1 line
141 KiB
JSON
1 line
141 KiB
JSON
{"openapi":"3.0.0","info":{"title":"Tenable Platform","version":"1.0.0"},"security":[{"cloud":[]}],"servers":[{"url":"https://cloud.tenable.com"}],"components":{"securitySchemes":{"cloud":{"type":"apiKey","in":"header","name":"X-ApiKeys","description":"Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY"}}},"x-samples-languages":["python","curl","node","powershell","ruby","javascript","objectivec","java","php","csharp","go","swift","kotlin"],"paths":{"/session":{"post":{"summary":"Create session","description":"**Note:** This endpoint is deprecated. Tenable best practice is to use API keys that are generated for specific user accounts. For your organization's integrations with the Tenable.io API, Tenable recommends you do not create and use session tokens.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","deprecated":true,"operationId":"session-create","tags":["Session"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"username":{"type":"string","description":"The username for the person who is attempting to log in."},"password":{"type":"string","description":"The password for the person who is attempting to log in.","format":"password"}},"required":["username","password"]}}}},"responses":{"200":{"description":"Returns the session token.","content":{"application/json":{"schema":{"type":"object","properties":{"token":{"type":"string","description":"The session token."}}},"examples":{"response":{"value":{"token":"k83049e04e76ea2b696f76e1cc83a2e87b6a52adbc014967f915c469e5739ac3"}}}}}},"400":{"description":"Returned if the username format is not valid."},"401":{"description":"Returned if the username or password is invalid."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if too many users are connected.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]},"get":{"summary":"Get user session","description":"Returns the user session data.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"session-get","tags":["Session"],"responses":{"200":{"description":"Returns the user session data.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string","description":"The unique ID of the user."},"uuid":{"type":"string","description":"The UUID of the user."},"uuid_id":{"type":"string","description":"The UUID of the user."},"username":{"type":"string","description":"The username for the user."},"user_name":{"type":"string","description":"The username for the user."},"email":{"type":"string","description":"The email address for the user."},"name":{"type":"string","description":"The full name for the user."},"type":{"type":"string","description":"The type of user (`local` or `ldap`)."},"permissions":{"type":"integer","description":"The user permissions as described in <a href=\"/docs/permissions\">Permissions</a>.","format":"int32"},"enabled":{"type":"integer","description":"If 1, the user is enabled."},"last_login_attempt":{"type":"integer","description":"The Unix timestamp of the last failed login attempt."},"login_fail_count":{"type":"integer","description":"The count of failed login attempts."},"login_fail_total":{"type":"integer","description":"The number of failed logins that may occur prior to the user being locked."},"two_factor":{"type":"object","description":"This attribute is only present if two-factor authentication is enabled for the user account.","properties":{"sms_phone":{"type":"string","description":"The mobile phone number Tenable.io uses during two-factor authentication for the user account."},"sms_enabled":{"type":"integer","description":"A value specifying whether two-factor authentication is enabled (`1`) or disabled (`0`) for the user account.","format":"int32"},"email_enabled":{"type":"integer","description":"A value specifying whether, in addition to sending a text message with the verification code, Tenable.io sends a backup email containing the verification code to the email associated with your user account. If this value is `0`, Tenable.io does not send a backup email message. If this value is `1`, Tenable.io sends a backup email message.","format":"int32"}}},"container_id":{"type":"integer","description":"The ID of the user's Tenable.io instance."},"container_uuid":{"type":"string","description":"The UUID of the user's Tenable.io instance."},"container_name":{"type":"string","description":"The name of the user's Tenable.io instance."},"features":{"type":"object","description":"A list of Tenable.io features enabled for the user's instance.","properties":{}},"apps":{"type":"object","description":"A list of Tenable.io products enabled for the user's instance.","properties":{"consec":{"type":"string","description":"The license status for Tenable.io Container Security, if enabled for the user's instance."},"was":{"type":"string","description":"The license status for Tenable.io Web Application Scanning, if enabled for the user's instance."}}},"group_uuids":{"type":"array","description":"The UUIDs of user groups to which the user belongs.","items":{"type":"string"}},"groups":{"description":"The list of user groups to which the user belongs.","type":"array","items":{"type":"object","properties":{"uuid":{"type":"string","description":"The UUID of the user group."},"name":{"type":"string","description":"The name of the user group."},"permissions":{"type":"integer","description":"The specified user's permissions for the user group. Default to `0`.","format":"int32"},"id":{"type":"integer","description":"The ID of the user group.","format":"int32"}}}},"lastlogin":{"type":"integer","description":"The Unix timestamp for the user's last login."},"connectors":{"type":"boolean","description":"Connectors for the user's Tenable.io instance."},"lockout":{"type":"integer","description":"Specifies whether the user account is locked out (`1`) or available (`0`)."}}},"examples":{"response":{"value":{"id":2,"uuid":"fb76f456-9a6f-4f63-8553-1cee234eb965","uuid_id":"fa76e456-9a6f-4f63-8553-1ced233eb965","username":"user2@example.com","user_name":"user2@example.com","email":"user2@example.org","name":"Sample User","type":"local","permissions":64,"enabled":true,"last_login_attempt":1540942030719,"login_fail_count":0,"login_fail_total":14,"two_factor":{"sms_phone":"+14108720555","sms_enabled":1,"email_enabled":0},"container_id":766315,"container_uuid":"3bc442f4-0cd1-4de0-95a3-3d8e587820ee","container_name":"demo","features":{"access_groups":true,"access_groups_migration":true,"advanced_search_v2":true,"agent_triage_m2":true,"agent_updates":true,"analytics":true,"analytics_v2":true,"asset_deleting_ui":true,"asset_management":true,"audits_workbench":false,"aws_connector_v1":true,"cfl_core_ssor":true,"connectors_gen2":false,"container_security":true,"container_security_gen2":true,"container_security_gen2_runtime":true,"credentials_mgmt":true,"credentials_mgmt_v2":true,"dashboards_gen2":false,"dashboards_gen2_blank_canvas":false,"dashboards_gen2_export":false,"dashboards_gen2_export_png":false,"dashboards_gen2_lumin_enabled":false,"dashboards_gen2_schedule":false,"dashboards_gen2_tag_filter":false,"dashboards_gen2_widget_filters":false,"dashboards_gen2_widget_library":false,"dynamic_tagging":true,"environment_management":true,"export_dashboard":true,"export_dashboard_pdf":true,"general_data_protection_compliance":true,"import_data":false,"indexing_v2":true,"lumin_beta_allowed":true,"lumin_beta_enabled":true,"modify_vulnerability":false,"pci_multiscan":true,"qualys_connector":true,"qualys_vuln_connector":true,"rbac":true,"recast_rules":true,"reporting":true,"scan_service":true,"scans_gen2":true,"state":true,"suggest_feature":true,"system":false,"tagging":true,"vm_service_query":true,"vulnerability_management_gen2":true,"was_discovery":true,"was_multi_scanning":true,"was_plugin_selection":true,"was_scan_progress":true,"webapp_scanning":true,"webapp_scanning_gen2":true},"apps":{},"group_uuids":[],"groups":[],"lastlogin":1543864186682}}}}}},"403":{"description":"Returned if the user does not have permission to view the session data."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]},"put":{"summary":"Update user settings","description":"Updates the settings for the current user.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"session-edit","tags":["Session"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"name":{"type":"string","description":"Full name for the user."},"email":{"type":"string","description":"Email address for the user."}}}}}},"responses":{"200":{"description":"Returns the user session data.","content":{"application/json":{"schema":{"type":"object","properties":{"uuid":{"type":"string","description":"The UUID for the user."},"id":{"type":"integer","description":"The unique ID of the user."},"user_name":{"type":"string","description":"The username for the user."},"username":{"type":"string","description":"The username for the user."},"email":{"type":"string","description":"The email address for the user."},"name":{"type":"string","description":"The real name of the user."},"type":{"type":"string","description":"The type of user (`local` or `ldap`)."},"container_uuid":{"type":"string","description":"The UUID of the user's Tenable.io instance."},"whatsnew_version":{"type":"string","description":"The version of the \"what's new\" messaging that appears when the user logs into the user interface."},"aggregate":{"type":"integer","description":"If `1`, aggregate collection is enabled."},"permissions":{"type":"integer","description":"The user permissions for the user as described in <a href=\"/docs/permissions\">Permissions</a>.","format":"int32"},"last_login_attempt":{"type":"integer","description":"The Unix timestamp for the last failed login attempt."},"login_fail_count":{"type":"integer","description":"The number of failed login attempts for the user since the last successful login."},"login_fail_total":{"type":"integer","description":"The total number of failed login attempts for the user."},"enabled":{"type":"boolean","description":"Specifies whether the user account is enabled (true) or disabled (false)."},"two_factor":{"type":"object","description":"This attribute is only present if two-factor authentication is enabled for the user account.","properties":{"sms_phone":{"type":"string","description":"The mobile phone number Tenable.io uses during two-factor authentication for the user account."},"sms_enabled":{"type":"integer","description":"A value specifying whether two-factor authentication is enabled (`1`) or disabled (`0`) for the user account.","format":"int32"},"email_enabled":{"type":"integer","description":"A value specifying whether, in addition to sending a text message with the verification code, Tenable.io sends a backup email containing the verification code to the email associated with your user account. If this value is `0`, Tenable.io does not send a backup email message. If this value is `1`, Tenable.io sends a backup email message.","format":"int32"}}},"lockout":{"type":"integer","description":"Specifies whether the user account is locked out (`1`) or available (`0`)."},"group_uuids":{"type":"array","description":"The UUIDs of user groups to which the user belongs.","items":{"type":"string"}},"groups":{"description":"The list of user groups to which the user belongs.","type":"array","items":{"type":"object","properties":{"uuid":{"type":"string","description":"The UUID of the user group."},"name":{"type":"string","description":"The name of the user group."},"id":{"type":"integer","description":"The ID of the user group.","format":"int32"}}}},"lastlogin":{"type":"integer","description":"The last time the user logged in to Tenable.io in the Unix time format."},"uuid_id":{"type":"string","description":"The UUID for the user."}}},"examples":{"response":{"value":{"id":2,"user_name":"user2@example.com","username":"user2@example.com","email":"user2@example.org","name":"Sample User","type":"local","whatsnew_version":"","aggregate":true,"permissions":64,"last_login_attempt":1540942130719,"login_fail_count":0,"login_fail_total":14,"enabled":true,"uuid":"fa76f456-9a6f-4f63-8553-1cee233fb965","container_uuid":"3bc442f4-0cd1-4de0-95a3-3d8e587820fe","lastlogin":1543864196682,"uuid_id":"fa76f456-9a6f-4f63-8553-1cfe233eb965"}}}}}},"403":{"description":"Returned if the user does not have permission to edit the session data."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if the server failed to edit the user.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]},"delete":{"summary":"Log out user","description":"Logs the current user out and destroys the session.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"session-destroy","tags":["Session"],"responses":{"200":{"description":"Returned if the session has been properly destroyed.","content":{"application/json":{"schema":{}}}},"401":{"description":"Returned if no session exists."