Skip to main content

Entrosity Vertex Portal API (0.1.0)

Download OpenAPI specification:Download

Entrosity Vertex portal REST API: Active Directory management per tenant — users (every attribute), groups and membership, OUs, Group Policy Objects (links, registry settings, security filtering), fine-grained password policies and CSV bulk imports. Vertex reaches the directory through the tenant's Entrosity Axis connector on a domain controller. This file is the source of truth for the backend server interfaces (oapi-codegen), request validation, and the frontend types (openapi-typescript). Run make gen after editing.

Authentication: Authorization: Bearer <product token>: users sign in on Entrosity Hub, which issues five-minute product tokens for Vertex (POST /api/platform/v1/auth/product-token {"product":"vertex"}, with the Hub's session cookie). Users, tenants (the Hub's organizations) and roles are managed on the Hub; Vertex keeps a copy.

Reads of lists come from Vertex's mirror of the directory (refreshed by syncs and after every change). Every change is an asynchronous operation: the API answers 202 with the operation, which the connector runs; follow it with GET /tenants/{t}/operations/{id}?wait=20 or the vertex.operation event of the live stream.

Every route's access rule (public, authenticated, global admin, tenant permission) is declared in internal/http/portal/access.go and enforced before the handler runs.

system

Liveness probe

Responses

Response samples

Content type
application/json
{
  • "status": "ok"
}

auth

Short-lived token for a tenant live stream (EventSource)

Returns a token valid for 60 seconds that opens GET /tenants/{tenantID}/stream?sse_token= for the given tenant and the caller's session. Access to the tenant is checked when the stream opens. Keeps the access token out of URLs.

Authorizations:
bearerAuth
Request Body schema: application/json
required
tenant_id
required
string <uuid>

Responses

Request samples

Content type
application/json
{
  • "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0"
}

Response samples

Content type
application/json
{
  • "token": "string",
  • "expires_in": 0
}

The signed-in user with their tenants and roles

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "email": "string",
  • "display_name": "string",
  • "status": "active",
  • "is_global_admin": true,
  • "memberships": [
    ],
  • "created_at": "2019-08-24T14:15:22Z"
}

admin

Cross-tenant counters

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "tenants_total": 0,
  • "tenants_active": 0,
  • "global_admins": 0,
  • "tenant_users": 0,
  • "tenants": [
    ]
}

List tenants

Authorizations:
bearerAuth
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 500 ]
Default: 50
q
string <= 200 characters
status
string (TenantStatus)
Enum: "active" "suspended"

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

Global admins (the platform admins of Entrosity Hub)

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "users": [
    ]
}

Cross-tenant audit log

Authorizations:
bearerAuth
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 500 ]
Default: 50
tenant_id
string <uuid>
actor_user_id
string <uuid>
action
string <= 100 characters
resource_type
string <= 100 characters
from
string <date-time>
to
string <date-time>

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

tenant

Tenant profile

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "slug": "string",
  • "status": "active",
  • "settings": {
    },
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z"
}

Change the tenant's settings (the name is the Hub's)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
Request Body schema: application/json
required
object (TenantSettings)
object (TenantRetention)

Overrides of the server's retention windows (sent as a whole).

job_days
integer [ 7 .. 730 ]

Finished operations.

audit_days
integer [ 30 .. 3650 ]

Audit log entries.

