# DoiT Cloud Intelligence Documentation > DoiT Cloud Intelligence Public APIs Documentation ## Guides - [Get Started](https://developer.doit.com/docs/start.md): Welcome to DoiT Cloud Intelligence™ Public API - [Rate limits](https://developer.doit.com/docs/rate-limits.md): Learn about the rate limits of DoiT API. - [Terraform Provider](https://developer.doit.com/docs/tf-provider.md): The DoiT Cloud Intelligence Terraform provider lets you manage DoiT Cloud Intelligence™ via code. - [Integrating with SOPS](https://developer.doit.com/docs/managing-the-api-token-with-sops.md): How to integrate DoiT Terraform provider using best practices for authentication, and SOPS secrets. - [MCP Server](https://developer.doit.com/docs/doit-mcp-server.md): Embed DoiT Cloud Intelligence in your FinOps, development, and architecture workflows - [Resource IDs](https://developer.doit.com/docs/resource-ids.md): Get the IDs for reports, budgets, and other resources. - [Filters](https://developer.doit.com/docs/filters.md): Filters are a powerful tool you can use to access the data you need - [API Availability Matrix](https://developer.doit.com/docs/availability-matrix.md): A list of our generally available APIs and the currently supported version - [Ava](https://developer.doit.com/docs/ava-our-ai-assitant.md): Ava is DoiT’s AI-powered, cloud expert virtual assistant. - [Reports API](https://developer.doit.com/docs/reports.md): Programmatically obtain cost, usage and savings information for your cloud infrastructure with easy-to-use RESTful API. - [Sharing API](https://developer.doit.com/docs/sharing-api.md): Take the unified approach to managing permissions of Cloud Analytics resources. - [Allocations API](https://developer.doit.com/docs/allocations.md): Programmatically manage Allocations that you use across DoiT Cloud Intelligence™ for reports, budgets, alerts, anomalies, and more. - [Annotations API](https://developer.doit.com/docs/annotations-api.md): Programmatically manage Cloud Analytics report annotations with a REST API. - [Labels API](https://developer.doit.com/docs/labels-api.md): The **Labels API** allows you to programmatically manage and apply custom metadata to your DoiT Cloud Intelligence™ resources. By defining and assigning labels, you can organize your cloud governance objects—such as budgets, allocations, and reports—to better align with your organization's team structure, cost centers, or environments. - [Anomalies API](https://developer.doit.com/docs/anomalies-1.md) - [Alerts](https://developer.doit.com/docs/alerts.md): Alerts are notifications for user-defined events or conditions. You can create alerts to track different metrics and dimensions, including allocations. - [Cloud Incidents](https://developer.doit.com/docs/knownissues.md) - [DataHub API](https://developer.doit.com/docs/datahub-api.md): Ingest data from various sources for contextualized analysis of your spend. - [Invoices API](https://developer.doit.com/docs/invoice.md): Programatically access cloud infrastructure invoices - [Insights API](https://developer.doit.com/docs/insights-api.md) - [Users API Overview](https://developer.doit.com/docs/users-api-overview.md): Programmatically manage your users - [Manage License-based Assets](https://developer.doit.com/docs/manage-license-based-assets.md): Programatically add or remove licenses for your Google Workspace or Office 365 subscriptions - [Manage AWS Assets](https://developer.doit.com/docs/manage-aws-assets.md) - [Support API](https://developer.doit.com/docs/support.md) - [Platforms and Products](https://developer.doit.com/docs/support-metadata.md): Possible values for `platform` and `product` fields - [Ticket Status and Severity](https://developer.doit.com/docs/ticket-statuses.md): How to parse API status and severity values - [Partner Provisioning](https://developer.doit.com/docs/partner-endpoints.md): Reference-style documentation for partner tenant provisioning, bulk provisioning, and job polling endpoints. ## API Reference - [Welcome](https://developer.doit.com/reference/welcome.md): Welcome to DoiT Cloud Intelligence™ API Reference - [List alerts](https://developer.doit.com/reference/listalerts.md): Returns a list of alerts that your account has access to. Alerts are listed in reverse chronological order by default. - [Create an alert](https://developer.doit.com/reference/createalert.md): Creates a new alert. - [Retrieve an alert](https://developer.doit.com/reference/getalert.md): Returns an alert by the specified Id. - [Delete an alert](https://developer.doit.com/reference/deletealert.md): Deletes the alert specified by the Id. - [Update an alert](https://developer.doit.com/reference/updatealert.md): Updates the alert specified by the Id. - [List anomalies](https://developer.doit.com/reference/listanomalies.md): Returns a list of detected anomalies. Anomalies are returned in reverse chronological order by default. The `notifications` array is always present on each anomaly item; it is empty unless `includeNotifications=true` is supplied. - [Retrieve an anomaly](https://developer.doit.com/reference/getanomaly.md): Returns the specified anomaly. - [List budget suggestions](https://developer.doit.com/reference/listbudgetsuggestions.md): Returns the pending AI-generated budget suggestions for your account. The set is small (a handful of pending suggestions) and is returned in full. Each suggestion can be accepted (after you create a matching budget via `POST /analytics/v1/budgets`) or dismissed. - [Accept a budget suggestion](https://developer.doit.com/reference/acceptbudgetsuggestion.md): Marks the suggestion as accepted and links it to an existing budget. Create the budget first via `POST /analytics/v1/budgets`, then pass its `id` as `budgetId`. The budget must belong to your account. - [Dismiss a budget