{"components":{"securitySchemes":{"bearerAuth":{"bearerFormat":"JWT","scheme":"bearer","type":"http"}}},"info":{"contact":{"email":"info@limacharlie.io"},"description":"This is the REST API for LimaCharlie.io, see https://docs.limacharlie.io/7-administration/access/api-keys/ for authentication information.","license":{"name":"Apache 2.0","url":"http://www.apache.org/licenses/LICENSE-2.0.html"},"termsOfService":"https://limacharlie.io/tos","title":"LimaCharlie.io REST API","version":"1.0.0"},"openapi":"3.1.0","paths":{"/autocomplete/task":{"get":{"operationId":"autocompleteTask","tags":["Sensors"],"parameters":[{"name":"aid","description":"agent ID","schema":{"type":"string"},"in":"query"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":{"additionalProperties":false,"description":"command line command and a set of assocuated flags and positionals","properties":{"optional":{"items":{"oneOf":[{"items":false,"prefixItems":[{"description":"command line flag","title":"flag","type":"string"},{"description":"command line flag value","title":"value","type":"string"}],"type":"array"},{"description":"command line flag with no value","title":"flag","type":"string"}]},"type":"array"},"positional":{"description":"positional argument","items":{"type":"string"},"title":"argument","type":"array"}},"title":"command","type":"object"},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get autocomplete information for sensor tasking.","summary":"Autocomplete Task"}},"/cloudsec/fleet/overview":{"get":{"operationId":"getCloudSecFleetOverview","tags":["Cloud Security"],"parameters":[{"name":"oids","description":"explicit org id(s) to include; repeat the parameter for several; omit (with no 'group') to span every org the caller can see","schema":{"type":"string"},"in":"query"},{"name":"group","description":"an org-group id: include the group's member orgs (the caller must be a member or owner of the group)","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of orgs to return for this page (default 25, hard cap 100)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"trend_days","description":"number of days of score trend window per org (default 30)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"next_cursor":{"type":"string"},"orgs":{"items":{"type":"object"},"type":"array"},"rollups":{"type":"object"},"skipped":{"type":"object"},"total_orgs":{"type":"integer"}},"required":["orgs"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the multi-org fleet posture board in one call: one posture row per authorized org (score, severity distribution, trend direction, coverage/freshness, usage counters) plus, on the first page, the cross-tenant rollups (widely-recurring rules, fleet risk distribution, orgs with failing providers). The org set is the caller's authorized orgs — optionally narrowed by 'oids' and/or an org 'group' — intersected with the orgs where the caller holds cloudsec.get and that are subscribed to the cloud-security extension; an org failing either filter is excluded, not an error. Keyset-paginated by org via 'cursor'/'limit'.","summary":"Get Cloud Security Fleet Overview","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/attack-paths":{"get":{"operationId":"getCloudSecAttackPaths","tags":["Cloud Security"],"parameters":[{"name":"severity","description":"repeatable severity filter (CRITICAL/HIGH/MEDIUM/LOW); paths whose source finding matches any value","schema":{"type":"string"},"in":"query"},{"name":"account","description":"repeatable account/project filter","schema":{"type":"string"},"in":"query"},{"name":"status","description":"repeatable status filter; the closed set is open | resolved | accepted (resolved = mitigated or false positive; accepted = a live risk somebody signed off on carrying, NOT a fix)","schema":{"type":"string"},"in":"query"},{"name":"q","description":"free-text filter over the source findings","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"paths":{"items":{"type":"object"},"type":"array"}},"required":["paths"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the headline toxic-combination attack paths for the organization (internet-exposed workload with a KEV vulnerability that can reach a sensitive resource). Supports the findings filter selectors (severity, account, status, q) to narrow the path list.","summary":"Get Cloud Security Attack Paths","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/azure/scope-hierarchy":{"get":{"operationId":"getCloudSecAzureScopeHierarchy","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get non-traversable Azure tenant, management-group, subscription, resource-group, and resource-scope containment evidence.","summary":"Get Cloud Security Azure Scope Hierarchy","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/caasm/assets":{"get":{"operationId":"getCloudSecCAASMAssets","tags":["Cloud Security"],"parameters":[{"name":"q","description":"optional substring filter over the asset urn/name/hostname/serial/os/email","schema":{"type":"string"},"in":"query"},{"name":"kind","description":"repeatable asset-kind filter (device | user | …)","schema":{"type":"string"},"in":"query"},{"name":"source","description":"repeatable: match assets ANY of these observing tools reported (sentinelone | ms_graph | limacharlie | …)","schema":{"type":"string"},"in":"query"},{"name":"posture_encryption","description":"repeatable disk-encryption posture filter. Pass an EMPTY value to select assets no source reported this fact for — unreported is not compliant","schema":{"type":"string"},"in":"query"},{"name":"posture_screen_lock","description":"repeatable screen-lock posture filter; empty selects unreported","schema":{"type":"string"},"in":"query"},{"name":"posture_compromised","description":"repeatable compromised-state posture filter; empty selects unreported","schema":{"type":"string"},"in":"query"},{"name":"posture_managed","description":"repeatable managed-state posture filter; empty selects unreported","schema":{"type":"string"},"in":"query"},{"name":"sort","description":"page order: 'urn' (default — stable, safe for a full walk or export) or 'last_seen' for most-recently-observed first","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of assets to return for this page; omit to use the backend default","schema":{"type":"integer"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data_as_of":{"type":"string"},"next_cursor":{"type":"string"},"resources":{"items":{"type":"object"},"type":"array"},"served_from":{"type":"string"}},"required":["resources"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the organization's merged third-party asset inventory: every device/identity the org's connected tools (EDR / IdP / MDM / scanners) report, entity-resolved to one row per real asset with per-source provenance retained in props (sources, merge key, hostname/serial/MACs/email, last_seen). Supports the kind / source / device-posture selectors, the 'sort' order, and keyset pagination via the optional 'cursor' and 'limit' query parameters; the response carries a 'next_cursor' to fetch the following page.","summary":"Get CAASM Assets","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/caasm/coverage":{"get":{"operationId":"getCloudSecCAASMCoverage","tags":["Cloud Security"],"parameters":[{"name":"status","description":"filter by finding status; repeatable. The closed set is open | resolved | accepted (resolved = mitigated or false positive; accepted = a live risk somebody signed off on carrying, NOT a fix)","schema":{"type":"string"},"in":"query"},{"name":"severity","description":"filter by severity; repeatable","schema":{"type":"string"},"in":"query"},{"name":"q","description":"optional substring filter","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of findings to return for this page; omit to use the backend default","schema":{"type":"integer"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"findings":{"items":{"type":"object"},"type":"array"},"next_cursor":{"type":"string"}},"required":["findings"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the organization's coverage-gap findings: assets observed by at least one connected tool but missing a tool the org's expected-coverage policy requires (e.g. seen by the IdP, no EDR). This is the findings worklist filtered to the coverage_gap class — the same shape as /cloudsec/{oid}/findings, with the class stamped server-side. Supports the status/severity/q selectors and keyset pagination.","summary":"Get CAASM Coverage Gaps","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/caasm/policy":{"get":{"operationId":"getCloudSecCAASMPolicy","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"next_cursor":{"type":"string"},"resources":{"items":{"type":"object"},"type":"array"}},"required":["resources"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the organization's stored expected-coverage policy. The policy is persisted as the org's single CAASMPolicy system-of-record row, so the response is the standard resource-list shape: 'resources' holds zero rows (no policy declared — coverage evaluation is then a no-op by design) or one row whose 'props' object is the policy ({expect:[...]}).","summary":"Get CAASM Coverage Policy","x-required-permissions":{"all_of":["cloudsec.get"]}},"post":{"operationId":"setCloudSecCAASMPolicy","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the coverage policy","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"policy":{"additionalProperties":false,"properties":{"expect":{"items":{"type":"object"},"type":"array"}},"type":"object"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"ok":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Set (upsert) the organization's expected-coverage policy: the declarative expectations the coverage engine evaluates over the merged asset inventory, e.g. {policy:{expect:[{label:\"edr-on-devices\",capability:\"edr\",kinds:[\"device\"]}]}}. The policy is validated before it is stored; an invalid policy is rejected loudly.","summary":"Set CAASM Coverage Policy","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/changes":{"get":{"operationId":"getCloudSecChanges","tags":["Cloud Security"],"parameters":[{"name":"limit","description":"max number of change events (default 50)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"changes":{"items":{"type":"object"},"type":"array"}},"required":["changes"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the recent cloud-finding lifecycle changes (created/closed), newest first.","summary":"Get Cloud Security Changes","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/chokepoints":{"get":{"operationId":"getCloudSecChokepoints","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"chokepoints":{"items":{"type":"object"},"type":"array"},"total_paths":{"type":"integer"}},"required":["chokepoints"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the estate-wide chokepoints: the shared attack-path hops ranked by how many distinct paths each one breaks, plus the total attack-path count — so 'fix this one resource' can be framed as 'closes N of M paths'. Precomputed on reproject; returns an empty list when the estate has no shared hops (or hasn't been analyzed yet).","summary":"Get Cloud Security Chokepoints","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/chokepoints/dismiss":{"post":{"operationId":"dismissCloudSecChokepoint","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the choke point urn (+ optional reason)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"reason":{"type":"string"},"urn":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"ok":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Dismiss an estate-wide choke point (by its resource urn) so it no longer surfaces on the risk overview. Optionally records a reason.","summary":"Dismiss Cloud Security Choke Point","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/chokepoints/restore":{"post":{"operationId":"restoreCloudSecChokepoint","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the choke point urn","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"urn":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"ok":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Restore (un-dismiss) a previously dismissed estate-wide choke point so it surfaces on the risk overview again.","summary":"Restore Cloud Security Choke Point","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/ciem/facets":{"get":{"operationId":"getCloudSecIdentityFacets","tags":["Cloud Security"],"parameters":[{"name":"provider","description":"repeatable: match identities produced by ANY of these sweeps. Alias of 'source'","schema":{"type":"string"},"in":"query"},{"name":"account","description":"repeatable: match identities observed in ANY of these accounts/projects","schema":{"type":"string"},"in":"query"},{"name":"region","description":"repeatable: match identities observed in ANY of these regions","schema":{"type":"string"},"in":"query"},{"name":"q","description":"case-insensitive substring filter over the identity's urn/email/kind","schema":{"type":"string"},"in":"query"},{"name":"source","description":"repeatable: match identities produced by ANY of these sweeps (okta | gcp | google_workspace | …). Same dimension as 'provider'; use this form to select several","schema":{"type":"string"},"in":"query"},{"name":"kind","description":"repeatable identity kind filter (user | service_account | group | ai_agent | …)","schema":{"type":"string"},"in":"query"},{"name":"criticality","description":"repeatable crown-jewel tier filter","schema":{"type":"string"},"in":"query"},{"name":"risk_band","description":"repeatable risk-band filter (critical | high | medium | low) — the band token the rail renders, not a numeric range","schema":{"type":"string"},"in":"query"},{"name":"mfa","description":"MFA state filter: on | off | unknown. 'unknown' is everyone the MFA question does not apply to (no identity-provider observation, or non-human) — it is NOT 'off'","schema":{"type":"string"},"in":"query"},{"name":"admin","description":"true/false: restrict to identities holding (or not holding) an admin role. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"external","description":"true/false: restrict to identities outside the org's own domains. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"public","description":"true/false: restrict to public principals (allUsers / allAuthenticatedUsers and their equivalents). Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"disabled","description":"true/false: restrict to disabled (or enabled) identities. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"crown_jewel","description":"true/false: restrict to identities the org's cloudsec_policy declares sensitive. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"can_escalate","description":"true/false: restrict to identities that can escalate their own privileges. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"dormant_90d","description":"true/false: restrict to identities with no observed activity in 90 days. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"with_sensitive","description":"true/false: restrict to principals holding at least one non-deny grant on a sensitive resource. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"facets":{"type":"object"}},"required":["facets"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the cross-cutting identity facet counts for the CIEM worklist (kind, MFA state, risk band, plus admin/external/public/disabled/dormant/stale-key/escalation/sensitive-access rollups and the total), so the identity view can lead with insight before the row list. The optional selectors CROSS-FILTER the rail: each dimension is counted under the other active selectors but not its own, so a value's count is exactly how many rows selecting it would list. With no selectors the response is the whole-population rollup, unchanged.","summary":"Get Cloud Security Identity Facets","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/ciem/identities":{"get":{"operationId":"getCloudSecIdentityAccessList","tags":["Cloud Security"],"parameters":[{"name":"provider","description":"repeatable: match identities produced by ANY of these sweeps. Alias of 'source'","schema":{"type":"string"},"in":"query"},{"name":"account","description":"repeatable: match identities observed in ANY of these accounts/projects","schema":{"type":"string"},"in":"query"},{"name":"region","description":"repeatable: match identities observed in ANY of these regions","schema":{"type":"string"},"in":"query"},{"name":"q","description":"case-insensitive substring filter over the identity's urn/email/kind","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of principals to return for this page; omit to use the backend default","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"source","description":"repeatable: match identities produced by ANY of these sweeps (okta | gcp | google_workspace | …). Same dimension as 'provider'; use this form to select several","schema":{"type":"string"},"in":"query"},{"name":"kind","description":"repeatable identity kind filter (user | service_account | group | ai_agent | …)","schema":{"type":"string"},"in":"query"},{"name":"criticality","description":"repeatable crown-jewel tier filter","schema":{"type":"string"},"in":"query"},{"name":"risk_band","description":"repeatable risk-band filter (critical | high | medium | low) — the band token the rail renders, not a numeric range","schema":{"type":"string"},"in":"query"},{"name":"mfa","description":"MFA state filter: on | off | unknown. 'unknown' is everyone the MFA question does not apply to (no identity-provider observation, or non-human) — it is NOT 'off'","schema":{"type":"string"},"in":"query"},{"name":"admin","description":"true/false: restrict to identities holding (or not holding) an admin role. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"external","description":"true/false: restrict to identities outside the org's own domains. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"public","description":"true/false: restrict to public principals (allUsers / allAuthenticatedUsers and their equivalents). Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"disabled","description":"true/false: restrict to disabled (or enabled) identities. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"crown_jewel","description":"true/false: restrict to identities the org's cloudsec_policy declares sensitive. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"can_escalate","description":"true/false: restrict to identities that can escalate their own privileges. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"dormant_90d","description":"true/false: restrict to identities with no observed activity in 90 days. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"with_sensitive","description":"true/false: restrict to principals holding at least one non-deny grant on a sensitive resource. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"next_cursor":{"oneOf":[{"type":"string"},{"type":"null"}]},"principals":{"items":{"type":"object"},"type":"array"}},"required":["principals"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one keyset-paginated page of the Access screen's identity population — the same per-principal effective-access rollup rows /ciem/public-access carries on its 'principals' payload (grant / privileged / sensitive-reach counts, posture facets, risk score), but server-filtered and pageable instead of a risk-ranked top-N. Takes the same selectors as /ciem/facets, so the rail's counts and this list always describe the same population. Ranked (risk_score DESC) by default; a walk that spans a projector recompute can move a row across the cursor, so use it for browsing, not for exact exports.","summary":"Get Cloud Security Identity Access List","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/ciem/identity":{"get":{"operationId":"getCloudSecIdentity","tags":["Cloud Security"],"parameters":[{"name":"urn","required":true,"description":"the canonical lcrn of the identity to fetch","schema":{"minLength":1,"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"identity":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the single-identity effective-access rollup for an identity urn — the same row shape the public-access principals list carries (grant/privileged/sensitive-reach counts, posture facets, risk score), but for ANY identity, not just the risk-ranked top-N. Powers the Identity 360 view. Returns a null identity when the urn is not a known identity.","summary":"Get Cloud Security Identity","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/ciem/public-access":{"get":{"operationId":"getCloudSecPublicAccess","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"access":{"items":{"type":"object"},"type":"array"}},"required":["access"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the CIEM findings where a public or external principal holds an allow grant on a sensitive resource (workloads and data stores).","summary":"Get Cloud Security Public Access","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/autofix":{"post":{"operationId":"postCloudSecCodeAutofix","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the finding to fix","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"finding_id":{"type":"string"},"provider":{"type":"string"},"repo":{"type":"string"}},"required":["finding_id"],"type":"object"}}},"required":true},"responses":{"200":{"description":"the remediation run the click created (or, before it opened its pull request, the one already working on this finding)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"accepted":{"type":"boolean"},"finding_id":{"type":"string"},"provider":{"type":"string"},"replayed":{"type":"boolean"},"repo":{"type":"string"},"run":{"type":"object"},"run_id":{"type":"string"},"state":{"type":"string"}},"required":["accepted"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"missing_permission: the caller is authorized for the organization but does not hold cloudsec.respond (cloudsec.set does not imply it); or cloud security is not enabled for the organization","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"permission":{"type":"string"}},"type":"object"}}}},"404":{"description":"finding_not_found","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"422":{"description":"action_unavailable: not a dependency finding AutoFix can raise, the fix-PR remediation is off, or the repository's provider has no AutoFix write lane","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"429":{"description":"capacity (active run limit) or the per-identity request quota","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"502":{"description":"the backend answered outside the documented vocabulary","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"disabled (remediation is not enabled for the organization) | unavailable (retryable)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Ask Cloud Security to open a pull request raising the vulnerable dependency a finding is about — the endpoint behind the AutoFix button. 'finding_id' is the id of an open dependency (SCA) finding as returned by /findings; the optional 'repo' narrows the search to one repository and is otherwise inferred. The finding id is the only input that decides anything: the backend resolves it against the dependency rows its own scan produced and raises THAT package to a fixed version of THAT advisory, so a fix can never be requested for a package or a version the organization's own scan did not find. Which fixed version: the advisory's fix on the installed version's release line when it publishes one; otherwise the lowest listed fix above the installed version, which is a MAJOR UPGRADE that may break code using the package. A major upgrade is proposed and flagged, never silent: the pull request title reads 'Fix \u003cadvisory\u003e (major upgrade): \u003cpackage\u003e \u003cfrom\u003e → \u003cto\u003e', its body carries a warning, before the evidence table, naming both release lines, its commit message says so (never with a conventional-commit '!' or 'BREAKING CHANGE', which would make release tooling cut a major release of your own project), and the 'cloudsec.code_autofix_opened' event carries 'major_upgrade': true with 'from_line' and 'to_line' (for example '4.x' and '5.x'). A release line is the caret range for npm, pip (with its epoch) and maven ('1.x', '0.21.x', '0.0.3'; a calendar-versioned year change counts) and the module major for go ('v0' is one line). The finding says what AutoFix would do before you ask: its 'code' block carries 'autofix_version' and, for a major upgrade, 'autofix_major_upgrade', 'autofix_from_line' and 'autofix_to_line'. When a remediation run (open_fix_pr) opens the pull request, the run's 'change.upgrade' records the same verdict. Pull requests opened before major upgrades were flagged are not re-flagged. Refused before any job runs or any of the daily limit is used: a finding whose installed release line has a listed fix below the installed version (the finding is stale), whose only fix on its line is a pre-release, or whose go fix is on a major AutoFix cannot raise a module to (a '/vN' path is a different module, and a go module is not raised across a major above v1, such as v20 to v23 '+incompatible'; go 'v0' to 'v1' is proposed and flagged). A request is a governed Code Security remediation run (action open_fix_pr on this finding): it needs the cloudsec.respond permission (cloudsec.set alone is refused with 403 missing_permission), the caller is recorded as the person who requested AND approved it, and the collector reports the outcome back to the run through an authenticated callback. The response returns the run ('run_id', 'state'; GET /cloudsec/{oid}/remediations/{run_id} follows it) once it is created, not once a pull request exists: the collector replica holding the connection clones the repository in a sandbox, edits the manifest and opens the pull request, which appears on the run ('change'), as the pull request itself, and in the 'cloudsec.code_autofix_opened' operational event (with 'remediation_id'). Pressing the button again before that run has opened its pull request returns the same run ('replayed': true). When remediation is not enabled for the organization the request is refused with 503 'disabled' (or 422 'action_unavailable' when the fix-PR remediation is off, or the repository's provider has no AutoFix write lane: GitHub, GitLab.com and Bitbucket Cloud do); it is never carried out another way. Each of these ends the run 'failed' with a closed 'failure_reason' and a 'cloudsec.code_autofix_refused' operational event carrying the reason in words: an organization with no enabled code_scanning policy; a connection whose GitHub App has not been granted Contents: Read and write and Pull requests: Read and write (the connection's App is read-only by default, and AutoFix is available only once those permissions are granted — GET /cloudsec/{oid}/code/capabilities reports which permission is missing; a connection that still names a separate Code Actions App uses that App instead); a finding whose package is flagged malicious (the remediation is removal and credential rotation, not an upgrade) or for which no fixed version has been published; an ecosystem other than npm, pip, go or maven; a repository outside the code_scanning policy scope or over the free-tier quota; a package that already has an AutoFix pull request open ('autofix_pr_already_open'; the event names it); and a connection that has reached its daily AutoFix limit ('autofix_budget_exhausted'). For npm the pull request also updates the lockfile beside the manifest (package-lock.json or npm-shrinkwrap.json, yarn.lock, pnpm-lock.yaml) so the fix installs as opened. A yarn or pnpm lockfile that cannot be rewritten safely is refused before any job runs (autofix_not_applicable, with the reason). A package-lock.json that cannot be regenerated (for example with autofix_registry_access: false) is flagged 'lockfile_stale', and the pull request says so prominently and names the command to run. For go the host writes go.sum from the Go checksum database; a go fix whose go.sum cannot be completed that way, or whose repository has no go.sum, is refused before any job runs (autofix_not_applicable) instead of opening a pull request that does not build.","summary":"Open a Pull Request Fixing a Dependency Finding","x-required-permissions":{"all_of":["cloudsec.respond"]}}},"/cloudsec/{oid}/code/capabilities":{"get":{"operationId":"getCloudSecCodeCapabilities","tags":["Cloud Security"],"parameters":[{"name":"repo","description":"optional: narrow the answer to one repository, '\u003cowner\u003e/\u003cname\u003e' or the bare name. It matters when an installation covers 'selected' repositories rather than all of them — a connection can hold checks:write and still be unable to publish on THIS repository, which is a different fix (Configure access on the installation page) from a missing permission. A repository under a different organization than the connection's is ignored rather than answered for.","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"connections":{"items":{"type":"object"},"type":"array"}},"required":["connections"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get what each source-control connection may actually do, detected from the GitHub App installation rather than inferred from configuration. One entry per enabled connection carrying: 'mode' ('unified' — one App does everything its permissions allow — or 'separate_actions_app' — a separately installed Code Actions App, which keeps working unchanged and takes precedence), 'repository_selection' ('all' or 'selected'), 'suspended' (true when EITHER installation behind the connection is suspended — in the two-App shape the one that clones and the one that writes are separate installations), 'verified_at' (when the installation was last read), and 'capabilities': one entry per capability ('repo_scanning', 'pr_checks', 'pr_comments', 'fix_pull_requests') with 'state' ('available', 'unavailable' or 'unknown'), 'needs' (the permissions it requires as 'slug:level'), 'missing' and a machine-readable 'reason' ('missing_permissions', 'installation_suspended', 'installation_not_found' — GitHub says the App installation no longer exists, so it is reported as a fact rather than as an unknown — 'verification_unavailable', 'repository_not_in_installation'). 'unknown' means the installation could not be read and is NOT the same as denied — a capability nobody could verify is never offered. Availability is not enablement: it says a control may be shown, not that anything is published. No credential or secret appears in the response.","summary":"Get Cloud Security Code Connection Capabilities","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/coverage":{"get":{"operationId":"getCloudSecCodeCoverage","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"the coverage report, or coverage null with a closed reason","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"coverage":{"additionalProperties":false,"properties":{"generated_at":{"type":"string"},"lines":{"items":{"type":"object"},"type":"array"},"oid":{"type":"string"}},"type":"object"},"reason":{"type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"coverage_unavailable: transport, retryable or unknown backend outcome","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"type":"string"}},"type":"object"}}}}},"description":"Code Security coverage with explicit denominators: workloads with an immutable digest, workloads fully resolved, digests with an exact source commit, workloads whose chain is proven, declarations attributed, pull-request context success, remediation outcomes, verification latency and runtime telemetry. Every line carries its `numerator` and `denominator` separately. A metric this version does not measure has both null, never 0 of 0. Show a percentage only when the line is measured, `complete`, not `truncated` and has a positive denominator; otherwise the line carries a closed `reason` and a concrete `action`, and clients must show the counts and the reason instead of a percentage. A successful response with `coverage: null` carries `reason: feature_disabled`. Requires cloudsec.get. Rate limit: 600 requests per hour per authenticated identity.","summary":"Read Code Security Coverage","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/fixes":{"get":{"operationId":"getCloudSecCodeFixes","tags":["Cloud Security"],"parameters":[{"name":"cursor","description":"opaque pagination cursor returned as next_cursor","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"maximum fixes to return (default 5, max 20)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"caveat":{"type":"string"},"distinct":{"type":"integer"},"fixes":{"items":{"type":"object"},"type":"array"},"next_cursor":{"type":"string"},"scope":{"type":"string"}},"required":["fixes","distinct","scope","caveat"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get a bounded page of concrete dependency upgrades grouped by the scanner's shared upgrade target (ecosystem, package and fix guidance). Counts cover distinct open supported findings and repositories and match a cause_key drill-down; they do not claim image or running-workload impact. Fix guidance may contain several versions or ranges. Supports opaque cursor pagination; limit defaults to 5 and is capped at 20.","summary":"Get Cloud Security Code Dependency Fixes","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/iac-map":{"post":{"operationId":"postCloudSecIaCMap","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"sanitized lc-iac-map/v1 document (no envelope)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"complete":{"type":"boolean"},"observed_at":{"type":"string"},"repository":{"type":"object"},"resources":{"items":{"type":"object"},"type":"array"},"schema":{"type":"string"},"source_kind":{"type":"string"},"successful":{"type":"boolean"},"tool":{"type":"string"},"workspace":{"type":"string"}},"required":["schema","repository","tool","workspace","source_kind","observed_at","complete","successful","resources"],"type":"object"}}},"required":true},"responses":{"200":{"description":"sanitized map reconcile result","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"result":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Accept only lc-iac-map/v1 JSON produced locally by limacharlie cloudsec code iac-map extract. Raw Terraform state/plans, compression, URLs, credentials, unknown fields and caller-supplied tenant identifiers are refused. Maximum 20 MiB, 100,000 resources, 100 workspaces per repository, depth 8, strings 4 KiB. State maps retain identity only; plans retain allowlisted desired booleans. Full source commit is required. Partial or unsuccessful snapshots cannot delete mappings; exact published replay writes nothing. Requires cloudsec.set and the default-off Code Security provenance feature. Rate limit: 30 requests per minute per authenticated identity. A processing receipt means the write was accepted but not published; poll GET /code/iac-map/status, and resubmit the same document if the status is retryable. It does not assert deployment or remediation verification.","summary":"Push Sanitized IaC Identity Evidence","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/code/iac-map/status":{"get":{"operationId":"getCloudSecIaCMapStatus","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"map receipt status","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"hash":{"type":"string"},"status":{"type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Read the status of one exact sanitized map receipt. processing means staging is ongoing; published means the complete generation is visible; retryable means a worker stopped or its lease expired and the same document should be resubmitted; superseded means a newer document replaced this receipt.","summary":"Read Sanitized IaC Map Receipt","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/code/image-repos":{"get":{"operationId":"getCloudSecCodeImageRepos","tags":["Cloud Security"],"parameters":[{"name":"q","description":"server-side repository or registry search","schema":{"type":"string"},"in":"query"},{"name":"provider","description":"repeatable provider filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"account","description":"repeatable account filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"registry","description":"repeatable registry filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"region","description":"repeatable registry region filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"has_findings","description":"true/false open-finding selector","schema":{"type":"boolean"},"in":"query"},{"name":"has_images","description":"true/false image-membership selector","schema":{"type":"boolean"},"in":"query"},{"name":"scanning_state","description":"native vulnerability-scanning state","schema":{"type":"string"},"in":"query"},{"name":"sort","description":"name | risk | images | last_pushed","schema":{"type":"string"},"in":"query"},{"name":"order","description":"asc | desc","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"opaque keyset cursor","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"page size (default 100, max 1000)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"coverage":{"type":"object"},"image_repos":{"items":{"type":"object"},"type":"array"},"next_cursor":{"type":"string"},"total":{"type":"integer"}},"required":["image_repos"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one keyset-paginated page of connected container-image repositories with exact image and open-finding rollups. Filters and sorting execute server-side; next_cursor, rather than page length, indicates whether more rows remain.","summary":"Get Cloud Security Image Repositories","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/image-repos/facets":{"get":{"operationId":"getCloudSecCodeImageRepoFacets","tags":["Cloud Security"],"parameters":[{"name":"q","description":"server-side repository or registry search","schema":{"type":"string"},"in":"query"},{"name":"provider","description":"repeatable provider filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"account","description":"repeatable account filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"registry","description":"repeatable registry filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"region","description":"repeatable registry region filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"has_findings","description":"true/false open-finding selector","schema":{"type":"boolean"},"in":"query"},{"name":"has_images","description":"true/false image-membership selector","schema":{"type":"boolean"},"in":"query"},{"name":"scanning_state","description":"native vulnerability-scanning state","schema":{"type":"string"},"in":"query"},{"name":"lineage_facet","description":"true to also return lineage_statuses (leave unset for the registry view)","schema":{"type":"boolean"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"accounts":{"items":{"type":"object"},"type":"array"},"lineage_statuses":{"items":{"additionalProperties":false,"properties":{"count":{"type":"integer"},"value":{"description":"verified | asserted | inferred | ambiguous | unknown","type":"string"}},"type":"object"},"type":"array"},"providers":{"items":{"type":"object"},"type":"array"},"registries":{"items":{"type":"object"},"type":"array"},"scanning_states":{"items":{"type":"object"},"type":"array"},"total":{"type":"integer"}},"required":["total"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get exact cross-filtered totals and provider, account, registry, and native-scanning-state buckets for image repositories. With lineage_facet=true the response also carries 'lineage_statuses': exact image counts by effective source-lineage status (verified, asserted, inferred, ambiguous, unknown; a lapsed decision counts as unknown), equal to the totals of the matching /code/images lineage_status filter. Lineage belongs to the image digest, so the repository filters do not narrow it.","summary":"Get Cloud Security Image Repository Facets","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/images":{"get":{"operationId":"getCloudSecCodeImages","tags":["Cloud Security"],"parameters":[{"name":"q","description":"server-side digest, reference, repository, registry, or tag search","schema":{"type":"string"},"in":"query"},{"name":"repo_urn","description":"repeatable exact image-repository URN","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"provider","description":"repeatable provider filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"account","description":"repeatable account filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"registry","description":"repeatable registry filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"tag","description":"repeatable exact tag filter","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"findings","description":"any | with | without","schema":{"type":"string"},"in":"query"},{"name":"running","description":"true/false runtime-observation selector","schema":{"type":"boolean"},"in":"query"},{"name":"signed","description":"true/false signature selector; omit for unconstrained","schema":{"type":"boolean"},"in":"query"},{"name":"lineage_status","description":"repeatable effective lineage status: verified | asserted | inferred | ambiguous | unknown","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"sort","description":"name | risk | pushed","schema":{"type":"string"},"in":"query"},{"name":"order","description":"asc | desc","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"opaque keyset cursor","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"page size (default 100, max 1000)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"coverage":{"type":"object"},"images":{"items":{"additionalProperties":false,"properties":{"lineage":{"additionalProperties":false,"properties":{"stale":{"description":"true when status was downgraded to unknown because stale_at passed","type":"boolean"},"stale_at":{"type":"string"},"status":{"description":"verified | asserted | inferred | ambiguous | unknown; a stale decision reads unknown","type":"string"},"tier":{"description":"inferred | tool_emitted | our_signed_push; absent when the status is unknown because the decision went stale","type":"string"}},"type":"object"}},"type":"object"},"type":"array"},"next_cursor":{"type":"string"},"total":{"type":"integer"}},"required":["images"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one keyset-paginated page of digest-global container images, including images with no findings. Repository membership, tags, finding rollups, runtime observations, and source-repository counts are joined server-side. Each image carries 'lineage': {tier, status, stale_at, stale}, a bounded summary of the digest's source-lineage decision (candidates stay on the detail route). A stale decision reads as status unknown with stale=true and no tier. lineage_status filters on that effective status server-side: pages are full, 'total' is the exact matching count and next_cursor pages normally. The summary reflects the last completed projection pass (lineage is materialized), except that the freshness rule is applied at read time, so a lapsed claim reads unknown immediately.","summary":"Get Cloud Security Container Images","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/images/{digest}":{"get":{"operationId":"getCloudSecCodeImage","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"digest","required":true,"description":"the sha256 digest returned by /code/images","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"image":{"type":"object"},"lineage":{"additionalProperties":false,"properties":{"candidates":{"items":{"additionalProperties":false,"properties":{"commit":{"type":"string"},"commit_range_status":{"description":"exact | unknown; inference never asserts an exact build commit","type":"string"},"dockerfile":{"type":"string"},"observed_commit":{"type":"string"},"repo_urn":{"type":"string"},"score":{"description":"Integer candidate match score, not a probability or percentage","type":"integer"},"signals":{"items":{"type":"string"},"type":"array"}},"type":"object"},"type":"array"},"digest":{"type":"string"},"observed_at":{"type":"string"},"reason":{"type":"string"},"stale_at":{"type":"string"},"status":{"description":"inferred | asserted | verified | ambiguous | unknown; an OCI label alone is asserted","type":"string"},"tier":{"description":"inferred | tool_emitted | our_signed_push","type":"string"}},"type":"object"},"membership_count":{"type":"integer"},"memberships":{"items":{"type":"object"},"type":"array"},"source_repositories":{"items":{"type":"object"},"type":"array"},"source_repository_count":{"type":"integer"},"workload_count":{"type":"integer"},"workloads":{"items":{"additionalProperties":false,"properties":{"deployment":{"additionalProperties":false,"properties":{"observed_at":{"type":"string"},"read_complete":{"type":"boolean"},"reason":{"description":"why no digest resolved, or stale / not_read / invalid_observation for unknown","type":"string"},"stale":{"type":"boolean"},"stale_at":{"description":"when the observation stops describing the present","type":"string"},"status":{"description":"resolved | partial | unresolved | not_running | unknown; a stale observation reads unknown","type":"string"}},"type":"object"},"name":{"type":"string"},"urn":{"type":"string"}},"type":"object"},"type":"array"}},"required":["image"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one digest-global image with registry memberships, bounded workload and source-repository samples, and a digest-bound lineage decision. An inferred or asserted tier is not verified build provenance. Each workload carries a bounded 'deployment' summary of its per-workload digest observation ({status, reason, read_complete, observed_at, stale_at, stale}), read in one batch for the whole list; it is absent for a workload kind that makes no such claim (a plain VM). Past stale_at the observation no longer describes the present and reads status unknown, reason stale, so a client never needs its own copy of the freshness window.","summary":"Get Cloud Security Container Image","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/impact":{"get":{"operationId":"getCloudSecCodeImpact","tags":["Cloud Security"],"parameters":[{"name":"repo_urn","description":"canonical repository URN of this organization","schema":{"type":"string"},"in":"query"},{"name":"commit","description":"full hexadecimal commit the question is about (optional with repo_urn)","schema":{"type":"string"},"in":"query"},{"name":"finding_id","description":"an IaC code finding id (fnd_...)","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"the consequence, or impact null with a closed reason","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"impact":{"additionalProperties":false,"properties":{"impacts":{"items":{"type":"object"},"type":"array"},"impacts_omitted":{"type":"integer"},"schema_version":{"type":"integer"},"stats":{"type":"object"},"summary":{"type":"object"}},"type":"object"},"reason":{"type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"impact_unavailable: transport, retryable or unknown backend outcome","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"type":"string"}},"type":"object"}}}}},"description":"Which live cloud resources a repository's infrastructure-as-code declarations are attributed to, and what is at stake on each: internet exposure, sensitive data reachable within two hops, privileged identity, the immutable artifact running there, and open findings. Select EITHER a repository (`repo_urn`, optionally `commit`, a full hexadecimal commit) OR one IaC code finding (`finding_id`). The answer is bounded: at most 100 declarations are considered (exact matches first), 500 graph rows, two hops and two seconds. Anything that could not be fully established — the graph did not answer, a deadline or bound was hit, a mapping is stale or ambiguous, a resource is not collected, a deployment is tag-only or not running — is reported as `partial` with a closed reason, never as no impact. Exposure, privilege and sensitivity are positive facts: `not_established` is not a statement that a resource is safe. Only `summary.no_impact` true means nothing live is touched. A successful response with `impact: null` carries `reason`: `feature_disabled` (the default-off Code Security impact feature is not enabled for this organization) or `subject_not_found`. Requires cloudsec.get. Rate limit: 600 requests per hour per authenticated identity.","summary":"Read the Live Consequence of Infrastructure Code","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/ingest":{"post":{"operationId":"postCloudSecCodeIngest","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the repository, the source format, and the document","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"commit":{"type":"string"},"default_branch":{"type":"string"},"document":{"type":"object"},"document_b64":{"type":"string"},"provider":{"type":"string"},"ref":{"type":"string"},"repo":{"type":"string"},"source":{"type":"string"}},"required":["source","repo"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"result":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"429":{"description":"the organization already has as many pushes in progress as it may (error_code 'ingest_busy', with a Retry-After header: retry after that delay), or the per-identity quota is spent (no Retry-After: back off before retrying). Nothing was recorded for the refused push, so re-sending it is safe","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"type":"string"}},"type":"object"}}}}},"description":"Push the results your own pipeline produced for one repository — a SARIF file, a CycloneDX bill of materials, or a report from the LimaCharlie code scanner run locally or in CI — and have them recorded as Cloud Security findings on that repository. 