Responses

Request samples

Content type
application/json
{
  • "settings": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "slug": "string",
  • "status": "active",
  • "settings": {
    },
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z"
}

Tenant members and their Vertex roles (managed on Entrosity Hub)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "users": [
    ]
}

Audit log of the tenant

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 500 ]
Default: 50
actor_user_id
string <uuid>
action
string <= 100 characters
resource_type
string <= 100 characters
from
string <date-time>
to
string <date-time>

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

directory

The tenant's directory settings (the AD password is never returned)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "configured": true,
  • "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
  • "server": "string",
  • "ad_username": "string",
  • "has_password": true,
  • "managed_ous": [
    ],
  • "default_user_ou": "string",
  • "upn_suffix": "string",
  • "user_attributes": [
    ],
  • "sync_interval_minutes": 0,
  • "writes": {
    },
  • "domain": {
    },
  • "last_test_at": "2019-08-24T14:15:22Z",
  • "last_sync_at": "2019-08-24T14:15:22Z",
  • "last_sync_status": "string",
  • "last_sync_error": "string",
  • "next_sync_at": "2019-08-24T14:15:22Z"
}

Set the connector, AD account, managed OUs and write switches

Needs a step_up_token (Entrosity Hub re-authentication). Leave ad_password out to keep the stored one. Write switches are off by default; even when on, the connector's local guard on the domain controller must allow the same kind of change.

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
Request Body schema: application/json
required
connector_id
required
string <uuid>
server
string <= 253 characters
ad_username
required
string [ 1 .. 256 ] characters

DOMAIN\name or name@domain

ad_password
string [ 1 .. 256 ] characters

Leave out to keep the stored password.

managed_ous
required
Array of strings <= 100 items [ items <= 2048 characters ]
default_user_ou
string <= 2048 characters
upn_suffix
string <= 253 characters
user_attributes
Array of strings <= 200 items [ items <= 128 characters ]
sync_interval_minutes
integer [ 5 .. 1440 ]
Default: 30
required
object (WriteSwitches)

What Vertex may change (all off by default). The connector's local guard must allow it too.

step_up_token
required
string [ 1 .. 4096 ] characters

Responses

Request samples

Content type
application/json
{
  • "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
  • "server": "string",
  • "ad_username": "string",
  • "ad_password": "string",
  • "managed_ous": [
    ],
  • "default_user_ou": "string",
  • "upn_suffix": "string",
  • "user_attributes": [
    ],
  • "sync_interval_minutes": 30,
  • "writes": {
    },
  • "step_up_token": "string"
}

Response samples

Content type
application/json
{
  • "configured": true,
  • "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
  • "server": "string",
  • "ad_username": "string",
  • "has_password": true,
  • "managed_ous": [
    ],
  • "default_user_ou": "string",
  • "upn_suffix": "string",
  • "user_attributes": [
    ],
  • "sync_interval_minutes": 0,
  • "writes": {
    },
  • "domain": {
    },
  • "last_test_at": "2019-08-24T14:15:22Z",
  • "last_sync_at": "2019-08-24T14:15:22Z",
  • "last_sync_status": "string",
  • "last_sync_error": "string",
  • "next_sync_at": "2019-08-24T14:15:22Z"
}

The tenant's Entrosity Axis connectors (which can run Vertex jobs)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

Check the AD account, the domain and the PowerShell modules

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Read users, groups, OUs, password policies and GPOs now

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Counters of the mirror, the last sync and the recent operations

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "settings": {
    },
  • "users": 0,
  • "users_disabled": 0,
  • "users_locked": 0,
  • "groups": 0,
  • "ous": 0,
  • "password_policies": 0,
  • "gpos": 0,
  • "operations_open": 0,
  • "operations_failed_today": 0,
  • "recent": [
    ]
}

Attributes of users, groups and OUs (for the attribute editor)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
query Parameters
class
string
Enum: "user" "group" "organizationalUnit"

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

Read the attribute schema from the directory again

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

users

Directory users (from the mirror)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 500 ]
Default: 50
q
string <= 200 characters
ou
string <= 2048 characters

DN of an OU; only objects below it.

enabled
boolean
locked
boolean
member_of
string <= 2048 characters

DN of a group the users are direct members of.

