satori api.yaml
openapi: 3.0.1
info:
title: Satori API
description: |-
This is an API SatoriCyber portal. Most API are protected bearer authentication. API identities should be created with Satori management portal.
Use authentication API for token creation.
termsOfService: http://swagger.io/terms/
contact:
email: support@satoricyber.com
license:
name: Apache 2.0
url: http://www.apache.org/licenses/LICENSE-2.0.html
version: "1.0"
tags:
- name: Accounts
description: "An account represents a Satori customer organization. Each account
\ has a unique identifier. Accounts contain objects such as Data Stores and Data
\ Access Controllers, Datasets, Security Policies and Masking Profiles."
- name: Service Accounts
description: "Service accounts are identities of the account that should only be
\ used for API access and process automation. Once you create a service account,
\ Satori generates service account credentials which are used to obtain authentication
\ tokens. Service accounts are assigned with a role that determines their permissions."
- name: DAC Access Tokens
description: "DAC access tokens are credentials used when integrating Satori with
\ BI tools. DAC access tokens should be kept secret, like passwords."
- name: Data Access Requests
description: "Data access requests are used to enable users to gain access to data
\ that is organized in datasets which include databases, schemas, tables or other
\ data assets. Once approved, the data consumer can then query the various data
\ stores to retrieve or manipulate data."
- name: Audit Log
description: "The Audit Log allows you to obtain complete, uniform and searchable
\ data access audits for all data stores with full user, access and data context.
\
The audit log data is retained in the account indefinitely and there
\ is no retention or roll-off window for the data. On the audit page, you can
\ query up to 90 days of audit data at a time."
- name: Data Export
description: "Data Export allows Satori customers to export the audit records to
\ their own storage system. Supported storage systems: Snowflake.
The
\ audit log data includes data access metadata such as queries, time of query,
\ usernames, data store, tags, locations, action types, country, volume, records,
\ tool used, policy name, city, time zone, client IP address, audit ID, query
\ ID, Auth. method, response time and processing time."
- name: Identity Providers
description: "Satori integrates with identity providers to manage users and groups
\ via the SCIM protocol.
The identity provider (IdP) is a service that
\ stores and verifies user identity. IdPs are typically cloud-hosted services,
\ and they often work with single sign-on (SSO) providers to authenticate users."
- name: "Data Inventory [DEPRECATED]"
description: This collection of Data Inventory API methods has been deprecated.
Refer to the new Data Inventory APIs based on assets.
- name: Masking Profiles
description: Satori’s masking profiles allow organizations to mask query responses
for their users to avoid exposing sensitive information.
Satori’s masking profiles can be applied to data detected and tagged by Satori’s data classification and tagging mechanism. - name: Security Policies description: The Satori Security Policy is a re-usable object that can be configured to contain multiple sets of dynamic masking configurations and data filtering configurations.
Satori's security policy engine is designed to protect
an organization's data by authorizing specific individuals or groups of individuals
to view data. The main objective of a security policy is to protect an organization's
business interests.
- name: Users and Roles
description: "Each Satori account can be accessed by multiple users. Each user is
\ assigned with a role to reflect their responsibilities.
There are 2
\ types of users in Satori:
- Account User - The account
\ user is created by the account admins in the management console. Account users
\ are required to use two-factor authentication which must be configured at the
\ first time log in. - Identity Provider User - The identity
\ provider user is created when a new user logins via SSO.
"
- name: Data Inventory
description: "Satori’s Data Inventory dynamically creates an inventory of the organization's
\ data, featuring the built-in Satori classifications. The data inventory provides
\ a holistic view of the organization's sensitive data and access patterns and
\ is augmented by powerful navigation, filtering and search functions.
The
\ inventory is a collection of assets. An asset represents a data asset in a data
\ store, for example: a database, schema, table or column in a relational database,
\ a database or a collection in MongoDB and so on.
In some data stores,
\ Satori supports listing semi-structured assets nested inside other assets. For
\ example, in a variant column in Snowflake users can store data in a JSON-like
\ format. Satori refers to such assets as semi-structured assets that are sub-assets
\ of the regular, structured assets."
- name: Data Access Controllers (DACs)
description: Satori provides multiple Data Access Controller (DAC) deployment options
to support the operational and security requirements of organizations.
- name: Datasets
description: "A dataset is a collection of data store objects such as tables or
\ schemas from one or more data stores, that you wish to govern access to as a
\ single unit.
Data engineers create datasets as part of the data development
\ lifecycle. Once a dataset is defined you can then assign a data stewards to
\ manage the day to day operations of access to data."
- name: User Directory
description: "The User Directory enables Satori administrators to define user groups
\ in Satori based on existing users, identity provider groups and data store groups.
\
Groups are used to set policies or analyze data access. Satori groups
\ are useful for organizations that do not use an identity provider, or in cases
\ where the association of users to groups in the identity provider does not match
\ how data is accessed."
- name: Taxonomy
description: The Satori taxonomy is predefined by Satori. You can not modify the
Satori Platform taxonomy tag categories or their classification tags.
The
Satori custom data classification mechanism is designed to provide you with the
ability to extend and enhance the Satori classification system by enabling you
to create additional categories and data classifiers specific to your business
or organization.
- name: Data Access Rules
description: Permissions to access data are defined for individual users or groups
and are limited to a predefined time range. Satori can automatically revoke permissions
if they are unused. This helps organizations avoid excess and unused permissions.
- name: Service Account Authentication
description: Service accounts are used for API access and process automation.
paths:
/api/accounts/{id}:
get:
tags:
- Accounts
summary: Retrieve an Account
description: This HTTP GET method is used to retrieve the details of a specific
account by its unique identifier (id).
operationId: byId
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/AccountOutput"
"400":
description: Invalid ID supplied
"404":
description: Account not found
security:
- BearerAuth: []
/api/accounts/{id}/settings/data-portal/pre-defined-data-access-purposes:
get:
tags:
- Accounts
summary: Retrieve Pre-Defined Data Access Purposes
description: This HTTP GET method is used to retrieve the list of predefined
data access purposes of the specified account.
operationId: getAccountDataPortalPreDefinedDataAccessPurpose
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
type: array
items:
$ref: "#/components/schemas/PreDefinedDataAccessPurposesOutput"
"400":
description: Bad configuration request
security:
- BearerAuth: []
/api/accounts/{id}/theme:
get:
tags:
- Accounts
summary: Retrieve Account Theme
description: "This HTTP GET method is used to fetch the theme settings associated
\ with a particular customer (Organization) account.
The theme settings
\ include visual customization options such as colors, fonts, logos, backgrounds
\ and design elements that define the look and feel of the account's interface
\ or user experience."
operationId: getAccountTheme
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/AccountThemeOutput"
"400":
description: Invalid ID supplied
"404":
description: Account not found
security:
- BearerAuth: []
put:
tags:
- Accounts
summary: Update Account Theme
description: "This HTTP PUT method is used to update the theme settings of a
\ specific customer account. This request includes the new theme settings,
\ such as updated colors, fonts, logos, backgrounds and design elements."
operationId: updateAccountTheme
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
multipart/form-data:
schema:
type: object
properties:
logo:
$ref: "#/components/schemas/FormDataContentDisposition"
logoMimeTypes:
type: string
logoSize:
type: integer
format: int32
backgroundColor:
type: string
textPrimaryColor:
type: string
primaryColor:
type: string
enabled:
type: boolean
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/AccountThemeOutput"
"400":
description: Invalid ID supplied
"404":
description: Account not found
security:
- BearerAuth: []
/api/accounts/{id}/identities:
get:
tags:
- Accounts
summary: List All User Identities
description: This HTTP GET method is used to fetch the list of identities linked
to a specified account. "Identities" refers to users and service accounts.
operationId: getAllAccountIdentities
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/IdentityMinimalOutput"
"400":
description: Invalid ID supplied
"404":
description: Account not found
security:
- BearerAuth: []
/api/accounts/{id}/identities-with-custom-expiration-time:
get:
tags:
- Accounts
summary: List Users with Custom Temporary Credentials Expiration
description: This HTTP GET method is used to fetch the list of users or groups
that has been configured with custom temporary credentials expiration.
operationId: getCustomExpirationTimeForAllIdentitiesInAccount
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/IdentitiesExpirationTimeOutput"
"400":
description: Invalid ID supplied
"404":
description: Account not found
security:
- BearerAuth: []
/api/accounts/{id}/settings/data-portal:
put:
tags:
- Accounts
summary: Update Data Portal Settings
description: "This PUT method is used to update the settings related to the
\ data portal for a specific account. The data portal settings include temporary
\ credentials for data access, predefined data access purpose and personal
\ access tokens associated with the account set in the management console."
operationId: updateAccountDataPortalSettings
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/AccountDataPortalSettingsDto"
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/AccountOutput"
"400":
description: Bad configuration request
security:
- BearerAuth: []
/api/accounts/{id}/notifications:
post:
tags:
- Accounts
summary: Update Account Notification Settings
description: This HTTP POST method is used to create new notifications associated
with the specified account. Notifications (DAC Alerts) are used notifying
the user about the current DAC version and certificate expirations.
operationId: updateAccountNotification
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
type: array
items:
$ref: "#/components/schemas/NotificationSettingDto"
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/NotificationsSettingsOutput"
"400":
description: Invalid ID supplied
"404":
description: Account not found
security:
- BearerAuth: []
/api/accounts/{id}/settings:
put:
tags:
- Accounts
summary: Update Account General Settings
description: This HTTP PUT method is used to update the general settings of
the specified account. These settings include the account name and SSO configurations
related to the account.
operationId: updateAccountSettings
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/AccountSettingsInput"
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/AccountOutput"
"400":
description: Bad configuration request
security:
- BearerAuth: []
/api/service-accounts/{id}:
get:
tags:
- Service Accounts
summary: Retrieve a Service Account
description: "This HTTP GET method is used to fetch the details of the specified
\ service account. A service account details include the name, creation date,
\ last updated date, the creator's name, the account ID and a description."
operationId: byId_1
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/AccountServiceOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
delete:
tags:
- Service Accounts
summary: Delete a service account
description: The HTTP DELETE method is used to delete a service account from
the system.
operationId: deleteById
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/service-accounts:
get:
tags:
- Service Accounts
summary: List all Service Accounts
description: "This HTTP GET method is used to fetch a list of all the service
\ accounts in the system. The service account details include the name, creation
\ date, last updated date, the creator's name, the account ID and a description
\ for the service accounts."
operationId: getAll
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/AccountServiceQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
post:
tags:
- Service Accounts
summary: Create a Service Account
description: "This HTTP POST method is used to create a new service account.The
\ service account includes an account ID, a description and the service account
\ key.
NOTE: Service accounts are created with an automatically generated
\ key that is not kept in the system."
operationId: create
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/ApiIdentityInput"
responses:
"201":
description: "Status OK, service account created."
content:
application/json:
schema:
$ref: "#/components/schemas/AccountServiceKeyOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/service-accounts/{id}/roles:
get:
tags:
- Service Accounts
summary: Retrieve a Service Account Role
description: This HTTP GET method is used to fetch the roles that have been
assigned to a specific service account. Roles typically define the permissions
and access rights the service account has within the system.
operationId: getServiceAccountRole
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, roles found"
content:
application/json:
schema:
type: array
items:
$ref: "#/components/schemas/RoleOutput"
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/service-accounts/{id}/reset-api-key:
post:
tags:
- Service Accounts
summary: Reset a Service Account Key
description: "This HTTP POST method is used to reset the service account key
\ for the specified service account. Resetting a service account key is done
\ for security reasons, such as when the key may have been compromised or
\ when it's necessary to rotate keys periodically.
NOTE: The key is
\ automatically generated and is not kept in the system."
operationId: resetApiKey
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, service account key was reset."
content:
application/json:
schema:
$ref: "#/components/schemas/AccountServiceKeyOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/service-accounts/{id}/roles/{roleId}:
put:
tags:
- Service Accounts
summary: Assign a Service Account Role
description: This HTTP PUT method is used to assign a new role to a service
account or update an existing role assignment. Roles determine what permissions
and access levels the service account will have.
operationId: setServiceAccountRole
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: roleId
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, service account role was changed"
"401":
description: Invalid Authorization
"404":
description: Provided role id lookup failed
security:
- BearerAuth: []
/api/dac-access-token/{id}:
get:
tags:
- DAC Access Tokens
summary: Retrieve a Dac Access Token
description: This HTTP GET method is used to fetch details about a specific
DAC access token.
operationId: getById
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, dac access token is found."
content:
application/json:
schema:
$ref: "#/components/schemas/DacAccessTokenOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- DAC Access Tokens
summary: Update a DACs Access Token
description: "This HTTP PUT method is used to update the details of a DAC access
\ token. Updates include changes to the token's permissions, expiration date
\ or status."
operationId: updateById
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DacAccessTokenInput"
required: true
responses:
"200":
description: "Status OK, DACs access token is updated"
content:
application/json:
schema:
$ref: "#/components/schemas/DacAccessTokenOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
post:
tags:
- DAC Access Tokens
summary: Create a Dac Access Token
description: "This HTTP POST method is used to create, renew or regenerate a
\ DAC access token."
operationId: create_1
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DacAccessTokenInput"
required: true
responses:
"201":
description: "Status OK, dac access token is created"
content:
application/json:
schema:
$ref: "#/components/schemas/DacAccessTokenOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
delete:
tags:
- DAC Access Tokens
summary: Delete a DACs access token
description: "This HTTP DELETE method is used to remove a DAC access token,
\ effectively invalidating it and preventing any further use."
operationId: deleteById_1
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/dac-access-token:
get:
tags:
- DAC Access Tokens
summary: List all the DACs Access Tokens
description: "This HTTP GET method is used to fetch details about all the DAC
\ access tokens in the system. This includes information such as token IDs,
\ the creation date, update date, updated by, issuance dates, the DAC name,
\ permissions and expiration date and time."
operationId: getAll_1
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DacAccessTokenQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/data-access-request/{id}/approve:
post:
tags:
- Data Access Requests
summary: Approve a Data Access Request
description: "This HTTP POST method is used to approve a data access request,
\ granting the data consumer access to the requested dataset. This is part
\ of a data access request flow, where a user (data consumer) must receive
\ an approval before being granted access to a specific dataset."
operationId: approveById
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/ApproveAccessRequestInput"
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/data-access-request/{id}:
get:
tags:
- Data Access Requests
summary: Retrieve a Data Access Request
description: "This HTTP GET method is used to fetch user information about a
\ specific data access request including, the user name, message, usage purpose
\ and data access level for the requested dataset."
operationId: byId_2
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, dataset found."
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRequestOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
delete:
tags:
- Data Access Requests
summary: Delete a Data Access Request
description: This HTTP DELETE method is used to remove or cancel a data access
request.
operationId: deleteById_2
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DeleteAccessRequestInput"
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/data-access-request:
get:
tags:
- Data Access Requests
summary: List all Dataset's Data Access Requests
description: "This HTTP GET method is used to fetch details about all data access
\ requests, including their status, requester information and requested datasets."
operationId: getAll_2
parameters:
- name: parentId
in: query
description: "Parent ID is required query param, should be a data policy ID"
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRequestQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/data-access-request/by-account-id:
get:
tags:
- Data Access Requests
summary: List Account's Data Access Requests
description: "This HTTP GET method is used to fetch all data access requests
\ associated with the specified account.
The data access request details
\ include, the name, display name, creation date, the data access level, unused
\ time limit, message, usage purpose, security policies, masking profiles
\ and whether the data access requires an approvers note."
operationId: getAllByAccountId
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: identity
in: query
schema:
type: array
items:
type: string
- name: identityType
in: query
schema:
type: array
items:
type: string
enum:
- USER
- DB_USER
- GROUP
- IDP_GROUP
- DATABRICKS_GROUP
- DATABRICKS_SERVICE_PRINCIPAL
- SNOWFLAKE_ROLE
- SNOWFLAKE_ACCOUNT_NAME
- SNOWFLAKE_DATABASE_ROLE
- CEL
- EVERYONE
- name: accessLevel
in: query
schema:
type: array
items:
type: string
- name: parent
in: query
schema:
type: array
items:
type: string
- name: datasetId
in: query
schema:
type: array
items:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRequestOverviewQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/data-access-request/approvable-requests:
get:
tags:
- Data Access Requests
summary: Lists all User's Approvable Requests
description: "This HTTP GET method is used to fetch all data access requests
\ that the current user (manager or data steward) has the authority to approve.
\
This is particularly useful for users with specific roles, such
\ as administrators, data stewards or managers, who need to review and manage
\ pending requests."
operationId: getApprovableRequests
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: userId
in: query
description: "When userId is specified, the requester should have READ permission
\ on that user. When it is not specified, the 'userId' will be handled with
\ the current user"
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/ListDataAccessRequestOverviewOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/data-access-request/submit-request:
post:
tags:
- Data Access Requests
summary: Create a Data Access Request
description: "This HTTP POST method allows a user to submit a request for access
\ to a specific dataset.
The data access request details include,
\ the username, the data access level, usage purpose and the data access rule."
operationId: submitRequest
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: parentId
in: query
description: "Parent ID is required query param, should be a data policy ID"
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/UserAccessRequestInput"
responses:
"202":
description: "Status OK, request created."
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/data-flow/analytics/{accountId}/tools:
get:
tags:
- Audit Log
summary: Retrieve an Aggregated List of Tools
description: "This HTTP GET method is used to fetch a list of analytics tools
\ that are linked to a specific account. These tools include software or platforms
\ used for data analysis, BI tools, or other analytics-related tasks."
operationId: genericToolsStats
parameters:
- name: accountId
in: path
required: true
schema:
type: string
- name: from
in: query
description: "Start query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625573940000
- name: to
in: query
description: "End query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625660399999
- name: dataStoreIdsFilter
in: query
schema:
type: array
items:
type: string
- name: dataStoreTypes
in: query
schema:
type: array
items:
type: string
- name: userNamesFilter
in: query
schema:
type: array
items:
type: string
- name: authMethodFilter
in: query
schema:
type: array
items:
type: string
- name: toolsFilter
in: query
schema:
type: array
items:
type: string
- name: toolTypesFilter
in: query
schema:
type: array
items:
type: string
- name: toolDriversFilter
in: query
schema:
type: array
items:
type: string
- name: locationsFilter
in: query
schema:
type: array
items:
type: string
- name: tagsFilter
in: query
schema:
type: array
items:
type: string
- name: incidentIdsFilter
in: query
schema:
type: array
items:
type: string
- name: policyNamesFilter
in: query
schema:
type: array
items:
type: string
- name: countriesFilter
in: query
schema:
type: array
items:
type: string
- name: citiesFilter
in: query
schema:
type: array
items:
type: string
- name: ipsFilter
in: query
schema:
type: array
items:
type: string
- name: actionTypesFilter
in: query
description: Filter for action types
schema:
type: array
items:
type: string
enum:
- ACTION_NONE
- ACTION_ALERT
- ACTION_BLOCK
- ACTION_MASK
- ACTION_REQUEST_BLOCK
- ACTION_ROW_FILTER
- ACTION_ORCH_MASK_POLICY_EXECUTED
- ACTION_ORCH_ROW_FILTER_POLICY_EXECUTED
- name: tagCategoriesFilter
in: query
schema:
type: array
items:
type: string
- name: hasIncidentsFilter
in: query
schema:
type: boolean
- name: hasIncidentsFilterV2
in: query
schema:
type: boolean
- name: hasDataStoreErrorsFilter
in: query
schema:
type: boolean
- name: includeAdministrateQueriesFilter
in: query
schema:
type: boolean
default: false
- name: governedQueries
in: query
schema:
type: array
items:
type: string
enum:
- GOVERNED
- UNGOVERNED
- name: groupsFilter
in: query
schema:
type: array
items:
type: string
- name: datasetsFilter
in: query
schema:
type: array
items:
type: string
- name: securityPoliciesFilter
in: query
schema:
type: array
items:
type: string
- name: flowId
in: query
schema:
type: string
- name: accessPermissionIds
in: query
schema:
type: array
items:
type: string
- name: queryIdFilter
in: query
schema:
type: string
- name: genericPropertiesFilter
in: query
schema:
type: string
- name: recordsRangeFilter
in: query
description: |-
This is a range parameter for the number of records returned from query of the form 'min:max'.
for example, '1:30' is a min of 1 and a max of 30, ':20' is without min and a max of 20 schema: type: string - name: volumesRangeFilter in: query description: |- This is a range parameter for the data volume returned from the query of the form 'min:max'.
for example, '1:30' is a min of 1 and a max of 30, ':20' is without min and a max of 20 schema: type: string - name: responseTime in: query description: |- This is a range parameter for the data store response time of the query of the form 'min:max'.
for example, '1:30' is a min of 1 and a max of 30, ':20' is without min and a max of 20 schema: type: string - name: processingTime in: query description: |- This is a range parameter for the processing time it took satori while running the query of the form 'min:max'.
for example, '1:30' is a min of 1 and a max of 30, ':20' is without min and a max of 20
schema:
type: string
- name: statementType
in: query
schema:
type: array
items:
type: string
- name: loginName
in: query
schema:
type: array
items:
type: string
- name: purposeSearch
in: query
schema:
type: string
responses:
"200":
description: "Status OK, metrics returned"
content:
application/json:
schema:
type: array
items:
$ref: "#/components/schemas/ActionListEntry"
example: |2
[
{
"toolName": "e.g. Python"
"numberOfQueries": 74
},
{}
]
"400":
description: Bad request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/data-flow/analytics/{accountId}/counters:
get:
tags:
- Audit Log
summary: Retrieve a Data Flow Aggregated Counters
description: This HTTP GET method is used to fetch a set of counters or metrics
that provide insights into the data flow activities and performance for the
specified account.
operationId: getDataFlowCounters
parameters:
- name: accountId
in: path
required: true
schema:
type: string
- name: from
in: query
description: "Start query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625573940000
- name: to
in: query
description: "End query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625660399999
- name: dataStoreIdsFilter
in: query
schema:
type: array
items:
type: string
- name: dataStoreTypes
in: query
schema:
type: array
items:
type: string
- name: userNamesFilter
in: query
schema:
type: array
items:
type: string
- name: authMethodFilter
in: query
schema:
type: array
items:
type: string
- name: toolsFilter
in: query
schema:
type: array
items:
type: string
- name: toolTypesFilter
in: query
schema:
type: array
items:
type: string
- name: toolDriversFilter
in: query
schema:
type: array
items:
type: string
- name: locationsFilter
in: query
schema:
type: array
items:
type: string
- name: tagsFilter
in: query
schema:
type: array
items:
type: string
- name: incidentIdsFilter
in: query
schema:
type: array
items:
type: string
- name: policyNamesFilter
in: query
schema:
type: array
items:
type: string
- name: countriesFilter
in: query
schema:
type: array
items:
type: string
- name: citiesFilter
in: query
schema:
type: array
items:
type: string
- name: ipsFilter
in: query
schema:
type: array
items:
type: string
- name: actionTypesFilter
in: query
description: Filter for action types
schema:
type: array
items:
type: string
enum:
- ACTION_NONE
- ACTION_ALERT
- ACTION_BLOCK
- ACTION_MASK
- ACTION_REQUEST_BLOCK
- ACTION_ROW_FILTER
- ACTION_ORCH_MASK_POLICY_EXECUTED
- ACTION_ORCH_ROW_FILTER_POLICY_EXECUTED
- name: tagCategoriesFilter
in: query
schema:
type: array
items:
type: string
- name: hasIncidentsFilter
in: query
schema:
type: boolean
- name: hasIncidentsFilterV2
in: query
schema:
type: boolean
- name: hasDataStoreErrorsFilter
in: query
schema:
type: boolean
- name: includeAdministrateQueriesFilter
in: query
schema:
type: boolean
default: false
- name: governedQueries
in: query
schema:
type: array
items:
type: string
enum:
- GOVERNED
- UNGOVERNED
- name: groupsFilter
in: query
schema:
type: array
items:
type: string
- name: datasetsFilter
in: query
schema:
type: array
items:
type: string
- name: securityPoliciesFilter
in: query
schema:
type: array
items:
type: string
- name: flowId
in: query
schema:
type: string
- name: accessPermissionIds
in: query
schema:
type: array
items:
type: string
- name: queryIdFilter
in: query
schema:
type: string
- name: genericPropertiesFilter
in: query
schema:
type: string
- name: recordsRangeFilter
in: query
description: |-
This is a range parameter for the number of records returned from query of the form 'min:max'.