'source' is 'sarif' | 'cyclonedx' | 'report'; 'repo' is the '\u003cowner\u003e/\u003cname\u003e' key /code/repos returns; the document goes in 'document' (a JSON object) or 'document_b64' (the same document base64-encoded, optionally gzipped, which is what a CI job piping a file will use). The repository must be selected by an enabled code_scanning policy, but it does NOT have to be one LimaCharlie collects: pushing for a repository no connected source-control organization covers creates it, carrying only what the push vouches for, and /code/repos then shows it with source 'ingest'. 'default_branch' is worth sending for such a repository, since nothing else can state it. Findings are deduplicated against the hosted scan by identity, so pushing results the hosted scanner also found updates them rather than duplicating them, and re-pushing an identical document writes nothing. A pushed document only ever closes findings that IT previously reported: it can never close what the hosted scanner found. Credential findings in a third-party document are deliberately not ingested (the format cannot carry the keyed digest a secret is identified by, and the plaintext is never accepted); the response's 'notes' says so when it happens.","summary":"Ingest Code Scan Results","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/code/pr_check":{"post":{"operationId":"postCloudSecCodePRCheck","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the pull request to check","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"action":{"type":"string"},"base_ref":{"type":"string"},"base_sha":{"type":"string"},"head_ref":{"type":"string"},"head_sha":{"type":"string"},"pr":{"type":"integer"},"prev_base_sha":{"type":"string"},"provider":{"type":"string"},"repo":{"type":"string"}},"required":["repo","pr","head_sha"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"accepted":{"type":"boolean"},"debounce_seconds":{"type":"integer"},"pr":{"type":"integer"},"provider":{"type":"string"},"repo":{"type":"string"}},"required":["accepted"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Ask the code lane to scan a pull request's base and head commits and report what the change INTRODUCES as a GitHub check run on the head commit — the endpoint behind pull-request checks. 'repo' is the repository (owner/name, its bare name, or its canonical urn), 'pr' its pull-request number, and 'base_sha'/'head_sha' the two FULL commit ids (a branch or tag name is refused: the check is published on the commit, and a ref would let it be attached to a commit nobody proposed). THE PULL REQUEST IS READ FROM THE SOURCE-CONTROL PROVIDER BEFORE ANYTHING IS SCANNED, and what it says wins: the check is only published when the pull request is open, belongs to this repository, and its head commit is the 'head_sha' you sent — otherwise it is refused. 'base_sha' is accepted for compatibility and is NOT used: the base commit, and both refs, are taken from the provider, because a caller-chosen base decides what the diff is measured from and a base equal to the head would make any pull request look like it introduced nothing. A pull request whose own base and head are the same commit is refused for the same reason. 'action' is the webhook action and must be opened, synchronize, reopened or edited. 'edited' is how a source-control provider reports a pull request being RETARGETED at a different base branch, which changes what the pull request introduces without pushing a commit — and because a title or body change is reported the same way, an 'edited' request must also carry 'prev_base_sha', the full commit id the pull request was based on before the edit (GitHub's changes.base.sha.from). That value is evidence, not a scan input: the check is refused if the provider says the base has not actually moved, so an editing spree costs no scan, no check run and nothing against the daily write budget. The response means the check was QUEUED, not that one will appear: it is acknowledged immediately, debounced per pull request (the response carries 'debounce_seconds' — a push of several commits becomes one check) and then handed to whichever collector replica holds that connection. That replica applies the rest of the decision, and each of these is a quiet no-op from the caller's point of view: a connection whose GitHub App has not been granted Checks: Read and write and Pull requests: Read and write (the connection's App is read-only by default; GET /cloudsec/{oid}/code/capabilities reports which permission is missing, and a connection that still names a separate Code Actions App uses that App instead), a repository outside the code_scanning policy scope or with pr_checks off, a repository over the free-tier quota, a connection that has spent its daily source-control write budget, or a connection whose collection is paused or failing over at that instant. Only findings NEW in the head commit are reported; the repository's own findings stay on /code/repos. The verdict is the check run's conclusion, set by the policy's gating.fail_on. For a GitLab.com or Bitbucket Cloud connection send 'provider' ('gitlab' or 'bitbucket'): the check is then a commit or build status plus the comment, published with the connection's separate write token, 'base_sha' is optional (the base is read from the provider), a Bitbucket 'head_sha' may be the 12-character form its webhooks carry, and 'edited' is not accepted.","summary":"Check What a Pull Request Introduces","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/code/protection":{"get":{"operationId":"getCloudSecCodeProtection","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"protection coverage","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"current_protected_count":{"type":"integer"},"enabled":{"type":"boolean"},"product":{"type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Read the current acknowledged protection count and whether Code Security is enabled for the organization.","summary":"Get Code Security Protection Coverage","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/provenance":{"get":{"operationId":"getCloudSecCodeProvenance","tags":["Cloud Security"],"parameters":[{"name":"repo_urn","description":"canonical repository URN","schema":{"type":"string"},"in":"query"},{"name":"commit","description":"full hexadecimal commit","schema":{"type":"string"},"in":"query"},{"name":"digest","description":"OCI sha256 digest","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"opaque next-page cursor","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"normalized attestations","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"result":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"provenance_unavailable: transport, retryable or unknown backend outcome","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"type":"string"}},"type":"object"}}}}},"description":"Read tenant-scoped normalized attestations by repository URN, full commit or digest. Cursors are opaque; conflicts are resolved across all claims even when filters select one commit.","summary":"Read Build Provenance","x-required-permissions":{"all_of":["cloudsec.get"]}},"post":{"operationId":"postCloudSecCodeProvenance","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"provenance document","content":{"application/json":{"schema":{"type":"object"}}},"required":true},"responses":{"200":{"description":"stored normalized metadata","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"result":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"415":{"description":"uncompressed application/json required","content":{"application/json":{"schema":{"type":"object"}}}},"503":{"description":"provenance_unavailable: transport, retryable or unknown backend outcome","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"type":"string"}},"type":"object"}}}}},"description":"Push a bounded lc-build-provenance/v1, SLSA v1 or offline Sigstore bundle for OCI sha256 artifacts. Authentication assigns tenant and actor; caller-supplied trust is rejected. Conflicts remain unknown. Requires uncompressed application/json with no query parameters. At most 1 MiB, 100 artifacts and 60 requests/minute per identity.","summary":"Push Build Provenance","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/code/repos":{"get":{"operationId":"getCloudSecCodeRepos","tags":["Cloud Security"],"parameters":[{"name":"q","description":"optional case-insensitive substring filter over the repository key ('\u003cowner\u003e/\u003cname\u003e') and urn","schema":{"type":"string"},"in":"query"},{"name":"has_findings","description":"true/false: restrict to repositories that do (or do not) have at least one OPEN finding. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"provider","description":"optional source-control provider filter (e.g. 'github'); omit for every provider that produces repositories","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of repositories to return for this page (default 100, max 500)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"next_cursor":{"type":"string"},"repos":{"items":{"type":"object"},"type":"array"}},"required":["repos"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the organization's source repositories as the code lane sees them: identity (repo, urn, owner, provider), the source-control facts the connector collected (visibility, archived, branch protection), the code-scan state (scan_status, code_scanned_at, code_scan_commit, languages, packages_total, scan_limits), and the OPEN finding rollup (open_findings, findings_by_class, findings_by_severity, top_severity). 'repo' is the '\u003cowner\u003e/\u003cname\u003e' key every other code route takes. scan_status is one of scanned | partial | unknown — 'partial' means the scan tripped a limit and its finding set is incomplete, and 'unknown' means this surface has no scan state for the repository and says so rather than implying it is clean (a machine-readable 'scan_status_reason' accompanies it). Supports keyset pagination via 'cursor' and 'limit'; the response carries 'next_cursor'. A page may be SHORT while 'next_cursor' is set — the cursor, not the page length, says whether the walk is done.","summary":"Get Cloud Security Code Repositories","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/sbom":{"get":{"operationId":"getCloudSecCodeRepoSBOM","tags":["Cloud Security"],"parameters":[{"name":"repo","required":true,"description":"required: the repository key '\u003cowner\u003e/\u003cname\u003e' as returned by /code/repos (a nested-owner provider's key is '\u003cgroup\u003e/\u003csubgroup\u003e/\u003cname\u003e'). Exactly one value, at most 512 bytes. No segment may be empty, '.' or '..'; owner segments use only letters, digits, '.', '_' and '-'; the name may not contain whitespace or control characters","schema":{"type":"string"},"in":"query"},{"name":"provider","description":"the source-control provider the repository key belongs to; defaults to 'github'","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"reason":{"type":"string"},"repo":{"type":"string"},"sbom":{"type":"object"},"urn":{"type":"string"}},"required":["repo"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get a short-lived, signed download link for a repository's software bill of materials (CycloneDX, gzip-compressed). The document is served directly from object storage rather than through this API, so the response carries 'sbom.url' plus 'expires_at', 'size_bytes', 'format' and 'content_encoding'; fetch the url with a plain unauthenticated GET before it expires. A repository with no SBOM is a SUCCESSFUL response with 'sbom' null and a machine-readable 'reason', and the reason says whether waiting will help: 'sbom_not_generated_yet' is PENDING (no code scan has completed on this repository yet, so an SBOM may appear later), 'no_sbom_for_this_repository' is TERMINAL and not a fault (a scan completed and found no dependency manifest to build a bill of materials from — an IaC, configuration or documentation repository stays in this state permanently, as does one whose findings arrived only through /code/ingest), and 'code_lane_not_enabled_in_datacenter' means this datacenter does not run the code lane at all. The vocabulary is OPEN: treat an unrecognized reason as terminal rather than retrying. A repository this organization does not have is an error.","summary":"Get Cloud Security Repository SBOM","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/scan":{"post":{"operationId":"postCloudSecCodeScan","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the repository to rescan","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"provider":{"type":"string"},"ref":{"type":"string"},"repo":{"type":"string"},"source":{"type":"string"}},"required":["repo"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"accepted":{"type":"boolean"},"debounce_seconds":{"type":"integer"},"provider":{"type":"string"},"repo":{"type":"string"}},"required":["accepted"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Ask the code lane to rescan one repository rather than waiting for its schedule — the endpoint behind push-triggered rescans. 'repo' is the repository (owner/name, its bare name, or its canonical urn) and the optional 'ref' is the git ref a push landed on (refs/heads/main). The response means the trigger was QUEUED, not that a scan will run: it is acknowledged immediately, debounced per repository (the response carries 'debounce_seconds' — a burst of pushes becomes one scan) and then handed to whichever collector replica holds that connection, which runs it as a single-repository pass without waiting for or restarting the periodic collection sweep. That replica applies the rest of the decision, and each of these outcomes is a quiet no-op from the caller's point of view: a repository outside the organization's code_scanning policy scope, a repository over the free-tier quota or the per-connection daily cap, a repository in a failure backoff, a ref naming a branch other than the one the last scan cloned (the lane scans the default branch), or a connection whose collection is paused or failing over at that instant, in which case the trigger is dropped and the repository's normal schedule is the backstop. Results are visible per repository on /code/repos, not on this response. 'provider' names the source-control provider (github, the default, gitlab or bitbucket); a GitLab or Bitbucket 'owner/name' without it is read as a GitHub repository.","summary":"Rescan a Repository Now","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/code/status":{"get":{"operationId":"getCloudSecCodeStatus","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"any_running":{"type":"boolean"},"code":{"items":{"type":"object"},"type":"array"},"totals":{"type":"object"}},"required":["code"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the code lane's run status: one entry per source-control connection ('code:\u003cprovider\u003e') carrying is_running, started_at, completed_at, last_stats and last_error, plus 'totals' — the organization's open code findings, their split by class, and how many repositories carry at least one. An empty 'code' list means the lane has never run in this organization; it does NOT mean the lane is off, which is a property of the org's code_scanning policy. This is the authoritative view of the RUN — when it disagrees with a repository's own 'scan_status', this one is current.","summary":"Get Cloud Security Code Scan Status","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/code/webhook":{"post":{"operationId":"postCloudSecCodeWebhook","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the connection and the hook it should deliver to","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"connection":{"type":"string"},"secret":{"type":"string"},"url":{"type":"string"}},"required":["connection","url","secret"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation — the connection's re-detected webhook status","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"detail":{"type":"string"},"missing_events":{"items":{"type":"string"},"type":"array"},"reason":{"type":"string"},"state":{"type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Point a GitHub connection's App webhook at this organization's LimaCharlie webhook adapter, so pushes and pull requests on every repository the App is installed on reach the code lane without a per-repository webhook. 'connection' is the cloudsec_provider record name of a GitHub connection; 'url' is the adapter's hook URL and 'secret' the webhook signing secret the adapter verifies (X-Hub-Signature-256). The URL is refused unless it is exactly 'https://\u003chooks domain\u003e/\u003cthis oid\u003e/github-code-webhook-\u003cname\u003e/\u003curl secret\u003e' where the hooks domain is this organization's own (the 'url.hooks' value of GET /orgs/{oid}/url, always under .hook.limacharlie.io): https only, no credentials, port, query or fragment, and the organization in the path must be the one in this route. 'secret' must be 20 to 256 characters with no whitespace. The App's webhook is rewritten with the App's own credential (url, content type json, TLS verification on, the secret) and the connection's re-detected webhook status is returned: 'state' ('available', 'unavailable' or 'unknown'), 'reason' ('webhook_not_configured', 'webhook_points_elsewhere', 'missing_events', 'verification_unavailable' or empty), 'missing_events' and 'detail'. Event subscriptions (Push, Pull request) cannot be changed through the API: when 'reason' is 'missing_events' an organization owner must tick them in the App's settings. A refusal (for example 'connection_not_found', 'provider_not_github', 'webhook_in_use_by_other_org' — the App's webhook already delivers to another organization — or 'webhook_not_active' — the App has no active webhook, which GitHub's API cannot create, so an organization owner must first enable it (tick Active) in the App's settings) is a 400 carrying a machine-readable 'reason'; a failure talking to GitHub (a 'reason' starting with 'github_') is a 502; a request that runs past its 50-second bound is a 504 with 'reason' 'timeout', and the change may still have been applied, so re-read the status before retrying; a transient failure inside LimaCharlie — the collection host failing without a refusal reason, or not being reachable or answering usably at all — is a 503 with 'reason' 'host_unavailable' and is safe to retry; a 500 with 'reason' 'hooks_domain_unavailable' means this organization's hooks domain could not be determined, and nothing was changed. Neither the URL nor the secret is ever returned or logged. Requires cloudsec.set.","summary":"Configure a Source-Control Connection's Webhook","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/compliance":{"get":{"operationId":"getCloudSecCompliance","tags":["Cloud Security"],"parameters":[{"name":"framework","description":"the framework id to assess (e.g. cis-gcp); defaults to cis-gcp; ignored when 'assignment' is set","schema":{"type":"string"},"in":"query"},{"name":"assignment","description":"the name of a scoped compliance assignment to evaluate instead of the whole estate; its framework is assessed over its in-scope resources","schema":{"type":"string"},"in":"query"},{"name":"format","description":"set to 'csv' to stream the export as a text/csv attachment instead of JSON (walks the full filtered set server-side, capped at 100k rows)","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"report":{"type":"object"}},"required":["report"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the per-control pass/fail compliance assessment for a framework (default cis-gcp) against the org's open findings, with evidence and a summary score. Pass 'assignment' to evaluate a named scoped assignment instead (its framework over its in-scope estate); when set, 'framework' is ignored.","summary":"Get Cloud Security Compliance","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/compliance/assignments":{"get":{"operationId":"listCloudSecComplianceAssignments","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"assignments":{"items":{"type":"object"},"type":"array"}},"required":["assignments"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List the org's scoped compliance assignments (name, framework, scope, and a full scoped summary score per assignment). Empty when the org has defined no assignments — the UI then shows only the whole-estate default.","summary":"List Cloud Security Compliance Assignments","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/compliance/attestations":{"get":{"operationId":"listCloudSecComplianceAttestations","tags":["Cloud Security"],"parameters":[{"name":"framework","description":"framework id","schema":{"type":"string"},"in":"query"},{"name":"assignment","description":"assignment name","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List immutable attestation revisions for an assignment and framework.","summary":"List Cloud Security Compliance Attestations","x-required-permissions":{"all_of":["cloudsec.get"]}},"post":{"operationId":"createCloudSecComplianceAttestation","tags":["Cloud Security"],"parameters":[{"name":"framework","description":"framework id","schema":{"type":"string"},"in":"query"},{"name":"assignment","description":"assignment name","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"attestation revision","content":{"application/json":{"schema":{"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Write one attributed immutable attestation revision. Revocation is a later revision, never an overwrite.","summary":"Create Cloud Security Compliance Attestation","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/compliance/events":{"get":{"operationId":"listCloudSecComplianceEvents","tags":["Cloud Security"],"parameters":[{"name":"assignment","description":"assignment name","schema":{"type":"string"},"in":"query"},{"name":"days","description":"lookback in days","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"limit","description":"maximum events","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List material control-state changes for ongoing compliance drift workflows.","summary":"List Cloud Security Compliance Events","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/compliance/export":{"get":{"operationId":"exportCloudSecComplianceRun","tags":["Cloud Security"],"parameters":[{"name":"run_id","required":true,"description":"immutable run id","schema":{"type":"string"},"in":"query"},{"name":"format","description":"json, csv, or pdf","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Render a deterministic JSON, CSV, or PDF artifact from an immutable run.","summary":"Export Cloud Security Compliance Run","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/compliance/frameworks":{"get":{"operationId":"listCloudSecComplianceFrameworks","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"frameworks":{"items":{"type":"object"},"type":"array"}},"required":["frameworks"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List the selectable compliance frameworks (id, name, version, control count).","summary":"List Cloud Security Compliance Frameworks","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/compliance/runs":{"get":{"operationId":"listCloudSecComplianceRuns","tags":["Cloud Security"],"parameters":[{"name":"run_id","description":"specific immutable run id","schema":{"type":"string"},"in":"query"},{"name":"framework","description":"framework id","schema":{"type":"string"},"in":"query"},{"name":"assignment","description":"assignment name","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"maximum runs, up to 200","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List immutable completed runs, or return one run and its historical control snapshot when run_id is supplied.","summary":"List Cloud Security Compliance Runs","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/compliance/schedules":{"get":{"operationId":"listCloudSecComplianceSchedules","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List recurring compliance assessment and delivery schedules.","summary":"List Cloud Security Compliance Schedules","x-required-permissions":{"all_of":["cloudsec.get"]}},"post":{"operationId":"upsertCloudSecComplianceSchedule","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"schedule","content":{"application/json":{"schema":{"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Create or revise an org-scoped weekly/monthly assessment schedule using an Output or secret reference.","summary":"Upsert Cloud Security Compliance Schedule","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/compliance/v2":{"post":{"operationId":"createCloudSecComplianceRun","tags":["Cloud Security"],"parameters":[{"name":"framework","description":"framework id for an estate-wide run","schema":{"type":"string"},"in":"query"},{"name":"assignment","description":"named assignment; its framework supersedes framework","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Evaluate compliance v2 using positive detector execution proof and persist an immutable historical run.","summary":"Create Cloud Security Compliance Run","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/data-security/facets":{"get":{"operationId":"getCloudSecDataStoreFacets","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"facets":{"type":"object"}},"required":["facets"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the data-security (DSPM) rollup over every data store: the total / sensitive / public / public-sensitive counts plus the store-kind, sensitivity, and exposure facets — computed server-side so the Data Security view leads with exact counts before its (separately paginated) row list.","summary":"Get Cloud Data Security Facets","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/data-security/stores":{"get":{"operationId":"getCloudSecDataStores","tags":["Cloud Security"],"parameters":[{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of stores to return for this page; omit to use the backend default","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"next_cursor":{"type":"string"},"stores":{"items":{"type":"object"},"type":"array"}},"required":["stores"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Keyset-paginated data-store rows served from the materialized graph store under the same selectors as /data-security/facets (provider, account, region, store_kind, tier, sensitivity, exposure) — the filtered Data Security list stays exact at any estate size instead of client-filtering a capped walk.","summary":"Get Cloud Data Security Stores","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/entities/resolve":{"post":{"operationId":"resolveCloudSecEntities","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"One to 100 identifiers, an optional Unix-second at timestamp (it also pins the UTC day of observation selectors) and up to 4 observation selectors answered in observed_matches (telemetry permission only)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"at":{"type":"integer"},"identifiers":{"items":{"additionalProperties":false,"properties":{"type":{"type":"string"},"value":{"type":"string"}},"required":["value"],"type":"object"},"type":"array"},"observation_selectors":{"items":{"additionalProperties":false,"properties":{"origin_sid":{"type":"string"},"platform":{"type":"string"},"type":{"type":"string"},"value":{"type":"string"}},"required":["type","value"],"type":"object"},"type":"array"}},"required":["identifiers"],"type":"object"}}},"required":true},"responses":{"200":{"description":"Entity response; observed pivots (also_seen_as, cloud_sign_ins, observed_matches) appear only for callers with insight.evt.get, and observations.status says forbidden, unavailable, incomplete or ok","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Read entity identity and activity with the caller's product permissions. Possible matches are unconfirmed.","summary":"Resolve Entities","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/entities/search":{"get":{"operationId":"searchCloudSecEntities","tags":["Cloud Security"],"parameters":[{"name":"q","required":true,"description":"Identifier prefix (at least 2 characters, at most 512 bytes)","schema":{"type":"string"},"in":"query"},{"name":"kind","description":"user or host","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"Page size, 1 to 100","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"cursor","description":"Opaque next_cursor from the previous page","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"Entity response; observed pivots (also_seen_as, cloud_sign_ins, observed_matches) appear only for callers with insight.evt.get, and observations.status says forbidden, unavailable, incomplete or ok","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Read entity identity and activity with the caller's product permissions. Possible matches are unconfirmed.","summary":"Search Entities","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/entities/{entity_id}":{"get":{"operationId":"getCloudSecEntity","tags":["Cloud Security"],"parameters":[{"name":"sightings_days","description":"Recent activity days, 1 to 365 (default 30)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"entity_id","required":true,"description":"Opaque entity identifier","schema":{"pattern":"^e[uh]_[a-z2-7]{1,37}$","type":"string"},"in":"path"}],"responses":{"200":{"description":"Entity response; observed pivots (also_seen_as, cloud_sign_ins, observed_matches) appear only for callers with insight.evt.get, and observations.status says forbidden, unavailable, incomplete or ok","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Read entity identity and activity with the caller's product permissions. Possible matches are unconfirmed.","summary":"Get Entity","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/entities/{entity_id}/activity":{"get":{"operationId":"getCloudSecEntityActivity","tags":["Cloud Security"],"parameters":[{"name":"since","description":"Unix seconds; default 30 days before until","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"until","description":"Unix seconds; default now; maximum window 30 days","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"sources","description":"Comma-separated email,detections,sensor,cloud (default all)","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"entity_id","required":true,"description":"Opaque entity identifier","schema":{"pattern":"^e[uh]_[a-z2-7]{1,37}$","type":"string"},"in":"path"}],"responses":{"200":{"description":"Entity response; observed pivots (also_seen_as, cloud_sign_ins, observed_matches) appear only for callers with insight.evt.get, and observations.status says forbidden, unavailable, incomplete or ok","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Read entity identity and activity with the caller's product permissions. Possible matches are unconfirmed.","summary":"Get Entity Activity","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/entities/{entity_id}/sightings":{"get":{"operationId":"getCloudSecEntitySightings","tags":["Cloud Security"],"parameters":[{"name":"kind","description":"user, logon, int_ip, ext_ip or hostname","schema":{"type":"string"},"in":"query"},{"name":"since","description":"Inclusive Unix-second timestamp","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"until","description":"Exclusive Unix-second timestamp","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"limit","description":"Page size, 1 to 500","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"cursor","description":"Opaque next_cursor from the previous page","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"entity_id","required":true,"description":"Opaque entity identifier","schema":{"pattern":"^e[uh]_[a-z2-7]{1,37}$","type":"string"},"in":"path"}],"responses":{"200":{"description":"Entity response; observed pivots (also_seen_as, cloud_sign_ins, observed_matches) appear only for callers with insight.evt.get, and observations.status says forbidden, unavailable, incomplete or ok","content":{"application/json":{"schema":{"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Read entity identity and activity with the caller's product permissions. Possible matches are unconfirmed.","summary":"Get Entity Sightings","x-required-permissions":{"all_of":["cloudsec.get","insight.evt.get"]}}},"/cloudsec/{oid}/findings":{"get":{"operationId":"getCloudSecFindings","tags":["Cloud Security"],"parameters":[{"name":"has_iac_origin","description":"true/false: recorded IaC origin evidence exists for the resource. False means no recorded evidence, not proof that no IaC source exists. Requires Code Security provenance queries enabled","schema":{"type":"boolean"},"in":"query"},{"name":"iac_attribution","description":"repeatable (maximum four): attributed | ambiguous | none | unknown. Unknown includes missing or unrecognized evidence; never interpreted as safe. Requires Code Security provenance queries enabled","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of findings to return for this page; omit to use the backend default","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"format","description":"set to 'csv' to stream the export as a text/csv attachment instead of JSON (walks the filtered set server-side, capped at 100k rows per request; see max_rows to fetch it in bounded chunks)","schema":{"type":"string"},"in":"query"},{"name":"max_rows","description":"with format=csv: end the export after roughly this many rows (1-100000, rounded up to whole 1000-row pages) instead of walking to the 100k cap. A chunk that stops early ends with a '# next_cursor=\u003ctoken\u003e' row; repeat the request with max_rows and cursor=\u003ctoken\u003e to continue exactly after it (a cursor is only honored together with max_rows; without max_rows the export always starts from the top). A chunk with no such row is the end of the set. Lets a client with a short timeout export a large set in bounded, resumable requests","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"repo","description":"repeatable: restrict to findings whose subject is one of these source repositories, keyed '\u003cowner\u003e/\u003cname\u003e' as /code/repos returns them. This is the AppSec code lane's selector; cloud findings have no repository and are excluded by it","schema":{"type":"string"},"in":"query"},{"name":"fix_state","description":"repeatable: restrict to findings by fix availability — fix_available | no_fix | unknown. 'unknown' is a first-class value and is NOT a synonym for 'no_fix': a fixed version we never collected is not a fix that does not exist. 'no_fix' is asserted only on a positive signal (a malicious package, or a VEX assertion that makes the fix moot)","schema":{"type":"string"},"in":"query"},{"name":"grain","description":"repeatable: which UNIT OF WORK a vulnerability finding states — package (upgrade \u003cpkg\u003e on host X, closes N CVEs; rule_id vulnerable-package) | cve (one finding per CVE with the affected resources as pivot targets; rule_id vulnerability) | other (everything else, including the container-image and source-repository vulnerability lanes). UNLIKE every other selector, OMITTING this is not 'no constraint': the default worklist leads with the package grain, excluding only the per-CVE rollups a package finding already states pair for pair, so the same pairs are never counted twice. Pass grain=cve to reach every per-CVE finding including those; pass both values for the unfiltered union. The 'grain' facet on /findings/facets always reports the full per-grain population, so a client can show what the default is holding back","schema":{"type":"string"},"in":"query"},{"name":"exploit_band","description":"repeatable: restrict to findings by exploit-urgency band — kev_overdue | kev_due | exploit_likely | exploit_probable | elevated | baseline | none, most urgent first. KEV dominates EPSS; a KEV entry whose remediation due date is missing or unparseable bands 'kev_due' and never 'kev_overdue'. 'none' selects findings with no exploit signal at all","schema":{"type":"string"},"in":"query"},{"name":"cause","description":"Exact shared-fix cause key. Empty means unconstrained; an unknown key returns no findings.","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"findings":{"items":{"type":"object"},"type":"array"}},"required":["findings"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the merged, risk-ranked cloud-security findings for the organization (CSPM misconfigurations + graph toxic-combination attack paths + CIEM access), ordered by lc_risk. Supports keyset pagination via the optional 'cursor' and 'limit' query parameters; the response carries a 'next_cursor' to fetch the following page. A dependency (SCA) finding's 'code' block carries 'autofix_version', the one version an AutoFix pull request would raise the package to, present only when AutoFix can act on the finding (it differs from 'fix_version' when the advisory lists one fix per release line); and, when that raise crosses the installed version's release line, 'autofix_major_upgrade': true with 'autofix_from_line' and 'autofix_to_line' (for example '4.x' and '5.x'): a major upgrade that may break code using the package, which the AutoFix pull request is flagged as. An 'autofix_version' without 'autofix_major_upgrade' stays on the installed line.","summary":"Get Cloud Security Findings","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/findings/bulk/status":{"post":{"operationId":"bulkSetCloudSecFindingStatus","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the finding ids + resolution","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"finding_ids":{"items":{"type":"string"},"type":"array"},"resolution":{"type":"object"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"updated":{"type":"integer"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Disposition many findings at once: apply one resolution to a list of finding ids.","summary":"Bulk Set Cloud Security Finding Status","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/findings/causes":{"get":{"operationId":"getCloudSecFindingCauses","tags":["Cloud Security"],"parameters":[{"name":"has_iac_origin","description":"true/false: recorded IaC origin evidence exists for the resource. False means no recorded evidence, not proof that no IaC source exists. Requires Code Security provenance queries enabled","schema":{"type":"boolean"},"in":"query"},{"name":"iac_attribution","description":"repeatable (maximum four): attributed | ambiguous | none | unknown. Unknown includes missing or unrecognized evidence; never interpreted as safe. Requires Code Security provenance queries enabled","schema":{"type":"string"},"in":"query"},{"name":"fix_state","description":"repeatable: restrict to findings by fix availability — fix_available | no_fix | unknown. 'unknown' is a first-class value and is NOT a synonym for 'no_fix': a fixed version we never collected is not a fix that does not exist. 'no_fix' is asserted only on a positive signal (a malicious package, or a VEX assertion that makes the fix moot)","schema":{"type":"string"},"in":"query"},{"name":"grain","description":"repeatable: which UNIT OF WORK a vulnerability finding states — package (upgrade \u003cpkg\u003e on host X, closes N CVEs; rule_id vulnerable-package) | cve (one finding per CVE with the affected resources as pivot targets; rule_id vulnerability) | other (everything else, including the container-image and source-repository vulnerability lanes). UNLIKE every other selector, OMITTING this is not 'no constraint': the default worklist leads with the package grain, excluding only the per-CVE rollups a package finding already states pair for pair, so the same pairs are never counted twice. Pass grain=cve to reach every per-CVE finding including those; pass both values for the unfiltered union. The 'grain' facet on /findings/facets always reports the full per-grain population, so a client can show what the default is holding back","schema":{"type":"string"},"in":"query"},{"name":"exploit_band","description":"repeatable: restrict to findings by exploit-urgency band — kev_overdue | kev_due | exploit_likely | exploit_probable | elevated | baseline | none, most urgent first. KEV dominates EPSS; a KEV entry whose remediation due date is missing or unparseable bands 'kev_due' and never 'kev_overdue'. 'none' selects findings with no exploit signal at all","schema":{"type":"string"},"in":"query"},{"name":"cause","description":"Exact shared-fix cause key. Empty means unconstrained; an unknown key returns no findings.","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"causes":{"items":{"type":"object"},"type":"array"},"distinct":{"type":"integer"}},"required":["causes","distinct"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get findings grouped by their CAUSE — the mutable object (e.g. a firewall rule) whose single edit resolves all of them — under the same filter selectors as the findings list. Pass `cause` to get the exact count for one cause; omit it for the top causes by count (`limit`, default 20, max 200) plus `distinct`, the total number of causes matching the filter.","summary":"Get Cloud Security Shared-Fix Causes","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/findings/classes":{"get":{"operationId":"getCloudSecFindingClasses","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"classes":{"items":{"type":"string"},"type":"array"}},"required":["classes"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the canonical finding_class vocabulary (the valid values for finding-class filters and suppression-policy matchers), served from the backend enum so UIs never guess at the valid set.","summary":"Get Cloud Security Finding Classes","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/findings/facets":{"get":{"operationId":"getCloudSecFindingFacets","tags":["Cloud Security"],"parameters":[{"name":"has_iac_origin","description":"true/false: recorded IaC origin evidence exists for the resource. False means no recorded evidence, not proof that no IaC source exists. Requires Code Security provenance queries enabled","schema":{"type":"boolean"},"in":"query"},{"name":"iac_attribution","description":"repeatable (maximum four): attributed | ambiguous | none | unknown. Unknown includes missing or unrecognized evidence; never interpreted as safe. Requires Code Security provenance queries enabled","schema":{"type":"string"},"in":"query"},{"name":"owner_pin","description":"repeatable: owners to keep in the capped 'owner' facet even when they would not rank into it — pass the calling user to keep their own row reachable. NOT a filter: it selects no rows and changes no count.","schema":{"type":"string"},"in":"query"},{"name":"repo","description":"repeatable: restrict to findings whose subject is one of these source repositories, keyed '\u003cowner\u003e/\u003cname\u003e'. The response's 'repo' facet counts the code lane's repositories (capped at the top 200 by count, with any actively selected repository pinned into it; 'repo_truncated' reports whether any were dropped) and never includes the non-repository findings","schema":{"type":"string"},"in":"query"},{"name":"fix_state","description":"repeatable: restrict to findings by fix availability — fix_available | no_fix | unknown. 'unknown' is a first-class value and is NOT a synonym for 'no_fix': a fixed version we never collected is not a fix that does not exist. 'no_fix' is asserted only on a positive signal (a malicious package, or a VEX assertion that makes the fix moot)","schema":{"type":"string"},"in":"query"},{"name":"grain","description":"repeatable: which UNIT OF WORK a vulnerability finding states — package (upgrade \u003cpkg\u003e on host X, closes N CVEs; rule_id vulnerable-package) | cve (one finding per CVE with the affected resources as pivot targets; rule_id vulnerability) | other (everything else, including the container-image and source-repository vulnerability lanes). UNLIKE every other selector, OMITTING this is not 'no constraint': the default worklist leads with the package grain, excluding only the per-CVE rollups a package finding already states pair for pair, so the same pairs are never counted twice. Pass grain=cve to reach every per-CVE finding including those; pass both values for the unfiltered union. The 'grain' facet on /findings/facets always reports the full per-grain population, so a client can show what the default is holding back","schema":{"type":"string"},"in":"query"},{"name":"exploit_band","description":"repeatable: restrict to findings by exploit-urgency band — kev_overdue | kev_due | exploit_likely | exploit_probable | elevated | baseline | none, most urgent first. KEV dominates EPSS; a KEV entry whose remediation due date is missing or unparseable bands 'kev_due' and never 'kev_overdue'. 