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/session/restore":{"post":{"summary":"Restore impersonated session","description":"Restores an impersonated session to the original user.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"session-restore","tags":["Session"],"responses":{"200":{"description":"Returned if the session has been properly restored.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"401":{"description":"Returned if no session exists."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/session/chpasswd":{"put":{"summary":"Change password","description":"Changes password for the current user.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"session-password","tags":["Session"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"current_password":{"type":"string","description":"The current password for the user.","format":"password"},"password":{"type":"string","description":"The new password for the user.","format":"password"}},"required":["password","current_password"]}}}},"responses":{"200":{"description":"Returned if the user password has been changed.","content":{"application/json":{"schema":{}}}},"400":{"description":"Returned if the password is too short."},"403":{"description":"Returned if the user does not have permission to change the password."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if the server failed to change the password.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]}},"/session/keys":{"put":{"summary":"Generate API keys","description":"Generates API keys for the current user.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"session-keys","tags":["Session"],"responses":{"200":{"description":"Returned if the user API keys were generated.","content":{"application/json":{"schema":{"type":"object","properties":{"accessKey":{"type":"string","description":"The access key for the user account in Tenable.io. Use this key in combination with the user's secret key to submit authorized API requests to Tenable.io."},"secretKey":{"type":"string","description":"The secret key for the user account in Tenable.io. Use this key in combination with the user's access key to submit authorized API requests to Tenable.io."}}},"examples":{"response":{"value":{"accessKey":"748a5a175273ea87b026d815378f328b4d02d89df070d7891bd869762adf5b69","secretKey":"d2c7a8d58c996a2eccba270de732d0c1833fb1107c2929cb5321c3f15c5bc0ee"}}}}}},"401":{"description":"Returned if the user is not logged in."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/session/two-factor/send-verification":{"post":{"summary":"Send verification code","description":"Start the process of enabling two-factor authentication by sending a one-time verification code to the provided phone number.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"session-send-code","tags":["Session"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"sms_phone":{"type":"string","description":"The phone number where Tenable.io sends the one-time verification code. Must begin with the `+` sign."}},"required":["sms_phone"]}}}},"responses":{"200":{"description":"Returned if the one-time verification code was sent successfully to the provided phone number.","content":{"application/json":{"schema":{}}}},"400":{"description":"Returned if the verification code could not be sent."},"404":{"description":"Returned if the user does not exist."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/session/two-factor/verify-code":{"post":{"summary":"Validate verification code","description":"Validate the verification code sent to a phone number. If this request is successful, it enables two-factor authentication for the current user.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"session-verify-code","tags":["Session"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"verification_code":{"type":"string","description":"The verification code sent in the send-verification request."}},"required":["verification_code"]}}}},"responses":{"200":{"description":"Returned if two-factor authentication was successfully enabled for this user.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"400":{"description":"Returned if the the verification code was empty, incorrect, or expired."},"404":{"description":"Returned if the user does not exist."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/session/two-factor":{"put":{"summary":"Configure two-factor authentication","description":"Configure the current user's two-factor authentication settings. Before you can change these settings, you must send and validate the verification code using the /session/two-factor/send-verification and /session/two-factor/verify-code endpoints.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"session-two-factor-settings","tags":["Session"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"email_enabled":{"type":"boolean","description":"Specifies whether backup notification for two-factor authentication is enabled. If enabled, Tenable.io sends the two-factor verification code via e-mail, as well as via the default SMS message."},"sms_enabled":{"type":"boolean","description":"Specifies whether two-factor authentication is enabled. If enabled, Tenable.io sends the verification code via an SMS message. This parameter must be enabled to enable two-factor verification for the user."},"sms_phone":{"type":"string","description":"The phone number to use for two-factor authentication. Must begin with the `+` sign. This field is required when sms\\_enabled is set to `true`.","example":"+155555555555"}},"required":["email_enabled","sms_enabled"]}}}},"responses":{"200":{"description":"Returned if the two-factor authentication settings update was successful.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"404":{"description":"Returned if the user does not exist."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/users":{"post":{"summary":"Create user","description":"Creates a new user.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-create","tags":["Users"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"username":{"type":"string","description":"The login name for the user."},"password":{"type":"string","description":"The initial password for the user.","format":"password"},"permissions":{"type":"integer","description":"The user permissions for the user as described in <a href=\"/docs/permissions\">Permissions</a>.","format":"int32"},"name":{"type":"string","description":"The name of the user (for example, first and last name)."},"email":{"type":"string","description":"The email address of the user."}},"required":["username","password","permissions"]}}}},"responses":{"200":{"description":"Returned if Tenable.io successfully creates the user.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"integer","description":"The unique ID of the user."},"username":{"type":"string","description":"The username for the user."},"name":{"type":"string","description":"The name of the user (for example, first and last name)."},"email":{"type":"string","description":"The email address for the user."},"permissions":{"type":"integer","description":"The user permissions for the user as described in <a href=\"/docs/permissions\">Permissions</a>.","format":"int32"},"lastlogin":{"type":"integer","description":"The last time the user logged in to Tenable.io in the Unix time format."},"type":{"type":"string","description":"The type of user. The only supported type is `local`."},"login_fail_count":{"type":"integer","description":"The number of failed login attempts for the user since the last successful login."},"login_fail_total":{"type":"integer","description":"The total number of failed login attempts for the user."},"last_login_attempt":{"type":"integer","description":"The timestamp of the last failed login attempt for the user."},"enabled":{"type":"boolean","description":"Specifies whether the user account is enabled (true) or disabled (false)."},"lockout":{"type":"integer","description":"Specifies whether the user account is locked out (1) or available (0)."},"uuid_id":{"type":"string","description":"The unique UUID for the user."}}},"examples":{"response":{"value":{"id":5,"user_name":"user2@example.com","username":"user4@api.demo","email":"user2@example.com","name":"Test User","type":"local","aggregate":true,"permissions":32,"login_fail_count":0,"login_fail_total":0,"enabled":true,"uuid":"ed6fd6a6-9d02-4178-8a71-7dd8b000e526","container_uuid":"36f234c4-4ae3-4353-9324-8ad3dcc7fcc5","uuid_id":"ed6fd6a6-9d02-4178-8a71-7dd8b000e526"}}}}}},"400":{"description":"Returned if a field in the request is invalid."},"403":{"description":"Returned if you do not have permission to create a user."},"409":{"description":"Returned if you attempted to create a duplicate user."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]},"get":{"summary":"List users","description":"Returns a list of users.<p>Requires BASIC [16] user permissions. If you use credentials with ADMIN [64] permissions, Tenable.io returns all fields for individual user details. Otherwise, user details include only the `uuid`, `id`, `username`, and `email` fields. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-list","tags":["Users"],"responses":{"200":{"description":"Returns a list of users.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"integer","description":"The unique ID of the user."},"username":{"type":"string","description":"The username for the user."},"name":{"type":"string","description":"The name of the user (for example, first and last name)."},"email":{"type":"string","description":"The email address for the user."},"permissions":{"type":"integer","description":"The user permissions for the user as described in <a href=\"/docs/permissions\">Permissions</a>.","format":"int32"},"lastlogin":{"type":"integer","description":"The last time the user logged in to Tenable.io in the Unix time format."},"type":{"type":"string","description":"The type of user. The only supported type is `local`."},"login_fail_count":{"type":"integer","description":"The number of failed login attempts for the user since the last successful login."},"login_fail_total":{"type":"integer","description":"The total number of failed login attempts for the user."},"last_login_attempt":{"type":"integer","description":"The timestamp of the last failed login attempt for the user."},"enabled":{"type":"boolean","description":"Specifies whether the user account is enabled (true) or disabled (false)."},"lockout":{"type":"integer","description":"Specifies whether the user account is locked out (1) or available (0)."},"uuid_id":{"type":"string","description":"The unique UUID for the user."}}},"examples":{"response":{"value":{"users":[{"id":2,"user_name":"admin@example.com","username":"admin@example.com","email":"admin@example.com","name":"Admin Example","type":"local","permissions":64,"login_fail_count":0,"login_fail_total":0,"enabled":true,"uuid":"7a676323-47bb-4838-9cec-c9f01448bb2d","container_uuid":"36f234c4-4ae3-4353-9324-8ad3dcc7fcc5","lastlogin":1544477990398,"uuid_id":"7a676323-47bb-4838-9cec-c9f01448bb2d"},{"id":4,"user_name":"user3@example.com","username":"user3@example.com","email":"user3@example.com","name":"User Sample 3rd","type":"local","permissions":32,"login_fail_count":0,"login_fail_total":0,"enabled":true,"uuid":"802ea9fe-701a-4c80-b001-59c252a178cb","container_uuid":"36f234c4-4ae3-4353-9324-8ad3dcc7fcc5","uuid_id":"802ea9fe-701a-4c80-b001-59c252a178cb"},{"id":5,"user_name":"user4@example.com","username":"user4@example.com","email":"user4@example.com","name":"User Test","type":"local","permissions":32,"login_fail_count":0,"login_fail_total":0,"enabled":true,"uuid":"ed6fd6a6-9d02-4178-8a71-7dd8b000e526","container_uuid":"36f234c4-4ae3-4353-9324-8ad3dcc7fcc5","uuid_id":"ed6fd6a6-9d02-4178-8a71-7dd8b000e526"}]}}}}}},"403":{"description":"Returned if you do not have permission to view the list of users."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/users/{user_id}":{"get":{"summary":"Get user details","description":"Returns details for a specific user.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-details","tags":["Users"],"parameters":[{"description":"The unique ID of the user.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"responses":{"200":{"description":"Returns the user details.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"integer","description":"The unique ID of the user."},"username":{"type":"string","description":"The username for the user."},"name":{"type":"string","description":"The name of the user (for example, first and last name)."},"email":{"type":"string","description":"The email address for the user."},"permissions":{"type":"integer","description":"The user permissions for the user as described in <a href=\"/docs/permissions\">Permissions</a>.","format":"int32"},"lastlogin":{"type":"integer","description":"The last time the user logged in to Tenable.io in the Unix time format."},"type":{"type":"string","description":"The type of user. The only supported type is `local`."