{ "info": { "_postman_id": "fbffa4b3-7d57-4629-b35d-8ccac7fc7bc2", "name": "ThoughtSpot Public REST 10.1.0.cl Security API", "schema": "https://schema.getpostman.com/json/collection/v2.1.0/collection.json", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "lastUpdatedBy": "35240", "uid": "35240-fbffa4b3-7d57-4629-b35d-8ccac7fc7bc2" }, "item": [ { "name": "api", "item": [ { "name": "rest", "item": [ { "name": "2.0", "item": [ { "name": "security", "item": [ { "name": "metadata", "item": [ { "name": "assign", "item": [ { "name": "assign Change Author", "id": "d2dbc5f7-ca9a-4a57-a377-661a90a7cd53", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"user_identifier\": \"\",\n \"current_owner_identifier\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/assign", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "assign" ] }, "description": "\n Version: 9.0.0.cl or later\n\nTransfers the ownership of one or several objects from one user to another.\n\nRequires `ADMINISTRATION` (**Can administer ThoughtSpot**) privilege.\n\nIf [Role-Based Access Control (RBAC)](https://developers.thoughtspot.com/docs/rbac) is enabled on your instance, the `USER_ADMINISTRATION` (**Can manage users**) privilege and edit access to the objects are required.\n\n\n\n\n#### Endpoint URL\n" }, "response": [ { "id": "cd4897eb-fa21-4f87-88b8-1cded5217581", "name": "Author assignment for given metadata objects is successful.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"user_identifier\": \"\",\n \"current_owner_identifier\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/assign", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "assign" ] } }, "status": "No Content", "code": 204, "_postman_previewlanguage": "text", "header": [], "cookie": [], "responseTime": null, "body": null, "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-cd4897eb-fa21-4f87-88b8-1cded5217581" }, { "id": "1c6b250d-0a15-48ba-a771-3d2e1867a033", "name": "Invalid request.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"user_identifier\": \"\",\n \"current_owner_identifier\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/assign", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "assign" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-1c6b250d-0a15-48ba-a771-3d2e1867a033" }, { "id": "e0853974-5dc7-4d29-ac50-41155f393680", "name": "Unauthorized access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"user_identifier\": \"\",\n \"current_owner_identifier\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/assign", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "assign" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-e0853974-5dc7-4d29-ac50-41155f393680" }, { "id": "9f01ae46-b7f8-4df6-bb71-ec99d50c0bd1", "name": "Forbidden access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"user_identifier\": \"\",\n \"current_owner_identifier\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/assign", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "assign" ] } }, "status": "Forbidden", "code": 403, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-9f01ae46-b7f8-4df6-bb71-ec99d50c0bd1" }, { "id": "ba2b646a-eb9f-4252-a41c-2980acc5bb64", "name": "Unexpected error", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"user_identifier\": \"\",\n \"current_owner_identifier\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/assign", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "assign" ] } }, "status": "Internal Server Error", "code": 500, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-ba2b646a-eb9f-4252-a41c-2980acc5bb64" } ], "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-d2dbc5f7-ca9a-4a57-a377-661a90a7cd53" } ], "id": "4d68216f-4b19-4697-9a3e-56d7dbbef70f", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-4d68216f-4b19-4697-9a3e-56d7dbbef70f" }, { "name": "fetch-object-privileges", "item": [ { "name": "fetch Object Privileges", "id": "613073dd-4f31-4ede-838c-7ca76c97d956", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": 20\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-object-privileges", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-object-privileges" ] }, "description": "\n Version: 26.3.0.cl or later\n\nThis API fetches the object privileges present for the given list of principals (user or group), on the given set of objects. It supports pagination, which can be enabled and configured using the request parameters. It provides users access to certain features based on privilege based access control.\n\n#### Usage guidelines\n\n- Specify the `type` (`USER` or `USER_GROUP`) and `identifier` (either GUID or name) of the principals for which you want to retrieve object privilege information in the `principals` array.\n- Specify the `type` (`LOGICAL_TABLE`) and `identifier` (either GUID or name) of the metadata objects for which you want to retrieve object privilege information in the `metadata` array. Only `LOGICAL_TABLE` metadata type is supported for now. It may be extended for other metadata types in future.\n- To control the offset from where principals have to be fetched, use `record_offset`. When `record_offset` is 0, information is fetched from the beginning.\n- To control the number of principals to be fetched, use `record_size`. Default `record_size` is 20.\n- Ensure `record_offset` for a subsequent request is one more than the value of `record_size` of the previous request.\n- Ensure using correct Authorization Bearer Token corresponding to specific user & org. \n\n#### Example request\n\n```json\n{\n \"principals\": [\n {\n \"type\": \"type-1\",\n \"identifier\": \"principal-guid-or-name-1\"\n },\n {\n \"type\": \"type-2\",\n \"identifier\": \"principal-guid-or-name-2\"\n }\n ],\n \"metadata\": [\n {\n \"type\": \"metadata-type-1\",\n \"identifier\": \"metadata-guid-or-name-1\"\n },\n {\n \"type\": \"metadata-type-2\",\n \"identifier\": \"metadata-guid-or-name-2\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": 20\n}\n```\n\n\n#### Response format\n\nThe API returns an array of `metadata_object_privileges` objects wrapped in JSON. Each `metadata_object_privileges` object contains:\n- Metadata information (GUID, name and type)\n- Array of `principal_object_privilege_info`.\n- Each `principal_object_privilege_info` contains:\n - Principal type. All principals of this type are listed as described below.\n - Array of `principal_object_privileges`.\n - Each `principal_object_privileges` contains:\n - Principal information (GUID, name, subtype)\n - List of applied object level privileges.