string
                  assetValue:
                    type: string
                  scanId:
                    type: string
                  metadata:
                    default: {}
                    type: object
                    propertyNames:
                      type: string
                    additionalProperties: {}
                  category:
                    type: string
                  interestScore:
                    type: number
                    minimum: 0
                    maximum: 1
                  confidence:
                    type: number
                    minimum: 0
                    maximum: 1
                  recommendedAction:
                    type: string
                  analysis:
                    type: string
                  technologies:
                    type: array
                    items:
                      type: object
                      propertyNames:
                        type: string
                      additionalProperties: {}
                  notableObservations:
                    type: array
                    items:
                      type: string
                  relationships:
                    type: array
                    items:
                      type: string
                  whyInteresting:
                    type: string
                  potentialVulnerabilities:
                    type: array
                    items:
                      type: object
                      propertyNames:
                        type: string
                      additionalProperties: {}
                  recommendedTools:
                    type: array
                    items:
                      type: object
                      propertyNames:
                        type: string
                      additionalProperties: {}
                  architectureMermaid:
                    type: string
                  chainingOpportunities:
                    type: array
                    items:
                      type: object
                      propertyNames:
                        type: string
                      additionalProperties: {}
                  endpoints:
                    type: array
                    items:
                      type: object
                      propertyNames:
                        type: string
                      additionalProperties: {}
                  insights:
                    type: array
                    items:
                      type: object
                      propertyNames:
                        type: string
                      additionalProperties: {}
                  cves:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          minLength: 1
                        technology:
                          type: string
                        version:
                          type: string
                        description:
                          type: string
                        cvssScore:
                          type: number
                        cvssSeverity:
                          type: string
                          enum:
                            - CRITICAL
                            - HIGH
                            - MEDIUM
                            - LOW
                        publishedAt:
                          type: string
                        references:
                          type: array
                          items:
                            type: string
                      required:
                        - id
                        - technology
                      additionalProperties: false
                  classifiedAt: {}
                  lastAnalysisAt: {}
                  reconVersion:
                    type: integer
                    minimum: 0
                    maximum: 9007199254740991
                  response:
                    type: string
                  changedResponse:
                    type: string
                  lastFetchedAt: {}
                  jsRecon:
                    type: object
                    propertyNames:
                      type: string
                    additionalProperties: {}
                  jsReconAnalyzedAt: {}
                  lastNotifiedJsBodyHash:
                    type: string
                  lastNotifiedJsAt: {}
                  type:
                    default: other
                    type: string
                    enum:
                      - authorization_issue
                      - api_endpoint
                      - auth_workflow
                      - sensitive_functionality
                      - business_logic_concern
                      - other
                  title:
                    type: string
                  description:
                    default: ''
                    type: string
                  priority:
                    default: medium
                    type: string
                    enum:
                      - low
                      - medium
                      - high
                      - critical
                  status:
                    default: new
                    type: string
                    enum:
                      - new
                      - analyzing
                      - investigating
                      - validating
                      - closed
                  createdAt:
                    default: '2026-09-18T11:34:11.692Z'
                  updatedAt:
                    default: '2026-09-18T11:34:11.692Z'
                required:
                  - userId
                  - assetKey
                  - metadata
                  - type
                  - title
                  - description
                  - priority
                  - status
                  - createdAt
                  - updatedAt
                additionalProperties: false
        '400':
          description: Request body failed schema validation.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  error:
                    type: string
                  details: {}
                required:
                  - error
                additionalProperties: false
        '401':
          description: No valid session cookie or API key.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
                additionalProperties: false
        '403':
          description: Email address not verified, or the caller lacks the required role.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
                additionalProperties: false
        '429':
          description: >-
            Risk-tier rate limit exceeded (writes 20/min, expensive 10/min, bulk
            60/min). Limited responses carry X-RateLimit-Limit,
            X-RateLimit-Remaining, X-RateLimit-Reset and Retry-After.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
                additionalProperties: false
      security:
        - apiKeyCookie: []
        - apiKeyHeader: []
        - bearerAuth: []
components:
  securitySchemes:
    apiKeyCookie:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: Browser session cookie set by Better Auth sign-in.
    apiKeyHeader:
      type: apiKey
      in: header
      name: x-api-key
      description: Personal API key (aquila_… prefix; settings → API keys).
    bearerAuth:
      type: http
      scheme: bearer
      description: Personal API key sent as a bearer token.

````