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

Create a user

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
Request Body schema: application/json
required
ou
string <= 2048 characters

Default the settings' default user OU.

name
string <= 64 characters

CN (default "given surname" or the logon name).

sam_account_name
required
string [ 1 .. 20 ] characters
user_principal_name
string <= 1024 characters

Default logon name @ the UPN suffix.

given_name
string <= 64 characters
surname
string <= 64 characters
display_name
string <= 256 characters
password
string [ 1 .. 256 ] characters

Without a password the account is created disabled.

enabled
boolean
Default: true
must_change_password
boolean
Default: true
password_never_expires
boolean
Default: false
cannot_change_password
boolean
Default: false
object (Attributes)

Attribute values by LDAP display name (binary as b64:<base64>).

groups
Array of strings <= 100 items [ items <= 2048 characters ]

Group DNs.

Responses

Request samples

Content type
application/json
{
  • "ou": "string",
  • "name": "string",
  • "sam_account_name": "string",
  • "user_principal_name": "string",
  • "given_name": "string",
  • "surname": "string",
  • "display_name": "string",
  • "password": "string",
  • "enabled": true,
  • "must_change_password": true,
  • "password_never_expires": false,
  • "cannot_change_password": false,
  • "attributes": {
    },
  • "groups": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Set a new password (optionally require a change at next logon, unlock)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Request Body schema: application/json
required
password
required
string [ 1 .. 256 ] characters
must_change
boolean
Default: true
unlock
boolean
Default: true

Responses

Request samples

Content type
application/json
{
  • "password": "string",
  • "must_change": true,
  • "unlock": true
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Unlock a locked-out user

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Enable or disable a user

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Request Body schema: application/json
required
enabled
required
boolean

Responses

Request samples

Content type
application/json
{
  • "enabled": true
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Add the user to groups and remove them from others (one operation per group)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Request Body schema: application/json
required
add
Array of strings <= 100 items [ items <= 2048 characters ]

Group DNs.

remove
Array of strings <= 100 items [ items <= 2048 characters ]

Responses

Request samples

Content type
application/json
{
  • "add": [
    ],
  • "remove": [
    ]
}

Response samples

Content type
application/json
{
  • "items": [
    ]
}

The same action on many users (one operation per user, or per group for membership)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
Request Body schema: application/json
required
user_ids
required
Array of strings <uuid> [ 1 .. 500 ] items [ items <uuid > ]
action
required
string (BulkUserAction)
Enum: "enable" "disable" "unlock" "move" "add_to_group" "remove_from_group" "delete"
target_ou
string <= 2048 characters

For move.

group_dn
string <= 2048 characters

For add_to_group / remove_from_group.

step_up_token
string <= 4096 characters

Required for delete.

Responses

Request samples

Content type
application/json
{
  • "user_ids": [
    ],
  • "action": "enable",
  • "target_ou": "string",
  • "group_dn": "string",
  • "step_up_token": "string"
}

Response samples

Content type
application/json
{
  • "items": [
    ]
}

groups

Directory groups (from the mirror)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 500 ]
Default: 50
q
string <= 200 characters
ou
string <= 2048 characters

DN of an OU; only objects below it.

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

Create a group

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
Request Body schema: application/json
required
ou
string <= 2048 characters
name
required
string [ 1 .. 64 ] characters
sam_account_name
string <= 20 characters
scope
required
string
Enum: "DomainLocal" "Global" "Universal"
category
required
string
Enum: "Security" "Distribution"
description
string <= 1024 characters
object (Attributes)

Attribute values by LDAP display name (binary as b64:<base64>).

