A new release of Qualys WAS, Version 4.0 which includes an API update, is targeted for release in mid-December. The updated APIs for WAS 4.0 enable customers to fully automate and integrate the Qualys WAS solution with their existing applications. WAS APIs enable customers to perform all the major functions within WAS including creating web applications to scan, launching and scheduling scans, and running and retrieving reports. The APIs enable custom integrations with GRC tools, bug tracking systems and web application firewalls (WAFs) just to name a few.
The exact dates for the release depend on the platform your subscription is on. The release dates by platform are as follows:
The specified item was not found.
A review of the many new UI features and enhancements can be found at The specified item was not found.
This API notification provides an early preview into the coming API changes in Qualys WAS 4.0, allowing you to proactively identify any changes that might be required for your automated scripts or programs that utilize the API methods. Two API modifications in this release may impact existing API implementations and required a 30-day notification which can be found at Qualys WAS 4.0 API Release Notification. The changes below are based on a limited release feature Progressive Scanning and therefore should not impact any subscription without the feature enabled.
Full release notes will be available to customers on the day of the release.
Details are in the attached document - high level summary of APIs updated:
Web App API,
- Schema: webapp.xsd
- Create/Update Web Application
- GET web application
- Schema: scan.xsd / wasscan.xsd
- Launch Scan
- GET scan
- Schema: schedule.xsd / wasscanschedule.xsd
- Create/update Schedule
- Get Schedule
Scan Report (XML)
- Schema: finding.xsd
- Get Finding
See attached PDF for details of changes and examples.
What is the <baseurl>?
This is the API server URL where your Qualys account is located. For an account on US Platform 1, this is <qualysapi.qualys.com>; on US Platform 2, this is <qualysapi.qg2.apps.qualys.com>; on EU Platform, this is <qualysapi.qualys.eu>.