403 Forbidden on /hosts/bulk_create API endpoint, possible license restriction?

#534 · closed · 3 comments

View on GitHub ↗

krapovneru

Hi folks, I’m trying to use the REST API endpoint: `POST /_api/v3/ws/<WORKSPACE_NAME>/hosts/bulk_create/` to create hosts in bulk. Authentication is done via API Token obtained from: `GET /_api/v3/token/` The token is successfully generated (HTTP 200), but when I try to call hosts/bulk_create, I always get: ``` 403 Forbidden You don’t have the permission to access the requested resource. It is either read-protected or not readable by the server. ``` ### What I already verified - Token is valid and returned correctly - Authorization header is: `Authorization: Token <my_token>` - Workspace exists - User has admin permissions in the UI (faraday) ### Example request ``` python url = f"{FARADAY_URL}/_api/v3/ws/{WORKSPACE}/hosts/bulk_create/" headers = { "Authorization": f"Token {api_token}", "Content-Type": "application/json" } payload = [ {"ip": "192.168.1.10", "name": "test-host"} ] requests.post(url, headers=headers, json=payload) ``` Is this endpoint restricted by license type? If so: • Which license tier is required for hosts/bulk_create? • Is there any official documentation listing API limitations per license? If not, could you advise what permissions or configuration are required?

Comments

ignaciosoto93

Hi @krapovneru, thanks for reporting this! **This is not a license restriction.** You're hitting a CSRF validation check because `/hosts/bulk_create` is a web UI endpoint (CSV upload) that expects a browser session token. API token auth will always fail CSRF validation there, returning 403. ### The fix Use the programmatic bulk create endpoint instead: POST /_api/v3/ws/{workspace_name}/bulk_create/ Authorization: Token Content-Type: application/json ```json { "hosts": [ { "ip": "192.168.1.1", "os": "Linux", "description": "Example host", "hostnames": ["host1.example.com"], "services": [], "vulnerabilities": [] } ], "command": { "tool": "my-tool", "command": "scan", "start_date": "2026-02-05T00:00:00" } } ``` Both hosts and command are required. On success you'll get a 201 Created with a command_id. Check that your target workspace is active and not read-only. Let us know if you run into anything else!

ignaciosoto93

Hi @krapovneru any update on this? Inactivity issues will be closed after 2 weeks. Thanks

ignaciosoto93

Closed for inactivity!