# ControlUp API Documentation > Documentation for ControlUp API ## API Reference - [Create and Manage API Keys](https://api.controlup.io/reference/how-to-create-api-keys.md) - [Rate Limiting](https://api.controlup.io/reference/rate-limiting.md) - [VDI & DaaS PowerShell Cmdlets](https://api.controlup.io/reference/vdi-daas-powershell-cmdlets.md) - [How to Make API Requests](https://api.controlup.io/reference/how-to-make-api-requests-1.md) - [Filtering API Results](https://api.controlup.io/reference/filtering-api-results.md) - [Create a tenant organization](https://api.controlup.io/reference/orgpubliccontroller_createtenantorganization.md): Creates a new tenant organization under the Tenant Manager organization. This endpoint is relevant only if you are an MSP. - [Copy Desktops data](https://api.controlup.io/reference/orgpubliccontroller_copyedgetenantdata.md): Copies ControlUp for Desktops scripts, alerts, and dashboards from a source organization to a target organization. Existing scripts, alerts, or dashboards in the target organization are not deleted. This endpoint is relevant only if you are an MSP and both organizations are licensed for ControlUp for Desktops. The copy process runs asynchronously and sends a notification to the email address associated with the API key when complete. - [List all tenants](https://api.controlup.io/reference/orgpubliccontroller_gettenantorganizations.md): Returns a paginated list of tenants (organizations) under the Tenant Manager. Only Tenant Manager admins with "Manage Settings" permission can access this endpoint. - [List all tags](https://api.controlup.io/reference/orgtagspubliccontroller_getall.md): Returns a list of all tags in your organization. - [Retrieve a tag](https://api.controlup.io/reference/orgtagspubliccontroller_getonebyid.md): Returns details of a tag. - [Create a tag](https://api.controlup.io/reference/orgtagspubliccontroller_create.md): Creates a new tag in your organization. - [Update a tag](https://api.controlup.io/reference/orgtagspubliccontroller_update.md): Updates an existing tag by its ID. Any parameters not passed are not changed. - [Delete a tag](https://api.controlup.io/reference/orgtagspubliccontroller_delete.md): Deletes a tag by its ID. - [List all users](https://api.controlup.io/reference/orguserspubliccontroller_getall.md): Returns a list of all users in your ControlUp organization, including users with a pending invitation. - [Retrieve a user](https://api.controlup.io/reference/orguserspubliccontroller_getonebyid.md): Returns details of a user. - [Update a user](https://api.controlup.io/reference/orguserspubliccontroller_update.md): Updates a user by its ID. Any parameters not passed are not changed. - [Delete a user](https://api.controlup.io/reference/orguserspubliccontroller_delete.md): Deletes a user by its ID from the organization. - [Revoke a user’s API keys](https://api.controlup.io/reference/orguserspubliccontroller_revoke.md): Revokes all API keys created by the specified user in the organization. Revoked API keys can no longer be used to access any data. - [Invite users](https://api.controlup.io/reference/orginvitationpubliccontroller_create.md): Invites users to your organization with the specified roles. You can invite multiple users with a single request by sending multiple objects in the request body. - [Resend invitation](https://api.controlup.io/reference/orginvitationpubliccontroller_update.md): Resends an invitation email to a previously invited email address. - [List all roles](https://api.controlup.io/reference/orgrolespubliccontroller_getall.md): Returns a list of all roles. - [Create a role](https://api.controlup.io/reference/orgrolespubliccontroller_create.md): Creates a new role. - [Retrieve a role](https://api.controlup.io/reference/orgrolespubliccontroller_getonebyid.md): Returns the details for a role, including the permissions within the role and the users to which the role is assigned. - [Update a role](https://api.controlup.io/reference/orgrolespubliccontroller_update.md): Updates an existing role by its ID. - [Delete a role](https://api.controlup.io/reference/orgrolespubliccontroller_delete.md): Deletes a role. If you delete a role, then the role is removed from any users/groups that are assigned the role. - [Retrieve organization settings](https://api.controlup.io/reference/orgsettingspubliccontroller_getonebyid.md): Returns the current settings for your organization. - [Update organization settings](https://api.controlup.io/reference/orgsettingspubliccontroller_update.md): Updates your organization settings by setting the value of the parameters passed. Any parameters not passed are not changed. - [Get SAML configuration](https://api.controlup.io/reference/orgsamlpubliccontroller_getonebyid.md): Returns your currently saved SAML configuration. - [Create SAML settings](https://api.controlup.io/reference/orgsamlpubliccontroller_create.md): Replaces your current SAML configuration by setting the values of the parameters passed. Any existing SAML configuration is overwritten. - [Update SAML settings](https://api.controlup.io/reference/orgsamlpubliccontroller_update.md): Updates your current SAML configuration by setting the values of the parameters passed. Any parameters not passed are not changed. - [Create SAML settings from IdP integration](https://api.controlup.io/reference/orgsamlpubliccontroller_configurebyidp.md): Automatically configures SAML SSO based on an existing integration with Entra ID. Any existing SAML configuration is overwritten. To use this endpoint, you must have already created an integration with Entra ID with the permissions required to configure Entra ID SAML settings. Use this endpoint as a shortcut so that you don't have to manually set up SAML SSO. [Learn more](https://support.controlup.com/docs/automatically-configure-saml-using-an-idp-integration). - [List all IP allowlist entries](https://api.controlup.io/reference/orgipallowlistpubliccontroller_getall.md): Returns a list of all IP allowlist entries. Each entry can contain multiple allowed IP addresses or ranges of IP addresses. If the IP allowlist is enabled in your organization settings, then only users with IP addresses on the allowlist can access your organization. - [Create an IP allowlist entry](https://api.controlup.io/reference/orgipallowlistpubliccontroller_create.md): Creates a new entry in the IP allowlist. Each entry can contain multiple allowed IP addresses or ranges of IP addresses. If the IP allowlist is enabled in your organization settings, then only users with IP addresses on the allowlist can access your organization. - [Update an IP allowlist entry](https://api.controlup.io/reference/orgipallowlistpubliccontroller_update.md): Updates an existing IP allowlist entry by its ID. All allowed IP addresses and ranges in the entry are overwritten by the ones you provide in the allowlist parameter. Any parameters not passed are not changed. - [Delete an IP allowlist entry](https://api.controlup.io/reference/orgipallowlistpubliccontroller_delete.md): Deletes an IP allowlist entry by its ID. Note that you can’t delete the first IP allowlist entry that is automatically added when a user first enables the IP allowlist. This ensures that the user who enabled the allowlist is not locked out of the organization. - [Get audit log](https://api.controlup.io/reference/orgauditlogpubliccontroller_getall.md): Returns your organization’s audit log. By default, events from the last 24 hours are returned, sorted from newest to oldest. All events are reported in UTC. - [List all SSO groups](https://api.controlup.io/reference/orgssogroupspubliccontroller_getall.md): Returns a list of all SSO groups in your organization. - [Create an SSO group](https://api.controlup.io/reference/orgssogroupspubliccontroller_create.md): Creates a new SSO group. - [Update an SSO Group](https://api.controlup.io/reference/orgssogroupspubliccontroller_update.md): Updates an existing SSO group by its ID. - [Delete an SSO group](https://api.controlup.io/reference/orgssogroupspubliccontroller_delete.md): Deletes an SSO group by its ID. - [List all Events](https://api.controlup.io/reference/eventscontroller_geteventslist.md): Returns a list of events based on specified time ranges and filtering criteria. This endpoint uses field projection, returning only the specific event attributes requested in the fields parameter. - [Get total count of events](https://api.controlup.io/reference/eventscontroller_gettotalevents.md): Returns the count of unique values (cardinality) for a specified field within a defined time range. This endpoint allows you to quantify the diversity of your event data such as counting unique users, distinct error types, or total event volume, while applying filters to narrow the scope. - [Retrieve an event](https://api.controlup.io/reference/eventscontroller_geteventbyuuid.md): Retrieves the details of a specific event. - [List all Alerts](https://api.controlup.io/reference/alertsconfigscontroller_getall.md): Returns a list of configured alerts. - [Retrieve a Devices Alert](https://api.controlup.io/reference/alertsdesktopcontroller_getalertbyid.md): Retrieves details of a specific Devices alert configuration. - [Update a Devices alert](https://api.controlup.io/reference/alertsdesktopcontroller_updatealertconfiguration.md): Updates an existing Devices alert. Only sent parameters are changed. - [Delete a Devices alert](https://api.controlup.io/reference/alertsdesktopcontroller_deletealertconfiguration.md): Deletes a Devices alert. - [Create a Devices alert](https://api.controlup.io/reference/alertsdesktopcontroller_createdesktopalert.md): Creates a new Devices alert. - [Retrieve license usage in time range](https://api.controlup.io/reference/orglicensepubliccontroller_getlicenseusage.md): Returns license usage data for your organization over a specified time range. For managed organizations, returns usage for that organization. For MSP organizations, returns aggregated usage across all managed organizations. - [How to Use the ControlUp for Desktops API](https://api.controlup.io/reference/how-to-use-the-edge-dx-api.md) - [Get scoped data index](https://api.controlup.io/reference/get-scoped-data-index.md): Returns the content of the specified data index, after applying a filter so that only data from devices within the `device_query` scope is returned. The endpoint first executes `device_query` against the _devices index to get a list of device IDs. The endpoint then executes `data_query` against the index you specify in the `index` parameter, only returning data that matches the list of device IDs. For example, you can use this endpoint to search the disk_info data index, but only return data for devices located in New York. A maximum of 10000 rows can be returned per request. To return more data, you must set `export` to true and use the `_source` parameter to set which fields to return in the data query. For example: `{"data_query":{"_source":["prop1","prop2"]},"export":true}` - [List all data indices](https://api.controlup.io/reference/get-data-indices.md): Returns a list of all data indices, along with the size and number of rows in each index. - [Create a data index](https://api.controlup.io/reference/post_data.md): Creates a new data index. - [Get a data index](https://api.controlup.io/reference/get-data-index.md): Retrieves the contents of a data index. Standard requests can return a maximum of 10000 rows across all pages. For example, if page 1 has 7000 rows, page 2 will be cut off at 3000 rows regardless of the number of rows in the dataset. If you need more rows, set `export`=`true` and use `_source` to specify which fields to include in the export. This method returns up to 65536 rows, or