{"files":{"SKILL.md":"---\nname: datadog-api-v2-collection\ndescription: \"Datadog API V2 Collection API skill. Use when working with Datadog API V2 Collection for api. Covers 1499 endpoints.\"\nversion: 1.0.0\ngenerator: lapsh\n---\n\n# Datadog API V2 Collection\nAPI version: 1.0\n\n## Auth\nOAuth2 | ApiKey DD-API-KEY in header | ApiKey DD-APPLICATION-KEY in header | Bearer bearer\n\n## Base URL\nhttps://api.datadoghq.com\n\n## Setup\n1. Set Authorization header with Bearer token\n2. GET /api/unstable/fleet/tracers -- list all fleet tracers\n3. POST /api/unstable/fleet/schedules -- create first schedule\n\n## Endpoints\n1499 endpoints across 1 group. See references/api-spec.lap for full details.\n\n### Api\n| Method | Path | Description |\n|--------|------|-------------|\n| GET | /api/unstable/fleet/agents/{agent_key}/tracers | List tracers for a specific agent |\n| POST | /api/unstable/fleet/schedules | Create a schedule |\n| DELETE | /api/unstable/fleet/schedules/{id} | Delete a schedule |\n| PATCH | /api/unstable/fleet/schedules/{id} | Update a schedule |\n| POST | /api/unstable/fleet/schedules/{id}/trigger | Trigger a schedule deployment |\n| GET | /api/unstable/fleet/tracers | List all fleet tracers |\n| GET | /api/unstable/llm-obs/config/evaluators/custom | List custom evaluator configurations |\n| DELETE | /api/unstable/llm-obs/config/evaluators/custom/{eval_name} | Delete a custom evaluator configuration |\n| GET | /api/unstable/llm-obs/config/evaluators/custom/{eval_name} | Get a custom evaluator configuration |\n| PUT | /api/unstable/llm-obs/config/evaluators/custom/{eval_name} | Create or update a custom evaluator configuration |\n| GET | /api/v2/actions-datastores | List datastores |\n| POST | /api/v2/actions-datastores | Create datastore |\n| DELETE | /api/v2/actions-datastores/{datastore_id} | Delete datastore |\n| GET | /api/v2/actions-datastores/{datastore_id} | Get datastore |\n| PATCH | /api/v2/actions-datastores/{datastore_id} | Update datastore |\n| DELETE | /api/v2/actions-datastores/{datastore_id}/items | Delete datastore item |\n| GET | /api/v2/actions-datastores/{datastore_id}/items | List datastore items |\n| PATCH | /api/v2/actions-datastores/{datastore_id}/items | Update datastore item |\n| DELETE | /api/v2/actions-datastores/{datastore_id}/items/bulk | Bulk delete datastore items |\n| POST | /api/v2/actions-datastores/{datastore_id}/items/bulk | Bulk write datastore items |\n| GET | /api/v2/actions/app_key_registrations | List App Key Registrations |\n| DELETE | /api/v2/actions/app_key_registrations/{app_key_id} | Unregister an App Key |\n| GET | /api/v2/actions/app_key_registrations/{app_key_id} | Get an existing App Key Registration |\n| PUT | /api/v2/actions/app_key_registrations/{app_key_id} | Register a new App Key |\n| POST | /api/v2/actions/connections | Create a new Action Connection |\n| DELETE | /api/v2/actions/connections/{connection_id} | Delete an existing Action Connection |\n| GET | /api/v2/actions/connections/{connection_id} | Get an existing Action Connection |\n| PATCH | /api/v2/actions/connections/{connection_id} | Update an existing Action Connection |\n| GET | /api/v2/agentless_scanning/accounts/aws | List AWS scan options |\n| POST | /api/v2/agentless_scanning/accounts/aws | Create AWS scan options |\n| DELETE | /api/v2/agentless_scanning/accounts/aws/{account_id} | Delete AWS scan options |\n| GET | /api/v2/agentless_scanning/accounts/aws/{account_id} | Get AWS scan options |\n| PATCH | /api/v2/agentless_scanning/accounts/aws/{account_id} | Update AWS scan options |\n| GET | /api/v2/agentless_scanning/accounts/azure | List Azure scan options |\n| POST | /api/v2/agentless_scanning/accounts/azure | Create Azure scan options |\n| DELETE | /api/v2/agentless_scanning/accounts/azure/{subscription_id} | Delete Azure scan options |\n| GET | /api/v2/agentless_scanning/accounts/azure/{subscription_id} | Get Azure scan options |\n| PATCH | /api/v2/agentless_scanning/accounts/azure/{subscription_id} | Update Azure scan options |\n| GET | /api/v2/agentless_scanning/accounts/gcp | List GCP scan options |\n| POST | /api/v2/agentless_scanning/accounts/gcp | Create GCP scan options |\n| DELETE | /api/v2/agentless_scanning/accounts/gcp/{project_id} | Delete GCP scan options |\n| GET | /api/v2/agentless_scanning/accounts/gcp/{project_id} | Get GCP scan options |\n| PATCH | /api/v2/agentless_scanning/accounts/gcp/{project_id} | Update GCP scan options |\n| GET | /api/v2/agentless_scanning/ondemand/aws | List AWS on demand tasks |\n| POST | /api/v2/agentless_scanning/ondemand/aws | Create AWS on demand task |\n| GET | /api/v2/agentless_scanning/ondemand/aws/{task_id} | Get AWS on demand task |\n| GET | /api/v2/annotation | List annotations |\n| POST | /api/v2/annotation | Create an annotation |\n| GET | /api/v2/annotation/page/{page_id} | Get annotations for a page |\n| DELETE | /api/v2/annotation/{annotation_id} | Delete an annotation |\n| PUT | /api/v2/annotation/{annotation_id} | Update an annotation |\n| PUT | /api/v2/anonymize_users | Anonymize users |\n| GET | /api/v2/api_keys | Get all API keys |\n| POST | /api/v2/api_keys | Create an API key |\n| DELETE | /api/v2/api_keys/{api_key_id} | Delete an API key |\n| GET | /api/v2/api_keys/{api_key_id} | Get API key |\n| PATCH | /api/v2/api_keys/{api_key_id} | Edit an API key |\n| GET | /api/v2/apicatalog/api | List APIs |\n| DELETE | /api/v2/apicatalog/api/{id} | Delete an API |\n| GET | /api/v2/apicatalog/api/{id}/openapi | Get an API |\n| PUT | /api/v2/apicatalog/api/{id}/openapi | Update an API |\n| POST | /api/v2/apicatalog/openapi | Create a new API |\n| GET | /api/v2/apm/config/metrics | Get all span-based metrics |\n| POST | /api/v2/apm/config/metrics | Create a span-based metric |\n| DELETE | /api/v2/apm/config/metrics/{metric_id} | Delete a span-based metric |\n| GET | /api/v2/apm/config/metrics/{metric_id} | Get a span-based metric |\n| PATCH | /api/v2/apm/config/metrics/{metric_id} | Update a span-based metric |\n| GET | /api/v2/apm/config/retention-filters | List all APM retention filters |\n| POST | /api/v2/apm/config/retention-filters | Create a retention filter |\n| PUT | /api/v2/apm/config/retention-filters-execution-order | Re-order retention filters |\n| DELETE | /api/v2/apm/config/retention-filters/{filter_id} | Delete a retention filter |\n| GET | /api/v2/apm/config/retention-filters/{filter_id} | Get a given APM retention filter |\n| PUT | /api/v2/apm/config/retention-filters/{filter_id} | Update a retention filter |\n| GET | /api/v2/apm/services | Get service list |\n| DELETE | /api/v2/app-builder/apps | Delete Multiple Apps |\n| GET | /api/v2/app-builder/apps | List Apps |\n| POST | /api/v2/app-builder/apps | Create App |\n| DELETE | /api/v2/app-builder/apps/{app_id} | Delete App |\n| GET | /api/v2/app-builder/apps/{app_id} | Get App |\n| PATCH | /api/v2/app-builder/apps/{app_id} | Update App |\n| DELETE | /api/v2/app-builder/apps/{app_id}/deployment | Unpublish App |\n| POST | /api/v2/app-builder/apps/{app_id}/deployment | Publish App |\n| PATCH | /api/v2/app-builder/apps/{app_id}/favorite | Update App Favorite Status |\n| PATCH | /api/v2/app-builder/apps/{app_id}/protection-level | Update App Protection Level |\n| POST | /api/v2/app-builder/apps/{app_id}/publish-request | Create Publish Request |\n| POST | /api/v2/app-builder/apps/{app_id}/revert | Revert App |\n| PATCH | /api/v2/app-builder/apps/{app_id}/self-service | Update App Self-Service Status |\n| PATCH | /api/v2/app-builder/apps/{app_id}/tags | Update App Tags |\n| PATCH | /api/v2/app-builder/apps/{app_id}/version-name | Name App Version |\n| GET | /api/v2/app-builder/apps/{app_id}/versions | List App Versions |\n| GET | /api/v2/app-builder/blueprint/{blueprint_id} | Get Blueprint |\n| GET | /api/v2/app-builder/blueprints | List Blueprints |\n| GET | /api/v2/app-builder/blueprints/integration-id/{integration_id} | Get Blueprints by Integration ID |\n| GET | /api/v2/app-builder/blueprints/slugs/{slugs} | Get Blueprints by Slugs |\n| GET | /api/v2/app-builder/tags | List Tags |\n| GET | /api/v2/application_keys | Get all application keys |\n| DELETE | /api/v2/application_keys/{app_key_id} | Delete an application key |\n| GET | /api/v2/application_keys/{app_key_id} | Get an application key |\n| PATCH | /api/v2/application_keys/{app_key_id} | Edit an application key |\n| GET | /api/v2/audit/events | Get a list of Audit Logs events |\n| POST | /api/v2/audit/events/search | Search Audit Logs events |\n| GET | /api/v2/authn_mappings | List all AuthN Mappings |\n| POST | /api/v2/authn_mappings | Create an AuthN Mapping |\n| DELETE | /api/v2/authn_mappings/{authn_mapping_id} | Delete an AuthN Mapping |\n| GET | /api/v2/authn_mappings/{authn_mapping_id} | Get an AuthN Mapping by UUID |\n| PATCH | /api/v2/authn_mappings/{authn_mapping_id} | Edit an AuthN Mapping |\n| GET | /api/v2/bits-ai/investigations | List Bits AI investigations |\n| POST | /api/v2/bits-ai/investigations | Trigger a Bits AI investigation |\n| GET | /api/v2/bits-ai/investigations/{id} | Get a Bits AI investigation |\n| GET | /api/v2/cases | Search cases |\n| POST | /api/v2/cases | Create a case |\n| POST | /api/v2/cases/aggregate | Aggregate cases |\n| POST | /api/v2/cases/bulk | Bulk update cases |\n| GET | /api/v2/cases/count | Count cases |\n| GET | /api/v2/cases/link | List case links |\n| POST | /api/v2/cases/link | Create a case link |\n| DELETE | /api/v2/cases/link/{link_id} | Delete a case link |\n| GET | /api/v2/cases/projects | Get all projects |\n| POST | /api/v2/cases/projects | Create a project |\n| GET | /api/v2/cases/projects/favorites | List project favorites |\n| DELETE | /api/v2/cases/projects/{project_id} | Remove a project |\n| GET | /api/v2/cases/projects/{project_id} | Get the details of a project |\n| PATCH | /api/v2/cases/projects/{project_id} | Update a project |\n| DELETE | /api/v2/cases/projects/{project_id}/favorites | Unfavorite a project |\n| POST | /api/v2/cases/projects/{project_id}/favorites | Favorite a project |\n| GET | /api/v2/cases/projects/{project_id}/notification_rules | Get notification rules |\n| POST | /api/v2/cases/projects/{project_id}/notification_rules | Create a notification rule |\n| DELETE | /api/v2/cases/projects/{project_id}/notification_rules/{notification_rule_id} | Delete a notification rule |\n| PUT | /api/v2/cases/projects/{project_id}/notification_rules/{notification_rule_id} | Update a notification rule |\n| GET | /api/v2/cases/projects/{project_id}/rules | List automation rules |\n| POST | /api/v2/cases/projects/{project_id}/rules | Create an automation rule |\n| DELETE | /api/v2/cases/projects/{project_id}/rules/{rule_id} | Delete an automation rule |\n| GET | /api/v2/cases/projects/{project_id}/rules/{rule_id} | Get an automation rule |\n| PUT | /api/v2/cases/projects/{project_id}/rules/{rule_id} | Update an automation rule |\n| POST | /api/v2/cases/projects/{project_id}/rules/{rule_id}/disable | Disable an automation rule |\n| POST | /api/v2/cases/projects/{project_id}/rules/{rule_id}/enable | Enable an automation rule |\n| GET | /api/v2/cases/types | Get all case types |\n| POST | /api/v2/cases/types | Create a case type |\n| GET | /api/v2/cases/types/custom_attributes | Get all custom attributes |\n| DELETE | /api/v2/cases/types/{case_type_id} | Delete a case type |\n| PUT | /api/v2/cases/types/{case_type_id} | Update a case type |\n| GET | /api/v2/cases/types/{case_type_id}/custom_attributes | Get all custom attributes config of case type |\n| POST | /api/v2/cases/types/{case_type_id}/custom_attributes | Create custom attribute config for a case type |\n| DELETE | /api/v2/cases/types/{case_type_id}/custom_attributes/{custom_attribute_id} | Delete custom attributes config |\n| PUT | /api/v2/cases/types/{case_type_id}/custom_attributes/{custom_attribute_id} | Update custom attribute config |\n| GET | /api/v2/cases/views | List case views |\n| POST | /api/v2/cases/views | Create a case view |\n| DELETE | /api/v2/cases/views/{view_id} | Delete a case view |\n| GET | /api/v2/cases/views/{view_id} | Get a case view |\n| PUT | /api/v2/cases/views/{view_id} | Update a case view |\n| GET | /api/v2/cases/{case_id} | Get the details of a case |\n| POST | /api/v2/cases/{case_id}/archive | Archive case |\n| POST | /api/v2/cases/{case_id}/assign | Assign case |\n| POST | /api/v2/cases/{case_id}/attributes | Update case attributes |\n| POST | /api/v2/cases/{case_id}/comment | Comment case |\n| DELETE | /api/v2/cases/{case_id}/comment/{cell_id} | Delete case comment |\n| PUT | /api/v2/cases/{case_id}/comment/{cell_id} | Update case comment |\n| DELETE | /api/v2/cases/{case_id}/custom_attributes/{custom_attribute_key} | Delete custom attribute from case |\n| POST | /api/v2/cases/{case_id}/custom_attributes/{custom_attribute_key} | Update case custom attribute |\n| POST | /api/v2/cases/{case_id}/description | Update case description |\n| POST | /api/v2/cases/{case_id}/due_date | Update case due date |\n| DELETE | /api/v2/cases/{case_id}/insights | Remove insights from a case |\n| PUT | /api/v2/cases/{case_id}/insights | Add insights to a case |\n| POST | /api/v2/cases/{case_id}/priority | Update case priority |\n| POST | /api/v2/cases/{case_id}/relationships/incidents | Link incident to case |\n| DELETE | /api/v2/cases/{case_id}/relationships/jira_issues | Remove Jira issue link from case |\n| PATCH | /api/v2/cases/{case_id}/relationships/jira_issues | Link existing Jira issue to case |\n| POST | /api/v2/cases/{case_id}/relationships/jira_issues | Create Jira issue for case |\n| POST | /api/v2/cases/{case_id}/relationships/notebook | Create investigation notebook for case |\n| PATCH | /api/v2/cases/{case_id}/relationships/project | Update case project |\n| POST | /api/v2/cases/{case_id}/relationships/servicenow_tickets | Create ServiceNow ticket for case |\n| POST | /api/v2/cases/{case_id}/resolved_reason | Update case resolved reason |\n| POST | /api/v2/cases/{case_id}/status | Update case status |\n| GET | /api/v2/cases/{case_id}/timelines | Get case timeline |\n| POST | /api/v2/cases/{case_id}/title | Update case title |\n| POST | /api/v2/cases/{case_id}/unarchive | Unarchive case |\n| POST | /api/v2/cases/{case_id}/unassign | Unassign case |\n| GET | /api/v2/cases/{case_id}/watchers | List case watchers |\n| DELETE | /api/v2/cases/{case_id}/watchers/{user_uuid} | Unwatch a case |\n| POST | /api/v2/cases/{case_id}/watchers/{user_uuid} | Watch a case |\n| GET | /api/v2/catalog/entity | Get a list of entities |\n| POST | /api/v2/catalog/entity | Create or update entities |\n| POST | /api/v2/catalog/entity/preview | Preview catalog entities |\n| DELETE | /api/v2/catalog/entity/{entity_id} | Delete a single entity |\n| GET | /api/v2/catalog/kind | Get a list of entity kinds |\n| POST | /api/v2/catalog/kind | Create or update kinds |\n| DELETE | /api/v2/catalog/kind/{kind_id} | Delete a single kind |\n| GET | /api/v2/catalog/relation | Get a list of entity relations |\n| POST | /api/v2/change-management/change-request | Create a change request |\n| GET | /api/v2/change-management/change-request/{change_request_id} | Get a change request |\n| PATCH | /api/v2/change-management/change-request/{change_request_id} | Update a change request |\n| POST | /api/v2/change-management/change-request/{change_request_id}/branch | Create a change request branch |\n| DELETE | /api/v2/change-management/change-request/{change_request_id}/decisions/{decision_id} | Delete a change request decision |\n| PATCH | /api/v2/change-management/change-request/{change_request_id}/decisions/{decision_id} | Update a change request decision |\n| GET | /api/v2/ci/github/accounts | List GitHub CI Visibility status |\n| PATCH | /api/v2/ci/github/accounts | Update GitHub CI Visibility status |\n| POST | /api/v2/ci/pipeline | Send pipeline event |\n| POST | /api/v2/ci/pipelines/analytics/aggregate | Aggregate pipelines events |\n| GET | /api/v2/ci/pipelines/events | Get a list of pipelines events |\n| POST | /api/v2/ci/pipelines/events/search | Search pipelines events |\n| PATCH | /api/v2/ci/test-optimization/settings/policies | Update Flaky Tests Management policies |\n| POST | /api/v2/ci/test-optimization/settings/policies | Get Flaky Tests Management policies |\n| DELETE | /api/v2/ci/test-optimization/settings/service | Delete Test Optimization service settings |\n| PATCH | /api/v2/ci/test-optimization/settings/service | Update Test Optimization service settings |\n| POST | /api/v2/ci/test-optimization/settings/service | Get Test Optimization service settings |\n| POST | /api/v2/ci/tests/analytics/aggregate | Aggregate tests events |\n| GET | /api/v2/ci/tests/events | Get a list of tests events |\n| POST | /api/v2/ci/tests/events/search | Search tests events |\n| GET | /api/v2/cloud_auth/aws/persona_mapping | List AWS cloud authentication persona mappings |\n| POST | /api/v2/cloud_auth/aws/persona_mapping | Create an AWS cloud authentication persona mapping |\n| DELETE | /api/v2/cloud_auth/aws/persona_mapping/{persona_mapping_id} | Delete an AWS cloud authentication persona mapping |\n| GET | /api/v2/cloud_auth/aws/persona_mapping/{persona_mapping_id} | Get an AWS cloud authentication persona mapping |\n| POST | /api/v2/cloud_security_management/custom_frameworks | Create a custom framework |\n| DELETE | /api/v2/cloud_security_management/custom_frameworks/{handle}/{version} | Delete a custom framework |\n| GET | /api/v2/cloud_security_management/custom_frameworks/{handle}/{version} | Get a custom framework |\n| PUT | /api/v2/cloud_security_management/custom_frameworks/{handle}/{version} | Update a custom framework |\n| GET | /api/v2/cloud_security_management/resource_filters | List resource filters |\n| PUT | /api/v2/cloud_security_management/resource_filters | Update resource filters |\n| PUT | /api/v2/cloudinventoryservice/syncconfigs | Enable Storage Management for a bucket |\n| DELETE | /api/v2/cloudinventoryservice/syncconfigs/{id} | Delete a Storage Management configuration |\n| POST | /api/v2/code-coverage/branch/summary | Get code coverage summary for a branch |\n| POST | /api/v2/code-coverage/commit/summary | Get code coverage summary for a commit |\n| GET | /api/v2/compliance_findings/rule_based_view | Get the rule-based view of compliance findings |\n| GET | /api/v2/container_images | Get all Container Images |\n| GET | /api/v2/containers | Get All Containers |\n| GET | /api/v2/cost/account_filters/{cloud_account_id} | Get account filters |\n| PATCH | /api/v2/cost/account_filters/{cloud_account_id} | Update account filters |\n| GET | /api/v2/cost/anomalies | List cost anomalies |\n| GET | /api/v2/cost/anomalies/{anomaly_id} | Get cost anomaly |\n| GET | /api/v2/cost/arbitrary_rule | List custom allocation rules |\n| POST | /api/v2/cost/arbitrary_rule | Create custom allocation rule |\n| POST | /api/v2/cost/arbitrary_rule/reorder | Reorder custom allocation rules |\n| GET | /api/v2/cost/arbitrary_rule/status | List custom allocation rule statuses |\n| DELETE | /api/v2/cost/arbitrary_rule/{rule_id} | Delete custom allocation rule |\n| GET | /api/v2/cost/arbitrary_rule/{rule_id} | Get custom allocation rule |\n| PATCH | /api/v2/cost/arbitrary_rule/{rule_id} | Update custom allocation rule |\n| GET | /api/v2/cost/aws_cur_config | List Cloud Cost Management AWS CUR configs |\n| POST | /api/v2/cost/aws_cur_config | Create Cloud Cost Management AWS CUR config |\n| DELETE | /api/v2/cost/aws_cur_config/{cloud_account_id} | Delete Cloud Cost Management AWS CUR config |\n| GET | /api/v2/cost/aws_cur_config/{cloud_account_id} | Get cost AWS CUR config |\n| PATCH | /api/v2/cost/aws_cur_config/{cloud_account_id} | Update Cloud Cost Management AWS CUR config |\n| GET | /api/v2/cost/azure_uc_config | List Cloud Cost Management Azure configs |\n| POST | /api/v2/cost/azure_uc_config | Create Cloud Cost Management Azure configs |\n| DELETE | /api/v2/cost/azure_uc_config/{cloud_account_id} | Delete Cloud Cost Management Azure config |\n| GET | /api/v2/cost/azure_uc_config/{cloud_account_id} | Get cost Azure UC config |\n| PATCH | /api/v2/cost/azure_uc_config/{cloud_account_id} | Update Cloud Cost Management Azure config |\n| PUT | /api/v2/cost/budget | Create or update a budget |\n| POST | /api/v2/cost/budget/csv/validate | Validate CSV budget |\n| PUT | /api/v2/cost/budget/custom-forecast | Create or replace a budget's custom forecast |\n| POST | /api/v2/cost/budget/validate | Validate budget |\n| DELETE | /api/v2/cost/budget/{budget_id} | Delete budget |\n| GET | /api/v2/cost/budget/{budget_id} | Get budget |\n| DELETE | /api/v2/cost/budget/{budget_id}/custom-forecast | Delete a budget's custom forecast |\n| GET | /api/v2/cost/budget/{budget_id}/custom-forecast | Get a budget's custom forecast |\n| GET | /api/v2/cost/budgets | List budgets |\n| GET | /api/v2/cost/commitments/commitment-list | Get commitments list |\n| GET | /api/v2/cost/commitments/coverage/scalar | Get commitments coverage (scalar) |\n| GET | /api/v2/cost/commitments/coverage/timeseries | Get commitments coverage (timeseries) |\n| GET | /api/v2/cost/commitments/on-demand-hot-spots/scalar | Get commitments on-demand hot spots (scalar) |\n| GET | /api/v2/cost/commitments/savings/scalar | Get commitments savings (scalar) |\n| GET | /api/v2/cost/commitments/savings/timeseries | Get commitments savings (timeseries) |\n| GET | /api/v2/cost/commitments/utilization/scalar | Get commitments utilization (scalar) |\n| GET | /api/v2/cost/commitments/utilization/timeseries | Get commitments utilization (timeseries) |\n| GET | /api/v2/cost/custom_costs | List Custom Costs files |\n| PUT | /api/v2/cost/custom_costs | Upload Custom Costs file |\n| DELETE | /api/v2/cost/custom_costs/{file_id} | Delete Custom Costs file |\n| GET | /api/v2/cost/custom_costs/{file_id} | Get Custom Costs file |\n| GET | /api/v2/cost/gcp_uc_config | List Google Cloud Usage Cost configs |\n| POST | /api/v2/cost/gcp_uc_config | Create Google Cloud Usage Cost config |\n| DELETE | /api/v2/cost/gcp_uc_config/{cloud_account_id} | Delete Google Cloud Usage Cost config |\n| GET | /api/v2/cost/gcp_uc_config/{cloud_account_id} | Get Google Cloud Usage Cost config |\n| PATCH | /api/v2/cost/gcp_uc_config/{cloud_account_id} | Update Google Cloud Usage Cost config |\n| GET | /api/v2/cost/oci_config | List Cloud Cost Management OCI configs |\n| POST | /api/v2/cost/recommendations | Search cost recommendations |\n| GET | /api/v2/cost/tag_descriptions | List Cloud Cost Management tag descriptions |\n| DELETE | /api/v2/cost/tag_descriptions/{tag_key} | Delete a Cloud Cost Management tag description |\n| GET | /api/v2/cost/tag_descriptions/{tag_key} | Get a Cloud Cost Management tag description |\n| PUT | /api/v2/cost/tag_descriptions/{tag_key} | Upsert a Cloud Cost Management tag description |\n| GET | /api/v2/cost/tag_descriptions/{tag_key}/generate | Generate a Cloud Cost Management tag description |\n| GET | /api/v2/cost/tag_keys | List Cloud Cost Management tag keys |\n| GET | /api/v2/cost/tag_keys/{tag_key} | Get a Cloud Cost Management tag key |\n| GET | /api/v2/cost/tag_metadata | List Cloud Cost Management tag key metadata |\n| GET | /api/v2/cost/tag_metadata/currency | Get the Cloud Cost Management billing currency |\n| GET | /api/v2/cost/tag_metadata/metrics | List available Cloud Cost Management metrics |\n| GET | /api/v2/cost/tag_metadata/months | List Cloud Cost Management tag metadata months |\n| GET | /api/v2/cost/tag_metadata/orchestrators | List Cloud Cost Management orchestrators |\n| GET | /api/v2/cost/tag_metadata/tag_sources | List Cloud Cost Management tag sources |\n| GET | /api/v2/cost/tags | List Cloud Cost Management tags |\n| GET | /api/v2/cost_by_tag/active_billing_dimensions | Get active billing dimensions for cost attribution |\n| GET | /api/v2/cost_by_tag/monthly_cost_attribution | Get Monthly Cost Attribution |\n| GET | /api/v2/csm/onboarding/agents | Get all CSM Agents |\n| GET | /api/v2/csm/onboarding/coverage_analysis/cloud_accounts | Get the CSM Cloud Accounts Coverage Analysis |\n| GET | /api/v2/csm/onboarding/coverage_analysis/hosts_and_containers | Get the CSM Hosts and Containers Coverage Analysis |\n| GET | /api/v2/csm/onboarding/coverage_analysis/serverless | Get the CSM Serverless Coverage Analysis |\n| GET | /api/v2/csm/onboarding/serverless/agents | Get all CSM Serverless Agents |\n| GET | /api/v2/csm/ownership/settings | Get ownership settings for the org |\n| POST | /api/v2/csm/ownership/settings | Update ownership settings for the org |\n| GET | /api/v2/csm/ownership/settings/untagged | Count untagged findings by ownership confidence |\n| GET | /api/v2/csm/ownership/{resource_id} | List ownership inferences for a resource |\n| GET | /api/v2/csm/ownership/{resource_id}/history | List ownership inference history for a resource |\n| GET | /api/v2/csm/ownership/{resource_id}/{owner_type} | Get an ownership inference by owner type |\n| GET | /api/v2/csm/ownership/{resource_id}/{owner_type}/evidence | Get the evidence for an ownership inference |\n| POST | /api/v2/csm/ownership/{resource_id}/{owner_type}/feedback | Submit feedback on an ownership inference |\n| GET | /api/v2/csm/ownership/{resource_id}/{owner_type}/history | List ownership history by owner type |\n| GET | /api/v2/csm/settings/agentless_hosts | List agentless hosts |\n| GET | /api/v2/csm/settings/agentless_hosts/facet_info | Get agentless host facet info |\n| GET | /api/v2/csm/settings/agentless_hosts/facets | List agentless host facets |\n| GET | /api/v2/csm/settings/hosts | List unified hosts |\n| GET | /api/v2/csm/settings/hosts/facet_info | Get unified host facet info |\n| GET | /api/v2/csm/settings/hosts/facets | List unified host facets |\n| GET | /api/v2/current_user | Get current user |\n| PATCH | /api/v2/current_user | Update current user |\n| GET | /api/v2/current_user/application_keys | Get all application keys owned by current user |\n| POST | /api/v2/current_user/application_keys | Create an application key for current user |\n| DELETE | /api/v2/current_user/application_keys/{app_key_id} | Delete an application key owned by current user |\n| GET | /api/v2/current_user/application_keys/{app_key_id} | Get one application key owned by current user |\n| PATCH | /api/v2/current_user/application_keys/{app_key_id} | Edit an application key owned by current user |\n| DELETE | /api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards | Delete items from a dashboard list |\n| GET | /api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards | Get items of a Dashboard List |\n| POST | /api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards | Add Items to a Dashboard List |\n| PUT | /api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards | Update items of a dashboard list |\n| GET | /api/v2/dashboard/{dashboard_id}/shared | List shared dashboards for a dashboard |\n| POST | /api/v2/dashboard/{dashboard_id}/shared/secure-embed | Create a secure embed for a dashboard |\n| DELETE | /api/v2/dashboard/{dashboard_id}/shared/secure-embed/{token} | Delete a secure embed for a dashboard |\n| GET | /api/v2/dashboard/{dashboard_id}/shared/secure-embed/{token} | Get a secure embed for a dashboard |\n| PATCH | /api/v2/dashboard/{dashboard_id}/shared/secure-embed/{token} | Update a secure embed for a dashboard |\n| GET | /api/v2/dashboards/usage | Get usage stats for all dashboards |\n| GET | /api/v2/dashboards/{dashboard_id}/usage | Get usage stats for a dashboard |\n| GET | /api/v2/data-observability/monitors/runs/{run_id}/status | Get data observability monitor run status |\n| POST | /api/v2/data-observability/monitors/{monitor_id}/run | Run a data observability monitor |\n| GET | /api/v2/datasets | Get all datasets |\n| POST | /api/v2/datasets | Create a dataset |\n| DELETE | /api/v2/datasets/{dataset_id} | Delete a dataset |\n| GET | /api/v2/datasets/{dataset_id} | Get a single dataset by ID |\n| PUT | /api/v2/datasets/{dataset_id} | Edit a dataset |\n| POST | /api/v2/ddsql/query/tabular | Execute a tabular DDSQL query |\n| POST | /api/v2/ddsql/query/tabular/fetch | Fetch the result of a DDSQL query |\n| POST | /api/v2/deletion/data/{product} | Creates a data deletion request |\n| GET | /api/v2/deletion/requests | Gets a list of data deletion requests |\n| PUT | /api/v2/deletion/requests/{id}/cancel | Cancels a data deletion request |\n| GET | /api/v2/deployment_gates | Get all deployment gates |\n| POST | /api/v2/deployment_gates | Create deployment gate |\n| GET | /api/v2/deployment_gates/{gate_id}/rules | Get rules for a deployment gate |\n| POST | /api/v2/deployment_gates/{gate_id}/rules | Create deployment rule |\n| DELETE | /api/v2/deployment_gates/{gate_id}/rules/{id} | Delete deployment rule |\n| GET | /api/v2/deployment_gates/{gate_id}/rules/{id} | Get deployment rule |\n| PUT | /api/v2/deployment_gates/{gate_id}/rules/{id} | Update deployment rule |\n| DELETE | /api/v2/deployment_gates/{id} | Delete deployment gate |\n| GET | /api/v2/deployment_gates/{id} | Get deployment gate |\n| PUT | /api/v2/deployment_gates/{id} | Update deployment gate |\n| POST | /api/v2/deployments/gates/evaluation | Trigger a deployment gate evaluation |\n| GET | /api/v2/deployments/gates/evaluation/{id} | Get a deployment gate evaluation result |\n| GET | /api/v2/domain_allowlist | Get Domain Allowlist |\n| PATCH | /api/v2/domain_allowlist | Sets Domain Allowlist |\n| POST | /api/v2/dora/deployment | Send a deployment event |\n| DELETE | /api/v2/dora/deployment/{deployment_id} | Delete a deployment event |\n| PATCH | /api/v2/dora/deployments | Patch a deployment event by version |\n| POST | /api/v2/dora/deployments | Get a list of deployment events |\n| GET | /api/v2/dora/deployments/{deployment_id} | Get a deployment event |\n| PATCH | /api/v2/dora/deployments/{deployment_id} | Patch a deployment event |\n| POST | /api/v2/dora/failure | Send an incident event |\n| DELETE | /api/v2/dora/failure/{failure_id} | Delete an incident event |\n| POST | /api/v2/dora/failures | Get a list of incident events |\n| GET | /api/v2/dora/failures/{failure_id} | Get an incident event |\n| POST | /api/v2/dora/incident | Send an incident event (legacy) |\n| GET | /api/v2/downtime | Get all downtimes |\n| POST | /api/v2/downtime | Schedule a downtime |\n| DELETE | /api/v2/downtime/{downtime_id} | Cancel a downtime |\n| GET | /api/v2/downtime/{downtime_id} | Get a downtime |\n| PATCH | /api/v2/downtime/{downtime_id} | Update a downtime |\n| POST | /api/v2/error-tracking/issues/search | Search error tracking issues |\n| GET | /api/v2/error-tracking/issues/{issue_id} | Get the details of an error tracking issue |\n| DELETE | /api/v2/error-tracking/issues/{issue_id}/assignee | Remove the assignee of an issue |\n| PUT | /api/v2/error-tracking/issues/{issue_id}/assignee | Update the assignee of an issue |\n| PUT | /api/v2/error-tracking/issues/{issue_id}/state | Update the state of an issue |\n| GET | /api/v2/events | Get a list of events |\n| POST | /api/v2/events | Post an event |\n| POST | /api/v2/events/search | Search events |\n| GET | /api/v2/events/{event_id} | Get an event |\n| GET | /api/v2/feature-flags | List feature flags |\n| POST | /api/v2/feature-flags | Create a feature flag |\n| GET | /api/v2/feature-flags/environments | List environments |\n| POST | /api/v2/feature-flags/environments | Create an environment |\n| DELETE | /api/v2/feature-flags/environments/{environment_id} | Delete an environment |\n| GET | /api/v2/feature-flags/environments/{environment_id} | Get an environment |\n| PUT | /api/v2/feature-flags/environments/{environment_id} | Update an environment |\n| POST | /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/pause | Pause a progressive rollout |\n| POST | /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/resume | Resume a progressive rollout |\n| POST | /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/start | Start a progressive rollout |\n| POST | /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/stop | Stop a progressive rollout |\n| GET | /api/v2/feature-flags/{feature_flag_id} | Get a feature flag |\n| PUT | /api/v2/feature-flags/{feature_flag_id} | Update a feature flag |\n| POST | /api/v2/feature-flags/{feature_flag_id}/archive | Archive a feature flag |\n| POST | /api/v2/feature-flags/{feature_flag_id}/environments/{environment_id}/allocations | Create targeting rules for a flag env |\n| PUT | /api/v2/feature-flags/{feature_flag_id}/environments/{environment_id}/allocations | Update targeting rules for a flag |\n| POST | /api/v2/feature-flags/{feature_flag_id}/environments/{environment_id}/disable | Disable a feature flag in an environment |\n| POST | /api/v2/feature-flags/{feature_flag_id}/environments/{environment_id}/enable | Enable a feature flag in an environment |\n| POST | /api/v2/feature-flags/{feature_flag_id}/unarchive | Unarchive a feature flag |\n| POST | /api/v2/feature-flags/{feature_flag_id}/variants | Add a variant to a feature flag |\n| DELETE | /api/v2/feature-flags/{feature_flag_id}/variants/{variant_id} | Delete a variant |\n| PUT | /api/v2/feature-flags/{feature_flag_id}/variants/{variant_id} | Update a variant |\n| GET | /api/v2/fleet/agent_versions | List available Datadog Agent versions |\n| GET | /api/v2/fleet/agents | List all Datadog Agents |\n| GET | /api/v2/fleet/agents/{agent_key} | Get detailed information about an agent |\n| GET | /api/v2/fleet/deployments | List all deployments |\n| POST | /api/v2/fleet/deployments/configure | Create a configuration deployment |\n| POST | /api/v2/fleet/deployments/upgrade | Upgrade hosts |\n| GET | /api/v2/fleet/deployments/{deployment_id} | Get a deployment by ID |\n| POST | /api/v2/fleet/deployments/{deployment_id}/cancel | Cancel a deployment |\n| GET | /api/v2/fleet/schedules | List all schedules |\n| GET | /api/v2/fleet/schedules/{id} | Get a schedule by ID |\n| GET | /api/v2/forms | List forms |\n| POST | /api/v2/forms | Create a form |\n| POST | /api/v2/forms/create_and_publish | Create and publish a form |\n| DELETE | /api/v2/forms/{form_id} | Delete a form |\n| GET | /api/v2/forms/{form_id} | Get a form |\n| PATCH | /api/v2/forms/{form_id} | Update a form |\n| POST | /api/v2/forms/{form_id}/clone | Clone a form |\n| POST | /api/v2/forms/{form_id}/publish | Publish a form version |\n| POST | /api/v2/forms/{form_id}/versions | Create or update a form version |\n| POST | /api/v2/forms/{form_id}/versions/upsert_and_publish | Upsert and publish a form version |\n| GET | /api/v2/global_orgs | List global orgs |\n| GET | /api/v2/governance/config | Get the Governance Console configuration |\n| GET | /api/v2/governance/control | List controls |\n| GET | /api/v2/governance/control/{detection_type} | Get a control |\n| PATCH | /api/v2/governance/control/{detection_type} | Update a control |\n| GET | /api/v2/governance/control/{detection_type}/detections | List control detections |\n| GET | /api/v2/governance/control/{detection_type}/notification_settings | Get control notification settings |\n| PUT | /api/v2/governance/control/{detection_type}/notification_settings | Update control notification settings |\n| POST | /api/v2/governance/detections/mitigate | Mitigate detections |\n| GET | /api/v2/governance/detections/{detection_id} | Get a detection |\n| PATCH | /api/v2/governance/detections/{detection_id} | Update a detection |\n| GET | /api/v2/governance/insights | List insights |\n| GET | /api/v2/governance/notification_settings | Get notification settings |\n| PATCH | /api/v2/governance/notification_settings | Update notification settings |\n| GET | /api/v2/hamr | Get HAMR organization connection |\n| POST | /api/v2/hamr | Create or update HAMR organization connection |\n| GET | /api/v2/identity_providers | List identity providers |\n| PATCH | /api/v2/identity_providers/{idp_id} | Update an identity provider |\n| GET | /api/v2/identity_providers/{idp_id}/users | List users with an identity provider override |\n| DELETE | /api/v2/idp/entity_integrations/{integration_id} | Delete an entity integration configuration |\n| GET | /api/v2/idp/entity_integrations/{integration_id} | Get an entity integration configuration |\n| PUT | /api/v2/idp/entity_integrations/{integration_id} | Create or update entity integration configuration |\n| GET | /api/v2/incidents | Get a list of incidents |\n| POST | /api/v2/incidents | Create an incident |\n| DELETE | /api/v2/incidents/config/global/incident-handles | Delete global incident handle |\n| GET | /api/v2/incidents/config/global/incident-handles | List global incident handles |\n| POST | /api/v2/incidents/config/global/incident-handles | Create global incident handle |\n| PUT | /api/v2/incidents/config/global/incident-handles | Update global incident handle |\n| GET | /api/v2/incidents/config/global/settings | Get global incident settings |\n| PATCH | /api/v2/incidents/config/global/settings | Update global incident settings |\n| POST | /api/v2/incidents/config/google-chat-configurations | Create an incident Google Chat configuration |\n| PATCH | /api/v2/incidents/config/google-chat-configurations/{id} | Update an incident Google Chat configuration |\n| POST | /api/v2/incidents/config/google-meet-configurations | Create an incident Google Meet configuration |\n| PATCH | /api/v2/incidents/config/google-meet-configurations/{id} | Update an incident Google Meet configuration |\n| GET | /api/v2/incidents/config/impact-fields | List incident impact fields |\n| POST | /api/v2/incidents/config/impact-fields | Create an incident impact field |\n| DELETE | /api/v2/incidents/config/impact-fields/{field_id} | Delete an incident impact field |\n| PUT | /api/v2/incidents/config/impact-fields/{field_id} | Update an incident impact field |\n| GET | /api/v2/incidents/config/notification-rules | List incident notification rules |\n| POST | /api/v2/incidents/config/notification-rules | Create an incident notification rule |\n| DELETE | /api/v2/incidents/config/notification-rules/{id} | Delete an incident notification rule |\n| GET | /api/v2/incidents/config/notification-rules/{id} | Get an incident notification rule |\n| PUT | /api/v2/incidents/config/notification-rules/{id} | Update an incident notification rule |\n| GET | /api/v2/incidents/config/notification-templates | List incident notification templates |\n| POST | /api/v2/incidents/config/notification-templates | Create incident notification template |\n| DELETE | /api/v2/incidents/config/notification-templates/{id} | Delete a notification template |\n| GET | /api/v2/incidents/config/notification-templates/{id} | Get incident notification template |\n| PATCH | /api/v2/incidents/config/notification-templates/{id} | Update incident notification template |\n| GET | /api/v2/incidents/config/postmortem-templates | List postmortem templates |\n| POST | /api/v2/incidents/config/postmortem-templates | Create postmortem template |\n| DELETE | /api/v2/incidents/config/postmortem-templates/{template_id} | Delete postmortem template |\n| GET | /api/v2/incidents/config/postmortem-templates/{template_id} | Get postmortem template |\n| PATCH | /api/v2/incidents/config/postmortem-templates/{template_id} | Update postmortem template |\n| GET | /api/v2/incidents/config/rules | List incident rules |\n| POST | /api/v2/incidents/config/rules | Create an incident rule |\n| DELETE | /api/v2/incidents/config/rules/{rule_id} | Delete an incident rule |\n| GET | /api/v2/incidents/config/rules/{rule_id} | Get an incident rule |\n| PATCH | /api/v2/incidents/config/rules/{rule_id} | Update an incident rule |\n| GET | /api/v2/incidents/config/types | Get a list of incident types |\n| POST | /api/v2/incidents/config/types | Create an incident type |\n| GET | /api/v2/incidents/config/types/org-settings | List incident type org settings |\n| DELETE | /api/v2/incidents/config/types/{incident_type_id} | Delete an incident type |\n| GET | /api/v2/incidents/config/types/{incident_type_id} | Get incident type details |\n| PATCH | /api/v2/incidents/config/types/{incident_type_id} | Update an incident type |\n| GET | /api/v2/incidents/config/types/{incident_type_id}/org-settings | Get org settings by incident type |\n| GET | /api/v2/incidents/config/user-defined-fields | Get a list of incident user-defined fields |\n| POST | /api/v2/incidents/config/user-defined-fields | Create an incident user-defined field |\n| DELETE | /api/v2/incidents/config/user-defined-fields/{field_id} | Delete an incident user-defined field |\n| GET | /api/v2/incidents/config/user-defined-fields/{field_id} | Get an incident user-defined field |\n| PATCH | /api/v2/incidents/config/user-defined-fields/{field_id} | Update an incident user-defined field |\n| GET | /api/v2/incidents/config/user-defined-roles | List incident user-defined roles |\n| POST | /api/v2/incidents/config/user-defined-roles | Create an incident user-defined role |\n| DELETE | /api/v2/incidents/config/user-defined-roles/{role_id} | Delete an incident user-defined role |\n| GET | /api/v2/incidents/config/user-defined-roles/{role_id} | Get an incident user-defined role |\n| PATCH | /api/v2/incidents/config/user-defined-roles/{role_id} | Update an incident user-defined role |\n| POST | /api/v2/incidents/import | Import an incident |\n| GET | /api/v2/incidents/search | Search for incidents |\n| DELETE | /api/v2/incidents/{incident_id} | Delete an existing incident |\n| GET | /api/v2/incidents/{incident_id} | Get the details of an incident |\n| PATCH | /api/v2/incidents/{incident_id} | Update an existing incident |\n| POST | /api/v2/incidents/{incident_id}/ai/postmortem | Get an AI-generated incident postmortem |\n| GET | /api/v2/incidents/{incident_id}/attachments | List incident attachments |\n| POST | /api/v2/incidents/{incident_id}/attachments | Create incident attachment |\n| POST | /api/v2/incidents/{incident_id}/attachments/postmortems | Create postmortem attachment |\n| DELETE | /api/v2/incidents/{incident_id}/attachments/{attachment_id} | Delete incident attachment |\n| PATCH | /api/v2/incidents/{incident_id}/attachments/{attachment_id} | Update incident attachment |\n| POST | /api/v2/incidents/{incident_id}/cases/page | Create a page from an incident |\n| PATCH | /api/v2/incidents/{incident_id}/configurations | Update an incident configuration |\n| POST | /api/v2/incidents/{incident_id}/configurations | Create an incident configuration |\n| GET | /api/v2/incidents/{incident_id}/impacts | List an incident's impacts |\n| POST | /api/v2/incidents/{incident_id}/impacts | Create an incident impact |\n| DELETE | /api/v2/incidents/{incident_id}/impacts/{impact_id} | Delete an incident impact |\n| PATCH | /api/v2/incidents/{incident_id}/impacts/{impact_id} | Update an incident impact |\n| POST | /api/v2/incidents/{incident_id}/page | Create an on-call page from an incident |\n| POST | /api/v2/incidents/{incident_id}/pages/link | Link a page to an incident |\n| GET | /api/v2/incidents/{incident_id}/relationships/integrations | Get a list of an incident's integration metadata |\n| POST | /api/v2/incidents/{incident_id}/relationships/integrations | Create an incident integration metadata |\n| DELETE | /api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id} | Delete an incident integration metadata |\n| GET | /api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id} | Get incident integration metadata details |\n| PATCH | /api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id} | Update an existing incident integration metadata |\n| GET | /api/v2/incidents/{incident_id}/relationships/todos | Get a list of an incident's todos |\n| POST | /api/v2/incidents/{incident_id}/relationships/todos | Create an incident todo |\n| DELETE | /api/v2/incidents/{incident_id}/relationships/todos/{todo_id} | Delete an incident todo |\n| GET | /api/v2/incidents/{incident_id}/relationships/todos/{todo_id} | Get incident todo details |\n| PATCH | /api/v2/incidents/{incident_id}/relationships/todos/{todo_id} | Update an incident todo |\n| GET | /api/v2/incidents/{incident_id}/responders | List incident responders |\n| POST | /api/v2/incidents/{incident_id}/responders | Create an incident responder |\n| DELETE | /api/v2/incidents/{incident_id}/responders/{responder_id} | Delete an incident responder |\n| GET | /api/v2/incidents/{incident_id}/responders/{responder_id} | Get an incident responder |\n| POST | /api/v2/incidents/{incident_id}/servicenow-records | Create an incident ServiceNow record |\n| GET | /api/v2/incidents/{incident_id}/timestamp-overrides | List incident timestamp overrides |\n| POST | /api/v2/incidents/{incident_id}/timestamp-overrides | Create an incident timestamp override |\n| DELETE | /api/v2/incidents/{incident_id}/timestamp-overrides/{id} | Delete an incident timestamp override |\n| PATCH | /api/v2/incidents/{incident_id}/timestamp-overrides/{id} | Update an incident timestamp override |\n| GET | /api/v2/integration/aws/accounts | List all AWS integrations |\n| POST | /api/v2/integration/aws/accounts | Create an AWS integration |\n| DELETE | /api/v2/integration/aws/accounts/{aws_account_config_id} | Delete an AWS integration |\n| GET | /api/v2/integration/aws/accounts/{aws_account_config_id} | Get an AWS integration by config ID |\n| PATCH | /api/v2/integration/aws/accounts/{aws_account_config_id} | Update an AWS integration |\n| DELETE | /api/v2/integration/aws/accounts/{aws_account_config_id}/ccm_config | Delete AWS CCM config |\n| GET | /api/v2/integration/aws/accounts/{aws_account_config_id}/ccm_config | Get AWS CCM config |\n| PATCH | /api/v2/integration/aws/accounts/{aws_account_config_id}/ccm_config | Update AWS CCM config |\n| POST | /api/v2/integration/aws/accounts/{aws_account_config_id}/ccm_config | Create AWS CCM config |\n| GET | /api/v2/integration/aws/accounts/{aws_account_config_id}/metric_name_filter_preview | Get AWS metric name filter preview |\n| POST | /api/v2/integration/aws/accounts/{aws_account_config_id}/metric_name_filter_preview | Preview AWS metric name filter |\n| GET | /api/v2/integration/aws/available_namespaces | List available namespaces |\n| DELETE | /api/v2/integration/aws/event_bridge | Delete an Amazon EventBridge source |\n| GET | /api/v2/integration/aws/event_bridge | Get all Amazon EventBridge sources |\n| POST | /api/v2/integration/aws/event_bridge | Create an Amazon EventBridge source |\n| POST | /api/v2/integration/aws/generate_new_external_id | Generate a new external ID |\n| GET | /api/v2/integration/aws/iam_permissions | Get AWS integration IAM permissions |\n| GET | /api/v2/integration/aws/iam_permissions/resource_collection | Get resource collection IAM permissions |\n| GET | /api/v2/integration/aws/iam_permissions/standard | Get AWS integration standard IAM permissions |\n| GET | /api/v2/integration/aws/logs/services | Get list of AWS log ready services |\n| POST | /api/v2/integration/aws/validate_ccm_config | Validate AWS CCM config |\n| GET | /api/v2/integration/gcp/accounts | List all GCP STS-enabled service accounts |\n| POST | /api/v2/integration/gcp/accounts | Create a new entry for your service account |\n| DELETE | /api/v2/integration/gcp/accounts/{account_id} | Delete an STS enabled GCP Account |\n| PATCH | /api/v2/integration/gcp/accounts/{account_id} | Update STS Service Account |\n| GET | /api/v2/integration/gcp/sts_delegate | List delegate account |\n| POST | /api/v2/integration/gcp/sts_delegate | Create a Datadog GCP principal |\n| GET | /api/v2/integration/google-chat/organizations | Get all Google Chat organization bindings |\n| GET | /api/v2/integration/google-chat/organizations/app/named-spaces/{domain_name}/{space_display_name} | Get space information by display name |\n| DELETE | /api/v2/integration/google-chat/organizations/{organization_binding_id} | Delete a Google Chat organization binding |\n| GET | /api/v2/integration/google-chat/organizations/{organization_binding_id} | Get a Google Chat organization binding |\n| DELETE | /api/v2/integration/google-chat/organizations/{organization_binding_id}/delegated-user | Delete the delegated user |\n| GET | /api/v2/integration/google-chat/organizations/{organization_binding_id}/delegated-user | Get the delegated user |\n| GET | /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles | Get all organization handles |\n| POST | /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles | Create organization handle |\n| DELETE | /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles/{handle_id} | Delete organization handle |\n| GET | /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles/{handle_id} | Get organization handle |\n| PATCH | /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles/{handle_id} | Update organization handle |\n| GET | /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences | Get all target audiences |\n| POST | /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences | Create a target audience |\n| DELETE | /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences/{target_audience_id} | Delete a target audience |\n| GET | /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences/{target_audience_id} | Get a target audience |\n| PATCH | /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences/{target_audience_id} | Update a target audience |\n| GET | /api/v2/integration/jira/accounts | List Jira accounts |\n| DELETE | /api/v2/integration/jira/accounts/{account_id} | Delete Jira account |\n| GET | /api/v2/integration/jira/issue-templates | List Jira issue templates |\n| POST | /api/v2/integration/jira/issue-templates | Create Jira issue template |\n| DELETE | /api/v2/integration/jira/issue-templates/{issue_template_id} | Delete Jira issue template |\n| GET | /api/v2/integration/jira/issue-templates/{issue_template_id} | Get Jira issue template |\n| PATCH | /api/v2/integration/jira/issue-templates/{issue_template_id} | Update Jira issue template |\n| GET | /api/v2/integration/ms-teams/configuration/channel/{tenant_name}/{team_name}/{channel_name} | Get channel information by name |\n| GET | /api/v2/integration/ms-teams/configuration/tenant-based-handles | Get all tenant-based handles |\n| POST | /api/v2/integration/ms-teams/configuration/tenant-based-handles | Create tenant-based handle |\n| DELETE | /api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id} | Delete tenant-based handle |\n| GET | /api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id} | Get tenant-based handle information |\n| PATCH | /api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id} | Update tenant-based handle |\n| DELETE | /api/v2/integration/ms-teams/configuration/user-binding/{tenant_id} | Delete user binding |\n| GET | /api/v2/integration/ms-teams/configuration/workflows-webhook-handles | Get all Workflows webhook handles |\n| POST | /api/v2/integration/ms-teams/configuration/workflows-webhook-handles | Create Workflows webhook handle |\n| DELETE | /api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id} | Delete Workflows webhook handle |\n| GET | /api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id} | Get Workflows webhook handle information |\n| PATCH | /api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id} | Update Workflows webhook handle |\n| GET | /api/v2/integration/oci/products | List tenancy products |\n| GET | /api/v2/integration/oci/tenancies | Get tenancy configs |\n| POST | /api/v2/integration/oci/tenancies | Create tenancy config |\n| DELETE | /api/v2/integration/oci/tenancies/{tenancy_ocid} | Delete tenancy config |\n| GET | /api/v2/integration/oci/tenancies/{tenancy_ocid} | Get tenancy config |\n| PATCH | /api/v2/integration/oci/tenancies/{tenancy_ocid} | Update tenancy config |\n| GET | /api/v2/integration/opsgenie/accounts | Get all Opsgenie accounts |\n| POST | /api/v2/integration/opsgenie/accounts | Create a new Opsgenie account |\n| DELETE | /api/v2/integration/opsgenie/accounts/{account_id} | Delete an Opsgenie account |\n| PATCH | /api/v2/integration/opsgenie/accounts/{account_id} | Update an Opsgenie account |\n| GET | /api/v2/integration/opsgenie/services | Get all service objects |\n| POST | /api/v2/integration/opsgenie/services | Create a new service object |\n| DELETE | /api/v2/integration/opsgenie/services/{integration_service_id} | Delete a single service object |\n| GET | /api/v2/integration/opsgenie/services/{integration_service_id} | Get a single service object |\n| PATCH | /api/v2/integration/opsgenie/services/{integration_service_id} | Update a single service object |\n| GET | /api/v2/integration/salesforce-incidents/incident-templates | Get all Salesforce incident templates |\n| POST | /api/v2/integration/salesforce-incidents/incident-templates | Create a Salesforce incident template |\n| DELETE | /api/v2/integration/salesforce-incidents/incident-templates/{incident_template_id} | Delete a Salesforce incident template |\n| PATCH | /api/v2/integration/salesforce-incidents/incident-templates/{incident_template_id} | Update a Salesforce incident template |\n| GET | /api/v2/integration/salesforce-incidents/organizations | Get all connected Salesforce organizations |\n| DELETE | /api/v2/integration/salesforce-incidents/organizations/{salesforce_org_id} | Delete a connected Salesforce organization |\n| GET | /api/v2/integration/servicenow/assignment_groups/{instance_id} | List ServiceNow assignment groups |\n| GET | /api/v2/integration/servicenow/business_services/{instance_id} | List ServiceNow business services |\n| GET | /api/v2/integration/servicenow/handles | List ServiceNow templates |\n| POST | /api/v2/integration/servicenow/handles | Create ServiceNow template |\n| DELETE | /api/v2/integration/servicenow/handles/{template_id} | Delete ServiceNow template |\n| GET | /api/v2/integration/servicenow/handles/{template_id} | Get ServiceNow template |\n| PUT | /api/v2/integration/servicenow/handles/{template_id} | Update ServiceNow template |\n| GET | /api/v2/integration/servicenow/instances | List ServiceNow instances |\n| GET | /api/v2/integration/servicenow/users/{instance_id} | List ServiceNow users |\n| GET | /api/v2/integration/slack/user-bindings | List Slack user bindings |\n| DELETE | /api/v2/integration/statuspage/account | Delete the Statuspage account |\n| GET | /api/v2/integration/statuspage/account | Get the Statuspage account |\n| PATCH | /api/v2/integration/statuspage/account | Update the Statuspage account |\n| POST | /api/v2/integration/statuspage/account | Create the Statuspage account |\n| GET | /api/v2/integration/statuspage/url_settings | Get all Statuspage URL settings |\n| POST | /api/v2/integration/statuspage/url_settings | Create a Statuspage URL setting |\n| DELETE | /api/v2/integration/statuspage/url_settings/{statuspage_url_setting_id} | Delete a Statuspage URL setting |\n| PATCH | /api/v2/integration/statuspage/url_settings/{statuspage_url_setting_id} | Update a Statuspage URL setting |\n| GET | /api/v2/integration/webhooks/configuration/auth-method | Get all auth methods |\n| POST | /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials | Create an OAuth2 client credentials auth method |\n| DELETE | /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials/{auth_method_id} | Delete an OAuth2 client credentials auth method |\n| GET | /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials/{auth_method_id} | Get an OAuth2 client credentials auth method |\n| PATCH | /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials/{auth_method_id} | Update an OAuth2 client credentials auth method |\n| GET | /api/v2/integrations | List Integrations |\n| GET | /api/v2/integrations/cloudflare/accounts | List Cloudflare accounts |\n| POST | /api/v2/integrations/cloudflare/accounts | Add Cloudflare account |\n| DELETE | /api/v2/integrations/cloudflare/accounts/{account_id} | Delete Cloudflare account |\n| GET | /api/v2/integrations/cloudflare/accounts/{account_id} | Get Cloudflare account |\n| PATCH | /api/v2/integrations/cloudflare/accounts/{account_id} | Update Cloudflare account |\n| GET | /api/v2/integrations/confluent-cloud/accounts | List Confluent accounts |\n| POST | /api/v2/integrations/confluent-cloud/accounts | Add Confluent account |\n| DELETE | /api/v2/integrations/confluent-cloud/accounts/{account_id} | Delete Confluent account |\n| GET | /api/v2/integrations/confluent-cloud/accounts/{account_id} | Get Confluent account |\n| PATCH | /api/v2/integrations/confluent-cloud/accounts/{account_id} | Update Confluent account |\n| GET | /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources | List Confluent Account resources |\n| POST | /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources | Add resource to Confluent account |\n| DELETE | /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources/{resource_id} | Delete resource from Confluent account |\n| GET | /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources/{resource_id} | Get resource from Confluent account |\n| PATCH | /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources/{resource_id} | Update resource in Confluent account |\n| GET | /api/v2/integrations/fastly/accounts | List Fastly accounts |\n| POST | /api/v2/integrations/fastly/accounts | Add Fastly account |\n| DELETE | /api/v2/integrations/fastly/accounts/{account_id} | Delete Fastly account |\n| GET | /api/v2/integrations/fastly/accounts/{account_id} | Get Fastly account |\n| PATCH | /api/v2/integrations/fastly/accounts/{account_id} | Update Fastly account |\n| GET | /api/v2/integrations/fastly/accounts/{account_id}/services | List Fastly services |\n| POST | /api/v2/integrations/fastly/accounts/{account_id}/services | Add Fastly service |\n| DELETE | /api/v2/integrations/fastly/accounts/{account_id}/services/{service_id} | Delete Fastly service |\n| GET | /api/v2/integrations/fastly/accounts/{account_id}/services/{service_id} | Get Fastly service |\n| PATCH | /api/v2/integrations/fastly/accounts/{account_id}/services/{service_id} | Update Fastly service |\n| GET | /api/v2/integrations/okta/accounts | List Okta accounts |\n| POST | /api/v2/integrations/okta/accounts | Add Okta account |\n| DELETE | /api/v2/integrations/okta/accounts/{account_id} | Delete Okta account |\n| GET | /api/v2/integrations/okta/accounts/{account_id} | Get Okta account |\n| PATCH | /api/v2/integrations/okta/accounts/{account_id} | Update Okta account |\n| GET | /api/v2/ip_allowlist | Get IP Allowlist |\n| PATCH | /api/v2/ip_allowlist | Update IP Allowlist |\n| GET | /api/v2/llm-obs/v1/annotated-interactions | Get annotated interactions by content IDs |\n| GET | /api/v2/llm-obs/v1/annotation-queues | List LLM Observability annotation queues |\n| POST | /api/v2/llm-obs/v1/annotation-queues | Create an LLM Observability annotation queue |\n| DELETE | /api/v2/llm-obs/v1/annotation-queues/{queue_id} | Delete an LLM Observability annotation queue |\n| PATCH | /api/v2/llm-obs/v1/annotation-queues/{queue_id} | Update an LLM Observability annotation queue |\n| GET | /api/v2/llm-obs/v1/annotation-queues/{queue_id}/annotated-interactions | Get annotated queue interactions |\n| POST | /api/v2/llm-obs/v1/annotation-queues/{queue_id}/annotations | Create or update annotations |\n| POST | /api/v2/llm-obs/v1/annotation-queues/{queue_id}/annotations/delete | Delete annotations |\n| POST | /api/v2/llm-obs/v1/annotation-queues/{queue_id}/interactions | Add annotation queue interactions |\n| POST | /api/v2/llm-obs/v1/annotation-queues/{queue_id}/interactions/delete | Delete annotation queue interactions |\n| GET | /api/v2/llm-obs/v1/annotation-queues/{queue_id}/label-schema | Get annotation queue label schema |\n| PUT | /api/v2/llm-obs/v1/annotation-queues/{queue_id}/label-schema | Update annotation queue label schema |\n| POST | /api/v2/llm-obs/v1/experimentation/analytics | Aggregate LLM Observability experimentation |\n| POST | /api/v2/llm-obs/v1/experimentation/search | Search LLM Observability experimentation entities |\n| POST | /api/v2/llm-obs/v1/experimentation/simple-search | Simple search experimentation entities |\n| GET | /api/v2/llm-obs/v1/experiments | List LLM Observability experiments |\n| POST | /api/v2/llm-obs/v1/experiments | Create an LLM Observability experiment |\n| POST | /api/v2/llm-obs/v1/experiments/delete | Delete LLM Observability experiments |\n| PATCH | /api/v2/llm-obs/v1/experiments/{experiment_id} | Update an LLM Observability experiment |\n| GET | /api/v2/llm-obs/v1/experiments/{experiment_id}/events | List LLM Observability experiment spans (v1) |\n| POST | /api/v2/llm-obs/v1/experiments/{experiment_id}/events | Push events for an LLM Observability experiment |\n| GET | /api/v2/llm-obs/v1/integrations/{integration}/accounts | List LLM integration accounts |\n| POST | /api/v2/llm-obs/v1/integrations/{integration}/{account_id}/inference | Run an LLM inference |\n| GET | /api/v2/llm-obs/v1/integrations/{integration}/{account_id}/models | List LLM integration models |\n| GET | /api/v2/llm-obs/v1/projects | List LLM Observability projects |\n| POST | /api/v2/llm-obs/v1/projects | Create an LLM Observability project |\n| POST | /api/v2/llm-obs/v1/projects/delete | Delete LLM Observability projects |\n| PATCH | /api/v2/llm-obs/v1/projects/{project_id} | Update an LLM Observability project |\n| GET | /api/v2/llm-obs/v1/prompts | List LLM Observability prompts |\n| POST | /api/v2/llm-obs/v1/prompts | Create an LLM Observability prompt |\n| DELETE | /api/v2/llm-obs/v1/prompts/{prompt_id} | Delete an LLM Observability prompt |\n| GET | /api/v2/llm-obs/v1/prompts/{prompt_id} | Get an LLM Observability prompt |\n| PATCH | /api/v2/llm-obs/v1/prompts/{prompt_id} | Update an LLM Observability prompt |\n| GET | /api/v2/llm-obs/v1/prompts/{prompt_id}/versions | List versions of an LLM Observability prompt |\n| POST | /api/v2/llm-obs/v1/prompts/{prompt_id}/versions | Create a new LLM Observability prompt version |\n| GET | /api/v2/llm-obs/v1/prompts/{prompt_id}/versions/{version} | Get a specific LLM Observability prompt version |\n| PATCH | /api/v2/llm-obs/v1/prompts/{prompt_id}/versions/{version} | Update a specific LLM Observability prompt version |\n| GET | /api/v2/llm-obs/v1/spans/events | List LLM Observability spans |\n| POST | /api/v2/llm-obs/v1/spans/events/search | Search LLM Observability spans |\n| GET | /api/v2/llm-obs/v1/topic-discovery-clustered-points | List patterns clustered points |\n| GET | /api/v2/llm-obs/v1/topic-discovery-configs | List patterns configurations |\n| PUT | /api/v2/llm-obs/v1/topic-discovery-configs | Create or update a patterns configuration |\n| GET | /api/v2/llm-obs/v1/topic-discovery-configs/latest | Get a patterns configuration |\n| DELETE | /api/v2/llm-obs/v1/topic-discovery-configs/{config_id} | Delete a patterns configuration |\n| GET | /api/v2/llm-obs/v1/topic-discovery-runs | List patterns runs |\n| POST | /api/v2/llm-obs/v1/topic-discovery-runs | Trigger a patterns run |\n| GET | /api/v2/llm-obs/v1/topic-discovery-runs/status | Get patterns run status |\n| GET | /api/v2/llm-obs/v1/topic-discovery-topics | List patterns topics |\n| GET | /api/v2/llm-obs/v1/topic-discovery-topics/with-cluster-points | List patterns topics with clustered points |\n| GET | /api/v2/llm-obs/v1/{project_id}/datasets | List LLM Observability datasets |\n| POST | /api/v2/llm-obs/v1/{project_id}/datasets | Create an LLM Observability dataset |\n| POST | /api/v2/llm-obs/v1/{project_id}/datasets/delete | Delete LLM Observability datasets |\n| PATCH | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id} | Update an LLM Observability dataset |\n| POST | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/batch_update | Batch update LLM Observability dataset records |\n| POST | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/clone | Clone an LLM Observability dataset |\n| GET | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/draft_state | Get LLM Observability dataset draft state |\n| PATCH | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/draft_state/lock | Lock LLM Observability dataset draft state |\n| PATCH | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/draft_state/unlock | Unlock LLM Observability dataset draft state |\n| GET | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/export | Export an LLM Observability dataset |\n| GET | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/records | List LLM Observability dataset records |\n| PATCH | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/records | Update LLM Observability dataset records |\n| POST | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/records | Append records to an LLM Observability dataset |\n| POST | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/records/delete | Delete LLM Observability dataset records |\n| POST | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/restore | Restore an LLM Observability dataset version |\n| GET | /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/versions | List LLM Observability dataset versions |\n| GET | /api/v2/llm-obs/v2/experiments/{experiment_id}/events | List LLM Observability experiment events (v2) |\n| POST | /api/v2/llm-obs/v2/{project_id}/datasets/{dataset_id}/records/upload | Upload records to an LLM Observability dataset |\n| GET | /api/v2/llm-obs/v3/experiments/{experiment_id}/events | List events for an LLM Observability experiment |\n| PUT | /api/v2/login/org_configs/max_session_duration | Update the maximum session duration |\n| POST | /api/v2/logs | Send logs |\n| POST | /api/v2/logs/analytics/aggregate | Aggregate events |\n| GET | /api/v2/logs/config/archive-order | Get archive order |\n| PUT | /api/v2/logs/config/archive-order | Update archive order |\n| GET | /api/v2/logs/config/archives | Get all archives |\n| POST | /api/v2/logs/config/archives | Create an archive |\n| DELETE | /api/v2/logs/config/archives/{archive_id} | Delete an archive |\n| GET | /api/v2/logs/config/archives/{archive_id} | Get an archive |\n| PUT | /api/v2/logs/config/archives/{archive_id} | Update an archive |\n| DELETE | /api/v2/logs/config/archives/{archive_id}/readers | Revoke role from an archive |\n| GET | /api/v2/logs/config/archives/{archive_id}/readers | List read roles for an archive |\n| POST | /api/v2/logs/config/archives/{archive_id}/readers | Grant role to an archive |\n| GET | /api/v2/logs/config/custom-destinations | Get all custom destinations |\n| POST | /api/v2/logs/config/custom-destinations | Create a custom destination |\n| DELETE | /api/v2/logs/config/custom-destinations/{custom_destination_id} | Delete a custom destination |\n| GET | /api/v2/logs/config/custom-destinations/{custom_destination_id} | Get a custom destination |\n| PATCH | /api/v2/logs/config/custom-destinations/{custom_destination_id} | Update a custom destination |\n| GET | /api/v2/logs/config/metrics | Get all log-based metrics |\n| POST | /api/v2/logs/config/metrics | Create a log-based metric |\n| DELETE | /api/v2/logs/config/metrics/{metric_id} | Delete a log-based metric |\n| GET | /api/v2/logs/config/metrics/{metric_id} | Get a log-based metric |\n| PATCH | /api/v2/logs/config/metrics/{metric_id} | Update a log-based metric |\n| GET | /api/v2/logs/config/restriction_queries | List restriction queries |\n| POST | /api/v2/logs/config/restriction_queries | Create a restriction query |\n| GET | /api/v2/logs/config/restriction_queries/role/{role_id} | Get restriction query for a given role |\n| GET | /api/v2/logs/config/restriction_queries/user/{user_id} | Get all restriction queries for a given user |\n| DELETE | /api/v2/logs/config/restriction_queries/{restriction_query_id} | Delete a restriction query |\n| GET | /api/v2/logs/config/restriction_queries/{restriction_query_id} | Get a restriction query |\n| PATCH | /api/v2/logs/config/restriction_queries/{restriction_query_id} | Update a restriction query |\n| PUT | /api/v2/logs/config/restriction_queries/{restriction_query_id} | Replace a restriction query |\n| DELETE | /api/v2/logs/config/restriction_queries/{restriction_query_id}/roles | Revoke role from a restriction query |\n| GET | /api/v2/logs/config/restriction_queries/{restriction_query_id}/roles | List roles for a restriction query |\n| POST | /api/v2/logs/config/restriction_queries/{restriction_query_id}/roles | Grant role to a restriction query |\n| GET | /api/v2/logs/events | Search logs (GET) |\n| POST | /api/v2/logs/events/search | Search logs (POST) |\n| GET | /api/v2/maintenance_windows | List maintenance windows |\n| POST | /api/v2/maintenance_windows | Create a maintenance window |\n| DELETE | /api/v2/maintenance_windows/{maintenance_window_id} | Delete a maintenance window |\n| PUT | /api/v2/maintenance_windows/{maintenance_window_id} | Update a maintenance window |\n| GET | /api/v2/metrics | Get a list of metrics |\n| DELETE | /api/v2/metrics/config/bulk-tags | Delete tags for multiple metrics |\n| POST | /api/v2/metrics/config/bulk-tags | Configure tags for multiple metrics |\n| POST | /api/v2/metrics/historical-metrics-configurations | Enable historical metrics ingestion |\n| DELETE | /api/v2/metrics/historical-metrics-configurations/{metric_name} | Delete a historical metrics configuration |\n| GET | /api/v2/metrics/historical-metrics-configurations/{metric_name} | Get a historical metrics configuration |\n| GET | /api/v2/metrics/tag-indexing-rules | List tag indexing rules |\n| POST | /api/v2/metrics/tag-indexing-rules | Create a tag indexing rule |\n| POST | /api/v2/metrics/tag-indexing-rules/order | Reorder tag indexing rules |\n| DELETE | /api/v2/metrics/tag-indexing-rules/{id} | Delete a tag indexing rule |\n| GET | /api/v2/metrics/tag-indexing-rules/{id} | Get a tag indexing rule |\n| PUT | /api/v2/metrics/tag-indexing-rules/{id} | Update a tag indexing rule |\n| GET | /api/v2/metrics/{metric_name}/active-configurations | List active tags and aggregations |\n| GET | /api/v2/metrics/{metric_name}/all-tags | List tags by metric name |\n| GET | /api/v2/metrics/{metric_name}/assets | Related Assets to a Metric |\n| GET | /api/v2/metrics/{metric_name}/estimate | Tag Configuration Cardinality Estimator |\n| GET | /api/v2/metrics/{metric_name}/tag-cardinalities | Get tag key cardinality details |\n| DELETE | /api/v2/metrics/{metric_name}/tag-indexing-rule-exemptions | Delete a tag indexing rule exemption |\n| GET | /api/v2/metrics/{metric_name}/tag-indexing-rule-exemptions | Get a tag indexing rule exemption |\n| POST | /api/v2/metrics/{metric_name}/tag-indexing-rule-exemptions | Create a tag indexing rule exemption |\n| GET | /api/v2/metrics/{metric_name}/tag-indexing-rules | List tag indexing rules for a metric |\n| DELETE | /api/v2/metrics/{metric_name}/tags | Delete a tag configuration |\n| GET | /api/v2/metrics/{metric_name}/tags | List tag configuration by name |\n| PATCH | /api/v2/metrics/{metric_name}/tags | Update a tag configuration |\n| POST | /api/v2/metrics/{metric_name}/tags | Create a tag configuration |\n| GET | /api/v2/metrics/{metric_name}/volumes | List distinct metric volumes by metric name |\n| GET | /api/v2/model-lab-api/artifacts/content | Get Model Lab artifact content |\n| GET | /api/v2/model-lab-api/facet-keys | List Model Lab run facet keys |\n| GET | /api/v2/model-lab-api/facet-values | List Model Lab run facet values |\n| GET | /api/v2/model-lab-api/project-facet-keys | List Model Lab project facet keys |\n| GET | /api/v2/model-lab-api/project-facet-values | List Model Lab project facet values |\n| GET | /api/v2/model-lab-api/projects | List Model Lab projects |\n| GET | /api/v2/model-lab-api/projects/{project_id} | Get a Model Lab project |\n| GET | /api/v2/model-lab-api/projects/{project_id}/artifacts | List Model Lab project artifacts |\n| DELETE | /api/v2/model-lab-api/projects/{project_id}/star | Remove star from a Model Lab project |\n| POST | /api/v2/model-lab-api/projects/{project_id}/star | Star a Model Lab project |\n| GET | /api/v2/model-lab-api/runs | List Model Lab runs |\n| DELETE | /api/v2/model-lab-api/runs/{run_id} | Delete a Model Lab run |\n| GET | /api/v2/model-lab-api/runs/{run_id} | Get a Model Lab run |\n| GET | /api/v2/model-lab-api/runs/{run_id}/artifacts | List Model Lab run artifacts |\n| DELETE | /api/v2/model-lab-api/runs/{run_id}/pin | Unpin a Model Lab run |\n| POST | /api/v2/model-lab-api/runs/{run_id}/pin | Pin a Model Lab run |\n| GET | /api/v2/monitor/notification_rule | Get all monitor notification rules |\n| POST | /api/v2/monitor/notification_rule | Create a monitor notification rule |\n| DELETE | /api/v2/monitor/notification_rule/{rule_id} | Delete a monitor notification rule |\n| GET | /api/v2/monitor/notification_rule/{rule_id} | Get a monitor notification rule |\n| PATCH | /api/v2/monitor/notification_rule/{rule_id} | Update a monitor notification rule |\n| GET | /api/v2/monitor/policy | Get all monitor configuration policies |\n| POST | /api/v2/monitor/policy | Create a monitor configuration policy |\n| DELETE | /api/v2/monitor/policy/{policy_id} | Delete a monitor configuration policy |\n| GET | /api/v2/monitor/policy/{policy_id} | Get a monitor configuration policy |\n| PATCH | /api/v2/monitor/policy/{policy_id} | Edit a monitor configuration policy |\n| GET | /api/v2/monitor/template | Get all monitor user templates |\n| POST | /api/v2/monitor/template | Create a monitor user template |\n| POST | /api/v2/monitor/template/validate | Validate a monitor user template |\n| DELETE | /api/v2/monitor/template/{template_id} | Delete a monitor user template |\n| GET | /api/v2/monitor/template/{template_id} | Get a monitor user template |\n| PUT | /api/v2/monitor/template/{template_id} | Update a monitor user template to a new version |\n| POST | /api/v2/monitor/template/{template_id}/validate | Validate an existing monitor user template |\n| GET | /api/v2/monitor/{monitor_id}/downtime_matches | Get active downtimes for a monitor |\n| GET | /api/v2/ndm/devices | Get the list of devices |\n| GET | /api/v2/ndm/devices/{device_id} | Get the device details |\n| GET | /api/v2/ndm/interfaces | Get the list of interfaces of the device |\n| GET | /api/v2/ndm/tags/devices/{device_id} | Get the list of tags for a device |\n| PATCH | /api/v2/ndm/tags/devices/{device_id} | Update the tags for a device |\n| GET | /api/v2/ndm/tags/interfaces/{interface_id} | List tags for an interface |\n| PATCH | /api/v2/ndm/tags/interfaces/{interface_id} | Update the tags for an interface |\n| GET | /api/v2/network-health-insights | List network health insights |\n| GET | /api/v2/network/connections/aggregate | Get all aggregated connections |\n| GET | /api/v2/network/dns/aggregate | Get all aggregated DNS traffic |\n| GET | /api/v2/oauth2/.well-known/sites | Get OAuth2 well-known sites |\n| DELETE | /api/v2/oauth2/clients/{client_uuid}/scopes_restriction | Delete an OAuth2 client scopes restriction |\n| GET | /api/v2/oauth2/clients/{client_uuid}/scopes_restriction | Get an OAuth2 client scopes restriction |\n| POST | /api/v2/oauth2/clients/{client_uuid}/scopes_restriction | Upsert an OAuth2 client scopes restriction |\n| POST | /api/v2/oauth2/register | Register an OAuth2 client |\n| GET | /api/v2/obs-pipelines/pipelines | List pipelines |\n| POST | /api/v2/obs-pipelines/pipelines | Create a new pipeline |\n| POST | /api/v2/obs-pipelines/pipelines/validate | Validate an observability pipeline |\n| DELETE | /api/v2/obs-pipelines/pipelines/{pipeline_id} | Delete a pipeline |\n| GET | /api/v2/obs-pipelines/pipelines/{pipeline_id} | Get a specific pipeline |\n| PUT | /api/v2/obs-pipelines/pipelines/{pipeline_id} | Update a pipeline |\n| POST | /api/v2/on-call/escalation-policies | Create On-Call escalation policy |\n| DELETE | /api/v2/on-call/escalation-policies/{policy_id} | Delete On-Call escalation policy |\n| GET | /api/v2/on-call/escalation-policies/{policy_id} | Get On-Call escalation policy |\n| PUT | /api/v2/on-call/escalation-policies/{policy_id} | Update On-Call escalation policy |\n| POST | /api/v2/on-call/pages | Create On-Call Page |\n| POST | /api/v2/on-call/pages/{page_id}/acknowledge | Acknowledge On-Call Page |\n| POST | /api/v2/on-call/pages/{page_id}/escalate | Escalate On-Call Page |\n| POST | /api/v2/on-call/pages/{page_id}/resolve | Resolve On-Call Page |\n| POST | /api/v2/on-call/schedules | Create On-Call schedule |\n| DELETE | /api/v2/on-call/schedules/{schedule_id} | Delete On-Call schedule |\n| GET | /api/v2/on-call/schedules/{schedule_id} | Get On-Call schedule |\n| PUT | /api/v2/on-call/schedules/{schedule_id} | Update On-Call schedule |\n| GET | /api/v2/on-call/schedules/{schedule_id}/on-call | Get scheduled on-call user |\n| GET | /api/v2/on-call/schedules/{schedule_id}/responders | Get on-call responders for a schedule |\n| GET | /api/v2/on-call/teams/{team_id}/on-call | Get team on-call users |\n| GET | /api/v2/on-call/teams/{team_id}/routing-rules | Get On-Call team routing rules |\n| PUT | /api/v2/on-call/teams/{team_id}/routing-rules | Set On-Call team routing rules |\n| GET | /api/v2/on-call/users/{user_id}/notification-channels | List On-Call notification channels for a user |\n| POST | /api/v2/on-call/users/{user_id}/notification-channels | Create an On-Call notification channel for a user |\n| DELETE | /api/v2/on-call/users/{user_id}/notification-channels/{channel_id} | Delete an On-Call notification channel for a user |\n| GET | /api/v2/on-call/users/{user_id}/notification-channels/{channel_id} | Get an On-Call notification channel for a user |\n| GET | /api/v2/on-call/users/{user_id}/notification-rules | List On-Call notification rules for a user |\n| POST | /api/v2/on-call/users/{user_id}/notification-rules | Create an On-Call notification rule for a user |\n| DELETE | /api/v2/on-call/users/{user_id}/notification-rules/{rule_id} | Delete an On-Call notification rule for a user |\n| GET | /api/v2/on-call/users/{user_id}/notification-rules/{rule_id} | Get an On-Call notification rule for a user |\n| PUT | /api/v2/on-call/users/{user_id}/notification-rules/{rule_id} | Update an On-Call notification rule for a user |\n| GET | /api/v2/org | List your managed organizations |\n| POST | /api/v2/org/disable | Disable the authenticated customer organization |\n| PATCH | /api/v2/org/saml_configurations | Update organization SAML preferences |\n| GET | /api/v2/org_authorized_clients | List org authorized clients |\n| DELETE | /api/v2/org_authorized_clients/{org_authorized_client_id} | Delete an org authorized client |\n| GET | /api/v2/org_authorized_clients/{org_authorized_client_id} | Get an org authorized client |\n| PATCH | /api/v2/org_authorized_clients/{org_authorized_client_id} | Update an org authorized client |\n| DELETE | /api/v2/org_authorized_clients/{org_authorized_client_id}/user/{user_id} | Delete a user's authorizations for a client |\n| GET | /api/v2/org_authorized_clients/{org_authorized_client_id}/user_authorized_clients | List user authorizations for a client |\n| DELETE | /api/v2/org_authorized_clients/{org_authorized_client_id}/user_authorized_clients/{user_authorized_client_id} | Delete a user authorization for a client |\n| GET | /api/v2/org_configs | List Org Configs |\n| GET | /api/v2/org_configs/{org_config_name} | Get a specific Org Config value |\n| PATCH | /api/v2/org_configs/{org_config_name} | Update a specific Org Config |\n| GET | /api/v2/org_connections | List Org Connections |\n| POST | /api/v2/org_connections | Create Org Connection |\n| DELETE | /api/v2/org_connections/{connection_id} | Delete Org Connection |\n| PATCH | /api/v2/org_connections/{connection_id} | Update Org Connection |\n| GET | /api/v2/org_group_memberships | List org group memberships |\n| PATCH | /api/v2/org_group_memberships/bulk | Bulk update org group memberships |\n| GET | /api/v2/org_group_memberships/{org_group_membership_id} | Get an org group membership |\n| PATCH | /api/v2/org_group_memberships/{org_group_membership_id} | Update an org group membership |\n| GET | /api/v2/org_group_policies | List org group policies |\n| POST | /api/v2/org_group_policies | Create an org group policy |\n| DELETE | /api/v2/org_group_policies/{org_group_policy_id} | Delete an org group policy |\n| GET | /api/v2/org_group_policies/{org_group_policy_id} | Get an org group policy |\n| PATCH | /api/v2/org_group_policies/{org_group_policy_id} | Update an org group policy |\n| GET | /api/v2/org_group_policy_configs | List org group policy configs |\n| GET | /api/v2/org_group_policy_overrides | List org group policy overrides |\n| POST | /api/v2/org_group_policy_overrides | Create an org group policy override |\n| DELETE | /api/v2/org_group_policy_overrides/{org_group_policy_override_id} | Delete an org group policy override |\n| GET | /api/v2/org_group_policy_overrides/{org_group_policy_override_id} | Get an org group policy override |\n| PATCH | /api/v2/org_group_policy_overrides/{org_group_policy_override_id} | Update an org group policy override |\n| GET | /api/v2/org_group_policy_suggestions | List org group policy suggestions |\n| GET | /api/v2/org_groups | List org groups |\n| POST | /api/v2/org_groups | Create an org group |\n| DELETE | /api/v2/org_groups/{org_group_id} | Delete an org group |\n| GET | /api/v2/org_groups/{org_group_id} | Get an org group |\n| PATCH | /api/v2/org_groups/{org_group_id} | Update an org group |\n| GET | /api/v2/permissions | List permissions |\n| GET | /api/v2/personal_access_tokens | Get all access tokens |\n| POST | /api/v2/personal_access_tokens | Create a personal access token |\n| DELETE | /api/v2/personal_access_tokens/{token_id} | Revoke a personal access token |\n| GET | /api/v2/personal_access_tokens/{token_id} | Get a personal access token |\n| PATCH | /api/v2/personal_access_tokens/{token_id} | Update a personal access token |\n| GET | /api/v2/posture_management/findings | List findings |\n| GET | /api/v2/posture_management/findings/{finding_id} | Get a finding |\n| GET | /api/v2/powerpacks | Get all powerpacks |\n| POST | /api/v2/powerpacks | Create a new powerpack |\n| DELETE | /api/v2/powerpacks/{powerpack_id} | Delete a powerpack |\n| GET | /api/v2/powerpacks/{powerpack_id} | Get a Powerpack |\n| PATCH | /api/v2/powerpacks/{powerpack_id} | Update a powerpack |\n| GET | /api/v2/processes | Get all processes |\n| POST | /api/v2/prodlytics | Send server-side events |\n| POST | /api/v2/product-analytics/accounts/facet_info | Get account facet info |\n| POST | /api/v2/product-analytics/accounts/query | Query accounts |\n| POST | /api/v2/product-analytics/analytics/scalar | Compute scalar analytics |\n| POST | /api/v2/product-analytics/analytics/timeseries | Compute timeseries analytics |\n| POST | /api/v2/product-analytics/users/event_filtered_query | Query event filtered users |\n| POST | /api/v2/product-analytics/users/facet_info | Get user facet info |\n| POST | /api/v2/product-analytics/users/query | Query users |\n| GET | /api/v2/product-analytics/{entity}/mapping | Get mapping |\n| POST | /api/v2/product-analytics/{entity}/mapping/connection | Create connection |\n| PUT | /api/v2/product-analytics/{entity}/mapping/connection | Update connection |\n| DELETE | /api/v2/product-analytics/{entity}/mapping/connection/{id} | Delete connection |\n| GET | /api/v2/product-analytics/{entity}/mapping/connections | List connections |\n| GET | /api/v2/pruned_trace/{trace_id} | Get a pruned trace by ID |\n| POST | /api/v2/query/scalar | Query scalar data across multiple products |\n| POST | /api/v2/query/timeseries | Query timeseries data across multiple products |\n| POST | /api/v2/reference-tables/queries/batch-rows | Batch rows query |\n| GET | /api/v2/reference-tables/tables | List tables |\n| POST | /api/v2/reference-tables/tables | Create reference table |\n| DELETE | /api/v2/reference-tables/tables/{id} | Delete table |\n| GET | /api/v2/reference-tables/tables/{id} | Get table |\n| PATCH | /api/v2/reference-tables/tables/{id} | Update reference table |\n| DELETE | /api/v2/reference-tables/tables/{id}/rows | Delete rows |\n| GET | /api/v2/reference-tables/tables/{id}/rows | Get rows by id |\n| POST | /api/v2/reference-tables/tables/{id}/rows | Upsert rows |\n| GET | /api/v2/reference-tables/tables/{id}/rows/list | List rows |\n| POST | /api/v2/reference-tables/uploads | Create reference table upload |\n| GET | /api/v2/remote_config/products/asm/waf/custom_rules | List all WAF custom rules |\n| POST | /api/v2/remote_config/products/asm/waf/custom_rules | Create a WAF custom rule |\n| DELETE | /api/v2/remote_config/products/asm/waf/custom_rules/{custom_rule_id} | Delete a WAF Custom Rule |\n| GET | /api/v2/remote_config/products/asm/waf/custom_rules/{custom_rule_id} | Get a WAF custom rule |\n| PUT | /api/v2/remote_config/products/asm/waf/custom_rules/{custom_rule_id} | Update a WAF Custom Rule |\n| GET | /api/v2/remote_config/products/asm/waf/exclusion_filters | List all WAF exclusion filters |\n| POST | /api/v2/remote_config/products/asm/waf/exclusion_filters | Create a WAF exclusion filter |\n| DELETE | /api/v2/remote_config/products/asm/waf/exclusion_filters/{exclusion_filter_id} | Delete a WAF exclusion filter |\n| GET | /api/v2/remote_config/products/asm/waf/exclusion_filters/{exclusion_filter_id} | Get a WAF exclusion filter |\n| PUT | /api/v2/remote_config/products/asm/waf/exclusion_filters/{exclusion_filter_id} | Update a WAF exclusion filter |\n| GET | /api/v2/remote_config/products/asm/waf/policies | List all WAF policies |\n| POST | /api/v2/remote_config/products/asm/waf/policies | Create a WAF Policy |\n| DELETE | /api/v2/remote_config/products/asm/waf/policies/{policy_id} | Delete a WAF Policy |\n| GET | /api/v2/remote_config/products/asm/waf/policies/{policy_id} | Get a WAF Policy |\n| PUT | /api/v2/remote_config/products/asm/waf/policies/{policy_id} | Update a WAF Policy |\n| GET | /api/v2/remote_config/products/cws/agent_rules | Get all Workload Protection agent rules |\n| POST | /api/v2/remote_config/products/cws/agent_rules | Create a Workload Protection agent rule |\n| DELETE | /api/v2/remote_config/products/cws/agent_rules/{agent_rule_id} | Delete a Workload Protection agent rule |\n| GET | /api/v2/remote_config/products/cws/agent_rules/{agent_rule_id} | Get a Workload Protection agent rule |\n| PATCH | /api/v2/remote_config/products/cws/agent_rules/{agent_rule_id} | Update a Workload Protection agent rule |\n| GET | /api/v2/remote_config/products/cws/policy | Get all Workload Protection policies |\n| POST | /api/v2/remote_config/products/cws/policy | Create a Workload Protection policy |\n| GET | /api/v2/remote_config/products/cws/policy/download | Download the Workload Protection policy |\n| DELETE | /api/v2/remote_config/products/cws/policy/{policy_id} | Delete a Workload Protection policy |\n| GET | /api/v2/remote_config/products/cws/policy/{policy_id} | Get a Workload Protection policy |\n| PATCH | /api/v2/remote_config/products/cws/policy/{policy_id} | Update a Workload Protection policy |\n| GET | /api/v2/remote_config/products/rum/configs/{config_id} | Get a RUM SDK configuration |\n| PUT | /api/v2/remote_config/products/rum/configs/{config_id} | Update a RUM SDK configuration |\n| GET | /api/v2/replay/heatmap/snapshots | List replay heatmap snapshots |\n| POST | /api/v2/replay/heatmap/snapshots | Create replay heatmap snapshot |\n| DELETE | /api/v2/replay/heatmap/snapshots/{snapshot_id} | Delete replay heatmap snapshot |\n| PATCH | /api/v2/replay/heatmap/snapshots/{snapshot_id} | Update replay heatmap snapshot |\n| GET | /api/v2/reporting/dataset/{dataset_id}/schedules | List dataset report schedules |\n| POST | /api/v2/reporting/print | Print a report |\n| POST | /api/v2/reporting/schedule | Create a report schedule |\n| GET | /api/v2/reporting/schedule/list | List report schedules |\n| GET | /api/v2/reporting/schedule/{resource_type}/{resource_id} | Get report schedules for a resource |\n| DELETE | /api/v2/reporting/schedule/{schedule_uuid} | Delete a report schedule |\n| GET | /api/v2/reporting/schedule/{schedule_uuid} | Get a report schedule |\n| PATCH | /api/v2/reporting/schedule/{schedule_uuid} | Update a report schedule |\n| PATCH | /api/v2/reporting/schedule/{schedule_uuid}/toggle | Toggle a report schedule |\n| DELETE | /api/v2/restriction_policy/{resource_id} | Delete a restriction policy |\n| GET | /api/v2/restriction_policy/{resource_id} | Get a restriction policy |\n| POST | /api/v2/restriction_policy/{resource_id} | Update a restriction policy |\n| GET | /api/v2/roles | List roles |\n| POST | /api/v2/roles | Create role |\n| GET | /api/v2/roles/templates | List role templates |\n| DELETE | /api/v2/roles/{role_id} | Delete role |\n| GET | /api/v2/roles/{role_id} | Get a role |\n| PATCH | /api/v2/roles/{role_id} | Update a role |\n| POST | /api/v2/roles/{role_id}/clone | Create a new role by cloning an existing role |\n| DELETE | /api/v2/roles/{role_id}/permissions | Revoke permission |\n| GET | /api/v2/roles/{role_id}/permissions | List permissions for a role |\n| POST | /api/v2/roles/{role_id}/permissions | Grant permission to a role |\n| DELETE | /api/v2/roles/{role_id}/users | Remove a user from a role |\n| GET | /api/v2/roles/{role_id}/users | Get all users of a role |\n| POST | /api/v2/roles/{role_id}/users | Add a user to a role |\n| POST | /api/v2/rum/analytics/aggregate | Aggregate RUM events |\n| GET | /api/v2/rum/applications | List all the RUM applications |\n| POST | /api/v2/rum/applications | Create a new RUM application |\n| PATCH | /api/v2/rum/applications/{app_id}/relationships/retention_filters | Order RUM retention filters |\n| GET | /api/v2/rum/applications/{app_id}/retention_filters | Get all RUM retention filters |\n| POST | /api/v2/rum/applications/{app_id}/retention_filters | Create a RUM retention filter |\n| GET | /api/v2/rum/applications/{app_id}/retention_filters/permanent | Get all permanent RUM retention filters |\n| GET | /api/v2/rum/applications/{app_id}/retention_filters/permanent/{permanent_rf_id} | Get a permanent RUM retention filter |\n| PATCH | /api/v2/rum/applications/{app_id}/retention_filters/permanent/{permanent_rf_id} | Update a permanent RUM retention filter |\n| DELETE | /api/v2/rum/applications/{app_id}/retention_filters/{rf_id} | Delete a RUM retention filter |\n| GET | /api/v2/rum/applications/{app_id}/retention_filters/{rf_id} | Get a RUM retention filter |\n| PATCH | /api/v2/rum/applications/{app_id}/retention_filters/{rf_id} | Update a RUM retention filter |\n| DELETE | /api/v2/rum/applications/{id} | Delete a RUM application |\n| GET | /api/v2/rum/applications/{id} | Get a RUM application |\n| PATCH | /api/v2/rum/applications/{id} | Update a RUM application |\n| GET | /api/v2/rum/config | Get the RUM configuration |\n| PATCH | /api/v2/rum/config | Update the RUM configuration |\n| POST | /api/v2/rum/config | Create the RUM configuration |\n| GET | /api/v2/rum/config/metrics | Get all RUM-based metrics |\n| POST | /api/v2/rum/config/metrics | Create a RUM-based metric |\n| DELETE | /api/v2/rum/config/metrics/{metric_id} | Delete a RUM-based metric |\n| GET | /api/v2/rum/config/metrics/{metric_id} | Get a RUM-based metric |\n| PATCH | /api/v2/rum/config/metrics/{metric_id} | Update a RUM-based metric |\n| GET | /api/v2/rum/events | Get a list of RUM events |\n| POST | /api/v2/rum/events/search | Search RUM events |\n| POST | /api/v2/rum/operations | Create a RUM operation |\n| GET | /api/v2/rum/operations/by-name/{name} | Get a RUM operation by name |\n| GET | /api/v2/rum/operations/search | Search RUM operations |\n| GET | /api/v2/rum/operations/strong_links | List RUM operation strong links |\n| POST | /api/v2/rum/operations/strong_links | Create a RUM operation strong link |\n| DELETE | /api/v2/rum/operations/strong_links/{rum_operation_id}/{feature_id} | Delete a RUM operation strong link |\n| PUT | /api/v2/rum/operations/strong_links/{rum_operation_id}/{feature_id} | Update a RUM operation strong link |\n| DELETE | /api/v2/rum/operations/{rum_operation_id} | Delete a RUM operation |\n| GET | /api/v2/rum/operations/{rum_operation_id} | Get a RUM operation |\n| PUT | /api/v2/rum/operations/{rum_operation_id} | Update a RUM operation |\n| POST | /api/v2/rum/query/insight/aggregated_long_tasks | Query aggregated long tasks |\n| POST | /api/v2/rum/query/insight/aggregated_signals_problems | Query aggregated signals and problems |\n| POST | /api/v2/rum/query/insight/aggregated_waterfall | Query aggregated waterfall |\n| GET | /api/v2/rum/replay/playlists | List RUM replay playlists |\n| POST | /api/v2/rum/replay/playlists | Create RUM replay playlist |\n| DELETE | /api/v2/rum/replay/playlists/{playlist_id} | Delete RUM replay playlist |\n| GET | /api/v2/rum/replay/playlists/{playlist_id} | Get RUM replay playlist |\n| PUT | /api/v2/rum/replay/playlists/{playlist_id} | Update RUM replay playlist |\n| DELETE | /api/v2/rum/replay/playlists/{playlist_id}/sessions | Bulk remove RUM replay playlist sessions |\n| GET | /api/v2/rum/replay/playlists/{playlist_id}/sessions | List RUM replay playlist sessions |\n| DELETE | /api/v2/rum/replay/playlists/{playlist_id}/sessions/{session_id} | Remove RUM replay session from playlist |\n| PUT | /api/v2/rum/replay/playlists/{playlist_id}/sessions/{session_id} | Add RUM replay session to playlist |\n| GET | /api/v2/rum/replay/sessions/{session_id}/views/{view_id}/segments | Get segments |\n| GET | /api/v2/rum/replay/sessions/{session_id}/watchers | List RUM replay session watchers |\n| DELETE | /api/v2/rum/replay/sessions/{session_id}/watches | Delete RUM replay session watch |\n| POST | /api/v2/rum/replay/sessions/{session_id}/watches | Create RUM replay session watch |\n| GET | /api/v2/rum/replay/viewership-history/sessions | List RUM replay viewership history sessions |\n| GET | /api/v2/saml_configurations | List SAML configurations |\n| POST | /api/v2/saml_configurations/idp_metadata | Upload IdP metadata |\n| GET | /api/v2/saml_configurations/{saml_config_uuid} | Get a SAML configuration |\n| PATCH | /api/v2/saml_configurations/{saml_config_uuid} | Update a SAML configuration |\n| GET | /api/v2/scorecard/campaigns | List all campaigns |\n| POST | /api/v2/scorecard/campaigns | Create a new campaign |\n| DELETE | /api/v2/scorecard/campaigns/{campaign_id} | Delete a campaign |\n| GET | /api/v2/scorecard/campaigns/{campaign_id} | Get a campaign |\n| PUT | /api/v2/scorecard/campaigns/{campaign_id} | Update a campaign |\n| GET | /api/v2/scorecard/outcomes | List all rule outcomes |\n| POST | /api/v2/scorecard/outcomes | Update Scorecard outcomes |\n| POST | /api/v2/scorecard/outcomes/batch | Create outcomes batch |\n| GET | /api/v2/scorecard/rules | List all rules |\n| POST | /api/v2/scorecard/rules | Create a new rule |\n| DELETE | /api/v2/scorecard/rules/{rule_id} | Delete a rule |\n| PUT | /api/v2/scorecard/rules/{rule_id} | Update an existing scorecard rule |\n| GET | /api/v2/scorecard/scorecards | List all scorecards |\n| GET | /api/v2/scorecard/scores/{aggregation} | List all scores |\n| DELETE | /api/v2/seats/users | Unassign seats from users |\n| GET | /api/v2/seats/users | Get users with seats |\n| POST | /api/v2/seats/users | Assign seats to users |\n| GET | /api/v2/security-entities/risk-scores | List Entity Risk Scores |\n| GET | /api/v2/security-entities/risk-scores/{entity_id} | Get Entity Risk Score |\n| GET | /api/v2/security/asm/services/{service_filter} | Get Application Security details for a service |\n| GET | /api/v2/security/cloud_workload/policy/download | Download the Workload Protection policy (US1-FED) |\n| GET | /api/v2/security/findings | List security findings |\n| PATCH | /api/v2/security/findings/assignee | Assign or unassign security findings |\n| GET | /api/v2/security/findings/automation/due_date_rules | Get all due date rules |\n| POST | /api/v2/security/findings/automation/due_date_rules | Create a due date rule |\n| POST | /api/v2/security/findings/automation/due_date_rules/reorder | Reorder due date rules |\n| DELETE | /api/v2/security/findings/automation/due_date_rules/{rule_id} | Delete a due date rule |\n| GET | /api/v2/security/findings/automation/due_date_rules/{rule_id} | Get a due date rule |\n| PUT | /api/v2/security/findings/automation/due_date_rules/{rule_id} | Update a due date rule |\n| GET | /api/v2/security/findings/automation/mute_rules | Get all mute rules |\n| POST | /api/v2/security/findings/automation/mute_rules | Create a mute rule |\n| POST | /api/v2/security/findings/automation/mute_rules/reorder | Reorder mute rules |\n| DELETE | /api/v2/security/findings/automation/mute_rules/{rule_id} | Delete a mute rule |\n| GET | /api/v2/security/findings/automation/mute_rules/{rule_id} | Get a mute rule |\n| PUT | /api/v2/security/findings/automation/mute_rules/{rule_id} | Update a mute rule |\n| GET | /api/v2/security/findings/automation/ticket_creation_rules | Get all ticket creation rules |\n| POST | /api/v2/security/findings/automation/ticket_creation_rules | Create a ticket creation rule |\n| POST | /api/v2/security/findings/automation/ticket_creation_rules/reorder | Reorder ticket creation rules |\n| DELETE | /api/v2/security/findings/automation/ticket_creation_rules/{rule_id} | Delete a ticket creation rule |\n| GET | /api/v2/security/findings/automation/ticket_creation_rules/{rule_id} | Get a ticket creation rule |\n| PUT | /api/v2/security/findings/automation/ticket_creation_rules/{rule_id} | Update a ticket creation rule |\n| DELETE | /api/v2/security/findings/cases | Detach security findings from their case |\n| POST | /api/v2/security/findings/cases | Create cases for security findings |\n| PATCH | /api/v2/security/findings/cases/{case_id} | Attach security findings to a case |\n| PATCH | /api/v2/security/findings/jira_issues | Attach security findings to a Jira issue |\n| POST | /api/v2/security/findings/jira_issues | Create Jira issues for security findings |\n| PATCH | /api/v2/security/findings/linear_issues | Attach security findings to a Linear issue |\n| POST | /api/v2/security/findings/linear_issues | Create Linear issues for security findings |\n| PATCH | /api/v2/security/findings/mute | Mute or unmute security findings |\n| POST | /api/v2/security/findings/search | Search security findings |\n| PATCH | /api/v2/security/findings/servicenow_tickets | Attach security findings to a ServiceNow ticket |\n| POST | /api/v2/security/findings/servicenow_tickets | Create ServiceNow tickets for security findings |\n| GET | /api/v2/security/sboms | List assets SBOMs |\n| GET | /api/v2/security/sboms/{asset_type} | Get SBOM |\n| GET | /api/v2/security/scanned-assets-metadata | List scanned assets metadata |\n| GET | /api/v2/security/siem/ioc-explorer | List indicators of compromise |\n| GET | /api/v2/security/siem/ioc-explorer/indicator | Get an indicator of compromise |\n| POST | /api/v2/security/siem/ioc-explorer/triage | Create or update an indicator triage state |\n| GET | /api/v2/security/signals/notification_rules | Get the list of signal-based notification rules |\n| POST | /api/v2/security/signals/notification_rules | Create a new signal-based notification rule |\n| DELETE | /api/v2/security/signals/notification_rules/{id} | Delete a signal-based notification rule |\n| GET | /api/v2/security/signals/notification_rules/{id} | Get details of a signal-based notification rule |\n| PATCH | /api/v2/security/signals/notification_rules/{id} | Patch a signal-based notification rule |\n| GET | /api/v2/security/vulnerabilities | List vulnerabilities |\n| POST | /api/v2/security/vulnerabilities | Import security vulnerabilities |\n| GET | /api/v2/security/vulnerabilities/notification_rules | Get the list of vulnerability notification rules |\n| POST | /api/v2/security/vulnerabilities/notification_rules | Create a new vulnerability-based notification rule |\n| DELETE | /api/v2/security/vulnerabilities/notification_rules/{id} | Delete a vulnerability-based notification rule |\n| GET | /api/v2/security/vulnerabilities/notification_rules/{id} | Get details of a vulnerability notification rule |\n| PATCH | /api/v2/security/vulnerabilities/notification_rules/{id} | Patch a vulnerability-based notification rule |\n| GET | /api/v2/security/vulnerable-assets | List vulnerable assets |\n| GET | /api/v2/security_monitoring/cloud_workload_security/agent_rules | Get all Workload Protection agent rules (US1-FED) |\n| POST | /api/v2/security_monitoring/cloud_workload_security/agent_rules | Create a Workload Protection agent rule (US1-FED) |\n| DELETE | /api/v2/security_monitoring/cloud_workload_security/agent_rules/{agent_rule_id} | Delete a Workload Protection agent rule (US1-FED) |\n| GET | /api/v2/security_monitoring/cloud_workload_security/agent_rules/{agent_rule_id} | Get a Workload Protection agent rule (US1-FED) |\n| PATCH | /api/v2/security_monitoring/cloud_workload_security/agent_rules/{agent_rule_id} | Update a Workload Protection agent rule (US1-FED) |\n| GET | /api/v2/security_monitoring/configuration/critical_assets | Get all critical assets |\n| POST | /api/v2/security_monitoring/configuration/critical_assets | Create a critical asset |\n| GET | /api/v2/security_monitoring/configuration/critical_assets/rules/{rule_id} | Get critical assets affecting a specific rule |\n| DELETE | /api/v2/security_monitoring/configuration/critical_assets/{critical_asset_id} | Delete a critical asset |\n| GET | /api/v2/security_monitoring/configuration/critical_assets/{critical_asset_id} | Get a critical asset |\n| PATCH | /api/v2/security_monitoring/configuration/critical_assets/{critical_asset_id} | Update a critical asset |\n| GET | /api/v2/security_monitoring/configuration/integration_config | List entity context sync configurations |\n| POST | /api/v2/security_monitoring/configuration/integration_config | Create an entity context sync configuration |\n| GET | /api/v2/security_monitoring/configuration/integration_config/entra_id/azure_app_registrations | Get Entra ID Azure App Registration prerequisites |\n| POST | /api/v2/security_monitoring/configuration/integration_config/validate | Validate entity context sync credentials |\n| DELETE | /api/v2/security_monitoring/configuration/integration_config/{integration_config_id} | Delete an entity context sync configuration |\n| GET | /api/v2/security_monitoring/configuration/integration_config/{integration_config_id} | Get an entity context sync configuration |\n| PATCH | /api/v2/security_monitoring/configuration/integration_config/{integration_config_id} | Update an entity context sync configuration |\n| POST | /api/v2/security_monitoring/configuration/integration_config/{integration_config_id}/validate | Validate an entity context sync configuration |\n| POST | /api/v2/security_monitoring/configuration/integration_config/{integration_type}/activate | Activate an entity context sync integration |\n| POST | /api/v2/security_monitoring/configuration/integration_config/{integration_type}/deactivate | Deactivate an entity context sync integration |\n| POST | /api/v2/security_monitoring/configuration/notification_rules/send_notification_preview | Test a notification rule |\n| GET | /api/v2/security_monitoring/configuration/security_filters | Get all security filters |\n| POST | /api/v2/security_monitoring/configuration/security_filters | Create a security filter |\n| GET | /api/v2/security_monitoring/configuration/security_filters/versions | Get the version history of security filters |\n| DELETE | /api/v2/security_monitoring/configuration/security_filters/{security_filter_id} | Delete a security filter |\n| GET | /api/v2/security_monitoring/configuration/security_filters/{security_filter_id} | Get a security filter |\n| PATCH | /api/v2/security_monitoring/configuration/security_filters/{security_filter_id} | Update a security filter |\n| GET | /api/v2/security_monitoring/configuration/suppressions | Get all suppression rules |\n| POST | /api/v2/security_monitoring/configuration/suppressions | Create a suppression rule |\n| POST | /api/v2/security_monitoring/configuration/suppressions/rules | Get suppressions affecting future rule |\n| GET | /api/v2/security_monitoring/configuration/suppressions/rules/{rule_id} | Get suppressions affecting a specific rule |\n| POST | /api/v2/security_monitoring/configuration/suppressions/validation | Validate a suppression rule |\n| DELETE | /api/v2/security_monitoring/configuration/suppressions/{suppression_id} | Delete a suppression rule |\n| GET | /api/v2/security_monitoring/configuration/suppressions/{suppression_id} | Get a suppression rule |\n| PATCH | /api/v2/security_monitoring/configuration/suppressions/{suppression_id} | Update a suppression rule |\n| GET | /api/v2/security_monitoring/configuration/suppressions/{suppression_id}/version_history | Get a suppression's version history |\n| GET | /api/v2/security_monitoring/content_packs/states | Get content pack states |\n| PUT | /api/v2/security_monitoring/content_packs/{content_pack_id}/activate | Activate content pack |\n| PUT | /api/v2/security_monitoring/content_packs/{content_pack_id}/deactivate | Deactivate content pack |\n| GET | /api/v2/security_monitoring/datasets | List datasets |\n| POST | /api/v2/security_monitoring/datasets | Create a dataset |\n| POST | /api/v2/security_monitoring/datasets/dependencies | Get dataset dependencies |\n| DELETE | /api/v2/security_monitoring/datasets/{dataset_id} | Delete a dataset |\n| GET | /api/v2/security_monitoring/datasets/{dataset_id} | Get a dataset |\n| PATCH | /api/v2/security_monitoring/datasets/{dataset_id} | Update a dataset |\n| GET | /api/v2/security_monitoring/datasets/{dataset_id}/version/{version} | Get a dataset at a specific version |\n| GET | /api/v2/security_monitoring/datasets/{dataset_id}/version_history | Get the version history of a dataset |\n| GET | /api/v2/security_monitoring/entity_context | Get entity context |\n| GET | /api/v2/security_monitoring/entity_context/{id} | Get a single entity context |\n| GET | /api/v2/security_monitoring/rules | List rules |\n| POST | /api/v2/security_monitoring/rules | Create a detection rule |\n| DELETE | /api/v2/security_monitoring/rules/bulk_delete | Bulk delete security monitoring rules |\n| POST | /api/v2/security_monitoring/rules/bulk_export | Bulk export security monitoring rules |\n| POST | /api/v2/security_monitoring/rules/convert | Convert a rule from JSON to Terraform |\n| POST | /api/v2/security_monitoring/rules/convert/bulk | Bulk convert rules to Terraform |\n| POST | /api/v2/security_monitoring/rules/test | Test a rule |\n| POST | /api/v2/security_monitoring/rules/validation | Validate a detection rule |\n| DELETE | /api/v2/security_monitoring/rules/{rule_id} | Delete an existing rule |\n| GET | /api/v2/security_monitoring/rules/{rule_id} | Get a rule's details |\n| PUT | /api/v2/security_monitoring/rules/{rule_id} | Update an existing rule |\n| GET | /api/v2/security_monitoring/rules/{rule_id}/convert | Convert an existing rule from JSON to Terraform |\n| POST | /api/v2/security_monitoring/rules/{rule_id}/restore/{version} | Restore a rule to a historical version |\n| POST | /api/v2/security_monitoring/rules/{rule_id}/test | Test an existing rule |\n| GET | /api/v2/security_monitoring/rules/{rule_id}/version_history | Get a rule's version history |\n| GET | /api/v2/security_monitoring/sample_log_generation/subscriptions | Get sample log generation subscriptions |\n| POST | /api/v2/security_monitoring/sample_log_generation/subscriptions | Subscribe to sample log generation |\n| POST | /api/v2/security_monitoring/sample_log_generation/subscriptions/bulk | Bulk subscribe to sample log generation |\n| DELETE | /api/v2/security_monitoring/sample_log_generation/subscriptions/{content_pack_id} | Unsubscribe from sample log generation |\n| GET | /api/v2/security_monitoring/signals | Get a quick list of security signals |\n| PATCH | /api/v2/security_monitoring/signals/bulk/assignee | Bulk update triage assignee of security signals |\n| PATCH | /api/v2/security_monitoring/signals/bulk/state | Bulk update triage state of security signals |\n| PATCH | /api/v2/security_monitoring/signals/bulk/update | Bulk update security signals |\n| POST | /api/v2/security_monitoring/signals/search | Get a list of security signals |\n| GET | /api/v2/security_monitoring/signals/{signal_id} | Get a signal's details |\n| PATCH | /api/v2/security_monitoring/signals/{signal_id}/assignee | Modify the triage assignee of a security signal |\n| GET | /api/v2/security_monitoring/signals/{signal_id}/entities | Get entities related to a signal |\n| PATCH | /api/v2/security_monitoring/signals/{signal_id}/incidents | Change the related incidents of a security signal |\n| GET | /api/v2/security_monitoring/signals/{signal_id}/investigation_queries | Get investigation queries for a signal |\n| PATCH | /api/v2/security_monitoring/signals/{signal_id}/state | Change the triage state of a security signal |\n| GET | /api/v2/security_monitoring/signals/{signal_id}/suggested_actions | Get suggested actions for a signal |\n| PATCH | /api/v2/security_monitoring/signals/{signal_id}/update | Update security signal triage state or assignee |\n| POST | /api/v2/security_monitoring/terraform/{resource_type}/bulk | Export security monitoring resources to Terraform |\n| POST | /api/v2/security_monitoring/terraform/{resource_type}/convert | Convert security monitoring resource to Terraform |\n| GET | /api/v2/security_monitoring/terraform/{resource_type}/{resource_id} | Export security monitoring resource to Terraform |\n| GET | /api/v2/sensitive-data-scanner/config | List Scanning Groups |\n| PATCH | /api/v2/sensitive-data-scanner/config | Reorder Groups |\n| POST | /api/v2/sensitive-data-scanner/config/groups | Create Scanning Group |\n| DELETE | /api/v2/sensitive-data-scanner/config/groups/{group_id} | Delete Scanning Group |\n| PATCH | /api/v2/sensitive-data-scanner/config/groups/{group_id} | Update Scanning Group |\n| POST | /api/v2/sensitive-data-scanner/config/rules | Create Scanning Rule |\n| DELETE | /api/v2/sensitive-data-scanner/config/rules/{rule_id} | Delete Scanning Rule |\n| PATCH | /api/v2/sensitive-data-scanner/config/rules/{rule_id} | Update Scanning Rule |\n| GET | /api/v2/sensitive-data-scanner/config/standard-patterns | List standard patterns |\n| POST | /api/v2/series | Submit metrics |\n| POST | /api/v2/service_accounts | Create a service account |\n| GET | /api/v2/service_accounts/{service_account_id}/access_tokens | List access tokens for a service account |\n| POST | /api/v2/service_accounts/{service_account_id}/access_tokens | Create an access token for a service account |\n| DELETE | /api/v2/service_accounts/{service_account_id}/access_tokens/{token_id} | Revoke an access token for a service account |\n| GET | /api/v2/service_accounts/{service_account_id}/access_tokens/{token_id} | Get an access token for a service account |\n| PATCH | /api/v2/service_accounts/{service_account_id}/access_tokens/{token_id} | Update an access token for a service account |\n| GET | /api/v2/service_accounts/{service_account_id}/application_keys | List application keys for this service account |\n| POST | /api/v2/service_accounts/{service_account_id}/application_keys | Create an application key for this service account |\n| DELETE | /api/v2/service_accounts/{service_account_id}/application_keys/{app_key_id} | Delete an application key for this service account |\n| GET | /api/v2/service_accounts/{service_account_id}/application_keys/{app_key_id} | Get one application key for this service account |\n| PATCH | /api/v2/service_accounts/{service_account_id}/application_keys/{app_key_id} | Edit an application key for this service account |\n| GET | /api/v2/services/definitions | Get all service definitions |\n| POST | /api/v2/services/definitions | Create or update service definition |\n| DELETE | /api/v2/services/definitions/{service_name} | Delete a single service definition |\n| GET | /api/v2/services/definitions/{service_name} | Get a single service definition |\n| GET | /api/v2/siem-historical-detections/histsignals | List hist signals |\n| POST | /api/v2/siem-historical-detections/histsignals/search | Search hist signals |\n| GET | /api/v2/siem-historical-detections/histsignals/{histsignal_id} | Get a hist signal's details |\n| GET | /api/v2/siem-historical-detections/jobs | List historical jobs |\n| POST | /api/v2/siem-historical-detections/jobs | Run a historical job |\n| POST | /api/v2/siem-historical-detections/jobs/signal_convert | Convert a job result to a signal |\n| DELETE | /api/v2/siem-historical-detections/jobs/{job_id} | Delete an existing job |\n| GET | /api/v2/siem-historical-detections/jobs/{job_id} | Get a job's details |\n| PATCH | /api/v2/siem-historical-detections/jobs/{job_id}/cancel | Cancel a historical job |\n| GET | /api/v2/siem-historical-detections/jobs/{job_id}/histsignals | Get a job's hist signals |\n| POST | /api/v2/slo/report | Create a new SLO report |\n| GET | /api/v2/slo/report/{report_id}/download | Get SLO report |\n| GET | /api/v2/slo/report/{report_id}/status | Get SLO report status |\n| GET | /api/v2/slo/{slo_id}/status | Get SLO status |\n| POST | /api/v2/snapshot | Create a graph snapshot |\n| DELETE | /api/v2/sourcemaps | Delete source maps |\n| GET | /api/v2/sourcemaps | Get a JavaScript source map |\n| GET | /api/v2/sourcemaps/list | List source maps |\n| PATCH | /api/v2/sourcemaps/restore | Restore source maps |\n| POST | /api/v2/sourcemaps/service_repository_info | Get service repository information |\n| GET | /api/v2/spa/recommendations/{service} | Get SPA Recommendations |\n| GET | /api/v2/spa/recommendations/{service}/{shard} | Get SPA Recommendations with a shard parameter |\n| POST | /api/v2/spans/analytics/aggregate | Aggregate spans |\n| GET | /api/v2/spans/events | Get a list of spans |\n| POST | /api/v2/spans/events/search | Search spans |\n| POST | /api/v2/static-analysis-sca/dependencies | Post dependencies for analysis |\n| POST | /api/v2/static-analysis-sca/dependencies/scan | Submit libraries for vulnerability scanning |\n| GET | /api/v2/static-analysis-sca/dependencies/scan/{job_id} | Retrieve a dependency scan result |\n| GET | /api/v2/static-analysis-sca/licenses/list | Get the list of SPDX licenses |\n| POST | /api/v2/static-analysis-sca/vulnerabilities/resolve-vulnerable-symbols | POST request to resolve vulnerable symbols |\n| GET | /api/v2/static-analysis/ai/memory | List AI memory violation results |\n| POST | /api/v2/static-analysis/ai/memory | Create an AI memory violation result |\n| DELETE | /api/v2/static-analysis/ai/memory/{id} | Delete an AI memory violation result |\n| GET | /api/v2/static-analysis/ai/prompts | List AI prompts |\n| GET | /api/v2/static-analysis/ai/rulesets | List AI custom rulesets |\n| POST | /api/v2/static-analysis/ai/rulesets | Create an AI custom ruleset |\n| DELETE | /api/v2/static-analysis/ai/rulesets/{ruleset_name} | Delete an AI custom ruleset |\n| GET | /api/v2/static-analysis/ai/rulesets/{ruleset_name} | Get an AI custom ruleset |\n| PATCH | /api/v2/static-analysis/ai/rulesets/{ruleset_name} | Update an AI custom ruleset |\n| POST | /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules | Create an AI custom rule |\n| DELETE | /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name} | Delete an AI custom rule |\n| GET | /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name} | Get an AI custom rule |\n| GET | /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}/revisions | List AI custom rule revisions |\n| POST | /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}/revisions | Create an AI custom rule revision |\n| GET | /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}/revisions/{id} | Get an AI custom rule revision |\n| GET | /api/v2/static-analysis/codegen/rulesets | List codegen rulesets |\n| GET | /api/v2/static-analysis/custom/rulesets | List Custom Rulesets |\n| PUT | /api/v2/static-analysis/custom/rulesets | Create Custom Ruleset |\n| DELETE | /api/v2/static-analysis/custom/rulesets/{ruleset_name} | Delete Custom Ruleset |\n| GET | /api/v2/static-analysis/custom/rulesets/{ruleset_name} | Show Custom Ruleset |\n| PATCH | /api/v2/static-analysis/custom/rulesets/{ruleset_name} | Update Custom Ruleset |\n| PUT | /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules | Create Custom Rule |\n| DELETE | /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name} | Delete Custom Rule |\n| GET | /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name} | Show Custom Rule |\n| GET | /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name}/revisions | List Custom Rule Revisions |\n| PUT | /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name}/revisions | Create Custom Rule Revision |\n| POST | /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name}/revisions/revert | Revert Custom Rule Revision |\n| GET | /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name}/revisions/{id} | Show Custom Rule Revision |\n| GET | /api/v2/static-analysis/default-rulesets/{language} | Get default rulesets for a language |\n| POST | /api/v2/static-analysis/rulesets | Ruleset get multiple |\n| GET | /api/v2/static-analysis/rulesets/{ruleset_name} | Get a SAST ruleset |\n| GET | /api/v2/static-analysis/secrets/rules | Returns a list of Secrets rules |\n| POST | /api/v2/static-analysis/static-analysis-server/analyze | Analyze code |\n| POST | /api/v2/static-analysis/static-analysis-server/get-ast | Get AST for source code |\n| GET | /api/v2/static-analysis/static-analysis-server/node-types/{language} | Get node types for a language |\n| GET | /api/v2/static-analysis/static-analysis-server/tree-sitter-wasm/{file} | Get tree-sitter WASM file |\n| GET | /api/v2/statuspages | List status pages |\n| POST | /api/v2/statuspages | Create status page |\n| GET | /api/v2/statuspages/degradations | List degradations |\n| GET | /api/v2/statuspages/maintenances | List maintenances |\n| DELETE | /api/v2/statuspages/{page_id} | Delete status page |\n| GET | /api/v2/statuspages/{page_id} | Get status page |\n| PATCH | /api/v2/statuspages/{page_id} | Update status page |\n| GET | /api/v2/statuspages/{page_id}/components | List components |\n| POST | /api/v2/statuspages/{page_id}/components | Create component |\n| DELETE | /api/v2/statuspages/{page_id}/components/{component_id} | Delete component |\n| GET | /api/v2/statuspages/{page_id}/components/{component_id} | Get component |\n| PATCH | /api/v2/statuspages/{page_id}/components/{component_id} | Update component |\n| GET | /api/v2/statuspages/{page_id}/degradation_templates | List degradation templates |\n| POST | /api/v2/statuspages/{page_id}/degradation_templates | Create degradation template |\n| DELETE | /api/v2/statuspages/{page_id}/degradation_templates/{template_id} | Delete degradation template |\n| GET | /api/v2/statuspages/{page_id}/degradation_templates/{template_id} | Get degradation template |\n| PATCH | /api/v2/statuspages/{page_id}/degradation_templates/{template_id} | Update degradation template |\n| POST | /api/v2/statuspages/{page_id}/degradations | Create degradation |\n| POST | /api/v2/statuspages/{page_id}/degradations/backfill | Create backfilled degradation |\n| DELETE | /api/v2/statuspages/{page_id}/degradations/{degradation_id} | Delete degradation |\n| GET | /api/v2/statuspages/{page_id}/degradations/{degradation_id} | Get degradation |\n| PATCH | /api/v2/statuspages/{page_id}/degradations/{degradation_id} | Update degradation |\n| DELETE | /api/v2/statuspages/{page_id}/degradations/{degradation_id}/updates/{update_id} | Soft delete degradation update |\n| PATCH | /api/v2/statuspages/{page_id}/degradations/{degradation_id}/updates/{update_id} | Edit degradation update |\n| GET | /api/v2/statuspages/{page_id}/maintenance_templates | List maintenance templates |\n| POST | /api/v2/statuspages/{page_id}/maintenance_templates | Create maintenance template |\n| DELETE | /api/v2/statuspages/{page_id}/maintenance_templates/{template_id} | Delete maintenance template |\n| GET | /api/v2/statuspages/{page_id}/maintenance_templates/{template_id} | Get maintenance template |\n| PATCH | /api/v2/statuspages/{page_id}/maintenance_templates/{template_id} | Update maintenance template |\n| POST | /api/v2/statuspages/{page_id}/maintenances | Schedule maintenance |\n| POST | /api/v2/statuspages/{page_id}/maintenances/backfill | Create backfilled maintenance |\n| GET | /api/v2/statuspages/{page_id}/maintenances/{maintenance_id} | Get maintenance |\n| PATCH | /api/v2/statuspages/{page_id}/maintenances/{maintenance_id} | Update maintenance |\n| PATCH | /api/v2/statuspages/{page_id}/maintenances/{maintenance_id}/updates/{update_id} | Edit maintenance update |\n| POST | /api/v2/statuspages/{page_id}/publish | Publish status page |\n| POST | /api/v2/statuspages/{page_id}/unpublish | Unpublish status page |\n| POST | /api/v2/stegadography/get-widgets | Get widgets from an image |\n| GET | /api/v2/synthetics/api-multistep/subtests/{public_id} | Get available subtests for a multistep test |\n| GET | /api/v2/synthetics/api-multistep/subtests/{public_id}/parents | Get parent tests for a subtest |\n| GET | /api/v2/synthetics/downtimes | List Synthetics downtimes |\n| POST | /api/v2/synthetics/downtimes | Create a Synthetics downtime |\n| DELETE | /api/v2/synthetics/downtimes/{downtime_id} | Delete a Synthetics downtime |\n| GET | /api/v2/synthetics/downtimes/{downtime_id} | Get a Synthetics downtime |\n| PUT | /api/v2/synthetics/downtimes/{downtime_id} | Update a Synthetics downtime |\n| DELETE | /api/v2/synthetics/downtimes/{downtime_id}/tests/{test_id} | Remove a test from a Synthetics downtime |\n| PUT | /api/v2/synthetics/downtimes/{downtime_id}/tests/{test_id} | Add a test to a Synthetics downtime |\n| GET | /api/v2/synthetics/settings/on_demand_concurrency_cap | Get the on-demand concurrency cap |\n| POST | /api/v2/synthetics/settings/on_demand_concurrency_cap | Save new value for on-demand concurrency cap |\n| POST | /api/v2/synthetics/suites | Create a test suite |\n| POST | /api/v2/synthetics/suites/bulk-delete | Bulk delete suites |\n| GET | /api/v2/synthetics/suites/search | Search test suites |\n| GET | /api/v2/synthetics/suites/{public_id} | Get a suite |\n| PUT | /api/v2/synthetics/suites/{public_id} | Edit a test suite |\n| PATCH | /api/v2/synthetics/suites/{public_id}/jsonpatch | Patch a test suite |\n| GET | /api/v2/synthetics/tests/browser/{public_id}/results | Get a browser test's latest results |\n| GET | /api/v2/synthetics/tests/browser/{public_id}/results/{result_id} | Get a browser test result |\n| POST | /api/v2/synthetics/tests/bulk-delete | Bulk delete tests |\n| GET | /api/v2/synthetics/tests/fast/{id} | Get a fast test result |\n| POST | /api/v2/synthetics/tests/network | Create a Network Path test |\n| GET | /api/v2/synthetics/tests/network/{public_id} | Get a Network Path test |\n| PUT | /api/v2/synthetics/tests/network/{public_id} | Edit a Network Path test |\n| GET | /api/v2/synthetics/tests/poll_results | Poll for test results |\n| POST | /api/v2/synthetics/tests/{public_id}/files/download | Get a presigned URL for downloading a test file |\n| POST | /api/v2/synthetics/tests/{public_id}/files/multipart-presigned-urls | Get presigned URLs for uploading a test file |\n| POST | /api/v2/synthetics/tests/{public_id}/files/multipart-upload-abort | Abort a multipart upload of a test file |\n| POST | /api/v2/synthetics/tests/{public_id}/files/multipart-upload-complete | Complete a multipart upload of a test file |\n| GET | /api/v2/synthetics/tests/{public_id}/parent-suites | Get parent suites for a test |\n| GET | /api/v2/synthetics/tests/{public_id}/results | Get a test's latest results |\n| GET | /api/v2/synthetics/tests/{public_id}/results/{result_id} | Get a test result |\n| GET | /api/v2/synthetics/tests/{public_id}/version_history | Get version history of a test |\n| GET | /api/v2/synthetics/tests/{public_id}/version_history/{version_number} | Get a specific version of a test |\n| PATCH | /api/v2/synthetics/variables/{variable_id}/jsonpatch | Patch a global variable |\n| GET | /api/v2/tag_policies | List tag policies |\n| POST | /api/v2/tag_policies | Create a tag policy |\n| DELETE | /api/v2/tag_policies/{policy_id} | Delete a tag policy |\n| GET | /api/v2/tag_policies/{policy_id} | Get a tag policy |\n| PATCH | /api/v2/tag_policies/{policy_id} | Update a tag policy |\n| GET | /api/v2/tag_policies/{policy_id}/score | Get a tag policy compliance score |\n| GET | /api/v2/tags/enrichment | List tag pipeline rulesets |\n| POST | /api/v2/tags/enrichment | Create tag pipeline ruleset |\n| POST | /api/v2/tags/enrichment/reorder | Reorder tag pipeline rulesets |\n| GET | /api/v2/tags/enrichment/status | List tag pipeline ruleset statuses |\n| POST | /api/v2/tags/enrichment/validate-query | Validate query |\n| DELETE | /api/v2/tags/enrichment/{ruleset_id} | Delete tag pipeline ruleset |\n| GET | /api/v2/tags/enrichment/{ruleset_id} | Get a tag pipeline ruleset |\n| PATCH | /api/v2/tags/enrichment/{ruleset_id} | Update tag pipeline ruleset |\n| GET | /api/v2/team | Get all teams |\n| POST | /api/v2/team | Create a team |\n| GET | /api/v2/team-hierarchy-links | Get team hierarchy links |\n| POST | /api/v2/team-hierarchy-links | Create a team hierarchy link |\n| DELETE | /api/v2/team-hierarchy-links/{link_id} | Remove a team hierarchy link |\n| GET | /api/v2/team-hierarchy-links/{link_id} | Get a team hierarchy link |\n| DELETE | /api/v2/team/connections | Delete team connections |\n| GET | /api/v2/team/connections | List team connections |\n| POST | /api/v2/team/connections | Create team connections |\n| GET | /api/v2/team/sync | Get team sync configurations |\n| POST | /api/v2/team/sync | Link Teams with GitHub Teams |\n| GET | /api/v2/team/{super_team_id}/member_teams | Get all member teams |\n| POST | /api/v2/team/{super_team_id}/member_teams | Add a member team |\n| DELETE | /api/v2/team/{super_team_id}/member_teams/{member_team_id} | Remove a member team |\n| DELETE | /api/v2/team/{team_id} | Remove a team |\n| GET | /api/v2/team/{team_id} | Get a team |\n| PATCH | /api/v2/team/{team_id} | Update a team |\n| GET | /api/v2/team/{team_id}/links | Get links for a team |\n| POST | /api/v2/team/{team_id}/links | Create a team link |\n| DELETE | /api/v2/team/{team_id}/links/{link_id} | Remove a team link |\n| GET | /api/v2/team/{team_id}/links/{link_id} | Get a team link |\n| PATCH | /api/v2/team/{team_id}/links/{link_id} | Update a team link |\n| GET | /api/v2/team/{team_id}/memberships | Get team memberships |\n| POST | /api/v2/team/{team_id}/memberships | Add a user to a team |\n| DELETE | /api/v2/team/{team_id}/memberships/{user_id} | Remove a user from a team |\n| PATCH | /api/v2/team/{team_id}/memberships/{user_id} | Update a user's membership attributes on a team |\n| GET | /api/v2/team/{team_id}/notification-rules | Get team notification rules |\n| POST | /api/v2/team/{team_id}/notification-rules | Create team notification rule |\n| DELETE | /api/v2/team/{team_id}/notification-rules/{rule_id} | Delete team notification rule |\n| GET | /api/v2/team/{team_id}/notification-rules/{rule_id} | Get team notification rule |\n| PUT | /api/v2/team/{team_id}/notification-rules/{rule_id} | Update team notification rule |\n| GET | /api/v2/team/{team_id}/permission-settings | Get permission settings for a team |\n| PUT | /api/v2/team/{team_id}/permission-settings/{action} | Update permission setting for team |\n| PATCH | /api/v2/test/flaky-test-management/tests | Update flaky test states |\n| POST | /api/v2/test/flaky-test-management/tests | Search flaky tests |\n| GET | /api/v2/trace/{trace_id} | Get a trace by ID |\n| GET | /api/v2/usage/application_security | Get hourly usage for application security |\n| GET | /api/v2/usage/billing_dimension_mapping | Get billing dimension mapping for usage endpoints |\n| GET | /api/v2/usage/cost_by_org | Get cost across multi-org account |\n| GET | /api/v2/usage/estimated_cost | Get estimated cost across your account |\n| GET | /api/v2/usage/historical_cost | Get historical cost across your account |\n| GET | /api/v2/usage/hourly_usage | Get hourly usage by product family |\n| GET | /api/v2/usage/lambda_traced_invocations | Get hourly usage for Lambda traced invocations |\n| GET | /api/v2/usage/observability_pipelines | Get hourly usage for observability pipelines |\n| GET | /api/v2/usage/projected_cost | Get projected cost across your account |\n| GET | /api/v2/usage/summary/available_fields | Get available fields for usage summary |\n| GET | /api/v2/usage/usage-attribution-types | Get usage attribution types |\n| GET | /api/v2/user_authorized_clients | List user authorized clients |\n| DELETE | /api/v2/user_authorized_clients/client/{client_id} | Delete all user authorized clients for a client |\n| DELETE | /api/v2/user_authorized_clients/{user_authorized_client_id} | Delete a user authorized client |\n| GET | /api/v2/user_authorized_clients/{user_authorized_client_id} | Get a user authorized client |\n| POST | /api/v2/user_invitations | Send invitation emails |\n| GET | /api/v2/user_invitations/{user_invitation_uuid} | Get a user invitation |\n| GET | /api/v2/users | List all users |\n| POST | /api/v2/users | Create a user |\n| DELETE | /api/v2/users/{user_id} | Disable a user |\n| GET | /api/v2/users/{user_id} | Get user details |\n| PATCH | /api/v2/users/{user_id} | Update a user |\n| GET | /api/v2/users/{user_id}/identity_providers | Get identity provider overrides for a user |\n| DELETE | /api/v2/users/{user_id}/invitations | Delete a pending user's invitations |\n| GET | /api/v2/users/{user_id}/orgs | Get a user organization |\n| GET | /api/v2/users/{user_id}/permissions | Get a user permissions |\n| PATCH | /api/v2/users/{user_id}/relationships/identity_providers | Update identity provider overrides for a user |\n| GET | /api/v2/users/{user_uuid}/memberships | Get user memberships |\n| GET | /api/v2/validate | Validate API key |\n| GET | /api/v2/validate_keys | Validate API and application keys |\n| GET | /api/v2/web-integrations/{integration_name}/accounts | List web integration accounts |\n| POST | /api/v2/web-integrations/{integration_name}/accounts | Create a web integration account |\n| DELETE | /api/v2/web-integrations/{integration_name}/accounts/{account_id} | Delete a web integration account |\n| GET | /api/v2/web-integrations/{integration_name}/accounts/{account_id} | Get a web integration account |\n| PATCH | /api/v2/web-integrations/{integration_name}/accounts/{account_id} | Update a web integration account |\n| GET | /api/v2/widgets/{experience_type} | Search widgets |\n| POST | /api/v2/widgets/{experience_type} | Create a widget |\n| DELETE | /api/v2/widgets/{experience_type}/{uuid} | Delete a widget |\n| GET | /api/v2/widgets/{experience_type}/{uuid} | Get a widget |\n| PUT | /api/v2/widgets/{experience_type}/{uuid} | Update a widget |\n| GET | /api/v2/workflows | List workflows |\n| POST | /api/v2/workflows | Create a Workflow |\n| DELETE | /api/v2/workflows/{workflow_id} | Delete an existing Workflow |\n| GET | /api/v2/workflows/{workflow_id} | Get an existing Workflow |\n| PATCH | /api/v2/workflows/{workflow_id} | Update an existing Workflow |\n| GET | /api/v2/workflows/{workflow_id}/instances | List workflow instances |\n| POST | /api/v2/workflows/{workflow_id}/instances | Execute a workflow |\n| GET | /api/v2/workflows/{workflow_id}/instances/{instance_id} | Get a workflow instance |\n| PUT | /api/v2/workflows/{workflow_id}/instances/{instance_id}/cancel | Cancel a workflow instance |\n\n## Common Questions\nMatch user requests to endpoints in references/api-spec.lap. Key patterns:\n- \"List all tracers?\" -> GET /api/unstable/fleet/agents/{agent_key}/tracers\n- \"Create a schedule?\" -> POST /api/unstable/fleet/schedules\n- \"Delete a schedule?\" -> DELETE /api/unstable/fleet/schedules/{id}\n- \"Partially update a schedule?\" -> PATCH /api/unstable/fleet/schedules/{id}\n- \"Create a trigger?\" -> POST /api/unstable/fleet/schedules/{id}/trigger\n- \"List all custom?\" -> GET /api/unstable/llm-obs/config/evaluators/custom\n- \"Delete a custom?\" -> DELETE /api/unstable/llm-obs/config/evaluators/custom/{eval_name}\n- \"Get custom details?\" -> GET /api/unstable/llm-obs/config/evaluators/custom/{eval_name}\n- \"Update a custom?\" -> PUT /api/unstable/llm-obs/config/evaluators/custom/{eval_name}\n- \"List all actions-datastores?\" -> GET /api/v2/actions-datastores\n- \"Create a actions-datastore?\" -> POST /api/v2/actions-datastores\n- \"Delete a actions-datastore?\" -> DELETE /api/v2/actions-datastores/{datastore_id}\n- \"Get actions-datastore details?\" -> GET /api/v2/actions-datastores/{datastore_id}\n- \"Partially update a actions-datastore?\" -> PATCH /api/v2/actions-datastores/{datastore_id}\n- \"List all items?\" -> GET /api/v2/actions-datastores/{datastore_id}/items\n- \"Create a bulk?\" -> POST /api/v2/actions-datastores/{datastore_id}/items/bulk\n- \"List all app_key_registrations?\" -> GET /api/v2/actions/app_key_registrations\n- \"Delete a app_key_registration?\" -> DELETE /api/v2/actions/app_key_registrations/{app_key_id}\n- \"Get app_key_registration details?\" -> GET /api/v2/actions/app_key_registrations/{app_key_id}\n- \"Update a app_key_registration?\" -> PUT /api/v2/actions/app_key_registrations/{app_key_id}\n- \"Create a connection?\" -> POST /api/v2/actions/connections\n- \"Delete a connection?\" -> DELETE /api/v2/actions/connections/{connection_id}\n- \"Get connection details?\" -> GET /api/v2/actions/connections/{connection_id}\n- \"Partially update a connection?\" -> PATCH /api/v2/actions/connections/{connection_id}\n- \"List all aws?\" -> GET /api/v2/agentless_scanning/accounts/aws\n- \"Create a aw?\" -> POST /api/v2/agentless_scanning/accounts/aws\n- \"Delete a aw?\" -> DELETE /api/v2/agentless_scanning/accounts/aws/{account_id}\n- \"Get aw details?\" -> GET /api/v2/agentless_scanning/accounts/aws/{account_id}\n- \"Partially update a aw?\" -> PATCH /api/v2/agentless_scanning/accounts/aws/{account_id}\n- \"List all azure?\" -> GET /api/v2/agentless_scanning/accounts/azure\n- \"Create a azure?\" -> POST /api/v2/agentless_scanning/accounts/azure\n- \"Delete a azure?\" -> DELETE /api/v2/agentless_scanning/accounts/azure/{subscription_id}\n- \"Get azure details?\" -> GET /api/v2/agentless_scanning/accounts/azure/{subscription_id}\n- \"Partially update a azure?\" -> PATCH /api/v2/agentless_scanning/accounts/azure/{subscription_id}\n- \"List all gcp?\" -> GET /api/v2/agentless_scanning/accounts/gcp\n- \"Create a gcp?\" -> POST /api/v2/agentless_scanning/accounts/gcp\n- \"Delete a gcp?\" -> DELETE /api/v2/agentless_scanning/accounts/gcp/{project_id}\n- \"Get gcp details?\" -> GET /api/v2/agentless_scanning/accounts/gcp/{project_id}\n- \"Partially update a gcp?\" -> PATCH /api/v2/agentless_scanning/accounts/gcp/{project_id}\n- \"List all annotation?\" -> GET /api/v2/annotation\n- \"Create a annotation?\" -> POST /api/v2/annotation\n- \"Get page details?\" -> GET /api/v2/annotation/page/{page_id}\n- \"Delete a annotation?\" -> DELETE /api/v2/annotation/{annotation_id}\n- \"Update a annotation?\" -> PUT /api/v2/annotation/{annotation_id}\n- \"List all api_keys?\" -> GET /api/v2/api_keys\n- \"Create a api_key?\" -> POST /api/v2/api_keys\n- \"Delete a api_key?\" -> DELETE /api/v2/api_keys/{api_key_id}\n- \"Get api_key details?\" -> GET /api/v2/api_keys/{api_key_id}\n- \"Partially update a api_key?\" -> PATCH /api/v2/api_keys/{api_key_id}\n- \"Search api?\" -> GET /api/v2/apicatalog/api\n- \"Delete a api?\" -> DELETE /api/v2/apicatalog/api/{id}\n- \"List all openapi?\" -> GET /api/v2/apicatalog/api/{id}/openapi\n- \"Create a openapi?\" -> POST /api/v2/apicatalog/openapi\n- \"List all metrics?\" -> GET /api/v2/apm/config/metrics\n- \"Create a metric?\" -> POST /api/v2/apm/config/metrics\n- \"Delete a metric?\" -> DELETE /api/v2/apm/config/metrics/{metric_id}\n- \"Get metric details?\" -> GET /api/v2/apm/config/metrics/{metric_id}\n- \"Partially update a metric?\" -> PATCH /api/v2/apm/config/metrics/{metric_id}\n- \"List all retention-filters?\" -> GET /api/v2/apm/config/retention-filters\n- \"Create a retention-filter?\" -> POST /api/v2/apm/config/retention-filters\n- \"Delete a retention-filter?\" -> DELETE /api/v2/apm/config/retention-filters/{filter_id}\n- \"Get retention-filter details?\" -> GET /api/v2/apm/config/retention-filters/{filter_id}\n- \"Update a retention-filter?\" -> PUT /api/v2/apm/config/retention-filters/{filter_id}\n- \"List all services?\" -> GET /api/v2/apm/services\n- \"List all apps?\" -> GET /api/v2/app-builder/apps\n- \"Create a app?\" -> POST /api/v2/app-builder/apps\n- \"Delete a app?\" -> DELETE /api/v2/app-builder/apps/{app_id}\n- \"Get app details?\" -> GET /api/v2/app-builder/apps/{app_id}\n- \"Partially update a app?\" -> PATCH /api/v2/app-builder/apps/{app_id}\n- \"Create a deployment?\" -> POST /api/v2/app-builder/apps/{app_id}/deployment\n- \"Create a publish-request?\" -> POST /api/v2/app-builder/apps/{app_id}/publish-request\n- \"Create a revert?\" -> POST /api/v2/app-builder/apps/{app_id}/revert\n- \"List all versions?\" -> GET /api/v2/app-builder/apps/{app_id}/versions\n- \"Get blueprint details?\" -> GET /api/v2/app-builder/blueprint/{blueprint_id}\n- \"List all blueprints?\" -> GET /api/v2/app-builder/blueprints\n- \"Get integration-id details?\" -> GET /api/v2/app-builder/blueprints/integration-id/{integration_id}\n- \"Get slug details?\" -> GET /api/v2/app-builder/blueprints/slugs/{slugs}\n- \"List all tags?\" -> GET /api/v2/app-builder/tags\n- \"List all application_keys?\" -> GET /api/v2/application_keys\n- \"Delete a application_key?\" -> DELETE /api/v2/application_keys/{app_key_id}\n- \"Get application_key details?\" -> GET /api/v2/application_keys/{app_key_id}\n- \"Partially update a application_key?\" -> PATCH /api/v2/application_keys/{app_key_id}\n- \"List all events?\" -> GET /api/v2/audit/events\n- \"Create a search?\" -> POST /api/v2/audit/events/search\n- \"List all authn_mappings?\" -> GET /api/v2/authn_mappings\n- \"Create a authn_mapping?\" -> POST /api/v2/authn_mappings\n- \"Delete a authn_mapping?\" -> DELETE /api/v2/authn_mappings/{authn_mapping_id}\n- \"Get authn_mapping details?\" -> GET /api/v2/authn_mappings/{authn_mapping_id}\n- \"Partially update a authn_mapping?\" -> PATCH /api/v2/authn_mappings/{authn_mapping_id}\n- \"List all investigations?\" -> GET /api/v2/bits-ai/investigations\n- \"Create a investigation?\" -> POST /api/v2/bits-ai/investigations\n- \"Get investigation details?\" -> GET /api/v2/bits-ai/investigations/{id}\n- \"List all cases?\" -> GET /api/v2/cases\n- \"Create a case?\" -> POST /api/v2/cases\n- \"Create a aggregate?\" -> POST /api/v2/cases/aggregate\n- \"List all count?\" -> GET /api/v2/cases/count\n- \"List all link?\" -> GET /api/v2/cases/link\n- \"Create a link?\" -> POST /api/v2/cases/link\n- \"Delete a link?\" -> DELETE /api/v2/cases/link/{link_id}\n- \"List all projects?\" -> GET /api/v2/cases/projects\n- \"Create a project?\" -> POST /api/v2/cases/projects\n- \"List all favorites?\" -> GET /api/v2/cases/projects/favorites\n- \"Delete a project?\" -> DELETE /api/v2/cases/projects/{project_id}\n- \"Get project details?\" -> GET /api/v2/cases/projects/{project_id}\n- \"Partially update a project?\" -> PATCH /api/v2/cases/projects/{project_id}\n- \"Create a favorite?\" -> POST /api/v2/cases/projects/{project_id}/favorites\n- \"List all notification_rules?\" -> GET /api/v2/cases/projects/{project_id}/notification_rules\n- \"Create a notification_rule?\" -> POST /api/v2/cases/projects/{project_id}/notification_rules\n- \"Delete a notification_rule?\" -> DELETE /api/v2/cases/projects/{project_id}/notification_rules/{notification_rule_id}\n- \"Update a notification_rule?\" -> PUT /api/v2/cases/projects/{project_id}/notification_rules/{notification_rule_id}\n- \"List all rules?\" -> GET /api/v2/cases/projects/{project_id}/rules\n- \"Create a rule?\" -> POST /api/v2/cases/projects/{project_id}/rules\n- \"Delete a rule?\" -> DELETE /api/v2/cases/projects/{project_id}/rules/{rule_id}\n- \"Get rule details?\" -> GET /api/v2/cases/projects/{project_id}/rules/{rule_id}\n- \"Update a rule?\" -> PUT /api/v2/cases/projects/{project_id}/rules/{rule_id}\n- \"Create a disable?\" -> POST /api/v2/cases/projects/{project_id}/rules/{rule_id}/disable\n- \"Create a enable?\" -> POST /api/v2/cases/projects/{project_id}/rules/{rule_id}/enable\n- \"List all types?\" -> GET /api/v2/cases/types\n- \"Create a type?\" -> POST /api/v2/cases/types\n- \"List all custom_attributes?\" -> GET /api/v2/cases/types/custom_attributes\n- \"Delete a type?\" -> DELETE /api/v2/cases/types/{case_type_id}\n- \"Update a type?\" -> PUT /api/v2/cases/types/{case_type_id}\n- \"Create a custom_attribute?\" -> POST /api/v2/cases/types/{case_type_id}/custom_attributes\n- \"Delete a custom_attribute?\" -> DELETE /api/v2/cases/types/{case_type_id}/custom_attributes/{custom_attribute_id}\n- \"Update a custom_attribute?\" -> PUT /api/v2/cases/types/{case_type_id}/custom_attributes/{custom_attribute_id}\n- \"List all views?\" -> GET /api/v2/cases/views\n- \"Create a view?\" -> POST /api/v2/cases/views\n- \"Delete a view?\" -> DELETE /api/v2/cases/views/{view_id}\n- \"Get view details?\" -> GET /api/v2/cases/views/{view_id}\n- \"Update a view?\" -> PUT /api/v2/cases/views/{view_id}\n- \"Get case details?\" -> GET /api/v2/cases/{case_id}\n- \"Create a archive?\" -> POST /api/v2/cases/{case_id}/archive\n- \"Create a assign?\" -> POST /api/v2/cases/{case_id}/assign\n- \"Create a attribute?\" -> POST /api/v2/cases/{case_id}/attributes\n- \"Create a comment?\" -> POST /api/v2/cases/{case_id}/comment\n- \"Delete a comment?\" -> DELETE /api/v2/cases/{case_id}/comment/{cell_id}\n- \"Update a comment?\" -> PUT /api/v2/cases/{case_id}/comment/{cell_id}\n- \"Create a description?\" -> POST /api/v2/cases/{case_id}/description\n- \"Create a due_date?\" -> POST /api/v2/cases/{case_id}/due_date\n- \"Create a priority?\" -> POST /api/v2/cases/{case_id}/priority\n- \"Create a incident?\" -> POST /api/v2/cases/{case_id}/relationships/incidents\n- \"Create a jira_issue?\" -> POST /api/v2/cases/{case_id}/relationships/jira_issues\n- \"Create a notebook?\" -> POST /api/v2/cases/{case_id}/relationships/notebook\n- \"Create a servicenow_ticket?\" -> POST /api/v2/cases/{case_id}/relationships/servicenow_tickets\n- \"Create a resolved_reason?\" -> POST /api/v2/cases/{case_id}/resolved_reason\n- \"Create a status?\" -> POST /api/v2/cases/{case_id}/status\n- \"List all timelines?\" -> GET /api/v2/cases/{case_id}/timelines\n- \"Create a title?\" -> POST /api/v2/cases/{case_id}/title\n- \"Create a unarchive?\" -> POST /api/v2/cases/{case_id}/unarchive\n- \"Create a unassign?\" -> POST /api/v2/cases/{case_id}/unassign\n- \"List all watchers?\" -> GET /api/v2/cases/{case_id}/watchers\n- \"Delete a watcher?\" -> DELETE /api/v2/cases/{case_id}/watchers/{user_uuid}\n- \"List all entity?\" -> GET /api/v2/catalog/entity\n- \"Create a entity?\" -> POST /api/v2/catalog/entity\n- \"Create a preview?\" -> POST /api/v2/catalog/entity/preview\n- \"Delete a entity?\" -> DELETE /api/v2/catalog/entity/{entity_id}\n- \"List all kind?\" -> GET /api/v2/catalog/kind\n- \"Create a kind?\" -> POST /api/v2/catalog/kind\n- \"Delete a kind?\" -> DELETE /api/v2/catalog/kind/{kind_id}\n- \"List all relation?\" -> GET /api/v2/catalog/relation\n- \"Create a change-request?\" -> POST /api/v2/change-management/change-request\n- \"Get change-request details?\" -> GET /api/v2/change-management/change-request/{change_request_id}\n- \"Partially update a change-request?\" -> PATCH /api/v2/change-management/change-request/{change_request_id}\n- \"Create a branch?\" -> POST /api/v2/change-management/change-request/{change_request_id}/branch\n- \"Delete a decision?\" -> DELETE /api/v2/change-management/change-request/{change_request_id}/decisions/{decision_id}\n- \"Partially update a decision?\" -> PATCH /api/v2/change-management/change-request/{change_request_id}/decisions/{decision_id}\n- \"List all accounts?\" -> GET /api/v2/ci/github/accounts\n- \"Create a pipeline?\" -> POST /api/v2/ci/pipeline\n- \"Create a policy?\" -> POST /api/v2/ci/test-optimization/settings/policies\n- \"Create a service?\" -> POST /api/v2/ci/test-optimization/settings/service\n- \"List all persona_mapping?\" -> GET /api/v2/cloud_auth/aws/persona_mapping\n- \"Create a persona_mapping?\" -> POST /api/v2/cloud_auth/aws/persona_mapping\n- \"Delete a persona_mapping?\" -> DELETE /api/v2/cloud_auth/aws/persona_mapping/{persona_mapping_id}\n- \"Get persona_mapping details?\" -> GET /api/v2/cloud_auth/aws/persona_mapping/{persona_mapping_id}\n- \"Create a custom_framework?\" -> POST /api/v2/cloud_security_management/custom_frameworks\n- \"Delete a custom_framework?\" -> DELETE /api/v2/cloud_security_management/custom_frameworks/{handle}/{version}\n- \"Get custom_framework details?\" -> GET /api/v2/cloud_security_management/custom_frameworks/{handle}/{version}\n- \"Update a custom_framework?\" -> PUT /api/v2/cloud_security_management/custom_frameworks/{handle}/{version}\n- \"List all resource_filters?\" -> GET /api/v2/cloud_security_management/resource_filters\n- \"Delete a syncconfig?\" -> DELETE /api/v2/cloudinventoryservice/syncconfigs/{id}\n- \"Create a summary?\" -> POST /api/v2/code-coverage/branch/summary\n- \"Search rule_based_view?\" -> GET /api/v2/compliance_findings/rule_based_view\n- \"List all container_images?\" -> GET /api/v2/container_images\n- \"List all containers?\" -> GET /api/v2/containers\n- \"Get account_filter details?\" -> GET /api/v2/cost/account_filters/{cloud_account_id}\n- \"Partially update a account_filter?\" -> PATCH /api/v2/cost/account_filters/{cloud_account_id}\n- \"List all anomalies?\" -> GET /api/v2/cost/anomalies\n- \"Get anomaly details?\" -> GET /api/v2/cost/anomalies/{anomaly_id}\n- \"List all arbitrary_rule?\" -> GET /api/v2/cost/arbitrary_rule\n- \"Create a arbitrary_rule?\" -> POST /api/v2/cost/arbitrary_rule\n- \"Create a reorder?\" -> POST /api/v2/cost/arbitrary_rule/reorder\n- \"List all status?\" -> GET /api/v2/cost/arbitrary_rule/status\n- \"Delete a arbitrary_rule?\" -> DELETE /api/v2/cost/arbitrary_rule/{rule_id}\n- \"Get arbitrary_rule details?\" -> GET /api/v2/cost/arbitrary_rule/{rule_id}\n- \"Partially update a arbitrary_rule?\" -> PATCH /api/v2/cost/arbitrary_rule/{rule_id}\n- \"List all aws_cur_config?\" -> GET /api/v2/cost/aws_cur_config\n- \"Create a aws_cur_config?\" -> POST /api/v2/cost/aws_cur_config\n- \"Delete a aws_cur_config?\" -> DELETE /api/v2/cost/aws_cur_config/{cloud_account_id}\n- \"Get aws_cur_config details?\" -> GET /api/v2/cost/aws_cur_config/{cloud_account_id}\n- \"Partially update a aws_cur_config?\" -> PATCH /api/v2/cost/aws_cur_config/{cloud_account_id}\n- \"List all azure_uc_config?\" -> GET /api/v2/cost/azure_uc_config\n- \"Create a azure_uc_config?\" -> POST /api/v2/cost/azure_uc_config\n- \"Delete a azure_uc_config?\" -> DELETE /api/v2/cost/azure_uc_config/{cloud_account_id}\n- \"Get azure_uc_config details?\" -> GET /api/v2/cost/azure_uc_config/{cloud_account_id}\n- \"Partially update a azure_uc_config?\" -> PATCH /api/v2/cost/azure_uc_config/{cloud_account_id}\n- \"Create a validate?\" -> POST /api/v2/cost/budget/csv/validate\n- \"Delete a budget?\" -> DELETE /api/v2/cost/budget/{budget_id}\n- \"Get budget details?\" -> GET /api/v2/cost/budget/{budget_id}\n- \"List all custom-forecast?\" -> GET /api/v2/cost/budget/{budget_id}/custom-forecast\n- \"List all budgets?\" -> GET /api/v2/cost/budgets\n- \"List all commitment-list?\" -> GET /api/v2/cost/commitments/commitment-list\n- \"List all scalar?\" -> GET /api/v2/cost/commitments/coverage/scalar\n- \"List all timeseries?\" -> GET /api/v2/cost/commitments/coverage/timeseries\n- \"List all custom_costs?\" -> GET /api/v2/cost/custom_costs\n- \"Delete a custom_cost?\" -> DELETE /api/v2/cost/custom_costs/{file_id}\n- \"Get custom_cost details?\" -> GET /api/v2/cost/custom_costs/{file_id}\n- \"List all gcp_uc_config?\" -> GET /api/v2/cost/gcp_uc_config\n- \"Create a gcp_uc_config?\" -> POST /api/v2/cost/gcp_uc_config\n- \"Delete a gcp_uc_config?\" -> DELETE /api/v2/cost/gcp_uc_config/{cloud_account_id}\n- \"Get gcp_uc_config details?\" -> GET /api/v2/cost/gcp_uc_config/{cloud_account_id}\n- \"Partially update a gcp_uc_config?\" -> PATCH /api/v2/cost/gcp_uc_config/{cloud_account_id}\n- \"List all oci_config?\" -> GET /api/v2/cost/oci_config\n- \"Create a recommendation?\" -> POST /api/v2/cost/recommendations\n- \"List all tag_descriptions?\" -> GET /api/v2/cost/tag_descriptions\n- \"Delete a tag_description?\" -> DELETE /api/v2/cost/tag_descriptions/{tag_key}\n- \"Get tag_description details?\" -> GET /api/v2/cost/tag_descriptions/{tag_key}\n- \"Update a tag_description?\" -> PUT /api/v2/cost/tag_descriptions/{tag_key}\n- \"List all generate?\" -> GET /api/v2/cost/tag_descriptions/{tag_key}/generate\n- \"List all tag_keys?\" -> GET /api/v2/cost/tag_keys\n- \"Get tag_key details?\" -> GET /api/v2/cost/tag_keys/{tag_key}\n- \"List all tag_metadata?\" -> GET /api/v2/cost/tag_metadata\n- \"List all currency?\" -> GET /api/v2/cost/tag_metadata/currency\n- \"List all months?\" -> GET /api/v2/cost/tag_metadata/months\n- \"List all orchestrators?\" -> GET /api/v2/cost/tag_metadata/orchestrators\n- \"List all tag_sources?\" -> GET /api/v2/cost/tag_metadata/tag_sources\n- \"List all active_billing_dimensions?\" -> GET /api/v2/cost_by_tag/active_billing_dimensions\n- \"List all monthly_cost_attribution?\" -> GET /api/v2/cost_by_tag/monthly_cost_attribution\n- \"Search agents?\" -> GET /api/v2/csm/onboarding/agents\n- \"List all cloud_accounts?\" -> GET /api/v2/csm/onboarding/coverage_analysis/cloud_accounts\n- \"List all hosts_and_containers?\" -> GET /api/v2/csm/onboarding/coverage_analysis/hosts_and_containers\n- \"List all serverless?\" -> GET /api/v2/csm/onboarding/coverage_analysis/serverless\n- \"List all settings?\" -> GET /api/v2/csm/ownership/settings\n- \"Create a setting?\" -> POST /api/v2/csm/ownership/settings\n- \"List all untagged?\" -> GET /api/v2/csm/ownership/settings/untagged\n- \"Get ownership details?\" -> GET /api/v2/csm/ownership/{resource_id}\n- \"List all history?\" -> GET /api/v2/csm/ownership/{resource_id}/history\n- \"List all evidence?\" -> GET /api/v2/csm/ownership/{resource_id}/{owner_type}/evidence\n- \"Create a feedback?\" -> POST /api/v2/csm/ownership/{resource_id}/{owner_type}/feedback\n- \"Search agentless_hosts?\" -> GET /api/v2/csm/settings/agentless_hosts\n- \"Search facet_info?\" -> GET /api/v2/csm/settings/agentless_hosts/facet_info\n- \"List all facets?\" -> GET /api/v2/csm/settings/agentless_hosts/facets\n- \"Search hosts?\" -> GET /api/v2/csm/settings/hosts\n- \"List all current_user?\" -> GET /api/v2/current_user\n- \"Create a application_key?\" -> POST /api/v2/current_user/application_keys\n- \"List all dashboards?\" -> GET /api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards\n- \"Create a dashboard?\" -> POST /api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards\n- \"List all shared?\" -> GET /api/v2/dashboard/{dashboard_id}/shared\n- \"Create a secure-embed?\" -> POST /api/v2/dashboard/{dashboard_id}/shared/secure-embed\n- \"Delete a secure-embed?\" -> DELETE /api/v2/dashboard/{dashboard_id}/shared/secure-embed/{token}\n- \"Get secure-embed details?\" -> GET /api/v2/dashboard/{dashboard_id}/shared/secure-embed/{token}\n- \"Partially update a secure-embed?\" -> PATCH /api/v2/dashboard/{dashboard_id}/shared/secure-embed/{token}\n- \"List all usage?\" -> GET /api/v2/dashboards/usage\n- \"Create a run?\" -> POST /api/v2/data-observability/monitors/{monitor_id}/run\n- \"List all datasets?\" -> GET /api/v2/datasets\n- \"Create a dataset?\" -> POST /api/v2/datasets\n- \"Delete a dataset?\" -> DELETE /api/v2/datasets/{dataset_id}\n- \"Get dataset details?\" -> GET /api/v2/datasets/{dataset_id}\n- \"Update a dataset?\" -> PUT /api/v2/datasets/{dataset_id}\n- \"Create a tabular?\" -> POST /api/v2/ddsql/query/tabular\n- \"Create a fetch?\" -> POST /api/v2/ddsql/query/tabular/fetch\n- \"Search requests?\" -> GET /api/v2/deletion/requests\n- \"List all deployment_gates?\" -> GET /api/v2/deployment_gates\n- \"Create a deployment_gate?\" -> POST /api/v2/deployment_gates\n- \"Delete a deployment_gate?\" -> DELETE /api/v2/deployment_gates/{id}\n- \"Get deployment_gate details?\" -> GET /api/v2/deployment_gates/{id}\n- \"Update a deployment_gate?\" -> PUT /api/v2/deployment_gates/{id}\n- \"Create a evaluation?\" -> POST /api/v2/deployments/gates/evaluation\n- \"Get evaluation details?\" -> GET /api/v2/deployments/gates/evaluation/{id}\n- \"List all domain_allowlist?\" -> GET /api/v2/domain_allowlist\n- \"Delete a deployment?\" -> DELETE /api/v2/dora/deployment/{deployment_id}\n- \"Get deployment details?\" -> GET /api/v2/dora/deployments/{deployment_id}\n- \"Partially update a deployment?\" -> PATCH /api/v2/dora/deployments/{deployment_id}\n- \"Create a failure?\" -> POST /api/v2/dora/failure\n- \"Delete a failure?\" -> DELETE /api/v2/dora/failure/{failure_id}\n- \"Get failure details?\" -> GET /api/v2/dora/failures/{failure_id}\n- \"List all downtime?\" -> GET /api/v2/downtime\n- \"Create a downtime?\" -> POST /api/v2/downtime\n- \"Delete a downtime?\" -> DELETE /api/v2/downtime/{downtime_id}\n- \"Get downtime details?\" -> GET /api/v2/downtime/{downtime_id}\n- \"Partially update a downtime?\" -> PATCH /api/v2/downtime/{downtime_id}\n- \"Get issue details?\" -> GET /api/v2/error-tracking/issues/{issue_id}\n- \"Create a event?\" -> POST /api/v2/events\n- \"Get event details?\" -> GET /api/v2/events/{event_id}\n- \"List all feature-flags?\" -> GET /api/v2/feature-flags\n- \"Create a feature-flag?\" -> POST /api/v2/feature-flags\n- \"List all environments?\" -> GET /api/v2/feature-flags/environments\n- \"Create a environment?\" -> POST /api/v2/feature-flags/environments\n- \"Delete a environment?\" -> DELETE /api/v2/feature-flags/environments/{environment_id}\n- \"Get environment details?\" -> GET /api/v2/feature-flags/environments/{environment_id}\n- \"Update a environment?\" -> PUT /api/v2/feature-flags/environments/{environment_id}\n- \"Create a pause?\" -> POST /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/pause\n- \"Create a resume?\" -> POST /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/resume\n- \"Create a start?\" -> POST /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/start\n- \"Create a stop?\" -> POST /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/stop\n- \"Get feature-flag details?\" -> GET /api/v2/feature-flags/{feature_flag_id}\n- \"Update a feature-flag?\" -> PUT /api/v2/feature-flags/{feature_flag_id}\n- \"Create a allocation?\" -> POST /api/v2/feature-flags/{feature_flag_id}/environments/{environment_id}/allocations\n- \"Create a variant?\" -> POST /api/v2/feature-flags/{feature_flag_id}/variants\n- \"Delete a variant?\" -> DELETE /api/v2/feature-flags/{feature_flag_id}/variants/{variant_id}\n- \"Update a variant?\" -> PUT /api/v2/feature-flags/{feature_flag_id}/variants/{variant_id}\n- \"List all agent_versions?\" -> GET /api/v2/fleet/agent_versions\n- \"List all agents?\" -> GET /api/v2/fleet/agents\n- \"Get agent details?\" -> GET /api/v2/fleet/agents/{agent_key}\n- \"List all deployments?\" -> GET /api/v2/fleet/deployments\n- \"Create a configure?\" -> POST /api/v2/fleet/deployments/configure\n- \"Create a upgrade?\" -> POST /api/v2/fleet/deployments/upgrade\n- \"Create a cancel?\" -> POST /api/v2/fleet/deployments/{deployment_id}/cancel\n- \"List all schedules?\" -> GET /api/v2/fleet/schedules\n- \"Get schedule details?\" -> GET /api/v2/fleet/schedules/{id}\n- \"List all forms?\" -> GET /api/v2/forms\n- \"Create a form?\" -> POST /api/v2/forms\n- \"Create a create_and_publish?\" -> POST /api/v2/forms/create_and_publish\n- \"Delete a form?\" -> DELETE /api/v2/forms/{form_id}\n- \"Get form details?\" -> GET /api/v2/forms/{form_id}\n- \"Partially update a form?\" -> PATCH /api/v2/forms/{form_id}\n- \"Create a clone?\" -> POST /api/v2/forms/{form_id}/clone\n- \"Create a publish?\" -> POST /api/v2/forms/{form_id}/publish\n- \"Create a version?\" -> POST /api/v2/forms/{form_id}/versions\n- \"Create a upsert_and_publish?\" -> POST /api/v2/forms/{form_id}/versions/upsert_and_publish\n- \"List all global_orgs?\" -> GET /api/v2/global_orgs\n- \"List all config?\" -> GET /api/v2/governance/config\n- \"List all control?\" -> GET /api/v2/governance/control\n- \"Get control details?\" -> GET /api/v2/governance/control/{detection_type}\n- \"Partially update a control?\" -> PATCH /api/v2/governance/control/{detection_type}\n- \"List all detections?\" -> GET /api/v2/governance/control/{detection_type}/detections\n- \"List all notification_settings?\" -> GET /api/v2/governance/control/{detection_type}/notification_settings\n- \"Create a mitigate?\" -> POST /api/v2/governance/detections/mitigate\n- \"Get detection details?\" -> GET /api/v2/governance/detections/{detection_id}\n- \"Partially update a detection?\" -> PATCH /api/v2/governance/detections/{detection_id}\n- \"List all insights?\" -> GET /api/v2/governance/insights\n- \"List all hamr?\" -> GET /api/v2/hamr\n- \"Create a hamr?\" -> POST /api/v2/hamr\n- \"List all identity_providers?\" -> GET /api/v2/identity_providers\n- \"Partially update a identity_provider?\" -> PATCH /api/v2/identity_providers/{idp_id}\n- \"List all users?\" -> GET /api/v2/identity_providers/{idp_id}/users\n- \"Delete a entity_integration?\" -> DELETE /api/v2/idp/entity_integrations/{integration_id}\n- \"Get entity_integration details?\" -> GET /api/v2/idp/entity_integrations/{integration_id}\n- \"Update a entity_integration?\" -> PUT /api/v2/idp/entity_integrations/{integration_id}\n- \"List all incidents?\" -> GET /api/v2/incidents\n- \"List all incident-handles?\" -> GET /api/v2/incidents/config/global/incident-handles\n- \"Create a incident-handle?\" -> POST /api/v2/incidents/config/global/incident-handles\n- \"Create a google-chat-configuration?\" -> POST /api/v2/incidents/config/google-chat-configurations\n- \"Partially update a google-chat-configuration?\" -> PATCH /api/v2/incidents/config/google-chat-configurations/{id}\n- \"Create a google-meet-configuration?\" -> POST /api/v2/incidents/config/google-meet-configurations\n- \"Partially update a google-meet-configuration?\" -> PATCH /api/v2/incidents/config/google-meet-configurations/{id}\n- \"List all impact-fields?\" -> GET /api/v2/incidents/config/impact-fields\n- \"Create a impact-field?\" -> POST /api/v2/incidents/config/impact-fields\n- \"Delete a impact-field?\" -> DELETE /api/v2/incidents/config/impact-fields/{field_id}\n- \"Update a impact-field?\" -> PUT /api/v2/incidents/config/impact-fields/{field_id}\n- \"List all notification-rules?\" -> GET /api/v2/incidents/config/notification-rules\n- \"Create a notification-rule?\" -> POST /api/v2/incidents/config/notification-rules\n- \"Delete a notification-rule?\" -> DELETE /api/v2/incidents/config/notification-rules/{id}\n- \"Get notification-rule details?\" -> GET /api/v2/incidents/config/notification-rules/{id}\n- \"Update a notification-rule?\" -> PUT /api/v2/incidents/config/notification-rules/{id}\n- \"List all notification-templates?\" -> GET /api/v2/incidents/config/notification-templates\n- \"Create a notification-template?\" -> POST /api/v2/incidents/config/notification-templates\n- \"Delete a notification-template?\" -> DELETE /api/v2/incidents/config/notification-templates/{id}\n- \"Get notification-template details?\" -> GET /api/v2/incidents/config/notification-templates/{id}\n- \"Partially update a notification-template?\" -> PATCH /api/v2/incidents/config/notification-templates/{id}\n- \"List all postmortem-templates?\" -> GET /api/v2/incidents/config/postmortem-templates\n- \"Create a postmortem-template?\" -> POST /api/v2/incidents/config/postmortem-templates\n- \"Delete a postmortem-template?\" -> DELETE /api/v2/incidents/config/postmortem-templates/{template_id}\n- \"Get postmortem-template details?\" -> GET /api/v2/incidents/config/postmortem-templates/{template_id}\n- \"Partially update a postmortem-template?\" -> PATCH /api/v2/incidents/config/postmortem-templates/{template_id}\n- \"Partially update a rule?\" -> PATCH /api/v2/incidents/config/rules/{rule_id}\n- \"List all org-settings?\" -> GET /api/v2/incidents/config/types/org-settings\n- \"Get type details?\" -> GET /api/v2/incidents/config/types/{incident_type_id}\n- \"Partially update a type?\" -> PATCH /api/v2/incidents/config/types/{incident_type_id}\n- \"List all user-defined-fields?\" -> GET /api/v2/incidents/config/user-defined-fields\n- \"Create a user-defined-field?\" -> POST /api/v2/incidents/config/user-defined-fields\n- \"Delete a user-defined-field?\" -> DELETE /api/v2/incidents/config/user-defined-fields/{field_id}\n- \"Get user-defined-field details?\" -> GET /api/v2/incidents/config/user-defined-fields/{field_id}\n- \"Partially update a user-defined-field?\" -> PATCH /api/v2/incidents/config/user-defined-fields/{field_id}\n- \"List all user-defined-roles?\" -> GET /api/v2/incidents/config/user-defined-roles\n- \"Create a user-defined-role?\" -> POST /api/v2/incidents/config/user-defined-roles\n- \"Delete a user-defined-role?\" -> DELETE /api/v2/incidents/config/user-defined-roles/{role_id}\n- \"Get user-defined-role details?\" -> GET /api/v2/incidents/config/user-defined-roles/{role_id}\n- \"Partially update a user-defined-role?\" -> PATCH /api/v2/incidents/config/user-defined-roles/{role_id}\n- \"Create a import?\" -> POST /api/v2/incidents/import\n- \"Search search?\" -> GET /api/v2/incidents/search\n- \"Delete a incident?\" -> DELETE /api/v2/incidents/{incident_id}\n- \"Get incident details?\" -> GET /api/v2/incidents/{incident_id}\n- \"Partially update a incident?\" -> PATCH /api/v2/incidents/{incident_id}\n- \"Create a postmortem?\" -> POST /api/v2/incidents/{incident_id}/ai/postmortem\n- \"List all attachments?\" -> GET /api/v2/incidents/{incident_id}/attachments\n- \"Create a attachment?\" -> POST /api/v2/incidents/{incident_id}/attachments\n- \"Delete a attachment?\" -> DELETE /api/v2/incidents/{incident_id}/attachments/{attachment_id}\n- \"Partially update a attachment?\" -> PATCH /api/v2/incidents/{incident_id}/attachments/{attachment_id}\n- \"Create a page?\" -> POST /api/v2/incidents/{incident_id}/cases/page\n- \"Create a configuration?\" -> POST /api/v2/incidents/{incident_id}/configurations\n- \"List all impacts?\" -> GET /api/v2/incidents/{incident_id}/impacts\n- \"Create a impact?\" -> POST /api/v2/incidents/{incident_id}/impacts\n- \"Delete a impact?\" -> DELETE /api/v2/incidents/{incident_id}/impacts/{impact_id}\n- \"Partially update a impact?\" -> PATCH /api/v2/incidents/{incident_id}/impacts/{impact_id}\n- \"List all integrations?\" -> GET /api/v2/incidents/{incident_id}/relationships/integrations\n- \"Create a integration?\" -> POST /api/v2/incidents/{incident_id}/relationships/integrations\n- \"Delete a integration?\" -> DELETE /api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id}\n- \"Get integration details?\" -> GET /api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id}\n- \"Partially update a integration?\" -> PATCH /api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id}\n- \"List all todos?\" -> GET /api/v2/incidents/{incident_id}/relationships/todos\n- \"Create a todo?\" -> POST /api/v2/incidents/{incident_id}/relationships/todos\n- \"Delete a todo?\" -> DELETE /api/v2/incidents/{incident_id}/relationships/todos/{todo_id}\n- \"Get todo details?\" -> GET /api/v2/incidents/{incident_id}/relationships/todos/{todo_id}\n- \"Partially update a todo?\" -> PATCH /api/v2/incidents/{incident_id}/relationships/todos/{todo_id}\n- \"List all responders?\" -> GET /api/v2/incidents/{incident_id}/responders\n- \"Create a responder?\" -> POST /api/v2/incidents/{incident_id}/responders\n- \"Delete a responder?\" -> DELETE /api/v2/incidents/{incident_id}/responders/{responder_id}\n- \"Get responder details?\" -> GET /api/v2/incidents/{incident_id}/responders/{responder_id}\n- \"Create a servicenow-record?\" -> POST /api/v2/incidents/{incident_id}/servicenow-records\n- \"List all timestamp-overrides?\" -> GET /api/v2/incidents/{incident_id}/timestamp-overrides\n- \"Create a timestamp-override?\" -> POST /api/v2/incidents/{incident_id}/timestamp-overrides\n- \"Delete a timestamp-override?\" -> DELETE /api/v2/incidents/{incident_id}/timestamp-overrides/{id}\n- \"Partially update a timestamp-override?\" -> PATCH /api/v2/incidents/{incident_id}/timestamp-overrides/{id}\n- \"Create a account?\" -> POST /api/v2/integration/aws/accounts\n- \"Delete a account?\" -> DELETE /api/v2/integration/aws/accounts/{aws_account_config_id}\n- \"Get account details?\" -> GET /api/v2/integration/aws/accounts/{aws_account_config_id}\n- \"Partially update a account?\" -> PATCH /api/v2/integration/aws/accounts/{aws_account_config_id}\n- \"List all ccm_config?\" -> GET /api/v2/integration/aws/accounts/{aws_account_config_id}/ccm_config\n- \"Create a ccm_config?\" -> POST /api/v2/integration/aws/accounts/{aws_account_config_id}/ccm_config\n- \"List all metric_name_filter_preview?\" -> GET /api/v2/integration/aws/accounts/{aws_account_config_id}/metric_name_filter_preview\n- \"Create a metric_name_filter_preview?\" -> POST /api/v2/integration/aws/accounts/{aws_account_config_id}/metric_name_filter_preview\n- \"List all available_namespaces?\" -> GET /api/v2/integration/aws/available_namespaces\n- \"List all event_bridge?\" -> GET /api/v2/integration/aws/event_bridge\n- \"Create a event_bridge?\" -> POST /api/v2/integration/aws/event_bridge\n- \"Create a generate_new_external_id?\" -> POST /api/v2/integration/aws/generate_new_external_id\n- \"List all iam_permissions?\" -> GET /api/v2/integration/aws/iam_permissions\n- \"List all resource_collection?\" -> GET /api/v2/integration/aws/iam_permissions/resource_collection\n- \"List all standard?\" -> GET /api/v2/integration/aws/iam_permissions/standard\n- \"Create a validate_ccm_config?\" -> POST /api/v2/integration/aws/validate_ccm_config\n- \"List all sts_delegate?\" -> GET /api/v2/integration/gcp/sts_delegate\n- \"Create a sts_delegate?\" -> POST /api/v2/integration/gcp/sts_delegate\n- \"List all organizations?\" -> GET /api/v2/integration/google-chat/organizations\n- \"Get named-space details?\" -> GET /api/v2/integration/google-chat/organizations/app/named-spaces/{domain_name}/{space_display_name}\n- \"Delete a organization?\" -> DELETE /api/v2/integration/google-chat/organizations/{organization_binding_id}\n- \"Get organization details?\" -> GET /api/v2/integration/google-chat/organizations/{organization_binding_id}\n- \"List all delegated-user?\" -> GET /api/v2/integration/google-chat/organizations/{organization_binding_id}/delegated-user\n- \"List all organization-handles?\" -> GET /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles\n- \"Create a organization-handle?\" -> POST /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles\n- \"Delete a organization-handle?\" -> DELETE /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles/{handle_id}\n- \"Get organization-handle details?\" -> GET /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles/{handle_id}\n- \"Partially update a organization-handle?\" -> PATCH /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles/{handle_id}\n- \"List all target-audiences?\" -> GET /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences\n- \"Create a target-audience?\" -> POST /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences\n- \"Delete a target-audience?\" -> DELETE /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences/{target_audience_id}\n- \"Get target-audience details?\" -> GET /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences/{target_audience_id}\n- \"Partially update a target-audience?\" -> PATCH /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences/{target_audience_id}\n- \"List all issue-templates?\" -> GET /api/v2/integration/jira/issue-templates\n- \"Create a issue-template?\" -> POST /api/v2/integration/jira/issue-templates\n- \"Delete a issue-template?\" -> DELETE /api/v2/integration/jira/issue-templates/{issue_template_id}\n- \"Get issue-template details?\" -> GET /api/v2/integration/jira/issue-templates/{issue_template_id}\n- \"Partially update a issue-template?\" -> PATCH /api/v2/integration/jira/issue-templates/{issue_template_id}\n- \"Get channel details?\" -> GET /api/v2/integration/ms-teams/configuration/channel/{tenant_name}/{team_name}/{channel_name}\n- \"List all tenant-based-handles?\" -> GET /api/v2/integration/ms-teams/configuration/tenant-based-handles\n- \"Create a tenant-based-handle?\" -> POST /api/v2/integration/ms-teams/configuration/tenant-based-handles\n- \"Delete a tenant-based-handle?\" -> DELETE /api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id}\n- \"Get tenant-based-handle details?\" -> GET /api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id}\n- \"Partially update a tenant-based-handle?\" -> PATCH /api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id}\n- \"Delete a user-binding?\" -> DELETE /api/v2/integration/ms-teams/configuration/user-binding/{tenant_id}\n- \"List all workflows-webhook-handles?\" -> GET /api/v2/integration/ms-teams/configuration/workflows-webhook-handles\n- \"Create a workflows-webhook-handle?\" -> POST /api/v2/integration/ms-teams/configuration/workflows-webhook-handles\n- \"Delete a workflows-webhook-handle?\" -> DELETE /api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id}\n- \"Get workflows-webhook-handle details?\" -> GET /api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id}\n- \"Partially update a workflows-webhook-handle?