'none' selects findings with no exploit signal at all","schema":{"type":"string"},"in":"query"},{"name":"cause","description":"Exact shared-fix cause key. Empty means unconstrained; an unknown key returns no findings.","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"facets":{"type":"object"}},"required":["facets"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the cross-filtered facet counts and total for the findings worklist under the same filter selectors as the findings list (severity, finding_class, status, account, owner, repo, reachable, kev, q). Each facet dimension is counted against the other active filters. The 'owner' facet is keyed by owner with the empty string holding the unassigned bucket, and is capped at the top 50 owners by count; 'owner_truncated' reports whether any were dropped. Repeat 'owner_pin' to keep specific owners in that capped facet (e.g. the calling user, so their own row stays visible on an estate with more owners than the cap) — it is NOT a filter and changes no count; the unassigned bucket is always included and outranks every pin.","summary":"Get Cloud Security Finding Facets","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/findings/{finding_id}":{"get":{"operationId":"getCloudSecFinding","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"finding_id","required":true,"description":"the finding id (fnd_...) to fetch","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"finding":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get a single cloud-security finding by its id, with full detail (vulnerability/CVE, evidence, remediation, status). Independent of the worklist pagination. A dependency (SCA) finding's 'code' block carries 'autofix_version', the one version an AutoFix pull request would raise the package to, present only when AutoFix can act on the finding (it differs from 'fix_version' when the advisory lists one fix per release line); and, when that raise crosses the installed version's release line, 'autofix_major_upgrade': true with 'autofix_from_line' and 'autofix_to_line' (for example '4.x' and '5.x'): a major upgrade that may break code using the package, which the AutoFix pull request is flagged as. An 'autofix_version' without 'autofix_major_upgrade' stays on the installed line.","summary":"Get Cloud Security Finding","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/findings/{finding_id}/evidence-chain":{"get":{"operationId":"getCloudSecFindingEvidenceChain","tags":["Cloud Security"],"parameters":[{"name":"runtime","description":"`true` to include the current runtime evidence on the observed stage (read-only)","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"finding_id","required":true,"description":"the finding id (fnd_ followed by 32 lowercase hex)","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"the chain, or chain null with a closed reason","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"chain":{"additionalProperties":false,"properties":{"complete":{"type":"boolean"},"finding_id":{"type":"string"},"gaps":{"type":"integer"},"generated_at":{"type":"string"},"oid":{"type":"string"},"stages":{"items":{"type":"object"},"type":"array"}},"type":"object"},"reason":{"type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"evidence_chain_unavailable: transport, retryable or unknown backend outcome","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"type":"string"}},"type":"object"}}}}},"description":"The evidence chain for one finding, in eight stages: declared (the code or IaC declaration), committed, built, running (the immutable artifact deployed), exposed, observed (runtime), responded (remediation) and verified. Each stage is `proven`, `partial`, `unknown` or `not_applicable`, with its evidence level, source, observation and expiry times, a closed `reason`, and bounded references (repository, file at an exact commit, digest, workload, remediation run). Every stage that is not proven carries a concrete next `action`. A reason this server version does not recognise is returned verbatim with `reason_recognised: false` and the action `review_reason`; clients must show it rather than drop it. `proven` says the evidence for the stage is complete. It does not say the news is good: read `outcome` (for example `not_observed` on a complete runtime window, or `regressed`). An unknown or partial stage is never a statement that something is safe, not exposed or fixed. Links are present only for permalinks that pin the exact commit. `runtime=true` adds the current runtime evidence to the observed stage; it reads existing evidence only and does not start a measurement (use POST .../runtime-check for that). A successful response with `chain: null` carries `reason`: `feature_disabled` (the default-off Code Security evidence chain feature is not enabled for this organization) or `finding_not_found`. Requires cloudsec.get. Rate limit: 600 requests per hour per authenticated identity.","summary":"Read a Finding's Evidence Chain","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/findings/{finding_id}/owner":{"post":{"operationId":"setCloudSecFindingOwner","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"finding_id","required":true,"description":"the finding id to assign","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"the owner","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"owner":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"ok":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Assign (or clear, with an empty owner) the owner of a finding.","summary":"Set Cloud Security Finding Owner","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/findings/{finding_id}/remediations":{"post":{"operationId":"postCloudSecFindingRemediation","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"finding_id","required":true,"description":"the finding id to remediate","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"remediation request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"action":{"type":"string"},"idempotency_key":{"type":"string"}},"required":["action","idempotency_key"],"type":"object"}}},"required":true},"responses":{"200":{"description":"the run, and whether this request replayed an existing one","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"result":{"additionalProperties":false,"properties":{"replayed":{"type":"boolean"},"run":{"type":"object"}},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"missing_permission: the caller is authorized for the organization but does not hold cloudsec.respond (cloudsec.set does not imply it); or cloud security is not enabled for the organization","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"permission":{"type":"string"}},"type":"object"}}}},"404":{"description":"not_found | finding_not_found","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"409":{"description":"idempotency_mismatch | generation_conflict | illegal_transition | target_changed | claim_lost","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"410":{"description":"approval_expired","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"422":{"description":"action_unavailable","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"429":{"description":"capacity (active run limit) or the per-identity request quota","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"502":{"description":"the backend answered outside the documented vocabulary","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"disabled | unavailable (retryable)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Request a governed remediation run for one finding. The server resolves every target from the finding; a caller cannot name a sensor, resource, target or actor. `idempotency_key` (1-128 of [A-Za-z0-9._:-]) makes the request safe to retry: the same key with the same finding and action returns the same run with `replayed: true`, and the same key with a different request is refused with idempotency_mismatch. Actions include the read-only targeted validations `validate_detection` (reads back the finding's temporary detection) and `validate_runtime` (reads the finding's runtime evidence), which change nothing and contact nothing. Every run waits for a human approval before it acts. Requires cloudsec.respond (cloudsec.set does not imply it) and the default-off Code Security remediation feature. Body: uncompressed application/json, at most 4 KiB, exactly {action, idempotency_key}; unknown fields are refused. Rate limit: 60 requests per minute per authenticated identity.","summary":"Request Code Security Remediation","x-required-permissions":{"all_of":["cloudsec.respond"]}}},"/cloudsec/{oid}/findings/{finding_id}/runtime-check":{"post":{"operationId":"postCloudSecFindingRuntimeCheck","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"finding_id","required":true,"description":"the finding id (fnd_...) to check","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"runtime evidence for the finding's packages","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"accepted":{"type":"boolean"},"runtime":{"additionalProperties":false,"properties":{"checked_at":{"type":"string"},"complete":{"type":"boolean"},"level":{"type":"string"},"packages":{"items":{"type":"object"},"type":"array"},"reason":{"type":"string"},"resource_urn":{"type":"string"},"retry_after_seconds":{"type":"integer"},"sensors":{"type":"integer"},"sensors_complete":{"type":"boolean"},"source":{"type":"string"},"status":{"type":"string"}},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Ask whether the code a finding is about was actually observed running on the resource, using the LimaCharlie agents already on it. INFORMATIONAL ONLY: the answer never changes the finding's risk score, status, severity or identity. Each package gets one of five states. `executing` means the package is the running executable. `loaded` means it is mapped into a running process. `not_observed` means a COMPLETE telemetry window saw the package never run. It is not a safety, remediation or exploitability claim, it never lowers the finding's risk, and it says only that the code was not seen running during that window. `present` means an agent is on the resource but the telemetry cannot support a claim. `unknown` means there is no usable evidence. Every state carries a reason, an evidence level, an observation time and an expiry, and the response reports how many sensors contributed and whether that sensor set was complete. A negative is reported only for a complete window over a complete sensor set; an incomplete or conflicting picture is always `present` or `unknown`, never a negative. Asking is what starts the measurement: the check publishes this finding's packages as relevant for the resource's sensors, and evidence accumulates over the following minutes. `complete` false with `retry_after_seconds` means the window has not matured yet, so ask again. Targets are derived from the finding id server-side; a caller cannot name a sensor, resource or package. Requires cloudsec.get and the default-off Code Security runtime-evidence feature. Rate limit: 600 requests per hour per authenticated identity.","summary":"Check Whether a Finding's Code Ran","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/findings/{finding_id}/status":{"post":{"operationId":"setCloudSecFindingStatus","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"finding_id","required":true,"description":"the finding id to disposition","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"the resolution","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"resolution":{"additionalProperties":false,"properties":{"expires_at":{"type":"integer"},"kind":{"type":"string"},"reason":{"type":"string"}},"type":"object"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"ok":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Disposition a finding: record an operator resolution (mitigated | accepted | false_positive) with an optional reason and (for accepted) an expires_at (unix seconds).","summary":"Set Cloud Security Finding Status","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/findings/{finding_id}/ticket":{"post":{"operationId":"setCloudSecFindingTicket","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"finding_id","required":true,"description":"the finding id to link","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"the ticket","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"ticket":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"ok":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Link (or clear) a ticket id/url to a finding.","summary":"Set Cloud Security Finding Ticket","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/free-tier":{"get":{"operationId":"getCloudSecFreeTier","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"enabled_providers":{"type":"number"},"is_free_tier":{"type":"boolean"},"max_providers":{"type":"number"},"sensor_quota":{"type":"number"}},"required":["is_free_tier","sensor_quota"],"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Report whether the organization is on the cloud-security free tier, and the limits that apply to it. Used to surface upgrade prompts before a limit is hit. Free-tier limits are enforced by the collector; this endpoint only describes them.","summary":"Get Cloud Security Free-Tier Status","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/graph/neighbors":{"get":{"operationId":"getCloudSecGraphNeighbors","tags":["Cloud Security"],"parameters":[{"name":"urn","required":true,"description":"the canonical lcrn of the resource to expand from","schema":{"minLength":1,"type":"string"},"in":"query"},{"name":"limit","description":"max neighbors to return (default 200, hard cap 500)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"graph":{"type":"object"}},"required":["graph"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Expand a single resource's 1-hop neighborhood in the security graph: every node directly connected to the given urn (in either direction) plus the connecting edges, in the same { graph: { nodes, edges } } induced-subgraph shape as a graph query. Server-bounded, ranked (sensitive → public → data/identity), and capped; 'truncated' is true when the resource has more neighbors than the cap. Powers click-to-expand on the graph canvas.","summary":"Get Cloud Security Graph Neighbors","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/inventory":{"get":{"operationId":"getCloudSecInventory","tags":["Cloud Security"],"parameters":[{"name":"has_iac_origin","description":"true/false: recorded IaC origin evidence exists for the resource. False means no recorded evidence, not proof that no IaC source exists. Requires Code Security provenance queries enabled","schema":{"type":"boolean"},"in":"query"},{"name":"type","description":"filter to one resource_type (e.g. compute_instance | Identity | ThirdPartyAsset)","schema":{"type":"string"},"in":"query"},{"name":"provider","description":"filter by producing sweep (gcp | okta | google_workspace | …). Single-valued; with type=Identity it is repeatable, or use the 'source' alias","schema":{"type":"string"},"in":"query"},{"name":"account","description":"filter by account/project. Single-valued; repeatable with type=Identity","schema":{"type":"string"},"in":"query"},{"name":"region","description":"filter by region. Single-valued; repeatable with type=Identity","schema":{"type":"string"},"in":"query"},{"name":"q","description":"case-insensitive substring filter over the resource's identifying fields","schema":{"type":"string"},"in":"query"},{"name":"account_empty","description":"set true to select only resources whose cloud account is empty; omit all account selectors to span the whole estate","schema":{"type":"boolean"},"in":"query"},{"name":"account_unscoped","description":"deprecated alias for account_empty","schema":{"type":"boolean"},"in":"query"},{"name":"sort","description":"page order for the merged lanes: 'urn' (default — stable, safe for a full walk or export) or 'risk' for type=Identity / 'last_seen' for type=ThirdPartyAsset. A ranked walk can move a row across the cursor when the projector recomputes mid-walk","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of resources to return for this page; omit to use the backend default","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"format","description":"set to 'csv' to stream the export as a text/csv attachment instead of JSON (walks the filtered set server-side, capped at 100k rows per request; see max_rows to fetch it in bounded chunks)","schema":{"type":"string"},"in":"query"},{"name":"max_rows","description":"with format=csv: end the export after roughly this many rows (1-100000, rounded up to whole 1000-row pages) instead of walking to the 100k cap. A chunk that stops early ends with a '# next_cursor=\u003ctoken\u003e' row; repeat the request with max_rows and cursor=\u003ctoken\u003e to continue exactly after it (a cursor is only honored together with max_rows; without max_rows the export always starts from the top). A chunk with no such row is the end of the set. Lets a client with a short timeout export a large set in bounded, resumable requests","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"source","description":"repeatable: match identities produced by ANY of these sweeps (okta | gcp | google_workspace | …). Same dimension as 'provider'; use this form to select several","schema":{"type":"string"},"in":"query"},{"name":"kind","description":"repeatable identity kind filter (user | service_account | group | ai_agent | …)","schema":{"type":"string"},"in":"query"},{"name":"criticality","description":"repeatable crown-jewel tier filter","schema":{"type":"string"},"in":"query"},{"name":"risk_band","description":"repeatable risk-band filter (critical | high | medium | low) — the band token the rail renders, not a numeric range","schema":{"type":"string"},"in":"query"},{"name":"mfa","description":"MFA state filter: on | off | unknown. 'unknown' is everyone the MFA question does not apply to (no identity-provider observation, or non-human) — it is NOT 'off'","schema":{"type":"string"},"in":"query"},{"name":"admin","description":"true/false: restrict to identities holding (or not holding) an admin role. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"external","description":"true/false: restrict to identities outside the org's own domains. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"public","description":"true/false: restrict to public principals (allUsers / allAuthenticatedUsers and their equivalents). Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"disabled","description":"true/false: restrict to disabled (or enabled) identities. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"crown_jewel","description":"true/false: restrict to identities the org's cloudsec_policy declares sensitive. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"can_escalate","description":"true/false: restrict to identities that can escalate their own privileges. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"dormant_90d","description":"true/false: restrict to identities with no observed activity in 90 days. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"with_sensitive","description":"true/false: restrict to principals holding at least one non-deny grant on a sensitive resource. Omit for no constraint","schema":{"type":"boolean"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data_as_of":{"type":"string"},"next_cursor":{"oneOf":[{"type":"string"},{"type":"null"}]},"resources":{"items":{"type":"object"},"type":"array"},"served_from":{"type":"string"}},"required":["resources"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the organization's cloud resource inventory — every collected resource with its type, account, region, and properties. Supports keyset pagination via the optional 'cursor' and 'limit' query parameters; the response carries a 'next_cursor' to fetch the following page. With type=Identity the rows are the MERGED identity inventory (one row per real identity, unified across the sweeps that observed it), which additionally accepts the identity cross-filter selectors below and the 'sort' order.","summary":"Get Cloud Inventory","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/inventory/facets":{"get":{"operationId":"getCloudSecInventoryFacets","tags":["Cloud Security"],"parameters":[{"name":"has_iac_origin","description":"true/false: recorded IaC origin evidence exists for the resource. False means no recorded evidence, not proof that no IaC source exists. Requires Code Security provenance queries enabled","schema":{"type":"boolean"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"accounts":{"items":{"type":"object"},"type":"array"},"providers":{"items":{"type":"object"},"type":"array"},"regions":{"items":{"type":"object"},"type":"array"},"types":{"items":{"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the inventory resource counts grouped by resource type, account, and region.","summary":"Get Cloud Inventory Facets","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/overview":{"get":{"operationId":"getCloudSecOverview","tags":["Cloud Security"],"parameters":[{"name":"trend_days","description":"number of days of score trend to include (default 30)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"properties":{"score":{"type":"integer"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the composed risk overview: score, severity distribution, top attack paths, account coverage, the score trend, and recent finding changes — in one round-trip.","summary":"Get Cloud Security Overview","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/policy/suggest":{"post":{"operationId":"suggestCloudSecPolicyValues","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the suggestion query","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"dimension":{"type":"string"},"limit":{"type":"number"},"q":{"type":"string"},"target":{"type":"string"}},"required":["dimension","q"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"evaluated":{"type":"number"},"truncated":{"type":"boolean"},"values":{"items":{"type":"object"},"type":"array"}},"required":["values"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Suggest values for a cloudsec_policy matcher dimension from the organization's own inventory as the operator types. dimension 'name' walks the estate's policy-matchable resources (bounded, truncation-flagged) for resource names containing the typed text; dimension 'account' filters the account facet. Optional 'target' (data_store|compute|identity|any) narrows the walked resource family to the rule set being edited. Returns ranked {value,count} suggestions. Read-only: nothing is saved.","summary":"Suggest Cloud Security Policy Matcher Values","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/policy/vocabulary":{"get":{"operationId":"getCloudSecPolicyVocabulary","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"content_classes":{"items":{"type":"string"},"type":"array"},"in_use":{"type":"object"},"providers":{"items":{"type":"string"},"type":"array"},"resource_types":{"type":"object"},"suggested_classes":{"items":{"type":"string"},"type":"array"},"surfaces":{"type":"object"},"tiers":{"items":{"type":"string"},"type":"array"}},"required":["surfaces"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the classification-policy vocabulary that drives the crown-jewel/coverage/exclusion rule form: the per-surface capability table (which matcher dimensions each policy surface accepts), the closed vocabularies (resource types grouped per section, providers, criticality tiers, content classes, suggested classes), and the org's in-use histograms (accounts, regions, label keys, network tags, resource types) so the form can offer autocomplete without the operator guessing at valid tokens.","summary":"Get Cloud Security Policy Vocabulary","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/providers/m365/certificate":{"post":{"operationId":"mintCloudSecM365Certificate","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the connection to generate the certificate for","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"client_id":{"type":"string"},"connection":{"type":"string"},"replace":{"type":"boolean"}},"required":["connection"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"certificate":{"type":"string"},"certificate_pem":{"type":"string"},"common_name":{"type":"string"},"created":{"type":"boolean"},"credentials":{"type":"string"},"not_after":{"type":"string"},"not_before":{"type":"string"},"secret_name":{"type":"string"},"thumbprint":{"type":"string"},"thumbprint_sha256":{"type":"string"}},"required":["created","secret_name","credentials","certificate","thumbprint","not_after"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Generate the certificate a Microsoft Entra / Microsoft 365 cloud security connection authenticates with. The key pair is stored in the organization's secret store (secret cloudsec-m365-\u003cconnection\u003e, referenced as the connection's credentials) and rotated automatically; the response carries only the public certificate (base64 DER, the .cer to upload to the app registration) and its thumbprint and validity. Repeat calls return the existing certificate unless replace is true.","summary":"Generate a Microsoft 365 Connection Certificate","x-required-permissions":{"all_of":["cloudsec.set","secret.set"]}}},"/cloudsec/{oid}/providers/manifest":{"get":{"operationId":"getCloudSecProviderManifests","tags":["Cloud Security"],"parameters":[{"name":"type","description":"the provider type to fetch the manifest for (e.g. gcp|aws|azure|okta); omit to list every provider the org has a manifest or a sweep for","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"manifest":{"type":"object"},"manifests":{"items":{"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the per-provider coverage manifests for the organization: for each provider, the collectors (resource kinds + edge kinds) with their status, the posture checks that can fire, the activity/CIEM support level, the validation grade, the known gaps, and the org's own scan coverage/freshness. Pass 'type' to fetch a single provider's manifest (returned under 'manifest' instead of 'manifests'), including a provider the org has never swept.","summary":"Get Cloud Security Provider Manifests","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/providers/test":{"post":{"operationId":"testCloudSecProvider","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the provider to test: {provider: \u003ccloudsec_provider record shape\u003e} with `credentials` inline (ephemeral) or a hive://secret/\u003cname\u003e reference","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"provider":{"type":"object"}},"required":["provider"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"report":{"additionalProperties":false,"properties":{"checks":{"items":{"additionalProperties":false,"properties":{"detail":{"type":"string"},"id":{"type":"string"},"name":{"type":"string"},"ok":{"type":"boolean"},"required":{"type":"boolean"}},"type":"object"},"type":"array"},"ok":{"type":"boolean"},"provider":{"type":"string"}},"type":"object"},"supported":{"type":"boolean"}},"required":["supported"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Preflight a cloud security provider configuration: connect to the provider with the given credentials (ephemeral — never stored) and probe every permission surface collection needs. Returns a structured report: report.ok is the overall verdict over the REQUIRED checks; each check carries id/name/required/ok/detail, and a failed optional check flags a gracefully-degraded surface rather than a failure.","summary":"Test Cloud Security Provider Credentials","x-required-permissions":{"all_of":["cloudsec.set"]}}},"/cloudsec/{oid}/queries":{"get":{"operationId":"getCloudSecQueries","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"queries":{"items":{"type":"object"},"type":"array"}},"required":["queries"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List the built-in cloud-security query pack (the canonical security questions runnable by name).","summary":"List Cloud Security Queries","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/query":{"post":{"operationId":"runCloudSecQuery","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the query to run: provide one of 'named', 'text', or 'query'","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"named":{"type":"string"},"project":{"type":"string"},"query":{"type":"object"},"text":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"rows":{"items":{"type":"object"},"type":"array"}},"required":["rows"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Run a graph query against the org's security graph. Provide exactly one of: 'named' (a query-pack name), 'text' (a text query), or 'query' (a DSL object). Returns alias→urn rows.","summary":"Run Cloud Security Query","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/remediations":{"get":{"operationId":"getCloudSecRemediations","tags":["Cloud Security"],"parameters":[{"name":"finding_id","description":"only runs for this finding","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"opaque next-page cursor from a previous response","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"a page of runs","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"result":{"additionalProperties":false,"properties":{"next_cursor":{"type":"string"},"runs":{"items":{"type":"object"},"type":"array"}},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"404":{"description":"not_found | finding_not_found","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"409":{"description":"idempotency_mismatch | generation_conflict | illegal_transition | target_changed | claim_lost","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"410":{"description":"approval_expired","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"422":{"description":"action_unavailable","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"429":{"description":"capacity (active run limit) or the per-identity request quota","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"502":{"description":"the backend answered outside the documented vocabulary","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"disabled | unavailable (retryable)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List remediation runs for the organization, optionally for one finding. Cursors are opaque. Requires cloudsec.get. An open_fix_pr run's 'change' is the pull request its executor opened or adopted (provider, repository, number, url, head_commit, and merge_commit once merged). 'change.upgrade' is the AutoFix major-upgrade verdict of a pull request the executor opened itself: {'major_upgrade': true, 'from_line', 'to_line'} for a raise across the installed version's release line (for example '4.x' to '5.x'), or {'major_upgrade': false}. It is ABSENT when not recorded, which never means 'not major': the executor adopted a pull request that was already open for the package (it may raise a different version), or the run was recorded before the verdict existed. Pull requests opened before major upgrades were flagged are not re-flagged. Each run in the list also carries 'latest_verdict' when it has recorded a verification verdict: {outcome, rollout: {stage}, reasons (at most 4 closed tokens, the scan-hold reasons first and then the rest in the verdict's own order, so a hold is never the reason that is cut; reasons_truncated when there were more), at}. It is the newest recorded verdict, so a list row can show which fixes are held up and why (for example an open_fix_pr run held by fix_digest_unscanned) without one GET per run; the full verdict with its counts stays on GET /remediations/{run_id}. The key is absent for a run that has recorded none, which never means 'verified'. The finding's runs panel (finding_id) carries it too.","summary":"List Code Security Remediations","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/remediations/{run_id}":{"get":{"operationId":"getCloudSecRemediation","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"run_id","required":true,"description":"the remediation run id (rem_ followed by 32 lowercase hex)","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"the run and its steps","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"result":{"additionalProperties":false,"properties":{"run":{"type":"object"},"steps":{"items":{"type":"object"},"type":"array"}},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"404":{"description":"not_found | finding_not_found","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"409":{"description":"idempotency_mismatch | generation_conflict | illegal_transition | target_changed | claim_lost","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"410":{"description":"approval_expired","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"422":{"description":"action_unavailable","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"429":{"description":"capacity (active run limit) or the per-identity request quota","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"502":{"description":"the backend answered outside the documented vocabulary","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"disabled | unavailable (retryable)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one remediation run with its recorded steps and evidence. Requires cloudsec.get. An open_fix_pr run's 'change' is the pull request its executor opened or adopted (provider, repository, number, url, head_commit, and merge_commit once merged). 'change.upgrade' is the AutoFix major-upgrade verdict of a pull request the executor opened itself: {'major_upgrade': true, 'from_line', 'to_line'} for a raise across the installed version's release line (for example '4.x' to '5.x'), or {'major_upgrade': false}. It is ABSENT when not recorded, which never means 'not major': the executor adopted a pull request that was already open for the package (it may raise a different version), or the run was recorded before the verdict existed. Pull requests opened before major upgrades were flagged are not re-flagged.","summary":"Get Code Security Remediation","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/remediations/{run_id}/approve":{"post":{"operationId":"postCloudSecRemediationApprove","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"run_id","required":true,"description":"the remediation run id (rem_ followed by 32 lowercase hex)","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"decision","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"generation":{"type":"integer"},"scope_digest":{"type":"string"}},"required":["generation","scope_digest"],"type":"object"}}},"required":true},"responses":{"200":{"description":"the run after the decision","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"result":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"missing_permission: the caller is authorized for the organization but does not hold cloudsec.respond (cloudsec.set does not imply it); or cloud security is not enabled for the organization","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"permission":{"type":"string"}},"type":"object"}}}},"404":{"description":"not_found | finding_not_found","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"409":{"description":"idempotency_mismatch | generation_conflict | illegal_transition | target_changed | claim_lost","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"410":{"description":"approval_expired","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"422":{"description":"action_unavailable","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"429":{"description":"capacity (active run limit) or the per-identity request quota","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"502":{"description":"the backend answered outside the documented vocabulary","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"disabled | unavailable (retryable)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Approve a run that is awaiting approval. `generation` and `scope_digest` must be the values of the run you reviewed: if the run or its target scope changed since, the approval is refused (generation_conflict or target_changed) and nothing runs. The actor is the authenticated caller. Requires cloudsec.respond. Body: at most 4 KiB, exactly {generation, scope_digest}. Rate limit: 60 requests per minute per authenticated identity.","summary":"Approve Code Security Remediation","x-required-permissions":{"all_of":["cloudsec.respond"]}}},"/cloudsec/{oid}/remediations/{run_id}/cancel":{"post":{"operationId":"postCloudSecRemediationCancel","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"run_id","required":true,"description":"the remediation run id (rem_ followed by 32 lowercase hex)","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"decision","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"generation":{"type":"integer"}},"required":["generation"],"type":"object"}}},"required":true},"responses":{"200":{"description":"the run after the decision","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"result":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"missing_permission: the caller is authorized for the organization but does not hold cloudsec.respond (cloudsec.set does not imply it); or cloud security is not enabled for the organization","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"permission":{"type":"string"}},"type":"object"}}}},"404":{"description":"not_found | finding_not_found","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"409":{"description":"idempotency_mismatch | generation_conflict | illegal_transition | target_changed | claim_lost","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"410":{"description":"approval_expired","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"422":{"description":"action_unavailable","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"429":{"description":"capacity (active run limit) or the per-identity request quota","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"502":{"description":"the backend answered outside the documented vocabulary","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"disabled | unavailable (retryable)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Cancel a run that has not finished. Works even when the remediation feature is disabled, so an operator can always stop work in flight. `generation` must be the value of the run you reviewed. The actor is the authenticated caller. Requires cloudsec.respond. Body: at most 4 KiB, exactly {generation}. Rate limit: 60 requests per minute per authenticated identity.","summary":"Cancel Code Security Remediation","x-required-permissions":{"all_of":["cloudsec.respond"]}}},"/cloudsec/{oid}/remediations/{run_id}/reject":{"post":{"operationId":"postCloudSecRemediationReject","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"run_id","required":true,"description":"the remediation run id (rem_ followed by 32 lowercase hex)","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"decision","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"generation":{"type":"integer"}},"required":["generation"],"type":"object"}}},"required":true},"responses":{"200":{"description":"the run after the decision","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"result":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"missing_permission: the caller is authorized for the organization but does not hold cloudsec.respond (cloudsec.set does not imply it); or cloud security is not enabled for the organization","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"permission":{"type":"string"}},"type":"object"}}}},"404":{"description":"not_found | finding_not_found","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"409":{"description":"idempotency_mismatch | generation_conflict | illegal_transition | target_changed | claim_lost","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"410":{"description":"approval_expired","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"422":{"description":"action_unavailable","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"429":{"description":"capacity (active run limit) or the per-identity request quota","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"502":{"description":"the backend answered outside the documented vocabulary","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"disabled | unavailable (retryable)","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Reject a run that is awaiting approval. `generation` must be the value of the run you reviewed. The actor is the authenticated caller. Requires cloudsec.respond. Body: at most 4 KiB, exactly {generation}. Rate limit: 60 requests per minute per authenticated identity.","summary":"Reject Code Security Remediation","x-required-permissions":{"all_of":["cloudsec.respond"]}}},"/cloudsec/{oid}/resolve/assets":{"get":{"operationId":"resolveCloudAssetsToSensors","tags":["Cloud Security"],"parameters":[{"name":"urn","description":"cloud asset URN(s) to resolve; repeat the parameter for a bulk request","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"resolved":{"items":{"type":"object"},"type":"array"}},"required":["resolved"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Resolve cloud asset URNs to the LimaCharlie sensor ids running on each. Pass one or more 'urn' query parameters (bulk). Unresolved URNs are returned in 'unresolved'.","summary":"Resolve Cloud Assets to Sensors","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/resolve/sensors":{"get":{"operationId":"resolveCloudSensorsToAssets","tags":["Cloud Security"],"parameters":[{"name":"sid","description":"sensor id(s) to resolve; repeat the parameter for a bulk request","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"resolved":{"items":{"type":"object"},"type":"array"}},"required":["resolved"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Resolve LimaCharlie sensor ids to the cloud asset (URN, with posture flags) each runs on. Pass one or more 'sid' query parameters (bulk). Unresolved sensors are returned in 'unresolved'.","summary":"Resolve Sensors to Cloud Assets","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/resource":{"get":{"operationId":"getCloudSecResource","tags":["Cloud Security"],"parameters":[{"name":"urn","required":true,"description":"the canonical lcrn of the resource to fetch","schema":{"minLength":1,"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"resource":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the single canonical record for any urn the system-of-record or security graph knows — { urn, resource_type, name, account, region, is_public, is_sensitive, props, first_seen }. Covers derived graph nodes (vulnerabilities, identities) that have no inventory row. Powers the resource drawer / urn click-through. Returns a null resource when the urn is unknown.","summary":"Get Cloud Security Resource","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/risk-trend":{"get":{"operationId":"getCloudSecRiskTrend","tags":["Cloud Security"],"parameters":[{"name":"trend_days","description":"number of days of score trend to include (default 30)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"trend":{"items":{"type":"object"},"type":"array"}},"required":["trend"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the organization's risk-score history over time (the Overview score-trend sparkline), oldest first.","summary":"Get Cloud Security Risk Trend","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/scan-status":{"get":{"operationId":"getCloudSecScanStatus","tags":["Cloud Security"],"parameters":[{"name":"provider","description":"the cloud provider to read status for (gcp|aws|azure); defaults to gcp","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"properties":{"status":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the cloud-collection run status for the organization — whether a sweep is in progress, when it last started/completed, the last diff stats, and any error. Optional 'provider' query parameter (default 'gcp').","summary":"Get Cloud Security Scan Status","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/simulate/findings":{"post":{"operationId":"simulateCloudSecFindingMatch","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the suppression matcher to simulate","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"match":{"type":"object"},"sample_limit":{"type":"number"}},"required":["match"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"evaluated":{"type":"number"},"matched":{"type":"number"},"sample":{"items":{"type":"object"},"type":"array"},"truncated":{"type":"boolean"}},"required":["evaluated","matched"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Evaluate a suppression-policy matcher (finding_class / rule / account globs / urn_prefix / max_severity) against the organization's OPEN findings, using the exact matching semantics the suppression engine applies. Returns evaluated/matched counts, a bounded sample of the findings the rule would disposition, and truncated=true when the walk hit its size/time bound. Read-only preview: nothing is dispositioned.","summary":"Simulate Cloud Security Finding Matchers","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/simulate/resources":{"post":{"operationId":"simulateCloudSecResourceMatch","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the matcher config to simulate","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"resource_types":{"items":{"type":"string"},"type":"array"},"rules":{"items":{"type":"object"},"type":"array"},"sample_limit":{"type":"number"},"surface":{"type":"string"},"target":{"type":"string"}},"required":["rules"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"evaluated":{"type":"number"},"indeterminate":{"type":"number"},"indeterminate_sample":{"items":{"type":"object"},"type":"array"},"matched":{"type":"number"},"sample":{"items":{"type":"object"},"type":"array"},"truncated":{"type":"boolean"}},"required":["evaluated","matched"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Evaluate a set of cloudsec_policy resource matcher rules against the organization's stored inventory. First-party authoring clients send surface so the preview validates the same capability and token vocabulary as policy persistence; target scopes the resource family walked. Returns evaluated/matched/indeterminate counts, a bounded sample of matching resources, and truncated=true when the walk hit its size/time bound. Read-only preview: nothing is saved.","summary":"Simulate Cloud Security Resource Matchers","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/cloudsec/{oid}/topology":{"get":{"operationId":"getCloudSecTopology","tags":["Cloud Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"available":{"type":"boolean"},"edges":{"items":{"type":"object"},"type":"array"},"generated_at":{"type":"integer"},"scopes":{"items":{"type":"object"},"type":"array"}},"required":["available","scopes","edges","generated_at"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Pre-aggregated estate topology: per-scope node counts and inter-scope relationship rollups, O(#scopes) response independent of resource count. available:false means the projector has not yet materialized this org — callers should fall back to the inventory walk.","summary":"Get Cloud Security Topology","x-required-permissions":{"all_of":["cloudsec.get"]}}},"/domain/{domain}/auth":{"get":{"operationId":"getDomainAuthRequirements","tags":["Billing"],"parameters":[{"name":"domain","required":true,"description":"email domain","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"anyOf":[{"additionalProperties":false,"description":"Empty object: the domain has no configured authentication requirements","type":"object"},{"additionalProperties":false,"properties":{"auth_ui":{"additionalProperties":false,"description":"Login-UI offering for the domain. Present only when the domain offers SSO. UI-only: enforcement is expressed via requirements.methods.","properties":{"sso_provider_id":{"type":"string"}},"required":["sso_provider_id"],"type":"object"},"is_partner_managed":{"description":"Whether the domain is linked to a Partner: standalone org creation is refused.","type":"boolean"},"is_unified_billing":{"description":"Whether the domain's unified-billing perks apply to the caller. False once the domain is linked to a Partner.","type":"boolean"},"requirements":{"additionalProperties":false,"properties":{"max_session_seconds":{"type":"integer"},"methods":{"anyOf":[{"type":"null"},{"items":{"type":"string"},"type":"array"}]},"mfa":{"anyOf":[{"type":"null"},{"items":{"type":"string"},"type":"array"}]},"mfa_reset_email":{"type":"string"},"new_account_mfa_grace_seconds":{"type":"integer"}},"required":["methods","mfa"],"type":"object"}},"required":["requirements","is_unified_billing","is_partner_managed"],"type":"object"}]}}}}},"description":"Get authentication requirements (MFA, sign-in methods) for a domain. This is a public endpoint used during login.","summary":"Get Domain Auth Requirements"}},"/errors/{oid}":{"get":{"operationId":"getErrorLog","tags":["Errors"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"errors":{"items":{"additionalProperties":false,"properties":{"component":{"type":"string"},"error":{"type":"string"},"oid":{"type":"string"},"ts":{"type":"number"}},"required":["component","error","oid","ts"],"type":"object"},"type":"array"}},"required":["errors"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the error log for the organization.","summary":"Get Error Logs","x-required-permissions":{"all_of":["audit.get"]}}},"/errors/{oid}/{component}":{"delete":{"operationId":"dismissError","tags":["Errors"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"component","required":true,"description":"Component name of the error to dismiss","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Dismiss a specific error for the organization.","summary":"Dismiss Error","x-required-permissions":{"all_of":["audit.get"]}}},"/events":{"get":{"operationId":"getAvailableEvents","tags":["General"],"parameters":[],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"events":{"items":{"type":"string"},"type":"array"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get available event names.","summary":"Get Possible Events"}},"/export/{oid}/sensors":{"post":{"operationId":"exportSensorList","tags":["Exports","Sensors"],"parameters":[{"name":"format","description":"format of the exported data, one of 'json' or 'csv'","schema":{"enum":["json","csv"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"sensors":{"oneOf":[{"items":{"additionalProperties":false,"properties":{"alive":{"description":"timestamp of last alive check","pattern":"^\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2}:\\d{2}$","title":"alive check","type":"string"},"app_control":{"additionalProperties":false,"properties":{"counters":{"additionalProperties":false,"description":"cumulative since the sensor started","properties":{"n_denied":{"type":"integer"},"n_evaluated":{"type":"integer"},"n_installed":{"description":"files written by a trusted installer that may run; absent when the policy names no installer","title":"installed files","type":"integer"},"n_lost":{"type":"integer"},"n_resident":{"description":"running processes the policy denied when it was installed (on_enable report or terminate); absent when on_enable is leave","title":"resident denials","type":"integer"},"n_terminated":{"description":"resident processes terminated (on_enable terminate in enforcing mode); absent when on_enable is leave","title":"terminated","type":"integer"},"n_unresolved":{"type":"integer"}},"title":"counters","type":"object"},"degraded":{"description":"bitmask of the reasons enforcement is not whole: 0x01 no policy, 0x02 stale, 0x04 hash unavailable, 0x08 not enforced, 0x10 enforcement point skew, 0x20 enforcement point has no key, 0x40 lease lapsed, 0x80 on_enable ignored, 0x100 sensor identities not applied, 0x200 policy refused","title":"degraded","type":"integer"},"enforced":{"additionalProperties":false,"description":"what the enforcement point reports; absent when none answered","properties":{"break_glass":{"description":"whether the break-glass is pulled","title":"break glass","type":"boolean"},"generation":{"description":"generation the enforcement point holds","title":"generation","type":"integer"},"is_connected":{"description":"whether anyone is there to answer the enforcement point","title":"connected","type":"boolean"},"mode":{"description":"mode the enforcement point is armed in","title":"mode","type":"integer"},"n_overloaded":{"description":"executions allowed without being judged because the host could not keep up","title":"overloaded","type":"integer"},"n_rules":{"description":"rules the enforcement point holds; absent when it does not evaluate rules","title":"rule count","type":"integer"}},"title":"enforcement point","type":"object"},"generation":{"description":"generation (issue time, epoch seconds) of the policy the sensor holds, 0 for none","title":"generation","type":"integer"},"label":{"description":"name of the policy record the sensor holds","title":"policy label","type":"string"},"mode":{"description":"enforcement mode: 0 off, 1 permissive, 2 permissive-sync, 3 enforcing","title":"mode","type":"integer"},"refused":{"additionalProperties":false,"description":"the policy the sensor declined, when it declined one","properties":{"generation":{"description":"generation of the declined policy","title":"generation","type":"integer"},"reason":{"description":"refusal reason: 21 invalid, 22 foreign, 23 expired, 24 unknown key, 25 refused, 26 not newer, 27 rolled back, 28 clock skew","title":"reason","type":"integer"},"ts":{"description":"when the sensor declined it, epoch seconds","title":"timestamp","type":"integer"}},"title":"refused policy","type":"object"},"reported_at":{"description":"when the posture was last published, epoch seconds","title":"reported at","type":"integer"},"stance":{"description":"policy stance: 0 blocklist, 1 allowlist","title":"stance","type":"integer"}},"type":"object"},"arch":{"description":"architecture of host running the sensor","title":"architecture","type":"integer"},"did":{"oneOf":[{"description":"UUID of the device","format":"uuid","title":"device identifier","type":"string"},{"enum":[""]}]},"enroll":{"description":"timestamp of sensor enrollment","pattern":"^\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2}:\\d{2}$","title":"enrollment timestamp","type":"string"},"ext_ip":{"oneOf":[{"description":"external IP of the host running the sensor","format":"ipv4","title":"external IP","type":"string"},{"enum":["internal",""]}]},"ext_plat":{"description":"external platform of the sensor","title":"external platform","type":"integer"},"hostname":{"description":"hostname of the host running the sensor","title":"hostname","type":"string"},"iid":{"description":"installation key identifier","title":"installation