Concepts

Core concepts for building with the Bevor API

Core Concepts

Understanding the fundamental concepts of the Bevor API will help you build effective security integrations and workflows.

Authentication & API Keys

All API endpoints require authentication using Bearer tokens. Include your API key in the Authorization header:

Authorization: Bearer YOUR_API_KEY

API Key Management

  • Creation & Refresh: API keys can be created and refreshed through the Bevor Dashboard
  • Team Scoping: API keys are scoped to specific teams, ensuring proper access control
  • Permission Scopes: API keys have their own scopes, allowing you to create read-only keys for different environments
  • Security: Never share API keys in public repositories or client-side code
  • User-Specific: API keys will technically be scoped to the user that created them. This is fine for most use-cases, but you might lose granularity in billing and activities. We recommend that each user generates their own API key

API Key Scopes

API keys support different permission levels to match your security requirements:

  • Full Access: Complete read and write access to all team resources
  • Read-Only: View-only access to projects, code versions, and audit results

Note

Use read-only API keys in production environments or CI/CD pipelines where you only need to retrieve analysis results and don't require write access to create new resources.

Get Your API Key

Create and manage API keys in the dashboard

Teams

Teams are the top-level organizational unit in Bevor:

  • Billing: Billing is managed by Stripe at the team level.
  • Access Control: API keys are scoped to teams, controlling which resources you can access
  • Management: Creating and updating teams is only accessible via the Bevor Dashboard
  • Collaboration: Inviting other users to a team can help you move faster.

Note

Team management operations (create, update, delete) are not available through the API. Use the dashboard for team administration.

Projects

Projects are generic containers for logical separation of code and security work:

  • Organization: Use projects to group related contract repositories, code iterations, or security assessments
  • Flexibility: Projects can represent different applications, protocols, or development phases
  • Tracking: All analyses and scans within a project are grouped together for easy management
  • Github: By default, each github repository will be its own project once linked

Project Use Cases

  • Local Development: Keep iterations through local development logically grouped to a single project
  • Protocol Iterations: Monitor security across different versions of your protocol
  • Feature Development: Separate security assessments for different features or modules

Code Versions

Code versions represent specific iterations or snapshots of your codebase:

  • Versioning: Track different versions of your smart contracts or applications
  • Analysis Tracking: Each code version can have multiple analyses associated with it
  • Iteration Management: Compare security findings across different code versions
  • Github: With our github integration, each commit will generate a new code version automatically. You can manually point Bevor to specific branches/commits if you want Bevor to process it.

Analyses

Analyses are security assessments performed on your code versions:

  • Non-Deterministic: Analyses may produce different results on subsequent runs
  • Iteratives: Each analysis can be iterated on either manually, or automatically via our chat interface for arbitration
  • Inheritance: If analyses are built upon prior versions, information is retained if we detect no changes in relevant segments of the underlying code
  • AI-Powered: Leverages advanced AI models for thorough security analysis
  • Bring Your Own Security (BYOS): With Bevor, you can automate your security practices with any tool that'd you like. If your pipeline can detect findings, and associate those to segments of code, we can ingest it. This keeps your security posture consistent with your actual workflow, while helping mitigate redundancy.

Security Analysis Best Practices

  • Iterate: Schedule analyses at key development milestones
  • Comparison: Compare analysis results across different code versions to track security improvements. Evaluate your security posture over time, see how your team remediates and attests to findings
  • Triage: Triage with your team, our internal AI-automated systems, or your own 3rd party AI systems, for optimal results

Workflow Example

Here's a typical workflow using the concepts above:

  1. Team Setup: Create a team in the dashboard for your organization
  2. API Key: Generate an API key
  3. Github Integration: Connect your Github, which automatically creates a new project
  4. Code Version: Our integration will automatically process the HEAD commit on your default branch, then any subsequent push commits pushed to remote. The code will be ready for you when you land on Bevor dashboard or access it via the API
  5. Question Answering: Use our chat interface to help onboard to the codebase if it's unfamiliar to you
  6. Analysis Kickoff: Kick off an analysis using Bevor's internal security pipeline, or upload findings using your own security workflow
  7. Triage: Take the initial findings and triage in our built-in chat interface to curate your findings, and produce new ones. Using your own workflow is completely valid to be able to reject findings, add new ones, or edit current ones
  8. Iterate: Make changes to your code. Bevor will process it, and carry over any relevant findings automatically, so that you never have to start from scratch. Only the changed segments are candidates to be re-analyzed if needed
  9. Collaborate: Tag your team members in findings, have them fork your work and continue where you left off, focus on different segments of the codebase, merge your analyses later to produce a final handoff
Interactive API Documentation

Explore endpoints, parameters, and examples

Integration Types

CLI and SDK

Terminal and typed Python interfaces backed by the same API resources.

Bevor Skills

Agent guidance for using the CLI and SDK in graph-aware coding workflows.

CI/CD

Continuous reporting and team insights integrated into your development pipeline.

API

Custom workflows and integrations for specialized use cases and protocol-specific needs.

Dashboard

In-depth insights and automation through the Bevor dashboard.

Multi-Agent Triaging (A2A)

Risk profiling and orchestration for complex security scenarios.

On-Premises Deployment

Note

Enterprise on-premises deployment is coming soon. For early access and custom deployment options, contact our sales team at contact@bevor.io.

On this page