your license count (whichever is greater). - [Get data index mappings](https://api.controlup.io/reference/get-data-index-mappings.md): Retrieves the fields within a data index, including the data type of each field. - [Retrieve a document](https://api.controlup.io/reference/retrieve-document.md): Retrieves a document within a data index by its ID. - [List all custom reports](https://api.controlup.io/reference/list-custom-reports.md): Returns a list of custom reports, including the configuration details of each report. - [Get a custom report](https://api.controlup.io/reference/get-custom-report.md): Retrieves the configuration details of a custom report by it's ID. - [List all Alerts](https://api.controlup.io/reference/get-alerts.md): Returns a list of configured alerts. You can either: * Use `query` to use an OpenSearch query. Note that you can't create an OpenSearch query using the request builder built into the documentation. * Use the remaining query parameters to query alerts. - [Create an Alert](https://api.controlup.io/reference/create-alert.md): Creates a new Alert. - [Retrieve Alert](https://api.controlup.io/reference/get-alert.md): Returns an alert by its ID. - [Edit alert](https://api.controlup.io/reference/edit-alert.md): Edits an existing alert by its ID. Any parameters not passed are unchanged. - [Delete alert](https://api.controlup.io/reference/delete-alert.md): Deletes an existing alert by its ID. - [List all devices](https://api.controlup.io/reference/list-devices.md): Returns a list of devices managed by your organization, along with information about each device. Standard requests can return a maximum of 10000 rows across all pages. For example, if page 1 has 7000 rows, page 2 will be cut off at 3000 rows regardless of the number of rows in the dataset. If you need more rows, set `export`=`true` and use `_source` to specify which fields to include in the export. This method returns up to 65536 rows, or your license count (whichever is greater). - [Delete devices](https://api.controlup.io/reference/delete-devices.md): Delete devices by their device ID. - [List all device tags](https://api.controlup.io/reference/list-device-tags.md): Returns a list of all device tags, including how many devices are using each tag. - [Update device tags](https://api.controlup.io/reference/update-tags.md): Adds or removes device tags. - [List all device groups](https://api.controlup.io/reference/list-device-groups.md): Returns a list of all device groups, including how many devices are in each group. - [Set device group](https://api.controlup.io/reference/add-device-group.md): Sets the device group for the specified devices. A device can belong to only one group at a time. - [Perform action on a single device](https://api.controlup.io/reference/run-an-action-single.md): Performs an action on the specified device. - [Perform action on multiple devices](https://api.controlup.io/reference/run-an-action.md): Performs an action on the specified devices. If you want to perform an action on only a single device, we recommend that you use [POST /devices/{deviceID}/action](run-an-action-single) for more options. - [Get system events](https://api.controlup.io/reference/get-system-events.md): Returns entries from the System Events log, which contains alerts, actions, configuration changes, etc. By default, the endpoint returns 10000 events starting with the oldest event. A maximum of 10000 events can be returned per request. - [Get system events with query](https://api.controlup.io/reference/get-system-events-query.md): Returns the same data as [GET /events](get-system-events), but lets you send an OpenSearch query in the request body. - [List all scripts](https://api.controlup.io/reference/list-all-scripts.md): Returns a list of all scripts. You can either: * Use `query` to use an OpenSearch query. Note that you can't create an OpenSearch query using the request builder built into the documentation. * Use the remaining query parameters to query scripts. - [List all surveys](https://api.controlup.io/reference/get-surveys.md): Returns a list of all surveys. You can either: * Use `query` to use an OpenSearch query. Note that you can't create an OpenSearch query using the request builder built into the documentation. * Use the remaining query parameters to query your surveys. - [Publish a survey](https://api.controlup.io/reference/publish-survey.md): Publishes a new survey. - [Get a survey](https://api.controlup.io/reference/get-survey.md): Returns the details of the specified survey. - [Delete a survey](https://api.controlup.io/reference/delete-survey.md): Deletes a survey - [Pause a survey](https://api.controlup.io/reference/pause-survey.md): Pauses a survey - [Resume a survey](https://api.controlup.io/reference/resume-survey.md): Resume a paused survey - [Complete a survey](https://api.controlup.io/reference/complete-survey.md): Completes a survey - [Get survey results](https://api.controlup.io/reference/get-survey-results.md): Returns one row for each time a survey was opened, started, or completed. Optionally, use the `include_answers` parameter to also return survey answers. If you are interested only in returning survey completions (results), you should add a filter to return only rows with `type=Result`. While you can use this endpoint to view all answers in a survey result, you can't query the endpoint based on the answers. To query survey answers, you can use GET [/user-sentiment/results/answers/raw](get-survey-answers). You can either: * Use `query` to use an OpenSearch query. Note that you can't create an OpenSearch query using the request builder built into the documentation. * Use the remaining query parameters to query your survey results. - [Get survey answers](https://api.controlup.io/reference/get-survey-answers.md): Returns a list of all answers to survey questions. Each row represents one answer to a survey question per user per device. You can either: * Use `query` to use an OpenSearch query. Note that you can't create an OpenSearch query using the request builder built into the documentation. * Use the remaining query parameters to query your survey results. - [Get host metrics per folder](https://api.controlup.io/reference/gethostmetrics.md): Returns average host resource consumption per folder throughout the search period. The granularity depends on the search period. - [Get host counts](https://api.controlup.io/reference/gethostcounts-1.md): Returns usage statistics per host. - [Get user activity status](https://api.controlup.io/reference/getuseractivity-1.md): Returns a list of users and their activity status throughout the search period. The search period is divided into smaller time windows according to the granularity parameter. The endpoint returns a user's activity status for each time window. - [Get Windows Events](https://api.controlup.io/reference/getwindowsevents.md): Returns matched Event Log Monitoring rows (30-day rolling retention, filtered on event timestamp). - [Get machine statistics](https://api.controlup.io/reference/getmachinestatsbymachine-1.md): Returns historical information about machine resource consumption. Visit the Machine Statistics Report documentation for column descriptions and more details. - [Get sizing recommendations for virtual environments](https://api.controlup.io/reference/getrecommendationvirtualization-1.md): Returns sizing recommendations to optimize resource allocation for machines based on historical information. Visit the Sizing Recommendations Report documentation for more details. - [Get sizing recommendation for machine for Azure environment](https://api.controlup.io/reference/getrecommendationazure-1.md): Returns sizing recommendations to optimize resource allocation for machines based on historical information. Visit the Sizing Recommendations Report documentation for more details. - [Get aggregated machine statistics](https://api.controlup.io/reference/getmachinesaggregated.md): Returns aggregated machine metrics (avg/min/max/count) grouped by a single machine dimension such as folder, operating system, hypervisor platform, Azure region/VM size, or GPU architecture/model. Always returns machine_count (COUNT(DISTINCT computer_id)) plus one column per _ combination. Visit the Machine Statistics Report documentation for column descriptions and more details. - [Get NetScaler metrics with time series](https://api.controlup.io/reference/getnetscalerusagewithtimeseries.md): Returns performance metrics for each NetScaler appliance. Visit the NetScaler Report documentation for column descriptions and more details. - [Get Load Balancer metrics with time series](https://api.controlup.io/reference/getloadbalancerusagewithtimeseries.md): Returns performance metrics for each load balancer. Visit the NetScaler Load Balancing Report documentation for column descriptions and more details. - [Get Gateway metrics with time series](https://api.controlup.io/reference/getgatewayusagetimeseries.md): Returns performance metrics for each NetScaler Gateway. Visit the NetScaler Gateway Report documentation for column descriptions and more details. - [Get NetScaler metrics](https://api.controlup.io/reference/getnetscalerusage-1.md): Returns performance metrics for each NetScaler appliance. Visit the NetScaler Report documentation for column descriptions and more details. - [Get Load Balancer metrics](https://api.controlup.io/reference/getloadbalancerusage-1.md): Returns performance metrics for each load balancer. Visit the NetScaler Load Balancing Report documentation for column descriptions and more details. - [Get Gateway metrics](https://api.controlup.io/reference/getgatewayusage-1.md): Returns performance metrics for each NetScaler Gateway. Visit the NetScaler Gateway Report documentation for column descriptions and more details. - [Start upload date](https://api.controlup.io/reference/getstartuploaddate.md): Returns date when the first historical data upload was started - [Get usage details for a process](https://api.controlup.io/reference/getprocessusagesingle.md): Returns usage details for the specified process including usage per machine, per user account, peak concurrent instances, and unique user count throughout the search period. - [Get usage details for all processes](https://api.controlup.io/reference/getprocessusageall.md): Returns usage details for all processes (number of unique users and, when no filters are supplied, peak concurrent users) per calendar day throughout the search period. When computerNames or userAccounts filters are supplied, peak_concurrency is omitted and the maximum date span is 90 days. - [Get session statistics](https://api.controlup.io/reference/getsessionsstatistics-1.md): Returns statistics for all user sessions. Visit the Session Activity Report documentation for column descriptions and more details. - [Get individual session details](https://api.controlup.io/reference/getsessiondetails.md): Returns activity details of individual session. Visit the Session Activity Report documentation for column descriptions and more details. - [Get session timeline](https://api.controlup.io/reference/getsessiontimeline.md): Returns the timeline of session state changes for a specific session. - [Get aggregated session activity](https://api.controlup.io/reference/getsessionsaggregated.md): Returns aggregated session activity metrics (avg/min/max/count) grouped by a single session dimension such as folder, delivery group, site, user, protocol, or initial program. Visit the Session Activity Report documentation for column descriptions and more details. - [Get usage details for an application](https://api.controlup.io/reference/getappusagesingle-1.md): Returns usage details for the specified