},"login_fail_count":{"type":"integer","description":"The number of failed login attempts for the user since the last successful login."},"login_fail_total":{"type":"integer","description":"The total number of failed login attempts for the user."},"last_login_attempt":{"type":"integer","description":"The timestamp of the last failed login attempt for the user."},"enabled":{"type":"boolean","description":"Specifies whether the user account is enabled (true) or disabled (false)."},"lockout":{"type":"integer","description":"Specifies whether the user account is locked out (1) or available (0)."},"uuid_id":{"type":"string","description":"The unique UUID for the user."}}},"examples":{"response":{"value":{"id":4,"user_name":"user3@example.com","username":"user3@example.com","email":"user3@example.com","name":"Test User","type":"local","permissions":32,"login_fail_count":0,"login_fail_total":0,"enabled":true,"uuid":"802ea9fe-701a-4c80-b001-59c252a178cb","container_uuid":"36f234c4-4ae3-4353-9324-8ad3dcc7fcc5","uuid_id":"802ea9fe-701a-4c80-b001-59c252a178cb"}}}}}},"403":{"description":"Returned if you do not have permission to view the given user details."},"404":{"description":"Returned if the user specified in the request does not exist."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]},"put":{"summary":"Update user","description":"Updates an existing user account.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-edit","tags":["Users"],"parameters":[{"description":"The unique ID of the user.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"permissions":{"type":"integer","description":"The user permissions for the user as described in <a href=\"/docs/permissions\">Permissions</a>.","format":"int32"},"name":{"type":"string","description":"The name of the user (for example, first and last name)."},"email":{"type":"string","description":"The email address of the user."},"enabled":{"type":"boolean","description":"Specifies whether the user's account is enabled (true) or disabled (false)."}},"required":["permissions"]}}}},"responses":{"200":{"description":"Returned if Tenable.io successfully updates the user.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"integer","description":"The unique ID of the user."},"username":{"type":"string","description":"The username for the user."},"name":{"type":"string","description":"The name of the user (for example, first and last name)."},"email":{"type":"string","description":"The email address for the user."},"permissions":{"type":"integer","description":"The user permissions for the user as described in <a href=\"/docs/permissions\">Permissions</a>.","format":"int32"},"lastlogin":{"type":"integer","description":"The last time the user logged in to Tenable.io in the Unix time format."},"type":{"type":"string","description":"The type of user. The only supported type is `local`."},"login_fail_count":{"type":"integer","description":"The number of failed login attempts for the user since the last successful login."},"login_fail_total":{"type":"integer","description":"The total number of failed login attempts for the user."},"last_login_attempt":{"type":"integer","description":"The timestamp of the last failed login attempt for the user."},"enabled":{"type":"boolean","description":"Specifies whether the user account is enabled (true) or disabled (false)."},"lockout":{"type":"integer","description":"Specifies whether the user account is locked out (1) or available (0)."},"uuid_id":{"type":"string","description":"The unique UUID for the user."}}},"examples":{"response":{"value":{"id":4,"user_name":"user3@example.com","username":"user3@example.com","email":"user3@example.com","name":"Test User","type":"local","whatsnew_version":"","aggregate":true,"permissions":32,"login_fail_count":0,"login_fail_total":0,"enabled":false,"uuid":"802ea9fe-701a-4c80-b001-59c252a178cb","container_uuid":"36f234c4-4ae3-4353-9324-8ad3dcc7fcc5","uuid_id":"802ea9fe-701a-4c80-b001-59c252a178cb"}}}}}},"400":{"description":"Returned if a field in the request is invalid."},"403":{"description":"Returned if you do not have permission to update a user."},"404":{"description":"Returned if the specified user does not exist."},"409":{"description":"Returned if you attempt to change your own account's enabled or disabled status."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]},"delete":{"summary":"Delete user","description":"Deletes a user.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-delete","tags":["Users"],"parameters":[{"description":"The unique ID of the user.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"responses":{"200":{"description":"Returned if Tenable.io deleted the user.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"403":{"description":"Returned if you do not have permission to delete the user."},"404":{"description":"Returned if the user you attempted to delete does not exist."},"409":{"description":"Returned if you tried to delete your own account."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if Tenable.io failed to delete the user.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]}},"/users/{user_id}/chpasswd":{"put":{"summary":"Change password","description":"Changes the password for a user.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-password","tags":["Users"],"parameters":[{"description":"The unique ID of the user whose password you want to change.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"current_password":{"type":"string","description":"The current password for the user.","format":"password"},"password":{"type":"string","description":"The new password for the user.","format":"password"}},"required":["current_password","password"]}}}},"responses":{"200":{"description":"Returned if Tenable.io successfully changed the user password.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"400":{"description":"Returned if Tenable.io cannot change the user password, because the new password is too short."},"403":{"description":"Returned if you do not have permission to change the user's password."},"404":{"description":"Returned if Tenable.io cannot find the specified user."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if Tenable.io failed to change the password.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]}},"/users/{user_id}/enabled":{"put":{"summary":"Enable user account","description":"Enables or disables an existing user account.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-enabled","tags":["Users"],"parameters":[{"description":"The unique ID of the user.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"enabled":{"type":"boolean","description":"The user's enabled or disabled status to be set (`true` to enable or `false` to disable)."}},"required":["enabled"]}}}},"responses":{"200":{"description":"Returns an array of user objects.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"integer","description":"The unique ID of the user."},"username":{"type":"string","description":"The username for the user."},"name":{"type":"string","description":"The name of the user (for example, first and last name)."},"email":{"type":"string","description":"The email address for the user."},"permissions":{"type":"integer","description":"The user permissions for the user as described in <a href=\"/docs/permissions\">Permissions</a>.","format":"int32"},"lastlogin":{"type":"integer","description":"The last time the user logged in to Tenable.io in the Unix time format."},"type":{"type":"string","description":"The type of user. The only supported type is `local`."},"login_fail_count":{"type":"integer","description":"The number of failed login attempts for the user since the last successful login."},"login_fail_total":{"type":"integer","description":"The total number of failed login attempts for the user."},"last_login_attempt":{"type":"integer","description":"The timestamp of the last failed login attempt for the user."},"enabled":{"type":"boolean","description":"Specifies whether the user account is enabled (true) or disabled (false)."},"lockout":{"type":"integer","description":"Specifies whether the user account is locked out (1) or available (0)."},"uuid_id":{"type":"string","description":"The unique UUID for the user."}}},"examples":{"response":{"value":{"object":"user"}}}}}},"403":{"description":"Returned if you do not have permission to update a user."},"404":{"description":"Returned if the user that the request specified does not exist."},"409":{"description":"Returned if you tried to change your own permissions."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/users/{user_id}/authorizations":{"get":{"summary":"Get user authorizations","description":"Returns user authorizations for accessing a Tenable.io instance. Access methods include user name and password, single sign-on (SSO) with SAML, and API.\n**Note:** All access methods are authorized by default.\n\nFor background information about managing user authorizations, see [Tenable.io Vulnerability Management User Guide](https://docs.tenable.com/cloud/Content/Settings/ManageUserAccessAuthorizations.htm).<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-list-auths","tags":["Users"],"parameters":[{"description":"The UUID of the user. You can find the user UUID by examining the output of the [GET /users](/reference#users-list) endpoint.","required":true,"name":"user_id","in":"path","schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Returns authorizations for the user.","content":{"application/json":{"schema":{"type":"object","properties":{"account_uuid":{"type":"string","description":"The UUID of the container.","format":"uuid"},"user_uuid":{"type":"string","description":"The UUID of the user.","format":"uuid"},"api_permitted":{"type":"boolean","description":"Indicates whether API access is authorized for the user."},"password_permitted":{"type":"boolean","description":"Indicates whether user name and password login is authorized for the user."},"saml_permitted":{"type":"boolean","description":"Indicates whether SSO with SAML is authorized for the user."}}},"examples":{"response":{"value":{"account_uuid":"40ac4662-6af3-4a0b-b422-93387ec0f298","user_uuid":"1e623352-a68b-42e0-8af8-f1b7c10a2b72","api_permitted":true,"password_permitted":false,"saml_permitted":true}}}}}},"404":{"description":"Returned if Tenable.io cannot find the specified user.","content":{"application/json":{"schema":{"type":"object","description":"Tenable.io API error response.","properties":{"error":{"type":"string","description":"The extended description of the cause of the Tenable.io API error."}}},"examples":{"response":{"value":{"error":"User[UUID=b6a6900e-a616-4266-b2be-765de43348dd] not found."}}}}}},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]},"put":{"summary":"Update user authorizations","description":"Updates user authorizations for accessing a Tenable.io instance. Use the endpoint to grant and revoke authorizations.\n\n**Note:** You cannot update authorizations for the current user.\n\nFor background information about managing user authorizations, see [Tenable.io Vulnerability Management User Guide](https://docs.tenable.com/cloud/Content/Settings/ManageUserAccessAuthorizations.htm).<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-update-auths","tags":["Users"],"parameters":[{"description":"The UUID of the user. You can find the user UUID by examining the output of the [GET /users](/reference#users-list) endpoint.","required":true,"name":"user_id","in":"path","schema":{"type":"string","format":"uuid"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","description":"Specify `true` or `false` to grant or revoke authorizations.","properties":{"api_permitted":{"type":"boolean","description":"Indicates whether API access is authorized for the user."},"password_permitted":{"type":"boolean","description":"Indicates whether user name and password login is authorized for the user."},"saml_permitted":{"type":"boolean","description":"Indicates whether SSO with SAML is authorized for the user."}},"required":["api_permitted","password_permitted","saml_permitted"]}}}},"responses":{"204":{"description":"Returned if the user's authorizations have been updated.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"400":{"description":"Returned if you specify invalid input parameters.","content":{"application/json":{"schema":{"type":"object","description":"Tenable.io API error response.","properties":{"error":{"type":"string","description":"The extended description of the cause of the Tenable.io API error."}}},"examples":{"response":{"value":{"error":"Unexpected character ('}' (code 125)): was expecting double-quote to start field name\n at [(String)\"{\r\n\"api_permitted\" : true,\r\n}\"; line: 3, column: 2]"}}}}}},"404":{"description":"Returned if Tenable.io cannot find the specified user.","content":{"application/json":{"schema":{"type":"object","description":"Tenable.io API error response.","properties":{"error":{"type":"string","description":"The extended description of the cause of the Tenable.io API error."