Casb
CasbApplications
List applications
Get application details
ModelsExpand Collapse
ApplicationListResponse = Array<ApplicationListResponseItem>
id: "BITBUCKET" | "BOX" | "CONFLUENCE" | 7 moreVendor identifier (e.g. microsoft_internal, google_workspace).
BITBUCKET - BITBUCKET
BOX - BOX
CONFLUENCE - CONFLUENCE
DROPBOX - DROPBOX
GITHUB - GITHUB
GOOGLE_WORKSPACE - GOOGLE_WORKSPACE
JIRA - JIRA
MICROSOFT_INTERNAL - MICROSOFT_INTERNAL
SALESFORCE - SALESFORCE
SLACK - SLACK
Vendor identifier (e.g. microsoft_internal, google_workspace).
BITBUCKET- BITBUCKETBOX- BOXCONFLUENCE- CONFLUENCEDROPBOX- DROPBOXGITHUB- GITHUBGOOGLE_WORKSPACE- GOOGLE_WORKSPACEJIRA- JIRAMICROSOFT_INTERNAL- MICROSOFT_INTERNALSALESFORCE- SALESFORCESLACK- SLACK
ApplicationGetResponse { id, auth_methods, category, 6 more } Full application detail for onboarding UI.
Full application detail for onboarding UI.
id: "BITBUCKET" | "BOX" | "CONFLUENCE" | 7 moreVendor identifier.
BITBUCKET - BITBUCKET
BOX - BOX
CONFLUENCE - CONFLUENCE
DROPBOX - DROPBOX
GITHUB - GITHUB
GOOGLE_WORKSPACE - GOOGLE_WORKSPACE
JIRA - JIRA
MICROSOFT_INTERNAL - MICROSOFT_INTERNAL
SALESFORCE - SALESFORCE
SLACK - SLACK
Vendor identifier.
BITBUCKET- BITBUCKETBOX- BOXCONFLUENCE- CONFLUENCEDROPBOX- DROPBOXGITHUB- GITHUBGOOGLE_WORKSPACE- GOOGLE_WORKSPACEJIRA- JIRAMICROSOFT_INTERNAL- MICROSOFT_INTERNALSALESFORCE- SALESFORCESLACK- SLACK
CasbApplicationsAuth Methods
Get auth methods
ModelsExpand Collapse
AuthMethodListResponse = Array<AuthMethodListResponseItem>
Whether setup requires human interaction or integration can be created purely using API (e.g., For OAuth can not be created without user interaction).
CasbIntegrations
List integrations
Get integration details
Create integration
Update integration
Delete integration
Pause integration
Resume integration
ModelsExpand Collapse
CasbPosture
CasbPostureFindings
List posture findings
Get a finding type
Create new findings export request
Mark a finding as ignored
Remove ignore marker from a finding
Update the severity for a finding
Reset severity for a finding back to the default
ModelsExpand Collapse
FindingListResponse { id, active_count, archived_count, 6 more } Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
finding: Finding { id, category, name, 4 more } Basic finding type information.
Basic finding type information.
Number of total (Active or archived) problematic instances identified in the security finding.
integration: Integration { created, last_hydrated, name, 12 more } Summary information about an integration.
Summary information about an integration.
vendor: Vendor { id, description, display_name, 5 more } Information about a vendor/service provider.
Information about a vendor/service provider.
credential_health_status?: "Initializing" | "Healthy" | "Unhealthy"Health status of integration credentials.
Health status of integration credentials.
FindingGetResponse { id, active_count, archived_count, 6 more } Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
finding: Finding { id, category, name, 4 more } Basic finding type information.
Basic finding type information.
Number of total (Active or archived) problematic instances identified in the security finding.
integration: Integration { created, last_hydrated, name, 12 more } Summary information about an integration.
Summary information about an integration.
vendor: Vendor { id, description, display_name, 5 more } Information about a vendor/service provider.
Information about a vendor/service provider.
credential_health_status?: "Initializing" | "Healthy" | "Unhealthy"Health status of integration credentials.
Health status of integration credentials.
FindingExportResponse { id, status, type, 5 more } Information about an export job.
Information about an export job.
The URL by which the successfully created export can be downloaded by the end users.
Contains information on errors which may have occurred during export creation.
FindingIgnoreResponse { id, active_count, archived_count, 6 more } Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
finding: Finding { id, category, name, 4 more } Basic finding type information.
Basic finding type information.
Number of total (Active or archived) problematic instances identified in the security finding.
integration: Integration { created, last_hydrated, name, 12 more } Summary information about an integration.
Summary information about an integration.
vendor: Vendor { id, description, display_name, 5 more } Information about a vendor/service provider.