application including usage per machine, per user account, and the peak number of concurrent instances throughout the search period. The granularity of the peak concurrent instances depends on the length of the search period, and how far back in the past the search period is. - [Get usage details for all applications](https://api.controlup.io/reference/getappusage-1.md): Returns usage details for all applications (number of unique users and peak number of concurrent users) throughout the search period. The granularity of the returned data depends on the length of the search period, and how far back in the past the search period is. Only applications with at least 1 user are returned. Usage details are returned per application version. - [Get application statistics](https://api.controlup.io/reference/getappstats-1.md): Returns usage details and resource consumption statistics for all applications (per version number). Statistics are aggregated either weekly (Monday-Sunday) or monthly, depending on the timeFrame parameter. Visit the App Statistics Report documentation for column descriptions and more details. - [List machines](https://api.controlup.io/reference/getmachines.md): Retrieves a paginated list of machines with optional filtering, sorting, and search capabilities - [Get machine details](https://api.controlup.io/reference/getmachine.md): Retrieves detailed information for a specific machine by its unique identifier. - [Create or update machines](https://api.controlup.io/reference/upsertmachines.md): Creates or updates machines in bulk. Identity is determined by FQDN computed as `computerName` or `computerName.domainName`. When a machine already exists, only provided fields that differ from current values are applied; unspecified fields are left unchanged. Note: If the ControlUp environment has the agent setting 'Deploy agents automatically (from monitor only)' enabled in the configuration console, adding a new machine (with isOutboundReady = false) via this endpoint will cause the ControlUp Monitor to attempt agent deployment to that machine automatically. This process runs from the Monitor service and requires valid domain credentials configured for the Monitor with local administrator rights on the target machines and necessary network/prerequisite access. - [Delete machines](https://api.controlup.io/reference/deletemachines.md): Deletes machines in bulk by FQDN. - [List triggers for the authenticated organization.](https://api.controlup.io/reference/get_v1-triggers.md): Returns a paginated list of triggers. Supports filtering, sorting, and optional scope-based lookups via the machine or folder parameters. When include=perMachine is specified, the response data array changes shape: instead of trigger items it returns per-machine groups. The machine or folder parameter is required in that case. Error codes returned in the errorCode field: scope_params_conflict (both machine and folder specified), scope_params_required (include token requires scope), machine_not_found (404), folder_not_found (404), scope_resolution_too_broad (folder resolved too many machines, also includes resolvedCount and limit), scope_params_invalid (malformed scope input). - [Get full details for a single trigger.](https://api.controlup.io/reference/get_v1-triggers-triggerid.md) - [List trigger schedules](https://api.controlup.io/reference/get_v1-trigger-schedules.md) - [Get trigger schedule by ID](https://api.controlup.io/reference/get_v1-trigger-schedules-scheduleid.md) - [Get Tables](https://api.controlup.io/reference/gettables.md): Retrieves a list of available metric tables - [Get Table Fields](https://api.controlup.io/reference/gettablefields.md): Retrieves the fields available for a specific metric table - [Query metrics](https://api.controlup.io/reference/query.md): Retrieves realtime metrics data with optional filtering, sorting, pagination, and aggregation capabilities - [List all devices](https://api.controlup.io/reference/getdevices.md): Returns a list of all devices managed by ControlUp for Compliance. - [Get device details](https://api.controlup.io/reference/getdevicedetails.md): Returns details for a specific device, including a summary of the number of issues detected on the device. - [List device vulnerabilities](https://api.controlup.io/reference/getdevicevulnerabilities.md): Returns a list of vulnerabilities (CVEs) detected on a specific device. - [List device patches](https://api.controlup.io/reference/getdevicepatches.md): Returns a list of missing OS and application patches detected on a specific device. - [List device compliance issues](https://api.controlup.io/reference/getdevicecompliance.md): Returns a list of issues from the compliance category detected on a specific device. - [List device misconfigurations](https://api.controlup.io/reference/getdevicemisconfig.md): Returns a list of misconfiguration issues detected on a specific device. - [List all alerts](https://api.controlup.io/reference/appget_alerts.md): Returns alerts generated within the specified time frame for all Scouts. The default time frame is the last 24 hours. - [List Scout IDs with alerts](https://api.controlup.io/reference/honeycombapiget_scout_alerts.md): Returns a list of Scout IDs that have triggered an alert within the specified time frame. The default time frame is the last 24 hours. - [List alerts for a Scout](https://api.controlup.io/reference/appget_alert_for_scout.md): Returns alerts generated within the specified time frame for a Scout. The default time frame is the last 24 hours. - [List alert policies for a Scout](https://api.controlup.io/reference/appget_scout_alert_policies.md): Returns all alert policies configured for a Scout. Currently, each Scout supports only a single alert policy. - [Get alert policy details](https://api.controlup.io/reference/appget_scout_alert.md): Returns detailed information about a specific alert policy for a Scout, including settings, notifications, and status. - [Create alert policy](https://api.controlup.io/reference/appcreate_scout_alert.md): Creates a new alert policy for a Scout. A Scout can have only one alert policy. If one already exists, you can update it or delete it. Alerts trigger when the Scout's test results meet certain conditions. - [Update alert policy](https://api.controlup.io/reference/appupdate_scout_alert.md): Updates an existing alert policy for a specific Scout. Any object not passed is unchanged. - [Delete alert policy](https://api.controlup.io/reference/appdelete_scout_alert.md): Deletes an Scout's alert policy. - [List all integrations](https://api.controlup.io/reference/honeycombapiget_org_integrations.md): Returns a list of active external integrations available for alert notifications. - [List all Scouts](https://api.controlup.io/reference/appget_scouts.md): Returns a list of your Scouts. - [Create a Scout](https://api.controlup.io/reference/appcreate_scout.md): Create a Scout to test EUC or network resources. Creating a Scout uses credits on your account. If you disable or delete the Scout, then the credits are returned to your account. See [License Information](https://support.controlup.com/docs/license-information) for more details. - [Get Scout info](https://api.controlup.io/reference/appget_scout_by_id.md): Returns the details of a specific Scout, and a summary of it's test results. By default, the summary uses test results from the last 24 hours. - [Edit Scout](https://api.controlup.io/reference/appedit_scout.md): Edits an existing Scout. Any parameters passed in this call will be updated to the new values. Unused parameters will not be changed. - [Delete Scout](https://api.controlup.io/reference/appdelete_scout.md): Deletes a Scout. This cannot be undone. Historical test result data for the Scout will still be available. The credits used to create the Scout will be returned to your account. - [Enable/disable Scout](https://api.controlup.io/reference/appdisable_scout.md): Enables or disables an existing Scout. A Scout only performs tests while it is enabled. Enabling a Scout uses credits on your account. Disabling a Scout returns the credits. - [List tests](https://api.controlup.io/reference/appget_tests.md): Returns a list of test, containing the the details and results of each tests. The tests are grouped by their Scouts, with the earliest tests appearing first in each group. By default, all tests from all Scouts in the last 24 hours are returned. - [List all Custom Hives](https://api.controlup.io/reference/honeycombapicustom_hives.md): Returns a list of the Custom Hives in your organization. - [List all Cloud Hives](https://api.controlup.io/reference/honeycombapicloud_hives.md): Returns a list of Cloud Hives. - [List all MFA users](https://api.controlup.io/reference/honeycombapiget_org_mfas.md): Returns a list of usernames for EUC gateway access that are associated with a phone number for MFA. - [Get Flows](https://api.controlup.io/reference/get_flows_workflows_v1_flows_get.md): Retrieve a complete list of workflows available in your organization. - [Get Flow](https://api.controlup.io/reference/get_flow_workflows_v1_flows__flowid__get.md): Retrieve details about a specific workflow by its ID. - [Get Flow Runs Status](https://api.controlup.io/reference/get_flow_runs_workflows_v1_flows__flowid__runs_get.md): Retrieve the status and details of runs for a specific workflow. - [Enable/Disable Flow](https://api.controlup.io/reference/update_flow_status_workflows_v1_flows__flowid__patch.md): Change the status of a flow (enable or disable) - [Delete Flow](https://api.controlup.io/reference/delete_flow_workflows_v1_flows__flowid__delete.md): Delete a flow by its ID from your organization. - [Get Forms](https://api.controlup.io/reference/get_all_forms_workflows_v1_forms_get.md): Retrieve a complete list of all forms available in your organization. - [Get Form](https://api.controlup.io/reference/get_form_workflows_v1_forms__formid__get.md): Retrieve details about a specific form by its ID. - [Delete Form](https://api.controlup.io/reference/delete_form_workflows_v1_forms__formid__delete.md): Delete a form by its ID from your organization. - [Get Integrations](https://api.controlup.io/reference/get_all_integrations_workflows_v1_integrations_get.md): Retrieve a complete list of available integrations in your organization. - [Get Integration](https://api.controlup.io/reference/get_integration_workflows_v1_integrations__integrationid__get.md): Retrieve details about a specific integration by its ID. - [Delete Integration](https://api.controlup.io/reference/delete_integration_workflows_v1_integrations__integrationid__delete.md): Delete an integration by its ID from your organization. - [Get supported cloud providers](https://api.controlup.io/reference/getproviders.md): Returns the cloud providers this platform can integrate with, together with their display names. A static capability catalog describing what the product supports — not which providers the caller's organization has actually onboarded. - [Get supported authentication types](https://api.controlup.io/reference/getallauthtypes.md): Returns the union of authentication types across every supported cloud provider. The unfiltered catalog: because entries span providers, not everything returned is valid for any one provider. Narrow to a single provider when the provider is already known. - [Get authentication types for a provider](https://api.controlup.io/reference/getproviderauthtypes.md): Returns only the authentication types valid for one named provider — the set to offer once a provider has been chosen, and the input a tenant or credential must be configured against. - [Get all features](https://api.controlup.io/reference/get_features.md): Returns every feature