openapi: 3.2.0 info: description: 'The Grafana backend exposes an HTTP API, the same API is used by the frontend to do everything from saving dashboards, creating users and updating data sources.' title: Grafana HTTP API. Enterprise API contact: name: Grafana Labs url: https://grafana.com email: hello@grafana.com version: 0.0.1 servers: - url: /api security: - basic: [] - api_key: [] tags: - description: These are only available in Grafana Enterprise name: Enterprise paths: /access-control/roles: get: description: 'Gets all existing roles. The response contains all global and organization local roles, for the organization which user is signed in. You need to have a permission with action `roles:read` and scope `roles:*`. The `delegatable` flag reduces the set of roles to only those for which the signed-in user has permissions to assign.' tags: - Enterprise summary: Get all roles operationId: listRoles parameters: - name: delegatable in: query schema: type: boolean - name: includeHidden in: query schema: type: boolean - name: targetOrgId in: query schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/listRolesResponse' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' post: description: 'Creates a new custom role and maps given permissions to that role. Note that roles with the same prefix as Fixed Roles can’t be created. You need to have a permission with action `roles:write` and scope `permissions:type:delegate`. `permissions:type:delegate` scope ensures that users can only create custom roles with the same, or a subset of permissions which the user has. For example, if a user does not have required permissions for creating users, they won’t be able to create a custom role which allows to do that. This is done to prevent escalation of privileges.' tags: - Enterprise summary: Create a new custom role operationId: createRole responses: '201': $ref: '#/components/responses/createRoleResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateRoleForm' required: true /access-control/roles/{roleUID}: get: description: 'Get a role for the given UID. You need to have a permission with action `roles:read` and scope `roles:*`.' tags: - Enterprise summary: Get a role operationId: getRole parameters: - name: roleUID in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/getRoleResponse' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' put: description: You need to have a permission with action `roles:write` and scope `permissions:type:delegate`. `permissions:type:delegate` scope ensures that users can only update custom roles with permissions which the user has. tags: - Enterprise summary: Update a custom role operationId: updateRole parameters: - name: roleUID in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/getRoleResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/UpdateRoleCommand' required: true delete: description: 'Delete a role with the given UID, and it’s permissions. If the role is assigned to a built-in role, the deletion operation will fail, unless force query param is set to true, and in that case all assignments will also be deleted. You need to have a permission with action `roles:delete` and scope `permissions:type:delegate`.' tags: - Enterprise summary: Delete a custom role operationId: deleteRole parameters: - name: force in: query schema: type: boolean - name: global in: query schema: type: boolean - name: roleUID in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' /access-control/roles/{roleUID}/assignments: get: description: 'Get role assignments for the role with the given UID. Does not include role assignments mapped through group attribute sync. You need to have a permission with action `teams.roles:list` and scope `teams:id:*` and `users.roles:list` and scope `users:id:*`.' tags: - Enterprise summary: Get role assignments operationId: getRoleAssignments parameters: - name: roleUID in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/getRoleAssignmentsResponse' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' put: description: 'Set role assignments for the role with the given UID. You need to have a permission with action `teams.roles:add` and `teams.roles:remove` and scope `permissions:type:delegate`, and `users.roles:add` and `users.roles:remove` and scope `permissions:type:delegate`.' tags: - Enterprise summary: Set role assignments operationId: setRoleAssignments parameters: - name: roleUID in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/setRoleAssignmentsResponse' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/SetRoleAssignmentsCommand' required: true /access-control/status: get: description: 'Returns an indicator to check if fine-grained access control is enabled or not. You need to have a permission with action `status:accesscontrol` and scope `services:accesscontrol`.' tags: - Enterprise summary: Get status operationId: getAccessControlStatus responses: '200': $ref: '#/components/responses/getAccessControlStatusResponse' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' /access-control/teams/roles/search: post: description: 'Lists the roles that have been directly assigned to the given teams. You need to have a permission with action `teams.roles:read` and scope `teams:id:*`.' tags: - Enterprise summary: List roles assigned to multiple teams operationId: listTeamsRoles responses: '200': $ref: '#/components/responses/listTeamsRolesResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/RolesSearchQuery' required: true /access-control/teams/{teamId}/roles: get: description: You need to have a permission with action `teams.roles:read` and scope `teams:id:`. tags: - Enterprise summary: Get team roles operationId: listTeamRoles parameters: - name: teamId in: path required: true schema: type: integer format: int64 - name: targetOrgId in: query schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' put: description: You need to have a permission with action `teams.roles:add` and `teams.roles:remove` and scope `permissions:type:delegate` for each. The delegate scope is required for permissions on roles being added. tags: - Enterprise summary: Update team role operationId: setTeamRoles parameters: - name: teamId in: path required: true schema: type: integer format: int64 - name: targetOrgId in: query schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/SetTeamRolesCommand' required: true post: description: You need to have a permission with action `teams.roles:add` and scope `permissions:type:delegate`. tags: - Enterprise summary: Add team role operationId: addTeamRole parameters: - name: teamId in: path required: true schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/AddTeamRoleCommand' required: true /access-control/teams/{teamId}/roles/{roleUID}: delete: description: You need to have a permission with action `teams.roles:remove` and scope `permissions:type:delegate`. tags: - Enterprise summary: Remove team role operationId: removeTeamRole parameters: - name: roleUID in: path required: true schema: type: string - name: teamId in: path required: true schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' /access-control/users/roles/search: post: description: 'Lists the roles that have been directly assigned to the given users. The list does not include built-in roles (Viewer, Editor, Admin or Grafana Admin), and it does not include roles that have been inherited from a team. You need to have a permission with action `users.roles:read` and scope `users:id:*`.' tags: - Enterprise summary: List roles assigned to multiple users operationId: listUsersRoles responses: '200': $ref: '#/components/responses/listUsersRolesResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/RolesSearchQuery' required: true /access-control/users/{userId}/roles: get: description: 'Lists the roles that have been directly assigned to a given user. The list does not include built-in roles (Viewer, Editor, Admin or Grafana Admin), and it does not include roles that have been inherited from a team. You need to have a permission with action `users.roles:read` and scope `users:id:`.' tags: - Enterprise summary: List roles assigned to a user operationId: listUserRoles parameters: - name: userId in: path required: true schema: type: integer format: int64 - name: includeHidden in: query schema: type: boolean - name: targetOrgId in: query schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/getAllRolesResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' put: description: 'Update the user’s role assignments to match the provided set of UIDs. This will remove any assigned roles that aren’t in the request and add roles that are in the set but are not already assigned to the user. Roles mapped through group attribute sync are not impacted. If you want to add or remove a single role, consider using Add a user role assignment or Remove a user role assignment instead. You need to have a permission with action `users.roles:add` and `users.roles:remove` and scope `permissions:type:delegate` for each. The delegate scope is required for permissions on roles being added.' tags: - Enterprise summary: Set user role assignments operationId: setUserRoles parameters: - name: userId in: path required: true schema: type: integer format: int64 - name: targetOrgId in: query schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/SetUserRolesCommand' required: true post: description: 'Assign a role to a specific user. For bulk updates consider Set user role assignments. You need to have a permission with action `users.roles:add` and scope `permissions:type:delegate`. `permissions:type:delegate` scope ensures that users can only assign roles which have same, or a subset of permissions which the user has. For example, if a user does not have required permissions for creating users, they won’t be able to assign a role which will allow to do that. This is done to prevent escalation of privileges.' tags: - Enterprise summary: Add a user role assignment operationId: addUserRole parameters: - name: userId in: path required: true schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/okResponse' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/AddUserRoleCommand' required: true /access-control/users/{userId}/roles/{roleUID}: delete: description: 'Revoke a role from a user. For bulk updates consider Set user role assignments. You need to have a permission with action `users.roles:remove` and scope `permissions:type:delegate`.' tags: - Enterprise summary: Remove a user role assignment operationId: removeUserRole parameters: - description: A flag indicating if the assignment is global or not. If set to false, the default org ID of the authenticated user will be used from the request to remove assignment. name: global in: query schema: type: boolean - name: roleUID in: path required: true schema: type: string - name: userId in: path required: true schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' /admin/ldap-sync-status: get: description: You need to have a permission with action `ldap.status:read`. tags: - Enterprise summary: Returns the current state of the LDAP background sync integration operationId: getSyncStatus responses: '200': $ref: '#/components/responses/getSyncStatusResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' /admin/provisioning/access-control/reload: post: tags: - Enterprise summary: You need to have a permission with action `provisioning:reload` with scope… operationId: adminProvisioningReloadAccessControl responses: '202': $ref: '#/components/responses/acceptedResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' /datasources/uid/{uid}/lbac/teams: get: tags: - Enterprise summary: Retrieves LBAC rules for a team