openapi: 3.2.0 info: title: Secureframe User Account API description: '## Introduction Secureframe exposes a REST API for use by customers, partners, and community developers.' version: '2023-10-18' x-logo: url: https://media.secureframe.com/logo-dark.svg servers: - url: https://api.secureframe.com - url: https://api-uk.secureframe.com tags: - name: User Account description: This document describes the API for reading and linking User Accounts. paths: /user_accounts: get: tags: - User Account operationId: companyUserVendorsIndex parameters: - name: include description: 'Comma delimited string of relationships to include. Note: company_vendor_connection is deprecated, please use integration_connection instead.' required: false in: query schema: type: array items: type: string enum: - company_user - company_vendor_connection - integration_connection explode: false style: form - name: page description: 'Used for pagination of response data (default: page 1). Specifies the offset of the next block of data to receive.' required: false in: query schema: type: integer - name: per_page description: 'Used for pagination of response data (default: 100 items per response). Specifies the number of results for a given page.' required: false in: query schema: type: integer - name: q description: Search and filter the User Account data using Lucene syntax. required: false in: query schema: type: string - name: relationships description: 'Set to true to return the associated relationships data within the response. (default: false)' required: false in: query schema: type: boolean - name: sort description: 'Comma delimited string of fields to sort the results by, applied in the order given. Prefix a field with `-` to sort it in descending order, for example `?sort=-active,created_at`. Sortable fields: `active`, `created_at`, `email`, `first_name`, `has_user`, `id`, `last_name`, `third_party_id`, `updated_at`, `vendor_name`.' required: false in: query schema: type: string responses: default: description: '' content: application/json: schema: type: object properties: data: type: array description: List of resources matching the query items: type: object description: Data envelope for the response properties: id: type: string format: uuid description: The identifier for this resource type: type: string description: The type of resource this object is attributes: $ref: '#/components/schemas/UserAccount' relationships: type: object description: Nested objects related to the top level object links: type: object description: Links to related API resources meta: type: object description: Metadata about the list response properties: total: type: integer description: Total number of records matching the query across all pages, independent of page and per_page included: type: array items: type: object description: Various objects that have been included via the `include` param properties: id: type: string format: uuid description: The identifier for this resource '403': description: Forbidden '401': description: Unauthorized '400': description: Bad Request description: 'Returns a list of User Accounts. ### Search parameters - `active` — Flag to indicate if this is an active User Account on the vendor side. Defaults to true if the vendor does not support or provide this value. - Valid values: `true`, `false` - `created_at` — The date this User Account was created - `email` — The email received from the connection - `first_name` — The first name of the user received from the connection - `has_user` — Flag to indicate if this User Account has a User. False indicates that it''s an unlinked account - Valid values: `true`, `false` - `id` — The ID of the User Account - `last_name` — The last name of the user received from the connection - `third_party_id` — The identifier for this User Account on the vendor side - `updated_at` — The date this User Account was last updated - `vendor_name` — The name of the vendor that this User Account is from' summary: List User Accounts security: - header_authorization: [] x-controller: api/company_user_vendors x-action: index /user_accounts/{id}: get: tags: - User Account operationId: companyUserVendorsShow parameters: - name: id description: Scope response to id required: true in: path schema: type: string - name: include description: 'Comma delimited string of relationships to include. Note: company_vendor_connection is deprecated, please use integration_connection instead.' required: false in: query schema: type: array items: type: string enum: - company_user - company_vendor_connection - integration_connection explode: false style: form - name: relationships description: 'Set to true to return the associated relationships data within the response. (default: false)' required: false in: query schema: type: boolean responses: default: description: '' content: application/json: schema: type: object properties: data: type: object description: Data envelope for the response properties: id: type: string format: uuid description: The identifier for this resource type: type: string description: The type of resource this object is attributes: $ref: '#/components/schemas/UserAccount' relationships: type: object description: Nested objects related to the top level object links: type: object description: Links to related API resources included: type: array items: type: object description: Various objects that have been included via the `include` param properties: id: type: string format: uuid description: The identifier for this resource '404': description: Resource not found '403': description: Forbidden '401': description: Unauthorized '400': description: Bad Request description: Returns a single User Account by ID summary: Get a User Account security: - header_authorization: [] x-controller: api/company_user_vendors x-action: show /user_accounts/{id}/link: put: tags: - User Account operationId: companyUserVendorsLink parameters: - name: id description: Scope response to id required: true in: path schema: type: string - name: user_id description: The ID of the user to link to the User Account. If user_id is not provided or is an empty string, the User Account will be unlinked. required: false in: query schema: type: string format: uuid responses: default: description: '' content: application/json: schema: type: object properties: data: type: object description: Data envelope for the response properties: id: type: string format: uuid description: The identifier for this resource type: type: string description: The type of resource this object is attributes: $ref: '#/components/schemas/UserAccount' relationships: type: object description: Nested objects related to the top level object links: type: object description: Links to related API resources included: type: array items: type: object description: Various objects that have been included via the `include` param properties: id: type: string format: uuid description: The identifier for this resource '404': description: Resource not found '403': description: Forbidden '401': description: Unauthorized '400': description: Bad Request description: Links a User to a User Account. summary: Link a User Account security: - header_authorization: [] x-controller: api/company_user_vendors x-action: link components: schemas: UserAccount: type: object properties: id: type: string format: uuid description: The identifier for this UserAccount. active: type: boolean description: Flag to indicate if this is an active user account on the vendor side. Defaults to true if the vendor does not support or provide this value. created_at: type: string format: date-time description: The date this UserAccount was created. email: type: string description: The email received from the connection. first_name: type: string description: The first name of the user received from the connection. has_user: type: boolean description: Flag to indicate if this UserAccount has a User. False indicates that it's an unlinked account. last_name: type: string description: The last name of the user received from the connection. third_party_id: type: string description: The identifier for this UserAccount on the vendor side. username: type: string description: The user name of the UserAccount on the vendor side. vendor_name: type: string description: The name of the vendor that this UserAccount is from. updated_at: type: string format: date-time description: The date this UserAccount was last updated. securitySchemes: header_authorization: type: apiKey name: Authorization in: header x-tagGroups: - name: Endpoints tags: - Cloud Resource - Cloud Resource Framework Asset Scope - Comment - Control - Custom Integration - Device - Device Framework Asset Scope - Evidence - File Upload - Framework - Framework Requirement - Integration Connection - Knowledge Base Answer - Knowledge Base Question - POA&M Item - Policy - Repository - Repository Framework Asset Scope - Risk - SSP Duty - SSP Duty Role - SSP Policy - SSP Report - SSP Report Assessment Objective - SSP Report Section - SSP Report Section Block - SSP Role - SSP Vendor - Security Questionnaire - Task - Test - Test Evidence - Test Export - Test Export Reading - Third Party Risk Management Vendor - Trust Center Request - User - User Account - User Evidence - User Security Settings - Vendor