openapi: 3.2.0 info: title: AppOmni Compliance Reports API description: 'Compliance control evaluation and report generation, retrieval and download. Derived faithfully from the AppOmni public Postman collection published by AppOmni at https://api.appomni.com/ — every path, method, parameter, request body and example response below is taken verbatim from that collection. No operation was invented.' version: 1.0.0 contact: name: AppOmni url: https://appomni.com/support/ license: name: Proprietary url: https://appomni.com/terms-of-service/ x-generated-from: AppOmni public Postman collection (publishedId 2sBXc7Mjib, published 2026-02-04) x-generated-source: https://api.appomni.com/api/collections/45135595/2sBXc7Mjib?segregateAuth=true&versionTag=latest x-generated-method: derived x-generated-date: '2026-09-04' servers: - url: https://{instance}.appomni.com description: AppOmni tenant. Replace {instance} with your AppOmni subdomain — e.g. `acme` if you log in at acme.appomni.com. variables: instance: default: example description: Your AppOmni tenant subdomain security: - bearerAuth: [] tags: - name: Reports paths: /api/v1/reports/list/list_reports/: get: operationId: listAvailableReports summary: List available reports tags: - Reports description: 'Returns a list of reports which a user can run. To list report groups, see /reports/group accepted_parameters can be passed when requesting a report. Response Fields Field Data Type Description Example report_package String The name of the app the report being requested is defined in core report_pretty_name String Human-readable name All Issues Export Report report_description String Detailed report description Report on all issues report_class String The name of the actual class in code defining this report. Used as a unique identifier for the report AllIssuesExportReport report_types Array[String] Possible output file types which can be specified when generating the report ["xlsx", "csv", "json"] service_type String Service type core accepted_parameters Array[Object] If the report generation can be changed according to certain parameters, they are listed here See accepted_parameters fields below category String Report category. See /report_categories for list of possible values summary is_internal Boolean Whether the report is for internal use only false accepted_parameters Fields Field Data Type Description Example name String Parameter name pk__in type String Parameter data type int required Boolean Whether the parameter is required false md_version Integer Metadata version 1 md_kind String Metadata kind reports.report.acceptedparameter' responses: '200': description: List Available Reports content: text/plain: schema: type: string example: "[\n {\n \"report_package\": \"core\",\n \"report_pretty_name\": \"All Issues Export Report\",\n \"report_description\": \"Report on all issues\",\n \"report_class\": \"AllIssuesExportReport\",\n \"report_types\": [\n \"xlsx\",\n \"csv\",\n \"json\"\n ],\n \"service_type\": \"core\",\n \"accepted_parameters\": [\n {\n \"name\": \"pk__in\",\n \"type\": \"int\",\n \"required\": false,\n \"md_version\": 1,\n \"md_kind\": \"reports.report.acceptedparameter\"\n },\n {\n \"name\": \"unique_id__in\",\n \"type\": \"str\",\n \"required\": false,\n \"md_version\": 1,\n \"md_kind\": \"reports.report.acceptedparameter\"\n },\n {\n \"name\": \"pk\",\n \"type\": \"int\",\n \"required\": false,\n \"md_version\": 1,\n \"md_kind\": \"reports.report.acceptedparameter\"\n },\n {\n \"name\": \"service_org_id\",\n \"type\": \"int\",\n \"required\": false,\n \"md_version\": 1,\n \"md_kind\": \"reports.report.acceptedparameter\"\n },\n {\n \"name\": \"instance_id__in\",\n \"type\": \"str\",\n \"required\": false,\n \"md_version\": 1,\n \"md_kind\": \"reports.report.acceptedparameter\"\n " '401': description: Unauthorized — missing or invalid AppOmni API token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden — the token lacks permission for this resource content: application/json: schema: $ref: '#/components/schemas/Error' /api/v1/reports/list/report_categories: get: operationId: listReportCategories summary: List report categories tags: - Reports description: 'Returns a list of all available report categories Response Fields Field Data Type Description Example category String The category identifier summary description String Human-readable description of the category Summary reports' responses: '200': description: List Report Categories content: application/json: schema: type: object examples: ListReportCategories: summary: List Report Categories value: access: Access compliance: Compliance summary: Summary connected_apps: Connected Apps setup_changes: Setup Changes '401': description: Unauthorized — missing or invalid AppOmni API token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden — the token lacks permission for this resource content: application/json: schema: $ref: '#/components/schemas/Error' /api/v1/reports/request/report: get: operationId: generateASingleReport summary: Generate a single report tags: - Reports