PUT/v1/vex

Upload a base64-encoded VEX document

Uploads a base64-encoded CycloneDX VEX document for a project. Provide project, projectName, projectVersion, and vex; project must be a UUID, and vex must contain valid base64-encoded data. The vex value is limited to 20,000,000 characters, so use POST for larger documents; the response includes a token for checking processing progress.

4 body fields

JSON payload for uploading a base64-encoded CycloneDX VEX document. All fields are required.

projectstringrequired
The project UUID, in the form of 8-4-4-4-12 hexadecimal characters.
projectNamestringrequired
The project name. Must contain at least one character.
projectVersionstringrequired
The project version. Must contain at least one character.
vexstringrequired
The VEX document encoded as base64. Must be valid base64 and no longer than 20,000,000 characters.

5 status codes
200Returns the project UUID and a token you can use to check VEX processing progress.
projectUuidstringrequired
UUID of the project the BOM was uploaded for
tokenstringrequired
Token used to check task progress
400Returned when the payload is invalid or the VEX document fails CycloneDX schema validation.
detailstringrequired
Human-readable explanation specific to this occurrence of the problem
instancestringoptional
Reference URI that identifies the specific occurrence of the problem
statusintegerrequired
HTTP status code generated by the origin server for this occurrence of the problem
titlestringrequired
Short, human-readable summary of the problem type
typestringoptional
A URI reference that identifies the problem type
errorsarray<string>optional
Errors identified during schema validation
401Returned when the request is unauthorized.
403Returned when access to the requested project is forbidden.
detailstringrequired
Human-readable explanation specific to this occurrence of the problem
instancestringoptional
Reference URI that identifies the specific occurrence of the problem
statusintegerrequired
HTTP status code generated by the origin server for this occurrence of the problem
titlestringrequired
Short, human-readable summary of the problem type
typestringoptional
A URI reference that identifies the problem type
404Returned when the project cannot be found.

Error handling

A 400 is returned when the payload is invalid or the VEX fails CycloneDX schema validation. All four fields are required: project must match the UUID format, projectName and projectVersion must be non-empty, and vex must be valid base64 and no longer than 20,000,000 characters. A 401 indicates an unauthorized request, a 403 indicates that the authenticated user lacks permission or access to the project, and a 404 is returned when the project cannot be found.