for example, '1:30' is a min of 1 and a max of 30, ':20' is without min and a max of 20
schema:
type: string
- name: statementType
in: query
schema:
type: array
items:
type: string
- name: loginName
in: query
schema:
type: array
items:
type: string
- name: purposeSearch
in: query
schema:
type: string
responses:
"200":
description: "Status OK, metrics returned"
content:
application/json:
schema:
$ref: "#/components/schemas/StatsGenericOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/data-flow/analytics/{accountId}/actions:
get:
tags:
- Audit Log
summary: Retrieve an Aggregated List of Actions
description: This HTTP GET method is used to fetch a list of actions or events
that have occurred within the data flow analytics processes for the specified
account.
operationId: violationSummaryAPI
parameters:
- name: accountId
in: path
required: true
schema:
type: string
- name: from
in: query
description: "Start query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625573940000
- name: to
in: query
description: "End query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625660399999
- name: dataStoreIdsFilter
in: query
schema:
type: array
items:
type: string
- name: dataStoreTypes
in: query
schema:
type: array
items:
type: string
- name: userNamesFilter
in: query
schema:
type: array
items:
type: string
- name: authMethodFilter
in: query
schema:
type: array
items:
type: string
- name: toolsFilter
in: query
schema:
type: array
items:
type: string
- name: toolTypesFilter
in: query
schema:
type: array
items:
type: string
- name: toolDriversFilter
in: query
schema:
type: array
items:
type: string
- name: locationsFilter
in: query
schema:
type: array
items:
type: string
- name: tagsFilter
in: query
schema:
type: array
items:
type: string
- name: incidentIdsFilter
in: query
schema:
type: array
items:
type: string
- name: policyNamesFilter
in: query
schema:
type: array
items:
type: string
- name: countriesFilter
in: query
schema:
type: array
items:
type: string
- name: citiesFilter
in: query
schema:
type: array
items:
type: string
- name: ipsFilter
in: query
schema:
type: array
items:
type: string
- name: actionTypesFilter
in: query
description: Filter for action types
schema:
type: array
items:
type: string
enum:
- ACTION_NONE
- ACTION_ALERT
- ACTION_BLOCK
- ACTION_MASK
- ACTION_REQUEST_BLOCK
- ACTION_ROW_FILTER
- ACTION_ORCH_MASK_POLICY_EXECUTED
- ACTION_ORCH_ROW_FILTER_POLICY_EXECUTED
- name: tagCategoriesFilter
in: query
schema:
type: array
items:
type: string
- name: hasIncidentsFilter
in: query
schema:
type: boolean
- name: hasIncidentsFilterV2
in: query
schema:
type: boolean
- name: hasDataStoreErrorsFilter
in: query
schema:
type: boolean
- name: includeAdministrateQueriesFilter
in: query
schema:
type: boolean
default: false
- name: governedQueries
in: query
schema:
type: array
items:
type: string
enum:
- GOVERNED
- UNGOVERNED
- name: groupsFilter
in: query
schema:
type: array
items:
type: string
- name: datasetsFilter
in: query
schema:
type: array
items:
type: string
- name: securityPoliciesFilter
in: query
schema:
type: array
items:
type: string
- name: flowId
in: query
schema:
type: string
- name: accessPermissionIds
in: query
schema:
type: array
items:
type: string
- name: queryIdFilter
in: query
schema:
type: string
- name: genericPropertiesFilter
in: query
schema:
type: string
- name: recordsRangeFilter
in: query
description: |-
This is a range parameter for the number of records returned from query of the form 'min:max'.
for example, '1:30' is a min of 1 and a max of 30, ':20' is without min and a max of 20
schema:
type: string
- name: statementType
in: query
schema:
type: array
items:
type: string
- name: loginName
in: query
schema:
type: array
items:
type: string
- name: purposeSearch
in: query
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/ViolationsResponse"
"400":
description: Bad request
security:
- BearerAuth: []
/api/data-flow/{accountId}/export:
get:
tags:
- Audit Log
summary: Export all Data Flows
description: "[Deprecated - use /api/export/data-flow] This HTTP GET method
\ is used to export audit logs in CSV format.
The exported data is
\ in CSV format and includes various types of information such as a list of
\ governed and ungoverned queries, masking and filtering actions, classification
\ categories, response and processing times, generic properties and login
\ name."
operationId: export
parameters:
- name: accountId
in: path
required: true
schema:
type: string
- name: from
in: query
description: "Start query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625573940000
- name: to
in: query
description: "End query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625660399999
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: fields
in: query
description: Field names which will be returned as columns in the responded
list
schema:
type: array
items:
type: string
enum:
- flow_timestamp
- identity.name
- data_store.id
- data_store.name
- data_store.type
- datasets.name
- datasets.id
- tags.name
- locations.length
- locations.location
- query.query_type
- volume.value
- records.value
- query.original_query
- tool
- incident_ids
- actions.policy_names
- result_set.column_name
- actions.type
- identity.authentication.method
- query.db_statement_type
- perf_stats.processing_time
- perf_stats.ds_response_time
- name: dataStoreIdsFilter
in: query
schema:
type: array
items:
type: string
- name: dataStoreTypes
in: query
schema:
type: array
items:
type: string
- name: userNamesFilter
in: query
schema:
type: array
items:
type: string
- name: authMethodFilter
in: query
schema:
type: array
items:
type: string
- name: toolsFilter
in: query
schema:
type: array
items:
type: string
- name: toolTypesFilter
in: query
schema:
type: array
items:
type: string
- name: toolDriversFilter
in: query
schema:
type: array
items:
type: string
- name: locationsFilter
in: query
schema:
type: array
items:
type: string
- name: tagsFilter
in: query
schema:
type: array
items:
type: string
- name: incidentIdsFilter
in: query
schema:
type: array
items:
type: string
- name: policyNamesFilter
in: query
schema:
type: array
items:
type: string
- name: countriesFilter
in: query
schema:
type: array
items:
type: string
- name: citiesFilter
in: query
schema:
type: array
items:
type: string
- name: ipsFilter
in: query
schema:
type: array
items:
type: string
- name: actionTypesFilter
in: query
description: Filter for action types
schema:
type: array
items:
type: string
enum:
- ACTION_NONE
- ACTION_ALERT
- ACTION_BLOCK
- ACTION_MASK
- ACTION_REQUEST_BLOCK
- ACTION_ROW_FILTER
- ACTION_ORCH_MASK_POLICY_EXECUTED
- ACTION_ORCH_ROW_FILTER_POLICY_EXECUTED
- name: tagCategoriesFilter
in: query
schema:
type: array
items:
type: string
- name: hasIncidentsFilter
in: query
schema:
type: boolean
- name: hasIncidentsFilterV2
in: query
schema:
type: boolean
- name: hasDataStoreErrorsFilter
in: query
schema:
type: boolean
- name: includeAdministrateQueriesFilter
in: query
schema:
type: boolean
default: false
- name: governedQueries
in: query
schema:
type: array
items:
type: string
enum:
- GOVERNED
- UNGOVERNED
- name: groupsFilter
in: query
schema:
type: array
items:
type: string
- name: datasetsFilter
in: query
schema:
type: array
items:
type: string
- name: securityPoliciesFilter
in: query
schema:
type: array
items:
type: string
- name: flowId
in: query
schema:
type: string
- name: accessPermissionIds
in: query
schema:
type: array
items:
type: string
- name: queryIdFilter
in: query
schema:
type: string
- name: genericPropertiesFilter
in: query
schema:
type: string
- name: recordsRangeFilter
in: query
description: |-
This is a range parameter for the number of records returned from query of the form 'min:max'.
for example, '1:30' is a min of 1 and a max of 30, ':20' is without min and a max of 20
schema:
type: string
- name: statementType
in: query
schema:
type: array
items:
type: string
- name: loginName
in: query
schema:
type: array
items:
type: string
- name: purposeSearch
in: query
schema:
type: string
responses:
"200":
description: Status OK
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
deprecated: true
security:
- BearerAuth: []
/api/data-flow/{accountId}/metrics:
get:
tags:
- Audit Log
summary: Retrieve an Account's Counters
description: "This HTTP GET method is used to fetch various metrics that track
\ the performance and status of data flow activities for the specified account.
\
These metrics include things like data processing rates, error rates,
\ throughput and a list of governed and ungoverned queries, masking and filtering
\ actions, classification categories, response and processing times, generic
\ properties and login name."
operationId: metrics
parameters:
- name: accountId
in: path
required: true
schema:
type: string
- name: from
in: query
description: "Start query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625573940000
- name: to
in: query
description: "End query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625660399999
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: dataStoreIdsFilter
in: query
schema:
type: array
items:
type: string
- name: dataStoreTypes
in: query
schema:
type: array
items:
type: string
- name: userNamesFilter
in: query
schema:
type: array
items:
type: string
- name: authMethodFilter
in: query
schema:
type: array
items:
type: string
- name: toolsFilter
in: query
schema:
type: array
items:
type: string
- name: toolTypesFilter
in: query
schema:
type: array
items:
type: string
- name: toolDriversFilter
in: query
schema:
type: array
items:
type: string
- name: locationsFilter
in: query
schema:
type: array
items:
type: string
- name: tagsFilter
in: query
schema:
type: array
items:
type: string
- name: incidentIdsFilter
in: query
schema:
type: array
items:
type: string
- name: policyNamesFilter
in: query
schema:
type: array
items:
type: string
- name: countriesFilter
in: query
schema:
type: array
items:
type: string
- name: citiesFilter
in: query
schema:
type: array
items:
type: string
- name: ipsFilter
in: query
schema:
type: array
items:
type: string
- name: actionTypesFilter
in: query
description: Filter for action types
schema:
type: array
items:
type: string
enum:
- ACTION_NONE
- ACTION_ALERT
- ACTION_BLOCK
- ACTION_MASK
- ACTION_REQUEST_BLOCK
- ACTION_ROW_FILTER
- ACTION_ORCH_MASK_POLICY_EXECUTED
- ACTION_ORCH_ROW_FILTER_POLICY_EXECUTED
- name: tagCategoriesFilter
in: query
schema:
type: array
items:
type: string
- name: hasIncidentsFilter
in: query
schema:
type: boolean
- name: hasIncidentsFilterV2
in: query
schema:
type: boolean
- name: hasDataStoreErrorsFilter
in: query
schema:
type: boolean
- name: includeAdministrateQueriesFilter
in: query
schema:
type: boolean
default: false
- name: governedQueries
in: query
schema:
type: array
items:
type: string
enum:
- GOVERNED
- UNGOVERNED
- name: groupsFilter
in: query
schema:
type: array
items:
type: string
- name: datasetsFilter
in: query
schema:
type: array
items:
type: string
- name: securityPoliciesFilter
in: query
schema:
type: array
items:
type: string
- name: flowId
in: query
schema:
type: string
- name: accessPermissionIds
in: query
schema:
type: array
items:
type: string
- name: queryIdFilter
in: query
schema:
type: string
- name: genericPropertiesFilter
in: query
schema:
type: string
- name: recordsRangeFilter
in: query
description: |-
This is a range parameter for the number of records returned from query of the form 'min:max'.
for example, '1:30' is a min of 1 and a max of 30, ':20' is without min and a max of 20
schema:
type: string
- name: statementType
in: query
schema:
type: array
items:
type: string
- name: loginName
in: query
schema:
type: array
items:
type: string
- name: purposeSearch
in: query
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/DashboardMetricsOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/data-flow/{accountId}/query:
get:
tags:
- Audit Log
summary: List all Data Flows
description: "This HTTP GET method is used to execute a query or retrieve the
\ results of a query that has been executed against the audit log for the
\ specified account.
The data includes a list of data flows, pagination,
\ filters and sorting as well as a list of governed and ungoverned queries,
\ masking and filtering actions, classification categories, security policies,
\ data access permissions, response and processing time, query name and login
\ name."
operationId: query
parameters:
- name: accountId
in: path
required: true
schema:
type: string
- name: from
in: query
description: "Start query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625573940000
- name: to
in: query
description: "End query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625660399999
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: page
in: query
schema:
minimum: 0
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
maximum: 1000
minimum: 1
type: integer
format: int32
default: 100
- name: nextPageToken
in: query
description: "This parameter is used for iterate query result pages without
\ re-run the query for each page. Initial query should contain this parameter
\ (for example, set to empty for the first page), while all following queries
\ should contain it. Each page result will contain the `nextPageToken` field
\ with the value of the token for the next page."
schema:
type: string
- name: dataStoreIdsFilter
in: query
schema:
type: array
items:
type: string
- name: dataStoreTypes
in: query
schema:
type: array
items:
type: string
- name: userNamesFilter
in: query
schema:
type: array
items:
type: string
- name: authMethodFilter
in: query
schema:
type: array
items:
type: string
- name: toolsFilter
in: query
schema:
type: array
items:
type: string
- name: toolTypesFilter
in: query
schema:
type: array
items:
type: string
- name: toolDriversFilter
in: query
schema:
type: array
items:
type: string
- name: locationsFilter
in: query
schema:
type: array
items:
type: string
- name: tagsFilter
in: query
schema:
type: array
items:
type: string
- name: incidentIdsFilter
in: query
schema:
type: array
items:
type: string
- name: policyNamesFilter
in: query
schema:
type: array
items:
type: string
- name: countriesFilter
in: query
schema:
type: array
items:
type: string
- name: citiesFilter
in: query
schema:
type: array
items:
type: string
- name: ipsFilter
in: query
schema:
type: array
items:
type: string
- name: actionTypesFilter
in: query
description: Filter for action types
schema:
type: array
items:
type: string
enum:
- ACTION_NONE
- ACTION_ALERT
- ACTION_BLOCK
- ACTION_MASK
- ACTION_REQUEST_BLOCK
- ACTION_ROW_FILTER
- ACTION_ORCH_MASK_POLICY_EXECUTED
- ACTION_ORCH_ROW_FILTER_POLICY_EXECUTED
- name: tagCategoriesFilter
in: query
schema:
type: array
items:
type: string
- name: hasIncidentsFilter
in: query
schema:
type: boolean
- name: hasIncidentsFilterV2
in: query
schema:
type: boolean
- name: hasDataStoreErrorsFilter
in: query
schema:
type: boolean
- name: includeAdministrateQueriesFilter
in: query
schema:
type: boolean
default: false
- name: governedQueries
in: query
schema:
type: array
items:
type: string
enum:
- GOVERNED
- UNGOVERNED
- name: groupsFilter
in: query
schema:
type: array
items:
type: string
- name: datasetsFilter
in: query
schema:
type: array
items:
type: string
- name: securityPoliciesFilter
in: query
schema:
type: array
items:
type: string
- name: flowId
in: query
schema:
type: string
- name: accessPermissionIds
in: query
schema:
type: array
items:
type: string
- name: queryIdFilter
in: query
schema:
type: string
- name: genericPropertiesFilter
in: query
schema:
type: string
- name: recordsRangeFilter
in: query
description: |-
This is a range parameter for the number of records returned from query of the form 'min:max'.
for example, '1:30' is a min of 1 and a max of 30, ':20' is without min and a max of 20
schema:
type: string
- name: statementType
in: query
schema:
type: array
items:
type: string
- name: loginName
in: query
schema:
type: array
items:
type: string
- name: purposeSearch
in: query
schema:
type: string
- name: queryName
in: query
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/DataFlowsQueriesOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/enterprise-audit/{accountId}/snowflake:
get:
tags:
- Data Export
summary: Retrieve Snowflake Data Export Settings
description: This HTTP GET method is used to fetch the settings for exporting
audit logs to a Snowflake account.
operationId: getEnterpriseAuditOfSnowflake
parameters:
- name: accountId
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/EnterpriseAuditSnowflakeOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/global-config/network/management-outbound-ips:
get:
tags:
- Global Settings
summary: List Management Console Outbound IPs
description: This HTTP GET method is used to obtain the IP addresses that are
used by the Satori management console to connect to various systems.
operationId: getManagementOutboundIps
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/ManagementIpsOutput"
"401":
description: Invalid Authorization
/api/identity-providers/{providerId}/saml/azure/activate-certificate:
post:
tags:
- Identity Providers
summary: Activate an Azure SAML Identity Provider certificate
description: This HTTP POST method is used to activate a specific Satori certificate
of an Azure AD SAML identity provider. The specified certificate will be set
as active and all other certificates will be deactivated.
operationId: activateAzureSamlCertificate
parameters:
- name: providerId
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/AzureSamlCertificateInput"
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/SamlIdpOutput"
"400":
description: Bad request - Certificate not found or invalid
"401":
description: Invalid Authorization
"404":
description: Identity Provider or certificate not found
security:
- BearerAuth: []
/api/identity-providers/{id}:
get:
tags:
- Identity Providers
summary: Retrieve an Identity Provider
description: "This HTTP GET method is used to fetch detailed information about
\ a specific identity provider, such as its version, status, type, creation
\ date and time, provider name and the linked data stores."
operationId: byId_3
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/IdentityProviderOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Identity Provider not found
security:
- BearerAuth: []
/api/identity-providers/{accountId}/saml/azure:
post:
tags:
- Identity Providers
summary: Create an Azure SAML Identity Provider
description: This HTTP POST method is used to set up Azure Active Directory
as a SAML identity provider for a specific account.
operationId: createAzureSamlIdentityProvider
parameters:
- name: accountId
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/AzureSamlIdentityProviderInput"
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/SamlIdpOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/identity-providers/{providerId}/saml/azure/delete-certificate:
post:
tags:
- Identity Providers
summary: Delete an Azure SAML Identity Provider certificate
description: This HTTP POST method is used to delete a specific Satori certificate
from an Azure AD SAML identity provider. The active certificate cannot be
deleted. At least one certificate must remain in the identity provider.
operationId: deleteAzureSamlCertificate
parameters:
- name: providerId
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/AzureSamlCertificateInput"
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/SamlIdpOutput"
"400":
description: Bad request - Cannot delete active certificate or last certificate
"401":
description: Invalid Authorization
"404":
description: Identity Provider or certificate not found
security:
- BearerAuth: []
/api/identity-providers/{accountId}/{id}:
delete:
tags:
- Identity Providers
summary: Delete an Identity Provider
description: "This HTTP DELETE method is used to delete a specific identity
\ provider configuration from an account.
This is done when the identity
\ provider is no longer required, or if you want to replace it with a different
\ provider."
operationId: deleteIdentityProvider
parameters:
- name: accountId
in: path
required: true
schema:
minLength: 1
type: string
- name: id
in: path
required: true
schema:
minLength: 1
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/IdentityProviderOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Identity Provider not found
"409":
description: identity provider is assigned to one or more data store
content:
application/json:
schema:
$ref: "#/components/schemas/DataStoreQueryOutput"
security:
- BearerAuth: []
/api/identity-providers/{providerId}/saml/azure/extend:
post:
tags:
- Identity Providers
summary: Extend an Azure SAML Identity Provider certificate
description: This HTTP POST method is used to extend the satori certificate
of an Azure AD SAML identity provider.
operationId: extendAzureSamlIdentityProvider
parameters:
- name: providerId
in: path
required: true
schema:
minLength: 1
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/SamlIdpOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Identity Provider not found
security:
- BearerAuth: []
/api/identity-providers/{providerId}/saml/azure/generate-certificate:
post:
tags:
- Identity Providers
summary: Generate new certificate to Azure SAML Identity Provider
description: This HTTP POST method creates and adds a new Satori certificate
to an existing Azure AD SAML identity provider. 3 certificates are allowed
per identity provider.
operationId: generateAzureSamlCertificate
parameters:
- name: providerId
in: path
required: true
schema:
minLength: 1
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/SamlIdpOutput"
"400":
description: Bad request - Maximum certificates reached or invalid provider
"401":
description: Invalid Authorization
"404":
description: Identity Provider not found
security:
- BearerAuth: []
/api/identity-providers:
get:
tags:
- Identity Providers
summary: List all Identity Providers
description: "This HTTP GET method is used to fetch a list of all identity providers,
\ giving an overview of the different authentication services available."
operationId: getIdentityProviders
parameters:
- name: accountId
in: query
schema:
type: string
- name: dataStoreId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/IdentityProviderQueryOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/identity-providers/{providerId}/saml/azure:
put:
tags:
- Identity Providers
summary: Update an Azure SAML Identity Provider
description: This HTTP PUT method is used to modify the settings of an Azure
AD SAML identity provider and certificates.
operationId: updateAzureSamlIdentityProvider
parameters:
- name: providerId
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/AzureSamlIdentityProviderInput"
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/SamlIdpOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Identity Provider not found
security:
- BearerAuth: []
/api/locations/{id}:
delete:
tags:
- "Data Inventory [DEPRECATED]"
summary: Delete a Location Record
description: This HTTP DELETE method is used to permanently delete a location
from the system. It is used when a location is no longer relevant or if a
location was added by mistake.
operationId: deleteById_3
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
deprecated: true
security:
- BearerAuth: []
/api/locations/{locationId}/history/v2:
get:
tags:
- "Data Inventory [DEPRECATED]"
summary: List a History for Location Record
description: "This HTTP GET method is used to provide a historical record of
\ events, changes or updates related to the specified location."
operationId: getLocationHistoryV2
parameters:
- name: locationId
in: path
required: true
schema:
type: string
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: nextPageToken
in: query
description: "This parameter is used for iterate query result pages without
\ re-run the query for each page. Initial query should contain this parameter
\ (for example, set to empty for the first page), while all following queries
\ should contain it. Each page result will contain the `nextPageToken` field
\ with the value of the token for the next page."
schema:
type: string
- name: from
in: query
schema:
type: integer
format: int64
- name: to
in: query
schema:
type: integer
format: int64
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/LocationHistoryQueryResponseOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
deprecated: true
security:
- BearerAuth: []
/api/locations/{locationId}/reset:
put:
tags:
- "Data Inventory [DEPRECATED]"
summary: Reset all Classification Tags
description: This HTTP PUT method is used to reset the classification state
of the specified location. This includes clearing configurations and resetting
attributes to their default values.
operationId: resetById
parameters:
- name: locationId
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/LocationOutput"
"401":
description: Invalid Authorization
"404":
description: Bad request
deprecated: true
security:
- BearerAuth: []
/api/locations/{locationId}:
put:
tags:
- "Data Inventory [DEPRECATED]"
summary: Update Classification
description: "This HTTP PUT method is used to enable users to update the information
\ associated with a specific location. Such as, changing the location's name,
\ type, address and user notes."
operationId: updateById_1
parameters:
- name: locationId
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/UpdateLocationInput"
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/LocationOutput"
"404":
description: Bad request
"401":
description: Invalid Authorization
deprecated: true
security:
- BearerAuth: []
/api/v1/masking/{id}:
get:
tags:
- Masking Profiles
summary: Retrieve a Masking Profile
description: This HTTP GET method is used to retrieve detailed information about
a specific masking profile configuration.
operationId: byId_4
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, masking profile found."
content:
application/json:
schema:
$ref: "#/components/schemas/MaskProfileOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- Masking Profiles
summary: Update a Masking Profile
description: "This HTTP PUT method is used to modify the masking profile rules
\ for a particular dataset resource. These rules determine how data is masked,
\ obfuscated or anonymized."
operationId: updateById_2
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/MaskProfileInput"
required: true
responses:
"200":
description: "Status OK, masking profile updated"
content:
application/json:
schema:
$ref: "#/components/schemas/MaskProfileOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
delete:
tags:
- Masking Profiles
summary: Delete a Masking Profile
description: "This HTTP DELETE method is used when a particular masking profile
\ configuration is no longer required, such as when data masking requirements
\ change or a specific configuration was created in error."
operationId: deleteById_4
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/masking:
get:
tags:
- Masking Profiles
summary: List all Masking Profiles
description: "This HTTP GET method is useful for administrators or data stewards
\ who need to review, audit, or manage the data masking settings across all
\ of the datasets."
operationId: getAll_3
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/MaskProfileQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
post:
tags:
- Masking Profiles
summary: Create a Masking Profile
description: "This HTTP POST method is used when you need to add a new masking
\ profile rule to protect certain data fields, such as Social Security Numbers,
\ credit card details, or email addresses from being exposed in their entirety."
operationId: create_2
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/MaskProfileInput"
required: true
responses:
"201":
description: "Status OK, masking profile created"
content:
application/json:
schema:
$ref: "#/components/schemas/MaskProfileOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/masking/templates:
get:
tags:
- Masking Profiles
summary: List all Masking Profile Templates
description: This HTTP GET method is used for retrieving predefined masking
profile templates.