description: 'Creates a request to generate a single report, which will be created as the desired file type. This will be queued up and processed by at a later time; most likely immediately.) - In addition to the required parameters ( report_package , report_type , report_class , and in most cases, monitored_service_id ), additional parameters may be provided as required by the individual report. Parameters that are not needed by the individual report will be ignored. - report_class and report_package , along with the supported file types, and any required additional parameters, can be found from the List Available Reports endpoint. - POST operation is available: - Certain reports contain data in the params, such as long lists of GUIDs, that cause length issues with the URLs if that data is encoded into the URL as a query string. - AppOmni accepts POST as an alternative, where the data is instead sent via the body of the request. Response Fields Field Data Type Description Example request_id String (UUID) Unique identifier for the request 5071137b-1e9a-4697-bb0c-c28128b7cbc8 report_status String Status of the report requested pending_report_id Integer ID of the pending report 8' parameters: - name: report_type in: query required: false description: Query parameter report_type schema: type: string example: xlsx responses: '202': description: Generate Single XLSX Report content: application/json: schema: type: object examples: GenerateSingleXLSXReport: summary: Generate Single XLSX Report value: request_id: 5071137b-1e9a-4697-bb0c-c28128b7cbc8 report_status: requested pending_report_id: 8 GenerateSingleCSVReport: summary: Generate Single CSV Report value: request_id: 5071137b-1e9a-4697-bb0c-c28128b7cbc8 report_status: requested pending_report_id: 8 GenerateSingleJSONReport: summary: Generate Single JSON Report value: request_id: 5071137b-1e9a-4697-bb0c-c28128b7cbc8 report_status: requested pending_report_id: 8 GenerateSingleReportwithacceptedparameters: summary: Generate Single Report with accepted parameters value: request_id: 5071137b-1e9a-4697-bb0c-c28128b7cbc8 report_status: requested pending_report_id: 8 '200': description: Generate Single Report '401': description: Unauthorized — missing or invalid AppOmni API token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden — the token lacks permission for this resource content: application/json: schema: $ref: '#/components/schemas/Error' post: operationId: generateASingleReport2 summary: Generate a single report tags: - Reports description: 'Creates a request to generate a single report using POST method. This is useful when report parameters contain long lists that would exceed URL length limits. Request Body Field Data Type Required Description Example report_params Object Yes Container for all report parameters See nested fields below report_params.report_name String No Custom name for the report test report_params.report_package String Yes The app targeted by the report core report_params.report_class String Yes Name of the Python class underlying the report AllIssuesExportReport report_params.report_type String Yes The output format for the created report file csv report_params.monitored_service_id Integer No Monitored service to run report against 36887 report_params.notify_external_emails Array[String] No Email addresses for report recipients without AppOmni accounts [" user@example.com "] Response Fields Field Data Type Description Example request_id String (UUID) Unique identifier for the request 5071137b-1e9a-4697-bb0c-c28128b7cbc8 report_status String Status of the report requested pending_report_id Integer ID of the pending report 8' requestBody: required: true content: application/json: schema: type: object example: report_params: report_name: test report_package: core report_class: AllIssuesExportReport report_type: csv monitored_service_id: 36887 notify_external_emails: - user@example.com responses: '200': description: Successful response '401': description: Unauthorized — missing or invalid AppOmni API token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden — the token lacks permission for this resource content: application/json: schema: $ref: '#/components/schemas/Error' /api/v1/reports/group: get: operationId: listReportGroups summary: List report groups tags: - Reports description: 'Returns a list of report groups configured in the system. Response Fields Field Data Type Description Example id Integer Unique identifier for the group 10239 created String (ISO datetime) Time group was created 2025-04-09T02:11:54.681071Z modified String (ISO datetime) Time group was last modified 2025-04-11T16:02:40.471780Z external_id String or null Unused externally null created_by Integer User ID of the report creator 1 modified_by Integer User ID of the last user to modify the group 1 owner Integer User ID of the report owner. Defaults to report creator 1 name String Report group name abcde report_configs Array[Object] Configuration for each individual report See report_configs fields below schedule_start_date String or null Date when scheduled