operationId: getTeamLBACRulesApi parameters: - name: uid in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/getTeamLBACRulesResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' put: tags: - Enterprise summary: Updates LBAC rules for a team operationId: updateTeamLBACRulesApi parameters: - name: uid in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/updateTeamLBACRulesResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/UpdateTeamLBACCommand' /datasources/{dataSourceUID}/cache: get: description: get cache config for a single data source tags: - Enterprise operationId: getDataSourceCacheConfig parameters: - name: dataSourceUID in: path required: true schema: type: string - description: Optional datasource type used to disambiguate datasource UID lookups. name: dataSourceType in: query schema: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/CacheConfigResponse' '500': $ref: '#/components/responses/internalServerError' summary: Get data source cache config x-summary-source: derived post: description: set cache config for a single data source tags: - Enterprise operationId: setDataSourceCacheConfig parameters: - name: dataSourceUID in: path required: true schema: type: string - description: Optional datasource type used to disambiguate datasource UID lookups. name: dataSourceType in: query schema: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/CacheConfigResponse' '400': $ref: '#/components/responses/badRequestError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/CacheConfigSetter' required: true summary: Set data source cache config x-summary-source: derived /datasources/{dataSourceUID}/cache/clean: post: description: clean cache for a single data source tags: - Enterprise operationId: cleanDataSourceCache parameters: - name: dataSourceUID in: path required: true schema: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/CacheConfigResponse' '500': $ref: '#/components/responses/internalServerError' summary: Clean data source cache x-summary-source: derived /datasources/{dataSourceUID}/cache/disable: post: description: disable cache for a single data source tags: - Enterprise operationId: disableDataSourceCache parameters: - name: dataSourceUID in: path required: true schema: type: string - description: Optional datasource type used to disambiguate datasource UID lookups. name: dataSourceType in: query schema: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/CacheConfigResponse' '500': $ref: '#/components/responses/internalServerError' summary: Disable data source cache x-summary-source: derived /datasources/{dataSourceUID}/cache/enable: post: description: enable cache for a single data source tags: - Enterprise operationId: enableDataSourceCache parameters: - name: dataSourceUID in: path required: true schema: type: string - description: Optional datasource type used to disambiguate datasource UID lookups. name: dataSourceType in: query schema: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/CacheConfigResponse' '500': $ref: '#/components/responses/internalServerError' summary: Enable data source cache x-summary-source: derived /licensing/check: get: tags: - Enterprise summary: Check license availability operationId: getStatus responses: '200': $ref: '#/components/responses/getStatusResponse' /licensing/custom-permissions: get: description: 'You need to have a permission with action `licensing.reports:read`. Deprecated. There is currently no replacement for this endpoint. Please reach out to Grafana support if you rely on this endpoint.' tags: - Enterprise summary: Get custom permissions report operationId: getCustomPermissionsReport deprecated: true responses: '500': $ref: '#/components/responses/internalServerError' /licensing/custom-permissions-csv: get: description: 'You need to have a permission with action `licensing.reports:read`. Deprecated. There is currently no replacement for this endpoint. Please reach out to Grafana support if you rely on this endpoint.' tags: - Enterprise summary: Get custom permissions report in CSV format operationId: getCustomPermissionsCSV deprecated: true responses: '500': $ref: '#/components/responses/internalServerError' /licensing/refresh-stats: get: description: You need to have a permission with action `licensing:read`. tags: - Enterprise summary: Refresh license stats operationId: refreshLicenseStats responses: '200': $ref: '#/components/responses/refreshLicenseStatsResponse' '500': $ref: '#/components/responses/internalServerError' /licensing/token: get: description: You need to have a permission with action `licensing:read`. tags: - Enterprise summary: Get license token operationId: getLicenseToken responses: '200': $ref: '#/components/responses/getLicenseTokenResponse' post: description: You need to have a permission with action `licensing:write`. tags: - Enterprise summary: Create license token operationId: postLicenseToken responses: '200': $ref: '#/components/responses/getLicenseTokenResponse' '400': $ref: '#/components/responses/badRequestError' requestBody: content: application/json: schema: $ref: '#/components/schemas/DeleteTokenCommand' required: true delete: description: 'Removes the license stored in the Grafana database. Available in Grafana Enterprise v7.4+. You need to have a permission with action `licensing:delete`.' tags: - Enterprise summary: Remove license from database operationId: deleteLicenseToken responses: '202': $ref: '#/components/responses/acceptedResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '422': $ref: '#/components/responses/unprocessableEntityError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/DeleteTokenCommand' required: true /licensing/token/renew: post: description: 'Manually ask license issuer for a new token. Available in Grafana Enterprise v7.4+. You need to have a permission with action `licensing:write`.' tags: - Enterprise summary: Manually force license refresh operationId: postRenewLicenseToken responses: '200': $ref: '#/components/responses/postRenewLicenseTokenResponse' '401': $ref: '#/components/responses/unauthorisedError' '404': $ref: '#/components/responses/notFoundError' requestBody: content: application/json: schema: type: object required: true /logout/saml: get: tags: - Enterprise summary: GetLogout initiates single logout process operationId: getSAMLLogout responses: '302': description: (empty) '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' /recording-rules: get: tags: - Enterprise summary: 'Lists all rules in the database: active or deleted' operationId: listRecordingRules responses: '200': $ref: '#/components/responses/listRecordingRulesResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' put: tags: - Enterprise summary: Update the active status of a rule operationId: updateRecordingRule responses: '200': $ref: '#/components/responses/recordingRuleResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/RecordingRuleJSON' required: true post: tags: - Enterprise summary: Create a recording rule that is then registered and started operationId: createRecordingRule responses: '200': $ref: '#/components/responses/recordingRuleResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/RecordingRuleJSON' required: true /recording-rules/test: post: tags: - Enterprise summary: Test a recording rule operationId: testCreateRecordingRule responses: '200': $ref: '#/components/responses/okResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '422': $ref: '#/components/responses/unprocessableEntityError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/RecordingRuleJSON' required: true /recording-rules/writer: get: tags: - Enterprise summary: Return the prometheus remote write target operationId: getRecordingRuleWriteTarget responses: '200': $ref: '#/components/responses/recordingRuleWriteTargetResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' post: description: It returns a 422 if there is not an existing prometheus data source configured. tags: - Enterprise summary: Create a remote write target operationId: createRecordingRuleWriteTarget responses: '200': $ref: '#/components/responses/recordingRuleWriteTargetResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '422': $ref: '#/components/responses/unprocessableEntityError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/PrometheusRemoteWriteTargetJSON' required: true delete: tags: - Enterprise summary: Delete the remote write target operationId: deleteRecordingRuleWriteTarget responses: '200': $ref: '#/components/responses/okResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' /recording-rules/{recordingRuleID}: delete: tags: - Enterprise summary: Delete removes the rule from the registry and stops it operationId: deleteRecordingRule parameters: - name: recordingRuleID in: path required: true schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/okResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' /reports: get: description: 'Available to org admins only and with a valid or expired license. You need to have a permission with action `reports:read` with scope `reports:*`.' tags: - Enterprise summary: List reports operationId: getReports responses: '200': $ref: '#/components/responses/getReportsResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' post: description: 'Available to org admins only and with a valid license. You need to have a permission with action `reports.admin:create`.' tags: - Enterprise summary: Create a report operationId: createReport responses: '200': $ref: '#/components/responses/createReportResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateOrUpdateReport' required: true /reports/dashboards/{uid}: get: description: 'Available to org admins only and with a valid or expired license. You need to have a permission with action `reports:read` with scope `reports:*`.' tags: - Enterprise summary: List reports by dashboard uid operationId: getReportsByDashboardUID parameters: - name: uid in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/getReportsResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' /reports/email: post: description: 'Generate and send a report. This API waits for the report to be generated before returning. We recommend that you set the client’s timeout to at least 60 seconds. Available to org admins only and with a valid license. Only available in Grafana Enterprise v7.0+. This API endpoint is experimental and may be deprecated in a future release. On deprecation, a migration strategy will be provided and the endpoint will remain functional until the next major release of Grafana. You need to have a permission with action `reports:send`.' tags: - Enterprise summary: Send a report operationId: sendReport responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/ReportEmail' required: true /reports/images/:image: get: description: 'Available to org admins only and with a valid or expired license. You need to have a permission with action `reports.settings:read`.' tags: - Enterprise summary: Get custom branding report image operationId: getSettingsImage responses: '200': $ref: '#/components/responses/contentResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' /reports/render/csvs: get: description: Available to all users and with a valid license. tags: - Enterprise summary: Download a CSV report operationId: renderReportCSVs parameters: - name: dashboards in: query schema: type: string - name: title in: query schema: type: string responses: '200': $ref: '#/components/responses/contentResponse' '204': $ref: '#/components/responses/noContentResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '500': $ref: '#/components/responses/internalServerError' /reports/render/pdfs: get: description: Available to all users and with a valid license. tags: - Enterprise summary: Render report for multiple dashboards operationId: renderReportPDFs parameters: - name: dashboards in: query schema: type: string - name: orientation in: query schema: type: string - name: layout in: query schema: type: string - name: title in: query schema: type: string - name: scaleFactor in: query schema: type: string - name: includeTables in: query schema: type: string responses: '200': $ref: '#/components/responses/contentResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '500': $ref: '#/components/responses/internalServerError' /reports/settings: get: description: 'Available to org admins only and with a valid or expired license. You need to have a permission with action `reports.settings:read`x.' tags: - Enterprise summary: Get report settings operationId: getReportSettings responses: '200': $ref: '#/components/responses/getReportSettingsResponse' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' post: description: 'Available to org admins only and with a valid or expired license. You need to have a permission with action `reports.settings:write`xx.' tags: - Enterprise summary: Save settings operationId: saveReportSettings responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/ReportSettings' required: true /reports/test-email: post: description: 'Available to org admins only and with a valid license. You need to have a permission with action `reports:send`.' tags: - Enterprise summary: Send test report via email operationId: sendTestEmail responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateOrUpdateReport' required: true /reports/{id}: get: description: 'Available to org admins only and with a valid or expired license. You need to have a permission with action `reports:read` with scope `reports:id:`. Requesting reports using the internal id will stop workgin in the future Use the reporting apiserver to manage reports. See: /apis/reporting.grafana.app/' tags: - Enterprise summary: Get a report operationId: getReport deprecated: true parameters: - name: id in: path required: true schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/getReportResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' put: description: 'Available to org admins only and with a valid or expired license. You need to have a permission with action `reports.admin:write` with scope `reports:id:`. Requesting reports using the internal id will stop workgin in the future Use the reporting apiserver to manage reports. See: /apis/reporting.grafana.app/' tags: - Enterprise summary: Update a report operationId: updateReport deprecated: true parameters: - name: id in: path required: true schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateOrUpdateReport' required: true delete: description: 'Available to org admins only and with a valid or expired license. You need to have a permission with action `reports.delete` with scope `reports:id:`. Requesting reports using the internal id will stop workgin in the future Use the reporting apiserver to manage reports. See: /apis/reporting.grafana.app/' tags: - Enterprise summary: Delete a report operationId: deleteReport deprecated: true parameters: - name: id in: path required: true schema: type: integer format: int64 responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' /saml/acs: post: tags: - Enterprise summary: It performs Assertion Consumer Service (ACS) operationId: postACS parameters: - name: RelayState in: query schema: type: string responses: '302': description: (empty) '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' /saml/metadata: get: tags: - Enterprise summary: It exposes the SP (Grafana's) metadata for the IdP's consumption operationId: getMetadata responses: '200': $ref: '#/components/responses/contentResponse' /saml/slo: get: description: 'There might be two possible requests: 1. Logout response (callback) when Grafana initiates single logout and IdP returns response to logout request. 2. Logout request when another SP initiates single logout and IdP sends logout request to the Grafana, or in case of IdP-initiated logout.' tags: - Enterprise summary: It performs Single Logout (SLO) callback operationId: getSLO responses: '302': description: (empty) '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' post: description: 'There might be two possible requests: 1. Logout response (callback) when Grafana initiates single logout and IdP returns response to logout request. 2. Logout request when another SP initiates single logout and IdP sends logout request to the Grafana, or in case of IdP-initiated logout.' tags: - Enterprise summary: It performs Single Logout (SLO) callback operationId: postSLO parameters: - name: SAMLRequest in: query schema: type: string - name: SAMLResponse in: query schema: type: string responses: '302': description: (empty) '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' /teams/{teamId}/groups: get: tags: - Enterprise summary: Get External Groups operationId: getTeamGroupsApi parameters: - name: teamId in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/getTeamGroupsApiResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' post: tags: - Enterprise summary: Add External Group operationId: addTeamGroupApi parameters: - name: teamId in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' requestBody: content: application/json: schema: $ref: '#/components/schemas/TeamGroupMapping' required: true delete: tags: - Enterprise summary: Remove External Group operationId: removeTeamGroupApiQuery parameters: - name: groupId in: query schema: type: string - name: teamId in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/okResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' /teams/{teamId}/groups/search: get: tags: - Enterprise summary: Search for team