Pre-defined masking profiles simplify the process
of creating masking configurations by providing commonly used patterns and
settings.
operationId: getAllTemplates
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/MaskProfileQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/network-access-policy/assign/{id}/{type}/{memberId}:
post:
tags:
- Network Access Policy
summary: Add a Member to Network Policy
description: This HTTP POST method is used to enforce specific network access
rules by assigning them to different members of an organization.
operationId: assign
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: type
in: path
required: true
schema:
type: string
enum:
- management
- datastore
- name: memberId
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, member assigned to network policy."
content:
application/json:
schema:
$ref: "#/components/schemas/NetworkPolicyOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/network-access-policy/{id}:
get:
tags:
- Network Access Policy
summary: Find a Network Policy
description: "This HTTP GET method is used for reviewing the details of a network
\ access policy, which includes the rules governing network access, the members
\ to whom the policy applies."
operationId: byId_5
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, network policy found."
content:
application/json:
schema:
$ref: "#/components/schemas/NetworkPolicyOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- Network Access Policy
summary: Update a Network Policy
description: This HTTP PUT method is used for making changes to the configuration
of a network access policy.
operationId: update
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/NetworkPolicyInput"
responses:
"200":
description: "Status OK, network policy updated."
content:
application/json:
schema:
$ref: "#/components/schemas/NetworkPolicyOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
delete:
tags:
- Network Access Policy
summary: Delete a Network Policy
description: "This HTTP DELETE method is used when you need to remove a network
\ access policy that is no longer required or has been replaced by a new policy.
\
NOTE: Deleting a policy ensures that it is no longer applied within
\ the system, this is critical for maintaining the correct access controls."
operationId: deleteById_5
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/network-access-policy/{accountId}:
post:
tags:
- Network Access Policy
summary: Create a Network Policy
description: "This HTTP POST method is used for establishing new network access
\ policies tailored to specific accounts.
NOTE: By creating a policy,
\ you can define how network access should be controlled for users, groups,
\ or roles associated with that account."
operationId: create_3
parameters:
- name: accountId
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/NetworkPolicyInput"
responses:
"201":
description: "Status OK, network policy created."
content:
application/json:
schema:
$ref: "#/components/schemas/NetworkPolicyOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/network-access-policy:
get:
tags:
- Network Access Policy
summary: Find Network Policies by Account ID
description: "This HTTP GET method is used to retrieve a list of all network
\ access policies that are currently configured in the system.
This
\ allows you to view and manage the network access rules and conditions applied
\ to various accounts, users or groups."
operationId: getAll_4
parameters:
- name: accountId
in: query
schema:
type: string
- name: memberId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/NetworkPolicyQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/security-policies/{id}:
get:
tags:
- Security Policies
summary: Retrieve a Security Policy
description: "This HTTP GET method is used to retrieve detailed information
\ about a specific security policy.
This includes details such as
\ the policy name, description, dynamic masking rules and data filtering actions."
operationId: byId_6
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: withStats
in: query
description: Expand the response with security policy stats
schema:
type: boolean
default: false
responses:
"200":
description: "Status OK, security policy found."
content:
application/json:
schema:
$ref: "#/components/schemas/SecurityPolicyOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- Security Policies
summary: Update a security policy
description: "This HTTP PUT method is used to allow administrators, data stewards
\ or authorized users (managers) to update the details of a specific security
\ policy.
This involves editing or creating the dynamic masking rules
\ and data filters or updating its description to reflect new security requirements."
operationId: updateById_3
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/SecurityPolicyInput"
required: true
responses:
"200":
description: "Status OK, security policy updated"
content:
application/json:
schema:
$ref: "#/components/schemas/SecurityPolicyOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
delete:
tags:
- Security Policies
summary: Delete a Security Policy
description: "This HTTP DELETE method is used to allow administrators, data
\ stewards or authorized users (managers) to delete an existing security policy.
\
The security policy is deleted when it is no longer required, has
\ been replaced by a new security policy, or if the system is undergoing changes
\ that render the policy obsolete."
operationId: deleteById_6
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: force
in: query
description: "Once forced, the policy will be deleted from all its references"
schema:
type: boolean
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/security-policies:
get:
tags:
- Security Policies
summary: List all Security Policies
description: "This HTTP GET method is used to provide a list of all security
\ policies within the system.
The list includes summaries of each
\ security policy, such as the security policy name, description, users and
\ queries."
operationId: getAll_5
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: withStats
in: query
description: Expand the response with security policy stats
schema:
type: boolean
default: false
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/SecurityPolicyMinimalQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
post:
tags:
- Security Policies
summary: Create a Security Policy
description: "This HTTP POST method is used to enable the creation of a new
\ security policy, which is then enforced within the system. This is useful
\ when new security requirements arise."
operationId: create_4
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/SecurityPolicyInput"
required: true
responses:
"201":
description: "Status OK, security policy created"
content:
application/json:
schema:
$ref: "#/components/schemas/SecurityPolicyOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/security-policies/statistics:
get:
tags:
- Security Policies
summary: List a Security Policy Statistics
description: This HTTP GET method is used to provide an aggregated list of the
security policies that have been implemented.
operationId: getSecurityPoliciesStatistics
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: securityPolicyIds
in: query
schema:
type: array
items:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/SecurityPolicyStatisticsQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/users/{id}:
get:
tags:
- Users and Roles
summary: Retrieve an User
description: "This HTTP GET method is used to provide the details of a specific
\ user, including personal information, account settings, roles and permissions."
operationId: byId_7
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, user found."
content:
application/json:
schema:
$ref: "#/components/schemas/UserResourceDto"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
delete:
tags:
- Users and Roles
summary: Delete a User
description: "This HTTP DELETE method's primary purpose is to permanently remove
\ a user from the system.
This includes user deactivation, account
\ closure, or in response to security concerns (for example, removing accounts
\ of former employees)."
operationId: deleteById_7
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/users:
get:
tags:
- Users and Roles
summary: List all Users
description: "This HTTP GET method is used to retrieve a list of users from
\ the system.
The user information for each user includes, account
\ ID, display name, first name, last name, creation and update dates, roles,
\ attributes aliases, temporary credentials expiration times and personal
\ access tokens."
operationId: getAll_6
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: usersType
in: query
schema:
type: string
default: BOTH
enum:
- MANAGED_USER
- SATORI_USER
- BOTH
- name: personalAccessTokens
in: query
schema:
type: boolean
- name: roleId
in: query
description: Satori Role ID
schema:
uniqueItems: true
type: array
items:
type: string
- name: status
in: query
description: The user activation status
schema:
type: string
enum:
- PENDING_ACTIVATION
- ACTIVE
- DISABLED
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/UsersQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
deprecated: true
security:
- BearerAuth: []
post:
tags:
- Users and Roles
summary: Create a User
description: "This HTTP POST method is used to add a new user to the system
\ with all the necessary details, such as their account ID, first name, last
\ name, email and password."
operationId: create_5
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/UserInput"
responses:
"201":
description: "Status OK, user created."
content:
application/json:
schema:
$ref: "#/components/schemas/UserResourceDto"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"403":
description: Resource Limit Exceeded
security:
- BearerAuth: []
/api/users/{id}/database-credentials:
get:
tags:
- Users and Roles
summary: Retrieve Satori Temporary Credentials
description: This HTTP GET method is used to provide access to the database
credentials assigned to a specific user.
operationId: getUserDatabaseCredentials
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: withPassword
in: query
description: Exposes temporary password
schema:
type: boolean
responses:
"200":
description: "Status OK, credentials found"
content:
application/json:
schema:
$ref: "#/components/schemas/UserDatabaseCredentialsOutput"
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- Users and Roles
summary: Regenerate Satori Temporary Credentials
description: This HTTP PUT method is used to modify the database credentials
assigned to a specific user.
operationId: reGenerateUserDatabaseCredentials
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, credentials regenerated"
content:
application/json:
schema:
$ref: "#/components/schemas/UserDatabaseCredentialsOutput"
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/users/{id}/roles:
get:
tags:
- Users and Roles
summary: Retrieve User's Role
description: This HTTP GET method is used to provide a list of roles assigned
to a specific user.
operationId: getUserRoles
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, roles found"
content:
application/json:
schema:
type: array
items:
$ref: "#/components/schemas/RoleOutput"
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- Users and Roles
summary: Update User's Role
description: "This HTTP PUT method is used for updating the roles assigned to
\ a specific user, changing their permissions and access levels as required."
operationId: setUserRoles
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/RolesSet"
required: true
responses:
"200":
description: "Status OK, user role was changed"
"401":
description: Invalid Authorization
"404":
description: Provided role id lookup failed
security:
- BearerAuth: []
/api/users/{id}/reset-mfa:
delete:
tags:
- Users and Roles
summary: Reset user MFA
description: "This HTTP DELETE method is used to reset or clear the MFA settings
\ associated with a user’s account.
This is necessary if a user is
\ having trouble with their MFA setup, if they need to switch MFA methods
\ or if the system requires a reset for security reasons."
operationId: resetMFA
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: "Status OK, MFA was reset"
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/users/{id}/send-activation-mail:
put:
tags:
- Users and Roles
summary: Send an Activation Mail
description: This HTTP PUT method is used to send an activation or verification
email to the user.
This email contains a link that the user must click
to activate their account or confirm their email address.
operationId: sendActivationMail
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, instructions have been sent to mail."
content:
application/json:
schema:
$ref: "#/components/schemas/ActivationOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/users/{id}/toggle-password-login:
put:
tags:
- Users and Roles
summary: Toggle (enable/disable) password login
description: "This HTTP PUT method is used to toggle the availability of password-based
\ login for a user.
Enabling this option allows the user to log in
\ with their password, while disabling it might require the user to use other
\ authentication methods, such as multi-factor authentication (MFA) or single
\ sign-on (SSO)."
operationId: togglePasswordLogin
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/users/{id}/access-settings:
put:
tags:
- Users and Roles
summary: Update access settings for specific user
description: This HTTP PUT method is used to modify the access settings assigned
to a specific user.
operationId: updateAccessSettings
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/AccessSettingsDto"
required: true
responses:
"200":
description: "Status OK, updated access settings"
content:
application/json:
schema:
$ref: "#/components/schemas/UserResourceDto"
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/users/{id}/attributes/custom:
put:
tags:
- Users and Roles
summary: Update custom user attributes
description: "This HTTP PUT method is used to update or set custom attributes
\ for a user. Custom attributes are additional fields that are not part of
\ the standard user profile but are used for storing extra information. These
\ attributes can include, number, boolean and or string.
NOTE: The
\ attribute must include a key (custom attribute name) and a value."
operationId: updateCustomAttributesById
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
type: string
responses:
"200":
description: "Status OK, user found."
content:
application/json:
schema:
$ref: "#/components/schemas/UserWithGroupsOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/users/{id}/profile:
put:
tags:
- Users and Roles
summary: Update a User Profile
description: "This HTTP PUT method is used to modify the user's profile information.
\ This is used for updating basic details, contact information or other user-specific
\ data."
operationId: updateUserProfile
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/UserProfileInput"
responses:
"200":
description: "Status OK, user profile updated."
content:
application/json:
schema:
$ref: "#/components/schemas/UserResourceDto"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/asset/{id}:
get:
tags:
- Data Inventory
summary: Retrieve an Inventory Asset
description: "This HTTP GET method is used to fetch details about a specific
\ asset. The asset details include, the asset name, status, asset details
\ (schema, table, column, values and types) and the creation date."
operationId: getById_1
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, asset found."
content:
application/json:
schema:
$ref: "#/components/schemas/AssetOutput"
"400":
description: Bad configuration request
"404":
description: Resource not found
"401":
description: Invalid Authorization
security:
- BearerAuth: []
put:
tags:
- Data Inventory
summary: Update an Inventory Asset
description: This HTTP PUT method is used to modify the inventory asset details
operationId: update_1
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/UpdateAssetInput"
required: true
responses:
"200":
description: "Status OK, asset updated"
content:
application/json:
schema:
$ref: "#/components/schemas/AssetOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
delete:
tags:
- Data Inventory
summary: Delete an Inventory Asset
description: This HTTP DELETE method is used to permanently delete an asset
from the system. It is used when an asset is no longer relevant or if an asset
was added by mistake.
operationId: deleteBy
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"202":
description: "Accepted, delete asset in progress."
"400":
description: Bad configuration request
"404":
description: Resource not found
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/asset/{dataStoreId}/export-tags-sql:
get:
tags:
- Data Inventory
summary: Export all Tags for Snowflake
description: This HTTP GET method is used to export tags associated with a specific
(Snowflake) data store in an SQL format.
operationId: exportSql
parameters:
- name: dataStoreId
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/asset/{accountId}/direct-children:
get:
tags:
- Data Inventory
summary: List all Asset's Direct Children
description: The HTTP GET method is used to retrieve all direct child assets
associated with a particular asset.
operationId: getAssetDirectChildren
parameters:
- name: accountId
in: path
required: true
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: dataStoreId
in: query
required: true
schema:
type: string
- name: parentId
in: query
schema:
type: string
- name: assetType
in: query
schema:
type: array
items:
type: string
enum:
- TABLE
- COLUMN
- SEMANTIC_MODEL
- REPORT
- DASHBOARD
- DATABASE
- SCHEMA
- JSON_PATH
- WAREHOUSE
- ENDPOINT
- TYPE
- FIELD
- EXTERNAL_LOCATION
- CATALOG
- BUCKET
- OBJECT
- COLLECTION
- VIEW
- ACCOUNT_ROLE
- SHARED_DB
- name: calculateTotalCount
in: query
description: "If true, the total number of assets (before pagination) will
\ be calculated, default is false"
schema:
type: boolean
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/AssetQueryOutput"
"400":
description: Bad request
"404":
description: Provided data store or account not found
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/asset/{assetId}/history:
get:
tags:
- Data Inventory
summary: List a History for Asset
description: "This HTTP GET method is used to provide a historical record of
\ events, changes or updates related to the specified asset."
operationId: getAssetHistory
parameters:
- name: assetId
in: path
required: true
schema:
type: string
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: nextPageToken
in: query
description: "This parameter is used for iterate query result pages without
\ re-run the query for each page. Initial query should contain this parameter
\ (for example, set to empty for the first page), while all following queries
\ should contain it. Each page result will contain the `nextPageToken` field
\ with the value of the token for the next page."
schema:
type: string
- name: from
in: query
schema:
type: integer
format: int64
- name: to
in: query
schema:
type: integer
format: int64
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/LocationHistoryQueryResponseOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/asset/{assetId}/reset:
put:
tags:
- Data Inventory
summary: Reset all Classification Tags
description: This HTTP PUT method is used to reset the classification state
of the specified asset. This includes clearing configurations and resetting
attributes to their default values.
operationId: resetById_1
parameters:
- name: assetId
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/AssetOutput"
"401":
description: Invalid Authorization
"404":
description: Bad request
security:
- BearerAuth: []
/api/v1/asset/{accountId}/search:
get:
tags:
- Data Inventory
summary: Search Inventory Assets
description: This HTTP GET method is used to enable users to search for assets
associated with a particular account.
operationId: search
parameters:
- name: accountId
in: path
required: true
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: dataStoreId
in: query
schema:
type: array
items:
type: string
- name: datasetId
in: query
schema:
type: array
items:
type: string
- name: locationPrefix
in: query
schema:
type: string
- name: tagsFilter
in: query
schema:
type: array
items:
type: string
- name: categoriesFilter
in: query
schema:
type: array
items:
type: string
- name: createdFrom
in: query
schema:
type: integer
format: int64
- name: createdTo
in: query
schema:
type: integer
format: int64
- name: updatedFrom
in: query
schema:
type: integer
format: int64
- name: updatedTo
in: query
schema:
type: integer
format: int64
- name: updatedByUser
in: query
description: Indicator for filtering only location that were updated by a
user.
schema:
type: boolean
- name: locationType
in: query
schema:
type: array
items:
type: string
enum:
- RELATIONAL_LOCATION
- MYSQL_LOCATION
- ATHENA_LOCATION
- MONGO_LOCATION
- S3_LOCATION
- DATABRICKS_LOCATION
- DATABRICKS_EXTERNAL_LOCATION
- GRAPHQL_LOCATION
- SNOWFLAKE_WAREHOUSE_LOCATION
- ASSET_LOCATION
- name: nextPageToken
in: query
schema:
type: string
- name: assetType
in: query
schema:
type: array
items:
type: string
enum:
- TABLE
- COLUMN
- SEMANTIC_MODEL
- REPORT
- DASHBOARD
- DATABASE
- SCHEMA
- JSON_PATH
- WAREHOUSE
- ENDPOINT
- TYPE
- FIELD
- EXTERNAL_LOCATION
- CATALOG
- BUCKET
- OBJECT
- COLLECTION
- VIEW
- ACCOUNT_ROLE
- SHARED_DB
- name: parentId
in: query
description: "Parent ID, see `directChildren` filter for parentId filter mode"
schema:
type: array
items:
type: string
- name: directChildren
in: query
description: "When true, parentId filter refers only for direct children of
\ the parent, otherwise all parent's assets sub-tree. Defaults to false."
schema:
type: boolean
- name: tag
in: query
description: "Filter by classifier IDs, for example: 'tag=EMAIL' or 'tag=UUID'
\ for custom classifiers"
schema:
type: array
items:
type: string
- name: category
in: query
description: "Filter by category IDs, for example: 'category=pii' or 'category=UUID'
\ for custom categories"
schema:
type: array
items:
type: string
- name: dataStoreType
in: query
schema:
type: array
items:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/AssetSearchQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/asset/{assetId}/classification:
put:
tags:
- Data Inventory
summary: Update Classification
description: The HTTP PUT method allows users to add or remove classifiers associated
with a specific asset. Users can also provide notes during the update.
operationId: updateById_4
parameters:
- name: assetId
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/UpdateLocationInput"
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/AssetOutput"
"404":
description: Bad request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/asset/update-semi-location:
put:
tags:
- Data Inventory
summary: Update a Semi-Structured Assets
description: The HTTP PUT method allows users to update the details of a JSON
path.
operationId: updateSemiPartOfLocation
parameters:
- name: id
in: query
schema:
type: string
- name: semiPart
in: query
description: a valid JSONPath leading by $
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/AssetOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-controllers/{id}/package/download:
get:
tags:
- Data Access Controllers (DACs)
summary: Download a Package
description: This HTTP GET method is used to download a package (specific version)
that is linked with the specified data access controller (DAC). This package
includes files or resources required for setting up or configuring the DAC.
operationId: downloadPackageForDac
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: version
in: query
schema:
type: string
responses:
"200":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-controllers/{id}/package/releases:
get:
tags:
- Data Access Controllers (DACs)
summary: List all Available Packages
description: This HTTP GET method is used to list the available releases or
versions of the package associated with the specified data access controller
(DAC).
operationId: getAllAvailableVersionsForDac
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: recommended
in: query
schema:
type: boolean
default: true
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/AvailablePackageVersionQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-controllers:
get:
tags:
- Data Access Controllers (DACs)
summary: List all Data Access Control
description: "This HTTP GET method is used to retrieve a list of all the data
\ access controllers (DACs), that are used for administrative tasks, reporting
\ or management of data access within the system."
operationId: getAllDataAccessControllers
parameters:
- name: accountId
in: query
schema:
type: string
- name: allowForCreation
in: query
description: Include only DACs that are available for data store creation
schema:
type: boolean
default: true
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: type
in: query
schema:
type: string
enum:
- PUBLIC
- PRIVATE
- PRIVATE_MANAGED
- name: region
in: query
schema:
type: string
- name: cloudProvider
in: query
schema:
type: string
enum:
- GCP
- AZURE
- AWS
- BYOC
- name: uniqueName
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-controllers/private:
get:
tags:
- Data Access Controllers (DACs)
summary: List all Private Data Access Controls
description: This HTTP GET method is used to retrieve a list of private or restricted
data access controllers (DACs).
operationId: getAllPrivateDataAccessControllers
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: metrics
in: query
schema:
type: boolean
default: false
- name: status
in: query
schema:
type: string
enum:
- OK
- WARN
- ERROR
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-controllers/{id}:
get:
tags:
- Data Access Controllers (DACs)
summary: Retrieve a Data Access Controller
description: This HTTP GET method is used to get detailed information about
a specific data access controller (DAC).
operationId: getDataAccessControllerById
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: accountId
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessControllerOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-controllers/package/releases:
get:
tags:
- Data Access Controllers (DACs)
summary: List a Recommended and Beta Versions
description: This HTTP GET method is used to retrieve a list of package releases
associated with data access controllers (DACs).
operationId: getRecommendedAndBetaVersions
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/AvailablePackageVersionQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-controllers/{id}/upload-logs:
post:
tags:
- Data Access Controllers (DACs)
summary: Trigger an Upload Log Action
description: This HTTP POST method is used to upload log files associated with
a specific data access controller (DAC).
operationId: postUploadLogRequest
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-controllers/update-log-collection:
post:
tags:
- Data Access Controllers (DACs)
summary: Update DACs Log Collection Configuration
description: This HTTP POST method is used to update the log collection settings
for a specific data access controller (DAC).
operationId: updateDacLogCollection
parameters:
- name: accountId
in: query
schema:
type: string
- name: dacId
in: query
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/LogCollection"
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessControllerOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-controllers/{id}/upgrade-config:
put:
tags:
- Data Access Controllers (DACs)
summary: Update a Data Access Controller Upgrade Configuration
description: "This HTTP PUT method is used to update the log collection configuration
\ for one or more data access controllers.
