openapi: 3.2.0 info: title: Asset Service Mobileapps API version: 2.1.020 contact: name: Synack Engineering email: engineering@synack.com description: Mobile application assets. servers: - url: https://client.synack.com/api/asset description: Commercial - url: https://client.synack.us/api/asset description: FedRAMP (Medium) tags: - name: Mobile Apps description: Mobile application assets. paths: /v2/scripts/{scriptUid}: parameters: - $ref: '#/components/parameters/ScriptUIDPath' get: x-excluded: true operationId: getAssetScript tags: - Mobile Apps description: Gets an asset script. responses: '200': $ref: '#/components/responses/SingleAssetScript' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gr - asset_scan_gr - asset_or - asset_lr summary: Get asset script x-summary-source: derived delete: x-excluded: true operationId: deleteAssetScript tags: - Mobile Apps description: Delete a script from a asset. responses: '204': $ref: '#/components/responses/204NoContent' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Delete asset script x-summary-source: derived patch: x-excluded: true operationId: patchAssetScript tags: - Mobile Apps description: Patch the properties of an asset script. requestBody: description: Script properties to patch. required: true content: application/json: schema: $ref: '#/components/schemas/UserRoleScriptUpdate' responses: '200': $ref: '#/components/responses/SingleUserRoleScript' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '422': $ref: '#/components/responses/422EntityNotProcessable' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Patch asset script x-summary-source: derived /v2/scripts/{scriptUid}/script-data: parameters: - $ref: '#/components/parameters/ScriptUIDPath' get: x-excluded: true operationId: getAssetScriptData tags: - Mobile Apps description: Gets the script data for an asset script. responses: '200': description: JSON-representation of the asset script data content: application/json: {} '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gr - asset_or - asset_lr summary: Get asset script data x-summary-source: derived /v2/assets/{assetUid}/binaries/{version}: parameters: - $ref: '#/components/parameters/AssetUIDPath' - $ref: '#/components/parameters/ApplicationVersionPath' put: x-excluded: true operationId: putApplicationBinary tags: - Mobile Apps description: Upsert an application binary file or the Url to the binary in the app store. requestBody: description: Application binary properties to patch. required: true content: application/json: schema: $ref: '#/components/schemas/ApplicationBinary' parameters: - $ref: '#/components/parameters/IfMatch' responses: '204': $ref: '#/components/responses/204NoContent' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '412': $ref: '#/components/responses/412PreconditionFailed' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Put application binary x-summary-source: derived delete: x-excluded: true operationId: deleteApplicationBinary tags: - Mobile Apps description: Delete an application binary. responses: '204': $ref: '#/components/responses/204NoContent' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Delete application binary x-summary-source: derived /v2/assets/{assetUid}/user-roles: parameters: - $ref: '#/components/parameters/AssetUIDPath' get: x-excluded: true operationId: getUserRoles tags: - Mobile Apps description: Gets a paginated list of all user roles for a mobile or web application. Returns a 409 status code if the asset is not one of these expected types. parameters: - $ref: '#/components/parameters/PerPageQuery' - $ref: '#/components/parameters/PageQuery' - in: query name: sort schema: type: string enum: - name - scannable - createdAt - updatedAt description: Optional property to sort results by. required: false - $ref: '#/components/parameters/SortDirQuery' - $ref: '#/components/parameters/ScannableQuery' responses: '200': $ref: '#/components/responses/PaginatedArrayOfUserRoles' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '409': $ref: '#/components/responses/409Conflict' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gr - asset_or - asset_lr - asset_srt_lr summary: Get user roles x-summary-source: derived post: x-excluded: true operationId: postUserRole tags: - Mobile Apps description: Adds a user role to a mobile or web application asset. Returns a 409 status code if the asset is not one of these expected types. requestBody: description: Mobile or web application user role to create. required: true content: application/json: schema: $ref: '#/components/schemas/UserRole' responses: '201': $ref: '#/components/responses/SingleUserRole' '204': $ref: '#/components/responses/204NoContent' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '409': $ref: '#/components/responses/409Conflict' '422': $ref: '#/components/responses/422EntityNotProcessable' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Post