key identifier","type":"string"},"installer_version":{"description":"version of the installer","title":"installer version","type":"string"},"int_ip":{"description":"internal IP of the host running the sensor","title":"internal IP","type":"string"},"is_del":{"description":"is the sensor deleted","title":"deleted status","type":"boolean"},"is_isolated":{"description":"isolation status of the sensor","title":"isolation status","type":"boolean"},"is_kernel_available":{"description":"is kernel available to the sensor","title":"kernel availability","type":"boolean"},"is_online":{"description":"is sensor online at the moment","title":"online status","type":"boolean"},"mac_addr":{"description":"MAC address of the host running the sensor","title":"MAC address","type":"string"},"metadata":{"oneOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}]},"oid":{"description":"UUID of the organization","format":"uuid","title":"organization identifier","type":"string"},"plat":{"description":"platform type of the host running the sensor","title":"platform","type":"integer"},"sealed":{"description":"seal status of the sensor","title":"seal status","type":"boolean"},"should_isolate":{"description":"isolation intent of the sensor","title":"isolation intent","type":"boolean"},"should_seal":{"description":"seal intent of the sensor","title":"seal intent","type":"boolean"},"sid":{"description":"UUID of the sensor","format":"uuid","title":"sensor identifier","type":"string"},"tags":{"oneOf":[{"items":{"description":"sensors tag","title":"tag","type":"string"},"type":"array"},{"type":"null"}]},"version":{"description":"version of the sensor","title":"sensor version","type":"string"}},"required":["sid","alive","arch","did","enroll","ext_ip","ext_plat","hostname","int_ip","is_isolated","is_kernel_available","mac_addr","oid","plat","sealed","should_isolate","should_seal"],"type":"object"},"type":"array"},{"type":"object"},{"description":"CSV-formatted sensor list when format=csv","type":"string"}]}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Export the full sensor list (info and tags) for the Organization.","summary":"Export Sensors","x-required-permissions":{"all_of":["sensor.get","sensor.list"]}}},"/extension/definition":{"get":{"operationId":"getAllExtension","tags":["Extensions"],"parameters":[],"responses":{"200":{"description":"All public and owned extension","content":{"application/json":{"schema":{"anyOf":[{"type":"null"},{"items":{"additionalProperties":false,"properties":{"cost":{"additionalProperties":false,"properties":{"minimum_sensor_count":{"type":"integer"},"per_metric":{"additionalProperties":false,"properties":{"cost":{"type":"number"},"metric_name":{"type":"string"},"unit":{"type":"number"}},"required":["metric_name","cost","unit"],"type":"object"},"per_month":{"type":"number"},"per_sensor":{"type":"number"}},"required":["per_month","per_sensor","minimum_sensor_count"],"type":"object"},"desc":{"type":"string"},"destination_url":{"type":"string"},"email":{"type":"string"},"flairs":{"type":"array"},"icon":{"type":"string"},"is_labs":{"type":"boolean"},"is_public":{"type":"boolean"},"label":{"type":"string"},"long_desc":{"type":"string"},"name":{"type":"string"},"perms":{"type":"array"},"required_extensions":{"oneOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}]},"shared_secret":{"type":"string"},"unsubscribe_warning":{"type":"string"},"website":{"type":"string"},"zero_state_desc":{"type":"string"},"zero_state_header":{"type":"string"}},"required":["name","desc","long_desc","email","website","label","zero_state_header","zero_state_desc","required_extensions","perms","flairs","cost","icon","is_public","is_labs"],"type":"object"},"type":"array"}]}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get all public and owned extensions","summary":"Get all public and owned extensions"},"post":{"operationId":"createExtension","tags":["Extensions"],"parameters":[],"requestBody":{"description":"Extension to create","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"cost":{"additionalProperties":false,"properties":{"minimum_sensor_count":{"type":"integer"},"per_metric":{"additionalProperties":false,"properties":{"cost":{"type":"integer"},"metric_name":{"type":"string"},"unit":{"type":"integer"}},"type":"object"},"per_month":{"type":"integer"},"per_sensor":{"type":"integer"}},"type":"object"},"desc":{"type":"string"},"destination_url":{"type":"string"},"flairs":{"items":{"type":"string"},"type":"array"},"icon":{"type":"string"},"is_labs":{"description":"Ignored: user-created extensions are never labs extensions","type":"boolean"},"is_public":{"description":"Ignored: user-created extensions are always private","type":"boolean"},"key_name":{"description":"Managed server-side","type":"string"},"label":{"type":"string"},"long_desc":{"type":"string"},"name":{"type":"string"},"owner":{"description":"Managed server-side","type":"string"},"perms":{"items":{"description":"Permission name, e.g. sensor.get","type":"string"},"type":"array"},"required_extensions":{"items":{"type":"string"},"type":"array"},"shared_secret":{"type":"string"},"stripe_plan":{"type":"string"},"unsubscribe_warning":{"type":"string"},"website":{"type":"string"},"zero_state_desc":{"type":"string"},"zero_state_header":{"type":"string"}},"required":["name","destination_url","shared_secret","desc","perms"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Create an extension","summary":"Create an extension"},"put":{"operationId":"updateExtension","tags":["Extensions"],"parameters":[],"requestBody":{"description":"Extension fields to update all fields required as this is not a patch","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"cost":{"additionalProperties":false,"properties":{"minimum_sensor_count":{"type":"integer"},"per_metric":{"additionalProperties":false,"properties":{"cost":{"type":"integer"},"metric_name":{"type":"string"},"unit":{"type":"integer"}},"type":"object"},"per_month":{"type":"integer"},"per_sensor":{"type":"integer"}},"type":"object"},"desc":{"type":"string"},"destination_url":{"type":"string"},"flairs":{"items":{"type":"string"},"type":"array"},"icon":{"type":"string"},"is_labs":{"description":"Ignored: user-created extensions are never labs extensions","type":"boolean"},"is_public":{"description":"Ignored: user-created extensions are always private","type":"boolean"},"key_name":{"description":"Managed server-side","type":"string"},"label":{"type":"string"},"long_desc":{"type":"string"},"name":{"type":"string"},"owner":{"description":"Managed server-side","type":"string"},"perms":{"items":{"description":"Permission name, e.g. sensor.get","type":"string"},"type":"array"},"required_extensions":{"items":{"type":"string"},"type":"array"},"shared_secret":{"type":"string"},"stripe_plan":{"type":"string"},"unsubscribe_warning":{"type":"string"},"website":{"type":"string"},"zero_state_desc":{"type":"string"},"zero_state_header":{"type":"string"}},"required":["name","destination_url","shared_secret","desc","perms"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Update an existing Extension","summary":"Update an existing Extension"}},"/extension/definition/{extensionName}":{"delete":{"operationId":"deleteExtension","tags":["Extensions"],"parameters":[{"name":"extensionName","required":true,"description":"extension name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Delete an Extension","summary":"Delete an existing Extension"},"get":{"operationId":"getExtension","tags":["Extensions"],"parameters":[{"name":"oid","description":"organization id","schema":{"format":"uuid","type":"string"},"in":"query"},{"name":"extensionName","required":true,"description":"extension name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"A extension","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"cost":{"additionalProperties":false,"properties":{"minimum_sensor_count":{"type":"integer"},"per_metric":{"additionalProperties":false,"properties":{"cost":{"type":"number"},"metric_name":{"type":"string"},"unit":{"type":"number"}},"required":["metric_name","cost","unit"],"type":"object"},"per_month":{"type":"number"},"per_sensor":{"type":"number"}},"required":["per_month","per_sensor","minimum_sensor_count"],"type":"object"},"desc":{"type":"string"},"email":{"type":"string"},"flairs":{"type":"array"},"icon":{"type":"string"},"is_labs":{"type":"boolean"},"is_public":{"type":"boolean"},"label":{"type":"string"},"long_desc":{"type":"string"},"name":{"type":"string"},"perms":{"type":"array"},"required_extensions":{"oneOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}]},"unsubscribe_warning":{"type":"string"},"website":{"type":"string"},"zero_state_desc":{"type":"string"},"zero_state_header":{"type":"string"}},"required":["name","desc","long_desc","email","website","label","zero_state_header","zero_state_desc","required_extensions","perms","flairs","cost","icon","is_public","is_labs"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get extension by extension name, extension must be public or owned by caller","summary":"Get extension by extension name, extension must be public or owned by caller","x-required-permissions":{"any_of":["ext.request","ext.conf.get"]}}},"/extension/public/definition":{"get":{"operationId":"getPublicExtensions","tags":["Extensions"],"parameters":[],"responses":{"200":{"description":"An array of Extensions","content":{"application/json":{"schema":{"items":{"additionalProperties":false,"properties":{"cost":{"additionalProperties":false,"properties":{"minimum_sensor_count":{"type":"integer"},"per_metric":{"additionalProperties":false,"properties":{"cost":{"type":"number"},"metric_name":{"type":"string"},"unit":{"type":"number"}},"required":["metric_name","cost","unit"],"type":"object"},"per_month":{"type":"number"},"per_sensor":{"type":"number"}},"required":["per_month","per_sensor","minimum_sensor_count"],"type":"object"},"desc":{"type":"string"},"email":{"type":"string"},"flairs":{"type":"array"},"icon":{"type":"string"},"is_labs":{"type":"boolean"},"is_public":{"type":"boolean"},"label":{"type":"string"},"long_desc":{"type":"string"},"name":{"type":"string"},"perms":{"type":"array"},"required_extensions":{"oneOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}]},"unsubscribe_warning":{"type":"string"},"website":{"type":"string"},"zero_state_desc":{"type":"string"},"zero_state_header":{"type":"string"}},"required":["name","desc","long_desc","email","website","label","zero_state_header","zero_state_desc","required_extensions","perms","flairs","cost","icon","is_public","is_labs"],"type":"object"},"type":"array"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get all public extensions - no auth required","summary":"Get all public extensions - no auth required"}},"/extension/request/{extensionName}":{"post":{"operationId":"createExtensionRequest","tags":["Extensions"],"parameters":[{"name":"data","description":"data","schema":{"type":"string"},"in":"query"},{"name":"gzdata","description":"data","schema":{"type":"string"},"in":"query"},{"name":"oid","description":"organization id","schema":{"format":"uuid","type":"string"},"in":"query"},{"name":"action","description":"action","schema":{"type":"string"},"in":"query"},{"name":"inv_id","description":"invitation id","schema":{"type":"string"},"in":"query"},{"name":"extensionName","required":true,"description":"extension name","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"JSON encoded string of the request data","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"action":{"type":"string"},"data":{"type":"string"},"gzdata":{"description":"base64(gzip(JSON)) alternative to data for payloads larger than the 10MB form limit","type":"string"},"impersonator_jwt":{"description":"optional JWT of an impersonating identity; the request is attributed to that identity instead of the caller","type":"string"},"inv_id":{"description":"optional investigation id to attribute the request to","type":"string"},"oid":{"format":"uuid","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"anyOf":[{"type":"null"},{"additionalProperties":true,"description":"Response payload produced by the extension; the shape is defined by the extension's response schema (see /extension/schema/{extensionName}) and is not under LimaCharlie's control","type":"object"}]},"error":{"description":"Only present when the extension reported an error","type":"string"}},"required":["data"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Create extension request to extension you are subscribed to","summary":"Create extension request","x-required-permissions":{"all_of":["ext.request"]}}},"/extension/schema/{extensionName}":{"get":{"operationId":"getExtensionSchema","tags":["Extensions"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"type":"string"},"in":"query"},{"name":"extensionName","required":true,"description":"extension name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"A extension","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"config_schema":{"additionalProperties":false,"properties":{"fields":{"oneOf":[{"type":"null"},{"additionalProperties":{"additionalProperties":false,"properties":{"data_type":{"type":"string"},"default_value":{"oneOf":[{"type":"boolean"},{"type":"string"}]},"description":{"type":"string"},"display_index":{"type":"integer"},"filter":{"additionalProperties":false,"properties":{},"type":"object"},"filters":{"items":{"additionalProperties":false,"properties":{},"type":"object"},"type":"array"},"is_list":{"type":"boolean"},"label":{"type":"string"},"object":{"additionalProperties":false,"properties":{"element_desc":{"type":"string"},"element_name":{"type":"string"},"fields":{"additionalProperties":{"additionalProperties":false,"properties":{"data_type":{"type":"string"},"default_value":{"oneOf":[{"type":"boolean"},{"type":"string"}]},"description":{"type":"string"},"display_index":{"type":"integer"},"enum_values":{"items":{"type":"object"},"type":"array"},"filter":{"additionalProperties":false,"properties":{},"type":"object"},"filters":{"items":{"type":"object"},"type":"array"},"is_list":{"type":"boolean"},"key":{"additionalProperties":false,"properties":{},"type":"object"},"label":{"type":"string"},"object":{"type":"object"},"placeholder":{"type":"string"},"requirements":{"items":{"items":{"type":"string"},"type":"array"},"type":"array"}},"type":"object"},"type":"object"},"key":{"additionalProperties":false,"properties":{"data_type":{"type":"string"},"name":{"type":"string"},"placeholder":{"type":"string"}},"type":"object"},"requirements":{"items":{"items":{"type":"string"},"type":"array"},"type":"array"},"supported_actions":{"items":{"type":"string"},"type":"array"}},"type":"object"},"placeholder":{"type":"string"},"supported_actions":{"items":{"type":"string"},"type":"array"}},"type":"object"},"type":"object"}]},"key":{"additionalProperties":false,"properties":{},"type":"object"},"requirements":{"oneOf":[{"type":"null"},{"items":{"items":{"type":"string"},"type":"array"},"type":"array"}]},"supported_actions":{"items":{"type":"string"},"type":"array"}},"type":"object"},"request_schema":{"additionalProperties":{"additionalProperties":false,"properties":{"is_default":{"type":"boolean"},"is_impersonated":{"type":"boolean"},"is_user_facing":{"type":"boolean"},"label":{"type":"string"},"long_description":{"type":"string"},"messages":{"additionalProperties":true,"type":"object"},"parameters":{"additionalProperties":{"additionalProperties":false,"properties":{"credentials":{"type":"string"},"data":{"additionalProperties":true,"type":"object"},"data_type":{"type":"string"},"default_value":{"type":"object"},"display_index":{"type":"integer"},"enum_values":{"items":{"type":"object"},"type":"array"},"is_interactive":{"type":"boolean"},"is_list":{"type":"boolean"},"name":{"type":"string"}},"type":"object"},"properties":{"fields":{"anyOf":[{"type":"null"},{"additionalProperties":true,"type":"object"}]},"requirements":{"anyOf":[{"type":"null"},{"items":{"items":{"type":"string"},"type":"array"},"type":"array"},{"additionalProperties":true,"type":"object"}]}},"type":"object"},"response":{"anyOf":[{"type":"null"},{"additionalProperties":true,"type":"object"}]},"short_description":{"type":"string"}},"type":"object"},"type":"object"},"required_events":{"items":{"type":"string"},"type":"array"},"views":{"items":{"additionalProperties":false,"properties":{"default_requests":{"items":{"type":"string"},"type":"array"},"layout_type":{"type":"string"},"name":{"type":"string"}},"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get extension schema by extension name","summary":"Get extension schema","x-required-permissions":{"all_of":["ext.request","ext.conf.set"]}}},"/feedback":{"post":{"operationId":"submitFeedback","parameters":[],"requestBody":{"description":"feedback payload","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"category":{"type":"string"},"details":{"type":"string"},"oid":{"type":"string"},"source":{"type":"string"},"summary":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Receive a generic JSON feedback object from a user and relay it to the LimaCharlie customer-feedback Slack channel.","summary":"Submit user feedback"}},"/groups":{"get":{"operationId":"getUserOrgGroups","tags":["Organizations","Groups"],"parameters":[],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"groups":{"items":{"type":"object"},"type":"array"}},"type":"object"},"examples":{"basic":{"value":{"groups":[{"name":"test","orgs":{"test":["test@test.com"]},"owner":"test@test.com"}]}}}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get groups the current user is owner of.","summary":"Get user groups"},"post":{"operationId":"createGroup","tags":["Organizations","Groups"],"parameters":[{"name":"name","required":true,"description":"name of the new group","schema":{"type":"string"},"in":"query"},{"name":"pid","description":"optional Partner id to create the group under (requires the partner.group.create partner permission; the group becomes partner-owned and may only contain orgs of the same Partner)","schema":{"format":"uuid","type":"string"},"in":"query"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"gid":{"description":"ID of the newly created group","format":"uuid","type":"string"}},"required":["gid"],"type":"object"},"success":{"type":"boolean"}},"required":["data","success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Create new organization group.","summary":"Create group"}},"/groups/concurrent":{"get":{"operationId":"getUserOrgGroupsConcurrent","tags":["Groups"],"parameters":[],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"groups":{"items":{"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Gets all group info objects a user is owner of. ","summary":"Get all owned group info"}},"/groups/{gid}":{"delete":{"operationId":"deleteGroup","tags":["Organizations","Groups"],"parameters":[{"name":"gid","required":true,"description":"group id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"},"success":{"type":"boolean"}},"required":["data","success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Delete group.","summary":"Delete group"},"get":{"operationId":"getGroup","tags":["Groups"],"parameters":[{"name":"gid","required":true,"description":"group id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"group":{"additionalProperties":false,"properties":{"group_id":{"type":"string"},"members":{"items":{"description":"Member user email","type":"string"},"type":"array"},"name":{"type":"string"},"orgs":{"items":{"additionalProperties":false,"properties":{"org_id":{"format":"uuid","type":"string"},"org_name":{"type":"string"}},"required":["org_id","org_name"],"type":"object"},"type":"array"},"owners":{"items":{"description":"Owner user email","type":"string"},"type":"array"},"perms":{"items":{"description":"Permission name, e.g. org.get","type":"string"},"type":"array"}},"required":["group_id","name","owners","members","orgs","perms"],"type":"object"}},"required":["group"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get group information.","summary":"Get group info"}},"/groups/{gid}/logs":{"get":{"operationId":"getGroupLogs","tags":["Groups"],"parameters":[{"name":"limit","description":"optional number of log lines to return","schema":{"default":"1000","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"gid","required":true,"description":"group id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"logs":{"items":{"additionalProperties":false,"properties":{"code":{"type":"string"},"email":{"type":"string"},"message":{"type":"string"},"timestamp":{"type":"integer"},"uid":{"type":"string"}},"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get group logs.","summary":"Get group logs"}},"/groups/{gid}/orgs":{"delete":{"operationId":"removeGroupMemberOrg","tags":["Organizations","Groups"],"parameters":[{"name":"oid","required":true,"description":"oid of the org to remove","schema":{"type":"string"},"in":"query"},{"name":"gid","required":true,"description":"group id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"},"success":{"type":"boolean"}},"required":["data","success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove organization from group.","summary":"Remove org from group"},"post":{"operationId":"addGroupMemberOrg","tags":["Groups"],"parameters":[{"name":"oid","description":"oid of the org to add","schema":{"type":"string"},"in":"query"},{"name":"gid","required":true,"description":"group id","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"request object","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"oid":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"},"success":{"type":"boolean"}},"required":["data","success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Add organization to group.","summary":"Add org to group","x-required-permissions":{"all_of":["user.ctrl"]}}},"/groups/{gid}/owners":{"delete":{"operationId":"removeGroupOwnerUser","tags":["Organizations","Groups"],"parameters":[{"name":"member_email","required":true,"description":"email of the user to remove","schema":{"type":"string"},"in":"query"},{"name":"gid","required":true,"description":"group id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"},"success":{"type":"boolean"}},"required":["data","success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove user from group owners.","summary":"Remove user from group owners"},"post":{"operationId":"addGroupOwnerUser","tags":["Groups"],"parameters":[{"name":"member_email","required":true,"description":"email of the user to add","schema":{"type":"string"},"in":"query"},{"name":"invite_missing","description":"if set to 'true' and the user does not exist, send them an invite email instead of failing","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"gid","required":true,"description":"group id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"invite_sent":{"description":"Only present when the user did not exist and invite_missing was set: an invite email was sent instead of adding the user","type":"boolean"},"success":{"description":"Present when the user was added as owner","type":"boolean"}},"type":"object"},"success":{"type":"boolean"}},"required":["data","success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Add user to group as owner.","summary":"Add user to group as owner"}},"/groups/{gid}/permissions":{"post":{"operationId":"setGroupPermissions","tags":["Groups"],"parameters":[{"name":"perm","required":true,"description":"full set of permissions for the group, repeated field","schema":{"type":"string"},"in":"query"},{"name":"gid","required":true,"description":"group id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"},"success":{"type":"boolean"}},"required":["data","success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Set group permissions.","summary":"Set group permissions"}},"/groups/{gid}/users":{"delete":{"operationId":"removeGroupMemberUser","tags":["Organizations","Groups"],"parameters":[{"name":"member_email","required":true,"description":"email of the user to remove","schema":{"type":"string"},"in":"query"},{"name":"gid","required":true,"description":"group id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"},"success":{"type":"boolean"}},"required":["data","success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove user from group as member.","summary":"Remove user from group as member"},"post":{"operationId":"addGroupMemberUser","tags":["Groups"],"parameters":[{"name":"member_email","required":true,"description":"email of the user to add","schema":{"type":"string"},"in":"query"},{"name":"invite_missing","description":"if set to 'true' and the user does not exist, send them an invite email instead of failing","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"gid","required":true,"description":"group id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"invite_sent":{"description":"Only present when the user did not exist and invite_missing was set: an invite email was sent instead of adding the user","type":"boolean"}},"type":"object"},"success":{"type":"boolean"}},"required":["data","success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Add user to group as member.","summary":"Add user to group as member"}},"/hive/{hive_name}/schema":{"get":{"operationId":"getHiveSchema","tags":["Hive"],"parameters":[{"name":"hive_name","required":true,"description":"type of hive record","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"schema":{"additionalProperties":true,"description":"JSON Schema describing the hive's record type","type":"object"}},"required":["schema"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the JSON Schema for a hive's record type.","summary":"Get Hive Schema"}},"/hive/{hive_name}/{oid}":{"get":{"operationId":"listHiveRecord","tags":["Hive"],"parameters":[{"name":"hive_name","required":true,"description":"type of hive record","schema":{"type":"string"},"in":"path"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":{"additionalProperties":false,"properties":{"data":{"oneOf":[{"additionalProperties":true,"description":"Record data, structure depends on hive type","type":"object"},{"type":"null"}]},"detection":{"type":"string"},"isDraft":{"type":"boolean"},"name":{"type":"string"},"sys_mtd":{"additionalProperties":false,"properties":{"created_at":{"type":"integer"},"created_by":{"oneOf":[{"type":"string"},{"type":"null"}]},"etag":{"type":"string"},"guid":{"oneOf":[{"type":"string"},{"type":"null"}]},"last_author":{"oneOf":[{"type":"string"},{"type":"null"}]},"last_error":{"oneOf":[{"type":"string"},{"type":"null"}]},"last_error_ts":{"oneOf":[{"type":"integer"},{"type":"null"}]},"last_mod":{"type":"integer"}},"required":["created_at","last_mod"],"type":"object"},"usr_mtd":{"additionalProperties":false,"properties":{"comment":{"type":"string"},"enabled":{"type":"boolean"},"expiry":{"oneOf":[{"type":"integer"},{"type":"null"}]},"tags":{"oneOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}]},"ui_actions":{"oneOf":[{"items":{"additionalProperties":false,"properties":{"label":{"type":"string"},"location":{"type":"string"}},"required":["label","location"],"type":"object"},"type":"array"},{"type":"null"}]}},"required":["comment","enabled"],"type":"object"}},"required":["data","sys_mtd","usr_mtd"],"type":"object"},"description":"Map of record names to HiveRecord objects","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List hive records.","summary":"List Hive Records"}},"/hive/{hive_name}/{oid}/{record_name}":{"delete":{"operationId":"deleteHiveRecord","tags":["Hive"],"parameters":[{"name":"hive_name","required":true,"description":"type of hive record","schema":{"type":"string"},"in":"path"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"record_name","required":true,"description":"record name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Delete the hive record.","summary":"Delete Hive Record"}},"/hive/{hive_name}/{oid}/{record_name}/data":{"get":{"operationId":"getHiveRecord","tags":["Hive"],"parameters":[{"name":"hive_name","required":true,"description":"type of hive record","schema":{"type":"string"},"in":"path"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"record_name","required":true,"description":"record name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"oneOf":[{"additionalProperties":true,"description":"Record data, structure depends on hive type","type":"object"},{"type":"null"}]},"detection":{"type":"string"},"isDraft":{"type":"boolean"},"name":{"type":"string"},"sys_mtd":{"additionalProperties":false,"properties":{"created_at":{"type":"integer"},"created_by":{"oneOf":[{"type":"string"},{"type":"null"}]},"etag":{"type":"string"},"guid":{"oneOf":[{"type":"string"},{"type":"null"}]},"last_author":{"oneOf":[{"type":"string"},{"type":"null"}]},"last_error":{"oneOf":[{"type":"string"},{"type":"null"}]},"last_error_ts":{"oneOf":[{"type":"integer"},{"type":"null"}]},"last_mod":{"type":"integer"}},"required":["created_at","last_mod"],"type":"object"},"usr_mtd":{"additionalProperties":false,"properties":{"comment":{"type":"string"},"enabled":{"type":"boolean"},"expiry":{"oneOf":[{"type":"integer"},{"type":"null"}]},"tags":{"oneOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}]},"ui_actions":{"oneOf":[{"items":{"additionalProperties":false,"properties":{"label":{"type":"string"},"location":{"type":"string"}},"required":["label","location"],"type":"object"},"type":"array"},{"type":"null"}]}},"required":["comment","enabled"],"type":"object"}},"required":["data","sys_mtd","usr_mtd"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the hive record data.","summary":"Get Hive Record"},"post":{"operationId":"setHiveRecord","tags":["Hive"],"parameters":[{"name":"etag","description":"the etag to use to conditionally set the record","schema":{"type":"string"},"in":"query"},{"name":"arl","description":"the ARL to use to set the record","schema":{"type":"string"},"in":"query"},{"name":"data","description":"the data to set","schema":{"type":"string"},"in":"query"},{"name":"hive_name","required":true,"description":"type of hive record","schema":{"type":"string"},"in":"path"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"record_name","required":true,"description":"record name","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"request object","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"data":{"description":"JSON encoded string of the record data","title":"data","type":"string"},"gzdata":{"description":"base64(gzip(JSON)) alternative to data for payloads larger than the 10MB form limit","title":"gzdata","type":"string"},"usr_mtd":{"description":"JSON encoded string of the record metadata","title":"usr_mtd","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"guid":{"description":"Globally unique ID of the record","type":"string"},"hive":{"additionalProperties":false,"properties":{"name":{"type":"string"},"partition":{"type":"string"}},"required":["name","partition"],"type":"object"},"name":{"type":"string"}},"required":["hive","name","guid"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Set the hive record data.","summary":"Set Hive Record"}},"/hive/{hive_name}/{oid}/{record_name}/mtd":{"get":{"operationId":"getHiveRecordMetadata","tags":["Hive"],"parameters":[{"name":"hive_name","required":true,"description":"type of hive record","schema":{"type":"string"},"in":"path"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"record_name","required":true,"description":"record name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"oneOf":[{"additionalProperties":true,"description":"Record data, structure depends on hive type","type":"object"},{"type":"null"}]},"detection":{"type":"string"},"isDraft":{"type":"boolean"},"name":{"type":"string"},"sys_mtd":{"additionalProperties":false,"properties":{"created_at":{"type":"integer"},"created_by":{"oneOf":[{"type":"string"},{"type":"null"}]},"etag":{"type":"string"},"guid":{"oneOf":[{"type":"string"},{"type":"null"}]},"last_author":{"oneOf":[{"type":"string"},{"type":"null"}]},"last_error":{"oneOf":[{"type":"string"},{"type":"null"}]},"last_error_ts":{"oneOf":[{"type":"integer"},{"type":"null"}]},"last_mod":{"type":"integer"}},"required":["created_at","last_mod"],"type":"object"},"usr_mtd":{"additionalProperties":false,"properties":{"comment":{"type":"string"},"enabled":{"type":"boolean"},"expiry":{"oneOf":[{"type":"integer"},{"type":"null"}]},"tags":{"oneOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}]},"ui_actions":{"oneOf":[{"items":{"additionalProperties":false,"properties":{"label":{"type":"string"},"location":{"type":"string"}},"required":["label","location"],"type":"object"},"type":"array"},{"type":"null"}]}},"required":["comment","enabled"],"type":"object"}},"required":["data","sys_mtd","usr_mtd"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the hive record metadata.","summary":"Get Hive Record Metadata"},"post":{"operationId":"setHiveRecordMetadata","tags":["Hive"],"parameters":[{"name":"usr_mtd","description":"the metadata to set","schema":{"type":"string"},"in":"query"},{"name":"etag","description":"the etag to use to conditionally set the metadata","schema":{"type":"string"},"in":"query"},{"name":"hive_name","required":true,"description":"type of hive record","schema":{"type":"string"},"in":"path"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"record_name","required":true,"description":"record name","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"request object","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"usr_mtd":{"description":"JSON encoded string of the record metadata","title":"usr_mtd","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"guid":{"description":"Globally unique ID of the record","type":"string"},"hive":{"additionalProperties":false,"properties":{"name":{"type":"string"},"partition":{"type":"string"}},"required":["name","partition"],"type":"object"},"name":{"type":"string"}},"required":["hive","name","guid"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Set the hive record metadata.","summary":"Set Hive Record Metadata"}},"/hive/{hive_name}/{oid}/{record_name}/rename":{"post":{"operationId":"renameHiveRecord","tags":["Hive"],"parameters":[{"name":"new_name","description":"new name of record","schema":{"type":"string"},"in":"query"},{"name":"hive_name","required":true,"description":"type of hive record","schema":{"type":"string"},"in":"path"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"record_name","required":true,"description":"record name","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"request object","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"new_name":{"description":"new name of record","title":"new_name","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"guid":{"description":"Globally unique ID of the record","type":"string"},"hive":{"additionalProperties":false,"properties":{"name":{"type":"string"},"partition":{"type":"string"}},"required":["name","partition"],"type":"object"},"name":{"type":"string"}},"required":["hive","name","guid"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Rename a hive record","summary":"Rename Hive Record"}},"/hive/{hive_name}/{oid}/{record_name}/validate":{"post":{"operationId":"validateHiveRecord","tags":["Hive"],"parameters":[{"name":"etag","description":"the etag to use to conditionally validate the record","schema":{"type":"string"},"in":"query"},{"name":"arl","description":"the ARL to use to validate the record","schema":{"type":"string"},"in":"query"},{"name":"data","description":"the data to validate","schema":{"type":"string"},"in":"query"},{"name":"hive_name","required":true,"description":"type of hive record","schema":{"type":"string"},"in":"path"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"record_name","required":true,"description":"record name","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"request object","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"data":{"description":"JSON encoded string of the record data","title":"data","type":"string"},"gzdata":{"description":"base64(gzip(JSON)) alternative to data for payloads larger than the 10MB form limit","title":"gzdata","type":"string"},"usr_mtd":{"description":"JSON encoded string of the record metadata","title":"usr_mtd","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Validate hive record data without storing it.","summary":"Validate Hive Record"}},"/hostnames/{oid}":{"get":{"operationId":"findSensorByHostname","tags":["Sensors"],"parameters":[{"name":"hostname","description":"hostname prefix to search for","schema":{"type":"string"},"in":"query"},{"name":"as_dict","description":"a boolean string (like 'true') indicating to return the records in a dictionary instead of the legacy list format","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"List of sensors matching the hostname","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"sid":{"anyOf":[{"items":{"items":false,"prefixItems":[{"format":"uuid","type":"string"},{"type":"string"}],"type":"array"},"type":"array"},{"items":{"additionalProperties":false,"properties":{"hostname":{"type":"string"},"sid":{"format":"uuid","type":"string"}},"type":"object"},"type":"array"}]}},"required":["sid"],"type":"object"},"examples":{"dict":{"value":{"sid":[{"hostname":"hostname1","sid":"a1b2c3d4-1234-5678-9abc-1234567890ab"},{"hostname":"hostname2","sid":"b2c3d4e5-2345-6789-abcd-234567890abc"}]}},"tuple":{"value":{"sid":[["a1b2c3d4-1234-5678-9abc-1234567890ab","hostname1"],["b2c3d4e5-2345-6789-abcd-234567890abc","hostname2"]]}}}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get sensors with hostnames matching given expression.","summary":"Get Sensors by Hostname","x-required-permissions":{"all_of":["sensor.list"]}}},"/insight/event_count/{oid}/{sid}":{"get":{"operationId":"getEventRetainedCount","tags":["Retention"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"is_detailed","description":"set to 'true' to get a per-hour breakdown of the event count","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"from_cache":{"type":"boolean"},"records":{"items":{"additionalProperties":false,"properties":{"Date":{"description":"Hour bucket timestamp (YYYY-MM-DD HH:00:00, UTC)","type":"string"},"Total":{"anyOf":[{"description":"Event count for the hour bucket","type":"integer"},{"type":"null"}]}},"type":"object"},"type":"array"},"total":{"anyOf":[{"description":"Total number of events retained over the window","type":"integer"},{"type":"null"}]}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve historical data from the sensor using Insight.","summary":"Get Historical Events","x-required-permissions":{"all_of":["insight.stat"]}}},"/insight/{oid}":{"get":{"operationId":"getInsightStatus","tags":["Retention"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"insight_bucket":{"type":"string"},"insight_dataset":{"type":"string"}},"required":["insight_bucket","insight_dataset"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Check if the organization is configured with Insight.","summary":"Get Retention Status","x-required-permissions":{"all_of":["insight.list"]}}},"/insight/{oid}/artifacts":{"get":{"operationId":"getArtifactList","tags":["Retention","Artifacts"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"cursor","description":"optional cursor for paginated access, set to '-' for first query","schema":{"type":"string"},"in":"query"},{"name":"hint","description":"optional hint for the type of artifact to query for","schema":{"type":"string"},"in":"query"},{"name":"source","description":"optional source (sensor or adapter ID) to filter the artifacts by","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"logs":{"items":{"additionalProperties":false,"properties":{"error":{"type":"string"},"expires":{"type":"integer"},"is_indexed":{"type":"boolean"},"path":{"type":"string"},"payload_id":{"type":"string"},"size":{"type":"integer"},"source":{"type":"string"},"ts":{"type":"integer"},"type":{"type":"string"}},"type":"object"},"type":"array"},"next_cursor":{"oneOf":[{"type":"string"},{"type":"null"}]}},"required":["logs"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the list of artifacts available during a time frame.","summary":"Get Artifact List","x-required-permissions":{"any_of":["insight.evt.get","insight.evt.get.simple"]}}},"/insight/{oid}/artifacts/originals/{artifact_id}":{"get":{"operationId":"getOriginalArtifact","tags":["Retention","Artifacts"],"parameters":[{"name":"is_compressed","description":"set to 'true' to enable compression, data returned 'events' is base64(gzip(data))","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"dest_bucket","description":"destination bucket for the artifact","schema":{"type":"string"},"in":"query"},{"name":"svc_creds","description":"service credentials for the destination bucket","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"artifact_id","required":true,"description":"artifact id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"expires":{"type":"integer"},"export":{"type":"string"},"export_id":{"type":"string"},"id":{"type":"string"},"oid":{"format":"uuid","type":"string"},"path":{"type":"string"},"payload":{"type":"string"},"records":{"additionalProperties":{"type":"string"},"type":"object"},"region":{"type":"string"},"size":{"type":"integer"},"source":{"type":"string"},"ts":{"type":"integer"},"type":{"type":"string"},"was_billed":{"type":"boolean"}},"required":["expires","export","export_id","id","oid","path","region","size","source","ts","type","was_billed"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"The content is restricted by an acl: scope tag the caller does not hold","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"description":"ACL_CONTENT_RESTRICTED","type":"string"}},"type":"object"}}}}},"description":"Retrieve the original version of a specific artifact.","summary":"Get Original Artifact","x-required-permissions":{"any_of":["insight.evt.get","insight.evt.get.simple"]}}},"/insight/{oid}/artifacts/payloads/{payload_id}":{"get":{"operationId":"getReadableArtifact","tags":["Retention","Artifacts"],"parameters":[{"name":"records","description":"the record IDs to retrieve specifically, repeated field","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"is_compressed","description":"set to 'true' to enable compression, data returned 'logs' is base64(gzip(data))","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"with_raw","description":"set to 'true' to include raw data in the response","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"payload_id","required":true,"description":"payload/log id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"logs":{"oneOf":[{"description":"Parsed log data. When is_compressed is 'true', this is base64(gzip(data))","type":"string"},{"additionalProperties":{"additionalProperties":false,"properties":{"export":{"type":"string"},"export_id":{"type":"string"},"id":{"type":"string"},"oid":{"format":"uuid","type":"string"},"path":{"type":"string"},"records":{"additionalProperties":{"type":"string"},"type":"object"},"requested_by":{"type":"string"},"size":{"type":"integer"},"source":{"type":"string"},"ts":{"type":"integer"},"type":{"type":"string"}},"required":["id","oid","path","size","source","ts","type"],"type":"object"},"description":"Parsed log data as an object with record IDs as keys","type":"object"}]}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"The content is restricted by an acl: scope tag the caller does not hold","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"description":"ACL_CONTENT_RESTRICTED","type":"string"}},"type":"object"}}}}},"description":"Retrieve the parsed/readable version of a specific artifact.","summary":"Get Readable Artifact","x-required-permissions":{"all_of":["insight.list"]}}},"/insight/{oid}/audit":{"get":{"operationId":"getAuditEvents","tags":["Retention"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"limit","description":"maximum number of audit events to return","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"event_type","description":"specific audit event type to fetch","schema":{"type":"string"},"in":"query"},{"name":"is_compressed","description":"set to 'true' to enable compression, data returned 'events' is base64(gzip(data))","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"cursor","description":"optional cursor for paginated access, set to '-' for first query","schema":{"type":"string"},"in":"query"},{"name":"is_forward","description":"direction of paginated query results, defaults to 'true' (ascending).","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"output_name","description":"send data to a named output instead","schema":{"type":"string"},"in":"query"},{"name":"sid","description":"only return events relating to a specific sensor id","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"events":{"oneOf":[{"description":"Compressed events data (base64(gzip(data))) when is_compressed is 'true'","type":"string"},{"description":"Uncompressed events array when is_compressed is not set or 'false'","items":{"additionalProperties":false,"properties":{"entity":{"additionalProperties":false,"properties":{"hive_name":{"type":"string"},"hive_partititon":{"type":"string"},"hive_record_name":{"type":"string"},"output_name":{"type":"string"},"sid":{"type":"string"},"stream":{"type":"string"}},"type":"object"},"etype":{"type":"string"},"ident":{"type":"string"},"msg":{"type":"string"},"mtd":{"additionalProperties":false,"properties":{"module":{"type":"string"},"n_billed":{"type":"integer"},"n_free":{"type":"integer"},"stream":{"type":"string"},"task":{"type":"string"}},"type":"object"},"oid":{"format":"uuid","type":"string"},"origin":{"type":"string"},"time":{"type":"integer"},"ts":{"type":"string"}},"required":["etype","msg","oid","origin","time","ts"],"type":"object"},"type":"array"}]},"next_cursor":{"type":"string"}},"required":["events"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve retained LimaCharlie audit logs using Insight.","summary":"Get Audit Events","x-required-permissions":{"all_of":["audit.get"]}}},"/insight/{oid}/detections":{"get":{"operationId":"getDetections","tags":["Retention"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"limit","description":"maximum number of detections to return","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"cat","description":"specific detection category to fetch","schema":{"type":"string"},"in":"query"},{"name":"is_compressed","description":"set to 'true' to enable compression, data returned 'detects' is base64(gzip(data))","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"cursor","description":"optional cursor for paginated access, set to '-' for first query","schema":{"type":"string"},"in":"query"},{"name":"is_forward","description":"direction of paginated query results, defaults to 'true' (ascending).","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"sid","description":"only return detections relating to a specific sensor id","schema":{"type":"string"},"in":"query"},{"name":"output_name","description":"send data to a named output instead","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"detects":{"oneOf":[{"description":"Compressed detections data (base64(gzip(data))) when is_compressed is 'true'","type":"string"},{"description":"Uncompressed detections array when is_compressed is not set or 'false'","items":{"additionalProperties":false,"properties":{"author":{"type":"string"},"cat":{"type":"string"},"detect":{"additionalProperties":false,"description":"SensorEvent or wrapped detection containing the event","properties":{"Event":{"additionalProperties":true,"description":"Alternative event data format","type":"object"},"author":{"type":"string"},"cat":{"type":"string"},"detect":{"additionalProperties":true,"description":"Nested SensorEvent in wrapped detection format","type":"object"},"detect_data":{"additionalProperties":true,"type":"object"},"detect_id":{"type":"string"},"detect_mtd":{"additionalProperties":true,"type":"object"},"event":{"additionalProperties":true,"description":"Event data, structure varies by event type","type":"object"},"gen_time":{"type":"integer"},"link":{"type":"string"},"mtd":{"additionalProperties":true,"type":"object"},"priority":{"type":"integer"},"routing":{"additionalProperties":false,"description":"Routing information for the event","properties":{"arch":{"oneOf":[{"type":"string"},{"type":"number"}]},"did":{"type":"string"},"event_id":{"type":"string"},"event_time":{"type":"integer"},"event_type":{"type":"string"},"ext_ip":{"type":"string"},"hostname":{"type":"string"},"iid":{"type":"string"},"int_ip":{"type":"string"},"investigation_id":{"type":"string"},"latency":{"type":"integer"},"link":{"type":"string"},"log_id":{"type":"string"},"log_type":{"type":"string"},"moduleid":{"type":"integer"},"oid":{"format":"uuid","type":"string"},"parent":{"type":"string"},"plat":{"oneOf":[{"type":"string"},{"type":"number"}]},"sid":{"format":"uuid","type":"string"},"tags":{"items":{"type":"string"},"type":"array"},"target":{"type":"string"},"this":{"type":"string"}},"required":["event_time","event_type","oid"],"type":"object"},"rule_tags":{"items":{"type":"string"},"type":"array"},"source":{"type":"string"},"source_rule":{"type":"string"}},"type":"object"},"detect_data":{"additionalProperties":true,"type":"object"},"detect_id":{"type":"string"},"detect_mtd":{"additionalProperties":true,"type":"object"},"gen_time":{"type":"integer"},"link":{"type":"string"},"mtd":{"additionalProperties":true,"type":"object"},"namespace":{"type":"string"},"priority":{"type":"integer"},"routing":{"additionalProperties":false,"description":"Routing information (duplicate of