Responses

Request samples

Content type
application/json
{
  • "ou": "string",
  • "name": "string",
  • "sam_account_name": "string",
  • "scope": "DomainLocal",
  • "category": "Security",
  • "description": "string",
  • "attributes": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Direct members of a group (from the mirror)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

Add and remove members (DNs)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Request Body schema: application/json
required
add
Array of strings <= 500 items [ items <= 2048 characters ]
remove
Array of strings <= 500 items [ items <= 2048 characters ]

Responses

Request samples

Content type
application/json
{
  • "add": [
    ],
  • "remove": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

objects

Organizational units (and the domain), with their GPO links

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

Create an organizational unit

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
Request Body schema: application/json
required
parent_dn
required
string <= 2048 characters
name
required
string [ 1 .. 64 ] characters
description
string <= 1024 characters
protect_from_deletion
boolean
Default: true

Responses

Request samples

Content type
application/json
{
  • "parent_dn": "string",
  • "name": "string",
  • "description": "string",
  • "protect_from_deletion": true
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

A user, group, OU or password policy with every mirrored attribute

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "kind": "user",
  • "dn": "string",
  • "parent_dn": "string",
  • "name": "string",
  • "sam_account_name": "string",
  • "user_principal_name": "string",
  • "display_name": "string",
  • "mail": "string",
  • "description": "string",
  • "enabled": true,
  • "locked": true,
  • "protected": true,
  • "in_scope": true,
  • "member_of": [
    ],
  • "member_count": 0,
  • "when_changed": "2019-08-24T14:15:22Z",
  • "last_logon": "2019-08-24T14:15:22Z",
  • "synced_at": "2019-08-24T14:15:22Z",
  • "sid": "string",
  • "attributes": {
    },
  • "members": [
    ],
  • "writable": [
    ]
}

Set, add, remove or clear attributes

Attribute names are LDAP display names. Values are strings (binary as b64:<base64>). Identity, security and membership attributes are refused (dedicated endpoints exist). The helpdesk role may change contact attributes of users only.

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Request Body schema: application/json
required
object (Attributes)

Attribute values by LDAP display name (binary as b64:<base64>).

object (Attributes)

Attribute values by LDAP display name (binary as b64:<base64>).

object (Attributes)

Attribute values by LDAP display name (binary as b64:<base64>).

clear
Array of strings <= 200 items [ items <= 128 characters ]

Responses

Request samples

Content type
application/json
{
  • "set": {
    },
  • "add": {
    },
  • "remove": {
    },
  • "clear": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Delete a user, group, OU or password policy

Needs a step-up token (header X-Step-Up-Token) and the deletes switch.

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

query Parameters
recursive
boolean
Default: false

OUs only — delete everything below as well.

header Parameters
X-Step-Up-Token
string [ 1 .. 4096 ] characters

Step-up token from Entrosity Hub (re-authentication), used once. Required (checked after authentication).

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Read the object live with all attributes (and which ones the AD account may write)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Move to another OU

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Request Body schema: application/json
required
target_ou
required
string [ 1 .. 2048 ] characters

Responses

Request samples

Content type
application/json
{
  • "target_ou": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Rename (the CN / OU name)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Request Body schema: application/json
required
new_name
required
string [ 1 .. 64 ] characters

Responses

Request samples

Content type
application/json
{
  • "new_name": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

gpos

Group Policy Objects

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
query Parameters
q
string <= 200 characters

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

Create a GPO (optionally linked to an OU)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
Request Body schema: application/json
required
name
required
string [ 1 .. 255 ] characters
comment
string <= 2048 characters
link_to
string <= 2048 characters

An OU DN to link the new GPO to.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "comment": "string",
  • "link_to": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

A GPO with the OUs it is linked to

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
gpoID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "display_name": "string",
  • "status": "AllSettingsEnabled",
  • "description": "string",
  • "owner": "string",
  • "wmi_filter": "string",
  • "created": "2019-08-24T14:15:22Z",
  • "modified": "2019-08-24T14:15:22Z",
  • "user_version": 0,
  • "computer_version": 0,
  • "builtin": true,
  • "link_count": 0,
  • "links": [
    ]
}

Rename, change the status or the comment

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
gpoID
required
string <uuid>
Request Body schema: application/json
required
name
string [ 1 .. 255 ] characters
status
string
Enum: "AllSettingsEnabled" "UserSettingsDisabled" "ComputerSettingsDisabled" "AllSettingsDisabled"
comment
string <= 2048 characters

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "status": "AllSettingsEnabled",
  • "comment": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Delete a GPO (backed up first on the domain controller)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
gpoID
required
string <uuid>
header Parameters
X-Step-Up-Token
string [ 1 .. 4096 ] characters

Step-up token from Entrosity Hub (re-authentication), used once. Required (checked after authentication).