NOTE: Each request must
\ include either dacId or accountId."
operationId: updateDacUpgradeConfig
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/UpgradeConfigDto"
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessControllerOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/dataset:
get:
tags:
- Datasets
summary: Query datasets by account id
description: This HTTP GET method is used to retrieve a list of datasets available
in the system.
operationId: queryDatasets
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: dataStoresFilter
in: query
schema:
type: array
items:
type: string
- name: dataStoreTypeFilter
in: query
schema:
type: array
items:
type: string
- name: locationsFilter
in: query
schema:
type: array
items:
type: string
- name: minimal
in: query
schema:
type: boolean
default: false
responses:
"200":
description: Status OK.
content:
application/json:
schema:
oneOf:
- $ref: "#/components/schemas/DataSetMinimalQueryResponse"
- $ref: "#/components/schemas/DataSetQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
post:
tags:
- Datasets
summary: Create a Dataset
description: "This HTTP POST method is used to create a new dataset with the
\ provided details. This includes defining the dataset’s name, description,
\ approvers (data stewards/access approvers), adding metadata as well as adding
\ an included and excluded location/s."
operationId: createDataset
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DataSetInput"
required: true
responses:
"201":
description: "Status OK, dataset created"
content:
application/json:
schema:
$ref: "#/components/schemas/DataSetOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/dataset/{id}:
get:
tags:
- Datasets
summary: Get a Dataset
description: "This HTTP GET method is used to fetch detailed information about
\ a specific dataset. This includes dataset name, description, metadata, schema,
\ classifiers, included and excluded location/s, permissions and default security
\ policies."
operationId: getDatasetById
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, dataset found."
content:
application/json:
schema:
$ref: "#/components/schemas/DataSetOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- Datasets
summary: Update a Dataset
description: "This HTTP PUT method is used to update the dataset with the provided
\ details. This includes changes to the dataset’s name, description, schema,
\ classifiers, included and excluded location/s, permissions and default security
\ policies."
operationId: updateDatasetById
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DataSetInput"
required: true
responses:
"200":
description: "Status OK, dataset updated"
content:
application/json:
schema:
$ref: "#/components/schemas/DataSetOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
delete:
tags:
- Datasets
summary: Delete a Dataset
description: This HTTP DELETE method is used to delete the dataset with the
specified ID. This action removes all associated data and metadata from the
system and it is typically irreversible.
operationId: deleteDatasetById
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/dataset/{id}/access-details:
get:
tags:
- Datasets
summary: Dataset Access Details
description: "This HTTP GET method is used to fetch detailed information about
\ the access permissions and history for a specific dataset.
This
\ includes user roles, permission levels, approvers, instant access rules,
\ pending access requests and any recent access or changes made to the dataset,
\ for a specific or the current user."
operationId: getDatasetAccessDetails
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
- name: userId
in: query
description: "Optional. Administrator users or service accounts can get access
\ details for specific users in their account. If not specified, the API
\ is based on the current user."
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/DatasetAccessDetailsOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/dataset/{id}/connection-details:
get:
tags:
- Datasets
summary: Dataset Connection Details
description: "This HTTP GET method is used to provide the necessary connection
\ details required to access or interact with a dataset. This includes database
\ connection strings, dataset ID, name, description, locations, API endpoints,
\ authentication tokens, and deployment type for a specific or the current
\ user."
operationId: getDatasetConnectionDetails
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
- name: userId
in: query
description: "Optional. Administrator users or service accounts can get access
\ details for specific users in their account. If not specified, the API
\ is based on the current user."
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/DatasetConnectionDetailsOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/dataset/access-details:
get:
tags:
- Datasets
summary: Datasets Access Details
description: "This HTTP GET method is used to retrieve user access information
\ across multiple datasets. This includes a list of datasets and their corresponding
\ access permissions, roles, and possibly audit logs or history of access
\ for a specific or the current user."
operationId: queryDatasetsAccessDetails
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: favorites
in: query
schema:
type: boolean
- name: recent
in: query
schema:
type: boolean
- name: dataPolicyIds
in: query
schema:
type: array
items:
type: string
- name: includeDataAccessRuleType
in: query
schema:
type: array
items:
type: string
enum:
- INSTANT_ACCESS
- SELF_SERVICE
- ACCESS_REQUEST
- name: excludeDataAccessRuleType
in: query
schema:
type: array
items:
type: string
enum:
- INSTANT_ACCESS
- SELF_SERVICE
- ACCESS_REQUEST
- name: hasPendingRequest
in: query
schema:
type: boolean
- name: userId
in: query
description: "Optional. Administrator users or service accounts can get access
\ details for specific users in their account. If not specified, the API
\ is based on the current user."
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/DatasetsAccessDetailsQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/dataset/access-details-dbs:
get:
tags:
- Datasets
summary: Data Stores Access Details
description: "This HTTP GET method is used to retrieve access details for multiple
\ datasets or a general overview of dataset access permissions. This includes
\ a list of datasets along with who has access, what permissions they have,
\ and any relevant audit logs for a specific user."
operationId: queryDetailedDatastoreDetails
parameters:
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: accountId
in: query
schema:
type: string
- name: userId
in: query
description: "Optional. Administrator users or service accounts can get access
\ details for specific users in their account. If not specified, the API
\ is based on the current user."
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/DatasetDetailsCliQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/datastore:
get:
tags:
- Data Stores
summary: Find Data Stores by Account ID
description: "This HTTP GET method is used to find a datastore with the account
\ ID. The information retrieved includes, the data store name, hostname, satori
\ host name, port, creation on and last updated dates, name of the creator
\ and the DAC ID."
operationId: find
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: ids
in: query
schema:
type: array
items:
type: string
- name: dataStoreType
in: query
schema:
type: array
items:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
- name: cloudProvider
in: query
schema:
type: array
items:
type: string
enum:
- GCP
- AZURE
- AWS
- BYOC
- name: activeDataStore
in: query
schema:
type: boolean
- name: region
in: query
schema:
type: string
- name: cloudAccountId
in: query
schema:
type: array
items:
type: string
- name: dacId
in: query
schema:
type: array
items:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/DataStoreQueryOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
post:
tags:
- Data Stores
summary: Create a Data Store
description: "This HTTP POST method is used to create a new data store within
\ the system. This API call allows you to define and establish a new storage
\ location where data can be managed, stored and accessed."
operationId: createDataStore
parameters:
- name: accountId
in: query
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DataStoreInput"
responses:
"201":
description: "Status OK, data store created"
content:
application/json:
schema:
$ref: "#/components/schemas/DataStoreOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"403":
description: Resource Limit Exceeded
"404":
description: Provided account not found
security:
- BearerAuth: []
/api/v1/datastore/demo:
post:
tags:
- Data Stores
summary: Create a Demo Data Store
description: "This HTTP POST method is used to create or activate a new demo
\ data store in the system. This API call allows you to set up a demo data
\ store on a specific user account, which can be used for testing, demos,
\ or investigative purposes."
operationId: createDemoDataStore
parameters:
- name: accountId
in: query
schema:
type: string
- name: type
in: query
schema:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
responses:
"201":
description: "Status OK, data store created"
content:
application/json:
schema:
$ref: "#/components/schemas/DataStoreOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"403":
description: Resource Limit Exceeded
"404":
description: Provided account not found
security:
- BearerAuth: []
/api/v1/datastore/{id}:
get:
tags:
- Data Stores
summary: Get a Data Store
description: "This HTTP GET method is used to retrieve detailed information
\ about a specific data store.
This API call allows you to access
\ the configuration, status, and other relevant details of the specified data
\ store."
operationId: getDataStoreById
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/DataStoreOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Provided data store not found
security:
- BearerAuth: []
put:
tags:
- Data Stores
summary: Update a Data Store
description: "This HTTP PUT method is used to update the configuration or details
\ of an existing data store.
This API call allows you to modify settings,
\ properties, or other aspects of the specified data store."
operationId: updateDataStoreById
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DataStoreInput"
responses:
"200":
description: "Status OK, data store updated"
content:
application/json:
schema:
$ref: "#/components/schemas/DataStoreOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Provided data store or account not found
security:
- BearerAuth: []
delete:
tags:
- Data Stores
summary: Delete a Data Store
description: This HTTP DELETE method is used to remove an existing data store
identified by the ID.
This API call permanently deletes the data store
and all its associated data and configurations.
operationId: deleteDataStoreById
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: "Status OK, data store deleted"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Provided data store not found
security:
- BearerAuth: []
/api/v1/datastore/{id}/generate-custom-ingress-port:
get:
tags:
- Data Stores
summary: Generate a Custom Ingress Port
description: "This HTTP GET method is used to generate or retrieve a custom
\ ingress port for a specific data store.
This API call provides a
\ port that can be used for accessing or routing traffic to the data store,
\ typically for custom networking configurations or specific use cases."
operationId: generateCustomIngressPort
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, port generated"
content:
application/json:
schema:
$ref: "#/components/schemas/DataStoreOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Provided data store or account not found
security:
- BearerAuth: []
/api/v1/datastore/{id}/identity-provider:
put:
tags:
- Data Stores
summary: Update Data Store Identity Provider
description: This HTTP PUT method is used to update or configure the identity
provider settings for a specific data store.
This API call allows
you to modify the identity provider that manages authentication and access
control for the data store.
operationId: updateIdentityProviderId
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: identityProviderId
in: query
schema:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/DataStoreOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Provided data store not found
security:
- BearerAuth: []
/api/v1/directory/group:
get:
tags:
- User Directory
summary: Query Directory Objects by Account ID
description: "This HTTP GET method is used to retrieve a list of groups from
\ the directory service.
This API call allows you to access details
\ about all groups that exist within the directory, including the number of
\ group members, group name, description, ID, creation and update info as
\ well as who created the group."
operationId: queryDirectoryGroups
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DirectoryQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
post:
tags:
- User Directory
summary: Create New Directory Object
description: "This HTTP POST method is used to create a new group within the
\ directory service.
This API call allows you to define and add a
\ new group, including specifying its name, description, and any initial members
\ of the group."
operationId: createDirectoryGroup
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DirectoryObjectInput"
responses:
"200":
description: Status OK
content:
application/json:
schema:
oneOf:
- $ref: "#/components/schemas/DirectoryObjectOutput"
- $ref: "#/components/schemas/DirectoryGroupOutput"
"401":
description: Invalid Authorization
"404":
description: Bad request
security:
- BearerAuth: []
/api/v1/directory/group/{id}:
get:
tags:
- User Directory
summary: Get a Directory Object
description: "This HTTP GET method is used to retrieve detailed information
\ about a specific group.
This API call allows you to access a group's
\ details including the group name, description, ID, creation and update info
\ as well as who created the group."
operationId: getDirectoryGroupById
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, directory object found."
content:
application/json:
schema:
oneOf:
- $ref: "#/components/schemas/DirectoryObjectOutput"
- $ref: "#/components/schemas/DirectoryGroupOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- User Directory
summary: Update Directory Object by ObjectId
description: "This HTTP PUT method is used to update the details of an existing
\ group within the directory service.
This API call allows you to
\ modify the group's name, description and members."
operationId: updateDirectoryGroupById
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DirectoryObjectInput"
responses:
"200":
description: Status OK
content:
application/json:
schema:
oneOf:
- $ref: "#/components/schemas/DirectoryObjectOutput"
- $ref: "#/components/schemas/DirectoryGroupOutput"
"401":
description: Invalid Authorization
"404":
description: Bad request
security:
- BearerAuth: []
delete:
tags:
- User Directory
summary: Delete a Directory Object
description: This HTTP DELETE method is used to remove an existing group from
the directory service.
operationId: deleteDirectoryGroupById
parameters:
- name: id
in: path
required: true
schema:
type: string
- name: force
in: query
schema:
type: boolean
default: false
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/export/asset:
get:
tags:
- Export Data
summary: Export Data Inventory (Assets)
description: "The HTTP GET method exports all assets related to a specific account.
\ The data inventory is exported in CSV format, with a maximum limit of 100,000
\ records."
operationId: exportAssetToCSV
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: dataStoreId
in: query
schema:
type: array
items:
type: string
- name: datasetId
in: query
schema:
type: array
items:
type: string
- name: locationPrefix
in: query
schema:
type: string
- name: tagsFilter
in: query
schema:
type: array
items:
type: string
- name: categoriesFilter
in: query
schema:
type: array
items:
type: string
- name: createdFrom
in: query
schema:
type: integer
format: int64
- name: createdTo
in: query
schema:
type: integer
format: int64
- name: updatedFrom
in: query
schema:
type: integer
format: int64
- name: updatedTo
in: query
schema:
type: integer
format: int64
- name: updatedByUser
in: query
description: Indicator for filtering only location that were updated by a
user.
schema:
type: boolean
- name: locationType
in: query
schema:
type: array
items:
type: string
enum:
- RELATIONAL_LOCATION
- MYSQL_LOCATION
- ATHENA_LOCATION
- MONGO_LOCATION
- S3_LOCATION
- DATABRICKS_LOCATION
- DATABRICKS_EXTERNAL_LOCATION
- GRAPHQL_LOCATION
- SNOWFLAKE_WAREHOUSE_LOCATION
- ASSET_LOCATION
- name: nextPageToken
in: query
schema:
type: string
- name: assetType
in: query
schema:
type: array
items:
type: string
enum:
- TABLE
- COLUMN
- SEMANTIC_MODEL
- REPORT
- DASHBOARD
- DATABASE
- SCHEMA
- JSON_PATH
- WAREHOUSE
- ENDPOINT
- TYPE
- FIELD
- EXTERNAL_LOCATION
- CATALOG
- BUCKET
- OBJECT
- COLLECTION
- VIEW
- ACCOUNT_ROLE
- SHARED_DB
- name: parentId
in: query
description: "Parent ID, see `directChildren` filter for parentId filter mode"
schema:
type: array
items:
type: string
- name: directChildren
in: query
description: "When true, parentId filter refers only for direct children of
\ the parent, otherwise all parent's assets sub-tree. Defaults to false."
schema:
type: boolean
- name: tag
in: query
description: "Filter by classifier IDs, for example: 'tag=EMAIL' or 'tag=UUID'
\ for custom classifiers"
schema:
type: array
items:
type: string
- name: category
in: query
description: "Filter by category IDs, for example: 'category=pii' or 'category=UUID'
\ for custom categories"
schema:
type: array
items:
type: string
- name: dataStoreType
in: query
schema:
type: array
items:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
- name: fields
in: query
description: Field names which will be returned as columns in the responded
list
schema:
type: array
items:
type: string
enum:
- dataStoreId
- dataStore.type
- dataStore.name
- assetType
- name
- description
- locationObject.fullLocation
- tags
- createdAt
- updatedAt
responses:
"200":
description: Status OK
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/export/data-access-request-overview:
get:
tags:
- Export Data
summary: Export Data Access Request Overview
description: The HTTP GET method exports the Data Access Request Overview in
CSV format.
operationId: exportDataAccessRequestOverviewToCsv
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: identity
in: query
schema:
type: array
items:
type: string
- name: identityType
in: query
schema:
type: array
items:
type: string
enum:
- USER
- DB_USER
- GROUP
- IDP_GROUP
- DATABRICKS_GROUP
- DATABRICKS_SERVICE_PRINCIPAL
- SNOWFLAKE_ROLE
- SNOWFLAKE_ACCOUNT_NAME
- SNOWFLAKE_DATABASE_ROLE
- CEL
- EVERYONE
- name: accessLevel
in: query
schema:
type: array
items:
type: string
- name: parent
in: query
schema:
type: array
items:
type: string
- name: datasetId
in: query
schema:
type: array
items:
type: string
- name: fields
in: query
description: Field names which will be returned as columns in the responded
list
schema:
type: array
items:
type: string
enum:
- type
- datasetId
- dataset.id
- dataset.name
- identity.identityType
- identity.identity
- identity.displayName
- accessLevel
- timeLimit
- unusedTimeLimit
- securityPolicies.id
- securityPolicies.name
- maskingProfiles.id
- maskingProfiles.name
- approvers
- requireApproverNote
- createdAt
- updatedAt
- suspended
responses:
"200":
description: Status OK
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/export/data-access-rule-history:
get:
tags:
- Export Data
summary: Export Data Access Rule History
description: The HTTP GET method exports the Data Access Rule History in CSV
format.
operationId: exportDataAccessRuleHistoryToCsv
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: nextPageToken
in: query
description: "This parameter is used for iterate query result pages without
\ re-run the query for each page. Initial query should contain this parameter
\ (for example, set to empty for the first page), while all following queries
\ should contain it. Each page result will contain the `nextPageToken` field
\ with the value of the token for the next page."
schema:
type: string
- name: from
in: query
schema:
type: integer
format: int64
- name: to
in: query
schema:
type: integer
format: int64
- name: performedBy
in: query
schema:
type: array
items:
type: string
- name: performedBySystem
in: query
description: Allows to include Account Activity records performed by System.
schema:
type: boolean
- name: dataConsumers
in: query
schema:
type: array
items:
type: string
- name: excludeSubActions
in: query
schema:
type: array
items:
type: string
- name: fields
in: query
description: Field names which will be returned as columns in the responded
list
schema:
type: array
items:
type: string
enum:
- timestamp
- dataset.id
- dataset.name
- performByIdentity
- end_user_identity
- action_sub_type
- system_note
- user_note
- access_approver_note
responses:
"200":
description: Status OK
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/export/data-access-rule-overview:
get:
tags:
- Export Data
summary: Export Data Access Rules Overview
description: The HTTP GET method exports the Data Access Rules Overview in CSV
format.
operationId: exportDataAccessRuleOverviewToCsv
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: type
in: query
schema:
type: array
items:
type: string
enum:
- INSTANT_ACCESS
- SELF_SERVICE
- ACCESS_REQUEST
- INSTANT_ACCESS_REQUEST
- name: identity
in: query
schema:
type: array
items:
type: string
- name: identityType
in: query
schema:
type: array
items:
type: string
enum:
- USER
- DB_USER
- GROUP
- IDP_GROUP
- DATABRICKS_GROUP
- DATABRICKS_SERVICE_PRINCIPAL
- SNOWFLAKE_ROLE
- SNOWFLAKE_ACCOUNT_NAME
- SNOWFLAKE_DATABASE_ROLE
- CEL
- EVERYONE
- name: accessLevel
in: query
schema:
type: array
items:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
- name: suspended
in: query
schema:
type: boolean
- name: parent
in: query
schema:
type: array
items:
type: string
- name: datasetId
in: query
schema:
type: array
items:
type: string
- name: fields
in: query
description: Field names which will be returned as columns in the responded
list
schema:
type: array
items:
type: string
enum:
- type
- datasetId
- dataset.id
- dataset.name
- identity.identityType
- identity.identity
- identity.displayName
- accessLevel
- timeLimit
- unusedTimeLimit
- securityPolicies.id
- securityPolicies.name
- maskingProfiles.id
- maskingProfiles.name
- approvers
- requireApproverNote
- createdAt
- updatedAt
- message
- purpose
- suspended
responses:
"200":
description: Status OK
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/export/data-flow:
get:
tags:
- Export Data
summary: Export all Data Flows
description: "This HTTP GET method is used to export audit logs in CSV format.
\
The exported data is in CSV format and includes various types of
\ information such as a list of governed and ungoverned queries, masking and
\ filtering actions, classification categories, response and processing times,
\ generic properties and login name."
operationId: exportDataFlowToCSV
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: from
in: query
description: "Start query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625573940000
- name: to
in: query
description: "End query time represented by milliseconds since Jan 1, 1970,
\ 00:00:00.000 GMT"
required: true
schema:
type: integer
format: int64
example: 1625660399999
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: fields
in: query
description: Field names which will be returned as columns in the responded
list
schema:
type: array
items:
type: string
enum:
- flow_timestamp
- identity.name
- data_store.id
- data_store.name
- data_store.type
- datasets.name
- datasets.id
- tags.name
- locations.length
- locations.location
- query.query_type
- volume.value
- records.value
- query.original_query
- tool
- incident_ids
- actions.policy_names
- result_set.column_name
- actions.type
- identity.authentication.method
- query.db_statement_type
- perf_stats.processing_time
- perf_stats.ds_response_time
- name: dataStoreIdsFilter
in: query
schema:
type: array
items:
type: string
- name: dataStoreTypes
in: query
schema:
type: array
items:
type: string
- name: userNamesFilter
in: query
schema:
type: array
items:
type: string
- name: authMethodFilter
in: query
schema:
type: array
items:
type: string
- name: toolsFilter
in: query
schema:
type: array
items:
type: string
- name: toolTypesFilter
in: query
schema:
type: array
items:
type: string
- name: toolDriversFilter
in: query
schema:
type: array
items:
type: string
- name: locationsFilter
in: query
schema:
type: array
items:
type: string
- name: tagsFilter
in: query
schema:
type: array
items:
type: string
- name: incidentIdsFilter
in: query
schema:
type: array
items:
type: string
- name: policyNamesFilter
in: query
schema:
type: array
items:
type: string
- name: countriesFilter
in: query
schema:
type: array
items:
type: string
- name: citiesFilter
in: query
schema:
type: array
items:
type: string
- name: ipsFilter
in: query
schema:
type: array
items:
type: string
- name: actionTypesFilter
in: query
description: Filter for action types
schema:
type: array
items:
type: string
enum:
- ACTION_NONE
- ACTION_ALERT
- ACTION_BLOCK
- ACTION_MASK
- ACTION_REQUEST_BLOCK
- ACTION_ROW_FILTER
- ACTION_ORCH_MASK_POLICY_EXECUTED
- ACTION_ORCH_ROW_FILTER_POLICY_EXECUTED
- name: tagCategoriesFilter
in: query
schema:
type: array
items:
type: string
- name: hasIncidentsFilter
in: query
schema:
type: boolean
- name: hasIncidentsFilterV2
in: query
schema:
type: boolean
- name: hasDataStoreErrorsFilter
in: query
schema:
type: boolean
- name: includeAdministrateQueriesFilter
in: query
schema:
type: boolean
default: false
- name: governedQueries
in: query
schema:
type: array
items:
type: string
enum:
- GOVERNED
- UNGOVERNED
- name: groupsFilter
in: query
schema:
type: array
items:
type: string
- name: datasetsFilter
in: query
schema:
type: array
items:
type: string
- name: securityPoliciesFilter
in: query
schema:
type: array
items:
type: string
- name: flowId
in: query
schema:
type: string
- name: accessPermissionIds
in: query
schema:
type: array
items:
type: string
- name: queryIdFilter
in: query
schema:
type: string
- name: genericPropertiesFilter
in: query
schema:
type: string
- name: recordsRangeFilter
in: query
description: |-
This is a range parameter for the number of records returned from query of the form 'min:max'.
for example, '1:30' is a min of 1 and a max of 30, ':20' is without min and a max of 20
schema:
type: string
- name: statementType
in: query
schema:
type: array
items:
type: string
- name: loginName
in: query
schema:
type: array
items:
type: string
- name: purposeSearch
in: query
schema:
type: string
responses:
"200":
description: Status OK
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/groups/{id}:
get:
tags:
- Groups
summary: Retrieve an IdP Group
description: "This HTTP GET method is used to retrieve detailed information
\ about a specific group.