detect.routing)","properties":{"arch":{"oneOf":[{"type":"string"},{"type":"number"}]},"did":{"type":"string"},"event_id":{"type":"string"},"event_time":{"type":"integer"},"event_type":{"type":"string"},"ext_ip":{"type":"string"},"hostname":{"type":"string"},"iid":{"type":"string"},"int_ip":{"type":"string"},"investigation_id":{"type":"string"},"latency":{"type":"integer"},"link":{"type":"string"},"log_id":{"type":"string"},"log_type":{"type":"string"},"moduleid":{"type":"integer"},"oid":{"format":"uuid","type":"string"},"parent":{"type":"string"},"plat":{"oneOf":[{"type":"string"},{"type":"number"}]},"sid":{"format":"uuid","type":"string"},"tags":{"items":{"type":"string"},"type":"array"},"target":{"type":"string"},"this":{"type":"string"}},"required":["event_time","event_type","oid"],"type":"object"},"rule_tags":{"items":{"type":"string"},"type":"array"},"source":{"type":"string"},"source_rule":{"type":"string"},"ts":{"type":"integer"}},"type":"object"},"type":"array"}]},"from_cache":{"type":"boolean"},"next_cursor":{"type":"string"},"prev_cursor":{"type":"string"}},"required":["detects"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"The content is restricted by an acl: scope tag the caller does not hold","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"description":"ACL_CONTENT_RESTRICTED","type":"string"}},"type":"object"}}}}},"description":"Retrieve historical detections using Insight.","summary":"Get Detections","x-required-permissions":{"all_of":["insight.det.get"]}}},"/insight/{oid}/detections/breakdown":{"get":{"operationId":"getDetectionBreakdown","tags":["Retention"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"breakdown":{"additionalProperties":{"type":"integer"},"description":"Map of detection categories to counts","type":"object"}},"required":["breakdown"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve detection type information using Insight.","summary":"Get Detections Breakdown","x-required-permissions":{"all_of":["insight.stat"]}}},"/insight/{oid}/detections/stats":{"get":{"operationId":"getDetectionStats","tags":["Retention"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"per","description":"optional time period to group by, one of: hour, day, week, month","schema":{"type":"string"},"in":"query"},{"name":"sid","description":"optional sensor ID to filter by","schema":{"format":"uuid","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"totals":{"anyOf":[{"additionalProperties":{"type":"integer"},"description":"Flat stats: map of timestamps to detection counts","type":"object"},{"additionalProperties":{"additionalProperties":{"type":"integer"},"type":"object"},"description":"Categorized stats: map of category names to timestamp-based stats","type":"object"}]}},"required":["totals"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve detection stats information using Insight.","summary":"Get Detection Stats","x-required-permissions":{"all_of":["insight.stat"]}}},"/insight/{oid}/detections/{atom}":{"get":{"operationId":"getDetectByDetectID","tags":["Retention"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"atom","required":true,"description":"event atom id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"event":{"additionalProperties":false,"description":"Detection event object","properties":{"author":{"type":"string"},"cat":{"type":"string"},"detect":{"additionalProperties":false,"description":"SensorEvent or wrapped detection containing the event","properties":{"Event":{"additionalProperties":true,"description":"Alternative event data format","type":"object"},"author":{"type":"string"},"cat":{"type":"string"},"detect":{"additionalProperties":true,"description":"Nested SensorEvent in wrapped detection format","type":"object"},"detect_data":{"additionalProperties":true,"type":"object"},"detect_id":{"type":"string"},"detect_mtd":{"additionalProperties":true,"type":"object"},"event":{"additionalProperties":true,"description":"Event data, structure varies by event type","type":"object"},"gen_time":{"type":"integer"},"link":{"type":"string"},"mtd":{"additionalProperties":true,"type":"object"},"priority":{"type":"integer"},"routing":{"additionalProperties":false,"description":"Routing information for the event","properties":{"arch":{"oneOf":[{"type":"string"},{"type":"number"}]},"did":{"type":"string"},"event_id":{"type":"string"},"event_time":{"type":"integer"},"event_type":{"type":"string"},"ext_ip":{"type":"string"},"hostname":{"type":"string"},"iid":{"type":"string"},"int_ip":{"type":"string"},"investigation_id":{"type":"string"},"latency":{"type":"integer"},"link":{"type":"string"},"log_id":{"type":"string"},"log_type":{"type":"string"},"moduleid":{"type":"integer"},"oid":{"format":"uuid","type":"string"},"parent":{"type":"string"},"plat":{"oneOf":[{"type":"string"},{"type":"number"}]},"sid":{"format":"uuid","type":"string"},"tags":{"items":{"type":"string"},"type":"array"},"target":{"type":"string"},"this":{"type":"string"}},"required":["event_time","event_type","oid","sid","this"],"type":"object"},"rule_tags":{"items":{"type":"string"},"type":"array"},"source":{"type":"string"},"source_rule":{"type":"string"}},"type":"object"},"detect_data":{"additionalProperties":true,"type":"object"},"detect_id":{"type":"string"},"detect_mtd":{"additionalProperties":true,"type":"object"},"gen_time":{"type":"integer"},"link":{"type":"string"},"mtd":{"additionalProperties":true,"type":"object"},"namespace":{"type":"string"},"priority":{"type":"integer"},"routing":{"additionalProperties":false,"description":"Routing information (duplicate of detect.routing)","properties":{"arch":{"oneOf":[{"type":"string"},{"type":"number"}]},"did":{"type":"string"},"event_id":{"type":"string"},"event_time":{"type":"integer"},"event_type":{"type":"string"},"ext_ip":{"type":"string"},"hostname":{"type":"string"},"iid":{"type":"string"},"int_ip":{"type":"string"},"investigation_id":{"type":"string"},"latency":{"type":"integer"},"link":{"type":"string"},"log_id":{"type":"string"},"log_type":{"type":"string"},"moduleid":{"type":"integer"},"oid":{"format":"uuid","type":"string"},"parent":{"type":"string"},"plat":{"oneOf":[{"type":"string"},{"type":"number"}]},"sid":{"format":"uuid","type":"string"},"tags":{"items":{"type":"string"},"type":"array"},"target":{"type":"string"},"this":{"type":"string"}},"required":["event_time","event_type","oid"],"type":"object"},"rule_tags":{"items":{"type":"string"},"type":"array"},"source":{"type":"string"},"source_rule":{"type":"string"},"ts":{"type":"integer"}},"required":["author","cat","detect","detect_id","namespace","source","source_rule","ts"],"type":"object"}},"required":["event"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve a specific detection by detect_id from Insight.","summary":"Get Detect by DetectID","x-required-permissions":{"all_of":["insight.det.get"]}}},"/insight/{oid}/ingestion_keys":{"delete":{"operationId":"removeIngestionKey","tags":["Retention"],"parameters":[{"name":"name","description":"name of the ingestion key to remove","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"request for the removal of ingestion key","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"name":{"description":"name of the ingestion key to remove","title":"name","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove an ingestion key.","summary":"Remove Ingestion Key","x-required-permissions":{"all_of":["ingestkey.ctrl"]}},"get":{"operationId":"getIngestionKeys","tags":["Retention"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"keys":{"additionalProperties":{"type":"string"},"type":"object"}},"required":["keys"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the ingestion keys.","summary":"Get Ingestion Keys","x-required-permissions":{"all_of":["ingestkey.ctrl"]}},"post":{"operationId":"addIngestionKey","tags":["Retention"],"parameters":[{"name":"name","description":"name of the ingestion key to create","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"request for the new ingestion key","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"name":{"description":"name of the ingestion key to create","title":"name","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"key":{"description":"The server-generated ingestion key value","type":"string"},"name":{"type":"string"}},"required":["name","key"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Create a new ingestion key.","summary":"Add Ingestion Key","x-required-permissions":{"all_of":["ingestkey.ctrl"]}}},"/insight/{oid}/metrics":{"post":{"operationId":"getEntityMetrics","tags":["Retention"],"parameters":[{"name":"start","description":"optional Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"optional Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"entity_type","description":"the type of entity to query for","schema":{"type":"string"},"in":"query"},{"name":"entity_id","description":"the unique ID of the entity to query","schema":{"type":"string"},"in":"query"},{"name":"metric_name","description":"the name of the metric to query","schema":{"type":"string"},"in":"query"},{"name":"bucket_seconds","description":"optional bucket size in seconds to aggregate the metric values by","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"entities":{"items":{"additionalProperties":false,"properties":{"entity":{"additionalProperties":false,"properties":{"entity_id":{"type":"string"},"entity_type":{"type":"string"},"metric_name":{"type":"string"},"oid":{"format":"uuid","type":"string"}},"required":["oid","entity_type","entity_id","metric_name"],"type":"object"},"metrics":{"items":{"additionalProperties":false,"properties":{"metric":{"type":"integer"},"ts":{"description":"Bucket-aligned unix timestamp in seconds","type":"integer"}},"required":["ts","metric"],"type":"object"},"type":"array"}},"required":["entity","metrics"],"type":"object"},"type":"array"}},"required":["entities"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve a history of metrics for entities.","summary":"Get Entity Metrics","x-required-permissions":{"all_of":["insight.stat"]}}},"/insight/{oid}/object_usage/{objType}":{"get":{"operationId":"getObjectSummary","tags":["Retention"],"parameters":[{"name":"name","required":true,"description":"name of the object to look for","schema":{"type":"string"},"in":"query"},{"name":"case_sensitive","description":"set to 'false' to disable case sensitivity","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"is_compressed","description":"set to 'true' to enable compression, data returned 'events' is base64(gzip(data))","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"objType","required":true,"description":"type of object, one of: user, email, domain, ip, file_hash, file_path, file_name, service_name, package_name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"from_cache":{"type":"boolean"},"logs":{"anyOf":[{"additionalProperties":{"type":"integer"},"description":"Map of external log ID to unix timestamp (seconds) of first sighting","type":"object"},{"description":"base64(gzip(JSON)) of the map when is_compressed=true","type":"string"}]},"usage":{"anyOf":[{"additionalProperties":{"type":"integer"},"description":"Map of sensor ID to unix timestamp (seconds) of first sighting","type":"object"},{"description":"base64(gzip(JSON)) of the map when is_compressed=true","type":"string"}]}},"required":["usage","logs"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve summarized usage for a specific object / indicator using Insight.","summary":"Get Object Summary","x-required-permissions":{"any_of":["insight.evt.get","insight.evt.get.simple"]}}},"/insight/{oid}/objects":{"post":{"operationId":"getSpecificObjects","tags":["Retention"],"parameters":[{"name":"objects","description":"a JSON dictionary like: {objType: [objName1, objName2, ...]}","schema":{"type":"string"},"in":"query"},{"name":"case_sensitive","description":"set to 'false' to disable case sensitivity","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"info","description":"the type of information to receive, one of: summary, locations (default: summary)","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"per-indicator location cap when info=locations (default 100, max 1000)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"with_wildcards","description":"set to 'true' to treat each object name as a BigQuery LIKE pattern (e.g. '10.10.%'). Only valid when info=locations.","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"anyOf":[{"additionalProperties":false,"description":"Batch summary response (info=summary)","patternProperties":{"^last_[0-9]+_days$":{"additionalProperties":{"additionalProperties":{"description":"Number of hits for the object name in the time bucket","type":"integer"},"description":"Map of object name to hit count","type":"object"},"description":"Map of object type to per-name hit counts","type":"object"}},"properties":{"from_cache":{"type":"boolean"}},"type":"object"},{"additionalProperties":{"additionalProperties":{"additionalProperties":false,"properties":{"locations":{"items":{"additionalProperties":false,"properties":{"first_ts":{"type":"integer"},"hostname":{"type":"string"},"last_ts":{"type":"integer"},"sid":{"format":"uuid","type":"string"}},"required":["sid","hostname","first_ts","last_ts"],"type":"object"},"type":"array"},"summary":{"additionalProperties":false,"properties":{"last_1_days":{"type":"integer"},"last_30_days":{"type":"integer"},"last_365_days":{"type":"integer"},"last_7_days":{"type":"integer"}},"required":["last_1_days","last_7_days","last_30_days","last_365_days"],"type":"object"}},"required":["summary","locations"],"type":"object"},"description":"Map of indicator (as supplied by the caller) to its summary and locations","type":"object"},"description":"Batch locations response (info=locations): map of object type to indicators","properties":{"errors":{"additionalProperties":{"type":"string"},"description":"Only present when some object types failed: map of object type to error message","type":"object"}},"type":"object"}]}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve historical information about specific objects / indicators using Insight.","summary":"Get Specific Objects","x-required-permissions":{"any_of":["insight.evt.get","insight.evt.get.simple"]}}},"/insight/{oid}/objects-details":{"get":{"operationId":"getSpecificObjectsFmtOutput","tags":["Retention"],"parameters":[{"name":"types","required":true,"description":"type of object, one of: user, email, domain, ip, file_hash, file_path, file_name, service_name, package_name","schema":{"type":"string"},"in":"query"},{"name":"name","required":true,"description":"name of the object to look for","schema":{"type":"string"},"in":"query"},{"name":"time_range","description":"a comma seperated list of ranges to search through, list must have 4 elements EX: 1,7,30,90","schema":{"type":"string"},"in":"query"},{"name":"info","description":"ignored: this endpoint always returns the summary form; kept for backwards compatibility","schema":{"type":"string"},"in":"query"},{"name":"with_wildcards","description":"set to 'true' to be able to use '%' wildcards in the object name","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"case_sensitive","description":"set to 'false' to disable case sensitivity","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"per_object","description":"set to 'true' to get results per object","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":{"additionalProperties":false,"description":"Hit counts per time bucket for the object type","patternProperties":{"^last_[0-9]+_days$":{"anyOf":[{"description":"Number of hits in the time bucket","type":"integer"},{"additionalProperties":{"type":"integer"},"description":"Number of hits per object value (when per_object=true)","type":"object"}]}},"type":"object"},"properties":{"from_cache":{"type":"boolean"},"name":{"type":"string"}},"required":["name"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve historical information about specific objects / indicators using Insight.","summary":"Get Objects summarized by list of types","x-required-permissions":{"any_of":["insight.evt.get","insight.evt.get.simple"]}}},"/insight/{oid}/objects/{objType}":{"get":{"operationId":"getObjectInformation","tags":["Retention"],"parameters":[{"name":"name","required":true,"description":"name of the object to look for","schema":{"type":"string"},"in":"query"},{"name":"info","required":true,"description":"the type of information to receive, one of: summary, locations","schema":{"type":"string"},"in":"query"},{"name":"case_sensitive","description":"set to 'false' to disable case sensitivity","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"with_wildcards","description":"set to 'true' to be able to use '%' wildcards in the object name","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"per_object","description":"set to 'true' to return one entry per object","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"limit","description":"maximum number of results to return","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"objType","required":true,"description":"type of object, one of: user, email, domain, ip, file_hash, file_path, file_name, service_name, package_name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"anyOf":[{"additionalProperties":false,"description":"Summary response (info=summary)","properties":{"from_cache":{"type":"boolean"},"last_1_days":{"anyOf":[{"description":"Number of hits in the time bucket","type":"integer"},{"additionalProperties":{"type":"integer"},"description":"Number of hits per object value (when per_object=true)","type":"object"}]},"last_30_days":{"anyOf":[{"description":"Number of hits in the time bucket","type":"integer"},{"additionalProperties":{"type":"integer"},"description":"Number of hits per object value (when per_object=true)","type":"object"}]},"last_365_days":{"anyOf":[{"description":"Number of hits in the time bucket","type":"integer"},{"additionalProperties":{"type":"integer"},"description":"Number of hits per object value (when per_object=true)","type":"object"}]},"last_7_days":{"anyOf":[{"description":"Number of hits in the time bucket","type":"integer"},{"additionalProperties":{"type":"integer"},"description":"Number of hits per object value (when per_object=true)","type":"object"}]},"name":{"type":"string"},"type":{"type":"string"}},"required":["type","name","last_1_days","last_7_days","last_30_days","last_365_days"],"type":"object"},{"additionalProperties":{"anyOf":[{"additionalProperties":false,"description":"Sensor-origin location","properties":{"first_ts":{"type":"integer"},"hostname":{"anyOf":[{"type":"string"},{"type":"null"}]},"last_ts":{"type":"integer"},"obj":{"description":"Only present when per_object=true","type":"string"},"sid":{"format":"uuid","type":"string"}},"required":["sid","first_ts","last_ts"],"type":"object"},{"additionalProperties":false,"description":"External-log-origin location","properties":{"first":{"type":"integer"},"id":{"type":"string"},"last":{"type":"integer"},"obj":{"description":"Only present when per_object=true","type":"string"},"records":{"items":{"type":"integer"},"type":"array"},"source":{"type":"string"},"type":{"type":"string"}},"required":["source","type","id","records","first","last"],"type":"object"}]},"description":"Locations response (info=locations): map of location key to location entry; empty object when nothing matched","properties":{"from_cache":{"type":"boolean"},"name":{"description":"Only present when at least one location matched","type":"string"},"type":{"description":"Only present when at least one location matched","type":"string"}},"type":"object"}]}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve historical information about specific objects / indicators using Insight.","summary":"Get Object Information","x-required-permissions":{"any_of":["insight.evt.get","insight.evt.get.simple"]}}},"/insight/{oid}/online/stats":{"get":{"operationId":"getOnlineStats","tags":["Retention"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"totals":{"anyOf":[{"additionalProperties":{"type":"integer"},"description":"Flat stats: map of timestamps to online sensor counts","type":"object"},{"additionalProperties":{"additionalProperties":{"type":"integer"},"type":"object"},"description":"Categorized stats: map of category names to timestamp-based stats","type":"object"}]}},"required":["totals"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve stats on sensors online using Insight.","summary":"Get Online Stats","x-required-permissions":{"all_of":["insight.stat"]}}},"/insight/{oid}/traffic/breakdown":{"get":{"operationId":"getTrafficBreakdown","tags":["Retention"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"breakdown":{"additionalProperties":{"type":"integer"},"description":"Map of traffic categories to counts","type":"object"}},"required":["breakdown"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve traffic type information using Insight.","summary":"Get Traffic Breakdown","x-required-permissions":{"all_of":["insight.stat"]}}},"/insight/{oid}/traffic/stats":{"get":{"operationId":"getTrafficStats","tags":["Retention"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"sid","description":"only return events relating to a specific sensor id","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"totals":{"anyOf":[{"additionalProperties":{"type":"integer"},"description":"Flat stats: map of timestamps to traffic counts","type":"object"},{"additionalProperties":{"additionalProperties":{"type":"integer"},"type":"object"},"description":"Categorized stats: map of category names to timestamp-based stats","type":"object"}]}},"required":["totals"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve traffic stats information using Insight.","summary":"Get Traffic Stats","x-required-permissions":{"all_of":["insight.stat"]}}},"/insight/{oid}/{sid}":{"get":{"operationId":"getHistoricEvents","tags":["Retention"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"limit","description":"maximum number of events to return","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"event_type","description":"specific event type to fetch","schema":{"type":"string"},"in":"query"},{"name":"is_compressed","description":"set to 'true' to enable compression, data returned 'events' is base64(gzip(data))","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"cursor","description":"optional cursor for paginated access, set to '-' for first query","schema":{"type":"string"},"in":"query"},{"name":"is_forward","description":"direction of paginated query results, defaults to 'true' (ascending).","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"output_name","description":"send data to a named output instead","schema":{"type":"string"},"in":"query"},{"name":"epcon","description":"internal: when present, routes the query through the get_historical_events RPC (epcon testing)","schema":{"type":"string"},"in":"query"},{"name":"stream","description":"internal: stream name override, only used together with epcon","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"events":{"oneOf":[{"items":{"additionalProperties":true,"description":"Event data, structure varies by event type","type":"object"},"type":"array"},{"description":"Compressed events data (base64(gzip(data))) when is_compressed is 'true'","type":"string"}]},"from_cache":{"type":"boolean"},"next_cursor":{"description":"cursor for the next page","title":"cursor","type":"string"}},"required":["events","next_cursor"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"The content is restricted by an acl: scope tag the caller does not hold","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"description":"ACL_CONTENT_RESTRICTED","type":"string"}},"type":"object"}}}}},"description":"Retrieve historical data from the sensor using Insight.","summary":"Get Historical Events","x-required-permissions":{"any_of":["insight.evt.get","insight.evt.get.simple"]}}},"/insight/{oid}/{sid}/overview":{"get":{"operationId":"getHistoricEventOverview","tags":["Retention"],"parameters":[{"name":"start","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"from_cache":{"type":"boolean"},"overview":{"items":{"type":"number"},"type":"array"}},"required":["overview"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve overview data of the historical data from the sensor using Insight.","summary":"Get Historical Overview","x-required-permissions":{"any_of":["insight.evt.get","insight.evt.get.simple"]}}},"/insight/{oid}/{sid}/{atom}":{"get":{"operationId":"getEventByAtom","tags":["Retention"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"atom","required":true,"description":"event atom id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"event":{"additionalProperties":true,"description":"Event data, structure varies by event type","type":"object"},"from_cache":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"The content is restricted by an acl: scope tag the caller does not hold","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"description":"ACL_CONTENT_RESTRICTED","type":"string"}},"type":"object"}}}}},"description":"Retrieve a specific event by atom from Insight.","summary":"Get Event by Atom","x-required-permissions":{"any_of":["insight.evt.get","insight.evt.get.simple"]}}},"/insight/{oid}/{sid}/{atom}/children":{"get":{"operationId":"getChildrenOfAtom","tags":["Retention"],"parameters":[{"name":"is_compressed","description":"set to 'true' to enable compression, data returned 'events' is base64(gzip(data))","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"atom","required":true,"description":"event atom id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"events":{"oneOf":[{"description":"Compressed events data (base64(gzip(data))) when is_compressed is 'true'","type":"string"},{"description":"Uncompressed events array when is_compressed is not set or 'false'","items":{"type":"object"},"type":"array"}]},"from_cache":{"type":"boolean"},"stopped_all_terminated":{"type":"boolean"},"stopped_deadline":{"type":"boolean"},"stopped_rebooted":{"type":"boolean"},"too_many_events":{"type":"boolean"}},"required":["events"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"The content is restricted by an acl: scope tag the caller does not hold","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"description":"ACL_CONTENT_RESTRICTED","type":"string"}},"type":"object"}}}}},"description":"Retrieve all children of atom from Insight.","summary":"Get Children Of Atom","x-required-permissions":{"any_of":["insight.evt.get","insight.evt.get.simple"]}}},"/installationkeys/{oid}":{"delete":{"operationId":"removeInstallationKey","tags":["Installation Keys"],"parameters":[{"name":"iid","description":"installer id to delete","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Delete an installation key for the organization.","summary":"Remove Installation Key","x-required-permissions":{"all_of":["ikey.del"]}},"get":{"operationId":"getInstallationKeys","tags":["Installation Keys"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":{"additionalProperties":{"additionalProperties":false,"properties":{"created":{"anyOf":[{"type":"string"},{"type":"number"}]},"desc":{"type":"string"},"iid":{"type":"string"},"json_key":{"description":"JSON enrollment key used by browser extensions and adapters","type":"string"},"key":{"description":"Base64-encoded sensor bootstrap key","type":"string"},"oid":{"type":"string"},"quota_remaining":{"type":"integer"},"quota_total":{"type":"integer"},"tags":{"description":"Comma-separated list of tags applied to enrolling sensors","type":"string"},"use_public_root_ca":{"type":"boolean"}},"required":["oid","iid","key","json_key","created","desc","tags","use_public_root_ca"],"type":"object"},"type":"object"},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the installation keys for the organization.","summary":"Get Installation Keys","x-required-permissions":{"all_of":["ikey.list"]}},"post":{"operationId":"addInstallationKey","tags":["Installation Keys"],"parameters":[{"name":"tags","description":"tags to associate with sensors","schema":{"type":"string"},"in":"query"},{"name":"desc","description":"description of key","schema":{"type":"string"},"in":"query"},{"name":"use_public_root_ca","description":"whether to use the public root CA","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"quota","description":"quota for the installation key","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"iid","description":"installation id key, required for update.","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"iid":{"description":"ID of the created or updated installation key","format":"uuid","type":"string"},"oid":{"format":"uuid","type":"string"}},"required":["oid","iid"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Create a new installation key for the organization.","summary":"Add Installation Key","x-required-permissions":{"all_of":["ikey.set"]}}},"/installationkeys/{oid}/{iid}":{"get":{"operationId":"getInstallationKey","tags":["Installation Keys"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"iid","required":true,"description":"installation key id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"created":{"anyOf":[{"type":"string"},{"type":"number"}]},"desc":{"type":"string"},"iid":{"type":"string"},"json_key":{"description":"JSON enrollment key used by browser extensions and adapters","type":"string"},"key":{"description":"Base64-encoded sensor bootstrap key","type":"string"},"oid":{"type":"string"},"quota_remaining":{"type":"integer"},"quota_total":{"type":"integer"},"tags":{"description":"Comma-separated list of tags applied to enrolling sensors","type":"string"},"use_public_root_ca":{"type":"boolean"}},"required":["oid","iid","key","json_key","created","desc","tags","use_public_root_ca"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get a specific installation key from the organization.","summary":"Get Installation Key","x-required-permissions":{"all_of":["ikey.list"]}}},"/invite/user":{"post":{"operationId":"inviteUserToLC","tags":["Groups"],"parameters":[],"requestBody":{"description":"invite user request","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"user_email":{"allOf":[{"type":"string"},{"format":"email","type":"string"},{"pattern":"^[^@]+@[^@]+$","type":"string"}]}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"exists":{"description":"Only present when the user already had an account; no invite email is sent in that case","type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Invite user to limacharlie.io.","summary":"Invite user to limacharlie.io"}},"/job/{oid}":{"get":{"operationId":"getJobs","tags":["Jobs"],"parameters":[{"name":"start","description":"required timestamp in seconds where to begin fetching jobs","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"required timestamp in seconds where to stop fetching jobs","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"limit","description":"maximum number of jobs to return","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"sid","description":"optionally only fetch jobs relating to a Sensor ID","schema":{"type":"string"},"in":"query"},{"name":"is_compressed","description":"set to 'true' to enable compression, data returned is base64(gzip(data))","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"with_data","description":"optionally include full job data, 'true' or 'false'","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"jobs":{"oneOf":[{"additionalProperties":false,"type":"object"},{"description":"Compressed jobs data (base64(gzip(data))) when is_compressed is 'true'","type":"string"}]}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Retrieve jobs for an organization.","summary":"Get Jobs","x-required-permissions":{"all_of":["job.get"]}}},"/job/{oid}/{job_id}":{"delete":{"operationId":"removeJob","tags":["Jobs"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"job_id","required":true,"description":"job id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Delete a specific job.","summary":"Remove Job","x-required-permissions":{"all_of":["job.set"]}},"get":{"operationId":"getJobInfo","tags":["Jobs"],"parameters":[{"name":"is_compressed","description":"set to 'true' to enable compression, data returned is base64(gzip(data))","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"with_data","description":"optionally include full job data, 'true' or 'false'","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"job_id","required":true,"description":"job id","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"job":{"anyOf":[{"additionalProperties":false,"properties":{"cause":{"type":"string"},"created":{"type":"integer"},"job_id":{"type":"string"},"last_change":{"type":"integer"},"last_narration":{"type":"string"},"oid":{"type":"string"},"record":{"additionalProperties":true,"description":"Full job data, only present when with_data=true; the shape is defined by the Service that owns the job","type":"object"},"replicant":{"type":"string"},"sids":{"items":{"type":"string"},"type":"array"},"stopped":{"type":"integer"}},"type":"object"},{"description":"base64(gzip(JSON)) of the job when is_compressed=true","type":"string"}]}},"required":["job"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Fetch a specific job.","summary":"Get Job","x-required-permissions":{"all_of":["job.get"]}}},"/mailsec/{oid}/actions/bulk/execute":{"post":{"operationId":"executeMailsecBulkAction","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the confirmed bulk action","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"action":{"type":"string"},"attempt":{"type":"string"},"confirm":{"type":"string"},"force":{"description":"Perform the action even if the organization is in alert-only mode (no automation in enforce mode). Without it, an action in such an organization is recorded but not performed, and the response says `force_required: true`; repeat the same request with `force: true` to perform it. The override is recorded in the organization's action audit and on the EMAIL_ACTION event. It is not part of a campaign or bulk confirmation token.","title":"force","type":"boolean"},"msg_uuids":{"items":{"type":"string"},"type":"array"},"reason":{"type":"string"},"text":{"description":"Only for `banner_message`: wording for this banner, replacing the organization's default and per-verdict wording (title, colour and logo remain the organization's). Plain text, at most 512 characters; `\u003c`, `\u003e` and control or bidirectional characters are refused. It is escaped into a fixed template and can never become markup. Refused on any other action.","title":"text","type":"string"}},"required":["action","msg_uuids","confirm"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"properties":{"accepted":{"type":"boolean"},"already_complete":{"type":"boolean"},"already_running":{"type":"boolean"},"bulk_id":{"type":"string"},"counts":{"additionalProperties":true,"type":"object"},"member_count":{"type":"integer"},"started":{"type":"boolean"},"state":{"type":"string"}},"required":["bulk_id"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Execute a previewed bulk remediation. Takes the `confirm` token from a preview plus the SAME `action`, `attempt` and `msg_uuids` the preview was taken over; a token that does not match this exact selection is refused, so a selection that changed since it was previewed is never acted on. `reason` is the operator's justification: it is recorded on the job's audit row AND on every message's, exactly as it is for a single-message action. It is deliberately NOT part of the confirmation, so rewording it between previewing and executing neither invalidates the token nor starts a second job over the same messages. The batch is too large to run inside one request — up to 500 provider writes, paced to respect Microsoft 365 / Google throttling — so this RETURNS IMMEDIATELY with a `bulk_id` and the work proceeds in the background. Poll GET /actions/bulk/{bulk_id} for per-message outcomes and running counts. Idempotent: re-sending the same request adopts the same job rather than acting twice (the confirmation re-derives to a fixed bulk id, and each message's action collapses onto the row it already has). Partial failure is a normal, honestly-reported outcome, never a rollback — provider actions are not transactional and there is no undo. Executed by the collector that holds the organization's provider lease, the single audited path to live mail.","summary":"Execute Bulk Email Security Action","x-required-permissions":{"all_of":["mailsec.act"]}}},"/mailsec/{oid}/actions/bulk/preview":{"post":{"operationId":"previewMailsecBulkAction","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the action and the selection to preview","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"action":{"type":"string"},"attempt":{"type":"string"},"msg_uuids":{"items":{"type":"string"},"type":"array"}},"required":["action","msg_uuids"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"properties":{"action":{"type":"string"},"cap":{"type":"integer"},"confirm":{"type":"string"},"member_count":{"type":"integer"},"messages":{"items":{"additionalProperties":true,"type":"object"},"type":"array"},"preview":{"type":"boolean"},"summary":{"additionalProperties":true,"type":"object"},"target_state":{"type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Preview a bulk remediation across a caller-supplied set of messages, and mint the confirmation that authorizes exactly that set. `action` is one of 'quarantine_message', 'trash_message', 'move_to_spam', 'restore_message', 'banner_message' or 'unbanner_message' (release_message, submit_sample and withdraw_sample are single-message actions and are refused here); `msg_uuids` is the selection (deduplicated and capped at 500 — a larger selection is refused rather than truncated, because acting on the first 500 of 900 leaves the rest in inboxes nobody will look at). NOTHING IS CHANGED and no job is created: this reads the index and returns, for each message, whether it still exists, its current verdict and placement, and whether it is already in the target state — plus summary counts and the distinct-mailbox count (the blast radius). Messages that expired past the 35-day retention, and messages already where the action would put them, are REPORTED, not dropped and not errors. The response carries a `confirm` token DERIVED FROM THE EXACT SELECTION: pass it, this action, this attempt and this same `msg_uuids` list to the execute route. Any change to the selection invalidates it, so a client that re-ran its search between previewing and executing is refused rather than acting on messages nobody approved.","summary":"Preview Bulk Email Security Action","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/actions/bulk/{bulk_id}":{"get":{"operationId":"getMailsecBulkAction","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"bulk_id","required":true,"description":"the bulk action to read, as returned by the execute route","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"properties":{"bulk_id":{"type":"string"},"counts":{"additionalProperties":true,"type":"object"},"items":{"items":{"additionalProperties":true,"type":"object"},"type":"array"},"stalled":{"type":"boolean"},"state":{"type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get a bulk remediation's progress and per-message outcomes: the state ('running', 'complete' or 'interrupted'), running counts (ok / skipped / failed / alert_only / not_found / pending), and each member's result with a reason and the `action_id` of its authoritative audit row (expandable through GET /actions/{action_id}). `stalled` is true when a running job's worker has gone away — the record has not been heartbeaten within its window — in which case re-sending the same execute request with the same confirmation finishes it. An unknown bulk id, or an ordinary action id passed here, returns a typed not-found rather than a partial answer.","summary":"Get Bulk Email Security Action Status","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/actions/{action_id}":{"get":{"operationId":"getMailsecAction","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"action_id","required":true,"description":"the audit entry to expand","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"action":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Expand one entry of the action audit, including the JSON request payload the message timeline omits. For a raw-message download that payload carries the access justification — without this route the reason the platform demands would be durably recorded and unreadable, which is accountability in appearance only. Gated on mailsec.get: reading who did what to a message is part of reading the product, not a separate privilege.","summary":"Get Email Security Action","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/analyze":{"post":{"operationId":"analyzeMailsecMessage","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the message to analyze","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"direction":{"type":"string"},"eml":{"type":"string"},"eml_b64":{"type":"string"},"org_domains":{"items":{"type":"string"},"type":"array"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Parse a submitted raw message into the Message Data Model. NOTHING IS INGESTED OR STORED: no message index row is written, no raw copy is kept, and the organization's mail history is unchanged — which is what makes this safe for rule CI, for support pasting a message that was never in the tenant, and for analyzing a sample before deciding what it is. Submit the message as base64 under 'eml_b64' (preferred) or as raw text under 'eml'. The verdict half of the response arrives with the signal engine; until then the payload says so explicitly rather than implying a benign result.","summary":"Analyze Email Security Message","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/banner/preview":{"post":{"operationId":"previewMailsecBanner","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the candidate banner","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"banner":{"additionalProperties":true,"type":"object"},"text":{"type":"string"},"verdict":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"properties":{"colors":{"items":{"type":"string"},"type":"array"},"error":{"type":"string"},"html":{"type":"string"},"limits":{"additionalProperties":true,"type":"object"},"valid":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Render a candidate warning banner policy exactly as it would appear in a message, without saving anything. `banner` is the body of a `mailsec_policy` record of type 'banners' (`title`, `color`, `logo_url`, `logo_alt`, `text`, `variants`; omit `policy_type`). `verdict` selects which per-verdict variant to render (malicious, suspicious, graymail, benign, unknown) and `text` previews a banner_message action's own wording. The answer comes from the same renderer and the same validation the collector and the hive use, so what it shows is what recipients get. An invalid banner is a 200 carrying valid:false and the reason, not an error response; a valid one carries the rendered `html` (plain text and closed-palette markup only; it contains a remote logo \u003cimg\u003e when `logo_url` is set, which some mail clients block until the recipient allows images).","summary":"Preview Email Security Warning Banner","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/campaigns":{"get":{"operationId":"getMailsecCampaigns","tags":["Email Security"],"parameters":[{"name":"state","description":"repeatable campaign-state filter; a campaign matching ANY value is included","schema":{"type":"string"},"in":"query"},{"name":"verdict","description":"repeatable verdict filter; a campaign matching ANY value is included","schema":{"type":"string"},"in":"query"},{"name":"all","description":"include all content clusters for hunting; default false requires a flagged member and at least two mailboxes","schema":{"type":"string"},"in":"query"},{"name":"min_members","description":"restrict to campaigns with at least this many member messages","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"since","description":"earliest campaign time, RFC3339 or unix seconds","schema":{"type":"string"},"in":"query"},{"name":"until","description":"latest campaign time, RFC3339 or unix seconds","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of campaigns to return for this page; omit to use the backend default","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"campaigns":{"items":{"type":"object"},"type":"array"},"next_cursor":{"oneOf":[{"type":"string"},{"type":"null"}]}},"required":["campaigns"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one keyset-paginated page of the organization's message campaigns — clusters with a flagged member and spread across at least two mailboxes — filtered by state, verdict, size and time. Use all=true to include benign and single-mailbox content clusters for hunting. The response carries a 'next_cursor'; an empty one is the last page.","summary":"Get Email Security Campaigns","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/campaigns/{campaign_id}":{"get":{"operationId":"getMailsecCampaign","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"campaign_id","required":true,"description":"the campaign to fetch","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"campaign":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one campaign's detail: its span, membership, verdict and the keys that bound its messages together. An unknown id returns a null campaign rather than an error.","summary":"Get Email Security Campaign","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/campaigns/{campaign_id}/actions":{"post":{"operationId":"actOnMailsecCampaign","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"campaign_id","required":true,"description":"the campaign to act on","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"the action to perform","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"action":{"type":"string"},"attempt":{"type":"string"},"confirm":{"type":"string"},"force":{"description":"Perform the action even if the organization is in alert-only mode (no automation in enforce mode). Without it, an action in such an organization is recorded but not performed, and the response says `force_required: true`; repeat the same request with `force: true` to perform it. The override is recorded in the organization's action audit and on the EMAIL_ACTION event. It is not part of a campaign or bulk confirmation token.","title":"force","type":"boolean"},"mode":{"description":"release_message only: analyst (default) or ai; authenticated actor/source remain gateway-owned.","title":"mode","type":"string"},"reason":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Perform a typed remediation action across every message in a campaign. Same body as the single-message action, plus `confirm`. WITHOUT `confirm` this PREVIEWS and changes nothing: it returns the member ids, the distinct mailboxes it would touch, the counts, and a `confirm` token derived from that exact member set. Passing the token back executes exactly that set — a campaign that grew while it was being read fails the confirmation instead of sweeping members nobody approved. The sweep is capped at 500 members.","summary":"Act On Email Security Campaign","x-required-permissions":{"all_of":["mailsec.act"]}}},"/mailsec/{oid}/connections/{record}/test":{"post":{"operationId":"testMailsecConnection","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"record","required":true,"description":"the mailsec_provider record to test","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"test options","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"include_watch":{"type":"boolean"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"checks":{"items":{"additionalProperties":false,"properties":{"detail":{"type":"string"},"id":{"type":"string"},"name":{"type":"string"},"remediation":{"type":"string"},"required":{"type":"boolean"},"status":{"type":"string"}},"required":["id","name","required","status"],"type":"object"},"type":"array"},"ok":{"type":"boolean"},"summary":{"type":"string"}},"required":["ok","summary","checks"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Probe a configured mail connection and report each requirement independently: the credential, each OAuth scope, a real directory read, and — for Google Workspace — whether we can read the notification subscription and whether the provider can publish to the topic. Each check carries a `remediation` string naming the exact fix. A failed OPTIONAL check is not an error: a Workspace tenant that granted only the narrow mail scope has a working connection without warning banners, and `ok` is true in that case. Set `include_watch` to verify notification delivery end to end; that is the one probe with a side effect (it establishes a push watch, which is idempotent and expires on its own).","summary":"Test Email Security Connection","x-required-permissions":{"all_of":["mailsec.act"]}}},"/mailsec/{oid}/coverage":{"get":{"operationId":"getMailsecCoverage","tags":["Email Security"],"parameters":[{"name":"since","description":"start of the volume window, RFC3339 or unix seconds; defaults to one window before 'until'","schema":{"type":"string"},"in":"query"},{"name":"until","description":"end of the volume window, RFC3339 or unix seconds; defaults to now","schema":{"type":"string"},"in":"query"},{"name":"window_days","description":"the volume window as a whole number of days back from now (1-35), the shorthand the CLI's --window-days uses. Cannot be combined with 'since'/'until' — name a window or a range, not both. The ceiling is the platform's maximum message retention, so a longer window could not describe a complete period for any organization","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the organization's email-security coverage: mailboxes discovered / protected / in error, message volume over the window, the verdict funnel, the parse-degradation rate, and backfill progress. With no window the default 24-hour period is served from a short-lived server-side memo; naming an explicit 'since'/'until', or a 'window_days', always computes the answer for that exact range. A window that reaches past the organization's own message-retention horizon comes back with 'volume.truncated' set: the counts are of what is really stored, and the flag