\" -> PATCH /api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id}\n- \"List all products?\" -> GET /api/v2/integration/oci/products\n- \"List all tenancies?\" -> GET /api/v2/integration/oci/tenancies\n- \"Create a tenancy?\" -> POST /api/v2/integration/oci/tenancies\n- \"Delete a tenancy?\" -> DELETE /api/v2/integration/oci/tenancies/{tenancy_ocid}\n- \"Get tenancy details?\" -> GET /api/v2/integration/oci/tenancies/{tenancy_ocid}\n- \"Partially update a tenancy?\" -> PATCH /api/v2/integration/oci/tenancies/{tenancy_ocid}\n- \"Delete a service?\" -> DELETE /api/v2/integration/opsgenie/services/{integration_service_id}\n- \"Get service details?\" -> GET /api/v2/integration/opsgenie/services/{integration_service_id}\n- \"Partially update a service?\" -> PATCH /api/v2/integration/opsgenie/services/{integration_service_id}\n- \"List all incident-templates?\" -> GET /api/v2/integration/salesforce-incidents/incident-templates\n- \"Create a incident-template?\" -> POST /api/v2/integration/salesforce-incidents/incident-templates\n- \"Delete a incident-template?\" -> DELETE /api/v2/integration/salesforce-incidents/incident-templates/{incident_template_id}\n- \"Partially update a incident-template?\" -> PATCH /api/v2/integration/salesforce-incidents/incident-templates/{incident_template_id}\n- \"Get assignment_group details?\" -> GET /api/v2/integration/servicenow/assignment_groups/{instance_id}\n- \"Get business_service details?\" -> GET /api/v2/integration/servicenow/business_services/{instance_id}\n- \"List all handles?\" -> GET /api/v2/integration/servicenow/handles\n- \"Create a handle?\" -> POST /api/v2/integration/servicenow/handles\n- \"Delete a handle?\" -> DELETE /api/v2/integration/servicenow/handles/{template_id}\n- \"Get handle details?\" -> GET /api/v2/integration/servicenow/handles/{template_id}\n- \"Update a handle?\" -> PUT /api/v2/integration/servicenow/handles/{template_id}\n- \"List all instances?\" -> GET /api/v2/integration/servicenow/instances\n- \"Get user details?\" -> GET /api/v2/integration/servicenow/users/{instance_id}\n- \"List all user-bindings?\" -> GET /api/v2/integration/slack/user-bindings\n- \"List all account?\" -> GET /api/v2/integration/statuspage/account\n- \"List all url_settings?\" -> GET /api/v2/integration/statuspage/url_settings\n- \"Create a url_setting?\" -> POST /api/v2/integration/statuspage/url_settings\n- \"Delete a url_setting?\" -> DELETE /api/v2/integration/statuspage/url_settings/{statuspage_url_setting_id}\n- \"Partially update a url_setting?\" -> PATCH /api/v2/integration/statuspage/url_settings/{statuspage_url_setting_id}\n- \"List all auth-method?\" -> GET /api/v2/integration/webhooks/configuration/auth-method\n- \"Create a oauth2-client-credential?\" -> POST /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials\n- \"Delete a oauth2-client-credential?\" -> DELETE /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials/{auth_method_id}\n- \"Get oauth2-client-credential details?\" -> GET /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials/{auth_method_id}\n- \"Partially update a oauth2-client-credential?\" -> PATCH /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials/{auth_method_id}\n- \"List all resources?\" -> GET /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources\n- \"Create a resource?\" -> POST /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources\n- \"Delete a resource?\" -> DELETE /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources/{resource_id}\n- \"Get resource details?\" -> GET /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources/{resource_id}\n- \"Partially update a resource?\" -> PATCH /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources/{resource_id}\n- \"List all ip_allowlist?\" -> GET /api/v2/ip_allowlist\n- \"List all annotated-interactions?\" -> GET /api/v2/llm-obs/v1/annotated-interactions\n- \"List all annotation-queues?\" -> GET /api/v2/llm-obs/v1/annotation-queues\n- \"Create a annotation-queue?\" -> POST /api/v2/llm-obs/v1/annotation-queues\n- \"Delete a annotation-queue?\" -> DELETE /api/v2/llm-obs/v1/annotation-queues/{queue_id}\n- \"Partially update a annotation-queue?\" -> PATCH /api/v2/llm-obs/v1/annotation-queues/{queue_id}\n- \"Create a delete?\" -> POST /api/v2/llm-obs/v1/annotation-queues/{queue_id}/annotations/delete\n- \"Create a interaction?\" -> POST /api/v2/llm-obs/v1/annotation-queues/{queue_id}/interactions\n- \"List all label-schema?\" -> GET /api/v2/llm-obs/v1/annotation-queues/{queue_id}/label-schema\n- \"Create a analytic?\" -> POST /api/v2/llm-obs/v1/experimentation/analytics\n- \"Create a simple-search?\" -> POST /api/v2/llm-obs/v1/experimentation/simple-search\n- \"List all experiments?\" -> GET /api/v2/llm-obs/v1/experiments\n- \"Create a experiment?\" -> POST /api/v2/llm-obs/v1/experiments\n- \"Partially update a experiment?\" -> PATCH /api/v2/llm-obs/v1/experiments/{experiment_id}\n- \"Create a inference?\" -> POST /api/v2/llm-obs/v1/integrations/{integration}/{account_id}/inference\n- \"List all models?\" -> GET /api/v2/llm-obs/v1/integrations/{integration}/{account_id}/models\n- \"List all prompts?\" -> GET /api/v2/llm-obs/v1/prompts\n- \"Create a prompt?\" -> POST /api/v2/llm-obs/v1/prompts\n- \"Delete a prompt?\" -> DELETE /api/v2/llm-obs/v1/prompts/{prompt_id}\n- \"Get prompt details?\" -> GET /api/v2/llm-obs/v1/prompts/{prompt_id}\n- \"Partially update a prompt?\" -> PATCH /api/v2/llm-obs/v1/prompts/{prompt_id}\n- \"Get version details?\" -> GET /api/v2/llm-obs/v1/prompts/{prompt_id}/versions/{version}\n- \"Partially update a version?\" -> PATCH /api/v2/llm-obs/v1/prompts/{prompt_id}/versions/{version}\n- \"List all topic-discovery-clustered-points?\" -> GET /api/v2/llm-obs/v1/topic-discovery-clustered-points\n- \"List all topic-discovery-configs?\" -> GET /api/v2/llm-obs/v1/topic-discovery-configs\n- \"List all latest?\" -> GET /api/v2/llm-obs/v1/topic-discovery-configs/latest\n- \"Delete a topic-discovery-config?\" -> DELETE /api/v2/llm-obs/v1/topic-discovery-configs/{config_id}\n- \"List all topic-discovery-runs?\" -> GET /api/v2/llm-obs/v1/topic-discovery-runs\n- \"Create a topic-discovery-run?\" -> POST /api/v2/llm-obs/v1/topic-discovery-runs\n- \"List all topic-discovery-topics?\" -> GET /api/v2/llm-obs/v1/topic-discovery-topics\n- \"List all with-cluster-points?\" -> GET /api/v2/llm-obs/v1/topic-discovery-topics/with-cluster-points\n- \"Partially update a dataset?\" -> PATCH /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}\n- \"Create a batch_update?\" -> POST /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/batch_update\n- \"List all draft_state?\" -> GET /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/draft_state\n- \"List all export?\" -> GET /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/export\n- \"List all records?\" -> GET /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/records\n- \"Create a record?\" -> POST /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/records\n- \"Create a restore?\" -> POST /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/restore\n- \"Create a upload?\" -> POST /api/v2/llm-obs/v2/{project_id}/datasets/{dataset_id}/records/upload\n- \"Create a log?\" -> POST /api/v2/logs\n- \"List all archive-order?\" -> GET /api/v2/logs/config/archive-order\n- \"List all archives?\" -> GET /api/v2/logs/config/archives\n- \"Delete a archive?\" -> DELETE /api/v2/logs/config/archives/{archive_id}\n- \"Get archive details?\" -> GET /api/v2/logs/config/archives/{archive_id}\n- \"Update a archive?\" -> PUT /api/v2/logs/config/archives/{archive_id}\n- \"List all readers?\" -> GET /api/v2/logs/config/archives/{archive_id}/readers\n- \"Create a reader?\" -> POST /api/v2/logs/config/archives/{archive_id}/readers\n- \"List all custom-destinations?\" -> GET /api/v2/logs/config/custom-destinations\n- \"Create a custom-destination?\" -> POST /api/v2/logs/config/custom-destinations\n- \"Delete a custom-destination?\" -> DELETE /api/v2/logs/config/custom-destinations/{custom_destination_id}\n- \"Get custom-destination details?\" -> GET /api/v2/logs/config/custom-destinations/{custom_destination_id}\n- \"Partially update a custom-destination?\" -> PATCH /api/v2/logs/config/custom-destinations/{custom_destination_id}\n- \"List all restriction_queries?\" -> GET /api/v2/logs/config/restriction_queries\n- \"Create a restriction_query?\" -> POST /api/v2/logs/config/restriction_queries\n- \"Get role details?\" -> GET /api/v2/logs/config/restriction_queries/role/{role_id}\n- \"Delete a restriction_query?\" -> DELETE /api/v2/logs/config/restriction_queries/{restriction_query_id}\n- \"Get restriction_query details?\" -> GET /api/v2/logs/config/restriction_queries/{restriction_query_id}\n- \"Partially update a restriction_query?\" -> PATCH /api/v2/logs/config/restriction_queries/{restriction_query_id}\n- \"Update a restriction_query?\" -> PUT /api/v2/logs/config/restriction_queries/{restriction_query_id}\n- \"List all roles?\" -> GET /api/v2/logs/config/restriction_queries/{restriction_query_id}/roles\n- \"Create a role?\" -> POST /api/v2/logs/config/restriction_queries/{restriction_query_id}/roles\n- \"List all maintenance_windows?\" -> GET /api/v2/maintenance_windows\n- \"Create a maintenance_window?\" -> POST /api/v2/maintenance_windows\n- \"Delete a maintenance_window?\" -> DELETE /api/v2/maintenance_windows/{maintenance_window_id}\n- \"Update a maintenance_window?\" -> PUT /api/v2/maintenance_windows/{maintenance_window_id}\n- \"Create a bulk-tag?\" -> POST /api/v2/metrics/config/bulk-tags\n- \"Create a historical-metrics-configuration?\" -> POST /api/v2/metrics/historical-metrics-configurations\n- \"Delete a historical-metrics-configuration?\" -> DELETE /api/v2/metrics/historical-metrics-configurations/{metric_name}\n- \"Get historical-metrics-configuration details?\" -> GET /api/v2/metrics/historical-metrics-configurations/{metric_name}\n- \"Search tag-indexing-rules?\" -> GET /api/v2/metrics/tag-indexing-rules\n- \"Create a tag-indexing-rule?\" -> POST /api/v2/metrics/tag-indexing-rules\n- \"Create a order?\" -> POST /api/v2/metrics/tag-indexing-rules/order\n- \"Delete a tag-indexing-rule?\" -> DELETE /api/v2/metrics/tag-indexing-rules/{id}\n- \"Get tag-indexing-rule details?\" -> GET /api/v2/metrics/tag-indexing-rules/{id}\n- \"Update a tag-indexing-rule?\" -> PUT /api/v2/metrics/tag-indexing-rules/{id}\n- \"List all active-configurations?\" -> GET /api/v2/metrics/{metric_name}/active-configurations\n- \"List all all-tags?\" -> GET /api/v2/metrics/{metric_name}/all-tags\n- \"List all assets?\" -> GET /api/v2/metrics/{metric_name}/assets\n- \"List all estimate?\" -> GET /api/v2/metrics/{metric_name}/estimate\n- \"List all tag-cardinalities?\" -> GET /api/v2/metrics/{metric_name}/tag-cardinalities\n- \"List all tag-indexing-rule-exemptions?\" -> GET /api/v2/metrics/{metric_name}/tag-indexing-rule-exemptions\n- \"Create a tag-indexing-rule-exemption?\" -> POST /api/v2/metrics/{metric_name}/tag-indexing-rule-exemptions\n- \"List all tag-indexing-rules?\" -> GET /api/v2/metrics/{metric_name}/tag-indexing-rules\n- \"Create a tag?\" -> POST /api/v2/metrics/{metric_name}/tags\n- \"List all volumes?\" -> GET /api/v2/metrics/{metric_name}/volumes\n- \"List all content?\" -> GET /api/v2/model-lab-api/artifacts/content\n- \"List all facet-keys?\" -> GET /api/v2/model-lab-api/facet-keys\n- \"List all facet-values?\" -> GET /api/v2/model-lab-api/facet-values\n- \"List all project-facet-keys?\" -> GET /api/v2/model-lab-api/project-facet-keys\n- \"List all project-facet-values?\" -> GET /api/v2/model-lab-api/project-facet-values\n- \"List all artifacts?\" -> GET /api/v2/model-lab-api/projects/{project_id}/artifacts\n- \"Create a star?\" -> POST /api/v2/model-lab-api/projects/{project_id}/star\n- \"List all runs?\" -> GET /api/v2/model-lab-api/runs\n- \"Delete a run?\" -> DELETE /api/v2/model-lab-api/runs/{run_id}\n- \"Get run details?\" -> GET /api/v2/model-lab-api/runs/{run_id}\n- \"Create a pin?\" -> POST /api/v2/model-lab-api/runs/{run_id}/pin\n- \"List all notification_rule?\" -> GET /api/v2/monitor/notification_rule\n- \"Get notification_rule details?\" -> GET /api/v2/monitor/notification_rule/{rule_id}\n- \"Partially update a notification_rule?\" -> PATCH /api/v2/monitor/notification_rule/{rule_id}\n- \"List all policy?\" -> GET /api/v2/monitor/policy\n- \"Delete a policy?\" -> DELETE /api/v2/monitor/policy/{policy_id}\n- \"Get policy details?\" -> GET /api/v2/monitor/policy/{policy_id}\n- \"Partially update a policy?\" -> PATCH /api/v2/monitor/policy/{policy_id}\n- \"List all template?\" -> GET /api/v2/monitor/template\n- \"Create a template?\" -> POST /api/v2/monitor/template\n- \"Delete a template?\" -> DELETE /api/v2/monitor/template/{template_id}\n- \"Get template details?\" -> GET /api/v2/monitor/template/{template_id}\n- \"Update a template?\" -> PUT /api/v2/monitor/template/{template_id}\n- \"List all downtime_matches?\" -> GET /api/v2/monitor/{monitor_id}/downtime_matches\n- \"List all devices?\" -> GET /api/v2/ndm/devices\n- \"Get device details?\" -> GET /api/v2/ndm/devices/{device_id}\n- \"List all interfaces?\" -> GET /api/v2/ndm/interfaces\n- \"Partially update a device?\" -> PATCH /api/v2/ndm/tags/devices/{device_id}\n- \"Get interface details?\" -> GET /api/v2/ndm/tags/interfaces/{interface_id}\n- \"Partially update a interface?\" -> PATCH /api/v2/ndm/tags/interfaces/{interface_id}\n- \"List all network-health-insights?\" -> GET /api/v2/network-health-insights\n- \"Search aggregate?\" -> GET /api/v2/network/connections/aggregate\n- \"List all sites?\" -> GET /api/v2/oauth2/.well-known/sites\n- \"List all scopes_restriction?\" -> GET /api/v2/oauth2/clients/{client_uuid}/scopes_restriction\n- \"Create a scopes_restriction?\" -> POST /api/v2/oauth2/clients/{client_uuid}/scopes_restriction\n- \"Create a register?\" -> POST /api/v2/oauth2/register\n- \"List all pipelines?\" -> GET /api/v2/obs-pipelines/pipelines\n- \"Delete a pipeline?\" -> DELETE /api/v2/obs-pipelines/pipelines/{pipeline_id}\n- \"Get pipeline details?\" -> GET /api/v2/obs-pipelines/pipelines/{pipeline_id}\n- \"Update a pipeline?\" -> PUT /api/v2/obs-pipelines/pipelines/{pipeline_id}\n- \"Create a escalation-policy?\" -> POST /api/v2/on-call/escalation-policies\n- \"Delete a escalation-policy?\" -> DELETE /api/v2/on-call/escalation-policies/{policy_id}\n- \"Get escalation-policy details?\" -> GET /api/v2/on-call/escalation-policies/{policy_id}\n- \"Update a escalation-policy?\" -> PUT /api/v2/on-call/escalation-policies/{policy_id}\n- \"Create a acknowledge?\" -> POST /api/v2/on-call/pages/{page_id}/acknowledge\n- \"Create a escalate?\" -> POST /api/v2/on-call/pages/{page_id}/escalate\n- \"Create a resolve?\" -> POST /api/v2/on-call/pages/{page_id}/resolve\n- \"Update a schedule?\" -> PUT /api/v2/on-call/schedules/{schedule_id}\n- \"List all on-call?\" -> GET /api/v2/on-call/schedules/{schedule_id}/on-call\n- \"List all routing-rules?\" -> GET /api/v2/on-call/teams/{team_id}/routing-rules\n- \"List all notification-channels?\" -> GET /api/v2/on-call/users/{user_id}/notification-channels\n- \"Create a notification-channel?\" -> POST /api/v2/on-call/users/{user_id}/notification-channels\n- \"Delete a notification-channel?\" -> DELETE /api/v2/on-call/users/{user_id}/notification-channels/{channel_id}\n- \"Get notification-channel details?\" -> GET /api/v2/on-call/users/{user_id}/notification-channels/{channel_id}\n- \"List all org?\" -> GET /api/v2/org\n- \"List all org_authorized_clients?\" -> GET /api/v2/org_authorized_clients\n- \"Delete a org_authorized_client?\" -> DELETE /api/v2/org_authorized_clients/{org_authorized_client_id}\n- \"Get org_authorized_client details?\" -> GET /api/v2/org_authorized_clients/{org_authorized_client_id}\n- \"Partially update a org_authorized_client?\" -> PATCH /api/v2/org_authorized_clients/{org_authorized_client_id}\n- \"Delete a user?\" -> DELETE /api/v2/org_authorized_clients/{org_authorized_client_id}/user/{user_id}\n- \"List all user_authorized_clients?\" -> GET /api/v2/org_authorized_clients/{org_authorized_client_id}/user_authorized_clients\n- \"Delete a user_authorized_client?\" -> DELETE /api/v2/org_authorized_clients/{org_authorized_client_id}/user_authorized_clients/{user_authorized_client_id}\n- \"List all org_configs?\" -> GET /api/v2/org_configs\n- \"Get org_config details?\" -> GET /api/v2/org_configs/{org_config_name}\n- \"Partially update a org_config?\" -> PATCH /api/v2/org_configs/{org_config_name}\n- \"List all org_connections?\" -> GET /api/v2/org_connections\n- \"Create a org_connection?\" -> POST /api/v2/org_connections\n- \"Delete a org_connection?\" -> DELETE /api/v2/org_connections/{connection_id}\n- \"Partially update a org_connection?\" -> PATCH /api/v2/org_connections/{connection_id}\n- \"List all org_group_memberships?\" -> GET /api/v2/org_group_memberships\n- \"Get org_group_membership details?\" -> GET /api/v2/org_group_memberships/{org_group_membership_id}\n- \"Partially update a org_group_membership?\" -> PATCH /api/v2/org_group_memberships/{org_group_membership_id}\n- \"List all org_group_policies?\" -> GET /api/v2/org_group_policies\n- \"Create a org_group_policy?\" -> POST /api/v2/org_group_policies\n- \"Delete a org_group_policy?\" -> DELETE /api/v2/org_group_policies/{org_group_policy_id}\n- \"Get org_group_policy details?\" -> GET /api/v2/org_group_policies/{org_group_policy_id}\n- \"Partially update a org_group_policy?\" -> PATCH /api/v2/org_group_policies/{org_group_policy_id}\n- \"List all org_group_policy_configs?\" -> GET /api/v2/org_group_policy_configs\n- \"List all org_group_policy_overrides?\" -> GET /api/v2/org_group_policy_overrides\n- \"Create a org_group_policy_override?\" -> POST /api/v2/org_group_policy_overrides\n- \"Delete a org_group_policy_override?\" -> DELETE /api/v2/org_group_policy_overrides/{org_group_policy_override_id}\n- \"Get org_group_policy_override details?\" -> GET /api/v2/org_group_policy_overrides/{org_group_policy_override_id}\n- \"Partially update a org_group_policy_override?\" -> PATCH /api/v2/org_group_policy_overrides/{org_group_policy_override_id}\n- \"List all org_group_policy_suggestions?\" -> GET /api/v2/org_group_policy_suggestions\n- \"List all org_groups?\" -> GET /api/v2/org_groups\n- \"Create a org_group?\" -> POST /api/v2/org_groups\n- \"Delete a org_group?\" -> DELETE /api/v2/org_groups/{org_group_id}\n- \"Get org_group details?\" -> GET /api/v2/org_groups/{org_group_id}\n- \"Partially update a org_group?\" -> PATCH /api/v2/org_groups/{org_group_id}\n- \"List all permissions?\" -> GET /api/v2/permissions\n- \"List all personal_access_tokens?\" -> GET /api/v2/personal_access_tokens\n- \"Create a personal_access_token?\" -> POST /api/v2/personal_access_tokens\n- \"Delete a personal_access_token?\" -> DELETE /api/v2/personal_access_tokens/{token_id}\n- \"Get personal_access_token details?\" -> GET /api/v2/personal_access_tokens/{token_id}\n- \"Partially update a personal_access_token?\" -> PATCH /api/v2/personal_access_tokens/{token_id}\n- \"List all findings?\" -> GET /api/v2/posture_management/findings\n- \"Get finding details?\" -> GET /api/v2/posture_management/findings/{finding_id}\n- \"List all powerpacks?\" -> GET /api/v2/powerpacks\n- \"Create a powerpack?\" -> POST /api/v2/powerpacks\n- \"Delete a powerpack?\" -> DELETE /api/v2/powerpacks/{powerpack_id}\n- \"Get powerpack details?\" -> GET /api/v2/powerpacks/{powerpack_id}\n- \"Partially update a powerpack?\" -> PATCH /api/v2/powerpacks/{powerpack_id}\n- \"Search processes?\" -> GET /api/v2/processes\n- \"Create a prodlytic?\" -> POST /api/v2/prodlytics\n- \"Create a facet_info?\" -> POST /api/v2/product-analytics/accounts/facet_info\n- \"Create a query?\" -> POST /api/v2/product-analytics/accounts/query\n- \"Create a scalar?\" -> POST /api/v2/product-analytics/analytics/scalar\n- \"Create a timesery?\" -> POST /api/v2/product-analytics/analytics/timeseries\n- \"Create a event_filtered_query?\" -> POST /api/v2/product-analytics/users/event_filtered_query\n- \"List all mapping?\" -> GET /api/v2/product-analytics/{entity}/mapping\n- \"List all connections?\" -> GET /api/v2/product-analytics/{entity}/mapping/connections\n- \"Get pruned_trace details?\" -> GET /api/v2/pruned_trace/{trace_id}\n- \"Create a batch-row?\" -> POST /api/v2/reference-tables/queries/batch-rows\n- \"List all tables?\" -> GET /api/v2/reference-tables/tables\n- \"Create a table?\" -> POST /api/v2/reference-tables/tables\n- \"Delete a table?\" -> DELETE /api/v2/reference-tables/tables/{id}\n- \"Get table details?\" -> GET /api/v2/reference-tables/tables/{id}\n- \"Partially update a table?\" -> PATCH /api/v2/reference-tables/tables/{id}\n- \"List all rows?\" -> GET /api/v2/reference-tables/tables/{id}/rows\n- \"Create a row?\" -> POST /api/v2/reference-tables/tables/{id}/rows\n- \"List all list?\" -> GET /api/v2/reference-tables/tables/{id}/rows/list\n- \"List all custom_rules?\" -> GET /api/v2/remote_config/products/asm/waf/custom_rules\n- \"Create a custom_rule?\" -> POST /api/v2/remote_config/products/asm/waf/custom_rules\n- \"Delete a custom_rule?\" -> DELETE /api/v2/remote_config/products/asm/waf/custom_rules/{custom_rule_id}\n- \"Get custom_rule details?\" -> GET /api/v2/remote_config/products/asm/waf/custom_rules/{custom_rule_id}\n- \"Update a custom_rule?\" -> PUT /api/v2/remote_config/products/asm/waf/custom_rules/{custom_rule_id}\n- \"List all exclusion_filters?\" -> GET /api/v2/remote_config/products/asm/waf/exclusion_filters\n- \"Create a exclusion_filter?\" -> POST /api/v2/remote_config/products/asm/waf/exclusion_filters\n- \"Delete a exclusion_filter?\" -> DELETE /api/v2/remote_config/products/asm/waf/exclusion_filters/{exclusion_filter_id}\n- \"Get exclusion_filter details?\" -> GET /api/v2/remote_config/products/asm/waf/exclusion_filters/{exclusion_filter_id}\n- \"Update a exclusion_filter?\" -> PUT /api/v2/remote_config/products/asm/waf/exclusion_filters/{exclusion_filter_id}\n- \"List all policies?\" -> GET /api/v2/remote_config/products/asm/waf/policies\n- \"Update a policy?\" -> PUT /api/v2/remote_config/products/asm/waf/policies/{policy_id}\n- \"List all agent_rules?\" -> GET /api/v2/remote_config/products/cws/agent_rules\n- \"Create a agent_rule?\" -> POST /api/v2/remote_config/products/cws/agent_rules\n- \"Delete a agent_rule?\" -> DELETE /api/v2/remote_config/products/cws/agent_rules/{agent_rule_id}\n- \"Get agent_rule details?\" -> GET /api/v2/remote_config/products/cws/agent_rules/{agent_rule_id}\n- \"Partially update a agent_rule?\" -> PATCH /api/v2/remote_config/products/cws/agent_rules/{agent_rule_id}\n- \"List all download?\" -> GET /api/v2/remote_config/products/cws/policy/download\n- \"Get config details?\" -> GET /api/v2/remote_config/products/rum/configs/{config_id}\n- \"Update a config?\" -> PUT /api/v2/remote_config/products/rum/configs/{config_id}\n- \"List all snapshots?\" -> GET /api/v2/replay/heatmap/snapshots\n- \"Create a snapshot?\" -> POST /api/v2/replay/heatmap/snapshots\n- \"Delete a snapshot?\" -> DELETE /api/v2/replay/heatmap/snapshots/{snapshot_id}\n- \"Partially update a snapshot?\" -> PATCH /api/v2/replay/heatmap/snapshots/{snapshot_id}\n- \"Create a print?\" -> POST /api/v2/reporting/print\n- \"Delete a restriction_policy?\" -> DELETE /api/v2/restriction_policy/{resource_id}\n- \"Get restriction_policy details?\" -> GET /api/v2/restriction_policy/{resource_id}\n- \"List all templates?\" -> GET /api/v2/roles/templates\n- \"Delete a role?\" -> DELETE /api/v2/roles/{role_id}\n- \"Partially update a role?\" -> PATCH /api/v2/roles/{role_id}\n- \"Create a permission?\" -> POST /api/v2/roles/{role_id}/permissions\n- \"Create a user?\" -> POST /api/v2/roles/{role_id}/users\n- \"List all applications?\" -> GET /api/v2/rum/applications\n- \"Create a application?\" -> POST /api/v2/rum/applications\n- \"List all retention_filters?\" -> GET /api/v2/rum/applications/{app_id}/retention_filters\n- \"Create a retention_filter?\" -> POST /api/v2/rum/applications/{app_id}/retention_filters\n- \"List all permanent?\" -> GET /api/v2/rum/applications/{app_id}/retention_filters/permanent\n- \"Get permanent details?\" -> GET /api/v2/rum/applications/{app_id}/retention_filters/permanent/{permanent_rf_id}\n- \"Partially update a permanent?\" -> PATCH /api/v2/rum/applications/{app_id}/retention_filters/permanent/{permanent_rf_id}\n- \"Delete a retention_filter?\" -> DELETE /api/v2/rum/applications/{app_id}/retention_filters/{rf_id}\n- \"Get retention_filter details?\" -> GET /api/v2/rum/applications/{app_id}/retention_filters/{rf_id}\n- \"Partially update a retention_filter?\" -> PATCH /api/v2/rum/applications/{app_id}/retention_filters/{rf_id}\n- \"Delete a application?\" -> DELETE /api/v2/rum/applications/{id}\n- \"Get application details?\" -> GET /api/v2/rum/applications/{id}\n- \"Partially update a application?\" -> PATCH /api/v2/rum/applications/{id}\n- \"Create a config?\" -> POST /api/v2/rum/config\n- \"Create a operation?\" -> POST /api/v2/rum/operations\n- \"Get by-name details?\" -> GET /api/v2/rum/operations/by-name/{name}\n- \"List all strong_links?\" -> GET /api/v2/rum/operations/strong_links\n- \"Create a strong_link?\" -> POST /api/v2/rum/operations/strong_links\n- \"Delete a strong_link?\" -> DELETE /api/v2/rum/operations/strong_links/{rum_operation_id}/{feature_id}\n- \"Update a strong_link?\" -> PUT /api/v2/rum/operations/strong_links/{rum_operation_id}/{feature_id}\n- \"Delete a operation?\" -> DELETE /api/v2/rum/operations/{rum_operation_id}\n- \"Get operation details?\" -> GET /api/v2/rum/operations/{rum_operation_id}\n- \"Update a operation?\" -> PUT /api/v2/rum/operations/{rum_operation_id}\n- \"Create a aggregated_long_task?\" -> POST /api/v2/rum/query/insight/aggregated_long_tasks\n- \"Create a aggregated_signals_problem?\" -> POST /api/v2/rum/query/insight/aggregated_signals_problems\n- \"Create a aggregated_waterfall?\" -> POST /api/v2/rum/query/insight/aggregated_waterfall\n- \"List all playlists?\" -> GET /api/v2/rum/replay/playlists\n- \"Create a playlist?\" -> POST /api/v2/rum/replay/playlists\n- \"Delete a playlist?\" -> DELETE /api/v2/rum/replay/playlists/{playlist_id}\n- \"Get playlist details?\" -> GET /api/v2/rum/replay/playlists/{playlist_id}\n- \"Update a playlist?\" -> PUT /api/v2/rum/replay/playlists/{playlist_id}\n- \"List all sessions?\" -> GET /api/v2/rum/replay/playlists/{playlist_id}/sessions\n- \"Delete a session?\" -> DELETE /api/v2/rum/replay/playlists/{playlist_id}/sessions/{session_id}\n- \"Update a session?\" -> PUT /api/v2/rum/replay/playlists/{playlist_id}/sessions/{session_id}\n- \"List all segments?\" -> GET /api/v2/rum/replay/sessions/{session_id}/views/{view_id}/segments\n- \"Create a watche?\" -> POST /api/v2/rum/replay/sessions/{session_id}/watches\n- \"List all saml_configurations?\" -> GET /api/v2/saml_configurations\n- \"Create a idp_metadata?\" -> POST /api/v2/saml_configurations/idp_metadata\n- \"Get saml_configuration details?\" -> GET /api/v2/saml_configurations/{saml_config_uuid}\n- \"Partially update a saml_configuration?\" -> PATCH /api/v2/saml_configurations/{saml_config_uuid}\n- \"List all campaigns?\" -> GET /api/v2/scorecard/campaigns\n- \"Create a campaign?\" -> POST /api/v2/scorecard/campaigns\n- \"Delete a campaign?\" -> DELETE /api/v2/scorecard/campaigns/{campaign_id}\n- \"Get campaign details?\" -> GET /api/v2/scorecard/campaigns/{campaign_id}\n- \"Update a campaign?\" -> PUT /api/v2/scorecard/campaigns/{campaign_id}\n- \"List all outcomes?\" -> GET /api/v2/scorecard/outcomes\n- \"Create a outcome?\" -> POST /api/v2/scorecard/outcomes\n- \"Create a batch?\" -> POST /api/v2/scorecard/outcomes/batch\n- \"List all scorecards?\" -> GET /api/v2/scorecard/scorecards\n- \"Get score details?\" -> GET /api/v2/scorecard/scores/{aggregation}\n- \"List all risk-scores?\" -> GET /api/v2/security-entities/risk-scores\n- \"Get risk-score details?\" -> GET /api/v2/security-entities/risk-scores/{entity_id}\n- \"List all due_date_rules?\" -> GET /api/v2/security/findings/automation/due_date_rules\n- \"Create a due_date_rule?\" -> POST /api/v2/security/findings/automation/due_date_rules\n- \"Delete a due_date_rule?\" -> DELETE /api/v2/security/findings/automation/due_date_rules/{rule_id}\n- \"Get due_date_rule details?\" -> GET /api/v2/security/findings/automation/due_date_rules/{rule_id}\n- \"Update a due_date_rule?\" -> PUT /api/v2/security/findings/automation/due_date_rules/{rule_id}\n- \"List all mute_rules?\" -> GET /api/v2/security/findings/automation/mute_rules\n- \"Create a mute_rule?\" -> POST /api/v2/security/findings/automation/mute_rules\n- \"Delete a mute_rule?\" -> DELETE /api/v2/security/findings/automation/mute_rules/{rule_id}\n- \"Get mute_rule details?\" -> GET /api/v2/security/findings/automation/mute_rules/{rule_id}\n- \"Update a mute_rule?\" -> PUT /api/v2/security/findings/automation/mute_rules/{rule_id}\n- \"List all ticket_creation_rules?\" -> GET /api/v2/security/findings/automation/ticket_creation_rules\n- \"Create a ticket_creation_rule?\" -> POST /api/v2/security/findings/automation/ticket_creation_rules\n- \"Delete a ticket_creation_rule?\" -> DELETE /api/v2/security/findings/automation/ticket_creation_rules/{rule_id}\n- \"Get ticket_creation_rule details?\" -> GET /api/v2/security/findings/automation/ticket_creation_rules/{rule_id}\n- \"Update a ticket_creation_rule?\" -> PUT /api/v2/security/findings/automation/ticket_creation_rules/{rule_id}\n- \"Partially update a case?\" -> PATCH /api/v2/security/findings/cases/{case_id}\n- \"Create a linear_issue?\" -> POST /api/v2/security/findings/linear_issues\n- \"List all sboms?\" -> GET /api/v2/security/sboms\n- \"Get sbom details?\" -> GET /api/v2/security/sboms/{asset_type}\n- \"List all scanned-assets-metadata?\" -> GET /api/v2/security/scanned-assets-metadata\n- \"Search ioc-explorer?\" -> GET /api/v2/security/siem/ioc-explorer\n- \"List all indicator?\" -> GET /api/v2/security/siem/ioc-explorer/indicator\n- \"Create a triage?\" -> POST /api/v2/security/siem/ioc-explorer/triage\n- \"List all vulnerabilities?\" -> GET /api/v2/security/vulnerabilities\n- \"Create a vulnerability?\" -> POST /api/v2/security/vulnerabilities\n- \"List all vulnerable-assets?\" -> GET /api/v2/security/vulnerable-assets\n- \"List all critical_assets?\" -> GET /api/v2/security_monitoring/configuration/critical_assets\n- \"Create a critical_asset?\" -> POST /api/v2/security_monitoring/configuration/critical_assets\n- \"Delete a critical_asset?\" -> DELETE /api/v2/security_monitoring/configuration/critical_assets/{critical_asset_id}\n- \"Get critical_asset details?\" -> GET /api/v2/security_monitoring/configuration/critical_assets/{critical_asset_id}\n- \"Partially update a critical_asset?\" -> PATCH /api/v2/security_monitoring/configuration/critical_assets/{critical_asset_id}\n- \"List all integration_config?\" -> GET /api/v2/security_monitoring/configuration/integration_config\n- \"Create a integration_config?\" -> POST /api/v2/security_monitoring/configuration/integration_config\n- \"List all azure_app_registrations?\" -> GET /api/v2/security_monitoring/configuration/integration_config/entra_id/azure_app_registrations\n- \"Delete a integration_config?\" -> DELETE /api/v2/security_monitoring/configuration/integration_config/{integration_config_id}\n- \"Get integration_config details?\" -> GET /api/v2/security_monitoring/configuration/integration_config/{integration_config_id}\n- \"Partially update a integration_config?\" -> PATCH /api/v2/security_monitoring/configuration/integration_config/{integration_config_id}\n- \"Create a activate?\" -> POST /api/v2/security_monitoring/configuration/integration_config/{integration_type}/activate\n- \"Create a deactivate?\" -> POST /api/v2/security_monitoring/configuration/integration_config/{integration_type}/deactivate\n- \"Create a send_notification_preview?\" -> POST /api/v2/security_monitoring/configuration/notification_rules/send_notification_preview\n- \"List all security_filters?\" -> GET /api/v2/security_monitoring/configuration/security_filters\n- \"Create a security_filter?\" -> POST /api/v2/security_monitoring/configuration/security_filters\n- \"Delete a security_filter?\" -> DELETE /api/v2/security_monitoring/configuration/security_filters/{security_filter_id}\n- \"Get security_filter details?\" -> GET /api/v2/security_monitoring/configuration/security_filters/{security_filter_id}\n- \"Partially update a security_filter?\" -> PATCH /api/v2/security_monitoring/configuration/security_filters/{security_filter_id}\n- \"Search suppressions?\" -> GET /api/v2/security_monitoring/configuration/suppressions\n- \"Create a suppression?\" -> POST /api/v2/security_monitoring/configuration/suppressions\n- \"Create a validation?\" -> POST /api/v2/security_monitoring/configuration/suppressions/validation\n- \"Delete a suppression?\" -> DELETE /api/v2/security_monitoring/configuration/suppressions/{suppression_id}\n- \"Get suppression details?\" -> GET /api/v2/security_monitoring/configuration/suppressions/{suppression_id}\n- \"Partially update a suppression?\" -> PATCH /api/v2/security_monitoring/configuration/suppressions/{suppression_id}\n- \"List all version_history?\" -> GET /api/v2/security_monitoring/configuration/suppressions/{suppression_id}/version_history\n- \"List all states?\" -> GET /api/v2/security_monitoring/content_packs/states\n- \"Create a dependency?\" -> POST /api/v2/security_monitoring/datasets/dependencies\n- \"Search entity_context?\" -> GET /api/v2/security_monitoring/entity_context\n- \"Get entity_context details?\" -> GET /api/v2/security_monitoring/entity_context/{id}\n- \"Search rules?\" -> GET /api/v2/security_monitoring/rules\n- \"Create a bulk_export?\" -> POST /api/v2/security_monitoring/rules/bulk_export\n- \"Create a convert?\" -> POST /api/v2/security_monitoring/rules/convert\n- \"Create a test?\" -> POST /api/v2/security_monitoring/rules/test\n- \"List all convert?\" -> GET /api/v2/security_monitoring/rules/{rule_id}/convert\n- \"List all subscriptions?\" -> GET /api/v2/security_monitoring/sample_log_generation/subscriptions\n- \"Create a subscription?\" -> POST /api/v2/security_monitoring/sample_log_generation/subscriptions\n- \"Delete a subscription?\" -> DELETE /api/v2/security_monitoring/sample_log_generation/subscriptions/{content_pack_id}\n- \"List all signals?\" -> GET /api/v2/security_monitoring/signals\n- \"Get signal details?\" -> GET /api/v2/security_monitoring/signals/{signal_id}\n- \"List all entities?\" -> GET /api/v2/security_monitoring/signals/{signal_id}/entities\n- \"List all investigation_queries?\" -> GET /api/v2/security_monitoring/signals/{signal_id}/investigation_queries\n- \"List all suggested_actions?\" -> GET /api/v2/security_monitoring/signals/{signal_id}/suggested_actions\n- \"Get terraform details?\" -> GET /api/v2/security_monitoring/terraform/{resource_type}/{resource_id}\n- \"Create a group?\" -> POST /api/v2/sensitive-data-scanner/config/groups\n- \"Delete a group?\" -> DELETE /api/v2/sensitive-data-scanner/config/groups/{group_id}\n- \"Partially update a group?\" -> PATCH /api/v2/sensitive-data-scanner/config/groups/{group_id}\n- \"List all standard-patterns?\" -> GET /api/v2/sensitive-data-scanner/config/standard-patterns\n- \"Create a sery?\" -> POST /api/v2/series\n- \"Create a service_account?\" -> POST /api/v2/service_accounts\n- \"List all access_tokens?\" -> GET /api/v2/service_accounts/{service_account_id}/access_tokens\n- \"Create a access_token?\" -> POST /api/v2/service_accounts/{service_account_id}/access_tokens\n- \"Delete a access_token?\" -> DELETE /api/v2/service_accounts/{service_account_id}/access_tokens/{token_id}\n- \"Get access_token details?\" -> GET /api/v2/service_accounts/{service_account_id}/access_tokens/{token_id}\n- \"Partially update a access_token?\" -> PATCH /api/v2/service_accounts/{service_account_id}/access_tokens/{token_id}\n- \"List all definitions?\" -> GET /api/v2/services/definitions\n- \"Create a definition?\" -> POST /api/v2/services/definitions\n- \"Delete a definition?\" -> DELETE /api/v2/services/definitions/{service_name}\n- \"Get definition details?\" -> GET /api/v2/services/definitions/{service_name}\n- \"List all histsignals?\" -> GET /api/v2/siem-historical-detections/histsignals\n- \"Get histsignal details?\" -> GET /api/v2/siem-historical-detections/histsignals/{histsignal_id}\n- \"List all jobs?\" -> GET /api/v2/siem-historical-detections/jobs\n- \"Create a job?\" -> POST /api/v2/siem-historical-detections/jobs\n- \"Create a signal_convert?\" -> POST /api/v2/siem-historical-detections/jobs/signal_convert\n- \"Delete a job?\" -> DELETE /api/v2/siem-historical-detections/jobs/{job_id}\n- \"Get job details?\" -> GET /api/v2/siem-historical-detections/jobs/{job_id}\n- \"Create a report?\" -> POST /api/v2/slo/report\n- \"List all sourcemaps?\" -> GET /api/v2/sourcemaps\n- \"Create a service_repository_info?\" -> POST /api/v2/sourcemaps/service_repository_info\n- \"Get recommendation details?\" -> GET /api/v2/spa/recommendations/{service}\n- \"Create a scan?\" -> POST /api/v2/static-analysis-sca/dependencies/scan\n- \"Get scan details?\" -> GET /api/v2/static-analysis-sca/dependencies/scan/{job_id}\n- \"Create a resolve-vulnerable-symbol?\" -> POST /api/v2/static-analysis-sca/vulnerabilities/resolve-vulnerable-symbols\n- \"List all memory?\" -> GET /api/v2/static-analysis/ai/memory\n- \"Create a memory?\" -> POST /api/v2/static-analysis/ai/memory\n- \"Delete a memory?\" -> DELETE /api/v2/static-analysis/ai/memory/{id}\n- \"List all rulesets?\" -> GET /api/v2/static-analysis/ai/rulesets\n- \"Create a ruleset?\" -> POST /api/v2/static-analysis/ai/rulesets\n- \"Delete a ruleset?\" -> DELETE /api/v2/static-analysis/ai/rulesets/{ruleset_name}\n- \"Get ruleset details?\" -> GET /api/v2/static-analysis/ai/rulesets/{ruleset_name}\n- \"Partially update a ruleset?\" -> PATCH /api/v2/static-analysis/ai/rulesets/{ruleset_name}\n- \"List all revisions?\" -> GET /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}/revisions\n- \"Create a revision?\" -> POST /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}/revisions\n- \"Get revision details?\" -> GET /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}/revisions/{id}\n- \"Get default-ruleset details?\" -> GET /api/v2/static-analysis/default-rulesets/{language}\n- \"Create a analyze?\" -> POST /api/v2/static-analysis/static-analysis-server/analyze\n- \"Create a get-ast?\" -> POST /api/v2/static-analysis/static-analysis-server/get-ast\n- \"Get node-type details?\" -> GET /api/v2/static-analysis/static-analysis-server/node-types/{language}\n- \"Get tree-sitter-wasm details?\" -> GET /api/v2/static-analysis/static-analysis-server/tree-sitter-wasm/{file}\n- \"List all statuspages?\" -> GET /api/v2/statuspages\n- \"Create a statuspage?\" -> POST /api/v2/statuspages\n- \"List all degradations?\" -> GET /api/v2/statuspages/degradations\n- \"List all maintenances?\" -> GET /api/v2/statuspages/maintenances\n- \"Delete a statuspage?\" -> DELETE /api/v2/statuspages/{page_id}\n- \"Get statuspage details?\" -> GET /api/v2/statuspages/{page_id}\n- \"Partially update a statuspage?\" -> PATCH /api/v2/statuspages/{page_id}\n- \"List all components?\" -> GET /api/v2/statuspages/{page_id}/components\n- \"Create a component?\" -> POST /api/v2/statuspages/{page_id}/components\n- \"Delete a component?\" -> DELETE /api/v2/statuspages/{page_id}/components/{component_id}\n- \"Get component details?\" -> GET /api/v2/statuspages/{page_id}/components/{component_id}\n- \"Partially update a component?\" -> PATCH /api/v2/statuspages/{page_id}/components/{component_id}\n- \"List all degradation_templates?\" -> GET /api/v2/statuspages/{page_id}/degradation_templates\n- \"Create a degradation_template?\" -> POST /api/v2/statuspages/{page_id}/degradation_templates\n- \"Delete a degradation_template?\" -> DELETE /api/v2/statuspages/{page_id}/degradation_templates/{template_id}\n- \"Get degradation_template details?\" -> GET /api/v2/statuspages/{page_id}/degradation_templates/{template_id}\n- \"Partially update a degradation_template?\" -> PATCH /api/v2/statuspages/{page_id}/degradation_templates/{template_id}\n- \"Create a degradation?\" -> POST /api/v2/statuspages/{page_id}/degradations\n- \"Create a backfill?\" -> POST /api/v2/statuspages/{page_id}/degradations/backfill\n- \"Delete a degradation?\" -> DELETE /api/v2/statuspages/{page_id}/degradations/{degradation_id}\n- \"Get degradation details?\" -> GET /api/v2/statuspages/{page_id}/degradations/{degradation_id}\n- \"Partially update a degradation?\" -> PATCH /api/v2/statuspages/{page_id}/degradations/{degradation_id}\n- \"Delete a update?\" -> DELETE /api/v2/statuspages/{page_id}/degradations/{degradation_id}/updates/{update_id}\n- \"Partially update a update?\" -> PATCH /api/v2/statuspages/{page_id}/degradations/{degradation_id}/updates/{update_id}\n- \"List all maintenance_templates?\" -> GET /api/v2/statuspages/{page_id}/maintenance_templates\n- \"Create a maintenance_template?\" -> POST /api/v2/statuspages/{page_id}/maintenance_templates\n- \"Delete a maintenance_template?\" -> DELETE /api/v2/statuspages/{page_id}/maintenance_templates/{template_id}\n- \"Get maintenance_template details?\" -> GET /api/v2/statuspages/{page_id}/maintenance_templates/{template_id}\n- \"Partially update a maintenance_template?\" -> PATCH /api/v2/statuspages/{page_id}/maintenance_templates/{template_id}\n- \"Create a maintenance?\" -> POST /api/v2/statuspages/{page_id}/maintenances\n- \"Get maintenance details?\" -> GET /api/v2/statuspages/{page_id}/maintenances/{maintenance_id}\n- \"Partially update a maintenance?\" -> PATCH /api/v2/statuspages/{page_id}/maintenances/{maintenance_id}\n- \"Create a unpublish?\" -> POST /api/v2/statuspages/{page_id}/unpublish\n- \"Create a get-widget?\" -> POST /api/v2/stegadography/get-widgets\n- \"Get subtest details?\" -> GET /api/v2/synthetics/api-multistep/subtests/{public_id}\n- \"List all parents?\" -> GET /api/v2/synthetics/api-multistep/subtests/{public_id}/parents\n- \"List all downtimes?\" -> GET /api/v2/synthetics/downtimes\n- \"Update a downtime?\" -> PUT /api/v2/synthetics/downtimes/{downtime_id}\n- \"Delete a test?\" -> DELETE /api/v2/synthetics/downtimes/{downtime_id}/tests/{test_id}\n- \"Update a test?\" -> PUT /api/v2/synthetics/downtimes/{downtime_id}/tests/{test_id}\n- \"List all on_demand_concurrency_cap?\" -> GET /api/v2/synthetics/settings/on_demand_concurrency_cap\n- \"Create a on_demand_concurrency_cap?\" -> POST /api/v2/synthetics/settings/on_demand_concurrency_cap\n- \"Create a suite?\" -> POST /api/v2/synthetics/suites\n- \"Create a bulk-delete?\" -> POST /api/v2/synthetics/suites/bulk-delete\n- \"Get suite details?\" -> GET /api/v2/synthetics/suites/{public_id}\n- \"Update a suite?\" -> PUT /api/v2/synthetics/suites/{public_id}\n- \"List all results?\" -> GET /api/v2/synthetics/tests/browser/{public_id}/results\n- \"Get result details?\" -> GET /api/v2/synthetics/tests/browser/{public_id}/results/{result_id}\n- \"Get fast details?\" -> GET /api/v2/synthetics/tests/fast/{id}\n- \"Create a network?\" -> POST /api/v2/synthetics/tests/network\n- \"Get network details?\" -> GET /api/v2/synthetics/tests/network/{public_id}\n- \"Update a network?\" -> PUT /api/v2/synthetics/tests/network/{public_id}\n- \"List all poll_results?\" -> GET /api/v2/synthetics/tests/poll_results\n- \"Create a download?\" -> POST /api/v2/synthetics/tests/{public_id}/files/download\n- \"Create a multipart-presigned-url?\" -> POST /api/v2/synthetics/tests/{public_id}/files/multipart-presigned-urls\n- \"Create a multipart-upload-abort?\" -> POST /api/v2/synthetics/tests/{public_id}/files/multipart-upload-abort\n- \"Create a multipart-upload-complete?\" -> POST /api/v2/synthetics/tests/{public_id}/files/multipart-upload-complete\n- \"List all parent-suites?\" -> GET /api/v2/synthetics/tests/{public_id}/parent-suites\n- \"Get version_history details?\" -> GET /api/v2/synthetics/tests/{public_id}/version_history/{version_number}\n- \"List all tag_policies?\" -> GET /api/v2/tag_policies\n- \"Create a tag_policy?\" -> POST /api/v2/tag_policies\n- \"Delete a tag_policy?\" -> DELETE /api/v2/tag_policies/{policy_id}\n- \"Get tag_policy details?\" -> GET /api/v2/tag_policies/{policy_id}\n- \"Partially update a tag_policy?\" -> PATCH /api/v2/tag_policies/{policy_id}\n- \"List all score?\" -> GET /api/v2/tag_policies/{policy_id}/score\n- \"List all enrichment?\" -> GET /api/v2/tags/enrichment\n- \"Create a enrichment?\" -> POST /api/v2/tags/enrichment\n- \"Create a validate-query?\" -> POST /api/v2/tags/enrichment/validate-query\n- \"Delete a enrichment?\" -> DELETE /api/v2/tags/enrichment/{ruleset_id}\n- \"Get enrichment details?\" -> GET /api/v2/tags/enrichment/{ruleset_id}\n- \"Partially update a enrichment?\" -> PATCH /api/v2/tags/enrichment/{ruleset_id}\n- \"List all team?\" -> GET /api/v2/team\n- \"Create a team?\" -> POST /api/v2/team\n- \"List all team-hierarchy-links?\" -> GET /api/v2/team-hierarchy-links\n- \"Create a team-hierarchy-link?\" -> POST /api/v2/team-hierarchy-links\n- \"Delete a team-hierarchy-link?\" -> DELETE /api/v2/team-hierarchy-links/{link_id}\n- \"Get team-hierarchy-link details?\" -> GET /api/v2/team-hierarchy-links/{link_id}\n- \"List all sync?\" -> GET /api/v2/team/sync\n- \"Create a sync?\" -> POST /api/v2/team/sync\n- \"List all member_teams?\" -> GET /api/v2/team/{super_team_id}/member_teams\n- \"Create a member_team?\" -> POST /api/v2/team/{super_team_id}/member_teams\n- \"Delete a member_team?\" -> DELETE /api/v2/team/{super_team_id}/member_teams/{member_team_id}\n- \"Delete a team?\" -> DELETE /api/v2/team/{team_id}\n- \"Get team details?\" -> GET /api/v2/team/{team_id}\n- \"Partially update a team?\" -> PATCH /api/v2/team/{team_id}\n- \"List all links?\" -> GET /api/v2/team/{team_id}/links\n- \"Get link details?\" -> GET /api/v2/team/{team_id}/links/{link_id}\n- \"Partially update a link?\" -> PATCH /api/v2/team/{team_id}/links/{link_id}\n- \"List all memberships?\" -> GET /api/v2/team/{team_id}/memberships\n- \"Create a membership?\" -> POST /api/v2/team/{team_id}/memberships\n- \"Delete a membership?\" -> DELETE /api/v2/team/{team_id}/memberships/{user_id}\n- \"Partially update a membership?\" -> PATCH /api/v2/team/{team_id}/memberships/{user_id}\n- \"List all permission-settings?\" -> GET /api/v2/team/{team_id}/permission-settings\n- \"Update a permission-setting?\" -> PUT /api/v2/team/{team_id}/permission-settings/{action}\n- \"Get trace details?\" -> GET /api/v2/trace/{trace_id}\n- \"List all application_security?\" -> GET /api/v2/usage/application_security\n- \"List all billing_dimension_mapping?\" -> GET /api/v2/usage/billing_dimension_mapping\n- \"List all cost_by_org?\" -> GET /api/v2/usage/cost_by_org\n- \"List all estimated_cost?\" -> GET /api/v2/usage/estimated_cost\n- \"List all historical_cost?\" -> GET /api/v2/usage/historical_cost\n- \"List all hourly_usage?\" -> GET /api/v2/usage/hourly_usage\n- \"List all lambda_traced_invocations?\" -> GET /api/v2/usage/lambda_traced_invocations\n- \"List all observability_pipelines?\" -> GET /api/v2/usage/observability_pipelines\n- \"List all projected_cost?\" -> GET /api/v2/usage/projected_cost\n- \"List all available_fields?\" -> GET /api/v2/usage/summary/available_fields\n- \"List all usage-attribution-types?\" -> GET /api/v2/usage/usage-attribution-types\n- \"Delete a client?\" -> DELETE /api/v2/user_authorized_clients/client/{client_id}\n- \"Get user_authorized_client details?\" -> GET /api/v2/user_authorized_clients/{user_authorized_client_id}\n- \"Create a user_invitation?\" -> POST /api/v2/user_invitations\n- \"Get user_invitation details?\" -> GET /api/v2/user_invitations/{user_invitation_uuid}\n- \"Partially update a user?\" -> PATCH /api/v2/users/{user_id}\n- \"List all orgs?\" -> GET /api/v2/users/{user_id}/orgs\n- \"List all validate?\" -> GET /api/v2/validate\n- \"List all validate_keys?\" -> GET /api/v2/validate_keys\n- \"Get widget details?\" -> GET /api/v2/widgets/{experience_type}\n- \"Delete a widget?\" -> DELETE /api/v2/widgets/{experience_type}/{uuid}\n- \"Update a widget?\" -> PUT /api/v2/widgets/{experience_type}/{uuid}\n- \"List all workflows?\" -> GET /api/v2/workflows\n- \"Create a workflow?\" -> POST /api/v2/workflows\n- \"Delete a workflow?\" -> DELETE /api/v2/workflows/{workflow_id}\n- \"Get workflow details?\" -> GET /api/v2/workflows/{workflow_id}\n- \"Partially update a workflow?\" -> PATCH /api/v2/workflows/{workflow_id}\n- \"Create a instance?\" -> POST /api/v2/workflows/{workflow_id}/instances\n- \"Get instance details?\" -> GET /api/v2/workflows/{workflow_id}/instances/{instance_id}\n- \"How to authenticate?\" -> See Auth section above\n\n## Response Tips\n- Check response schemas in references/api-spec.lap for field details\n- Paginated endpoints accept limit/offset or cursor parameters\n- Create/update endpoints return the modified resource on success\n- Error responses include status codes and descriptions in the spec\n\n## References\n- Full spec: See references/api-spec.lap for complete endpoint details, parameter tables, and response schemas\n\n> Generated from the official API spec by [LAP](https://lap.sh)\n","references/api-spec.lap":"@lap v0.3\n# Machine-readable API spec. Each @endpoint block is one API call.\n@api Datadog API V2 Collection\n@base https://api.datadoghq.com\n@version 1.0\n@auth OAuth2 | ApiKey DD-API-KEY in header | ApiKey DD-APPLICATION-KEY in header | Bearer bearer\n@endpoints 1500\n@hint download_for_search\n@toc api(1500)\n\n@endpoint GET /api/unstable/fleet/agents/{agent_key}/tracers\n@desc List tracers for a specific agent\n@required {agent_key: str # The unique identifier (agent key) for the Datadog Agent.}\n@optional {page_number: int(int64)=0 # Page number for pagination (starts at 0)., page_size: int(int64)=10 # Number of results per page (must be greater than 0 and less than or equal to 100)., sort_attribute: str # Attribute to sort by., sort_descending: bool=true # Sort order (true for descending, false for ascending).}\n@returns(200) {data: map{attributes: map{tracers: [map]}, id: str, type: str}, meta: map{total_filtered_count: int(int64)}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/unstable/fleet/schedules\n@desc Create a schedule\n@required {data: map{attributes!: map, type!: str} # Data for creating a new schedule.}\n@returns(201) {data: map{attributes: map{created_at_unix: int(int64), created_by: str, name: str, query: str, rule: map{days_of_week: [str], maintenance_window_duration: int(int64), start_maintenance_window: str, timezone: str}, status: str, updated_at_unix: int(int64), updated_by: str, version_to_latest: int(int64)}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Staging Environment - Conservative Updates\",\"query\":\"env:staging\",\"rule\":{\"days_of_week\":[\"Fri\"],\"maintenance_window_duration\":240,\"start_maintenance_window\":\"22:00\",\"timezone\":\"UTC\"},\"status\":\"active\",\"version_to_latest\":1},\"type\":\"schedule\"}}\n\n@endpoint DELETE /api/unstable/fleet/schedules/{id}\n@desc Delete a schedule\n@required {id: str # The unique identifier of the schedule to delete.}\n@returns(204) Schedule successfully deleted.\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/unstable/fleet/schedules/{id}\n@desc Update a schedule\n@required {id: str # The unique identifier of the schedule to update., data: map{attributes: map, type!: str} # Data for partially updating a schedule.}\n@returns(200) {data: map{attributes: map{created_at_unix: int(int64), created_by: str, name: str, query: str, rule: map{days_of_week: [str], maintenance_window_duration: int(int64), start_maintenance_window: str, timezone: str}, status: str, updated_at_unix: int(int64), updated_by: str, version_to_latest: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"rule\":{\"days_of_week\":[\"Mon\",\"Wed\",\"Fri\"],\"maintenance_window_duration\":240,\"start_maintenance_window\":\"03:00\",\"timezone\":\"America/New_York\"}},\"type\":\"schedule\"}}\n\n@endpoint POST /api/unstable/fleet/schedules/{id}/trigger\n@desc Trigger a schedule deployment\n@required {id: str # The unique identifier of the schedule to trigger.}\n@returns(201) {data: map{attributes: map{config_operations: [map], estimated_end_time_unix: int(int64), filter_query: str, high_level_status: str, hosts: [map], packages: [map], total_hosts: int(int64)}, id: str, type: str}, meta: map{hosts: map{current_page: int(int64), page_size: int(int64), total_hosts: int(int64), total_pages: int(int64)}}} # CREATED - Deployment successfully created and started.\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/unstable/fleet/tracers\n@desc List all fleet tracers\n@optional {page_number: int(int64)=0 # Page number for pagination (starts at 0)., page_size: int(int64)=10 # Number of results per page (must be greater than 0 and less than or equal to 100)., sort_attribute: str # Attribute to sort by., sort_descending: bool=true # Sort order (true for descending, false for ascending)., filter: str # Filter string for narrowing down tracer results.}\n@returns(200) {data: map{attributes: map{tracers: [map]}, id: str, type: str}, meta: map{total_filtered_count: int(int64)}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/unstable/llm-obs/config/evaluators/custom\n@desc List custom evaluator configurations\n@returns(200) {data: [map]} # OK\n@errors {401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint DELETE /api/unstable/llm-obs/config/evaluators/custom/{eval_name}\n@desc Delete a custom evaluator configuration\n@required {eval_name: str # The name of the custom LLM Observability evaluator configuration.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/unstable/llm-obs/config/evaluators/custom/{eval_name}\n@desc Get a custom evaluator configuration\n@required {eval_name: str # The name of the custom LLM Observability evaluator configuration.}\n@returns(200) {data: map{attributes: map{category: str, created_at: str(date-time), created_by: map{email: str}, eval_name: str, last_updated_by: map{email: str}, llm_judge_config: map{assessment_criteria: map, context_query: str?, inference_params: map, last_used_library_prompt_template_name: str?, modified_library_prompt_template: bool?, output_schema: map?, parsing_type: str, prompt_template: [map], target_query: str?, user_specified_json_post_processing_function: str?}, llm_provider: map{bedrock: map, integration_account_id: str, integration_provider: str, model_name: str, vertex_ai: map}, target: map{application_name: str, enabled: bool, eval_scope: str, experiment_project_ids: [str(uuid)], filter: str?, root_spans_only: bool?, sampling_percentage: num(double)?}, updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/unstable/llm-obs/config/evaluators/custom/{eval_name}\n@desc Create or update a custom evaluator configuration\n@required {eval_name: str # The name of the custom LLM Observability evaluator configuration., data: map{attributes!: map, id: str, type!: str} # Data object for creating or updating a custom LLM Observability evaluator configuration.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"llm_judge_config\":{\"inference_params\":{\"max_tokens\":1024,\"temperature\":0.7},\"parsing_type\":\"structured_output\"},\"llm_provider\":{\"integration_provider\":\"openai\",\"model_name\":\"gpt-4o\"},\"target\":{\"application_name\":\"my-llm-app\",\"enabled\":true,\"sampling_percentage\":50}},\"id\":\"my-custom-evaluator\",\"type\":\"evaluator_config\"}}\n\n@endpoint GET /api/v2/actions-datastores\n@desc List datastores\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/actions-datastores\n@desc Create datastore\n@optional {data: map{attributes: map, id: str, type!: str} # Data wrapper containing the configuration needed to create a new datastore.}\n@returns(200) {data: map{id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"datastore-name\",\"org_access\":\"contributor\",\"primary_column_name\":\"primaryKey\",\"primary_key_generation_strategy\":\"none\"},\"type\":\"datastores\"}}\n\n@endpoint DELETE /api/v2/actions-datastores/{datastore_id}\n@desc Delete datastore\n@required {datastore_id: str # The unique identifier of the datastore to retrieve.}\n@returns(200) OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/actions-datastores/{datastore_id}\n@desc Get datastore\n@required {datastore_id: str # The unique identifier of the datastore to retrieve.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), creator_user_id: int(int64), creator_user_uuid: str, description: str, modified_at: str(date-time), name: str, org_id: int(int64), primary_column_name: str, primary_key_generation_strategy: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/actions-datastores/{datastore_id}\n@desc Update datastore\n@required {datastore_id: str # The unique identifier of the datastore to retrieve.}\n@optional {data: map{attributes: map, id: str, type!: str} # Data wrapper containing the datastore identifier and the attributes to update.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), creator_user_id: int(int64), creator_user_uuid: str, description: str, modified_at: str(date-time), name: str, org_id: int(int64), primary_column_name: str, primary_key_generation_strategy: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"datastores\"}}\n\n@endpoint DELETE /api/v2/actions-datastores/{datastore_id}/items\n@desc Delete datastore item\n@required {datastore_id: str # The unique identifier of the datastore to retrieve.}\n@optional {data: map{attributes: map, type!: str} # Data wrapper containing the information needed to identify and delete a specific datastore item.}\n@returns(200) {data: map{id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"id\":\"a7656bcc-51d4-4884-adf7-4d0d9a3e0633\",\"item_key\":\"primaryKey\"},\"type\":\"items\"}}\n\n@endpoint GET /api/v2/actions-datastores/{datastore_id}/items\n@desc List datastore items\n@required {datastore_id: str # The unique identifier of the datastore to retrieve.}\n@optional {filter: str # Optional query filter to search items using the [logs search syntax](https://docs.datadoghq.com/logs/explorer/search_syntax/)., item_key: str # Optional primary key value to retrieve a specific item. Cannot be used together with the filter parameter., page[limit]: int(int64) # Optional field to limit the number of items to return per page for pagination. Up to 100 items can be returned per page., page[offset]: int(int64) # Optional field to offset the number of items to skip from the beginning of the result set for pagination., sort: str # Optional field to sort results by. Prefix with '-' for descending order (e.g., '-created_at').}\n@returns(200) {data: [map], meta: map{page: map{hasMore: bool, totalCount: int(int64), totalFilteredCount: int(int64)}, schema: map{fields: [map], primary_key: str}}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/actions-datastores/{datastore_id}/items\n@desc Update datastore item\n@required {datastore_id: str # The unique identifier of the datastore to retrieve.}\n@optional {data: map{attributes: map, id: str, type!: str} # Data wrapper containing the item identifier and the changes to apply during the update operation.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), org_id: int(int64), primary_column_name: str, signature: str, store_id: str, value: map}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"item_changes\":{\"ops_set\":{\"count\":42,\"status\":\"active\"}},\"item_key\":\"my-item-key\"},\"type\":\"items\"}}\n\n@endpoint DELETE /api/v2/actions-datastores/{datastore_id}/items/bulk\n@desc Bulk delete datastore items\n@required {datastore_id: str # The ID of the datastore.}\n@optional {data: map{attributes: map, id: str, type!: str} # Data wrapper containing the data needed to delete items from a datastore.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"type\":\"items\"}}\n\n@endpoint POST /api/v2/actions-datastores/{datastore_id}/items/bulk\n@desc Bulk write datastore items\n@required {datastore_id: str # The unique identifier of the datastore to retrieve.}\n@optional {data: map{attributes: map, type!: str} # Data wrapper containing the items to insert and their configuration for the bulk insert operation.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"conflict_mode\":\"overwrite_on_conflict\",\"values\":[{\"data\":\"example data\",\"key\":\"value\"},{\"data\":\"example data2\",\"key\":\"value2\"}]},\"type\":\"items\"}}\n\n@endpoint GET /api/v2/actions/app_key_registrations\n@desc List App Key Registrations\n@optional {page[size]: int(int64): any # The number of App Key Registrations to return per page., page[number]: int(int64) # The page number to return.}\n@returns(200) {data: [map], meta: map{total: int(int64), total_filtered: int(int64)}} # OK\n@errors {400: Bad request, 403: Forbidden, 429: Too many requests}\n\n@endpoint DELETE /api/v2/actions/app_key_registrations/{app_key_id}\n@desc Unregister an App Key\n@required {app_key_id: str # The ID of the app key}\n@returns(204) No Content\n@errors {400: Bad request, 403: Forbidden, 404: Not found, 429: Too many requests}\n\n@endpoint GET /api/v2/actions/app_key_registrations/{app_key_id}\n@desc Get an existing App Key Registration\n@required {app_key_id: str # The ID of the app key}\n@returns(200) {data: map{id: str(uuid), type: str}} # OK\n@errors {400: Bad request, 403: Forbidden, 404: Not found, 429: Too many requests}\n\n@endpoint PUT /api/v2/actions/app_key_registrations/{app_key_id}\n@desc Register a new App Key\n@required {app_key_id: str # The ID of the app key}\n@returns(201) {data: map{id: str(uuid), type: str}} # Created\n@errors {400: Bad request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/actions/connections\n@desc Create a new Action Connection\n@required {data: map{attributes!: map, id: str, type!: str} # Data related to the connection.}\n@returns(201) {data: map{attributes: map{integration: any, name: str}, id: str, type: str}} # Successfully created Action Connection\n@errors {400: Bad Request, 403: Forbidden, 429: Too Many Request}\n@example_request {\"data\":{\"attributes\":{\"integration\":{\"credentials\":{\"account_id\":\"123456789123\",\"role\":\"MyRoleUpdated\",\"type\":\"AWSAssumeRole\"},\"type\":\"AWS\"},\"name\":\"My AWS Connection\"},\"type\":\"action_connection\"}}\n\n@endpoint DELETE /api/v2/actions/connections/{connection_id}\n@desc Delete an existing Action Connection\n@required {connection_id: str # The ID of the action connection}\n@returns(204) The resource was deleted successfully.\n@errors {403: Forbidden, 404: Not Found, 429: Too Many Request}\n\n@endpoint GET /api/v2/actions/connections/{connection_id}\n@desc Get an existing Action Connection\n@required {connection_id: str # The ID of the action connection}\n@returns(200) {data: map{attributes: map{integration: any, name: str}, id: str, type: str}} # Successfully get Action Connection\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Request}\n\n@endpoint PATCH /api/v2/actions/connections/{connection_id}\n@desc Update an existing Action Connection\n@required {connection_id: str # The ID of the action connection, data: map{attributes!: map, type!: str} # Data related to the connection update.}\n@returns(200) {data: map{attributes: map{integration: any, name: str}, id: str, type: str}} # Successfully updated Action Connection\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Request}\n@example_request {\"data\":{\"attributes\":{\"integration\":{\"type\":\"AWS\"},\"name\":\"My AWS Connection\"},\"type\":\"action_connection\"}}\n\n@endpoint GET /api/v2/agentless_scanning/accounts/aws\n@desc List AWS scan options\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/agentless_scanning/accounts/aws\n@desc Create AWS scan options\n@required {data: map{attributes!: map, id!: str, type!: str} # Object for the scan options of a single AWS account.}\n@returns(201) {data: map{attributes: map{compliance_host: bool, lambda: bool, sensitive_data: bool, vuln_containers_os: bool, vuln_host_os: bool}, id: str, type: str}} # Agentless scan options enabled successfully.\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compliance_host\":false,\"lambda\":true,\"sensitive_data\":false,\"vuln_containers_os\":true,\"vuln_host_os\":true},\"id\":\"123456789012\",\"type\":\"aws_scan_options\"}}\n\n@endpoint DELETE /api/v2/agentless_scanning/accounts/aws/{account_id}\n@desc Delete AWS scan options\n@required {account_id: str # The ID of an AWS account.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/agentless_scanning/accounts/aws/{account_id}\n@desc Get AWS scan options\n@required {account_id: str # The ID of an AWS account.}\n@returns(200) {data: map{attributes: map{compliance_host: bool, lambda: bool, sensitive_data: bool, vuln_containers_os: bool, vuln_host_os: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/agentless_scanning/accounts/aws/{account_id}\n@desc Update AWS scan options\n@required {account_id: str # The ID of an AWS account., data: map{attributes!: map, id!: str, type!: str} # Object for the scan options of a single AWS account.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compliance_host\":false,\"lambda\":true,\"sensitive_data\":false,\"vuln_containers_os\":true,\"vuln_host_os\":true},\"id\":\"123456789012\",\"type\":\"aws_scan_options\"}}\n\n@endpoint GET /api/v2/agentless_scanning/accounts/azure\n@desc List Azure scan options\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/agentless_scanning/accounts/azure\n@desc Create Azure scan options\n@optional {data: map{attributes: map, id!: str, type!: str} # Single Azure scan options entry.}\n@returns(201) {data: map{attributes: map{compliance_host: bool, function: bool, vuln_containers_os: bool, vuln_host_os: bool}, id: str, type: str}} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compliance_host\":false,\"vuln_containers_os\":true,\"vuln_host_os\":true},\"id\":\"12345678-90ab-cdef-1234-567890abcdef\",\"type\":\"azure_scan_options\"}}\n\n@endpoint DELETE /api/v2/agentless_scanning/accounts/azure/{subscription_id}\n@desc Delete Azure scan options\n@required {subscription_id: str # The Azure subscription ID.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/agentless_scanning/accounts/azure/{subscription_id}\n@desc Get Azure scan options\n@required {subscription_id: str # The Azure subscription ID.}\n@returns(200) {data: map{attributes: map{compliance_host: bool, function: bool, vuln_containers_os: bool, vuln_host_os: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/agentless_scanning/accounts/azure/{subscription_id}\n@desc Update Azure scan options\n@required {subscription_id: str # The Azure subscription ID.}\n@optional {data: map{attributes: map, id!: str, type!: str} # Data object for updating the scan options of a single Azure subscription.}\n@returns(200) {data: map{attributes: map{compliance_host: bool, function: bool, vuln_containers_os: bool, vuln_host_os: bool}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"vuln_containers_os\":false},\"id\":\"12345678-90ab-cdef-1234-567890abcdef\",\"type\":\"azure_scan_options\"}}\n\n@endpoint GET /api/v2/agentless_scanning/accounts/gcp\n@desc List GCP scan options\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/agentless_scanning/accounts/gcp\n@desc Create GCP scan options\n@optional {data: map{attributes: map, id!: str, type!: str} # Single GCP scan options entry.}\n@returns(201) {data: map{attributes: map{cloud_function: bool, compliance_host: bool, vuln_containers_os: bool, vuln_host_os: bool}, id: str, type: str}} # Agentless scan options enabled successfully.\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compliance_host\":false,\"vuln_containers_os\":true,\"vuln_host_os\":true},\"id\":\"company-project-id\",\"type\":\"gcp_scan_options\"}}\n\n@endpoint DELETE /api/v2/agentless_scanning/accounts/gcp/{project_id}\n@desc Delete GCP scan options\n@required {project_id: str # The GCP project ID.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/agentless_scanning/accounts/gcp/{project_id}\n@desc Get GCP scan options\n@required {project_id: str # The GCP project ID.}\n@returns(200) {data: map{attributes: map{cloud_function: bool, compliance_host: bool, vuln_containers_os: bool, vuln_host_os: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/agentless_scanning/accounts/gcp/{project_id}\n@desc Update GCP scan options\n@required {project_id: str # The GCP project ID.}\n@optional {data: map{attributes: map, id!: str, type!: str} # Data object for updating the scan options of a single GCP project.}\n@returns(200) {data: map{attributes: map{cloud_function: bool, compliance_host: bool, vuln_containers_os: bool, vuln_host_os: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"vuln_containers_os\":false},\"id\":\"company-project-id\",\"type\":\"gcp_scan_options\"}}\n\n@endpoint GET /api/v2/agentless_scanning/ondemand/aws\n@desc List AWS on demand tasks\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/agentless_scanning/ondemand/aws\n@desc Create AWS on demand task\n@required {data: map{attributes!: map, type!: str} # Object for a single AWS on demand task.}\n@returns(201) {data: map{attributes: map{arn: str, assigned_at: str, created_at: str, status: str}, id: str, type: str}} # AWS on demand task created successfully.\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"arn\":\"arn:aws:ec2:us-east-1:727000456123:instance/i-0eabb50529b67a1ba\"},\"type\":\"aws_resource\"}}\n\n@endpoint GET /api/v2/agentless_scanning/ondemand/aws/{task_id}\n@desc Get AWS on demand task\n@required {task_id: str # The UUID of the task.}\n@returns(200) {data: map{attributes: map{arn: str, assigned_at: str, created_at: str, status: str}, id: str, type: str}} # OK.\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/annotation\n@desc List annotations\n@required {page_id: str # ID of the page to list annotations for, prefixed with the page type and joined by a colon (for example, `dashboard:abc-def-xyz` or `notebook:1234567890`)., start_time: int(int64) # Start of the time window in milliseconds since the Unix epoch., end_time: int(int64) # End of the time window in milliseconds since the Unix epoch.}\n@optional {widget_id: str # Optional widget ID to restrict results to annotations on a specific widget.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/annotation\n@desc Create an annotation\n@required {data: map{attributes!: map, type!: str} # Data for creating an annotation.}\n@returns(200) {data: map{attributes: map{author_id: str, color: str, created_at: int(int64), description: str, end_time: int(int64)?, modified_at: int(int64), page_id: str, start_time: int(int64), type: str, widget_ids: [str]}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"color\":\"blue\",\"description\":\"Deployed v2.3.1 to production.\",\"page_id\":\"dashboard:abc-def-xyz\",\"start_time\":1704067200000,\"type\":\"pointInTime\",\"widget_ids\":[\"1234567890\"]},\"type\":\"annotation\"}}\n\n@endpoint GET /api/v2/annotation/page/{page_id}\n@desc Get annotations for a page\n@required {page_id: str # The ID of the page, prefixed with the page type and joined by a colon (for example, `dashboard:abc-def-xyz` or `notebook:1234567890`)., start_time: int(int64) # Start of the time window in milliseconds since the Unix epoch., end_time: int(int64) # End of the time window in milliseconds since the Unix epoch.}\n@returns(200) {data: map{attributes: map{annotations: map, global_annotations: [str(uuid)], widget_mapping: map}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint DELETE /api/v2/annotation/{annotation_id}\n@desc Delete an annotation\n@required {annotation_id: str(uuid) # The ID of the annotation.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint PUT /api/v2/annotation/{annotation_id}\n@desc Update an annotation\n@required {annotation_id: str(uuid) # The ID of the annotation., data: map{attributes!: map, type!: str} # Data for creating an annotation.}\n@returns(200) {data: map{attributes: map{author_id: str, color: str, created_at: int(int64), description: str, end_time: int(int64)?, modified_at: int(int64), page_id: str, start_time: int(int64), type: str, widget_ids: [str]}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"color\":\"green\",\"description\":\"Deployed v2.3.1 to production (updated).\",\"page_id\":\"dashboard:abc-def-xyz\",\"start_time\":1704067200000,\"type\":\"pointInTime\",\"widget_ids\":[\"1234567890\"]},\"type\":\"annotation\"}}\n\n@endpoint PUT /api/v2/anonymize_users\n@desc Anonymize users\n@required {data: map{attributes!: map, id: str, type!: str} # Object to anonymize a list of users.}\n@returns(200) {data: map{attributes: map{anonymize_errors: [map], anonymized_user_ids: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Authentication error, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"user_ids\":[\"00000000-0000-0000-0000-000000000000\"]},\"type\":\"anonymize_users_request\"}}\n\n@endpoint GET /api/v2/api_keys\n@desc Get all API keys\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # API key attribute used to sort results. Sort order is ascending by default. In order to specify a descending sort, prefix the attribute with a minus sign., filter: str # Filter API keys by the specified string., filter[created_at][start]: str # Only include API keys created on or after the specified date., filter[created_at][end]: str # Only include API keys created on or before the specified date., filter[modified_at][start]: str # Only include API keys modified on or after the specified date., filter[modified_at][end]: str # Only include API keys modified on or before the specified date., include: str # Comma separated list of resource paths for related resources to include in the response. Supported resource paths are `created_by` and `modified_by`., filter[remote_config_read_enabled]: bool # Filter API keys by remote config read enabled status., filter[category]: str # Filter API keys by category.}\n@returns(200) {data: [map], included: [any], meta: map{max_allowed: int(int64), page: map{total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/api_keys\n@desc Create an API key\n@required {data: map{attributes!: map, type!: str} # Object used to create an API key.}\n@returns(201) {data: map{attributes: map{category: str, created_at: str(date-time), date_last_used: str(date-time)?, key: str, last4: str, modified_at: str(date-time), name: str, remote_config_read_enabled: bool}, id: str, relationships: map{created_by: map{data: map}, modified_by: map?{data: map?}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"API Key for submitting metrics\"},\"type\":\"api_keys\"}}\n\n@endpoint DELETE /api/v2/api_keys/{api_key_id}\n@desc Delete an API key\n@required {api_key_id: str # The ID of the API key.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/api_keys/{api_key_id}\n@desc Get API key\n@required {api_key_id: str # The ID of the API key.}\n@optional {include: str # Comma separated list of resource paths for related resources to include in the response. Supported resource paths are `created_by` and `modified_by`.}\n@returns(200) {data: map{attributes: map{category: str, created_at: str(date-time), date_last_used: str(date-time)?, key: str, last4: str, modified_at: str(date-time), name: str, remote_config_read_enabled: bool}, id: str, relationships: map{created_by: map{data: map}, modified_by: map?{data: map?}}, type: str}, included: [any]} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/api_keys/{api_key_id}\n@desc Edit an API key\n@required {api_key_id: str # The ID of the API key., data: map{attributes!: map, id!: str, type!: str} # Object used to update an API key.}\n@returns(200) {data: map{attributes: map{category: str, created_at: str(date-time), date_last_used: str(date-time)?, key: str, last4: str, modified_at: str(date-time), name: str, remote_config_read_enabled: bool}, id: str, relationships: map{created_by: map{data: map}, modified_by: map?{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"API Key for submitting metrics\"},\"id\":\"00112233-4455-6677-8899-aabbccddeeff\",\"type\":\"api_keys\"}}\n\n@endpoint GET /api/v2/apicatalog/api\n@desc List APIs\n@optional {query: str # Filter APIs by name, page[limit]: int(int64)=20 # Number of items per page., page[offset]: int(int64)=0 # Offset for pagination.}\n@returns(200) {data: [map], meta: map{pagination: map{limit: int(int64), offset: int(int64), total_count: int(int64)}}} # OK\n@errors {400: Bad request, 403: Forbidden, 429: Too many requests}\n\n@endpoint DELETE /api/v2/apicatalog/api/{id}\n@desc Delete an API\n@required {id: str(uuid) # ID of the API to delete}\n@returns(204) API deleted successfully\n@errors {400: Bad request, 403: Forbidden, 404: API not found error, 429: Too many requests}\n\n@endpoint GET /api/v2/apicatalog/api/{id}/openapi\n@desc Get an API\n@required {id: str(uuid) # ID of the API to retrieve}\n@returns(200) OK\n@errors {400: Bad request, 403: Forbidden, 404: API not found error, 429: Too many requests}\n\n@endpoint PUT /api/v2/apicatalog/api/{id}/openapi\n@desc Update an API\n@required {id: str(uuid) # ID of the API to modify}\n@returns(200) {data: map{attributes: map{failed_endpoints: [map]}, id: str(uuid)}} # API updated successfully\n@errors {400: Bad request, 403: Forbidden, 404: API not found error, 429: Too many requests}\n\n@endpoint POST /api/v2/apicatalog/openapi\n@desc Create a new API\n@returns(201) {data: map{attributes: map{failed_endpoints: [map]}, id: str(uuid)}} # API created successfully\n@errors {400: Bad request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/apm/config/metrics\n@desc Get all span-based metrics\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/apm/config/metrics\n@desc Create a span-based metric\n@required {data: map{attributes!: map, id!: str, type!: str} # The new span-based metric properties.}\n@returns(200) {data: map{attributes: map{compute: map{aggregation_type: str, include_percentiles: bool, path: str}, filter: map{query: str}, group_by: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compute\":{\"aggregation_type\":\"distribution\",\"include_percentiles\":false,\"path\":\"@duration\"},\"filter\":{\"query\":\"@http.status_code:200 service:my-service\"},\"group_by\":[{\"path\":\"resource_name\",\"tag_name\":\"resource_name\"}]},\"id\":\"my.metric\",\"type\":\"spans_metrics\"}}\n\n@endpoint DELETE /api/v2/apm/config/metrics/{metric_id}\n@desc Delete a span-based metric\n@required {metric_id: str # The name of the span-based metric.}\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/apm/config/metrics/{metric_id}\n@desc Get a span-based metric\n@required {metric_id: str # The name of the span-based metric.}\n@returns(200) {data: map{attributes: map{compute: map{aggregation_type: str, include_percentiles: bool, path: str}, filter: map{query: str}, group_by: [map]}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/apm/config/metrics/{metric_id}\n@desc Update a span-based metric\n@required {metric_id: str # The name of the span-based metric., data: map{attributes!: map, type!: str} # The new span-based metric properties.}\n@returns(200) {data: map{attributes: map{compute: map{aggregation_type: str, include_percentiles: bool, path: str}, filter: map{query: str}, group_by: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compute\":{\"include_percentiles\":false},\"filter\":{\"query\":\"@http.status_code:200 service:my-service\"},\"group_by\":[{\"path\":\"resource_name\",\"tag_name\":\"resource_name\"}]},\"type\":\"spans_metrics\"}}\n\n@endpoint GET /api/v2/apm/config/retention-filters\n@desc List all APM retention filters\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/apm/config/retention-filters\n@desc Create a retention filter\n@required {data: map{attributes!: map, type!: str} # The body of the retention filter to be created.}\n@returns(200) {data: map{attributes: map{created_at: int(int64), created_by: str, editable: bool, enabled: bool, execution_order: int(int64), filter: map{query: str}, filter_type: str, modified_at: int(int64), modified_by: str, name: str, rate: num(double), trace_rate: num(double)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"filter\":{\"query\":\"@http.status_code:200 service:my-service\"},\"filter_type\":\"spans-sampling-processor\",\"name\":\"my retention filter\",\"rate\":1,\"trace_rate\":1},\"type\":\"apm_retention_filter\"}}\n\n@endpoint PUT /api/v2/apm/config/retention-filters-execution-order\n@desc Re-order retention filters\n@required {data: [map{id!: str, type!: str}] # A list of retention filters objects.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":[{\"id\":\"7RBOb7dLSYWI01yc3pIH8w\",\"type\":\"apm_retention_filter\"}]}\n\n@endpoint DELETE /api/v2/apm/config/retention-filters/{filter_id}\n@desc Delete a retention filter\n@required {filter_id: str # The ID of the retention filter.}\n@returns(200) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/apm/config/retention-filters/{filter_id}\n@desc Get a given APM retention filter\n@required {filter_id: str # The ID of the retention filter.}\n@returns(200) {data: map{attributes: map{created_at: int(int64), created_by: str, editable: bool, enabled: bool, execution_order: int(int64), filter: map{query: str}, filter_type: str, modified_at: int(int64), modified_by: str, name: str, rate: num(double), trace_rate: num(double)}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/apm/config/retention-filters/{filter_id}\n@desc Update a retention filter\n@required {filter_id: str # The ID of the retention filter., data: map{attributes!: map, id!: str, type!: str} # The body of the retention filter to be updated.}\n@returns(200) {data: map{attributes: map{created_at: int(int64), created_by: str, editable: bool, enabled: bool, execution_order: int(int64), filter: map{query: str}, filter_type: str, modified_at: int(int64), modified_by: str, name: str, rate: num(double), trace_rate: num(double)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"filter\":{\"query\":\"@http.status_code:200 service:my-service\"},\"filter_type\":\"spans-sampling-processor\",\"name\":\"my retention filter\",\"rate\":1,\"trace_rate\":1},\"id\":\"retention-filter-id\",\"type\":\"apm_retention_filter\"}}\n\n@endpoint GET /api/v2/apm/services\n@desc Get service list\n@required {filter[env]: str: any # Filter services by environment. Can be set to `*` to return all services across all environments.}\n@returns(200) {data: map{attributes: map{metadata: [map], services: [str]}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint DELETE /api/v2/app-builder/apps\n@desc Delete Multiple Apps\n@optional {data: [map{id!: str(uuid), type!: str}] # An array of objects containing the IDs of the apps to delete.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":[{\"id\":\"aea2ed17-b45f-40d0-ba59-c86b7972c901\",\"type\":\"appDefinitions\"},{\"id\":\"f69bb8be-6168-4fe7-a30d-370256b6504a\",\"type\":\"appDefinitions\"},{\"id\":\"ab1ed73e-13ad-4426-b0df-a0ff8876a088\",\"type\":\"appDefinitions\"}]}\n\n@endpoint GET /api/v2/app-builder/apps\n@desc List Apps\n@optional {limit: int(int64) # The number of apps to return per page., page: int(int64) # The page number to return., filter[user_name]: str # Filter apps by the app creator. Usually the user's email., filter[user_uuid]: str(uuid) # Filter apps by the app creator's UUID., filter[name]: str # Filter by app name., filter[query]: str # Filter apps by the app name or the app creator., filter[deployed]: bool # Filter apps by whether they are published., filter[tags]: str # Filter apps by tags., filter[favorite]: bool # Filter apps by whether you have added them to your favorites., filter[self_service]: bool # Filter apps by whether they are enabled for self-service., sort: [str] # The fields and direction to sort apps by.}\n@returns(200) {data: [map], included: [map], meta: map{page: map{totalCount: int(int64), totalFilteredCount: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/app-builder/apps\n@desc Create App\n@optional {data: map{attributes: map, type!: str} # The data object containing the app definition.}\n@returns(201) {data: map{id: str(uuid), type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"components\":[],\"description\":\"This is a simple example app\",\"name\":\"Example App\",\"queries\":[],\"rootInstanceName\":\"grid0\"},\"type\":\"appDefinitions\"}}\n\n@endpoint DELETE /api/v2/app-builder/apps/{app_id}\n@desc Delete App\n@required {app_id: str(uuid) # The ID of the app to delete.}\n@returns(200) {data: map{id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 410: Gone, 429: Too many requests}\n\n@endpoint GET /api/v2/app-builder/apps/{app_id}\n@desc Get App\n@required {app_id: str(uuid) # The ID of the app to retrieve.