flag with its enabled state for the caller's organization, as a map of name to boolean. Rollout toggles, not entitlements: a flag being on says the functionality is switched on for the organization, not that its license permits or has capacity for it. - [Get a feature status](https://api.controlup.io/reference/get_features-feature.md): Returns the enabled state of one named feature flag, for callers that already know which flag they care about and want a single answer rather than the whole map. Names are case-sensitive. - [Get host pool cost breakdown and trend](https://api.controlup.io/reference/gethostpoolcost.md): Returns what the pool spent over a date range (default last 30 days), broken down by Compute, Disk, and Network, with a day-by-day trend series carrying the same split, cost per active user, and comparison against the previous equivalent period. Totals cover the pool as a whole and are not attributed to individual session hosts. - [Get host pool autoscale savings](https://api.controlup.io/reference/gethostpoolsavings.md): Returns what autoscale saved: projected always-on cost versus actual spend, the savings delta and percentage, monthly and cumulative totals, and a daily trend. Answers whether autoscale is paying off rather than what the pool actually cost; returns autoscaleEnabled=false with zero savings when autoscale is not configured. - [Get per-host cost breakdown](https://api.controlup.io/reference/gethostpoolhostscost.md): Returns paginated cost attributed to each session host, with Compute/Disk/Network split, disk tier, power state, and Premium SSD optimization flags, including hosts that have since been deleted. Answers which host in the pool is expensive; it gives no pool-level total or trend. - [Export host pool cost data as CSV](https://api.controlup.io/reference/gethostpoolcostexport.md): Streams a CSV file attachment of per-host daily cost records with savings data, one row per session host per day, including deleted hosts. The response is flushed progressively, one day at a time. Returns a file rather than queryable JSON — intended for bulk export and offline analysis, not for answering questions about a pool. - [Create host pool deployment](https://api.controlup.io/reference/createhostpooldeployment.md): Starts an asynchronous shell deployment for an Azure Virtual Desktop host pool. The job creates the host pool ARM resource, application group, workspace registration, then imports the created control-plane tree into Foundry. - [Get host pools](https://api.controlup.io/reference/gethostpools.md): Returns one row per host pool across all subscriptions, with identity (name, subscription, resource group, region, type) and latest-value counts for hosts, sessions, and average CPU. Does not include cost, memory, or AVD configuration. - [Get host pool statistics](https://api.controlup.io/reference/gethostpoolsstatistics.md): Returns six organization-wide totals: pooled and personal pool counts, available and draining session host counts, and active and total session counts, across all pools matching the optional provider and filter criteria. No per-pool rows, so a total cannot be traced back to the pools behind it, but far cheaper than paging the list. - [Get a host pool by ID](https://api.controlup.io/reference/gethostpool.md): Returns a single host pool in the same shape as one row of the host pool list: identity, resource metadata, and latest-value host, session, and CPU counts. Does not include AVD configuration, cost, memory, or 7-day rollups. - [Delete host pool](https://api.controlup.io/reference/deletehostpool.md): Soft-deletes the host pool from DaaS IQ management without modifying the Azure resource. Historical data is retained and becomes visible again if the host pool is re-imported. Autoscale configuration and VM settings are not retained. - [Get host pool extended details](https://api.controlup.io/reference/gethostpooldetails.md): Returns the full host pool record: identity and resource metadata, AVD configuration (load balancing, max sessions per host, drain mode, OS, VNet), 7-day session rollups, session capacity percentage, latest CPU and memory, and month-to-date cost. Cost is one total with no breakdown or date range, and metrics are current or rolled-up values, never series. Aggregates several sources, so use it per pool rather than iterating a list. - [Get host pool metrics](https://api.controlup.io/reference/gethostpoolmetrics.md): Returns timestamped series over a date range for active and total sessions, running and stopped hosts, average CPU and memory, and connection errors — intended for charting. Every value is a series rather than a current reading, and connection errors are available nowhere else. - [Get session hosts for a host pool](https://api.controlup.io/reference/getsessionhosts.md): Returns the VMs that make up the pool — one row per session host with power state, agent status, drain state, VM SKU, OS, per-host CPU and memory, and session counts. Stored inventory rather than a live Azure read, so power and agent state are current as of each row's SyncedAt. Describes the machines, not the users occupying them, and carries no cost data. - [Get user sessions for a host pool](https://api.controlup.io/reference/gethostpoolsessions.md): Returns the people currently logged in to the pool — one row per user session, across all of its session hosts. In Azure AVD this includes Active, Pending, and Disconnected sessions: any session where the user has not logged off. Describes the occupants, not the machines they are running on. - [Delete host pool from Azure](https://api.controlup.io/reference/harddeletehostpool.md): Dispatches an Azure teardown job for associated resources (application groups, session host VMs, and the host pool ARM resource), then soft-deletes the host pool from DaaS IQ. VNet, subnet, resource group, workspace, and storage accounts are not deleted. All session hosts must be deallocated before this operation is accepted. - [Get VM settings for a host pool](https://api.controlup.io/reference/gethostpoolvmsettings.md): Returns the template used when adding new session hosts to the pool: deployment region and resource group, primary and alternative VM size, source image and version, OS disk size, and virtual network. Password fields return placeholders, never plaintext. Describes hosts that would be created, not hosts that exist. - [Create or replace VM settings for a host pool](https://api.controlup.io/reference/savehostpoolvmsettings.md): Stores the template future session hosts are built from: naming, domain join, image, VM size, disk, and network. A full replacement, not a patch — omitted fields are cleared, so send the complete settings every time. Adding hosts later reads these saved settings rather than taking them in the request. - [Delete VM settings for a host pool](https://api.controlup.io/reference/deletehostpoolvmsettings.md): Discards the stored template, after which the pool has no settings to build new hosts from until they are saved again. Affects the template only: existing session hosts keep running and are not modified or deleted. Idempotent — deleting settings that were never configured still succeeds. - [Validate VM settings for a host pool](https://api.controlup.io/reference/validatehostpoolvmsettings.md): Checks a VM settings payload and echoes it back enriched with resolved lookup details, without saving anything. Send a body to test settings before committing them; omit the body to re-validate what is already stored. A dry run only — use the save operation to persist. - [Get scaling policy for a host pool](https://api.controlup.io/reference/gethostpoolscalingpolicy.md): Returns the pool's weekly autoscale schedule: time blocks and which scaling profile each one assigns. Returns assignments only: profile bodies such as thresholds and host counts are not expanded, and the schedule does not indicate which block is in effect right now. - [Save scaling policy for a host pool](https://api.controlup.io/reference/savehostpoolscalingpolicy.md): Creates or updates the scaling policy for a specific host pool with time blocks and profile assignments. - [Delete scaling policy for a host pool](https://api.controlup.io/reference/deletehostpoolscalingpolicy.md): Removes the scaling policy from a specific host pool. - [Get active scaling profile for a host pool](https://api.controlup.io/reference/gethostpoolactivescalingprofile.md): Returns the one scaling profile in effect at the current UTC time, resolved from the pool's weekly schedule. Covers the present moment only, not the rest of the week. - [Create session hosts](https://api.controlup.io/reference/createsessionhostdeployment.md): Adds session hosts to an existing host pool. The new hosts are built from the VM settings already saved on that pool, so those settings must be in place before this call and are not accepted in the request body. For pools with a DynamicHosts scaling profile, scale-in cleanup treats all stopped zero-session hosts above MinHosts as elastic capacity, including manually added hosts. - [Get a job by ID](https://api.controlup.io/reference/getjob.md): Returns one job's full record: status, progress, current step, and error details. Does not include the job's input parameters, and is heavier than the status-only payload — prefer that for repeated polling. Regular users can only access jobs they initiated. Admins can access any job in their organization. - [Get job parameters](https://api.controlup.io/reference/getjobparameters.md): Returns the raw input parameters a job was created with, as a JSON object whose structure depends on JobType. Carries the inputs only — no status, progress, or errors. Regular users can only access parameters for jobs they initiated. Admins can access any job in their organization. - [Get jobs](https://api.controlup.io/reference/getjobs.md): Returns a paginated list of jobs for the current organization, each row carrying the job ID that per-job operations require. Regular users see only their own jobs. Admins see all user-initiated jobs, and system-scheduled background jobs only when includeSystemJobs=true. Rows carry no job parameters and no logs. - [Get job status](https://api.controlup.io/reference/getjobstatus.md): Returns six fields only — id, jobType, status, progress, currentStep, cancellationRequested — as the cheapest way to poll a running job. Omits error details, parameters, and logs, so it cannot explain why a job failed. - [Cancel a job](https://api.controlup.io/reference/canceljob.md): Requests cancellation of a background job. The job will stop at the next safe checkpoint. Regular users can only cancel jobs they initiated. Admins can cancel any job in their organization. - [Retry a failed job](https://api.controlup.io/reference/retryjob.md): Creates a new job by retrying a previously failed job with the same parameters. The original failed job remains as a historical record. The new retry job is linked to the original via RetryOfJobId for traceability. Only failed jobs whose type is registered as user-retriable can be retried, and a concurrency guard permits just one active retry per original job. - [Get job logs](https://api.controlup.io/reference/getjoblogs.md): Returns a job's user-facing log entries as structured JSON, oldest first, with cursor-based pagination via after and limit. Structured records suited to filtering or incremental tailing, as opposed to the plain-text transcript of the same logs. - [Get job logs transcript](https://api.controlup.io/reference/getjoblogstranscript.md): Returns the same log entries as a streamed plain-text document for reading or download (no cursor, so no incremental tailing). Success is `text/plain`; validation, not-found, and