\n\n#### Example response\n\n```json\n{\n \"metadata_object_privileges\": [\n {\n \"metadata_id\": \"metadata-guid-1\",\n \"metadata_name\": \"metadata-name-1\",\n \"metadata_type\": \"metadata-type-1\",\n \"principal_object_privilege_info\": [\n {\n \"principal_type\": \"principal-type-1\",\n \"principal_object_privileges\": [\n {\n \"principal_id\": \"principal-guid-1\",\n \"principal_name\": \"principal-name-1\",\n \"principal_sub_type\": \"principal-sub-type-1\",\n \"object_privileges\": \"[object-privilege-1, object-privilege-2]\"\n },\n {\n \"principal_id\": \"principal-guid-2\",\n \"principal_name\": \"principal-name-2\",\n \"principal_sub_type\": \"principal-sub-type-2\",\n \"object_privileges\": \"[object-privilege-1, object-privilege-2]\"\n }\n ]\n },\n {\n \"principal_type\": \"principal-type-2\",\n \"principal_object_privileges\": [\n {\n \"principal_id\": \"principal-guid-3\",\n \"principal_name\": \"principal-guid-4\",\n \"principal_sub_type\": \"principal-sub-type-4\",\n \"object_privileges\": \"[object-privilege-1]\"\n }\n ]\n }\n ]\n },\n {\n \"metadata_id\": \"metadata-guid-2\",\n \"metadata_name\": \"metadata-name-2\",\n \"metadata_type\": \"metadata-type-2\",\n \"principal_object_privilege_info\": [\n {\n \"principal_type\": \"principal-type-1\",\n \"principal_object_privileges\": [\n {\n \"principal_id\": \"principal-guid-1\",\n \"principal_name\": \"principal-name-1\",\n \"principal_sub_type\": \"principal-sub-type-1\",\n \"object_privileges\": \"[object-privilege-3, object-privilege-4]\"\n },\n {\n \"principal_id\": \"principal-guid-2\",\n \"principal_name\": \"principal-name-2\",\n \"principal_sub_type\": \"principal-sub-type-2\",\n \"object_privileges\": \"[object-privilege-4]\"\n }\n ]\n }\n ]\n }\n ]\n}\n```\n\n\n\n#### Endpoint URL\n" }, "response": [ { "id": "464cebe9-152b-4020-bf0a-d0f0af435469", "name": "Fetching defined object privileges of metadata objects is successful.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": 20\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-object-privileges", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-object-privileges" ] } }, "status": "OK", "code": 200, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"metadata_object_privileges\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-464cebe9-152b-4020-bf0a-d0f0af435469" }, { "id": "3bc2d46b-6418-461d-95eb-0730ed93b2a6", "name": "Invalid request.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": 20\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-object-privileges", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-object-privileges" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-3bc2d46b-6418-461d-95eb-0730ed93b2a6" }, { "id": "fdcfc3a1-0fc9-4f1a-b252-8784b157c9da", "name": "Unauthorized access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": 20\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-object-privileges", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-object-privileges" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-fdcfc3a1-0fc9-4f1a-b252-8784b157c9da" }, { "id": "3eb54dba-84c1-48de-9cd0-482653aff776", "name": "Forbidden access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": 20\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-object-privileges", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-object-privileges" ] } }, "status": "Forbidden", "code": 403, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-3eb54dba-84c1-48de-9cd0-482653aff776" }, { "id": "49b703f6-ea33-48a4-a275-a8b41fcb0d06", "name": "Unexpected error", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": 20\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-object-privileges", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-object-privileges" ] } }, "status": "Internal Server Error", "code": 500, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-49b703f6-ea33-48a4-a275-a8b41fcb0d06" } ], "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-613073dd-4f31-4ede-838c-7ca76c97d956" } ], "id": "9717a2f5-2364-46d0-a71f-1535c960b295", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-9717a2f5-2364-46d0-a71f-1535c960b295" }, { "name": "fetch-permissions", "item": [ { "name": "fetch Permissions On Metadata", "id": "7cf9148a-7e0c-4135-a935-ef81b44460ca", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ],\n \"include_dependent_objects\": false,\n \"record_offset\": 0,\n \"record_size\": -1,\n \"permission_type\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-permissions" ] }, "description": "\n Version: 9.0.0.cl or later\n\nFetches permission details for a given metadata object.\n\nRequires view access to the metadata object.\n\n#### Usage guidelines\n\n* To fetch a list of users and groups for a metadata object, specify `type` and GUID or name of the metadata object.\n* To get permission details for a specific user or group, add `type` and GUID or name of the principal object to your API request.\n\nUpon successful execution, the API returns permission details and principal information for the object specified in the API request.\n\n\n\n\n#### Endpoint URL\n" }, "response": [ { "id": "7c927b20-0cfe-403c-921e-0eaeec1b8d78", "name": "Fetching permissions of metadata objects is successful.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ],\n \"include_dependent_objects\": false,\n \"record_offset\": 0,\n \"record_size\": -1,\n \"permission_type\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-permissions" ] } }, "status": "OK", "code": 200, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"metadata_permission_details\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-7c927b20-0cfe-403c-921e-0eaeec1b8d78" }, { "id": "a7130f21-4d93-4880-b6fe-ba4794e1664e", "name": "Invalid request.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ],\n \"include_dependent_objects\": false,\n \"record_offset\": 0,\n \"record_size\": -1,\n \"permission_type\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-permissions" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-a7130f21-4d93-4880-b6fe-ba4794e1664e" }, { "id": "9f339078-f9cb-48a9-adb5-824ec5b18e76", "name": "Unauthorized access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ],\n \"include_dependent_objects\": false,\n \"record_offset\": 0,\n \"record_size\": -1,\n \"permission_type\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-permissions" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-9f339078-f9cb-48a9-adb5-824ec5b18e76" }, { "id": "538cfa90-f784-4b5f-93d7-0b01a63b3081", "name": "Forbidden access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ],\n \"include_dependent_objects\": false,\n \"record_offset\": 0,\n \"record_size\": -1,\n \"permission_type\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-permissions" ] } }, "status": "Forbidden", "code": 403, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-538cfa90-f784-4b5f-93d7-0b01a63b3081" }, { "id": "226a8997-3e3d-4c0f-85d5-c95d49242563", "name": "Unexpected error", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ],\n \"include_dependent_objects\": false,\n \"record_offset\": 0,\n \"record_size\": -1,\n \"permission_type\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "fetch-permissions" ] } }, "status": "Internal Server Error", "code": 500, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-226a8997-3e3d-4c0f-85d5-c95d49242563" } ], "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-7cf9148a-7e0c-4135-a935-ef81b44460ca" } ], "id": "b23ff12b-190a-4374-8ee0-5ab9ef6698e7", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-b23ff12b-190a-4374-8ee0-5ab9ef6698e7" }, { "name": "manage-object-privilege", "item": [ { "name": "manage Object Privilege", "id": "e1dfe971-2897-4b05-98d9-43b3fa67f5c5", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"operation\": \"ADD\",\n \"metadata_type\": \"LOGICAL_TABLE\",\n \"object_privilege_types\": [\n \"SPOTTER_COACHING_PRIVILEGE\",\n \"SPOTTER_COACHING_PRIVILEGE\"\n ],\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/manage-object-privilege", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "manage-object-privilege" ] }, "description": "\n Version: 26.3.0.cl or later\n\nThis API allows the addition or deletion of object level privileges for a set of users and groups, on a set of metadata objects. It provides users to access certain features based on privilege based access control.