suggestion](https://developer.doit.com/reference/dismissbudgetsuggestion.md): Marks the suggestion as dismissed so it no longer appears in the pending list. - [List budgets](https://developer.doit.com/reference/listbudgets.md): Returns a list of budgets that your account has access to. Budgets are listed in reverse chronological order by default. - [Create a budget](https://developer.doit.com/reference/createbudget.md): Create a new budget - [Retrieve a budget](https://developer.doit.com/reference/getbudget.md): Returns the current utilization and configuration of the specified budget. - [Delete a budget](https://developer.doit.com/reference/deletebudget.md): Deletes the specified budget. - [Update a budget](https://developer.doit.com/reference/updatebudget.md): Updates the specified budget. - [List cloud incidents](https://developer.doit.com/reference/listknownissues.md): Returns a list of all the active and historical cloud incidents for Google Cloud and Amazon Web Services. Incidents are returned in reverse chronological order by default. - [Retrieve a cloud incident](https://developer.doit.com/reference/getknownissue.md): Returns the specified cloud incident. - [List allocations](https://developer.doit.com/reference/listallocations.md): Returns a list of allocations that your account has access to. Allocations are listed in reverse chronological order by default. - [Create an allocation](https://developer.doit.com/reference/createallocation.md): Creates a new allocation. - [Retrieve an allocation](https://developer.doit.com/reference/getallocation.md): Returns an allocation by the specified Id. - [Delete an allocation](https://developer.doit.com/reference/deleteallocation.md): Deletes the allocation specified by the Id. - [Update an allocation](https://developer.doit.com/reference/updateallocation.md): Updates the allocation specified by the Id. - [List annotations](https://developer.doit.com/reference/listannotations.md): Returns a list of annotations that your account has access to. Annotations are listed in reverse chronological order by default. - [Create an annotation](https://developer.doit.com/reference/createannotation.md): Creates a new annotation. - [Retrieve an annotation](https://developer.doit.com/reference/getannotation.md): Returns an annotation by the specified Id. - [Delete an annotation](https://developer.doit.com/reference/deleteannotation.md): Deletes the annotation specified by the Id. - [Update an annotation](https://developer.doit.com/reference/updateannotation.md): Updates the annotation specified by the Id. - [Retrieve a dimension](https://developer.doit.com/reference/getdimensions.md): Returns a dimension by type and key. - [List dimensions](https://developer.doit.com/reference/listdimensions.md): Returns a list of the dimensions that your account has access to. - [List labels](https://developer.doit.com/reference/listlabels.md): Returns a list of labels that your account has access to. Labels are listed in reverse chronological order by default. - [Create a label](https://developer.doit.com/reference/createlabel.md): Creates a new label. - [Retrieve a label](https://developer.doit.com/reference/getlabel.md): Returns a label by the specified Id. - [Delete a label](https://developer.doit.com/reference/deletelabel.md): Deletes the label specified by the Id. - [Update a label](https://developer.doit.com/reference/updatelabel.md): Updates the label specified by the Id. - [Assign or unassign objects to a label](https://developer.doit.com/reference/assignobjectstolabel.md): Assigns or un-assigns objects to the label specified by the ID. - [Get label assignments](https://developer.doit.com/reference/getlabelassignments.md): Returns the list of objects currently assigned to the label specified by the ID. - [List folders](https://developer.doit.com/reference/listfolders.md): Returns Cloud Analytics folders the current customer has access to. Folders are returned in id-ascending order. - [Create a folder](https://developer.doit.com/reference/createfolder.md): Creates a new Cloud Analytics folder. - [Get a folder](https://developer.doit.com/reference/getfolder.md): Returns the specified Cloud Analytics folder. - [Update a folder](https://developer.doit.com/reference/updatefolder.md): Updates the specified folder. All fields are optional. To reparent the folder, set `parentFolderId` to the target folder ID (use "root" for the top level). If a sibling at the target has the same name, the folder is auto-renamed. To move reports or allocations into or out of a folder, update the item's `folderId` field via the report or allocation PATCH endpoint. - [Delete a folder](https://developer.doit.com/reference/deletefolder.md): Deletes the specified folder. All nested folders will be deleted. Any reports or allocations contained in the folder are moved to the root. - [Reports](https://developer.doit.com/reference/reports.md): Learn how to use the Reports API to manage and interact with Cloud Analytics reports, including listing, creating, updating, and querying reports. - [List reports](https://developer.doit.com/reference/listreports.md): Returns a list of all Cloud Analytics reports that your account has access to. Reports are returned in reverse chronological order by default. - [Create a report](https://developer.doit.com/reference/createreport.md): Creates a new report. - [Run a query](https://developer.doit.com/reference/query.md): Runs a report query with the specified configuration without persisting it. Fields that are not populated will use their default values if needed. - [Get report results](https://developer.doit.com/reference/getreport.md): Returns the results of the specified report. - [Delete a report](https://developer.doit.com/reference/deletereport.md): Deletes the specified Cloud Analytics report. - [Update a