This API call allows you to access details
\ about a specific IdP group including details such as, the group name, description,
\ email address, display name, members, ID, creation and last update date
\ and time. "
operationId: retrieve
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, group found."
content:
application/json:
schema:
$ref: "#/components/schemas/IdpGroupOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/groups:
get:
tags:
- Groups
summary: List all IdP Groups
description: "This HTTP GET method is used to retrieve a list of all groups
\ in the system.
This API call allows you to access details about
\ each IdP group, including the group members, access settings, temporary
\ credentials expiration time and date."
operationId: retrieveAll
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
- name: names
in: query
description: List of group names to filter by
schema:
type: array
items:
type: string
- name: memberId
in: query
schema:
type: string
- name: memberEmail
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/IdpGroupQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/taxonomy/custom/category:
post:
tags:
- Taxonomy
summary: Create a Custom Category
description: "This HTTP POST method is used to create a new custom category
\ within a taxonomy system.
This API call allows you to define and
\ add a new category with specified attributes, which can be used to classify
\ or organize data within the taxonomy."
operationId: createCustomTaxonomyCategory
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/TaxonomyCategoryInput"
required: true
responses:
"201":
description: "Status OK, custom taxonomy category created"
content:
application/json:
schema:
$ref: "#/components/schemas/TaxonomyNodeOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/taxonomy/custom/classifier:
post:
tags:
- Taxonomy
summary: Create a Custom Classifier
description: "This HTTP POST method is used to create a new custom classifier
\ in a custom category folder of the taxonomy system.
This API call
\ allows you to define and add a new classifier, which can be used to categorize
\ or organize data according to specific criteria or rules."
operationId: createCustomTaxonomyClassifier
parameters:
- name: accountId
in: query
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/TaxonomyCustomClassifierInput"
required: true
responses:
"201":
description: "Status OK, custom taxonomy classifier created"
content:
application/json:
schema:
$ref: "#/components/schemas/TaxonomyNodeOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/taxonomy/custom/{id}:
get:
tags:
- Taxonomy
summary: Retrieve a Custom Node
description: "This HTTP GET method is used to retrieve detailed information
\ about a specific custom taxonomy item.
This API call provides details
\ about the custom taxonomy, such as its attributes, categories, classifiers,
\ and any other relevant information associated with it."
operationId: getCustomTaxonomyNodeById
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, custom taxonomy node found."
content:
application/json:
schema:
$ref: "#/components/schemas/TaxonomyNodeOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
delete:
tags:
- Taxonomy
summary: Delete a Custom Node
description: This HTTP DELETE method is used to remove a specific custom taxonomy
item.
This API call permanently deletes the taxonomy item and all
its associated data.
operationId: deleteCustomTaxonomyNodeById
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/taxonomy/custom:
get:
tags:
- Taxonomy
summary: List all Custom Taxonomy
description: "This HTTP GET method is used to retrieve a list of all custom
\ taxonomy items within the system.
This API call provides information
\ about each custom taxonomy, including their attributes and classifications."
operationId: getAllCustomTaxonomyNodesForAccountId
parameters:
- name: accountId
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/TaxonomyNodeQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/taxonomy/satori:
get:
tags:
- Taxonomy
summary: List all Satori Taxonomy
description: "This HTTP GET method is used to retrieve information about the
\ Satori taxonomy within the system.
This API call provides details
\ about the Satori taxonomy, including its structure, categories, classifiers,
\ and any other relevant information associated with it."
operationId: getAllSatoriTaxonomyNodes
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/SatoriTaxonomyQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/taxonomy/custom/remove-from-locations/{id}:
delete:
tags:
- Taxonomy
summary: Remove a Custom Classifier from all Locations
description: "This HTTP DELETE method is used to remove a specific custom taxonomy
\ item from associated locations.
This API call disassociates the
\ taxonomy item from any locations it was previously linked to, without deleting
\ the taxonomy item itself."
operationId: removeCustomTaxonomyNodeFromLocations
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"202":
description: Status OK. Operation accepted.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/taxonomy/satori/remove-from-locations/{id}:
delete:
tags:
- Taxonomy
summary: Remove a Satori Classifier from all Locations
description: "This HTTP DELETE method is used to remove a specific Satori taxonomy
\ item from associated locations.
This API call disassociates the
\ taxonomy item from any locations it was previously linked to, without deleting
\ the taxonomy item itself."
operationId: removeSatoriTaxonomyNodeFromLocations
parameters:
- name: accountId
in: query
schema:
type: string
- name: id
in: path
required: true
schema:
type: string
responses:
"202":
description: Status OK. Operation accepted.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/taxonomy/custom/category/{id}:
put:
tags:
- Taxonomy
summary: Update a Custom Category
description: "This HTTP PUT method is used to update the details of an existing
\ custom taxonomy category.
This API call allows you to modify the
\ attributes, name, description, or other relevant properties of the specified
\ category within the taxonomy system."
operationId: updateCustomTaxonomyCategoryById
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/TaxonomyCategoryInput"
required: true
responses:
"200":
description: "Status OK, custom taxonomy category updated"
content:
application/json:
schema:
$ref: "#/components/schemas/TaxonomyNodeOutput"
"400":
description: Bad request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/taxonomy/custom/classifier/{id}:
put:
tags:
- Taxonomy
summary: Update a Custom Classifier
description: "This HTTP PUT method is used to update the details of an existing
\ custom taxonomy classifier.
This API call allows you to modify attributes,
\ name, description, or other relevant properties of the specified classifier
\ within the taxonomy system."
operationId: updateCustomTaxonomyClassifierById
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/TaxonomyCustomClassifierInput"
required: true
responses:
"200":
description: "Status OK, custom taxonomy classifier updated"
content:
application/json:
schema:
$ref: "#/components/schemas/TaxonomyNodeOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/users:
get:
tags:
- Users and Roles
summary: List all Users
description: Lists all users
operationId: queryUsers
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: usersType
in: query
schema:
type: string
default: BOTH
enum:
- MANAGED_USER
- SATORI_USER
- BOTH
- name: personalAccessTokens
in: query
schema:
type: boolean
- name: roleId
in: query
description: Satori Role ID
schema:
uniqueItems: true
type: array
items:
type: string
- name: status
in: query
description: The user activation status
schema:
type: string
enum:
- PENDING_ACTIVATION
- ACTIVE
- DISABLED
- name: idpGroups
in: query
schema:
type: array
items:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/UsersQueryOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/data-access-rule/instant-access:
get:
tags:
- Data Access Rules
summary: List all Data Access Permissions
description: This HTTP GET method is used to retrieve information about data
access rules that provide instant access.
operationId: getAllByParent
parameters:
- name: parentId
in: query
description: "Parent ID is a required query param, could be a dataset ID or
\ a data policy ID"
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessPermissionQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
post:
tags:
- Data Access Rules
summary: Create a Data Access Permission
description: This HTTP POST method is used to create or define a new data access
rule that grants instant access.
operationId: create_6
parameters:
- name: parentId
in: query
description: "Parent ID is a required query param, could be a dataset ID or
\ a data policy ID"
required: true
schema:
minLength: 1
type: string
- name: accessRequestId
in: query
schema:
type: string
- name: allowOverrideExistingUserAccess
in: query
schema:
type: boolean
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessPermissionRuleInput"
responses:
"201":
description: "Status OK, data access rule created"
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRuleOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/data-access-rule/instant-access/{id}:
get:
tags:
- Data Access Rules
summary: Retrieve a Data Access Permission
description: This HTTP GET method is used to retrieve detailed information about
a specific data access rule that provides instant access.
operationId: getById_2
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, data access permission found."
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessPermissionRuleOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- Data Access Rules
summary: Update a Data Access Permission
description: This HTTP PUT method is used to update the details of an existing
data access rule that provides instant access.
operationId: updateById_5
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessPermissionRuleUpdateInput"
required: true
responses:
"200":
description: "Status OK, data access rule updated"
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessPermissionRuleOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
delete:
tags:
- Data Access Rules
summary: Delete a Data Access Permission
description: This HTTP DELETE method is used to remove a specific data access
rule that provides instant access.
operationId: deleteById_8
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-rule/access-request:
get:
tags:
- Data Access Rules
summary: List all Data Access Requests
description: This HTTP GET method is used to retrieve information about data
access rules related to access requests.
operationId: getAllByParent_1
parameters:
- name: parentId
in: query
description: "Parent ID is a required query param, could be a dataset ID or
\ a data policy ID"
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRequestRuleQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
post:
tags:
- Data Access Rules
summary: Create a Data Access Request Rule
description: This HTTP POST method is used to create or define a new data access
rule related to access requests.
operationId: create_7
parameters:
- name: parentId
in: query
description: "Parent ID is a required query param, could be a dataset ID or
\ a data policy ID"
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRequestRuleInput"
responses:
"201":
description: "Status OK, data access rule created"
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRuleOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/data-access-rule/access-request/{id}:
get:
tags:
- Data Access Rules
summary: Retrieve a Data Access Request
description: This HTTP GET method is used to retrieve detailed information about
a specific data access rule related to access requests.
operationId: getById_3
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, data access request found."
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRequestRuleOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- Data Access Rules
summary: Update a Data Access Request
description: "This HTTP PUT method is used to retrieve detailed information
\ about a specific data access rule, which is related to handling access requests."
operationId: updateById_6
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRequestRuleUpdateInput"
required: true
responses:
"200":
description: "Status OK, data access rule updated"
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRequestRuleOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
delete:
tags:
- Data Access Rules
summary: Delete a Data Access Request
description: This HTTP DELETE method is used to remove a specific data access
rule that pertains to access requests.
operationId: deleteById_9
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/v1/data-access-rule:
get:
tags:
- Data Access Rules
summary: List all Data Access Rules
description: This HTTP GET method is used to retrieve a list of all data access
rules in the system.
operationId: query_1
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: type
in: query
schema:
type: array
items:
type: string
enum:
- INSTANT_ACCESS
- SELF_SERVICE
- ACCESS_REQUEST
- INSTANT_ACCESS_REQUEST
- name: identity
in: query
schema:
type: array
items:
type: string
- name: identityType
in: query
schema:
type: array
items:
type: string
enum:
- USER
- DB_USER
- GROUP
- IDP_GROUP
- DATABRICKS_GROUP
- DATABRICKS_SERVICE_PRINCIPAL
- SNOWFLAKE_ROLE
- SNOWFLAKE_ACCOUNT_NAME
- SNOWFLAKE_DATABASE_ROLE
- CEL
- EVERYONE
- name: accessLevel
in: query
schema:
type: array
items:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
- name: suspended
in: query
schema:
type: boolean
- name: parent
in: query
schema:
type: array
items:
type: string
- name: datasetId
in: query
schema:
type: array
items:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRuleResourceQueryResponseOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/data-access-rule/history:
get:
tags:
- Data Access Rules
summary: List Data Access Rule History
description: "This HTTP GET method is used to retrieve the history or log of
\ changes related to data access rules.
This API call provides information
\ about past modifications, including updates, deletions, and creation of
\ access rules, along with timestamps and the users who made the changes."
operationId: queryHistory
parameters:
- name: accountId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
- name: nextPageToken
in: query
description: "This parameter is used for iterate query result pages without
\ re-run the query for each page. Initial query should contain this parameter
\ (for example, set to empty for the first page), while all following queries
\ should contain it. Each page result will contain the `nextPageToken` field
\ with the value of the token for the next page."
schema:
type: string
- name: from
in: query
schema:
type: integer
format: int64
- name: to
in: query
schema:
type: integer
format: int64
- name: performedBy
in: query
schema:
type: array
items:
type: string
- name: performedBySystem
in: query
description: Allows to include Account Activity records performed by System.
schema:
type: boolean
- name: dataConsumers
in: query
schema:
type: array
items:
type: string
- name: excludeSubActions
in: query
schema:
type: array
items:
type: string
responses:
"200":
description: Status OK
content:
application/json:
schema:
$ref: "#/components/schemas/ResourceQueryPageResponseOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/data-access-rule/self-service:
get:
tags:
- Data Access Rules
summary: List all Data Access Self-Service
description: 'This HTTP GET method is used to retrieve information about data
access rules specifically related to self-service access. '
operationId: getAllByParent_2
parameters:
- name: parentId
in: query
description: "Parent ID is a required query param, could be a dataset ID or
\ a data policy ID"
required: true
schema:
minLength: 1
type: string
- name: page
in: query
schema:
type: integer
format: int32
default: 0
- name: pageSize
in: query
schema:
type: integer
format: int32
default: 5
- name: orderBy
in: query
schema:
type: array
items:
type: string
- name: orderDirection
in: query
schema:
type: array
items:
type: string
- name: search
in: query
schema:
type: string
responses:
"200":
description: Status OK.
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessSelfServiceRuleQueryResponse"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
post:
tags:
- Data Access Rules
summary: Create a Data Access Self-Service
description: This HTTP POST method is used to create or define a new data access
rule for self-service access.
operationId: create_8
parameters:
- name: parentId
in: query
description: "Parent ID is a required query param, could be a dataset ID or
\ a data policy ID"
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessSelfServiceRuleInput"
responses:
"201":
description: "Status OK, data access rule created"
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessRuleOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
security:
- BearerAuth: []
/api/v1/data-access-rule/self-service/{id}:
get:
tags:
- Data Access Rules
summary: Retrieve a Data Access Self-Service
description: "This HTTP GET method is used to retrieve detailed information
\ about a specific self-service data access rule.
This API call provides
\ details about the self service data access rule’s configuration, conditions,
\ and any permissions or settings."
operationId: getById_4
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"200":
description: "Status OK, data access self-service rule found."
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessSelfServiceRuleOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
put:
tags:
- Data Access Rules
summary: Update a Data Access Self-Service
description: This HTTP PUT method is used to update the details of an existing
self-service data access rule.
operationId: updateById_7
parameters:
- name: id
in: path
required: true
schema:
minLength: 1
type: string
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessSelfServiceRuleUpdateInput"
required: true
responses:
"200":
description: "Status OK, data access rule updated"
content:
application/json:
schema:
$ref: "#/components/schemas/DataAccessSelfServiceRuleOutput"
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
delete:
tags:
- Data Access Rules
summary: Delete a Data Access Self-Service
description: 'This HTTP DELETE method is used to remove a specific self-service
data access rule. '
operationId: deleteById_10
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
"204":
description: Status OK.
"400":
description: Bad configuration request
"401":
description: Invalid Authorization
"404":
description: Resource not found
security:
- BearerAuth: []
/api/authentication/token:
post:
tags:
- Service Account Authentication
summary: Create Authentication Bearer
description: "This HTTP POST method is used to generate or request an authentication
\ token.
NOTE: The token usually has a defined validity period and
\ is used to authenticate subsequent API requests."
operationId: authenticate
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/TokenAuthenticationInput"
responses:
"201":
description: "Status OK, bearer created."
content:
application/json:
schema:
$ref: "#/components/schemas/TokenOutput"
"400":
description: Bad configuration request
/api/authentication/oauth/token:
post:
tags:
- Service Account Authentication
summary: Create OAuth Authentication Token
description: This HTTP POST method is used for obtaining authentication tokens
that allow secure access to resources protected by OAuth 2.0.
operationId: oAuthClientCredentialsAuthentication
requestBody:
content:
application/x-www-form-urlencoded:
schema:
type: object
properties:
grant_type:
type: string
client_id:
type: string
client_secret:
type: string
responses:
"201":
description: "Status OK, bearer created."