\n\n#### Usage guidelines\n\n- Specify the `operation`. The supported operations are: `ADD`, `REMOVE`.\n- Specify the type of the objects on which the object privileges are being provided in `metadata_type`. Only `LOGICAL_TABLE` metadata type is supported for now. It may be extended for other metadata types in future.\n- Specify the list of object privilege types in the `object_privilege_types` array. The supported object privilege types are: `SPOTTER_COACHING_PRIVILEGE`.\n- Specify the identifiers (either GUID or name) for the metadata objects in the `metadata_identifiers` array.\n- Specify the `type` (`USER` or `USER_GROUP`) and `identifier` (either GUID or name) of the principals to which you want to apply the given operation and given object privileges in the `principals` array.\n- Ensure using correct Authorization Bearer Token corresponding to specific user & org.\n\n#### Example request\n\n```json\n{\n \"operation\": \"operation-type\",\n \"metadata_type\": \"metadata-type\",\n \"object_privilege_types\": [\"privilege-type-1\", \"privilege-type-2\"],\n \"metadata_identifiers\": [\"metadata-guid-or-name-1\", \"metadata-guid-or-name-1\"],\n \"principals\": [\n {\n \"type\": \"type-1\", \n \"identifier\": \"principal-guid-or-name-1\"\n },\n {\n \"type\": \"type-2\",\n \"identifier\": \"principal-guid-or-name-2\"\n }\n ]\n}\n```\n\n> ###### Note:\n> * Only admin users, users with edit access and users with coaching privilege on a given data-model can add or remove principals related to SPOTTER_COACHING_PRIVILEGE \n\n\n\n#### Endpoint URL\n" }, "response": [ { "id": "47cc09e3-cd2e-42d8-abb8-598633a6e381", "name": "Object privileges added/removed successfully", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"operation\": \"ADD\",\n \"metadata_type\": \"LOGICAL_TABLE\",\n \"object_privilege_types\": [\n \"SPOTTER_COACHING_PRIVILEGE\",\n \"SPOTTER_COACHING_PRIVILEGE\"\n ],\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/manage-object-privilege", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "manage-object-privilege" ] } }, "status": "No Content", "code": 204, "_postman_previewlanguage": "text", "header": [], "cookie": [], "responseTime": null, "body": null, "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-47cc09e3-cd2e-42d8-abb8-598633a6e381" }, { "id": "6da01cf9-0f74-488d-bede-15945bb37f90", "name": "Invalid request", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"operation\": \"ADD\",\n \"metadata_type\": \"LOGICAL_TABLE\",\n \"object_privilege_types\": [\n \"SPOTTER_COACHING_PRIVILEGE\",\n \"SPOTTER_COACHING_PRIVILEGE\"\n ],\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/manage-object-privilege", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "manage-object-privilege" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-6da01cf9-0f74-488d-bede-15945bb37f90" }, { "id": "3832d825-3d6a-40dc-9227-753d4b43936e", "name": "Unauthorized access", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"operation\": \"ADD\",\n \"metadata_type\": \"LOGICAL_TABLE\",\n \"object_privilege_types\": [\n \"SPOTTER_COACHING_PRIVILEGE\",\n \"SPOTTER_COACHING_PRIVILEGE\"\n ],\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/manage-object-privilege", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "manage-object-privilege" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-3832d825-3d6a-40dc-9227-753d4b43936e" }, { "id": "adfdfd62-6b86-42f8-89a7-219a215ef696", "name": "Forbidden access", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"operation\": \"ADD\",\n \"metadata_type\": \"LOGICAL_TABLE\",\n \"object_privilege_types\": [\n \"SPOTTER_COACHING_PRIVILEGE\",\n \"SPOTTER_COACHING_PRIVILEGE\"\n ],\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/manage-object-privilege", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "manage-object-privilege" ] } }, "status": "Forbidden", "code": 403, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-adfdfd62-6b86-42f8-89a7-219a215ef696" }, { "id": "b9ac9ea5-ee62-4378-8ed8-2d3bcfe4981c", "name": "Unexpected error", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"operation\": \"ADD\",\n \"metadata_type\": \"LOGICAL_TABLE\",\n \"object_privilege_types\": [\n \"SPOTTER_COACHING_PRIVILEGE\",\n \"SPOTTER_COACHING_PRIVILEGE\"\n ],\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/manage-object-privilege", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "manage-object-privilege" ] } }, "status": "Internal Server Error", "code": 500, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-b9ac9ea5-ee62-4378-8ed8-2d3bcfe4981c" } ], "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-e1dfe971-2897-4b05-98d9-43b3fa67f5c5" } ], "id": "0fa285b9-2968-428b-979f-edc18f0332a3", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-0fa285b9-2968-428b-979f-edc18f0332a3" }, { "name": "publish", "item": [ { "name": "publish Metadata", "id": "0da53e55-dc85-404a-8cc0-98af9c81457f", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"skip_validation\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/publish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "publish" ] }, "description": "\n Version: 26.5.0.cl or later\n\nAllows publishing metadata objects across organizations in ThoughtSpot.\n\nRequires ADMINISTRATION role and TENANT scope.\n\nThe API endpoint allows publishing the following types of metadata objects:\n* Liveboards\n* Answers\n* Logical Tables\n\nThis API will essentially share the objects along with it's dependencies to\nthe org admins of the orgs to which it is being published.\n\n\n\n\n#### Endpoint URL\n" }, "response": [ { "id": "ac2fc468-6290-458c-b376-980d5d831186", "name": "Publishing metadata objects is successful.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"skip_validation\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/publish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "publish" ] } }, "status": "No Content", "code": 204, "_postman_previewlanguage": "text", "header": [], "cookie": [], "responseTime": null, "body": null, "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-ac2fc468-6290-458c-b376-980d5d831186" }, { "id": "2f667da1-dde6-4b50-8ce3-8713516b0174", "name": "Invalid request.