}\n@optional {version: str # The version number of the app to retrieve. If not specified, the latest version is returned. Version numbers start at 1 and increment with each update. The special values `latest` and `deployed` can be used to retrieve the latest version or the published version, respectively.}\n@returns(200) {data: map{attributes: map{components: [map], description: str, favorite: bool, name: str, queries: [any], rootInstanceName: str, tags: [str]}, id: str(uuid), type: str}, included: [map], meta: map{created_at: str(date-time), deleted_at: str(date-time), org_id: int(int64), updated_at: str(date-time), updated_since_deployment: bool, user_id: int(int64), user_name: str, user_uuid: str(uuid), version: int(int64)}, relationship: map{connections: [map], deployment: map{data: map{id: str(uuid), type: str}, meta: map{created_at: str(date-time), user_id: int(int64), user_name: str, user_uuid: str(uuid)}}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 410: Gone, 429: Too many requests}\n\n@endpoint PATCH /api/v2/app-builder/apps/{app_id}\n@desc Update App\n@required {app_id: str(uuid) # The ID of the app to update.}\n@optional {data: map{attributes: map, id: str(uuid), type!: str} # The data object containing the new app definition. Any fields not included in the request remain unchanged.}\n@returns(200) {data: map{attributes: map{components: [map], description: str, favorite: bool, name: str, queries: [any], rootInstanceName: str, tags: [str]}, id: str(uuid), type: str}, included: [map], meta: map{created_at: str(date-time), deleted_at: str(date-time), org_id: int(int64), updated_at: str(date-time), updated_since_deployment: bool, user_id: int(int64), user_name: str, user_uuid: str(uuid), version: int(int64)}, relationship: map{connections: [map], deployment: map{data: map{id: str(uuid), type: str}, meta: map{created_at: str(date-time), user_id: int(int64), user_name: str, user_uuid: str(uuid)}}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"components\":[],\"description\":\"This is a simple example app\",\"name\":\"Example App\",\"queries\":[],\"rootInstanceName\":\"grid0\"},\"id\":\"9e20cbaf-68da-45a6-9ccf-54193ac29fa5\",\"type\":\"appDefinitions\"}}\n\n@endpoint DELETE /api/v2/app-builder/apps/{app_id}/deployment\n@desc Unpublish App\n@required {app_id: str(uuid) # The ID of the app to unpublish.}\n@returns(200) {data: map{attributes: map{app_version_id: str(uuid)}, id: str(uuid), meta: map{created_at: str(date-time), user_id: int(int64), user_name: str, user_uuid: str(uuid)}, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/app-builder/apps/{app_id}/deployment\n@desc Publish App\n@required {app_id: str(uuid) # The ID of the app to publish.}\n@returns(201) {data: map{attributes: map{app_version_id: str(uuid)}, id: str(uuid), meta: map{created_at: str(date-time), user_id: int(int64), user_name: str, user_uuid: str(uuid)}, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/app-builder/apps/{app_id}/favorite\n@desc Update App Favorite Status\n@required {app_id: str(uuid) # The ID of the app.}\n@optional {data: map{attributes: map, type: str} # Data for updating an app's favorite status.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"favorite\":true},\"type\":\"favorites\"}}\n\n@endpoint PATCH /api/v2/app-builder/apps/{app_id}/protection-level\n@desc Update App Protection Level\n@required {app_id: str(uuid) # The ID of the app.}\n@optional {data: map{attributes: map, type: str} # Data for updating an app's publication protection level.}\n@returns(200) {data: map{attributes: map{components: [map], description: str, favorite: bool, name: str, queries: [any], rootInstanceName: str, tags: [str]}, id: str(uuid), type: str}, included: [map], meta: map{created_at: str(date-time), deleted_at: str(date-time), org_id: int(int64), updated_at: str(date-time), updated_since_deployment: bool, user_id: int(int64), user_name: str, user_uuid: str(uuid), version: int(int64)}, relationship: map{connections: [map], deployment: map{data: map{id: str(uuid), type: str}, meta: map{created_at: str(date-time), user_id: int(int64), user_name: str, user_uuid: str(uuid)}}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"protectionLevel\":\"approval_required\"},\"type\":\"protectionLevel\"}}\n\n@endpoint POST /api/v2/app-builder/apps/{app_id}/publish-request\n@desc Create Publish Request\n@required {app_id: str(uuid) # The ID of the app.}\n@optional {data: map{attributes: map, type: str} # Data for creating a publish request.}\n@returns(201) {data: map{attributes: map{app_version_id: str(uuid)}, id: str(uuid), meta: map{created_at: str(date-time), user_id: int(int64), user_name: str, user_uuid: str(uuid)}, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Adds new dashboard widgets and a few bug fixes.\",\"title\":\"Release v1.2 to production\"},\"type\":\"publishRequest\"}}\n\n@endpoint POST /api/v2/app-builder/apps/{app_id}/revert\n@desc Revert App\n@required {app_id: str(uuid) # The ID of the app., version: str # The version number of the app to revert to. Cannot be `latest`. The special value `deployed` can be used to revert to the currently published version.}\n@returns(200) {data: map{attributes: map{components: [map], description: str, favorite: bool, name: str, queries: [any], rootInstanceName: str, tags: [str]}, id: str(uuid), type: str}, included: [map], meta: map{created_at: str(date-time), deleted_at: str(date-time), org_id: int(int64), updated_at: str(date-time), updated_since_deployment: bool, user_id: int(int64), user_name: str, user_uuid: str(uuid), version: int(int64)}, relationship: map{connections: [map], deployment: map{data: map{id: str(uuid), type: str}, meta: map{created_at: str(date-time), user_id: int(int64), user_name: str, user_uuid: str(uuid)}}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/app-builder/apps/{app_id}/self-service\n@desc Update App Self-Service Status\n@required {app_id: str(uuid) # The ID of the app.}\n@optional {data: map{attributes: map, type: str} # Data for updating an app's self-service status.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"selfService\":true},\"type\":\"selfService\"}}\n\n@endpoint PATCH /api/v2/app-builder/apps/{app_id}/tags\n@desc Update App Tags\n@required {app_id: str(uuid) # The ID of the app.}\n@optional {data: map{attributes: map, type: str} # Data for replacing an app's tags.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"tags\":[\"team:platform\",\"service:ops\"]},\"type\":\"tags\"}}\n\n@endpoint PATCH /api/v2/app-builder/apps/{app_id}/version-name\n@desc Name App Version\n@required {app_id: str(uuid) # The ID of the app., version: str # The version number of the app to name. The special values `latest` and `deployed` can also be used to target the latest or currently published version.}\n@optional {data: map{attributes: map, type: str} # Data for naming a specific app version.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"v1.2.0 - bug fix release\"},\"type\":\"versionNames\"}}\n\n@endpoint GET /api/v2/app-builder/apps/{app_id}/versions\n@desc List App Versions\n@required {app_id: str(uuid) # The ID of the app.}\n@optional {limit: int(int64) # The number of versions to return per page., page: int(int64) # The page number to return.}\n@returns(200) {data: [map], meta: map{page: map{totalCount: int(int64), totalFilteredCount: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/app-builder/blueprint/{blueprint_id}\n@desc Get Blueprint\n@required {blueprint_id: str(uuid) # The ID of the blueprint to retrieve.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), definition: str, description: str, embedded_datastore_blueprints: map, embedded_native_actions: [map], embedded_workflow_blueprints: map, integration_id: str, mocked_outputs: map, name: str, slug: str, tags: [str], tile_background: str, tile_icon_action_fqn: str, updated_at: str(date-time)}, id: str(uuid), type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/app-builder/blueprints\n@desc List Blueprints\n@optional {limit: int(int64) # The number of blueprints to return per page. Defaults to 10. Maximum is 100., page: int(int64) # The page of results to return. Starts at 0.}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/app-builder/blueprints/integration-id/{integration_id}\n@desc Get Blueprints by Integration ID\n@required {integration_id: str # The integration ID to filter blueprints by.}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/app-builder/blueprints/slugs/{slugs}\n@desc Get Blueprints by Slugs\n@required {slugs: str # A comma-separated list of blueprint slugs.}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/app-builder/tags\n@desc List Tags\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/application_keys\n@desc Get all application keys\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # Application key attribute used to sort results. Sort order is ascending by default. In order to specify a descending sort, prefix the attribute with a minus sign., filter: str # Filter application keys by the specified string., filter[created_at][start]: str # Only include application keys created on or after the specified date., filter[created_at][end]: str # Only include application keys created on or before the specified date., filter[owned_by]: str # Filter application keys by owner ID., include: str # Resource path for related resources to include in the response. Only `owned_by` is supported.}\n@returns(200) {data: [map], included: [any], meta: map{max_allowed_per_user: int(int64), page: map{total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/application_keys/{app_key_id}\n@desc Delete an application key\n@required {app_key_id: str # The ID of the application key.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/application_keys/{app_key_id}\n@desc Get an application key\n@required {app_key_id: str # The ID of the application key.}\n@optional {include: str # Resource path for related resources to include in the response. Only `owned_by` is supported.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), key: str, last4: str, last_used_at: str(date-time)?, name: str, scopes: [str]?}, id: str, relationships: map{owned_by: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/application_keys/{app_key_id}\n@desc Edit an application key\n@required {app_key_id: str # The ID of the application key., data: map{attributes!: map, id!: str, type!: str} # Object used to update an application key.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), key: str, last4: str, last_used_at: str(date-time)?, name: str, scopes: [str]?}, id: str, relationships: map{owned_by: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Application Key for managing dashboards\",\"scopes\":[\"dashboards_read\",\"dashboards_write\",\"dashboards_public_share\"]},\"id\":\"00112233-4455-6677-8899-aabbccddeeff\",\"type\":\"application_keys\"}}\n\n@endpoint GET /api/v2/audit/events\n@desc Get a list of Audit Logs events\n@optional {filter[query]: str: any # Search query following Audit Logs syntax., filter[from]: str(date-time) # Minimum timestamp for requested events., filter[to]: str(date-time) # Maximum timestamp for requested events., sort: str # Order of events in results., page[cursor]: str # List following results with a cursor provided in the previous query., page[limit]: int(int32)=10 # Maximum number of events in the response.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/audit/events/search\n@desc Search Audit Logs events\n@optional {filter: map{from: str, query: str, to: str} # Search and filter query settings., options: map{time_offset: int(int64), timezone: str} # Global query options that are used during the query. Note: Specify either timezone or time offset, not both. Otherwise, the query fails., page: map{cursor: str, limit: int(int32)} # Paging attributes for listing events., sort: str(timestamp/-timestamp) # Sort parameters when querying events.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"filter\":{\"from\":\"now-15m\",\"query\":\"@type:session AND @session.type:user\",\"to\":\"now\"},\"options\":{\"timezone\":\"GMT\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\",\"limit\":25},\"sort\":\"timestamp\"}\n\n@endpoint GET /api/v2/authn_mappings\n@desc List all AuthN Mappings\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # Sort AuthN Mappings depending on the given field., filter: str # Filter all mappings by the given string., resource_type: str # Filter by mapping resource type. Defaults to \"role\" if not specified.}\n@returns(200) {data: [map], included: [any], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {403: Authentication Error, 429: Too many requests}\n\n@endpoint POST /api/v2/authn_mappings\n@desc Create an AuthN Mapping\n@required {data: map{attributes: map, relationships: any, type!: str} # Data for creating an AuthN Mapping.}\n@returns(200) {data: map{attributes: map{attribute_key: str, attribute_value: str, created_at: str(date-time), modified_at: str(date-time), saml_assertion_attribute_id: str}, id: str, relationships: map{role: map{data: map}, saml_assertion_attribute: map{data: map}, team: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Authentication Error, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"attribute_key\":\"member-of\",\"attribute_value\":\"Development\"},\"type\":\"authn_mappings\"}}\n\n@endpoint DELETE /api/v2/authn_mappings/{authn_mapping_id}\n@desc Delete an AuthN Mapping\n@required {authn_mapping_id: str # The UUID of the AuthN Mapping.}\n@returns(204) OK\n@errors {403: Authentication Error, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/authn_mappings/{authn_mapping_id}\n@desc Get an AuthN Mapping by UUID\n@required {authn_mapping_id: str # The UUID of the AuthN Mapping.}\n@returns(200) {data: map{attributes: map{attribute_key: str, attribute_value: str, created_at: str(date-time), modified_at: str(date-time), saml_assertion_attribute_id: str}, id: str, relationships: map{role: map{data: map}, saml_assertion_attribute: map{data: map}, team: map{data: map}}, type: str}, included: [any]} # OK\n@errors {403: Authentication Error, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/authn_mappings/{authn_mapping_id}\n@desc Edit an AuthN Mapping\n@required {authn_mapping_id: str # The UUID of the AuthN Mapping., data: map{attributes: map, id!: str, relationships: any, type!: str} # Data for updating an AuthN Mapping.}\n@returns(200) {data: map{attributes: map{attribute_key: str, attribute_value: str, created_at: str(date-time), modified_at: str(date-time), saml_assertion_attribute_id: str}, id: str, relationships: map{role: map{data: map}, saml_assertion_attribute: map{data: map}, team: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Authentication Error, 404: Not Found, 409: Conflict, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"attribute_key\":\"member-of\",\"attribute_value\":\"Development\"},\"id\":\"3653d3c6-0c75-11ea-ad28-fb5701eabc7d\",\"type\":\"authn_mappings\"}}\n\n@endpoint GET /api/v2/bits-ai/investigations\n@desc List Bits AI investigations\n@optional {page[offset]: int(int64): any # Offset for pagination., page[limit]: int(int64)=25 # Maximum number of investigations to return., filter[monitor_id]: int(int64) # Filter investigations by monitor ID.}\n@returns(200) {data: [map], links: map{first: str, last: str?, next: str, prev: str?, self: str}, meta: map{page: map{limit: int(int64), offset: int(int64), total: int(int64)}}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint POST /api/v2/bits-ai/investigations\n@desc Trigger a Bits AI investigation\n@required {data: map{attributes!: map, type!: str} # Data for the trigger investigation request.}\n@returns(200) {data: map{attributes: map{investigation_id: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"trigger\":{\"monitor_alert_trigger\":{\"event_id\":\"1234567890123456789\",\"event_ts\":1700000000000,\"monitor_id\":12345678},\"type\":\"monitor_alert_trigger\"}},\"type\":\"trigger_investigation_request\"}}\n\n@endpoint GET /api/v2/bits-ai/investigations/{id}\n@desc Get a Bits AI investigation\n@required {id: str # The ID of the investigation.}\n@returns(200) {data: map{attributes: map{conclusions: [map], status: str, title: str}, id: str, type: str}, links: map{self: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cases\n@desc Search cases\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort[field]: str # Specify which field to sort, filter: str # Search query, sort[asc]: bool=false # Specify if order is ascending or not}\n@returns(200) {data: [map], meta: map{page: map{current: int(int64), size: int(int64), total: int(int64)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases\n@desc Create a case\n@required {data: map{attributes!: map, relationships: map, type!: str} # Case creation data}\n@returns(201) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"priority\":\"NOT_DEFINED\",\"status_name\":\"Open\",\"title\":\"Security breach investigation\",\"type_id\":\"3b010bde-09ce-4449-b745-71dd5f861963\"},\"relationships\":{\"assignee\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"user\"}},\"project\":{\"data\":{\"id\":\"e555e290-ed65-49bd-ae18-8acbfcf18db7\",\"type\":\"project\"}}},\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/aggregate\n@desc Aggregate cases\n@required {data: map{attributes!: map, type!: str} # Data object wrapping the aggregation query type and attributes.}\n@returns(200) {data: map{attributes: map{groups: [map], total: num(double)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"group_by\":{\"groups\":[\"status\"],\"limit\":14},\"query_filter\":\"service:case-api\"},\"type\":\"aggregate\"}}\n\n@endpoint POST /api/v2/cases/bulk\n@desc Bulk update cases\n@required {data: map{attributes!: map, type!: str} # Data object wrapping the bulk update type and attributes.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"case_ids\":[\"case-id-1\",\"case-id-2\"],\"payload\":{\"priority\":\"P1\"},\"type\":\"priority\"},\"type\":\"bulk\"}}\n\n@endpoint GET /api/v2/cases/count\n@desc Count cases\n@optional {query_filter: str # Filter query for cases., group_bys: str # Comma-separated fields to group by., limit: int(int64) # Maximum facet values to return.}\n@returns(200) {data: map{attributes: map{groups: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cases/link\n@desc List case links\n@required {entity_type: str # The entity type to look up links for. Use `CASE` to find links for a specific case., entity_id: str # The UUID of the entity to look up links for.}\n@optional {relationship: str # Optional filter to only return links of a specific relationship type (for example, `BLOCKS` or `CAUSES`).}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/link\n@desc Create a case link\n@required {data: map{attributes!: map, type!: str} # Data object for creating a case link.}\n@returns(201) {data: map{attributes: map{child_entity_id: str, child_entity_type: str, parent_entity_id: str, parent_entity_type: str, relationship: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"child_entity_id\":\"4417921d-0866-4a38-822c-6f2a0f65f77d\",\"child_entity_type\":\"CASE\",\"parent_entity_id\":\"bf0cbac6-4c16-4cfb-b6bf-ca5e0ec37a4f\",\"parent_entity_type\":\"CASE\",\"relationship\":\"BLOCKS\"},\"type\":\"link\"}}\n\n@endpoint DELETE /api/v2/cases/link/{link_id}\n@desc Delete a case link\n@required {link_id: str # The UUID of the case link.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cases/projects\n@desc Get all projects\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/projects\n@desc Create a project\n@required {data: map{attributes!: map, type!: str} # Project create.}\n@returns(201) {data: map{attributes: map{columns_config: map{columns: [map]}, enabled_custom_case_types: [str], key: str, name: str, restricted: bool, settings: map{auto_close_inactive_cases: map, auto_transition_assigned_cases: map, integration_incident: map, integration_jira: map, integration_monitor: map, integration_on_call: map, integration_service_now: map, notification: map}}, id: str, relationships: map{member_team: map{data: [map], links: map}, member_user: map{data: [map]}}, type: str}} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"key\":\"SEC\",\"name\":\"Security Investigation\"},\"type\":\"project\"}}\n\n@endpoint GET /api/v2/cases/projects/favorites\n@desc List project favorites\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/cases/projects/{project_id}\n@desc Remove a project\n@required {project_id: str # Project UUID.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: API error response, 429: Too many requests}\n\n@endpoint GET /api/v2/cases/projects/{project_id}\n@desc Get the details of a project\n@required {project_id: str # Project UUID.}\n@returns(200) {data: map{attributes: map{columns_config: map{columns: [map]}, enabled_custom_case_types: [str], key: str, name: str, restricted: bool, settings: map{auto_close_inactive_cases: map, auto_transition_assigned_cases: map, integration_incident: map, integration_jira: map, integration_monitor: map, integration_on_call: map, integration_service_now: map, notification: map}}, id: str, relationships: map{member_team: map{data: [map], links: map}, member_user: map{data: [map]}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/cases/projects/{project_id}\n@desc Update a project\n@required {project_id: str # Project UUID., data: map{attributes: map, type!: str} # Project update.}\n@returns(200) {data: map{attributes: map{columns_config: map{columns: [map]}, enabled_custom_case_types: [str], key: str, name: str, restricted: bool, settings: map{auto_close_inactive_cases: map, auto_transition_assigned_cases: map, integration_incident: map, integration_jira: map, integration_monitor: map, integration_on_call: map, integration_service_now: map, notification: map}}, id: str, relationships: map{member_team: map{data: [map], links: map}, member_user: map{data: [map]}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"project\"}}\n\n@endpoint DELETE /api/v2/cases/projects/{project_id}/favorites\n@desc Unfavorite a project\n@required {project_id: str # Project UUID.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/projects/{project_id}/favorites\n@desc Favorite a project\n@required {project_id: str # Project UUID.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cases/projects/{project_id}/notification_rules\n@desc Get notification rules\n@required {project_id: str # Project UUID}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/projects/{project_id}/notification_rules\n@desc Create a notification rule\n@required {project_id: str # Project UUID, data: map{attributes!: map, type!: str} # Notification rule create}\n@returns(201) {data: map{attributes: map{is_enabled: bool, query: str, recipients: [map], triggers: [map]}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"recipients\":[{\"type\":\"EMAIL\"}],\"triggers\":[{\"type\":\"CASE_CREATED\"}]},\"type\":\"notification_rule\"}}\n\n@endpoint DELETE /api/v2/cases/projects/{project_id}/notification_rules/{notification_rule_id}\n@desc Delete a notification rule\n@required {project_id: str # Project UUID, notification_rule_id: str # Notification Rule UUID}\n@returns(204) No Content\n@errors {403: Forbidden, 404: API error response, 429: Too many requests}\n\n@endpoint PUT /api/v2/cases/projects/{project_id}/notification_rules/{notification_rule_id}\n@desc Update a notification rule\n@required {project_id: str # Project UUID, notification_rule_id: str # Notification Rule UUID, data: map{attributes: map, type!: str} # Notification rule update}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"recipients\":[{\"type\":\"EMAIL\"}],\"triggers\":[{\"type\":\"CASE_CREATED\"}]},\"type\":\"notification_rule\"}}\n\n@endpoint GET /api/v2/cases/projects/{project_id}/rules\n@desc List automation rules\n@required {project_id: str # The UUID of the project that owns the automation rules.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/projects/{project_id}/rules\n@desc Create an automation rule\n@required {project_id: str # The UUID of the project that owns the automation rules., data: map{attributes!: map, type!: str} # Data object for creating an automation rule.}\n@returns(201) {data: map{attributes: map{action: map{data: map, type: str}, created_at: str(date-time), modified_at: str(date-time), name: str, state: str, trigger: map{data: map, type: str}}, id: str, relationships: map{created_by: map?{data: map?}, modified_by: map?{data: map?}}, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":{\"data\":{\"handle\":\"workflow-handle-123\"},\"type\":\"EXECUTE_WORKFLOW\"},\"name\":\"Auto-assign workflow\",\"state\":\"ENABLED\",\"trigger\":{\"type\":\"CASE_CREATED\"}},\"type\":\"rule\"}}\n\n@endpoint DELETE /api/v2/cases/projects/{project_id}/rules/{rule_id}\n@desc Delete an automation rule\n@required {project_id: str # The UUID of the project that owns the automation rules., rule_id: str # The UUID of the automation rule.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cases/projects/{project_id}/rules/{rule_id}\n@desc Get an automation rule\n@required {project_id: str # The UUID of the project that owns the automation rules., rule_id: str # The UUID of the automation rule.}\n@returns(200) {data: map{attributes: map{action: map{data: map, type: str}, created_at: str(date-time), modified_at: str(date-time), name: str, state: str, trigger: map{data: map, type: str}}, id: str, relationships: map{created_by: map?{data: map?}, modified_by: map?{data: map?}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/cases/projects/{project_id}/rules/{rule_id}\n@desc Update an automation rule\n@required {project_id: str # The UUID of the project that owns the automation rules., rule_id: str # The UUID of the automation rule., data: map{attributes: map, type!: str} # Data object for updating an automation rule.}\n@returns(200) {data: map{attributes: map{action: map{data: map, type: str}, created_at: str(date-time), modified_at: str(date-time), name: str, state: str, trigger: map{data: map, type: str}}, id: str, relationships: map{created_by: map?{data: map?}, modified_by: map?{data: map?}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":{\"data\":{\"handle\":\"workflow-handle-123\"},\"type\":\"EXECUTE_WORKFLOW\"},\"name\":\"Auto-assign workflow\",\"state\":\"ENABLED\",\"trigger\":{\"type\":\"CASE_CREATED\"}},\"type\":\"rule\"}}\n\n@endpoint POST /api/v2/cases/projects/{project_id}/rules/{rule_id}/disable\n@desc Disable an automation rule\n@required {project_id: str # The UUID of the project that owns the automation rules., rule_id: str # The UUID of the automation rule.}\n@returns(200) {data: map{attributes: map{action: map{data: map, type: str}, created_at: str(date-time), modified_at: str(date-time), name: str, state: str, trigger: map{data: map, type: str}}, id: str, relationships: map{created_by: map?{data: map?}, modified_by: map?{data: map?}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/projects/{project_id}/rules/{rule_id}/enable\n@desc Enable an automation rule\n@required {project_id: str # The UUID of the project that owns the automation rules., rule_id: str # The UUID of the automation rule.}\n@returns(200) {data: map{attributes: map{action: map{data: map, type: str}, created_at: str(date-time), modified_at: str(date-time), name: str, state: str, trigger: map{data: map, type: str}}, id: str, relationships: map{created_by: map?{data: map?}, modified_by: map?{data: map?}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cases/types\n@desc Get all case types\n@returns(200) {data: [map]} # OK\n@errors {401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/types\n@desc Create a case type\n@required {data: map{attributes!: map, type!: str} # Data object for creating a case type.}\n@returns(201) {data: map{attributes: map{deleted_at: str(date-time)?, description: str, emoji: str, name: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Investigations done in case management\",\"emoji\":\"🕵🏻‍♂️\",\"name\":\"Investigation\"},\"type\":\"case_type\"}}\n\n@endpoint GET /api/v2/cases/types/custom_attributes\n@desc Get all custom attributes\n@returns(200) {data: [map]} # OK\n@errors {401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint DELETE /api/v2/cases/types/{case_type_id}\n@desc Delete a case type\n@required {case_type_id: str # The UUID of the case type.}\n@returns(204) No Content\n@errors {401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint PUT /api/v2/cases/types/{case_type_id}\n@desc Update a case type\n@required {case_type_id: str # The UUID of the case type., data: map{attributes: map, type!: str} # Data object for updating a case type.}\n@returns(200) {data: map{attributes: map{deleted_at: str(date-time)?, description: str, emoji: str, name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Investigations done in case management\",\"emoji\":\"🕵🏻‍♂️\",\"name\":\"Investigation\"},\"type\":\"case_type\"}}\n\n@endpoint GET /api/v2/cases/types/{case_type_id}/custom_attributes\n@desc Get all custom attributes config of case type\n@required {case_type_id: str # The UUID of the case type.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/types/{case_type_id}/custom_attributes\n@desc Create custom attribute config for a case type\n@required {case_type_id: str # The UUID of the case type., data: map{attributes!: map, type!: str} # Data object for creating a custom attribute configuration.}\n@returns(201) {data: map{attributes: map{case_type_id: str, description: str, display_name: str, is_multi: bool, key: str, type: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"AWS Region, must be a valid region supported by AWS\",\"display_name\":\"AWS Region\",\"is_multi\":true,\"key\":\"aws_region\",\"type\":\"NUMBER\"},\"type\":\"custom_attribute\"}}\n\n@endpoint DELETE /api/v2/cases/types/{case_type_id}/custom_attributes/{custom_attribute_id}\n@desc Delete custom attributes config\n@required {case_type_id: str # The UUID of the case type., custom_attribute_id: str # Case Custom attribute's UUID}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint PUT /api/v2/cases/types/{case_type_id}/custom_attributes/{custom_attribute_id}\n@desc Update custom attribute config\n@required {case_type_id: str # The UUID of the case type., custom_attribute_id: str # Case Custom attribute's UUID, data: map{attributes: map, type!: str} # Data object for updating a custom attribute configuration.}\n@returns(200) {data: map{attributes: map{case_type_id: str, description: str, display_name: str, is_multi: bool, key: str, type: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Updated description.\",\"display_name\":\"AWS Region\"},\"type\":\"custom_attribute\"}}\n\n@endpoint GET /api/v2/cases/views\n@desc List case views\n@required {project_id: str # Filter views by project identifier.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/views\n@desc Create a case view\n@required {data: map{attributes!: map, type!: str} # Data object for creating a case view.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), name: str, np_rule_id: str, query: str}, id: str, relationships: map{created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Open bugs\",\"project_id\":\"e555e290-ed65-49bd-ae18-8acbfcf18db7\",\"query\":\"status:open type:bug\"},\"type\":\"view\"}}\n\n@endpoint DELETE /api/v2/cases/views/{view_id}\n@desc Delete a case view\n@required {view_id: str # The UUID of the case view.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cases/views/{view_id}\n@desc Get a case view\n@required {view_id: str # The UUID of the case view.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), name: str, np_rule_id: str, query: str}, id: str, relationships: map{created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/cases/views/{view_id}\n@desc Update a case view\n@required {view_id: str # The UUID of the case view., data: map{attributes: map, type!: str} # Data object for updating a case view.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), name: str, np_rule_id: str, query: str}, id: str, relationships: map{created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Updated view name\"},\"type\":\"view\"}}\n\n@endpoint GET /api/v2/cases/{case_id}\n@desc Get the details of a case\n@required {case_id: str # Case's UUID or key}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/{case_id}/archive\n@desc Archive case\n@required {case_id: str # Case's UUID or key, data: map{type!: str} # Case empty request data}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/assign\n@desc Assign case\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Case assign}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assignee_id\":\"f98a5a5b-e0ff-45d4-b2f5-afe6e74de504\"},\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/attributes\n@desc Update case attributes\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Case update attributes}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"attributes\":{\"env\":[\"prod\"],\"service\":[\"web-store\",\"web-api\"],\"team\":[\"engineering\"]}},\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/comment\n@desc Comment case\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Case comment}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"comment\":\"This is my comment !\"},\"type\":\"case\"}}\n\n@endpoint DELETE /api/v2/cases/{case_id}/comment/{cell_id}\n@desc Delete case comment\n@required {case_id: str # Case's UUID or key, cell_id: str # The UUID of the timeline cell (comment) to update.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/cases/{case_id}/comment/{cell_id}\n@desc Update case comment\n@required {case_id: str # Case's UUID or key, cell_id: str # The UUID of the timeline cell (comment) to update., data: map{attributes!: map, type!: str} # Data object for updating a case comment.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"comment\":\"Updated comment text\"},\"type\":\"case\"}}\n\n@endpoint DELETE /api/v2/cases/{case_id}/custom_attributes/{custom_attribute_key}\n@desc Delete custom attribute from case\n@required {case_id: str # Case's UUID or key, custom_attribute_key: str # Case Custom attribute's key}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/{case_id}/custom_attributes/{custom_attribute_key}\n@desc Update case custom attribute\n@required {case_id: str # Case's UUID or key, custom_attribute_key: str # Case Custom attribute's key, data: map{attributes!: map, type!: str} # Case update custom attribute}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"is_multi\":false,\"type\":\"NUMBER\",\"value\":42},\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/description\n@desc Update case description\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Case update description}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Seeing some weird memory increase... We shouldn't ignore this\"},\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/due_date\n@desc Update case due date\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Data object for updating a case's due date.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"due_date\":\"2026-12-31\"},\"type\":\"case\"}}\n\n@endpoint DELETE /api/v2/cases/{case_id}/insights\n@desc Remove insights from a case\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Data object containing the insights to add or remove.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"insights\":[{\"ref\":\"/monitors/12345?q=total\",\"resource_id\":\"12345\",\"type\":\"SECURITY_SIGNAL\"}]},\"type\":\"case\"}}\n\n@endpoint PUT /api/v2/cases/{case_id}/insights\n@desc Add insights to a case\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Data object containing the insights to add or remove.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"insights\":[{\"ref\":\"/monitors/12345?q=total\",\"resource_id\":\"12345\",\"type\":\"SECURITY_SIGNAL\"}]},\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/priority\n@desc Update case priority\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Case priority status}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"priority\":\"NOT_DEFINED\"},\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/relationships/incidents\n@desc Link incident to case\n@required {case_id: str # Case's UUID or key, data: map{id!: str, type!: str} # Incident relationship data}\n@returns(201) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"incidents\"}}\n\n@endpoint DELETE /api/v2/cases/{case_id}/relationships/jira_issues\n@desc Remove Jira issue link from case\n@required {case_id: str # Case's UUID or key}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/cases/{case_id}/relationships/jira_issues\n@desc Link existing Jira issue to case\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Jira issue link data}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"jira_issue_url\":\"https://jira.example.com/browse/PROJ-123\"},\"type\":\"issues\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/relationships/jira_issues\n@desc Create Jira issue for case\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Jira issue creation data}\n@returns(202) Accepted\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"fields\":{},\"issue_type_id\":\"10001\",\"jira_account_id\":\"1234\",\"project_id\":\"5678\"},\"type\":\"issues\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/relationships/notebook\n@desc Create investigation notebook for case\n@required {case_id: str # Case's UUID or key, data: map{type!: str} # Notebook creation data}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"notebook\"}}\n\n@endpoint PATCH /api/v2/cases/{case_id}/relationships/project\n@desc Update case project\n@required {case_id: str # Case's UUID or key, data: map{id!: str, type!: str} # Relationship to project object.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"e555e290-ed65-49bd-ae18-8acbfcf18db7\",\"type\":\"project\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/relationships/servicenow_tickets\n@desc Create ServiceNow ticket for case\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # ServiceNow ticket creation data}\n@returns(202) Accepted\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assignment_group\":\"IT Support\",\"instance_name\":\"my-instance\"},\"type\":\"tickets\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/resolved_reason\n@desc Update case resolved reason\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Data object for updating a case's resolved reason.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"security_resolved_reason\":\"FALSE_POSITIVE\"},\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/status\n@desc Update case status\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Case update status}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"status\":\"OPEN\",\"status_name\":\"Open\"},\"type\":\"case\"}}\n\n@endpoint GET /api/v2/cases/{case_id}/timelines\n@desc Get case timeline\n@required {case_id: str # Case's UUID or key}\n@optional {page[size]: int(int64)=100: any # Number of timeline cells to return per page., page[number]: int(int64)=0 # Zero-based page number for pagination., sort[ascending]: bool=false # If `true`, returns timeline cells in chronological order (oldest first). Defaults to `false` (newest first).}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/{case_id}/title\n@desc Update case title\n@required {case_id: str # Case's UUID or key, data: map{attributes!: map, type!: str} # Case update title}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"title\":\"Memory leak investigation on API\"},\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/unarchive\n@desc Unarchive case\n@required {case_id: str # Case's UUID or key, data: map{type!: str} # Case empty request data}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"case\"}}\n\n@endpoint POST /api/v2/cases/{case_id}/unassign\n@desc Unassign case\n@required {case_id: str # Case's UUID or key, data: map{type!: str} # Case empty request data}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, closed_at: str(date-time)?, created_at: str(date-time), custom_attributes: map, description: str, jira_issue: map?{result: map, status: str}, key: str, modified_at: str(date-time)?, priority: str, service_now_ticket: map?{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str, type_id: str}, id: str, relationships: map{assignee: map?{data: map?}, created_by: map?{data: map?}, modified_by: map?{data: map?}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"case\"}}\n\n@endpoint GET /api/v2/cases/{case_id}/watchers\n@desc List case watchers\n@required {case_id: str # Case's UUID or key}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/cases/{case_id}/watchers/{user_uuid}\n@desc Unwatch a case\n@required {case_id: str # Case's UUID or key, user_uuid: str # The UUID of the user to add or remove as a watcher.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cases/{case_id}/watchers/{user_uuid}\n@desc Watch a case\n@required {case_id: str # Case's UUID or key, user_uuid: str # The UUID of the user to add or remove as a watcher.}\n@returns(201) Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/catalog/entity\n@desc Get a list of entities\n@optional {page[offset]: int(int64)=0: any # Specific offset to use as the beginning of the returned page., page[limit]: int(int64)=100 # Maximum number of entities in the response., filter[id]: str # Filter entities by UUID., filter[ref]: str # Filter entities by reference, filter[name]: str # Filter entities by name., filter[kind]: str # Filter entities by kind., filter[owner]: str # Filter entities by owner., filter[relation][type]: str # Filter entities by relation type., filter[exclude_snapshot]: str # Filter entities by excluding snapshotted entities., include: str # Include relationship data., includeDiscovered: bool=false # If true, includes discovered services from APM and USM that do not have entity definitions.}\n@returns(200) {data: [map], included: [any], links: map{next: str, previous: str, self: str}, meta: map{count: int(int64), includeCount: int(int64)}} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/catalog/entity\n@desc Create or update entities\n@returns(202) {data: [map], included: [any], meta: map{count: int(int64), includeCount: int(int64)}} # ACCEPTED\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"apiVersion\":\"v3\",\"integrations\":{\"opsgenie\":{\"serviceURL\":\"https://www.opsgenie.com/service/shopping-cart\"},\"pagerduty\":{\"serviceURL\":\"https://www.pagerduty.com/service-directory/Pshopping-cart\"}},\"kind\":\"service\",\"metadata\":{\"additionalOwners\":[{\"name\":\"\"}],\"contacts\":[{\"contact\":\"https://slack/\",\"type\":\"slack\"}],\"id\":\"4b163705-23c0-4573-b2fb-f6cea2163fcb\",\"inheritFrom\":\"application:default/myapp\",\"links\":[{\"name\":\"mylink\",\"type\":\"link\",\"url\":\"https://mylink\"}],\"name\":\"myService\",\"namespace\":\"default\",\"tags\":[\"this:tag\",\"that:tag\"]}}\n\n@endpoint POST /api/v2/catalog/entity/preview\n@desc Preview catalog entities\n@returns(202) {data: [map]} # Accepted\n@errors {429: Too many requests}\n\n@endpoint DELETE /api/v2/catalog/entity/{entity_id}\n@desc Delete a single entity\n@required {entity_id: str # UUID or Entity Ref.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/catalog/kind\n@desc Get a list of entity kinds\n@optional {page[offset]: int(int64)=0: any # Specific offset to use as the beginning of the returned page., page[limit]: int(int64)=100 # Maximum number of kinds in the response., filter[id]: str # Filter entities by UUID., filter[name]: str # Filter entities by name.}\n@returns(200) {data: [map], meta: map{count: int(int64)}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/catalog/kind\n@desc Create or update kinds\n@returns(202) {data: [map], meta: map{count: int(int64)}} # ACCEPTED\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"kind\":\"my-job\"}\n\n@endpoint DELETE /api/v2/catalog/kind/{kind_id}\n@desc Delete a single kind\n@required {kind_id: str # Entity kind.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/catalog/relation\n@desc Get a list of entity relations\n@optional {page[offset]: int(int64)=0: any # Specific offset to use as the beginning of the returned page., page[limit]: int(int64)=100 # Maximum number of relations in the response., filter[type]: str # Filter relations by type., filter[from_ref]: str # Filter relations by the reference of the first entity in the relation., filter[to_ref]: str # Filter relations by the reference of the second entity in the relation., include: str # Include relationship data., includeDiscovered: bool=false # If true, includes relationships discovered by APM and USM.}\n@returns(200) {data: [map], included: [map], links: map{next: str, previous: str, self: str}, meta: map{count: int(int64), includeCount: int(int64)}} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/change-management/change-request\n@desc Create a change request\n@required {data: map{attributes!: map, type!: str} # Data object to create a change request.}\n@returns(201) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, change_request_linked_incident_uuid: str, change_request_maintenance_window_query: str, change_request_plan: str, change_request_risk: str, change_request_type: str, closed_at: str(date-time)?, created_at: str(date-time), creation_source: str, description: str, end_date: str(date-time), key: str, modified_at: str(date-time), plan_notebook_id: int(int64), priority: str, project_id: str, start_date: str(date-time), status: str, title: str, type: str}, id: str, relationships: map{change_request_decisions: map{data: [map]}, created_by: map{data: map?}, modified_by: map{data: map?}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"change_request_linked_incident_uuid\":\"00000000-0000-0000-0000-000000000000\",\"change_request_maintenance_window_query\":\"\",\"change_request_plan\":\"1. Deploy to staging 2. Run tests 3. Deploy to production\",\"change_request_risk\":\"LOW\",\"change_request_type\":\"NORMAL\",\"description\":\"Deploying new payment service v2.1\",\"end_date\":\"2024-01-02T15:00:00Z\",\"project_id\":\"d4bbe1af-f36e-42f1-87c1-493ca35c320e\",\"requested_teams\":[\"team-handle-1\"],\"start_date\":\"2024-01-01T03:00:00Z\",\"title\":\"Deploy new payment service\"},\"type\":\"change_request\"}}\n\n@endpoint GET /api/v2/change-management/change-request/{change_request_id}\n@desc Get a change request\n@required {change_request_id: str # The identifier of the change request.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, change_request_linked_incident_uuid: str, change_request_maintenance_window_query: str, change_request_plan: str, change_request_risk: str, change_request_type: str, closed_at: str(date-time)?, created_at: str(date-time), creation_source: str, description: str, end_date: str(date-time), key: str, modified_at: str(date-time), plan_notebook_id: int(int64), priority: str, project_id: str, start_date: str(date-time), status: str, title: str, type: str}, id: str, relationships: map{change_request_decisions: map{data: [map]}, created_by: map{data: map?}, modified_by: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/change-management/change-request/{change_request_id}\n@desc Update a change request\n@required {change_request_id: str # The identifier of the change request., data: map{attributes: map, relationships: map, type!: str} # Data object to update a change request.}\n@optional {included: [map{attributes: map, id!: str, relationships: map, type!: str}] # Included resources for the change request update.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, change_request_linked_incident_uuid: str, change_request_maintenance_window_query: str, change_request_plan: str, change_request_risk: str, change_request_type: str, closed_at: str(date-time)?, created_at: str(date-time), creation_source: str, description: str, end_date: str(date-time), key: str, modified_at: str(date-time), plan_notebook_id: int(int64), priority: str, project_id: str, start_date: str(date-time), status: str, title: str, type: str}, id: str, relationships: map{change_request_decisions: map{data: [map]}, created_by: map{data: map?}, modified_by: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"change_request_plan\":\"Updated deployment plan\",\"change_request_risk\":\"LOW\",\"change_request_type\":\"NORMAL\",\"end_date\":\"2024-01-02T15:00:00Z\",\"id\":\"CHM-1234\",\"start_date\":\"2024-01-01T03:00:00Z\"},\"relationships\":{\"change_request_decisions\":{\"data\":[{\"id\":\"decision-id-0\"}]}},\"type\":\"change_request\"},\"included\":[{\"attributes\":{\"change_request_status\":\"REQUESTED\",\"request_reason\":\"Please review and approve this change\"},\"id\":\"decision-id-0\",\"type\":\"change_request_decision\"}]}\n\n@endpoint POST /api/v2/change-management/change-request/{change_request_id}/branch\n@desc Create a change request branch\n@required {change_request_id: str # The identifier of the change request., data: map{attributes!: map, type!: str} # Data object to create a change request branch.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, change_request_linked_incident_uuid: str, change_request_maintenance_window_query: str, change_request_plan: str, change_request_risk: str, change_request_type: str, closed_at: str(date-time)?, created_at: str(date-time), creation_source: str, description: str, end_date: str(date-time), key: str, modified_at: str(date-time), plan_notebook_id: int(int64), priority: str, project_id: str, start_date: str(date-time), status: str, title: str, type: str}, id: str, relationships: map{change_request_decisions: map{data: [map]}, created_by: map{data: map?}, modified_by: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"branch_name\":\"chm/CHM-1234\",\"repo_id\":\"DataDog/test-repo\"},\"type\":\"change_request_branch\"}}\n\n@endpoint DELETE /api/v2/change-management/change-request/{change_request_id}/decisions/{decision_id}\n@desc Delete a change request decision\n@required {change_request_id: str # The identifier of the change request., decision_id: str # The identifier of the change request decision.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, change_request_linked_incident_uuid: str, change_request_maintenance_window_query: str, change_request_plan: str, change_request_risk: str, change_request_type: str, closed_at: str(date-time)?, created_at: str(date-time), creation_source: str, description: str, end_date: str(date-time), key: str, modified_at: str(date-time), plan_notebook_id: int(int64), priority: str, project_id: str, start_date: str(date-time), status: str, title: str, type: str}, id: str, relationships: map{change_request_decisions: map{data: [map]}, created_by: map{data: map?}, modified_by: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/change-management/change-request/{change_request_id}/decisions/{decision_id}\n@desc Update a change request decision\n@required {change_request_id: str # The identifier of the change request., decision_id: str # The identifier of the change request decision., data: map{attributes: map, relationships: map, type!: str} # Data object to update a change request decision.}\n@optional {included: [map{attributes: map, id!: str, relationships: map, type!: str}] # Included resources for the change request update.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, attributes: map, change_request_linked_incident_uuid: str, change_request_maintenance_window_query: str, change_request_plan: str, change_request_risk: str, change_request_type: str, closed_at: str(date-time)?, created_at: str(date-time), creation_source: str, description: str, end_date: str(date-time), key: str, modified_at: str(date-time), plan_notebook_id: int(int64), priority: str, project_id: str, start_date: str(date-time), status: str, title: str, type: str}, id: str, relationships: map{change_request_decisions: map{data: [map]}, created_by: map{data: map?}, modified_by: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"id\":\"CHM-1234\"},\"relationships\":{\"change_request_decisions\":{\"data\":[{\"id\":\"decision-id-0\"}]}},\"type\":\"change_request\"},\"included\":[{\"attributes\":{\"change_request_status\":\"REQUESTED\",\"request_reason\":\"Please review and approve this change\"},\"id\":\"decision-id-0\",\"type\":\"change_request_decision\"}]}\n\n@endpoint GET /api/v2/ci/github/accounts\n@desc List GitHub CI Visibility status\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/ci/github/accounts\n@desc Update GitHub CI Visibility status\n@required {data: map{attributes!: map, type!: str} # Data object for updating a GitHub account's CI Visibility opt-in status.}\n@returns(200) {data: map{attributes: map{account: str, enabled: bool, host: str, repo_count: int(int64), repositories: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"account\":\"datadog\",\"enabled\":true,\"host\":\"github.com\",\"repository\":{\"enabled\":true,\"name\":\"shopist\"}},\"type\":\"ci_github_account\"}}\n\n@endpoint POST /api/v2/ci/pipeline\n@desc Send pipeline event\n@optional {data: any # Data of the pipeline events to create.}\n@returns(202) Request accepted for processing\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 408: Request Timeout, 413: Payload Too Large, 429: Too Many Requests, 500: Internal Server Error, 503: Service Unavailable}\n@example_request {\"data\":{\"attributes\":{\"resource\":{\"end\":\"2024-11-25T20:08:11.018Z\",\"git\":{\"author_email\":\"john.doe@email.com\",\"repository_url\":\"https://github.com/organization/example-repository\",\"sha\":\"7f263865994b76066c4612fd1965215e7dcb4cd2\"},\"level\":\"pipeline\",\"name\":\"Deploy to AWS\",\"partial_retry\":false,\"start\":\"2024-11-25T20:06:41.018Z\",\"status\":\"success\",\"unique_id\":\"3eacb6f3-ff04-4e10-8a9c-46e6d054024a\",\"url\":\"https://my-ci-provider.example/pipelines/my-pipeline/run/1\"}},\"type\":\"cipipeline_resource_request\"}}\n\n@endpoint POST /api/v2/ci/pipelines/analytics/aggregate\n@desc Aggregate pipelines events\n@optional {compute: [map{aggregation!: str, interval: str, metric: str, type: str}] # The list of metrics or timeseries to compute for the retrieved buckets., filter: map{from: str, query: str, to: str} # The search and filter query settings., group_by: [map{facet!: str, histogram: map, limit: int(int64), missing: any, sort: map, total: any}] # The rules for the group-by., options: map{time_offset: int(int64), timezone: str} # Global query options that are used during the query. Only supply timezone or time offset, not both. Otherwise, the query fails.}\n@returns(200) {data: map{buckets: [map]}, links: map{next: str}, meta: map{elapsed: int(int64), request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"compute\":[{\"aggregation\":\"pc90\",\"interval\":\"5m\",\"metric\":\"@duration\",\"type\":\"timeseries\"}],\"filter\":{\"from\":\"now-15m\",\"query\":\"@ci.provider.name:github AND @ci.status:error\",\"to\":\"now\"},\"group_by\":[{\"facet\":\"@ci.status\",\"histogram\":{\"interval\":10,\"max\":100,\"min\":50},\"sort\":{\"aggregation\":\"count\",\"order\":\"asc\"}}],\"options\":{\"timezone\":\"GMT\"}}\n\n@endpoint GET /api/v2/ci/pipelines/events\n@desc Get a list of pipelines events\n@optional {filter[query]: str: any # Search query following log syntax., filter[from]: str(date-time) # Minimum timestamp for requested events., filter[to]: str(date-time) # Maximum timestamp for requested events., sort: str # Order of events in results., page[cursor]: str # List following results with a cursor provided in the previous query., page[limit]: int(int32)=10 # Maximum number of events in the response.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/ci/pipelines/events/search\n@desc Search pipelines events\n@optional {filter: map{from: str, query: str, to: str} # The search and filter query settings., options: map{time_offset: int(int64), timezone: str} # Global query options that are used during the query. Only supply timezone or time offset, not both. Otherwise, the query fails., page: map{cursor: str, limit: int(int32)} # Paging attributes for listing events., sort: str(timestamp/-timestamp) # Sort parameters when querying events.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"filter\":{\"from\":\"now-15m\",\"query\":\"@ci.provider.name:github AND @ci.status:error\",\"to\":\"now\"},\"options\":{\"timezone\":\"GMT\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\",\"limit\":25},\"sort\":\"timestamp\"}\n\n@endpoint PATCH /api/v2/ci/test-optimization/settings/policies\n@desc Update Flaky Tests Management policies\n@required {data: map{attributes!: map, type!: str} # Data object for update Flaky Tests Management policies request.}\n@returns(200) {data: map{attributes: map{attempt_to_fix: map{retries: int(int64)}, disabled: map{auto_disable_rule: map, branch_rule: map, enabled: bool, failure_rate_rule: map}, quarantined: map{auto_quarantine_rule: map, branch_rule: map, enabled: bool, failure_rate_rule: map}, repository_id: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"attempt_to_fix\":{\"retries\":3},\"disabled\":{\"enabled\":false},\"quarantined\":{\"auto_quarantine_rule\":{\"enabled\":true,\"window_seconds\":3600},\"branch_rule\":{\"branches\":[\"main\"],\"enabled\":true,\"excluded_branches\":[],\"excluded_test_services\":[]},\"enabled\":true,\"failure_rate_rule\":{\"branches\":[\"main\"],\"enabled\":true,\"min_runs\":10,\"threshold\":0.5}},\"repository_id\":\"github.com/example-org/example-repo\"},\"type\":\"test_optimization_update_flaky_tests_management_policies_request\"}}\n\n@endpoint POST /api/v2/ci/test-optimization/settings/policies\n@desc Get Flaky Tests Management policies\n@required {data: map{attributes!: map, type!: str} # Data object for get Flaky Tests Management policies request.}\n@returns(200) {data: map{attributes: map{attempt_to_fix: map{retries: int(int64)}, disabled: map{auto_disable_rule: map, branch_rule: map, enabled: bool, failure_rate_rule: map}, quarantined: map{auto_quarantine_rule: map, branch_rule: map, enabled: bool, failure_rate_rule: map}, repository_id: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"repository_id\":\"github.com/example-org/example-repo\"},\"type\":\"test_optimization_get_flaky_tests_management_policies_request\"}}\n\n@endpoint DELETE /api/v2/ci/test-optimization/settings/service\n@desc Delete Test Optimization service settings\n@required {data: map{attributes!: map, type!: str} # Data object for delete service settings request.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"env\":\"prod\",\"repository_id\":\"github.com/datadog/test-service\",\"service_name\":\"test-service\"},\"type\":\"test_optimization_delete_service_settings_request\"}}\n\n@endpoint PATCH /api/v2/ci/test-optimization/settings/service\n@desc Update Test Optimization service settings\n@required {data: map{attributes!: map, type!: str} # Data object for update service settings request.}\n@returns(200) {data: map{attributes: map{auto_test_retries_enabled: bool, auto_test_retries_enabled_is_overridden: bool, code_coverage_enabled: bool, code_coverage_enabled_is_overridden: bool, early_flake_detection_enabled: bool, early_flake_detection_enabled_is_overridden: bool, env: str, failed_test_replay_enabled: bool, failed_test_replay_enabled_is_overridden: bool, pr_comments_enabled: bool, repository_id: str, service_name: str, test_impact_analysis_enabled: bool, test_impact_analysis_enabled_is_overridden: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"env\":\"prod\",\"repository_id\":\"github.com/datadog/test-service\",\"service_name\":\"test-service\",\"test_impact_analysis_enabled_inherit\":true},\"type\":\"test_optimization_update_service_settings_request\"}}\n\n@endpoint POST /api/v2/ci/test-optimization/settings/service\n@desc Get Test Optimization service settings\n@required {data: map{attributes!: map, type!: str} # Data object for get service settings request.}\n@returns(200) {data: map{attributes: map{auto_test_retries_enabled: bool, auto_test_retries_enabled_is_overridden: bool, code_coverage_enabled: bool, code_coverage_enabled_is_overridden: bool, early_flake_detection_enabled: bool, early_flake_detection_enabled_is_overridden: bool, env: str, failed_test_replay_enabled: bool, failed_test_replay_enabled_is_overridden: bool, pr_comments_enabled: bool, repository_id: str, service_name: str, test_impact_analysis_enabled: bool, test_impact_analysis_enabled_is_overridden: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"env\":\"prod\",\"repository_id\":\"github.com/datadog/test-service\",\"service_name\":\"test-service\"},\"type\":\"test_optimization_get_service_settings_request\"}}\n\n@endpoint POST /api/v2/ci/tests/analytics/aggregate\n@desc Aggregate tests events\n@optional {compute: [map{aggregation!: str, interval: str, metric: str, type: str}] # The list of metrics or timeseries to compute for the retrieved buckets., filter: map{from: str, query: str, to: str} # The search and filter query settings., group_by: [map{facet!: str, histogram: map, limit: int(int64), missing: any, sort: map, total: any}] # The rules for the group-by., options: map{time_offset: int(int64), timezone: str} # Global query options that are used during the query. Only supply timezone or time offset, not both. Otherwise, the query fails.}\n@returns(200) {data: map{buckets: [map]}, links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"compute\":[{\"aggregation\":\"pc90\",\"interval\":\"5m\",\"metric\":\"@duration\",\"type\":\"timeseries\"}],\"filter\":{\"from\":\"now-15m\",\"query\":\"@test.service:web-tests AND @test.status:fail\",\"to\":\"now\"},\"group_by\":[{\"facet\":\"@test.service\",\"histogram\":{\"interval\":10,\"max\":100,\"min\":50},\"sort\":{\"aggregation\":\"count\",\"order\":\"asc\"}}],\"options\":{\"timezone\":\"GMT\"}}\n\n@endpoint GET /api/v2/ci/tests/events\n@desc Get a list of tests events\n@optional {filter[query]: str: any # Search query following log syntax., filter[from]: str(date-time) # Minimum timestamp for requested events., filter[to]: str(date-time) # Maximum timestamp for requested events., sort: str # Order of events in results., page[cursor]: str # List following results with a cursor provided in the previous query., page[limit]: int(int32)=10 # Maximum number of events in the response.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/ci/tests/events/search\n@desc Search tests events\n@optional {filter: map{from: str, query: str, to: str} # The search and filter query settings., options: map{time_offset: int(int64), timezone: str} # Global query options that are used during the query. Only supply timezone or time offset, not both. Otherwise, the query fails., page: map{cursor: str, limit: int(int32)} # Paging attributes for listing events., sort: str(timestamp/-timestamp) # Sort parameters when querying events.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"filter\":{\"from\":\"now-15m\",\"query\":\"@test.service:web-tests AND @test.status:fail\",\"to\":\"now\"},\"options\":{\"timezone\":\"GMT\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\",\"limit\":25},\"sort\":\"timestamp\"}\n\n@endpoint GET /api/v2/cloud_auth/aws/persona_mapping\n@desc List AWS cloud authentication persona mappings\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/cloud_auth/aws/persona_mapping\n@desc Create an AWS cloud authentication persona mapping\n@required {data: map{attributes!: map, type!: str} # Data for creating an AWS cloud authentication persona mapping}\n@returns(201) {data: map{attributes: map{account_identifier: str, account_uuid: str, arn_pattern: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"account_identifier\":\"test@test.com\",\"arn_pattern\":\"arn:aws:iam::123456789012:user/testuser\"},\"type\":\"aws_cloud_auth_config\"}}\n\n@endpoint DELETE /api/v2/cloud_auth/aws/persona_mapping/{persona_mapping_id}\n@desc Delete an AWS cloud authentication persona mapping\n@required {persona_mapping_id: str # The ID of the persona mapping}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cloud_auth/aws/persona_mapping/{persona_mapping_id}\n@desc Get an AWS cloud authentication persona mapping\n@required {persona_mapping_id: str # The ID of the persona mapping}\n@returns(200) {data: map{attributes: map{account_identifier: str, account_uuid: str, arn_pattern: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/cloud_security_management/custom_frameworks\n@desc Create a custom framework\n@required {data: map{attributes!: map, type!: str} # Contains type and attributes for custom frameworks.}\n@returns(200) {data: map{attributes: map{handle: str, version: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 409: Conflict, 429: Too many requests, 500: Bad Request}\n@example_request {\"data\":{\"attributes\":{\"handle\":\"sec2\",\"name\":\"security-framework\",\"requirements\":[{\"controls\":[{\"name\":\"control\",\"rules_id\":[\"def-000-be9\"]}],\"name\":\"criteria\"}],\"version\":\"2\"},\"type\":\"custom_framework\"}}\n\n@endpoint DELETE /api/v2/cloud_security_management/custom_frameworks/{handle}/{version}\n@desc Delete a custom framework\n@required {handle: str # The framework handle, version: str # The framework version}\n@returns(200) {data: map{attributes: map{description: str, handle: str, icon_url: str, name: str, version: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests, 500: Bad Request}\n\n@endpoint GET /api/v2/cloud_security_management/custom_frameworks/{handle}/{version}\n@desc Get a custom framework\n@required {handle: str # The framework handle, version: str # The framework version}\n@returns(200) {data: map{attributes: map{handle: str, icon_url: str, name: str, requirements: [map], version: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests, 500: Bad Request}\n\n@endpoint PUT /api/v2/cloud_security_management/custom_frameworks/{handle}/{version}\n@desc Update a custom framework\n@required {handle: str # The framework handle, version: str # The framework version, data: map{attributes!: map, type!: str} # Contains type and attributes for custom frameworks.}\n@returns(200) {data: map{attributes: map{handle: str, version: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests, 500: Bad Request}\n@example_request {\"data\":{\"attributes\":{\"handle\":\"sec2\",\"name\":\"security-framework\",\"requirements\":[{\"controls\":[{\"name\":\"control\",\"rules_id\":[\"def-000-be9\"]}],\"name\":\"criteria\"}],\"version\":\"2\"},\"type\":\"custom_framework\"}}\n\n@endpoint GET /api/v2/cloud_security_management/resource_filters\n@desc List resource filters\n@optional {cloud_provider: str # Filter resource filters by cloud provider (e.g. aws, gcp, azure)., account_id: str # Filter resource filters by cloud provider account ID. This parameter is only valid when provider is specified., skip_cache: bool # Skip cache for resource filters.}\n@returns(200) {data: map{attributes: map{cloud_provider: map, uuid: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint PUT /api/v2/cloud_security_management/resource_filters\n@desc Update resource filters\n@required {data: map{attributes!: map, id: str, type!: str} # The definition of `UpdateResourceFilterRequestData` object.}\n@returns(201) {data: map{attributes: map{cloud_provider: map, uuid: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"aws\":{\"123456789\":[\"environment:production\",\"team:devops\"]},\"azure\":{\"sub-001\":[\"app:frontend\"]},\"gcp\":{\"project-abc\":[\"region:us-central1\"]}},\"id\":\"csm_resource_filter\",\"type\":\"csm_resource_filter\"}}\n\n@endpoint PUT /api/v2/cloudinventoryservice/syncconfigs\n@desc Enable Storage Management for a bucket\n@required {data: map{attributes!: map, id!: str, type!: str} # Storage Management configuration data for the create or update request.}\n@returns(200) {data: map{attributes: map{aws_account_id: str, aws_bucket_name: str, aws_region: str, azure_client_id: str, azure_container_name: str, azure_storage_account_name: str, azure_tenant_id: str, cloud_provider: str, error: str, error_code: str, gcp_bucket_name: str, gcp_project_id: str, gcp_service_account_email: str, prefix: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"aws\":{\"aws_account_id\":\"123456789012\",\"destination_bucket_name\":\"my-inventory-bucket\",\"destination_bucket_region\":\"us-east-1\",\"destination_prefix\":\"logs/\"}},\"id\":\"aws\",\"type\":\"cloud_provider\"}}\n\n@endpoint DELETE /api/v2/cloudinventoryservice/syncconfigs/{id}\n@desc Delete a Storage Management configuration\n@required {id: str # Unique identifier of the Storage Management configuration.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/code-coverage/branch/summary\n@desc Get code coverage summary for a branch\n@required {data: map{attributes!: map, type!: str} # Data object for branch summary request.}\n@returns(200) {data: map{attributes: map{codeowners: map?, evaluated_flags_count: int(int64), evaluated_reports_count: int(int64), patch_coverage: num(double)?, services: map?, total_coverage: num(double)?}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests, 500: Internal server error}\n@example_request {\"data\":{\"attributes\":{\"branch\":\"prod\",\"repository_url\":\"https://github.com/datadog/test-service\"},\"type\":\"ci_app_coverage_branch_summary_request\"}}\n\n@endpoint POST /api/v2/code-coverage/commit/summary\n@desc Get code coverage summary for a commit\n@required {data: map{attributes!: map, type!: str} # Data object for commit summary request.}\n@returns(200) {data: map{attributes: map{codeowners: map?, evaluated_flags_count: int(int64), evaluated_reports_count: int(int64), patch_coverage: num(double)?, services: map?, total_coverage: num(double)?}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests, 500: Internal server error}\n@example_request {\"data\":{\"attributes\":{\"commit_sha\":\"66adc9350f2cc9b250b69abddab733dd55e1a588\",\"repository_url\":\"https://github.com/datadog/test-service\"},\"type\":\"ci_app_coverage_commit_summary_request\"}}\n\n@endpoint GET /api/v2/compliance_findings/rule_based_view\n@desc Get the rule-based view of compliance findings\n@required {to: int(int64) # Timestamp of the query end, in milliseconds since the Unix epoch.}\n@optional {framework: str= # Compliance framework handle to filter rules and findings by., version: str # Version of the compliance framework to filter rules and findings by., query_findings_without_framework_version: bool=false # When `true`, returns findings without a `framework_version` tag. Used for findings from custom frameworks or those created before framework versioning was introduced., include_rules_without_findings: bool=false # When `true`, includes rules in the response that have no associated findings., is_custom: bool # Set to `true` when the requested `framework` is a custom framework., query: str= # Additional event-platform filters applied to the underlying findings query. For example, `scored:true project_id:datadog-prod-us5`.}\n@returns(200) {data: map{attributes: map{count: int(int64), rules: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests, 503: Service Unavailable}\n\n@endpoint GET /api/v2/container_images\n@desc Get all Container Images\n@optional {filter[tags]: str: any # Comma-separated list of tags to filter Container Images by., group_by: str # Comma-separated list of tags to group Container Images by., sort: str # Attribute to sort Container Images by., page[size]: int(int32)=1000 # Maximum number of results returned., page[cursor]: str # String to query the next page of results. This key is provided with each valid response from the API in `meta.pagination.next_cursor`.}\n@returns(200) {data: [any], links: map{first: str, last: str?, next: str?, prev: str?, self: str}, meta: map{pagination: map{cursor: str, limit: int(int32), next_cursor: str, prev_cursor: str?, total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 429: Too many requests}\n\n@endpoint GET /api/v2/containers\n@desc Get All Containers\n@optional {filter[tags]: str: any # Comma-separated list of tags to filter containers by., group_by: str # Comma-separated list of tags to group containers by., sort: str # Attribute to sort containers by., page[size]: int(int32)=1000 # Maximum number of results returned., page[cursor]: str # String to query the next page of results. This key is provided with each valid response from the API in `meta.pagination.next_cursor`.}\n@returns(200) {data: [any], links: map{first: str, last: str?, next: str?, prev: str?, self: str}, meta: map{pagination: map{cursor: str, limit: int(int32), next_cursor: str, prev_cursor: str?, total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/account_filters/{cloud_account_id}\n@desc Get account filters\n@required {cloud_account_id: int(int64) # Cloud Account id.}\n@returns(200) {data: map{attributes: map{account_filters: map{excluded_accounts: [str], include_new_accounts: bool?, included_accounts: [str]}, account_id: str, cloud: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/cost/account_filters/{cloud_account_id}\n@desc Update account filters\n@required {cloud_account_id: int(int64) # Cloud Account id., data: map{attributes!: map, type!: str} # Account filters patch data.}\n@returns(200) {data: map{attributes: map{account_filters: map{excluded_accounts: [str], include_new_accounts: bool?, included_accounts: [str]}, account_id: str, cloud: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"account_filters\":{\"include_new_accounts\":false,\"included_accounts\":[\"123456789123\",\"123456789143\"]}},\"type\":\"account_filters_patch_request\"}}\n\n@endpoint GET /api/v2/cost/anomalies\n@desc List cost anomalies\n@optional {start: int(int64) # Start time as Unix milliseconds. Defaults to the start of the latest stable seven-day window., end: int(int64) # End time as Unix milliseconds. Defaults to the end of the latest stable seven-day window., filter: str # Optional JSON object mapping cost tag keys to allowed values, for example `{\"team\":[\"payments\"],\"env\":[\"prod\"]}`. Filters match anomaly dimensions or correlated tags., min_anomalous_threshold: str # Minimum absolute anomalous cost change to include. Numeric value; defaults to `1`., min_cost_threshold: str # Minimum absolute actual cost to include. Numeric value; defaults to `0`., dismissal_cause: str # Filter by resolution state. Use `none` for unresolved anomalies, `all` or `*` for resolved anomalies, or a comma-separated list of causes., order_by: str # Sort field. One of `start_date`, `end_date`, `duration`, `max_cost`, `anomalous_cost`, or `dismissal_date`. Defaults to `anomalous_cost`., order: str # Sort direction. One of `asc` or `desc`. Defaults to `desc`., limit: int(int64) # Maximum number of anomalies to return. Defaults to `200`., offset: int(int64) # Pagination offset. Defaults to `0`., provider_ids: [str] # Optional repeated cloud or SaaS provider filters, such as `aws`, `gcp`, `azure`, `Oracle`, `datadog`, `OpenAI`, or `Anthropic`.}\n@returns(200) {data: map{attributes: map{anomalies: [map], avg_daily_anomalous_cost: num(double), total_actual_cost: num(double), total_anomalous_cost: num(double), total_count: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/anomalies/{anomaly_id}\n@desc Get cost anomaly\n@required {anomaly_id: str # The UUID of the cost anomaly.}\n@returns(200) {data: map{attributes: map{actual_cost: num(double), anomalous_cost_change: num(double), anomaly_end: int(int64), anomaly_start: int(int64), correlated_tags: map?, dimensions: map, dismissal: map{cause: str, dismissal_id: str, message: str, updated_at: int(int64), updated_by: str}, max_cost: num(double), provider: str, query: str, uuid: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/arbitrary_rule\n@desc List custom allocation rules\n@returns(200) {data: [map], meta: map{total_count: int(int64)}} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/cost/arbitrary_rule\n@desc Create custom allocation rule\n@optional {data: map{attributes: map, id: str, type!: str} # The definition of `ArbitraryCostUpsertRequestData` object.}\n@returns(200) {data: map{attributes: map{costs_to_allocate: [map], created: str(date-time), enabled: bool, last_modified_user_uuid: str, order_id: int(int64), processing_status: str, provider: [str], rejected: bool, rule_name: str, strategy: map{allocated_by: [map], allocated_by_filters: [map], allocated_by_tag_keys: [str], based_on_costs: [map], based_on_timeseries: map, evaluate_grouped_by_filters: [map], evaluate_grouped_by_tag_keys: [str], granularity: str, method: str}, type: str, updated: str(date-time), version: int(int32)}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"costs_to_allocate\":[{\"condition\":\"is\",\"tag\":\"account_id\",\"value\":\"123456789\"},{\"condition\":\"in\",\"tag\":\"environment\",\"value\":\"\",\"values\":[\"production\",\"staging\"]}],\"enabled\":true,\"order_id\":1,\"provider\":[\"aws\",\"gcp\"],\"rule_name\":\"example-arbitrary-cost-rule\",\"strategy\":{\"allocated_by_tag_keys\":[\"team\",\"environment\"],\"based_on_costs\":[{\"condition\":\"is\",\"tag\":\"service\",\"value\":\"web-api\"},{\"condition\":\"not in\",\"tag\":\"team\",\"value\":\"\",\"values\":[\"legacy\",\"deprecated\"]}],\"granularity\":\"daily\",\"method\":\"proportional\"},\"type\":\"shared\"},\"type\":\"upsert_arbitrary_rule\"}}\n\n@endpoint POST /api/v2/cost/arbitrary_rule/reorder\n@desc Reorder custom allocation rules\n@required {data: [map{id: str, type!: str}] # The `ReorderRuleResourceArray` `data`.}\n@returns(204) Successfully reordered rules\n@errors {429: Too many requests}\n@example_request {\"data\":[{\"id\":\"456\",\"type\":\"arbitrary_rule\"},{\"id\":\"123\",\"type\":\"arbitrary_rule\"},{\"id\":\"789\",\"type\":\"arbitrary_rule\"}]}\n\n@endpoint GET /api/v2/cost/arbitrary_rule/status\n@desc List custom allocation rule statuses\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint DELETE /api/v2/cost/arbitrary_rule/{rule_id}\n@desc Delete custom allocation rule\n@required {rule_id: int(int64) # The unique identifier of the custom allocation rule}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/cost/arbitrary_rule/{rule_id}\n@desc Get custom allocation rule\n@required {rule_id: int(int64) # The unique identifier of the custom allocation rule}\n@returns(200) {data: map{attributes: map{costs_to_allocate: [map], created: str(date-time), enabled: bool, last_modified_user_uuid: str, order_id: int(int64), processing_status: str, provider: [str], rejected: bool, rule_name: str, strategy: map{allocated_by: [map], allocated_by_filters: [map], allocated_by_tag_keys: [str], based_on_costs: [map], based_on_timeseries: map, evaluate_grouped_by_filters: [map], evaluate_grouped_by_tag_keys: [str], granularity: str, method: str}, type: str, updated: str(date-time), version: int(int32)}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/cost/arbitrary_rule/{rule_id}\n@desc Update custom allocation rule\n@required {rule_id: int(int64) # The unique identifier of the custom allocation rule}\n@optional {data: map{attributes: map, id: str, type!: str} # The definition of `ArbitraryCostUpsertRequestData` object.}\n@returns(200) {data: map{attributes: map{costs_to_allocate: [map], created: str(date-time), enabled: bool, last_modified_user_uuid: str, order_id: int(int64), processing_status: str, provider: [str], rejected: bool, rule_name: str, strategy: map{allocated_by: [map], allocated_by_filters: [map], allocated_by_tag_keys: [str], based_on_costs: [map], based_on_timeseries: map, evaluate_grouped_by_filters: [map], evaluate_grouped_by_tag_keys: [str], granularity: str, method: str}, type: str, updated: str(date-time), version: int(int32)}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"costs_to_allocate\":[{\"condition\":\"is\",\"tag\":\"account_id\",\"value\":\"123456789\"},{\"condition\":\"in\",\"tag\":\"environment\",\"value\":\"\",\"values\":[\"production\",\"staging\"]}],\"enabled\":true,\"order_id\":1,\"provider\":[\"aws\",\"gcp\"],\"rule_name\":\"example-arbitrary-cost-rule\",\"strategy\":{\"allocated_by_tag_keys\":[\"team\",\"environment\"],\"based_on_costs\":[{\"condition\":\"is\",\"tag\":\"service\",\"value\":\"web-api\"},{\"condition\":\"not in\",\"tag\":\"team\",\"value\":\"\",\"values\":[\"legacy\",\"deprecated\"]}],\"granularity\":\"daily\",\"method\":\"proportional\"},\"type\":\"shared\"},\"type\":\"upsert_arbitrary_rule\"}}\n\n@endpoint GET /api/v2/cost/aws_cur_config\n@desc List Cloud Cost Management AWS CUR configs\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/cost/aws_cur_config\n@desc Create Cloud Cost Management AWS CUR config\n@required {data: map{attributes: map, type!: str} # AWS CUR config Post data.}\n@returns(200) {data: map{attributes: map{account_filters: map{excluded_accounts: [str], include_new_accounts: bool?, included_accounts: [str]}, account_id: str, bucket_name: str, bucket_region: str, created_at: str, error_messages: [str]?, months: int(int64), report_name: str, report_prefix: str, status: str, status_updated_at: str, updated_at: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"account_filters\":{\"excluded_accounts\":[\"123456789123\",\"123456789143\"],\"include_new_accounts\":true,\"included_accounts\":[\"123456789123\",\"123456789143\"]},\"account_id\":\"123456789123\",\"bucket_name\":\"dd-cost-bucket\",\"bucket_region\":\"us-east-1\",\"report_name\":\"dd-report-name\",\"report_prefix\":\"dd-report-prefix\"},\"type\":\"aws_cur_config_post_request\"}}\n\n@endpoint DELETE /api/v2/cost/aws_cur_config/{cloud_account_id}\n@desc Delete Cloud Cost Management AWS CUR config\n@required {cloud_account_id: int(int64) # Cloud Account id.}\n@returns(204) No Content\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/aws_cur_config/{cloud_account_id}\n@desc Get cost AWS CUR config\n@required {cloud_account_id: int(int64) # The unique identifier of the cloud account}\n@returns(200) {data: map{attributes: map{account_filters: map{excluded_accounts: [str], include_new_accounts: bool?, included_accounts: [str]}, account_id: str, bucket_name: str, bucket_region: str, created_at: str, error_messages: [str]?, months: int(int64), report_name: str, report_prefix: str, status: str, status_updated_at: str, updated_at: str}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/cost/aws_cur_config/{cloud_account_id}\n@desc Update Cloud Cost Management AWS CUR config\n@required {cloud_account_id: int(int64) # Cloud Account id., data: map{attributes!: map, type!: str} # AWS CUR config Patch data.}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"account_filters\":{\"excluded_accounts\":[\"123456789123\",\"123456789143\"],\"include_new_accounts\":true,\"included_accounts\":[\"123456789123\",\"123456789143\"]},\"is_enabled\":true},\"type\":\"aws_cur_config_patch_request\"}}\n\n@endpoint GET /api/v2/cost/azure_uc_config\n@desc List Cloud Cost Management Azure configs\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/cost/azure_uc_config\n@desc Create Cloud Cost Management Azure configs\n@required {data: map{attributes: map, type!: str} # Azure config Post data.}\n@returns(200) {data: map{attributes: map{configs: [map], id: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"account_id\":\"1234abcd-1234-abcd-1234-1234abcd1234\",\"actual_bill_config\":{\"export_name\":\"dd-actual-export\",\"export_path\":\"dd-export-path\",\"storage_account\":\"dd-storage-account\",\"storage_container\":\"dd-storage-container\"},\"amortized_bill_config\":{\"export_name\":\"dd-actual-export\",\"export_path\":\"dd-export-path\",\"storage_account\":\"dd-storage-account\",\"storage_container\":\"dd-storage-container\"},\"client_id\":\"1234abcd-1234-abcd-1234-1234abcd1234\",\"scope\":\"/subscriptions/1234abcd-1234-abcd-1234-1234abcd1234\"},\"type\":\"azure_uc_config_post_request\"}}\n\n@endpoint DELETE /api/v2/cost/azure_uc_config/{cloud_account_id}\n@desc Delete Cloud Cost Management Azure config\n@required {cloud_account_id: int(int64) # Cloud Account id.}\n@returns(204) No Content\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/azure_uc_config/{cloud_account_id}\n@desc Get cost Azure UC config\n@required {cloud_account_id: int(int64) # The unique identifier of the cloud account}\n@returns(200) {data: map{attributes: map{configs: [map]}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/cost/azure_uc_config/{cloud_account_id}\n@desc Update Cloud Cost Management Azure config\n@required {cloud_account_id: int(int64) # Cloud Account id., data: map{attributes: map, type!: str} # Azure config Patch data.