report](https://developer.doit.com/reference/updatereport.md): Updates a report with the specified configuration. Only specified fields will be updated. - [Get report config](https://developer.doit.com/reference/getreportconfig.md): Returns the configuration of the specified Cloud Analytics report. - [List custom themes](https://developer.doit.com/reference/listcustomthemes.md): Returns the list of custom color themes defined for your account. - [Create a custom theme](https://developer.doit.com/reference/createcustomtheme.md): Creates a new custom color theme. Requires Cloud Analytics Admin permission. - [Retrieve a custom theme](https://developer.doit.com/reference/getcustomtheme.md): Returns a custom theme by the specified Id. - [Update a custom theme](https://developer.doit.com/reference/updatecustomtheme.md): Updates the custom theme specified by the Id. Requires Cloud Analytics Admin permission. - [Delete a custom theme](https://developer.doit.com/reference/deletecustomtheme.md): Deletes the custom theme specified by the Id. Requires Cloud Analytics Admin permission. - [Set the active theme](https://developer.doit.com/reference/setactivetheme.md): Sets the theme active for the authenticated user. Send the reserved sentinel `themeId: "default"` to clear the active theme and fall back to the built-in default. Returns the updated active theme. - [Get the active theme](https://developer.doit.com/reference/getactivetheme.md): Returns the theme currently active for the authenticated user. `themeId` is the reserved sentinel `"default"` when no custom or preset theme is selected and the user is on the built-in default. - [Get resource permissions](https://developer.doit.com/reference/getresourcepermission-2.md): Returns the permissions associated with the specified Cloud Analytics resource. Supports Allocations, Alerts, Budgets, and Reports. - [Update resource permissions](https://developer.doit.com/reference/updateresourcepermission.md): Updates the permissions associated with the specified Cloud Analytics resource. Supports Allocations, Alerts, Budgets, and Reports. - [Retrieve an asset](https://developer.doit.com/reference/getasset.md): Returns the full details of an asset specified by the asset id. - [Create an asset](https://developer.doit.com/reference/createasset.md): Creates a new asset. - [List assets](https://developer.doit.com/reference/idofassets.md): Returns a list of all available customer assets, such as Google Cloud billing accounts, G Suite/Workspace subscriptions, etc. Assets are returned in reverse chronological order by default. - [Update an asset](https://developer.doit.com/reference/idofasset.md): Updates an existing asset, such as G Suite/Workspace or Office 365 subscription, to add or remove licenses. - [Ingest CSV file](https://developer.doit.com/reference/datahubeventscsvfile.md): Sends a batch of events to DataHub using a CSV file, either uncompressed or compressed in ZIP or GZ format. It may take up to 15 minutes for the data to become available in the DoiT console. - [Ingest JSON](https://developer.doit.com/reference/datahubevents.md): Sends a batch of events to DataHub. - [Delete specific events](https://developer.doit.com/reference/deletedatahubeventsbyfilter.md): Deletes specific events using filters. Note that the two filters, `eventIds` and `time ranges`, are mutually exclusive. - [List datasets](https://developer.doit.com/reference/listdatahubdatasets.md): Returns a list of all DataHub datasets for the customer. - [Create dataset](https://developer.doit.com/reference/createdatahubdataset.md): Creates a new DataHub dataset. A dataset is a logical grouping of events that share the same provider name. Creating a dataset allows you to define metadata such as name and description before ingesting events. - [Delete datasets](https://developer.doit.com/reference/deletedatahubdatasets.md): Deletes one or more DataHub datasets and all their associated data. - [Retrieve a dataset](https://developer.doit.com/reference/getdatahubdataset.md): Returns a specific DataHub dataset by name. - [Delete a dataset](https://developer.doit.com/reference/deletedatahubdataset.md): Deletes a specific DataHub dataset. - [Update dataset](https://developer.doit.com/reference/updatedatahubdataset.md): Updates an existing DataHub dataset's metadata. Only the description field can be updated. The dataset name is immutable and serves as the resource identifier. To rename a dataset, delete it and create a new one. If `name` is included in the request body, it must match the dataset name in the URL path. A mismatched name will be rejected with a 400 error. - [List invoices](https://developer.doit.com/reference/listinvoices.md): Returns a list of all the current and historical invoices for your organization. Invoices are returned in reverse chronological order by default. - [Retrieve an invoice](https://developer.doit.com/reference/getinvoice.md): Returns the full details of an invoice specified by the invoice number. - [Get diagram cost snapshot](https://developer.doit.com/reference/getclouddiagramcostsnapshot.md): Returns a bounded cost snapshot for the specified diagram layer over a date window. The response composes the diagram's total spend, period-over-period change, top resources by cost (capped at 5), top services by cost (capped at 5), and a trend series (most recent 12 buckets at the requested interval). - [Get resource relationships](https://developer.doit.com/reference/getclouddiagramresourcerelationships.md): Walks the diagram graph from the anchor resource and returns related resources. Edge traversal walks the diagram's link set (same-scheme guard, BFS, cycle-safe); group traversal walks the group membership set. The result list is capped at 200 relations; `truncated` is `true` when the cap is hit. Read-only: does not mutate diagram