content:
application/json:
schema:
$ref: "#/components/schemas/OAuthTokenOutput"
"400":
description: Bad configuration request
components:
schemas:
AWSMarketplaceDto:
required:
- marketplaceAccountId
- marketplaceCustomerId
- marketplaceProductCode
- provider
type: object
allOf:
- $ref: "#/components/schemas/MarketplaceDto"
- type: object
properties:
marketplaceAccountId:
minLength: 1
type: string
marketplaceCustomerId:
minLength: 1
type: string
marketplaceProductCode:
minLength: 1
type: string
AccountDataPortalSettingsDto:
type: object
properties:
defaultTemporaryCredentialsExpirationTime:
$ref: "#/components/schemas/ExpirationTimeDto"
preDefinedDataAccessPurposes:
type: array
items:
$ref: "#/components/schemas/PreDefinedDataAccessPurposeDto"
defaultPurpose:
type: string
enablePersonalAccessToken:
type: boolean
AccountOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
ssoEnabled:
type: boolean
ssoMetadataXml:
type: string
ssoValidLoginHours:
type: integer
format: int32
demoAccount:
type: boolean
dataStorageLocation:
type: string
enum:
- US
- EU
marketplaceDetails:
$ref: "#/components/schemas/MarketplaceDto"
dataPortalSettings:
$ref: "#/components/schemas/AccountDataPortalSettingsDto"
subscription:
$ref: "#/components/schemas/AccountSubscriptionDto"
featureVersion:
type: string
notificationsSettings:
type: array
items:
$ref: "#/components/schemas/NotificationSettingOutput"
usersNotificationSettings:
type: array
items:
$ref: "#/components/schemas/UserNotificationsSettingsDto"
customEmailUserAttribute:
type: string
awsExternalId:
type: string
commvaultTenantId:
type: string
usersNotificationsSettings:
type: array
writeOnly: true
items:
$ref: "#/components/schemas/UserNotificationsSettingsDto"
AccountSubscriptionDto:
type: object
properties:
type:
type: string
enum:
- PROSPECT
- DEMO
- TEST_DRIVE
- PAID_CUSTOMER
- PAST_CUSTOMER
- PARTNER
- E2E
AzureMarketplaceDto:
required:
- provider
type: object
allOf:
- $ref: "#/components/schemas/MarketplaceDto"
- type: object
properties:
customerTenantId:
type: string
BaseNotificationChannel:
type: object
properties:
type:
type: string
enum:
- EMAIL
- SLACK
ExpirationTimeDto:
type: object
properties:
value:
type: integer
format: int32
timeframe:
type: string
enum:
- Nanos
- Micros
- Millis
- Seconds
- Minutes
- Hours
- HalfDays
- Days
- Weeks
- Months
- Years
- Decades
- Centuries
- Millennia
- Eras
- Forever
description:
type: string
MarketplaceDto:
required:
- provider
type: object
properties:
provider:
type: string
enum:
- AWS
- AZURE
discriminator:
propertyName: provider
NotificationSettingOutput:
type: object
properties:
notificationKeys:
type: array
items:
type: string
recipients:
type: array
items:
type: string
channel:
type: string
enum:
- EMAIL
- SLACK
active:
type: boolean
updatedAt:
type: string
format: date-time
PreDefinedDataAccessPurposeDto:
type: object
properties:
purpose:
type: string
requiredReason:
type: boolean
UserNotificationsSettingsDto:
type: object
properties:
type:
type: string
enum:
- ACCESS_GRANTED
- ACCESS_DENIED
- ACCESS_REVOKED
- ACCESS_REQUEST_PENDING_APPROVAL
channels:
type: array
items:
$ref: "#/components/schemas/BaseNotificationChannel"
active:
type: boolean
overriddenDefault:
type: boolean
slackIntegrationActive:
type: boolean
PreDefinedDataAccessPurposesOutput:
type: object
properties:
purposes:
type: array
items:
$ref: "#/components/schemas/PreDefinedDataAccessPurposeDto"
defaultPurpose:
type: string
AccountThemeOutput:
type: object
properties:
enabled:
type: boolean
logo:
$ref: "#/components/schemas/AssetsParam"
backgroundColor:
type: string
primaryColor:
type: string
textPrimaryColor:
type: string
AssetsParam:
type: object
properties:
filename:
type: string
mimeType:
type: string
size:
type: integer
format: int32
originalFilename:
type: string
IdentityMinimalOutput:
type: object
properties:
id:
type: string
name:
type: string
type:
type: string
DataAccessIdentityOutput:
type: object
properties:
identityType:
type: string
enum:
- USER
- DB_USER
- GROUP
- IDP_GROUP
- DATABRICKS_GROUP
- DATABRICKS_SERVICE_PRINCIPAL
- SNOWFLAKE_ROLE
- SNOWFLAKE_ACCOUNT_NAME
- SNOWFLAKE_DATABASE_ROLE
- CEL
- EVERYONE
identity:
type: string
id:
type: string
displayName:
type: string
IdentitiesExpirationTimeOutput:
type: object
properties:
identitiesAndExpirationTime:
type: array
items:
$ref: "#/components/schemas/IdentityWithExpirationTime"
IdentityWithExpirationTime:
type: object
properties:
identity:
$ref: "#/components/schemas/DataAccessIdentityOutput"
temporaryCredentialsExpirationTime:
$ref: "#/components/schemas/ExpirationTimeDto"
NotificationsSettingsOutput:
type: array
properties:
empty:
type: boolean
first:
$ref: "#/components/schemas/NotificationSettingOutput"
last:
$ref: "#/components/schemas/NotificationSettingOutput"
items:
$ref: "#/components/schemas/NotificationSettingOutput"
NotificationSettingDto:
type: object
properties:
notificationKeys:
type: array
items:
type: string
recipients:
type: array
items:
type: string
channel:
type: string
enum:
- EMAIL
- SLACK
active:
type: boolean
AccountSettingsInput:
required:
- name
type: object
properties:
name:
minLength: 1
type: string
ssoEnabled:
type: boolean
ssoMetadataXml:
type: string
ssoValidLoginHours:
type: integer
format: int32
FormDataContentDisposition:
type: object
properties:
type:
type: string
parameters:
type: object
additionalProperties:
type: string
fileName:
type: string
creationDate:
type: string
format: date-time
modificationDate:
type: string
format: date-time
readDate:
type: string
format: date-time
size:
type: integer
format: int64
name:
type: string
AccountServiceOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
accountId:
type: string
description:
type: string
bot:
type: boolean
blocked:
type: boolean
bruteForceBlocked:
type: boolean
AccountServiceKeyOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
accountId:
type: string
description:
type: string
bot:
type: boolean
blocked:
type: boolean
bruteForceBlocked:
type: boolean
apiKey:
type: string
ApiIdentityInput:
required:
- accountId
- description
type: object
properties:
accountId:
minLength: 1
type: string
description:
minLength: 1
type: string
AccountServiceQueryOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/AccountServiceOutput"
count:
type: integer
format: int64
RoleOutput:
type: object
properties:
id:
type: string
name:
type: string
description:
type: string
DacAccessTokenOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
expirationTime:
type: string
format: date-time
permissions:
type: array
items:
type: string
enum:
- CLIENT_ACCESS
- SPECIAL_URL
enable:
type: boolean
token:
type: string
DacAccessTokenInput:
required:
- name
type: object
properties:
name:
minLength: 1
type: string
expirationTime:
type: string
format: date-time
permissions:
type: array
items:
type: string
enum:
- CLIENT_ACCESS
- SPECIAL_URL
enable:
type: boolean
DacAccessTokenQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DacAccessTokenWithoutTokenOutput"
count:
type: integer
format: int64
DacAccessTokenWithoutTokenOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
expirationTime:
type: string
format: date-time
permissions:
type: array
items:
type: string
enum:
- CLIENT_ACCESS
- SPECIAL_URL
enable:
type: boolean
ApproveAccessRequestInput:
type: object
properties:
approverNote:
type: string
DataAccessRequestOutput:
type: object
allOf:
- $ref: "#/components/schemas/DataAccessRuleOutput"
- type: object
properties:
timeLimit:
$ref: "#/components/schemas/DurationTimeLimitOutput"
user:
type: string
message:
type: string
purpose:
type: string
dataAccessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
requireApproverNote:
type: boolean
userPermissions:
$ref: "#/components/schemas/UserAccessRequestResourcePermissions"
DataAccessUnusedTimeLimitOutput:
type: object
properties:
unusedDaysUntilRevocation:
type: integer
format: int32
shouldRevoke:
type: boolean
DurationTimeLimitOutput:
type: object
properties:
shouldExpire:
type: boolean
unitType:
type: string
enum:
- MINUTES
- HOURS
- DAYS
- WEEKS
- MONTHS
- YEARS
units:
type: integer
format: int32
UserAccessRequestResourcePermissions:
type: object
properties:
canEdit:
type: boolean
canApprove:
type: boolean
DeleteAccessRequestInput:
type: object
properties:
rejectionNote:
type: string
DataAccessRequestQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataAccessRequestOutput"
count:
type: integer
format: int64
DataAccessRequestOverviewOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
identity:
$ref: "#/components/schemas/DataAccessIdentityOutput"
accessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
timeLimit:
$ref: "#/components/schemas/DurationTimeLimit"
unusedTimeLimit:
$ref: "#/components/schemas/DataAccessUnusedTimeLimit"
message:
type: string
purpose:
type: string
dataset:
$ref: "#/components/schemas/IdAndName"
securityPolicies:
type: array
items:
$ref: "#/components/schemas/IdAndName"
maskingProfiles:
type: array
items:
$ref: "#/components/schemas/IdAndName"
requireApproverNote:
type: boolean
userPermissions:
$ref: "#/components/schemas/UserAccessRequestResourcePermissions"
id:
type: string
DataAccessRequestOverviewQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataAccessRequestOverviewOutput"
count:
type: integer
format: int64
DataAccessUnusedTimeLimit:
type: object
properties:
unusedDaysUntilRevocation:
type: integer
format: int32
shouldRevoke:
type: boolean
DurationTimeLimit:
type: object
properties:
shouldExpire:
type: boolean
unitType:
type: string
enum:
- MINUTES
- HOURS
- DAYS
- WEEKS
- MONTHS
- YEARS
units:
type: integer
format: int32
IdAndName:
type: object
properties:
id:
type: string
name:
type: string
ListDataAccessRequestOverviewOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataAccessRequestOverviewOutput"
count:
type: integer
format: int64
UserAccessRequestInput:
type: object
properties:
message:
type: string
purpose:
type: string
dataAccessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
dataAccessRuleId:
type: string
ActionListEntry:
type: object
properties:
toolName:
type: string
numberOfQueries:
type: integer
StatsGenericOutput:
type: object
properties:
datastoresInUse:
type: integer
format: int32
distinctUserAccess:
type: integer
format: int32
bytesProcessed:
type: integer
numberOfQueries:
type: integer
lastQueriedAt:
type: string
format: date-time
ViolationsResponse:
type: object
properties:
masked:
type: integer
blocked:
type: integer
alerted:
type: integer
others:
type: integer
DashboardMetricsOutput:
type: object
properties:
dataStoresCount:
type: integer
format: int64
activeDataStoresCount:
type: integer
format: int64
governedQueriesCount:
type: integer
format: int64
queriesCount:
type: integer
format: int64
usersCount:
type: integer
format: int64
DataFlowsQueriesOutput:
type: object
properties:
records:
type: array
items:
type: object
count:
type: integer
format: int64
nextPageToken:
type: string
dsIdsToNamesMap:
type: object
additionalProperties:
type: string
EnterpriseAuditSnowflakeOutput:
type: object
properties:
enabled:
type: boolean
description: indicates if Audit logs are exported to Snowflake
region:
type: string
description: a Snowflake region where the Audit logs shared (should be the
same region as shared account)
sharedAccount:
type: string
description: Audit logs are shared with this customer's Snowflake account
ManagementIpsOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
ips:
type: array
items:
type: string
SamlIdpOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
providerName:
type: string
linkedDataStores:
type: array
items:
type: string
providerPublicCert:
type: string
providerLoginUrl:
type: string
providerIdentifier:
type: string
consumerEntityId:
type: string
consumerServiceUrl:
type: string
satoriPublicCert:
type: string
satoriPublicCerts:
type: array
items:
$ref: "#/components/schemas/SatoriPublicCertificate"
provider:
type: string
writeOnly: true
SatoriPublicCertificate:
type: object
properties:
publicCert:
type: string
expiryDate:
type: string
format: date-time
active:
type: boolean
AzureSamlCertificateInput:
required:
- satoriPublicCert
type: object
properties:
satoriPublicCert:
minLength: 1
type: string
IdentityProviderOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
providerName:
type: string
linkedDataStores:
type: array
items:
type: string
provider:
type: string
writeOnly: true
AzureSamlIdentityProviderInput:
required:
- provider
type: object
properties:
provider:
type: string
enum:
- OKTA_API
- AZURE_SAML
- AZURE_API
- ONELOGIN_API
- SCIM
providerPublicCert:
type: string
providerIdentifier:
type: string
providerLoginUrl:
type: string
consumerEntityId:
type: string
consumerServiceUrl:
type: string
AWSIamRoleCredentialsOutput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsOutput"
- type: object
properties:
awsServiceRoleARN:
type: string
AWSServicePrincipalTokenCredentialsOutput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsOutput"
- type: object
properties:
clientId:
type: string
AzureM2MServicePrincipalTokenCredentialsOutput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsOutput"
- type: object
properties:
clientId:
type: string
AzureServicePrincipalTokenCredentialsOutput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsOutput"
- type: object
properties:
tenantId:
type: string
clientId:
type: string
CloudProviderRegions:
type: object
properties:
cloudProvider:
type: string
enum:
- GCP
- AZURE
- AWS
- BYOC
regions:
type: array
items:
$ref: "#/components/schemas/RegionsMetadata"
CredentialsOutput:
type: object
properties:
hasPassword:
type: boolean
type:
type: string
enum:
- RSA_KEY_PAIR
- USERNAME_PASSWORD
- AZURE_SERVICE_PRINCIPAL_TOKEN
- AZURE_M2M_SERVICE_PRINCIPAL_TOKEN
- AWS_SERVICE_PRINCIPAL_TOKEN
- AWS_IAM_ROLE
- SERVICE_TOKEN
discriminator:
propertyName: type
DataStoreDiscoveryDetailsOutput:
type: object
properties:
objectId:
type: string
externalId:
type: string
cloudAccountId:
type: string
cloudAccountProvider:
type: string
enum:
- AWS
- SNOWFLAKE
- MONGO_ATLAS
- DATABRICKS
engineType:
type: string
cloudAccountName:
type: string
cluster:
type: boolean
DataStoreMinimalOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
hostname:
type: string
satoriHostname:
type: string
dataAccessControllerId:
type: string
parent:
type: string
type:
type: string
projectIds:
type: array
items:
type: string
originPort:
type: integer
format: int32
hasIdp:
type: boolean
demo:
type: boolean
dataStoreSettings:
$ref: "#/components/schemas/DataStoreSettingsOutput"
regions:
type: array
items:
$ref: "#/components/schemas/CloudProviderRegions"
discoveryDetails:
$ref: "#/components/schemas/DataStoreDiscoveryDetailsOutput"
environment:
type: string
DataStoreQueryOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataStoreMinimalOutput"
count:
type: integer
format: int64
DataStoreSettingsOutput:
type: object
description: specific datastore settings
oneOf:
- $ref: "#/components/schemas/MongoDBSettingsDto"
- $ref: "#/components/schemas/DatabricksDBSettingsOutput"
- $ref: "#/components/schemas/FabricDBSettingsOutput"
DatabricksDBSettingsOutput:
type: object
properties:
accountId:
type: string
warehouseId:
type: string
workspaceId:
type: string
orchestrationSettings:
$ref: "#/components/schemas/OrchestrationSettingsDto"
credentials:
$ref: "#/components/schemas/CredentialsOutput"
description: Required on creation of Databricks data store.
FabricDBSettingsOutput:
type: object
properties:
workspaceId:
type: string
orchestrationSettings:
$ref: "#/components/schemas/OrchestrationSettingsDto"
credentials:
$ref: "#/components/schemas/CredentialsOutput"
description: Required on creation of Fabric data store.
MongoDBSettingsDto:
type: object
properties:
deploymentType:
type: string
enum:
- MONGODB
- MONGODB_SRV
originConnectivitySecured:
type: boolean
awsServiceRoleArn:
type: string
description: Optional for MONGODB_SRV deployment. The IAM role ARN assumed
by the DAC and used for updating records in the hosted DNS zone.
awsHostedZoneId:
type: string
description: Optional for MONGODB_SRV deployment. The Hosted AWS DNS Zone
created for mapping MongoDB SRV records to Satori.
description: Required on creation of MongoDB data store.
OrchestrationSettingsDto:
type: object
properties:
enabled:
type: boolean
userAttributeKeyName:
type: string
RSAKeyPairCredentialsOutput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsOutput"
- type: object
properties:
username:
type: string
publicKey:
type: string
RegionsMetadata:
type: object
properties:
name:
type: string
countryName:
type: string
countryCode:
type: string
TokenCredentialsOutput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsOutput"
UsernamePasswordCredentialsOutput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsOutput"
- type: object
properties:
username:
type: string
IdentityProviderQueryOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/IdentityProviderOutput"
count:
type: integer
format: int64
IdentityInfo:
type: object
properties:
type:
type: string
name:
type: string
id:
type: string
displayName:
type: string
LocationHistoryOutput:
type: object
properties:
id:
type: string
identity:
$ref: "#/components/schemas/IdentityInfo"
actionType:
type: string
actionSubType:
type: string
timestamp:
type: string
format: date-time
userNote:
type: string
systemNote:
type: string
statusChanged:
type: string
enum:
- CLASSIFIED
- UNCLASSIFIED
- DELETED
classifiersAdded:
type: array
items:
type: string
classifiersRemoved:
type: array
items:
type: string
LocationHistoryQueryResponseOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/LocationHistoryOutput"
count:
type: integer
format: int64
nextPageToken:
type: string
AbstractLocationDto:
type: object
properties:
type:
type: string
deprecated: true
enum:
- RELATIONAL_LOCATION
- MYSQL_LOCATION
- ATHENA_LOCATION
- MONGO_LOCATION
- S3_LOCATION
- DATABRICKS_LOCATION
- DATABRICKS_EXTERNAL_LOCATION
- GRAPHQL_LOCATION
- SNOWFLAKE_WAREHOUSE_LOCATION
- ASSET_LOCATION
description: "Deprecated, use locationPath field."
deprecated: true
discriminator:
propertyName: type
AssetLocationDto:
type: object
allOf:
- $ref: "#/components/schemas/AbstractLocationDto"
- type: object
properties:
assetType:
type: string
enum:
- TABLE
- COLUMN
- SEMANTIC_MODEL
- REPORT
- DASHBOARD
- DATABASE
- SCHEMA
- JSON_PATH
- WAREHOUSE
- ENDPOINT
- TYPE
- FIELD
- EXTERNAL_LOCATION
- CATALOG
- BUCKET
- OBJECT
- COLLECTION
- VIEW
- ACCOUNT_ROLE
- SHARED_DB
name:
type: string
locationParts:
type: array
items:
type: string
parentTypes:
type: array
items:
type: string
enum:
- TABLE
- COLUMN
- SEMANTIC_MODEL
- REPORT
- DASHBOARD
- DATABASE
- SCHEMA
- JSON_PATH
- WAREHOUSE
- ENDPOINT
- TYPE
- FIELD
- EXTERNAL_LOCATION
- CATALOG
- BUCKET
- OBJECT
- COLLECTION
- VIEW
- ACCOUNT_ROLE
- SHARED_DB
AthenaLocationDto:
type: object
allOf:
- $ref: "#/components/schemas/AbstractLocationDto"
- type: object
properties:
catalog:
type: string
db:
type: string
table:
type: string
column:
type: string
semiPath:
$ref: "#/components/schemas/RelationalSemiPathField"
DatabricksExternalLocationDto:
type: object
allOf:
- $ref: "#/components/schemas/AbstractLocationDto"
- type: object
properties:
name:
type: string
url:
type: string
DatabricksLocationDto:
type: object
allOf:
- $ref: "#/components/schemas/AbstractLocationDto"
- type: object
properties:
catalog:
type: string
schema:
type: string
table:
type: string
column:
type: string
semiPath:
$ref: "#/components/schemas/RelationalSemiPathField"
GraphQLLocationDto:
type: object
allOf:
- $ref: "#/components/schemas/AbstractLocationDto"
- type: object
properties:
endpoint:
type: string
rootType:
type: string
field:
type: string
semiPath:
$ref: "#/components/schemas/RelationalSemiPathField"
LocationOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
dataStoreId:
type: string
location:
$ref: "#/components/schemas/AbstractLocationDto"
status:
type: string
tags:
type: array
items:
$ref: "#/components/schemas/TagOutput"
MongoLocationDto:
type: object
allOf:
- $ref: "#/components/schemas/AbstractLocationDto"
- type: object
properties:
db:
type: string
collection:
type: string
MySqlLocationDto:
type: object
allOf:
- $ref: "#/components/schemas/AbstractLocationDto"
- type: object
properties:
db:
type: string
table:
type: string
column:
type: string
semiPath:
$ref: "#/components/schemas/RelationalSemiPathField"
RelationalLocationDto:
type: object
allOf:
- $ref: "#/components/schemas/AbstractLocationDto"
- type: object
properties:
db:
type: string
schema:
type: string
table:
type: string
column:
type: string
semiPath:
$ref: "#/components/schemas/RelationalSemiPathField"
RelationalSemiPathField:
type: object
properties:
value:
type: string
type:
type: string
enum:
- JSON
S3LocationDto:
type: object
allOf:
- $ref: "#/components/schemas/AbstractLocationDto"
- type: object
properties:
bucket:
type: string
objectKey:
type: string
SnowflakeWorkhouseLocationDto:
type: object
allOf:
- $ref: "#/components/schemas/AbstractLocationDto"
- type: object
properties:
name:
type: string
TagOutput:
type: object
properties:
name:
type: string
displayName:
type: string
updatedAt:
type: string
format: date-time
updatedByUser:
type: boolean
status:
type: string
enum:
- ACTIVE
- DELETED
UpdateLocationInput:
type: object
properties:
addTags:
type: array
items:
type: string
removeTags:
type: array
items:
type: string
notes:
type: string
forceDelete:
type: boolean
MaskConfig:
type: object
properties:
type:
type: string
enum:
- TRUNCATE
- TRUNCATE_END
- REPLACE_CHAR
- REPLACE_STRING
- HASH
- EMAIL_PREFIX
- EMAIL_SUFFIX
- EMAIL_FULL
- EMAIL_HASH
- CREDIT_CARD_PREFIX
- CREDIT_CARD_FULL
- CREDIT_CARD_HASH
- IP_SUFFIX
- IP_FULL
- IP_HASH
- DATE_YEAR_ONLY
- DATE_1970_AGAIN
- NO_ACTION
- REDACT
- NUMBER_ZERO
- NUMBER_ROUND
- TRANSFORM
- SQL_FUNCTION
replacement:
type: string
truncate:
type: integer
format: int32
functionId:
type: string
sqlFunction:
type: string
tag:
type: string
continueWith:
$ref: "#/components/schemas/MaskConfigProperties"
MaskConfigProperties:
type: object
properties:
type:
type: string
enum:
- TRUNCATE
- TRUNCATE_END
- REPLACE_CHAR
- REPLACE_STRING
- HASH
- EMAIL_PREFIX
- EMAIL_SUFFIX
- EMAIL_FULL
- EMAIL_HASH
- CREDIT_CARD_PREFIX
- CREDIT_CARD_FULL
- CREDIT_CARD_HASH
- IP_SUFFIX
- IP_FULL
- IP_HASH
- DATE_YEAR_ONLY
- DATE_1970_AGAIN
- NO_ACTION
- REDACT
- NUMBER_ZERO
- NUMBER_ROUND
- TRANSFORM
- SQL_FUNCTION
replacement:
type: string
truncate:
type: integer
format: int32
functionId:
type: string
sqlFunction:
type: string
MaskProfileOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
description:
type: string
maskConfigs:
type: array
items:
$ref: "#/components/schemas/MaskConfig"
MaskProfileInput:
required:
- maskConfigs
- name
type: object
properties:
name:
minLength: 1
type: string
description:
type: string
maskConfigs:
minItems: 1
type: array
items:
$ref: "#/components/schemas/MaskConfig"
MaskProfileQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/MaskProfileOutput"
count:
type: integer
format: int64
IPRange:
type: object
properties:
ipRange:
type: string
NetworkPolicyMember:
type: object
properties:
type:
type: string
enum:
- management
- datastore
id:
type: string
NetworkPolicyOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
allowedRules:
type: array
items:
$ref: "#/components/schemas/NetworkPolicyRule"
blockedRules:
type: array
items:
$ref: "#/components/schemas/NetworkPolicyRule"
members:
type: array
items:
$ref: "#/components/schemas/NetworkPolicyMember"
NetworkPolicyRule:
type: object
properties:
ipRanges:
type: array
items:
$ref: "#/components/schemas/IPRange"
note:
type: string
NetworkPolicyInput:
type: object
properties:
name:
type: string
allowedRules:
type: array
items:
$ref: "#/components/schemas/NetworkPolicyRule"
blockedRules:
type: array
items:
$ref: "#/components/schemas/NetworkPolicyRule"
NetworkPolicyQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/NetworkPolicyOutput"
count:
type: integer
format: int64
ApplyMaskingProfileInput:
type: object
allOf:
- $ref: "#/components/schemas/MaskingActionInput"
- type: object
properties:
maskingProfileId:
type: string
AthenaTableLocationPrefixInput:
type: object
allOf:
- $ref: "#/components/schemas/LocationPrefixInput"
- type: object
properties:
catalog:
type: string
db:
type: string
table:
type: string
CurrentUserPermissions:
type: object
properties:
currentUserIsOwner:
type: boolean
canEditPolicies:
type: boolean
DataAccessIdentity:
type: object
properties:
identityType:
type: string
enum:
- USER
- DB_USER
- GROUP
- IDP_GROUP
- DATABRICKS_GROUP
- DATABRICKS_SERVICE_PRINCIPAL
- SNOWFLAKE_ROLE
- SNOWFLAKE_ACCOUNT_NAME
- SNOWFLAKE_DATABASE_ROLE
- CEL
- EVERYONE
identity:
type: string
id:
type: string
DataFilterCriteria:
type: object
properties:
condition:
type: string
enum:
- IS
- IS_NOT
identity:
$ref: "#/components/schemas/DataAccessIdentity"
DataFilterDefaultValues:
type: object
properties:
type:
type: string
enum:
- STRING
- NUMERIC
- CEL
- SQL
- NO_VALUE
- ALL_OTHER_VALUES
values:
type: array
items:
type: string
DataFilterValues:
type: object
properties:
type:
type: string
enum:
- STRING
- NUMERIC
- CEL
- SQL
- ANY_VALUE
- ALL_OTHER_VALUES
values:
type: array
items:
type: string
DatabricksTableLocationPrefixInput:
type: object
allOf:
- $ref: "#/components/schemas/LocationPrefixInput"
- type: object
properties:
catalog:
type: string
schema:
type: string
table:
type: string
GraphQLTableLocationPrefixInput:
type: object
allOf:
- $ref: "#/components/schemas/LocationPrefixInput"
- type: object
properties:
endpoint:
type: string
rootType:
type: string
LocationPrefixInput:
type: object
properties:
type:
type: string
enum:
- RELATIONAL_TABLE_LOCATION
- MYSQL_TABLE_LOCATION
- ATHENA_TABLE_LOCATION
- MONGO_TABLE_LOCATION
- S3_TABLE_LOCATION
- DATABRICKS_TABLE_LOCATION
- GRAPHQL_TABLE_LOCATION
description: "Deprecated, use locationPath field."
deprecated: true
discriminator:
propertyName: type
MaskingActionInput:
type: object
properties:
type:
type: string
enum:
- APPLY_MASKING_PROFILE
discriminator:
propertyName: type
oneOf:
- $ref: "#/components/schemas/ApplyMaskingProfileInput"
MaskingSecurityProfileInput:
type: object
properties:
active:
type: boolean
rules:
type: array
items:
$ref: "#/components/schemas/MaskingSecurityRuleInput"
MaskingSecurityRuleInput:
type: object
properties:
id:
type: string
description:
type: string
active:
type: boolean
criteria:
$ref: "#/components/schemas/DataFilterCriteria"
maskingAction:
$ref: "#/components/schemas/MaskingActionInput"
MongoTableLocationPrefixInput:
type: object
allOf:
- $ref: "#/components/schemas/LocationPrefixInput"
- type: object
properties:
db:
type: string
collection:
type: string
MySqlTableLocationPrefixInput:
type: object
allOf:
- $ref: "#/components/schemas/LocationPrefixInput"
- type: object
properties:
db:
type: string
table:
type: string
NodeLocationDto:
type: object
properties:
name:
type: string
type:
type: string
description: "[Optional] Asset type, when not specified, defaults takes
\ place, resolved by data store type and locationPath length."
enum:
- TABLE
- COLUMN
- SEMANTIC_MODEL
- REPORT
- DASHBOARD
- DATABASE
- SCHEMA
- JSON_PATH
- WAREHOUSE
- ENDPOINT
- TYPE
- FIELD
- EXTERNAL_LOCATION
- CATALOG
- BUCKET
- OBJECT
- COLLECTION
- VIEW
- ACCOUNT_ROLE
- SHARED_DB
description: "Location path, can be either a dot seperated string \"a.b.c\"
\ or a list of location parts with name and type [{name: ...}, {name: ...},\
\ {name: ....}]."