groups with optional filtering and pagination operationId: searchTeamGroups parameters: - name: teamId in: path required: true schema: type: integer format: int64 - name: page in: query schema: type: integer format: int64 default: 1 - description: Number of items per page name: perpage in: query schema: type: integer format: int64 default: 1000 - description: If set it will return results where the query value is contained in the name field. Query values with spaces need to be URL encoded. name: query in: query schema: type: string - description: Filter by exact name match name: name in: query schema: type: string responses: '200': $ref: '#/components/responses/searchTeamGroupsResponse' '400': $ref: '#/components/responses/badRequestError' '401': $ref: '#/components/responses/unauthorisedError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' components: schemas: PrometheusRemoteWriteTargetJSON: type: object properties: data_source_uid: type: string id: type: string remote_write_path: type: string Duration: description: 'A Duration represents the elapsed time between two instants as an int64 nanosecond count. The representation limits the largest representable duration to approximately 290 years.' type: integer format: int64 SetUserRolesCommand: type: object properties: global: type: boolean includeHidden: type: boolean roleUids: type: array items: type: string ErrorResponseBody: type: object required: - message properties: error: description: Error An optional detailed description of the actual error. Only included if running in developer mode. type: string message: description: a human readable version of the error type: string status: description: 'Status An optional status to denote the cause of the error. For example, a 412 Precondition Failed error may include additional information of why that error happened.' type: string TokenStatus: type: integer format: int64 UpdateTeamLBACCommand: type: object properties: rules: type: array items: $ref: '#/components/schemas/TeamLBACRule' ReportSettings: type: object properties: branding: $ref: '#/components/schemas/ReportBrandingOptions' embeddedImageTheme: type: string footerFontFamily: type: string footerItems: type: array items: $ref: '#/components/schemas/FooterItem' id: type: integer format: int64 orgId: type: integer format: int64 pdfDashboardTitleEnabled: type: boolean pdfHeaderEnabled: type: boolean pdfTheme: type: string pdfTimeRangeEnabled: type: boolean userId: type: integer format: int64 RoleDTO: type: object required: - version - uid - name - displayName - description - group - updated - created properties: created: type: string format: date-time delegatable: type: boolean description: type: string displayName: type: string global: type: boolean group: type: string hidden: type: boolean mapped: type: boolean name: type: string permissions: type: array items: $ref: '#/components/schemas/Permission' uid: type: string updated: type: string format: date-time version: type: integer format: int64 ReportSchedule: type: object properties: dayOfMonth: type: string endDate: type: string format: date-time frequency: type: string intervalAmount: type: integer format: int64 intervalFrequency: type: string startDate: type: string format: date-time timeZone: type: string workdaysOnly: type: boolean ReportOptions: type: object properties: csvEncoding: type: string layout: type: string orientation: type: string pdfCombineOneFile: type: boolean pdfShowTemplateVariables: type: boolean timeRange: $ref: '#/components/schemas/ReportTimeRange' CacheConfigSetter: description: 'ConfigSetter defines the cache parameters that users can configure per datasource This is only intended to be consumed by the SetCache HTTP Handler' type: object properties: dataSourceID: type: integer format: int64 dataSourceUID: type: string enabled: type: boolean ttlQueriesMs: description: TTL MS, or "time to live", is how long a cached item will stay in the cache before it is removed (in milliseconds) type: integer format: int64 ttlResourcesMs: type: integer format: int64 useDefaultTTL: description: If UseDefaultTTL is enabled, then the TTLQueriesMS and TTLResourcesMS in this object is always sent as the default TTL located in grafana.ini type: boolean State: type: string RolesSearchQuery: type: object properties: includeHidden: type: boolean orgId: type: integer format: int64 teamIds: type: array items: type: integer format: int64 userIds: type: array items: type: integer format: int64 Token: type: object properties: account: type: string anonymousRatio: type: integer format: int64 company: type: string details_url: type: string exp: type: integer format: int64 iat: type: integer format: int64 included_users: type: integer format: int64 iss: type: string jti: type: string lexp: type: integer format: int64 lic_exp_warn_days: type: integer format: int64 lid: type: string limit_by: type: string max_concurrent_user_sessions: type: integer format: int64 nbf: type: integer format: int64 prod: type: array items: type: string slug: type: string status: $ref: '#/components/schemas/TokenStatus' sub: type: string tok_exp_warn_days: type: integer format: int64 trial: type: boolean trial_exp: type: integer format: int64 update_days: type: integer format: int64 usage_billing: type: boolean ReportEmail: type: object properties: emails: description: Comma-separated list of emails to which to send the report to. type: string id: description: Send the report to the emails specified in the report. Required if emails is not present. type: string format: int64 useEmailsFromReport: description: Send the report to the emails specified in the report. Required if emails is not present. type: boolean SuccessResponseBody: type: object properties: message: type: string SearchTeamGroupsQueryResult: type: object properties: page: type: integer format: int64 