user role x-summary-source: derived /v2/user-roles/{userRoleUid}: parameters: - $ref: '#/components/parameters/UserRoleUIDPath' get: x-excluded: true operationId: getUserRole tags: - Mobile Apps description: Retrieves the properties of the supplied user role. responses: '200': $ref: '#/components/responses/SingleUserRole' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gr - asset_or - asset_lr - asset_srt_lr summary: Get user role x-summary-source: derived patch: x-excluded: true operationId: patchUserRole tags: - Mobile Apps description: Patch properties of a user role for a mobile or web application asset. Will return a 409 status code if the type is not one of these expected types. requestBody: description: User role to patch. required: true content: application/json: schema: $ref: '#/components/schemas/UserRole' responses: '200': $ref: '#/components/responses/SingleUserRole' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '409': $ref: '#/components/responses/409Conflict' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Patch user role x-summary-source: derived delete: x-excluded: true operationId: deleteUserRole tags: - Mobile Apps description: Delete a user role from a mobile or web application asset. Will return a 409 status code if the type is not one of these expected types. responses: '204': $ref: '#/components/responses/204NoContent' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Delete user role x-summary-source: derived /v2/user-roles/{userRoleUid}/scripts/{scriptUid}: parameters: - $ref: '#/components/parameters/UserRoleUIDPath' - $ref: '#/components/parameters/ScriptUIDPath' patch: x-excluded: true operationId: patchUserRoleScript tags: - Mobile Apps description: Patch properties of a script that's been assigned to user role for a mobile or web application asset. requestBody: description: Updatable properties of a script to patch. required: true content: application/json: schema: $ref: '#/components/schemas/UserRoleScriptUpdate' responses: '200': $ref: '#/components/responses/SingleUserRoleScript' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '422': $ref: '#/components/responses/422EntityNotProcessable' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Patch user role script x-summary-source: derived /v2/user-roles/{userRoleUid}/user-role-credentials: parameters: - $ref: '#/components/parameters/UserRoleUIDPath' get: x-excluded: true operationId: getUserRoleCredentials parameters: - $ref: '#/components/parameters/PerPageQuery' - $ref: '#/components/parameters/PageQuery' - in: query name: sort schema: type: string enum: - status - createdAt - updatedAt description: Optional property to sort results by. required: false - $ref: '#/components/parameters/SortDirQuery' - in: query name: userUid schema: $ref: '#/components/schemas/UserUID' required: false description: Restricts the credentials to only those available to the user. This query parameter is ignored if the user is a researcher. tags: - Mobile Apps description: Gets the paginated credentials owned by the user role. responses: '200': $ref: '#/components/responses/PaginatedArrayOfUserRoleCredentials' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gr - asset_or - asset_lr - asset_srt_lr summary: Get user role credentials x-summary-source: derived post: x-excluded: true operationId: postUserRoleCredential tags: - Mobile Apps description: Add a credential to a user role. Returns 409 Conflict if the credentials do not match the structure of previously created credentials. requestBody: description: A single credential or an array of credentials. required: true content: application/json: schema: $ref: '#/components/schemas/SingleOrMultiUserRoleCredential' responses: '201': $ref: '#/components/responses/SingleOrMultiUserRoleCredentialResponse' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '409': $ref: '#/components/responses/409Conflict' '413': $ref: '#/components/responses/413RequestEntityTooLarge' '422': $ref: '#/components/responses/422EntityNotProcessable' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Post user role credential x-summary-source: derived patch: x-excluded: true operationId: patchUserRoleCredentials tags: - Mobile Apps description: Update the properties of multlipe user role credentials. Returns 409 Conflict when the credential format does not match existing credentials. requestBody: description: A single credential update or an array of multiple credential updates. required: true content: application/json: schema: $ref: '#/components/schemas/MultiUserRoleCredentialUpdate' responses: '200': $ref: '#/components/responses/MultiUserRoleCredentialResponse' '400': $ref: '#/components/responses/400BadRequest' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '409': $ref: '#/components/responses/409Conflict' '413': $ref: '#/components/responses/413RequestEntityTooLarge' '422': $ref: '#/components/responses/422EntityNotProcessable' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Patch user role credentials x-summary-source: derived delete: x-excluded: true operationId: deleteUserRoleCredentials tags: - Mobile Apps parameters: - $ref: '#/components/parameters/CredentialUIDQuery' description: Delete every credential belonging to the user role. responses: '204': $ref: '#/components/responses/204NoContent' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '413': $ref: '#/components/responses/413RequestEntityTooLarge' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Delete user role credentials x-summary-source: derived /v2/user-role-credentials/{credentialUid}: parameters: - $ref: '#/components/parameters/CredentialUIDPath' delete: x-excluded: true operationId: deleteUserRoleCredential tags: - Mobile Apps description: Delete a user role credentialt. responses: '204': $ref: '#/components/responses/204NoContent' '401': $ref: '#/components/responses/401Unauthorized' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gw - asset_client_ow - asset_boss_ow - asset_client_lw - asset_boss_lw summary: Delete user role credential x-summary-source: derived /v2/user-role-credentials: parameters: - in: query name: organizationUid schema: $ref: '#/components/schemas/OrganizationUID' required: true description: Unique identifier for an organization. - in: query name: listingUid schema: $ref: '#/components/schemas/ListingUID' required: true description: Unique identifier for a listing. - in: query name: userUid schema: $ref: '#/components/schemas/UserUID' required: true description: Unique identifier for a user. post: x-excluded: true operationId: assignUserRoleCredentialsToUser tags: - Mobile Apps description: Assign user role credentials to a user for mobile application or web application assets in a listing. responses: '200': description: The assignments occurred successfully '204': $ref: '#/components/responses/204NoContent' '403': $ref: '#/components/responses/403Forbidden' '404': $ref: '#/components/responses/404NotFound' '409': $ref: '#/components/responses/409Conflict' '500': $ref: '#/components/responses/500InternalServerError' '503': $ref: '#/components/responses/503ServiceUnavailable' security: - OAuth2: - asset_gr - asset_or - asset_lr - asset_srt_lr summary: Assign user role credentials to user x-summary-source: derived components: schemas: CredentialCounts: description: Credential counts by credential status in context of a user role. type: object readOnly: true properties: unchecked: type: integer description: Total of credentials in context of a user role with unchecked status. invalid: type: integer description: Total of credentials in context of a user role with invalid status. valid: type: integer description: Total of credentials in context of a user role with valid status. UserRole: allOf: - type: object properties: uid: $ref: '#/components/schemas/UID' name: type: string description: Unique name for the role with the mobile or web application. scannable: type: boolean description: Only roles with this property set to true will be scanned by automated scanners. default: false authenticationStrategies: $ref: '#/components/schemas/AuthenticationStrategies' credentials: type: array description: Credentials owned by this role. readOnly: true items: $ref: '#/components/schemas/UserRoleCredentialSummary' credentialCounts: $ref: '#/components/schemas/CredentialCounts' - $ref: '#/components/schemas/Updatable' ArrayOfUserRoleCredentials: type: array items: $ref: '#/components/schemas/UserRoleCredential' MultiUserRoleCredentialUpdate: type: array items: $ref: '#/components/schemas/UserRoleCredentialUpdateMultiItem' WritableUID: type: string pattern: ^[0-9a-f]{12} description: Unique Identifier for POST/PATCH/PUT request bodies. UserRoleUID: type: string pattern: ^[0-9a-f]{12} description: Unique identifier for a mobile or web application user role. readOnly: true UserRoleScript: allOf: - type: object description: Script used to test a mobile or web applications. properties: uid: $ref: '#/components/schemas/UID' status: $ref: '#/components/schemas/CheckerStatus' filename: type: string description: Generated script name. readOnly: true error: type: string description: Optional text of error message. Server will unset this property when status is set to any value other than invalid. imageCaptureUrl: type: string format: uri description: Optional Url to image capture of the script execution. lastCheckedAt: type: string format: date-time description: The most reecent date time the script was run. lastSuccessfulAt: type: string format: date-time description: The most recent date time the script was successfully run. CheckerStatus: type: string enum: - unchecked - invalid - valid description: Status reported by automated checkers. ListingUID: type: string pattern: ^[-_0-9a-z]{1,50} description: Unique identifier for an listing. readOnly: true AuthenticationStrategy: allOf: - type: object properties: scripts: $ref: '#/components/schemas/Scripts' SingleOrMultiUserRoleCredential: oneOf: - $ref: '#/components/schemas/UserRoleCredential' - type: array items: $ref: '#/components/schemas/UserRoleCredential' UserRoleCredentialUpdate: description: Update to a credential used by an application in context of a user role. type: object properties: credentialData: $ref: '#/components/schemas/Base64Data' status: $ref: '#/components/schemas/CheckerStatus' lastCheckedAt: type: string format: date-time description: The last date time the credential was checked. sharing: $ref: '#/components/schemas/CredentialSharing' Base64Data: type: string description: Base64 encoding of data. example: TXkgdm9pY2UgaXMgbXkgcGFzc3dvcmQu UserRoleCredentialSummary: description: Credential used by an application in context of a user role. type: object properties: uid: $ref: '#/components/schemas/UID' status: $ref: '#/components/schemas/CheckerStatus' lastCheckedAt: type: string format: date-time description: The last date time the credential was checked. sharing: $ref: '#/components/schemas/CredentialSharing' Creatable: type: object required: - createdAt - createdBy properties: createdAt: type: string format: date-time readOnly: true description: Automatically set by the server to the time the request was processed whenever the resource was created. createdBy: $ref: '#/components/schemas/OperationUserUID' ScriptRole: type: string enum: - authentication - sessionValidation - recordedLogin ApplicationBinary: type: object properties: version: type: string readOnly: true downloadUrl: type: string format: uri ArrayOfUserRoles: type: array items: $ref: '#/components/schemas/UserRole' UserUID: type: string pattern: ^[-_0-9a-z]{1,100} description: Unique identifier for a user. AuthenticationStrategies: type: object description: Map of authentication strategies for various scanners, keyed by asset scanner name. properties: tarantulaBurpV2: $ref: '#/components/schemas/AuthenticationStrategy' burp: $ref: '#/components/schemas/AuthenticationStrategy' UID: type: string pattern: ^[0-9a-f]{12} readOnly: true description: Unique Identifier. ProblemDetails: type: object description: 'See [RFC 7807: Problem Details for HTTP APIs](https://tools.ietf.org/html/rfc7807)' properties: type: type: string readOnly: true title: type: string readOnly: true status: type: integer format: int32 minimum: 100 maximum: 511 description: HTTP Status code. readOnly: true detail: type: string description: Message detailing the problem. readOnly: true instance: type: string description: generated problem instance number to correlate with logs readOnly: true failedValidation: type: array description: Array of failed validation rules. readOnly: true items: $ref: '#/components/schemas/FailedValidation' failedValidations: type: array description: Array of indexed failed validation rules. readOnly: true items: $ref: '#/components/schemas/IndexedFailedValidations' maxBatchSize: type: integer description: Maximum processable batch size. readOnly: true batchSize: type: integer description: Batch size sent when batch is too large. readOnly: true AssetUID: type: string pattern: ^[0-9a-f]{24} description: Unique identifier for an asset. Scripts: type: object description: Map of scripts used by this strategy, keyed by script role. properties: authentication: $ref: '#/components/schemas/UserRoleScript' sessionValidation: $ref: '#/components/schemas/UserRoleScript' recordedLogin: $ref: '#/components/schemas/UserRoleScript' FailedValidation: type: object required: - message properties: property: type: string readOnly: true value: type: string readOnly: true message: type: string readOnly: true UserRoleCredentialUpdateMultiItem: description: Item in a bulk update to a credentials used by an application in context of a user role. allOf: - $ref: '#/components/schemas/UserRoleCredentialUpdate' - type: object required: - uid properties: uid: $ref: '#/components/schemas/WritableUID' Updatable: allOf: - $ref: '#/components/schemas/Creatable' - type: object properties: updatedAt: type: string format: date-time readOnly: true description: Automatically set by the server to the time the request was processed whenever the resource is updated. updatedBy: $ref: '#/components/schemas/OperationUserUID' OrganizationUID: type: string pattern: ^[-_0-9a-z]{1,50} description: Unique identifier for an organization. CredentialUID: type: string pattern: ^[0-9a-f]{12} description: Unique identifier for a credential. OperationUserUID: type: string pattern: ^[0-9a-f]{12} readOnly: true description: Automatically set by the server to the requesting user whenever the resource is updated. May be a user account or a service account if the action is