> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an image target

> Scan a container image for known vulnerabilities. The platform scans the image's packages and records what is known against them, so name the image the way the registry does, tag and all (registry.example.com/acme/api:1.4.2). One row per image per organization: an image two clusters run is one target, and adding one that discovery already filed is refused as taken. The first scan runs shortly after; scan_image_now runs one at once. Needs the infrastructure suite.



## OpenAPI

````yaml /api-reference/openapi.json post /image_targets
openapi: 3.1.0
info:
  description: >-
    A resource-shaped endpoint onto the same tool surface the MCP server
    (/api/mcp) reaches. Every gate, refusal and audit row a caller sees here is
    the exact one the MCP endpoint answers for the same tool. Authenticated with
    an API key holding the api:admin scope, or the read-only api:config_read
    scope for GET alone.
  title: SRE Agent configuration API
  version: 1.0.0
servers:
  - url: https://sreagent.app/api/v1/config
security:
  - apiKey: []
tags:
  - name: ai_providers
  - name: ai_settings
  - name: alert_mutes
  - name: alert_routes
  - name: aws_external_id
  - name: certificate_monitors
  - name: change_notifications
  - name: compliance_periods
  - name: connectors
  - name: data_sources
  - name: deploy_policies
  - name: export
  - name: github_settings
  - name: image_targets
  - name: notification_settings
  - name: organization_settings
  - name: outbound_configs
  - name: outbound_rules
  - name: overseer_settings
  - name: prompt_templates
  - name: repo_settings
  - name: service_bindings
  - name: slack
  - name: slis
  - name: slos
  - name: status_page_components
  - name: status_page_incidents
  - name: status_page_settings
  - name: synthetic_checks
  - name: team_members
  - name: teams
  - name: ticket_import_rules
  - name: ticket_integrations
paths:
  /image_targets:
    post:
      tags:
        - image_targets
      summary: Create an image target
      description: >-
        Scan a container image for known vulnerabilities. The platform scans the
        image's packages and records what is known against them, so name the
        image the way the registry does, tag and all
        (registry.example.com/acme/api:1.4.2). One row per image per
        organization: an image two clusters run is one target, and adding one
        that discovery already filed is refused as taken. The first scan runs
        shortly after; scan_image_now runs one at once. Needs the infrastructure
        suite.
      operationId: create_image_target
      parameters: []
      requestBody:
        content:
          application/json:
            schema:
              properties:
                image_ref:
                  description: >-
                    The image reference, as the registry spells it. A digest is
                    accepted where the registry serves one.
                  type: string
              required:
                - image_ref
              type: object
        required: true
      responses:
        '201':
          description: Created.
        '409':
          description: A row already matches this resource's natural key.
        '422':
          description: The tool refused the request's shape or content.
        default:
          description: The request failed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      description: The body of every failed request.
      properties:
        error:
          type: string
          description: >-
            A short machine-readable code such as forbidden, conflict or
            read_only_key.
        message:
          type: string
          description: A sentence that says what to change.
      required:
        - error
        - message
      additionalProperties: true
  securitySchemes:
    apiKey:
      description: >-
        An sre_ak_* API key holding the api:admin scope (or api:config_read,
        which every write refuses with read_only_key).
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.