Information about a vendor/service provider.
credential_health_status?: "Initializing" | "Healthy" | "Unhealthy"Health status of integration credentials.
Health status of integration credentials.
FindingUnignoreResponse { id, active_count, archived_count, 6 more } Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
finding: Finding { id, category, name, 4 more } Basic finding type information.
Basic finding type information.
Number of total (Active or archived) problematic instances identified in the security finding.
integration: Integration { created, last_hydrated, name, 12 more } Summary information about an integration.
Summary information about an integration.
vendor: Vendor { id, description, display_name, 5 more } Information about a vendor/service provider.
Information about a vendor/service provider.
credential_health_status?: "Initializing" | "Healthy" | "Unhealthy"Health status of integration credentials.
Health status of integration credentials.
FindingTuneSeverityResponse { id, active_count, archived_count, 6 more } Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
finding: Finding { id, category, name, 4 more } Basic finding type information.
Basic finding type information.
Number of total (Active or archived) problematic instances identified in the security finding.
integration: Integration { created, last_hydrated, name, 12 more } Summary information about an integration.
Summary information about an integration.
vendor: Vendor { id, description, display_name, 5 more } Information about a vendor/service provider.
Information about a vendor/service provider.
credential_health_status?: "Initializing" | "Healthy" | "Unhealthy"Health status of integration credentials.
Health status of integration credentials.
FindingResetSeverityResponse { id, active_count, archived_count, 6 more } Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
Aggregated finding information with counts and metadata. This is optimized for list API queries and represents a finding along with its instance statistics.
finding: Finding { id, category, name, 4 more } Basic finding type information.
Basic finding type information.
Number of total (Active or archived) problematic instances identified in the security finding.
integration: Integration { created, last_hydrated, name, 12 more } Summary information about an integration.
Summary information about an integration.
vendor: Vendor { id, description, display_name, 5 more } Information about a vendor/service provider.
Information about a vendor/service provider.
credential_health_status?: "Initializing" | "Healthy" | "Unhealthy"Health status of integration credentials.
Health status of integration credentials.
CasbPostureFindingsInstances
List instances of a finding
Get a finding instance using an instance ID
Create a finding instances export
Archive a finding
Remove the archive marking from a finding instance
ModelsExpand Collapse
InstanceListResponse { affliction_date, asset, dlp_contexts, 4 more } A specific instance of a security finding. In the API interface, we refer to the ‘finding’ table in our DB as finding instances, optimized for the p99 use case.
A specific instance of a security finding. In the API interface, we refer to the ‘finding’ table in our DB as finding instances, optimized for the p99 use case.
asset: Asset { category, external_id, fields, 3 more } Asset information including metadata and categorization.
Asset information including metadata and categorization.
dlp_contexts: Array<DLPContext>DLP context information if this is a content finding.
DLP context information if this is a content finding.
remediations: Array<Remediation>A list of the 10 most recent remediation jobs for this finding instance, ordered by creation time (most recent first). The ‘stale’ field indicates whether the remediation job was created before the finding instance’s affliction_date (true) or after it (false). If there has never been a remediation job for this finding instance, this field will be an empty array.
A list of the 10 most recent remediation jobs for this finding instance, ordered by creation time (most recent first). The ‘stale’ field indicates whether the remediation job was created before the finding instance’s affliction_date (true) or after it (false). If there has never been a remediation job for this finding instance, this field will be an empty array.
webhooks: Array<Webhook>The most recent webhook job invocation for each webhook configuration associated with this finding instance. Each entry represents the latest job (any status) per webhook config. The ‘stale’ field indicates whether the job was invoked before the finding instance’s current affliction_date. If no webhook jobs have been created, this field will be an empty array.
The most recent webhook job invocation for each webhook configuration associated with this finding instance. Each entry represents the latest job (any status) per webhook config. The ‘stale’ field indicates whether the job was invoked before the finding instance’s current affliction_date. If no webhook jobs have been created, this field will be an empty array.
InstanceGetResponse { affliction_date, asset, dlp_contexts, 4 more } A specific instance of a security finding. In the API interface, we refer to the ‘finding’ table in our DB as finding instances, optimized for the p99 use case.
A specific instance of a security finding. In the API interface, we refer to the ‘finding’ table in our DB as finding instances, optimized for the p99 use case.
asset: Asset { category, external_id, fields, 3 more } Asset information including metadata and categorization.
Asset information including metadata and categorization.
dlp_contexts: Array<DLPContext>DLP context information if this is a content finding.