example: "For input, these are available options: 'a.b.c' or [{name: 'a'}, {name:\
\ 'b'}, {name: 'c'}] or [{name: 'a', type: 'DATABASE'}, {name: 'b', type:\
\ 'SCHEMA'}, {name: 'c', type: 'VIEW'}] However, the output will always be
\ a fully populated list of location parts"
RelationalTableLocationPrefixInput:
type: object
allOf:
- $ref: "#/components/schemas/LocationPrefixInput"
- type: object
properties:
db:
type: string
schema:
type: string
table:
type: string
RowLevelSecurityMap:
type: object
properties:
name:
type: string
filters:
type: array
items:
$ref: "#/components/schemas/RowLevelSecurityMapDataFilter"
defaults:
$ref: "#/components/schemas/DataFilterDefaultValues"
RowLevelSecurityMapDataFilter:
type: object
properties:
criteria:
$ref: "#/components/schemas/DataFilterCriteria"
values:
$ref: "#/components/schemas/DataFilterValues"
RowLevelSecurityProfileInput:
type: object
properties:
active:
type: boolean
rules:
type: array
items:
$ref: "#/components/schemas/RowLevelSecurityRuleInput"
maps:
type: array
items:
$ref: "#/components/schemas/RowLevelSecurityMap"
RowLevelSecurityRuleFilterInput:
type: object
properties:
locationPath:
type: array
description: "Location path, can be either a dot seperated string \"a.b.c\"
\ or a list of location parts with name and type [{name: ...}, {name:\
\ ...}, {name: ....}]."
example: "For input, these are available options: 'a.b.c' or [{name: 'a'},\
\ {name: 'b'}, {name: 'c'}] or [{name: 'a', type: 'DATABASE'}, {name:\
\ 'b', type: 'SCHEMA'}, {name: 'c', type: 'VIEW'}] However, the output
\ will always be a fully populated list of location parts"
items:
$ref: "#/components/schemas/NodeLocationDto"
dataStoreId:
type: string
locationPrefix:
$ref: "#/components/schemas/LocationPrefixInput"
logicYaml:
type: string
advanced:
type: boolean
RowLevelSecurityRuleInput:
type: object
properties:
id:
type: string
description:
type: string
active:
type: boolean
filter:
$ref: "#/components/schemas/RowLevelSecurityRuleFilterInput"
S3TableLocationPrefixInput:
type: object
allOf:
- $ref: "#/components/schemas/LocationPrefixInput"
- type: object
properties:
bucket:
type: string
objectKey:
type: string
SecurityPolicyOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
stats:
$ref: "#/components/schemas/SecurityPolicyStats"
profiles:
$ref: "#/components/schemas/SecurityProfilesInput"
currentUserPermissions:
$ref: "#/components/schemas/CurrentUserPermissions"
SecurityPolicyStats:
type: object
properties:
assignedToDatasets:
type: object
additionalProperties:
type: string
SecurityProfilesInput:
type: object
properties:
rowLevelSecurity:
$ref: "#/components/schemas/RowLevelSecurityProfileInput"
masking:
$ref: "#/components/schemas/MaskingSecurityProfileInput"
SecurityPolicyInput:
required:
- name
type: object
properties:
name:
minLength: 1
type: string
profiles:
$ref: "#/components/schemas/SecurityProfilesInput"
SecurityPolicyMinimalOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
currentUserIsOwner:
type: boolean
SecurityPolicyMinimalQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/SecurityPolicyMinimalOutput"
count:
type: integer
format: int64
SecurityPolicyStatisticsOutput:
type: object
properties:
securityPolicyId:
type: string
users:
type: integer
format: int64
queries:
type: integer
format: int64
SecurityPolicyStatisticsQueryResponse:
type: array
properties:
empty:
type: boolean
first:
$ref: "#/components/schemas/SecurityPolicyStatisticsOutput"
last:
$ref: "#/components/schemas/SecurityPolicyStatisticsOutput"
items:
$ref: "#/components/schemas/SecurityPolicyStatisticsOutput"
AccessSettingsDto:
type: object
properties:
temporaryCredentialsExpirationTime:
$ref: "#/components/schemas/ExpirationTimeDto"
JsonNode:
type: object
UserResourceDto:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
accountId:
type: string
parent:
type: string
displayName:
type: string
email:
type: string
lastName:
type: string
firstName:
type: string
authMethod:
type: integer
format: int32
activated:
type: boolean
status:
type: string
enum:
- PENDING_ACTIVATION
- ACTIVE
- DISABLED
accessSettings:
$ref: "#/components/schemas/AccessSettingsDto"
roles:
type: array
items:
type: string
attributes:
type: object
additionalProperties:
$ref: "#/components/schemas/JsonNode"
aliases:
type: array
items:
type: string
customAttributes:
type: object
additionalProperties:
$ref: "#/components/schemas/JsonNode"
customAliases:
type: array
items:
type: string
personalAccessTokenConfigured:
type: boolean
managed:
type: boolean
UserInput:
required:
- accountId
type: object
properties:
accountId:
minLength: 1
type: string
email:
type: string
format: email
firstName:
type: string
lastName:
type: string
UserMinimalResourceDto:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
accountId:
type: string
parent:
type: string
displayName:
type: string
email:
type: string
lastName:
type: string
firstName:
type: string
authMethod:
type: integer
format: int32
activated:
type: boolean
status:
type: string
enum:
- PENDING_ACTIVATION
- ACTIVE
- DISABLED
accessSettings:
$ref: "#/components/schemas/AccessSettingsDto"
roles:
type: array
items:
type: string
attributes:
type: object
additionalProperties:
$ref: "#/components/schemas/JsonNode"
aliases:
type: array
items:
type: string
personalAccessTokenConfigured:
type: boolean
managed:
type: boolean
UsersQueryOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/UserMinimalResourceDto"
count:
type: integer
format: int64
UserDatabaseCredentialsOutput:
type: object
properties:
username:
type: string
password:
type: string
expiredAt:
type: string
format: date-time
ActivationOutput:
type: object
properties:
uri:
type: string
RolesSet:
type: object
properties:
rolesIds:
uniqueItems: true
type: array
items:
type: string
UserWithGroupsOutput:
type: object
properties:
id:
type: string
fullName:
type: string
email:
type: string
groups:
type: array
items:
type: string
UserProfileInput:
required:
- firstName
- lastName
type: object
properties:
lastName:
minLength: 1
type: string
firstName:
minLength: 1
type: string
AssetOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
locationParts:
type: array
items:
type: string
locationPartTypes:
type: array
items:
type: string
enum:
- TABLE
- COLUMN
- SEMANTIC_MODEL
- REPORT
- DASHBOARD
- DATABASE
- SCHEMA
- JSON_PATH
- WAREHOUSE
- ENDPOINT
- TYPE
- FIELD
- EXTERNAL_LOCATION
- CATALOG
- BUCKET
- OBJECT
- COLLECTION
- VIEW
- ACCOUNT_ROLE
- SHARED_DB
assetType:
type: string
enum:
- TABLE
- COLUMN
- SEMANTIC_MODEL
- REPORT
- DASHBOARD
- DATABASE
- SCHEMA
- JSON_PATH
- WAREHOUSE
- ENDPOINT
- TYPE
- FIELD
- EXTERNAL_LOCATION
- CATALOG
- BUCKET
- OBJECT
- COLLECTION
- VIEW
- ACCOUNT_ROLE
- SHARED_DB
name:
type: string
description:
type: string
tags:
type: array
items:
$ref: "#/components/schemas/TagOutput"
dataStoreId:
type: string
dataStoreType:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
properties:
type: object
additionalProperties:
type: object
AssetQueryOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/AssetOutput"
count:
type: integer
format: int64
AssetSearchQueryOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/AssetOutput"
count:
type: integer
format: int64
nextPageToken:
type: string
dsIdsToNamesMap:
type: object
additionalProperties:
type: string
UpdateAssetInput:
type: object
properties:
description:
type: string
AvailablePackageVersionOutput:
type: object
properties:
version:
type: string
createdAt:
type: string
format: date-time
type:
type: string
enum:
- PATCH
- RECOMMENDED
- BETA
- CURRENT
AvailablePackageVersionQueryOutput:
type: object
properties:
count:
type: integer
format: int64
records:
type: array
items:
$ref: "#/components/schemas/AvailablePackageVersionOutput"
AWSProviderConfigurationInput:
type: object
allOf:
- $ref: "#/components/schemas/ProviderConfigurationDto"
- type: object
properties:
awsAccountId:
type: string
AutoUpgradeConfigDto:
required:
- maintenanceWindow
type: object
allOf:
- $ref: "#/components/schemas/UpgradeConfigDto"
- type: object
properties:
maintenanceWindow:
$ref: "#/components/schemas/MaintenanceWindowDto"
DataAccessControllerMinimalOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
uniqueName:
type: string
region:
type: string
cloudProvider:
type: string
enum:
- GCP
- AZURE
- AWS
- BYOC
type:
type: string
enum:
- PUBLIC
- PRIVATE
- PRIVATE_MANAGED
parent:
type: string
name:
type: string
ips:
type: array
items:
type: string
loadBalancer:
type: string
enum:
- INTERNAL
- EXTERNAL
creationStatus:
type: string
enum:
- NEW
- IN_PROGRESS
- CREATED
domain:
type: string
currentVersion:
$ref: "#/components/schemas/Version"
upgradeStatus:
$ref: "#/components/schemas/UpgradeStatus"
upgradeConfig:
$ref: "#/components/schemas/UpgradeConfigDto"
upgradePendingVersion:
type: string
logCollection:
$ref: "#/components/schemas/LogCollection"
providerConfiguration:
$ref: "#/components/schemas/ProviderConfigurationDto"
DataAccessQueryOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataAccessControllerMinimalOutput"
count:
type: integer
format: int64
accountIdsToNamesMap:
type: object
additionalProperties:
type: string
FrequencyDto:
type: object
properties:
type:
type: string
enum:
- WEEKLY
- MONTHLY
discriminator:
propertyName: type
oneOf:
- $ref: "#/components/schemas/WeeklyFrequencyDto"
- $ref: "#/components/schemas/MonthlyFrequencyDto"
LogCollection:
type: object
properties:
permission:
type: string
enum:
- SATORI
- CUSTOMER
MaintenanceWindowDto:
required:
- duration
- frequency
- startTime
type: object
properties:
frequency:
$ref: "#/components/schemas/FrequencyDto"
startTime:
type: string
description: "Start time format is: '00:00' - '23:59'"
duration:
type: integer
description: Duration should be at least 8 hours.
format: int32
ManualUpgradeConfigDto:
type: object
allOf:
- $ref: "#/components/schemas/UpgradeConfigDto"
MonthlyFrequencyDto:
required:
- day
type: object
allOf:
- $ref: "#/components/schemas/FrequencyDto"
- type: object
properties:
day:
type: integer
description: Day can be between 1 to 31.
format: int32
ProviderConfigurationDto:
type: object
SelectiveUpgradeConfigDto:
type: object
allOf:
- $ref: "#/components/schemas/UpgradeConfigDto"
- type: object
properties:
version:
type: string
description: A version number to be updated immediately
UpgradeConfigDto:
type: object
properties:
type:
type: string
enum:
- MANUAL
- AUTO
- SELECTIVE
discriminator:
propertyName: type
oneOf:
- $ref: "#/components/schemas/ManualUpgradeConfigDto"
- $ref: "#/components/schemas/AutoUpgradeConfigDto"
- $ref: "#/components/schemas/SelectiveUpgradeConfigDto"
UpgradeStatus:
type: object
properties:
version:
type: string
startedAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
finishedAt:
type: string
format: date-time
status:
type: string
enum:
- IN_PROGRESS
- SUCCESS
- FAILURE
statusMessage:
type: string
Version:
type: object
properties:
version:
type: string
lastUpdated:
type: string
format: date-time
WeeklyFrequencyDto:
required:
- day
type: object
allOf:
- $ref: "#/components/schemas/FrequencyDto"
- type: object
properties:
day:
type: string
enum:
- SUN
- MON
- TUE
- WED
- THU
- FRI
- SAT
DataAccessControllerOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
uniqueName:
type: string
region:
type: string
cloudProvider:
type: string
enum:
- GCP
- AZURE
- AWS
- BYOC
type:
type: string
enum:
- PUBLIC
- PRIVATE
- PRIVATE_MANAGED
parent:
type: string
name:
type: string
ips:
type: array
items:
type: string
loadBalancer:
type: string
enum:
- INTERNAL
- EXTERNAL
creationStatus:
type: string
enum:
- NEW
- IN_PROGRESS
- CREATED
domain:
type: string
currentVersion:
$ref: "#/components/schemas/Version"
upgradeStatus:
$ref: "#/components/schemas/UpgradeStatus"
upgradeConfig:
$ref: "#/components/schemas/UpgradeConfigDto"
upgradePendingVersion:
type: string
logCollection:
$ref: "#/components/schemas/LogCollection"
providerConfiguration:
$ref: "#/components/schemas/ProviderConfigurationDto"
suspendedStrategy:
$ref: "#/components/schemas/SuspendedStrategy"
yamlConfiguration:
type: string
terraformConfiguration:
type: string
gcpProjectName:
type: string
revision:
type: integer
format: int32
ingressPortRange:
type: string
SuspendedStrategy:
type: object
properties:
stopConfigurationDistribution:
type: boolean
ApproverIdentity:
type: object
properties:
type:
type: string
enum:
- USER
- GROUP
- DIRECTORY
- MANAGER
discriminator:
propertyName: type
DataPolicyRulesOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
priority:
type: integer
format: int32
tagsYaml:
type: string
rulesYaml:
type: string
DataPolicySecurityPoliciesOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
defaultSecurityPolicyIds:
type: array
items:
type: string
DataSetCurrentUserPermissions:
type: object
properties:
canEditDataPolicy:
type: boolean
canViewDataPolicy:
type: boolean
canEditInventory:
type: boolean
canViewInventory:
type: boolean
DataSetOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
currentUserPermissions:
$ref: "#/components/schemas/DataSetCurrentUserPermissions"
name:
type: string
description:
type: string
ownersIds:
type: array
items:
type: string
approvers:
type: array
items:
$ref: "#/components/schemas/ApproverIdentity"
ownersNamesMap:
type: object
additionalProperties:
$ref: "#/components/schemas/IdentityWithManaged"
includeLocations:
type: array
items:
$ref: "#/components/schemas/DatasetLocationOutput"
excludeLocations:
type: array
items:
$ref: "#/components/schemas/DatasetLocationOutput"
dataPolicyId:
type: string
permissionsEnabled:
type: boolean
customAccessRequestsEnabled:
type: boolean
customPolicy:
$ref: "#/components/schemas/DataPolicyRulesOutput"
defaultSecurityPolicies:
$ref: "#/components/schemas/DataPolicySecurityPoliciesOutput"
externalReference:
$ref: "#/components/schemas/ExternalReference"
externalUrl:
type: string
DatasetLocationOutput:
type: object
properties:
locationPath:
type: array
description: "Location path, can be either a dot seperated string \"a.b.c\"
\ or a list of location parts with name and type [{name: ...}, {name:\
\ ...}, {name: ....}]."
example: "For input, these are available options: 'a.b.c' or [{name: 'a'},\
\ {name: 'b'}, {name: 'c'}] or [{name: 'a', type: 'DATABASE'}, {name:\
\ 'b', type: 'SCHEMA'}, {name: 'c', type: 'VIEW'}] However, the output
\ will always be a fully populated list of location parts"
items:
$ref: "#/components/schemas/NodeLocationDto"
dataStoreId:
type: string
location:
$ref: "#/components/schemas/AbstractLocationDto"
DirectoryApproverIdentity:
type: object
allOf:
- $ref: "#/components/schemas/ApproverIdentity"
- type: object
properties:
id:
type: string
ExternalReference:
type: object
properties:
type:
type: string
enum:
- COLLIBRA
GroupApproverIdentity:
type: object
allOf:
- $ref: "#/components/schemas/ApproverIdentity"
- type: object
properties:
id:
type: string
IdentityWithManaged:
type: object
properties:
id:
type: string
name:
type: string
type:
type: string
managed:
type: boolean
ManagerApproverIdentity:
type: object
allOf:
- $ref: "#/components/schemas/ApproverIdentity"
UserApproverIdentity:
type: object
allOf:
- $ref: "#/components/schemas/ApproverIdentity"
- type: object
properties:
id:
type: string
DataPolicyRulesInput:
type: object
properties:
priority:
type: integer
format: int32
tagsYaml:
type: string
rulesYaml:
type: string
DataPolicySecurityPoliciesInput:
type: object
properties:
defaultSecurityPolicyIds:
type: array
items:
type: string
DataSetInput:
required:
- excludeLocations
- includeLocations
- name
- ownersIds
type: object
properties:
name:
minLength: 1
type: string
description:
type: string
ownersIds:
type: array
items:
type: string
approvers:
type: array
items:
$ref: "#/components/schemas/ApproverIdentity"
includeLocations:
type: array
items:
$ref: "#/components/schemas/DataStoreLocationInput"
excludeLocations:
type: array
items:
$ref: "#/components/schemas/DataStoreLocationInput"
permissionsEnabled:
type: boolean
customAccessRequestsEnabled:
type: boolean
customPolicy:
$ref: "#/components/schemas/DataPolicyRulesInput"
defaultSecurityPolicies:
$ref: "#/components/schemas/DataPolicySecurityPoliciesInput"
externalUrl:
type: string
DataStoreLocationInput:
type: object
properties:
locationPath:
type: array
description: "Location path, can be either a dot seperated string \"a.b.c\"
\ or a list of location parts with name and type [{name: ...}, {name:\
\ ...}, {name: ....}]."
example: "For input, these are available options: 'a.b.c' or [{name: 'a'},\
\ {name: 'b'}, {name: 'c'}] or [{name: 'a', type: 'DATABASE'}, {name:\
\ 'b', type: 'SCHEMA'}, {name: 'c', type: 'VIEW'}] However, the output
\ will always be a fully populated list of location parts"
items:
$ref: "#/components/schemas/NodeLocationDto"
dataStoreId:
type: string
location:
$ref: "#/components/schemas/AbstractLocationDto"
AccessRulesDetails:
type: object
properties:
id:
type: string
securityPolicyNames:
type: array
items:
type: string
type:
type: string
enum:
- SELF_SERVICE
- ACCESS_REQUEST
- INSTANCE_REQUEST
- INSTANCE_ACCESS
accessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
timeLimit:
$ref: "#/components/schemas/DataAccessTimeLimitOutput"
unusedTimeLimit:
$ref: "#/components/schemas/DataAccessUnusedTimeLimitOutput"
identity:
$ref: "#/components/schemas/DataAccessIdentityOutput"
approvers:
type: array
items:
$ref: "#/components/schemas/DatasetIdentityInfo"
requestable:
type: boolean
DataAccessTimeLimitOutput:
type: object
properties:
shouldExpire:
type: boolean
DatasetAccessDetailsOutput:
type: object
properties:
id:
type: string
name:
type: string
description:
type: string
administrators:
type: array
items:
$ref: "#/components/schemas/DatasetIdentityInfo"
approvers:
type: array
items:
$ref: "#/components/schemas/DatasetIdentityInfo"
availableAccessRules:
type: array
items:
$ref: "#/components/schemas/AccessRulesDetails"
instantAccessRule:
$ref: "#/components/schemas/AccessRulesDetails"
pendingRequest:
$ref: "#/components/schemas/PendingRequestDetails"
customAccessRequestsEnabled:
type: boolean
DatasetIdentityInfo:
type: object
properties:
name:
type: string
ExpirationTimeLimitOutput:
type: object
properties:
shouldExpire:
type: boolean
expiration:
type: string
format: date-time
PendingRequestDetails:
type: object
properties:
id:
type: string
message:
type: string
purpose:
type: string
originRuleId:
type: string
DataStoreConnectionDetails:
type: object
properties:
id:
type: string
name:
type: string
type:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
satoriHostname:
type: string
port:
type: integer
format: int32
satoriAuthEnabled:
type: boolean
dataStoreSettings:
$ref: "#/components/schemas/IConnectionSettingsOutput"
DatasetConnectionDetailsOutput:
type: object
properties:
id:
type: string
name:
type: string
description:
type: string
includeLocations:
type: array
items:
$ref: "#/components/schemas/DatasetLocationOutput"
excludeLocations:
type: array
items:
$ref: "#/components/schemas/DatasetLocationOutput"
dataStores:
type: array
items:
$ref: "#/components/schemas/DataStoreConnectionDetails"
IConnectionSettingsOutput:
type: object
description: specific datastore settings
oneOf:
- $ref: "#/components/schemas/MongoDBConnectionSettingOutput"
MongoDBConnectionSettingOutput:
type: object
properties:
type:
type: string
enum:
- MONGO
- ORCHESTRATION
deploymentType:
type: string
enum:
- MONGODB
- MONGODB_SRV
OrchestrationDBConnectionSettingOutput:
type: object
properties:
type:
type: string
enum:
- MONGO
- ORCHESTRATION
hostname:
type: string
DataSetMinimalOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
currentUserIsOwner:
type: boolean
DataSetMinimalQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataSetMinimalOutput"
count:
type: integer
format: int64
DataSetQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataSetOutput"
count:
type: integer
format: int64
DataStoreInfoOutput:
type: object
properties:
id:
type: string
name:
type: string
type:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
DatasetAccessDetailsMinimalOutput:
type: object
properties:
id:
type: string
name:
type: string
description:
type: string
dataStores:
type: array
items:
$ref: "#/components/schemas/DataStoreInfoOutput"
hasPendingRequest:
type: boolean
hasPermission:
type: boolean
canRequest:
type: boolean
DatasetsAccessDetailsQueryOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DatasetAccessDetailsMinimalOutput"
count:
type: integer
format: int64
DataStoreDetailsCliOutput:
type: object
properties:
id:
type: string
name:
type: string
type:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
satoriHostname:
type: string
port:
type: integer
format: int32
satoriAuthEnabled:
type: boolean
dataStoreSettings:
$ref: "#/components/schemas/IConnectionSettingsOutput"
dbs:
type: array
items:
type: string
DatasetDetailsCliOutput:
type: object
properties:
id:
type: string
name:
type: string
description:
type: string
dataStoreIds:
uniqueItems: true
type: array
items:
type: string
DatasetDetailsCliQueryOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DatasetDetailsCliOutput"
count:
type: integer
format: int64
dataStoreDetails:
type: array
items:
$ref: "#/components/schemas/DataStoreDetailsCliOutput"
AuthorizationAnalyticsSettingsOutput:
type: object
properties:
credentials:
$ref: "#/components/schemas/DataStoreCredentialsOutput"
autoScanEnabled:
type: boolean
enabled:
type: boolean
BaselinePolicyDto:
type: object
properties:
type:
type: string
enum:
- BASELINE_POLICY
- DEFAULT_ACCESS_LEVEL
discriminator:
propertyName: type
oneOf:
- $ref: "#/components/schemas/BaselinePolicyImplDto"
- $ref: "#/components/schemas/DefaultAccessLevelDto"
BaselinePolicyExclusionsDto:
type: object
properties:
excludedIdentities:
type: array
description: Only user type is supported.