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"skip_validation\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/publish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "publish" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-2f667da1-dde6-4b50-8ce3-8713516b0174" }, { "id": "d56a0954-94ca-441c-84b2-bccaf7d7a6cf", "name": "Unauthorized access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"skip_validation\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/publish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "publish" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-d56a0954-94ca-441c-84b2-bccaf7d7a6cf" }, { "id": "44a470b5-786b-4803-b491-13f1bebd24be", "name": "Forbidden access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"skip_validation\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/publish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "publish" ] } }, "status": "Forbidden", "code": 403, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-44a470b5-786b-4803-b491-13f1bebd24be" }, { "id": "fac8c0ba-5ffd-4735-be71-061ad0f9a840", "name": "Unexpected error", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LOGICAL_TABLE\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"skip_validation\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/publish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "publish" ] } }, "status": "Internal Server Error", "code": 500, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-fac8c0ba-5ffd-4735-be71-061ad0f9a840" } ], "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-0da53e55-dc85-404a-8cc0-98af9c81457f" } ], "id": "c2eec79b-780e-48bd-a90e-e6556676df6b", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-c2eec79b-780e-48bd-a90e-e6556676df6b" }, { "name": "share", "item": [ { "name": "share Metadata", "id": "938f4c51-e3ea-4fbd-bf9f-459fbcfadb0c", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"permissions\": [\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"READ_ONLY\",\n \"content_share_mode\": \"MODIFY\"\n },\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"MODIFY\",\n \"content_share_mode\": \"MODIFY\"\n }\n ],\n \"message\": \"\",\n \"metadata_type\": \"LOGICAL_COLUMN\",\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n }\n ],\n \"visualization_identifiers\": [\n \"\",\n \"\"\n ],\n \"enable_custom_url\": false,\n \"notify_on_share\": true,\n \"has_lenient_discoverability\": false\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/share", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "share" ] }, "description": "\n Version: 9.0.0.cl or later\n\nAllows sharing one or several metadata objects with users and groups in ThoughtSpot.\n\nRequires edit access to the metadata object.\n\n#### Supported metadata objects:\n* Liveboards\n* Visualizations\n* Answers\n* Models\n* Views\n* Connections\n* Collections\n\n#### Object permissions\n\nYou can provide `READ_ONLY` or `MODIFY` access when sharing an object with another user or group. The `READ_ONLY` permission grants view access to the shared object, whereas `MODIFY` provides edit access.\n\nTo prevent a user or group from accessing the shared object, specify the GUID or name of the principal and set `shareMode` to `NO_ACCESS`.\n\n#### Sharing a visualization\n\n* Sharing a visualization implicitly shares the entire Liveboard with the recipient.\n* Object permissions set for a shared visualization also apply to the Liveboard unless overridden by another API request or via UI.\n* If email notifications for object sharing are enabled, a notification with a link to the shared visualization will be sent to the recipient\u2019s email address. Although this link opens the shared visualization, recipients can also access other visualizations in the Liveboard.\n\n#### Sharing a collection\n\nCollections support **dual permissions** that provide fine-grained control:\n\n* **Collection permissions** (`share_mode`) - controls access to the collection itself (view, edit, delete the collection)\n* **Content permissions** (`content_share_mode`) - controls access to objects within the collection (view, edit objects inside)\n\n**Default Behavior:**\n- If only `share_mode` is specified, the content permissions default to `READ_ONLY` (except when `share_mode` is `NO_ACCESS`, then content also gets `NO_ACCESS`)\n- To give users edit access to collection contents, explicitly set `content_share_mode: \"MODIFY\"`\n\n## Examples\n\nThe following JSON examples can be copy-pasted as request bodies for the REST v2 API endpoint:\n\n```bash\nPOST /callosum/v1/v2/security/metadata/share\nContent-Type: application/x-www-form-urlencoded\n```\n\n### Basic collection sharing\nShare a collection with read-only access:\n\n```json\n{\n \"metadata_type\": \"COLLECTION\",\n \"metadata_identifiers\": [\"Sales Reports Collection\"],\n \"permissions\": [{\n \"principal\": {\n \"type\": \"USER\",\n \"identifier\": \"alice@company.com\"\n },\n \"share_mode\": \"READ_ONLY\"\n }],\n \"notification\": {\n \"message\": \"I've shared the Sales Reports collection with you\",\n \"notify_on_share\": true\n }\n}\n```\n\n### Collection sharing with dual permissions\nShare a collection with different permissions for the collection vs. its contents:\n\n```json\n{\n \"metadata_type\": \"COLLECTION\",\n \"metadata_identifiers\": [\"Marketing Analytics\"],\n \"permissions\": [{\n \"principal\": {\n \"type\": \"USER\",\n \"identifier\": \"bob@company.com\"\n },\n \"share_mode\": \"MODIFY\",\n \"content_share_mode\": \"READ_ONLY\"\n }, {\n \"principal\": {\n \"type\": \"USER_GROUP\",\n \"identifier\": \"Marketing Team\"\n },\n \"share_mode\": \"READ_ONLY\",\n \"content_share_mode\": \"READ_ONLY\"\n }],\n \"notification\": {\n \"emails\": [\"bob@company.com\"],\n \"message\": \"You can edit the collection but content is read-only\",\n \"enable_custom_url\": false,\n \"notify_on_share\": true\n },\n \"has_lenient_discoverability\": false\n}\n```\n\n### Multiple collections sharing\nShare multiple collections with different users:\n\n```json\n{\n \"metadata\": [\n {\n \"type\": \"COLLECTION\",\n \"identifier\": \"Q4 Reports\"\n },\n {\n \"type\": \"COLLECTION\",\n \"identifier\": \"Executive Dashboard Collection\"\n }\n ],\n \"permissions\": [{\n \"principal\": {\n \"type\": \"USER_GROUP\",\n \"identifier\": \"Executives\"\n },\n \"share_mode\": \"MODIFY\"\n }, {\n \"principal\": {\n \"type\": \"USER\",\n \"identifier\": \"manager@company.com\"\n },\n \"share_mode\": \"READ_ONLY\",\n \"content_share_mode\": \"MODIFY\"\n }],\n \"notification\": {\n \"message\": \"Sharing quarterly collections with leadership team\",\n \"notify_on_share\": true\n }\n}\n```\n\n### Remove collection access\nRemove access to a collection by setting share_mode to NO_ACCESS:\n\n```json\n{\n \"metadata_type\": \"COLLECTION\",\n \"metadata_identifiers\": [\"Confidential Reports\"],\n \"permissions\": [{\n \"principal\": {\n \"type\": \"USER\",\n \"identifier\": \"former-employee@company.com\"\n },\n \"share_mode\": \"NO_ACCESS\"\n }],\n \"notification\": {\n \"notify_on_share\": false\n }\n}\n```\n\n### Collection Permission Scenarios\n\n**Scenario 1: Collection Admin**\n- `share_mode: MODIFY` + `content_share_mode: MODIFY` = Full control over collection and its contents\n\n**Scenario 2: Collection Curator**\n- `share_mode: MODIFY` + `content_share_mode: READ_ONLY` = Can manage collection structure but not edit contents\n\n**Scenario 3: Content Editor**\n- `share_mode: READ_ONLY` + `content_share_mode: MODIFY` = Can edit objects within collection but can't change collection itself\n\n**Scenario 4: Viewer**\n- `share_mode: READ_ONLY` + `content_share_mode: READ_ONLY` = View-only access to collection and contents\n\n\n\n\n#### Endpoint URL\n" }, "response": [ { "id": "eb6ec202-a4bb-4943-a8a8-816626e3c13b", "name": "Sharing metadata objects is successful.