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

The last read XML report of the GPO (all its settings)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
gpoID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "gpo_id": "20e838d2-adfd-4c08-856b-b9b9401a1d0f",
  • "xml": "string",
  • "complete": true,
  • "fetched_at": "2019-08-24T14:15:22Z"
}

Read the GPO's report from the domain controller

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
gpoID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Set or remove registry-based policy settings

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
gpoID
required
string <uuid>
Request Body schema: application/json
required
Array of objects (RegistryValue) <= 100 items
Array of objects (RegistryValue) <= 100 items

Responses

Request samples

Content type
application/json
{
  • "set": [
    ],
  • "remove": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Security filtering and delegation (one trustee)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
gpoID
required
string <uuid>
Request Body schema: application/json
required
trustee
required
string [ 1 .. 300 ] characters
trustee_type
required
string
Enum: "User" "Group" "Computer"
level
required
string
Enum: "None" "GpoRead" "GpoApply" "GpoEdit" "GpoEditDeleteModifySecurity"
replace
boolean
Default: false

Responses

Request samples

Content type
application/json
{
  • "trustee": "string",
  • "trustee_type": "User",
  • "level": "None",
  • "replace": false
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Back the GPO up on the domain controller

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
gpoID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

password-policies

Fine-grained password policies (PSOs)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

Create a password policy

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
Request Body schema: application/json
required
name
required
string [ 1 .. 64 ] characters
required
object (PasswordPolicySettings)
apply_to
Array of strings <= 500 items [ items <= 2048 characters ]

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "settings": {
    },
  • "apply_to": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Change settings and whom the policy applies to

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
objectID
required
string <uuid>

The object's GUID (objectGUID).

Request Body schema: application/json
required
object (PasswordPolicySettings)
apply_to
Array of strings <= 500 items [ items <= 2048 characters ]
unapply
Array of strings <= 500 items [ items <= 2048 characters ]

Responses

Request samples

Content type
application/json
{
  • "settings": {
    },
  • "apply_to": [
    ],
  • "unapply": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

imports

Bulk imports of users

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 500 ]
Default: 50

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

Upload a CSV and validate it (nothing changes until commit)

The CSV (UTF-8, comma or semicolon separated, header row) is parsed and every row checked against the mirror: create (new logon name), update (existing user) or invalid (with the problems). Columns: sAMAccountName (required), password, ou, name, givenName, sn, displayName, userPrincipalName, mail, enabled, mustChangePassword, groups (;-separated DNs or group names), the common attributes by their LDAP names, and any other attribute as attr:<ldapName>. Passwords are kept encrypted until the import ends and never shown again.

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
Request Body schema: application/json
required
filename
string <= 255 characters
csv
required
string [ 1 .. 5242880 ] characters
mode
required
string (ImportMode)
Enum: "create" "update" "upsert"
object (ImportOptions)

Responses

Request samples

Content type
application/json
{
  • "filename": "string",
  • "csv": "string",
  • "mode": "create",
  • "options": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "filename": "string",
  • "mode": "create",
  • "status": "validated",
  • "options": {
    },
  • "total": 0,
  • "invalid": 0,
  • "to_create": 0,
  • "to_update": 0,
  • "created": 0,
  • "updated": 0,
  • "unchanged": 0,
  • "failed": 0,
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_at": "2019-08-24T14:15:22Z",
  • "committed_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z",
  • "expires_at": "2019-08-24T14:15:22Z"
}