says the period asked about is longer than the period kept. Because an explicit window (including 'window_days') is recomputed rather than served from the memo, those calls are counted against a per-organization read budget and answer 429 past it; the default no-window call is not counted.","summary":"Get Email Security Coverage","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/group-actions/{job_id}":{"get":{"operationId":"getMailsecGroupAction","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"job_id","required":true,"description":"group action job","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"job status","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Read preview or execution progress. Only a completely prepared manifest has a confirmation token. Counts distinguish successful, skipped, alert-only and failed members.","summary":"Get Email Security Group Action","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/group-actions/{job_id}/confirm":{"post":{"operationId":"postMailsecGroupActionConfirm","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"job_id","required":true,"description":"group action job","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"complete-preview consent","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"confirmation":{"type":"string"}},"required":["confirmation"],"type":"object"}}},"required":true},"responses":{"200":{"description":"confirmed job","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Execute the complete preview with its confirmation token, from the same authenticated actor that prepared it. Execution resumes across collector handover and never adds recipient copies delivered after the snapshot. Poll the job for outcomes.","summary":"Confirm Email Security Group Action","x-required-permissions":{"all_of":["mailsec.act"]}}},"/mailsec/{oid}/groups":{"get":{"operationId":"getMailsecGroups","tags":["Email Security"],"parameters":[{"name":"q","description":"literal case-insensitive substring of subject or sender; requires since or an indexed selector","schema":{"type":"string"},"in":"query"},{"name":"mailbox","description":"one protected mailbox address","schema":{"type":"string"},"in":"query"},{"name":"sender_email","description":"exact sender address","schema":{"type":"string"},"in":"query"},{"name":"sender_root_domain","description":"sender registrable root domain","schema":{"type":"string"},"in":"query"},{"name":"campaign_id","description":"campaign identity","schema":{"type":"string"},"in":"query"},{"name":"group_id","description":"one message group identity","schema":{"type":"string"},"in":"query"},{"name":"link_domain","description":"link registrable root domain","schema":{"type":"string"},"in":"query"},{"name":"attachment_sha256","description":"attachment digest","schema":{"type":"string"},"in":"query"},{"name":"state","description":"repeatable copy placement state","schema":{"type":"string"},"in":"query"},{"name":"direction","description":"repeatable copy direction","schema":{"type":"string"},"in":"query"},{"name":"min_score","description":"minimum copy score, 0-100","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"lane","description":"live or backfill; same supported combinations as messages","schema":{"type":"string"},"in":"query"},{"name":"verdict","description":"repeatable engine verdict filter","schema":{"type":"string"},"in":"query"},{"name":"severity","description":"repeatable threat severity filter","schema":{"type":"string"},"in":"query"},{"name":"disposition","description":"repeatable analyst disposition filter, or none","schema":{"type":"string"},"in":"query"},{"name":"user_reported","description":"tri-state report filter","schema":{"type":"string"},"in":"query"},{"name":"inspection_incomplete","description":"true/false: incomplete inspection; false excludes unmeasured copies","schema":{"type":"string"},"in":"query"},{"name":"flagged","description":"true/false: canonical triage eligibility on the matching copy","schema":{"type":"string"},"in":"query"},{"name":"all","description":"include every group when true","schema":{"type":"string"},"in":"query"},{"name":"since","description":"earliest matching copy time, RFC3339 or unix seconds","schema":{"type":"string"},"in":"query"},{"name":"until","description":"exclusive latest matching copy time","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"opaque filter-bound cursor","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"page size","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the flagged message-group triage queue. Every message-list filter applies to recipient copies: a group is returned when one copy matches ALL filters (OR within a repeated key). Filtered order uses the newest matching copy. Rows summarize the whole group, and actions affect all copies frozen at preview. Pass all=true to include unflagged groups. Opaque filtered cursors pin a 50-minute snapshot; short or empty pages may still carry a continuation. Exact matched_copies counts are omitted to bound per-page cost. Narrow the filters on group_filter_too_broad; lane combinations follow the message-list refusals.","summary":"Get Email Security Message Groups","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/groups/{group_id}":{"get":{"operationId":"getMailsecGroup","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"group_id","required":true,"description":"message group identity","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one consistent aggregate of every indexed recipient copy. Counts are exact, with placement and disposition summaries, campaign and representative message. An absent group returns null.","summary":"Get Email Security Message Group","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/groups/{group_id}/actions/preview":{"post":{"operationId":"postMailsecGroupActionPreview","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"group_id","required":true,"description":"message group identity","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"frozen action parameters","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"action":{"type":"string"},"clear":{"type":"boolean"},"disposition":{"type":"string"},"force":{"type":"boolean"},"note":{"type":"string"},"preview_id":{"type":"string"},"reason":{"type":"string"},"text":{"type":"string"}},"required":["preview_id","action"],"type":"object"}}},"required":true},"responses":{"200":{"description":"durable preview job","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Prepare a durable snapshot of all recipient copies. Requires mailsec.act because it creates a manifest. Reuse preview_id when retrying the same request. Poll the returned job until ready; preparing jobs have no confirmation token and cannot execute. Force, reason, banner text and disposition parameters are frozen in the preview. set_disposition additionally requires mailsec.set; notes are limited to 1024 characters.","summary":"Prepare Email Security Group Action","x-required-permissions":{"all_of":["mailsec.act"]}}},"/mailsec/{oid}/messages":{"get":{"operationId":"getMailsecMessages","tags":["Email Security"],"parameters":[{"name":"mailbox","description":"restrict to one protected mailbox address","schema":{"type":"string"},"in":"query"},{"name":"sender_email","description":"restrict to one sender address","schema":{"type":"string"},"in":"query"},{"name":"sender_root_domain","description":"restrict to one sender registrable domain","schema":{"type":"string"},"in":"query"},{"name":"campaign_id","description":"restrict to the members of one campaign","schema":{"type":"string"},"in":"query"},{"name":"group_id","description":"restrict to recipient copies of one hardened message group","schema":{"type":"string"},"in":"query"},{"name":"severity","description":"repeatable threat severity: informational | low | medium | high | critical; nonflagged verdicts are informational","schema":{"type":"string"},"in":"query"},{"name":"link_domain","description":"restrict to messages linking to this registrable root domain (e.g. 'evil.example', not 'login.evil.example'). The incident-response pivot: who else received mail pointing at this infrastructure","schema":{"type":"string"},"in":"query"},{"name":"attachment_sha256","description":"restrict to messages carrying an attachment with this SHA-256","schema":{"type":"string"},"in":"query"},{"name":"verdict","description":"repeatable verdict filter; a message matching ANY value is included","schema":{"type":"string"},"in":"query"},{"name":"state","description":"repeatable message-state filter; a message matching ANY value is included","schema":{"type":"string"},"in":"query"},{"name":"direction","description":"repeatable direction filter (inbound | outbound | internal)","schema":{"type":"string"},"in":"query"},{"name":"lane","description":"processing lane filter (live | backfill). Omit to include either lane. This filter works with time-window, IOC-pivot and verdict queries (free-text q with verdict+lane also requires since), but cannot be combined with mailbox, sender_email or campaign_id; those combinations are refused with the typed backend error 'lane_unsupported'","schema":{"type":"string"},"in":"query"},{"name":"flagged","description":"true/false: canonical disposition/verdict/user-report triage eligibility","schema":{"type":"string"},"in":"query"},{"name":"inspection_incomplete","description":"true/false: filter inspected messages by incomplete coverage; false excludes unmeasured rows","schema":{"type":"string"},"in":"query"},{"name":"user_reported","description":"true/false: restrict to messages a user did (or did not) report. OMIT for no constraint — absent is not the same as false, which selects mail nobody reported","schema":{"type":"string"},"in":"query"},{"name":"min_score","description":"restrict to messages scoring at least this much","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"disposition","description":"repeatable analyst/SOAR disposition: malicious, spam, graymail, benign, simulation, or none (untriaged); OR within this filter","schema":{"type":"string"},"in":"query"},{"name":"q","description":"free-text filter over the message's subject and sender address, at most 512 characters. The text is matched LITERALLY and case-insensitively: '%' and '_' are ordinary characters rather than wildcards, surrounding whitespace is ignored, and text that is only whitespace is not a filter at all. It is matched row by row rather than looked up, so it must be accompanied by something that bounds the read: a 'since', or one of group_id, mailbox, sender_email, campaign_id, link_domain, attachment_sha256, or a single 'verdict'/'severity'. On its own it is refused, because it would read the whole retained index — and return nothing at all when it matches nothing. 'until' alone does not count: the index is walked newest-first. A search that is bounded only by time is also counted against a per-organization read budget and answers 429 past it; one carrying a mailbox, sender, campaign or IOC filter is an index lookup and is not counted","schema":{"type":"string"},"in":"query"},{"name":"since","description":"earliest message time, RFC3339 or unix seconds; REQUIRED alongside a 'q' that carries no other narrowing filter","schema":{"type":"string"},"in":"query"},{"name":"until","description":"latest message time, RFC3339 or unix seconds","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of messages to return for this page; omit to use the backend default","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"messages":{"items":{"type":"object"},"type":"array"},"next_cursor":{"oneOf":[{"type":"string"},{"type":"null"}]}},"required":["messages"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one keyset-paginated page of the organization's message index, filtered by time, verdict, mailbox, sender, campaign, state, user-report status, and the IOC pivots (link_domain, attachment_sha256) that answer 'who else received this'. The response carries a 'next_cursor'; an empty one is the last page. A cursor is BOUND TO ITS FILTER SET — the backend chooses its read index from the filter and stamps that choice into the cursor, so changing a filter mid-walk fails the next page rather than silently resuming at a position that means something else. Restart the walk instead.","summary":"Get Email Security Messages","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/messages/dispositions":{"post":{"operationId":"setMailsecBulkDisposition","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"decisions","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"clear":{"type":"boolean"},"disposition":{"type":"string"},"msg_uuids":{"items":{"type":"string"},"type":"array"},"note":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"per-message results","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Record the same independent disposition on 1-500 unique message ids. Returns a per-message result; partial failure is explicit. Use clear=true to remove dispositions.","summary":"Set Email Security Bulk Disposition","x-required-permissions":{"all_of":["mailsec.set"]}}},"/mailsec/{oid}/messages/{msg_uuid}":{"get":{"operationId":"getMailsecMessage","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"msg_uuid","required":true,"description":"the message's permanent identity, as returned on every index row","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"mdm":{"type":"object"},"mdm_source":{"type":"string"},"mdm_unavailable_reason":{"type":"string"},"message":{"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one message's full detail: the index row, the complete signal rationale behind its verdict, its action timeline, and the Message Data Model. `mdm_source` says which model you are reading, because the two are not equivalent. 'stored' is the model the collector actually judged with — the enrichments it resolved at ingest (sender prevalence, lookalike distances, link features, domain age) and the verdict as stamped, sealed beside the raw message. 'eml_reparse' is today's parser reading the original bytes: the same message, a different parse, and no enrichments at all. 'stored' is served whenever it exists; 'eml_reparse' is the fallback for mail ingested before stored models existed. An analyst deciding whether the engine was right needs to know which one they are looking at, so the field is always present. Neither requires a justification — the model is the product's own structured view, and it is the ORIGINAL BYTES that are gated. When no model can be produced at all, `mdm_unavailable_reason` says why instead of the response quietly omitting it. An unknown or expired id returns a null message rather than an error — the index has a 35-day retention and a miss is a normal outcome. Because the model carries the message body, a read that returns one is recorded in the organization's audit log as `mailsec_message_content_read`, naming your identity and whether it is a user, a user API key or an org API key; repeat reads of the same message by the same identity within an hour are recorded once.","summary":"Get Email Security Message","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/messages/{msg_uuid}/actions":{"post":{"operationId":"actOnMailsecMessage","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"msg_uuid","required":true,"description":"the message to act on","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"the action to perform","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"action":{"type":"string"},"attempt":{"type":"string"},"category":{"description":"Why the sample is being sent, required for 'submit_sample' and ignored by every other action: 'missed_threat' (the message was judged benign or unknown and is a threat), 'false_positive' (the message was flagged and is legitimate) or 'other'.","enum":["missed_threat","false_positive","other"],"title":"category"},"force":{"description":"Perform the action even if the organization is in alert-only mode (no automation in enforce mode). Without it, an action in such an organization is recorded but not performed, and the response says `force_required: true`; repeat the same request with `force: true` to perform it. The override is recorded in the organization's action audit and on the EMAIL_ACTION event. It is not part of a campaign or bulk confirmation token.","title":"force","type":"boolean"},"mode":{"description":"release_message only: analyst (default) or ai. Caller mode describes the decision; actor/source remain authenticated by the gateway.","title":"mode","type":"string"},"reason":{"type":"string"},"text":{"description":"Only for `banner_message`: wording for this banner, replacing the organization's default and per-verdict wording (title, colour and logo remain the organization's). Plain text, at most 512 characters; `\u003c`, `\u003e` and control or bidirectional characters are refused. It is escaped into a fixed template and can never become markup. Refused on any other action.","title":"text","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Perform a typed remediation action on one message at the provider. `action` is one of 'quarantine_message', 'trash_message', 'move_to_spam', 'restore_message', 'release_message', 'banner_message', 'unbanner_message', 'submit_sample' or 'withdraw_sample'; `reason` is recorded in the organization's action audit alongside your identity. `attempt` is an idempotency token: two requests carrying the same one collapse onto a single action, and omitting it collapses onto the action already recorded rather than performing a second visible one on somebody's mailbox. 'banner_message' applies the organization's own warning banner: its look (title, colour, logo) and its default and per-verdict wording come from the `mailsec_policy` record of type 'banners' and are rendered server-side into a fixed, escaped template; the optional `text` replaces the wording for this one action. 'submit_sample' sends a copy of this ONE message to LimaCharlie so it can improve detection, and is the only action that does not touch the mailbox. It is off unless the organization has opted in with a `mailsec_policy` record of type 'sample_sharing', it is never automatic, and it can only be done by a person or an API key (never by a D\u0026R rule, an automation or the AI agent). It requires `category` ('missed_threat': we called it benign and it is a threat; 'false_positive': we flagged it and it is legitimate; or 'other') and a `reason` of 1 to 1024 characters. The response carries the `submission_id`, and submitting a message that already has an active submission succeeds without storing a second copy. 'withdraw_sample' (optional `reason`, up to 1024 characters) deletes the copy you sent for this message. The submissions you have made can be listed with GET /v1/mailsec/{oid}/submissions and withdrawn at any time. Both sample actions are available on this route only: the campaign and bulk routes refuse them. The action is executed by the collector that holds the organization's provider lease, which is what makes it the single audited path to live mail.","summary":"Act On Email Security Message","x-required-permissions":{"all_of":["mailsec.act"]}}},"/mailsec/{oid}/messages/{msg_uuid}/disposition":{"post":{"operationId":"setMailsecDisposition","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"msg_uuid","required":true,"description":"message to classify","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"decision","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"clear":{"type":"boolean"},"disposition":{"type":"string"},"note":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"decision committed; telemetry queued","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Record an analyst or SOAR disposition independently of the engine verdict. Values: malicious, spam, graymail, benign, simulation. Use clear=true to remove the decision. Notes are limited to 1024 characters; attribution is authenticated by the gateway. Does not run automations.","summary":"Set Email Security Disposition","x-required-permissions":{"all_of":["mailsec.set"]}}},"/mailsec/{oid}/messages/{msg_uuid}/eml":{"get":{"operationId":"getMailsecMessageEML","tags":["Email Security"],"parameters":[{"name":"justification","required":true,"description":"why this message's original bytes are being accessed. REQUIRED; recorded against your identity in the organization's action audit and retained for 400 days. The backend enforces a minimum length","schema":{"minLength":1,"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"msg_uuid","required":true,"description":"the message whose original bytes are being requested","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Download one message's ORIGINAL bytes (decrypted RFC822). This is a privileged read of a person's mail and is gated separately from the rest of the surface: it requires BOTH mailsec.get and mailsec.get.eml, plus a 'justification' describing why the message is being accessed. The justification is recorded against the caller's authenticated identity in the organization's action audit and retained for 400 days; failed attempts are recorded as well, subject to a per-organization rate limit of their own. Raw copies expire 35 days after delivery (400 for flagged messages), after which this returns a typed expiry error while the index row remains readable. A served download is also recorded in the organization's audit log as `mailsec_message_content_read`, with the size and the justification.","summary":"Download Email Security Raw Message","x-required-permissions":{"all_of":["mailsec.get","mailsec.get.eml"]}}},"/mailsec/{oid}/messages/{msg_uuid}/revisions":{"get":{"operationId":"getMailsecMessageRevisions","tags":["Email Security"],"parameters":[{"name":"limit","description":"the maximum number of revisions to return; omit for the backend default, which serves an ordinary message's whole history in one read","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"msg_uuid","required":true,"description":"the message whose verdict-revision history is being read","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"revisions":{"items":{"type":"object"},"type":"array"},"revisions_truncated":{"type":"boolean"}},"required":["revisions"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one message's full verdict-revision history, oldest first: every time the AI triage agent or an analyst replaced the engine's class, each with WHO decided (actor and mode), WHEN, the structured rationale behind it, and the PRIOR state it displaced — the prior of the first revision being the original scorer verdict and the engine version that produced it. The message detail response already carries the most recent revisions inline for the drawer; this route serves the whole chain, for the rare message with more revisions than the drawer inlines and for an audit export that wants it entire. It is not paginated — a message's revisions are few by nature — but a 'revisions_truncated' flag reports the pathological case where the history exceeded the backend's ceiling. Gated on mailsec.get: a revision is the product's own structured record of a decision about a message you can already open, not the original bytes that mailsec.get.eml guards.","summary":"Get Email Security Message Verdict Revisions","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/messages/{msg_uuid}/similar":{"get":{"operationId":"getMailsecSimilarMessages","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"msg_uuid","required":true,"description":"the message to find neighbours of","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"messages":{"items":{"type":"object"},"type":"array"},"since":{"type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get recent messages sharing at least one clustering key (normalized subject, body similarity hash, link-domain set, attachment hashes) with this one. These are CANDIDATES, not a cluster: every row carries the keys that matched, and the decision that two messages are the same attack belongs to the clustering engine. The response echoes the lookback window, because 'no similar messages' only means anything alongside it.","summary":"Get Similar Email Security Messages","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/messages/{msg_uuid}/verdict":{"post":{"operationId":"reviseMailsecMessageVerdict","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"msg_uuid","required":true,"description":"the message being re-judged","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"the re-judgement","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"mode":{"type":"string"},"rationale":{"items":{"type":"string"},"type":"array"},"score":{"type":"integer"},"verdict":{"type":"string"}},"required":["verdict","mode","rationale"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"properties":{"actor":{"type":"string"},"already_current":{"type":"boolean"},"applied":{"type":"boolean"},"decided_at":{"type":"string"},"event_emitted":{"type":"boolean"},"flagged_mirrored":{"type":"boolean"},"mode":{"type":"string"},"newly_flagged":{"type":"boolean"},"prior":{"additionalProperties":true,"properties":{"engine_version":{"type":"string"},"mode":{"type":"string"},"score":{"type":"integer"},"verdict":{"type":"string"}},"type":"object"},"rationale":{"items":{"type":"string"},"type":"array"},"rationale_truncated":{"type":"boolean"},"retained":{"type":"boolean"},"revision_seq":{"type":"integer"},"verdict":{"type":"string"}},"required":["applied","revision_seq","already_current"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Record a re-judgement of one message, replacing the class the detection engine stamped. `verdict` is required and is one of 'malicious', 'suspicious', 'graymail', 'benign' or 'unknown' — 'unknown' is an honest abstention that escalates to a human queue, and 'error' is refused because it means judgement itself failed, which is an engine fact nobody decides. `mode` is required and says which SEAT decided: 'analyst' for a person, 'ai' for an autonomous triage agent calling with its own org credentials. 'auto' is refused — that is the scorer's own path and it does not override itself. `rationale` is REQUIRED and is a non-empty list of short strings: a class with no reason is a naked verdict, and the same explainability contract applies to a revision as to the engine. It is BOUNDED — the backend keeps at most 10 bullets of at most 280 characters each, clipping on a character boundary and setting `rationale_truncated` when it did, rather than refusing the verdict over an over-long explanation. `score` is optional; omitting it keeps the engine's score beside the new class. WHO revised is stamped from your authenticated identity and is never read from the request body — an override nobody can attribute is one nobody can review, and a body-supplied actor would let an agent claim to be a person. A NO-OP IS A SUCCESS, NOT AN ERROR: re-recording the class, score and mode a message already carries changes nothing, so the response is 200 with `applied: false` and `already_current: true`, and `revision_seq` names the revision that already says it. Distinguish the two through the body, not the status. Re-wording the rationale alone is not a change; a person confirming an agent's call IS one, because the mode moves. When a revision applies, `prior` carries the verdict, score, mode and engine version it replaced, `newly_flagged` says whether the message entered the flagged set, `flagged_mirrored` whether its 400-day evidence row was updated in the same transaction, and `event_emitted` / `retained` whether the EMAIL_VERDICT event shipped and the evidence reached the retained lane. The revision is durable before either of those is attempted, so a failure to ship telemetry is reported as a retryable error whose body still says `applied: true` — the recorded judgement is never silently discarded, and the event is never claimed when it did not ship.","summary":"Revise Email Security Message Verdict","x-required-permissions":{"all_of":["mailsec.act"]}}},"/mailsec/{oid}/onboarding":{"get":{"operationId":"getMailsecOnboarding","tags":["Email Security"],"parameters":[{"name":"provider","description":"which provider to describe (gworkspace | m365); defaults to gworkspace","schema":{"type":"string"},"in":"query"},{"name":"project_id","description":"the customer's Google Cloud project, to substitute into the commands","schema":{"type":"string"},"in":"query"},{"name":"sa_email","description":"the customer's service account address, to substitute into the commands","schema":{"type":"string"},"in":"query"},{"name":"topic","description":"override the suggested Pub/Sub topic name","schema":{"type":"string"},"in":"query"},{"name":"subscription","description":"override the suggested Pub/Sub subscription name","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"scopes":{"items":{"type":"object"},"type":"array"},"script":{"type":"string"},"steps":{"items":{"type":"object"},"type":"array"}},"required":["scopes","steps"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"The setup steps, OAuth scopes and gcloud commands needed to connect a mail tenant, for rendering in a setup flow. Each step carries a `console` (which admin console it happens in) and, where we can verify it, a `verified_by` naming the check in the connection test that proves it was done. `script` is every command in order as one paste. Supply `project_id` and `sa_email` once a service account exists and the commands come back ready to run rather than templated.","summary":"Get Email Security Onboarding Steps","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/provider-quarantine":{"get":{"operationId":"getMailsecProviderQuarantine","tags":["Email Security"],"parameters":[{"name":"connection","description":"Connection record name","schema":{"maxLength":256,"type":"string"},"in":"query"},{"name":"status","description":"quarantined, filteredAsSpam or failed","schema":{"allOf":[{"type":"string"},{"enum":["","quarantined","filteredAsSpam","failed"]}]},"in":"query"},{"name":"since","description":"Inclusive provider timestamp, RFC3339 or Unix seconds","schema":{"type":"string"},"in":"query"},{"name":"until","description":"Exclusive provider timestamp, RFC3339 or Unix seconds","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"Opaque continuation bound to this filter set","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"Page size, maximum 1000","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"Observations, next_cursor and coverage","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List quarantined, spam-filtered and failed Microsoft deliveries with independent coverage per connection/feed. An empty list with not_granted, pending, stale or error coverage is not proof that no messages were blocked. Failed means delivery failed, not hosted quarantine.","summary":"List Microsoft Provider Quarantine Observations","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/release-requests":{"get":{"operationId":"getMailsecReleaseRequests","tags":["Email Security"],"parameters":[{"name":"connection","description":"Connection record name","schema":{"maxLength":256,"type":"string"},"in":"query"},{"name":"status","description":"requested, released or denied","schema":{"allOf":[{"type":"string"},{"enum":["","requested","released","denied"]}]},"in":"query"},{"name":"since","description":"Inclusive provider timestamp, RFC3339 or Unix seconds","schema":{"type":"string"},"in":"query"},{"name":"until","description":"Exclusive provider timestamp, RFC3339 or Unix seconds","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"Opaque continuation bound to this filter set","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"Page size, maximum 1000","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"Release activity, next_cursor and coverage","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List end-user release requests and subsequent release/denial audit observations from Microsoft hosted quarantine. This route observes activity; it does not approve or perform release. Coverage is independent of message-trace coverage.","summary":"List Microsoft Quarantine Release Activity","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/reports":{"get":{"operationId":"getMailsecReports","tags":["Email Security"],"parameters":[{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of reports to return for this page; omit to use the backend default","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"status","description":"restrict to reports in these states ('open', 'triaging', 'resolved'); repeatable, and omitting it returns every state","schema":{"type":"string"},"in":"query"},{"name":"oldest_first","description":"order by age instead of recency, which is what an SLA queue is read by: the oldest unworked report first","schema":{"type":"boolean"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the user-report (abuse mailbox) queue: messages the organization's own people reported as suspicious, with their triage state.","summary":"Get Email Security User Reports","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/reports/{report_id}":{"get":{"operationId":"getMailsecReport","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"report_id","required":true,"description":"the user report to read","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Read one user report: who reported it, the message they reported, the original it refers to once located across the tenant's mailboxes, and its triage state. An unknown id returns a null report rather than an error, matching the message drawer.","summary":"Get an Email Security User Report","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/reports/{report_id}/reopen":{"post":{"operationId":"reopenMailsecReport","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"report_id","required":true,"description":"the user report to put back in the queue","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Put a resolved user report back in the queue: its status returns to 'open' and it is worked again. This is the escape hatch for a resolution nobody made — a report from an automated sender is born resolved and attributed to 'system:automated-sender', and the classifier never overrules a human, which is what makes a reopen stick. It serves a wrong AI resolution and an analyst's mis-click equally; none of the three is special here. The resolution columns are deliberately KEPT: only the status moves, so the row still reads 'previously resolved benign by system:automated-sender' rather than erasing the very thing being disputed. Takes no request body — who reopened is stamped from your authenticated identity, never supplied by the caller. Reopening a report that is already open or being triaged succeeds and reports 'already_open', so two analysts clicking at once is not an error; `reopened_from` names the state it came out of. An unknown report id is an error rather than a silent success, because this route names one specific row to change.","summary":"Reopen Email Security User Report","x-required-permissions":{"all_of":["mailsec.set"]}}},"/mailsec/{oid}/reports/{report_id}/resolve":{"post":{"operationId":"resolveMailsecReport","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"report_id","required":true,"description":"the user report to resolve","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"the triage outcome","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"disposition":{"type":"string"},"remediation":{"additionalProperties":false,"properties":{"action":{"type":"string"},"attempt":{"type":"string"},"confirm":{"type":"string"},"force":{"type":"boolean"},"reason":{"type":"string"},"scope":{"type":"string"}},"type":"object"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Record a triage outcome on a user report. `disposition` is required and is one of 'malicious', 'spam', 'graymail', 'benign', or 'simulation'. Resolution sets the linked message disposition and queues optional reporter replies. Optional remediation supports message, group or campaign scope with preview then confirmation, additionally requires mailsec.act, and leaves the report open on failure or withholding. Group scope requires a UUID attempt reused through preview, confirmation and polling; its durable job may return remediation_pending until every member completes. Only the reported original is classified. Resolving an already-resolved report succeeds and reports 'already_resolved', so two analysts clicking at once is not an error.","summary":"Resolve Email Security User Report","x-required-permissions":{"all_of":["mailsec.set"]}}},"/mailsec/{oid}/rules/backtest":{"post":{"operationId":"backtestMailsecRule","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the candidate rule and the window to replay it over","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"rule":{"type":"object"},"since":{"type":"string"},"until":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Replay a candidate detection rule over the organization's indexed message window and report what it would have matched, so its precision is known before it is enabled. Bounded to the window this product retains (35 days) rather than the full-history retro-hunt; every response carries a coverage_note saying what was actually examined, and counts what it could not examine (skipped_no_raw, skipped_unparse, truncated) so a precision figure is never read as covering more than it did. precision is null — not 0 — when nothing it matched has an analyst disposition yet. Because every message in the window is fetched from storage and re-parsed, this is the most expensive read on this surface and is bounded per organization: past the budget it answers 429 with a Retry-After.","summary":"Backtest Email Security Rule","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/rules/validate":{"post":{"operationId":"validateMailsecRule","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"the candidate rule","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"rule":{"type":"object"},"rule_id":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Compile a candidate detection rule and report its errors, without saving it. Runs the same validation the dr-mail hive applies on save, so a rule this accepts is a rule that will save. An invalid rule is a 200 carrying valid:false and the reason, not an error response.","summary":"Validate Email Security Rule","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/senders/{key}":{"get":{"operationId":"getMailsecSenderProfile","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"key","required":true,"description":"the sender to profile: a qualified key ('email:someone@example.com' or 'domain:example.com'), or a bare address or domain","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the organization's accumulated profile for one correspondent: first and last contact, volume, and the prevalence signals the engine reasons about. A key with no profile means no history at all, which the response says explicitly rather than returning a zeroed profile that would read as a known-but-quiet sender. Keys are lowercased when built, so a bare address or domain is resolved here rather than requiring the caller to know the convention.","summary":"Get Email Security Sender Profile","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/submissions":{"get":{"operationId":"getMailsecSubmissions","tags":["Email Security"],"parameters":[{"name":"category","description":"restrict to one category ('missed_threat', 'false_positive' or 'other')","schema":{"type":"string"},"in":"query"},{"name":"since","description":"earliest submission time, RFC3339","schema":{"type":"string"},"in":"query"},{"name":"until","description":"latest submission time, RFC3339","schema":{"type":"string"},"in":"query"},{"name":"cursor","description":"an opaque keyset-pagination token returned as 'next_cursor' by a previous page; omit for the first page","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"the maximum number of submissions to return for this page, 1 to 200; omit to use the default of 50","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"available":{"type":"boolean"},"enabled":{"type":"boolean"},"next_cursor":{"oneOf":[{"type":"string"},{"type":"null"}]},"submissions":{"items":{"additionalProperties":true,"type":"object"},"type":"array"}},"required":["enabled","available","submissions"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List the message samples this organization has sent to LimaCharlie with the 'submit_sample' action, newest first, one keyset-paginated page at a time. Each entry shows what was kept about the message (its id, the category and reason given, who sent it and when, the verdict, score and matched rules at that time, the sender, subject and size), when it will be deleted automatically, and how many times LimaCharlie staff have opened it. `enabled` says whether the organization has opted in to sample submission, and `available` says whether this datacenter offers it; both are always present, so an empty list can be told apart from a feature that is off. The response carries a 'next_cursor'; an empty one is the last page.","summary":"List Email Security Sample Submissions","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/submissions/{submission_id}":{"delete":{"operationId":"withdrawMailsecSubmission","tags":["Email Security"],"parameters":[{"name":"reason","description":"why the sample is being withdrawn; recorded in the organization's audit trail. Maximum 1024 characters","schema":{"maxLength":1024,"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"submission_id","required":true,"description":"the submission to withdraw","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"action_id":{"type":"string"},"submission_id":{"type":"string"},"withdrawn":{"type":"boolean"}},"required":["withdrawn","submission_id"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Withdraw a sample you sent to LimaCharlie: the stored copy of the message and its submission record are PERMANENTLY deleted, and the withdrawal is recorded in the organization's action audit and audit log under your identity. `withdrawn` is true when this call deleted the copy, and the response then carries the `action_id` of the audit entry. Withdrawing a submission that is unknown, already withdrawn or expired is not an error: it returns `withdrawn: false` with no `action_id` and never deletes anything a second time. `reason` optionally records why.","summary":"Withdraw Email Security Sample Submission","x-required-permissions":{"all_of":["mailsec.act"]}},"get":{"operationId":"getMailsecSubmission","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"submission_id","required":true,"description":"the submission to read, as returned by the submissions list or the 'submit_sample' action","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"reviews":{"items":{"additionalProperties":true,"type":"object"},"type":"array"},"submission":{"oneOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}]}},"required":["submission","reviews"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get one sample submission and the times LimaCharlie staff have opened it. `reviews` lists the time of each access of the stored copy, and never who did it. An unknown, withdrawn or expired submission is not an error: the response is `submission: null` with no reviews, the same way an unknown message or report is answered, so branch on null.","summary":"Get Email Security Sample Submission","x-required-permissions":{"all_of":["mailsec.get"]}}},"/mailsec/{oid}/tenant":{"delete":{"operationId":"deleteMailsecTenant","tags":["Email Security"],"parameters":[{"name":"confirmation","required":true,"description":"the single-use token returned by GET /v1/mailsec/{oid}/tenant. REQUIRED, valid for five minutes, and spent by this call","schema":{"minLength":1,"type":"string"},"in":"query"},{"name":"reason","description":"why the organization's email security data is being deleted; recorded in the organization's audit trail. Maximum 1024 characters","schema":{"maxLength":1024,"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Step two of deleting all Email Security data for an organization. PERMANENTLY deletes the message index and stored models, the raw message copies, the campaigns, the sender profiles, the user reports, the verdict revisions and the remediation audit for this organization. It cannot be undone and the data cannot be re-derived; mail already delivered in the provider is untouched. Requires a `confirmation` token obtained from GET /v1/mailsec/{oid}/tenant within the last five minutes; the token is single use, so a retried request is refused rather than purging twice. Supply `reason` to record why in the organization's audit trail. The purge also stops the organization's mail connections at the provider and removes its Email Security connection and policy configuration, so nothing has to be disconnected first. An accepted purge runs to completion on the backend even if this request times out: a large tenant's object walk outlives any gateway budget, so a TIMEOUT IS NOT A FAILURE — the purge continues and records itself. A second DELETE issued while one is in flight is refused by name rather than starting a second purge. Requires owner authority: mailsec.act plus billing.ctrl and user.ctrl.","summary":"Delete All Email Security Data For An Organization","x-required-permissions":{"all_of":["mailsec.act","billing.ctrl","user.ctrl"]}},"get":{"operationId":"getMailsecTenantPurgeConfirmation","tags":["Email Security"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"confirmation":{"description":"single-use token to pass to DELETE /v1/mailsec/{oid}/tenant","title":"confirmation","type":"string"},"expires_in_seconds":{"type":"integer"},"warning":{"type":"string"}},"required":["confirmation","expires_in_seconds","warning"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Step one of deleting all Email Security data for an organization. Mints a single-use confirmation token, valid for five minutes, and returns it alongside a warning naming exactly what the deletion destroys. Nothing is deleted by this call. Pass the token back as the `confirmation` query parameter on DELETE /v1/mailsec/{oid}/tenant to perform the deletion. Requires owner authority: mailsec.act plus billing.ctrl and user.ctrl.","summary":"Prepare Email Security Tenant Deletion","x-required-permissions":{"all_of":["mailsec.act","billing.ctrl","user.ctrl"]}}},"/mitre/{oid}":{"get":{"operationId":"getOrgMITREReport","tags":["Rules"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"description":{"type":"string"},"domain":{"type":"string"},"name":{"type":"string"},"sorting":{"type":"integer"},"techniques":{"items":{"additionalProperties":false,"properties":{"color":{"type":"string"},"enabled":{"type":"boolean"},"techniqueID":{"type":"string"}},"required":["color","enabled","techniqueID"],"type":"object"},"type":"array"},"versions":{"additionalProperties":false,"properties":{"layer":{"type":"string"},"navigator":{"type":"string"}},"required":["layer","navigator"],"type":"object"}},"required":["description","domain","name","sorting","techniques","versions"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Generate a JSON MITRE report for a specific organization with its current detection rules.","summary":"Get MITRE report","x-required-permissions":{"all_of":["dr.list"]}}},"/models/{oid}/batch":{"post":{"operationId":"batchModelRequests","tags":["Model Request"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"Batch model request data","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"is_stop_on_failure":{"type":"boolean"},"requests":{"items":{"additionalProperties":false,"properties":{"delete_record":{"additionalProperties":false,"properties":{"model_name":{"type":"string"},"oid":{"type":"string"},"primary_key":{"type":"string"}},"type":"object"},"write_model_record":{"additionalProperties":false,"properties":{"expiry":{"type":"integer"},"fields":{"type":"object"},"model_name":{"type":"string"},"oid":{"type":"string"},"primary_key":{"type":"string"}},"type":"object"}},"type":"object"},"type":"array"}},"required":["requests"],"type":"object"}}},"required":true},"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"responses":{"items":{"additionalProperties":false,"properties":{"Data":{"anyOf":[{"type":"null"},{"additionalProperties":true,"description":"For write operations, the written mutation echoed back; null for delete operations","type":"object"}]},"Error":{"anyOf":[{"type":"null"},{"additionalProperties":true,"description":"Null when the operation succeeded; error details are not serialized, so a failed operation surfaces as an empty object","type":"object"}]}},"required":["Data","Error"],"type":"object"},"type":"array"}},"required":["responses"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Execute multiple model operations in a single batch","summary":"Batch model requests","x-required-permissions":{"all_of":["model.set","model.del"]}}},"/models/{oid}/model/{model_name}/aggregate_view":{"post":{"operationId":"queryAggregateView","tags":["Model Request"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"model_name","required":true,"description":"name of the model","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"Aggregate view query request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"aggregate_by":{"type":"string"},"aggregate_value":{"type":"string"},"ascending":{"type":"boolean"},"cursor":{"type":"string"},"filters":{"type":"object"},"include_tags":{"type":"boolean"},"limit":{"type":"integer"},"search":{"additionalProperties":false,"properties":{"field":{"type":"string"},"op":{"type":"string"},"value":{"type":"string"}},"type":"object"},"sort_by":{"type":"string"}},"required":["aggregate_by"],"type":"object"}}},"required":true},"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"next_cursor":{"description":"Pagination cursor for the next page; empty when there are no more rows","type":"string"},"results":{"items":{"additionalProperties":true,"description":"Aggregated