Export results for systems and people
Every completed scan has immutable report artifacts. Choose the format for the consumer rather than parsing the console UI.
Available formats
| Format | Endpoint suffix | Best for |
|---|---|---|
| Canonical JSON | /reports/json |
Automation, data pipelines, archival, custom dashboards |
| Accessible HTML | /reports/html |
Human review, sharing inside an authenticated workflow, printing |
| Excel workbook | /reports/xlsx |
Remediation ownership, filtering, status tracking, stakeholder handoff |
| ACR evidence workbook | /reports/acr |
Section 508/ACR evidence preparation; not an auto-generated conformity claim |
| Evidence manifest | /reports/evidence |
Integrity verification and audit provenance |
| Complete site data | /reports/data |
Streamed ZIP with complete deterministic NDJSON page, finding, and issue-group datasets |
The response ETag is SHA-256-backed. Store it with the artifact if your evidence system needs to detect accidental replacement.
Download without corrupting binary formats
curl --fail-with-body \
--url "https://api.accesspreflight.com/v1/scans/${SCAN_ID}/reports/xlsx" \
--header "Authorization: Bearer ${ACCESSPREFLIGHT_API_KEY}" \
--output "accesspreflight-${SCAN_ID}.xlsx"
Do not treat XLSX as text or JSON. In a browser, request it as a blob and revoke any temporary object URL after download.
What the Excel workbook provides
The workbook is the default cross-functional handoff. It includes scan context and normalized rows suitable for filtering and import:
- findings with severity, automation, confidence, rule, fingerprint, and suppression state;
- representative occurrences and semantic locators;
- coverage and manual-review work;
- policy/requirement coverage and normative-source links;
- remediation guidance and ownership fields where available;
- release-check context, engine versions, and evidence provenance.
Summary consistency values are materialized when the report is generated; the
workbook contains no formulas and does not depend on Excel recalculation.
Manual review and Policy coverage provide explicit assignee, decision,
evidence-reference, and review-status handoff columns. Normative URLs, mapping
versions/digests, applicability rationale, and limitations live separately in
Policy evidence so operational edits do not blur source provenance.
Occurrence samples are capped; use totals to understand scope. Evidence excerpts are sanitized and truncated.
For a whole-site scan, XLSX contains Summary, Pages, Issue groups, and a bounded Representative findings sheet. Use /reports/data when every page and finding is required; the aggregate JSON and HTML intentionally bound the highest-risk page and issue-group previews.
Canonical JSON for automation
The canonical report schema evolves separately from the public API. Inspect the report's schema version before decoding. Consumers should tolerate additive fields and reject a major schema version they do not support.
Use report JSON when you need all normalized evidence in one artifact. Use the paginated findings endpoint when you need incremental UI rendering or filters.
Accessible HTML for review
The HTML report is self-contained, keyboard navigable, printable, and contains the same core content as JSON. It has no external runtime resources. It still contains tenant data, so distribute it according to your organization's access and retention policy.
ACR export is evidence, not a signed VPAT
The ACR workbook organizes Section 508-oriented evidence and outstanding review. A qualified person must decide responses, scope, exceptions, and final claims. AccessPreflight does not automatically issue a VPAT or guarantee procurement acceptance.
Profile mapping workbook
Profiles have their own standalone mapping export:
curl --fail-with-body \
--url "https://api.accesspreflight.com/v1/profiles/${PROFILE_AT_VERSION}/mapping.xlsx" \
--header "Authorization: Bearer ${ACCESSPREFLIGHT_API_KEY}" \
--output "${PROFILE_AT_VERSION}-mapping.xlsx"
Use it to review the expected coverage denominator, manual and unsupported scope, source references, and mapping approval status before adopting a profile.