An example CSV with the supported columns

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

An import with its counters

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
importID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "filename": "string",
  • "mode": "create",
  • "status": "validated",
  • "options": {
    },
  • "total": 0,
  • "invalid": 0,
  • "to_create": 0,
  • "to_update": 0,
  • "created": 0,
  • "updated": 0,
  • "unchanged": 0,
  • "failed": 0,
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_at": "2019-08-24T14:15:22Z",
  • "committed_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z",
  • "expires_at": "2019-08-24T14:15:22Z"
}

Rows of an import (preview before, results after commit)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
importID
required
string <uuid>
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 500 ]
Default: 50
status
string (ImportRowStatus)
Enum: "pending" "skipped" "created" "updated" "unchanged" "failed"
action
string (ImportRowAction)
Enum: "create" "update" "invalid"

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

Apply the valid rows (invalid rows are skipped)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
importID
required
string <uuid>
Request Body schema: application/json
required
step_up_token
required
string [ 1 .. 4096 ] characters

Responses

Request samples

Content type
application/json
{
  • "step_up_token": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "filename": "string",
  • "mode": "create",
  • "status": "validated",
  • "options": {
    },
  • "total": 0,
  • "invalid": 0,
  • "to_create": 0,
  • "to_update": 0,
  • "created": 0,
  • "updated": 0,
  • "unchanged": 0,
  • "failed": 0,
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_at": "2019-08-24T14:15:22Z",
  • "committed_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z",
  • "expires_at": "2019-08-24T14:15:22Z"
}

Discard a validated import (and its passwords)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
importID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "filename": "string",
  • "mode": "create",
  • "status": "validated",
  • "options": {
    },
  • "total": 0,
  • "invalid": 0,
  • "to_create": 0,
  • "to_update": 0,
  • "created": 0,
  • "updated": 0,
  • "unchanged": 0,
  • "failed": 0,
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_at": "2019-08-24T14:15:22Z",
  • "committed_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z",
  • "expires_at": "2019-08-24T14:15:22Z"
}

Every row with its outcome (never contains passwords)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
importID
required
string <uuid>

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

operations

Operations (changes and reads), newest first

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 500 ]
Default: 50
target_id
string <= 64 characters

Object GUID or GPO id.

status
string (OperationStatus)
Enum: "pending" "queued" "running" "succeeded" "failed" "cancelled" "timeout"
class
string (OperationClass)
Enum: "read" "user" "group" "ou" "gpo" "pso"
changes_only
boolean
Default: false

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

One operation; with `wait`, answers as soon as it finished (or after `wait` seconds)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
operationID
required
string <uuid>
query Parameters
wait
integer [ 0 .. 25 ]
Default: 0

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

Cancel an operation that has not finished (best effort once running)

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
operationID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "op": "string",
  • "class": "read",
  • "is_delete": true,
  • "target_kind": "string",
  • "target_id": "string",
  • "target_dn": "string",
  • "summary": "string",
  • "params": { },
  • "status": "pending",
  • "progress_pct": 0,
  • "progress_message": "string",
  • "error_code": "string",
  • "error": "string",
  • "result": { },
  • "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
  • "created_by_email": "string",
  • "bulk_import_id": "3271335f-cc5f-4601-90d0-a1a10b5951a0",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z",
  • "finished_at": "2019-08-24T14:15:22Z"
}

events

Live updates (server-sent events)

text/event-stream of the tenant's live updates: vertex.operation (an Operation changed: queued, progress, finished), vertex.directory ({kinds: [...]}: the mirror changed, reload those lists), vertex.import ({import_id}: a bulk import progressed) and vertex.settings. Authenticate with a bearer token or, for EventSource, ?sse_token= from POST /auth/sse-token.

Authorizations:
bearerAuth
path Parameters
tenantID
required
string <uuid>
query Parameters
sse_token
string <= 4096 characters

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}