row; columns depend on the model's aggregate view definition","type":"object"},"type":"array"}},"required":["results","next_cursor"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Query aggregated data from model records with aggregate views","summary":"Query aggregate view","x-required-permissions":{"all_of":["model.get"]}}},"/models/{oid}/model/{model_name}/index_records":{"get":{"operationId":"listIndexRecords","tags":["Model Request"],"parameters":[{"name":"index_key_name","required":true,"description":"name of the index key","schema":{"type":"string"},"in":"query"},{"name":"index_key_value","required":true,"description":"value of the index key","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"maximum number of records to return","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"cursor","description":"pagination cursor","schema":{"type":"string"},"in":"query"},{"name":"no_limit","description":"return all records without limit","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"show_expiry","description":"include record expiry information","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"model_name","required":true,"description":"name of the model","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"cursor":{"description":"Pagination cursor for the next page; empty when there are no more records","type":"string"},"records":{"additionalProperties":{"additionalProperties":true,"description":"Model record. Fields are defined by the org's model definition and are not statically known.","type":"object"},"description":"Map of record primary key to record","type":"object"}},"required":["records","cursor"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List records from a model index","summary":"List index records","x-required-permissions":{"all_of":["model.get"]}}},"/models/{oid}/model/{model_name}/index_records_by_key_prefix":{"get":{"operationId":"listIndexRecordsByKeyPrefix","tags":["Model Request"],"parameters":[{"name":"index_key_name","required":true,"description":"name of the index key","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"maximum number of records to return","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"cursor","description":"pagination cursor","schema":{"type":"string"},"in":"query"},{"name":"no_limit","description":"return all records without limit","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"show_expiry","description":"include record expiry information","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"model_name","required":true,"description":"name of the model","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"cursor":{"description":"Pagination cursor for the next page; empty when there are no more records","type":"string"},"records":{"additionalProperties":{"additionalProperties":true,"description":"Model record. Fields are defined by the org's model definition and are not statically known.","type":"object"},"description":"Map of record primary key to record","type":"object"}},"required":["records","cursor"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List records from a model index using key prefix matching","summary":"List index records by key prefix","x-required-permissions":{"all_of":["model.get"]}}},"/models/{oid}/model/{model_name}/index_value_counts":{"get":{"operationId":"getIndexValueCounts","tags":["Model Request"],"parameters":[{"name":"index_name","required":true,"description":"name of the index to count values for","schema":{"type":"string"},"in":"query"},{"name":"sort_desc","description":"sort by count descending (default: false)","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"model_name","required":true,"description":"name of the model","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"total_count":{"description":"Total number of unique values for the index","type":"integer"},"values":{"items":{"additionalProperties":false,"properties":{"count":{"type":"integer"},"value":{"type":"string"}},"required":["value","count"],"type":"object"},"type":"array"}},"required":["values","total_count"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get unique counts a specific index in a model","summary":"Get unique index counts","x-required-permissions":{"all_of":["model.get"]}}},"/models/{oid}/model/{model_name}/record":{"delete":{"operationId":"deleteModelRecord","tags":["Model Request"],"parameters":[{"name":"primary_key","required":true,"description":"primary key of the record","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"model_name","required":true,"description":"name of the model","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Delete a record in a model","summary":"Delete model record","x-required-permissions":{"all_of":["model.del"]}},"get":{"operationId":"getModelRecord","tags":["Model Request"],"parameters":[{"name":"primary_key","required":true,"description":"primary key of the record","schema":{"type":"string"},"in":"query"},{"name":"metadata","description":"return metadata","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"model_name","required":true,"description":"name of the model","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":true,"description":"Model record. Fields are defined by the org's model definition and are not statically known.","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get a record from a model","summary":"Get model record","x-required-permissions":{"all_of":["model.get"]}},"post":{"operationId":"createModelRecord","tags":["Model Request"],"parameters":[{"name":"primary_key","required":true,"description":"primary key of the record","schema":{"type":"string"},"in":"query"},{"name":"fields","required":true,"description":"fields of the record","schema":{"type":"string"},"in":"query"},{"name":"expiry","description":"expiration of the record","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"model_name","required":true,"description":"name of the model","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"fields":{"additionalProperties":true,"description":"The record fields as written; defined by the org's model definition","type":"object"},"model_name":{"type":"string"},"oid":{"format":"uuid","type":"string"},"opt_expiry":{"anyOf":[{"type":"null"},{"type":"integer"}]},"primary_key":{"type":"string"}},"required":["oid","model_name","primary_key","fields","opt_expiry"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Create a record in a model","summary":"Create model record","x-required-permissions":{"all_of":["model.set"]}}},"/models/{oid}/model/{model_name}/records":{"get":{"operationId":"getModelRecords","tags":["Model Request"],"parameters":[{"name":"index_key_name","required":true,"description":"name of the index key to look records up by","schema":{"type":"string"},"in":"query"},{"name":"index_key_value","required":true,"description":"value of the index key to look records up by","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"maximum number of records to return","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"model_name","required":true,"description":"name of the model","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"cursor":{"description":"Pagination cursor for the next page; empty when there are no more records","type":"string"},"records":{"additionalProperties":{"additionalProperties":true,"description":"Model record. Fields are defined by the org's model definition and are not statically known.","type":"object"},"description":"Map of record primary key to record","type":"object"}},"required":["records","cursor"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get multiple records from a model","summary":"Get model records","x-required-permissions":{"all_of":["model.get"]}},"post":{"operationId":"listModelRecords","tags":["Model Request"],"parameters":[{"name":"limit","description":"maximum number of records per cursor","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"cursor","description":"cursor of the last set of records fetched","schema":{"type":"string"},"in":"query"},{"name":"show_expiry","description":"include record expiry information","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"model_name","required":true,"description":"name of the model","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"cursor":{"description":"Pagination cursor for the next page; empty when there are no more records","type":"string"},"records":{"additionalProperties":{"additionalProperties":true,"description":"Model record. Fields are defined by the org's model definition and are not statically known.","type":"object"},"description":"Map of record primary key to record","type":"object"}},"required":["records","cursor"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List all records from a model","summary":"List model records","x-required-permissions":{"all_of":["model.get"]}}},"/models/{oid}/model/{model_name}/search":{"get":{"operationId":"substringSearchModels","tags":["Model Request"],"parameters":[{"name":"index_key_name","required":true,"description":"which index key to search for substring","schema":{"type":"string"},"in":"query"},{"name":"substring","required":true,"description":"substring to search","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"model_name","required":true,"description":"name of the model","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":{"additionalProperties":true,"description":"Model record. Fields are defined by the org's model definition and are not statically known.","type":"object"},"description":"Map of record primary key to matching record","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"model substring search","summary":"search substring for searchable indexes","x-required-permissions":{"all_of":["model.get"]}}},"/models/{oid}/query":{"get":{"operationId":"queryModels","tags":["Model Request"],"parameters":[{"name":"starting_model_name","required":true,"description":"starting model name","schema":{"type":"string"},"in":"query"},{"name":"starting_key_name","required":true,"description":"starting key name","schema":{"type":"string"},"in":"query"},{"name":"starting_key_value","required":true,"description":"starting key value","schema":{"type":"string"},"in":"query"},{"name":"plan","required":true,"description":"list of query step json records","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"additionalProperties":{"additionalProperties":true,"description":"Model record reached by the traversal; fields depend on the model's definition","type":"object"},"description":"Map of record key to the records reached by the final traversal step","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Traverse different models","summary":"Query/traverse different models","x-required-permissions":{"all_of":["model.get"]}}},"/modules/{oid}":{"post":{"operationId":"upgradeOrg","tags":["Modules"],"parameters":[{"name":"is_fallback","description":"if set to true downgrade to the previous version of the sensor, 'true' or 'false'","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"is_sleep","description":"if set to true moves sensors to dormant mode, 'true' or 'false'","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"specific_version","description":"if set, will upgrade sensors to the specific version string specified","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Update the sensor version for the organization.","summary":"Update Sensors","x-required-permissions":{"all_of":["module.update"]}}},"/online/{oid}":{"get":{"operationId":"getOnlineSensors","tags":["Sensors"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"count":{"type":"integer"},"online":{"type":"integer"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the number of sensors online belonging to the organization.","summary":"Get Online Count","x-required-permissions":{"all_of":["sensor.list"]}},"post":{"operationId":"getOnlineSensorsInList","tags":["Sensors"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"List of sensor ids to check online status for.","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"sids":{"items":{"format":"uuid","type":"string"},"type":"array"}},"type":"object"},"examples":{"basic":{"summary":"List of sensor ids","description":"List of sensor ids to check online status for.","value":{"sids":["f47ac10b-58cc-4372-a567-0e02b2c3d479","f47ac10b-58cc-4372-a567-0e02b2c3d480"]}}}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":{"type":"boolean"},"description":"Map of sensor ID to its online status","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the online status of multiple sensors.","summary":"Get Online Statuses","x-required-permissions":{"all_of":["sensor.list"]}}},"/ontology":{"get":{"operationId":"getOntology","tags":["General"],"parameters":[],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"architectures":{"additionalProperties":{"type":"integer"},"type":"object"},"native_edr_events":{"items":{"type":"string"},"type":"array"},"permissions":{"items":{"type":"string"},"type":"array"},"platforms":{"additionalProperties":{"type":"integer"},"type":"object"}},"required":["platforms","architectures","native_edr_events","permissions"],"type":"object"}}}}},"description":"Get the ontology of various components of LimaCharlie.","summary":"Get Ontology"}},"/orgs/new":{"get":{"operationId":"requestCheckOrgName","tags":["Organizations"],"parameters":[{"name":"name","required":true,"description":"organization name","schema":{"type":"string"},"in":"query"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"is_available":{"type":"boolean"}},"required":["is_available"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Check the availability of an organization mame.","summary":"Check organization name availability."},"post":{"operationId":"requestCreateOrg","tags":["Organizations"],"parameters":[{"name":"name","description":"organization name","schema":{"type":"string"},"in":"query"},{"name":"loc","description":"location where org is created","schema":{"type":"string"},"in":"query"},{"name":"template","description":"an infrastructure as code template to use to populate the org","schema":{"type":"string"},"in":"query"},{"name":"description","description":"organization description","schema":{"type":"string"},"in":"query"},{"name":"pid","description":"optional Partner id to create the organization under (requires the partner.org.create partner permission; enforces the Partner's billing precondition, creation rate limit and org ceiling)","schema":{"format":"uuid","type":"string"},"in":"query"}],"requestBody":{"description":"organization creation request","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"loc":{"type":"string"},"name":{"type":"string"},"template":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"code":{"type":"string"},"loc":{"type":"string"},"oid":{"type":"string"}},"required":["oid","code","loc"],"type":"object"},"success":{"type":"boolean"}},"required":["success","data"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Request the creation of a new organization.","summary":"Request organization creation."}},"/orgs/{oid}":{"get":{"operationId":"getOrgInfo","tags":["Organizations"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"code":{"type":"string"},"desc":{"type":"string"},"is_ready":{"type":"boolean"},"latest_versions":{"additionalProperties":false,"properties":{"experimental":{"type":"string"},"fallback":{"type":"string"},"latest":{"type":"string"}},"required":["experimental","fallback","latest"],"type":"object"},"n_installation_keys":{"type":"number"},"n_outputs":{"type":"number"},"n_rules":{"type":"number"},"name":{"type":"string"},"oid":{"type":"string"},"sensor_quota":{"type":"number"},"sensor_version":{"type":"string"},"site_name":{"type":"string"},"status":{"type":"string"}},"required":["latest_versions","n_installation_keys","n_outputs","n_rules","name","oid","sensor_quota","sensor_version","site_name","code","status","is_ready"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get information about the organization.","summary":"Get Org Info","x-required-permissions":{"all_of":["org.get"]}}},"/orgs/{oid}/acl/{scope}/resources":{"get":{"operationId":"getACLScopeResources","tags":["Organizations"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"scope","required":true,"description":"normalized ACL scope name without the acl: prefix","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"records":{"type":"object"}},"required":["records"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List configuration records carrying the requested ACL scope tag. Results are grouped by Hive and include metadata only.","summary":"Get ACL Scope Resources","x-required-permissions":{"all_of":["acl.get"]}}},"/orgs/{oid}/addons":{"get":{"operationId":"getOrgAddons","tags":["Resources"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"addons":{"additionalProperties":{"additionalProperties":{"additionalProperties":false,"properties":{"cost":{"oneOf":[{"type":"number"},{"type":"string"}]},"desc":{"type":"string"}},"type":"object"},"type":"object"},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List all addons subscribed to by an organization with details including cost and description.","summary":"Get Org Addons"}},"/orgs/{oid}/billing/details":{"get":{"operationId":"getOrgBillingDetails","tags":["Billing"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"customer":{"additionalProperties":true,"description":"Stripe Customer object with sources, subscriptions and invoice_settings.default_payment_method expanded; the shape is defined by the Stripe API and is not under LimaCharlie's control","type":"object"},"status":{"additionalProperties":false,"properties":{"is_past_due":{"type":"boolean"}},"required":["is_past_due"],"type":"object"},"unified":{"additionalProperties":false,"description":"Only present when the customer's email domain is part of a unified-billing arrangement","properties":{"customer":{"additionalProperties":true,"description":"Stripe Customer object of the unified-billing parent; the shape is defined by the Stripe API and is not under LimaCharlie's control","type":"object"},"invoice_date":{"description":"Day of the month the unified invoice is issued","type":"integer"}},"required":["customer","invoice_date"],"type":"object"},"upcoming_invoice":{"anyOf":[{"type":"null"},{"additionalProperties":true,"description":"Stripe Invoice object with up to 100 upcoming lines (plan products expanded); the shape is defined by the Stripe API and is not under LimaCharlie's control","type":"object"}]}},"required":["customer","status","upcoming_invoice"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get comprehensive billing details for an organization including Stripe customer, subscription status, and upcoming invoice.","summary":"Get Org Billing Details","x-required-permissions":{"all_of":["org.get","billing.ctrl"]}}},"/orgs/{oid}/billing/invoice/{year}/{month}":{"get":{"operationId":"getOrgInvoiceForMonth","tags":["Billing"],"parameters":[{"name":"format","description":"output format: json, simple_json, simple_csv, or empty for URL only","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"year","required":true,"description":"invoice year (YYYY)","schema":{"type":"string"},"in":"path"},{"name":"month","required":true,"description":"invoice month (MM)","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"anyOf":[{"additionalProperties":false,"description":"Default response (no format specified)","properties":{"url":{"description":"Stripe hosted invoice URL","type":"string"}},"required":["url"],"type":"object"},{"additionalProperties":false,"description":"format=json response","properties":{"invoice":{"additionalProperties":true,"description":"Stripe Invoice object with all lines (plan products expanded); the shape is defined by the Stripe API and is not under LimaCharlie's control","type":"object"}},"required":["invoice"],"type":"object"},{"additionalProperties":false,"description":"format=simple_json response","properties":{"lines":{"items":{"additionalProperties":false,"properties":{"amount":{"type":"integer"},"description":{"type":"string"},"product":{"type":"string"},"quantity":{"type":"integer"},"scheme":{"type":"string"},"unit_amount":{"type":"integer"}},"required":["product","amount","unit_amount","scheme","quantity","description"],"type":"object"},"type":"array"}},"required":["lines"],"type":"object"},{"additionalProperties":false,"description":"format=simple_csv response","properties":{"csv":{"description":"CSV rendering of the simplified invoice lines","type":"string"}},"required":["csv"],"type":"object"}]}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the URL or data of a single invoice created in a specific month (bucketed by creation date): the first paid or open invoice found. An org can have several invoices for one billing period, so this can omit charges. To get every invoice of a billing period, use GET /orgs/{oid}/billing/invoices/{year}/{month}, which buckets invoices by accrual period rather than creation date, so the two routes do not return the same invoices for a given month.","summary":"Get Org Invoice For Month","x-required-permissions":{"all_of":["org.get","billing.ctrl"]}}},"/orgs/{oid}/billing/invoices/{year}/{month}":{"get":{"operationId":"getOrgInvoicesForBillingPeriod","tags":["Billing"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"year","required":true,"description":"billing period year (YYYY)","schema":{"type":"string"},"in":"path"},{"name":"month","required":true,"description":"billing period month (MM)","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"complete":{"description":"True when no more invoices can appear for this billing period: the org has no Stripe customer or subscription, or the month is over and its subscription is in a period ending after the month (so the cycle invoice of any period ending in the month has been cut), and no invoice of the period is still a draft. False for the current month, while the cycle invoice of a period ending in the month has not been cut yet, and while Stripe holds a new invoice as a draft (about an hour). Totals of an incomplete period will change.","type":"boolean"},"invoices":{"items":{"additionalProperties":false,"properties":{"billing_reason":{"description":"Stripe billing reason, e.g. subscription_cycle, subscription_update or manual","type":"string"},"created":{"description":"Unix seconds","type":"integer"},"currency":{"type":"string"},"discount":{"description":"Sum of lines[].discount in cents (item and invoice level discounts)","type":"integer"},"hosted_invoice_url":{"type":"string"},"id":{"type":"string"},"lines":{"items":{"additionalProperties":false,"properties":{"amount":{"description":"Line amount in cents before discounts; negative for credits and proration refunds","type":"integer"},"description":{"type":"string"},"discount":{"description":"Discount applied to this line in cents","type":"integer"},"id":{"type":"string"},"period_end":{"description":"Unix seconds","type":"integer"},"period_start":{"description":"Start of the period this line pays for, unix seconds. Licensed (per-unit) fees are billed in advance, so on a cycle invoice they cover the month after the invoice's own period.","type":"integer"},"plan_id":{"description":"Stripe plan ID, else price ID for one-off prices, else empty","type":"string"},"product":{"description":"Product description (from the plan, else the price), else plan_id","type":"string"},"proration":{"type":"boolean"},"quantity":{"type":"integer"},"unit_amount":{"description":"Unit price in cents; a decimal number because per-unit prices can be fractions of a cent. For tiered prices, which have no single unit price, it is amount / quantity.","type":"number"}},"required":["id","description","product","plan_id","quantity","unit_amount","amount","discount","proration","period_start","period_end"],"type":"object"},"type":"array"},"number":{"type":"string"},"period_end":{"description":"Unix seconds","type":"integer"},"period_start":{"description":"Unix seconds","type":"integer"},"status":{"description":"paid, open or uncollectible","type":"string"},"subtotal":{"description":"Sum of lines[].amount in cents, before all discounts (item and invoice level) and exclusive tax","type":"integer"},"tax":{"description":"Exclusive tax in cents added on top of subtotal - discount (tax included in line amounts is not counted here)","type":"integer"},"total":{"description":"What the org was charged overall for this invoice, in cents: subtotal - discount + tax. For unified billing orgs the UNIFIED-BILLING line is excluded, so this is the org's share of the parent invoice.","type":"integer"},"unified_billing":{"description":"True when the invoice carries the UNIFIED-BILLING line that zeroes it, i.e. its total is charged on the unified billing parent invoice instead","type":"boolean"}},"required":["id","number","status","billing_reason","created","period_start","period_end","currency","subtotal","discount","tax","total","unified_billing","hosted_invoice_url","lines"],"type":"object"},"type":"array"},"month":{"type":"integer"},"pending_invoices":{"description":"Number of draft invoices of this billing period, not yet included in invoices","type":"integer"},"year":{"type":"integer"}},"required":["year","month","invoices","complete","pending_invoices"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"429":{"description":"Stripe or this endpoint is rate limited; retry after the Retry-After delay","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"Stripe is temporarily unavailable; retry after the Retry-After delay","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get every finalized (paid, open or uncollectible) invoice of billing period year-month, sorted by creation time. Billing period M is every invoice cut during M, plus the regular monthly (subscription_cycle) invoice of a subscription period ending in M, including one ending exactly at the start of M+1: for a subscription anchored on the 1st, the invoice cut at the start of M+1 for M's usage and M+1's licensed (per-sensor) fees billed in advance. Formally, an invoice belongs to M when min(created, period_end) falls in (start of M, start of M+1], UTC. This matches how org invoices roll up into the unified billing parent invoice cut early in M+1. Assumes monthly subscriptions. complete tells whether more invoices can still appear for the period (current month, subscription period ending in M not invoiced yet, invoices Stripe still holds as drafts). Amounts are integer cents (unit_amount may be fractional) and reflect what the org was actually charged: for unified billing orgs the zeroing UNIFIED-BILLING line is excluded, so total is what the org was charged overall, i.e. its share of the parent invoice. For every invoice, subtotal - discount + tax = total.","summary":"Get Org Invoices For Billing Period","x-required-permissions":{"all_of":["org.get","billing.ctrl"]}}},"/orgs/{oid}/billing/quota":{"post":{"operationId":"requestOrgBillingQuota","tags":["Billing"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"Quota change request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"quota":{"type":"integer"}},"required":["quota"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"type":"object"},"is_success":{"type":"boolean"}},"required":["is_success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Request a quota (sensor count) change for an organization.","summary":"Request Org Billing Quota","x-required-permissions":{"all_of":["billing.ctrl"]}}},"/orgs/{oid}/billing/sku":{"get":{"operationId":"getOrgSkuDefinitions","tags":["Billing"],"parameters":[{"name":"sku","description":"Optional metered SKU identifier; omitted returns all SKUs.","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"skus":{"items":{"type":"object"},"type":"array"}},"required":["skus"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get metered SKU definitions with metadata and current Stripe pricing for an organization.","summary":"Get Org SKU Definitions","x-required-permissions":{"all_of":["org.get"]}}},"/orgs/{oid}/billing/status":{"get":{"operationId":"getOrgBillingStatus","tags":["Billing"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"is_past_due":{"type":"boolean"},"org_name":{"type":"string"}},"required":["is_past_due","org_name"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the billing status (past due or not) for an organization.","summary":"Get Org Billing Status","x-required-permissions":{"all_of":["org.get"]}}},"/orgs/{oid}/delete":{"delete":{"operationId":"completeOrgDelete","tags":["Organizations"],"parameters":[{"name":"confirmation","required":true,"description":"confirmation token obtained during initialization","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"data":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"},"success":{"type":"boolean"}},"required":["data","success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"Deletion is pending; retry the same confirmation. Retry-After specifies the retry delay.","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"reason":{"type":"string"},"retryable":{"type":"boolean"}},"type":"object"}}}}},"description":"Complete the deletion process for an organization.","summary":"Complete Org Delete","x-required-permissions":{"all_of":["billing.ctrl","user.ctrl"]}},"get":{"operationId":"initOrgDelete","tags":["Organizations"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"confirmation":{"description":"confirmation token","title":"confirmation","type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"503":{"description":"A deletion is running or confirmation storage is unavailable; retry after Retry-After.","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"reason":{"type":"string"},"retryable":{"type":"boolean"}},"type":"object"}}}}},"description":"Initiate the deletion process for an organization.","summary":"Start Delete Org","x-required-permissions":{"all_of":["billing.ctrl","user.ctrl"]}}},"/orgs/{oid}/invoice_url/{year}/{month}":{"get":{"operationId":"getLegacyOrgInvoices","tags":["Billing"],"parameters":[{"name":"format","description":"json, simple_json, simple_csv, or empty for invoice URLs","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"year","required":true,"description":"invoice year","schema":{"type":"string"},"in":"path"},{"name":"month","required":true,"description":"invoice month","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"Legacy invoice response","content":{"application/json":{"schema":{"additionalProperties":true,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Compatibility endpoint for the legacy billing SDK. Returns paid/open invoices whose billing periods overlap the requested month, searched within two days of its creation boundaries. JSON returns invoice for one match or invoices for several. URL format returns url and, for multiple matches, urls. The overlap contract can return the same off-cycle invoice in adjacent months; do not sum months without deduplicating invoice IDs. Results are newest-first by creation time and ID. Prefer /billing/invoices/{year}/{month} for unique accrual-period attribution.","summary":"Get Legacy Org Invoices","x-required-permissions":{"all_of":["org.get","billing.ctrl"]}}},"/orgs/{oid}/keys":{"delete":{"operationId":"removeOrgApiKey","tags":["Api Keys"],"parameters":[{"name":"key_hash","description":"hash of the key to remove","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove an API key from an organization.","summary":"Remove API Key","x-required-permissions":{"all_of":["apikey.ctrl"]}},"get":{"operationId":"getOrgApiKeys","tags":["Api Keys"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"api_keys":{"additionalProperties":{"additionalProperties":false,"properties":{"allowed_ip_range":{"type":"string"},"by":{"type":"string"},"last_used":{"type":"integer"},"name":{"type":"string"},"priv":{"items":{"type":"string"},"type":"array"}},"required":["name","last_used"],"type":"object"},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List API keys in organization.","summary":"Get API Keys","x-required-permissions":{"all_of":["apikey.ctrl"]}},"post":{"operationId":"addOrgApiKey","tags":["Api Keys"],"parameters":[{"name":"key_name","description":"name of the key to add","schema":{"type":"string"},"in":"query"},{"name":"perms","description":"comma separated values of the permissions of the key to add","schema":{"type":"string"},"in":"query"},{"name":"allowed_ip_range","description":"optional CIDR of the allowed IP ranges of the key to add","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"allowed_ip_range":{"type":"string"},"api_key":{"type":"string"},"key_hash":{"type":"string"},"key_name":{"type":"string"},"perms":{"items":{"type":"string"},"type":"array"},"success":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Add a new user to the organization.","summary":"Add API Key","x-required-permissions":{"all_of":["apikey.ctrl"]}}},"/orgs/{oid}/name":{"post":{"operationId":"renameOrg","tags":["Organizations"],"parameters":[{"name":"name","description":"new name for the organization","schema":{"type":"string"},"in":"query"},{"name":"description","description":"new description for the organization","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"new_name":{"type":"string"},"oid":{"type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Rename an organization.","summary":"Org Rename","x-required-permissions":{"all_of":["billing.ctrl"]}}},"/orgs/{oid}/org_create_status":{"get":{"operationId":"getOrgCreateStatus","tags":["Api Keys"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"org_create_steps":{"oneOf":[{"additionalProperties":false,"properties":{"step1_starting_org_creation":{"type":"integer"},"step2_max_org_check_passed":{"type":"integer"},"step3_org_record_created":{"type":"integer"},"step4_stripe_customer_created":{"type":"integer"},"step5_stripe_subscription_created":{"type":"integer"},"step6_org_creation_succeeded":{"type":"integer"}},"type":"object"},{"type":"null"}]}},"required":["org_create_steps"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get org creation status steps","summary":"Get org create status","x-required-permissions":{"all_of":["org.get"]}}},"/orgs/{oid}/quota":{"post":{"operationId":"setOrgQuota","tags":["Billing"],"parameters":[{"name":"quota","description":"new sensor quota to request for organization","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Request a new sensor quota for an organization.","summary":"Set Org Quota","x-required-permissions":{"all_of":["billing.ctrl"]}}},"/orgs/{oid}/resources":{"delete":{"operationId":"unregisterOrgFromResource","tags":["Resources"],"parameters":[{"name":"res_cat","description":"resource category of the resource to unsubscribe from, like 'lookup'","schema":{"type":"string"},"in":"query"},{"name":"res_name","description":"resource name of the resource to unsubscribe from","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Unsubscribe an organization from a resource.","summary":"Unsubscribe Org to Resource","x-required-permissions":{"all_of":["billing.ctrl"]}},"get":{"operationId":"getOrgResources","tags":["Resources"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"resources":{"additionalProperties":{"items":{"type":"string"},"type":"array"},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List all resources subscribed to by an organization.","summary":"Get Org Resources"},"post":{"operationId":"registerOrgToResource","tags":["Resources"],"parameters":[{"name":"res_cat","description":"resource category of the resource to subscribe to, like 'lookup'","schema":{"type":"string"},"in":"query"},{"name":"res_name","description":"resource name of the resource to subscribe to","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Subscribe the organization to a resource.","summary":"Subscribe Org to Resource","x-required-permissions":{"all_of":["billing.ctrl"]}}},"/orgs/{oid}/schema":{"delete":{"operationId":"resetOrgSchemas","tags":["Schema"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Reset all schemas in organization. The name parameter is not supported; individual schemas cannot be reset.","summary":"Reset Org Schemas","x-required-permissions":{"all_of":["org.get"]}},"get":{"operationId":"getOrgSchemas","tags":["Schema"],"parameters":[{"name":"platform","description":"Optional platform name to filter the event types by.","schema":{"type":"string"},"in":"query"},{"name":"name","description":"Schema name or prefix; omit to list available schemas","schema":{"minLength":1,"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"anyOf":[{"additionalProperties":false,"properties":{"event_types":{"items":{"type":"string"},"type":"array"}},"type":"object"},{"anyOf":[{"additionalProperties":false,"properties":{"schema":{"additionalProperties":false,"properties":{"elements":{"items":{"description":"Schema element key, prefixed with a 1-letter data type (s = string, i = integer, b = boolean)","type":"string"},"type":"array"},"event_type":{"type":"string"}},"required":["event_type","elements"],"type":"object"}},"required":["schema"],"type":"object"},{"additionalProperties":false,"properties":{"schemas":{"additionalProperties":{"items":{"description":"Schema element key, prefixed with a 1-letter data type (s = string, i = integer, b = boolean)","type":"string"},"type":"array"},"description":"Map of event type to its schema elements","type":"object"}},"required":["schemas"],"type":"object"}]}]}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List the learned event schemas in an organization. With name, return one schema (for example evt:DNS_REQUEST), or all schemas under a prefix (for example evt:). An empty name is invalid. platform filters the list only.","summary":"Get Org Schemas","x-required-permissions":{"all_of":["org.get"]}}},"/orgs/{oid}/status":{"get":{"operationId":"getOrgStatus","tags":["Organizations"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"code":{"type":"string"},"is_ready":{"type":"boolean"},"name":{"type":"string"},"oid":{"type":"string"},"status":{"type":"string"}},"required":["oid","code","name","status","is_ready"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get organization initialization status for polling during creation.","summary":"Get Org Status"}},"/orgs/{oid}/stories":{"get":{"operationId":"listStories","tags":["Organizations"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"stories":{"items":{"type":"string"},"type":"array"}},"required":["stories"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List the names of all lc:story:* stories defined in the org. A story exists wherever at least one component carries a tag matching lc:story:NAME[:...].","summary":"List Stories"}},"/orgs/{oid}/stories/{name}":{"get":{"operationId":"getStory","tags":["Organizations"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"name","required":true,"description":"story name (slug, ^[a-z0-9][a-z0-9_-]{0,63}$)","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"edges":{"items":{"additionalProperties":false,"properties":{"from":{"type":"string"},"label":{"type":"string"},"origin":{"enum":["derived","declared"]},"to":{"type":"string"}},"required":["from","to","origin"],"type":"object"},"type":"array"},"name":{"type":"string"},"nodes":{"items":{"additionalProperties":false,"properties":{"id":{"type":"string"},"label":{"type":"string"},"name":{"type":"string"},"type":{"type":"string"}},"required":["id","type","name"],"type":"object"},"type":"array"}},"required":["name","nodes","edges"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the assembled graph for one lc:story:NAME story: the set of components carrying lc:story:NAME[:...] tags plus the directed edges between them. Edges are derived from the member records' own configuration (origin: derived) or declared with links: tags (origin: declared).","summary":"Get Story"}},"/orgs/{oid}/subscription/extension/{extensionName}":{"delete":{"operationId":"deleteExtensionSubscription","tags":["Extensions"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"extensionName","required":true,"description":"extension name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Delete extension subscription","summary":"Delete extension subscription","x-required-permissions":{"all_of":["billing.ctrl"]}},"patch":{"operationId":"reKeyExtensionSubscription","tags":["Extensions"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"extensionName","required":true,"description":"extension name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Re-key extension subscription","summary":"Re-key extension subscription","x-required-permissions":{"all_of":["billing.ctrl","user.ctrl"]}},"post":{"operationId":"createExtensionSubscription","tags":["Extensions"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"extensionName","required":true,"description":"extension name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Create extension subscription","summary":"Create extension subscription","x-required-permissions":{"all_of":["billing.ctrl","user.ctrl"]}}},"/orgs/{oid}/subscriptions":{"get":{"operationId":"getOrgSubscriptions","tags":["Extensions","Extensions"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"An array of Extension Subscriptions","content":{"application/json":{"schema":{"additionalProperties":{"additionalProperties":false,"properties":{"extension_name":{"type":"string"},"is_labs":{"type":"boolean"},"is_public":{"type":"boolean"},"key_name":{"type":"string"},"label":{"type":"string"},"oid":{"type":"string"},"org_name":{"type":"string"}},"required":["extension_name","org_name","oid","key_name","is_public","is_labs","label"],"type":"object"},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get all org extension subscriptions","summary":"Get all org extension subscriptions","x-required-permissions":{"any_of":["billing.ctrl","ext.request","ext.conf.set","ext.conf.del","ext.conf.get","ext.conf.set.mtd","ext.conf.get.mtd"]}}},"/orgs/{oid}/ui_actions":{"get":{"operationId":"getUIActions","tags":["Hive"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"actions":{"items":{"additionalProperties":false,"properties":{"label":{"type":"string"},"location":{"type":"string"},"record_name":{"type":"string"},"source_hive":{"type":"string"}},"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get all UI actions defined in the organization's hive records. This is a synchronous call that returns immediately.","summary":"Get UI Actions","x-required-permissions":{"all_of":["org.get"]}}},"/orgs/{oid}/ui_actions/execute":{"post":{"operationId":"executeUIAction","tags":["Hive"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"request object. context_data is a JSON-serialized string passed as playbook parameters or appended to the AI agent prompt.","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"context_data":{"type":"string"},"record_name":{"type":"string"},"source_hive":{"type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"description":"For source_hive=playbook: the extension-manager dispatch acknowledgement. For source_hive=ai_agent: session metadata from the AI Sessions service. Both shapes are defined by the downstream service.","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Execute a UI action from a hive record. This is an asynchronous call that returns immediately. For playbook actions (source_hive=playbook), the playbook execution is dispatched in the background. For AI agent actions (source_hive=ai_agent), an AI session is created and the session metadata is returned; the actual AI execution continues in the background.","summary":"Execute UI Action","x-required-permissions":{"any_of":["ext.request","ai_agent.exec"]}}},"/orgs/{oid}/url":{"get":{"operationId":"getOrgURLs","tags":["Organizations"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"allowlist_ips":{"additionalProperties":{"items":{"type":"string"},"type":"array"},"description":"Static IPs to allow for each hostname, primary first then standby. Every listed address must be allowed.","title":"Allowlist IPs","type":"object"},"certs":{"anyOf":[{"type":"null"},{"additionalProperties":{"type":"string"},"type":"object"}]},"site_name":{"type":"string"},"url":{"additionalProperties":false,"properties":{"ai":{"type":"string"},"artifacts":{"type":"string"},"cases":{"type":"string"},"edr":{"type":"string"},"hooks":{"type":"string"},"lc":{"type":"string"},"lc_wss":{"type":"string"},"live":{"type":"string"},"logs":{"type":"string"},"private_endpoints":{"additionalProperties":{"type":"boolean"},"type":"object"},"region_code":{"type":"string"},"replay":{"type":"string"},"search":{"type":"string"}},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the various access URLs used by resources related to the organization.","summary":"Get Org URLs"}},"/orgs/{oid}/users":{"delete":{"operationId":"removeOrgUser","tags":["Users"],"parameters":[{"name":"email","description":"email of the user to remove","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove a user from an organization.","summary":"Remove Org User","x-required-permissions":{"all_of":["user.ctrl"]}},"get":{"operationId":"getOrgUsers","tags":["Users"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"users":{"items":{"type":"string"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List all users in organization.","summary":"Get Org Users","x-required-permissions":{"all_of":["user.ctrl"]}},"post":{"operationId":"addOrgUser","tags":["Users"],"parameters":[{"name":"email","description":"email of the user to add","schema":{"type":"string"},"in":"query"},{"name":"invite_missing","description":"if the user does not exist, send an invite","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"role","description":"role to assign to the user (Owner, Administrator, Operator, Viewer, Basic). If not provided, defaults to Basic.","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"invite_sent":{"description":"Only present when the user did not exist and invite_missing was set: an invite email was sent instead of adding the user","type":"boolean"},"role":{"description":"Role assigned to the user; only present when the user was newly added","type":"string"},"success":{"description":"Present when the user was added to the organization (or already was a member)","type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Add a new user to the organization.","summary":"Add Org User","x-required-permissions":{"all_of":["user.ctrl"]}}},"/orgs/{oid}/users/permissions":{"delete":{"operationId":"removeUserPermission","tags":["Users"],"parameters":[{"name":"email","description":"email of the user to remove the permission from","schema":{"type":"string"},"in":"query"},{"name":"perm","description":"permission to remove","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove a user permission.","summary":"Remove User Permission","x-required-permissions":{"all_of":["user.ctrl"]}},"get":{"operationId":"getUsersAndPermissions","tags":["Users"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"direct_users":{"items":{"additionalProperties":false,"properties":{"MFA_enabled":{"type":"boolean"},"MFA_types":{"items":{"type":"string"},"type":"array"},"auth_providers":{"items":{"type":"string"},"type":"array"},"email":{"type":"string"},"perms":{"items":{"type":"string"},"type":"array"},"uid":{"type":"string"}},"required":["email","uid","perms"],"type":"object"},"type":"array"},"from_groups":{"additionalProperties":{"additionalProperties":false,"properties":{"MFA_enabled":{"type":"boolean"},"MFA_types":{"items":{"type":"string"},"type":"array"},"auth_providers":{"items":{"type":"string"},"type":"array"},"email":{"type":"string"},"groups":{"additionalProperties":{"type":"boolean"},"type":"object"},"hasDirectAccess":{"type":"boolean"},"is_admin":{"type":"boolean"}},"required":["email","groups"],"type":"object"},"type":"object"},"group_info":{"additionalProperties":{"additionalProperties":false,"properties":{"name":{"type":"string"},"owners":{"items":{"type":"string"},"type":"array"},"perms":{"items":{"type":"string"},"type":"array"}},"type":"object"},"type":"object"},"user_permissions":{"additionalProperties":{"items":{"type":"string"},"type":"array"},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List all users and permissions in organization.","summary":"Get User Permissions","x-required-permissions":{"all_of":["user.ctrl"]}},"post":{"operationId":"addUserPermission","tags":["Users"],"parameters":[{"name":"email","description":"email of the user to add a permission to","schema":{"type":"string"},"in":"query"},{"name":"perm","description":"permission to give","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Add a new user to the organization.","summary":"Add User Permission","x-required-permissions":{"all_of":["user.ctrl"]}}},"/outputs/{oid}":{"delete":{"operationId":"removeOutput","tags":["Outputs"],"parameters":[{"name":"name","description":"output module name to disable","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"JSON encoded string of the request data","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"name":{"description":"output module name to disable","title":"name","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Disable a specific output module for an organization.","summary":"Remove Output","x-required-permissions":{"any_of":["output.del","live_stream.ctrl"]}},"get":{"operationId":"getOutputs","tags":["Outputs"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":{"additionalProperties":true,"properties":{"by":{"description":"who created the output","title":"by","type":"string"},"for":{"description":"data type for output","title":"for","type":"string"},"is_built_in":{"description":"if the output is built in","title":"is built in","type":"boolean"},"module":{"description":"output module name to enable","title":"module","type":"string"},"name":{"description":"what to name this output","title":"name","type":"string"},"oid":{"description":"organization id","title":"oid","type":"string"}},"type":"object"},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the various outputs for an