> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://hiddenlayer.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://hiddenlayer.ferndocs.com/_mcp/server.

# Scan a remote model

POST https://api.hiddenlayer.ai/scan/v3/jobs
Content-Type: application/json; charset=utf-8

Reference: https://hiddenlayer.ferndocs.com/api-reference/llm-proxy-api/jobs/request

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Servers

- `https://api.hiddenlayer.ai` (ProdUs, default)
- `https://api.eu.hiddenlayer.ai` (ProdEu)

## Request

### Body (application/json; charset=utf-8)

This endpoint expects a ScanJobRequest.

- `inventory` (ScanJobRequestInventory, required)
- `access` (ScanJobRequestAccess, required) — Access method for the location of files associated with the scan
- `scan_id` (string, optional) — unique identifier for the scan
- `status` (enum, optional) — Status of the scan
  - Allowed values: `pending`, `running`, `done`, `failed`, `canceled`

## Response

### 201

Scan job request was accepted

- `inventory` (ScanJobInventory, required)
- `scan_id` (string, optional) — unique identifier for the scan
- `status` (enum, optional) — Status of the scan
  - Allowed values: `pending`, `running`, `done`, `failed`, `canceled`

## Errors

### 400 Bad Request Error

The request failed due to a client error, with one or more of the following possible causes: 1. The request required a tenant_id field, which was missing. 2. The request was malformed syntactically or semantically.

- `any`

### 422 Unprocessable Entity Error

Validation Error

- `errors` (list of ProblemDetailsErrorsItems, required) — Error details
- `type` (string, optional) — https://www.rfc-editor.org/rfc/rfc9457.html#name-type
- `title` (string, optional) — https://www.rfc-editor.org/rfc/rfc9457.html#name-title
- `detail` (string, optional) — https://www.rfc-editor.org/rfc/rfc9457.html#name-detail
- `instance` (string, optional) — https://www.rfc-editor.org/rfc/rfc9457.html#name-instance

## Types

### ScanJobRequestInventory

- `model_name` (string, required) — Name of the model
- `model_version` (string, required) — If you do not provide a version, one will be generated for you.
- `requesting_entity` (string, required) — Entity that requested the scan
- `scan_target` (ScanJobRequestInventoryScanTarget, optional) — Specifies what to scan. Must provide at least one of: deep_scan with file location details, provider_details, or both.
- `request_source` (enum, optional) — Identifies the system that requested the scan
  - Allowed values: `Hybrid Upload`, `API Upload`, `Integration`, `UI Upload`, `AI Asset Discovery`
- `origin` (string, optional) — Specifies the platform or service where the model originated before being scanned
- `requested_scan_location` (string, optional, deprecated) — **DEPRECATED**: Use `scan_target` instead. Location of files to be scanned. Maintained for backwards compatibility. If both `requested_scan_location` and `scan_target` are provided, `scan_target` takes precedence.

### ScanJobRequestAccess

Access method for the location of files associated with the scan

- `source` (enum, optional)
  - Allowed values: `LOCAL`, `AWS_PRESIGNED`, `AWS_IAM_ROLE`, `AZURE_BLOB_SAS`, `AZURE_BLOB_AD`, `GOOGLE_SIGNED`, `GOOGLE_OAUTH`, `HUGGING_FACE`, `NONE`

### ScanJobInventory

- `model_name` (string, required) — Name of the model
- `model_version` (string, required) — If you do not provide a version, one will be generated for you.
- `requesting_entity` (string, required) — Entity that requested the scan
- `scan_target` (ScanJobInventoryScanTarget, optional) — Specifies what to scan. Must provide at least one of: deep_scan with file location details, provider_details, or both.
- `request_source` (enum, optional) — Identifies the system that requested the scan
  - Allowed values: `Hybrid Upload`, `API Upload`, `Integration`, `UI Upload`, `AI Asset Discovery`
- `origin` (string, optional) — Specifies the platform or service where the model originated before being scanned
- `requested_scan_location` (string, optional, deprecated) — **DEPRECATED**: Use `scan_target` instead. Location of files to be scanned. Maintained for backwards compatibility. If both `requested_scan_location` and `scan_target` are provided, `scan_target` takes precedence.