perPage: type: integer format: int64 teamGroups: type: array items: $ref: '#/components/schemas/TeamGroupDTO' totalCount: type: integer format: int64 RoleAssignmentsDTO: type: object properties: role_uid: type: string service_accounts: type: array items: type: integer format: int64 teams: type: array items: type: integer format: int64 users: type: array items: type: integer format: int64 SyncResult: type: object title: SyncResult holds the result of a sync with LDAP. This gives us information on which users were updated and how. properties: Elapsed: $ref: '#/components/schemas/Duration' FailedUsers: type: array items: $ref: '#/components/schemas/FailedUser' MissingUserIds: type: array items: type: integer format: int64 Started: type: string format: date-time UpdatedUserIds: type: array items: type: integer format: int64 CreateRoleForm: type: object properties: description: type: string displayName: type: string global: type: boolean group: type: string hidden: type: boolean name: type: string permissions: type: array items: $ref: '#/components/schemas/Permission' uid: type: string SetTeamRolesCommand: type: object properties: includeHidden: type: boolean roleUids: type: array items: type: string FailedUser: description: FailedUser holds the information of an user that failed type: object properties: Error: type: string Login: type: string Report: type: object properties: created: type: string format: date-time dashboards: type: array items: $ref: '#/components/schemas/ReportDashboard' enableCsv: type: boolean enableDashboardUrl: type: boolean formats: type: array items: $ref: '#/components/schemas/Type' id: type: integer format: int64 message: type: string name: type: string options: $ref: '#/components/schemas/ReportOptions' orgId: type: integer format: int64 recipients: type: string replyTo: type: string scaleFactor: type: integer format: int64 schedule: $ref: '#/components/schemas/ReportSchedule' state: $ref: '#/components/schemas/State' subject: type: string uid: type: string updated: type: string format: date-time urls: type: array items: $ref: '#/components/schemas/ReportURLItem' userId: type: integer format: int64 TeamGroupMapping: description: '---------------------' type: object properties: groupId: type: string ReportBrandingOptions: type: object properties: emailFooterLink: type: string emailFooterMode: type: string emailFooterText: type: string emailLogoUrl: type: string reportLogoUrl: type: string UpdateRoleCommand: type: object required: - displayName - description - group properties: description: type: string displayName: type: string global: type: boolean group: type: string hidden: type: boolean name: type: string permissions: type: array items: $ref: '#/components/schemas/Permission' SetRoleAssignmentsCommand: type: object properties: service_accounts: type: array items: type: integer format: int64 teams: type: array items: type: integer format: int64 users: type: array items: type: integer format: int64 TeamLBACRules: type: object properties: rules: type: array items: $ref: '#/components/schemas/TeamLBACRule' CreateOrUpdateReport: type: object properties: dashboards: type: array items: $ref: '#/components/schemas/ReportDashboard' enableCsv: type: boolean enableDashboardUrl: type: boolean formats: type: array items: $ref: '#/components/schemas/Type' message: type: string name: type: string options: $ref: '#/components/schemas/ReportOptions' recipients: type: string replyTo: type: string scaleFactor: type: integer format: int64 schedule: $ref: '#/components/schemas/ReportSchedule' state: $ref: '#/components/schemas/State' subject: type: string urls: type: array items: $ref: '#/components/schemas/ReportURLItem' Permission: description: Permission is the model for access control permissions type: object properties: action: type: string created: type: string format: date-time scope: type: string updated: type: string format: date-time TeamLBACRule: type: object properties: rules: type: array items: type: string teamId: type: string teamUid: type: string ReportDashboard: type: object properties: dashboard: $ref: '#/components/schemas/ReportDashboardID' reportVariables: {} timeRange: $ref: '#/components/schemas/ReportTimeRange' AccessControlStatus: type: object properties: enabled: type: boolean Type: type: string ActiveSyncStatusDTO: description: ActiveSyncStatusDTO holds the information for LDAP background Sync type: object properties: enabled: type: boolean nextSync: type: string format: date-time prevSync: $ref: '#/components/schemas/SyncResult' schedule: type: string AddUserRoleCommand: type: object properties: global: type: boolean roleUid: type: string TeamGroupDTO: type: object properties: groupId: type: string orgId: type: integer format: int64 teamId: type: integer format: int64 teamUid: type: string uid: description: 'Deprecated: always empty; no per-entry id.' type: string x-deprecated: true ReportURLItem: type: object properties: title: type: string url: type: string RecordingRuleJSON: description: RecordingRuleJSON is the external representation of a recording rule type: object properties: active: type: boolean count: type: boolean description: type: string dest_data_source_uid: type: string id: type: string interval: type: integer format: int64 name: type: string prom_name: type: string queries: type: array items: type: object additionalProperties: {} range: type: integer format: int64 target_ref_id: type: string ActiveUserStats: type: object properties: active_admins_and_editors: type: integer format: int64 active_anonymous_devices: type: integer format: int64 active_users: type: integer format: int64 active_viewers: type: integer format: int64 FooterItem: type: object properties: color: type: string fontSize: type: string fontStyle: type: string fontWeight: type: string type: type: string value: type: string