}}},"examples":{"response":{"value":{"error":"User[UUID=b6a6900e-a616-4266-b2be-765de43348dd] not found."}}}}}},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/users/{user_id}/keys":{"put":{"summary":"Generate API keys","description":"Generates the API keys for a user.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-keys","tags":["Users"],"parameters":[{"description":"The unique ID of the user.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"responses":{"200":{"description":"Returned if Tenable.io successfully generated the API keys for the user.","content":{"application/json":{"schema":{"type":"object","properties":{"accessKey":{"type":"string","description":"The access key for the user account in Tenable.io. Use this key in combination with the user's secret key to submit authorized API requests to Tenable.io."},"secretKey":{"type":"string","description":"The secret key for the user account in Tenable.io. Use this key in combination with the user's access key to submit authorized API requests to Tenable.io."}}},"examples":{"response":{"value":{"accessKey":"26e07fb07181cf86e1bc7a240ce398645cf2bb80bbbefc178f100d6f5ffc067d","secretKey":"4be00decc6ea29e65d2910f1d54d23c14190a267285de4b05a481b1e6d3f0fd6"}}}}}},"403":{"description":"Returned if you do not have permission to generate API keys for the user."},"404":{"description":"Returned if Tenable.io cannot find the specified user."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if Tenable.io failed to generate the keys.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]}},"/users/{user_id}/impersonate":{"post":{"summary":"Impersonate user","description":"Allows the current administrator to impersonate the given user.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-impersonate","tags":["Users"],"parameters":[{"description":"The unique ID of the user you want to impersonate.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"responses":{"200":{"description":"Returned if the impersonation was successful.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"404":{"description":"Returned if Tenable.io cannot find the specified user."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/users/{user_id}/two-factor/send-verification":{"post":{"summary":"Send verification code","description":"Sends a one-time verification code to the user's phone number to start the process of enabling two-factor authentication.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-two-factor-enable","tags":["Users"],"parameters":[{"description":"The unique ID of the user.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"sms_phone":{"type":"string","description":"The phone number where Tenable.io sends the one-time verification code."}},"required":["sms_phone"]}}}},"responses":{"200":{"description":"Returned if Tenable.io sent the one-time verification code successfully to the specified phone number.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"400":{"description":"Returned if Tenable.io cannot send the verification code."},"404":{"description":"Returned if Tenable.io cannot find the specified user."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/users/{user_id}/two-factor/verify-code":{"post":{"summary":"Validate verification code","description":"Validate the verification code sent to a phone number. If this request is successful, it enables two-factor authentication for the specified user.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-two-factor-enable-verify","tags":["Users"],"parameters":[{"description":"The unique ID of the user.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"verification_code":{"type":"string","description":"The verification code sent in the send-verification request."}},"required":["verification_code"]}}}},"responses":{"200":{"description":"Returned if Tenable.io successfully validated the verification code and enabled two-factor authentication.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"400":{"description":"Returned if Tenable.io failed to validate the verification code because the verification code was empty, incorrect, or expired."},"404":{"description":"Returned if the user specified in the request does not exist."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/users/{user_id}/two-factor":{"put":{"summary":"Configure two-factor authentication ","description":"Enables or disables a user's two-factor authentication settings.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"users-two-factor","tags":["Users"],"parameters":[{"description":"The unique ID of the user.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"email_enabled":{"type":"boolean","description":"Specifies whether backup notification for two-factor authentication is enabled. If enabled, Tenable.io sends the two-factor verification code via e-mail, as well as via the default SMS message."},"sms_enabled":{"type":"boolean","description":"Specifies whether two-factor authentication is enabled. If enabled, Tenable.io sends the verification code via an SMS message. This parameter must be enabled to enable two-factor verification for the user."},"sms_phone":{"type":"string","description":"The phone number to use for two-factor authentication. Must begin with the `+` sign. This field is required when sms\\_enabled is set to `true`.","example":"+155555555555"}},"required":["email_enabled","sms_enabled","sms_phone"]}}}},"responses":{"200":{"description":"Returned if the two-factor authentication settings update was successful.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"404":{"description":"Returned if the user that the request specified does not exist."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/groups":{"post":{"summary":"Create group","description":"Create a group.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"groups-create","tags":["Groups"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"name":{"type":"string","description":"The name of the group."}},"required":["name"]}}}},"responses":{"200":{"description":"Returned if Tenable.io successfully creates the user group.","content":{"application/json":{"schema":{"type":"object","properties":{"permissions":{"type":"integer","description":"The permissions for the group."},"name":{"type":"string","description":"The name of the group."},"uuid":{"type":"string","description":"The UUID for the group."},"id":{"type":"integer","description":"The unique ID of the group."}}},"examples":{"response":{"value":{"uuid":"59ec5f27-8206-48e7-aa6c-d8ce18fd0f73","name":"Read Only","permissions":0,"container_uuid":"f4fbe518-e648-49dd-b6a4-e80c1ff12805","id":2}}}}}},"400":{"description":"Returned if your request message contains an invalid parameter."},"403":{"description":"Returned if you do not have permission to create a group."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if Tenable.io fails to add the group.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]},"get":{"summary":"List groups","description":"Returns the group list.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"groups-list","tags":["Groups"],"responses":{"200":{"description":"Returns the groups list.","content":{"application/json":{"schema":{"type":"array","items":{"type":"object","properties":{"user_count":{"type":"integer","description":"The number of users in the group."},"permissions":{"type":"integer","description":"The permissions for the group."},"name":{"type":"string","description":"The name of the group."},"uuid":{"type":"string","description":"The UUID for the group."},"id":{"type":"integer","description":"The unique ID of the group."}}}},"examples":{"response":{"value":{"groups":[{"uuid":"3a0fb06a-ed61-45e0-84d8-8e4e2da586ca","name":"admins","permissions":0,"container_uuid":"f4fbe518-e648-49dd-b6a4-e80c1ff12805","user_count":0,"id":1},{"uuid":"59ec5f27-8206-48e7-aa6c-d8ce18fd0f73","name":"Read Only","permissions":0,"container_uuid":"f4fbe518-e648-49dd-b6a4-e80c1ff12805","user_count":0,"id":2}]}}}}}},"403":{"description":"Returned if you do not have permission to view the list."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/groups/{group_id}":{"put":{"summary":"Update group","description":"Edit a group.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"groups-edit","tags":["Groups"],"parameters":[{"description":"The unique ID of the group.","required":true,"name":"group_id","in":"path","schema":{"type":"integer","format":"int32"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"name":{"type":"string","description":"The name of the group."}},"required":["name"]}}}},"responses":{"200":{"description":"Returned if Tenable.io updates the user group.","content":{"application/json":{"schema":{"type":"object","properties":{"user_count":{"type":"integer","description":"The number of users in the group."},"permissions":{"type":"integer","description":"The permissions for the group."},"name":{"type":"string","description":"The name of the group."},"uuid":{"type":"string","description":"The UUID for the group."},"id":{"type":"integer","description":"The unique ID of the group."}}},"examples":{"response":{"value":{"uuid":"59ec5f27-8206-48e7-aa6c-d8ce18fd0f73","name":"Read Only Users","permissions":0,"container_uuid":"f4fbe518-e648-49dd-b6a4-e80c1ff12805","user_count":0,"id":2}}}}}},"400":{"description":"Returned if your request message contains an invalid parameter."},"403":{"description":"Returned if you do not have permission to edit a group."},"404":{"description":"Returned if Tenable.io cannot find the specified group."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if Tenable.io fails to edit the group.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]},"delete":{"summary":"Delete group","description":"Delete a group.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"groups-delete","tags":["Groups"],"parameters":[{"description":"The unique ID of the group.","required":true,"name":"group_id","in":"path","schema":{"type":"integer","format":"int32"}}],"responses":{"200":{"description":"Returned if Tenable.io successfully deletes the specified user group.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"400":{"description":"Returned if Tenable.io cannot find the specified user group."},"403":{"description":"Returned if you do not have permission to delete the group."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if Tenable.io fails to delete the group.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]}},"/groups/{group_id}/users":{"get":{"summary":"List users in group","description":"Return the group user list.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"groups-list-users","tags":["Groups"],"parameters":[{"description":"The unique ID of the group.","required":true,"name":"group_id","in":"path","schema":{"type":"integer","format":"int32"}}],"responses":{"200":{"description":"Returns if the group user list.","content":{"application/json":{"schema":{"type":"array","items":{"type":"object","properties":{"id":{"type":"integer","description":"The unique ID of the user."},"username":{"type":"string","description":"The username for the user."},"name":{"type":"string","description":"The name of the user (for example, first and last name)."},"email":{"type":"string","description":"The email address for the user."},"permissions":{"type":"integer","description":"The user permissions for the user as described in <a href=\"/docs/permissions\">Permissions</a>.","format":"int32"},"lastlogin":{"type":"integer","description":"The last time the user logged in to Tenable.io in the Unix time format."},"type":{"type":"string","description":"The type of user. The only supported type is `local`."},"login_fail_count":{"type":"integer","description":"The number of failed login attempts for the user since the last successful login."},"login_fail_total":{"type":"integer","description":"The total number of failed login attempts for the user."},"last_login_attempt":{"type":"integer","description":"The timestamp of the last failed login attempt for the user."},"enabled":{"type":"boolean","description":"Specifies whether the user account is enabled (true) or disabled (false)."},"lockout":{"type":"integer","description":"Specifies whether the user account is locked out (1) or available (0)."},"uuid_id":{"type":"string","description":"The unique UUID for the user."