state. - [Find diagrams](https://developer.doit.com/reference/findclouddiagrams.md): Returns diagram URLs matching the provided resource IDs. - [Get diagrams with stats](https://developer.doit.com/reference/getclouddiagramsstats.md): Returns a list of all diagrams with activity stats for the given time period. - [Get diagram components](https://developer.doit.com/reference/getclouddiagramcomponents.md): Returns diagram and layer data. When the request body is empty, returns all diagrams the caller has access to. When the body is populated, returns full diagram data including layer components projected to key display and cloud fields. - [Search diagrams and components](https://developer.doit.com/reference/searchclouddiagrams.md): Full-text search across diagram layers, components by name, and components by property values. Returns three result categories: diagram (matching layers), component (matching components by name), and prop (matching components by property values). - [Get layer components](https://developer.doit.com/reference/getstatussheetcomponents.md): Returns the specified components of a diagram layer. Provide at least one component type with one or more IDs in the request body (for example, `node` or `element`). - [Export diagram as JSON](https://developer.doit.com/reference/exportclouddiagramjson.md): Exports the full content of a diagram layer as a structured JSON document, including all components and export metadata. - [List layer snapshots](https://developer.doit.com/reference/listclouddiagramlayersnapshots.md): Returns the list of saved snapshots for the specified diagram layer. - [Get a layer snapshot](https://developer.doit.com/reference/getclouddiagramlayersnapshot.md): Returns a single snapshot of the specified diagram layer identified by its ID. - [List activity groups for a layer](https://developer.doit.com/reference/listclouddiagramactivitygroups.md): Returns snapshot activity groups for the specified diagram layer, ordered by timestamp descending. Each group contains a snapshot reference and the individual activity records that belong to it. - [List node activities](https://developer.doit.com/reference/listclouddiagramnodeactivities.md): Returns individual activity records for the specified component node, ordered by timestamp descending. - [List CloudFlows](https://developer.doit.com/reference/listcloudflows.md): Returns a cursor-paginated list of CloudFlows. - [Trigger a webhook flow](https://developer.doit.com/reference/triggercloudflowwebhook.md): Triggers execution of a published CloudFlow whose first node is a webhook trigger. The request body must be valid JSON and is passed to the flow as webhook payload data. - [List connections](https://developer.doit.com/reference/listcloudflowconnections.md): Returns a cursor-paginated list of cloud provider connections for the authenticated tenant. - [Create a connection](https://developer.doit.com/reference/createcloudflowconnection.md): Creates a new cloud provider connection. Exactly one of `gcpConfig` or `awsConfig` must be supplied. Returns `400 invalid_connection_config` when both or neither are present. - [Retrieve a connection](https://developer.doit.com/reference/getcloudflowconnection.md): Returns a single connection by ID. - [Update a connection](https://developer.doit.com/reference/updatecloudflowconnection.md): Partially updates a connection. All fields are optional. At most one of `gcpConfig` or `awsConfig` may be set per request. - [Delete a connection](https://developer.doit.com/reference/deletecloudflowconnection.md): Deletes a connection. Returns 409 if the connection is referenced by one or more flows. - [List templates](https://developer.doit.com/reference/listcloudflowtemplates.md): Returns the catalogue of available CloudFlow templates (blueprints). Templates are read-only. To create a flow from a template, use `POST /flows` with a `templateId`. - [Retrieve a template](https://developer.doit.com/reference/getcloudflowtemplate.md): Returns a single CloudFlow template by ID. - [Refine a CloudFlow from natural language intent](https://developer.doit.com/reference/refinecloudflow.md): Refines the specified CloudFlow by generating and updating nodes and connections based on the provided natural language intent. The operation streams incremental build events as they are produced. - [Build a new CloudFlow from scratch](https://developer.doit.com/reference/buildcloudflow.md): Creates a new CloudFlow and generates its nodes and connections based on the provided natural language intent. The operation streams incremental build events, including the ID of the newly created flow, as they are produced. - [List roles](https://developer.doit.com/reference/listroles.md): Returns a list of roles. - [List organizations](https://developer.doit.com/reference/listorganizations.md): Returns a list of organizations. - [List users](https://developer.doit.com/reference/listusers.md): Returns a list of users in the organization, including both active users and invited users. When the `email` query parameter is provided, returns only the user matching that email address. If no user is found for the given email, an empty list is returned. - [Delete user](https://developer.doit.com/reference/deleteuser.md): Deletes a user. - [Update user](https://developer.doit.com/reference/updateuser.md): Updates user information, including name, job function, phone, language, and role. - [Invite user](https://developer.doit.com/reference/inviteuser.md): Invites a new user to the organization with specified role and organization. - [Resend invite](https://developer.doit.com/reference/resendinvite.md): Resets the invite expiry to 48 hours from now, invalidates the previous invite token (so old email links stop working), and triggers a fresh invitation email. Works on invites in any