reports start null last_run_date String or null Date when the group was last run null next_run_date String or null Date when the group will next run null schedule_interval String Schedule interval (daily, weekly, monthly, quarterly, or empty string) "" notify_external_emails Array[String] Email addresses for report recipients without AppOmni accounts [] notify_internal_users Array[Integer] List of AppOmni user IDs for report recipients [1] report_configs Fields Field Data Type Description Example report_package String The app targeted by the report core report_class String Name of the Python class underlying the report InsightsReport report_type String Output file format csv monitored_service_id Integer or null Monitored service to run report against null report_name String Human readable report name All Insights parameters Object Parameters to change report contents {} md_version Integer Metadata version 1 md_kind String Metadata kind reports.report.config_data' responses: '200': description: List Available Report Groups content: text/plain: schema: type: string example: "[\n {\n \"id\": 9905,\n \"created\": \"2025-01-15T20:29:52.541539Z\",\n \"modified\": \"2025-01-15T20:29:52.541555Z\",\n \"external_id\": null,\n \"created_by\": 1,\n \"modified_by\": null,\n \"owner\": 1,\n \"name\": \"asd\",\n \"report_configs\": [\n {\n \"report_package\": \"core\",\n \"report_class\": \"UnifiedIdentityExportReport\",\n \"report_type\": \"json\",\n \"monitored_service_id\": null,\n \"report_name\": \"All AppOmni Unified Identities\",\n \"parameters\": {},\n \"md_version\": 1,\n \"md_kind\": \"reports.report.config_data\"\n }\n ],\n \"schedule_start_date\": null,\n \"last_run_date\": null,\n \"next_run_date\": null,\n \"schedule_interval\": \"\",\n \"notify_external_emails\": [],\n \"notify_internal_users\": [\n 1\n ]\n }," '401': description: Unauthorized — missing or invalid AppOmni API token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden — the token lacks permission for this resource content: application/json: schema: $ref: '#/components/schemas/Error' post: operationId: createAReportGroup summary: Create a report group tags: - Reports description: 'Creates a report group, with the option to generate the reports in the group on a schedule. Request Body Field Data Type Required Description Example name String Yes Desired name for the report group My Report Group notify_external_emails Array[String] No Email addresses for report recipients without AppOmni accounts [" user1@example.com "," user2@example.com "] notify_internal_users Array[Integer] No List of AppOmni user ids for report recipients. The user''s email will be looked up during report generation [1] report_configs Array[Object] Yes Configuration for each individual report See nested fields below report_configs.monitored_service_id Integer No Available from the /monitoredservice endpoint 15033 report_configs.parameters Object No Parameters to change report contents. These vary between reports. The list of possible parameters is shown in the accepted_parameters report attribute returned from the list_reports endpoint {} report_configs.report_class String Yes Name of the Python class underlying the report (unique identifier). Must match a report_class from the list_reports endpoint GithubUsersByRepositoryReport report_configs.report_name String Yes Human readable report name GitHub Users by Repository report_configs.report_package String Yes The app targeted by the report. Must match the report_package returned by the list_reports endpoint github report_configs.report_type String Yes Output file format (csv, json, xlsx, etc.) csv schedule_interval String No One of: "daily", "weekly", "monthly", "quarterly" daily schedule_start_date String No In the format YYYY-MM-DD, e.g. "2025-04-01" 2025-04-01 Response Fields Field Data Type Description Example id Integer Unique identifier for the group 10239 created String (ISO datetime) Time group was created 2025-04-09T02:11:54.681071Z modified String (ISO datetime) Time group was last modified 2025-04-11T16:02:40.471780Z external_id String or null Unused externally null created_by Integer User ID of the report creator 1 modified_by Integer User ID of the last user to modify the group 1 owner Integer User ID of the report owner. Defaults to report creator. Unused 1 name String Report group name My Report Group report_configs Array[Object] See explanation in request section above See report_configs fields below' requestBody: required: true content: application/json: schema: type: object example: name: My Report Group notify_external_emails: - user1@example.com - user2@example.com notify_internal_users: - 1 report_configs: - monitored_service_id: 15033 parameters: {} report_class: GithubUsersByRepositoryReport report_name: GitHub Users by Repository report_package: github report_type: csv - monitored_service_id: 67953 parameters: {} report_class: SNOWISOComplianceReport report_name: ServiceNow ISO 27001 Compliance Report report_package: snow report_type: json schedule_interval: daily schedule_start_date: '2025-04-01' responses: '200': description: Create a Report Group content: application/json: schema: type: object examples: CreateaReportGroup: summary: Create a Report Group value: id: 10206 created: '2025-04-01T22:47:38.632762Z' modified: '2025-04-01T22:47:38.644764Z' external_id: null created_by: 21946 modified_by: 21946 owner: 21946 name: My Report Group report_configs: - report_package: github report_class: GithubUsersByRepositoryReport report_type: csv monitored_service_id: 15033 report_name: GitHub Users by Repository parameters: {} md_version: 1 md_kind: reports.report.config_data - report_package: snow report_class: SNOWISOComplianceReport report_type: json monitored_service_id: 67953 report_name: ServiceNow ISO 27001 Compliance Report parameters: {} md_version: 1 md_kind: reports.report.config_data schedule_start_date: '2025-04-01' last_run_date: null next_run_date: '2025-04-01T00:00:00Z' schedule_interval: daily notify_external_emails: [] notify_internal_users: - 1 '401': description: Unauthorized — missing or invalid AppOmni API token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden — the token lacks permission for this resource content: application/json: schema: $ref: '#/components/schemas/Error' /api/v1/reports/group/{group_id}: get: operationId: reportGroupDetails summary: Report group details tags: - Reports description: 'Returns the details for a single specified report group. Response Fields Field Data Type Description Example id Integer Unique identifier for the group 10239 created String (ISO datetime) Time group was created 2025-04-09T02:11:54.681071Z modified String (ISO datetime) Time group was last modified 2025-04-11T16:02:40.471780Z external_id String or null Unused externally null created_by Integer User ID of the report creator 1 modified_by Integer User ID of the last user to modify the group 1 owner Integer User ID of the report owner. Defaults to report creator 1 name String Report group name abcde report_configs Array[Object] Configuration for each individual report See report_configs fields below schedule_start_date String or null Date when scheduled reports start null last_run_date String or null Date when the group was last run null next_run_date String or null Date when the group will next run null schedule_interval String Schedule interval (daily, weekly, monthly, quarterly, or empty string) "" notify_external_emails Array[String] Email addresses for report recipients without AppOmni accounts [] notify_internal_users Array[Integer] List of AppOmni user IDs for report recipients [1] report_configs Fields Field Data Type Description Example report_package String The app targeted by the report core report_class String Name of the Python class underlying the report InsightsReport report_type String Output file format csv monitored_service_id Integer or null Monitored service to run report against null report_name String Human readable report name All Insights parameters Object Parameters to change report contents {} md_version Integer Metadata version 1 md_kind String Metadata kind reports.report.config_data' parameters: - name: group_id in: path required: true description: Path parameter group_id schema: type: string responses: '200': description: Report Group Details content: application/json: schema: type: object examples: ReportGroupDetails: summary: Report Group Details value: id: 10239 created: '2025-04-09T02:11:54.681071Z' modified: '2025-04-11T16:02:40.471780Z' external_id: null created_by: 21946 modified_by: 21946 owner: 21946 name: abcde report_configs: - report_package: core report_class: InsightsReport report_type: csv monitored_service_id: null report_name: All Insights parameters: {} md_version: 1 md_kind: reports.report.config_data - report_package: core report_class: AllFindingsExportReport report_type: csv monitored_service_id: null report_name: All Findings parameters: {} md_version: 1 md_kind: reports.report.config_data schedule_start_date: null last_run_date: null next_run_date: null schedule_interval: '' notify_external_emails: [] notify_internal_users: - 1 '401': description: Unauthorized — missing or invalid AppOmni API token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden — the token lacks permission for this resource content: application/json: schema: $ref: '#/components/schemas/Error' patch: operationId: updateReportGroupDetails summary: Update report group details tags: - Reports description: 'Updates the details for a single specified report group. Request Body Note: The "/" utilized in the below report_configs entries denotes nesting. See the example request body. Field Data Type Required Description Example name String Yes Desired name for the report group abcde notify_external_emails Array[String] No Email addresses for report recipients without AppOmni accounts [] notify_internal_users Array[Integer] No List of AppOmni user ids for report recipients. The user''s email will be looked up during report generation [] report_configs Array[Object] Yes Configuration for each individual report See nested fields below