### ProblemDetailsErrorsItems

- `code` (string, optional)
- `detail` (string, optional)
- `pointer` (list of string, optional) — array of JSON Pointers

### ScanJobRequestInventoryScanTarget

Specifies what to scan. Must provide at least one of: deep_scan with file location details, provider_details, or both.

### ScanJobInventoryScanTarget

Specifies what to scan. Must provide at least one of: deep_scan with file location details, provider_details, or both.

## Examples

**Request**

```json
{
  "inventory": {
    "model_name": "keras-tf-2025-05-27",
    "model_version": "1.0.0",
    "requesting_entity": "string"
  }
}
```

**Response**

```json
{
  "inventory": {
    "model_name": "keras-tf-2025-05-27",
    "model_version": "1.0.0",
    "requesting_entity": "string",
    "scan_target": null,
    "request_source": "Hybrid Upload",
    "origin": "Hugging Face",
    "requested_scan_location": "/files-to-scan"
  },
  "scan_id": "00000000-0000-0000-0000-000000000000",
  "status": "pending"
}
```

**SDK Code**

```python
import requests

url = "https://api.hiddenlayer.ai/scan/v3/jobs"

payload = "{\n  \"inventory\": {\n    \"model_name\": \"keras-tf-2025-05-27\",\n    \"model_version\": \"1.0.0\",\n    \"requesting_entity\": \"string\"\n  }\n}"
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json; charset=utf-8"
}

response = requests.post(url, data=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.hiddenlayer.ai/scan/v3/jobs';
const options = {
  method: 'POST',
  headers: {
    Authorization: 'Bearer <token>',
    'Content-Type': 'application/json; charset=utf-8'
  },
  body: '{\n  "inventory": {\n    "model_name": "keras-tf-2025-05-27",\n    "model_version": "1.0.0",\n    "requesting_entity": "string"\n  }\n}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.hiddenlayer.ai/scan/v3/jobs"

	payload := strings.NewReader("{\n  \"inventory\": {\n    \"model_name\": \"keras-tf-2025-05-27\",\n    \"model_version\": \"1.0.0\",\n    \"requesting_entity\": \"string\"\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json; charset=utf-8")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.hiddenlayer.ai/scan/v3/jobs")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json; charset=utf-8'
request.body = "{\n  \"inventory\": {\n    \"model_name\": \"keras-tf-2025-05-27\",\n    \"model_version\": \"1.0.0\",\n    \"requesting_entity\": \"string\"\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.hiddenlayer.ai/scan/v3/jobs")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json; charset=utf-8")
  .body("{\n  \"inventory\": {\n    \"model_name\": \"keras-tf-2025-05-27\",\n    \"model_version\": \"1.0.0\",\n    \"requesting_entity\": \"string\"\n  }\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.hiddenlayer.ai/scan/v3/jobs', [
  'body' => '{
  "inventory": {
    "model_name": "keras-tf-2025-05-27",
    "model_version": "1.0.0",
    "requesting_entity": "string"
  }
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json; charset=utf-8',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.hiddenlayer.ai/scan/v3/jobs");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json; charset=utf-8");
request.AddParameter("application/json; charset=utf-8", "{\n  \"inventory\": {\n    \"model_name\": \"keras-tf-2025-05-27\",\n    \"model_version\": \"1.0.0\",\n    \"requesting_entity\": \"string\"\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json; charset=utf-8"
]

let postData = NSData(data: "{
  "inventory": {
    "model_name": "keras-tf-2025-05-27",
    "model_version": "1.0.0",
    "requesting_entity": "string"
  }
}".data(using: String.Encoding.utf8)!)

let request = NSMutableURLRequest(url: NSURL(string: "https://api.hiddenlayer.ai/scan/v3/jobs")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```