CreateProject

Updated at:
Copy as MD

Creates a project.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-codesec:CreateProject

create

*All Resource

*

None None

Request syntax

POST /v1/projects HTTP/1.1

Request parameters

Parameter

Type

Required

Description

Example

name

string

Yes

The project name.

user_paswd_103

description

string

No

The description.

This is default function description by fc-deploy component

instructionPrompt

string

No

The natural language prompt that describes scanning or result processing preferences, such as ignoring low-risk vulnerabilities.

such as ignoring low-severity vulnerabilities, etc.

source

object

No

The project source.

type

string

No

The project type.

api

engines

object

No

The engine switches for the project or scan snapshot. Only SAST and SCA are supported.

sast

boolean

No

Specifies whether SAST is supported.

true

sastConfig

object

No

The engine-level configuration.

remediation

boolean

No

Specifies whether to generate remediation suggestions.

sca

boolean

No

Specifies whether SCA is supported.

false

scaConfig

object

No

The engine-level configuration.

remediation

boolean

No

Specifies whether to generate remediation suggestions.

Response elements

Element

Type

Description

Example

object

Schema of Response

configRevision

integer

The project configuration version number.

1

createdAt

string

The creation time.

2026-08-27T00:53:46.774Z

createdBy

string

The user ID of the project creator.

3221

description

string

The description.

This is default function description by fc-deploy component

engines

object

The engine switches for the project or scan snapshot. Only SAST and SCA are supported.

sast

boolean

Specifies whether SAST is supported.

true

sca

boolean

Specifies whether SCA is supported.

true

id

integer

The project ID.

111

instructionPrompt

string

The natural language prompt that describes scanning or result processing preferences, such as ignoring low-risk vulnerabilities.

such as ignoring low-severity vulnerabilities, etc.

name

string

The project name.

name

requestId

string

The request ID.

9A1F403F-0A85-5578-8B7C-55E3E9408659

source

object

The project source.

type

string

The project type.

api

updatedAt

string

The update time.

2026-08-27T00:53:46.774Z

Examples

Success response

JSON format

{
  "configRevision": 1,
  "createdAt": "2026-08-27T00:53:46.774Z",
  "createdBy": "3221",
  "description": "This is default function description by fc-deploy component",
  "engines": {
    "sast": true,
    "sca": true
  },
  "id": 111,
  "instructionPrompt": "such as ignoring low-severity vulnerabilities, etc.",
  "name": "name",
  "requestId": "9A1F403F-0A85-5578-8B7C-55E3E9408659",
  "source": {
    "type": "api"
  },
  "updatedAt": "2026-08-27T00:53:46.774Z"
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidParameter.%s Invalid parameter:%s. Invalid parameter:%s.
400 NotFound.%s The resource does not exist. The resource does not exist.
400 Conflict.%s config conflict:%s. Parameter business configuration conflict:%s.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.