report_configs/md_version Integer No Metadata version 1 report_configs/monitored_service_id Integer No Available from the /monitoredservice endpoint 15033 report_configs/parameters Object No Parameters to change report contents. These vary between reports. The list of possible parameters is shown in the accepted_parameters report attribute returned from the list_reports endpoint {"object": "account"} report_configs/report_class String Yes Name of the Python class underlying the report (unique identifier). Must match a report_class from the list_reports endpoint GithubUsersByRepositoryReport report_configs/report_name String Yes Human readable report name GitHub Users by Repository report_configs/report_package String Yes The app targeted by the report. Must match the report_package returned by the list_reports endpoint github report_configs/report_type String Yes Output file format (csv, json, xlsx, etc.) csv schedule_interval String No One of: "daily", "weekly", "monthly", "quarterly" daily schedule_start_date String No In the format YYYY-MM-DD, e.g. "2025-04-01" 2025-04-23 Response Fields Documentation Field Data Type Description Example id Integer Unique identifier for the group 10239 created String (ISO datetime) Time group was created 2025-04-09T02:11:54.681071Z modified String (ISO datetime) Time group was last modified 2025-04-11T16:02:40.471780Z external_id String or null Unused externally null created_by Integer User ID of the report creator 1 modified_by Integer User ID of the last user to modify the group 1 owner Integer User ID of the report owner. Defaults to report creator. Unused 1 name String Report group name abcde report_configs Array[Object] See explanation in request section above See report_configs fields below md_version , md_kind , owner , & external_id are "unused" from the customer perspective.' parameters: - name: group_id in: path required: true description: Path parameter group_id schema: type: string requestBody: required: true content: application/json: schema: type: object example: name: abcde notify_external_emails: [] notify_internal_users: [] report_configs: - md_version: 1 monitored_service_id: 15033 parameters: {} report_class: GithubUsersByRepositoryReport report_name: GitHub Users by Repository report_package: github report_type: csv - md_version: 1 monitored_service_id: 74301 parameters: object: account report_class: AccessGrantsByObjectReport report_name: Access Grants by Object report_package: sfdc report_type: xlsx schedule_interval: daily schedule_start_date: '2025-04-23' responses: '200': description: Report Group Details content: application/json: schema: type: object examples: ReportGroupDetails: summary: Report Group Details value: id: 10239 created: '2025-04-09T02:11:54.681071Z' modified: '2025-04-11T16:02:40.471780Z' external_id: null created_by: 21946 modified_by: 21946 owner: 21946 name: abcde report_configs: - report_package: core report_class: InsightsReport report_type: csv monitored_service_id: null report_name: All Insights parameters: {} md_version: 1 md_kind: reports.report.config_data - report_package: core report_class: AllFindingsExportReport report_type: csv monitored_service_id: null report_name: All Findings parameters: {} md_version: 1 md_kind: reports.report.config_data schedule_start_date: null last_run_date: null next_run_date: null schedule_interval: '' notify_external_emails: [] notify_internal_users: - 1 '401': description: Unauthorized — missing or invalid AppOmni API token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden — the token lacks permission for this resource content: application/json: schema: $ref: '#/components/schemas/Error' /api/v1/reports/request/group/: get: operationId: runAReportGroup summary: Run a report group tags: - Reports description: 'Requests that a report group be run. The returned request_id is used to check the status of the request later. Response Fields Documentation Field Data Type Description Example request_id String (UUID) Unique identifier for the request that can be used to check status 32a8aa4a-aea2-49a4-a915-854d58a6d987' parameters: - name: group_id in: query required: false description: Query parameter group_id schema: type: string responses: '200': description: Run a Report Group content: application/json: schema: type: object examples: RunaReportGroup: summary: Run a Report Group value: request_id: 32a8aa4a-aea2-49a4-a915-854d58a6d987 '401': description: Unauthorized — missing or invalid AppOmni API token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden — the token lacks permission for this resource content: application/json: schema: $ref: '#/components/schemas/Error' components: schemas: Error: type: object title: Error description: Standard Django REST Framework error envelope returned by the AppOmni API. properties: detail: type: string description: Human readable error message securitySchemes: bearerAuth: type: http scheme: bearer description: 'AppOmni API access token, created and managed in the AppOmni platform under Settings > API Settings. Sent as `Authorization: Bearer `.'