state including `Cancelled` — resending a cancelled invite reactivates it to `Pending`. Returns `404` if no invite exists for the given ID (never created, or already accepted and removed). Requires `usersManager` permission. - [Cancel invite](https://developer.doit.com/reference/cancelinvite.md): Marks the invite as `Cancelled` and invalidates the invite token so any outstanding email links stop working. The invite document is retained (soft cancel) — the user row remains visible in `GET /iam/v1/users` with `inviteStatus: Cancelled`. Use `DELETE /iam/v1/users/{id}` to fully remove the record. Returns `404` if no invite exists for the given ID, and `409` if the invite is already cancelled. Requires `usersManager` permission. - [List commitments](https://developer.doit.com/reference/listcommitments.md): Returns a list of commitments for the customer. Commitments are listed in reverse chronological order by default. - [Retrieve a commitment](https://developer.doit.com/reference/getcommitment.md): Returns a commitment by the specified Id. - [List insights](https://developer.doit.com/reference/getinsightresults.md): Returns a paginated list of insights with their aggregate summaries (savings, risk counts). Use query parameters to filter by status, category, provider, or priority. Does not include individual resource-level results — use the resource-results endpoint for those. - [Create insights (batch)](https://developer.doit.com/reference/postinsightresults.md): Creates or updates multiple insights in a single batch request. Each insight in the batch includes its metadata and resource results inline. For granular control over insight metadata and resource results independently, use the single-insight and resource-results endpoints instead. - [Delete insights (batch)](https://developer.doit.com/reference/deleteinsightresults.md): Deletes all insights matching the specified key from the batch source. This removes the insight and all its associated resource results. For single-insight deletion, use `DELETE /source/{sourceID}/insight/{insightKey}` instead. - [Update Insight Status](https://developer.doit.com/reference/updateinsightstatus.md): Updates the display status (e.g. actionable, acknowledged, dismissed) of a single insight. Only insights created via the public API can have their status changed. Deprecated: use the status field on the create/update insight endpoint instead. - [List resource results for an insight](https://developer.doit.com/reference/getinsightresourceresults.md): Returns a paginated list of individual resource-level results for a specific insight. Each resource result represents a single cloud resource (e.g. an EC2 instance, a GCS bucket) affected by the insight, along with its risk scores or potential savings. - [Retrieve an insight](https://developer.doit.com/reference/getinsightresult.md): Returns the metadata and aggregate summary for a single insight identified by source and key. Does not include individual resource-level results — use the resource-results endpoint for those. - [Create or update an insight](https://developer.doit.com/reference/postinsightresult.md): Creates or updates a single insight for the given source and key. If an insight with the same key already exists for the source, it will be updated. Resource results are managed separately via the resource-results endpoint. - [Delete an insight](https://developer.doit.com/reference/deleteinsightresult.md): Permanently deletes a single insight and all its associated resource results. Only insights created via the public API can be deleted. - [Replace resource results for an insight](https://developer.doit.com/reference/postinsightresourceresults.md): Replaces all resource results for the specified insight. Any existing unresolved resource results not present in the new set will be removed. The response includes server-computed fields (severity, resolved, enhancement) for each resource result. To delete all resource results, send an empty array. - [Ask Ava (streaming)](https://developer.doit.com/reference/askavastreaming.md): Send a question to Ava and receive a streaming response via Server-Sent Events (SSE). The response streams back events containing the answer text, conversation ID, and message metadata. - [Ask Ava](https://developer.doit.com/reference/askavasync.md): Send a question to Ava and receive a synchronous response. Set `ephemeral` to `true` to skip conversation persistence (recommended for programmatic consumers). When `ephemeral` is `false` (default), the response includes a `conversationId` that can be used with the delete endpoint. - [Submit feedback](https://developer.doit.com/reference/avafeedback.md): Submit feedback on an Ava answer to help improve response quality. - [Delete a conversation](https://developer.doit.com/reference/deleteavaconversation.md): Deletes an Ava conversation by its ID. - [Get supported features for a connected account](https://developer.doit.com/reference/getcloudconnectsupportedfeatures.md): Returns the list of supported features and their permission status for a cloud account connected via CloudConnect. The account must belong to the authenticated customer. Supports AWS and Azure accounts. - [Create or update an AWS account role](https://developer.doit.com/reference/createaccountrole.md): Creates or updates a CloudConnect document for an AWS account. Unlike the CloudFormation variant, this endpoint does not update Firestore channel documents or require a CloudFormation stack ID. - [Get an AWS account](https://developer.doit.com/reference/getawsaccount.md): Returns the current state of an AWS account including role, supported features, and optional S3 bucket configuration. - [Delete an AWS account role](https://developer.doit.com/reference/deleteaccountrole.md): Deletes a CloudConnect document for an AWS