DLP context information if this is a content finding.
remediations: Array<Remediation>A list of the 10 most recent remediation jobs for this finding instance, ordered by creation time (most recent first). The ‘stale’ field indicates whether the remediation job was created before the finding instance’s affliction_date (true) or after it (false). If there has never been a remediation job for this finding instance, this field will be an empty array.
A list of the 10 most recent remediation jobs for this finding instance, ordered by creation time (most recent first). The ‘stale’ field indicates whether the remediation job was created before the finding instance’s affliction_date (true) or after it (false). If there has never been a remediation job for this finding instance, this field will be an empty array.
webhooks: Array<Webhook>The most recent webhook job invocation for each webhook configuration associated with this finding instance. Each entry represents the latest job (any status) per webhook config. The ‘stale’ field indicates whether the job was invoked before the finding instance’s current affliction_date. If no webhook jobs have been created, this field will be an empty array.
The most recent webhook job invocation for each webhook configuration associated with this finding instance. Each entry represents the latest job (any status) per webhook config. The ‘stale’ field indicates whether the job was invoked before the finding instance’s current affliction_date. If no webhook jobs have been created, this field will be an empty array.
InstanceExportResponse { id, status, type, 5 more } Information about an export job.
Information about an export job.
The URL by which the successfully created export can be downloaded by the end users.
Contains information on errors which may have occurred during export creation.
InstanceArchiveResponse { affliction_date, asset, dlp_contexts, 4 more } A specific instance of a security finding. In the API interface, we refer to the ‘finding’ table in our DB as finding instances, optimized for the p99 use case.
A specific instance of a security finding. In the API interface, we refer to the ‘finding’ table in our DB as finding instances, optimized for the p99 use case.
asset: Asset { category, external_id, fields, 3 more } Asset information including metadata and categorization.
Asset information including metadata and categorization.
dlp_contexts: Array<DLPContext>DLP context information if this is a content finding.
DLP context information if this is a content finding.
remediations: Array<Remediation>A list of the 10 most recent remediation jobs for this finding instance, ordered by creation time (most recent first). The ‘stale’ field indicates whether the remediation job was created before the finding instance’s affliction_date (true) or after it (false). If there has never been a remediation job for this finding instance, this field will be an empty array.
A list of the 10 most recent remediation jobs for this finding instance, ordered by creation time (most recent first). The ‘stale’ field indicates whether the remediation job was created before the finding instance’s affliction_date (true) or after it (false). If there has never been a remediation job for this finding instance, this field will be an empty array.
webhooks: Array<Webhook>The most recent webhook job invocation for each webhook configuration associated with this finding instance. Each entry represents the latest job (any status) per webhook config. The ‘stale’ field indicates whether the job was invoked before the finding instance’s current affliction_date. If no webhook jobs have been created, this field will be an empty array.
The most recent webhook job invocation for each webhook configuration associated with this finding instance. Each entry represents the latest job (any status) per webhook config. The ‘stale’ field indicates whether the job was invoked before the finding instance’s current affliction_date. If no webhook jobs have been created, this field will be an empty array.
InstanceUnarchiveResponse { affliction_date, asset, dlp_contexts, 4 more } A specific instance of a security finding. In the API interface, we refer to the ‘finding’ table in our DB as finding instances, optimized for the p99 use case.
A specific instance of a security finding. In the API interface, we refer to the ‘finding’ table in our DB as finding instances, optimized for the p99 use case.
asset: Asset { category, external_id, fields, 3 more } Asset information including metadata and categorization.
Asset information including metadata and categorization.
dlp_contexts: Array<DLPContext>DLP context information if this is a content finding.
DLP context information if this is a content finding.
remediations: Array<Remediation>A list of the 10 most recent remediation jobs for this finding instance, ordered by creation time (most recent first). The ‘stale’ field indicates whether the remediation job was created before the finding instance’s affliction_date (true) or after it (false). If there has never been a remediation job for this finding instance, this field will be an empty array.
A list of the 10 most recent remediation jobs for this finding instance, ordered by creation time (most recent first). The ‘stale’ field indicates whether the remediation job was created before the finding instance’s affliction_date (true) or after it (false). If there has never been a remediation job for this finding instance, this field will be an empty array.
webhooks: Array<Webhook>The most recent webhook job invocation for each webhook configuration associated with this finding instance. Each entry represents the latest job (any status) per webhook config. The ‘stale’ field indicates whether the job was invoked before the finding instance’s current affliction_date. If no webhook jobs have been created, this field will be an empty array.
The most recent webhook job invocation for each webhook configuration associated with this finding instance. Each entry represents the latest job (any status) per webhook config. The ‘stale’ field indicates whether the job was invoked before the finding instance’s current affliction_date. If no webhook jobs have been created, this field will be an empty array.
