---
title: Intruder API Integration on Truto
slug: intruder
category: Security
canonical: "https://truto.one/integrations/detail/intruder/"
---

# Intruder API Integration on Truto



**Category:** Security  
**Status:** Generally available

## MCP-ready AI tools

Truto exposes 31 tools for Intruder that AI agents can call directly.

- **list_all_intruder_health** — Check that the Intruder API is running normally. Returns: status, authenticated_as, openapi, info, paths, components, servers.
- **list_all_intruder_issue_occurrences** — List occurrences for an issue in Intruder. Returns: id, occurrence_id, target, display_address, port, protocol, extra_info, age, snoozed, snooze_reason, snooze_until, exploit_likelihood, cvss_score, first_seen_at, target_last_scanned_at, cves. Required: issue_id. occurrence_id is the stable ID that persists across scans; id may change between scans.
- **list_all_intruder_issues** — List current issues in Intruder, with filters for severity, snoozing, tags, target addresses, and new occurrences since a timestamp. Returns: id, severity, title, description, remediation, snoozed, snooze_reason, snooze_until, occurrences, exploit_likelihood, cvss_score.
- **create_a_intruder_scan** — Start a scan in Intruder. Returns the created scan including its id, status, scan_type, created_at, target_addresses, and start_time. Optionally pass target_addresses and/or tag_names in the body — with no body it scans all targets. Max 500 active and scheduled scans.
- **list_all_intruder_scans** — List current scans in Intruder. Returns scan records including id, status, scan_type, schedule_period, and created_at; filter by scan_type, status, schedule_period, or tag_names.
- **intruder_scans_cancel** — Cancel a running scan in Intruder. Returns the confirmation string "Scan was cancelled" on success. Required: scan_id.
- **get_single_intruder_scan_by_id** — Get a single Intruder scan's details by id. Returns: id, status, created_at, target_addresses, scan_type, throttled, web_ports_only, schedule_period, start_time, completed_time, openapi, info, paths, components, servers. Required: id.
- **intruder_targets_bulk_create** — Bulk add multiple targets in Intruder, including CIDR ranges. Returns the created target including id, address, display_address, target_status, license_type, and tags. Required: address for each target in the array.
- **create_a_intruder_target** — Add a target in Intruder. Returns the created target including id, address, display_address, target_status, target_type, license_type, and tags. Required: address; type and url when target_authentication is supplied.
- **list_all_intruder_targets** — List Intruder targets. Returns: id, address, display_address, has_api_schemas, has_authentications, last_scanned, license_type, waf_provider, waf_interference, tags, target_status, target_type. Filter by address, status, type, tags, or last scan date.
- **delete_a_intruder_target_by_id** — Delete an Intruder target by id. Returns an empty 204 response on success. Required: id.
- **list_all_intruder_fixed_occurrences** — List fixed occurrences in Intruder — vulnerabilities that have been resolved. Returns each occurrence with id, title, severity, cvss_score, affected_host, first_seen_at, and remediated_at.
- **list_all_intruder_licenses** — List infrastructure and application license counts in Intruder. Returns: total_infrastructure_licenses, available_infrastructure_licenses, consumed_infrastructure_licenses, total_application_licenses, available_application_licenses, consumed_application_licenses.
- **create_a_intruder_occurrence_comment** — Add a comment to an occurrence in Intruder. Returns the created comment including its id, content, commenter_type, user, and created_at. Required: issue_id, occurrence_id, content.
- **list_all_intruder_occurrence_comments** — List comments on an occurrence in Intruder, newest first. Returns: id, content, commenter_type, user, created_at, edited_at. Required: issue_id, occurrence_id.
- **list_all_intruder_occurrence_scanner_output** — List scanner output entries for an occurrence of an issue in Intruder. Returns: id, plugin, scanner_output. Required: issue_id, occurrence_id.
- **create_a_intruder_scan_schedule** — Create a scan schedule in intruder that runs recurring scans on your targets. Returns: id, notice, openapi, info, paths, components, servers. Requires name, first_scan_time, and scan_frequency (monthly, daily, weekly, or quarterly); first_scan_time must be in the future and on the hour.
- **delete_a_intruder_scan_schedule_by_id** — Delete a scan schedule in intruder by id, stopping its scheduled recurring scans. Returns an empty 204 response on success. Required: id.
- **list_all_intruder_scan_schedules** — List all scan schedules in intruder. Returns: id, name, schedule_period, first_scan_time, next_scan_date, status, throttled, web_ports_only, latest_scan_id, latest_scan_status, last_scan_start_time, last_scan_end_time, targets, target_tags, upload_to_drata, upload_to_vanta.
- **update_a_intruder_scan_schedule_by_id** — Update a scan schedule in intruder by id. All body fields (name, first_scan_time, scan_frequency, tags, targets, throttled, web_ports_only, upload_to_drata, upload_to_vanta) are optional for a partial update. Returns: notice, openapi, info, paths, components, servers. Required: id.
- **list_all_intruder_tags** — List tags in Intruder. Returns the collection of tag records, each containing its name (up to 40 characters), which also serves as the tag's identifier when adding or removing it from targets. Default page size 25.
- **create_a_intruder_target_api_schema** — Add an API schema to a target in Intruder by uploading a schema file. Returns the created schema including its id, name, base_url, and target_authentication_id. Required: target_id, name, base_url, file (multipart).
- **delete_a_intruder_target_api_schema_by_id** — Delete an API schema from an Intruder target by id. Returns an empty 204 response on success. Required: id and target_id.
- **list_all_intruder_target_api_schemas** — List API schemas attached to an Intruder target. Returns each schema's id, name, base_url, and target_authentication_id. Required: target_id.
- **update_a_intruder_target_api_schema_by_id** — Update an API schema on an Intruder target, optionally replacing its schema file. Returns the updated schema including its id, name, base_url, and target_authentication_id. Required: id and target_id.
- **create_a_intruder_target_authentication** — Add an authentication to a target in Intruder. Returns the created authentication object including its id, url, type, name, and enabled status. Required: target_id, type, url.
- **delete_a_intruder_target_authentication_by_id** — Delete an authentication from a target in Intruder by id. Returns an empty 204 response on success. Required: target_id, id.
- **list_all_intruder_target_authentications** — List the authentications configured for a target in Intruder. Returns each authentication's id, url, type, name, and enabled status. Required: target_id.
- **update_a_intruder_target_authentication_by_id** — Update an authentication on a target in Intruder. Returns the updated authentication with id, url, type, name, and enabled status. Required: target_id, id. All cookies, headers, and additional_parameters key-value pairs you want present must be included in the request; omitted values are removed.
- **create_a_intruder_target_tag** — Create a tag for a target in Intruder. Returns the created tag object including its name (up to 40 characters). Required: target_id, name.
- **intruder_target_tags_bulk_delete** — Delete a tag from a target in Intruder by tag name. Returns an empty 204 response on success. Required: target_id, tag_name.