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"permissions\": [\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"READ_ONLY\",\n \"content_share_mode\": \"MODIFY\"\n },\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"MODIFY\",\n \"content_share_mode\": \"MODIFY\"\n }\n ],\n \"message\": \"\",\n \"metadata_type\": \"LOGICAL_COLUMN\",\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n }\n ],\n \"visualization_identifiers\": [\n \"\",\n \"\"\n ],\n \"enable_custom_url\": false,\n \"notify_on_share\": true,\n \"has_lenient_discoverability\": false\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/share", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "share" ] } }, "status": "No Content", "code": 204, "_postman_previewlanguage": "text", "header": [], "cookie": [], "responseTime": null, "body": null, "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-eb6ec202-a4bb-4943-a8a8-816626e3c13b" }, { "id": "8a8023c1-db98-45b7-ae2f-44d4019cb8b0", "name": "Invalid request.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"permissions\": [\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"READ_ONLY\",\n \"content_share_mode\": \"MODIFY\"\n },\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"MODIFY\",\n \"content_share_mode\": \"MODIFY\"\n }\n ],\n \"message\": \"\",\n \"metadata_type\": \"LOGICAL_COLUMN\",\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n }\n ],\n \"visualization_identifiers\": [\n \"\",\n \"\"\n ],\n \"enable_custom_url\": false,\n \"notify_on_share\": true,\n \"has_lenient_discoverability\": false\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/share", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "share" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-8a8023c1-db98-45b7-ae2f-44d4019cb8b0" }, { "id": "0f68af6a-4450-4ea6-b9a7-74e479e3f9a0", "name": "Unauthorized access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"permissions\": [\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"READ_ONLY\",\n \"content_share_mode\": \"MODIFY\"\n },\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"MODIFY\",\n \"content_share_mode\": \"MODIFY\"\n }\n ],\n \"message\": \"\",\n \"metadata_type\": \"LOGICAL_COLUMN\",\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n }\n ],\n \"visualization_identifiers\": [\n \"\",\n \"\"\n ],\n \"enable_custom_url\": false,\n \"notify_on_share\": true,\n \"has_lenient_discoverability\": false\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/share", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "share" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-0f68af6a-4450-4ea6-b9a7-74e479e3f9a0" }, { "id": "553e8416-1f31-46e0-b6ce-72aa92558494", "name": "Forbidden access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"permissions\": [\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"READ_ONLY\",\n \"content_share_mode\": \"MODIFY\"\n },\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"MODIFY\",\n \"content_share_mode\": \"MODIFY\"\n }\n ],\n \"message\": \"\",\n \"metadata_type\": \"LOGICAL_COLUMN\",\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n }\n ],\n \"visualization_identifiers\": [\n \"\",\n \"\"\n ],\n \"enable_custom_url\": false,\n \"notify_on_share\": true,\n \"has_lenient_discoverability\": false\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/share", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "share" ] } }, "status": "Forbidden", "code": 403, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-553e8416-1f31-46e0-b6ce-72aa92558494" }, { "id": "27030586-4371-42ba-85fc-7e51683840a1", "name": "Unexpected error", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"permissions\": [\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"READ_ONLY\",\n \"content_share_mode\": \"MODIFY\"\n },\n {\n \"principal\": {\n \"identifier\": \"\",\n \"type\": \"USER\"\n },\n \"share_mode\": \"MODIFY\",\n \"content_share_mode\": \"MODIFY\"\n }\n ],\n \"message\": \"\",\n \"metadata_type\": \"LOGICAL_COLUMN\",\n \"metadata_identifiers\": [\n \"\",\n \"\"\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n }\n ],\n \"visualization_identifiers\": [\n \"\",\n \"\"\n ],\n \"enable_custom_url\": false,\n \"notify_on_share\": true,\n \"has_lenient_discoverability\": false\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/share", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "share" ] } }, "status": "Internal Server Error", "code": 500, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-27030586-4371-42ba-85fc-7e51683840a1" } ], "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-938f4c51-e3ea-4fbd-bf9f-459fbcfadb0c" } ], "id": "a1e215e8-f1f4-4458-a8d3-a79621968548", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-a1e215e8-f1f4-4458-a8d3-a79621968548" }, { "name": "unpublish", "item": [ { "name": "unpublish Metadata", "id": "231ef4a5-c1cc-405e-b79c-c0b9ceae0358", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"include_dependencies\": \"\",\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"force\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/unpublish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "unpublish" ] }, "description": "\n Version: 26.5.0.cl or later\n\nAllows unpublishing metadata objects from organizations in ThoughtSpot.\n\nRequires ADMINISTRATION role and TENANT scope.\n\nThe API endpoint allows unpublishing the following types of metadata objects:\n* Liveboards\n* Answers\n* Logical Tables\n\nWhen unpublishing objects, you can:\n* Include dependencies by setting `include_dependencies` to true - this will unpublish all dependent objects if no other published object is using them\n* Force unpublish by setting `force` to true - this will break all dependent objects in the unpublished organizations\n\n\n\n\n#### Endpoint URL\n" }, "response": [ { "id": "ecb3b38b-d848-474c-bc4c-721cb5aea668", "name": "Unpublishing metadata objects is successful.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"include_dependencies\": \"\",\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"force\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/unpublish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "unpublish" ] } }, "status": "No Content", "code": 204, "_postman_previewlanguage": "text", "header": [], "cookie": [], "responseTime": null, "body": null, "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-ecb3b38b-d848-474c-bc4c-721cb5aea668" }, { "id": "99e8e42d-f8ac-4ae5-881a-223b200065bf", "name": "Invalid request.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"include_dependencies\": \"\",\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"force\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/unpublish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "unpublish" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-99e8e42d-f8ac-4ae5-881a-223b200065bf" }, { "id": "b9714b4a-1001-447a-9e90-72ab52691ecd", "name": "Unauthorized access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"include_dependencies\": \"\",\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"force\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/unpublish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "unpublish" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-b9714b4a-1001-447a-9e90-72ab52691ecd" }, { "id": "82db14a6-fe13-4fa7-bc2c-17b5489682b8", "name": "Forbidden access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"include_dependencies\": \"\",\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"force\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/unpublish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "unpublish" ] } }, "status": "Forbidden", "code": 403, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-82db14a6-fe13-4fa7-bc2c-17b5489682b8" }, { "id": "70eb1b2b-2fa1-4842-81ab-7321c3bc9bf3", "name": "Unexpected error", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"include_dependencies\": \"\",\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"ANSWER\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"org_identifiers\": [\n \"\",\n \"\"\n ],\n \"force\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/metadata/unpublish", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "metadata", "unpublish" ] } }, "status": "Internal Server Error", "code": 500, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-70eb1b2b-2fa1-4842-81ab-7321c3bc9bf3" } ], "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-231ef4a5-c1cc-405e-b79c-c0b9ceae0358" } ], "id": "edb8b37b-b584-4941-9fd6-993d01fc5fff", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-edb8b37b-b584-4941-9fd6-993d01fc5fff" } ], "id": "f69fb18a-c97c-4991-9be3-1a5d94d00d93", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-f69fb18a-c97c-4991-9be3-1a5d94d00d93" }, { "name": "column", "item": [ { "name": "rules", "item": [ { "name": "fetch", "item": [ { "name": "fetch Column Security Rules", "id": "fc9da610-9083-4c6d-840a-f64446c1c38f", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"tables\": [\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n },\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/fetch", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "fetch" ] }, "description": "\nBeta Version: 10.12.0.cl or later\n\nFetches column security rules for specified tables.\n\nThis API endpoint retrieves column-level security rules configured for tables. It returns information about which columns are secured and which groups have access to those columns.\n\n#### Usage guidelines\n\n- Provide an array of table identifiers using either `identifier` (GUID or name) or `obj_identifier` (object ID)\n- At least one of `identifier` or `obj_identifier` must be provided for each table\n- The API returns column security rules for all specified tables\n- Users must have appropriate permissions to access security rules for the specified tables\n\n#### Required permissions\n\n- `ADMINISTRATION` - Can administer ThoughtSpot\n- `DATAMANAGEMENT` - Can manage data\n- `CAN_MANAGE_WORKSHEET_VIEWS_TABLES` - Can manage worksheet views and tables\n\n#### Example request\n\n```json\n{\n \"tables\": [\n {\n \"identifier\": \"table-guid\",\n \"obj_identifier\": \"table-object-id\"\n }\n ]\n}\n```\n\n#### Response format\n\nThe API returns an array of `ColumnSecurityRuleResponse` objects wrapped in a `data` field. Each `ColumnSecurityRuleResponse` object contains:\n- Table information (GUID and object ID) \n- Array of column security rules with column details, group access, and source table information\n\n#### Example response\n\n```json\n{\n \"data\": [\n {\n \"guid\": \"table-guid\",\n \"objId\": \"table-object-id\",\n \"columnSecurityRules\": [\n {\n \"column\": {\n \"id\": \"col_123\",\n \"name\": \"Salary\"\n },\n \"groups\": [\n {\n \"id\": \"group_1\",\n \"name\": \"HR Department\"\n }\n ],\n \"sourceTableDetails\": {\n \"id\": \"source-table-guid\",\n \"name\": \"Employee_Data\"\n }\n }\n ]\n }\n ]\n}\n```\n\n\n\n#### Endpoint URL\n" }, "response": [ { "id": "3e20107d-0d4c-4b14-b913-e8677519b7b1", "name": "Successfully fetched column security rules", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"tables\": [\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n },\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/fetch", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "fetch" ] } }, "status": "OK", "code": 200, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "[\n {\n \"table_guid\": \"\",\n \"obj_id\": \"\",\n \"column_security_rules\": [\n {\n \"column\": {\n \"id\": \"\",\n \"name\": \"\"\n },\n \"groups\": [\n {\n \"id\": \"\",\n \"name\": \"\"\n },\n {\n \"id\": \"\",\n \"name\": \"\"\n }\n ],\n \"source_table_details\": {\n \"id\": \"\",\n \"name\": \"\"\n }\n },\n {\n \"column\": {\n \"id\": \"\",\n \"name\": \"\"\n },\n \"groups\": [\n {\n \"id\": \"\",\n \"name\": \"\"\n },\n {\n \"id\": \"\",\n \"name\": \"\"\n }\n ],\n \"source_table_details\": {\n \"id\": \"\",\n \"name\": \"\"\n }\n }\n ]\n },\n {\n \"table_guid\": \"\",\n \"obj_id\": \"\",\n \"column_security_rules\": [\n {\n \"column\": {\n \"id\": \"\",\n \"name\": \"\"\n },\n \"groups\": [\n {\n \"id\": \"\",\n \"name\": \"\"\n },\n {\n \"id\": \"\",\n \"name\": \"\"\n }\n ],\n \"source_table_details\": {\n \"id\": \"\",\n \"name\": \"\"\n }\n },\n {\n \"column\": {\n \"id\": \"\",\n \"name\": \"\"\n },\n \"groups\": [\n {\n \"id\": \"\",\n \"name\": \"\"\n },\n {\n \"id\": \"\",\n \"name\": \"\"\n }\n ],\n \"source_table_details\": {\n \"id\": \"\",\n \"name\": \"\"\n }\n }\n ]\n }\n]", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-3e20107d-0d4c-4b14-b913-e8677519b7b1" }, { "id": "95210dd2-aa43-432e-8310-9d25f91e8515", "name": "Bad request - Table not found or invalid parameters", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"tables\": [\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n },\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/fetch", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "fetch" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-95210dd2-aa43-432e-8310-9d25f91e8515" }, { "id": "9a736cbb-4ff5-43d5-a723-a4f08e1c5da0", "name": "Unauthorized access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"tables\": [\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n },\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/fetch", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "fetch" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-9a736cbb-4ff5-43d5-a723-a4f08e1c5da0" }, { "id": "1e7a36d1-8e01-41ac-84f4-e4814962cca5", "name": "Forbidden - User doesn't have permission to access security rules for this table", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"tables\": [\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n },\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/fetch", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "fetch" ] } }, "status": "Forbidden", "code": 403, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-1e7a36d1-8e01-41ac-84f4-e4814962cca5" }, { "id": "dff8f35b-e082-49be-8cab-ea7b06e73d07", "name": "Internal server error", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"tables\": [\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n },\n {\n \"identifier\": \"\",\n \"obj_identifier\": \"\"\n }\n ]\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/fetch", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "fetch" ] } }, "status": "Internal Server Error", "code": 500, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-dff8f35b-e082-49be-8cab-ea7b06e73d07" } ], "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-fc9da610-9083-4c6d-840a-f64446c1c38f" } ], "id": "726c00e5-8968-4757-a1fd-298c5bef9069", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-726c00e5-8968-4757-a1fd-298c5bef9069" }, { "name": "update", "item": [ { "name": "update Column Security Rules", "id": "011ae333-f162-40a2-925d-8e7d2a67c58f", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"column_security_rules\": [\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REMOVE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n },\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n }\n ],\n \"identifier\": \"\",\n \"obj_identifier\": \"\",\n \"clear_csr\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/update", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "update" ] }, "description": "\nBeta Version: 10.12.0.cl or later\n\nCreates, updates, or deletes column security rules for specified tables.\n\nThis API endpoint allows you to create, update, or delete column-level security rules on columns of a table. The operation follows an \"all or none\" policy: if defining security rules for any of the provided columns fails, the entire operation will be rolled back, and no rules will be created.\n\n#### Usage guidelines\n\n- Provide table identifier using either `identifier` (GUID or name) or `obj_identifier` (object ID)\n- Use `clear_csr: true` to remove all column security rules from the table\n- For each column, specify the security rule using `column_security_rules` array\n- Use `is_unsecured: true` to mark a specific column as unprotected\n- Use `group_access` operations to manage group associations:\n - `ADD`: Add groups to the column's access list\n - `REMOVE`: Remove groups from the column's access list\n - `REPLACE`: Replace all existing groups with the specified groups\n\n#### Required permissions\n\n- `ADMINISTRATION` - Can administer ThoughtSpot\n- `DATAMANAGEMENT` - Can manage data (if RBAC is disabled)\n- `CAN_MANAGE_WORKSHEET_VIEWS_TABLES` - Can manage worksheet views and tables (if RBAC is enabled)\n\n#### Example request\n\n```json\n{\n \"identifier\": \"table-guid\",\n \"obj_identifier\": \"table-object-id\",\n \"clear_csr\": false,\n \"column_security_rules\": [\n {\n \"column_identifier\": \"col id or col name\",\n \"is_unsecured\": false,\n \"group_access\": [\n {\n \"operation\": \"ADD\",\n \"group_identifiers\": [\"hr_group_id\", \"hr_group_name\", \"finance_group_id\"]\n }\n ]\n },\n {\n \"column_identifier\": \"col id or col name\",\n \"is_unsecured\": true\n },\n {\n \"column_identifier\": \"col id or col name\",\n \"is_unsecured\": false,\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\"management_group_id\", \"management_group_name\"]\n }\n ]\n }\n ]\n}\n```\n\n#### Request Body Schema\n\n- `identifier` (string, optional): GUID or name of the table for which we want to create column security rules\n- `obj_identifier` (string, optional): The object ID of the table\n- `clear_csr` (boolean, optional): If true, then all the secured columns will be marked as unprotected, and all the group associations will be removed\n- `column_security_rules` (array of objects, required): An array where each object defines the security rule for a specific column\n\nEach column security rule object contains:\n- `column_identifier` (string, required): Column identifier (col_id or name)\n- `is_unsecured` (boolean, optional): If true, the column will be marked as unprotected and all groups associated with it will be removed\n- `group_access` (array of objects, optional): Array of group operation objects\n\nEach group operation object contains:\n- `operation` (string, required): Operation type - ADD, REMOVE, or REPLACE\n- `group_identifiers` (array of strings, required): Array of group identifiers (name or GUID) on which the operation will be performed\n\n#### Response\n\nThis API does not return any response body. A successful operation returns HTTP 200 status code.\n\n#### Operation Types\n\n- **ADD**: Adds the specified groups to the column's access list\n- **REMOVE**: Removes the specified groups from the column's access list \n- **REPLACE**: Replaces all existing groups with the specified groups \n\n\n\n#### Endpoint URL\n" }, "response": [ { "id": "68b051a4-8ffb-4c4f-aff1-01218c42668e", "name": "Successfully updated column security rules", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"column_security_rules\": [\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REMOVE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n },\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n }\n ],\n \"identifier\": \"\",\n \"obj_identifier\": \"\",\n \"clear_csr\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/update", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "update" ] } }, "status": "No Content", "code": 204, "_postman_previewlanguage": "text", "header": [], "cookie": [], "responseTime": null, "body": null, "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-68b051a4-8ffb-4c4f-aff1-01218c42668e" }, { "id": "5dc5e0ac-5aaf-49de-9214-9634c2886674", "name": "Bad request - Invalid parameters or table not found", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"column_security_rules\": [\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REMOVE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n },\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n }\n ],\n \"identifier\": \"\",\n \"obj_identifier\": \"\",\n \"clear_csr\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/update", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "update" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-5dc5e0ac-5aaf-49de-9214-9634c2886674" }, { "id": "a0edc384-6b21-42a3-8ce7-dbf2c8e14fc1", "name": "Unauthorized access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"column_security_rules\": [\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REMOVE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n },\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n }\n ],\n \"identifier\": \"\",\n \"obj_identifier\": \"\",\n \"clear_csr\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/update", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "update" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-a0edc384-6b21-42a3-8ce7-dbf2c8e14fc1" }, { "id": "2a7a7061-bdac-4ca2-973e-14f8c2e95762", "name": "Forbidden - User doesn't have permission to modify security rules for this table", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"column_security_rules\": [\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REMOVE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n },\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n }\n ],\n \"identifier\": \"\",\n \"obj_identifier\": \"\",\n \"clear_csr\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/update", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "update" ] } }, "status": "Forbidden", "code": 403, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-2a7a7061-bdac-4ca2-973e-14f8c2e95762" }, { "id": "10268d20-1211-4e0c-bb3a-c23cda4a8c24", "name": "Internal server error", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"column_security_rules\": [\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REMOVE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n },\n {\n \"column_identifier\": \"\",\n \"is_unsecured\": \"\",\n \"group_access\": [\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n },\n {\n \"operation\": \"REPLACE\",\n \"group_identifiers\": [\n \"\",\n \"\"\n ]\n }\n ]\n }\n ],\n \"identifier\": \"\",\n \"obj_identifier\": \"\",\n \"clear_csr\": \"\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/column/rules/update", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "column", "rules", "update" ] } }, "status": "Internal Server Error", "code": 500, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-10268d20-1211-4e0c-bb3a-c23cda4a8c24" } ], "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-011ae333-f162-40a2-925d-8e7d2a67c58f" } ], "id": "0da434ad-bc9d-4185-96b1-dd03f864507b", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-0da434ad-bc9d-4185-96b1-dd03f864507b" } ], "id": "b9681bdc-f885-4b87-9530-5fe4ee2434ad", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-b9681bdc-f885-4b87-9530-5fe4ee2434ad" } ], "id": "4f56773e-a281-4081-8744-7aa215aaf6cc", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-4f56773e-a281-4081-8744-7aa215aaf6cc" }, { "name": "principals", "item": [ { "name": "fetch-permissions", "item": [ { "name": "fetch Permissions Of Principals", "id": "ce606ebc-95ef-4536-9415-3ae8e862d2dc", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": -1,\n \"default_metadata_type\": \"LOGICAL_TABLE\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/principals/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "principals", "fetch-permissions" ] }, "description": "\n Version: 9.0.0.cl or later\n\nFetches object permission details for a given principal object such as a user and group.\n\nRequires view access to the metadata object. \n\n#### Usage guidelines\n\n* To get a list of all metadata objects that a user or group can access, specify the `type` and GUID or name of the principal.\n* To get permission details for a specific object, add the `type` and GUID or name of the metadata object to your API request.\n\nUpon successful execution, the API returns a list of metadata objects and permission details for each object. \n\n\n\n\n#### Endpoint URL\n" }, "response": [ { "id": "d062dd2b-17d6-4378-89ab-e05e760ba266", "name": "Fetching permissions of principals is successful.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": -1,\n \"default_metadata_type\": \"LOGICAL_TABLE\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/principals/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "principals", "fetch-permissions" ] } }, "status": "OK", "code": 200, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"principal_permission_details\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-d062dd2b-17d6-4378-89ab-e05e760ba266" }, { "id": "1a73e424-b1b7-4c9e-aa14-0d97ab2d9517", "name": "Invalid request.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": -1,\n \"default_metadata_type\": \"LOGICAL_TABLE\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/principals/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "principals", "fetch-permissions" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-1a73e424-b1b7-4c9e-aa14-0d97ab2d9517" }, { "id": "ecf46117-1aab-4a49-986f-858c0149c4d6", "name": "Unauthorized access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": -1,\n \"default_metadata_type\": \"LOGICAL_TABLE\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/principals/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "principals", "fetch-permissions" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-ecf46117-1aab-4a49-986f-858c0149c4d6" }, { "id": "c6b8e61f-db0d-4835-8b3a-28c48fc52b30", "name": "Forbidden access.", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": -1,\n \"default_metadata_type\": \"LOGICAL_TABLE\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/principals/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "principals", "fetch-permissions" ] } }, "status": "Forbidden", "code": 403, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-c6b8e61f-db0d-4835-8b3a-28c48fc52b30" }, { "id": "84b84050-1fc7-45bc-b9a6-328a887ea9d7", "name": "Unexpected error", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"principals\": [\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"USER_GROUP\"\n }\n ],\n \"metadata\": [\n {\n \"identifier\": \"\",\n \"type\": \"CONNECTION\"\n },\n {\n \"identifier\": \"\",\n \"type\": \"LIVEBOARD\"\n }\n ],\n \"record_offset\": 0,\n \"record_size\": -1,\n \"default_metadata_type\": \"LOGICAL_TABLE\"\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/api/rest/2.0/security/principals/fetch-permissions", "host": [ "{{baseUrl}}" ], "path": [ "api", "rest", "2.0", "security", "principals", "fetch-permissions" ] } }, "status": "Internal Server Error", "code": 500, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"error\": {}\n}", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-84b84050-1fc7-45bc-b9a6-328a887ea9d7" } ], "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-ce606ebc-95ef-4536-9415-3ae8e862d2dc" } ], "id": "795e9227-d790-478e-bcdb-dde4eb844ea1", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-795e9227-d790-478e-bcdb-dde4eb844ea1" } ], "id": "8862329d-efb3-4c1b-ab32-6c802348d9aa", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-8862329d-efb3-4c1b-ab32-6c802348d9aa" } ], "id": "87078571-1958-4a09-b379-10fd8e37d9cf", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-87078571-1958-4a09-b379-10fd8e37d9cf" } ], "id": "130e52c3-5294-46c7-a374-497f7450708b", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-130e52c3-5294-46c7-a374-497f7450708b" } ], "id": "ec40c377-5beb-4b4e-8245-a951b55f8abf", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-ec40c377-5beb-4b4e-8245-a951b55f8abf" } ], "id": "ca07deb0-5efa-46a9-8d48-6b909dcb069b", "createdAt": "2026-07-28T03:16:34.000Z", "updatedAt": "2026-07-28T03:16:34.000Z", "uid": "35240-ca07deb0-5efa-46a9-8d48-6b909dcb069b" } ], "auth": { "type": "bearer", "bearer": [ { "key": "token", "value": "{{bearerToken}}", "type": "string" } ] }, "variable": [ { "key": "base-url", "value": "https://localhost:443" }, { "key": "baseUrl", "value": "{{base-url}}" } ] }