}\n@returns(200) {data: map{attributes: map{configs: [map], id: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"is_enabled\":true},\"type\":\"azure_uc_config_patch_request\"}}\n\n@endpoint PUT /api/v2/cost/budget\n@desc Create or update a budget\n@optional {data: map{attributes: map, id: str, type: str} # A budget and all its entries.}\n@returns(200) {data: map{attributes: map{costs: map{actual: num(double)?, amount: num(double)?, forecast: num(double)?, ootb_forecast: num(double)?}, costs_period_end: int(int64), costs_period_start: int(int64), costs_unit: map{family: str, id: str, name: str, plural: str, scale_factor: num(double), short_name: str}, created_at: int(int64), created_by: str, end_month: int(int64), entries: [map], metrics_query: str, name: str, org_id: int(int64), start_month: int(int64), total_amount: num(double), updated_at: int(int64), updated_by: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"created_at\":1738258683590,\"created_by\":\"00000000-0a0a-0a0a-aaa0-00000000000a\",\"end_month\":202502,\"metrics_query\":\"aws.cost.amortized{service:ec2} by {service}\",\"name\":\"my budget\",\"org_id\":123,\"start_month\":202501,\"total_amount\":1000,\"updated_at\":1738258683590,\"updated_by\":\"00000000-0a0a-0a0a-aaa0-00000000000a\"},\"id\":\"00000000-0a0a-0a0a-aaa0-00000000000a\",\"type\":\"\"}}\n\n@endpoint POST /api/v2/cost/budget/csv/validate\n@desc Validate CSV budget\n@returns(200) {errors: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint PUT /api/v2/cost/budget/custom-forecast\n@desc Create or replace a budget's custom forecast\n@required {data: map{attributes!: map, id: str, type!: str} # Custom forecast resource wrapper in an upsert request.}\n@returns(200) {data: map{attributes: map{budget_uid: str, created_at: int(int64), created_by: str, entries: [map], updated_at: int(int64), updated_by: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"budget_uid\":\"00000000-0000-0000-0000-000000000001\",\"entries\":[{\"amount\":400,\"month\":202501,\"tag_filters\":[{\"tag_key\":\"service\",\"tag_value\":\"ec2\"}]},{\"amount\":450,\"month\":202502,\"tag_filters\":[{\"tag_key\":\"service\",\"tag_value\":\"ec2\"}]}]},\"id\":\"\",\"type\":\"custom_forecast\"}}\n\n@endpoint POST /api/v2/cost/budget/validate\n@desc Validate budget\n@optional {data: map{attributes: map, id: str, type!: str} # The data object for a budget validation request, containing the resource type, ID, and budget attributes to validate.}\n@returns(200) {data: map{attributes: map{errors: [str], valid: bool}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"created_at\":1738258683590,\"created_by\":\"00000000-0a0a-0a0a-aaa0-00000000000a\",\"end_month\":202502,\"entries\":[{\"amount\":500,\"month\":202501,\"tag_filters\":[{\"tag_key\":\"service\",\"tag_value\":\"ec2\"}]},{\"amount\":500,\"month\":202502,\"tag_filters\":[{\"tag_key\":\"service\",\"tag_value\":\"ec2\"}]}],\"metrics_query\":\"aws.cost.amortized{service:ec2} by {service}\",\"name\":\"my budget\",\"org_id\":123,\"start_month\":202501,\"total_amount\":1000,\"updated_at\":1738258683590,\"updated_by\":\"00000000-0a0a-0a0a-aaa0-00000000000a\"},\"id\":\"1\",\"type\":\"budget\"}}\n\n@endpoint DELETE /api/v2/cost/budget/{budget_id}\n@desc Delete budget\n@required {budget_id: str # Budget id.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/cost/budget/{budget_id}\n@desc Get budget\n@required {budget_id: str # Budget id.}\n@optional {actual: bool # When `true`, includes actual cost data in the response., forecast: bool # When `true`, includes forecast cost data in the response, including `ootb_forecast` and `custom_forecast` per entry., start: int(int64) # Start of the cost window in milliseconds since epoch. Must be used together with `end`., end: int(int64) # End of the cost window in milliseconds since epoch. Must be used together with `start`.}\n@returns(200) {data: map{attributes: map{costs: map{actual: num(double)?, amount: num(double)?, forecast: num(double)?, ootb_forecast: num(double)?}, costs_period_end: int(int64), costs_period_start: int(int64), costs_unit: map{family: str, id: str, name: str, plural: str, scale_factor: num(double), short_name: str}, created_at: int(int64), created_by: str, end_month: int(int64), entries: [map], metrics_query: str, name: str, org_id: int(int64), start_month: int(int64), total_amount: num(double), updated_at: int(int64), updated_by: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/cost/budget/{budget_id}/custom-forecast\n@desc Delete a budget's custom forecast\n@required {budget_id: str # Budget id.}\n@returns(204) No Content\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/budget/{budget_id}/custom-forecast\n@desc Get a budget's custom forecast\n@required {budget_id: str # Budget id.}\n@returns(200) {data: map{attributes: map{budget_uid: str, created_at: int(int64), created_by: str, entries: [map], updated_at: int(int64), updated_by: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/budgets\n@desc List budgets\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/cost/commitments/commitment-list\n@desc Get commitments list\n@required {provider: str # Cloud provider for commitment programs (aws or azure)., product: str # Cloud product identifier (for example, ec2, rds, virtualmachines)., start: int(int64) # Start of the query time range in Unix milliseconds., end: int(int64) # End of the query time range in Unix milliseconds.}\n@optional {filterBy: str # Optional filter expression to narrow down results., commitmentType: str # Type of commitment to query. ri for Reserved Instances, sp for Savings Plans. Defaults to ri.}\n@returns(200) {commitments: [any], meta: map{committed_spend_unit: map{family: str, id: int(int64), name: str, plural: str, scale_factor: num(double), short_name: str}}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/commitments/coverage/scalar\n@desc Get commitments coverage (scalar)\n@required {provider: str # Cloud provider for commitment programs (aws or azure)., product: str # Cloud product identifier (for example, ec2, rds, virtualmachines)., start: int(int64) # Start of the query time range in Unix milliseconds., end: int(int64) # End of the query time range in Unix milliseconds.}\n@optional {filterBy: str # Optional filter expression to narrow down results.}\n@returns(200) {columns: [map]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/commitments/coverage/timeseries\n@desc Get commitments coverage (timeseries)\n@required {provider: str # Cloud provider for commitment programs (aws or azure)., product: str # Cloud product identifier (for example, ec2, rds, virtualmachines)., start: int(int64) # Start of the query time range in Unix milliseconds., end: int(int64) # End of the query time range in Unix milliseconds.}\n@optional {filterBy: str # Optional filter expression to narrow down results.}\n@returns(200) {cost: map{series: map, times: [int(int64)], unit: map{family: str, id: int(int64), name: str, plural: str, scale_factor: num(double), short_name: str}}, hours: map{series: map, times: [int(int64)], unit: map{family: str, id: int(int64), name: str, plural: str, scale_factor: num(double), short_name: str}}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/commitments/on-demand-hot-spots/scalar\n@desc Get commitments on-demand hot spots (scalar)\n@required {provider: str # Cloud provider for commitment programs (aws or azure)., product: str # Cloud product identifier (for example, ec2, rds, virtualmachines)., start: int(int64) # Start of the query time range in Unix milliseconds., end: int(int64) # End of the query time range in Unix milliseconds.}\n@optional {filterBy: str # Optional filter expression to narrow down results.}\n@returns(200) {columns: [map], meta: map{on_demand_filters: str}, total: [map]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/commitments/savings/scalar\n@desc Get commitments savings (scalar)\n@required {provider: str # Cloud provider for commitment programs (aws or azure)., product: str # Cloud product identifier (for example, ec2, rds, virtualmachines)., start: int(int64) # Start of the query time range in Unix milliseconds., end: int(int64) # End of the query time range in Unix milliseconds.}\n@optional {filterBy: str # Optional filter expression to narrow down results.}\n@returns(200) {columns: [map]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/commitments/savings/timeseries\n@desc Get commitments savings (timeseries)\n@required {provider: str # Cloud provider for commitment programs (aws or azure)., product: str # Cloud product identifier (for example, ec2, rds, virtualmachines)., start: int(int64) # Start of the query time range in Unix milliseconds., end: int(int64) # End of the query time range in Unix milliseconds.}\n@optional {filterBy: str # Optional filter expression to narrow down results.}\n@returns(200) {actual_cost: map{series: map, times: [int(int64)], unit: map{family: str, id: int(int64), name: str, plural: str, scale_factor: num(double), short_name: str}}, effective_savings_rate: map{series: map, times: [int(int64)], unit: map{family: str, id: int(int64), name: str, plural: str, scale_factor: num(double), short_name: str}}, on_demand_equivalent_cost: map{series: map, times: [int(int64)], unit: map{family: str, id: int(int64), name: str, plural: str, scale_factor: num(double), short_name: str}}, realized_savings: map{series: map, times: [int(int64)], unit: map{family: str, id: int(int64), name: str, plural: str, scale_factor: num(double), short_name: str}}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/commitments/utilization/scalar\n@desc Get commitments utilization (scalar)\n@required {provider: str # Cloud provider for commitment programs (aws or azure)., product: str # Cloud product identifier (for example, ec2, rds, virtualmachines)., start: int(int64) # Start of the query time range in Unix milliseconds., end: int(int64) # End of the query time range in Unix milliseconds.}\n@optional {filterBy: str # Optional filter expression to narrow down results., commitmentType: str # Type of commitment to query. ri for Reserved Instances, sp for Savings Plans. Defaults to ri.}\n@returns(200) {columns: [map], product_breakdown: [map]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/commitments/utilization/timeseries\n@desc Get commitments utilization (timeseries)\n@required {provider: str # Cloud provider for commitment programs (aws or azure)., product: str # Cloud product identifier (for example, ec2, rds, virtualmachines)., start: int(int64) # Start of the query time range in Unix milliseconds., end: int(int64) # End of the query time range in Unix milliseconds.}\n@optional {filterBy: str # Optional filter expression to narrow down results., commitmentType: str # Type of commitment to query. ri for Reserved Instances, sp for Savings Plans. Defaults to ri.}\n@returns(200) {series: map, times: [int(int64)], unit: map{family: str, id: int(int64), name: str, plural: str, scale_factor: num(double), short_name: str}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/custom_costs\n@desc List Custom Costs files\n@optional {page[number]: int(int64): any # Page number for pagination, page[size]: int(int64)=100 # Page size for pagination, filter[status]: str # Filter by file status, filter[name]: str # Filter files by name with case-insensitive substring matching., filter[provider]: [str] # Filter by provider., sort: str=created_at # Sort key with optional descending prefix}\n@returns(200) {data: [map], meta: map{count_by_status: map, providers: [str], total_filtered_count: int(int64), version: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint PUT /api/v2/cost/custom_costs\n@desc Upload Custom Costs file\n@returns(202) {data: map{attributes: map{billed_cost: num(double), billing_currency: str, charge_period: map{end: num(double), start: num(double)}, name: str, provider_names: [str], status: str, uploaded_at: num(double), uploaded_by: map{email: str, icon: str, name: str}}, id: str, type: str}, meta: map{version: str}} # Accepted\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request [{\"BilledCost\":100.5,\"BillingCurrency\":\"USD\",\"ChargeDescription\":\"Monthly usage charge for my service\",\"ChargePeriodEnd\":\"2023-02-28\",\"ChargePeriodStart\":\"2023-02-01\"}]\n\n@endpoint DELETE /api/v2/cost/custom_costs/{file_id}\n@desc Delete Custom Costs file\n@required {file_id: str # File ID.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/custom_costs/{file_id}\n@desc Get Custom Costs file\n@required {file_id: str # File ID.}\n@returns(200) {data: map{attributes: map{billed_cost: num(double), billing_currency: str, charge_period: map{end: num(double), start: num(double)}, content: [map], name: str, provider_names: [str], status: str, uploaded_at: num(double), uploaded_by: map{email: str, icon: str, name: str}}, id: str, type: str}, meta: map{version: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/gcp_uc_config\n@desc List Google Cloud Usage Cost configs\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/cost/gcp_uc_config\n@desc Create Google Cloud Usage Cost config\n@required {data: map{attributes: map, type!: str} # Google Cloud Usage Cost config post data.}\n@returns(200) {data: map{attributes: map{account_id: str, bucket_name: str, created_at: str, dataset: str, error_messages: [str]?, export_prefix: str, export_project_name: str, months: int(int32), project_id: str, service_account: str, status: str, status_updated_at: str, updated_at: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"billing_account_id\":\"123456_A123BC_12AB34\",\"bucket_name\":\"dd-cost-bucket\",\"export_dataset_name\":\"billing\",\"export_prefix\":\"datadog_cloud_cost_usage_export\",\"export_project_name\":\"dd-cloud-cost-report\",\"service_account\":\"dd-ccm-gcp-integration@my-environment.iam.gserviceaccount.com\"},\"type\":\"gcp_uc_config_post_request\"}}\n\n@endpoint DELETE /api/v2/cost/gcp_uc_config/{cloud_account_id}\n@desc Delete Google Cloud Usage Cost config\n@required {cloud_account_id: int(int64) # Cloud Account id.}\n@returns(204) No Content\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/gcp_uc_config/{cloud_account_id}\n@desc Get Google Cloud Usage Cost config\n@required {cloud_account_id: int(int64) # The unique identifier of the cloud account}\n@returns(200) {data: map{attributes: map{account_id: str, bucket_name: str, created_at: str, dataset: str, error_messages: [str]?, export_prefix: str, export_project_name: str, months: int(int64), project_id: str, service_account: str, status: str, status_updated_at: str, updated_at: str}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/cost/gcp_uc_config/{cloud_account_id}\n@desc Update Google Cloud Usage Cost config\n@required {cloud_account_id: int(int64) # Cloud Account id., data: map{attributes!: map, type!: str} # Google Cloud Usage Cost config patch data.}\n@returns(200) {data: map{attributes: map{account_id: str, bucket_name: str, created_at: str, dataset: str, error_messages: [str]?, export_prefix: str, export_project_name: str, months: int(int32), project_id: str, service_account: str, status: str, status_updated_at: str, updated_at: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"is_enabled\":true},\"type\":\"gcp_uc_config_patch_request\"}}\n\n@endpoint GET /api/v2/cost/oci_config\n@desc List Cloud Cost Management OCI configs\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/cost/recommendations\n@desc Search cost recommendations\n@optional {page[size]: str: any # Number of results per page (1–10000)., page[token]: str # Pagination token from a previous response., filter: str # Filter expression applied to the recommendations., sort: [map{expression: str, order: str}] # Ordered list of sort clauses applied to the result set., view: str # Active view name (for example, `active`, `dismissed`, `open`, `in-progress`, or `completed`).}\n@returns(200) {data: [map], meta: map{page: map{filter: str, next_page_token: str, page_size: int(int32), page_token: str}}} # OK\n@errors {429: Too many requests}\n@example_request {\"filter\":\"@resource_table:aws_ec2_instance\",\"sort\":[{\"expression\":\"potential_daily_savings.amount\",\"order\":\"DESC\"}]}\n\n@endpoint GET /api/v2/cost/tag_descriptions\n@desc List Cloud Cost Management tag descriptions\n@optional {filter[cloud]: str: any # Filter descriptions to a specific cloud provider (for example, `aws`). Omit to return descriptions across all clouds.}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint DELETE /api/v2/cost/tag_descriptions/{tag_key}\n@desc Delete a Cloud Cost Management tag description\n@required {tag_key: str # The tag key whose description is being deleted.}\n@optional {cloud: str # Cloud provider to scope the deletion to (for example, `aws`). Omit to delete every description for the tag key.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/tag_descriptions/{tag_key}\n@desc Get a Cloud Cost Management tag description\n@required {tag_key: str # The tag key whose description is being fetched.}\n@optional {filter[cloud]: str: any # Cloud provider to scope the lookup to (for example, `aws`). Omit to use the resolved fallback.}\n@returns(200) {data: map{attributes: map{cloud: str, created_at: str, description: str, source: str, tag_key: str, updated_at: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/cost/tag_descriptions/{tag_key}\n@desc Upsert a Cloud Cost Management tag description\n@required {tag_key: str # The tag key whose description is being upserted., data: map{attributes!: map, id: str, type!: str} # Resource envelope carrying the tag key description being upserted. The `id` is informational; the authoritative tag key is taken from the URL path.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"cloud\":\"aws\",\"description\":\"AWS account that owns this cost.\"},\"id\":\"account_id\",\"type\":\"cost_tag_description\"}}\n\n@endpoint GET /api/v2/cost/tag_descriptions/{tag_key}/generate\n@desc Generate a Cloud Cost Management tag description\n@required {tag_key: str # The tag key to generate an AI description for.}\n@returns(200) {data: map{attributes: map{description: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/tag_keys\n@desc List Cloud Cost Management tag keys\n@optional {filter[metric]: str: any # The Cloud Cost Management metric to scope the tag keys to. When omitted, returns tag keys across all metrics., filter[tags]: [str] # Filter to return only tag keys that appear with the given `key:value` tag values. For example, `filter[tags]=providername:aws` returns tag keys found on the same cost data, such as `is_aws_ec2_compute` and `aws_instance_type`.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/tag_keys/{tag_key}\n@desc Get a Cloud Cost Management tag key\n@required {tag_key: str # The Cloud Cost Management tag key. Tag keys can contain forward slashes (for example, `kubernetes/instance`).}\n@optional {filter[metric]: str: any # The Cloud Cost Management metric to scope the tag key details to. When omitted, returns details across all metrics., page[size]: int(int32)=50 # Controls the size of the internal tag value search scope. This does **not** restrict the number of example tag values returned in the response. Defaults to 50, maximum 10000.}\n@returns(200) {data: map{attributes: map{details: map{description: str, tag_values: [str]}, sources: [str], value: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/tag_metadata\n@desc List Cloud Cost Management tag key metadata\n@required {filter[month]: str: any # The month to scope the query to, in `YYYY-MM` format.}\n@optional {filter[provider]: str: any # Filter results to a specific provider. Common cloud values are `aws`, `azure`, `gcp`, `Oracle` (OCI), and `custom`. SaaS billing integrations (for example, `Snowflake`, `MongoDB`, `Databricks`) are also accepted using their display-name string. Values are case-sensitive., filter[metric]: str # Filter results to a specific Cloud Cost Management metric (for example, `aws.cost.net.amortized`). When omitted, every available metric for the requested period is returned., filter[tag_key]: str # Restrict results to a single tag key., filter[daily]: str # When `true`, return one row per day with the day in the `date` attribute. Defaults to the monthly roll-up when omitted.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/tag_metadata/currency\n@desc Get the Cloud Cost Management billing currency\n@required {filter[month]: str: any # The month to scope the query to, in `YYYY-MM` format.}\n@optional {filter[provider]: str: any # Filter results to a specific provider. Common cloud values are `aws`, `azure`, `gcp`, `Oracle` (OCI), and `custom`. SaaS billing integrations (for example, `Snowflake`, `MongoDB`, `Databricks`) are also accepted using their display-name string. Values are case-sensitive.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/tag_metadata/metrics\n@desc List available Cloud Cost Management metrics\n@required {filter[month]: str: any # The month to scope the query to, in `YYYY-MM` format.}\n@optional {filter[provider]: str: any # Filter results to a specific provider. Common cloud values are `aws`, `azure`, `gcp`, `Oracle` (OCI), and `custom`. SaaS billing integrations (for example, `Snowflake`, `MongoDB`, `Databricks`) are also accepted using their display-name string. Values are case-sensitive.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/tag_metadata/months\n@desc List Cloud Cost Management tag metadata months\n@required {filter[provider]: str: any # Provider to scope the query to. Use the value of the `providername` tag in CCM (for example, `aws`, `azure`, `gcp`, `Oracle`, `Confluent Cloud`, `Snowflake`). For costs uploaded through the Custom Costs API, use `custom`. Values are case-sensitive.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/tag_metadata/orchestrators\n@desc List Cloud Cost Management orchestrators\n@required {filter[month]: str: any # The month to scope the query to, in `YYYY-MM` format.}\n@optional {filter[provider]: str: any # Filter results to a specific provider. Common cloud values are `aws`, `azure`, `gcp`, `Oracle` (OCI), and `custom`. SaaS billing integrations (for example, `Snowflake`, `MongoDB`, `Databricks`) are also accepted using their display-name string. Values are case-sensitive.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/tag_metadata/tag_sources\n@desc List Cloud Cost Management tag sources\n@required {filter[month]: str: any # The month to scope the query to, in `YYYY-MM` format.}\n@optional {filter[provider]: str: any # Filter results to a specific provider. Common cloud values are `aws`, `azure`, `gcp`, `Oracle` (OCI), and `custom`. SaaS billing integrations (for example, `Snowflake`, `MongoDB`, `Databricks`) are also accepted using their display-name string. Values are case-sensitive., filter[metric]: str # Filter results to tag keys that have data for a specific Cloud Cost Management metric (for example, `aws.cost.net.amortized`). When omitted, all tag keys for the requested period are returned.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost/tags\n@desc List Cloud Cost Management tags\n@optional {filter[metric]: str: any # The Cloud Cost Management metric to scope the tags to. When omitted, returns tags across all metrics., filter[match]: str # A substring used to filter the returned tags by name., filter[tags]: [str] # Filter to return only tags that appear with the given `key:value` tag values. For example, `filter[tags]=providername:aws` returns tags found on the same cost data, such as `aws_instance_type:t3.micro` and `aws_instance_type:m5.large`., filter[tag_keys]: [str] # Restrict the returned tags to those whose key matches one of the given tag keys., page[size]: int(int32)=50 # Controls the size of the internal tag search scope. This does **not** restrict the number of tags returned in the response. Defaults to 50, maximum 10000.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/cost_by_tag/active_billing_dimensions\n@desc Get active billing dimensions for cost attribution\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/cost_by_tag/monthly_cost_attribution\n@desc Get Monthly Cost Attribution\n@required {start_month: str(date-time) # Datetime in ISO-8601 format, UTC, precise to month: `[YYYY-MM]` for cost beginning in this month., fields: str # Comma-separated list specifying cost types (e.g., `_on_demand_cost`, `_committed_cost`, `_total_cost`) and the proportions (`_percentage_in_org`, `_percentage_in_account`). Use `*` to retrieve all fields. Example: `infra_host_on_demand_cost,infra_host_percentage_in_account` To obtain the complete list of active billing dimensions that can be used to replace `` in the field names, make a request to the [Get active billing dimensions API](https://docs.datadoghq.com/api/latest/usage-metering/#get-active-billing-dimensions-for-cost-attribution).}\n@optional {end_month: str(date-time) # Datetime in ISO-8601 format, UTC, precise to month: `[YYYY-MM]` for cost ending this month., sort_direction: str # The direction to sort by: `[desc, asc]`., sort_name: str # The billing dimension to sort by. Always sorted by total cost. Example: `infra_host`., tag_breakdown_keys: str # Comma separated list of tag keys used to group cost. If no value is provided the cost will not be broken down by tags. To see which tags are available, look for the value of `tag_config_source` in the API response., next_record_id: str # List following results with a next_record_id provided in the previous query., include_descendants: bool=true # Include child org cost in the response. Defaults to `true`.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/onboarding/agents\n@desc Get all CSM Agents\n@optional {page: int(int32) # The page index for pagination (zero-based)., size: int(int32) # The number of items to include in a single page., query: str # A search query string to filter results (for example, `hostname:COMP-T2H4J27423`)., order_direction: str # The sort direction for results. Use `asc` for ascending or `desc` for descending.}\n@returns(200) {data: [map], meta: map{page_index: int(int64), page_size: int(int64), total_filtered: int(int64)}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/onboarding/coverage_analysis/cloud_accounts\n@desc Get the CSM Cloud Accounts Coverage Analysis\n@returns(200) {data: map{attributes: map{aws_coverage: map{configured_resources_count: int(int64), coverage: num(double), partially_configured_resources_count: int(int64), total_resources_count: int(int64)}, azure_coverage: map{configured_resources_count: int(int64), coverage: num(double), partially_configured_resources_count: int(int64), total_resources_count: int(int64)}, gcp_coverage: map{configured_resources_count: int(int64), coverage: num(double), partially_configured_resources_count: int(int64), total_resources_count: int(int64)}, org_id: int(int64), total_coverage: map{configured_resources_count: int(int64), coverage: num(double), partially_configured_resources_count: int(int64), total_resources_count: int(int64)}}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/onboarding/coverage_analysis/hosts_and_containers\n@desc Get the CSM Hosts and Containers Coverage Analysis\n@returns(200) {data: map{attributes: map{cspm_coverage: map{configured_resources_count: int(int64), coverage: num(double), partially_configured_resources_count: int(int64), total_resources_count: int(int64)}, cws_coverage: map{configured_resources_count: int(int64), coverage: num(double), partially_configured_resources_count: int(int64), total_resources_count: int(int64)}, org_id: int(int64), total_coverage: map{configured_resources_count: int(int64), coverage: num(double), partially_configured_resources_count: int(int64), total_resources_count: int(int64)}, vm_coverage: map{configured_resources_count: int(int64), coverage: num(double), partially_configured_resources_count: int(int64), total_resources_count: int(int64)}}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/onboarding/coverage_analysis/serverless\n@desc Get the CSM Serverless Coverage Analysis\n@returns(200) {data: map{attributes: map{cws_coverage: map{configured_resources_count: int(int64), coverage: num(double), partially_configured_resources_count: int(int64), total_resources_count: int(int64)}, org_id: int(int64), total_coverage: map{configured_resources_count: int(int64), coverage: num(double), partially_configured_resources_count: int(int64), total_resources_count: int(int64)}}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/onboarding/serverless/agents\n@desc Get all CSM Serverless Agents\n@optional {page: int(int32) # The page index for pagination (zero-based)., size: int(int32) # The number of items to include in a single page., query: str # A search query string to filter results (for example, `hostname:COMP-T2H4J27423`)., order_direction: str # The sort direction for results. Use `asc` for ascending or `desc` for descending.}\n@returns(200) {data: [map], meta: map{page_index: int(int64), page_size: int(int64), total_filtered: int(int64)}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/ownership/settings\n@desc Get ownership settings for the org\n@returns(200) {data: map{attributes: map{auto_tag: bool, confidence_level: str, version: int(int64)}, id: str, type: str}} # OK\n@errors {401: Unauthorized, 429: Too many requests}\n\n@endpoint POST /api/v2/csm/ownership/settings\n@desc Update ownership settings for the org\n@required {data: map{attributes!: map, type!: str} # The data wrapper for an ownership settings request.}\n@returns(200) {data: map{attributes: map{auto_tag: bool, confidence_level: str, version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"auto_tag\":true,\"confidence_level\":\"high\"},\"type\":\"ownership_settings\"}}\n\n@endpoint GET /api/v2/csm/ownership/settings/untagged\n@desc Count untagged findings by ownership confidence\n@returns(200) {data: map{attributes: map{high_confidence: int(int64), low_confidence: int(int64), medium_confidence: int(int64), total: int(int64)}, id: str, type: str}} # OK\n@errors {401: Unauthorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/ownership/{resource_id}\n@desc List ownership inferences for a resource\n@required {resource_id: str # The identifier of the resource to retrieve ownership inferences for.}\n@returns(200) {data: map{attributes: map{items: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/ownership/{resource_id}/history\n@desc List ownership inference history for a resource\n@required {resource_id: str # The identifier of the resource to retrieve inference history for.}\n@optional {cursor: str # An opaque, base64-encoded cursor token returned by a previous call in `pagination.next_cursor`. Omit to fetch the first page., limit: int(int32)=25 # The maximum number of history entries to return per page.}\n@returns(200) {data: map{attributes: map{items: [map], pagination: map{has_more: bool, next_cursor: str?}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/ownership/{resource_id}/{owner_type}\n@desc Get an ownership inference by owner type\n@required {resource_id: str # The identifier of the resource to retrieve the ownership inference for., owner_type: str # The owner type of the inference to retrieve.}\n@optional {If-None-Match: str # A previously returned `ETag` value. When supplied and the resource has not changed, the endpoint returns `304 Not Modified`.}\n@returns(200) {data: map{attributes: map{checksum: str, confidence: str, created_at: str(date-time), evidence_versions: [map]?, explanation: str, owner_type: str, primary_contact_ref: str?, sources: [map], status: str, updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/ownership/{resource_id}/{owner_type}/evidence\n@desc Get the evidence for an ownership inference\n@required {resource_id: str # The identifier of the resource to retrieve evidence for., owner_type: str # The owner type of the inference to retrieve evidence for.}\n@optional {If-None-Match: str # A previously returned weak `ETag` value. When supplied and the evidence has not changed, the endpoint returns `304 Not Modified`.}\n@returns(200) {data: map{attributes: map{evidence_versions: [map]?}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/csm/ownership/{resource_id}/{owner_type}/feedback\n@desc Submit feedback on an ownership inference\n@required {resource_id: str # The identifier of the resource that the feedback applies to., owner_type: str # The type of owner that the feedback applies to., data: map{attributes!: map, type!: str} # The data wrapper for an ownership feedback request.}\n@returns(201) {data: map{attributes: map{action: str, checksum: str, new_status: str, owner_type: str, previous_status: str, primary_contact_ref: str?, updated_at: str(date-time)}, id: str, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":\"confirm\",\"actor_handle\":\"user@example.com\",\"actor_type\":\"user\",\"inference_checksum\":\"abc123\"},\"type\":\"ownership_feedback\"}}\n\n@endpoint GET /api/v2/csm/ownership/{resource_id}/{owner_type}/history\n@desc List ownership history by owner type\n@required {resource_id: str # The identifier of the resource to retrieve inference history for., owner_type: str # The owner type to filter history by.}\n@optional {cursor: str # An opaque, base64-encoded cursor token returned by a previous call in `pagination.next_cursor`. Omit to fetch the first page., limit: int(int32)=25 # The maximum number of history entries to return per page.}\n@returns(200) {data: map{attributes: map{items: [map], pagination: map{has_more: bool, next_cursor: str?}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/settings/agentless_hosts\n@desc List agentless hosts\n@optional {page: int(int32)=0 # The page index for pagination (zero-based)., size: int(int32)=10 # The number of agentless hosts to return per page., query: str # A search query string to filter agentless hosts.}\n@returns(200) {data: [map], meta: map{page_index: int(int64), page_size: int(int64), total_filtered: int(int64)}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/settings/agentless_hosts/facet_info\n@desc Get agentless host facet info\n@required {facet: str # The facet identifier to retrieve value distribution for. Valid values are `resource_name`, `account_id`, `resource_type`, `cloud_provider`, `has_vulnerability_scanning`, and `has_posture_management`.}\n@optional {search: str # A search string to filter the facet values., query: str # A filter query to scope the facet value counts.}\n@returns(200) {data: map{attributes: map{items: [map]}, id: str, meta: map{total_count: int(int64)}, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/settings/agentless_hosts/facets\n@desc List agentless host facets\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/settings/hosts\n@desc List unified hosts\n@optional {page: int(int32)=0 # The page index for pagination (zero-based)., size: int(int32)=10 # The number of hosts to return per page., query: str # A search query string to filter unified hosts.}\n@returns(200) {data: [map], meta: map{page_index: int(int64), page_size: int(int64), total_filtered: int(int64), total_pages: int(int64)}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/settings/hosts/facet_info\n@desc Get unified host facet info\n@required {facet: str # The facet identifier to retrieve value distribution for. Valid values include `resource_name`, `account_id`, `resource_type`, `cloud_provider`, `agentless_vulnerability_scanning`, `agentless_posture_management`, `hostname`, `agent_version`, `os`, `cluster_name`, `agent_posture_management`, `agent_cws_enabled`, `agent_csm_vm_hosts_enabled`, and `agent_csm_vm_containers_enabled`.}\n@optional {search: str # A search string to filter the facet values., query: str # A filter query to scope the facet value counts.}\n@returns(200) {data: map{attributes: map{items: [map]}, id: str, meta: map{total_count: int(int64)}, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/csm/settings/hosts/facets\n@desc List unified host facets\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/current_user\n@desc Get current user\n@returns(200) {data: map{attributes: map{created_at: str(date-time), disabled: bool, email: str, handle: str, icon: str, last_login_time: str(date-time)?, mfa_enabled: bool, modified_at: str(date-time), name: str?, service_account: bool, status: str, title: str?, uuid: str, verified: bool}, id: str, relationships: map{org: map{data: map}, other_orgs: map{data: [map]}, other_users: map{data: [map]}, roles: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {403: Authentication error, 429: Too many requests}\n\n@endpoint PATCH /api/v2/current_user\n@desc Update current user\n@required {data: map{attributes!: map, id!: str, type!: str} # Object to update a user.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), disabled: bool, email: str, handle: str, icon: str, last_login_time: str(date-time)?, mfa_enabled: bool, modified_at: str(date-time), name: str?, service_account: bool, status: str, title: str?, uuid: str, verified: bool}, id: str, relationships: map{org: map{data: map}, other_orgs: map{data: [map]}, other_users: map{data: [map]}, roles: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"email\":\"jane.doe@example.com\",\"name\":\"Jane Doe\",\"title\":\"Staff Engineer\"},\"id\":\"00000000-0000-9999-0000-000000000000\",\"type\":\"users\"}}\n\n@endpoint GET /api/v2/current_user/application_keys\n@desc Get all application keys owned by current user\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # Application key attribute used to sort results. Sort order is ascending by default. In order to specify a descending sort, prefix the attribute with a minus sign., filter: str # Filter application keys by the specified string., filter[created_at][start]: str # Only include application keys created on or after the specified date., filter[created_at][end]: str # Only include application keys created on or before the specified date., include: str # Resource path for related resources to include in the response. Only `owned_by` is supported.}\n@returns(200) {data: [map], included: [any], meta: map{max_allowed_per_user: int(int64), page: map{total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/current_user/application_keys\n@desc Create an application key for current user\n@required {data: map{attributes!: map, type!: str} # Object used to create an application key.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), key: str, last4: str, last_used_at: str(date-time)?, name: str, scopes: [str]?}, id: str, relationships: map{owned_by: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Application Key for managing dashboards\",\"scopes\":[\"dashboards_read\",\"dashboards_write\",\"dashboards_public_share\"]},\"type\":\"application_keys\"}}\n\n@endpoint DELETE /api/v2/current_user/application_keys/{app_key_id}\n@desc Delete an application key owned by current user\n@required {app_key_id: str # The ID of the application key.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/current_user/application_keys/{app_key_id}\n@desc Get one application key owned by current user\n@required {app_key_id: str # The ID of the application key.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), key: str, last4: str, last_used_at: str(date-time)?, name: str, scopes: [str]?}, id: str, relationships: map{owned_by: map{data: map}}, type: str}, included: [any]} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/current_user/application_keys/{app_key_id}\n@desc Edit an application key owned by current user\n@required {app_key_id: str # The ID of the application key., data: map{attributes!: map, id!: str, type!: str} # Object used to update an application key.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), key: str, last4: str, last_used_at: str(date-time)?, name: str, scopes: [str]?}, id: str, relationships: map{owned_by: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Application Key for managing dashboards\",\"scopes\":[\"dashboards_read\",\"dashboards_write\",\"dashboards_public_share\"]},\"id\":\"00112233-4455-6677-8899-aabbccddeeff\",\"type\":\"application_keys\"}}\n\n@endpoint DELETE /api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards\n@desc Delete items from a dashboard list\n@required {dashboard_list_id: int(int64) # ID of the dashboard list to delete items from.}\n@optional {dashboards: [map{id!: str, type!: str}] # List of dashboards to delete from the dashboard list.}\n@returns(200) {deleted_dashboards_from_list: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"dashboards\":[{\"id\":\"q5j-nti-fv6\",\"type\":\"host_timeboard\"}]}\n\n@endpoint GET /api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards\n@desc Get items of a Dashboard List\n@required {dashboard_list_id: int(int64) # ID of the dashboard list to get items from.}\n@returns(200) {dashboards: [map], total: int(int64)} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards\n@desc Add Items to a Dashboard List\n@required {dashboard_list_id: int(int64) # ID of the dashboard list to add items to.}\n@optional {dashboards: [map{id!: str, type!: str}] # List of dashboards to add the dashboard list.}\n@returns(200) {added_dashboards_to_list: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"dashboards\":[{\"id\":\"q5j-nti-fv6\",\"type\":\"host_timeboard\"}]}\n\n@endpoint PUT /api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards\n@desc Update items of a dashboard list\n@required {dashboard_list_id: int(int64) # ID of the dashboard list to update items from.}\n@optional {dashboards: [map{id!: str, type!: str}] # List of dashboards to update the dashboard list to.}\n@returns(200) {dashboards: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"dashboards\":[{\"id\":\"q5j-nti-fv6\",\"type\":\"host_timeboard\"}]}\n\n@endpoint GET /api/v2/dashboard/{dashboard_id}/shared\n@desc List shared dashboards for a dashboard\n@required {dashboard_id: str # ID of the dashboard.}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {403: Forbidden, 404: Dashboard Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/dashboard/{dashboard_id}/shared/secure-embed\n@desc Create a secure embed for a dashboard\n@required {dashboard_id: str # The ID of the dashboard., data: map{attributes!: map, type!: str} # Data object for creating a secure embed.}\n@returns(200) {data: map{attributes: map{created_at: str, credential: str, dashboard_id: str, global_time: map{live_span: str}, global_time_selectable: bool, id: str, selectable_template_vars: [map], share_type: str, status: str, title: str, token: str, url: str, viewing_preferences: map{high_density: bool, theme: str}}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Dashboard Not Found, 409: Conflict — max 1000 share URLs per dashboard exceeded, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"global_time\":{\"live_span\":\"1h\"},\"global_time_selectable\":true,\"selectable_template_vars\":[{\"default_values\":[\"1\"],\"name\":\"org_id\",\"prefix\":\"org_id\",\"visible_tags\":[\"1\"]}],\"status\":\"active\",\"title\":\"Q1 Metrics Dashboard\",\"viewing_preferences\":{\"high_density\":false,\"theme\":\"system\"}},\"type\":\"secure_embed_request\"}}\n\n@endpoint DELETE /api/v2/dashboard/{dashboard_id}/shared/secure-embed/{token}\n@desc Delete a secure embed for a dashboard\n@required {dashboard_id: str # The ID of the dashboard., token: str # The share token identifying the secure embed.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/dashboard/{dashboard_id}/shared/secure-embed/{token}\n@desc Get a secure embed for a dashboard\n@required {dashboard_id: str # The ID of the dashboard., token: str # The share token identifying the secure embed.}\n@returns(200) {data: map{attributes: map{created_at: str, credential_suffix: str, dashboard_id: str, global_time: map{live_span: str}, global_time_selectable: bool, id: str, selectable_template_vars: [map], share_type: str, status: str, title: str, token: str, url: str, viewing_preferences: map{high_density: bool, theme: str}}, id: str, type: str}} # OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/dashboard/{dashboard_id}/shared/secure-embed/{token}\n@desc Update a secure embed for a dashboard\n@required {dashboard_id: str # The ID of the dashboard., token: str # The share token identifying the secure embed., data: map{attributes!: map, type!: str} # Data object for updating a secure embed.}\n@returns(200) {data: map{attributes: map{created_at: str, credential_suffix: str, dashboard_id: str, global_time: map{live_span: str}, global_time_selectable: bool, id: str, selectable_template_vars: [map], share_type: str, status: str, title: str, token: str, url: str, viewing_preferences: map{high_density: bool, theme: str}}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"status\":\"active\",\"title\":\"Q1 Metrics Dashboard (Updated)\"},\"type\":\"secure_embed_update_request\"}}\n\n@endpoint GET /api/v2/dashboards/usage\n@desc Get usage stats for all dashboards\n@optional {page[limit]: int(int64)=250: any # Maximum number of dashboards to return per page. Server-side maximum is 500; values above 500 return a 400 Bad Request., page[offset]: int(int64)=0 # Zero-based offset into the result set., filter[edited_before]: str # Return only dashboards whose last edit (`edited_at`) is strictly before this ISO 8601 timestamp (`edited_at < value`; boundary matches are excluded). Must include a timezone offset (for example, `Z` or `+00:00`); naive timestamps return HTTP 400., filter[viewed_before]: str # Return only dashboards whose most recent view (`viewed_at`) is strictly before this ISO 8601 timestamp, including dashboards that have never been viewed. Must include a timezone offset; naive timestamps return HTTP 400. Orgs without Real User Monitoring (RUM) will see all dashboards returned by this filter.}\n@returns(200) {data: [map], links: map{first: str, last: str?, next: str?, prev: str?, self: str}, meta: map{page: map{first_offset: int(int64), last_offset: int(int64)?, limit: int(int64), next_offset: int(int64)?, offset: int(int64), prev_offset: int(int64)?, total: int(int64)?, type: str}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/dashboards/{dashboard_id}/usage\n@desc Get usage stats for a dashboard\n@required {dashboard_id: str # The ID of the dashboard.}\n@returns(200) {data: map{attributes: map{author: map?{handle: str, id: str, is_disabled: bool, name: str}, created_at: str(date-time)?, dashboard_quality_score: num(double)?, edited_at: str(date-time)?, org_id: int(int64), teams: [str]?, title: str, total_views: int(int64), total_views_by_type: map?, viewed_at: str(date-time)?, viewer: map?{handle: str, id: str, is_disabled: bool, name: str}, widget_count: int(int64)?, widget_count_by_type: map?}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/data-observability/monitors/runs/{run_id}/status\n@desc Get data observability monitor run status\n@required {run_id: str # The ID of the monitor run to retrieve status for.}\n@returns(200) {data: map{attributes: map{error_message: str, status: str}, id: str, type: str}} # OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/data-observability/monitors/{monitor_id}/run\n@desc Run a data observability monitor\n@required {monitor_id: int(int64) # The ID of the data observability monitor to run.}\n@returns(200) {data: map{id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/datasets\n@desc Get all datasets\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/datasets\n@desc Create a dataset\n@required {data: map{attributes!: map, type!: str} # **Datasets Object Constraints** - **Tag limit per dataset**:   - Each restricted dataset supports a maximum of 10 key:value pairs per product.  - **Tag key rules per telemetry type**:   - Only one tag key or attribute may be used to define access within a single telemetry type.   - The same or different tag key may be used across different telemetry types.  - **Tag value uniqueness**:   - Tag values must be unique within a single dataset.   - A tag value used in one dataset cannot be reused in another dataset of the same telemetry type.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time)?, created_by: str(uuid), name: str, principals: [str], product_filters: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Security Audit Dataset\",\"principals\":[\"role:94172442-be03-11e9-a77a-3b7612558ac1\"],\"product_filters\":[{\"filters\":[\"source:cloudtrail\"],\"product\":\"logs\"}],\"restriction_query_id\":\"00000000-0000-0000-0000-000000000001\"},\"type\":\"dataset\"}}\n\n@endpoint DELETE /api/v2/datasets/{dataset_id}\n@desc Delete a dataset\n@required {dataset_id: str # The ID of a defined dataset.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/datasets/{dataset_id}\n@desc Get a single dataset by ID\n@required {dataset_id: str # The ID of a defined dataset.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time)?, created_by: str(uuid), name: str, principals: [str], product_filters: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/datasets/{dataset_id}\n@desc Edit a dataset\n@required {dataset_id: str # The ID of a defined dataset., data: map{attributes!: map, type!: str} # **Datasets Object Constraints** - **Tag limit per dataset**:   - Each restricted dataset supports a maximum of 10 key:value pairs per product.  - **Tag key rules per telemetry type**:   - Only one tag key or attribute may be used to define access within a single telemetry type.   - The same or different tag key may be used across different telemetry types.  - **Tag value uniqueness**:   - Tag values must be unique within a single dataset.   - A tag value used in one dataset cannot be reused in another dataset of the same telemetry type.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time)?, created_by: str(uuid), name: str, principals: [str], product_filters: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Security Audit Dataset\",\"principals\":[\"role:94172442-be03-11e9-a77a-3b7612558ac1\"],\"product_filters\":[{\"filters\":[\"@application.id:ABCD\"],\"product\":\"logs\"}]},\"type\":\"dataset\"}}\n\n@endpoint POST /api/v2/ddsql/query/tabular\n@desc Execute a tabular DDSQL query\n@required {data: map{attributes!: map, type!: str} # JSON:API resource object for a DDSQL tabular query execution request.}\n@returns(200) {data: map{attributes: map{columns: [map], query_id: str, state: str, warnings: [str]}, id: str, type: str}, meta: map{elapsed: int(int64), request_id: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"query\":\"SELECT cloud_provider, count(*) FROM dd.hosts group by cloud_provider\",\"row_limit\":1000,\"time\":{\"from_timestamp\":1736942400000,\"to_timestamp\":1736946000000}},\"type\":\"ddsql_query_request\"}}\n\n@endpoint POST /api/v2/ddsql/query/tabular/fetch\n@desc Fetch the result of a DDSQL query\n@required {data: map{attributes!: map, type!: str} # JSON:API resource object for a DDSQL tabular query fetch request.}\n@returns(200) {data: map{attributes: map{columns: [map], query_id: str, state: str, warnings: [str]}, id: str, type: str}, meta: map{elapsed: int(int64), request_id: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"query_id\":\"eyJxdWVyeSI6ICJTRUxFQ1QgKiBGUk9NIGxvZ3MifQ==\"},\"type\":\"ddsql_query_fetch_request\"}}\n\n@endpoint POST /api/v2/deletion/data/{product}\n@desc Creates a data deletion request\n@required {product: str # Name of the product to be deleted, either `logs` or `rum`., data: map{attributes!: map, type!: str} # Data needed to create a data deletion request.}\n@returns(200) {data: map{attributes: map{created_at: str, created_by: str, from_time: int(int64), indexes: [str], is_created: bool, org_id: int(int64), product: str, query: str, starting_at: str, status: str, to_time: int(int64), total_unrestricted: int(int64), updated_at: str}, id: str, type: str}, meta: map{count_product: map, count_status: map, next_page: str, product: str, request_status: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 412: Precondition failed error, 429: Too many requests, 500: Internal server error}\n\n@endpoint GET /api/v2/deletion/requests\n@desc Gets a list of data deletion requests\n@optional {next_page: str # The next page of the previous search. If the next_page parameter is included, the rest of the query elements are ignored., product: str # Retrieve only the requests related to the given product., query: str # Retrieve only the requests that matches the given query., status: str # Retrieve only the requests with the given status., page_size: int(int64)=50 # Sets the page size of the search.}\n@returns(200) {data: [map], meta: map{count_product: map, count_status: map, next_page: str, product: str, request_status: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 500: Internal server error}\n\n@endpoint PUT /api/v2/deletion/requests/{id}/cancel\n@desc Cancels a data deletion request\n@required {id: str # ID of the deletion request.}\n@returns(200) {data: map{attributes: map{created_at: str, created_by: str, from_time: int(int64), indexes: [str], is_created: bool, org_id: int(int64), product: str, query: str, starting_at: str, status: str, to_time: int(int64), total_unrestricted: int(int64), updated_at: str}, id: str, type: str}, meta: map{count_product: map, count_status: map, next_page: str, product: str, request_status: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 412: Precondition failed error, 429: Too many requests, 500: Internal server error}\n\n@endpoint GET /api/v2/deployment_gates\n@desc Get all deployment gates\n@optional {page[cursor]: str: any # Cursor for pagination. Use the `meta.page.next_cursor` value from the previous response., page[size]: int(int64)=50 # Number of results per page. Defaults to 50. Must be between 1 and 1000.}\n@returns(200) {data: [map], meta: map{page: map{cursor: str, next_cursor: str, size: int(int64)}}} # OK\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/deployment_gates\n@desc Create deployment gate\n@required {data: map{attributes!: map, type!: str} # Parameters for creating a deployment gate.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: map{handle: str, id: str, name: str}, dry_run: bool, env: str, identifier: str, service: str, updated_at: str(date-time), updated_by: map{handle: str, id: str, name: str}}, id: str, type: str}} # OK\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"dry_run\":false,\"env\":\"production\",\"identifier\":\"pre\",\"service\":\"my-service\"},\"type\":\"deployment_gate\"}}\n\n@endpoint GET /api/v2/deployment_gates/{gate_id}/rules\n@desc Get rules for a deployment gate\n@required {gate_id: str # The ID of the deployment gate.}\n@returns(200) {data: map{attributes: map{rules: [map]}, id: str, type: str}} # OK\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/deployment_gates/{gate_id}/rules\n@desc Create deployment rule\n@required {gate_id: str # The ID of the deployment gate.}\n@optional {data: map{attributes!: map, type!: str} # Parameters for creating a deployment rule.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: map{handle: str, id: str, name: str}, dry_run: bool, gate_id: str, name: str, options: any, type: str, updated_at: str(date-time), updated_by: map{handle: str, id: str, name: str}}, id: str, type: str}} # OK\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"dry_run\":false,\"name\":\"My deployment rule\",\"options\":[\"resource1\",\"resource2\"],\"type\":\"faulty_deployment_detection\"},\"type\":\"deployment_rule\"}}\n\n@endpoint DELETE /api/v2/deployment_gates/{gate_id}/rules/{id}\n@desc Delete deployment rule\n@required {gate_id: str # The ID of the deployment gate., id: str # The ID of the deployment rule.}\n@returns(204) No Content\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 404: Deployment gate not found., 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/deployment_gates/{gate_id}/rules/{id}\n@desc Get deployment rule\n@required {gate_id: str # The ID of the deployment gate., id: str # The ID of the deployment rule.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: map{handle: str, id: str, name: str}, dry_run: bool, gate_id: str, name: str, options: any, type: str, updated_at: str(date-time), updated_by: map{handle: str, id: str, name: str}}, id: str, type: str}} # OK\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 404: Deployment rule not found., 429: Too many requests, 500: Internal Server Error}\n\n@endpoint PUT /api/v2/deployment_gates/{gate_id}/rules/{id}\n@desc Update deployment rule\n@required {gate_id: str # The ID of the deployment gate., id: str # The ID of the deployment rule., data: map{attributes!: map, type!: str} # Parameters for updating a deployment rule.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: map{handle: str, id: str, name: str}, dry_run: bool, gate_id: str, name: str, options: any, type: str, updated_at: str(date-time), updated_by: map{handle: str, id: str, name: str}}, id: str, type: str}} # OK\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 404: Deployment rule not found., 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"dry_run\":false,\"name\":\"Updated deployment rule\",\"options\":[\"resource1\",\"resource2\"]},\"type\":\"deployment_rule\"}}\n\n@endpoint DELETE /api/v2/deployment_gates/{id}\n@desc Delete deployment gate\n@required {id: str # The ID of the deployment gate.}\n@returns(204) No Content\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 404: Deployment gate not found., 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/deployment_gates/{id}\n@desc Get deployment gate\n@required {id: str # The ID of the deployment gate.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: map{handle: str, id: str, name: str}, dry_run: bool, env: str, identifier: str, service: str, updated_at: str(date-time), updated_by: map{handle: str, id: str, name: str}}, id: str, type: str}} # OK\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 404: Deployment gate not found., 429: Too many requests, 500: Internal Server Error}\n\n@endpoint PUT /api/v2/deployment_gates/{id}\n@desc Update deployment gate\n@required {id: str # The ID of the deployment gate., data: map{attributes!: map, id!: str, type!: str} # Parameters for updating a deployment gate.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: map{handle: str, id: str, name: str}, dry_run: bool, env: str, identifier: str, service: str, updated_at: str(date-time), updated_by: map{handle: str, id: str, name: str}}, id: str, type: str}} # OK\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 404: Deployment gate not found., 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"dry_run\":false},\"id\":\"12345678-1234-1234-1234-123456789012\",\"type\":\"deployment_gate\"}}\n\n@endpoint POST /api/v2/deployments/gates/evaluation\n@desc Trigger a deployment gate evaluation\n@required {data: map{attributes!: map, type!: str} # Data for a deployment gate evaluation request.}\n@returns(202) {data: map{attributes: map{evaluation_id: str}, id: str(uuid), type: str}} # Accepted\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 404: Deployment gate not found., 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"env\":\"staging\",\"identifier\":\"pre-deploy\",\"primary_tag\":\"region:us-east-1\",\"service\":\"transaction-backend\",\"version\":\"v1.2.3\"},\"type\":\"deployment_gates_evaluation_request\"}}\n\n@endpoint GET /api/v2/deployments/gates/evaluation/{id}\n@desc Get a deployment gate evaluation result\n@required {id: str(uuid) # The evaluation ID returned by the trigger endpoint.}\n@returns(200) {data: map{attributes: map{dry_run: bool, evaluation_id: str, evaluation_url: str, gate_id: str(uuid), gate_status: str, rules: [map]}, id: str, type: str}} # OK\n@errors {400: Bad request., 401: Unauthorized, 403: Forbidden, 404: Deployment gate not found., 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/domain_allowlist\n@desc Get Domain Allowlist\n@returns(200) {data: map{attributes: map{domains: [str], enabled: bool}, id: str?, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/domain_allowlist\n@desc Sets Domain Allowlist\n@required {data: map{attributes: map, id: str, type!: str} # The email domain allowlist for an org.}\n@returns(200) {data: map{attributes: map{domains: [str], enabled: bool}, id: str?, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"domains\":[\"@static-test-domain.test\"],\"enabled\":false},\"type\":\"domain_allowlist\"}}\n\n@endpoint POST /api/v2/dora/deployment\n@desc Send a deployment event\n@required {data: map{attributes!: map} # The JSON:API data.}\n@returns(200) {data: map{id: str, type: str}} # OK\n@returns(202) {data: map{id: str, type: str}} # OK - but delayed due to incident\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"custom_tags\":[\"language:java\",\"department:engineering\"],\"env\":\"staging\",\"finished_at\":1693491984000000000,\"git\":{\"commit_sha\":\"66adc9350f2cc9b250b69abddab733dd55e1a588\",\"repository_url\":\"https://github.com/organization/example-repository\"},\"service\":\"test-service\",\"started_at\":1693491974000000000,\"team\":\"backend\",\"version\":\"v1.12.07\"}}}\n\n@endpoint DELETE /api/v2/dora/deployment/{deployment_id}\n@desc Delete a deployment event\n@required {deployment_id: str # The ID of the deployment event to delete.}\n@returns(202) Accepted\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint PATCH /api/v2/dora/deployments\n@desc Patch a deployment event by version\n@required {data: map{attributes!: map, type!: str} # The JSON:API data for patching a deployment identified by service, environment, and version.}\n@returns(202) Accepted\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"change_failure\":true,\"env\":\"production\",\"service\":\"my-service\",\"version\":\"v1.2.3\"},\"type\":\"dora_deployment_patch_request\"}}\n\n@endpoint POST /api/v2/dora/deployments\n@desc Get a list of deployment events\n@required {data: map{attributes!: map, type: str} # The JSON:API data.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"from\":\"2025-01-01T00:00:00Z\",\"limit\":100,\"query\":\"service:(test-service OR api-service) env:production team:backend\",\"sort\":\"-finished_at\",\"to\":\"2025-01-31T23:59:59Z\"},\"type\":\"dora_deployments_list_request\"}}\n\n@endpoint GET /api/v2/dora/deployments/{deployment_id}\n@desc Get a deployment event\n@required {deployment_id: str # The ID of the deployment event.}\n@returns(200) {data: map{attributes: map{custom_tags: [str]?, env: str, finished_at: str(date-time), git: map{commit_sha: str, repository_id: str}, service: str, started_at: str(date-time), team: str, version: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint PATCH /api/v2/dora/deployments/{deployment_id}\n@desc Patch a deployment event\n@required {deployment_id: str # The ID of the deployment event., data: map{attributes!: map, id!: str, type!: str} # The JSON:API data for patching a deployment.}\n@returns(202) Accepted\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"change_failure\":true,\"remediation\":{\"id\":\"eG42zNIkVjM\",\"type\":\"rollback\"}},\"id\":\"z_RwVLi7v4Y\",\"type\":\"dora_deployment_patch_request\"}}\n\n@endpoint POST /api/v2/dora/failure\n@desc Send an incident event\n@required {data: map{attributes!: map} # The JSON:API data.}\n@returns(200) {data: map{id: str, type: str}} # OK\n@returns(202) {data: map{id: str, type: str}} # OK - but delayed due to incident\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"custom_tags\":[\"language:java\",\"department:engineering\"],\"env\":\"staging\",\"finished_at\":1693491984000000000,\"git\":{\"commit_sha\":\"66adc9350f2cc9b250b69abddab733dd55e1a588\",\"repository_url\":\"https://github.com/organization/example-repository\"},\"name\":\"Webserver is down failing all requests.\",\"services\":[\"test-service\"],\"severity\":\"High\",\"started_at\":1693491974000000000,\"team\":\"backend\",\"version\":\"v1.12.07\"}}}\n\n@endpoint DELETE /api/v2/dora/failure/{failure_id}\n@desc Delete an incident event\n@required {failure_id: str # The ID of the incident event to delete.}\n@returns(202) Accepted\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/dora/failures\n@desc Get a list of incident events\n@required {data: map{attributes!: map, type: str} # The JSON:API data.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"from\":\"2025-01-01T00:00:00Z\",\"limit\":100,\"query\":\"severity:(SEV-1 OR SEV-2) env:production team:backend\",\"sort\":\"-started_at\",\"to\":\"2025-01-31T23:59:59Z\"},\"type\":\"dora_failures_list_request\"}}\n\n@endpoint GET /api/v2/dora/failures/{failure_id}\n@desc Get an incident event\n@required {failure_id: str # The ID of the incident event.}\n@returns(200) {data: map{attributes: map{custom_tags: [str]?, env: str, finished_at: str(date-time), git: map{commit_sha: str, repository_url: str}, name: str, services: [str], severity: str, started_at: str(date-time), team: str, version: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/dora/incident\n@desc Send an incident event (legacy)\n@required {data: map{attributes!: map} # The JSON:API data.}\n@returns(200) {data: map{id: str, type: str}} # OK\n@returns(202) {data: map{id: str, type: str}} # OK - but delayed due to incident\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"custom_tags\":[\"language:java\",\"department:engineering\"],\"env\":\"staging\",\"finished_at\":1693491984000000000,\"git\":{\"commit_sha\":\"66adc9350f2cc9b250b69abddab733dd55e1a588\",\"repository_url\":\"https://github.com/organization/example-repository\"},\"name\":\"Webserver is down failing all requests.\",\"services\":[\"test-service\"],\"severity\":\"High\",\"started_at\":1693491974000000000,\"team\":\"backend\",\"version\":\"v1.12.07\"}}}\n\n@endpoint GET /api/v2/downtime\n@desc Get all downtimes\n@optional {current_only: bool # Only return downtimes that are active when the request is made., include: str # Comma-separated list of resource paths for related resources to include in the response. Supported resource paths are `created_by` and `monitor`., page[offset]: int(int64)=0 # Specific offset to use as the beginning of the returned page., page[limit]: int(int64)=30 # Maximum number of downtimes in the response.}\n@returns(200) {data: [map], included: [any], meta: map{page: map{total_filtered_count: int(int64)}}} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/downtime\n@desc Schedule a downtime\n@required {data: map{attributes!: map, type!: str} # Object to create a downtime.}\n@returns(200) {data: map{attributes: map{canceled: str(date-time)?, created: str(date-time), display_timezone: str?, message: str?, modified: str(date-time), monitor_identifier: any, mute_first_recovery_notification: bool, notify_end_states: [str], notify_end_types: [str], schedule: any, scope: str, status: str}, id: str, relationships: map{created_by: map{data: map?}, monitor: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"display_timezone\":\"America/New_York\",\"message\":\"Message about the downtime\",\"monitor_identifier\":{\"monitor_id\":123},\"mute_first_recovery_notification\":false,\"notify_end_states\":[\"alert\",\"warn\"],\"notify_end_types\":[\"canceled\",\"expired\"],\"schedule\":{\"timezone\":\"America/New_York\"},\"scope\":\"env:(staging OR prod) AND datacenter:us-east-1\"},\"type\":\"downtime\"}}\n\n@endpoint DELETE /api/v2/downtime/{downtime_id}\n@desc Cancel a downtime\n@required {downtime_id: str # ID of the downtime to cancel.}\n@returns(204) OK\n@errors {403: Forbidden, 404: Downtime not found, 429: Too many requests}\n\n@endpoint GET /api/v2/downtime/{downtime_id}\n@desc Get a downtime\n@required {downtime_id: str # ID of the downtime to fetch.}\n@optional {include: str # Comma-separated list of resource paths for related resources to include in the response. Supported resource paths are `created_by` and `monitor`.}\n@returns(200) {data: map{attributes: map{canceled: str(date-time)?, created: str(date-time), display_timezone: str?, message: str?, modified: str(date-time), monitor_identifier: any, mute_first_recovery_notification: bool, notify_end_states: [str], notify_end_types: [str], schedule: any, scope: str, status: str}, id: str, relationships: map{created_by: map{data: map?}, monitor: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/downtime/{downtime_id}\n@desc Update a downtime\n@required {downtime_id: str # ID of the downtime to update., data: map{attributes!: map, id!: str, type!: str} # Object to update a downtime.}\n@returns(200) {data: map{attributes: map{canceled: str(date-time)?, created: str(date-time), display_timezone: str?, message: str?, modified: str(date-time), monitor_identifier: any, mute_first_recovery_notification: bool, notify_end_states: [str], notify_end_types: [str], schedule: any, scope: str, status: str}, id: str, relationships: map{created_by: map{data: map?}, monitor: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Downtime not found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"display_timezone\":\"America/New_York\",\"message\":\"Message about the downtime\",\"monitor_identifier\":{\"monitor_id\":123},\"mute_first_recovery_notification\":false,\"notify_end_states\":[\"alert\",\"warn\"],\"notify_end_types\":[\"canceled\",\"expired\"],\"schedule\":{\"timezone\":\"America/New_York\"},\"scope\":\"env:(staging OR prod) AND datacenter:us-east-1\"},\"id\":\"00000000-0000-1234-0000-000000000000\",\"type\":\"downtime\"}}\n\n@endpoint POST /api/v2/error-tracking/issues/search\n@desc Search error tracking issues\n@required {data: map{attributes!: map, type!: str} # Search issues request.}\n@optional {include: [str] # Comma-separated list of relationship objects that should be included in the response. Possible values are `issue`, `issue.assignee`, `issue.case`, and `issue.team_owners`.}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"from\":1671612804000,\"order_by\":\"IMPACTED_SESSIONS\",\"persona\":\"BACKEND\",\"query\":\"service:orders-* AND @language:go\",\"to\":1671620004000},\"type\":\"search_request\"}}\n\n@endpoint GET /api/v2/error-tracking/issues/{issue_id}\n@desc Get the details of an error tracking issue\n@required {issue_id: str # The identifier of the issue.}\n@optional {include: [str] # Comma-separated list of relationship objects that should be included in the response. Possible values are `assignee`, `case`, and `team_owners`.}\n@returns(200) {data: map{attributes: map{error_message: str, error_type: str, file_path: str, first_seen: int(int64), first_seen_version: str, function_name: str, is_crash: bool, languages: [str], last_seen: int(int64), last_seen_version: str, platform: str, regression: map{regressed_at: str(date-time), regressed_at_version: str, resolved_at: str(date-time)}, service: str, state: str}, id: str, relationships: map{assignee: map{data: map}, case: map{data: map}, team_owners: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/error-tracking/issues/{issue_id}/assignee\n@desc Remove the assignee of an issue\n@required {issue_id: str # The identifier of the issue.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/error-tracking/issues/{issue_id}/assignee\n@desc Update the assignee of an issue\n@required {issue_id: str # The identifier of the issue., data: map{id!: str, type!: str} # Update issue assignee request.}\n@returns(200) {data: map{attributes: map{error_message: str, error_type: str, file_path: str, first_seen: int(int64), first_seen_version: str, function_name: str, is_crash: bool, languages: [str], last_seen: int(int64), last_seen_version: str, platform: str, regression: map{regressed_at: str(date-time), regressed_at_version: str, resolved_at: str(date-time)}, service: str, state: str}, id: str, relationships: map{assignee: map{data: map}, case: map{data: map}, team_owners: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"87cb11a0-278c-440a-99fe-701223c80296\",\"type\":\"assignee\"}}\n\n@endpoint PUT /api/v2/error-tracking/issues/{issue_id}/state\n@desc Update the state of an issue\n@required {issue_id: str # The identifier of the issue., data: map{attributes!: map, id!: str, type!: str} # Update issue state request.}\n@returns(200) {data: map{attributes: map{error_message: str, error_type: str, file_path: str, first_seen: int(int64), first_seen_version: str, function_name: str, is_crash: bool, languages: [str], last_seen: int(int64), last_seen_version: str, platform: str, regression: map{regressed_at: str(date-time), regressed_at_version: str, resolved_at: str(date-time)}, service: str, state: str}, id: str, relationships: map{assignee: map{data: map}, case: map{data: map}, team_owners: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"state\":\"RESOLVED\"},\"id\":\"c1726a66-1f64-11ee-b338-da7ad0900002\",\"type\":\"error_tracking_issue\"}}\n\n@endpoint GET /api/v2/events\n@desc Get a list of events\n@optional {filter[query]: str: any # Search query following events syntax., filter[from]: str # Minimum timestamp for requested events, in milliseconds., filter[to]: str # Maximum timestamp for requested events, in milliseconds., sort: str # Order of events in results., page[cursor]: str # List following results with a cursor provided in the previous query., page[limit]: int(int32)=10 # Maximum number of events in the response.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/events\n@desc Post an event\n@required {data: map{attributes!: map, type!: str} # An event object.}\n@returns(202) {data: map{attributes: map{attributes: map{evt: map}}, type: str}, links: map{self: str}} # OK\n@errors {400: Bad request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"aggregation_key\":\"deduplication_key_here\",\"attributes\":{\"custom\":{\"my-object-attribute\":{\"my-array-attribute\":[1,2,3],\"my-array-object-attribute\":[{\"name\":\"test-object-1\"},{\"name\":\"test-object-2\"}],\"my-integer-attribute\":1},\"my-string-attribute\":\"my-custom-value\"},\"links\":[{\"category\":\"runbook\",\"title\":\"Datadog website\",\"url\":\"https://datadoghq.com\"}],\"priority\":\"1\",\"status\":\"error\"},\"category\":\"alert\",\"message\":\"Something is broken!\",\"tags\":[\"service:my-test-service\",\"datacenter:primary\"],\"title\":\"My Alerting Event\"},\"type\":\"event\"}}\n\n@endpoint POST /api/v2/events/search\n@desc Search events\n@optional {filter: map{from: str, query: str, to: str} # The search and filter query settings., options: map{timeOffset: int(int64), timezone: str} # The global query options that are used. Either provide a timezone or a time offset but not both, otherwise the query fails., page: map{cursor: str, limit: int(int32)} # Pagination settings., sort: str(timestamp/-timestamp) # The sort parameters when querying events.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"filter\":{\"from\":\"now-15m\",\"query\":\"service:web* AND @http.status_code:[200 TO 299]\",\"to\":\"now\"},\"options\":{\"timezone\":\"GMT\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\",\"limit\":25},\"sort\":\"timestamp\"}\n\n@endpoint GET /api/v2/events/{event_id}\n@desc Get an event\n@required {event_id: str # The UID of the event.}\n@returns(200) {data: map{attributes: map{attributes: any, message: str, tags: [str], timestamp: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/feature-flags\n@desc List feature flags\n@optional {key: str # Filter feature flags by key (partial matching)., is_archived: bool # Filter by archived status., limit: int(int64)=100 # Maximum number of results to return., offset: int(int64)=0 # Number of results to skip.}\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/feature-flags\n@desc Create a feature flag\n@required {data: map{attributes!: map, type!: str} # Data for creating a new feature flag.}\n@returns(201) {data: map{attributes: map{archived_at: str(date-time)?, created_at: str(date-time), created_by: str(uuid), description: str, distribution_channel: str, feature_flag_environments: [map], json_schema: str?, key: str, last_updated_by: str(uuid), name: str, require_approval: bool, staleness_status: str, tags: [str], updated_at: str(date-time), value_type: str, variants: [map]}, id: str(uuid), type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"default_variant_key\":\"variant-a\",\"description\":\"A sample feature flag\",\"enabled\":true,\"key\":\"feature-flag-abc123\",\"name\":\"Feature Flag ABC 123\",\"variants\":[{\"description\":\"Variant A\",\"key\":\"variant-a\"},{\"description\":\"Variant B\",\"key\":\"variant-b\"}]},\"type\":\"feature-flags\"}}\n\n@endpoint GET /api/v2/feature-flags/environments\n@desc List environments\n@optional {name: str # Filter environments by name (partial matching)., key: str # Filter environments by key (partial matching)., dd_env: str # Filter environments by queries that contain the provided DD_ENV value., limit: int(int64)=100 # Maximum number of results to return., offset: int(int64)=0 # Number of results to skip.}\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/feature-flags/environments\n@desc Create an environment\n@required {data: map{attributes!: map, type!: str} # Data for creating a new environment.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), description: str?, is_production: bool, key: str, name: str, queries: [str], require_feature_flag_approval: bool, updated_at: str(date-time)}, id: str(uuid), type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"staging-environment\",\"queries\":[\"staging\",\"canary\"]},\"type\":\"environments\"}}\n\n@endpoint DELETE /api/v2/feature-flags/environments/{environment_id}\n@desc Delete an environment\n@required {environment_id: str(uuid) # The ID of the environment.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/feature-flags/environments/{environment_id}\n@desc Get an environment\n@required {environment_id: str(uuid) # The ID of the environment.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), description: str?, is_production: bool, key: str, name: str, queries: [str], require_feature_flag_approval: bool, updated_at: str(date-time)}, id: str(uuid), type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/feature-flags/environments/{environment_id}\n@desc Update an environment\n@required {environment_id: str(uuid) # The ID of the environment., data: map{attributes!: map, type!: str} # Data for updating an environment.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), description: str?, is_production: bool, key: str, name: str, queries: [str], require_feature_flag_approval: bool, updated_at: str(date-time)}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"production-environment\",\"queries\":[\"production\",\"prod-us\"]},\"type\":\"environments\"}}\n\n@endpoint POST /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/pause\n@desc Pause a progressive rollout\n@required {exposure_schedule_id: str(uuid) # The ID of the exposure schedule.}\n@returns(200) {data: map{attributes: map{absolute_start_time: str(date-time)?, allocation_id: str(uuid), control_variant_id: str?, created_at: str(date-time), guardrail_triggered_action: str?, guardrail_triggers: [map], id: str(uuid), rollout_options: map{autostart: bool, selection_interval_ms: int(int64), strategy: str}, rollout_steps: [map], updated_at: str(date-time)}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n\n@endpoint POST /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/resume\n@desc Resume a progressive rollout\n@required {exposure_schedule_id: str(uuid) # The ID of the exposure schedule.}\n@returns(200) {data: map{attributes: map{absolute_start_time: str(date-time)?, allocation_id: str(uuid), control_variant_id: str?, created_at: str(date-time), guardrail_triggered_action: str?, guardrail_triggers: [map], id: str(uuid), rollout_options: map{autostart: bool, selection_interval_ms: int(int64), strategy: str}, rollout_steps: [map], updated_at: str(date-time)}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n\n@endpoint POST /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/start\n@desc Start a progressive rollout\n@required {exposure_schedule_id: str(uuid) # The ID of the exposure schedule.}\n@returns(200) {data: map{attributes: map{absolute_start_time: str(date-time)?, allocation_id: str(uuid), control_variant_id: str?, created_at: str(date-time), guardrail_triggered_action: str?, guardrail_triggers: [map], id: str(uuid), rollout_options: map{autostart: bool, selection_interval_ms: int(int64), strategy: str}, rollout_steps: [map], updated_at: str(date-time)}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n\n@endpoint POST /api/v2/feature-flags/exposure-schedules/{exposure_schedule_id}/stop\n@desc Stop a progressive rollout\n@required {exposure_schedule_id: str(uuid) # The ID of the exposure schedule.}\n@returns(200) {data: map{attributes: map{absolute_start_time: str(date-time)?, allocation_id: str(uuid), control_variant_id: str?, created_at: str(date-time), guardrail_triggered_action: str?, guardrail_triggers: [map], id: str(uuid), rollout_options: map{autostart: bool, selection_interval_ms: int(int64), strategy: str}, rollout_steps: [map], updated_at: str(date-time)}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n\n@endpoint GET /api/v2/feature-flags/{feature_flag_id}\n@desc Get a feature flag\n@required {feature_flag_id: str(uuid) # The ID of the feature flag.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, created_at: str(date-time), created_by: str(uuid), description: str, distribution_channel: str, feature_flag_environments: [map], json_schema: str?, key: str, last_updated_by: str(uuid), name: str, require_approval: bool, staleness_status: str, tags: [str], updated_at: str(date-time), value_type: str, variants: [map]}, id: str(uuid), type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/feature-flags/{feature_flag_id}\n@desc Update a feature flag\n@required {feature_flag_id: str(uuid) # The ID of the feature flag., data: map{attributes!: map, type!: str} # Data for updating a feature flag.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, created_at: str(date-time), created_by: str(uuid), description: str, distribution_channel: str, feature_flag_environments: [map], json_schema: str?, key: str, last_updated_by: str(uuid), name: str, require_approval: bool, staleness_status: str, tags: [str], updated_at: str(date-time), value_type: str, variants: [map]}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Updated description for the feature flag\",\"enabled\":true,\"name\":\"Updated Feature Flag XYZ789\"},\"type\":\"feature-flags\"}}\n\n@endpoint POST /api/v2/feature-flags/{feature_flag_id}/archive\n@desc Archive a feature flag\n@required {feature_flag_id: str(uuid) # The ID of the feature flag.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, created_at: str(date-time), created_by: str(uuid), description: str, distribution_channel: str, feature_flag_environments: [map], json_schema: str?, key: str, last_updated_by: str(uuid), name: str, require_approval: bool, staleness_status: str, tags: [str], updated_at: str(date-time), value_type: str, variants: [map]}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/feature-flags/{feature_flag_id}/environments/{environment_id}/allocations\n@desc Create targeting rules for a flag env\n@required {feature_flag_id: str(uuid) # The ID of the feature flag., environment_id: str(uuid) # The ID of the environment., data: map{attributes!: map, type!: str} # Data wrapper for allocation request payloads.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), environment_ids: [str(uuid)], experiment_id: str?, exposure_schedule: map{absolute_start_time: str(date-time)?, allocation_id: str(uuid), control_variant_id: str?, created_at: str(date-time), guardrail_triggered_action: str?, guardrail_triggers: [map], id: str(uuid), rollout_options: map, rollout_steps: [map], updated_at: str(date-time)}, guardrail_metrics: [map], id: str(uuid), key: str, name: str, order_position: int(int64), targeting_rules: [map], type: str, updated_at: str(date-time), variant_weights: [map]}, id: str(uuid), type: str}} # Created\n@returns(202) {data: map{attributes: map{created_at: str(date-time), environment_ids: [str(uuid)], experiment_id: str?, exposure_schedule: map{absolute_start_time: str(date-time)?, allocation_id: str(uuid), control_variant_id: str?, created_at: str(date-time), guardrail_triggered_action: str?, guardrail_triggers: [map], id: str(uuid), rollout_options: map, rollout_steps: [map], updated_at: str(date-time)}, guardrail_metrics: [map], id: str(uuid), key: str, name: str, order_position: int(int64), targeting_rules: [map], type: str, updated_at: str(date-time), variant_weights: [map]}, id: str(uuid), type: str}} # Accepted - Approval required for this change\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"key\":\"prod-rollout\",\"name\":\"Production Rollout\",\"type\":\"FEATURE_GATE\",\"variant_weights\":[{\"value\":50,\"variant_id\":\"550e8400-e29b-41d4-a716-446655440001\"},{\"value\":50,\"variant_id\":\"550e8400-e29b-41d4-a716-446655440002\"}]},\"type\":\"allocations\"}}\n\n@endpoint PUT /api/v2/feature-flags/{feature_flag_id}/environments/{environment_id}/allocations\n@desc Update targeting rules for a flag\n@required {feature_flag_id: str(uuid) # The ID of the feature flag., environment_id: str(uuid) # The ID of the environment., data: [map{attributes!: map, type!: str}] # Targeting rules (allocations) to replace existing ones with.}\n@returns(200) {data: [map]} # OK\n@returns(202) {data: [map]} # Accepted - Approval required for this change\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":[{\"attributes\":{\"key\":\"prod-rollout\",\"name\":\"Production Rollout\",\"type\":\"FEATURE_GATE\",\"variant_weights\":[{\"value\":50,\"variant_id\":\"550e8400-e29b-41d4-a716-446655440001\"},{\"value\":50,\"variant_id\":\"550e8400-e29b-41d4-a716-446655440002\"}]},\"type\":\"allocations\"}]}\n\n@endpoint POST /api/v2/feature-flags/{feature_flag_id}/environments/{environment_id}/disable\n@desc Disable a feature flag in an environment\n@required {feature_flag_id: str(uuid) # The ID of the feature flag., environment_id: str(uuid) # The ID of the environment.}\n@returns(200) OK\n@returns(202) Accepted - Approval required for this change\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/feature-flags/{feature_flag_id}/environments/{environment_id}/enable\n@desc Enable a feature flag in an environment\n@required {feature_flag_id: str(uuid) # The ID of the feature flag., environment_id: str(uuid) # The ID of the environment.}\n@returns(200) OK\n@returns(202) Accepted - Approval required for this change\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/feature-flags/{feature_flag_id}/unarchive\n@desc Unarchive a feature flag\n@required {feature_flag_id: str(uuid) # The ID of the feature flag.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time)?, created_at: str(date-time), created_by: str(uuid), description: str, distribution_channel: str, feature_flag_environments: [map], json_schema: str?, key: str, last_updated_by: str(uuid), name: str, require_approval: bool, staleness_status: str, tags: [str], updated_at: str(date-time), value_type: str, variants: [map]}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/feature-flags/{feature_flag_id}/variants\n@desc Add a variant to a feature flag\n@required {feature_flag_id: str(uuid) # The ID of the feature flag., key: str # The unique key of the variant., name: str # The name of the variant., value: str # The value of the variant as a string.}\n@returns(201) {created_at: str(date-time), id: str(uuid), key: str, name: str, updated_at: str(date-time), value: str} # Created\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict - A variant with this key already exists on the flag., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"key\":\"dark\",\"name\":\"Dark Theme\",\"value\":\"dark\"},\"type\":\"variants\"}}\n\n@endpoint DELETE /api/v2/feature-flags/{feature_flag_id}/variants/{variant_id}\n@desc Delete a variant\n@required {feature_flag_id: str(uuid) # The ID of the feature flag., variant_id: str(uuid) # The ID of the variant.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict - A pending suggestion already exists for this property., 429: Too many requests}\n\n@endpoint PUT /api/v2/feature-flags/{feature_flag_id}/variants/{variant_id}\n@desc Update a variant\n@required {feature_flag_id: str(uuid) # The ID of the feature flag., variant_id: str(uuid) # The ID of the variant.}\n@optional {name: str # The display name of the variant., value: str # The value of the variant as a string.}\n@returns(200) {created_at: str(date-time), id: str(uuid), key: str, name: str, updated_at: str(date-time), value: str} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict - A pending suggestion already exists for this property., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Dark Theme Updated\",\"value\":\"dark_v2\"},\"id\":\"550e8400-e29b-41d4-a716-446655440002\",\"type\":\"variants\"}}\n\n@endpoint GET /api/v2/fleet/agent_versions\n@desc List available Datadog Agent versions\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64)}}} # OK\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/fleet/agents\n@desc List all Datadog Agents\n@optional {page_number: int(int64)=0 # Page number for pagination, starting at 0., page_size: int(int64)=10 # Number of agents to return per page. Maximum value is 100. Defaults to 10., filter: str # Filter string to narrow down agent results., tags: str # Comma-separated list of tag keys to select which tags are included in each agent's `tags` attribute. Does not filter which agents are returned., sort_attribute: str # Agent attribute to sort results by. Must be a supported attribute name; unsupported values return a 400 error., sort_descending: bool # Set to `true` to sort results in descending order. Defaults to ascending.}\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/fleet/agents/{agent_key}\n@desc Get detailed information about an agent\n@required {agent_key: str # The unique identifier (Agent key) for the Datadog Agent. Must be a 32-character lowercase hexadecimal string.}\n@optional {include: str # Comma-separated list of additional fields to include in the response. Valid values are `integrations` and `configuration_files`. Omitting this parameter returns only `agent_infos`. Unrecognized values are silently ignored rather than causing an error.}\n@returns(200) {data: map{attributes: map{agent_infos: map{active_ha_agent: str, agent_version: str, api_key_name: str, api_key_uuid: str, cloud_provider: str, cluster_name: str, config_id: str, datadog_agent_key: str, datadog_data_center: str, ecs_fargate_cluster_name: str, ecs_fargate_task_arn: str, enabled_products: [str], env: [str], first_seen_at: int(int64), ha_agent_hosts: [str], ha_agent_state: str, hostname: str, hostname_aliases: [str], install_method_installer_version: str, install_method_tool: str, ip_addresses: [str], is_single_step_instrumentation_enabled: bool, last_restart_at: int(int64), os: str, os_version: str, otel_collectors: [map], pod_name: str, preferred_ha_active_agent: str, python_version: str, region: [str], remote_agent_management: str, remote_config_status: str, services: [str], support_agent_upgrade: bool, tags: [str], team: str}, configuration_files: map{agent_configuration: map, application_monitoring_configuration: map, otel_collectors_configuration: [map], security_agent_configuration: map, system_probe_configuration: map}, integrations: map{configuration_files: [map], error_integrations: [map], missing_integrations: [map], warning_integrations: [map], working_integrations: [map]}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/fleet/deployments\n@desc List all deployments\n@optional {page_size: int(int64)=10 # Number of deployments to return per page. Maximum value is 100., page_number: int(int64)=0 # Page number for pagination, starting at 0., sort: str # Field to sort results by (for example, `start_date`). Must be a supported field name; unsupported values return a 400 error., ascending: bool # Set to `true` to sort in ascending order. This setting has no effect unless `sort` is also set. Defaults to descending order., filter: str # Query used to filter deployments. Uses the Datadog query syntax. Filtering on an unsupported field returns a 400 error. For example: - `status:failed` or `status:done_with_errors`: deployments that need investigation. - `status:running`: deployments currently in flight. - `update_type:update_package` or `update_type:update_config_operations`: deployments of a given type.}\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/fleet/deployments/configure\n@desc Create a configuration deployment\n@required {data: map{attributes!: map, type!: str} # Data for creating a new v2 configuration deployment.}\n@returns(200) {data: map{attributes: map{dry_run: map{config_validated: bool, non_upgradable_by_reason: map, non_upgradable_hosts: int(int64)}, query: str, total_hosts: int(int64)}, id: str, type: str}} # OK\n@returns(201) {data: map{attributes: map{author: str, config_operations: [map], duration_seconds: int(int64), error_summary: str, estimated_finished_at: int(int64), finished_at: int(int64), is_scheduled: bool, query: str, schedule_id: str, started_at: int(int64), status: str, target_versions: [str], total_hosts: int(int64), update_type: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"config_operations\":[{\"file_op\":\"merge-patch\",\"file_path\":\"/datadog.yaml\",\"patch\":{\"apm_config\":{\"enabled\":true},\"log_level\":\"info\",\"logs_enabled\":true}}],\"filter_query\":\"env:prod AND datacenter:us-east-1\"},\"type\":\"deployment\"}}\n\n@endpoint POST /api/v2/fleet/deployments/upgrade\n@desc Upgrade hosts\n@required {data: map{attributes!: map, type!: str} # Data for creating a new v2 package upgrade deployment.}\n@returns(201) {data: map{attributes: map{author: str, config_operations: [map], duration_seconds: int(int64), error_summary: str, estimated_finished_at: int(int64), finished_at: int(int64), is_scheduled: bool, query: str, schedule_id: str, started_at: int(int64), status: str, target_versions: [str], total_hosts: int(int64), update_type: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"filter_query\":\"env:prod AND service:web\",\"target_packages\":[{\"name\":\"datadog-agent\",\"version\":\"7.52.0\"}]},\"type\":\"deployment\"}}\n\n@endpoint GET /api/v2/fleet/deployments/{deployment_id}\n@desc Get a deployment by ID\n@required {deployment_id: str # The unique identifier of the deployment to retrieve.}\n@returns(200) {data: map{attributes: map{author: str, canceled_hosts: int(int64), config_operations: [map], duration_seconds: int(int64), error_summary: str, estimated_finished_at: int(int64), failed_hosts: int(int64), high_level_status: str, hosts: [map], is_scheduled: bool, query: str, running_hosts: int(int64), schedule_id: str, skipped_hosts: int(int64), succeeded_hosts: int(int64), target_versions: [str], total_hosts: int(int64), update_type: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/fleet/deployments/{deployment_id}/cancel\n@desc Cancel a deployment\n@required {deployment_id: str # The unique identifier of the deployment to cancel.}\n@returns(200) {data: map{attributes: map{message: str, status: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/fleet/schedules\n@desc List all schedules\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/fleet/schedules/{id}\n@desc Get a schedule by ID\n@required {id: str # The unique identifier of the schedule to retrieve.}\n@returns(200) {data: map{attributes: map{created_at: str, created_by: str, is_default: bool, name: str, next_run: str, notification_rule: map{handles: [str], tags: [str]}, query: str, rule: map{days_of_week: [str], interval: int(int64), maintenance_window_duration: int(int64), start_maintenance_window: str, timezone: str}, status: str, updated_at: str, updated_by: str, version_to_latest: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/forms\n@desc List forms\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n\n@endpoint POST /api/v2/forms\n@desc Create a form\n@required {data: map{attributes!: map, type!: str} # The data for creating a form.}\n@returns(200) {data: map{attributes: map{active: bool, anonymous: bool, created_at: str(date-time), datastore_config: map{datastore_id: str(uuid), primary_column_name: str, primary_key_generation_strategy: str}, description: str, end_date: str(date-time)?, has_submitted: bool?, idp_survey: bool, modified_at: str(date-time), name: str, org_id: int(int64), publication: map{created_at: str(date-time), form_id: str(uuid), form_version: int(int64), id: str, modified_at: str(date-time), org_id: int(int64), publish_seq: int(int64), user_id: int(int64), user_uuid: str(uuid)}, self_service: bool, single_response: bool, user_id: int(int64), user_uuid: str(uuid), version: map{created_at: str(date-time), data_definition: map, definition_signature: str, etag: str?, id: str, modified_at: str(date-time), state: str, ui_definition: map, user_id: int(int64), user_uuid: str(uuid), version: int(int64)}}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"anonymous\":false,\"data_definition\":{},\"description\":\"A form to collect user feedback.\",\"idp_survey\":false,\"name\":\"User Feedback Form\",\"single_response\":false,\"ui_definition\":{}},\"type\":\"forms\"}}\n\n@endpoint POST /api/v2/forms/create_and_publish\n@desc Create and publish a form\n@required {data: map{attributes!: map, type!: str} # The data for creating a form.}\n@returns(200) {data: map{attributes: map{active: bool, anonymous: bool, created_at: str(date-time), datastore_config: map{datastore_id: str(uuid), primary_column_name: str, primary_key_generation_strategy: str}, description: str, end_date: str(date-time)?, has_submitted: bool?, idp_survey: bool, modified_at: str(date-time), name: str, org_id: int(int64), publication: map{created_at: str(date-time), form_id: str(uuid), form_version: int(int64), id: str, modified_at: str(date-time), org_id: int(int64), publish_seq: int(int64), user_id: int(int64), user_uuid: str(uuid)}, self_service: bool, single_response: bool, user_id: int(int64), user_uuid: str(uuid), version: map{created_at: str(date-time), data_definition: map, definition_signature: str, etag: str?, id: str, modified_at: str(date-time), state: str, ui_definition: map, user_id: int(int64), user_uuid: str(uuid), version: int(int64)}}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"anonymous\":false,\"data_definition\":{},\"description\":\"A form to collect user feedback.\",\"idp_survey\":false,\"name\":\"User Feedback Form\",\"single_response\":false,\"ui_definition\":{}},\"type\":\"forms\"}}\n\n@endpoint DELETE /api/v2/forms/{form_id}\n@desc Delete a form\n@required {form_id: str(uuid) # The ID of the form.}\n@returns(200) {data: map{id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n\n@endpoint GET /api/v2/forms/{form_id}\n@desc Get a form\n@required {form_id: str(uuid) # The ID of the form.}\n@optional {version: str=latest # The version of the form to retrieve. Use 'latest' for the most recent draft, 'published' for the last published version, or a specific version number.}\n@returns(200) {data: map{attributes: map{active: bool, anonymous: bool, created_at: str(date-time), datastore_config: map{datastore_id: str(uuid), primary_column_name: str, primary_key_generation_strategy: str}, description: str, end_date: str(date-time)?, has_submitted: bool?, idp_survey: bool, modified_at: str(date-time), name: str, org_id: int(int64), publication: map{created_at: str(date-time), form_id: str(uuid), form_version: int(int64), id: str, modified_at: str(date-time), org_id: int(int64), publish_seq: int(int64), user_id: int(int64), user_uuid: str(uuid)}, self_service: bool, single_response: bool, user_id: int(int64), user_uuid: str(uuid), version: map{created_at: str(date-time), data_definition: map, definition_signature: str, etag: str?, id: str, modified_at: str(date-time), state: str, ui_definition: map, user_id: int(int64), user_uuid: str(uuid), version: int(int64)}}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/forms/{form_id}\n@desc Update a form\n@required {form_id: str(uuid) # The ID of the form., data: map{attributes!: map, id: str(uuid), type!: str} # The data for updating a form.}\n@returns(200) {data: map{attributes: map{active: bool, anonymous: bool, created_at: str(date-time), datastore_config: map{datastore_id: str(uuid), primary_column_name: str, primary_key_generation_strategy: str}, description: str, end_date: str(date-time)?, has_submitted: bool?, idp_survey: bool, modified_at: str(date-time), name: str, org_id: int(int64), publication: map{created_at: str(date-time), form_id: str(uuid), form_version: int(int64), id: str, modified_at: str(date-time), org_id: int(int64), publish_seq: int(int64), user_id: int(int64), user_uuid: str(uuid)}, self_service: bool, single_response: bool, user_id: int(int64), user_uuid: str(uuid), version: map{created_at: str(date-time), data_definition: map, definition_signature: str, etag: str?, id: str, modified_at: str(date-time), state: str, ui_definition: map, user_id: int(int64), user_uuid: str(uuid), version: int(int64)}}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"form_update\":{\"description\":\"An updated description.\",\"name\":\"Updated Form Name\"}},\"type\":\"forms\"}}\n\n@endpoint POST /api/v2/forms/{form_id}/clone\n@desc Clone a form\n@required {form_id: str(uuid) # The ID of the form to clone., data: map{attributes: map, type!: str} # The data for cloning a form.}\n@returns(200) {data: map{attributes: map{active: bool, anonymous: bool, created_at: str(date-time), datastore_config: map{datastore_id: str(uuid), primary_column_name: str, primary_key_generation_strategy: str}, description: str, end_date: str(date-time)?, has_submitted: bool?, idp_survey: bool, modified_at: str(date-time), name: str, org_id: int(int64), publication: map{created_at: str(date-time), form_id: str(uuid), form_version: int(int64), id: str, modified_at: str(date-time), org_id: int(int64), publish_seq: int(int64), user_id: int(int64), user_uuid: str(uuid)}, self_service: bool, single_response: bool, user_id: int(int64), user_uuid: str(uuid), version: map{created_at: str(date-time), data_definition: map, definition_signature: str, etag: str?, id: str, modified_at: str(date-time), state: str, ui_definition: map, user_id: int(int64), user_uuid: str(uuid), version: int(int64)}}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Copy of My Form\"},\"type\":\"forms\"}}\n\n@endpoint POST /api/v2/forms/{form_id}/publish\n@desc Publish a form version\n@required {form_id: str(uuid) # The ID of the form., data: map{attributes!: map, type!: str} # The data for publishing a form version.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), form_id: str(uuid), form_version: int(int64), id: str, modified_at: str(date-time), org_id: int(int64), publish_seq: int(int64), user_id: int(int64), user_uuid: str(uuid)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"version\":1},\"type\":\"form_publications\"}}\n\n@endpoint POST /api/v2/forms/{form_id}/versions\n@desc Create or update a form version\n@required {form_id: str(uuid) # The ID of the form., data: map{attributes!: map, type!: str} # The data for creating or updating a form version.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), data_definition: map{description: str, properties: map, required: [str], title: str, type: str}, definition_signature: str, etag: str?, id: str, modified_at: str(date-time), state: str, ui_definition: map{ui:order: [str], ui:theme: map}, user_id: int(int64), user_uuid: str(uuid), version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"data_definition\":{},\"state\":\"draft\",\"ui_definition\":{},\"upsert_params\":{\"match_policy\":\"none\"}},\"type\":\"form_versions\"}}\n\n@endpoint POST /api/v2/forms/{form_id}/versions/upsert_and_publish\n@desc Upsert and publish a form version\n@required {form_id: str(uuid) # The ID of the form., data: map{attributes!: map, type!: str} # The data for upserting and publishing a form version.}\n@returns(200) {data: map{attributes: map{active: bool, anonymous: bool, created_at: str(date-time), datastore_config: map{datastore_id: str(uuid), primary_column_name: str, primary_key_generation_strategy: str}, description: str, end_date: str(date-time)?, has_submitted: bool?, idp_survey: bool, modified_at: str(date-time), name: str, org_id: int(int64), publication: map{created_at: str(date-time), form_id: str(uuid), form_version: int(int64), id: str, modified_at: str(date-time), org_id: int(int64), publish_seq: int(int64), user_id: int(int64), user_uuid: str(uuid)}, self_service: bool, single_response: bool, user_id: int(int64), user_uuid: str(uuid), version: map{created_at: str(date-time), data_definition: map, definition_signature: str, etag: str?, id: str, modified_at: str(date-time), state: str, ui_definition: map, user_id: int(int64), user_uuid: str(uuid), version: int(int64)}}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"data_definition\":{},\"ui_definition\":{},\"upsert_params\":{\"etag\":\"b51f08b698d88d8027a935d9db649774949f5fb41a0c559bfee6a9a13225c72d\"}},\"type\":\"form_versions\"}}\n\n@endpoint GET /api/v2/global_orgs\n@desc List global orgs\n@required {user_handle: str # The handle of the authenticated user.}\n@optional {page[limit]: int(int32)=100: any # Maximum number of results returned., page[cursor]: str # String to query the next page of results. This key is provided with each valid response from the API in `meta.page.next_cursor`.}\n@returns(200) {data: [map], links: map{next: str?, prev: str?, self: str}, meta: map{page: map{cursor: str, limit: int(int32), next_cursor: str?, prev_cursor: str?, type: str}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/governance/config\n@desc Get the Governance Console configuration\n@returns(200) {data: map{attributes: map{assignment_notifications_enabled: bool, enabled: bool, usage_attribution_configured: bool, xorg_insights_enabled: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/governance/control\n@desc List controls\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/governance/control/{detection_type}\n@desc Get a control\n@required {detection_type: str # The detection type that identifies the control, for example `unused_api_keys`.}\n@returns(200) {data: map{attributes: map{active_detections_count: int(int64), category: str, created_at: str(date-time), created_by: str, description: str, detection_parameters: map, insights: [str], last_detection_at: str(date-time)?, mitigated_detections_count: int(int64), mitigation_parameters: map, mitigation_type: str, mitigations: [map], name: str, priority: str, product: str, resource_type: str, resource_type_display_name: str, supported_detection_parameters: [map], type: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/governance/control/{detection_type}\n@desc Update a control\n@required {detection_type: str # The detection type that identifies the control, for example `unused_api_keys`., data: map{attributes: map, type!: str} # The data of a governance control update request.}\n@returns(200) {data: map{attributes: map{active_detections_count: int(int64), category: str, created_at: str(date-time), created_by: str, description: str, detection_parameters: map, insights: [str], last_detection_at: str(date-time)?, mitigated_detections_count: int(int64), mitigation_parameters: map, mitigation_type: str, mitigations: [map], name: str, priority: str, product: str, resource_type: str, resource_type_display_name: str, supported_detection_parameters: [map], type: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"detection_parameters\":{\"api_key_threshold\":60},\"mitigation_type\":\"revoke_api_key\"},\"type\":\"governance_control\"}}\n\n@endpoint GET /api/v2/governance/control/{detection_type}/detections\n@desc List control detections\n@required {detection_type: str # The detection type that identifies the control; for example, `unused_api_keys`.}\n@optional {filter[state]: str: any # Restrict the results to detections in the given state., filter[query]: str # Restrict the results to detections matching the given free-text query., sort: str # A comma-separated list of attributes to sort detections by. Prefix an attribute with `-` for descending order.  The attributes available for sorting are `id`, `created_at`, `assigned_to`, `detection_type`, `display_name`, `exception_at`, `mitigate_after`, `mitigated_at`, `priority`, `resource_id`, and `state`. Defaults to `created_at,-id`., page[number]: int(int64)=0 # The zero-based index of the page to return; the first page is 0., page[size]: int(int64) # The number of detections to return per page.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/governance/control/{detection_type}/notification_settings\n@desc Get control notification settings\n@required {detection_type: str # The detection type that identifies the control; for example, `unused_api_keys`.}\n@returns(200) {data: map{attributes: map{event_settings: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint PUT /api/v2/governance/control/{detection_type}/notification_settings\n@desc Update control notification settings\n@required {detection_type: str # The detection type that identifies the control; for example, `unused_api_keys`., data: map{attributes: map, type!: str} # The data of a control notification settings update request.}\n@returns(200) {data: map{attributes: map{event_settings: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"event_settings\":[{\"enabled\":true,\"event_type\":\"new_detection\",\"targets\":[{\"handle\":\"#governance-alerts\",\"type\":\"slack\"}]}]},\"type\":\"control_notification_settings\"}}\n\n@endpoint POST /api/v2/governance/detections/mitigate\n@desc Mitigate detections\n@required {data: map{attributes: map, type!: str} # The data of a governance mitigation request.}\n@returns(202) Accepted\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"detection_ids\":[\"3f9b2c1a-8d4e-4a6b-9c2f-1e7d5a0b3c4d\"],\"detection_type\":\"unused_api_keys\",\"mitigation_parameters\":{},\"mitigation_type\":\"revoke_api_key\"},\"type\":\"governance_control_detection\"}}\n\n@endpoint GET /api/v2/governance/detections/{detection_id}\n@desc Get a detection\n@required {detection_id: str # The unique identifier of the detection.}\n@returns(200) {data: map{attributes: map{assigned_team: str, assigned_to: str, assignment_source: str, control_id: str, created_at: str(date-time), detection_type: str, display_name: str, exception_at: str(date-time), exception_by: str, metadata: any, mitigate_after: str(date-time), mitigated_at: str(date-time), priority: int(int64), resource_id: str, resource_type: str, state: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/governance/detections/{detection_id}\n@desc Update a detection\n@required {detection_id: str # The unique identifier of the detection., data: map{attributes: map, type!: str} # The data of a governance control detection update request.}\n@returns(200) {data: map{attributes: map{assigned_team: str, assigned_to: str, assignment_source: str, control_id: str, created_at: str(date-time), detection_type: str, display_name: str, exception_at: str(date-time), exception_by: str, metadata: any, mitigate_after: str(date-time), mitigated_at: str(date-time), priority: int(int64), resource_id: str, resource_type: str, state: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assigned_to\":\"11111111-2222-3333-4444-555555555555\",\"state\":\"exception\"},\"type\":\"governance_control_detection\"}}\n\n@endpoint GET /api/v2/governance/insights\n@desc List insights\n@optional {filter[product]: [str]: any # Restrict the results to insights belonging to the given products. May be repeated to filter by multiple products. Matching is case-insensitive.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/governance/notification_settings\n@desc Get notification settings\n@returns(200) {data: map{attributes: map{assignment_notifications_enabled: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint PATCH /api/v2/governance/notification_settings\n@desc Update notification settings\n@required {data: map{attributes: map, type!: str} # The data of a governance notification settings update request.}\n@returns(200) {data: map{attributes: map{assignment_notifications_enabled: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assignment_notifications_enabled\":true},\"type\":\"governance_notification_settings\"}}\n\n@endpoint GET /api/v2/hamr\n@desc Get HAMR organization connection\n@returns(200) {data: map{attributes: map{hamr_status: int(int64), is_primary: bool, modified_at: str, modified_by: str, target_org_datacenter: str, target_org_name: str, target_org_uuid: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/hamr\n@desc Create or update HAMR organization connection\n@required {data: map{attributes!: map, id!: str, type!: str} # Data object for a HAMR organization connection request.}\n@returns(200) {data: map{attributes: map{hamr_status: int(int64), is_primary: bool, modified_at: str, modified_by: str, target_org_datacenter: str, target_org_name: str, target_org_uuid: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"hamr_status\":4,\"is_primary\":true,\"modified_by\":\"admin@example.com\",\"target_org_datacenter\":\"us1\",\"target_org_name\":\"Production Backup Org\",\"target_org_uuid\":\"660f9511-f3ac-52e5-b827-557766551111\"},\"id\":\"550e8400-e29b-41d4-a716-446655440000\",\"type\":\"hamr_org_connections\"}}\n\n@endpoint GET /api/v2/identity_providers\n@desc List identity providers\n@returns(200) {data: [map]} # OK\n@errors {403: Authentication error, 429: Too many requests}\n\n@endpoint PATCH /api/v2/identity_providers/{idp_id}\n@desc Update an identity provider\n@required {idp_id: str # The ID of the identity provider., data: map{attributes!: map, id!: str, type!: str} # Data object for updating an organization identity provider.}\n@returns(200) {data: map{attributes: map{authentication_method: str, enabled: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true},\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"identity_providers\"}}\n\n@endpoint GET /api/v2/identity_providers/{idp_id}/users\n@desc List users with an identity provider override\n@required {idp_id: str # The ID of the identity provider.}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str=email # User attribute to order results by. Options include `email` and `name`., sort_dir: str # Direction of sort. Options: `asc`, `desc`., filter: str # Filter users by the given string. Defaults to no filtering., filter[status]: str # Filter on status attribute. Comma-separated list, with possible values `Active`, `Pending`, and `Disabled`. Defaults to no filtering.}\n@returns(200) {data: [map], included: [any], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/idp/entity_integrations/{integration_id}\n@desc Delete an entity integration configuration\n@required {integration_id: str # The identifier of the integration whose configuration is being managed. Supported values are `github`, `jira`, and `pagerduty`.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/idp/entity_integrations/{integration_id}\n@desc Get an entity integration configuration\n@required {integration_id: str # The identifier of the integration whose configuration is being managed. Supported values are `github`, `jira`, and `pagerduty`.}\n@returns(200) {data: map{attributes: map{config: map, integration_id: str, org_id: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/idp/entity_integrations/{integration_id}\n@desc Create or update entity integration configuration\n@required {integration_id: str # The identifier of the integration whose configuration is being managed. Supported values are `github`, `jira`, and `pagerduty`., data: map{attributes!: map, type!: str} # JSON:API resource object used in a request to create or update an entity integration configuration.}\n@returns(200) {data: map{attributes: map{config: map, integration_id: str, org_id: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"config\":{\"enabled_repos\":[{\"github_org_name\":\"myorg\",\"hostname\":\"github.com\",\"repo_name\":\"myrepo\"}]}},\"type\":\"entity_integration_config_requests\"}}\n\n@endpoint GET /api/v2/incidents\n@desc Get a list of incidents\n@optional {include: [str] # Specifies which types of related objects should be included in the response., page[size]: int(int64)=10 # Size for a given page. The maximum allowed value is 100., page[offset]: int(int64)=0 # Specific offset to use as the beginning of the returned page.}\n@returns(200) {data: [map], included: [any], meta: map{pagination: map{next_offset: int(int64), offset: int(int64), size: int(int64)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents\n@desc Create an incident\n@required {data: map{attributes!: map, relationships: map, type!: str} # Incident data for a create request.}\n@returns(201) {data: map{attributes: map{archived: str(date-time)?, case_id: int(int64)?, created: str(date-time), customer_impact_duration: int(int64), customer_impact_end: str(date-time)?, customer_impact_scope: str?, customer_impact_start: str(date-time)?, customer_impacted: bool, declared: str(date-time), declared_by: map?{image_48_px: str, name: str}, declared_by_uuid: str?, detected: str(date-time)?, fields: map, incident_type_uuid: str, is_test: bool, modified: str(date-time), non_datadog_creator: map?{image_48_px: str, name: str}, notification_handles: [map]?, public_id: int(int64), resolved: str(date-time)?, severity: str, state: str?, time_to_detect: int(int64), time_to_internal_response: int(int64), time_to_repair: int(int64), time_to_resolve: int(int64), title: str, visibility: str?}, id: str, relationships: map{attachments: map{data: [map]}, commander_user: map?{data: map?}, created_by_user: map{data: map}, declared_by_user: map{data: map}, impacts: map{data: [map]}, integrations: map{data: [map]}, last_modified_by_user: map{data: map}, responders: map{data: [map]}, user_defined_fields: map{data: [map]}}, type: str}, included: [any]} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"customer_impact_scope\":\"Example customer impact scope\",\"customer_impacted\":false,\"fields\":{\"severity\":{\"type\":\"dropdown\",\"value\":\"SEV-5\"}},\"incident_type_uuid\":\"00000000-0000-0000-0000-000000000000\",\"initial_cells\":[{\"cell_type\":\"markdown\",\"content\":{\"content\":\"An example timeline cell message.\"},\"important\":false}],\"is_test\":false,\"notification_handles\":[{\"display_name\":\"Jane Doe\",\"handle\":\"@user@email.com\"},{\"display_name\":\"Slack Channel\",\"handle\":\"@slack-channel\"},{\"display_name\":\"Incident Workflow\",\"handle\":\"@workflow-from-incident\"}],\"title\":\"A test incident title\"},\"relationships\":{\"commander_user\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"users\"}}},\"type\":\"incidents\"}}\n\n@endpoint DELETE /api/v2/incidents/config/global/incident-handles\n@desc Delete global incident handle\n@returns(204) No Content\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/config/global/incident-handles\n@desc List global incident handles\n@optional {include: str # Comma-separated list of related resources to include in the response}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/config/global/incident-handles\n@desc Create global incident handle\n@required {data: map{attributes!: map, id: str, relationships: map, type!: str} # Data object representing an incident handle in a create or update request.}\n@optional {include: str # Comma-separated list of related resources to include in the response}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), fields: map{severity: [str]}, modified_at: str(date-time), name: str}, id: str, relationships: map?{commander_user: map{data: map}, created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"fields\":{\"severity\":[\"SEV-1\"]},\"name\":\"@incident-sev-1\"},\"id\":\"b2494081-cdf0-4205-b366-4e1dd4fdf0bf\",\"relationships\":{\"commander_user\":{\"data\":{\"id\":\"f7b538b1-ed7c-4e84-82de-fdf84a539d40\",\"type\":\"incident_types\"}},\"incident_type\":{\"data\":{\"id\":\"f7b538b1-ed7c-4e84-82de-fdf84a539d40\",\"type\":\"incident_types\"}}},\"type\":\"incidents_handles\"}}\n\n@endpoint PUT /api/v2/incidents/config/global/incident-handles\n@desc Update global incident handle\n@required {data: map{attributes!: map, id: str, relationships: map, type!: str} # Data object representing an incident handle in a create or update request.}\n@optional {include: str # Comma-separated list of related resources to include in the response}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), fields: map{severity: [str]}, modified_at: str(date-time), name: str}, id: str, relationships: map?{commander_user: map{data: map}, created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"fields\":{\"severity\":[\"SEV-1\"]},\"name\":\"@incident-sev-1\"},\"id\":\"b2494081-cdf0-4205-b366-4e1dd4fdf0bf\",\"relationships\":{\"commander_user\":{\"data\":{\"id\":\"f7b538b1-ed7c-4e84-82de-fdf84a539d40\",\"type\":\"incident_types\"}},\"incident_type\":{\"data\":{\"id\":\"f7b538b1-ed7c-4e84-82de-fdf84a539d40\",\"type\":\"incident_types\"}}},\"type\":\"incidents_handles\"}}\n\n@endpoint GET /api/v2/incidents/config/global/settings\n@desc Get global incident settings\n@returns(200) {data: map{attributes: map{analytics_dashboard_id: str, created: str(date-time), modified: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/config/global/settings\n@desc Update global incident settings\n@required {data: map{attributes: map, type!: str} # Data object in the global incident settings request.}\n@returns(200) {data: map{attributes: map{analytics_dashboard_id: str, created: str(date-time), modified: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"analytics_dashboard_id\":\"00000000-0000-0000-0000-000000000003-def\"},\"type\":\"incidents_global_settings\"}}\n\n@endpoint POST /api/v2/incidents/config/google-chat-configurations\n@desc Create an incident Google Chat configuration\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Google Chat configuration data in a create request.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), domain_id: str, modified_at: str(date-time), space_name_template: str, space_target_audience_id: str, space_time_zone: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"domain_id\":\"my-domain\",\"space_name_template\":\"{{incident.title}}\",\"space_target_audience_id\":\"123456789\",\"space_time_zone\":\"America/New_York\"},\"relationships\":{\"incident_type\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"incident_types\"}}},\"type\":\"google_chat_configurations\"}}\n\n@endpoint PATCH /api/v2/incidents/config/google-chat-configurations/{id}\n@desc Update an incident Google Chat configuration\n@required {id: str(uuid) # The UUID of the Google Chat configuration., data: map{attributes: map, id!: str(uuid), type!: str} # Google Chat configuration data in a patch request.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), domain_id: str, modified_at: str(date-time), space_name_template: str, space_target_audience_id: str, space_time_zone: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"domain_id\":\"updated-domain\"},\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"google_chat_configurations\"}}\n\n@endpoint POST /api/v2/incidents/config/google-meet-configurations\n@desc Create an incident Google Meet configuration\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Google Meet configuration data in a create request.}\n@returns(201) {data: map{attributes: map{allow_manual_meeting_creation: bool, auto_summarize: bool, created_at: str(date-time), modified_at: str(date-time)}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"allow_manual_meeting_creation\":true,\"auto_summarize\":false},\"relationships\":{\"incident_type\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"incident_types\"}}},\"type\":\"google_meet_configurations\"}}\n\n@endpoint PATCH /api/v2/incidents/config/google-meet-configurations/{id}\n@desc Update an incident Google Meet configuration\n@required {id: str(uuid) # The UUID of the Google Meet configuration., data: map{attributes: map, id!: str(uuid), type!: str} # Google Meet configuration data in a patch request.}\n@returns(200) {data: map{attributes: map{allow_manual_meeting_creation: bool, auto_summarize: bool, created_at: str(date-time), modified_at: str(date-time)}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"auto_summarize\":true},\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"google_meet_configurations\"}}\n\n@endpoint GET /api/v2/incidents/config/impact-fields\n@desc List incident impact fields\n@returns(200) {data: [map], included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/config/impact-fields\n@desc Create an incident impact field\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Impact field data in a create request.}\n@returns(201) {data: map{attributes: map{display_name: str, field_choices: [map], field_type: str, name: str, tag_key: str?}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"display_name\":\"Customer Impact Scope\",\"field_choices\":[{\"description\":\"Affects all customers\",\"display_name\":\"All Customers\",\"value\":\"all_customers\"},{\"description\":\"Affects some customers\",\"display_name\":\"Some Customers\",\"value\":\"some_customers\"}],\"field_type\":\"dropdown\",\"name\":\"customer_impact_scope\"},\"relationships\":{\"incident_type\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"incident_types\"}}},\"type\":\"impact_fields\"}}\n\n@endpoint DELETE /api/v2/incidents/config/impact-fields/{field_id}\n@desc Delete an incident impact field\n@required {field_id: str(uuid) # The UUID of the impact field.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/incidents/config/impact-fields/{field_id}\n@desc Update an incident impact field\n@required {field_id: str(uuid) # The UUID of the impact field., data: map{attributes!: map, relationships!: map, type!: str} # Impact field data in a create request.}\n@returns(200) {data: map{attributes: map{display_name: str, field_choices: [map], field_type: str, name: str, tag_key: str?}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"display_name\":\"Customer Impact Scope Updated\",\"field_type\":\"dropdown\",\"name\":\"customer_impact_scope\"},\"relationships\":{\"incident_type\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"incident_types\"}}},\"type\":\"impact_fields\"}}\n\n@endpoint GET /api/v2/incidents/config/notification-rules\n@desc List incident notification rules\n@optional {include: str # Comma-separated list of resources to include. Supported values: `created_by_user`, `last_modified_by_user`, `incident_type`, `notification_template`}\n@returns(200) {data: [map], included: [any], meta: map{pagination: map{next_offset: int(int64), offset: int(int64), size: int(int64)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/config/notification-rules\n@desc Create an incident notification rule\n@required {data: map{attributes!: map, relationships: map, type!: str} # Notification rule data for a create request.}\n@returns(201) {data: map{attributes: map{conditions: [map], created: str(date-time), enabled: bool, handles: [str], modified: str(date-time), renotify_on: [str], trigger: str, visibility: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}, notification_template: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"conditions\":[{\"field\":\"severity\",\"values\":[\"SEV-1\",\"SEV-2\"]}],\"enabled\":true,\"handles\":[\"@team-email@company.com\",\"@slack-channel\"],\"renotify_on\":[\"status\",\"severity\"],\"trigger\":\"incident_created_trigger\",\"visibility\":\"organization\"},\"relationships\":{\"incident_type\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"incident_types\"}},\"notification_template\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"notification_templates\"}}},\"type\":\"incident_notification_rules\"}}\n\n@endpoint DELETE /api/v2/incidents/config/notification-rules/{id}\n@desc Delete an incident notification rule\n@required {id: str(uuid) # The ID of the notification rule.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: `created_by_user`, `last_modified_by_user`, `incident_type`, `notification_template`}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/config/notification-rules/{id}\n@desc Get an incident notification rule\n@required {id: str(uuid) # The ID of the notification rule.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: `created_by_user`, `last_modified_by_user`, `incident_type`, `notification_template`}\n@returns(200) {data: map{attributes: map{conditions: [map], created: str(date-time), enabled: bool, handles: [str], modified: str(date-time), renotify_on: [str], trigger: str, visibility: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}, notification_template: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/incidents/config/notification-rules/{id}\n@desc Update an incident notification rule\n@required {id: str(uuid) # The ID of the notification rule., data: map{attributes!: map, id!: str(uuid), relationships: map, type!: str} # Notification rule data for an update request.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: `created_by_user`, `last_modified_by_user`, `incident_type`, `notification_template`}\n@returns(200) {data: map{attributes: map{conditions: [map], created: str(date-time), enabled: bool, handles: [str], modified: str(date-time), renotify_on: [str], trigger: str, visibility: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}, notification_template: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"conditions\":[{\"field\":\"severity\",\"values\":[\"SEV-1\",\"SEV-2\"]}],\"enabled\":true,\"handles\":[\"@team-email@company.com\",\"@slack-channel\"],\"renotify_on\":[\"status\",\"severity\"],\"trigger\":\"incident_created_trigger\",\"visibility\":\"organization\"},\"id\":\"00000000-0000-0000-0000-000000000001\",\"relationships\":{\"incident_type\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"incident_types\"}},\"notification_template\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"notification_templates\"}}},\"type\":\"incident_notification_rules\"}}\n\n@endpoint GET /api/v2/incidents/config/notification-templates\n@desc List incident notification templates\n@optional {filter[incident-type]: str(uuid): any # Optional incident type ID filter., include: str # Comma-separated list of relationships to include. Supported values: `created_by_user`, `last_modified_by_user`, `incident_type`}\n@returns(200) {data: [map], included: [any], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/config/notification-templates\n@desc Create incident notification template\n@required {data: map{attributes!: map, relationships: map, type!: str} # Notification template data for a create request.}\n@returns(201) {data: map{attributes: map{category: str, content: str, created: str(date-time), modified: str(date-time), name: str, subject: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"category\":\"alert\",\"content\":\"An incident has been declared.\\n\\nTitle: {{incident.title}}\\nSeverity: {{incident.severity}}\\nAffected Services: {{incident.services}}\\nStatus: {{incident.state}}\\n\\nPlease join the incident channel for updates.\",\"name\":\"Incident Alert Template\",\"subject\":\"{{incident.severity}} Incident: {{incident.title}}\"},\"relationships\":{\"incident_type\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"incident_types\"}}},\"type\":\"notification_templates\"}}\n\n@endpoint DELETE /api/v2/incidents/config/notification-templates/{id}\n@desc Delete a notification template\n@required {id: str(uuid) # The ID of the notification template.}\n@optional {include: str # Comma-separated list of relationships to include. Supported values: `created_by_user`, `last_modified_by_user`, `incident_type`}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/config/notification-templates/{id}\n@desc Get incident notification template\n@required {id: str(uuid) # The ID of the notification template.}\n@optional {include: str # Comma-separated list of relationships to include. Supported values: `created_by_user`, `last_modified_by_user`, `incident_type`}\n@returns(200) {data: map{attributes: map{category: str, content: str, created: str(date-time), modified: str(date-time), name: str, subject: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/config/notification-templates/{id}\n@desc Update incident notification template\n@required {id: str(uuid) # The ID of the notification template., data: map{attributes: map, id!: str(uuid), type!: str} # Notification template data for an update request.}\n@optional {include: str # Comma-separated list of relationships to include. Supported values: `created_by_user`, `last_modified_by_user`, `incident_type`}\n@returns(200) {data: map{attributes: map{category: str, content: str, created: str(date-time), modified: str(date-time), name: str, subject: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"category\":\"update\",\"content\":\"Incident Status Update:\\n\\nTitle: {{incident.title}}\\nNew Status: {{incident.state}}\\nSeverity: {{incident.severity}}\\nServices: {{incident.services}}\\nCommander: {{incident.commander}}\\n\\nFor more details, visit the incident page.\",\"name\":\"Incident Status Update Template\",\"subject\":\"Incident Update: {{incident.title}} - {{incident.state}}\"},\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"notification_templates\"}}\n\n@endpoint GET /api/v2/incidents/config/postmortem-templates\n@desc List postmortem templates\n@optional {filter[incident-type]: str(uuid): any # Filter postmortem templates by the associated incident type ID., sort: str=created_at # The attribute to sort results by. Prefix with `-` for descending order.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/config/postmortem-templates\n@desc Create postmortem template\n@required {data: map{attributes!: map, id: str, relationships: map, type!: str} # Data object for creating or updating a postmortem template.}\n@returns(201) {data: map{attributes: map{confluence_postmortem_settings: map{account_id: str, parent_id: str?, space_id: str}, content: str, createdAt: str(date-time), google_docs_postmortem_settings: map{account_id: str, parent_folder_id: str}, is_default: str(date-time)?, location: str, modifiedAt: str(date-time), name: str}, id: str, relationships: map{incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"content\":\"# Overview\\n\\n# What Happened\\n\\n# Timeline\\n\\n# Action Items\",\"name\":\"Standard Postmortem Template\"},\"relationships\":{\"incident_type\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000009\",\"type\":\"incident_types\"}}},\"type\":\"postmortem_templates\"}}\n\n@endpoint DELETE /api/v2/incidents/config/postmortem-templates/{template_id}\n@desc Delete postmortem template\n@required {template_id: str # The ID of the postmortem template.}\n@returns(204) No Content\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/config/postmortem-templates/{template_id}\n@desc Get postmortem template\n@required {template_id: str # The ID of the postmortem template.}\n@returns(200) {data: map{attributes: map{confluence_postmortem_settings: map{account_id: str, parent_id: str?, space_id: str}, content: str, createdAt: str(date-time), google_docs_postmortem_settings: map{account_id: str, parent_folder_id: str}, is_default: str(date-time)?, location: str, modifiedAt: str(date-time), name: str}, id: str, relationships: map{incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/config/postmortem-templates/{template_id}\n@desc Update postmortem template\n@required {template_id: str # The ID of the postmortem template., data: map{attributes!: map, id: str, relationships: map, type!: str} # Data object for creating or updating a postmortem template.}\n@returns(200) {data: map{attributes: map{confluence_postmortem_settings: map{account_id: str, parent_id: str?, space_id: str}, content: str, createdAt: str(date-time), google_docs_postmortem_settings: map{account_id: str, parent_folder_id: str}, is_default: str(date-time)?, location: str, modifiedAt: str(date-time), name: str}, id: str, relationships: map{incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Standard Postmortem Template\"},\"id\":\"00000000-0000-0000-0000-000000000004\",\"type\":\"postmortem_templates\"}}\n\n@endpoint GET /api/v2/incidents/config/rules\n@desc List incident rules\n@optional {filter[task_id]: str: any # Filter rules by task ID., filter[trigger]: str # Filter rules by trigger., incidentTypeUUID: str(uuid) # Filter rules by incident type UUID.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/config/rules\n@desc Create an incident rule\n@required {data: map{attributes!: map, type!: str} # Incident rule data in a create request.}\n@returns(201) {data: map{attributes: map{condition: map{normalized_query: str?, raw_query: str?}, condition_table_type: int(int64), conditions: [map], created: str(date-time), created_by_uuid: str(uuid), deleted: str(date-time)?, enabled: bool, execution_type: int(int64), incident_settings_association_uuid: str(uuid)?, match_any_condition: bool, modified: str(date-time), modified_by_uuid: str(uuid), org_id: int(int64), task_id: str?, task_payload: str?, trigger: str}, id: str(uuid), type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"condition\":{\"raw_query\":\"severity:SEV-1\"},\"condition_table_type\":1,\"enabled\":true,\"execution_type\":1,\"task_id\":\"notify-incident-handles-job\",\"task_payload\":\"{}\",\"trigger\":\"incident_created_trigger\"},\"type\":\"incident_rules\"}}\n\n@endpoint DELETE /api/v2/incidents/config/rules/{rule_id}\n@desc Delete an incident rule\n@required {rule_id: str(uuid) # The UUID of the incident rule.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/config/rules/{rule_id}\n@desc Get an incident rule\n@required {rule_id: str(uuid) # The UUID of the incident rule.}\n@returns(200) {data: map{attributes: map{condition: map{normalized_query: str?, raw_query: str?}, condition_table_type: int(int64), conditions: [map], created: str(date-time), created_by_uuid: str(uuid), deleted: str(date-time)?, enabled: bool, execution_type: int(int64), incident_settings_association_uuid: str(uuid)?, match_any_condition: bool, modified: str(date-time), modified_by_uuid: str(uuid), org_id: int(int64), task_id: str?, task_payload: str?, trigger: str}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/config/rules/{rule_id}\n@desc Update an incident rule\n@required {rule_id: str(uuid) # The UUID of the incident rule., data: map{attributes: map, id!: str(uuid), type!: str} # Incident rule data in a patch request.}\n@returns(200) {data: map{attributes: map{condition: map{normalized_query: str?, raw_query: str?}, condition_table_type: int(int64), conditions: [map], created: str(date-time), created_by_uuid: str(uuid), deleted: str(date-time)?, enabled: bool, execution_type: int(int64), incident_settings_association_uuid: str(uuid)?, match_any_condition: bool, modified: str(date-time), modified_by_uuid: str(uuid), org_id: int(int64), task_id: str?, task_payload: str?, trigger: str}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":false},\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"incident_rules\"}}\n\n@endpoint GET /api/v2/incidents/config/types\n@desc Get a list of incident types\n@optional {include_deleted: bool=false # Include deleted incident types in the response.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/config/types\n@desc Create an incident type\n@required {data: map{attributes!: map, type!: str} # Incident type data for a create request.}\n@returns(201) {data: map{attributes: map{configuration: map{allow_incident_deletion: bool, allow_workflows: bool, create_message: str, editable_timestamps: bool, private_incidents: bool, private_incidents_by_default: bool, slug_source: str, test_incidents: bool}, createdAt: str(date-time), createdBy: str, description: str, is_default: bool, lastModifiedBy: str, modifiedAt: str(date-time), name: str, prefix: str}, id: str, relationships: map{created_by_user: map{data: map}, google_meet_configuration: map?{data: map?}, last_modified_by_user: map{data: map}, microsoft_teams_configuration: map?{data: map?}, zoom_configuration: map?{data: map?}}, type: str}} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"createdBy\":\"00000000-0000-0000-0000-000000000000\",\"description\":\"Any incidents that harm (or have the potential to) the confidentiality, integrity, or availability of our data.\",\"is_default\":false,\"lastModifiedBy\":\"00000000-0000-0000-0000-000000000000\",\"name\":\"Security Incident\",\"prefix\":\"IR\"},\"type\":\"incident_types\"}}\n\n@endpoint GET /api/v2/incidents/config/types/org-settings\n@desc List incident type org settings\n@optional {page[size]: int(int64): any # Maximum number of results to return., page[offset]: int(int64) # The offset for pagination., include-deleted: bool # Whether to include deleted records., include: str # Comma-separated list of related resources to include in the response.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint DELETE /api/v2/incidents/config/types/{incident_type_id}\n@desc Delete an incident type\n@required {incident_type_id: str # The UUID of the incident type.}\n@returns(204) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/config/types/{incident_type_id}\n@desc Get incident type details\n@required {incident_type_id: str # The UUID of the incident type.}\n@returns(200) {data: map{attributes: map{configuration: map{allow_incident_deletion: bool, allow_workflows: bool, create_message: str, editable_timestamps: bool, private_incidents: bool, private_incidents_by_default: bool, slug_source: str, test_incidents: bool}, createdAt: str(date-time), createdBy: str, description: str, is_default: bool, lastModifiedBy: str, modifiedAt: str(date-time), name: str, prefix: str}, id: str, relationships: map{created_by_user: map{data: map}, google_meet_configuration: map?{data: map?}, last_modified_by_user: map{data: map}, microsoft_teams_configuration: map?{data: map?}, zoom_configuration: map?{data: map?}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/config/types/{incident_type_id}\n@desc Update an incident type\n@required {incident_type_id: str # The UUID of the incident type., data: map{attributes!: map, id!: str, type!: str} # Incident type data for a patch request.}\n@returns(200) {data: map{attributes: map{configuration: map{allow_incident_deletion: bool, allow_workflows: bool, create_message: str, editable_timestamps: bool, private_incidents: bool, private_incidents_by_default: bool, slug_source: str, test_incidents: bool}, createdAt: str(date-time), createdBy: str, description: str, is_default: bool, lastModifiedBy: str, modifiedAt: str(date-time), name: str, prefix: str}, id: str, relationships: map{created_by_user: map{data: map}, google_meet_configuration: map?{data: map?}, last_modified_by_user: map{data: map}, microsoft_teams_configuration: map?{data: map?}, zoom_configuration: map?{data: map?}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"createdBy\":\"00000000-0000-0000-0000-000000000000\",\"description\":\"Any incidents that harm (or have the potential to) the confidentiality, integrity, or availability of our data. Note: This will notify the security team.\",\"is_default\":false,\"lastModifiedBy\":\"00000000-0000-0000-0000-000000000000\",\"name\":\"Security Incident\",\"prefix\":\"IR\"},\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"incident_types\"}}\n\n@endpoint GET /api/v2/incidents/config/types/{incident_type_id}/org-settings\n@desc Get org settings by incident type\n@required {incident_type_id: str(uuid) # The UUID of the incident type.}\n@optional {include: str # Comma-separated list of related resources to include in the response.}\n@returns(200) {data: map{attributes: map{created: str(date-time), modified: str(date-time), settings: map}, id: str(uuid), relationships: map{incident_type: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/config/user-defined-fields\n@desc Get a list of incident user-defined fields\n@optional {page[size]: int(int64)=1000: any # The number of results to return per page. Must be between 0 and 1000., page[number]: int(int64)=0 # The page number to retrieve, starting at 0., include-deleted: bool=false # When true, include soft-deleted fields in the response., filter[incident-type]: str # Filter results to fields associated with the given incident type UUID., include: str # Comma-separated list of related resources to include. Supported values are \"last_modified_by_user\", \"created_by_user\", and \"incident_type\".}\n@returns(200) {data: [map], meta: map{offset: int(int64), size: int(int64)}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/config/user-defined-fields\n@desc Create an incident user-defined field\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Data for creating an incident user-defined field.}\n@optional {include: str # Comma-separated list of related resources to include. Supported values are \"last_modified_by_user\", \"created_by_user\", and \"incident_type\".}\n@returns(201) {data: map{attributes: map{category: str?, collected: str?, created: str(date-time), default_value: str?, deleted: str(date-time)?, display_name: str, metadata: map?{category: str, search_limit_param: str, search_params: map, search_query_param: str, search_result_path: str, search_url: str}, modified: str(date-time)?, name: str, ordinal: str?, required: bool, reserved: bool, tag_key: str?, type: int(int32)?, valid_values: [map]?}, id: str, relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"category\":\"what_happened\",\"collected\":\"active\",\"default_value\":\"critical\",\"display_name\":\"Root Cause\",\"name\":\"root_cause\",\"ordinal\":\"1.5\",\"required\":false,\"tag_key\":\"datacenter\",\"type\":3,\"valid_values\":[{\"description\":\"A critical severity incident.\",\"display_name\":\"Critical\",\"short_description\":\"Critical\",\"value\":\"critical\"}]},\"relationships\":{\"incident_type\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"incident_types\"}}},\"type\":\"user_defined_field\"}}\n\n@endpoint DELETE /api/v2/incidents/config/user-defined-fields/{field_id}\n@desc Delete an incident user-defined field\n@required {field_id: str # The ID of the incident user-defined field.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/config/user-defined-fields/{field_id}\n@desc Get an incident user-defined field\n@required {field_id: str # The ID of the incident user-defined field.}\n@optional {include: str # Comma-separated list of related resources to include. Supported values are \"last_modified_by_user\", \"created_by_user\", and \"incident_type\".}\n@returns(200) {data: map{attributes: map{category: str?, collected: str?, created: str(date-time), default_value: str?, deleted: str(date-time)?, display_name: str, metadata: map?{category: str, search_limit_param: str, search_params: map, search_query_param: str, search_result_path: str, search_url: str}, modified: str(date-time)?, name: str, ordinal: str?, required: bool, reserved: bool, tag_key: str?, type: int(int32)?, valid_values: [map]?}, id: str, relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}} # OK\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/config/user-defined-fields/{field_id}\n@desc Update an incident user-defined field\n@required {field_id: str # The ID of the incident user-defined field., data: map{attributes!: map, id!: str, type!: str} # Data for updating an incident user-defined field.}\n@optional {include: str # Comma-separated list of related resources to include. Supported values are \"last_modified_by_user\", \"created_by_user\", and \"incident_type\".}\n@returns(200) {data: map{attributes: map{category: str?, collected: str?, created: str(date-time), default_value: str?, deleted: str(date-time)?, display_name: str, metadata: map?{category: str, search_limit_param: str, search_params: map, search_query_param: str, search_result_path: str, search_url: str}, modified: str(date-time)?, name: str, ordinal: str?, required: bool, reserved: bool, tag_key: str?, type: int(int32)?, valid_values: [map]?}, id: str, relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"category\":\"what_happened\",\"collected\":\"active\",\"default_value\":\"critical\",\"display_name\":\"Root Cause\",\"ordinal\":\"1.5\",\"required\":false,\"valid_values\":[{\"description\":\"A critical severity incident.\",\"display_name\":\"Critical\",\"short_description\":\"Critical\",\"value\":\"critical\"}]},\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"user_defined_field\"}}\n\n@endpoint GET /api/v2/incidents/config/user-defined-roles\n@desc List incident user-defined roles\n@optional {filter[incident-type]: str(uuid): any # Filter roles by incident type UUID., include: str # Comma-separated list of related resources to include in the response.}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/config/user-defined-roles\n@desc Create an incident user-defined role\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Data for creating an incident user-defined role.}\n@optional {include: str # Comma-separated list of related resources to include in the response.}\n@returns(201) {data: map{attributes: map{created: str(date-time), description: str?, modified: str(date-time), name: str, policy: map{is_single: bool}}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"The technical lead for the incident.\",\"name\":\"Tech Lead\",\"policy\":{\"is_single\":true}},\"relationships\":{\"incident_type\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"incident_types\"}}},\"type\":\"incident_user_defined_roles\"}}\n\n@endpoint DELETE /api/v2/incidents/config/user-defined-roles/{role_id}\n@desc Delete an incident user-defined role\n@required {role_id: str(uuid) # The UUID of the incident user-defined role.}\n@returns(204) No Content\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/config/user-defined-roles/{role_id}\n@desc Get an incident user-defined role\n@required {role_id: str(uuid) # The UUID of the incident user-defined role.}\n@optional {include: str # Comma-separated list of related resources to include in the response.}\n@returns(200) {data: map{attributes: map{created: str(date-time), description: str?, modified: str(date-time), name: str, policy: map{is_single: bool}}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/config/user-defined-roles/{role_id}\n@desc Update an incident user-defined role\n@required {role_id: str(uuid) # The UUID of the incident user-defined role., data: map{attributes: map, id!: str(uuid), type!: str} # Data for updating an incident user-defined role.}\n@optional {include: str # Comma-separated list of related resources to include in the response.}\n@returns(200) {data: map{attributes: map{created: str(date-time), description: str?, modified: str(date-time), name: str, policy: map{is_single: bool}}, id: str(uuid), relationships: map{created_by_user: map{data: map}, incident_type: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Updated Tech Lead\"},\"id\":\"00000000-0000-0000-0000-000000000002\",\"type\":\"incident_user_defined_roles\"}}\n\n@endpoint POST /api/v2/incidents/import\n@desc Import an incident\n@required {data: map{attributes!: map, relationships: map, type!: str} # Incident data for an import request.}\n@optional {include: [str] # Specifies which related object types to include in the response when importing an incident.}\n@returns(201) {data: map{attributes: map{archived: str(date-time)?, case_id: int(int64)?, created: str(date-time), created_by_uuid: str?, creation_idempotency_key: str?, customer_impact_end: str(date-time)?, customer_impact_scope: str?, customer_impact_start: str(date-time)?, declared: str(date-time)?, declared_by_uuid: str?, detected: str(date-time)?, fields: map, incident_type_uuid: str, is_test: bool, last_modified_by_uuid: str?, modified: str(date-time), non_datadog_creator: map?{image_48_px: str, name: str}, notification_handles: [map]?, public_id: int(int64), resolved: str(date-time)?, severity: str, state: str?, title: str, visibility: str?}, id: str, relationships: map{attachments: map{data: [map]}, commander_user: map?{data: map?}, created_by_user: map{data: map}, declared_by_user: map{data: map}, impacts: map{data: [map]}, incident_type: map{data: map}, integrations: map{data: [map]}, last_modified_by_user: map{data: map}, responders: map{data: [map]}, user_defined_fields: map{data: [map]}}, type: str}, included: [any]} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"declared\":\"2025-01-01T00:00:00Z\",\"detected\":\"2025-01-01T00:00:00Z\",\"fields\":{\"severity\":{\"value\":\"SEV-5\"},\"state\":{\"value\":\"active\"}},\"incident_type_uuid\":\"00000000-0000-0000-0000-000000000000\",\"resolved\":\"2025-01-01T01:00:00Z\",\"title\":\"Imported incident from external system\",\"visibility\":\"organization\"},\"relationships\":{\"commander_user\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"users\"}},\"declared_by_user\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"users\"}}},\"type\":\"incidents\"}}\n\n@endpoint GET /api/v2/incidents/search\n@desc Search for incidents\n@required {query: str # Specifies which incidents should be returned. The query can contain any number of incident facets joined by `ANDs`, along with multiple values for each of those facets joined by `OR`s. For example: `state:active AND severity:(SEV-2 OR SEV-1)`.}\n@optional {include: str # Specifies which types of related objects should be included in the response., sort: str # Specifies the order of returned incidents., page[size]: int(int64)=10 # Size for a given page. The maximum allowed value is 100., page[offset]: int(int64)=0 # Specific offset to use as the beginning of the returned page.}\n@returns(200) {data: map{attributes: map{facets: map{commander: [map], created_by: [map], fields: [map], impact: [map], last_modified_by: [map], postmortem: [map], responder: [map], severity: [map], state: [map], time_to_repair: [map], time_to_resolve: [map]}, incidents: [map], total: int(int32)}, type: str}, included: [any], meta: map{pagination: map{next_offset: int(int64), offset: int(int64), size: int(int64)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/incidents/{incident_id}\n@desc Delete an existing incident\n@required {incident_id: str # The UUID of the incident.}\n@returns(204) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/{incident_id}\n@desc Get the details of an incident\n@required {incident_id: str # The UUID of the incident.}\n@optional {include: [str] # Specifies which types of related objects should be included in the response.}\n@returns(200) {data: map{attributes: map{archived: str(date-time)?, case_id: int(int64)?, created: str(date-time), customer_impact_duration: int(int64), customer_impact_end: str(date-time)?, customer_impact_scope: str?, customer_impact_start: str(date-time)?, customer_impacted: bool, declared: str(date-time), declared_by: map?{image_48_px: str, name: str}, declared_by_uuid: str?, detected: str(date-time)?, fields: map, incident_type_uuid: str, is_test: bool, modified: str(date-time), non_datadog_creator: map?{image_48_px: str, name: str}, notification_handles: [map]?, public_id: int(int64), resolved: str(date-time)?, severity: str, state: str?, time_to_detect: int(int64), time_to_internal_response: int(int64), time_to_repair: int(int64), time_to_resolve: int(int64), title: str, visibility: str?}, id: str, relationships: map{attachments: map{data: [map]}, commander_user: map?{data: map?}, created_by_user: map{data: map}, declared_by_user: map{data: map}, impacts: map{data: [map]}, integrations: map{data: [map]}, last_modified_by_user: map{data: map}, responders: map{data: [map]}, user_defined_fields: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/{incident_id}\n@desc Update an existing incident\n@required {incident_id: str # The UUID of the incident., data: map{attributes: map, id!: str, relationships: map, type!: str} # Incident data for an update request.}\n@optional {include: [str] # Specifies which types of related objects should be included in the response.}\n@returns(200) {data: map{attributes: map{archived: str(date-time)?, case_id: int(int64)?, created: str(date-time), customer_impact_duration: int(int64), customer_impact_end: str(date-time)?, customer_impact_scope: str?, customer_impact_start: str(date-time)?, customer_impacted: bool, declared: str(date-time), declared_by: map?{image_48_px: str, name: str}, declared_by_uuid: str?, detected: str(date-time)?, fields: map, incident_type_uuid: str, is_test: bool, modified: str(date-time), non_datadog_creator: map?{image_48_px: str, name: str}, notification_handles: [map]?, public_id: int(int64), resolved: str(date-time)?, severity: str, state: str?, time_to_detect: int(int64), time_to_internal_response: int(int64), time_to_repair: int(int64), time_to_resolve: int(int64), title: str, visibility: str?}, id: str, relationships: map{attachments: map{data: [map]}, commander_user: map?{data: map?}, created_by_user: map{data: map}, declared_by_user: map{data: map}, impacts: map{data: [map]}, integrations: map{data: [map]}, last_modified_by_user: map{data: map}, responders: map{data: [map]}, user_defined_fields: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"customer_impact_scope\":\"Example customer impact scope\",\"customer_impacted\":false,\"fields\":{\"severity\":{\"type\":\"dropdown\",\"value\":\"SEV-5\"}},\"notification_handles\":[{\"display_name\":\"Jane Doe\",\"handle\":\"@user@email.com\"},{\"display_name\":\"Slack Channel\",\"handle\":\"@slack-channel\"},{\"display_name\":\"Incident Workflow\",\"handle\":\"@workflow-from-incident\"}],\"title\":\"A test incident title\"},\"id\":\"00000000-0000-0000-4567-000000000000\",\"relationships\":{\"commander_user\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"users\"}},\"integrations\":{\"data\":[{\"id\":\"00000000-abcd-0005-0000-000000000000\",\"type\":\"incident_integrations\"},{\"id\":\"00000000-abcd-0006-0000-000000000000\",\"type\":\"incident_integrations\"}]},\"postmortem\":{\"data\":{\"id\":\"00000000-0000-abcd-3000-000000000000\",\"type\":\"incident_postmortems\"}}},\"type\":\"incidents\"}}\n\n@endpoint POST /api/v2/incidents/{incident_id}/ai/postmortem\n@desc Get an AI-generated incident postmortem\n@required {incident_id: str # The UUID of the incident.}\n@returns(200) {data: map{attributes: map{action_items: str, customer_impact: str, executive_summary: str, key_timeline: str, lessons_learned: str, system_overview: str}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/{incident_id}/attachments\n@desc List incident attachments\n@required {incident_id: str # The UUID of the incident.}\n@optional {filter[attachment_type]: str: any # Filter attachments by type. Supported values are `1` (`postmortem`) and `2` (`link`)., include: str # Resource to include in the response. Supported value: `last_modified_by_user`.}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/{incident_id}/attachments\n@desc Create incident attachment\n@required {incident_id: str # The UUID of the incident.}\n@optional {include: str # Resource to include in the response. Supported value: `last_modified_by_user`., data: map{attributes: map, id: str, type!: str} # Attachment data for a create request.}\n@returns(201) {data: map{attributes: map{attachment: map{documentUrl: str, title: str}, attachment_type: str, modified: str(date-time)}, id: str, relationships: map{incident: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"attachment\":{\"documentUrl\":\"https://app.datadoghq.com/notebook/123/Postmortem-IR-123\",\"title\":\"Postmortem-IR-123\"},\"attachment_type\":\"postmortem\"},\"type\":\"incident_attachments\"}}\n\n@endpoint POST /api/v2/incidents/{incident_id}/attachments/postmortems\n@desc Create postmortem attachment\n@required {incident_id: str # The ID of the incident, data: map{attributes!: map, type!: str} # Postmortem attachment data}\n@returns(201) {data: map{attributes: map{attachment: map{documentUrl: str, title: str}, attachment_type: str, modified: str(date-time)}, id: str, relationships: map{incident: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"cells\":[{\"id\":\"cell-1\",\"type\":\"markdown\"}],\"content\":\"# Incident Report - IR-123\\n[...]\",\"postmortem_template_id\":\"93645509-874e-45c4-adfa-623bfeaead89-123\",\"title\":\"Postmortem-IR-123\"},\"type\":\"incident_attachments\"}}\n\n@endpoint DELETE /api/v2/incidents/{incident_id}/attachments/{attachment_id}\n@desc Delete incident attachment\n@required {incident_id: str # The UUID of the incident., attachment_id: str # The ID of the attachment.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/{incident_id}/attachments/{attachment_id}\n@desc Update incident attachment\n@required {incident_id: str # The UUID of the incident., attachment_id: str # The ID of the attachment.}\n@optional {include: str # Resource to include in the response. Supported value: `last_modified_by_user`., data: map{attributes: map, id: str, type!: str} # Attachment data for an update request.}\n@returns(200) {data: map{attributes: map{attachment: map{documentUrl: str, title: str}, attachment_type: str, modified: str(date-time)}, id: str, relationships: map{incident: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"attachment\":{\"documentUrl\":\"https://app.datadoghq.com/notebook/124/Postmortem-IR-124\",\"title\":\"Postmortem-IR-124\"}},\"id\":\"00000000-abcd-0002-0000-000000000000\",\"type\":\"incident_attachments\"}}\n\n@endpoint POST /api/v2/incidents/{incident_id}/cases/page\n@desc Create a page from an incident\n@required {incident_id: str # The UUID of the incident., data: map{attributes!: map, type!: str} # Page data in a create request.}\n@returns(200) {data: map{id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"A critical incident affecting production systems.\",\"services\":[\"web-store\"],\"tags\":[\"env:prod\"],\"target\":{\"identifier\":\"my-oncall-team\",\"type\":\"team_handle\"},\"title\":\"Production outage - SEV-1\"},\"type\":\"page\"}}\n\n@endpoint PATCH /api/v2/incidents/{incident_id}/configurations\n@desc Update an incident configuration\n@required {incident_id: str # The UUID of the incident., data: map{attributes: map, id!: str(uuid), type!: str} # Incident configuration data in a patch request.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), execute_integrations: bool, execute_notification_rules: bool, incident_id: str, include_in_analytics: bool, include_in_search: bool, modified_at: str(date-time)}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"include_in_search\":false},\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"incidents_configurations\"}}\n\n@endpoint POST /api/v2/incidents/{incident_id}/configurations\n@desc Create an incident configuration\n@required {incident_id: str # The UUID of the incident., data: map{attributes: map, type!: str} # Incident configuration data in a create request.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), execute_integrations: bool, execute_notification_rules: bool, incident_id: str, include_in_analytics: bool, include_in_search: bool, modified_at: str(date-time)}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"execute_integrations\":true,\"execute_notification_rules\":true,\"include_in_analytics\":true,\"include_in_search\":true},\"type\":\"incidents_configurations\"}}\n\n@endpoint GET /api/v2/incidents/{incident_id}/impacts\n@desc List an incident's impacts\n@required {incident_id: str # The UUID of the incident.}\n@optional {include: [str] # Specifies which related resources should be included in the response.}\n@returns(200) {data: [map], included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/{incident_id}/impacts\n@desc Create an incident impact\n@required {incident_id: str # The UUID of the incident., data: map{attributes!: map, type!: str} # Incident impact data for a create request.}\n@optional {include: [str] # Specifies which related resources should be included in the response.}\n@returns(201) {data: map{attributes: map{created: str(date-time), description: str, end_at: str(date-time)?, fields: map, impact_type: str, modified: str(date-time), start_at: str(date-time)}, id: str, relationships: map{created_by_user: map{data: map}, incident: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Service was unavailable for external users\",\"end_at\":\"2025-08-29T13:17:00Z\",\"fields\":{\"customers_impacted\":\"all\",\"products_impacted\":[\"shopping\",\"marketing\"]},\"start_at\":\"2025-08-28T13:17:00Z\"},\"type\":\"incident_impacts\"}}\n\n@endpoint DELETE /api/v2/incidents/{incident_id}/impacts/{impact_id}\n@desc Delete an incident impact\n@required {incident_id: str # The UUID of the incident., impact_id: str # The UUID of the incident impact.}\n@returns(204) No Content\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/{incident_id}/impacts/{impact_id}\n@desc Update an incident impact\n@required {incident_id: str # The UUID of the incident., impact_id: str # The UUID of the incident impact., data: map{attributes: map, type!: str} # Incident impact data for a patch request.}\n@optional {include: [str] # Specifies which related resources should be included in the response.}\n@returns(200) {data: map{attributes: map{created: str(date-time), description: str, end_at: str(date-time)?, fields: map, impact_type: str, modified: str(date-time), start_at: str(date-time)}, id: str, relationships: map{created_by_user: map{data: map}, incident: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Patched service impact description\"},\"type\":\"incident_impacts\"}}\n\n@endpoint POST /api/v2/incidents/{incident_id}/page\n@desc Create an on-call page from an incident\n@required {incident_id: str # The UUID of the incident., data: map{attributes!: map, type!: str} # On-call page data in a create request.}\n@returns(200) {data: map{id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"A critical incident affecting production systems.\",\"services\":[\"web-store\"],\"target\":{\"identifier\":\"my-oncall-team\",\"type\":\"team_handle\"},\"title\":\"Production outage - SEV-1\"},\"type\":\"page\"}}\n\n@endpoint POST /api/v2/incidents/{incident_id}/pages/link\n@desc Link a page to an incident\n@required {incident_id: str # The UUID of the incident., data: map{attributes: map, id!: str, type!: str} # On-call page data in a link request.}\n@returns(201) {data: map{attributes: map{created: str(date-time), incident_id: str, integration_type: int(int32), metadata: any, modified: str(date-time), status: int(int32)}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 409: Conflict - page already linked to incident., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"key\":\"PAGE-12345\",\"page_target\":{\"identifier\":\"my-oncall-team\",\"type\":\"team_handle\"}},\"id\":\"PAGE-12345\",\"type\":\"page\"}}\n\n@endpoint GET /api/v2/incidents/{incident_id}/relationships/integrations\n@desc Get a list of an incident's integration metadata\n@required {incident_id: str # The UUID of the incident.}\n@returns(200) {data: [map], included: [any], meta: map{pagination: map{next_offset: int(int64), offset: int(int64), size: int(int64)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/{incident_id}/relationships/integrations\n@desc Create an incident integration metadata\n@required {incident_id: str # The UUID of the incident., data: map{attributes!: map, type!: str} # Incident integration metadata data for a create request.}\n@returns(201) {data: map{attributes: map{created: str(date-time), incident_id: str, integration_type: int(int32), metadata: any, modified: str(date-time), status: int(int32)}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"incident_id\":\"00000000-aaaa-0000-0000-000000000000\",\"integration_type\":1,\"metadata\":{\"channels\":[{\"channel_id\":\"C0123456789\",\"channel_name\":\"#new-channel\",\"redirect_url\":\"https://slack.com/app_redirect?channel=C0123456789&team=T01234567\",\"team_id\":\"T01234567\"}]}},\"type\":\"incident_integrations\"}}\n\n@endpoint DELETE /api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id}\n@desc Delete an incident integration metadata\n@required {incident_id: str # The UUID of the incident., integration_metadata_id: str # The UUID of the incident integration metadata.}\n@returns(204) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id}\n@desc Get incident integration metadata details\n@required {incident_id: str # The UUID of the incident., integration_metadata_id: str # The UUID of the incident integration metadata.}\n@returns(200) {data: map{attributes: map{created: str(date-time), incident_id: str, integration_type: int(int32), metadata: any, modified: str(date-time), status: int(int32)}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id}\n@desc Update an existing incident integration metadata\n@required {incident_id: str # The UUID of the incident., integration_metadata_id: str # The UUID of the incident integration metadata., data: map{attributes!: map, type!: str} # Incident integration metadata data for a patch request.}\n@returns(200) {data: map{attributes: map{created: str(date-time), incident_id: str, integration_type: int(int32), metadata: any, modified: str(date-time), status: int(int32)}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"incident_id\":\"00000000-aaaa-0000-0000-000000000000\",\"integration_type\":1,\"metadata\":{\"channels\":[{\"channel_id\":\"C0123456789\",\"channel_name\":\"#updated-channel-name\",\"redirect_url\":\"https://slack.com/app_redirect?channel=C0123456789&team=T01234567\",\"team_id\":\"T01234567\"}]}},\"type\":\"incident_integrations\"}}\n\n@endpoint GET /api/v2/incidents/{incident_id}/relationships/todos\n@desc Get a list of an incident's todos\n@required {incident_id: str # The UUID of the incident.