## How it works

1. **Link your customer's Intruder account.** Use Truto's frontend SDK; we handle every OAuth and API key flow so you don't need to create the OAuth app.
2. **Authentication is automatic.** Truto refreshes tokens, stores credentials securely, and injects them into every API request.
3. **Call Truto's API to reach Intruder.** The Proxy API is a 1-to-1 mapping of the Intruder API.
4. **Get a unified response format.** Every response uses a single shape, with cursor-based pagination and data in the `result` field.

## Use cases

- **Embed continuous vulnerability data in compliance platforms** — Compliance and GRC tools can pull Intruder scan schedules, open issues, and remediation timestamps to automatically evidence SOC 2, ISO 27001, and HIPAA controls for their customers.
- **Power ASPM and risk aggregation dashboards** — Security posture platforms can ingest Intruder issues, occurrences, and raw scanner output to unify DAST findings with SAST and cloud data into a single prioritized risk view.
- **Auto-provision scanning for developer platforms** — Internal developer portals and cloud management tools can create Intruder targets, attach API schemas, and tag assets whenever a new service or environment is spun up, giving every microservice continuous coverage.
- **Sync vulnerabilities into ticketing workflows** — Project management and ITSM tools can convert Intruder issues and occurrences into prioritized tickets based on severity and CVSS score, and close them automatically when the fix is detected.
- **Enable MSSP and multi-tenant security portals** — Managed service providers can offer a branded portal to run on-demand scans, track license consumption per tenant, and collaborate with clients via comments on specific vulnerability occurrences.

## What you can build

- **Vulnerability-to-ticket sync** — Create tickets from Intruder issues and occurrences, mapping severity and CVSS score, and auto-close them when matching fixed occurrences appear.
- **Automated target provisioning** — Bulk-create Intruder targets with tags whenever your platform detects a new IP, CIDR block, or web asset, so new infrastructure is scanned without manual setup.
- **Authenticated DAST scanning setup** — Let users upload an OpenAPI schema and target authentication credentials from your UI so Intruder can scan behind login pages and against specific API routes.
- **On-demand and scheduled scan controls** — Trigger scans, cancel in-progress runs, and manage recurring scan schedules — including Drata and Vanta upload flags — directly from your application.
- **Compliance evidence export** — Surface scan schedules, open issues, and fixed occurrence timestamps as auditor-ready evidence of continuous vulnerability management SLAs.
- **Collaborative remediation comments** — Allow analysts and developers to post and read comments on specific vulnerability occurrences without leaving your product.

## FAQs

### How do end users authenticate their Intruder account?

Users connect their Intruder account through Truto's hosted auth flow using their API key. Truto securely stores and injects credentials on every request, so you don't handle secrets.

### Can we create and manage scan schedules programmatically?

Yes. You can create, list, update, and delete scan schedules, including setting recurrence and the native upload_to_drata and upload_to_vanta flags for compliance workflows.

### How fresh is the vulnerability data?

Data is fetched on-demand from Intruder's API when you call list endpoints for issues, occurrences, or fixed occurrences, so results reflect the current state at request time. You can poll on your own cadence to keep downstream systems in sync.

### Can we scan authenticated web apps and APIs?

Yes. You can attach target authentications (cookies, headers, credentials) and upload API schemas to a target, enabling Intruder to perform DAST scans behind login pages and against defined API routes.

### Does Truto handle pagination across large result sets?

Yes. Truto normalizes pagination for list endpoints like issues, occurrences, targets, and scans so you can iterate through full result sets without implementing Intruder's pagination logic yourself.

### What target operations are supported?

You can create single or bulk targets, list all targets, delete targets by ID, and manage tags via create and bulk delete operations — enough to fully automate asset provisioning and organization.

### Can we track license consumption for multi-tenant use cases?

Yes. The list_all_intruder_licenses endpoint lets MSSPs and multi-tenant platforms query infrastructure and application license usage for billing or capacity planning.