performed by an automated. CredentialSharing: type: string description: Determines the limits on users that may be assigned; "one" permits only one user to be assigned, "many" places no limit, and "all" prevents any users to explicitly assigned as all users are implicitly allowed to use the credential. enum: - one - many - all UserRoleScriptUpdate: type: object description: Updatable properties of a script in context of a user role. properties: status: $ref: '#/components/schemas/CheckerStatus' error: type: string description: Optional text of error message. Server will unset this property when status is set to any value other than invalid. imageCaptureUrl: type: string format: uri description: Optional Url to image capture of the script execution. lastCheckedAt: type: string format: date-time description: The most recent date time the script was run. lastSuccessfulAt: type: string format: date-time description: The most recent date time the script was successfully run. IndexedFailedValidations: type: object properties: index: type: integer description: Zero-based index indicating the which item in request containing an array of items has failed validation. readOnly: true failedValidation: type: array description: Array of failed validation rules. readOnly: true items: $ref: '#/components/schemas/FailedValidation' AssetScript: allOf: - type: object description: Script used to test web applications. properties: uid: $ref: '#/components/schemas/UID' name: type: string description: Must be unique across all scripts owned by an asset. scriptRole: $ref: '#/components/schemas/ScriptRole' scriptData: $ref: '#/components/schemas/Base64Data' - $ref: '#/components/schemas/Updatable' UserRoleCredential: description: Credential used by an application in context of a user role. allOf: - type: object required: - credentialData - status - sharing properties: uid: $ref: '#/components/schemas/UID' userRoleUid: $ref: '#/components/schemas/UserRoleUID' assetUid: $ref: '#/components/schemas/AssetUID' required: false organizationUid: $ref: '#/components/schemas/OrganizationUID' required: false credentialData: $ref: '#/components/schemas/Base64Data' status: $ref: '#/components/schemas/CheckerStatus' lastCheckedAt: type: string format: date-time description: The last date time the credential was checked. sharing: $ref: '#/components/schemas/CredentialSharing' assignedUsers: description: User assigned to a credential and role. type: array readOnly: true items: $ref: '#/components/schemas/UserUID' - $ref: '#/components/schemas/Updatable' headers: PaginationCurrentPage: description: Current page in a paginated response. schema: type: integer format: int32 minimum: 1 Link: description: Standard link header. schema: type: string ETag: description: An identifier for a specific version of a resource schema: type: string pattern: ^(?:W\/)?\".*\"$ PaginationTotalCount: description: Total number of items in all pages of a paginated response. schema: format: int32 minimum: 1 PaginationLimit: description: Maximum number of items returned in a paginated response. schema: type: integer format: int32 minimum: 1 PaginationTotalPages: description: Total number of pages in a paginated response. schema: type: integer format: int32 minimum: 1 responses: SingleUserRoleScript: description: The current state of a user role script. headers: ETag: $ref: '#/components/headers/ETag' content: application/json: schema: $ref: '#/components/schemas/UserRoleScript' 413RequestEntityTooLarge: description: Returned generally when the size of the request body is too large to process, or specifically when the request contains too many items, typically in a bulk API operation. content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' PaginatedArrayOfUserRoles: description: Paginated user roles for a mobile or web application asset. headers: Pagination-Limit: $ref: '#/components/headers/PaginationLimit' Pagination-Current-Page: $ref: '#/components/headers/PaginationCurrentPage' Pagination-Total-Pages: $ref: '#/components/headers/PaginationTotalPages' Pagination-Total-Count: $ref: '#/components/headers/PaginationTotalCount' Link: $ref: '#/components/headers/Link' content: application/json: schema: $ref: '#/components/schemas/ArrayOfUserRoles' 404NotFound: description: Not found. MultiUserRoleCredentialResponse: description: A single user role credential or an array of user role credentials. content: application/json: schema: $ref: '#/components/schemas/ArrayOfUserRoleCredentials' SingleUserRole: description: The current state of a user role. headers: ETag: $ref: '#/components/headers/ETag' content: application/json: schema: $ref: '#/components/schemas/UserRole' 500InternalServerError: description: Internal Server Error. content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' 503ServiceUnavailable: description: Service Unavailable. content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' 422EntityNotProcessable: description: Entity Not Processable content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' 403Forbidden: description: Forbidden SingleOrMultiUserRoleCredentialResponse: description: A single user role credential or an array of user role credentials. headers: ETag: $ref: '#/components/headers/ETag' content: application/json: schema: $ref: '#/components/schemas/SingleOrMultiUserRoleCredential' 412PreconditionFailed: description: Precondition Failed. 