Skip to content

API access without browser login #655

Description

@kokimo1

Is your feature request related to a problem? Please describe.
Equalify API currently requires SSO JWT auth, so it's not possible to call the API from automated workflows.

Our (SDD) use case: we currently have an automated triage pipeline in development that relies on a manual step to grab new audit results after a scan is done. Basically, I manually export all blockers as CSV from the dash, then I plug it into the system we use to triage/track ongoing auto-detected Equalify issues at the template level in the Red multishite codebase. Note: our janky system currently involves Power Automate scripts, an Office Script in an Excel spreadsheet hosted in an SDD SharePoint folder, and Jira....we have long term plans to brain this thing with an MCP server, ETA TBD.

Describe the solution you'd like
Preferably, programmatic API access that doesn't require browser login. examples:

  1. long-lived API token (like a GitHub personal access token)
  2. API key
  3. service account

How does this feature satisfy Equalify project goals?
API-based automation will make Equalify more useful for UIC. Programmatic access to scan results would be huuuge for teams (like SDD) that integrate Equalify with external trackers (like Jira). Also, this should reduce the risk of data getting stale due to missed human-generated imports.

This would also support the "future integration with existing ticketing systems" suggested feautre mentioned in #578, as ticketing integrations would need programmatic API access.

Describe alternatives you've considered

  • Manual CSV export (current workflow): this works, but it requires a human (me) to do it after every scheduled scan and is kind of a PITA
  • Scraping the Equalify UI: I didn't consider this idea, Claude Code volunteered it and labeled it as "fragile and not recommended"

Additional context
API docs: https://equalify.uic.edu/dashboard/technical/backend-api

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions