openapi: 3.2.0 info: title: Harness Scorecards API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: Scorecards paths: /v1/scorecards: get: summary: Get all scorecards available tags: - Scorecards responses: '200': $ref: '#/components/responses/ScorecardResponseList' operationId: get-scorecards x-stoplight: id: sd1pqx1g9pu0o x-internal: false security: - x-api-key: [] parameters: - $ref: '#/components/parameters/AccountHeader5' post: summary: Create scorecard tags: - Scorecards operationId: create-scorecard responses: '201': $ref: '#/components/responses/DefaultSaveResponse' x-stoplight: id: 7ky7v205witp4 security: - x-api-key: [] parameters: - $ref: '#/components/parameters/AccountHeader5' requestBody: content: application/json: schema: $ref: '#/components/schemas/ScorecardDetailsRequest' x-internal: false /v1/scorecards/{scorecard-id}: get: summary: Get scorecard details for given scorecardId tags: - Scorecards responses: '200': $ref: '#/components/responses/ScorecardDetailsResponse' operationId: get-scorecard x-internal: false security: - x-api-key: [] parameters: - $ref: '#/components/parameters/AccountHeader5' - $ref: '#/components/parameters/ScorecardIdentifier' x-stoplight: id: 7q992jg8e5lre put: summary: Update scorecard details for given scorecardId tags: - Scorecards operationId: update-scorecard responses: '200': $ref: '#/components/responses/DefaultSaveResponse' x-stoplight: id: zfrmn6vx8zk2x security: - x-api-key: [] parameters: - $ref: '#/components/parameters/AccountHeader5' - $ref: '#/components/parameters/ScorecardIdentifier' requestBody: content: application/json: schema: $ref: '#/components/schemas/ScorecardDetailsRequest' x-internal: false delete: summary: Delete scorecard details for given scorecardId operationId: delete-scorecard security: - x-api-key: [] parameters: - $ref: '#/components/parameters/AccountHeader5' - $ref: '#/components/parameters/ScorecardIdentifier' x-internal: false responses: '204': description: No Content tags: - Scorecards x-stoplight: id: t4gtsw95rgoh8 /v1/scorecards/{scorecard-id}/stats: get: summary: Get scorecard stats for given scorecardId tags: - Scorecards responses: '200': $ref: '#/components/responses/ScorecardStatsResponse' operationId: get-scorecard-stats x-stoplight: id: y6e6yo2hkheeh security: - x-api-key: [] parameters: - $ref: '#/components/parameters/AccountHeader5' - $ref: '#/components/parameters/ScorecardIdentifier' /v1/entity-facets: get: summary: Get all entity facets for given kind tags: - Scorecards responses: '200': $ref: '#/components/responses/FacetsResponse' operationId: get-entity-facets x-stoplight: id: 8fjdnw2gtfpr7 security: - x-api-key: [] parameters: - $ref: '#/components/parameters/AccountHeader5' - $ref: '#/components/parameters/CatalogKind' components: schemas: ScorecardStatsResponse: title: ScorecardStatsResponse x-stoplight: id: csadnzoryu4um description: ScorecardStatsResponse type: object properties: name: type: string x-stoplight: id: czewiwd87fr8u timestamp: type: integer x-stoplight: id: 5p8wtkrmax6su format: int64 stats: type: array x-stoplight: id: f4tm5re3zal0h items: $ref: '#/components/schemas/ScorecardStats' required: - name - stats ScorecardResponse: title: ScorecardResponse x-stoplight: id: c9gm3c9wg18qw type: object properties: scorecard: $ref: '#/components/schemas/Scorecard' ScorecardChecks: title: ScorecardChecks x-stoplight: id: cyvlqdjbff44c type: object properties: identifier: type: string x-stoplight: id: je2zi36q1g4po weightage: type: number x-stoplight: id: v58bql7f1tfs7 format: double custom: type: boolean x-stoplight: id: bupb1l0ow77d1 required: - identifier - custom ScorecardDetails: title: ScorecardDetails x-stoplight: id: ifbfldq39cf27 type: object properties: name: type: string identifier: type: string description: type: string filter: $ref: '#/components/schemas/ScorecardFilter' weightage_strategy: type: string x-stoplight: id: qeeywjc4bkkda enum: - EQUAL_WEIGHTS - CUSTOM default: EQUAL_WEIGHTS published: type: boolean x-stoplight: id: qlznynr2iay1n checks_missing: type: array x-stoplight: id: gntwsigybxa08 items: x-stoplight: id: 6xqs4rtf0fexq type: string components: type: integer x-stoplight: id: 8rc2peneqokdm percentage: type: number x-stoplight: id: lzqyp3vjd6kto format: double minimum: 0 maximum: 100 required: - name - identifier - filter - published ScorecardStats: title: ScorecardStats x-stoplight: id: mfzfyuj9dxi9v type: object description: ScorecardStats x-internal: false properties: name: type: string x-stoplight: id: skt0gj9ivt90s namespace: type: string x-stoplight: id: oklu13i7o6ebd owner: type: string x-stoplight: id: uiiw13t7o6uda system: type: string x-stoplight: id: up1h022u2v98y kind: type: string x-stoplight: id: azw80jiyldmxq type: type: string x-stoplight: id: oijvwg17eyejq score: type: integer x-stoplight: id: ehz071o8ft8bg required: - name - namespace - owner - system - kind - type - score ScorecardDetailsResponse: title: ScorecardDetailsResponse