account. - [Update an AWS feature](https://developer.doit.com/reference/updateawsfeature.md): Updates an AWS feature for an existing CloudConnect account. Unlike the CloudFormation variant, this endpoint does not update Firestore channel documents, require a CloudFormation stack ID, or handle StackSet member role ARNs. - [List service quotas](https://developer.doit.com/reference/listservicequotas.md): Returns the latest service quota usage snapshots collected by DoiT for the authenticated customer. Results include only quotas retained by DoiT's monitoring collectors and are not a complete or live inventory from the cloud providers. Results are sorted by utilization percentage in descending order. - [Create reseller handshakes (batch)](https://developer.doit.com/reference/createbillingtransferresellerhandshakes.md): Maps reseller to distributor; also sends the handshake if required, as part of AWS billing transfer onboarding. Distributor-only; callers without the ChannelOps distributor tier entitlement receive `403`. Each item in the batch is processed independently; per-item outcomes are returned in `results[]` with HTTP `200` even when some items fail. Malformed items (missing fields, duplicate `resellerPmaAccountId` within the batch) are rejected up front with `422` and reported in `invalidItems`, and none of the batch is processed in that case. - [List program management accounts](https://developer.doit.com/reference/listbillingtransferprogrammanagementaccounts.md): Lists the caller's program management accounts (PMAs) and the reseller tenants mapped to each one, including AWS Organizations handshake status per account. Distributor-only. - [Create end-customer mappings (batch)](https://developer.doit.com/reference/createbillingtransferendcustomermappings.md): Maps end-customer AWS accounts under a reseller's PMA to their DoiT tenant, as part of AWS billing transfer onboarding. Reseller-only; distributors are explicitly denied (`403`). Unlike `POST /billingtransfer/v1/resellerhandshakes`, this endpoint has no `Idempotency-Key` requirement and no `dryRun` support. This path is a deliberate exception to the de-hyphenation convention used by the sibling `resellerhandshakes` and `programmanagementaccounts` paths — it stays hyphenated to match the existing Go route and its console-facing equivalent. Each item in the batch is processed independently; per-item outcomes are returned in `results[]` with HTTP `200`. Malformed items are rejected up front and reported in `invalidItems` without processing any of the batch. - [Get program management account status](https://developer.doit.com/reference/getbillingtransferprogrammanagementaccountsstatus.md): Lightweight polling surface for the onboarding wizard: returns each of the caller's PMAs with only its IAM status/diff and timestamps — no tenant fan-out, no handshake aggregation, no pagination. Distributor-only. - [List end-customers under a reseller PMA](https://developer.doit.com/reference/listbillingtransferendcustomers.md): Lists the end-customer AWS account mappings under a reseller's program management account, identified by `dpmaId` and `resellerPmaAccountId`. Callable by the reseller who owns the PMA or the distributor who owns the DPMA. - [List end-customers under a reseller PMA, by reseller PMA alone](https://developer.doit.com/reference/listbillingtransferendcustomersbyreseller.md): Same result as `GET /billingtransfer/v1/end-customers`, identified by `resellerPmaAccountId` alone (no `dpmaId` needed). Callable by the reseller who owns the PMA or the distributor who owns its DPMA. - [List the caller's reseller PMA nodes](https://developer.doit.com/reference/listbillingtransferreselleraccounts.md): Lists every reseller program management account (RPMA) node belonging to the calling reseller, with handshake state and status but without end-customer tenants — the reseller-tier analog of `GET /billingtransfer/v1/programmanagementaccounts`. - [List the caller's reseller PMA nodes with their end-customer tenants](https://developer.doit.com/reference/listbillingtransferreselleraccountswithtenants.md): Lists every reseller PMA node belonging to the calling reseller, each with the end-customer tenants connected under it — the reseller-tier analog of `GET /billingtransfer/v1/programmanagementaccounts`. `region`, `iamStatus` and `lastRefreshTime` are inherited from the parent DPMA root; the reseller node itself carries no IAM/region metadata of its own. - [List contracts](https://developer.doit.com/reference/listcontracts.md): Lists the contracts held by the specified customer. Callable by a T1/T2 PartnerOps principal for its own tenant or any descendant tenant. Read access requires contractsReadOnly, contractsViewer, or a write-capable role (without contractsReadOnly). User API tokens must include the matching permission in their scope. - [Create contract](https://developer.doit.com/reference/createcontract.md): Creates a draft contract for the specified customer. Requires the caller to be the direct parent (T1 for a T2-level contract, T2 for a T3-level contract). Write access requires a role without contractsReadOnly; user API tokens must include the matching permission in their scope. - [Retrieve a contract](https://developer.doit.com/reference/getcontract.md): Returns the specified contract. - [Update contract](https://developer.doit.com/reference/updatecontract.md): Creates a new version of the contract. The contract type is immutable and cannot be changed by an update. - [Activate contract](https://developer.doit.com/reference/activatecontract.md): Transitions a draft contract to active or scheduled (when the start date is in the future). Produces the same system state as activating via the Console. - [Cancel contract](https://developer.doit.com/reference/cancelcontract.md): Cancels (deactivates) a contract. Active contracts cannot be deleted; cancel is the terminal operation. - [List contract templates](https://developer.doit.com/reference/listcontracttemplates.md): Lists contract templates owned by the authenticated tenant (from the bearer token). Requires ContractTemplatesAdmin, DoiT API access (`platform:externalApi`), and the `channelops:contracts:templates` entitlement. - [Create contract template](https://developer.doit.com/reference/createcontracttemplate.md): Creates a contract template for the authenticated tenant (from the bearer token). Requires ContractTemplatesAdmin, DoiT API access (`platform:externalApi`), and the `channelops:contracts:templates` entitlement. - [Get contract template](https://developer.doit.com/reference/getcontracttemplate.md): Returns a single contract template owned by the authenticated tenant (from the bearer token). Requires ContractTemplatesAdmin, DoiT API access (`platform:externalApi`), and the `channelops:contracts:templates` entitlement. - [Update contract template](https://developer.doit.com/reference/updatecontracttemplate.md): Updates a contract template owned by the authenticated tenant (from the bearer token). Requires ContractTemplatesAdmin, DoiT API access (`platform:externalApi`), and the `channelops:contracts:templates` entitlement. - [Archive contract template](https://developer.doit.com/reference/archivecontracttemplate.md): Soft-deletes (archives) a contract template owned by the authenticated tenant (from the bearer token). Instantiated contracts are unaffected. Requires ContractTemplatesAdmin, DoiT API access (`platform:externalApi`), and the `channelops:contracts:templates` entitlement. - [List AWS organizations](https://developer.doit.com/reference/listawsorganizations.md): Returns all AWS Organizations accessible to the authenticated tenant. Each item includes metadata, trailing 30-day aggregate statistics, precomputed YTD/lifetime savings totals per SP type so customer-level savings can be aggregated client-side by summing across organizations, and estimated monthly potential savings (`monthlyPotentialSavings`) per SP type from the latest projection. - [Get an AWS organization](https://developer.doit.com/reference/getawsorganization.md): Returns a single AWS Organization including metadata, 30-day aggregates, and the trailing-window stats that drive the customer Overview screen: - `monthlyStats` — last 6 calendar months (ESR, on-demand cost, cost with savings). - `dailyCoverage` — last 30 days of commitment coverage breakdown. - `savingsTotals` — year-to-date and lifetime savings per SP type. - `monthlyPotentialSavings` — estimated monthly additional savings per SP type from the latest projection. - [List member accounts under an organization](https://developer.doit.com/reference/listawsmemberaccounts.md): Returns all member AWS accounts under the specified organization that have active or historical commitment coverage. Includes 30-day statistics and estimated monthly potential savings (`monthlyPotentialSavings`) per SP type. - [Get a member account](https://developer.doit.com/reference/getawsmemberaccount.md): Returns a single member AWS account including 30-day aggregates and the trailing-window stats that drive the member-account Overview view: - `monthlyStats` — last 6 calendar months per SP type. - `dailyCoverage` — last 30 days of commitment coverage breakdown. - `savingsTotals` — year-to-date and lifetime savings per SP type, clamped to the parent organization's onboarding start. - `monthlyPotentialSavings` — estimated monthly additional savings per SP type, attributed from the parent organization's projection. - [List AWS Savings Plans](https://developer.doit.com/reference/listawssavingsplans.md): Returns the paginated list of Savings Plans for the specified organization. Filterable by plan type and state. - [List AWS Reserved Instances](https://developer.doit.com/reference/listawsreservedinstances.md): Returns the paginated list of Reserved Instances (RIs) for the specified organization. Filterable by state, instance type/family, region, and offering class. - [List organization engine settings](https://developer.doit.com/reference/listawsorganizationssettings.md): Returns automation and recommendation engine settings for every onboarded organization, broken down by product line (`compute`, `database`). Settings are configured at the customer level and apply uniformly across all organizations. Only product lines that are activated/onboarded for a given organization are returned. The `purchaseAccountId` is the member AWS account designated to execute SP purchases on behalf of that organization. - [List AWS recommendations](https://developer.doit.com/reference/listawsrecommendations.md): Returns commitment purchase recommendations for the organization. Multiple recommendations may exist per organization (one per service). - [Get an AWS recommendation](https://developer.doit.com/reference/getawsrecommendation.md): Returns full detail for a single recommendation including analysis metrics. - [List AWS planned purchases](https://developer.doit.com/reference/listawsplannedpurchases.md): Returns the laddering projections for the organization — one item per available `purchases-projection` document (typically `compute` and/or `database`; up to four product lines as PS4C expands). With no filters, returns all existing projection documents for the organization in stable product-line order (`compute`, then `database`, then any future lines in enum order). When a filtered product line has no projection document, the response is an empty `items` array (not `404`). Partial projection documents return only the fields available in storage. `404` is returned only when the organization does not exist or the caller cannot access it. An organization that is not