}}}},"examples":{"response":{"value":{"users":[{"id":1,"user_name":"nessus_ms_agent","username":"nessus_ms_agent","name":"system","type":"local","permissions":128,"last_login_attempt":0,"login_fail_count":0,"login_fail_total":0,"enabled":false,"uuid":"47e6b2ea-4e3c-4c09-b137-72e9f53b97f6","container_uuid":"f4fbe518-e648-49dd-b6a4-e80c1ff12805","uuid_id":"47e6b2ea-4e3c-4c09-b137-72e9f53b97f6"},{"id":20,"user_name":"user2@example.com","username":"user2@example.com","email":"user2@example.com","name":"Sample User","type":"local","permissions":64,"last_login_attempt":0,"login_fail_count":0,"login_fail_total":0,"enabled":false,"uuid":"001e849b-16ca-4233-b1fe-b785b534c7b0","container_uuid":"f4fbe518-e648-49dd-b6a4-e80c1ff12805","uuid_id":"001e849b-16ca-4233-b1fe-b785b534c7b0"},{"id":2,"user_name":"user3@example.com","username":"user3@example.com","email":"user3@example.com","name":"user3@example.com","type":"local","permissions":64,"last_login_attempt":0,"login_fail_count":0,"login_fail_total":0,"enabled":false,"uuid":"e6b5cd6d-1e03-4697-8f81-33277a85f175","container_uuid":"f4fbe518-e648-49dd-b6a4-e80c1ff12805","uuid_id":"e6b5cd6d-1e03-4697-8f81-33277a85f175"}]}}}}}},"403":{"description":"Returned if you do not have permission to list a group's users."},"404":{"description":"Returned if Tenable.io cannot find the specified group."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/groups/{group_id}/users/{user_id}":{"post":{"summary":"Add user to group","description":"Add a user to the group.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"groups-add-user","tags":["Groups"],"parameters":[{"description":"The unique ID of the group.","required":true,"name":"group_id","in":"path","schema":{"type":"integer","format":"int32"}},{"description":"The unique ID of the user.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"responses":{"200":{"description":"Returned if Tenable.io successfully added the user to the group.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"403":{"description":"Returned if you do not have permission to add users to a group."},"404":{"description":"Returned if Tenable.io cannot find the specified group or user."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if Tenable.io fails to add the user to the group.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]},"delete":{"summary":"Delete user from group","description":"Deletes a user from the group.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"groups-delete-user","tags":["Groups"],"parameters":[{"description":"The unique ID of the group.","required":true,"name":"group_id","in":"path","schema":{"type":"integer","format":"int32"}},{"description":"The unique ID of the user.","required":true,"name":"user_id","in":"path","schema":{"type":"integer","format":"int32"}}],"responses":{"200":{"description":"Returned if Tenable.io removes the user from the group.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"403":{"description":"Returned if you do not have permission to delete users from the group."},"404":{"description":"Returned if Tenable.io cannot find the specified group or user."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}},"500":{"description":"Returned if Tenable.io fails to remove the user from the group.","content":{"application/json":{"examples":{"response":{"value":{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred. Please wait a moment and try your request again."}}}}}}},"security":[{"cloud":[]}]}},"/settings/connectors":{"post":{"summary":"Create connector","description":"Creates a connector.<ul>**Note:** The workflow for creating AWS connectors is as follows:<li>First, [get the available AWS cloudtrails for the account](#connectors-get-aws-cloudtrails)</li><li>Then use the cloudtrail(s) as a required input parameter to create the AWS connector.</li></ul></br><p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"connectors-create-connector","tags":["Connectors"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"name":{"type":"string","description":"The name of the connector. The name can contain only alphanumeric characters and comma (`,`), dot (`.`), dash (`-`), at sign (`@`), and underscore (`_`) characters."},"type":{"type":"string","description":"The type of the connector. Types include: \n* aws \n* aws_keyless \n* azure\n* gcp","enum":["aws","aws_keyless","azure"]},"network_uuid":{"type":"string","description":"The UUID of the [network](https://developer.tenable.com/docs/manage-networks-tio) to associate with the connector. You can find the UUID using the [GET /networks](/reference#networks-list) endpoint. If you do not specify a network, Tenable.io automatically associates the connector with the default network (UUID `00000000-0000-0000-0000-000000000000`).\n**Note**: Tenable recommends creating a network for each connector type in use to prevent asset records in different cloud environments from overwriting each other. For more information, see [Managing Networks](https://developer.tenable.com/docs/manage-networks-tio).","format":"UUID","default":"00000000-0000-0000-0000-000000000000"},"params":{"type":"object","description":"The connector parameters: \n* For AWS connectors, the parameters include the access key, secret key, associated accounts, and cloudtrails. \n* For keyless AWS connectors, the parameters include associated AWS accounts (sub-accounts) and cloudtrails. \n* For Azure connectors, the parameters include the application ID, tenant ID, client secret key, and an optional list of subscription IDs. If you don't provide subscription IDs, Tenable.io automatically discovers them.\n* For GCP connectors, the service account key.","properties":{"access_key":{"description":"The AWS access key.\n<b>Note: </b>The access key is not included in the keyless AWS connector parameters.","type":"string"},"secret_key":{"description":"For AWS connectors, the AWS secret key.","type":"string"},"trails":{"description":"For AWS connectors, a list of AWS cloudtrails associated with the connector. The trails must be available to be used by the connector. Use the [POST /settings/connectors/aws/cloudtrails](/reference#connectors-get-aws-cloudtrails) endpoint to check the `availability` property of cloudtrail objects.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"sub_accounts":{"description":"For AWS connectors, a list of AWS accounts associated with the connector.","type":"array","items":{"type":"object","properties":{"role_arn":{"type":"string","description":"The Amazon Resource Name (ARN) of the role generated based on the associated account ID."},"external_id":{"description":"The UUID of your Tenable.io instance used by AWS to identify it as a client application. You can obtain the UUID of your Tenable.io account using the GET /session endpoint. The UUID corresponds to the container_uuid attribute of the response message for that endpoint.","type":"string"},"trails":{"description":"For keyless AWS connectors, a list of AWS cloudtrails associated with the account.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on events instead of enumerating all assets in the account every single time."}}}},"application_id":{"description":"For Azure connectors, Azure application ID.","type":"string"},"tenant_id":{"type":"string","description":"For Azure connectors, Azure tenant ID."},"subscription_id":{"type":"string","description":"For Azure connectors, Azure subscription ID. If you do not provide subscription IDs, Tenable.io automatically discovers them."},"service_account_key":{"type":"string","description":"For GCP connectors, Base64-encoded string value of the service account key JSON file. For more information, see [GCP documentation](https://cloud.google.com/iam/docs/creating-managing-service-account-keys).\n\n**Important!** The `service_account_key` value must include only the literal encoded string. Do not include the `data:application/json;base64` prefix."}}},"schedule":{"type":"object","description":"The data import schedule.","properties":{"units":{"type":"string","description":"The units of time for the import interval. Units can include:\n - days\n - hours\n - minutes\n - weeks"},"value":{"type":"integer","description":"The number of units between import intervals."}}}},"required":["name","type","params"]}}}},"responses":{"200":{"description":"Returned if Tenable.io successfully creates a connector.","content":{"application/json":{"schema":{"type":"object","properties":{"type":{"type":"string","description":"The type of the connector. Types include:\n - aws\n - aws_keyless\n - azure\n - gcp"},"human_type":{"type":"string","description":"The human-readable connector type."},"data_type":{"type":"string","description":"The data type imported by the connector. For Azure and AWS connectors, the value is always `assets`."},"name":{"type":"string","description":"The name of the connector. The name must be unique within a Tenable.io instance."},"network_uuid":{"type":"string","format":"UUID","description":"The UUID of the [network](https://developer.tenable.com/docs/manage-networks-tio) associated with the connector."},"status":{"type":"string","description":"The import status of the connector. Status values can include:\n - Completed—Tenable.io successfully used the connector to import assets (no imports scheduled)\n - Scheduled—Imports using the connector are scheduled for future dates\n - Saved—Tenable.io saved the connector configuration, but did not import assets at this time (no imports scheduled)\n - Error—Tenable.io failed to import assets using the connector"},"status_message":{"type":"string","description":"Extended description of the connector status. For information about connector error codes, see <a href=\"/docs/connectors-tio\">Connectors</a>."},"schedule":{"type":"object","properties":{}},"date_created":{"type":"string","description":"An ISO timestamp indicating the date and time on which the connector was created, for example, `2018-08-09T13:51:17.243Z`."},"date_modified":{"type":"string","description":"An ISO timestamp indicating the date and time on which the connector was last modified or new records were imported, for example, `2018-08-09T13:51:17.243Z`."},"id":{"type":"string","description":"The UUID of the connector."},"container_uuid":{"type":"string","description":"The UUID of the Tenable.io instance."},"expired":{"type":"boolean","description":"Indicates whether the Vulnerability Management license for the Tenable.io instance associated with the connector is expired."},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on on the service provider event stream instead of enumerating all assets in the account every single time."},"last_sync_time":{"type":"string","description":"An ISO timestamp indicating the date and time of the last successful import, for example, `2018-08-09T13:51:17.243Z`."},"params":{"type":"object","description":"The connector parameters: \n* For AWS connectors, the parameters include the access key, secret key, associated accounts, and cloudtrails. \n* For keyless AWS connectors, the parameters include associated AWS accounts (sub-accounts) and cloudtrails. \n* For Azure connectors, the parameters include the application ID, tenant ID, client secret key, and an optional list of subscription IDs. If you don't provide subscription IDs, Tenable.io automatically discovers them.","properties":{"access_key":{"description":"For AWS connectors, the AWS access key.\n<b>Note: </b>The access key is not included in the keyless AWS connector parameters.","type":"string"},"trails":{"description":"For AWS connectors, a list of AWS cloudtrails associated with the connector.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"sub_accounts":{"description":"For AWS connectors, a list of AWS accounts associated with the connector.","type":"array","items":{"type":"object","properties":{"role_arn":{"type":"string","description":"The Amazon Resource Name (ARN) of the role generated based on the associated account ID."},"external_id":{"description":"The UUID of your Tenable.io instance used by AWS to identify it as a client application. You can obtain the UUID of your Tenable.io account using the GET /session endpoint. The UUID corresponds to the container_uuid attribute of the response message for that endpoint.","type":"string"},"trails":{"description":"For keyless AWS connectors, a list of AWS cloudtrails associated with the account.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on events instead of enumerating all assets in the account every single time."}}}},"status":{"description":"For Azure connectors, a list of import status records.","type":"array","items":{"type":"object","properties":{"last_event_seen":{"type":"string","description":"An ISO timestamp indicating the last time the connector found new or changed records and successfully imported them."},"release_timestamp":{"description":"An ISO timestamp indicating the last time the connector successfully completed an import (regardless of whether it found any changes).","type":"string"},"message":{"type":"string","description":"The extended import status message."}}}},"application_id":{"description":"For Azure connectors, Azure application ID.","type":"string"},"tenant_id":{"type":"string","description":"For Azure connectors, Azure tenant ID."