Scans your repository with the Surface CLI (apisec-surface) and uploads the result to APIsec. Surface replaces Code Discovery / Code Bolt; applications created by Code Discovery are updated in place.
- Add two repository secrets (Settings → Secrets and variables → Actions):
API_DISCOVERY_ENDPOINT: your APIsec API URL, for examplehttps://api.apisecapps.comAPI_DISCOVERY_TOKEN: an APIsec personal access token with theapp:createpermission
- Add
.github/workflows/api-discovery.yml:
name: API Discovery
on:
push:
branches: [main]
jobs:
discover:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: apisec-inc/apisec-bolt-code-discovery-github-action@v1
with:
api-endpoint: ${{ secrets.API_DISCOVERY_ENDPOINT }}
api-token: ${{ secrets.API_DISCOVERY_TOKEN }}Existing Code Discovery workflows only need the tag changed to @v1. The contents: write and pull-requests: write permissions are no longer needed.
- uses: apisec-inc/apisec-bolt-code-discovery-github-action@v1
with:
api-endpoint: ${{ secrets.API_DISCOVERY_ENDPOINT }}
api-token: ${{ secrets.API_DISCOVERY_TOKEN }}
dry-run: true| Input | Required | Default | Description |
|---|---|---|---|
api-endpoint |
Yes | APIsec API URL | |
api-token |
Yes | APIsec personal access token | |
repo-path |
No | . |
Repository root to analyze |
dry-run |
No | false |
Analyze only; do not upload |
config-path |
No | .codediscovery.yml |
Ignored |
host-url |
No | Ignored; set the instance host in the APIsec console | |
pr-title |
No | Ignored; no spec PR is opened | |
pr-body |
No | Ignored; no spec PR is opened |
| Output | Description |
|---|---|
success |
true only when the scan completed |
application-id |
APIsec application id after a successful upload |
endpoints-count |
Number of API routes found |
frameworks-detected |
Comma-separated frameworks |
spec-path |
Empty (the spec is published by APIsec) |
instance-id |
Empty |
pr-url |
Empty |
The Action never fails the workflow. Check success if a later step should stop.
- Installs Python 3.11 and Surface CLI
1.0.0 - Registers or reuses one APIsec application per GitHub repository
- Uploads the Surface analysis; APIsec publishes the OpenAPI spec
After the first run, set the instance host URL in the APIsec console if the default / is not your API base.
- No pull request is opened and no files are committed to your repository.
host-url,config-path,pr-titleandpr-bodyare accepted but ignored.spec-path,instance-idandpr-urloutputs are empty.
- Java: Spring Boot, Micronaut, JAX-RS (Jersey, Quarkus, RESTEasy), Servlet
- Python: FastAPI, Flask, Django
- JavaScript / TypeScript: Express, NestJS, Fastify, Koa
- .NET: ASP.NET Core, ASP.NET MVC / Web API, Web Forms, gRPC, WCF
- Ruby: Rails, Sinatra, Grape, Hanami, Roda, Padrino
- GraphQL
Go (Gin) and Argos are not yet supported in Surface. Keep those repositories on @v0.1.9 until they are.
Pin @v0.1.9 to run Code Discovery again.