Running and Managing Scanners
Scanners typically run on a schedule you or an administrator configured, or manually when you start a scan. After you configure scanners, you run them day to day. Most of that work happens under Providers, where you manage provider connections, scanners, and scan activity in one place.
Scanner Actions
-
Run Discovery Scan
Start a manual scan when you want fresh metadata without waiting for the next scheduled window. Successful runs update or add services in the matching Portfolio catalogs according to your rules.
-
View Scanner
Inspect connection health, the last completed run, and scan history to verify whether discovery is healthy, slow, or failing authentication.
-
Pause Scheduled Runs
Temporarily stop scheduled triggers when you need a quiet period—for example during maintenance or while you fix credentials—without deleting the scanner.
-
Resume Scheduled Runs
Re-enable scheduled scanning after a pause.
-
Scanner Settings
Change names, descriptions, credentials, provider scope, or scan-related settings your product exposes, then save, so future runs use the new definition.
For API gateway providers that support policy write, granting the scanner connection’s identity the provider’s write scope enables policy write (apply, enable, disable, and remove) on the scanner’s discovered APIs. Policy write reuses the same connection you use for scanning. For provider-specific write scopes, see Policy Write Prerequisites.
-
Delete Scanner
Remove the scanner from Providers when the provider link is no longer authorized or useful. Consider the impact on discovered services in Portfolio and on dependent teams before you delete the scanner.
When you delete an Akamai API Security scanner, the system attempts to remove the Akamai correlation policy from the scanner’s environments. If the removal fails, the correlation policy may remain applied; check Automated Policies to verify. Discovered services remain in your portfolio regardless. Deleting an API gateway scanner used for policy write doesn’t remove policies that were previously applied to the provider’s APIs through policy write. Those policies remain active on the gateway. Anypoint stops tracking them, and you lose the ability to manage them from Anypoint until you reconnect a scanner with the provider’s write scope.