onboarded for PS4C still returns `200` with an empty `items` array when no projection documents exist — use `GET /ps4commitments/v1/aws/organizations` (or get-by-id) for `onboardingStatus`. **Pagination**: results are returned in stable product-line order (`compute`, then `database`, then any future lines in enum order). Use `maxResults` to limit page size (default 50, max 500). When more items remain, the response includes a non-null `pageToken`; pass it unchanged on the next request with the same query parameters (`service`, `maxResults`). `rowCount` is the number of items in this page. An invalid `pageToken` returns `400` with code `pagination_token_invalid`; an expired token returns `400` with code `pagination_token_expired`. - [List available platforms](https://developer.doit.com/reference/listplatforms.md): Returns a list of all the available platforms. - [List available products](https://developer.doit.com/reference/listproducts.md): Returns a list of all the available products of specific platforms. - [Update a request](https://developer.doit.com/reference/idofticketupdate.md): Partially updates a support request. Supports setting the request `status` and/or `assignee`. DoiT employees may set any of `open`, `pending`, `hold`, or `solved` and may set the `assignee`; customers may set only `solved` (parity with the console "mark as resolved" action) and may not set an assignee. `closed` is not settable via the API (Zendesk auto-closes from `solved`). The `assignee` is a DoiT-employee email, resolved server-side to a Zendesk agent; an email that does not resolve to an active agent returns `400`. At least one mutable field must be present. The response echoes the fields that were applied. - [List requests](https://developer.doit.com/reference/idoftickets.md): Returns a list of all historical requests that your account has access to. Tickets are returned in reverse chronological order by default. - [Create a request](https://developer.doit.com/reference/idofticketspost.md): Creates a new support request - [Get a request](https://developer.doit.com/reference/idofticketget.md): Returns the details of a single support request by its ID. - [List request comments](https://developer.doit.com/reference/idofticketcommentslist.md): Returns all comments on a support request. For customers, only public comments are returned. For DoiT employees, both public and private comments are returned. All comments are returned in a single response (no pagination). - [Add a comment](https://developer.doit.com/reference/idofticketcommentspost.md): Adds a comment to an existing support request. For customers, comments are always public. For DoiT employees, comments can be marked as private (internal notes) by setting the `private` field to `true`. - [Add tags to a support request](https://developer.doit.com/reference/idoftickettagsadd.md): Adds one or more tags to an existing support request. The operation is surgical — only the tags listed in the request are added; existing tags on the ticket are preserved. Re-adding a tag that is already present is a successful no-op. All submitted tags are normalized (trim + lowercase) before storage. For customers, the system additionally applies a `customer_tag/` namespace prefix to prevent collisions with internal DoiT process tags. The response echoes the actual stored strings so callers can verify the transform. - [Remove tags from a support request](https://developer.doit.com/reference/idoftickettagsremove.md): Removes one or more tags from an existing support request. The operation is surgical — only the tags listed in the request are removed; tags not listed are preserved. Removing a tag that is not present is a successful no-op. For customers, the system applies the same `customer_tag/` namespace mapping as on add, so a customer who added `my_tag` (stored as `customer_tag/my_tag`) can remove it by sending `my_tag`. - [List tags on a support request](https://developer.doit.com/reference/listtickettags.md): Returns the tags currently set on a support request. DoiT employee (doer) callers receive the full tag set verbatim, including internal namespaces (e.g. `tier/*`, `synapse_*`). Customer callers receive only tags under the `customer_tag/` namespace, with that prefix stripped (e.g. a tag added as `billing` reads back as `billing`). Always present; empty array when the caller has no visible tags. - [Validate a user](https://developer.doit.com/reference/validate.md): Returns the domain and email of the current API user. - [List account team](https://developer.doit.com/reference/listaccountteam.md): Returns a list of all DoiT account managers assigned to your organization. ## Changelog - [Support Requests error codes](https://developer.doit.com/changelog/support-requests-error-codes.md) - [Actual and expected max cost on anomaly responses](https://developer.doit.com/changelog/actual-and-expected-max-cost-on-anomaly-responses.md) - [Build a CloudFlow from scratch](https://developer.doit.com/changelog/build-a-cloudflow-from-scratch.md) - [Contract Templates](https://developer.doit.com/changelog/contract-templates.md) - [CloudAnalytics report features](https://developer.doit.com/changelog/cloudanalytics-report-features.md) - [Support request tags and status](https://developer.doit.com/changelog/update-status-of-support-request.md) - [PartnerOps Contract endpoint](https://developer.doit.com/changelog/partnerops-contract-endpoint.md) - [Result array required for create/update Insights](https://developer.doit.com/changelog/result-array-required-for-createupdate-insights.md) - [CloudFlow Endpoints](https://developer.doit.com/changelog/cloudflow-endpoint.md) - [Cloud Analytics: report display settings and active theme API](https://developer.doit.com/changelog/cloud-analytics-report-display-settings-and-active-theme-api.md)