}\n@returns(200) {data: [map], included: [any], meta: map{pagination: map{next_offset: int(int64), offset: int(int64), size: int(int64)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/{incident_id}/relationships/todos\n@desc Create an incident todo\n@required {incident_id: str # The UUID of the incident., data: map{attributes!: map, type!: str} # Incident todo data for a create request.}\n@returns(201) {data: map{attributes: map{assignees: [any], completed: str?, content: str, created: str(date-time), due_date: str?, incident_id: str, modified: str(date-time)}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # CREATED\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assignees\":[\"@test.user@test.com\"],\"completed\":\"2023-03-06T22:00:00.000000+00:00\",\"content\":\"Restore lost data.\",\"due_date\":\"2023-07-10T05:00:00.000000+00:00\",\"incident_id\":\"00000000-aaaa-0000-0000-000000000000\"},\"type\":\"incident_todos\"}}\n\n@endpoint DELETE /api/v2/incidents/{incident_id}/relationships/todos/{todo_id}\n@desc Delete an incident todo\n@required {incident_id: str # The UUID of the incident., todo_id: str # The UUID of the incident todo.}\n@returns(204) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/{incident_id}/relationships/todos/{todo_id}\n@desc Get incident todo details\n@required {incident_id: str # The UUID of the incident., todo_id: str # The UUID of the incident todo.}\n@returns(200) {data: map{attributes: map{assignees: [any], completed: str?, content: str, created: str(date-time), due_date: str?, incident_id: str, modified: str(date-time)}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/{incident_id}/relationships/todos/{todo_id}\n@desc Update an incident todo\n@required {incident_id: str # The UUID of the incident., todo_id: str # The UUID of the incident todo., data: map{attributes!: map, type!: str} # Incident todo data for a patch request.}\n@returns(200) {data: map{attributes: map{assignees: [any], completed: str?, content: str, created: str(date-time), due_date: str?, incident_id: str, modified: str(date-time)}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assignees\":[\"@test.user@test.com\"],\"completed\":\"2023-03-06T22:00:00.000000+00:00\",\"content\":\"Restore lost data.\",\"due_date\":\"2023-07-10T05:00:00.000000+00:00\",\"incident_id\":\"00000000-aaaa-0000-0000-000000000000\"},\"type\":\"incident_todos\"}}\n\n@endpoint GET /api/v2/incidents/{incident_id}/responders\n@desc List incident responders\n@required {incident_id: str # The UUID of the incident.}\n@returns(200) {data: [map], included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/{incident_id}/responders\n@desc Create an incident responder\n@required {incident_id: str # The UUID of the incident., data: map{relationships!: map, type!: str} # Incident responder data in a create request.}\n@returns(201) {data: map{attributes: map{created: str(date-time), external_id: str?, external_source: str?, is_billable: bool, last_active: str(date-time)?, meta: map?, modified: str(date-time)}, id: str(uuid), relationships: map{created_by: map{data: map}, last_modified_by: map{data: map}, role_assignments: map{data: [map]}, user: map?{data: map?}}, type: str}, included: [map]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"relationships\":{\"user\":{\"data\":{\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"users\"}}},\"type\":\"incident_responders\"}}\n\n@endpoint DELETE /api/v2/incidents/{incident_id}/responders/{responder_id}\n@desc Delete an incident responder\n@required {incident_id: str # The UUID of the incident., responder_id: str(uuid) # The UUID of the incident responder.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/incidents/{incident_id}/responders/{responder_id}\n@desc Get an incident responder\n@required {incident_id: str # The UUID of the incident., responder_id: str(uuid) # The UUID of the incident responder.}\n@returns(200) {data: map{attributes: map{created: str(date-time), external_id: str?, external_source: str?, is_billable: bool, last_active: str(date-time)?, meta: map?, modified: str(date-time)}, id: str(uuid), relationships: map{created_by: map{data: map}, last_modified_by: map{data: map}, role_assignments: map{data: [map]}, user: map?{data: map?}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/{incident_id}/servicenow-records\n@desc Create an incident ServiceNow record\n@required {incident_id: str # The UUID of the incident., data: map{attributes!: map, type!: str} # ServiceNow record data in a create request.}\n@returns(201) {data: map{attributes: map{created: str(date-time), incident_id: str, integration_type: int(int32), metadata: any, modified: str(date-time), status: int(int32)}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assignment_group\":\"IT Support\",\"configuration_item_mapping\":\"my-service\",\"instance_name\":\"my-instance\"},\"type\":\"incident_servicenow_record_prompt\"}}\n\n@endpoint GET /api/v2/incidents/{incident_id}/timestamp-overrides\n@desc List incident timestamp overrides\n@required {incident_id: str # The UUID of the incident.}\n@returns(200) {data: [map], included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/incidents/{incident_id}/timestamp-overrides\n@desc Create an incident timestamp override\n@required {incident_id: str # The UUID of the incident., data: map{attributes!: map, type!: str} # Timestamp override data in a create request.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), deleted_at: str(date-time)?, incident_id: str, modified_at: str(date-time), timestamp_type: str, timestamp_value: str(date-time)}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"timestamp_type\":\"detected\",\"timestamp_value\":\"2024-01-01T10:00:00.000Z\"},\"type\":\"incidents_timestamp_overrides\"}}\n\n@endpoint DELETE /api/v2/incidents/{incident_id}/timestamp-overrides/{id}\n@desc Delete an incident timestamp override\n@required {incident_id: str # The UUID of the incident., id: str(uuid) # The UUID of the timestamp override.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/incidents/{incident_id}/timestamp-overrides/{id}\n@desc Update an incident timestamp override\n@required {incident_id: str # The UUID of the incident., id: str(uuid) # The UUID of the timestamp override., data: map{attributes: map, id!: str(uuid), type!: str} # Timestamp override data in a patch request.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), deleted_at: str(date-time)?, incident_id: str, modified_at: str(date-time), timestamp_type: str, timestamp_value: str(date-time)}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"timestamp_value\":\"2024-01-01T11:00:00.000Z\"},\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"incidents_timestamp_overrides\"}}\n\n@endpoint GET /api/v2/integration/aws/accounts\n@desc List all AWS integrations\n@optional {aws_account_id: str # Optional query parameter to filter accounts by AWS Account ID. If not provided, all accounts are returned.}\n@returns(200) {data: [map]} # AWS Accounts List object\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/aws/accounts\n@desc Create an AWS integration\n@required {data: map{attributes!: map, type!: str} # AWS Account Create Request data.}\n@returns(200) {data: map{attributes: map{account_tags: [str]?, auth_config: any, aws_account_id: str, aws_partition: str, aws_regions: any, created_at: str(date-time), logs_config: map{lambda_forwarder: map}, metrics_config: map{automute_enabled: bool, collect_cloudwatch_alarms: bool, collect_custom_metrics: bool, enabled: bool, metric_name_filters: [any], namespace_filters: any, tag_filters: [map]}, modified_at: str(date-time), resources_config: map{cloud_security_posture_management_collection: bool, extended_collection: bool}, traces_config: map{xray_services: any}}, id: str, type: str}} # AWS Account object\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"account_tags\":[\"env:prod\"],\"auth_config\":{\"access_key_id\":\"ACCESS_KEY_ID\",\"secret_access_key\":\"SECRET_ACCESS_KEY\"},\"aws_account_id\":\"123456789012\",\"aws_partition\":\"aws\",\"aws_regions\":{\"include_all\":true},\"logs_config\":{\"lambda_forwarder\":{\"lambdas\":[\"arn:aws:lambda:us-east-1:123456789012:function:DatadogLambdaLogForwarder\"],\"sources\":[\"s3\"]}},\"metrics_config\":{\"automute_enabled\":true,\"collect_cloudwatch_alarms\":false,\"collect_custom_metrics\":false,\"enabled\":true,\"metric_name_filters\":[{\"include_only\":[\"aws.ec2.network_in\"],\"namespace\":\"AWS/EC2\"}],\"tag_filters\":[{\"namespace\":\"AWS/EC2\"}]},\"resources_config\":{\"cloud_security_posture_management_collection\":false,\"extended_collection\":true}},\"type\":\"account\"}}\n\n@endpoint DELETE /api/v2/integration/aws/accounts/{aws_account_config_id}\n@desc Delete an AWS integration\n@required {aws_account_config_id: str # Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/api/latest/aws-integration/#list-all-aws-integrations) endpoint and query by AWS Account ID.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/aws/accounts/{aws_account_config_id}\n@desc Get an AWS integration by config ID\n@required {aws_account_config_id: str # Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/api/latest/aws-integration/#list-all-aws-integrations) endpoint and query by AWS Account ID.}\n@returns(200) {data: map{attributes: map{account_tags: [str]?, auth_config: any, aws_account_id: str, aws_partition: str, aws_regions: any, created_at: str(date-time), logs_config: map{lambda_forwarder: map}, metrics_config: map{automute_enabled: bool, collect_cloudwatch_alarms: bool, collect_custom_metrics: bool, enabled: bool, metric_name_filters: [any], namespace_filters: any, tag_filters: [map]}, modified_at: str(date-time), resources_config: map{cloud_security_posture_management_collection: bool, extended_collection: bool}, traces_config: map{xray_services: any}}, id: str, type: str}} # AWS Account object\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/aws/accounts/{aws_account_config_id}\n@desc Update an AWS integration\n@required {aws_account_config_id: str # Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/api/latest/aws-integration/#list-all-aws-integrations) endpoint and query by AWS Account ID., data: map{attributes!: map, id: str, type!: str} # AWS Account Update Request data.}\n@returns(200) {data: map{attributes: map{account_tags: [str]?, auth_config: any, aws_account_id: str, aws_partition: str, aws_regions: any, created_at: str(date-time), logs_config: map{lambda_forwarder: map}, metrics_config: map{automute_enabled: bool, collect_cloudwatch_alarms: bool, collect_custom_metrics: bool, enabled: bool, metric_name_filters: [any], namespace_filters: any, tag_filters: [map]}, modified_at: str(date-time), resources_config: map{cloud_security_posture_management_collection: bool, extended_collection: bool}, traces_config: map{xray_services: any}}, id: str, type: str}} # AWS Account object\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"account_tags\":[\"env:prod\"],\"auth_config\":{\"access_key_id\":\"ACCESS_KEY_ID\",\"secret_access_key\":\"SECRET_ACCESS_KEY\"},\"aws_account_id\":\"123456789012\",\"aws_partition\":\"aws\",\"aws_regions\":{\"include_all\":true},\"logs_config\":{\"lambda_forwarder\":{\"lambdas\":[\"arn:aws:lambda:us-east-1:123456789012:function:DatadogLambdaLogForwarder\"],\"sources\":[\"s3\"]}},\"metrics_config\":{\"automute_enabled\":true,\"collect_cloudwatch_alarms\":false,\"collect_custom_metrics\":false,\"enabled\":true,\"metric_name_filters\":[{\"include_only\":[\"aws.ec2.network_in\"],\"namespace\":\"AWS/EC2\"}],\"tag_filters\":[{\"namespace\":\"AWS/EC2\"}]},\"resources_config\":{\"cloud_security_posture_management_collection\":false,\"extended_collection\":true}},\"id\":\"00000000-abcd-0001-0000-000000000000\",\"type\":\"account\"}}\n\n@endpoint DELETE /api/v2/integration/aws/accounts/{aws_account_config_id}/ccm_config\n@desc Delete AWS CCM config\n@required {aws_account_config_id: str # Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/api/latest/aws-integration/#list-all-aws-integrations) endpoint and query by AWS Account ID.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/aws/accounts/{aws_account_config_id}/ccm_config\n@desc Get AWS CCM config\n@required {aws_account_config_id: str # Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/api/latest/aws-integration/#list-all-aws-integrations) endpoint and query by AWS Account ID.}\n@returns(200) {data: map{attributes: map{data_export_configs: [map]}, id: str, type: str}} # AWS CCM Config object\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/aws/accounts/{aws_account_config_id}/ccm_config\n@desc Update AWS CCM config\n@required {aws_account_config_id: str # Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/api/latest/aws-integration/#list-all-aws-integrations) endpoint and query by AWS Account ID., data: map{attributes!: map, type!: str} # AWS CCM Config Create/Update Request data.}\n@returns(200) {data: map{attributes: map{data_export_configs: [map]}, id: str, type: str}} # AWS CCM Config object\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"ccm_config\":{\"data_export_configs\":[{\"bucket_name\":\"billing\",\"bucket_region\":\"us-east-1\",\"report_name\":\"cost-and-usage-report\",\"report_prefix\":\"reports\",\"report_type\":\"CUR2.0\"}]}},\"type\":\"ccm_config\"}}\n\n@endpoint POST /api/v2/integration/aws/accounts/{aws_account_config_id}/ccm_config\n@desc Create AWS CCM config\n@required {aws_account_config_id: str # Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/api/latest/aws-integration/#list-all-aws-integrations) endpoint and query by AWS Account ID., data: map{attributes!: map, type!: str} # AWS CCM Config Create/Update Request data.}\n@returns(200) {data: map{attributes: map{data_export_configs: [map]}, id: str, type: str}} # AWS CCM Config object\n@errors {403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"ccm_config\":{\"data_export_configs\":[{\"bucket_name\":\"billing\",\"bucket_region\":\"us-east-1\",\"report_name\":\"cost-and-usage-report\",\"report_prefix\":\"reports\",\"report_type\":\"CUR2.0\"}]}},\"type\":\"ccm_config\"}}\n\n@endpoint GET /api/v2/integration/aws/accounts/{aws_account_config_id}/metric_name_filter_preview\n@desc Get AWS metric name filter preview\n@required {aws_account_config_id: str # Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/api/latest/aws-integration/#list-all-aws-integrations) endpoint and query by AWS Account ID.}\n@returns(200) {data: map{attributes: map{namespaces: [map]}, id: str, type: str}} # AWS metric name filter preview result\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/aws/accounts/{aws_account_config_id}/metric_name_filter_preview\n@desc Preview AWS metric name filter\n@required {aws_account_config_id: str # Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/api/latest/aws-integration/#list-all-aws-integrations) endpoint and query by AWS Account ID., data: map{attributes!: map, type!: str} # AWS metric name filter preview request data.}\n@returns(200) {data: map{attributes: map{namespaces: [map]}, id: str, type: str}} # AWS metric name filter preview result\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"metric_name_filters\":[{\"exclude_only\":[\"aws.ec2.network_in\"],\"namespace\":\"AWS/EC2\"}]},\"type\":\"metric_name_filter_preview\"}}\n\n@endpoint GET /api/v2/integration/aws/available_namespaces\n@desc List available namespaces\n@returns(200) {data: map{attributes: map{namespaces: [str]}, id: str, type: str}} # AWS Namespaces List object\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint DELETE /api/v2/integration/aws/event_bridge\n@desc Delete an Amazon EventBridge source\n@required {data: map{attributes!: map, type!: str} # Amazon EventBridge delete request data.}\n@returns(200) {data: map{attributes: map{status: str}, id: str, type: str}} # Amazon EventBridge source deleted.\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"account_id\":\"123456789012\",\"event_generator_name\":\"app-alerts-zyxw3210\",\"region\":\"us-east-1\"},\"type\":\"event_bridge\"}}\n\n@endpoint GET /api/v2/integration/aws/event_bridge\n@desc Get all Amazon EventBridge sources\n@returns(200) {data: map{attributes: map{accounts: [map], is_installed: bool}, id: str, type: str}} # Amazon EventBridge sources list.\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/aws/event_bridge\n@desc Create an Amazon EventBridge source\n@required {data: map{attributes!: map, type!: str} # Amazon EventBridge create request data.}\n@returns(200) {data: map{attributes: map{event_source_name: str, has_bus: bool, region: str, status: str}, id: str, type: str}} # Amazon EventBridge source created.\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"account_id\":\"123456789012\",\"create_event_bus\":true,\"event_generator_name\":\"app-alerts\",\"region\":\"us-east-1\"},\"type\":\"event_bridge\"}}\n\n@endpoint POST /api/v2/integration/aws/generate_new_external_id\n@desc Generate a new external ID\n@returns(200) {data: map{attributes: map{external_id: str}, id: str, type: str}} # AWS External ID object\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/aws/iam_permissions\n@desc Get AWS integration IAM permissions\n@returns(200) {data: map{attributes: map{permissions: [str]}, id: str, type: str}} # AWS IAM Permissions object\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/integration/aws/iam_permissions/resource_collection\n@desc Get resource collection IAM permissions\n@returns(200) {data: map{attributes: map{permissions: [str]}, id: str, type: str}} # AWS integration resource collection IAM permissions.\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/integration/aws/iam_permissions/standard\n@desc Get AWS integration standard IAM permissions\n@returns(200) {data: map{attributes: map{permissions: [str]}, id: str, type: str}} # AWS integration standard IAM permissions.\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/integration/aws/logs/services\n@desc Get list of AWS log ready services\n@returns(200) {data: map{attributes: map{logs_services: [str]}, id: str, type: str}} # AWS Logs Services List object\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/aws/validate_ccm_config\n@desc Validate AWS CCM config\n@required {data: map{attributes!: map, type!: str} # AWS CCM config validation request data.}\n@returns(200) {data: map{attributes: map{account_id: str, issues: [map]}, id: str, type: str}} # AWS CCM Config validation result\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 503: Service Unavailable}\n@example_request {\"data\":{\"attributes\":{\"account_id\":\"123456789012\",\"bucket_name\":\"billing\",\"bucket_region\":\"us-east-1\",\"report_name\":\"cost-and-usage-report\",\"report_prefix\":\"reports\"},\"type\":\"ccm_config_validation\"}}\n\n@endpoint GET /api/v2/integration/gcp/accounts\n@desc List all GCP STS-enabled service accounts\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/gcp/accounts\n@desc Create a new entry for your service account\n@optional {data: map{attributes: map, type: str} # Additional metadata on your generated service account.}\n@returns(201) {data: map{attributes: map{account_tags: [str], automute: bool, client_email: str, cloud_run_revision_filters: [str], host_filters: [str], is_cspm_enabled: bool, is_global_location_enabled: bool, is_per_project_quota_enabled: bool, is_resource_change_collection_enabled: bool, is_security_command_center_enabled: bool, metric_namespace_configs: [map], monitored_resource_configs: [map], region_filter_configs: [str], resource_collection_enabled: bool}, id: str, meta: map{accessible_projects: [str]}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"client_email\":\"datadog-service-account@test-project.iam.gserviceaccount.com\",\"cloud_run_revision_filters\":[\"$KEY:$VALUE\"],\"host_filters\":[\"$KEY:$VALUE\"],\"is_global_location_enabled\":true,\"is_per_project_quota_enabled\":true,\"is_resource_change_collection_enabled\":true,\"is_security_command_center_enabled\":true,\"metric_namespace_configs\":[{\"disabled\":true,\"id\":\"aiplatform\"},{\"filters\":[\"snapshot.*\",\"!*_by_region\"],\"id\":\"pubsub\"}],\"monitored_resource_configs\":[{\"filters\":[\"$KEY:$VALUE\"],\"type\":\"gce_instance\"}],\"region_filter_configs\":[\"nam4\",\"europe-north1\"]},\"type\":\"gcp_service_account\"}}\n\n@endpoint DELETE /api/v2/integration/gcp/accounts/{account_id}\n@desc Delete an STS enabled GCP Account\n@required {account_id: str # Your GCP STS enabled service account's unique ID.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/gcp/accounts/{account_id}\n@desc Update STS Service Account\n@required {account_id: str # Your GCP STS enabled service account's unique ID.}\n@optional {data: map{attributes: map, id: str, type: str} # Data on your service account.}\n@returns(201) {data: map{attributes: map{account_tags: [str], automute: bool, client_email: str, cloud_run_revision_filters: [str], host_filters: [str], is_cspm_enabled: bool, is_global_location_enabled: bool, is_per_project_quota_enabled: bool, is_resource_change_collection_enabled: bool, is_security_command_center_enabled: bool, metric_namespace_configs: [map], monitored_resource_configs: [map], region_filter_configs: [str], resource_collection_enabled: bool}, id: str, meta: map{accessible_projects: [str]}, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"client_email\":\"datadog-service-account@test-project.iam.gserviceaccount.com\",\"cloud_run_revision_filters\":[\"$KEY:$VALUE\"],\"host_filters\":[\"$KEY:$VALUE\"],\"is_global_location_enabled\":true,\"is_per_project_quota_enabled\":true,\"is_resource_change_collection_enabled\":true,\"is_security_command_center_enabled\":true,\"metric_namespace_configs\":[{\"disabled\":true,\"id\":\"aiplatform\"},{\"filters\":[\"snapshot.*\",\"!*_by_region\"],\"id\":\"pubsub\"}],\"monitored_resource_configs\":[{\"filters\":[\"$KEY:$VALUE\"],\"type\":\"gce_instance\"}],\"region_filter_configs\":[\"nam4\",\"europe-north1\"]},\"id\":\"d291291f-12c2-22g4-j290-123456678897\",\"type\":\"gcp_service_account\"}}\n\n@endpoint GET /api/v2/integration/gcp/sts_delegate\n@desc List delegate account\n@returns(200) {data: map{attributes: map{delegate_account_email: str}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/gcp/sts_delegate\n@desc Create a Datadog GCP principal\n@returns(200) {data: map{attributes: map{delegate_account_email: str}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {}\n\n@endpoint GET /api/v2/integration/google-chat/organizations\n@desc Get all Google Chat organization bindings\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/google-chat/organizations/app/named-spaces/{domain_name}/{space_display_name}\n@desc Get space information by display name\n@required {domain_name: str # The Google Chat domain name., space_display_name: str # The Google Chat space display name.}\n@returns(200) {data: map{attributes: map{display_name: str, organization_binding_id: str, resource_name: str, space_uri: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/integration/google-chat/organizations/{organization_binding_id}\n@desc Delete a Google Chat organization binding\n@required {organization_binding_id: str # Your organization binding ID.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/google-chat/organizations/{organization_binding_id}\n@desc Get a Google Chat organization binding\n@required {organization_binding_id: str # Your organization binding ID.}\n@returns(200) {data: map{attributes: map{domain_id: str, domain_name: str}, id: str, relationships: map{delegated_user: map{data: map}}, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/integration/google-chat/organizations/{organization_binding_id}/delegated-user\n@desc Delete the delegated user\n@required {organization_binding_id: str # Your organization binding ID.}\n@returns(204) OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/google-chat/organizations/{organization_binding_id}/delegated-user\n@desc Get the delegated user\n@required {organization_binding_id: str # Your organization binding ID.}\n@returns(200) {data: map{attributes: map{display_name: str, email: str, features: [str]}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles\n@desc Get all organization handles\n@required {organization_binding_id: str # Your organization binding ID.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles\n@desc Create organization handle\n@required {organization_binding_id: str # Your organization binding ID., data: map{attributes!: map} # Organization handle data for a create request., type: str=google-chat-organization-handle # Organization handle resource type.}\n@returns(201) {data: map{attributes: map{name: str, space_display_name: str, space_resource_name: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"fake-handle-name\",\"space_resource_name\":\"spaces/AAAAAAAAA\"}},\"type\":\"google-chat-organization-handle\"}\n\n@endpoint DELETE /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles/{handle_id}\n@desc Delete organization handle\n@required {organization_binding_id: str # Your organization binding ID., handle_id: str # Your organization handle ID.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles/{handle_id}\n@desc Get organization handle\n@required {organization_binding_id: str # Your organization binding ID., handle_id: str # Your organization handle ID.}\n@returns(200) {data: map{attributes: map{name: str, space_display_name: str, space_resource_name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/google-chat/organizations/{organization_binding_id}/organization-handles/{handle_id}\n@desc Update organization handle\n@required {organization_binding_id: str # Your organization binding ID., handle_id: str # Your organization handle ID., data: map{attributes!: map} # Organization handle data for an update request., type: str=google-chat-organization-handle # Organization handle resource type.}\n@returns(200) {data: map{attributes: map{name: str, space_display_name: str, space_resource_name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"fake-handle-name\",\"space_resource_name\":\"spaces/AAAAAAAAA\"}},\"type\":\"google-chat-organization-handle\"}\n\n@endpoint GET /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences\n@desc Get all target audiences\n@required {organization_binding_id: str # Your organization binding ID.}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences\n@desc Create a target audience\n@required {organization_binding_id: str # Your organization binding ID., data: map{attributes!: map, type!: str} # Data for a create target audience request.}\n@returns(201) {data: map{attributes: map{audience_id: str, audience_name: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"audience_id\":\"fake-audience-id-1\",\"audience_name\":\"fake audience name 1\"},\"type\":\"google-chat-target-audience\"}}\n\n@endpoint DELETE /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences/{target_audience_id}\n@desc Delete a target audience\n@required {organization_binding_id: str # Your organization binding ID., target_audience_id: str # Your target audience ID.}\n@returns(204) OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences/{target_audience_id}\n@desc Get a target audience\n@required {organization_binding_id: str # Your organization binding ID., target_audience_id: str # Your target audience ID.}\n@returns(200) {data: map{attributes: map{audience_id: str, audience_name: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/google-chat/organizations/{organization_binding_id}/target-audiences/{target_audience_id}\n@desc Update a target audience\n@required {organization_binding_id: str # Your organization binding ID., target_audience_id: str # Your target audience ID., data: map{attributes!: map, type!: str} # Data for an update target audience request.}\n@returns(200) {data: map{attributes: map{audience_id: str, audience_name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"audience_id\":\"updated-audience-id\",\"audience_name\":\"updated-audience-name\"},\"type\":\"google-chat-target-audience\"}}\n\n@endpoint GET /api/v2/integration/jira/accounts\n@desc List Jira accounts\n@returns(200) {data: [map], meta: map{public_key: str}} # OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/integration/jira/accounts/{account_id}\n@desc Delete Jira account\n@required {account_id: str(uuid) # The ID of the Jira account to delete}\n@returns(204) No Content\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/jira/issue-templates\n@desc List Jira issue templates\n@returns(200) {data: [map], included: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/integration/jira/issue-templates\n@desc Create Jira issue template\n@optional {data: map{attributes: map, type: str} # Data object for creating a Jira issue template}\n@returns(201) {data: map{attributes: map{fields: map, issue_type_id: str, name: str, project_id: str}, id: str(uuid), relationships: map{jira-account: map{data: map}}, type: str}, included: [map]} # Created\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"fields\":{\"description\":{\"payload\":\"Test\",\"type\":\"json\"}},\"issue_type_id\":\"12730\",\"jira-account\":{\"id\":\"80f16d40-1fba-486e-b1fc-983e6ca19bec\"},\"name\":\"test-template\",\"project_id\":\"10772\"},\"type\":\"jira-issue-template\"}}\n\n@endpoint DELETE /api/v2/integration/jira/issue-templates/{issue_template_id}\n@desc Delete Jira issue template\n@required {issue_template_id: str(uuid) # The ID of the Jira issue template to delete}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/integration/jira/issue-templates/{issue_template_id}\n@desc Get Jira issue template\n@required {issue_template_id: str(uuid) # The ID of the Jira issue template to retrieve}\n@returns(200) {data: map{attributes: map{fields: map, issue_type_id: str, name: str, project_id: str}, id: str(uuid), relationships: map{jira-account: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/jira/issue-templates/{issue_template_id}\n@desc Update Jira issue template\n@required {issue_template_id: str(uuid) # The ID of the Jira issue template to update, data: map{attributes!: map, type!: str} # Data object for updating a Jira issue template}\n@returns(200) {data: map{attributes: map{fields: map, issue_type_id: str, name: str, project_id: str}, id: str(uuid), relationships: map{jira-account: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"fields\":{\"description\":{\"payload\":\"Updated Description\",\"type\":\"json\"}},\"name\":\"test_template_updated\"},\"type\":\"jira-issue-template\"}}\n\n@endpoint GET /api/v2/integration/ms-teams/configuration/channel/{tenant_name}/{team_name}/{channel_name}\n@desc Get channel information by name\n@required {tenant_name: str # Your tenant name., team_name: str # Your team name., channel_name: str # Your channel name.}\n@returns(200) {data: map{attributes: map{is_primary: bool, team_id: str, tenant_id: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/ms-teams/configuration/tenant-based-handles\n@desc Get all tenant-based handles\n@optional {tenant_id: str # Your tenant id., name: str # Your tenant-based handle name.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 412: Failed Precondition, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/ms-teams/configuration/tenant-based-handles\n@desc Create tenant-based handle\n@required {data: map{attributes!: map, type!: str} # Tenant-based handle data from a response.}\n@returns(201) {data: map{attributes: map{channel_id: str, name: str, team_id: str, tenant_id: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 412: Failed Precondition, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"channel_id\":\"fake-channel-id\",\"name\":\"fake-handle-name\",\"team_id\":\"00000000-0000-0000-0000-000000000000\",\"tenant_id\":\"00000000-0000-0000-0000-000000000001\"},\"type\":\"tenant-based-handle\"}}\n\n@endpoint DELETE /api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id}\n@desc Delete tenant-based handle\n@required {handle_id: str # Your tenant-based handle id.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 412: Failed Precondition, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id}\n@desc Get tenant-based handle information\n@required {handle_id: str # Your tenant-based handle id.}\n@returns(200) {data: map{attributes: map{channel_id: str, name: str, team_id: str, tenant_id: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 412: Failed Precondition, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id}\n@desc Update tenant-based handle\n@required {handle_id: str # Your tenant-based handle id., data: map{attributes!: map, type!: str} # Tenant-based handle data from a response.}\n@returns(200) {data: map{attributes: map{channel_id: str, name: str, team_id: str, tenant_id: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 412: Failed Precondition, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"channel_id\":\"fake-channel-id\",\"name\":\"fake-handle-name\",\"team_id\":\"00000000-0000-0000-0000-000000000000\",\"tenant_id\":\"00000000-0000-0000-0000-000000000001\"},\"type\":\"tenant-based-handle\"}}\n\n@endpoint DELETE /api/v2/integration/ms-teams/configuration/user-binding/{tenant_id}\n@desc Delete user binding\n@required {tenant_id: str # Your tenant id.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 412: Failed Precondition, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/ms-teams/configuration/workflows-webhook-handles\n@desc Get all Workflows webhook handles\n@optional {name: str # Your Workflows webhook handle name.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 412: Failed Precondition, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/ms-teams/configuration/workflows-webhook-handles\n@desc Create Workflows webhook handle\n@required {data: map{attributes!: map, type!: str} # Workflows Webhook handle data from a response.}\n@returns(201) {data: map{attributes: map{name: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 412: Failed Precondition, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"fake-handle-name\",\"url\":\"https://fake.url.com\"},\"type\":\"workflows-webhook-handle\"}}\n\n@endpoint DELETE /api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id}\n@desc Delete Workflows webhook handle\n@required {handle_id: str # Your Workflows webhook handle id.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 412: Failed Precondition, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id}\n@desc Get Workflows webhook handle information\n@required {handle_id: str # Your Workflows webhook handle id.}\n@returns(200) {data: map{attributes: map{name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 412: Failed Precondition, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id}\n@desc Update Workflows webhook handle\n@required {handle_id: str # Your Workflows webhook handle id., data: map{attributes!: map, type!: str} # Workflows Webhook handle data from a response.}\n@returns(200) {data: map{attributes: map{name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 412: Failed Precondition, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"fake-handle-name\",\"url\":\"https://fake.url.com\"},\"type\":\"workflows-webhook-handle\"}}\n\n@endpoint GET /api/v2/integration/oci/products\n@desc List tenancy products\n@required {productKeys: str # Comma-separated list of product keys to filter by.}\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/integration/oci/tenancies\n@desc Get tenancy configs\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/integration/oci/tenancies\n@desc Create tenancy config\n@required {data: map{attributes: map, id!: str, type!: str} # The data object for creating a new OCI tenancy integration configuration, including the tenancy ID, type, and configuration attributes.}\n@returns(201) {data: map{attributes: map{billing_plan_id: int(int32), config_version: int(int64), cost_collection_enabled: bool, dd_compartment_id: str, dd_stack_id: str, home_region: str, logs_config: map{compartment_tag_filters: [str], enabled: bool, enabled_services: [str]}, metrics_config: map{compartment_tag_filters: [str], enabled: bool, excluded_services: [str]}, parent_tenancy_name: str, regions_config: map{available: [str], disabled: [str], enabled: [str]}, resource_collection_enabled: bool, tenancy_name: str, user_ocid: str}, id: str, type: str}} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"auth_credentials\":{\"fingerprint\":\"\",\"private_key\":\"<PRIVATE_KEY>\"},\"cost_collection_enabled\":true,\"dd_compartment_id\":\"ocid.compartment.test\",\"dd_stack_id\":\"ocid.stack.test\",\"home_region\":\"us-ashburn-1\",\"logs_config\":{\"compartment_tag_filters\":[\"datadog:true\",\"env:prod\"],\"enabled\":true,\"enabled_services\":[\"service_1\",\"service_2\"]},\"metrics_config\":{\"compartment_tag_filters\":[\"datadog:true\",\"env:prod\"],\"enabled\":true,\"excluded_services\":[\"service_1\",\"service_2\"]},\"regions_config\":{\"available\":[\"us-ashburn-1\",\"us-phoenix-1\"],\"disabled\":[\"us-phoenix-1\"],\"enabled\":[\"us-ashburn-1\"]},\"resource_collection_enabled\":true,\"user_ocid\":\"ocid.user.test\"},\"id\":\"ocid.tenancy.test\",\"type\":\"oci_tenancy\"}}\n\n@endpoint DELETE /api/v2/integration/oci/tenancies/{tenancy_ocid}\n@desc Delete tenancy config\n@required {tenancy_ocid: str # The OCID of the tenancy config to delete.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/integration/oci/tenancies/{tenancy_ocid}\n@desc Get tenancy config\n@required {tenancy_ocid: str # The OCID of the tenancy config to retrieve.}\n@returns(200) {data: map{attributes: map{billing_plan_id: int(int32), config_version: int(int64), cost_collection_enabled: bool, dd_compartment_id: str, dd_stack_id: str, home_region: str, logs_config: map{compartment_tag_filters: [str], enabled: bool, enabled_services: [str]}, metrics_config: map{compartment_tag_filters: [str], enabled: bool, excluded_services: [str]}, parent_tenancy_name: str, regions_config: map{available: [str], disabled: [str], enabled: [str]}, resource_collection_enabled: bool, tenancy_name: str, user_ocid: str}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/oci/tenancies/{tenancy_ocid}\n@desc Update tenancy config\n@required {tenancy_ocid: str # The OCID of the tenancy config to update., data: map{attributes: map, id!: str, type!: str} # The data object for updating an existing OCI tenancy integration configuration, including the tenancy ID, type, and updated attributes.}\n@returns(200) {data: map{attributes: map{billing_plan_id: int(int32), config_version: int(int64), cost_collection_enabled: bool, dd_compartment_id: str, dd_stack_id: str, home_region: str, logs_config: map{compartment_tag_filters: [str], enabled: bool, enabled_services: [str]}, metrics_config: map{compartment_tag_filters: [str], enabled: bool, excluded_services: [str]}, parent_tenancy_name: str, regions_config: map{available: [str], disabled: [str], enabled: [str]}, resource_collection_enabled: bool, tenancy_name: str, user_ocid: str}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"auth_credentials\":{\"fingerprint\":\"\",\"private_key\":\"<PRIVATE_KEY>\"},\"cost_collection_enabled\":true,\"home_region\":\"us-ashburn-1\",\"logs_config\":{\"compartment_tag_filters\":[\"datadog:true\",\"env:prod\"],\"enabled\":true,\"enabled_services\":[\"service_1\",\"service_2\"]},\"metrics_config\":{\"compartment_tag_filters\":[\"datadog:true\",\"env:prod\"],\"enabled\":true,\"excluded_services\":[\"service_1\",\"service_2\"]},\"regions_config\":{\"available\":[\"us-ashburn-1\",\"us-phoenix-1\"],\"disabled\":[\"us-phoenix-1\"],\"enabled\":[\"us-ashburn-1\"]},\"resource_collection_enabled\":true,\"user_ocid\":\"ocid.user.test\"},\"id\":\"ocid.tenancy.test\",\"type\":\"oci_tenancy\"}}\n\n@endpoint GET /api/v2/integration/opsgenie/accounts\n@desc Get all Opsgenie accounts\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/opsgenie/accounts\n@desc Create a new Opsgenie account\n@required {data: map{attributes!: map, type!: str} # Opsgenie account data for a create request.}\n@returns(201) {data: map{attributes: map{region: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"api_key\":\"00000000-0000-0000-0000-000000000000\",\"region\":\"us\"},\"type\":\"opsgenie-account\"}}\n\n@endpoint DELETE /api/v2/integration/opsgenie/accounts/{account_id}\n@desc Delete an Opsgenie account\n@required {account_id: str # The UUID of the Opsgenie account.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/opsgenie/accounts/{account_id}\n@desc Update an Opsgenie account\n@required {account_id: str # The UUID of the Opsgenie account., data: map{attributes!: map, id!: str, type!: str} # Opsgenie account data for an update request.}\n@returns(200) {data: map{attributes: map{region: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 422: The server cannot process the request because it contains invalid data., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"api_key\":\"00000000-0000-0000-0000-000000000000\",\"region\":\"us\"},\"id\":\"596da4af-0563-4097-90ff-07230c3f9db3\",\"type\":\"opsgenie-account\"}}\n\n@endpoint GET /api/v2/integration/opsgenie/services\n@desc Get all service objects\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/opsgenie/services\n@desc Create a new service object\n@required {data: map{attributes!: map, type!: str} # Opsgenie service data for a create request.}\n@returns(201) {data: map{attributes: map{custom_url: str?, name: str, region: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"custom_url\":\"https://example.com\",\"name\":\"fake-opsgenie-service-name\",\"opsgenie_api_key\":\"00000000-0000-0000-0000-000000000000\",\"region\":\"us\"},\"type\":\"opsgenie-service\"}}\n\n@endpoint DELETE /api/v2/integration/opsgenie/services/{integration_service_id}\n@desc Delete a single service object\n@required {integration_service_id: str # The UUID of the service.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/opsgenie/services/{integration_service_id}\n@desc Get a single service object\n@required {integration_service_id: str # The UUID of the service.}\n@returns(200) {data: map{attributes: map{custom_url: str?, name: str, region: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/opsgenie/services/{integration_service_id}\n@desc Update a single service object\n@required {integration_service_id: str # The UUID of the service., data: map{attributes!: map, id!: str, type!: str} # Opsgenie service for an update request.}\n@returns(200) {data: map{attributes: map{custom_url: str?, name: str, region: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"custom_url\":\"https://example.com\",\"name\":\"fake-opsgenie-service-name\",\"opsgenie_api_key\":\"00000000-0000-0000-0000-000000000000\",\"region\":\"us\"},\"id\":\"596da4af-0563-4097-90ff-07230c3f9db3\",\"type\":\"opsgenie-service\"}}\n\n@endpoint GET /api/v2/integration/salesforce-incidents/incident-templates\n@desc Get all Salesforce incident templates\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/salesforce-incidents/incident-templates\n@desc Create a Salesforce incident template\n@required {data: map{attributes!: map, type!: str} # Salesforce incident template data for a create request.}\n@returns(201) {data: map{attributes: map{description: str, name: str, owner_id: str, priority: str, salesforce_org_id: str(uuid), subject: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"An incident was detected by Datadog monitors.\",\"name\":\"production-outage\",\"owner_id\":\"005000000000000\",\"priority\":\"High\",\"salesforce_org_id\":\"596da4af-0563-4097-90ff-07230c3f9db3\",\"subject\":\"Datadog Incident: Production Outage\"},\"type\":\"salesforce-incidents-incident-template\"}}\n\n@endpoint DELETE /api/v2/integration/salesforce-incidents/incident-templates/{incident_template_id}\n@desc Delete a Salesforce incident template\n@required {incident_template_id: str # The ID of the Salesforce incident template.}\n@returns(204) OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/salesforce-incidents/incident-templates/{incident_template_id}\n@desc Update a Salesforce incident template\n@required {incident_template_id: str # The ID of the Salesforce incident template., data: map{attributes!: map, id!: str, type!: str} # Salesforce incident template data for an update request.}\n@returns(200) {data: map{attributes: map{description: str, name: str, owner_id: str, priority: str, salesforce_org_id: str(uuid), subject: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"production-outage-renamed\"},\"id\":\"596da4af-0563-4097-90ff-07230c3f9db3\",\"type\":\"salesforce-incidents-incident-template\"}}\n\n@endpoint GET /api/v2/integration/salesforce-incidents/organizations\n@desc Get all connected Salesforce organizations\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/integration/salesforce-incidents/organizations/{salesforce_org_id}\n@desc Delete a connected Salesforce organization\n@required {salesforce_org_id: str # The Datadog-assigned ID of the connected Salesforce organization.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/servicenow/assignment_groups/{instance_id}\n@desc List ServiceNow assignment groups\n@required {instance_id: str(uuid) # The ID of the ServiceNow instance}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/servicenow/business_services/{instance_id}\n@desc List ServiceNow business services\n@required {instance_id: str(uuid) # The ID of the ServiceNow instance}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/servicenow/handles\n@desc List ServiceNow templates\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/integration/servicenow/handles\n@desc Create ServiceNow template\n@required {data: map{attributes!: map, type!: str} # Data object for creating a ServiceNow template}\n@returns(201) {data: map{attributes: map{assignment_group_id: str(uuid), business_service_id: str(uuid), fields_mapping: map, handle_name: str, instance_id: str(uuid), servicenow_tablename: str, user_id: str(uuid)}, id: str(uuid), type: str}} # Created\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assignment_group_id\":\"65b3341b-0680-47f9-a6d4-134db45c603e\",\"business_service_id\":\"65b3341b-0680-47f9-a6d4-134db45c603e\",\"fields_mapping\":{\"category\":\"software\",\"priority\":\"1\"},\"handle_name\":\"incident-template\",\"instance_id\":\"65b3341b-0680-47f9-a6d4-134db45c603e\",\"servicenow_tablename\":\"incident\",\"user_id\":\"65b3341b-0680-47f9-a6d4-134db45c603e\"},\"type\":\"servicenow_templates\"}}\n\n@endpoint DELETE /api/v2/integration/servicenow/handles/{template_id}\n@desc Delete ServiceNow template\n@required {template_id: str(uuid) # The ID of the ServiceNow template to delete}\n@returns(200) OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/servicenow/handles/{template_id}\n@desc Get ServiceNow template\n@required {template_id: str(uuid) # The ID of the ServiceNow template to retrieve}\n@returns(200) {data: map{attributes: map{assignment_group_id: str(uuid), business_service_id: str(uuid), fields_mapping: map, handle_name: str, instance_id: str(uuid), servicenow_tablename: str, user_id: str(uuid)}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/integration/servicenow/handles/{template_id}\n@desc Update ServiceNow template\n@required {template_id: str(uuid) # The ID of the ServiceNow template to update, data: map{attributes!: map, type!: str} # Data object for updating a ServiceNow template}\n@returns(200) {data: map{attributes: map{assignment_group_id: str(uuid), business_service_id: str(uuid), fields_mapping: map, handle_name: str, instance_id: str(uuid), servicenow_tablename: str, user_id: str(uuid)}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assignment_group_id\":\"65b3341b-0680-47f9-a6d4-134db45c603e\",\"business_service_id\":\"65b3341b-0680-47f9-a6d4-134db45c603e\",\"fields_mapping\":{\"category\":\"hardware\",\"priority\":\"2\"},\"handle_name\":\"incident-template-updated\",\"instance_id\":\"65b3341b-0680-47f9-a6d4-134db45c603e\",\"servicenow_tablename\":\"incident\",\"user_id\":\"65b3341b-0680-47f9-a6d4-134db45c603e\"},\"type\":\"servicenow_templates\"}}\n\n@endpoint GET /api/v2/integration/servicenow/instances\n@desc List ServiceNow instances\n@returns(200) {data: [map]} # OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/servicenow/users/{instance_id}\n@desc List ServiceNow users\n@required {instance_id: str(uuid) # The ID of the ServiceNow instance}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/slack/user-bindings\n@desc List Slack user bindings\n@required {user_uuid: str(uuid) # The UUID of the Datadog user to list Slack bindings for.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint DELETE /api/v2/integration/statuspage/account\n@desc Delete the Statuspage account\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/statuspage/account\n@desc Get the Statuspage account\n@returns(200) {data: map{attributes: map{api_key: str}, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/statuspage/account\n@desc Update the Statuspage account\n@required {data: map{attributes!: map, type!: str} # Statuspage account data for an update request.}\n@returns(200) {data: map{attributes: map{api_key: str}, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"api_key\":\"00000000-0000-0000-0000-000000000000\"},\"type\":\"statuspage-account\"}}\n\n@endpoint POST /api/v2/integration/statuspage/account\n@desc Create the Statuspage account\n@required {data: map{attributes!: map, type!: str} # Statuspage account data for a create request.}\n@returns(201) {data: map{attributes: map{api_key: str}, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"api_key\":\"00000000-0000-0000-0000-000000000000\"},\"type\":\"statuspage-account\"}}\n\n@endpoint GET /api/v2/integration/statuspage/url_settings\n@desc Get all Statuspage URL settings\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/statuspage/url_settings\n@desc Create a Statuspage URL setting\n@required {data: map{attributes!: map, type!: str} # Statuspage URL setting data for a create request.}\n@returns(201) {data: map{attributes: map{custom_tags: str, url: str}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"custom_tags\":\"team:collaboration-integrations\",\"url\":\"https://example.statuspage.io\"},\"type\":\"statuspage-url-setting\"}}\n\n@endpoint DELETE /api/v2/integration/statuspage/url_settings/{statuspage_url_setting_id}\n@desc Delete a Statuspage URL setting\n@required {statuspage_url_setting_id: str # The UUID of the Statuspage URL setting.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/statuspage/url_settings/{statuspage_url_setting_id}\n@desc Update a Statuspage URL setting\n@required {statuspage_url_setting_id: str # The UUID of the Statuspage URL setting., data: map{attributes!: map, id!: str, type!: str} # Statuspage URL setting data for an update request.}\n@returns(200) {data: map{attributes: map{custom_tags: str, url: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"custom_tags\":\"team:collaboration-integrations\",\"url\":\"https://example.statuspage.io\"},\"id\":\"596da4af-0563-4097-90ff-07230c3f9db3\",\"type\":\"statuspage-url-setting\"}}\n\n@endpoint GET /api/v2/integration/webhooks/configuration/auth-method\n@desc Get all auth methods\n@optional {include: str # Comma-separated list of relationships to include in the response.}\n@returns(200) {data: [map], included: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials\n@desc Create an OAuth2 client credentials auth method\n@required {data: map{attributes!: map, type!: str} # OAuth2 client credentials data for a create request.}\n@returns(201) {data: map{attributes: map{access_token_url: str, audience: str?, client_id: str, name: str, protocol: str, scope: str?}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"access_token_url\":\"https://example.com/oauth/token\",\"audience\":\"https://api.example.com\",\"client_id\":\"my-client-id\",\"client_secret\":\"my-client-secret\",\"name\":\"my-oauth2-auth\",\"scope\":\"read:webhooks write:webhooks\"},\"type\":\"webhooks-auth-method-oauth2-client-credentials\"}}\n\n@endpoint DELETE /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials/{auth_method_id}\n@desc Delete an OAuth2 client credentials auth method\n@required {auth_method_id: str # The UUID of the auth method.}\n@returns(204) OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials/{auth_method_id}\n@desc Get an OAuth2 client credentials auth method\n@required {auth_method_id: str # The UUID of the auth method.}\n@returns(200) {data: map{attributes: map{access_token_url: str, audience: str?, client_id: str, name: str, protocol: str, scope: str?}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integration/webhooks/configuration/auth-method/oauth2-client-credentials/{auth_method_id}\n@desc Update an OAuth2 client credentials auth method\n@required {auth_method_id: str # The UUID of the auth method., data: map{attributes!: map, type!: str} # OAuth2 client credentials data for an update request.}\n@returns(200) {data: map{attributes: map{access_token_url: str, audience: str?, client_id: str, name: str, protocol: str, scope: str?}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"my-oauth2-auth-renamed\"},\"type\":\"webhooks-auth-method-oauth2-client-credentials\"}}\n\n@endpoint GET /api/v2/integrations\n@desc List Integrations\n@returns(200) {data: [map]} # Successful Response.\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/integrations/cloudflare/accounts\n@desc List Cloudflare accounts\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integrations/cloudflare/accounts\n@desc Add Cloudflare account\n@required {data: map{attributes!: map, type!: str} # Data object for creating a Cloudflare account.}\n@returns(201) {data: map{attributes: map{email: str, name: str, resources: [str], zones: [str]}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"api_key\":\"EXAMPLE_API_KEY_abc123\",\"email\":\"test-email@example.com\",\"name\":\"test-name\",\"resources\":[\"web\",\"dns\",\"lb\",\"worker\"],\"zones\":[\"zone_id_1\",\"zone_id_2\"]},\"type\":\"cloudflare-accounts\"}}\n\n@endpoint DELETE /api/v2/integrations/cloudflare/accounts/{account_id}\n@desc Delete Cloudflare account\n@required {account_id: str # None}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integrations/cloudflare/accounts/{account_id}\n@desc Get Cloudflare account\n@required {account_id: str # None}\n@returns(200) {data: map{attributes: map{email: str, name: str, resources: [str], zones: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integrations/cloudflare/accounts/{account_id}\n@desc Update Cloudflare account\n@required {account_id: str # None, data: map{attributes: map, type: str} # Data object for updating a Cloudflare account.}\n@returns(200) {data: map{attributes: map{email: str, name: str, resources: [str], zones: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"api_key\":\"EXAMPLE_API_KEY_abc123\",\"email\":\"test-email@example.com\",\"resources\":[\"web\",\"dns\",\"lb\",\"worker\"],\"zones\":[\"zone_id_1\",\"zone_id_2\"]},\"type\":\"cloudflare-accounts\"}}\n\n@endpoint GET /api/v2/integrations/confluent-cloud/accounts\n@desc List Confluent accounts\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integrations/confluent-cloud/accounts\n@desc Add Confluent account\n@required {data: map{attributes!: map, type!: str} # The data body for adding a Confluent account.}\n@returns(201) {data: map{attributes: map{api_key: str, resources: [map], tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"api_key\":\"TESTAPIKEY123\",\"api_secret\":\"test-api-secret-123\",\"resources\":[{\"enable_custom_metrics\":false,\"id\":\"resource-id-123\",\"resource_type\":\"kafka\",\"tags\":[\"myTag\",\"myTag2:myValue\"]}],\"tags\":[\"myTag\",\"myTag2:myValue\"]},\"type\":\"confluent-cloud-accounts\"}}\n\n@endpoint DELETE /api/v2/integrations/confluent-cloud/accounts/{account_id}\n@desc Delete Confluent account\n@required {account_id: str # Confluent Account ID.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integrations/confluent-cloud/accounts/{account_id}\n@desc Get Confluent account\n@required {account_id: str # Confluent Account ID.}\n@returns(200) {data: map{attributes: map{api_key: str, resources: [map], tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integrations/confluent-cloud/accounts/{account_id}\n@desc Update Confluent account\n@required {account_id: str # Confluent Account ID., data: map{attributes!: map, type!: str} # Data object for updating a Confluent account.}\n@returns(200) {data: map{attributes: map{api_key: str, resources: [map], tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"api_key\":\"TESTAPIKEY123\",\"api_secret\":\"test-api-secret-123\",\"tags\":[\"myTag\",\"myTag2:myValue\"]},\"type\":\"confluent-cloud-accounts\"}}\n\n@endpoint GET /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources\n@desc List Confluent Account resources\n@required {account_id: str # Confluent Account ID.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources\n@desc Add resource to Confluent account\n@required {account_id: str # Confluent Account ID., data: map{attributes!: map, id!: str, type!: str} # JSON:API request for updating a Confluent resource.}\n@returns(201) {data: map{attributes: map{enable_custom_metrics: bool, id: str, resource_type: str, tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enable_custom_metrics\":false,\"resource_type\":\"kafka\",\"tags\":[\"myTag\",\"myTag2:myValue\"]},\"id\":\"resource-id-123\",\"type\":\"confluent-cloud-resources\"}}\n\n@endpoint DELETE /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources/{resource_id}\n@desc Delete resource from Confluent account\n@required {account_id: str # Confluent Account ID., resource_id: str # Confluent Account Resource ID.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources/{resource_id}\n@desc Get resource from Confluent account\n@required {account_id: str # Confluent Account ID., resource_id: str # Confluent Account Resource ID.}\n@returns(200) {data: map{attributes: map{enable_custom_metrics: bool, id: str, resource_type: str, tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integrations/confluent-cloud/accounts/{account_id}/resources/{resource_id}\n@desc Update resource in Confluent account\n@required {account_id: str # Confluent Account ID., resource_id: str # Confluent Account Resource ID., data: map{attributes!: map, id!: str, type!: str} # JSON:API request for updating a Confluent resource.}\n@returns(200) {data: map{attributes: map{enable_custom_metrics: bool, id: str, resource_type: str, tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enable_custom_metrics\":false,\"resource_type\":\"kafka\",\"tags\":[\"myTag\",\"myTag2:myValue\"]},\"id\":\"resource-id-123\",\"type\":\"confluent-cloud-resources\"}}\n\n@endpoint GET /api/v2/integrations/fastly/accounts\n@desc List Fastly accounts\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integrations/fastly/accounts\n@desc Add Fastly account\n@required {data: map{attributes!: map, type!: str} # Data object for creating a Fastly account.}\n@returns(201) {data: map{attributes: map{name: str, services: [map]}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"api_key\":\"ABCDEFG123\",\"name\":\"test-name\",\"services\":[{\"id\":\"6abc7de6893AbcDe9fghIj\",\"tags\":[\"myTag\",\"myTag2:myValue\"]}]},\"type\":\"fastly-accounts\"}}\n\n@endpoint DELETE /api/v2/integrations/fastly/accounts/{account_id}\n@desc Delete Fastly account\n@required {account_id: str # Fastly Account id.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integrations/fastly/accounts/{account_id}\n@desc Get Fastly account\n@required {account_id: str # Fastly Account id.}\n@returns(200) {data: map{attributes: map{name: str, services: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integrations/fastly/accounts/{account_id}\n@desc Update Fastly account\n@required {account_id: str # Fastly Account id., data: map{attributes: map, type: str} # Data object for updating a Fastly account.}\n@returns(200) {data: map{attributes: map{name: str, services: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"api_key\":\"ABCDEFG123\"},\"type\":\"fastly-accounts\"}}\n\n@endpoint GET /api/v2/integrations/fastly/accounts/{account_id}/services\n@desc List Fastly services\n@required {account_id: str # Fastly Account id.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integrations/fastly/accounts/{account_id}/services\n@desc Add Fastly service\n@required {account_id: str # Fastly Account id., data: map{attributes: map, id!: str, type!: str} # Data object for Fastly service requests.}\n@returns(201) {data: map{attributes: map{tags: [str]}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"tags\":[\"myTag\",\"myTag2:myValue\"]},\"id\":\"abc123\",\"type\":\"fastly-services\"}}\n\n@endpoint DELETE /api/v2/integrations/fastly/accounts/{account_id}/services/{service_id}\n@desc Delete Fastly service\n@required {account_id: str # Fastly Account id., service_id: str # Fastly Service ID.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integrations/fastly/accounts/{account_id}/services/{service_id}\n@desc Get Fastly service\n@required {account_id: str # Fastly Account id., service_id: str # Fastly Service ID.}\n@returns(200) {data: map{attributes: map{tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integrations/fastly/accounts/{account_id}/services/{service_id}\n@desc Update Fastly service\n@required {account_id: str # Fastly Account id., service_id: str # Fastly Service ID., data: map{attributes: map, id!: str, type!: str} # Data object for Fastly service requests.}\n@returns(200) {data: map{attributes: map{tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"tags\":[\"myTag\",\"myTag2:myValue\"]},\"id\":\"abc123\",\"type\":\"fastly-services\"}}\n\n@endpoint GET /api/v2/integrations/okta/accounts\n@desc List Okta accounts\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/integrations/okta/accounts\n@desc Add Okta account\n@required {data: map{attributes!: map, id: str, type!: str} # Schema for an Okta account.}\n@returns(201) {data: map{attributes: map{api_key: str, auth_method: str, client_id: str, client_secret: str, domain: str, name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"auth_method\":\"oauth\",\"client_id\":\"client_id\",\"client_secret\":\"client_secret\",\"domain\":\"https://example.okta.com/\",\"name\":\"Okta-Prod\"},\"id\":\"f749daaf-682e-4208-a38d-c9b43162c609\",\"type\":\"okta-accounts\"}}\n\n@endpoint DELETE /api/v2/integrations/okta/accounts/{account_id}\n@desc Delete Okta account\n@required {account_id: str # None}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/integrations/okta/accounts/{account_id}\n@desc Get Okta account\n@required {account_id: str # None}\n@returns(200) {data: map{attributes: map{api_key: str, auth_method: str, client_id: str, client_secret: str, domain: str, name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/integrations/okta/accounts/{account_id}\n@desc Update Okta account\n@required {account_id: str # None, data: map{attributes: map, type: str} # Data object for updating an Okta account.}\n@returns(200) {data: map{attributes: map{api_key: str, auth_method: str, client_id: str, client_secret: str, domain: str, name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"auth_method\":\"oauth\",\"domain\":\"https://example.okta.com/\"},\"type\":\"okta-accounts\"}}\n\n@endpoint GET /api/v2/ip_allowlist\n@desc Get IP Allowlist\n@returns(200) {data: map{attributes: map{enabled: bool, entries: [map]}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/ip_allowlist\n@desc Update IP Allowlist\n@required {data: map{attributes: map, id: str, type!: str} # IP allowlist data.}\n@returns(200) {data: map{attributes: map{enabled: bool, entries: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":false,\"entries\":[{\"data\":{\"attributes\":{\"cidr_block\":\"127.0.0.1/32\"},\"type\":\"ip_allowlist_entry\"}}]},\"type\":\"ip_allowlist\"}}\n\n@endpoint POST /api/v2/llm-obs/deletion/data/llmobs\n@desc Delete LLM Observability data\n@required {data: map{attributes!: map, type!: str} # Data object for an LLM Observability data deletion request.}\n@returns(202) {data: map{attributes: map{created_at: str(date-time), created_by: str, from_time: int(int64), org_id: int(int64), product: str, query: str, to_time: int(int64)}, id: str, type: str}} # Accepted\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"from\":1705314600000,\"query\":{\"query\":\"@trace_id:abc123def456\"},\"to\":1705315200000},\"type\":\"create_deletion_req\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/annotated-interactions\n@desc Get annotated interactions by content IDs\n@required {contentIds: [str] # One or more content IDs to retrieve annotated interactions for. At least one is required.}\n@optional {offset: int(int32)=0 # Pagination offset. Must be >= 0. Defaults to 0., limit: int(int32)=100 # Maximum number of results to return. Must be > 0. Defaults to 100.}\n@returns(200) {data: map{attributes: map{annotated_interactions: [map], total_count: int(int32)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/llm-obs/v1/annotation-queues\n@desc List LLM Observability annotation queues\n@optional {projectId: str # Filter annotation queues by project ID. Cannot be used together with `queueIds`., queueIds: [str] # Filter annotation queues by queue IDs (comma-separated). Cannot be used together with `projectId`.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/llm-obs/v1/annotation-queues\n@desc Create an LLM Observability annotation queue\n@required {data: map{attributes!: map, type!: str} # Data object for creating an LLM Observability annotation queue.}\n@returns(201) {data: map{attributes: map{annotation_schema: map{label_schemas: [map]}, created_at: str(date-time), created_by: str, description: str, modified_at: str(date-time), modified_by: str, name: str, owned_by: str, project_id: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Queue for annotating customer support traces\",\"name\":\"My annotation queue\",\"project_id\":\"00000000-0000-0000-0000-000000000002\"},\"type\":\"queues\"}}\n\n@endpoint DELETE /api/v2/llm-obs/v1/annotation-queues/{queue_id}\n@desc Delete an LLM Observability annotation queue\n@required {queue_id: str # The ID of the LLM Observability annotation queue.}\n@returns(204) No Content\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/llm-obs/v1/annotation-queues/{queue_id}\n@desc Update an LLM Observability annotation queue\n@required {queue_id: str # The ID of the LLM Observability annotation queue., data: map{attributes!: map, type!: str} # Data object for updating an LLM Observability annotation queue.}\n@returns(200) {data: map{attributes: map{annotation_schema: map{label_schemas: [map]}, created_at: str(date-time), created_by: str, description: str, modified_at: str(date-time), modified_by: str, name: str, owned_by: str, project_id: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Updated description\",\"name\":\"Updated queue name\"},\"type\":\"queues\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/annotation-queues/{queue_id}/annotated-interactions\n@desc Get annotated queue interactions\n@required {queue_id: str # The ID of the LLM Observability annotation queue.}\n@returns(200) {data: map{attributes: map{annotated_interactions: [any]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/llm-obs/v1/annotation-queues/{queue_id}/annotations\n@desc Create or update annotations\n@required {queue_id: str # The ID of the LLM Observability annotation queue., data: map{attributes!: map, type!: str} # Data object for creating or updating annotations.}\n@returns(200) {data: map{attributes: map{annotations: [map], errors: [map]}, id: str, type: str}} # OK — annotations created or updated. Per-item errors are listed in `errors`.\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found — the queue does not exist., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"annotations\":[{\"interaction_id\":\"00000000-0000-0000-0000-000000000001\",\"label_values\":[{\"label_schema_id\":\"abc-123\",\"value\":\"good\"},{\"label_schema_id\":\"ef56gh78\",\"value\":\"positive\"}]}]},\"type\":\"annotations\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/annotation-queues/{queue_id}/annotations/delete\n@desc Delete annotations\n@required {queue_id: str # The ID of the LLM Observability annotation queue., data: map{attributes!: map, type!: str} # Data object for deleting annotations.}\n@returns(200) {data: map{attributes: map{annotation_ids: [str], errors: [map]}, id: str, type: str}} # OK — annotations deleted. Errors for annotations that could not be deleted are listed in `errors`.\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found — the queue does not exist., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"annotation_ids\":[\"00000000-0000-0000-0000-000000000000\"]},\"type\":\"annotations\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/annotation-queues/{queue_id}/interactions\n@desc Add annotation queue interactions\n@required {queue_id: str # The ID of the LLM Observability annotation queue., data: map{attributes!: map, type!: str} # Data object for adding interactions to an annotation queue.}\n@returns(201) {data: map{attributes: map{interactions: [any]}, id: str, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"interactions\":[{\"content_id\":\"trace-abc-123\",\"type\":\"trace\"}]},\"type\":\"interactions\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/annotation-queues/{queue_id}/interactions/delete\n@desc Delete annotation queue interactions\n@required {queue_id: str # The ID of the LLM Observability annotation queue., data: map{attributes!: map, type!: str} # Data object for deleting interactions from an annotation queue.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"interaction_ids\":[\"00000000-0000-0000-0000-000000000000\",\"00000000-0000-0000-0000-000000000001\"]},\"type\":\"interactions\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/annotation-queues/{queue_id}/label-schema\n@desc Get annotation queue label schema\n@required {queue_id: str # The ID of the LLM Observability annotation queue.}\n@returns(200) {data: map{attributes: map{annotation_schema: map{label_schemas: [map]}}, id: str, type: str}} # OK\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint PUT /api/v2/llm-obs/v1/annotation-queues/{queue_id}/label-schema\n@desc Update annotation queue label schema\n@required {queue_id: str # The ID of the LLM Observability annotation queue., data: map{attributes!: map, type!: str} # Data object for updating an annotation queue label schema.}\n@returns(200) {data: map{attributes: map{annotation_schema: map{label_schemas: [map]}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"annotation_schema\":{\"label_schemas\":[{\"has_assessment\":true,\"is_assessment\":true,\"is_required\":true,\"name\":\"is_correct\",\"type\":\"boolean\"}]}},\"type\":\"queues\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/experimentation/analytics\n@desc Aggregate LLM Observability experimentation\n@required {data: map{attributes!: map, type!: str} # Data object for an analytics request.}\n@returns(200) {data: map{attributes: map{hit_count: int(int64), result: map{values: [map]}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"aggregate\":{\"compute\":[{\"metric\":\"score_value\",\"name\":\"avg_faithfulness\"}],\"group_by\":[{\"field\":\"span_id\"}],\"indexes\":[\"experiment-evals\"],\"search\":{\"query\":\"@experiment_id:3fd6b5e0-8910-4b1c-a7d0-5b84de329012 @label:faithfulness\"}}},\"type\":\"experimentation\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/experimentation/search\n@desc Search LLM Observability experimentation entities\n@required {data: map{attributes!: map, type!: str} # Data object for an experimentation search request.}\n@returns(200) {data: map{attributes: map{dataset_records: [map]?, datasets: [map]?, experiment_runs: [map]?, experiments: [map]?, projects: [map]?}, id: str, type: str}, meta: map{after: str?}} # OK — all results returned in a single page.\n@returns(206) {data: map{attributes: map{dataset_records: [map]?, datasets: [map]?, experiment_runs: [map]?, experiments: [map]?, projects: [map]?}, id: str, type: str}, meta: map{after: str?}} # Partial Content — more results are available. Use `meta.after` as the next `page.cursor`.\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"filter\":{\"query\":\"@project_id:a33671aa-24fd-4dcd-9b33-a8ec7dde7751\",\"scope\":[\"experiments\"]},\"page\":{\"limit\":50}},\"type\":\"experimentation\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/experimentation/simple-search\n@desc Simple search experimentation entities\n@required {data: map{attributes!: map, type!: str} # Data object for an experimentation simple search request.}\n@returns(200) {data: map{attributes: map{dataset_records: [map]?, datasets: [map]?, experiment_runs: [map]?, experiments: [map]?, projects: [map]?}, id: str, type: str}, meta: map{page: map{current: int(int32), limit: int(int32), total_count: int(int32), total_pages: int(int32)}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"filter\":{\"query\":\"@project_id:a33671aa-24fd-4dcd-9b33-a8ec7dde7751\",\"scope\":[\"experiments\"]},\"page\":{\"limit\":50,\"number\":1},\"sort\":[{\"direction\":\"desc\",\"field\":\"created_at\"}]},\"type\":\"experimentation\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/experiments\n@desc List LLM Observability experiments\n@optional {filter[project_id]: str: any # Filter experiments by project ID. Required if `filter[dataset_id]` is not provided., filter[dataset_id]: str # Filter experiments by dataset ID., filter[id]: str # Filter experiments by experiment ID. Can be specified multiple times., filter[name]: str # Filter experiments by their exact run name., filter[experiment]: str # Filter by logical experiment name. This is the `name` field set when creating an experiment through `POST /experiments`. Returns all experiment runs that share the same name, enabling cross-commit and cross-branch comparisons., filter[metadata]: str # Filter by JSONB metadata containment. Provide a JSON object string where experiments whose metadata contains all specified key-value pairs are returned. For example: `{\"commit\":\"abc123\",\"branch\":\"main\"}`., filter[parent_experiment_id]: str # Filter experiments by the ID of their parent (baseline) experiment. Returns all experiments that were run against the given baseline. Can be specified multiple times., filter[is_deleted]: bool # When `true`, return only soft-deleted experiments. Defaults to `false`., include[user_data]: bool # When `true`, enrich each experiment with its author's user data in the `author` field., include[dataset_names]: bool # When `true`, enrich each experiment with its dataset name in the `dataset_name` field., page[cursor]: str # Use the pagination cursor returned in `meta.after` to retrieve the next page of results., page[limit]: int(int64) # Maximum number of results to return per page. Values above 5000 are clamped to 5000. Defaults to 5000.}\n@returns(200) {data: [map], meta: map{after: str?}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/llm-obs/v1/experiments\n@desc Create an LLM Observability experiment\n@required {data: map{attributes!: map, type!: str} # Data object for creating an LLM Observability experiment.}\n@returns(200) {data: map{attributes: map{aggregate_data: map?, author: map{email: str, handle: str, icon: str, id: str, name: str}, config: map?, created_at: str(date-time), dataset_id: str, dataset_name: str?, dataset_version: int(int64), deleted_at: str(date-time)?, description: str?, error: str?, experiment: str, metadata: map?, name: str, parent_experiment_id: str?, project_id: str, run_count: int(int32), status: str, updated_at: str(date-time)}, id: str, type: str}} # OK\n@returns(201) {data: map{attributes: map{aggregate_data: map?, author: map{email: str, handle: str, icon: str, id: str, name: str}, config: map?, created_at: str(date-time), dataset_id: str, dataset_name: str?, dataset_version: int(int64), deleted_at: str(date-time)?, description: str?, error: str?, experiment: str, metadata: map?, name: str, parent_experiment_id: str?, project_id: str, run_count: int(int32), status: str, updated_at: str(date-time)}, id: str, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"dataset_id\":\"9f64e5c7-dc5a-45c8-a17c-1b85f0bec97d\",\"name\":\"My Experiment v1\",\"project_id\":\"a33671aa-24fd-4dcd-9b33-a8ec7dde7751\"},\"type\":\"experiments\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/experiments/delete\n@desc Delete LLM Observability experiments\n@required {data: map{attributes!: map, type!: str} # Data object for deleting LLM Observability experiments.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"experiment_ids\":[\"3fd6b5e0-8910-4b1c-a7d0-5b84de329012\"]},\"type\":\"experiments\"}}\n\n@endpoint PATCH /api/v2/llm-obs/v1/experiments/{experiment_id}\n@desc Update an LLM Observability experiment\n@required {experiment_id: str # The ID of the LLM Observability experiment., data: map{attributes!: map, type!: str} # Data object for updating an LLM Observability experiment.}\n@returns(200) {data: map{attributes: map{aggregate_data: map?, author: map{email: str, handle: str, icon: str, id: str, name: str}, config: map?, created_at: str(date-time), dataset_id: str, dataset_name: str?, dataset_version: int(int64), deleted_at: str(date-time)?, description: str?, error: str?, experiment: str, metadata: map?, name: str, parent_experiment_id: str?, project_id: str, run_count: int(int32), status: str, updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"experiments\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/experiments/{experiment_id}/events\n@desc List LLM Observability experiment spans (v1)\n@required {experiment_id: str # The ID of the LLM Observability experiment.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/llm-obs/v1/experiments/{experiment_id}/events\n@desc Push events for an LLM Observability experiment\n@required {experiment_id: str # The ID of the LLM Observability experiment., data: map{attributes!: map, type!: str} # Data object for pushing experiment events.}\n@returns(202) Accepted\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"metrics\":[{\"assessment\":\"pass\",\"label\":\"faithfulness\",\"metric_type\":\"score\",\"span_id\":\"span-7a1b2c3d\",\"timestamp_ms\":1705314600000}],\"spans\":[{\"dataset_id\":\"9f64e5c7-dc5a-45c8-a17c-1b85f0bec97d\",\"duration\":1500000000,\"name\":\"llm_call\",\"project_id\":\"a33671aa-24fd-4dcd-9b33-a8ec7dde7751\",\"span_id\":\"span-7a1b2c3d\",\"start_ns\":1705314600000000000,\"status\":\"ok\",\"trace_id\":\"abc123def456\"}]},\"type\":\"events\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/integrations/{integration}/accounts\n@desc List LLM integration accounts\n@required {integration: str # The name of the LLM integration.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/llm-obs/v1/integrations/{integration}/{account_id}/inference\n@desc Run an LLM inference\n@required {integration: str # The name of the LLM integration., account_id: str # The ID of the integration account., messages: [map{content: str, contents: [map], id: str, role: str, tool_calls: [map], tool_results: [map]}] # List of messages in an inference conversation., model_id: str # The model identifier to use for inference.}\n@optional {anthropic_metadata: map{effort: str, thinking: map} # Anthropic-specific metadata for an inference request., azure_openai_metadata: map{deployment_id: str, model_version: str, resource_name: str} # Azure OpenAI-specific metadata for an integration account or inference request., bedrock_metadata: map{region: str} # Amazon Bedrock-specific metadata for an inference request., frequency_penalty: num(double) # Penalty for token frequency to reduce repetition., json_schema: str # JSON schema for structured output, if supported by the model., max_completion_tokens: int(int64) # Maximum number of completion tokens to generate (alternative to max_tokens for some providers)., max_tokens: int(int64) # Maximum number of tokens to generate., openai_metadata: map{reasoning_effort: str, reasoning_summary: str} # OpenAI-specific metadata for an inference request., presence_penalty: num(double) # Penalty for token presence to encourage topic diversity., temperature: num(double) # Sampling temperature between 0 and 2. Higher values produce more random output., tools: [map{function!: map, type!: str}] # List of tools available to the model., top_k: int(int64) # Top-K sampling parameter., top_p: num(double) # Nucleus sampling probability mass., vertex_ai_metadata: map{location: str, project: str, project_ids: [str]} # Vertex AI-specific metadata for an integration account or inference request.}\n@returns(200) {anthropic_metadata: map{effort: str?, thinking: map{budget_tokens: int(int64)?, type: str}}, azure_openai_metadata: map{deployment_id: str, model_version: str, resource_name: str}, bedrock_metadata: map{region: str}, error_response: map{message: str, type: str}, frequency_penalty: num(double)?, json_schema: str?, max_completion_tokens: int(int64)?, max_tokens: int(int64)?, messages: [map], model_id: str, openai_metadata: map{reasoning_effort: str?, reasoning_summary: str?}, presence_penalty: num(double)?, response: map{assessment: str?, content: str, finish_reason: str, inference_codes: [map], input_tokens: int(int64), internal_reasoning: map{reasoning_tokens: int(int64)?, text: str}, latency: int(int64), output_tokens: int(int64), tools: [map], total_tokens: int(int64)}, temperature: num(double)?, tools: [map], top_k: int(int64)?, top_p: num(double)?, vertex_ai_metadata: map{location: str, project: str, project_ids: [str]}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"max_tokens\":256,\"messages\":[{\"content\":\"What is the capital of France?\",\"role\":\"user\"}],\"model_id\":\"gpt-4o\",\"temperature\":0.7}\n\n@endpoint GET /api/v2/llm-obs/v1/integrations/{integration}/{account_id}/models\n@desc List LLM integration models\n@required {integration: str # The name of the LLM integration., account_id: str # The ID of the integration account.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/llm-obs/v1/projects\n@desc List LLM Observability projects\n@optional {filter[id]: str: any # Filter projects by project ID., filter[name]: str # Filter projects by name., page[cursor]: str # Use the Pagination cursor to retrieve the next page of results., page[limit]: int(int64) # Maximum number of results to return per page.}\n@returns(200) {data: [map], meta: map{after: str?}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/llm-obs/v1/projects\n@desc Create an LLM Observability project\n@required {data: map{attributes!: map, type!: str} # Data object for creating an LLM Observability project.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), description: str?, name: str, updated_at: str(date-time)}, id: str, type: str}} # OK\n@returns(201) {data: map{attributes: map{created_at: str(date-time), description: str?, name: str, updated_at: str(date-time)}, id: str, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"My LLM Project\"},\"type\":\"projects\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/projects/delete\n@desc Delete LLM Observability projects\n@required {data: map{attributes!: map, type!: str} # Data object for deleting LLM Observability projects.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"project_ids\":[\"a33671aa-24fd-4dcd-9b33-a8ec7dde7751\"]},\"type\":\"projects\"}}\n\n@endpoint PATCH /api/v2/llm-obs/v1/projects/{project_id}\n@desc Update an LLM Observability project\n@required {project_id: str # The ID of the LLM Observability project., data: map{attributes!: map, type!: str} # Data object for updating an LLM Observability project.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), description: str?, name: str, updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"projects\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/prompts\n@desc List LLM Observability prompts\n@optional {filter[prompt_id]: str: any # Optional filter for prompts by prompt ID.}\n@returns(200) {data: [map]} # OK\n@errors {401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/llm-obs/v1/prompts\n@desc Create an LLM Observability prompt\n@required {data: map{attributes!: map, type!: str} # Data object for creating an LLM Observability prompt.