},"subscription_id":{"type":"string","description":"For Azure connectors, Azure subscription ID. If you do not provide subscription IDs, Tenable.io automatically discovers them."},"service":{"description":"The service targeted by the connector. Values include:\n* aws \n* aws_keyless \n* azure\n* gcp","type":"string"}}}}},"examples":{"response":{"value":{"connector":{"type":"aws","human_type":"AWS","data_type":"assets","name":"AWS Connector - New","status":"Scheduled","status_message":"","schedule":{"units":"days","value":1},"schedule_full":{"units":"days","value":1},"date_created":"2019-03-24T20:50:23.635Z","id":"f2506bed-bffa-442b-bfde-506c52306111","container_uuid":"gdf930d-7e3d-452c-82e8-494c1be98ef19","expired":false,"incremental_mode":false,"params":{"access_key":"AJIAJLRNVRLZRDZLVBXR","trails":[{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":""}],"service":"aws"},"network_uuid":"11f04eb9-7c78-46c8-9025-fae048390f59"}}}}}}},"400":{"description":"Returned if you specify invalid input parameters."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]},"get":{"summary":"List connectors","description":"Returns a list of connectors.<p>For information about connector error codes, see <a href=\"/docs/connectors-tio\">Connectors</a>.</p><p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"connectors-list-connectors","tags":["Connectors"],"parameters":[{"description":"Maximum number of records requested (or service imposed limit if not in request). Must be in the int32 format. Default is 1000.","required":false,"name":"limit","in":"query","schema":{"type":"integer","format":"int32"}},{"description":"The number of records to skip in the returned result set. Must be in the int32 format. Default is 0.","required":false,"name":"offset","in":"query","schema":{"type":"integer","format":"int32"}},{"description":"The fields to sort on, for example, `sort=date_created:desc`. If you specify multiple fields, fields must be separated by commas. Sortable fields include: \n* date_created \n* name","required":false,"name":"sort","in":"query","schema":{"type":"string"}}],"responses":{"200":{"description":"Returns a list of connectors with pagination information.","content":{"application/json":{"schema":{"type":"object","properties":{"connectors":{"type":"array","items":{"type":"object","properties":{"type":{"type":"string","description":"The type of the connector. Types include:\n - aws\n - aws_keyless\n - azure\n - gcp"},"human_type":{"type":"string","description":"The human-readable connector type."},"data_type":{"type":"string","description":"The data type imported by the connector. For Azure and AWS connectors, the value is always `assets`."},"name":{"type":"string","description":"The name of the connector. The name must be unique within a Tenable.io instance."},"network_uuid":{"type":"string","format":"UUID","description":"The UUID of the [network](https://developer.tenable.com/docs/manage-networks-tio) associated with the connector."},"status":{"type":"string","description":"The import status of the connector. Status values can include:\n - Completed—Tenable.io successfully used the connector to import assets (no imports scheduled)\n - Scheduled—Imports using the connector are scheduled for future dates\n - Saved—Tenable.io saved the connector configuration, but did not import assets at this time (no imports scheduled)\n - Error—Tenable.io failed to import assets using the connector"},"status_message":{"type":"string","description":"Extended description of the connector status. For information about connector error codes, see <a href=\"/docs/connectors-tio\">Connectors</a>."},"schedule":{"type":"object","properties":{}},"date_created":{"type":"string","description":"An ISO timestamp indicating the date and time on which the connector was created, for example, `2018-08-09T13:51:17.243Z`."},"date_modified":{"type":"string","description":"An ISO timestamp indicating the date and time on which the connector was last modified or new records were imported, for example, `2018-08-09T13:51:17.243Z`."},"id":{"type":"string","description":"The UUID of the connector."},"container_uuid":{"type":"string","description":"The UUID of the Tenable.io instance."},"expired":{"type":"boolean","description":"Indicates whether the Vulnerability Management license for the Tenable.io instance associated with the connector is expired."},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on on the service provider event stream instead of enumerating all assets in the account every single time."},"last_sync_time":{"type":"string","description":"An ISO timestamp indicating the date and time of the last successful import, for example, `2018-08-09T13:51:17.243Z`."},"params":{"type":"object","description":"The connector parameters: \n* For AWS connectors, the parameters include the access key, secret key, associated accounts, and cloudtrails. \n* For keyless AWS connectors, the parameters include associated AWS accounts (sub-accounts) and cloudtrails. \n* For Azure connectors, the parameters include the application ID, tenant ID, client secret key, and an optional list of subscription IDs. If you don't provide subscription IDs, Tenable.io automatically discovers them.","properties":{"access_key":{"description":"For AWS connectors, the AWS access key.\n<b>Note: </b>The access key is not included in the keyless AWS connector parameters.","type":"string"},"trails":{"description":"For AWS connectors, a list of AWS cloudtrails associated with the connector.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"sub_accounts":{"description":"For AWS connectors, a list of AWS accounts associated with the connector.","type":"array","items":{"type":"object","properties":{"role_arn":{"type":"string","description":"The Amazon Resource Name (ARN) of the role generated based on the associated account ID."},"external_id":{"description":"The UUID of your Tenable.io instance used by AWS to identify it as a client application. You can obtain the UUID of your Tenable.io account using the GET /session endpoint. The UUID corresponds to the container_uuid attribute of the response message for that endpoint.","type":"string"},"trails":{"description":"For keyless AWS connectors, a list of AWS cloudtrails associated with the account.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on events instead of enumerating all assets in the account every single time."}}}},"status":{"description":"For Azure connectors, a list of import status records.","type":"array","items":{"type":"object","properties":{"last_event_seen":{"type":"string","description":"An ISO timestamp indicating the last time the connector found new or changed records and successfully imported them."},"release_timestamp":{"description":"An ISO timestamp indicating the last time the connector successfully completed an import (regardless of whether it found any changes).","type":"string"},"message":{"type":"string","description":"The extended import status message."}}}},"application_id":{"description":"For Azure connectors, Azure application ID.","type":"string"},"tenant_id":{"type":"string","description":"For Azure connectors, Azure tenant ID."},"subscription_id":{"type":"string","description":"For Azure connectors, Azure subscription ID. If you do not provide subscription IDs, Tenable.io automatically discovers them."},"service":{"description":"The service targeted by the connector. Values include:\n* aws \n* aws_keyless \n* azure\n* gcp","type":"string"}}}}}},"pagination":{"type":"object","properties":{"total":{"type":"integer","description":"The total number of records matching your search criteria. Must be in the int32 format."},"limit":{"type":"integer","description":"Maximum number of records requested (or service imposed limit if not in request). Must be in the int32 format."},"offset":{"type":"integer","description":"The number of skipped records in the returned result set. Must be in the int32 format."},"sort":{"description":"An array of the fields you specified as sort fields in the request, which Tenable.io uses to sort the returned data.","type":"array","items":{"type":"string"}}}}}},"examples":{"response":{"value":{"connectors":[{"type":"aws","human_type":"AWS","data_type":"assets","name":"AWS Connector","status":"Saved","status_message":"","date_created":"2019-03-21T20:18:59.509Z","id":"e5cc1ab0-e64a-4636-8676-95d79a5a3c40","container_uuid":"gdf930d-7e3d-452c-82e8-494c1be98ef19","expired":false,"incremental_mode":false,"params":{"access_key":"AJIAJLRNVRLZRDZLVBXR","trails":[{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"}],"sub_accounts":[],"service":"aws"},"network_uuid":"11f04eb9-7c78-46c8-9025-fae048390f59"},{"type":"azure","human_type":"Azure","data_type":"assets","name":"Azure Connector","status":"Completed","status_message":"Import completed successfully","date_created":"2019-03-21T19:56:23.713Z","date_modified":"2019-03-21T20:09:01.241Z","id":"ec58a94d-31f5-42e7-b5be-2fef687c7fad","container_uuid":"gdf930d-7e3d-452c-82e8-494c1be98ef19","expired":false,"incremental_mode":false,"last_sync_time":"2019-03-21T20:09:01.241Z","params":{"status":{"c2fa7307-c53b-5ce0-a772-2ec880e85759":{"last_event_seen":"2019-03-21T20:08:59.190Z","release_timestamp":"2019-03-21T20:09:00.315Z","message":"Import completed successfully","state":"SUCCESS"},"a90ae1b5-20e2-4bf9-82b3-0082159365ea":{"last_event_seen":"2019-03-21T20:09:01.241Z","release_timestamp":"2019-03-21T20:09:01.504Z","message":"Import completed successfully","state":"SUCCESS"}},"application_id":"559829df-59ba-49e4-94a0-6e5af2b508di","tenant_id":"5a2b8079-0320-405f-ad21-17a3103014f7","subscription_id":[],"service":"azure"},"network_uuid":"00000000-0000-0000-0000-000000000000"},{"type":"aws_keyless","human_type":"AWS","data_type":"assets","name":"AWS Keyless Connector","status":"Saved","status_message":"","date_created":"2019-03-20T14:18:30.350Z","id":"cee93baa-ec30-4ccc-ab81-80719ba629ff","container_uuid":"gdf930d-7e3d-452c-82e8-494c1be98ef19","expired":false,"incremental_mode":false,"params":{"sub_accounts":[{"role_arn":"arn:aws:iam::795163652895:role/tenableio-connector","external_id":"gdf930d-7e3d-452c-82e8-494c1be98ef19","trails":[{"arn":"arn:aws:cloudtrail:us-east-1:795163652895:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"}],"incremental_mode":false,"account_id":"795163652895"}],"service":"aws"},"network_uuid":"13f04eb9-7c78-36c8-9025-fae048390f57"}],"pagination":{"total":3,"offset":0,"limit":50,"sort":[{"name":"date_created","order":"desc"}]}}}}}}},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]},"put":{"summary":"Update connector","description":"Updates the specified connector. You can change the connector name, associated service accounts, and schedule. You cannot change the connector type for an existing connector.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"connectors-update-connector","tags":["Connectors"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"name":{"type":"string","description":"The name of the connector."},"network_uuid":{"type":"string","description":"The UUID of the [network](https://developer.tenable.com/docs/manage-networks-tio) to associate with the connector. You can find the UUID using the [GET /networks](/reference#networks-list) endpoint. If you do not specify a network, Tenable.io automatically associates the connector with the default network (UUID `00000000-0000-0000-0000-000000000000`).\n**Note**: Tenable recommends creating a network for each connector type in use to prevent asset records in different cloud environments from overwriting each other. For more information, see [Managing Networks](https://developer.tenable.com/docs/manage-networks-tio).","format":"UUID","example":"00000000-0000-0000-0000-000000000000"},"params":{"type":"object","description":"The connector parameters: \n* For AWS connectors, the parameters include the access key, secret key, associated accounts, and cloudtrails. \n* For keyless AWS connectors, the parameters include associated AWS accounts (sub-accounts) and cloudtrails. \n* For Azure connectors, the parameters include the application ID, tenant ID, client secret key, and an optional list of subscription IDs. If you don't provide subscription IDs, Tenable.io automatically discovers them.\n* For GCP connectors, the service account key.","properties":{"access_key":{"description":"The AWS access key.\n<b>Note: </b>The access key is not included in the keyless AWS connector parameters.","type":"string"},"secret_key":{"description":"For AWS connectors, the AWS secret key.","type":"string"},"trails":{"description":"For AWS connectors, a list of AWS cloudtrails associated with the connector. The trails must be available to be used by the connector. Use the [POST /settings/connectors/aws/cloudtrails](/reference#connectors-get-aws-cloudtrails) endpoint to check the `availability` property of cloudtrail objects.