forbidden responses are `application/json` like other Jobs endpoints. - [Get license information](https://api.controlup.io/reference/get_license.md): Returns the caller's organization license: status, type, expiration, entitled features, current usage, and whether capacity is exhausted. Commercial entitlement and consumption — what the organization is permitted and how much of it has been used — as distinct from feature flags, which switch functionality on independently of licensing. - [Execute an action on a master image](https://api.controlup.io/reference/executemasterimageaction.md): Creates a background job to perform the action (start, stop). Poll the statusUrl for progress updates. - [Download an RDP file for a master image](https://api.controlup.io/reference/getmasterimagerdpfile.md): Returns a downloadable .rdp connection descriptor for the master image's VM, built from its resolvable connection address. Returns a file attachment rather than JSON, and only generates the descriptor — it does not start the VM, open a session, or supply credentials. - [Get supported OS families for Master Images](https://api.controlup.io/reference/getosfamilies.md): Returns the fixed set of operating system families that Azure Virtual Desktop supports, as id and display name. A static catalog containing no organization data; the values populate the OS family choice when promoting a VM. - [Get curated Marketplace images for deployment](https://api.controlup.io/reference/getmarketplaceimages.md): Returns the curated catalog of Azure Marketplace OS images that can be deployed as new Master Images, all of them Gen 2, Generalized, and TrustedLaunch. A static catalog rather than anything the organization owns, and deliberately narrower than the full Azure Marketplace. - [List Master Images](https://api.controlup.io/reference/listmasterimages.md): Returns one row per managed Master Image in the organization, paginated and sorted, each with status, power state, OS family and version, source type, region, gallery wiring, and latest published version. No version history and no indication of which operations are currently running. - [Get Master Image by ID](https://api.controlup.io/reference/getmasterimage.md): Returns one Master Image in the same shape as a list row: name, OS, status and power state, source type, region, VM and gallery resource IDs, disk and security settings, and latest published version. The image itself — not which operations run or are permitted, and not its published versions. - [Get Master Image operation state](https://api.controlup.io/reference/getoperationstate.md): Returns the image's single in-flight operation, if any, plus server-computed flags for the actions it now permits. Trust these flags rather than inferring availability from lifecycle and power-state fields. Covers the image as a whole, not any individual published version. - [Get decommission plan](https://api.controlup.io/reference/getdecommissionplan.md): Previews what retiring the whole Master Image would delete or retain — VM, disks, gallery definition, related Azure resources — with any warnings. A read-only dry run covering the whole image, not the leftovers of a single publish. - [Deploy Master Image from Gallery image version](https://api.controlup.io/reference/post_cloud-master-images-deploy-from-gallery.md): Creates a new Master Image by deploying a fresh VM from a gallery image version. This is a long-running operation: the endpoint returns immediately with a Job tracking object. Poll the Job StatusUrl for progress updates. The Master Image starts in Deploying status and transitions to Ready when the VM is provisioned. - [Deploy Master Image from curated Marketplace](https://api.controlup.io/reference/post_cloud-master-images-deploy-from-marketplace.md): Deploys a new Azure VM from a curated Marketplace OS image and registers it as a Master Image. This is a long-running operation: the endpoint returns immediately with a Job tracking object. Poll the Job StatusUrl for progress updates. The background job deploys the VM, creates the ACG Image Definition, and transitions the Master Image from Deploying to Ready. Accepts only images drawn from the curated Marketplace catalog, not arbitrary Marketplace offers. - [Deploy Master Image from Managed Image](https://api.controlup.io/reference/post_cloud-master-images-deploy-from-managed-image.md): Deploys a new Azure VM from an existing Azure Managed Image and registers it as a Master Image. This is a long-running operation: the endpoint returns immediately with a Job tracking object. Poll the Job StatusUrl for progress updates. The region is derived server-side from the managed image's location. The Master Image starts in Deploying status and transitions to Ready when the VM is provisioned. - [List Master Image versions](https://api.controlup.io/reference/listmasterimageversions.md): Returns the publish history of one Master Image, newest first: version name, publish time and author, status, target regions, and whether temporary artifacts remain. The immutable gallery versions publishing produced — not the Master Image, nor the VM it was captured from. - [Get Master Image version operation state](https://api.controlup.io/reference/getversionoperationstate.md): Returns in-flight operations on one published version, plus flags for the actions it permits, such as retrying a failed publish or cleaning up leftovers. Scoped to a single version and may report several concurrent operations, unlike the image-level equivalent. - [Get publish artifact cleanup plan](https://api.controlup.io/reference/getpublishcleanupplan.md): Previews the temporary resources one publish left behind and that DaaS IQ can remove. A read-only dry run scoped to those leftovers: never the published version, which stays in the gallery, nor the Master Image's own VM and gallery resources. - [Delete Master Image version](https://api.controlup.io/reference/deletemasterimageversion.md): Dispatches a background job that removes one published gallery version, the deployable artifact itself. Destroys the version permanently, unlike artifact cleanup, which removes only the temporary resources a publish left behind and leaves the version in place. The Master Image and its other versions survive. - [Delete publish artifacts](https://api.controlup.io/reference/deletepublishartifacts.md): Dispatches a background job that removes the temporary resources one publish left behind, such as the builder VM and its disks. The execution counterpart of the cleanup plan, which previews the same set without deleting. The published version stays in the gallery and remains deployable. - [Retry failed Master Image version publish](https://api.controlup.io/reference/retrypublish.md): Retries the latest failed publish job for the specified version by creating a new background job with the same parameters. Use this instead of POST publish when recovering a failed version row. - [Promote existing VM as Master Image](https://api.controlup.io/reference/promotevmtomasterimage.md): Creates a new Master Image by registering an existing Azure VM. Creates a corresponding Image Definition in the specified Azure Compute Gallery. The VM must be Gen 2 (Trusted Launch) and not already imported. - [Delete Master Image](https://api.controlup.io/reference/deletemasterimage.md): Soft deletes the Master Image record by default. When deprovision=true, dispatches a background cleanup job that removes managed Azure resources, then soft deletes the Master Image record. - [Publish Master Image version](https://api.controlup.io/reference/publishmasterimageversion.md): Dispatches a background job that clones the Master VM into a temporary publish VM, runs AVD Agent Update and optional SXS Stack Update, runs sysprep, captures an ACG Image Version, then cleans up the temporary publish VM. The Master VM must be in Ready status and stopped (deallocated). - [List onboarding flows](https://api.controlup.io/reference/listonboardingflows.md): Returns a summary of every onboarding flow for the signed-in user, with each flow's progress and dismissal state. Scoped to the current user rather than the organization, and summaries only — per-step detail is not included. - [Get onboarding flow](https://api.controlup.io/reference/getonboardingflow.md): Returns one onboarding flow for the signed-in user, identified by its slug, including per-step state and the currently active step. Expands the step detail that the flow summaries omit. - [Update onboarding flow](https://api.controlup.io/reference/updateonboardingflow.md): Changes flow-level state for the signed-in user: how the flow is displayed, and which step is active. Moves the pointer between steps; it does not change whether any individual step is complete. - [Start onboarding flow](https://api.controlup.io/reference/startonboardingflow.md): Marks a flow as begun for the signed-in user and returns it with its steps initialised. Opens the flow; recording progress within it and closing it are separate operations. - [Update onboarding step](https://api.controlup.io/reference/updateonboardingstep.md): Sets the completion state of one named step and returns the whole flow with that step updated. The only way to mark a step done; flow-level updates change the active step but never its state. - [Dismiss onboarding flow](https://api.controlup.io/reference/dismissonboardingflow.md): Hides the flow for the signed-in user who chose to skip it, leaving step progress untouched. Reflects the user opting out rather than finishing: dismissing does not complete the remaining steps. - [Get overview graph data](https://api.controlup.io/reference/getoverviewgraph.md): Returns one count per level of the hierarchy — subscriptions, regions, resource groups, host pools, session hosts, images, sessions — for the funnel at the top of the Overview. Scalars, not rows; a level that a filter pins to one item returns its name instead of a count. - [Get overview subscriptions](https://api.controlup.io/reference/getoverviewsubscriptions.md): Returns one row per subscription with counts of everything beneath it plus rolled-up cost and performance. What a subscription contains and costs, unlike its registration record, which carries no metrics. - [Get overview regions](https://api.controlup.io/reference/getoverviewregions.md): Returns one row per Azure region holding onboarded resources, with subscription counts, resource statistics, cost, and performance rolled up within it. Only regions in use, not the catalog of regions a subscription could deploy into. - [Get overview resource groups](https://api.controlup.io/reference/getoverviewresourcegroups.md): Returns one row per resource group, with host pool counts, host statistics, cost, and performance rolled up. Only groups holding onboarded resources, not every group that exists in Azure. - [Get overview host pools](https://api.controlup.io/reference/getoverviewhostpools.md): Returns one row per host pool with host statistics, session counts, cost, and performance metrics. Carries cost and accepts filters from any level of the hierarchy; the plain host pool list is the one for simply enumerating pools. Neither carries AVD configuration or time-series metrics. - [Get overview session hosts](https://api.controlup.io/reference/getoverviewsessionhosts.md): Returns one row per session host VM with power state, session count, performance metrics, and cost. Spans every host pool, so it answers "which hosts anywhere are unhealthy, idle, or expensive". - [Get overview images](https://api.controlup.io/reference/getoverviewimages.md): Returns one row per image that onboarded resources are running, with version, status, and consumer count. Covers images of any origin, unlike the master