openapi: 3.2.0 info: version: v3 title: Fortify on Demand Web API Explorer Personal Access Tokens… servers: - url: https://api.ams.fortify.com tags: - name: Personal Access Tokens paths: /api/v3/personal-access-tokens/{personalAccessTokenId}: get: tags: - Personal Access Tokens summary: Get a specific personal access token description: 'Allowed Scopes: api-tenant' operationId: PersonalAccessTokensV3_GetPersonalAccessToken parameters: - name: personalAccessTokenId in: path description: The personal access token id required: true schema: type: integer format: int32 responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/PersonalAccessTokenModel' text/json: schema: $ref: '#/components/schemas/PersonalAccessTokenModel' application/xml: schema: $ref: '#/components/schemas/PersonalAccessTokenModel' text/xml: schema: $ref: '#/components/schemas/PersonalAccessTokenModel' '401': description: Unauthorized '403': description: Forbidden '404': description: NotFound '500': description: InternalServerError put: tags: - Personal Access Tokens summary: Update an existing personal access token description: 'Allowed Scopes: api-tenant' operationId: PersonalAccessTokensV3_PutPersonalAccessToken parameters: - name: personalAccessTokenId in: path description: The personal access token ID required: true schema: type: integer format: int32 responses: '200': description: Ok '401': description: Unauthorized '403': description: Forbidden '404': description: NotFound '422': description: UnprocessableEntity content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' text/json: schema: $ref: '#/components/schemas/ErrorResponse' application/xml: schema: $ref: '#/components/schemas/ErrorResponse' text/xml: schema: $ref: '#/components/schemas/ErrorResponse' '500': description: InternalServerError content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' text/json: schema: $ref: '#/components/schemas/ErrorResponse' application/xml: schema: $ref: '#/components/schemas/ErrorResponse' text/xml: schema: $ref: '#/components/schemas/ErrorResponse' requestBody: content: application/json: schema: $ref: '#/components/schemas/PutPersonalAccessTokenRequest' text/json: schema: $ref: '#/components/schemas/PutPersonalAccessTokenRequest' application/xml: schema: $ref: '#/components/schemas/PutPersonalAccessTokenRequest' text/xml: schema: $ref: '#/components/schemas/PutPersonalAccessTokenRequest' application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/PutPersonalAccessTokenRequest' multipart/form-data: schema: $ref: '#/components/schemas/PutPersonalAccessTokenRequest' description: Request containing the updated token information required: true delete: tags: - Personal Access Tokens summary: Deletes a personal access token description: 'Allowed Scopes: api-tenant' operationId: PersonalAccessTokensV3_DeletePersonalAccessToken parameters: - name: personalAccessTokenId in: path description: The personal access token ID required: true schema: type: integer format: int32 responses: '200': description: Ok '401': description: Unauthorized '403': description: Forbidden '404': description: NotFound '500': description: InternalServerError /api/v3/personal-access-tokens: get: tags: - Personal Access Tokens summary: Returns a list of personal access tokens description: 'Allowed Scopes: api-tenant For security leads the returned list includes all personal access tokens in the tenant. Users in other roles can only query their own personal access tokens.' operationId: PersonalAccessTokensV3_GetPersonalAccessTokens parameters: - name: filters in: query description: 'A delimited list of field filters.

Field name and value should be separated by a colon (:).

Multiple fields should be separated by a plus (+). Multiple fields are treated as an AND condition. Example, fieldname1:value+fieldname2:value

Multiple values for a field should be separated by a pipe (|). Mulitple values for a field are treated as an OR condition. Example, fieldname1:value1|value2

The supported field names are name and userName. Note that filtering on userName is only available to security leads.

Filtering is not supported for the following fields: allowedScopes, id, isAuthorized, lastSuccessfulLoginDate, lastSuccessfulLoginIpAddress, secretExpirationDate, secretLifetimeDays, userId' required: false schema: type: string - name: orderBy in: query description: The field name to order the results by. required: false schema: type: string - name: orderByDirection in: query description: The direction to order the results by. ASC and DESC are valid values. required: false schema: type: string responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/PersonalAccessTokenModelListResponse' text/json: schema: $ref: '#/components/schemas/PersonalAccessTokenModelListResponse' application/xml: schema: $ref: '#/components/schemas/PersonalAccessTokenModelListResponse' text/xml: schema: $ref: '#/components/schemas/PersonalAccessTokenModelListResponse' '401': description: Unauthorized '403': description: Forbidden '500': description: InternalServerError post: tags: - Personal Access Tokens summary: Creates a personal access token description: 'Allowed Scopes: api-tenant The reqeust body should include either secretLifetimeDays or secretExpirationDate. If both are specified secretLifetimeDays is ignored.' operationId: PersonalAccessTokensV3_PostPersonalAccessToken responses: '201': description: Created content: application/json: schema: $ref: '#/components/schemas/CreatePersonalAccessTokenResult' text/json: schema: $ref: '#/components/schemas/CreatePersonalAccessTokenResult' application/xml: schema: $ref: '#/components/schemas/CreatePersonalAccessTokenResult' text/xml: schema: $ref: '#/components/schemas/CreatePersonalAccessTokenResult' '401': description: Unauthorized '403': description: Forbidden '422': description: UnprocessableEntity content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' text/json: schema: $ref: '#/components/schemas/ErrorResponse' application/xml: schema: $ref: '#/components/schemas/ErrorResponse' text/xml: schema: $ref: '#/components/schemas/ErrorResponse' '500': description: InternalServerError requestBody: content: application/json: schema: $ref: '#/components/schemas/PostPersonalAccessTokenRequest' text/json: schema: $ref: '#/components/schemas/PostPersonalAccessTokenRequest' application/xml: schema: $ref: '#/components/schemas/PostPersonalAccessTokenRequest' text/xml: schema: $ref: '#/components/schemas/PostPersonalAccessTokenRequest' application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/PostPersonalAccessTokenRequest' multipart/form-data: schema: $ref: '#/components/schemas/PostPersonalAccessTokenRequest' required: true /api/v3/personal-access-tokens/{personalAccessTokenId}/secret: put: tags: - Personal Access Tokens summary: Creates a new personal access token secret description: 'Allowed Scopes: api-tenant Creating a new personal access token secret will void the current secret. The reqeust body should include either secretLifetimeDays or secretExpirationDate. If both are specified secretLifetimeDays is ignored.' operationId: PersonalAccessTokensV3_PutPersonalAccessTokenSecret parameters: - name: personalAccessTokenId in: path description: The personal access token ID required: true schema: type: integer format: int32 responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/CreatePersonalAccessTokenResult' text/json: schema: $ref: '#/components/schemas/CreatePersonalAccessTokenResult' application/xml: schema: $ref: '#/components/schemas/CreatePersonalAccessTokenResult' text/xml: schema: $ref: '#/components/schemas/CreatePersonalAccessTokenResult' '401': description: Unauthorized '403': description: Forbidden '404': description: NotFound '500': description: InternalServerError requestBody: content: application/json: schema: $ref: '#/components/schemas/PutPersonalAccessTokenSecretRequest' text/json: schema: $ref: '#/components/schemas/PutPersonalAccessTokenSecretRequest' application/xml: schema: $ref: '#/components/schemas/PutPersonalAccessTokenSecretRequest' text/xml: schema: $ref: '#/components/schemas/PutPersonalAccessTokenSecretRequest' application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/PutPersonalAccessTokenSecretRequest' multipart/form-data: schema: $ref: '#/components/schemas/PutPersonalAccessTokenSecretRequest' description: Request containing secret lifetime or expiration date required: true components: schemas: PostPersonalAccessTokenRequest: required: - name - isAuthorized - allowedScopes type: object properties: name: description: The name of the personal access token type: string isAuthorized: description: Flag indicating if the token is authorized to use the API type: boolean allowedScopes: description: Comma delimited list of tenant API scopes the token can be used for type: string secretLifetimeDays: format: int32 description: Number of days the token's secret is valid for type: integer secretExpirationDate: format: date-time description: Date in MM/dd/yyyy format on which the secret should expire and after which will no longer be valid type: string Error: description: Error type: object properties: errorCode: format: int32 description: The error code type: integer message: description: The error message type: string PutPersonalAccessTokenRequest: type: object properties: name: description: The name of the personal access token type: string isAuthorized: description: Flag indicating if the token is authorized to use the API type: boolean allowedScopes: description: Comma delimited list of tenant API scopes the token can be used for type: string CreatePersonalAccessTokenResult: type: object properties: id: format: int32 type: integer secret: type: string ErrorResponse: description: Error Response type: object properties: errors: description: List of errors type: array items: $ref: '#/components/schemas/Error' PutPersonalAccessTokenSecretRequest: type: object properties: secretLifetimeDays: format: int32 description: Number of days the token's secret is valid for type: integer secretExpirationDate: format: date-time description: Date in MM/dd/yyyy format on which the secret should expire and after which will no longer be valid type: string PersonalAccessTokenModelListResponse: description: Generic List Response type: object properties: items: description: The list of items type: array items: $ref: '#/components/schemas/PersonalAccessTokenModel' totalCount: format: int32 description: Total count of items type: integer offset: format: int32 description: Offset of the starting record. 0 indicates the first record. type: integer limit: format: int32 description: Maximum records to return. type: integer PersonalAccessTokenModel: type: object properties: id: format: int32 type: integer name: type: string isAuthorized: type: boolean secretExpirationDate: format: date-time type: string secretLifetimeDays: format: int32 type: integer allowedScopes: type: string lastSuccessfulLoginDate: format: date-time type: string lastSuccessfulLoginIpAddress: type: string userId: format: int32 type: integer userName: type: string