ReportTimeRange: type: object properties: from: type: string to: type: string DeleteTokenCommand: type: object properties: instance: type: string AddTeamRoleCommand: type: object properties: roleUid: type: string CacheConfigResponse: type: object properties: created: type: string format: date-time dataSourceID: description: Fields that can be set by the API caller - read/write type: integer format: int64 dataSourceUID: type: string defaultTTLMs: description: 'These are returned by the HTTP API, but are managed internally - read-only Note: ''created'' and ''updated'' are special properties managed automatically by xorm, but we are setting them manually' type: integer format: int64 enabled: type: boolean message: type: string ttlQueriesMs: description: TTL MS, or "time to live", is how long a cached item will stay in the cache before it is removed (in milliseconds) type: integer format: int64 ttlResourcesMs: type: integer format: int64 updated: type: string format: date-time useDefaultTTL: description: If UseDefaultTTL is enabled, then the TTLQueriesMS and TTLResourcesMS in this object is always sent as the default TTL located in grafana.ini type: boolean ReportDashboardID: type: object properties: id: type: integer format: int64 name: type: string uid: type: string responses: getReportSettingsResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/ReportSettings' getStatusResponse: description: (empty) content: application/json: schema: type: boolean createRoleResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/RoleDTO' getReportsResponse: description: (empty) content: application/json: schema: type: array items: $ref: '#/components/schemas/Report' getAllRolesResponse: description: (empty) content: application/json: schema: type: array items: $ref: '#/components/schemas/RoleDTO' searchTeamGroupsResponse: description: (empty) content: application/json: schema: type: array items: $ref: '#/components/schemas/SearchTeamGroupsQueryResult' getRoleAssignmentsResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/RoleAssignmentsDTO' postRenewLicenseTokenResponse: description: (empty) content: application/json: schema: type: boolean internalServerError: description: InternalServerError is a general error indicating something went wrong internally. content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' badRequestError: description: BadRequestError is returned when the request is invalid and it cannot be processed. content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' getLicenseTokenResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/Token' getAccessControlStatusResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/AccessControlStatus' acceptedResponse: description: AcceptedResponse content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' notFoundError: description: NotFoundError is returned when the requested resource was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' getTeamGroupsApiResponse: description: (empty) content: application/json: schema: type: array items: $ref: '#/components/schemas/TeamGroupDTO' getReportResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/Report' getTeamLBACRulesResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/TeamLBACRules' listTeamsRolesResponse: description: (empty) content: application/json: schema: type: object additionalProperties: type: array items: $ref: '#/components/schemas/RoleDTO' recordingRuleWriteTargetResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/PrometheusRemoteWriteTargetJSON' okResponse: description: An OKResponse is returned if the request was successful. content: application/json: schema: $ref: '#/components/schemas/SuccessResponseBody' unauthorisedError: description: UnauthorizedError is returned when the request is not authenticated. content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' getSyncStatusResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/ActiveSyncStatusDTO' createReportResponse: description: (empty) content: application/json: schema: type: object properties: id: type: integer format: int64 message: type: string listRolesResponse: description: (empty) content: application/json: schema: type: array items: $ref: '#/components/schemas/RoleDTO' listRecordingRulesResponse: description: (empty) content: application/json: schema: type: array items: $ref: '#/components/schemas/RecordingRuleJSON' getRoleResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/RoleDTO' noContentResponse: description: (empty) content: application/json: schema: type: object listUsersRolesResponse: description: (empty) content: application/json: schema: type: object additionalProperties: type: array items: $ref: '#/components/schemas/RoleDTO' contentResponse: description: (empty) content: application/json: schema: type: array items: type: integer format: uint8 recordingRuleResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/RecordingRuleJSON' updateTeamLBACRulesResponse: description: (empty) content: application/json: schema: type: object properties: id: type: integer format: int64 message: type: string name: type: string rules: type: array items: $ref: '#/components/schemas/TeamLBACRule' uid: type: string forbiddenError: description: ForbiddenError is returned if the user/token has insufficient permissions to access the requested resource. content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' unprocessableEntityError: description: UnprocessableEntityError content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' refreshLicenseStatsResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/ActiveUserStats' setRoleAssignmentsResponse: description: (empty) content: application/json: schema: $ref: '#/components/schemas/RoleAssignmentsDTO' securitySchemes: api_key: type: apiKey name: Authorization in: header basic: type: http scheme: basic