image view, which covers only what DaaS IQ builds. - [Get overview master images](https://api.controlup.io/reference/getoverviewmasterimages.md): Returns one row per DaaS IQ-managed Master Image with its version count and display name. A roll-up only; build configuration, publish history, and operation state live on the Master Images list. - [Get overview user sessions](https://api.controlup.io/reference/getoverviewusersessions.md): Returns one row per current user session (Active, Pending, or Disconnected), denormalised with its host pool, subscription, and region. Ordered by user principal name. Spans every host pool, so it answers "where is this user connected". - [Get overview application groups](https://api.controlup.io/reference/getoverviewapplicationgroups.md): Returns one row per application group — the AVD object publishing RemoteApp programs or a full desktop — with its type, host pool, and session statistics. Sits between a workspace and a host pool, so it is neither what users pick nor what session hosts join. - [Get overview workspaces](https://api.controlup.io/reference/getoverviewworkspaces.md): Returns one row per AVD workspace with its application group count, host pools, and session statistics. Top of the publishing hierarchy and what users see in their client; owns application groups, not hosts. - [Get scaling profiles](https://api.controlup.io/reference/getscalingprofiles.md): Returns every scaling profile in the organization — reusable autoscale configurations that a host pool's weekly schedule assigns to time blocks. Profiles are organization-wide and not bound to any pool, so this does not say where a profile is used. Filterable and sortable on Id, Name, Description, Color. - [Create a scaling profile](https://api.controlup.io/reference/createscalingprofile.md): Creates a new scaling profile with the specified configuration. - [Get a scaling profile by ID](https://api.controlup.io/reference/getscalingprofile.md): Returns one scaling profile with its complete nested configuration, including thresholds and host count rules. Returns the definition only — it does not say which host pools use the profile or whether it is currently active. - [Update a scaling profile](https://api.controlup.io/reference/updatescalingprofile.md): Updates an existing scaling profile with the specified configuration. - [Delete a scaling profile](https://api.controlup.io/reference/deletescalingprofile.md): Deletes a scaling profile. Cannot delete profiles that are currently in use by schedules. - [Update scaling profile color](https://api.controlup.io/reference/updatescalingprofilecolor.md): Updates the display color of a scaling profile. - [Execute an action on a session host](https://api.controlup.io/reference/executesessionhostaction.md): Creates a background job to perform the action (restart, stop, drain mode, remove). Poll the statusUrl for progress updates. - [Get user sessions for a session host](https://api.controlup.io/reference/getsessionhostsessions.md): Returns the people currently logged in to one session host, scoped to that host alone. In Azure AVD this includes Active, Pending, and Disconnected sessions: any session where the user has not logged off. Covers a single host, not the whole pool. - [Verify subscription credentials (Deprecated)](https://api.controlup.io/reference/verifysubscriptioncredentials.md): DEPRECATED: Use POST /api/v1/cloud/tenants/{tenantId}/credentials/{credentialId}/verify to verify tenant credentials instead. Verifies cloud provider credentials and permissions synchronously. Check the IsSuccess field to determine if credentials are valid. - [Verify subscription credentials - transcript (Deprecated)](https://api.controlup.io/reference/verifysubscriptioncredentialstranscript.md): DEPRECATED: Use POST /api/v1/cloud/tenants/{tenantId}/credentials/{credentialId}/verify/transcript instead. Verifies the connection and permissions with formatted output lines. Check IsSuccess field for result. - [Verify subscription credentials - streaming (Deprecated)](https://api.controlup.io/reference/get_cloud-subscriptions-id-credentials-verify-stream.md): Streams real-time cloud credentials verification progress over a WebSocket connection using structured JSON messages. All messages are serialized as JSON with camelCase property names and inherit from ControlUp.Foundry.Domain.Models.Verification.Messages.VerificationMessage. **Message Types (see Domain.Models.Verification.Messages namespace):** - ControlUp.Foundry.Domain.Models.Verification.Messages.VerificationStartedMessage: Verification process begins - Properties: `type`, `timestamp` - ControlUp.Foundry.Domain.Models.Verification.Messages.StepStartedMessage: A verification step begins - Properties: `type`, `timestamp`, `stepNumber`, `stepName` - ControlUp.Foundry.Domain.Models.Verification.Messages.StepCompletedMessage: A verification step completes - Properties: `type`, `timestamp`, `stepNumber`, `stepName`, `status`, `duration`, `detail` - `status` values: "success" | "warning" | "failure" - ControlUp.Foundry.Domain.Models.Verification.Messages.VerificationCompletedMessage: Verification process ends - Properties: `type`, `timestamp`, `success`, `duration`, `errorMessage` **Usage Flow:** 1. Client establishes WebSocket connection to `/api/v1/cloud/subscriptions/{id}/credentials/verify/stream` 2. Server validates subscription exists and user has permission 3. Server accepts WebSocket connection (HTTP 101 Switching Protocols) 4. Server sends ControlUp.Foundry.Domain.Models.Verification.Messages.VerificationStartedMessage 5. For each verification step (provider-specific): - Server sends ControlUp.Foundry.Domain.Models.Verification.Messages.StepStartedMessage - Server performs verification against cloud provider API - Server sends ControlUp.Foundry.Domain.Models.Verification.Messages.StepCompletedMessage with results 6. Server sends ControlUp.Foundry.Domain.Models.Verification.Messages.VerificationCompletedMessage 7. Server closes WebSocket with normal closure or error status **WebSocket Client Example (JavaScript):** ```javascript const subscriptionId = '123e4567-e89b-12d3-a456-426614174000'; const ws = new WebSocket(`wss://api.example.com/api/v1/cloud/subscriptions/${subscriptionId}/credentials/verify/stream`); ws.onopen = () => { console.log('WebSocket connected - waiting for verification to start...'); }; ws.onmessage = (event) => { const message = JSON.parse(event.data); switch(message.type) { case 'verification_started': console.log('Verification started at:', message.timestamp); // Initialize UI for verification progress break; case 'step_started': console.log(`Step ${message.stepNumber}: ${message.stepName} - started`); // Show spinner/progress indicator for this step break; case 'step_completed': console.log(`Step ${message.stepNumber}: ${message.stepName} - ${message.status} in ${message.duration}`); if (message.detail) { console.log(` Detail: ${message.detail}`); } // Update UI with status icon: ✓ (success), ⚠ (warning), ✗ (failure) break; case 'verification_completed': console.log(`Verification ${message.success ? 'succeeded' : 'failed'} - Duration: ${message.duration}`); if (message.errorMessage) { console.error(`Error: ${message.errorMessage}`); } // Finalize UI with overall result break; default: console.warn('Unknown message type:', message.type); } }; ws.onerror = (error) => { console.error('WebSocket error:', error); // Handle connection errors }; ws.onclose = (event) => { console.log(`WebSocket closed - Code: ${event.code}, Reason: ${event.reason}`); // Clean up UI and resources }; ``` **Example Message Sequence (Azure Subscription):** ```json {"type":"verification_started","timestamp":"2025-10-23T10:30:00.000Z"} {"type":"step_started","stepNumber":1,"stepName":"Validating Azure credentials format","timestamp":"2025-10-23T10:30:00.100Z"} {"type":"step_completed","stepNumber":1,"stepName":"Validating Azure credentials format","status":"success","duration":"00:00:00.150","timestamp":"2025-10-23T10:30:00.250Z"} {"type":"step_started","stepNumber":2,"stepName":"Testing connectivity to Azure Resource Manager","timestamp":"2025-10-23T10:30:00.300Z"} {"type":"step_completed","stepNumber":2,"stepName":"Testing connectivity to Azure Resource Manager","status":"success","duration":"00:00:01.200","detail":"Successfully authenticated with tenant ID: abc123","timestamp":"2025-10-23T10:30:01.500Z"} {"type":"step_started","stepNumber":3,"stepName":"Verifying required Azure permissions","timestamp":"2025-10-23T10:30:01.550Z"} {"type":"step_completed","stepNumber":3,"stepName":"Verifying required Azure permissions","status":"failure","duration":"00:00:00.800","detail":"Missing required role: Virtual Machine Contributor","timestamp":"2025-10-23T10:30:02.350Z"} {"type":"verification_completed","success":false,"duration":"00:00:02.500","errorMessage":"Verification failed","timestamp":"2025-10-23T10:30:02.500Z"} ``` **Notes:** - All timestamps are in ISO 8601 UTC format - Duration fields are in TimeSpan format (hh:mm:ss.fffffff) - Step numbers are sequential, starting from 1 - The `detail` field in ControlUp.Foundry.Domain.Models.Verification.Messages.StepCompletedMessage is optional (null for success, may contain info for warnings/failures) - WebSocket closes automatically after sending ControlUp.Foundry.Domain.Models.Verification.Messages.VerificationCompletedMessage - If an error occurs during verification, the server will attempt to close the WebSocket with appropriate status code - [Verify subscription credentials - streaming (Deprecated)](https://api.controlup.io/reference/post_cloud-subscriptions-id-credentials-verify-sse.md): **DEPRECATED:** Use tenant-based credential verification endpoints instead. SSE replacement for the WebSocket `/verify/stream` endpoint. Same message format, simpler protocol. - [Get available regions for a subscription](https://api.controlup.io/reference/getregions.md): Returns the regions the subscription can deploy into, paginated, filterable and sortable. Region identity and display names only — availability zones are omitted here and available per region from the single-region lookup. - [Get region metadata](https://api.controlup.io/reference/getregionmetadata.md): Returns one named region's metadata in the subscription's context, including the availability zones that the region list omits. Describes a single region rather than enumerating which regions are available. - [Get available VM sizes for a region with filtering, sorting, and pagination support](https://api.controlup.io/reference/getvmsizes.md): Returns the VM SKUs offered in a region with full specifications: CPU count, memory, disk limits, IOPS, and capability flags. Describes what each SKU is capable of, not whether the subscription has quota left to deploy one. Supports filtering, sorting, and pagination for large result sets. - [Get available OS disk size options for a region](https://api.controlup.io/reference/getosdisks.md): Returns a flat, paged list of the OS disk size options offered for the subscription and region, optionally narrowed to an availability zone. Disk sizing choices only — not VM compute specifications, and not the subscription's remaining quota. - [Get compute quota usage for a region](https://api.controlup.io/reference/getcomputequota.md): Returns current vCPU quota usage and limits for the subscription in a region, per VM family (for example standardDSv3Family) plus the total regional quota. Answers whether there is headroom to deploy, which the VM size catalog cannot; compare against a SKU's family and core count. Supports filtering, sorting, and pagination, and is cached server-side for 5 minutes, so very recent deployments may not be reflected. Useful filter examples: - Families with active usage: filter=gt(currentUsage,0) - Specific family lookup: filter=eq(name,standardDSv3Family) - Total regional quota: filter=eq(name,cores) - [Check host pool create permissions](https://api.controlup.io/reference/checkhostpoolcreatepermissions.md): Advisory check that the subscription's service principal can create AVD control-plane resources: host pool, application group, and workspace update. Covers the control-plane portion of the Create Host Pool wizard (POST host-pool-deployments); when initial session hosts will also be created, additionally call the session host create pre-flight. Each required permission is evaluated at exactly the scope the create flow exercises it against (inherited grants from resource group, subscription, or management group count). Advisory only — a failed check never blocks creation. The result carries one of three statuses: - granted: all required actions confirmed at their target scopes. - missingPermissions: at least one action could not be confirmed; display the returned message as a warning. - unknown: the check itself could not run (transient error); do not show a warning. - [Check session host create permissions](https://api.controlup.io/reference/checksessionhostcreatepermissions.md): Advisory check that the subscription's service principal can provision session host VMs: VM, NIC, and disk creation, VM extensions, run commands, subnet join, gallery image read, and host pool registration-token generation. Covers three flows: initial session hosts at host pool creation (host count greater than zero), POST session-host-deployments, and autoscale scale-out. Each required permission is evaluated at exactly the scope the provisioning flow exercises it against (inherited grants from resource group, subscription, or management group count). Advisory only — a failed check never blocks creation. The result carries one of three statuses: - granted: all required actions confirmed at their target scopes. - missingPermissions: at least one action could not be confirmed; display the returned message as a warning. - unknown: the check itself could not run (transient error); do not show a warning. - [Lookup virtual networks in a subscription](https://api.controlup.io/reference/lookupvirtualnetworks.md): Queries Azure for virtual networks in the subscription, to choose where session hosts will be placed. - [Lookup virtual machines in a subscription](https://api.controlup.io/reference/lookupvirtualmachines.md): Queries Azure for virtual machines in the subscription, to pick an existing VM to promote to a Master Image. Lists VMs whether or not DaaS IQ manages them. - [Lookup Azure Compute Galleries in a subscription](https://api.controlup.io/reference/lookupgalleries.md): Queries Azure for Compute Galleries — the containers holding image definitions and their versions. Top level of the gallery hierarchy: the galleries themselves, not the images inside them. - [Lookup Azure resource groups in a subscription](https://api.controlup.io/reference/lookupresourcegroups.md): Queries Azure for resource groups in the subscription, to choose where new resources will be created. The containers themselves, not the resources they hold. - [Lookup AVD workspaces in a subscription](https://api.controlup.io/reference/lookupworkspaces.md): Queries Azure for AVD workspaces — the object that publishes application groups to users. Not host pools: a workspace holds no session hosts and reaches pools only via its application groups. - [Lookup Azure Managed Images in a subscription](https://api.controlup.io/reference/lookupmanagedimages.md): Queries Azure for standalone Managed Images (Microsoft.Compute/images), with HyperV generation, OS state, and disk size. Unversioned artifacts living outside any compute gallery, so a different resource type from gallery images. Only Gen 2 generalized images are usable as a Master Image source. - [Lookup gallery images in a subscription](https://api.controlup.io/reference/lookupgalleryimages.md): Queries Azure for gallery image definitions — the named images inside a compute gallery. Middle level of the gallery hierarchy: a definition is not deployable, since deployment targets a version. - [Lookup gallery image versions in a subscription](https://api.controlup.io/reference/lookupgalleryimageversions.md): Queries Azure for published versions of gallery image definitions. Leaf level of the gallery hierarchy, and the one to pick when a deployment needs a concrete artifact. - [Discover resources in a subscription (Deprecated)](https://api.controlup.io/reference/discoverresources.md): DEPRECATED: Use GET /api/v1/cloud/tenants/{tenantId}/resources/discover to discover resources via tenant instead. Queries the cloud provider to retrieve resource metadata with pagination and sorting support. Supports multiple resource types in a single request. Returns base CloudResourceDto without type-specific properties. - [Discover host pools in a subscription (Deprecated)](https://api.controlup.io/reference/discoverhostpools.md): DEPRECATED: Use GET /api/v1/cloud/tenants/{tenantId}/resources/discover/hostpools to discover host pools via tenant instead. Queries Azure to retrieve host pool metadata with pagination, sorting, and filtering support. Returns type-specific properties including host pool type, load balancer configuration, and session limits. - [Discover images in a subscription (Deprecated)](https://api.controlup.io/reference/discoverimages.md): DEPRECATED: Use GET /api/v1/cloud/tenants/{tenantId}/resources/discover/images to discover images via tenant instead. Queries Azure to retrieve image metadata with pagination and sorting support. Returns type-specific properties including source type (Managed/SharedImageGallery), OS type, and disk information. - [Import cloud resources (Deprecated)](https://api.controlup.io/reference/importresources.md): DEPRECATED: Use POST /api/v1/cloud/tenants/{tenantId}/resources/import to import resources via tenant instead. Creates a long-running background job to gather and import resource data from cloud providers. Only one import job per subscription can be active at a time. Poll the statusUrl for progress updates. - [Get subscriptions](https://api.controlup.io/reference/getsubscriptions.md): Returns every cloud subscription registered in the organization, optionally narrowed to one provider, with provider identifiers, lifecycle state, and owning tenant. Rows carry the subscription ID that per-subscription operations require, and describe registration rather than contents: no host pools, no resources, and no live credential health. - [Create a subscription (Deprecated)](https://api.controlup.io/reference/createsubscription.md): DEPRECATED: Use POST /api/v1/cloud/tenants to create a tenant with credentials, then link subscriptions. Creates a new cloud subscription with the provided configuration. - [Get a subscription by ID](https://api.controlup.io/reference/getsubscription.md): Returns one subscription in the same shape as a row of the subscription list: provider identifiers, lifecycle state, and owning tenant. Describes how the subscription is registered in DaaS IQ, not what it contains or whether its credentials currently work. - [Update a subscription (Deprecated)](https://api.controlup.io/reference/updatesubscription.md): DEPRECATED: Use PUT /api/v1/cloud/tenants/{tenantId}/credentials/{credentialId} to update tenant credentials. Updates an existing subscription with the provided configuration. Provider changes are only allowed for subscriptions in Draft state. - [Rotate subscription credentials (Deprecated)](https://api.controlup.io/reference/patchsubscription.md): DEPRECATED: Use PATCH /api/v1/cloud/tenants/{tenantId}/credentials/{credentialId} to rotate tenant credentials. Rotates the secrets/credentials for an existing subscription. - [Delete a subscription (Deprecated)](https://api.controlup.io/reference/deletesubscription.md): DEPRECATED: Use DELETE /api/v1/cloud/tenants/{tenantId} to delete a tenant and its subscriptions. Deletes a cloud subscription and all associated resources. - [Get subscription status (Deprecated)](https://api.controlup.io/reference/getsubscriptionstatus.md): DEPRECATED: Use GET /api/v1/cloud/tenants/{tenantId}/status to get tenant status instead. Returns the current status of a subscription including health and verification details. - [Refresh subscription status (Deprecated)](https://api.controlup.io/reference/refreshsubscriptionstatus.md): DEPRECATED: Use POST /api/v1/cloud/tenants/{tenantId}/status/refresh to refresh tenant status instead. Refreshes the subscription status by verifying its connection and credentials. Check the Status field for the current health. - [Get tenant credentials](https://api.controlup.io/reference/gettenantcredentials.md): Returns every credential in the tenant's pool — the default one plus any additional service principals added for load balancing — with sensitive values masked. Describes how credentials are configured, not whether they currently work: health, cooldown, and usage metrics are absent. - [Add a credential](https://api.controlup.io/reference/addtenantcredential.md): Adds a new credential to a tenant's credential pool. This is useful for adding additional service principals for load balancing API calls. Automatically triggers credential verification in the background to update health status. - [Get a credential by ID](https://api.controlup.io/reference/gettenantcredential.md): Returns one credential's configuration: auth type, masked secret fields, and whether it is enabled. Configuration only — it reports nothing about that credential's live health, cooldown, or usage. - [Update a credential](https://api.controlup.io/reference/updatetenantcredential.md): Updates an existing credential with new authentication details. Automatically clears any stale operational state (cooldown, health metrics) after update. Automatically triggers credential verification in the background to update health status. - [Patch a credential](https://api.controlup.io/reference/patchtenantcredential.md): Partially updates a credential. Only provided fields will be updated. Automatically clears any stale operational state (cooldown, health metrics) after update. Automatically triggers credential verification in the background to update health status. - [Delete a credential](https://api.controlup.io/reference/deletetenantcredential.md): Soft deletes a credential from a tenant. If deleting the default credential, another credential will be automatically promoted to default (prioritizes enabled credentials, then oldest by creation date). Validation rules: - Cannot delete the only credential for a tenant - Cannot delete if it would leave no enabled credentials - [Enable a credential](https://api.controlup.io/reference/enabletenantcredential.md): Enables a credential for use in the credential pool. Enabled credentials will be selected for API operations via round-robin (LRU) selection. Automatically clears any stale operational state (cooldown, health metrics) to provide a fresh start. - [Disable a credential](https://api.controlup.io/reference/disabletenantcredential.md): Disables a credential from being used in the credential pool. Disabled credentials will not be selected for API operations but remain in the system. Cannot disable the last enabled credential for a tenant. - [Get credentials status](https://api.controlup.io/reference/gettenantcredentialspoolstatus.md): Returns live operational status for every credential in the tenant: health, rate-limit cooldown, and usage metrics. Reports whether credentials are currently working rather than how they are configured, and covers the whole pool in one call. - [Get credential