> ## Documentation Index
> Fetch the complete documentation index at: https://docs.attaxr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List scans

> List the caller's scans, newest first. The q search matches the scan target.



## OpenAPI

````yaml /api/openapi.json get /api/scans
openapi: 3.1.0
info:
  title: Aquila API
  version: 1.0.0
  description: >-
    Event-driven reconnaissance platform API. All /api/* routes except
    /api/public/* require an authenticated session (cookie), an X-Api-Key
    header, or a bearer token. Auth endpoints under /api/auth/* are generated by
    Better Auth.
servers:
  - url: https://aquila.attaxr.com
  - url: http://localhost
security: []
tags:
  - name: AI
  - name: Agents
  - name: Bulk Delete
  - name: Chat
  - name: Constraints
  - name: Dashboard
  - name: Events
  - name: JS
  - name: JS Analysis
  - name: JS Monitoring
  - name: Leads
  - name: MCP Key
  - name: Models
  - name: Notification Channels
  - name: Notification Event Preferences
  - name: Notifications
  - name: OOB
  - name: Provider Keys
  - name: Public Shares
  - name: Reinforcements
  - name: Reports
  - name: Scans
  - name: Schedules
  - name: Shares
  - name: Tools
  - name: User Profiles
  - name: V1
  - name: Vulnerabilities
  - name: Workflows
paths:
  /api/scans:
    get:
      tags:
        - Scans
      summary: List scans
      description: >-
        List the caller's scans, newest first. The q search matches the scan
        target.
      operationId: getApiScans
      parameters:
        - name: q
          in: query
          required: false
          schema:
            type: string
          description: Case-insensitive contains search.
        - name: page
          in: query
          required: false
          schema:
            type: integer
          description: Page number, 1-based.
        - name: limit
          in: query
          required: false
          schema:
            type: integer
          description: Items per page (1-100, default 20).
        - name: sort
          in: query
          required: false
          schema:
            type: string
            enum:
              - createdAt
              - updatedAt
          description: Sort column (allowlisted).
        - name: order
          in: query
          required: false
          schema:
            type: string
            enum:
              - asc
              - desc
          description: Sort direction (default desc).
      responses:
        '200':
          description: One page of scans.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  items:
                    type: array
                    items:
                      type: object
                      properties:
                        _id:
                          type: string
                        userId:
                          type: string
                        target:
                          type: string
                        type:
                          type: string
                        scope:
                          default: []
                          type: array
                          items:
                            type: object
                            properties:
                              type:
                                type: string
                              value:
                                type: string
                            required:
                              - type
                              - value
                            additionalProperties: false
                        workflowSteps:
                          default: []
                          type: array
                          items:
                            type: object
                            properties:
                              name:
                                type: string
                              tool:
                                type: string
                              args:
                                default: []
                                type: array
                                items:
                                  type: string
                              env:
                                default: {}
                                type: object
                                propertyNames:
                                  type: string
                                additionalProperties:
                                  type: string
                              retryCount:
                                default: 0
                                type: integer
                                minimum: -9007199254740991
                                maximum: 9007199254740991
                              timeout:
                                default: 300
                                type: integer
                                minimum: -9007199254740991
                                maximum: 9007199254740991
                              status:
                                type: string
                            required:
                              - name
                              - tool
                              - args
                              - env
                              - retryCount
                              - timeout
                            additionalProperties: {}
                        status:
                          default: pending
                          type: string
                          enum:
                            - pending
                            - queued
                            - running
                            - completed
                            - failed
                            - cancelled
                        workflowId:
                          type: string
                        startedAt: {}
                        completedAt: {}
                        error:
                          type: string
                        metadata:
                          default: {}
                          type: object
                          propertyNames:
                            type: string
                          additionalProperties: {}
                        createdAt:
                          default: '2026-09-18T11:34:11.686Z'
                        updatedAt:
                          default: '2026-09-18T11:34:11.686Z'
                      required:
                        - userId
                        - target
                        - type
                        - scope
                        - workflowSteps
                        - status
                        - metadata
                        - createdAt
                        - updatedAt
                      additionalProperties: false
                  total:
                    type: number
                  page:
                    type: number
                  limit:
                    type: number
                  totalPages:
                    type: number
                required:
                  - items
                  - total
                  - page
                  - limit
                  - totalPages
                additionalProperties: false
        '401':
          description: No valid session cookie or API key.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
                additionalProperties: false
      security:
        - apiKeyCookie: []
        - apiKeyHeader: []
        - bearerAuth: []
components:
  securitySchemes:
    apiKeyCookie:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: Browser session cookie set by Better Auth sign-in.
    apiKeyHeader:
      type: apiKey
      in: header
      name: x-api-key
      description: Personal API key (aquila_… prefix; settings → API keys).
    bearerAuth:
      type: http
      scheme: bearer
      description: Personal API key sent as a bearer token.

````