x-stoplight: id: 7z732csnjjs8z type: object properties: scorecard: $ref: '#/components/schemas/ScorecardDetails' checks: type: array items: $ref: '#/components/schemas/ScorecardChecksDetails' required: - scorecard - checks Facets: title: Facets x-stoplight: id: 0yxeh06749fxw type: object properties: type: type: array x-stoplight: id: 8zjtnynlcnjjn items: x-stoplight: id: bi0jhb6t58jfk type: string owners: type: array x-stoplight: id: ttni8vwtfjy37 items: x-stoplight: id: nv9qgpkbxeyx6 type: string tags: type: array x-stoplight: id: 35250e4csgeng items: x-stoplight: id: gaxccdx1p5nq5 type: string lifecycle: type: array x-stoplight: id: pm47xtp6sjdm9 items: x-stoplight: id: r76ps8dcmup2d type: string required: - type - owners - tags - lifecycle Check: title: Check x-stoplight: id: d3s3zmsa21jqu type: object description: Check properties: identifier: type: string x-stoplight: id: u2xn1u2797lk3 name: type: string x-stoplight: id: 0livvjhoy8g3l description: type: string x-stoplight: id: f7xb30y8u47he expression: type: string x-stoplight: id: 5g5fqsfh15x7r tags: type: array x-stoplight: id: mnwbadmsdi09d items: x-stoplight: id: fitl6f8ktom9c type: string custom: type: boolean x-stoplight: id: 04nibhaa1qklq required: - identifier - name - custom x-internal: false ScorecardDetailsRequest: title: ScorecardDetailsRequest x-stoplight: id: z2l4mp8px3bsf type: object properties: scorecard: $ref: '#/components/schemas/ScorecardDetails' checks: type: array x-stoplight: id: edrtpiucltli5 items: $ref: '#/components/schemas/ScorecardChecks' required: - scorecard - checks ScorecardFilter: title: ScorecardFilter x-stoplight: id: xwnr2xalsb1fv type: object properties: kind: type: string x-stoplight: id: ni2n6gaelw2sh type: type: string x-stoplight: id: pit0to8ng7rtl owners: type: array x-stoplight: id: ibe4axxxrnwpl items: x-stoplight: id: kde7prhuw2ww2 type: string tags: type: array x-stoplight: id: 9sqie0nb3f08d items: x-stoplight: id: 8sko0og6lpbyh type: string lifecycle: type: array x-stoplight: id: 9rtf97h3uu9z3 items: x-stoplight: id: etzt6sp88w5iz type: string required: - kind Scorecard: title: Scorecard x-stoplight: id: ck1klmib92a8q type: object properties: name: type: string x-stoplight: id: 0036s8sh4ovml identifier: type: string x-stoplight: id: vy3cv7a0ja9km description: type: string x-stoplight: id: 9ec2odnrqvkcm checks: type: array items: $ref: '#/components/schemas/Check' published: type: boolean x-stoplight: id: 5z7snnygtkcme checks_missing: type: array x-stoplight: id: 69qa1yprs1y5z items: x-stoplight: id: 4mdevxdftzonf type: string components: type: integer x-stoplight: id: 9ec2oenrqokcm percentage: type: number x-stoplight: id: iyqzo3vjc6kto format: double minimum: 0 maximum: 100 required: - name - identifier - checks DefaultSaveResponse: title: DefaultSaveResponse x-stoplight: id: 4dbdqgfzqv8nz type: object description: 'Default response for Save/Edit operations ' properties: status: type: string x-stoplight: id: cskevfqvaydbn required: - status ScorecardChecksDetails: title: ScorecardChecksDetails x-stoplight: id: hynxqf3tp1ysq allOf: - $ref: '#/components/schemas/ScorecardChecks' - type: object x-stoplight: id: 12snka2hxk667 properties: name: type: string x-stoplight: id: ntpqrqq3ymwb3 description: type: string x-stoplight: id: jlr6zyb75u9bt required: - name responses: ScorecardDetailsResponse: description: Response for scorecard details content: application/json: schema: $ref: '#/components/schemas/ScorecardDetailsResponse' application/yaml: schema: $ref: '#/components/schemas/ScorecardDetailsResponse' ScorecardResponseList: description: Response for all scorecards available content: application/json: schema: type: array items: $ref: '#/components/schemas/ScorecardResponse' application/yaml: schema: type: array items: $ref: '#/components/schemas/ScorecardResponse' ScorecardStatsResponse: description: Response for scorecard stats content: application/json: schema: $ref: '#/components/schemas/ScorecardStatsResponse' application/yaml: schema: $ref: '#/components/schemas/ScorecardStatsResponse' FacetsResponse: description: Response for entity facets content: application/json: schema: $ref: '#/components/schemas/Facets' application/yaml: schema: $ref: '#/components/schemas/Facets' DefaultSaveResponse: description: Default response for Save/Edit operations content: application/json: schema: $ref: '#/components/schemas/DefaultSaveResponse' application/yaml: schema: $ref: '#/components/schemas/DefaultSaveResponse' parameters: CatalogKind: name: kind in: query required: true schema: type: string description: This is used to filter backstage catalog entity facets by kind ScorecardIdentifier: name: scorecard-id in: path description: Scorecard Identifier required: true schema: type: string AccountHeader5: name: Harness-Account in: header required: false schema: type: string description: Identifier field of the account the resource is scoped to. securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks