> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cotool.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Dispose an observability gap

> Resolve or dismiss an org-level observability gap once, for every threat it affects. Resolving a blocking gap enqueues a reassessment for each linked threat whose hunt it blocked.



## OpenAPI

````yaml https://app.cotool.ai/api/docs/openapi.json post /api/hunt/gaps/{gapId}/status
openapi: 3.1.0
info:
  title: Cotool API
  version: 1.0.0
  description: >-
    # Cotool API Documentation


    The Cotool API allows you to interact with the Cotool platform
    programmatically, enabling you to build powerful integrations and automate
    your workflows.


    ## Getting an API Key


    Follow these steps to generate your API key:


    1. **Log in** to the Cotool web interface

    2. **Navigate** to `/settings/api-keys`

    3. **Click** "Generate Key"

    4. **Copy and store** your API key securely ⚠️ *It won't be shown again*


    ## API Key Authentication


    For programmatic access and integrations, use your API key with the
    Authorization header:


    ```http

    Authorization: Bearer your_api_key_here

    ```


    ```bash

    curl -X GET "https://app.cotool.ai/api/endpoint" \
      -H "Authorization: Bearer your_api_key_here" \
      -H "Content-Type: application/json"
    ```
servers:
  - url: https://app.cotool.ai
    description: Production server
security:
  - ApiKeyAuth: []
paths:
  /api/hunt/gaps/{gapId}/status:
    post:
      tags:
        - Hunt
      summary: Dispose an observability gap
      description: >-
        Resolve or dismiss an org-level observability gap once, for every threat
        it affects. Resolving a blocking gap enqueues a reassessment for each
        linked threat whose hunt it blocked.
      parameters:
        - in: path
          name: gapId
          schema:
            type: string
          required: true
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                status:
                  type: string
                  enum:
                    - resolved
                    - dismissed
                reason:
                  type: string
              required:
                - status
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  gap:
                    type: object
                    properties:
                      id:
                        type: string
                      organizationId:
                        type: string
                      product:
                        type: string
                      logSource:
                        type: string
                      scopeType:
                        type: string
                        enum:
                          - org
                          - integration
                          - account
                          - environment
                          - asset_group
                          - tenant
                          - domain
                      scopeId:
                        type:
                          - string
                          - 'null'
                      scopeKey:
                        type: string
                      blocking:
                        type: boolean
                      status:
                        type: string
                        enum:
                          - open
                          - resolved
                          - dismissed
                      establishedAt:
                        type: string
                      statusAt:
                        type:
                          - string
                          - 'null'
                      statusActor:
                        anyOf:
                          - type: object
                            properties:
                              type:
                                type: string
                                const: agent
                              runId:
                                type: string
                            required:
                              - type
                              - runId
                          - type: object
                            properties:
                              type:
                                type: string
                                const: human
                              userId:
                                type: string
                            required:
                              - type
                              - userId
                          - type: 'null'
                      statusReason:
                        type:
                          - string
                          - 'null'
                      createdAt:
                        type: string
                      updatedAt:
                        type: string
                    required:
                      - id
                      - organizationId
                      - product
                      - logSource
                      - scopeType
                      - scopeId
                      - scopeKey
                      - blocking
                      - status
                      - establishedAt
                      - statusAt
                      - statusActor
                      - statusReason
                      - createdAt
                      - updatedAt
                  linkedThreats:
                    type: array
                    items:
                      type: object
                      properties:
                        threatId:
                          type: string
                        threatTitle:
                          type: string
                        canonicalKey:
                          type: string
                        blocking:
                          type: boolean
                      required:
                        - threatId
                        - threatTitle
                        - canonicalKey
                        - blocking
                  reassessedThreatIds:
                    type: array
                    items:
                      type: string
                required:
                  - gap
                  - linkedThreats
                  - reassessedThreatIds
        '400':
          description: Bad request — input validation failed or the request was malformed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationError'
        '401':
          description: Unauthorized — missing or invalid API key / session
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Caller lacks the alert.triage permission.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Gap not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      x-codeSamples:
        - lang: shell
          label: cURL
          source: |-
            curl -X POST "https://app.cotool.ai/api/hunt/gaps/:gapId/status" \
              -H "Authorization: Bearer YOUR_API_KEY" \
              -H "Content-Type: application/json" \
              -d '{"status":"resolved","reason":"string"}'
components:
  schemas:
    ValidationError:
      type: object
      properties:
        error:
          type: string
          description: Error message describing what went wrong
        issues:
          type: array
          description: >-
            Detailed validation issues, present when request or response schema
            validation fails
          items:
            type: object
            additionalProperties: true
      required:
        - error
    Error:
      type: object
      properties:
        error:
          type: string
          description: Error message describing what went wrong
      required:
        - error
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: >-
        API Key authentication for programmatic access. Include your API key in
        the Authorization header as: `Bearer your_api_key_here`

````