CasbPostureExports
List all export jobs
Get a single export job
ModelsExpand Collapse
ExportListResponse { id, status, type, 5 more } Information about an export job.
Information about an export job.
The URL by which the successfully created export can be downloaded by the end users.
Contains information on errors which may have occurred during export creation.
ExportGetResponse { id, status, type, 5 more } Information about an export job.
Information about an export job.
The URL by which the successfully created export can be downloaded by the end users.
Contains information on errors which may have occurred during export creation.
CasbPostureFinding Types
List all finding types
Get finding by ID
ModelsExpand Collapse
CasbPostureFinding TypesRemediation Types
List remediation types for a finding type
CasbPostureContent
List DLP content findings
Create a content export
ModelsExpand Collapse
ContentListResponse { asset_id, asset_name, dlp_contexts, 4 more } Content asset with DLP information.
Content asset with DLP information.
dlp_contexts: Array<DLPContext>DLP context information for this asset.
DLP context information for this asset.
integration: Integration { created, last_hydrated, name, 12 more } Summary information about an integration.
Summary information about an integration.
vendor: Vendor { id, description, display_name, 5 more } Information about a vendor/service provider.
Information about a vendor/service provider.
credential_health_status?: "Initializing" | "Healthy" | "Unhealthy"Health status of integration credentials.
Health status of integration credentials.
ContentExportResponse { id, status, type, 5 more } Information about an export job.
Information about an export job.
The URL by which the successfully created export can be downloaded by the end users.
Contains information on errors which may have occurred during export creation.
CasbPostureRemediations
CasbPostureRemediationsJobs
List remediation jobs
Creates remediation jobs
Create a remediation jobs export
ModelsExpand Collapse
JobListResponse { id, asset, created_at, 11 more } Information about a remediation job.
Information about a remediation job.
asset: Asset { id, category, external_id, 3 more } Asset information for a remediation job.
Asset information for a remediation job.
Email of the user who triggered the remediation. For account-token actors this is the literal “Account API Token”; for policy actors this is empty.
JobCreateResponse { created, failed }
created: Array<Created>Successfully created remediation jobs.
Successfully created remediation jobs.
asset: Asset { id, category, external_id, 3 more } Asset information for a remediation job.
Asset information for a remediation job.
Email of the user who triggered the remediation. For account-token actors this is the literal “Account API Token”; for policy actors this is empty.
JobExportResponse { id, status, type, 5 more } Information about an export job.
Information about an export job.
The URL by which the successfully created export can be downloaded by the end users.
Contains information on errors which may have occurred during export creation.
CasbPostureWebhooks
List webhook configurations
Create a new webhook configuration
Get webhook configuration by ID
Update an existing webhook configuration
Delete a webhook configuration
Test a webhook configuration before creating it
Test an existing webhook configuration
ModelsExpand Collapse
WebhookListResponse { id, authentication_type, created_at, 6 more } Webhook configuration for sending finding notifications.
Webhook configuration for sending finding notifications.
authentication_type: "Basic Auth" | "None" | "Bearer Auth" | 2 moreType of authentication used for the webhook.
Type of authentication used for the webhook.
Target URL for the webhook configuration. Where resulting data will be sent.
WebhookCreateResponse { id, authentication_type, created_at, 6 more } Webhook configuration for sending finding notifications.
Webhook configuration for sending finding notifications.
authentication_type: "Basic Auth" | "None" | "Bearer Auth" | 2 moreType of authentication used for the webhook.
Type of authentication used for the webhook.
Target URL for the webhook configuration. Where resulting data will be sent.
WebhookGetResponse { id, authentication_type, created_at, 6 more } Webhook configuration for sending finding notifications.
Webhook configuration for sending finding notifications.
authentication_type: "Basic Auth" | "None" | "Bearer Auth" | 2 moreType of authentication used for the webhook.
Type of authentication used for the webhook.
Target URL for the webhook configuration. Where resulting data will be sent.
WebhookUpdateResponse { id, authentication_type, created_at, 6 more } Webhook configuration for sending finding notifications.
Webhook configuration for sending finding notifications.
authentication_type: "Basic Auth" | "None" | "Bearer Auth" | 2 moreType of authentication used for the webhook.
Type of authentication used for the webhook.
Target URL for the webhook configuration. Where resulting data will be sent.
CasbPostureWebhooksJobs
Create webhook jobs
ModelsExpand Collapse
JobCreateResponse { created, failed }
created: Array<Created>Successfully created webhook jobs.
Successfully created webhook jobs.