401Unauthorized: description: Unauthorized. 400BadRequest: description: Bad Request PaginatedArrayOfUserRoleCredentials: description: Paginated user role credentials for an organization. headers: Pagination-Limit: $ref: '#/components/headers/PaginationLimit' Pagination-Current-Page: $ref: '#/components/headers/PaginationCurrentPage' Pagination-Total-Pages: $ref: '#/components/headers/PaginationTotalPages' Pagination-Total-Count: $ref: '#/components/headers/PaginationTotalCount' Link: $ref: '#/components/headers/Link' content: application/json: schema: $ref: '#/components/schemas/ArrayOfUserRoleCredentials' 204NoContent: description: No content. SingleAssetScript: description: An application script. headers: ETag: $ref: '#/components/headers/ETag' content: application/json: schema: $ref: '#/components/schemas/AssetScript' 409Conflict: description: Conflict. content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' parameters: PageQuery: name: page in: query schema: type: integer format: int32 minimum: 1 required: false description: 'Page to retrieve in paginated response. A server-selected default of 1 will be used when no page is requested via query parameter. ' SortDirQuery: name: sortDir in: query schema: type: string enum: - asc - desc default: asc required: false description: Direction of sort-order for items in the response. AssetUIDPath: name: assetUid in: path schema: $ref: '#/components/schemas/AssetUID' required: true description: Unique identifier for an asset. IfMatch: name: If-Match in: header required: true description: 'Used to prevent the lost-update problem. The operation will only continue if the ETag of the resource matches the supplied value; other was a 412 status will be returned. Provide a returned ETag value or * to force the operation. ' schema: type: string pattern: ^(?:\".*\"|\*)$ PerPageQuery: name: perPage in: query schema: type: integer format: int32 minimum: 1 maximum: 5000 required: false description: 'Requested page size for pagination. A server-selected default of 100 will be used when no perPage is requested via query parameter. ' UserRoleUIDPath: name: userRoleUid in: path schema: $ref: '#/components/schemas/UID' required: true description: Unique identifier for an asset user role. ScannableQuery: name: scannable in: query schema: type: boolean required: false description: Constrains the response to include users roles with a matching value for the scannable property. CredentialUIDQuery: name: credentialUid[] in: query explode: true schema: type: array items: $ref: '#/components/schemas/CredentialUID' required: false description: Unique identifier for a credential. If not supplied the request will apply to all credentials the user is authorized to access. ScriptUIDPath: name: scriptUid in: path schema: $ref: '#/components/schemas/UID' required: true description: Unique identifier for an asset script. ApplicationVersionPath: name: version in: path schema: type: string required: true description: The version of an application. CredentialUIDPath: name: credentialUid in: path schema: $ref: '#/components/schemas/UID' required: true description: Unique identifier for an asset credential. securitySchemes: OAuth2: type: oauth2 flows: implicit: authorizationUrl: login.synack.com scopes: asset_lr: Grants per-listing read access for all types of assets. asset_srt_lr: Grants per-listing read access to assets that may be read by SRTs. asset_or: Grants organization-level read access for all types of assets owned by a particular organization. asset_boss_ow: Grants organization-level access to assets owned by a particular organization that may be modified by BOSS users. asset_boss_lw: Grants per-listing write access to assets that may be modified by BOSS users. asset_client_ow: Grants organization-level access to assets owned by a particular organization that may be modified by Client users. asset_client_lw: Grants per-listing write access to assets that may be modified by Client users. asset_user_or: Grants user-level read access to asset stats that owned by a particular organization. asset_gr: Grants unrestricted read access to all assets. Except for credential data of cloud accout assets. asset_gw: Grants unrestricted write access to all assets. asset_scan_gr: Grants unrestricted read access to all assets. Including credential data of cloud account assets.