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"sub_accounts":{"description":"For AWS connectors, a list of AWS accounts associated with the connector.","type":"array","items":{"type":"object","properties":{"role_arn":{"type":"string","description":"The Amazon Resource Name (ARN) of the role generated based on the associated account ID."},"external_id":{"description":"The UUID of your Tenable.io instance used by AWS to identify it as a client application. You can obtain the UUID of your Tenable.io account using the GET /session endpoint. The UUID corresponds to the container_uuid attribute of the response message for that endpoint.","type":"string"},"trails":{"description":"For keyless AWS connectors, a list of AWS cloudtrails associated with the account.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on events instead of enumerating all assets in the account every single time."}}}},"application_id":{"description":"For Azure connectors, Azure application ID.","type":"string"},"tenant_id":{"type":"string","description":"For Azure connectors, Azure tenant ID."},"subscription_id":{"type":"string","description":"For Azure connectors, Azure subscription ID. If you do not provide subscription IDs, Tenable.io automatically discovers them."},"service_account_key":{"type":"string","description":"For GCP connectors, Base64-encoded string value of the service account key JSON file. For more information, see [GCP documentation](https://cloud.google.com/iam/docs/creating-managing-service-account-keys).\n\n**Important!** The `service_account_key` value must include only the literal encoded string. Do not include the `data:application/json;base64` prefix."}}},"schedule":{"type":"object","description":"The data import schedule.","properties":{"units":{"type":"string","description":"The units of time for the import interval. Units can include:\n - days\n - hours\n - minutes\n - weeks"},"value":{"type":"integer","description":"The number of units between import intervals."}}}},"required":["name","params"]}}}},"responses":{"200":{"description":"Returned if Tenable.io successfully updates a connector.","content":{"application/json":{"schema":{"type":"object","properties":{"type":{"type":"string","description":"The type of the connector. Types include:\n - aws\n - aws_keyless\n - azure\n - gcp"},"human_type":{"type":"string","description":"The human-readable connector type."},"data_type":{"type":"string","description":"The data type imported by the connector. For Azure and AWS connectors, the value is always `assets`."},"name":{"type":"string","description":"The name of the connector. The name must be unique within a Tenable.io instance."},"network_uuid":{"type":"string","format":"UUID","description":"The UUID of the [network](https://developer.tenable.com/docs/manage-networks-tio) associated with the connector."},"status":{"type":"string","description":"The import status of the connector. Status values can include:\n - Completed—Tenable.io successfully used the connector to import assets (no imports scheduled)\n - Scheduled—Imports using the connector are scheduled for future dates\n - Saved—Tenable.io saved the connector configuration, but did not import assets at this time (no imports scheduled)\n - Error—Tenable.io failed to import assets using the connector"},"status_message":{"type":"string","description":"Extended description of the connector status. For information about connector error codes, see <a href=\"/docs/connectors-tio\">Connectors</a>."},"schedule":{"type":"object","properties":{}},"date_created":{"type":"string","description":"An ISO timestamp indicating the date and time on which the connector was created, for example, `2018-08-09T13:51:17.243Z`."},"date_modified":{"type":"string","description":"An ISO timestamp indicating the date and time on which the connector was last modified or new records were imported, for example, `2018-08-09T13:51:17.243Z`."},"id":{"type":"string","description":"The UUID of the connector."},"container_uuid":{"type":"string","description":"The UUID of the Tenable.io instance."},"expired":{"type":"boolean","description":"Indicates whether the Vulnerability Management license for the Tenable.io instance associated with the connector is expired."},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on on the service provider event stream instead of enumerating all assets in the account every single time."},"last_sync_time":{"type":"string","description":"An ISO timestamp indicating the date and time of the last successful import, for example, `2018-08-09T13:51:17.243Z`."},"params":{"type":"object","description":"The connector parameters: \n* For AWS connectors, the parameters include the access key, secret key, associated accounts, and cloudtrails. \n* For keyless AWS connectors, the parameters include associated AWS accounts (sub-accounts) and cloudtrails. \n* For Azure connectors, the parameters include the application ID, tenant ID, client secret key, and an optional list of subscription IDs. If you don't provide subscription IDs, Tenable.io automatically discovers them.","properties":{"access_key":{"description":"For AWS connectors, the AWS access key.\n<b>Note: </b>The access key is not included in the keyless AWS connector parameters.","type":"string"},"trails":{"description":"For AWS connectors, a list of AWS cloudtrails associated with the connector.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"sub_accounts":{"description":"For AWS connectors, a list of AWS accounts associated with the connector.","type":"array","items":{"type":"object","properties":{"role_arn":{"type":"string","description":"The Amazon Resource Name (ARN) of the role generated based on the associated account ID."},"external_id":{"description":"The UUID of your Tenable.io instance used by AWS to identify it as a client application. You can obtain the UUID of your Tenable.io account using the GET /session endpoint. The UUID corresponds to the container_uuid attribute of the response message for that endpoint.","type":"string"},"trails":{"description":"For keyless AWS connectors, a list of AWS cloudtrails associated with the account.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on events instead of enumerating all assets in the account every single time."}}}},"status":{"description":"For Azure connectors, a list of import status records.","type":"array","items":{"type":"object","properties":{"last_event_seen":{"type":"string","description":"An ISO timestamp indicating the last time the connector found new or changed records and successfully imported them."},"release_timestamp":{"description":"An ISO timestamp indicating the last time the connector successfully completed an import (regardless of whether it found any changes).","type":"string"},"message":{"type":"string","description":"The extended import status message."}}}},"application_id":{"description":"For Azure connectors, Azure application ID.","type":"string"},"tenant_id":{"type":"string","description":"For Azure connectors, Azure tenant ID."},"subscription_id":{"type":"string","description":"For Azure connectors, Azure subscription ID. If you do not provide subscription IDs, Tenable.io automatically discovers them."},"service":{"description":"The service targeted by the connector. Values include:\n* aws \n* aws_keyless \n* azure\n* gcp","type":"string"}}}}},"examples":{"response":{"value":{"connector":{"type":"azure","human_type":"Azure","data_type":"assets","name":"Azure Connector - Updated","status":"Scheduled","status_message":"","schedule":{"units":"days","value":1},"schedule_full":{"units":"days","value":1},"date_created":"2019-03-24T23:21:42.898Z","id":"bc312ad1-6039-406b-b0a9-c0e311b05dc1","container_uuid":"gdf930d-7e3d-452c-82e8-494c1be98ef19","expired":false,"incremental_mode":false,"params":{"application_id":"559829df-59ba-49e4-94a0-6e5af2b508di","tenant_id":"5a2b8079-0320-405f-ad21-17a3103014f7","subscription_id":["a90ae1b5-20e2-4bf9-82b3-0082159365ea","c2fa7307-c53b-5ce0-a772-2ec880e85759"],"service":"azure"},"network_uuid":"13f04eb9-7c78-36c8-9025-fae048390f57"}}}}}}},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/settings/connectors{connector_id}":{"get":{"summary":"Get connector details","description":"Returns the details for the specified connector.<p>For information about connector error codes, see <a href=\"/docs/connectors-tio\">Connectors</a>.</p><p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"connectors-connector-details","tags":["Connectors"],"parameters":[{"description":"The UUID of the connector to return details for.","required":true,"name":"connector_id","in":"path","schema":{"type":"string"}}],"responses":{"200":{"description":"Returns the connector details.","content":{"application/json":{"schema":{"type":"object","properties":{"type":{"type":"string","description":"The type of the connector. Types include:\n - aws\n - aws_keyless\n - azure\n - gcp"},"human_type":{"type":"string","description":"The human-readable connector type."},"data_type":{"type":"string","description":"The data type imported by the connector. For Azure and AWS connectors, the value is always `assets`."},"name":{"type":"string","description":"The name of the connector. The name must be unique within a Tenable.io instance."},"network_uuid":{"type":"string","format":"UUID","description":"The UUID of the [network](https://developer.tenable.com/docs/manage-networks-tio) associated with the connector."},"status":{"type":"string","description":"The import status of the connector. Status values can include:\n - Completed—Tenable.io successfully used the connector to import assets (no imports scheduled)\n - Scheduled—Imports using the connector are scheduled for future dates\n - Saved—Tenable.io saved the connector configuration, but did not import assets at this time (no imports scheduled)\n - Error—Tenable.io failed to import assets using the connector"},"status_message":{"type":"string","description":"Extended description of the connector status. For information about connector error codes, see <a href=\"/docs/connectors-tio\">Connectors</a>."},"schedule":{"type":"object","properties":{}},"date_created":{"type":"string","description":"An ISO timestamp indicating the date and time on which the connector was created, for example, `2018-08-09T13:51:17.243Z`."},"date_modified":{"type":"string","description":"An ISO timestamp indicating the date and time on which the connector was last modified or new records were imported, for example, `2018-08-09T13:51:17.243Z`."},"id":{"type":"string","description":"The UUID of the connector."},"container_uuid":{"type":"string","description":"The UUID of the Tenable.io instance."},"expired":{"type":"boolean","description":"Indicates whether the Vulnerability Management license for the Tenable.io instance associated with the connector is expired."},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on on the service provider event stream instead of enumerating all assets in the account every single time."},"last_sync_time":{"type":"string","description":"An ISO timestamp indicating the date and time of the last successful import, for example, `2018-08-09T13:51:17.243Z`."},"params":{"type":"object","description":"The connector parameters: \n* For AWS connectors, the parameters include the access key, secret key, associated accounts, and cloudtrails. \n* For keyless AWS connectors, the parameters include associated AWS accounts (sub-accounts) and cloudtrails. \n* For Azure connectors, the parameters include the application ID, tenant ID, client secret key, and an optional list of subscription IDs. If you don't provide subscription IDs, Tenable.io automatically discovers them.","properties":{"access_key":{"description":"For AWS connectors, the AWS access key.\n<b>Note: </b>The access key is not included in the keyless AWS connector parameters.","type":"string"},"trails":{"description":"For AWS connectors, a list of AWS cloudtrails associated with the connector.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"sub_accounts":{"description":"For AWS connectors, a list of AWS accounts associated with the connector.","type":"array","items":{"type":"object","properties":{"role_arn":{"type":"string","description":"The Amazon Resource Name (ARN) of the role generated based on the associated account ID."},"external_id":{"description":"The UUID of your Tenable.io instance used by AWS to identify it as a client application. You can obtain the UUID of your Tenable.io account using the GET /session endpoint. The UUID corresponds to the container_uuid attribute of the response message for that endpoint.","type":"string"},"trails":{"description":"For keyless AWS connectors, a list of AWS cloudtrails associated with the account.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on events instead of enumerating all assets in the account every single time."}}}},"status":{"description":"For Azure connectors, a list of import status records.","type":"array","items":{"type":"object","properties":{"last_event_seen":{"type":"string","description":"An ISO timestamp indicating the last time the connector found new or changed records and successfully imported them."},"release_timestamp":{"description":"An ISO timestamp indicating the last time the connector successfully completed an import (regardless of whether it found any changes).","type":"string"},"message":{"type":"string","description":"The extended import status message."}}}},"application_id":{"description":"For Azure connectors, Azure application ID.","type":"string"},"tenant_id":{"type":"string","description":"For Azure connectors, Azure tenant ID."},"subscription_id":{"type":"string","description":"For Azure connectors, Azure subscription ID. If you do not provide subscription IDs, Tenable.io automatically discovers them."},"service":{"description":"The service targeted by the connector. Values include:\n* aws \n* aws_keyless \n* azure\n* gcp","type":"string"}}}}},"examples":{"response":{"value":{"connector":{"type":"aws","human_type":"AWS","data_type":"assets","name":"AWS Keyless Connector","status":"Scheduled","status_message":"","schedule":{"units":"days","value":1},"schedule_full":{"units":"days","value":1},"date_created":"2019-03-24T20:50:23.635Z","id":"f2506bed-bffa-442b-bfde-506c52306111","container_uuid":"gdf930d-7e3d-452c-82e8-494c1be98ef19","expired":false,"incremental_mode":false,"params":{"access_key":"AJIAJLRNVRLZRDZLVBXR","trails":[{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":""}],"service":"aws"},"network_uuid":"13f04eb9-7c78-36c8-9025-fae048390f57"}}}}}}},"404":{"description":"Returned if Tenable.io cannot not find the specified connector."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]},"delete":{"summary":"Delete connector","description":"Deletes the specified connector.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"connectors-delete-connector","tags":["Connectors"],"parameters":[{"description":"The UUID of the connector to delete.","required":true,"name":"connector_id","in":"path","schema":{"type":"string"}}],"responses":{"204":{"description":"Returned if Tenable.io successfully deleted the specified connector.","content":{"application/json":{"schema":{},"examples":{"response":{"value":{}}}}}},"404":{"description":"Returned if Tenable.io cannot find the specified connector."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/settings/connectors/aws/cloudtrails":{"post":{"summary":"List AWS cloudtrails","description":"Returns a list of available AWS cloudtrails. You can then use the cloudtrails to [create an AWS connector](#connectors-create-connector)</a>.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"connectors-get-aws-cloudtrails","tags":["Connectors"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"region":{"type":"array","description":"A complete list of available AWS regions as shown in the following example.","items":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}}},"credentials":{"type":"object","description":"For AWS connectors, the credentials object, including access key and secret key.","properties":{"access_key":{"type":"string","description":"The AWS access key."},"secret_key":{"type":"string","description":"The AWS secret key."}}},"account_id":{"type":"string","description":"For keyless AWS connectors, the AWS account ID."}},"required":["regions"]}}}},"responses":{"200":{"description":"Returned if Tenable.io successfully retrieves the list of cloudtrails.","content":{"application/json":{"schema":{"type":"object","properties":{"trails":{"type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}}}},"examples":{"response":{"value":{"trails":[{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/TenableAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"},{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":"success"}]}}}}}},"400":{"description":"Returned if you specify invalid input parameters."},"403":{"description":"Returned if you specify invalid AWS credentials or account ID."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}},"/settings/connectors/{connector_id}/import":{"post":{"summary":"Import data","description":"Imports data using a connector. This creates an asynchronous import job in Tenable.io. You can check the import status by examining the `status_message` property in [connector details](#connectors-connector-details)</a>.<p>Requires ADMINISTRATOR [64] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"connectors-import-assets-connector","tags":["Connectors"],"parameters":[{"description":"The UUID of the connector for which to import the data.","required":true,"name":"connector_id","in":"path","schema":{"type":"string"}}],"responses":{"200":{"description":"Returned if Tenable.io successfully schedules the connector for import.","content":{"application/json":{"schema":{"type":"object","properties":{"connector":{"type":"object","properties":{"type":{"type":"string","description":"The type of the connector. Types include:\n - aws\n - aws_keyless\n - azure\n - gcp"},"human_type":{"type":"string","description":"The human-readable connector type."},"data_type":{"type":"string","description":"The data type imported by the connector. For Azure and AWS connectors, the value is always `assets`."},"name":{"type":"string","description":"The name of the connector. The name must be unique within a Tenable.io instance."},"network_uuid":{"type":"string","format":"UUID","description":"The UUID of the [network](https://developer.tenable.com/docs/manage-networks-tio) associated with the connector."},"status":{"type":"string","description":"The import status of the connector. Status values can include:\n - Completed—Tenable.io successfully used the connector to import assets (no imports scheduled)\n - Scheduled—Imports using the connector are scheduled for future dates\n - Saved—Tenable.io saved the connector configuration, but did not import assets at this time (no imports scheduled)\n - Error—Tenable.io failed to import assets using the connector"},"status_message":{"type":"string","description":"Extended description of the connector status. For information about connector error codes, see <a href=\"/docs/connectors-tio\">Connectors</a>."},"schedule":{"type":"object","properties":{}},"date_created":{"type":"string","description":"An ISO timestamp indicating the date and time on which the connector was created, for example, `2018-08-09T13:51:17.243Z`."},"date_modified":{"type":"string","description":"An ISO timestamp indicating the date and time on which the connector was last modified or new records were imported, for example, `2018-08-09T13:51:17.243Z`."},"id":{"type":"string","description":"The UUID of the connector."},"container_uuid":{"type":"string","description":"The UUID of the Tenable.io instance."},"expired":{"type":"boolean","description":"Indicates whether the Vulnerability Management license for the Tenable.io instance associated with the connector is expired."},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on on the service provider event stream instead of enumerating all assets in the account every single time."},"last_sync_time":{"type":"string","description":"An ISO timestamp indicating the date and time of the last successful import, for example, `2018-08-09T13:51:17.243Z`."},"params":{"type":"object","description":"The connector parameters: \n* For AWS connectors, the parameters include the access key, secret key, associated accounts, and cloudtrails. \n* For keyless AWS connectors, the parameters include associated AWS accounts (sub-accounts) and cloudtrails. \n* For Azure connectors, the parameters include the application ID, tenant ID, client secret key, and an optional list of subscription IDs. If you don't provide subscription IDs, Tenable.io automatically discovers them.","properties":{"access_key":{"description":"For AWS connectors, the AWS access key.\n<b>Note: </b>The access key is not included in the keyless AWS connector parameters.","type":"string"},"trails":{"description":"For AWS connectors, a list of AWS cloudtrails associated with the connector.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"sub_accounts":{"description":"For AWS connectors, a list of AWS accounts associated with the connector.","type":"array","items":{"type":"object","properties":{"role_arn":{"type":"string","description":"The Amazon Resource Name (ARN) of the role generated based on the associated account ID."},"external_id":{"description":"The UUID of your Tenable.io instance used by AWS to identify it as a client application. You can obtain the UUID of your Tenable.io account using the GET /session endpoint. The UUID corresponds to the container_uuid attribute of the response message for that endpoint.","type":"string"},"trails":{"description":"For keyless AWS connectors, a list of AWS cloudtrails associated with the account.","type":"array","items":{"type":"object","properties":{"arn":{"type":"string","description":"Amazon Resource Name (ARN) of the cloudtrail."},"name":{"type":"string","description":"The name of the cloudtrail."},"region":{"type":"object","properties":{"name":{"type":"string","description":"The AWS region code, for example, `us-east-1`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions."},"friendly_name":{"description":"The AWS region name, for example, `US East (N. Virginia)`. The value of `All` indicates that the cloudtrail is associated with all AWS available regions.","type":"string"}}},"availability":{"description":"Indicates whether a cloudtrail is available to be used by a connector (logging is turned on in AWS, or it has at least one EventSelector with IncludeManagementEvents). Values include:\n - `success`—The cloudtrail is available.\n - `error`—The cloudtrail is not available.","type":"string","enum":["success","error"]}}}},"incremental_mode":{"type":"boolean","description":"Indicates whether a connector has completed the initial full import successfully. If the value is `true`, then the connector is in incremental mode where it imports assets based on events instead of enumerating all assets in the account every single time."}}}},"status":{"description":"For Azure connectors, a list of import status records.","type":"array","items":{"type":"object","properties":{"last_event_seen":{"type":"string","description":"An ISO timestamp indicating the last time the connector found new or changed records and successfully imported them."},"release_timestamp":{"description":"An ISO timestamp indicating the last time the connector successfully completed an import (regardless of whether it found any changes).","type":"string"},"message":{"type":"string","description":"The extended import status message."}}}},"application_id":{"description":"For Azure connectors, Azure application ID.","type":"string"},"tenant_id":{"type":"string","description":"For Azure connectors, Azure tenant ID."},"subscription_id":{"type":"string","description":"For Azure connectors, Azure subscription ID. If you do not provide subscription IDs, Tenable.io automatically discovers them."},"service":{"description":"The service targeted by the connector. Values include:\n* aws \n* aws_keyless \n* azure\n* gcp","type":"string"}}}}}}},"examples":{"response":{"value":{"connector":{"type":"aws","human_type":"AWS","data_type":"assets","name":"AWS Connector","status":"Scheduled","status_message":"Import completed successfully","date_created":"2019-03-25T17:21:19.495Z","date_modified":"2019-03-25T17:21:28.457Z","id":"8d70056d-eee5-4ef5-a5b2-0acc0262c59d","container_uuid":"gdf930d-7e3d-452c-82e8-494c1be98ef19","expired":false,"incremental_mode":false,"last_sync_time":"2019-03-25T17:21:28.457Z","params":{"access_key":"AJIAJLRNVRLZRDZLVBXR","trails":[{"arn":"arn:aws:cloudtrail:us-east-1:069647819620:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"All","friendly_name":"All"},"availability":""}],"sub_accounts":[{"role_arn":"arn:aws:iam::795163652895:role/tenableio-connector","external_id":"gdf930d-7e3d-452c-82e8-494c1be98ef19","trails":[{"arn":"arn:aws:cloudtrail:us-east-1:795163652895:trail/ExampleAWSTrail","name":"ExampleAWSTrail","region":{"name":"us-west-1","friendly_name":"us-west-1"},"availability":""}],"incremental_mode":false,"account_id":"795163652895"}],"service":"aws"},"network_uuid":"13f04eb9-7c78-36c8-9025-fae048390f57"}}}}}}},"404":{"description":"Returned if Tenable.io cannot find the connector you specified."},"429":{"description":"Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](/docs/rate-limiting).","content":{"text/html":{"examples":{"response":{"value":"<html>\n\n<head>\n <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n <center>\n <h1>429 Too Many Requests</h1>\n </center>\n <hr>\n <center>nginx</center>\n</body>\n\n</html>"}}}}}},"security":[{"cloud":[]}]}}},"x-explorer-enabled":true,"x-proxy-enabled":true,"x-samples-enabled":true} |