Mark a finding as an exception so it no longer appears in the active Scan Results list
curl --request POST \
--url https://api.trycomp.ai/v1/cloud-security/findings/{findingId}/exception \
--header 'Content-Type: application/json' \
--data '
{
"reason": "Bucket hosts intentionally public marketing assets; writes restricted to the marketing IAM role."
}
'const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
reason: 'Bucket hosts intentionally public marketing assets; writes restricted to the marketing IAM role.'
})
};
fetch('https://api.trycomp.ai/v1/cloud-security/findings/{findingId}/exception', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.trycomp.ai/v1/cloud-security/findings/{findingId}/exception"
payload = { "reason": "Bucket hosts intentionally public marketing assets; writes restricted to the marketing IAM role." }
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)Cloud Security
Mark a finding as an exception so it no | Comp AI API
Accepts session, API key, or service token auth. For API key / service token callers without an explicit user attribution, the action is attributed to the.
POST
/
v1
/
cloud-security
/
findings
/
{findingId}
/
exception
Mark a finding as an exception so it no longer appears in the active Scan Results list
curl --request POST \
--url https://api.trycomp.ai/v1/cloud-security/findings/{findingId}/exception \
--header 'Content-Type: application/json' \
--data '
{
"reason": "Bucket hosts intentionally public marketing assets; writes restricted to the marketing IAM role."
}
'const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
reason: 'Bucket hosts intentionally public marketing assets; writes restricted to the marketing IAM role.'
})
};
fetch('https://api.trycomp.ai/v1/cloud-security/findings/{findingId}/exception', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.trycomp.ai/v1/cloud-security/findings/{findingId}/exception"
payload = { "reason": "Bucket hosts intentionally public marketing assets; writes restricted to the marketing IAM role." }
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)Path Parameters
Body
application/json
Documentation for why this finding does not apply or is being accepted. Minimum 20 non-whitespace characters.
Example:
"Bucket hosts intentionally public marketing assets; writes restricted to the marketing IAM role."
Free-text reviewer or approval reference.
Example:
"Approved by CISO 2026-Q1"
ISO date when this exception should auto-expire. Null/missing = never.
Example:
"2026-08-13"
Response
201 - undefined
Was this page helpful?