organization.","summary":"Get Outputs","x-required-permissions":{"all_of":["output.list"]}},"post":{"operationId":"setOutput","tags":["Outputs"],"parameters":[{"name":"module","description":"output module name to enable","schema":{"type":"string"},"in":"query"},{"name":"type","description":"data type for output","schema":{"type":"string"},"in":"query"},{"name":"name","description":"what to name this output","schema":{"type":"string"},"in":"query"},{"name":"inv_id","description":"if specified, only events part of this investigation id will be sent to this output","schema":{"type":"string"},"in":"query"},{"name":"tag","description":"if specified, only events coming from sensors with the specific tag will be sent to this output","schema":{"type":"string"},"in":"query"},{"name":"acl_scopes","description":"ACL scope names whose restricted records this output may receive; omitted means restricted records are excluded","schema":{"items":{"type":"string"},"type":"array"},"in":"query"},{"name":"cat","description":"if specified, only detections in this category will be sent to this output","schema":{"type":"string"},"in":"query"},{"name":"is_flat","description":"if the json should be flattened (true, false)","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"is_compression","description":"if data should be sent compressed (true, false)","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"dir","description":"directory for output","schema":{"type":"string"},"in":"query"},{"name":"max_bytes","description":"max size in bytes before rotation","schema":{"type":"string"},"in":"query"},{"name":"backup_count","description":"maximum number of output in rotation","schema":{"type":"string"},"in":"query"},{"name":"bucket","description":"name of the bucket for output","schema":{"type":"string"},"in":"query"},{"name":"key_id","description":"public key id for auth","schema":{"type":"string"},"in":"query"},{"name":"sec_per_file","description":"seconds per output files","schema":{"type":"string"},"in":"query"},{"name":"dest_host","description":"destination host for output","schema":{"type":"string"},"in":"query"},{"name":"username","description":"username for auth","schema":{"type":"string"},"in":"query"},{"name":"slack_channel","description":"slack channel to output to","schema":{"type":"string"},"in":"query"},{"name":"is_tls","description":"whether connection should be secured over tls (true, false)","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"is_no_header","description":"whether protocol header should be sent before the data (true, false)","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"is_delete_on_failure","description":"if enabled, the output will be deleted as soon as a connection error occurs (true, false)","schema":{"type":"string"},"in":"query"},{"name":"event_white_list","description":"whitelist of event types to allow","schema":{"type":"string"},"in":"query"},{"name":"event_black_list","description":"blacklist of event types to disallow","schema":{"type":"string"},"in":"query"},{"name":"cat_black_list","description":"blacklist of categories to disallow","schema":{"type":"string"},"in":"query"},{"name":"routing_topic","description":"topic to publish on from the routing of then event","schema":{"type":"string"},"in":"query"},{"name":"literal_topic","description":"literal topic to publish on","schema":{"type":"string"},"in":"query"},{"name":"is_no_routing","description":"if true, do not include event routing, acts as an event pass-through","schema":{"type":"string"},"in":"query"},{"name":"sample_rate","description":"sample events out as 1/sample_rate","schema":{"type":"string"},"in":"query"},{"name":"is_payload_as_string","description":"include the event as a JSON string instead of a JSON object","schema":{"type":"string"},"in":"query"},{"name":"is_prefix_data","description":"encapsulate the data inside a JSON object with a key equal to the event type","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"JSON encoded string of the request data","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"custom_transform":{"description":"custom transform expression","title":"custom transform","type":"string"},"module":{"description":"output module name to enable","title":"module","type":"string"},"name":{"description":"what to name this output","title":"name","type":"string"},"password":{"description":"password for auth","title":"password","type":"string"},"secret_key":{"description":"secret key for auth","title":"secret key","type":"string"},"slack_api_token":{"description":"slack api token","title":"slack api token","type":"string"},"structured_data":{"description":"structured data expression","title":"structured data","type":"string"},"type":{"description":"data type for output","title":"type","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"properties":{"by":{"description":"who created the output","title":"by","type":"string"},"for":{"description":"data type for output","title":"for","type":"string"},"is_built_in":{"description":"if the output is built in","title":"is built in","type":"boolean"},"module":{"description":"output module name to enable","title":"module","type":"string"},"name":{"description":"what to name this output","title":"name","type":"string"},"oid":{"description":"organization id","title":"oid","type":"string"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"The content is restricted by an acl: scope tag the caller does not hold","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"description":"ACL_CONTENT_RESTRICTED","type":"string"}},"type":"object"}}}}},"description":"Enable a specific output module for an organization.","summary":"Set Output","x-required-permissions":{"any_of":["output.set","live_stream.ctrl"]}}},"/outputs/{oid}/samples":{"get":{"operationId":"getOutputSamples","tags":["Outputs"],"parameters":[{"name":"name","required":true,"description":"output module name to get samples from","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"items":{"additionalProperties":false,"properties":{"sample":{"items":{"oneOf":[{"type":"null"},{"type":"string"}]},"type":"array"}},"required":["sample"],"type":"object"},"type":"array"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"The content is restricted by an acl: scope tag the caller does not hold","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"description":"ACL_CONTENT_RESTRICTED","type":"string"}},"type":"object"}}}}},"description":"Get sample data from an Output.","summary":"Get Output Samples","x-required-permissions":{"all_of":["output.list"]}}},"/partners/{pid}":{"get":{"operationId":"getPartner","tags":["Partners"],"parameters":[{"name":"pid","required":true,"description":"partner id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"billing_enabled":{"description":"Whether this Partner can receive organizations. Same meaning as the field of this name on GET /user/partners","type":"boolean"},"description":{"type":"string"},"linked_domains":{"items":{"type":"string"},"type":"array"},"name":{"type":"string"},"pid":{"type":"string"},"policy":{"additionalProperties":false,"properties":{"creation_rate_count":{"type":"integer"},"creation_rate_window_seconds":{"type":"integer"},"org_ceiling":{"type":"integer"}},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get a Partner: name, creation policy, whether consolidated billing is enabled, and linked domains. Requires the 'partner.org.list' partner permission (DB-enforced).","summary":"Get partner"}},"/partners/{pid}/admins":{"delete":{"operationId":"removePartnerAdmin","tags":["Partners"],"parameters":[{"name":"email","required":true,"description":"email of the user to revoke partner permissions from","schema":{"type":"string"},"in":"query"},{"name":"pid","required":true,"description":"partner id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove a user's partner_admins row — instant revocation (no cache in the partner authorization path). Refuses to remove the partner owner's row (owner transfer is internal-only). Requires the 'partner.ctrl' partner permission (DB-enforced).","summary":"Remove partner admin"},"get":{"operationId":"listPartnerAdmins","tags":["Partners"],"parameters":[{"name":"pid","required":true,"description":"partner id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"admins":{"items":{"additionalProperties":false,"properties":{"email":{"type":"string"},"is_owner":{"type":"boolean"},"permissions":{"items":{"type":"string"},"type":"array"},"uid":{"type":"string"}},"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List the Partner's admins and the partner permissions each holds. Requires the 'partner.ctrl' partner permission (DB-enforced).","summary":"List partner admins"},"post":{"operationId":"setPartnerAdmin","tags":["Partners"],"parameters":[{"name":"email","required":true,"description":"email of the user to grant partner permissions to","schema":{"type":"string"},"in":"query"},{"name":"permissions","description":"partner permissions to grant (repeated); mutually exclusive with role","schema":{"type":"string"},"in":"query"},{"name":"role","description":"partner role preset (Partner Owner, Partner Administrator, Partner Operator, Partner Viewer); mutually exclusive with permissions","schema":{"type":"string"},"in":"query"},{"name":"pid","required":true,"description":"partner id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"success":{"type":"boolean"}},"required":["success"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Grant (or overwrite) a user's partner permissions, by explicit list or role preset. Refuses writes to the partner owner's row (owner changes are internal-only). Requires the 'partner.ctrl' partner permission (DB-enforced).","summary":"Set partner admin"}},"/partners/{pid}/groups":{"get":{"operationId":"listPartnerGroups","tags":["Partners"],"parameters":[{"name":"pid","required":true,"description":"partner id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"groups":{"items":{"additionalProperties":false,"properties":{"gid":{"type":"string"},"name":{"type":"string"}},"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List the organization groups owned by a Partner. Requires the 'partner.org.list' partner permission (DB-enforced).","summary":"List partner groups"}},"/partners/{pid}/orgs":{"get":{"operationId":"listPartnerOrgs","tags":["Partners"],"parameters":[{"name":"pid","required":true,"description":"partner id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"orgs":{"items":{"additionalProperties":false,"properties":{"billing_plan":{"type":"string"},"external_groups":{"items":{"type":"string"},"type":"array"},"name":{"type":"string"},"oid":{"type":"string"},"status":{"type":"string"}},"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List the organizations owned by a Partner, including per-org non-partner groups that span them (access paths the Partner does not own). Requires the 'partner.org.list' partner permission (DB-enforced).","summary":"List partner orgs"}},"/partners/{pid}/orgs/attach":{"post":{"operationId":"attachPartnerOrg","tags":["Partners"],"parameters":[{"name":"oid","required":true,"description":"organization id to attach","schema":{"format":"uuid","type":"string"},"in":"query"},{"name":"pid","required":true,"description":"partner id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"oid":{"type":"string"},"resumed":{"description":"True when the control-plane half was already done and only the billing metadata was (re)applied","type":"boolean"},"success":{"type":"boolean"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Bring an existing organization under the Partner: writes orgs.pid and swaps the subscription metadata to the partner keys (clearing any self_billed marker; no billing-cycle anchor change). Requires the 'partner.org.attach' partner permission (DB-enforced) AND user.ctrl on the target organization. Idempotent: re-running an attach whose billing-metadata step failed resumes at that step.","summary":"Attach an organization to a Partner"}},"/payload/{oid}":{"get":{"operationId":"listPayloads","tags":["Payload"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"payloads":{"additionalProperties":{"additionalProperties":false,"properties":{"by":{"type":"string"},"created":{"type":"integer"},"name":{"type":"string"},"oid":{"type":"string"},"put_url":{"type":"string"},"size":{"type":"integer"}},"required":["name","oid","by","created","size"],"type":"object"},"type":"object"},"replicants":{"items":{"type":"string"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the list of existing payloads.","summary":"List Payloads","x-required-permissions":{"all_of":["payload.ctrl"]}}},"/payload/{oid}/{payloadName}":{"delete":{"operationId":"removePayload","tags":["Payload"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"payloadName","required":true,"description":"payload name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"description":"Empty acknowledgement object","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove an existing payload.","summary":"Remove Payload","x-required-permissions":{"all_of":["payload.ctrl"]}},"get":{"operationId":"getPayload","tags":["Payload"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"payloadName","required":true,"description":"payload name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"get_url":{"type":"string"}},"required":["get_url"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the content of a payload.","summary":"Get Payload","x-required-permissions":{"all_of":["payload.ctrl"]}},"post":{"operationId":"addPayload","tags":["Payload"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"payloadName","required":true,"description":"payload name","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"put_url":{"description":"Signed URL to HTTP PUT the payload content to","type":"string"}},"required":["put_url"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Create a new payload.","summary":"Add Payload","x-required-permissions":{"all_of":["payload.ctrl"]}}},"/plans":{"get":{"operationId":"getAvailablePlans","tags":["Users"],"parameters":[],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"plans":{"items":{"additionalProperties":false,"properties":{"id":{"type":"string"},"name":{"type":"string"},"region":{"type":"string"}},"required":["id","name","region"],"type":"object"},"type":"array"}},"required":["plans"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the list of plans available for the authenticated user based on their email domain.","summary":"Get Available Plans"}},"/quota_usage/{oid}":{"get":{"operationId":"getOrgQuotaUsage","tags":["Sensors"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"breakdown":{"type":"object"},"quota":{"type":"integer"},"usage":{"type":"integer"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the enforced sensor quota usage for the organization. This is the weighted virtual-sensor count the platform actually uses to decide whether a sensor may come online, so it is the value to size sensor_quota against. It can read higher than the /online count, which weights EPP/response-mode sensors at 0.","summary":"Get Sensor Quota Usage","x-required-permissions":{"all_of":["sensor.list"]}}},"/runtime_mtd/{oid}":{"get":{"operationId":"getRuntimeMtd","tags":["General"],"parameters":[{"name":"entity_type","description":"optionally return only entities of a specific type","schema":{"type":"string"},"in":"query"},{"name":"entity_name","description":"optionally return only the entity with the given name","schema":{"type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"entities":{"description":"Array of entity metadata objects","items":{"additionalProperties":true,"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the runtime metadata of various entities running in an org.","summary":"Get Runtime Metadata","x-required-permissions":{"any_of":["sensor.list","cloudsensor.get"]}}},"/sensors/{oid}":{"get":{"operationId":"getSensorList","tags":["Sensors"],"parameters":[{"name":"continuation_token","description":"optional token provided as a previous response to fetch the next page of data","schema":{"type":"string"},"in":"query"},{"name":"selector","description":"optional sensor selector to filter the list with","schema":{"type":"string"},"in":"query"},{"name":"limit","description":"optional maximum number of sensors to return in a page of data","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"is_compressed","description":"optional boolean indicating if the response should be compressed","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"with_ip","description":"optional internal or external IP of sensors to list","schema":{"type":"string"},"in":"query"},{"name":"with_hostname_prefix","description":"optional hostname prefix of sensors to list","schema":{"type":"string"},"in":"query"},{"name":"with_tags","description":"optionally include sensor tags in response","schema":{"type":"string"},"in":"query"},{"name":"is_online_only","description":"optional boolean indicating if the response should include only the online sensors","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"List of sensors","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"continuation_token":{"type":"string"},"from_cache":{"type":"boolean"},"matched_count":{"description":"total number of sensors matching the selector","title":"matched count","type":"integer"},"sensors":{"oneOf":[{"description":"base64 encoded gzip compressed list of sensors","title":"compressed list of sensors","type":"string"},{"items":{"additionalProperties":false,"properties":{"alive":{"description":"timestamp of last alive check","pattern":"^\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2}:\\d{2}$","title":"alive check","type":"string"},"app_control":{"additionalProperties":false,"properties":{"counters":{"additionalProperties":false,"description":"cumulative since the sensor started","properties":{"n_denied":{"type":"integer"},"n_evaluated":{"type":"integer"},"n_installed":{"description":"files written by a trusted installer that may run; absent when the policy names no installer","title":"installed files","type":"integer"},"n_lost":{"type":"integer"},"n_resident":{"description":"running processes the policy denied when it was installed (on_enable report or terminate); absent when on_enable is leave","title":"resident denials","type":"integer"},"n_terminated":{"description":"resident processes terminated (on_enable terminate in enforcing mode); absent when on_enable is leave","title":"terminated","type":"integer"},"n_unresolved":{"type":"integer"}},"title":"counters","type":"object"},"degraded":{"description":"bitmask of the reasons enforcement is not whole: 0x01 no policy, 0x02 stale, 0x04 hash unavailable, 0x08 not enforced, 0x10 enforcement point skew, 0x20 enforcement point has no key, 0x40 lease lapsed, 0x80 on_enable ignored, 0x100 sensor identities not applied, 0x200 policy refused","title":"degraded","type":"integer"},"enforced":{"additionalProperties":false,"description":"what the enforcement point reports; absent when none answered","properties":{"break_glass":{"description":"whether the break-glass is pulled","title":"break glass","type":"boolean"},"generation":{"description":"generation the enforcement point holds","title":"generation","type":"integer"},"is_connected":{"description":"whether anyone is there to answer the enforcement point","title":"connected","type":"boolean"},"mode":{"description":"mode the enforcement point is armed in","title":"mode","type":"integer"},"n_overloaded":{"description":"executions allowed without being judged because the host could not keep up","title":"overloaded","type":"integer"},"n_rules":{"description":"rules the enforcement point holds; absent when it does not evaluate rules","title":"rule count","type":"integer"}},"title":"enforcement point","type":"object"},"generation":{"description":"generation (issue time, epoch seconds) of the policy the sensor holds, 0 for none","title":"generation","type":"integer"},"label":{"description":"name of the policy record the sensor holds","title":"policy label","type":"string"},"mode":{"description":"enforcement mode: 0 off, 1 permissive, 2 permissive-sync, 3 enforcing","title":"mode","type":"integer"},"refused":{"additionalProperties":false,"description":"the policy the sensor declined, when it declined one","properties":{"generation":{"description":"generation of the declined policy","title":"generation","type":"integer"},"reason":{"description":"refusal reason: 21 invalid, 22 foreign, 23 expired, 24 unknown key, 25 refused, 26 not newer, 27 rolled back, 28 clock skew","title":"reason","type":"integer"},"ts":{"description":"when the sensor declined it, epoch seconds","title":"timestamp","type":"integer"}},"title":"refused policy","type":"object"},"reported_at":{"description":"when the posture was last published, epoch seconds","title":"reported at","type":"integer"},"stance":{"description":"policy stance: 0 blocklist, 1 allowlist","title":"stance","type":"integer"}},"type":"object"},"arch":{"description":"architecture of host running the sensor","title":"architecture","type":"integer"},"did":{"oneOf":[{"description":"UUID of the device","format":"uuid","title":"device identifier","type":"string"},{"enum":[""]}]},"enroll":{"description":"timestamp of sensor enrollment","pattern":"^\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2}:\\d{2}$","title":"enrollment timestamp","type":"string"},"ext_ip":{"oneOf":[{"description":"external IP of the host running the sensor","format":"ipv4","title":"external IP","type":"string"},{"enum":["internal",""]}]},"ext_plat":{"description":"external platform of the sensor","title":"external platform","type":"integer"},"hostname":{"description":"hostname of the host running the sensor","title":"hostname","type":"string"},"iid":{"description":"installation key identifier","title":"installation key identifier","type":"string"},"installer_version":{"description":"version of the installer","title":"installer version","type":"string"},"int_ip":{"description":"internal IP of the host running the sensor","title":"internal IP","type":"string"},"is_del":{"description":"is the sensor deleted","title":"deleted status","type":"boolean"},"is_isolated":{"description":"isolation status of the sensor","title":"isolation status","type":"boolean"},"is_kernel_available":{"description":"is kernel available to the sensor","title":"kernel availability","type":"boolean"},"is_online":{"description":"is sensor online at the moment","title":"online status","type":"boolean"},"mac_addr":{"description":"MAC address of the host running the sensor","title":"MAC address","type":"string"},"metadata":{"oneOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}]},"oid":{"description":"UUID of the organization","format":"uuid","title":"organization identifier","type":"string"},"plat":{"description":"platform type of the host running the sensor","title":"platform","type":"integer"},"sealed":{"description":"seal status of the sensor","title":"seal status","type":"boolean"},"should_isolate":{"description":"isolation intent of the sensor","title":"isolation intent","type":"boolean"},"should_seal":{"description":"seal intent of the sensor","title":"seal intent","type":"boolean"},"sid":{"description":"UUID of the sensor","format":"uuid","title":"sensor identifier","type":"string"},"tags":{"oneOf":[{"items":{"description":"sensors tag","title":"tag","type":"string"},"type":"array"},{"type":"null"}]},"version":{"description":"version of the sensor","title":"sensor version","type":"string"}},"required":["sid","alive","arch","did","enroll","ext_ip","ext_plat","hostname","int_ip","is_isolated","is_kernel_available","mac_addr","oid","plat","sealed","should_isolate","should_seal"],"type":"object"},"type":"array"}]},"warning":{"description":"warning emitted when the result set was truncated by safety limits","title":"warning","type":"string"}},"required":["sensors"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the list of sensors belonging to the organization.","summary":"Get Sensor List","x-required-permissions":{"all_of":["sensor.list"]}}},"/service/{oid}":{"get":{"operationId":"getAvailableServices","tags":["Service"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"replicants":{"items":{"type":"string"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the list of Services enabled on this organization.","summary":"Get Available Services","x-required-permissions":{"all_of":["replicant.get"]}}},"/service/{oid}/{service_name}":{"post":{"operationId":"makeServiceRequest","tags":["Service"],"parameters":[{"name":"is_async","description":"if set to 'true', this REST call will not wait for the Service to finish handling the request","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"service_name","required":true,"description":"Service name to send the request to","schema":{"type":"string"},"in":"path"}],"requestBody":{"description":"request object","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"jwt":{"description":"optional JWT token to use for authentication to the Service","title":"jwt","type":"string"},"request_data":{"description":"JSON data to send to the Service","title":"request_data","type":"string"}},"required":["request_data"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":true,"description":"Response payload produced by the Service handling the request; the shape is defined by each Service and is not under LimaCharlie's control. Requests with is_async=true (the default) return an empty object.","type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Send a request to a Service.","summary":"Make Service Request","x-required-permissions":{"all_of":["replicant.task"]}}},"/service/{service_name}/usage":{"get":{"operationId":"getServiceUsage","tags":["Service"],"parameters":[{"name":"service_name","required":true,"description":"Service name to send the request to","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"params":{"additionalProperties":true,"description":"Service usage parameters","type":"object"}},"required":["params"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the usage parameters for requests to the service.","summary":"Get Service Usage","x-required-permissions":{"all_of":["replicant.task"]}}},"/sites":{"get":{"operationId":"getSites","tags":["General"],"parameters":[],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"shared_allowlist_ips":{"additionalProperties":{"items":{"type":"string"},"type":"array"},"description":"Static IPs to allow for each hostname, primary first then standby. Every listed address must be allowed.","title":"Allowlist IPs","type":"object"},"sites":{"additionalProperties":{"additionalProperties":false,"properties":{"ai":{"type":"string"},"allowlist_ips":{"additionalProperties":{"items":{"type":"string"},"type":"array"},"description":"Static IPs to allow for each hostname, primary first then standby. Every listed address must be allowed.","title":"Allowlist IPs","type":"object"},"artifacts":{"type":"string"},"cases":{"type":"string"},"edr":{"type":"string"},"hooks":{"type":"string"},"lc":{"type":"string"},"lc_wss":{"type":"string"},"live":{"type":"string"},"logs":{"type":"string"},"private_endpoints":{"additionalProperties":{"type":"boolean"},"type":"object"},"region_code":{"type":"string"},"replay":{"type":"string"},"search":{"type":"string"}},"type":"object"},"description":"Site name to its hostnames and allowlist IPs.","title":"Sites","type":"object"}},"type":"object"}}}}},"description":"List every customer-facing site (region) with its public hostnames and the static IPs to allow for them, plus the hostnames shared by all sites. This is the machine-readable form of the allow list published in the documentation. No authentication required.","summary":"Get Sites"}},"/tags/{oid}":{"get":{"operationId":"listOrgTags","tags":["Sensors","Tags"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"tags":{"oneOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}]}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List all the tags in use by sensors belonging to the organization.","summary":"List All Sensor Tags","x-required-permissions":{"all_of":["sensor.list"]}}},"/tags/{oid}/{tag}":{"get":{"operationId":"findSensorsWithTag","tags":["Sensors","Tags"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"},{"name":"tag","required":true,"description":"tag to search for","schema":{"type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":{"items":{"type":"string"},"type":"array"},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Search for sensors with given tags.","summary":"Find Sensors by Tag","x-required-permissions":{"all_of":["sensor.list"]}}},"/test_template":{"post":{"operationId":"testTemplate","tags":["Rules"],"parameters":[],"requestBody":{"description":"JSON encoded string of the request data","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"template":{"description":"template expression","title":"template","type":"string"},"test_data":{"description":"test data to apply the template from","title":"test data","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the resulting data from applying a template.","summary":"Simulate a template being apply to data"}},"/test_transform":{"post":{"operationId":"testTransform","tags":["Outputs"],"parameters":[],"requestBody":{"description":"JSON encoded string of the request data","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"test_data":{"description":"test data to apply the transform to","title":"test data","type":"string"},"transform":{"description":"transform expression","title":"transform","type":"string"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the resulting data from applying a transform.","summary":"Simulate a transform being apply to data"}},"/usage/{oid}":{"get":{"operationId":"getOrgUsageStats","tags":["Organizations"],"parameters":[{"name":"days","description":"number of days to look back for usage stats","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"start","description":"optional Unix epoch timestamp in SECONDS (not milliseconds) where to begin, e.g. 1735689600. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"end","description":"optional Unix epoch timestamp in SECONDS (not milliseconds) where to stop, e.g. 1735693200. Millisecond values are rejected.","schema":{"description":"Unix epoch timestamp in SECONDS (10 digits), not milliseconds.","pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"from_cache":{"type":"boolean"},"note":{"type":"string"},"usage":{"additionalProperties":{"additionalProperties":{"type":"integer"},"properties":{"date":{"type":"string"}},"required":["date"],"type":"object"},"type":"object"}},"required":["usage"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get various organization usage stats. Supports either a days lookback or explicit start/end epoch timestamps. If start and end are provided, they take precedence over days.","summary":"Get Usage Stats","x-required-permissions":{"all_of":["org.get"]}}},"/user/orgs":{"get":{"operationId":"getUserOrgs","tags":["Organizations"],"parameters":[{"name":"offset","description":"number of organizations to skip from the start","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"limit","description":"maximum number of organizations to return (default 10)","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"filter","description":"case-insensitive substring filter on name, description, or oid","schema":{"type":"string"},"in":"query"},{"name":"sort_by","description":"field to sort by: 'name' or 'description' (default: 'name')","schema":{"type":"string"},"in":"query"},{"name":"sort_order","description":"sort order: 'asc' or 'desc' (default: 'asc')","schema":{"type":"string"},"in":"query"},{"name":"fields","description":"comma-separated list of fields to return (e.g. 'oid,name,description'). Supported fields: code, oid, name, description, status, sensor_online, sensor_quota, billing_quantity, sensor_version, permissions, errors, site_name, latest_versions. If not specified, all fields are returned.","schema":{"type":"string"},"in":"query"},{"name":"membership","description":"filter by membership type: 'direct' (only orgs the user is a direct admin of) or 'group' (only orgs accessed via group membership). If not specified, all orgs are returned.","schema":{"type":"string"},"in":"query"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"orgs":{"items":{"additionalProperties":false,"properties":{"billing_quantity":{"oneOf":[{"type":"integer"},{"type":"null"}]},"code":{"type":"string"},"description":{"type":"string"},"errors":{"oneOf":[{"type":"null"},{"items":{"additionalProperties":false,"properties":{"component":{"type":"string"},"error":{"type":"string"},"oid":{"type":"string"},"ts":{"type":"number"}},"type":"object"},"type":"array"}]},"latest_versions":{"oneOf":[{"type":"null"},{"additionalProperties":false,"properties":{"experimental":{"type":"string"},"fallback":{"type":"string"},"latest":{"type":"string"}},"type":"object"}]},"name":{"type":"string"},"oid":{"type":"string"},"permissions":{"items":{"type":"string"},"type":"array"},"sensor_online":{"oneOf":[{"type":"integer"},{"type":"null"}]},"sensor_quota":{"oneOf":[{"type":"integer"},{"type":"null"}]},"sensor_version":{"oneOf":[{"type":"string"},{"type":"null"}]},"site_name":{"oneOf":[{"type":"string"},{"type":"null"}]},"status":{"type":"string"}},"type":"object"},"type":"array"},"total":{"type":"integer"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get all organizations the current token has access to, including oid, name and description.","summary":"Get Accessible Orgs"}},"/user/partners":{"get":{"operationId":"getUserPartners","tags":["Partners"],"parameters":[],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"partners":{"items":{"additionalProperties":false,"properties":{"billing_enabled":{"description":"Whether this Partner can receive organizations. False means creating or attaching an org under it is refused until LimaCharlie enables consolidated billing, which the caller cannot do. UI that offers a Partner as a creation target should filter on this","type":"boolean"},"name":{"type":"string"},"permissions":{"items":{"type":"string"},"type":"array"},"pid":{"type":"string"}},"type":"object"},"type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"List the Partners the calling user is a member of, with the partner permissions they hold. Self-scoped: requires no permission.","summary":"Get user partners"}},"/user/self/auth":{"get":{"operationId":"getUserAuthRequirements","tags":["Billing"],"parameters":[],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"anyOf":[{"additionalProperties":false,"description":"Empty object: the domain has no configured authentication requirements","type":"object"},{"additionalProperties":false,"properties":{"auth_ui":{"additionalProperties":false,"description":"Login-UI offering for the domain. Present only when the domain offers SSO. UI-only: enforcement is expressed via requirements.methods.","properties":{"sso_provider_id":{"type":"string"}},"required":["sso_provider_id"],"type":"object"},"is_partner_managed":{"description":"Whether the domain is linked to a Partner: standalone org creation is refused.","type":"boolean"},"is_unified_billing":{"description":"Whether the domain's unified-billing perks apply to the caller. False once the domain is linked to a Partner.","type":"boolean"},"requirements":{"additionalProperties":false,"properties":{"max_session_seconds":{"type":"integer"},"methods":{"anyOf":[{"type":"null"},{"items":{"type":"string"},"type":"array"}]},"mfa":{"anyOf":[{"type":"null"},{"items":{"type":"string"},"type":"array"}]},"mfa_reset_email":{"type":"string"},"new_account_mfa_grace_seconds":{"type":"integer"}},"required":["methods","mfa"],"type":"object"}},"required":["requirements","is_unified_billing","is_partner_managed"],"type":"object"}]}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get authentication requirements (MFA, sign-in methods) for the authenticated user's email domain.","summary":"Get User Auth Requirements"}},"/usp/validate/{oid}":{"post":{"operationId":"validateUSPMapping","tags":["USP"],"parameters":[{"name":"oid","required":true,"description":"organization id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"USP mapping validation request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"hostname":{"description":"Default hostname for sensors. If not specified, defaults to 'validation-test'.","title":"Default Hostname","type":"string"},"indexing":{"description":"Optional list of indexing rules to apply to parsed events. Structure validated by backend.","items":{"type":"object"},"title":"Indexing Rules","type":"array"},"json_input":{"description":"Pre-parsed JSON input as an array of objects. Mutually exclusive with text_input.","items":{"type":"object"},"title":"JSON Input","type":"array"},"mapping":{"description":"A single mapping descriptor to validate. Structure validated by backend.","title":"Single Mapping","type":"object"},"mappings":{"description":"List of mapping descriptors for multi-mapping selection. Structure validated by backend.","items":{"type":"object"},"title":"Multiple Mappings","type":"array"},"platform":{"description":"The parser platform type to use (e.g., 'text', 'json', 'cef', 'gcp', 'aws').","title":"Platform","type":"string"},"text_input":{"description":"Newline-separated text input to parse. Mutually exclusive with json_input.","title":"Text Input","type":"string"}},"required":["platform"],"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"errors":{"description":"List of errors encountered during validation.","items":{"type":"string"},"title":"Errors","type":"array"},"results":{"description":"List of successfully parsed events.","items":{"type":"object"},"title":"Parsed Results","type":"array"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Validate USP adapter mapping configurations by testing them against sample input without affecting production systems. This allows you to verify that your parsing rules, mappings, and indexing configurations work as expected before deploying them. The request body is passed through to the backend validation service.","summary":"Validate USP Mapping"}},"/{sid}":{"delete":{"operationId":"deleteSensor","tags":["Sensors"],"parameters":[{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Delete a sensor.","summary":"Delete Sensor","x-required-permissions":{"all_of":["sensor.del"]}},"get":{"operationId":"getSensorInfo","tags":["Sensors"],"parameters":[{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"info":{"additionalProperties":false,"properties":{"alive":{"description":"timestamp of last alive check","pattern":"^\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2}:\\d{2}$","title":"alive check","type":"string"},"arch":{"description":"architecture of host running the sensor","title":"architecture","type":"integer"},"cursor":{"description":"cursor for the next page","type":"string"},"did":{"oneOf":[{"description":"UUID of the device","format":"uuid","title":"device identifier","type":"string"},{"enum":[""]}]},"enroll":{"description":"timestamp of sensor enrollment","pattern":"^\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2}:\\d{2}$","title":"enrollment timestamp","type":"string"},"error":{"oneOf":[{"type":"string"},{"type":"null"}]},"ext_ip":{"oneOf":[{"description":"external IP of the host running the sensor","format":"ipv4","title":"external IP","type":"string"},{"enum":["internal",""]}]},"ext_plat":{"description":"external platform of the sensor","title":"external platform","type":"integer"},"hostname":{"description":"hostname of the host running the sensor","title":"hostname","type":"string"},"iid":{"description":"installation key identifier","title":"installation key identifier","type":"string"},"installer_version":{"description":"version of the installer","title":"installer version","type":"string"},"int_ip":{"description":"internal IP of the host running the sensor","title":"internal IP","type":"string"},"is_del":{"description":"is the sensor deleted","title":"deleted status","type":"boolean"},"is_isolated":{"description":"isolation status of the sensor","title":"isolation status","type":"boolean"},"is_kernel_available":{"description":"is kernel available to the sensor","title":"kernel availability","type":"boolean"},"is_online":{"description":"is sensor online at the moment","title":"online status","type":"boolean"},"mac_addr":{"description":"MAC address of the host running the sensor","title":"MAC address","type":"string"},"metadata":{"oneOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}]},"oid":{"description":"UUID of the organization","format":"uuid","title":"organization identifier","type":"string"},"plat":{"description":"platform type of the host running the sensor","title":"platform","type":"integer"},"sealed":{"description":"seal status of the sensor","title":"seal status","type":"boolean"},"should_isolate":{"description":"isolation intent of the sensor","title":"isolation intent","type":"boolean"},"should_seal":{"description":"seal intent of the sensor","title":"seal intent","type":"boolean"},"sid":{"description":"UUID of the sensor","format":"uuid","title":"sensor identifier","type":"string"},"tags":{"items":{"description":"sensors tag","title":"tag","type":"string"},"type":"array"},"version":{"description":"version of the sensor","title":"sensor version","type":"string"}},"required":["sid","alive","arch","did","enroll","ext_ip","ext_plat","hostname","int_ip","is_isolated","is_kernel_available","mac_addr","oid","plat","sealed","should_isolate","should_seal"],"type":"object"},"online":{"additionalProperties":false,"properties":{"error":{"type":"string"},"is_online":{"type":"boolean"}},"type":"object"}},"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the sensor information and online status.","summary":"Get Sensor Info","x-required-permissions":{"all_of":["sensor.get"]}},"patch":{"operationId":"undeleteSensor","tags":["Sensors"],"parameters":[{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Undelete a sensor.","summary":"Undelete Sensor","x-required-permissions":{"all_of":["sensor.del"]}},"post":{"operationId":"taskSensor","tags":["Sensors"],"parameters":[{"name":"tasks","description":"list of tasks to send","schema":{"type":"string"},"in":"query"},{"name":"investigation_id","description":"tag included in data returned from sensor resulting from the tasks","schema":{"type":"string"},"in":"query"},{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"requestBody":{"description":"specification for the tasks to be performed","content":{"application/x-www-form-urlencoded":{"schema":{"additionalProperties":false,"properties":{"investigation_id":{"description":"a tag included in data returned from sensor resulting from the tasks","title":"investigation id","type":"string"},"tasks":{"description":"list of tasks to send","items":{"type":"string"},"title":"tasks","type":"array"}},"type":"object"}}},"required":true},"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"403":{"description":"The content is restricted by an acl: scope tag the caller does not hold","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"},"error_code":{"description":"ACL_CONTENT_RESTRICTED","type":"string"}},"type":"object"}}}}},"description":"Send a task to a sensor.","summary":"Task Sensor","x-required-permissions":{"all_of":["sensor.task"]}}},"/{sid}/isolation":{"delete":{"operationId":"rejoinSensor","tags":["Sensors"],"parameters":[{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove the sensor from network isolation.","summary":"Rejoin Sensor","x-required-permissions":{"all_of":["sensor.task"]}},"get":{"operationId":"getSensorIsolation","tags":["Sensors"],"parameters":[{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"is_isolated":{"type":"boolean"},"should_isolate":{"type":"boolean"}},"required":["is_isolated","should_isolate"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the sensor isolation status.","summary":"Get Isolation Status","x-required-permissions":{"all_of":["sensor.get"]}},"post":{"operationId":"isolateSensor","tags":["Sensors"],"parameters":[{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Set the sensor in network isolation.","summary":"Isolate Sensor","x-required-permissions":{"all_of":["sensor.task"]}}},"/{sid}/seal":{"delete":{"operationId":"unsealSensor","tags":["Sensors"],"parameters":[{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove the sensor seal.","summary":"Unseal Sensor","x-required-permissions":{"all_of":["sensor.task"]}},"get":{"operationId":"getSensorSeal","tags":["Sensors"],"parameters":[{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"is_sealed":{"type":"boolean"},"should_seal":{"type":"boolean"}},"required":["is_sealed","should_seal"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the sensor seal status.","summary":"Get Seal Status","x-required-permissions":{"all_of":["sensor.get"]}},"post":{"operationId":"sealSensor","tags":["Sensors"],"parameters":[{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Set the sensor seal status.","summary":"Seal Sensor","x-required-permissions":{"all_of":["sensor.task"]}}},"/{sid}/tags":{"delete":{"operationId":"removeSensorTag","tags":["Sensors","Tags"],"parameters":[{"name":"tag","description":"tag to delete","schema":{"type":"string"},"in":"query"},{"name":"tags","description":"tags to delete, as a comma separated list","schema":{"type":"string"},"in":"query"},{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Remove a tag from the sensor.","summary":"Untag Sensor","x-required-permissions":{"all_of":["sensor.tag"]}},"get":{"operationId":"getSensorTags","tags":["Sensors","Tags"],"parameters":[{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"tags":{"additionalProperties":{"additionalProperties":{"items":{"type":"string"},"type":"array"},"type":"object"},"type":"object"}},"required":["tags"],"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Get the sensor tags.","summary":"Get Sensor Tags","x-required-permissions":{"all_of":["sensor.get"]}},"post":{"operationId":"addSensorTag","tags":["Sensors","Tags"],"parameters":[{"name":"tags","description":"list of tags to add","schema":{"type":"string"},"in":"query"},{"name":"ttl","description":"number of seconds the tag is valid for","schema":{"pattern":"^[0-9]+$","type":"string"},"in":"query"},{"name":"is_did","description":"if set, indicates that the sid provided is really a DeviceID (did) and all its sensors should betagged","schema":{"enum":["1","t","T","true","TRUE","True","0","f","F","false","FALSE","False"]},"in":"query"},{"name":"sid","required":true,"description":"sensor id","schema":{"format":"uuid","type":"string"},"in":"path"}],"responses":{"200":{"description":"successful operation","content":{"application/json":{"schema":{"additionalProperties":false,"type":"object"}}}},"400":{"description":"Malformed request","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}},"401":{"description":"Access token is missing or invalid","content":{"application/json":{"schema":{"additionalProperties":false,"properties":{"error":{"type":"string"}},"type":"object"}}}}},"description":"Add tags to the sensor.","summary":"Tag Sensor","x-required-permissions":{"all_of":["sensor.tag"]}}}},"security":[{"bearerAuth":[]}],"servers":[{"url":"https://api.limacharlie.io/v1"}],"tags":[{"name":"Api Keys","description":"Operations related to the management of API Keys."},{"name":"Artifacts","description":"Operations related to the management of Artifacts."},{"name":"Billing","description":"Operations related to the management of Billing."},{"name":"Cloud Security","description":"Operations related to the CNAPP cloud-security posture, findings, and security graph."},{"name":"Email Security","description":"Operations related to email security: mailbox coverage, the message index, campaigns, sender profiles, remediation audit, and standalone message analysis."},{"name":"Errors","description":"Operations related to the Error logs."},{"name":"Exports","description":"Operations related to the exporting of data."},{"name":"Extensions","description":"Operations related to the management of Extensions."},{"name":"General","description":"Misc. Operations."},{"name":"Groups","description":"Operations related to the management of Groups."},{"name":"Hive","description":"Operations related to the configuration hive."},{"name":"Installation Keys","description":"Operations related to the management of Installation Keys."},{"name":"Jobs","description":"Operations related to the management of Jobs."},{"name":"Model Request","description":"Operations related to the management of Models."},{"name":"Modules","description":"Operations related to the management of sensor versions deployed."},{"name":"Organizations","description":"Operations related to the management of Organizations."},{"name":"Outputs","description":"Operations related to the forwarding of data."},{"name":"Partners","description":"Operations related to the management of Partners (MSSP control objects)."},{"name":"Payload","description":"Operations related to the management of Payloads."},{"name":"Resources","description":"Operations related to subscription and updating of Resources."},{"name":"Retention","description":"Operations related to data retention, visualization and searching."},{"name":"Rules","description":"Operations related to the Detection \u0026 Response rules."},{"name":"Schema","description":"Operations related to the interaction with Schemas."},{"name":"Sensors","description":"Operations related to the interaction with Sensors."},{"name":"Service","description":"Operations related to interaction with LimaCharlie Services."},{"name":"Tags","description":"Operations related to the tagging of sensors."},{"name":"USP","description":"Operations related to Universal Sensor Protocol adapters."},{"name":"Users","description":"Operations related to user and permissions management."}],"x-explorer-enabled":true,"x-samples-enabled":true,"x-samples-languages":["curl","node","ruby","javascript","python","go"]}