status](https://api.controlup.io/reference/gettenantcredentialstatus.md): Returns live operational status for one credential: health, rate-limit cooldown, and usage metrics. Reports whether that credential is currently working rather than how it is configured, and covers a single credential rather than the pool. - [Verify default credentials](https://api.controlup.io/reference/verifytenantdefaultcredentials.md): Tests one credential live against Azure AD — the tenant's default specifically, not round-robin selection — and returns step-by-step results. Success clears stale operational state such as cooldown and health metrics. Scoped to authentication by that single credential; refreshing the tenant status is the broader check that walks every subscription and updates overall tenant health. - [Verify a credential by ID](https://api.controlup.io/reference/verifytenantcredential.md): Verifies a specific credential for a tenant. Tests authentication with Azure AD and tenant access. This verifies the exact credential specified - NOT round-robin selection. On successful verification, automatically clears any stale operational state (cooldown, health metrics). - [Verify default credentials (transcript)](https://api.controlup.io/reference/verifytenantdefaultcredentialstranscript.md): Verifies the default credential for a tenant with formatted output lines. Check IsSuccess field for result. This verifies the specific default credential - NOT round-robin selection. On successful verification, automatically clears any stale operational state (cooldown, health metrics). - [Verify a credential by ID (transcript)](https://api.controlup.io/reference/verifytenantcredentialtranscript.md): Verifies a specific credential for a tenant with formatted output lines. Check IsSuccess field for result. This verifies the exact credential specified - NOT round-robin selection. On successful verification, automatically clears any stale operational state (cooldown, health metrics). - [Verify default credentials - streaming (Deprecated)](https://api.controlup.io/reference/get_cloud-tenants-tenantid-credentials-verify-stream.md): Streams real-time verification progress for the tenant's default credential over a WebSocket, as structured JSON messages. Verifies that one default credential rather than exercising round-robin selection, and clears stale cooldown and health metrics on success. **DEPRECATED:** use `POST /api/v1/cloud/tenants/{tenantId}/credentials/verify/sse` instead — same message format over a simpler protocol. This WebSocket endpoint is kept only for backward compatibility with existing UI clients. - [Verify a credential by ID - streaming (Deprecated)](https://api.controlup.io/reference/get_cloud-tenants-tenantid-credentials-credentialid-verify-stream.md): Streams real-time verification progress for one named credential over a WebSocket, as structured JSON messages. Verifies the exact credential given rather than exercising round-robin selection, and clears stale cooldown and health metrics on success. **DEPRECATED:** use `POST /api/v1/cloud/tenants/{tenantId}/credentials/{credentialId}/verify/sse` instead — same message format over a simpler protocol. This WebSocket endpoint is kept only for backward compatibility with existing UI clients. - [Verify default credentials - streaming](https://api.controlup.io/reference/post_cloud-tenants-tenantid-credentials-verify-sse.md): Streams real-time tenant credential verification progress via Server-Sent Events (SSE). Each event is a JSON message: `data: {"type":"step_started","stepName":"...","stepNumber":1}\n\n` Replaces the WebSocket-based `/verify/stream` endpoint. Same message format, simpler protocol. - [Verify a credential by ID - streaming](https://api.controlup.io/reference/post_cloud-tenants-tenantid-credentials-credentialid-verify-sse.md): Streams real-time tenant credential verification progress via Server-Sent Events (SSE). Each event is a JSON message: `data: {"type":"step_started","stepName":"...","stepNumber":1}\n\n` Replaces the WebSocket-based `/verify/stream` endpoint. Same message format, simpler protocol. - [Discover subscriptions accessible by tenant's default credentials](https://api.controlup.io/reference/discovertenantsubscriptions.md): Discovers the subscriptions the tenant's default credential can reach — for Azure, those the service principal was granted. Each row is flagged with isAlreadyManaged, so this distinguishes what could still be onboarded from what already has been. Exercises only the default credential. - [Discover resources across subscriptions in a tenant](https://api.controlup.io/reference/discovertenantresources.md): Discovers resource metadata for several types at once by querying the cloud provider live, each row flagged with isAlreadyManaged so resources already imported into DaaS IQ can be told apart from candidates. If subscriptionIds is provided, only those subscriptions are queried (faster — skips subscription discovery). If subscriptionIds is not provided, all accessible subscriptions are discovered and queried. - [Discover host pools across all subscriptions in a tenant](https://api.controlup.io/reference/discovertenanthostpools.md): Discovers host pools as they exist in Azure, with pool type, load balancer configuration, and session limits. Includes pools never imported, so it answers "what is out there" rather than "what do we manage". - [Discover images across all subscriptions in a tenant (Deprecated)](https://api.controlup.io/reference/discovertenantimages.md): DEPRECATED: Image discovery is replaced by Image Management. Use /discover/resources/virtualmachines for the import wizard. Image metadata with source type (Managed or SharedImageGallery), OS type, and disk information. - [Import cloud resources for a tenant](https://api.controlup.io/reference/importtenantresources.md): Creates a single long-running parent job that orchestrates subscription-level import jobs. The parent job discovers subscriptions, dispatches child import jobs (one per subscription), aggregates progress, and determines overall success/failure. Two modes are supported: 1. **Import All**: Set `importAll: true` to discover all subscriptions and import all resources 2. **Selective Import**: Provide specific subscriptions and resource IDs to import Selective imports default to reconcile behavior: subscriptions and resources omitted from the request are soft-deleted. Set `importMode` to `Additive` for host-pool-only imports that must preserve all existing managed resources. When importing, CloudSubscription records are automatically created for Azure subscriptions that don't exist yet in the system. These subscriptions are linked to the tenant and use the tenant's default credentials. - [Get tenants](https://api.controlup.io/reference/gettenants.md): Returns the cloud provider tenants in the organization — Azure AD, AWS Organizations, GCP Organizations — optionally narrowed to one provider, each with its default credential masked. Configuration only: no health, verification results, or the subscriptions beneath each tenant. - [Create a new tenant with default credential](https://api.controlup.io/reference/createtenant.md): Creates a new tenant with the specified configuration and default credential in a single operation. The provided credentials will become the tenant's default credential used for API authentication. Note: For Azure providers, the TenantId field in credentials is automatically populated from the ProviderTenantId. - [Get a tenant by ID](https://api.controlup.io/reference/gettenant.md): Returns one tenant in the same shape as a list row: provider, identifiers, and masked default credential. Configuration only: no health, no verification results, and no credentials beyond the default. - [Update an existing tenant](https://api.controlup.io/reference/updatetenant.md): Updates an existing tenant with the specified configuration. Provider changes are only allowed for tenants in Draft state. If AuthType and Credentials are provided, also updates the default credential. - [Partially update a tenant](https://api.controlup.io/reference/patchtenant.md): Partially updates a tenant. All fields are optional - only provided fields will be updated. For credential updates, you can provide partial credentials (e.g., just clientSecret) to update specific fields. - [Delete a tenant](https://api.controlup.io/reference/deletetenant.md): Soft deletes a tenant and its associated credentials. - [Get tenant status](https://api.controlup.io/reference/gettenantstatus.md): Returns the tenant's aggregated health and verification details, computed from every credential and subscription beneath it. Reads the last stored result without contacting the cloud provider, so it is fast and safe to call repeatedly, but reflects the previous evaluation rather than this moment; a never-evaluated tenant reports Unknown. Use this to display known health. To re-test connectivity right now, refresh the status instead. Use the `include` parameter to request additional details: - `subscriptions` - Include status for each subscription under the tenant - `credentials` - Include detailed status (health, cooldown, usage metrics) for each credential Multiple values can be combined with commas: `include=subscriptions,credentials` - [Refresh tenant status](https://api.controlup.io/reference/refreshtenantstatus.md): Re-tests the tenant against the cloud provider now, verifying every subscription beneath it and re-aggregating the result, then stores it so later reads of the tenant status return this outcome. The authoritative answer to "is this tenant working right now", at the cost of live provider calls across every subscription. Covers the whole tenant, whereas verifying a credential tests one credential in isolation. Use the `include` parameter to request additional details: - `subscriptions` - Include status for each subscription under the tenant - `credentials` - Include detailed status (health, cooldown, usage metrics) for each credential Multiple values can be combined with commas: `include=subscriptions,credentials` - [Execute an action on a user session](https://api.controlup.io/reference/executeusersessionaction.md): Creates a background job to perform the action (send message, sign out, disconnect). Poll the statusUrl for progress updates. - [Get current user information](https://api.controlup.io/reference/get_users-user-info.md): Returns the calling user's identity, organization context, and permissions, read from the bearer token's claims. Answers "who am I" and "which organization am I in"; it takes no user ID and cannot look anyone else up. - [Get health status](https://api.controlup.io/reference/get_health.md): Returns the health status of the API and its dependencies. - [Get liveness status](https://api.controlup.io/reference/get_health-live.md): Returns a lightweight process liveness response without checking external dependencies. - [Get build info](https://api.controlup.io/reference/get_health-info.md): Returns build metadata for deployment verification (version, etc.). ## Changelog - [June 2026](https://api.controlup.io/changelog/june-2026.md) - [May 2026](https://api.controlup.io/changelog/may-2026.md) - [March 2026](https://api.controlup.io/changelog/march-2026.md) - [February 2026](https://api.controlup.io/changelog/february-2026.md) - [December 2025](https://api.controlup.io/changelog/december-2025.md) - [October 2025](https://api.controlup.io/changelog/october-2025.md) - [September 2025](https://api.controlup.io/changelog/september-2025.md) - [July 2025](https://api.controlup.io/changelog/july-2025.md) - [June 2025](https://api.controlup.io/changelog/june-2025.md) - [April 2025](https://api.controlup.io/changelog/april-2025.md)