items:
$ref: "#/components/schemas/DataAccessIdentityInput"
excludedQueryPatterns:
type: array
items:
$ref: "#/components/schemas/ExcludedQueryPatternDto"
BaselinePolicyImplDto:
type: object
allOf:
- $ref: "#/components/schemas/BaselinePolicyDto"
- type: object
properties:
unassociatedQueriesCategory:
$ref: "#/components/schemas/UnassociatedQueriesCategoryDto"
unsupportedQueriesCategory:
$ref: "#/components/schemas/UnsupportedQueriesCategoryDto"
exclusions:
$ref: "#/components/schemas/BaselinePolicyExclusionsDto"
DataAccessIdentityInput:
required:
- identityType
type: object
properties:
identityType:
type: string
enum:
- USER
- DB_USER
- GROUP
- IDP_GROUP
- DATABRICKS_GROUP
- DATABRICKS_SERVICE_PRINCIPAL
- SNOWFLAKE_ROLE
- SNOWFLAKE_ACCOUNT_NAME
- SNOWFLAKE_DATABASE_ROLE
- CEL
- EVERYONE
identity:
type: string
DataStoreCredentialsOutput:
type: object
properties:
type:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
DataStoreOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
hostname:
type: string
satoriHostname:
type: string
dataAccessControllerId:
type: string
parent:
type: string
type:
type: string
projectIds:
type: array
items:
type: string
originPort:
type: integer
format: int32
hasIdp:
type: boolean
demo:
type: boolean
dataStoreSettings:
$ref: "#/components/schemas/DataStoreSettingsOutput"
regions:
type: array
items:
$ref: "#/components/schemas/CloudProviderRegions"
discoveryDetails:
$ref: "#/components/schemas/DataStoreDiscoveryDetailsOutput"
environment:
type: string
identityProviderId:
type: string
customIngressPort:
type: integer
format: int32
baselineSecurityPolicy:
$ref: "#/components/schemas/BaselinePolicyDto"
networkPolicy:
$ref: "#/components/schemas/NetworkPolicyMinimalOutput"
satoriAuthSettings:
$ref: "#/components/schemas/SatoriAuthSettingsOutput"
authorizationAnalyticsSettings:
$ref: "#/components/schemas/AuthorizationAnalyticsSettingsOutput"
sandboxEnvironment:
$ref: "#/components/schemas/SandboxEnvironment"
enableProxy:
type: boolean
DefaultAccessLevelDto:
type: object
allOf:
- $ref: "#/components/schemas/BaselinePolicyDto"
- type: object
properties:
defaultAccessLevel:
type: string
enum:
- NONE
- READ_ONLY
- READ_WRITE
- OWNER
ExcludedQueryPatternDto:
type: object
properties:
pattern:
type: string
NetworkPolicyMinimalOutput:
type: object
properties:
name:
type: string
allowedRules:
type: array
items:
$ref: "#/components/schemas/NetworkPolicyRule"
blockedRules:
type: array
items:
$ref: "#/components/schemas/NetworkPolicyRule"
SandboxEnvironment:
type: object
properties:
users:
type: array
items:
$ref: "#/components/schemas/SandboxUser"
SandboxUser:
type: object
properties:
username:
type: string
password:
type: string
SatoriAuthSettingsOutput:
type: object
properties:
enabled:
type: boolean
credentials:
$ref: "#/components/schemas/CredentialsOutput"
enablePersonalAccessToken:
type: boolean
UnassociatedQueriesCategoryDto:
type: object
properties:
queryAction:
type: string
enum:
- PASS
- REDACT
- BLOCK
UnsupportedQueriesCategoryDto:
type: object
properties:
queryAction:
type: string
enum:
- PASS
- REDACT
- BLOCK
AISecurityPolicy:
type: object
properties:
promptInjectionEnabled:
type: boolean
piiProtectionMode:
type: string
enum:
- OPEN
- BLOCK
- OPTIONAL
maskingProfileId:
type: string
rateLimit:
$ref: "#/components/schemas/AISecurityPolicyRateLimit"
AISecurityPolicyRateLimit:
type: object
properties:
numOfTokens:
type: integer
format: int32
numOfTimeUnit:
type: integer
format: int32
timeUnit:
type: string
enum:
- NANOSECONDS
- MICROSECONDS
- MILLISECONDS
- SECONDS
- MINUTES
- HOURS
- DAYS
AWSAccount:
type: object
properties:
id:
type: string
name:
type: string
arn:
type: string
AWSIamRoleCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsInput"
- type: object
properties:
awsServiceRoleARN:
type: string
AWSServicePrincipalTokenCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsInput"
- type: object
properties:
clientId:
type: string
clientSecret:
type: string
AiDBSettingsDto:
type: object
properties:
modelHost:
type: string
modelCategory:
type: string
defaultModel:
type: string
selectedModels:
type: array
items:
type: string
customModels:
type: array
items:
$ref: "#/components/schemas/CustomModel"
securityPolicy:
$ref: "#/components/schemas/AISecurityPolicy"
description: Additional Settings for AI Datastore
AtlasCluster:
type: object
properties:
id:
type: string
name:
type: string
project:
$ref: "#/components/schemas/AtlasProject"
enabled:
type: boolean
AtlasCredentialsInput:
type: object
properties:
privateKey:
type: string
publicKey:
type: string
availableClusters:
type: array
items:
$ref: "#/components/schemas/AtlasCluster"
AtlasProject:
type: object
properties:
id:
type: string
name:
type: string
AuthorizationAnalyticsSettingsInput:
type: object
properties:
credentials:
$ref: "#/components/schemas/DataStoreCredentialsInput"
autoScanEnabled:
type: boolean
enabled:
type: boolean
AzureM2MServicePrincipalTokenCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsInput"
- type: object
properties:
clientId:
type: string
clientSecret:
type: string
AzureServicePrincipalTokenCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsInput"
- type: object
properties:
tenantId:
type: string
clientId:
type: string
clientSecret:
type: string
BedrockCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/DataStoreCredentialsInput"
- type: object
properties:
availableAccounts:
type: array
items:
$ref: "#/components/schemas/AWSAccount"
BigQueryCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/DataStoreCredentialsInput"
- type: object
properties:
content:
type: string
filename:
type: string
availableProjects:
uniqueItems: true
type: array
items:
$ref: "#/components/schemas/GcpProject"
client_email:
type: string
CredentialsInput:
type: object
properties:
type:
type: string
enum:
- RSA_KEY_PAIR
- USERNAME_PASSWORD
- AZURE_SERVICE_PRINCIPAL_TOKEN
- AZURE_M2M_SERVICE_PRINCIPAL_TOKEN
- AWS_SERVICE_PRINCIPAL_TOKEN
- AWS_IAM_ROLE
- SERVICE_TOKEN
discriminator:
propertyName: type
CustomModel:
type: object
properties:
value:
type: string
name:
type: string
DataStoreCredentialsInput:
type: object
properties:
type:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
discriminator:
propertyName: type
DataStoreInput:
required:
- hostname
- name
type: object
properties:
name:
minLength: 1
type: string
hostname:
minLength: 1
type: string
type:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
dataAccessControllerId:
type: string
projectIds:
type: array
description: "BigQuery - project IDs, Athena - AWS Account ID, CockroachDB
\ - cluster ID"
items:
type: string
description: "BigQuery - project IDs, Athena - AWS Account ID, CockroachDB
\ - cluster ID"
originPort:
type: integer
format: int32
baselineSecurityPolicy:
$ref: "#/components/schemas/BaselinePolicyDto"
dataStoreSettings:
$ref: "#/components/schemas/DataStoreSettingsDto"
customIngressPort:
type: integer
format: int32
satoriHostname:
type: string
networkPolicy:
$ref: "#/components/schemas/NetworkPolicyInput"
satoriAuthSettings:
$ref: "#/components/schemas/SatoriAuthSettingsInput"
authorizationAnalyticsSettings:
$ref: "#/components/schemas/AuthorizationAnalyticsSettingsInput"
DataStoreSettingsDto:
type: object
description: specific datastore settings
oneOf:
- $ref: "#/components/schemas/MongoDBSettingsDto"
- $ref: "#/components/schemas/AiDBSettingsDto"
- $ref: "#/components/schemas/DatabricksDBSettingsInput"
- $ref: "#/components/schemas/FabricDBSettingsInput"
DatabricksDBSettingsInput:
type: object
properties:
accountId:
type: string
warehouseId:
type: string
workspaceId:
type: string
orchestrationSettings:
$ref: "#/components/schemas/OrchestrationSettingsDto"
credentials:
$ref: "#/components/schemas/CredentialsInput"
FabricDBSettingsInput:
type: object
properties:
workspaceId:
type: string
orchestrationSettings:
$ref: "#/components/schemas/OrchestrationSettingsDto"
credentials:
$ref: "#/components/schemas/CredentialsInput"
GcpProject:
type: object
properties:
id:
type: string
name:
type: string
enabled:
type: boolean
MongoCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/DataStoreCredentialsInput"
- type: object
properties:
username:
type: string
password:
type: string
atlas:
$ref: "#/components/schemas/AtlasCredentialsInput"
PostgreSQLCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/DataStoreCredentialsInput"
- type: object
properties:
username:
type: string
password:
type: string
dbname:
type: string
RSAKeyPairCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsInput"
- type: object
properties:
username:
type: string
privateKey:
type: string
publicKey:
type: string
RedshiftCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/DataStoreCredentialsInput"
- type: object
properties:
username:
type: string
password:
type: string
dbname:
type: string
S3CredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/DataStoreCredentialsInput"
- type: object
properties:
availableAccounts:
type: array
items:
$ref: "#/components/schemas/AWSAccount"
SatoriAuthSettingsInput:
type: object
properties:
enabled:
type: boolean
credentials:
$ref: "#/components/schemas/CredentialsInput"
enablePersonalAccessToken:
type: boolean
SnowflakeCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/DataStoreCredentialsInput"
- type: object
properties:
username:
type: string
password:
type: string
account:
type: string
role:
type: string
warehouse:
type: string
TokenCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsInput"
- type: object
properties:
token:
type: string
UsernamePasswordCredentialsInput:
type: object
allOf:
- $ref: "#/components/schemas/CredentialsInput"
- type: object
properties:
username:
type: string
password:
type: string
DirectoryObjectOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
description:
type: string
DbRoleMemberOutput:
type: object
allOf:
- $ref: "#/components/schemas/GroupMemberOutput"
- type: object
properties:
dsType:
type: string
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
DirectoryGroupMemberOutput:
type: object
allOf:
- $ref: "#/components/schemas/GroupMemberOutput"
- type: object
properties:
id:
type: string
DirectoryGroupOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
description:
type: string
members:
type: array
items:
$ref: "#/components/schemas/GroupMemberOutput"
subGroups:
type: array
items:
$ref: "#/components/schemas/DirectoryGroupOutput"
accessSettings:
$ref: "#/components/schemas/AccessSettingsDto"
GroupMemberOutput:
required:
- type
type: object
properties:
name:
type: string
type:
type: string
discriminator:
propertyName: type
oneOf:
- $ref: "#/components/schemas/UsernameMemberOutput"
- $ref: "#/components/schemas/IdpGroupMemberOutput"
- $ref: "#/components/schemas/DbRoleMemberOutput"
- $ref: "#/components/schemas/DirectoryGroupMemberOutput"
IdpGroupMemberOutput:
type: object
properties:
id:
type: string
email:
type: string
displayName:
type: string
UsernameMemberOutput:
type: object
allOf:
- $ref: "#/components/schemas/GroupMemberOutput"
- type: object
properties:
id:
type: string
email:
type: string
DbRoleMemberInput:
type: object
allOf:
- $ref: "#/components/schemas/GroupMemberInput"
- type: object
properties:
dsType:
type: string
description: DataStore type
enum:
- SNOWFLAKE
- REDSHIFT
- BIGQUERY
- POSTGRESQL
- ATHENA
- MSSQL
- SYNAPSE
- MYSQL
- OCEANBASE
- API_SERVER
- MARIA_DB
- COCKROACH_DB
- OPENSEARCH
- ELASTICSEARCH
- GREENPLUM
- S3
- MONGO
- DATABRICKS
- FABRIC
- AZURE_OPEN_AI
- OPEN_AI
- BEDROCK
- ORACLE
- DB2
- DYNAMO_DB
- DOCUMENT_DB
- REDIS
- MEMCACHED
DirectoryGroupMemberInput:
type: object
allOf:
- $ref: "#/components/schemas/GroupMemberInput"
DirectoryObjectInput:
type: object
properties:
name:
type: string
description:
type: string
members:
type: array
items:
$ref: "#/components/schemas/GroupMemberInput"
GroupMemberInput:
type: object
properties:
type:
type: string
writeOnly: true
enum:
- USERNAME
- IDP_GROUP
- DB_ROLE
- DIRECTORY_GROUP
name:
type: string
discriminator:
propertyName: type
oneOf:
- $ref: "#/components/schemas/UsernameMemberInput"
- $ref: "#/components/schemas/IdpGroupMemberInput"
- $ref: "#/components/schemas/DbRoleMemberInput"
- $ref: "#/components/schemas/DirectoryGroupMemberInput"
IdpGroupMemberInput:
type: object
allOf:
- $ref: "#/components/schemas/GroupMemberInput"
- type: object
properties:
provider:
type: string
enum:
- OKTA
- AZURE
- ONELOGIN
- SCIM
UsernameMemberInput:
type: object
allOf:
- $ref: "#/components/schemas/GroupMemberInput"
- type: object
properties:
email:
type: string
DirectoryQueryOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DirectoryObjectOutput"
count:
type: integer
format: int64
IdpGroupOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
name:
type: string
members:
type: array
items:
$ref: "#/components/schemas/IdpGroupMemberOutput"
accessSettings:
$ref: "#/components/schemas/AccessSettingsDto"
IdpGroupQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/IdpGroupOutput"
count:
type: integer
format: int64
TaxonomyNodeOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
nodeType:
type: string
enum:
- CATEGORY
- CLASSIFIER
name:
type: string
tag:
type: string
description:
type: string
parentNode:
type: string
TaxonomyCategoryInput:
required:
- name
type: object
properties:
name:
minLength: 1
type: string
description:
type: string
parentNode:
type: string
color:
type: string
ClassifierConfig:
type: object
properties:
type:
type: string
enum:
- SATORI_BASED
- CUSTOM
- NON_AUTOMATIC
fieldNamePattern:
type: string
satoriBaseClassifierId:
type: string
fieldType:
type: string
enum:
- ANY
- TEXT
- NUMERIC
- DATE
values:
$ref: "#/components/schemas/ClassifierValues"
additionalSatoriCategoriesToTag:
type: array
items:
type: string
ClassifierScopeInput:
type: object
properties:
datasetIds:
type: array
items:
type: string
includeLocations:
type: array
items:
$ref: "#/components/schemas/DataStoreLocationInput"
ClassifierValues:
type: object
properties:
values:
type: array
items:
type: string
caseInsensitive:
type: boolean
regex:
type: boolean
TaxonomyCustomClassifierInput:
required:
- name
type: object
properties:
name:
minLength: 1
type: string
description:
type: string
parentNode:
type: string
scope:
$ref: "#/components/schemas/ClassifierScopeInput"
config:
$ref: "#/components/schemas/ClassifierConfig"
TaxonomyNodeQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/TaxonomyNodeOutput"
count:
type: integer
format: int64
SatoriTaxonomyNode:
type: object
properties:
id:
type: string
nodeType:
type: string
enum:
- CATEGORY
- CLASSIFIER
parentNode:
type: string
tag:
type: string
name:
type: string
description:
type: string
SatoriTaxonomyQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/SatoriTaxonomyNode"
count:
type: integer
format: int64
DataAccessPermissionOrigin:
type: object
properties:
originType:
type: string
enum:
- ACCESS_REQUEST
- SELF_SERVICE
dateRequested:
type: string
format: date-time
user:
type: string
message:
type: string
purpose:
type: string
DataAccessPermissionRuleOutput:
type: object
allOf:
- $ref: "#/components/schemas/DataAccessRuleOutput"
- type: object
properties:
timeLimit:
$ref: "#/components/schemas/ExpirationTimeLimitOutput"
origin:
$ref: "#/components/schemas/DataAccessPermissionOrigin"
approverNote:
type: string
DataAccessRequestRuleOutput:
type: object
allOf:
- $ref: "#/components/schemas/DataAccessRuleOutput"
- type: object
properties:
timeLimit:
$ref: "#/components/schemas/DurationTimeLimitOutput"
requireApproverNote:
type: boolean
approvers:
type: array
items:
$ref: "#/components/schemas/ApproverIdentity"
permissions:
$ref: "#/components/schemas/UserAccessRequestResourcePermissions"
DataAccessRuleOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
type:
type: string
enum:
- INSTANT_ACCESS
- SELF_SERVICE
- ACCESS_REQUEST
- INSTANT_ACCESS_REQUEST
suspended:
type: boolean
identity:
$ref: "#/components/schemas/DataAccessIdentityOutput"
accessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
timeLimit:
$ref: "#/components/schemas/DataAccessTimeLimitOutput"
unusedTimeLimit:
$ref: "#/components/schemas/DataAccessUnusedTimeLimitOutput"
securityPolicyIds:
type: array
items:
type: string
discriminator:
propertyName: type
DataAccessSelfServiceRuleOutput:
type: object
properties:
entityVersion:
type: integer
format: int64
createdAt:
type: string
format: date-time
updatedAt:
type: string
format: date-time
nameCreatedBy:
type: string
nameUpdatedBy:
type: string
parentId:
type: string
id:
type: string
type:
type: string
enum:
- INSTANT_ACCESS
- SELF_SERVICE
- ACCESS_REQUEST
- INSTANT_ACCESS_REQUEST
suspended:
type: boolean
identity:
$ref: "#/components/schemas/DataAccessIdentityOutput"
accessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
timeLimit:
$ref: "#/components/schemas/DurationTimeLimitOutput"
unusedTimeLimit:
$ref: "#/components/schemas/DataAccessUnusedTimeLimitOutput"
securityPolicyIds:
type: array
items:
type: string
DataAccessPermissionRuleInput:
required:
- accessLevel
- identity
- timeLimit
- unusedTimeLimit
type: object
properties:
accessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
timeLimit:
$ref: "#/components/schemas/ExpirationTimeLimitInput"
unusedTimeLimit:
$ref: "#/components/schemas/DataAccessUnusedTimeLimitInput"
securityPolicyIds:
type: array
items:
type: string
suspended:
type: boolean
identity:
$ref: "#/components/schemas/DataAccessIdentityInput"
approverNote:
type: string
DataAccessUnusedTimeLimitInput:
type: object
properties:
unusedDaysUntilRevocation:
maximum: 180
type: integer
format: int32
shouldRevoke:
type: boolean
ExpirationTimeLimitInput:
type: object
properties:
shouldExpire:
type: boolean
expiration:
type: string
format: date-time
DataAccessPermissionQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataAccessPermissionRuleOutput"
count:
type: integer
format: int64
DataAccessPermissionRuleUpdateInput:
required:
- accessLevel
- timeLimit
- unusedTimeLimit
type: object
properties:
accessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
timeLimit:
$ref: "#/components/schemas/ExpirationTimeLimitInput"
unusedTimeLimit:
$ref: "#/components/schemas/DataAccessUnusedTimeLimitInput"
securityPolicyIds:
type: array
items:
type: string
suspended:
type: boolean
DataAccessRequestRuleInput:
required:
- accessLevel
- identity
- timeLimit
- unusedTimeLimit
type: object
properties:
accessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
timeLimit:
$ref: "#/components/schemas/DurationTimeLimitInput"
unusedTimeLimit:
$ref: "#/components/schemas/DataAccessUnusedTimeLimitInput"
securityPolicyIds:
type: array
items:
type: string
suspended:
type: boolean
identity:
$ref: "#/components/schemas/DataAccessIdentityInput"
requireApproverNote:
type: boolean
approvers:
type: array
items:
$ref: "#/components/schemas/ApproverIdentity"
DurationTimeLimitInput:
type: object
properties:
shouldExpire:
type: boolean
unitType:
type: string
enum:
- MINUTES
- HOURS
- DAYS
- WEEKS
- MONTHS
- YEARS
units:
type: integer
format: int32
DataAccessRequestRuleQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataAccessRequestRuleOutput"
count:
type: integer
format: int64
DataAccessRequestRuleUpdateInput:
required:
- accessLevel
- timeLimit
- unusedTimeLimit
type: object
properties:
accessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
timeLimit:
$ref: "#/components/schemas/DurationTimeLimitInput"
unusedTimeLimit:
$ref: "#/components/schemas/DataAccessUnusedTimeLimitInput"
securityPolicyIds:
type: array
items:
type: string
suspended:
type: boolean
requireApproverNote:
type: boolean
approvers:
type: array
items:
$ref: "#/components/schemas/ApproverIdentity"
DataAccessRuleResourceQueryResponseOutput:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataAccessRuleOutput"
count:
type: integer
format: int64
ResourceQueryPageResponseOutput:
type: object
properties:
records:
type: array
items:
type: object
count:
type: integer
format: int64
nextPageToken:
type: string
DataAccessSelfServiceRuleInput:
required:
- accessLevel
- identity
- timeLimit
- unusedTimeLimit
type: object
properties:
accessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
timeLimit:
$ref: "#/components/schemas/DurationTimeLimitInput"
unusedTimeLimit:
$ref: "#/components/schemas/DataAccessUnusedTimeLimitInput"
securityPolicyIds:
type: array
items:
type: string
suspended:
type: boolean
identity:
$ref: "#/components/schemas/DataAccessIdentityInput"
DataAccessSelfServiceRuleQueryResponse:
type: object
properties:
records:
type: array
items:
$ref: "#/components/schemas/DataAccessSelfServiceRuleOutput"
count:
type: integer
format: int64
DataAccessSelfServiceRuleUpdateInput:
required:
- accessLevel
- timeLimit
- unusedTimeLimit
type: object
properties:
accessLevel:
type: string
enum:
- READ_ONLY
- READ_WRITE
- OWNER
timeLimit:
$ref: "#/components/schemas/DurationTimeLimitInput"
unusedTimeLimit:
$ref: "#/components/schemas/DataAccessUnusedTimeLimitInput"
securityPolicyIds:
type: array
items:
type: string
suspended:
type: boolean
TokenOutput:
type: object
properties:
token:
type: string
TokenAuthenticationInput:
required:
- serviceAccountId
- serviceAccountKey
type: object
properties:
serviceAccountId:
minLength: 1
type: string
serviceAccountKey:
minLength: 1
type: string
OAuthTokenOutput:
type: object
properties:
access_token:
type: string
token_type:
type: string
expires_in:
type: integer
description: The number of seconds until the token expires
format: int64
securitySchemes:
BearerAuth:
type: http
scheme: bearer