}\n@returns(200) {data: map{attributes: map{author: str, created_at: str(date-time), created_from: str, datasets: [map], description: str, extracted_from: str, in_registry: bool, last_seen_at: str(date-time), last_version_created_at: str(date-time), ml_app: str, ml_apps: [str], num_versions: int(int64), prompt_id: str, source: str, tags: [str], title: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Answers customer questions using the company knowledge base.\",\"prompt_id\":\"customer-support-assistant\",\"template\":[{\"content\":\"You are a helpful customer support assistant for {{company_name}}.\",\"role\":\"system\"},{\"content\":\"Help {{customer_name}} with this question: {{question}}\",\"role\":\"user\"}],\"title\":\"Customer Support Assistant\"},\"type\":\"prompt-templates\"}}\n\n@endpoint DELETE /api/v2/llm-obs/v1/prompts/{prompt_id}\n@desc Delete an LLM Observability prompt\n@required {prompt_id: str # The customer-provided identifier of the LLM Observability prompt.}\n@returns(200) {data: map{attributes: map{deleted_at: str(date-time), prompt_id: str}, id: str, type: str}} # OK\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/llm-obs/v1/prompts/{prompt_id}\n@desc Get an LLM Observability prompt\n@required {prompt_id: str # The customer-provided identifier of the LLM Observability prompt.}\n@optional {label: str # **Deprecated.** Optional label of the prompt version to return. Do not use this parameter for new integrations. If omitted, the latest version is returned. If the prompt has no labels, the latest version is returned even when a label is requested. If the prompt has labels but none match the requested label, a 404 response is returned.}\n@returns(200) {data: map{attributes: map{chat_template: [map], labels: [str], prompt_id: str, prompt_version_uuid: str, template: str, version: str}, id: str, type: str}} # OK\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/llm-obs/v1/prompts/{prompt_id}\n@desc Update an LLM Observability prompt\n@required {prompt_id: str # The customer-provided identifier of the LLM Observability prompt., data: map{attributes!: map, type!: str} # Data object for updating an LLM Observability prompt.}\n@returns(200) {data: map{attributes: map{author: str, created_at: str(date-time), created_from: str, datasets: [map], description: str, extracted_from: str, in_registry: bool, last_seen_at: str(date-time), last_version_created_at: str(date-time), ml_app: str, ml_apps: [str], num_versions: int(int64), prompt_id: str, source: str, tags: [str], title: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Answers customer questions using the company knowledge base.\",\"title\":\"Customer Support Assistant\"},\"type\":\"prompt-templates\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/prompts/{prompt_id}/versions\n@desc List versions of an LLM Observability prompt\n@required {prompt_id: str # The customer-provided identifier of the LLM Observability prompt.}\n@returns(200) {data: [map]} # OK\n@errors {401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/llm-obs/v1/prompts/{prompt_id}/versions\n@desc Create a new LLM Observability prompt version\n@required {prompt_id: str # The customer-provided identifier of the LLM Observability prompt., data: map{attributes!: map, type!: str} # Data object for creating an LLM Observability prompt version.}\n@returns(200) {data: map{attributes: map{author: str, created_at: str(date-time), datasets: [map], description: str, labels: [str], last_seen_at: str(date-time), ml_app: str, ml_apps: [str], prompt_id: str, prompt_uuid: str, tags: [str], template: any, user_version: str, version: int(int64), version_created_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Give concise answers and cite relevant help-center articles.\",\"template\":[{\"content\":\"You are a helpful customer support assistant for {{company_name}}.\",\"role\":\"system\"},{\"content\":\"Help {{customer_name}} with this question: {{question}}\",\"role\":\"user\"}]},\"type\":\"prompt-template-versions\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/prompts/{prompt_id}/versions/{version}\n@desc Get a specific LLM Observability prompt version\n@required {prompt_id: str # The customer-provided identifier of the LLM Observability prompt., version: int(int64) # The version number of the LLM Observability prompt.}\n@returns(200) {data: map{attributes: map{author: str, created_at: str(date-time), datasets: [map], description: str, labels: [str], last_seen_at: str(date-time), ml_app: str, ml_apps: [str], prompt_id: str, prompt_uuid: str, tags: [str], template: any, user_version: str, version: int(int64), version_created_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/llm-obs/v1/prompts/{prompt_id}/versions/{version}\n@desc Update a specific LLM Observability prompt version\n@required {prompt_id: str # The customer-provided identifier of the LLM Observability prompt., version: int(int64) # The version number of the LLM Observability prompt., data: map{attributes!: map, type!: str} # Data object for updating an LLM Observability prompt version.}\n@returns(200) {data: map{attributes: map{author: str, created_at: str(date-time), datasets: [map], description: str, labels: [str], last_seen_at: str(date-time), ml_app: str, ml_apps: [str], prompt_id: str, prompt_uuid: str, tags: [str], template: any, user_version: str, version: int(int64), version_created_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Give concise answers and cite relevant help-center articles.\"},\"type\":\"prompt-template-versions\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/spans/events\n@desc List LLM Observability spans\n@optional {filter[from]: str: any # Start of the time range. Accepts ISO 8601 or relative format (e.g., `now-15m`). Defaults to `now-15m`., filter[to]: str # End of the time range. Accepts ISO 8601 or relative format. Defaults to `now`., filter[query]: str # Search query using LLM Observability query syntax. Supports attribute filters using the field:value syntax (e.g. session_id, trace_id, ml_app, meta.span.kind). When provided, structured field filters (`filter[span_id]`, `filter[trace_id]`, etc.) are ignored., filter[span_id]: str # Filter by exact span ID., filter[trace_id]: str # Filter by exact trace ID., filter[span_kind]: str # Filter by span kind (e.g., llm, agent, tool, task, workflow)., filter[span_name]: str # Filter by span name., filter[ml_app]: str # Filter by ML application name., page[limit]: int(int64) # Maximum number of spans to return. Defaults to `10`., page[cursor]: str # Cursor from the previous response to retrieve the next page., sort: str # Sort order for the results., include_attachments: bool # Whether to include attachment data in the response. Defaults to `true`.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/llm-obs/v1/spans/events/search\n@desc Search LLM Observability spans\n@required {data: map{attributes!: map, type!: str} # Data object for an LLM Observability spans search request.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"filter\":{\"from\":\"now-900s\",\"ml_app\":\"my-llm-app\",\"span_kind\":\"llm\",\"to\":\"now\"},\"options\":{\"include_attachments\":true},\"page\":{\"limit\":10}},\"type\":\"spans\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/topic-discovery-clustered-points\n@desc List patterns clustered points\n@required {topic_id: str # The ID of the topic to retrieve clustered points for.}\n@optional {page_size: int(int64) # Maximum number of clustered points to return per page., page_token: str # Pagination token to retrieve the next page of clustered points.}\n@returns(200) {data: map{attributes: map{next_page_token: str?, points: [map], topic_id: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/llm-obs/v1/topic-discovery-configs\n@desc List patterns configurations\n@returns(200) {data: map{attributes: map{configs: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint PUT /api/v2/llm-obs/v1/topic-discovery-configs\n@desc Create or update a patterns configuration\n@required {data: map{attributes!: map, type!: str} # Data object for creating or updating an LLM Observability patterns configuration.}\n@returns(200) {data: map{attributes: map{account_id: str?, created_at: str(date-time), evp_query: str, hierarchy_depth: int(int32), integration_provider: str?, model_name: str?, name: str, num_records: int(int32), sampling_ratio: num(double), scope: str, template: str?, updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"evp_query\":\"@ml_app:support-bot\",\"hierarchy_depth\":2,\"name\":\"Support chatbot topics\",\"num_records\":1000,\"sampling_ratio\":0.1},\"type\":\"topic_discovery_configs\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/topic-discovery-configs/latest\n@desc Get a patterns configuration\n@returns(200) {data: map{attributes: map{account_id: str?, created_at: str(date-time), evp_query: str, hierarchy_depth: int(int32), integration_provider: str?, model_name: str?, name: str, num_records: int(int32), sampling_ratio: num(double), scope: str, template: str?, updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint DELETE /api/v2/llm-obs/v1/topic-discovery-configs/{config_id}\n@desc Delete a patterns configuration\n@required {config_id: str # The ID of the patterns configuration.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/llm-obs/v1/topic-discovery-runs\n@desc List patterns runs\n@required {config_id: str # The ID of the patterns configuration.}\n@returns(200) {data: map{attributes: map{runs: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/llm-obs/v1/topic-discovery-runs\n@desc Trigger a patterns run\n@required {data: map{attributes!: map, type!: str} # Data object for triggering an LLM Observability patterns run.}\n@returns(202) {data: map{attributes: map{config_id: str, run_id: str, status: str}, id: str, type: str}} # Accepted\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"config_id\":\"a7c8d9e0-1234-5678-9abc-def012345678\"},\"type\":\"topic_discovery\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/topic-discovery-runs/status\n@desc Get patterns run status\n@required {config_id: str # The ID of the patterns configuration.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), progress: [map], status: str, step: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/llm-obs/v1/topic-discovery-topics\n@desc List patterns topics\n@required {config_id: str # The ID of the patterns configuration.}\n@optional {run_id: str # The ID of a specific patterns run. Defaults to the most recent completed run.}\n@returns(200) {data: map{attributes: map{completed_at: str(date-time)?, config_id: str, config_snapshot: map{account_id: str, evp_query: str, hierarchy_depth: int(int32), integration_provider: str, model_name: str, num_records: int(int32), sampling_ratio: num(double)}, created_at: str(date-time), previous_run_id: str, run_id: str, topics: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/llm-obs/v1/topic-discovery-topics/with-cluster-points\n@desc List patterns topics with clustered points\n@required {config_id: str # The ID of the patterns configuration.}\n@optional {run_id: str # The ID of a specific patterns run. Defaults to the most recent completed run., include_metrics: bool # When true, enrich each clustered point with span metrics such as status, duration, token counts, estimated cost, and evaluations.}\n@returns(200) {data: map{attributes: map{completed_at: str(date-time)?, config_id: str, config_snapshot: map{account_id: str, evp_query: str, hierarchy_depth: int(int32), integration_provider: str, model_name: str, num_records: int(int32), sampling_ratio: num(double)}, created_at: str(date-time), previous_run_id: str, run_id: str, topics: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/llm-obs/v1/{project_id}/datasets\n@desc List LLM Observability datasets\n@required {project_id: str # The ID of the LLM Observability project.}\n@optional {filter[name]: str: any # Filter datasets by name., filter[id]: str # Filter datasets by dataset ID., page[cursor]: str # Use the Pagination cursor to retrieve the next page of results., page[limit]: int(int64) # Maximum number of results to return per page.}\n@returns(200) {data: [map], meta: map{after: str?}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/llm-obs/v1/{project_id}/datasets\n@desc Create an LLM Observability dataset\n@required {project_id: str # The ID of the LLM Observability project., data: map{attributes!: map, type!: str} # Data object for creating an LLM Observability dataset.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), current_version: int(int64), description: str?, metadata: map?, name: str, updated_at: str(date-time)}, id: str, type: str}} # OK\n@returns(201) {data: map{attributes: map{created_at: str(date-time), current_version: int(int64), description: str?, metadata: map?, name: str, updated_at: str(date-time)}, id: str, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"My LLM Dataset\"},\"type\":\"datasets\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/{project_id}/datasets/delete\n@desc Delete LLM Observability datasets\n@required {project_id: str # The ID of the LLM Observability project., data: map{attributes!: map, type!: str} # Data object for deleting LLM Observability datasets.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"dataset_ids\":[\"9f64e5c7-dc5a-45c8-a17c-1b85f0bec97d\"]},\"type\":\"datasets\"}}\n\n@endpoint PATCH /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}\n@desc Update an LLM Observability dataset\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset., data: map{attributes!: map, type!: str} # Data object for updating an LLM Observability dataset.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), current_version: int(int64), description: str?, metadata: map?, name: str, updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"datasets\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/batch_update\n@desc Batch update LLM Observability dataset records\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset., data: map{attributes!: map, id!: str, type!: str} # Data object for batch-updating records in an LLM Observability dataset.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 413: Payload Too Large, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"create_new_version\":true,\"delete_records\":[\"rec-old-record-1\"],\"insert_records\":[{\"expected_output\":{\"answer\":\"Paris\"},\"input\":{\"question\":\"What is the capital of France?\"},\"tags\":[\"topic:geography\"]}],\"update_records\":[{\"expected_output\":{\"answer\":\"Paris, France\"},\"id\":\"rec-7c3f5a1b-9e2d-4f8a-b1c6-3d7e9f0a2b4c\"}]},\"id\":\"9f64e5c7-dc5a-45c8-a17c-1b85f0bec97d\",\"type\":\"datasets\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/clone\n@desc Clone an LLM Observability dataset\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the source LLM Observability dataset to clone., data: map{attributes!: map, id!: str, type!: str} # Data object for cloning an LLM Observability dataset.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), current_version: int(int64), description: str?, metadata: map?, name: str, updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Clone of the original dataset for experimentation.\",\"name\":\"My cloned dataset\"},\"id\":\"9f64e5c7-dc5a-45c8-a17c-1b85f0bec97d\",\"type\":\"datasets\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/draft_state\n@desc Get LLM Observability dataset draft state\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset.}\n@returns(200) {data: map{attributes: map{drafting_since: str(date-time), user: map{email: str, handle: str, icon: str, id: str, name: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint PATCH /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/draft_state/lock\n@desc Lock LLM Observability dataset draft state\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset.}\n@returns(200) {data: map{attributes: map{drafting_since: str(date-time), user: map{email: str, handle: str, icon: str, id: str, name: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint PATCH /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/draft_state/unlock\n@desc Unlock LLM Observability dataset draft state\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/export\n@desc Export an LLM Observability dataset\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset.}\n@optional {format: str # Export format for the dataset contents. Only `csv` is currently supported., version: int(int64) # Version of the dataset to export. If omitted, the current version is used. Must be between 0 and the current version of the dataset, inclusive.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/records\n@desc List LLM Observability dataset records\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset.}\n@optional {filter[version]: int(int64): any # Retrieve records from a specific dataset version. Defaults to the current version., page[cursor]: str # Use the Pagination cursor to retrieve the next page of results., page[limit]: int(int64) # Maximum number of results to return per page.}\n@returns(200) {data: [map], meta: map{after: str?}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/records\n@desc Update LLM Observability dataset records\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset., data: map{attributes!: map, type!: str} # Data object for updating records in an LLM Observability dataset.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"records\":[{\"id\":\"rec-7c3f5a1b-9e2d-4f8a-b1c6-3d7e9f0a2b4c\"}]},\"type\":\"records\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/records\n@desc Append records to an LLM Observability dataset\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset., data: map{attributes!: map, type!: str} # Data object for appending records to an LLM Observability dataset.}\n@returns(200) {data: [map]} # OK\n@returns(201) {data: [map]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"records\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/records/delete\n@desc Delete LLM Observability dataset records\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset., data: map{attributes!: map, type!: str} # Data object for deleting records from an LLM Observability dataset.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"record_ids\":[\"rec-7c3f5a1b-9e2d-4f8a-b1c6-3d7e9f0a2b4c\"]},\"type\":\"records\"}}\n\n@endpoint POST /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/restore\n@desc Restore an LLM Observability dataset version\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset., data: map{attributes!: map, id!: str, type!: str} # Data object for restoring an LLM Observability dataset to a previous version.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"dataset_version\":1},\"id\":\"9f64e5c7-dc5a-45c8-a17c-1b85f0bec97d\",\"type\":\"datasets\"}}\n\n@endpoint GET /api/v2/llm-obs/v1/{project_id}/datasets/{dataset_id}/versions\n@desc List LLM Observability dataset versions\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/llm-obs/v2/experiments/{experiment_id}/events\n@desc List LLM Observability experiment events (v2)\n@required {experiment_id: str # The ID of the LLM Observability experiment.}\n@returns(200) {data: map{attributes: map{spans: [map], summary_metrics: [map]}, id: str, type: str}, meta: map{after: str?}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/llm-obs/v2/{project_id}/datasets/{dataset_id}/records/upload\n@desc Upload records to an LLM Observability dataset\n@required {project_id: str # The ID of the LLM Observability project., dataset_id: str # The ID of the LLM Observability dataset.}\n@optional {deduplicate: bool=false # Whether to skip records whose `input` already exists in the dataset. Defaults to `false`., overwrite: bool=true # Whether to overwrite existing records that share the same user-provided `id`. Defaults to `true`., tags: [str] # Tags to apply to every uploaded record, in addition to any tags defined on individual rows. Can be repeated, e.g. `tags=env:prod&tags=team:ai`., include[user_data]: bool # Whether to enrich the response with user metadata.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/llm-obs/v3/experiments/{experiment_id}/events\n@desc List events for an LLM Observability experiment\n@required {experiment_id: str # The ID of the LLM Observability experiment.}\n@optional {page[limit]: int(int64)=5000: any # Maximum number of spans to return per page. Defaults to 5000., page[cursor]: str # Opaque cursor from a previous response to fetch the next page of results.}\n@returns(200) {data: map{attributes: map{spans: [map], summary_metrics: [map]}, id: str, type: str}, meta: map{after: str?}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint PUT /api/v2/login/org_configs/max_session_duration\n@desc Update the maximum session duration\n@required {data: map{attributes!: map, type!: str} # The data object for a maximum session duration update request.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"max_session_duration\":604800},\"type\":\"max_session_duration\"}}\n\n@endpoint POST /api/v2/logs\n@desc Send logs\n@optional {Content-Encoding: str # HTTP header used to compress the media-type., ddtags: str # Log tags can be passed as query parameters with `text/plain` content type.}\n@returns(202) Request accepted for processing (always 202 empty JSON).\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 408: Request Timeout, 413: Payload Too Large, 429: Too Many Requests, 500: Internal Server Error, 503: Service Unavailable}\n@example_request {\"ddsource\":\"nginx\",\"ddtags\":\"env:staging,version:5.1\",\"hostname\":\"i-012345678\",\"message\":\"2019-11-19T14:37:58,995 INFO [process.name][20081] Hello World\",\"service\":\"payment\"}\n\n@endpoint POST /api/v2/logs/analytics/aggregate\n@desc Aggregate events\n@optional {compute: [map{aggregation!: str, interval: str, metric: str, type: str}] # The list of metrics or timeseries to compute for the retrieved buckets., filter: map{from: str, indexes: [str], query: str, storage_tier: str, to: str} # The search and filter query settings, group_by: [map{facet!: str, histogram: map, limit: int(int64), missing: any, sort: map, total: any}] # The rules for the group by, options: map{timeOffset: int(int64), timezone: str} # Global query options that are used during the query. Note: These fields are currently deprecated and do not affect the query results., page: map{cursor: str} # Paging settings}\n@returns(200) {data: map{buckets: [map]}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"compute\":[{\"aggregation\":\"pc90\",\"interval\":\"5m\",\"metric\":\"@duration\",\"type\":\"timeseries\"}],\"filter\":{\"from\":\"now-15m\",\"indexes\":[\"main\",\"web\"],\"query\":\"service:web* AND @http.status_code:[200 TO 299]\",\"storage_tier\":\"indexes\",\"to\":\"now\"},\"group_by\":[{\"facet\":\"host\",\"histogram\":{\"interval\":10,\"max\":100,\"min\":50},\"sort\":{\"aggregation\":\"count\",\"order\":\"asc\"}}],\"options\":{\"timezone\":\"GMT\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\"}}\n\n@endpoint GET /api/v2/logs/config/archive-order\n@desc Get archive order\n@returns(200) {data: map{attributes: map{archive_ids: [str]}, type: str}} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint PUT /api/v2/logs/config/archive-order\n@desc Update archive order\n@optional {data: map{attributes!: map, type!: str} # The definition of an archive order.}\n@returns(200) {data: map{attributes: map{archive_ids: [str]}, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"archive_ids\":[\"a2zcMylnM4OCHpYusxIi1g\",\"a2zcMylnM4OCHpYusxIi2g\",\"a2zcMylnM4OCHpYusxIi3g\"]},\"type\":\"archive_order\"}}\n\n@endpoint GET /api/v2/logs/config/archives\n@desc Get all archives\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/logs/config/archives\n@desc Create an archive\n@optional {data: map{attributes: map, type!: str} # The definition of an archive.}\n@returns(200) {data: map{attributes: map{compression_method: str, destination: map?, include_tags: bool, lookup_attributes: [str], name: str, partitioning_attributes: [str], query: str, rehydration_max_scan_size_in_gb: int(int64)?, rehydration_tags: [str], state: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compression_method\":\"GZIP\",\"destination\":{\"container\":\"container-name\",\"storage_account\":\"account-name\",\"type\":\"azure\"},\"include_tags\":false,\"name\":\"Nginx Archive\",\"query\":\"source:nginx\",\"rehydration_max_scan_size_in_gb\":100,\"rehydration_tags\":[\"team:intake\",\"team:app\"]},\"type\":\"archives\"}}\n\n@endpoint DELETE /api/v2/logs/config/archives/{archive_id}\n@desc Delete an archive\n@required {archive_id: str # The ID of the archive.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not found, 429: Too many requests}\n\n@endpoint GET /api/v2/logs/config/archives/{archive_id}\n@desc Get an archive\n@required {archive_id: str # The ID of the archive.}\n@returns(200) {data: map{attributes: map{compression_method: str, destination: map?, include_tags: bool, lookup_attributes: [str], name: str, partitioning_attributes: [str], query: str, rehydration_max_scan_size_in_gb: int(int64)?, rehydration_tags: [str], state: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not found, 429: Too many requests}\n\n@endpoint PUT /api/v2/logs/config/archives/{archive_id}\n@desc Update an archive\n@required {archive_id: str # The ID of the archive.}\n@optional {data: map{attributes: map, type!: str} # The definition of an archive.}\n@returns(200) {data: map{attributes: map{compression_method: str, destination: map?, include_tags: bool, lookup_attributes: [str], name: str, partitioning_attributes: [str], query: str, rehydration_max_scan_size_in_gb: int(int64)?, rehydration_tags: [str], state: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compression_method\":\"GZIP\",\"destination\":{\"container\":\"container-name\",\"storage_account\":\"account-name\",\"type\":\"azure\"},\"include_tags\":false,\"name\":\"Nginx Archive\",\"query\":\"source:nginx\",\"rehydration_max_scan_size_in_gb\":100,\"rehydration_tags\":[\"team:intake\",\"team:app\"]},\"type\":\"archives\"}}\n\n@endpoint DELETE /api/v2/logs/config/archives/{archive_id}/readers\n@desc Revoke role from an archive\n@required {archive_id: str # The ID of the archive.}\n@optional {data: map{id: str, type: str} # Relationship to role object.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"3653d3c6-0c75-11ea-ad28-fb5701eabc7d\",\"type\":\"roles\"}}\n\n@endpoint GET /api/v2/logs/config/archives/{archive_id}/readers\n@desc List read roles for an archive\n@required {archive_id: str # The ID of the archive.}\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not found, 429: Too many requests}\n\n@endpoint POST /api/v2/logs/config/archives/{archive_id}/readers\n@desc Grant role to an archive\n@required {archive_id: str # The ID of the archive.}\n@optional {data: map{id: str, type: str} # Relationship to role object.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"3653d3c6-0c75-11ea-ad28-fb5701eabc7d\",\"type\":\"roles\"}}\n\n@endpoint GET /api/v2/logs/config/custom-destinations\n@desc Get all custom destinations\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/logs/config/custom-destinations\n@desc Create a custom destination\n@optional {data: map{attributes!: map, type!: str} # The definition of a custom destination.}\n@returns(200) {data: map{attributes: map{enabled: bool, forward_tags: bool, forward_tags_restriction_list: [str], forward_tags_restriction_list_type: str, forwarder_destination: any, name: str, query: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"forward_tags\":true,\"forward_tags_restriction_list\":[\"datacenter\",\"host\"],\"forward_tags_restriction_list_type\":\"ALLOW_LIST\",\"forwarder_destination\":{\"endpoint\":\"https://example.com\",\"type\":\"http\"},\"name\":\"Nginx logs\",\"query\":\"source:nginx\"},\"type\":\"custom_destination\"}}\n\n@endpoint DELETE /api/v2/logs/config/custom-destinations/{custom_destination_id}\n@desc Delete a custom destination\n@required {custom_destination_id: str # The ID of the custom destination.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/logs/config/custom-destinations/{custom_destination_id}\n@desc Get a custom destination\n@required {custom_destination_id: str # The ID of the custom destination.}\n@returns(200) {data: map{attributes: map{enabled: bool, forward_tags: bool, forward_tags_restriction_list: [str], forward_tags_restriction_list_type: str, forwarder_destination: any, name: str, query: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/logs/config/custom-destinations/{custom_destination_id}\n@desc Update a custom destination\n@required {custom_destination_id: str # The ID of the custom destination.}\n@optional {data: map{attributes: map, id!: str, type!: str} # The definition of a custom destination.}\n@returns(200) {data: map{attributes: map{enabled: bool, forward_tags: bool, forward_tags_restriction_list: [str], forward_tags_restriction_list_type: str, forwarder_destination: any, name: str, query: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"forward_tags\":true,\"forward_tags_restriction_list\":[\"datacenter\",\"host\"],\"forward_tags_restriction_list_type\":\"ALLOW_LIST\",\"forwarder_destination\":{\"endpoint\":\"https://example.com\",\"type\":\"http\"},\"name\":\"Nginx logs\",\"query\":\"source:nginx\"},\"id\":\"be5d7a69-d0c8-4d4d-8ee8-bba292d98139\",\"type\":\"custom_destination\"}}\n\n@endpoint GET /api/v2/logs/config/metrics\n@desc Get all log-based metrics\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/logs/config/metrics\n@desc Create a log-based metric\n@required {data: map{attributes!: map, id!: str, type!: str} # The new log-based metric properties.}\n@returns(200) {data: map{attributes: map{compute: map{aggregation_type: str, include_percentiles: bool, path: str}, filter: map{query: str}, group_by: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compute\":{\"aggregation_type\":\"distribution\",\"include_percentiles\":true,\"path\":\"@duration\"},\"filter\":{\"query\":\"service:web* AND @http.status_code:[200 TO 299]\"},\"group_by\":[{\"path\":\"@http.status_code\",\"tag_name\":\"status_code\"}]},\"id\":\"logs.page.load.count\",\"type\":\"logs_metrics\"}}\n\n@endpoint DELETE /api/v2/logs/config/metrics/{metric_id}\n@desc Delete a log-based metric\n@required {metric_id: str # The name of the log-based metric.}\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/logs/config/metrics/{metric_id}\n@desc Get a log-based metric\n@required {metric_id: str # The name of the log-based metric.}\n@returns(200) {data: map{attributes: map{compute: map{aggregation_type: str, include_percentiles: bool, path: str}, filter: map{query: str}, group_by: [map]}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/logs/config/metrics/{metric_id}\n@desc Update a log-based metric\n@required {metric_id: str # The name of the log-based metric., data: map{attributes!: map, type!: str} # The new log-based metric properties.}\n@returns(200) {data: map{attributes: map{compute: map{aggregation_type: str, include_percentiles: bool, path: str}, filter: map{query: str}, group_by: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compute\":{\"include_percentiles\":true},\"filter\":{\"query\":\"service:web* AND @http.status_code:[200 TO 299]\"},\"group_by\":[{\"path\":\"@http.status_code\",\"tag_name\":\"status_code\"}]},\"type\":\"logs_metrics\"}}\n\n@endpoint GET /api/v2/logs/config/restriction_queries\n@desc List restriction queries\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return.}\n@returns(200) {data: [map]} # OK\n@errors {403: Authentication error, 429: Too many requests}\n\n@endpoint POST /api/v2/logs/config/restriction_queries\n@desc Create a restriction query\n@optional {data: map{attributes: map, type: str} # Data related to the creation of a restriction query.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), last_modifier_email: str, last_modifier_name: str, modified_at: str(date-time), restriction_query: str, role_count: int(int64), user_count: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Authentication error, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"restriction_query\":\"env:sandbox\"},\"type\":\"logs_restriction_queries\"}}\n\n@endpoint GET /api/v2/logs/config/restriction_queries/role/{role_id}\n@desc Get restriction query for a given role\n@required {role_id: str # The ID of the role.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint GET /api/v2/logs/config/restriction_queries/user/{user_id}\n@desc Get all restriction queries for a given user\n@required {user_id: str # The ID of the user.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/logs/config/restriction_queries/{restriction_query_id}\n@desc Delete a restriction query\n@required {restriction_query_id: str # The ID of the restriction query.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint GET /api/v2/logs/config/restriction_queries/{restriction_query_id}\n@desc Get a restriction query\n@required {restriction_query_id: str # The ID of the restriction query.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), last_modifier_email: str, last_modifier_name: str, modified_at: str(date-time), restriction_query: str, role_count: int(int64), user_count: int(int64)}, id: str, relationships: map{roles: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/logs/config/restriction_queries/{restriction_query_id}\n@desc Update a restriction query\n@required {restriction_query_id: str # The ID of the restriction query.}\n@optional {data: map{attributes: map, type: str} # Data related to the update of a restriction query.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), last_modifier_email: str, last_modifier_name: str, modified_at: str(date-time), restriction_query: str, role_count: int(int64), user_count: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"restriction_query\":\"env:sandbox\"},\"type\":\"logs_restriction_queries\"}}\n\n@endpoint PUT /api/v2/logs/config/restriction_queries/{restriction_query_id}\n@desc Replace a restriction query\n@required {restriction_query_id: str # The ID of the restriction query.}\n@optional {data: map{attributes: map, type: str} # Data related to the update of a restriction query.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), last_modifier_email: str, last_modifier_name: str, modified_at: str(date-time), restriction_query: str, role_count: int(int64), user_count: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"restriction_query\":\"env:sandbox\"},\"type\":\"logs_restriction_queries\"}}\n\n@endpoint DELETE /api/v2/logs/config/restriction_queries/{restriction_query_id}/roles\n@desc Revoke role from a restriction query\n@required {restriction_query_id: str # The ID of the restriction query.}\n@optional {data: map{id: str, type: str} # Relationship to role object.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"3653d3c6-0c75-11ea-ad28-fb5701eabc7d\",\"type\":\"roles\"}}\n\n@endpoint GET /api/v2/logs/config/restriction_queries/{restriction_query_id}/roles\n@desc List roles for a restriction query\n@required {restriction_query_id: str # The ID of the restriction query.}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint POST /api/v2/logs/config/restriction_queries/{restriction_query_id}/roles\n@desc Grant role to a restriction query\n@required {restriction_query_id: str # The ID of the restriction query.}\n@optional {data: map{id: str, type: str} # Relationship to role object.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"3653d3c6-0c75-11ea-ad28-fb5701eabc7d\",\"type\":\"roles\"}}\n\n@endpoint GET /api/v2/logs/events\n@desc Search logs (GET)\n@optional {filter[query]: str: any # Search query following logs syntax., filter[indexes]: [str] # For customers with multiple indexes, the indexes to search. Defaults to '*' which means all indexes, filter[from]: str(date-time) # Minimum timestamp for requested logs., filter[to]: str(date-time) # Maximum timestamp for requested logs., filter[storage_tier]: str # Specifies the storage type to be used, sort: str # Order of logs in results., page[cursor]: str # List following results with a cursor provided in the previous query., page[limit]: int(int32)=10 # Maximum number of logs in the response.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/logs/events/search\n@desc Search logs (POST)\n@optional {filter: map{from: str, indexes: [str], query: str, storage_tier: str, to: str} # The search and filter query settings, options: map{timeOffset: int(int64), timezone: str} # Global query options that are used during the query. Note: These fields are currently deprecated and do not affect the query results., page: map{cursor: str, limit: int(int32)} # Paging attributes for listing logs., sort: str(timestamp/-timestamp) # Sort parameters when querying logs.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"filter\":{\"from\":\"now-15m\",\"indexes\":[\"main\",\"web\"],\"query\":\"service:web* AND @http.status_code:[200 TO 299]\",\"storage_tier\":\"indexes\",\"to\":\"now\"},\"options\":{\"timezone\":\"GMT\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\",\"limit\":25},\"sort\":\"timestamp\"}\n\n@endpoint GET /api/v2/maintenance_windows\n@desc List maintenance windows\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/maintenance_windows\n@desc Create a maintenance window\n@required {data: map{attributes!: map, type!: str} # Data object for creating a maintenance window.}\n@returns(201) {data: map{attributes: map{created_by: str, end_at: str(date-time), name: str, query: str, start_at: str(date-time), updated_by: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"end_at\":\"2026-06-01T06:00:00Z\",\"name\":\"Weekly maintenance\",\"query\":\"project:SEC\",\"start_at\":\"2026-06-01T00:00:00Z\"},\"type\":\"maintenance_window\"}}\n\n@endpoint DELETE /api/v2/maintenance_windows/{maintenance_window_id}\n@desc Delete a maintenance window\n@required {maintenance_window_id: str # The UUID of the maintenance window.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/maintenance_windows/{maintenance_window_id}\n@desc Update a maintenance window\n@required {maintenance_window_id: str # The UUID of the maintenance window., data: map{attributes: map, type!: str} # Data object for updating a maintenance window.}\n@returns(200) {data: map{attributes: map{created_by: str, end_at: str(date-time), name: str, query: str, start_at: str(date-time), updated_by: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"end_at\":\"2026-06-01T06:00:00Z\",\"name\":\"Weekly maintenance\",\"query\":\"project:SEC\",\"start_at\":\"2026-06-01T00:00:00Z\"},\"type\":\"maintenance_window\"}}\n\n@endpoint GET /api/v2/metrics\n@desc Get a list of metrics\n@optional {filter[configured]: bool: any # Only return custom metrics that have been configured (`true`) or not configured (`false`) with Metrics Without Limits., filter[is_configurable]: bool # Only return metrics that are eligible (`true`) or ineligible (`false`) for configuration with Metrics Without Limits., filter[tags_configured]: str # Only return metrics that have the given tag key(s) in their Metrics Without Limits configuration (included or excluded)., filter[metric_type]: str # Only return metrics of the given metric type., filter[include_percentiles]: bool # Only return distribution metrics that have percentile aggregations enabled (true) or disabled (false)., filter[queried]: bool # Only return metrics that have been queried (true) or not queried (false) in the look back window. Set the window with `filter[queried][window][seconds]`; if omitted, a default window is used., filter[queried][window][seconds]: int(int64)=2592000 # This parameter has no effect unless `filter[queried]` is also set. Only return metrics that have been queried or not queried in the specified window. The default value is 2,592,000 seconds (30 days), the maximum value is 15,552,000 seconds (180 days), and the minimum value is 1 second. For example: `filter[queried]=true&filter[queried][window][seconds]=604800`., filter[tags]: str # Only return metrics that were submitted with tags matching this expression. You can use AND, OR, IN, and wildcards. For example: `filter[tags]=env IN (staging,test) AND service:web*`., filter[related_assets]: bool # Only return metrics that are used in at least one dashboard, monitor, notebook, or SLO., include: str # Include related resources in the response. Set to `metric_volumes` to include indexed and ingested volume counts for each metric., sort: str # Sort results by metric volume. Prefix a key with `-` for descending order. Supported keys: `metric_volumes.indexed_volume`, `metric_volumes.ingested_volume`, `metric_volumes.indexed_volume_delta`, `metric_volumes.ingested_volume_delta`. Requires a paginated request (`page[size]` or `page[cursor]`)., window[seconds]: int(int64)=3600 # Only return metrics that have been actively reporting in the specified window. The default value is 3600 seconds (1 hour), the maximum value is 2,592,000 seconds (30 days), and the minimum value is 1 second., page[size]: int(int32)=10000 # Maximum number of results per page. Send `page[size]` on the first request to opt in to pagination. On each subsequent request, send `page[cursor]` set to the value of `meta.pagination.next_cursor` from the previous response. The default value is 10000, the maximum value is 10000, and the minimum value is 1., page[cursor]: str # Cursor for pagination. Use `page[size]` to opt-in to pagination and get the first page; for subsequent pages, use the value from `meta.pagination.next_cursor` in the response. Pagination is complete when `next_cursor` is null.}\n@returns(200) {data: [any], included: [map], links: map{first: str, last: str?, next: str?, prev: str?, self: str}, meta: map{pagination: map{cursor: str?, limit: int(int32), next_cursor: str?, type: str}}} # Success\n@errors {400: Bad Request, 403: Forbidden, 429: Too Many Requests}\n\n@endpoint DELETE /api/v2/metrics/config/bulk-tags\n@desc Delete tags for multiple metrics\n@required {data: map{attributes: map, id!: str, type!: str} # Request object to bulk delete all tag configurations for metrics matching the given prefix.}\n@returns(202) {data: map{attributes: map{emails: [str], exclude_tags_mode: bool, status: str, tags: [str]}, id: str, type: str}} # Accepted\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Requests}\n@example_request {\"data\":{\"attributes\":{\"emails\":[\"sue@example.com\",\"bob@example.com\"]},\"id\":\"kafka.lag\",\"type\":\"metric_bulk_configure_tags\"}}\n\n@endpoint POST /api/v2/metrics/config/bulk-tags\n@desc Configure tags for multiple metrics\n@required {data: map{attributes: map, id!: str, type!: str} # Request object to bulk configure tags for metrics matching the given prefix.}\n@returns(202) {data: map{attributes: map{emails: [str], exclude_tags_mode: bool, status: str, tags: [str]}, id: str, type: str}} # Accepted\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Requests}\n@example_request {\"data\":{\"attributes\":{\"emails\":[\"sue@example.com\",\"bob@example.com\"],\"tags\":[\"host\",\"pod_name\",\"is_shadow\"]},\"id\":\"kafka.lag\",\"type\":\"metric_bulk_configure_tags\"}}\n\n@endpoint POST /api/v2/metrics/historical-metrics-configurations\n@desc Enable historical metrics ingestion\n@required {data: map{id!: str, type!: str} # Data object for enabling historical metrics ingestion for a metric.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time)}, id: str, type: str}} # OK\n@returns(201) {data: map{attributes: map{created_at: str(date-time)}, id: str, type: str}} # Created\n@errors {400: Bad Request, 404: Not Found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"dd.test.metric\",\"type\":\"historical_metrics_configurations\"}}\n\n@endpoint DELETE /api/v2/metrics/historical-metrics-configurations/{metric_name}\n@desc Delete a historical metrics configuration\n@required {metric_name: str # The name of the metric.}\n@returns(204) No Content\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/metrics/historical-metrics-configurations/{metric_name}\n@desc Get a historical metrics configuration\n@required {metric_name: str # The name of the metric.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/metrics/tag-indexing-rules\n@desc List tag indexing rules\n@optional {page[limit]: int(int64): any # Page size (1–1000, default 100)., page[offset]: int(int64) # Page offset from the start of the list (default 0)., search: str # Substring filter on rule name.}\n@returns(200) {data: [map], links: map{first: str, last: str?, next: str?, prev: str?, self: str}, meta: map{total: int(int64)}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too Many Requests}\n\n@endpoint POST /api/v2/metrics/tag-indexing-rules\n@desc Create a tag indexing rule\n@required {data: map{attributes!: map, type!: str} # Data object for creating a tag indexing rule.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), created_by_handle: str, exclude_tags_mode: bool, ignored_metric_name_matches: [str], metric_name_matches: [str], modified_at: str(date-time), modified_by_handle: str, name: str, options: map{data: map, version: int(int64)}, rule_order: int(int64), tags: [str]}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too Many Requests}\n@example_request {\"data\":{\"attributes\":{\"metric_name_matches\":[\"dd.test.*\"],\"name\":\"my-indexing-rule\",\"tags\":[\"env\",\"service\"]},\"type\":\"tag_indexing_rules\"}}\n\n@endpoint POST /api/v2/metrics/tag-indexing-rules/order\n@desc Reorder tag indexing rules\n@required {data: map{attributes!: map, type!: str} # Data object for the reorder operation.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Requests}\n@example_request {\"data\":{\"attributes\":{\"rule_ids\":[\"00000000-0000-0000-0000-000000000001\",\"00000000-0000-0000-0000-000000000002\"]},\"type\":\"tag_indexing_rules\"}}\n\n@endpoint DELETE /api/v2/metrics/tag-indexing-rules/{id}\n@desc Delete a tag indexing rule\n@required {id: str # ID of the tag indexing rule.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 429: Too Many Requests}\n\n@endpoint GET /api/v2/metrics/tag-indexing-rules/{id}\n@desc Get a tag indexing rule\n@required {id: str # ID of the tag indexing rule.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by_handle: str, exclude_tags_mode: bool, ignored_metric_name_matches: [str], metric_name_matches: [str], modified_at: str(date-time), modified_by_handle: str, name: str, options: map{data: map, version: int(int64)}, rule_order: int(int64), tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Requests}\n\n@endpoint PUT /api/v2/metrics/tag-indexing-rules/{id}\n@desc Update a tag indexing rule\n@required {id: str # ID of the tag indexing rule., data: map{attributes: map, type!: str} # Data object for updating a tag indexing rule.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by_handle: str, exclude_tags_mode: bool, ignored_metric_name_matches: [str], metric_name_matches: [str], modified_at: str(date-time), modified_by_handle: str, name: str, options: map{data: map, version: int(int64)}, rule_order: int(int64), tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too Many Requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"my-updated-rule\",\"tags\":[\"env\",\"service\",\"version\"]},\"type\":\"tag_indexing_rules\"}}\n\n@endpoint GET /api/v2/metrics/{metric_name}/active-configurations\n@desc List active tags and aggregations\n@required {metric_name: str # The name of the metric.}\n@optional {window[seconds]: int(int64): any # The number of seconds of look back (from now). Default value is 604,800 (1 week), minimum value is 7200 (2 hours), maximum value is 2,630,000 (1 month).}\n@returns(200) {data: map{attributes: map{active_aggregations: [map], active_tags: [str]}, id: str, type: str}} # Success\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Requests}\n\n@endpoint GET /api/v2/metrics/{metric_name}/all-tags\n@desc List tags by metric name\n@required {metric_name: str # The name of the metric.}\n@optional {window[seconds]: int(int64): any # The number of seconds of look back (from now) to query for tag data. Default value is 14400 (4 hours), minimum value is 14400 (4 hours)., filter[tags]: str # Filter results to tags from data points that have the specified tags. For example, `filter[tags]=env:staging,host:123` returns tags only from data points with both `env:staging` and `host:123`., filter[match]: str # Filter returned tags to those matching a substring. For example, `filter[match]=env` returns tags like `env:prod`, `environment:staging`, etc., filter[include_tag_values]: bool # Whether to include tag values in the response. Defaults to true., filter[allow_partial]: bool # Whether to allow partial results. Defaults to false., page[limit]: int(int32)=1000000 # Maximum number of results to return.}\n@returns(200) {data: map{attributes: map{ingested_tags: [str], tags: [str]}, id: str, type: str}} # Success\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Requests}\n\n@endpoint GET /api/v2/metrics/{metric_name}/assets\n@desc Related Assets to a Metric\n@required {metric_name: str # The name of the metric.}\n@returns(200) {data: map{id: str, relationships: map{dashboards: map{data: [map]}, monitors: map{data: [map]}, notebooks: map{data: [map]}, slos: map{data: [map]}}, type: str}, included: [any]} # Success\n@errors {400: API error response., 403: API error response., 404: API error response., 429: Too Many Requests}\n\n@endpoint GET /api/v2/metrics/{metric_name}/estimate\n@desc Tag Configuration Cardinality Estimator\n@required {metric_name: str # The name of the metric.}\n@optional {filter[groups]: str: any # Comma-separated list of tag keys that the metric is configured to query with. For example: `filter[groups]=app,host`., filter[hours_ago]: int(int32) # The number of hours of look back (from now) to estimate cardinality with. If unspecified, it defaults to 0 hours., filter[num_aggregations]: int(int32) # Deprecated. Number of aggregations has no impact on volume., filter[pct]: bool # A boolean, for distribution metrics only, to estimate cardinality if the metric includes additional percentile aggregators., filter[timespan_h]: int(int32) # A window, in hours, from the look back to estimate cardinality with. The minimum and default is 1 hour.}\n@returns(200) {data: map{attributes: map{estimate_type: str, estimated_at: str(date-time), estimated_output_series: int(int64)}, id: str, type: str}} # Success\n@errors {400: API error response., 403: API error response., 404: API error response., 429: Too Many Requests}\n\n@endpoint GET /api/v2/metrics/{metric_name}/tag-cardinalities\n@desc Get tag key cardinality details\n@required {metric_name: str # The name of the metric.}\n@returns(200) {data: [map], meta: map{metric_name: str}} # Success\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Requests}\n\n@endpoint DELETE /api/v2/metrics/{metric_name}/tag-indexing-rule-exemptions\n@desc Delete a tag indexing rule exemption\n@required {metric_name: str # The name of the metric.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 429: Too Many Requests}\n\n@endpoint GET /api/v2/metrics/{metric_name}/tag-indexing-rule-exemptions\n@desc Get a tag indexing rule exemption\n@required {metric_name: str # The name of the metric.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by_handle: str, kind: str, reason: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Requests}\n\n@endpoint POST /api/v2/metrics/{metric_name}/tag-indexing-rule-exemptions\n@desc Create a tag indexing rule exemption\n@required {metric_name: str # The name of the metric., data: map{attributes!: map, type!: str} # Data object for creating a tag indexing rule exemption.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), created_by_handle: str, kind: str, reason: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too Many Requests}\n@example_request {\"data\":{\"attributes\":{\"reason\":\"This metric has a pre-existing tag configuration.\"},\"type\":\"tag_indexing_rule_exemptions\"}}\n\n@endpoint GET /api/v2/metrics/{metric_name}/tag-indexing-rules\n@desc List tag indexing rules for a metric\n@required {metric_name: str # The name of the metric.}\n@returns(200) {data: [map], links: map{first: str, last: str?, next: str?, prev: str?, self: str}, meta: map{total: int(int64)}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too Many Requests}\n\n@endpoint DELETE /api/v2/metrics/{metric_name}/tags\n@desc Delete a tag configuration\n@required {metric_name: str # The name of the metric.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not found, 429: Too Many Requests}\n\n@endpoint GET /api/v2/metrics/{metric_name}/tags\n@desc List tag configuration by name\n@required {metric_name: str # The name of the metric.}\n@returns(200) {data: map{attributes: map{aggregations: [map], created_at: str(date-time), exclude_tags_mode: bool, include_percentiles: bool, metric_type: str, modified_at: str(date-time), tags: [str]}, id: str, relationships: map{metric_volumes: map{data: map}}, type: str}} # Success\n@errors {403: Forbidden, 404: No tag configuration exists for the metric, 429: Too Many Requests}\n\n@endpoint PATCH /api/v2/metrics/{metric_name}/tags\n@desc Update a tag configuration\n@required {metric_name: str # The name of the metric., data: map{attributes: map, id!: str, type!: str} # Object for a single tag configuration to be edited.}\n@returns(200) {data: map{attributes: map{aggregations: [map], created_at: str(date-time), exclude_tags_mode: bool, include_percentiles: bool, metric_type: str, modified_at: str(date-time), tags: [str]}, id: str, relationships: map{metric_volumes: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 422: Unprocessable Entity, 429: Too Many Requests}\n@example_request {\"data\":{\"attributes\":{\"group_by\":[\"app\",\"datacenter\"],\"include_percentiles\":false},\"id\":\"http.endpoint.request\",\"type\":\"manage_tags\"}}\n\n@endpoint POST /api/v2/metrics/{metric_name}/tags\n@desc Create a tag configuration\n@required {metric_name: str # The name of the metric., data: map{attributes: map, id!: str, type!: str} # Object for a single metric to be configure tags on.}\n@returns(201) {data: map{attributes: map{aggregations: [map], created_at: str(date-time), exclude_tags_mode: bool, include_percentiles: bool, metric_type: str, modified_at: str(date-time), tags: [str]}, id: str, relationships: map{metric_volumes: map{data: map}}, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too Many Requests}\n@example_request {\"data\":{\"attributes\":{\"include_percentiles\":false,\"metric_type\":\"distribution\",\"tags\":[\"app\",\"datacenter\"]},\"id\":\"http.endpoint.request\",\"type\":\"manage_tags\"}}\n\n@endpoint GET /api/v2/metrics/{metric_name}/volumes\n@desc List distinct metric volumes by metric name\n@required {metric_name: str # The name of the metric.}\n@optional {window[seconds]: int(int64): any # The number of seconds of look back (from now). Default value is 3,600 (1 hour), maximum value is 2,592,000 (1 month).}\n@returns(200) {data: any} # Success\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too Many Requests}\n\n@endpoint GET /api/v2/model-lab-api/artifacts/content\n@desc Get Model Lab artifact content\n@required {project_id: str # ID of the project., artifact_path: str # Path to the artifact relative to the project directory.}\n@returns(200) OK\n@errors {400: Bad Request, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/model-lab-api/facet-keys\n@desc List Model Lab run facet keys\n@required {filter[project_id]: int(int64): any # Filter by project ID.}\n@returns(200) {data: map{attributes: map{metrics: [str]?, parameters: [str], tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/model-lab-api/facet-values\n@desc List Model Lab run facet values\n@required {filter[project_id]: int(int64): any # Filter by project ID., facet_type: str # Facet type. Valid values: parameter, attribute, tag, metric., facet_name: str # Facet name.}\n@returns(200) {data: map{attributes: map{facet_name: str, facet_type: str, metric_stat_ranges: [map], numeric_range: map{max: num(double), min: num(double)}, values: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/model-lab-api/project-facet-keys\n@desc List Model Lab project facet keys\n@returns(200) {data: map{attributes: map{metrics: [str]?, parameters: [str], tags: [str]}, id: str, type: str}} # OK\n@errors {429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/model-lab-api/project-facet-values\n@desc List Model Lab project facet values\n@required {facet_type: str # Facet type. Valid values: tag., facet_name: str # Facet name.}\n@returns(200) {data: map{attributes: map{facet_name: str, facet_type: str, metric_stat_ranges: [map], numeric_range: map{max: num(double), min: num(double)}, values: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/model-lab-api/projects\n@desc List Model Lab projects\n@optional {filter: str # Text search filter for project name or description., filter[owner_id]: str(uuid) # Filter by owner UUID., filter[tags]: str # Filter by tags. Format: key:value,key2:value2., sort: str=-updated_at # Sort field. Valid values: name, created_at, updated_at. Prefix with '-' for descending order (e.g., -updated_at)., page[size]: int(int64)=25 # Number of items per page. Maximum is 100., page[number]: int(int64)=1 # Page number (1-indexed).}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str?, prev: str?, self: str}, meta: map{page: map{first_number: int(int64), last_number: int(int64), next_number: int(int64)?, number: int(int64), prev_number: int(int64)?, size: int(int64), total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/model-lab-api/projects/{project_id}\n@desc Get a Model Lab project\n@required {project_id: int(int64) # The ID of the Model Lab project.}\n@returns(200) {data: map{attributes: map{artifact_storage_location: str, created_at: str(date-time), deleted_at: str(date-time)?, description: str, external_url: str?, is_starred: bool, name: str, owner_id: str?, tags: [map], updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/model-lab-api/projects/{project_id}/artifacts\n@desc List Model Lab project artifacts\n@required {project_id: int(int64) # The ID of the Model Lab project.}\n@returns(200) {data: map{attributes: map{files: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint DELETE /api/v2/model-lab-api/projects/{project_id}/star\n@desc Remove star from a Model Lab project\n@required {project_id: int(int64) # The ID of the Model Lab project.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/model-lab-api/projects/{project_id}/star\n@desc Star a Model Lab project\n@required {project_id: int(int64) # The ID of the Model Lab project.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/model-lab-api/runs\n@desc List Model Lab runs\n@optional {filter[id]: str: any # Filter by run ID(s). Comma-separated list for multiple IDs., filter: str # Text search filter for run name or description., filter[owner_id]: str # Filter by owner UUID., filter[status]: str # Filter by run status. Valid values: pending, running, completed, failed, killed, unresponsive, paused., filter[project_id]: int(int64) # Filter by project ID., filter[tags]: str # Filter by tags. Format: key:value,key2:value2., filter[params]: str # Filter by params. Format: key:value,key2:>0.5,key3:true., filter[parent_run_id]: str # Filter by parent run ID. Use 'null' to return only root runs (runs with no parent)., pinned_first: bool # Sort pinned runs before non-pinned runs. Pinned runs are ordered by pin time descending., include_pinned: bool # Include all runs pinned by the current user, regardless of other filters., include_descendant_matches: bool # When true, also return runs whose descendants match the active filters. The descendant_match field in each result indicates whether the run was included via a descendant match., sort: str=-updated_at # Sort field. Valid values: name, created_at, updated_at, duration. Prefix with '-' for descending order (e.g., -updated_at)., page[size]: int(int64)=25 # Number of items per page. Maximum is 100., page[number]: int(int64)=1 # Page number (1-indexed).}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str?, prev: str?, self: str}, meta: map{page: map{first_number: int(int64), last_number: int(int64), next_number: int(int64)?, number: int(int64), prev_number: int(int64)?, size: int(int64), total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint DELETE /api/v2/model-lab-api/runs/{run_id}\n@desc Delete a Model Lab run\n@required {run_id: int(int64) # The ID of the Model Lab run.}\n@returns(204) No Content\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/model-lab-api/runs/{run_id}\n@desc Get a Model Lab run\n@required {run_id: int(int64) # The ID of the Model Lab run.}\n@returns(200) {data: map{attributes: map{completed_at: str(date-time)?, created_at: str(date-time), deleted_at: str(date-time)?, descendant_match: bool, description: str, duration: num(double)?, external_url: str?, has_children: bool, is_pinned: bool, metric_summaries: [map], mlflow_artifact_location: str, name: str, owner_id: str?, params: [map]?, project_id: int(int64), started_at: str(date-time), status: str, tags: [map], updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/model-lab-api/runs/{run_id}/artifacts\n@desc List Model Lab run artifacts\n@required {run_id: int(int64) # The ID of the Model Lab run.}\n@optional {path: str # Optional subdirectory path within the run's artifacts.}\n@returns(200) {data: map{attributes: map{files: [map], path_in_project: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint DELETE /api/v2/model-lab-api/runs/{run_id}/pin\n@desc Unpin a Model Lab run\n@required {run_id: int(int64) # The ID of the Model Lab run.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/model-lab-api/runs/{run_id}/pin\n@desc Pin a Model Lab run\n@required {run_id: int(int64) # The ID of the Model Lab run.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/monitor/notification_rule\n@desc Get all monitor notification rules\n@optional {page: int(int32) # The page to start paginating from. If `page` is not specified, the argument defaults to the first page., per_page: int(int32) # The number of rules to return per page. If `per_page` is not specified, the argument defaults to 100., sort: str # String for sort order, composed of field and sort order separated by a colon, for example `name:asc`. Supported sort directions: `asc`, `desc`. Supported fields: `name`, `created_at`., filters: str # JSON-encoded filter object. Supported keys: * `text`: Free-text query matched against rule name, tags, and recipients. * `tags`: Array of strings. Return rules that have any of these tags. * `recipients`: Array of strings. Return rules that have any of these recipients., include: str # Comma-separated list of resource paths for related resources to include in the response. Supported resource path is `created_by`.}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/monitor/notification_rule\n@desc Create a monitor notification rule\n@required {data: map{attributes!: map, type: str} # Object to create a monitor notification rule.}\n@returns(200) {data: map{attributes: map{conditional_recipients: map{conditions: [map], fallback_recipients: [str]}, created: str(date-time), filter: any, modified: str(date-time), name: str, recipients: [str]}, id: str, relationships: map{created_by: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"filter\":{\"tags\":[\"team:product\",\"host:abc\"]},\"name\":\"A notification rule name\",\"recipients\":[\"slack-test-channel\",\"jira-test\"]},\"type\":\"monitor-notification-rule\"}}\n\n@endpoint DELETE /api/v2/monitor/notification_rule/{rule_id}\n@desc Delete a monitor notification rule\n@required {rule_id: str # ID of the monitor notification rule to delete.}\n@returns(204) OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/monitor/notification_rule/{rule_id}\n@desc Get a monitor notification rule\n@required {rule_id: str # ID of the monitor notification rule to fetch.}\n@optional {include: str # Comma-separated list of resource paths for related resources to include in the response. Supported resource path is `created_by`.}\n@returns(200) {data: map{attributes: map{conditional_recipients: map{conditions: [map], fallback_recipients: [str]}, created: str(date-time), filter: any, modified: str(date-time), name: str, recipients: [str]}, id: str, relationships: map{created_by: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/monitor/notification_rule/{rule_id}\n@desc Update a monitor notification rule\n@required {rule_id: str # ID of the monitor notification rule to update., data: map{attributes!: map, id!: str, type: str} # Object to update a monitor notification rule.}\n@returns(200) {data: map{attributes: map{conditional_recipients: map{conditions: [map], fallback_recipients: [str]}, created: str(date-time), filter: any, modified: str(date-time), name: str, recipients: [str]}, id: str, relationships: map{created_by: map{data: map?}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"filter\":{\"tags\":[\"team:product\",\"host:abc\"]},\"name\":\"A notification rule name\",\"recipients\":[\"slack-test-channel\",\"jira-test\"]},\"id\":\"00000000-0000-1234-0000-000000000000\",\"type\":\"monitor-notification-rule\"}}\n\n@endpoint GET /api/v2/monitor/policy\n@desc Get all monitor configuration policies\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/monitor/policy\n@desc Create a monitor configuration policy\n@required {data: map{attributes!: map, type!: str} # A monitor configuration policy data.}\n@returns(200) {data: map{attributes: map{policy: any, policy_type: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"policy\":{\"tag_key\":\"datacenter\",\"tag_key_required\":true,\"valid_tag_values\":[\"prod\",\"staging\"]},\"policy_type\":\"tag\"},\"type\":\"monitor-config-policy\"}}\n\n@endpoint DELETE /api/v2/monitor/policy/{policy_id}\n@desc Delete a monitor configuration policy\n@required {policy_id: str # ID of the monitor configuration policy.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/monitor/policy/{policy_id}\n@desc Get a monitor configuration policy\n@required {policy_id: str # ID of the monitor configuration policy.}\n@returns(200) {data: map{attributes: map{policy: any, policy_type: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/monitor/policy/{policy_id}\n@desc Edit a monitor configuration policy\n@required {policy_id: str # ID of the monitor configuration policy., data: map{attributes!: map, id!: str, type!: str} # A monitor configuration policy data.}\n@returns(200) {data: map{attributes: map{policy: any, policy_type: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"policy\":{\"tag_key\":\"datacenter\",\"tag_key_required\":true,\"valid_tag_values\":[\"prod\",\"staging\"]},\"policy_type\":\"tag\"},\"id\":\"00000000-0000-1234-0000-000000000000\",\"type\":\"monitor-config-policy\"}}\n\n@endpoint GET /api/v2/monitor/template\n@desc Get all monitor user templates\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/monitor/template\n@desc Create a monitor user template\n@required {data: map{attributes!: map, type!: str} # Monitor user template data.}\n@returns(200) {data: map{attributes: map{created: str(date-time), description: str?, modified: str(date-time), monitor_definition: map, tags: [str], template_variables: [map], title: str, version: int(int64)?}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"This is a template for monitoring user activity.\",\"monitor_definition\":{\"message\":\"You may need to add web hosts if this is consistently high.\",\"name\":\"Bytes received on host0\",\"query\":\"avg(last_5m):sum:system.net.bytes_rcvd{host:host0} > 100\",\"type\":\"query alert\"},\"tags\":[\"product:Our Custom App\",\"integration:Azure\"],\"template_variables\":[{\"available_values\":[\"value1\",\"value2\"],\"defaults\":[\"defaultValue\"],\"name\":\"regionName\",\"tag_key\":\"datacenter\"}],\"title\":\"Postgres CPU Monitor\"},\"type\":\"monitor-user-template\"}}\n\n@endpoint POST /api/v2/monitor/template/validate\n@desc Validate a monitor user template\n@required {data: map{attributes!: map, type!: str} # Monitor user template data.}\n@returns(204) OK\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"This is a template for monitoring user activity.\",\"monitor_definition\":{\"message\":\"You may need to add web hosts if this is consistently high.\",\"name\":\"Bytes received on host0\",\"query\":\"avg(last_5m):sum:system.net.bytes_rcvd{host:host0} > 100\",\"type\":\"query alert\"},\"tags\":[\"product:Our Custom App\",\"integration:Azure\"],\"template_variables\":[{\"available_values\":[\"value1\",\"value2\"],\"defaults\":[\"defaultValue\"],\"name\":\"regionName\",\"tag_key\":\"datacenter\"}],\"title\":\"Postgres CPU Monitor\"},\"type\":\"monitor-user-template\"}}\n\n@endpoint DELETE /api/v2/monitor/template/{template_id}\n@desc Delete a monitor user template\n@required {template_id: str # ID of the monitor user template.}\n@returns(204) OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/monitor/template/{template_id}\n@desc Get a monitor user template\n@required {template_id: str # ID of the monitor user template.}\n@optional {with_all_versions: bool # Whether to include all versions of the template in the response in the versions field.}\n@returns(200) {data: map{attributes: map{created: str(date-time), description: str?, modified: str(date-time), monitor_definition: map, tags: [str], template_variables: [map], title: str, version: int(int64)?, versions: [map]}, id: str, type: str}} # OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/monitor/template/{template_id}\n@desc Update a monitor user template to a new version\n@required {template_id: str # ID of the monitor user template., data: map{attributes!: map, id!: str, type!: str} # Monitor user template data.}\n@returns(200) {data: map{attributes: map{created: str(date-time), description: str?, modified: str(date-time), monitor_definition: map, tags: [str], template_variables: [map], title: str, version: int(int64)?, versions: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"This is a template for monitoring user activity.\",\"monitor_definition\":{\"message\":\"You may need to add web hosts if this is consistently high.\",\"name\":\"Bytes received on host0\",\"query\":\"avg(last_5m):sum:system.net.bytes_rcvd{host:host0} > 100\",\"type\":\"query alert\"},\"tags\":[\"product:Our Custom App\",\"integration:Azure\"],\"template_variables\":[{\"available_values\":[\"value1\",\"value2\"],\"defaults\":[\"defaultValue\"],\"name\":\"regionName\",\"tag_key\":\"datacenter\"}],\"title\":\"Postgres CPU Monitor\"},\"id\":\"00000000-0000-1234-0000-000000000000\",\"type\":\"monitor-user-template\"}}\n\n@endpoint POST /api/v2/monitor/template/{template_id}/validate\n@desc Validate an existing monitor user template\n@required {template_id: str # ID of the monitor user template., data: map{attributes!: map, id!: str, type!: str} # Monitor user template data.}\n@returns(204) OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"This is a template for monitoring user activity.\",\"monitor_definition\":{\"message\":\"You may need to add web hosts if this is consistently high.\",\"name\":\"Bytes received on host0\",\"query\":\"avg(last_5m):sum:system.net.bytes_rcvd{host:host0} > 100\",\"type\":\"query alert\"},\"tags\":[\"product:Our Custom App\",\"integration:Azure\"],\"template_variables\":[{\"available_values\":[\"value1\",\"value2\"],\"defaults\":[\"defaultValue\"],\"name\":\"regionName\",\"tag_key\":\"datacenter\"}],\"title\":\"Postgres CPU Monitor\"},\"id\":\"00000000-0000-1234-0000-000000000000\",\"type\":\"monitor-user-template\"}}\n\n@endpoint GET /api/v2/monitor/{monitor_id}/downtime_matches\n@desc Get active downtimes for a monitor\n@required {monitor_id: int(int64) # The id of the monitor.}\n@optional {page[offset]: int(int64)=0: any # Specific offset to use as the beginning of the returned page., page[limit]: int(int64)=30 # Maximum number of downtimes in the response.}\n@returns(200) {data: [map], meta: map{page: map{total_filtered_count: int(int64)}}} # OK\n@errors {404: Monitor Not Found error, 429: Too many requests}\n\n@endpoint GET /api/v2/ndm/devices\n@desc Get the list of devices\n@optional {page[size]: int(int64)=50: any # Size for a given page. The maximum allowed value is 500. Defaults to 50., page[number]: int(int64)=0 # Specific page number to return. Defaults to 0., sort: str=name # The field to sort the devices by. Defaults to `name`., filter[tag]: str # Filter devices by tag.}\n@returns(200) {data: [map], meta: map{page: map{total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/ndm/devices/{device_id}\n@desc Get the device details\n@required {device_id: str # The id of the device to fetch.}\n@returns(200) {data: map{attributes: map{description: str, device_type: str, integration: str, ip_address: str, location: str, model: str, name: str, os_hostname: str, os_name: str, os_version: str, ping_status: str, product_name: str, serial_number: str, status: str, subnet: str, sys_object_id: str, tags: [str], vendor: str, version: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/ndm/interfaces\n@desc Get the list of interfaces of the device\n@required {device_id: str # The ID of the device to get interfaces from.}\n@optional {get_ip_addresses: bool # Whether to get the IP addresses of the interfaces.}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/ndm/tags/devices/{device_id}\n@desc Get the list of tags for a device\n@required {device_id: str # The id of the device to fetch tags for.}\n@returns(200) {data: map{attributes: map{tags: [str]}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/ndm/tags/devices/{device_id}\n@desc Update the tags for a device\n@required {device_id: str # The id of the device to update tags for.}\n@optional {data: map{attributes: map, id: str, type: str} # The list tags response data.}\n@returns(200) {data: map{attributes: map{tags: [str]}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"tags\":[\"tag:test\",\"tag:testbis\"]},\"id\":\"example:1.2.3.4\",\"type\":\"tags\"}}\n\n@endpoint GET /api/v2/ndm/tags/interfaces/{interface_id}\n@desc List tags for an interface\n@required {interface_id: str # The ID of the interface for which to retrieve tags.}\n@returns(200) {data: map{attributes: map{tags: [str]}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/ndm/tags/interfaces/{interface_id}\n@desc Update the tags for an interface\n@required {interface_id: str # The ID of the interface for which to update tags.}\n@optional {data: map{attributes: map, id: str, type: str} # Response data for listing interface tags.}\n@returns(200) {data: map{attributes: map{tags: [str]}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"tags\":[\"tag:test\",\"tag:testbis\"]},\"id\":\"example:1.2.3.4:1\",\"type\":\"tags\"}}\n\n@endpoint GET /api/v2/network-health-insights\n@desc List network health insights\n@optional {from: str # Unix timestamp (number of seconds since epoch) of the start of the query window. If not provided, the start of the query window will be 15 minutes before the `to` timestamp. If neither `from` nor `to` are provided, the query window will be `[now - 15m, now]`., to: str # Unix timestamp (number of seconds since epoch) of the end of the query window. If not provided, the end of the query window will be the current time. If neither `from` nor `to` are provided, the query window will be `[now - 15m, now]`.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/network/connections/aggregate\n@desc Get all aggregated connections\n@optional {from: int(int64) # Unix timestamp (number of seconds since epoch) of the start of the query window. If not provided, the start of the query window is 15 minutes before the `to` timestamp. If neither `from` nor `to` are provided, the query window is `[now - 15m, now]`., to: int(int64) # Unix timestamp (number of seconds since epoch) of the end of the query window. If not provided, the end of the query window is the current time. If neither `from` nor `to` are provided, the query window is `[now - 15m, now]`., group_by: str # Comma-separated list of fields to group connections by. The maximum number of group_by(s) is 10., tags: str # Comma-separated list of tags to filter connections by., query: str # Free-form search query using AND/OR/NOT operators, wildcards, and parentheses. When provided, takes precedence over the `tags` parameter., limit: int(int32)=100 # The number of connections to be returned. The maximum value is 7500. The default is 100.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/network/dns/aggregate\n@desc Get all aggregated DNS traffic\n@optional {from: int(int64) # Unix timestamp (number of seconds since epoch) of the start of the query window. If not provided, the start of the query window is 15 minutes before the `to` timestamp. If neither `from` nor `to` are provided, the query window is `[now - 15m, now]`., to: int(int64) # Unix timestamp (number of seconds since epoch) of the end of the query window. If not provided, the end of the query window is the current time. If neither `from` nor `to` are provided, the query window is `[now - 15m, now]`., group_by: str # Comma-separated list of fields to group DNS traffic by. The server side defaults to `network.dns_query` if unspecified. `server_ungrouped` may be used if groups are not desired. The maximum number of group_by(s) is 10., tags: str # Comma-separated list of tags to filter DNS traffic by., query: str # Free-form search query using AND/OR/NOT operators, wildcards, and parentheses. When provided, takes precedence over the `tags` parameter., limit: int(int32)=100 # The number of aggregated DNS entries to be returned. The maximum value is 7500. The default is 100.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/oauth2/.well-known/sites\n@desc Get OAuth2 well-known sites\n@returns(200) {data: map{attributes: map{sites: [str]}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint DELETE /api/v2/oauth2/clients/{client_uuid}/scopes_restriction\n@desc Delete an OAuth2 client scopes restriction\n@required {client_uuid: str(uuid) # UUID of the OAuth2 client.}\n@returns(204) No Content\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/oauth2/clients/{client_uuid}/scopes_restriction\n@desc Get an OAuth2 client scopes restriction\n@required {client_uuid: str(uuid) # UUID of the OAuth2 client.}\n@returns(200) {data: map{attributes: map{required_permission_scopes: [str]?, scopes_restriction: map?{oidc_scopes: [str], permission_scopes: [str]}}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/oauth2/clients/{client_uuid}/scopes_restriction\n@desc Upsert an OAuth2 client scopes restriction\n@required {client_uuid: str(uuid) # UUID of the OAuth2 client., data: map{attributes: map, type!: str} # Data object of an upsert OAuth2 scopes restriction request.}\n@returns(200) {data: map{attributes: map{required_permission_scopes: [str]?, scopes_restriction: map?{oidc_scopes: [str], permission_scopes: [str]}}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"oidc_scopes\":[\"openid\",\"email\"],\"permission_scopes\":[\"dashboards_read\",\"metrics_read\"]},\"type\":\"upsert_scopes_restriction\"}}\n\n@endpoint POST /api/v2/oauth2/register\n@desc Register an OAuth2 client\n@required {client_name: str # Human-readable name of the client. Control characters are rejected., redirect_uris: [str] # Array of redirection URI strings used by the client in redirect-based flows.}\n@optional {client_uri: str # URL of the home page of the client., grant_types: [str] # OAuth 2.0 grant types the client may use. Defaults to `authorization_code` and `refresh_token` when omitted., jwks_uri: str # URL referencing the client's JSON Web Key Set., logo_uri: str # URL referencing a logo for the client., policy_uri: str # URL pointing to the client's privacy policy., response_types: [str] # OAuth 2.0 response types the client may use. Only `code` is supported., scope: str # Space-separated list of scope values the client may request., token_endpoint_auth_method: str # Requested authentication method for the token endpoint. Only `none` is supported., tos_uri: str # URL pointing to the client's terms of service.}\n@returns(201) {client_id: str(uuid), client_name: str, grant_types: [str], redirect_uris: [str], response_types: [str], token_endpoint_auth_method: str} # Created\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"client_name\":\"Example MCP Client\",\"grant_types\":[\"authorization_code\",\"refresh_token\"],\"redirect_uris\":[\"https://example.com/oauth/callback\"],\"response_types\":[\"code\"],\"token_endpoint_auth_method\":\"none\"}\n\n@endpoint GET /api/v2/obs-pipelines/pipelines\n@desc List pipelines\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return.}\n@returns(200) {data: [map], meta: map{totalCount: int(int64)}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/obs-pipelines/pipelines\n@desc Create a new pipeline\n@required {data: map{attributes!: map, type!: str} # Contains the the pipeline configuration.}\n@returns(201) {data: map{attributes: map{config: map{destinations: [any], pipeline_type: str, processor_groups: [map], processors: [map], sources: [any], use_legacy_search_syntax: bool}, name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"config\":{\"destinations\":[{\"id\":\"datadog-logs-destination\",\"inputs\":[\"my-processor-group\"],\"type\":\"datadog_logs\"}],\"pipeline_type\":\"logs\",\"processor_groups\":[{\"enabled\":true,\"id\":\"my-processor-group\",\"include\":\"service:my-service\",\"inputs\":[\"datadog-agent-source\"],\"processors\":[{\"enabled\":true,\"id\":\"filter-processor\",\"include\":\"status:error\",\"type\":\"filter\"},{\"enabled\":true,\"field\":\"message\",\"id\":\"json-processor\",\"include\":\"*\",\"type\":\"parse_json\"}]}],\"processors\":[],\"sources\":[{\"id\":\"datadog-agent-source\",\"type\":\"datadog_agent\"}]},\"name\":\"Main Observability Pipeline\"},\"type\":\"pipelines\"}}\n\n@endpoint POST /api/v2/obs-pipelines/pipelines/validate\n@desc Validate an observability pipeline\n@required {data: map{attributes!: map, type!: str} # Contains the the pipeline configuration.}\n@returns(200) {errors: [map]} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"config\":{\"destinations\":[{\"id\":\"datadog-logs-destination\",\"inputs\":[\"my-processor-group\"],\"type\":\"datadog_logs\"}],\"pipeline_type\":\"logs\",\"processor_groups\":[{\"enabled\":true,\"id\":\"my-processor-group\",\"include\":\"service:my-service\",\"inputs\":[\"datadog-agent-source\"],\"processors\":[{\"enabled\":true,\"id\":\"filter-processor\",\"include\":\"status:error\",\"type\":\"filter\"},{\"enabled\":true,\"field\":\"message\",\"id\":\"json-processor\",\"include\":\"*\",\"type\":\"parse_json\"}]}],\"processors\":[],\"sources\":[{\"id\":\"datadog-agent-source\",\"type\":\"datadog_agent\"}]},\"name\":\"Main Observability Pipeline\"},\"type\":\"pipelines\"}}\n\n@endpoint DELETE /api/v2/obs-pipelines/pipelines/{pipeline_id}\n@desc Delete a pipeline\n@required {pipeline_id: str # The ID of the pipeline to delete.}\n@returns(204) OK\n@errors {403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n\n@endpoint GET /api/v2/obs-pipelines/pipelines/{pipeline_id}\n@desc Get a specific pipeline\n@required {pipeline_id: str # The ID of the pipeline to retrieve.}\n@returns(200) {data: map{attributes: map{config: map{destinations: [any], pipeline_type: str, processor_groups: [map], processors: [map], sources: [any], use_legacy_search_syntax: bool}, name: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint PUT /api/v2/obs-pipelines/pipelines/{pipeline_id}\n@desc Update a pipeline\n@required {pipeline_id: str # The ID of the pipeline to update., data: map{attributes!: map, id!: str, type!: str} # Contains the pipeline’s ID, type, and configuration attributes.}\n@returns(200) {data: map{attributes: map{config: map{destinations: [any], pipeline_type: str, processor_groups: [map], processors: [map], sources: [any], use_legacy_search_syntax: bool}, name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"config\":{\"destinations\":[{\"id\":\"datadog-logs-destination\",\"inputs\":[\"my-processor-group\"],\"type\":\"datadog_logs\"}],\"pipeline_type\":\"logs\",\"processor_groups\":[{\"enabled\":true,\"id\":\"my-processor-group\",\"include\":\"service:my-service\",\"inputs\":[\"datadog-agent-source\"],\"processors\":[{\"enabled\":true,\"id\":\"filter-processor\",\"include\":\"status:error\",\"type\":\"filter\"},{\"enabled\":true,\"field\":\"message\",\"id\":\"json-processor\",\"include\":\"*\",\"type\":\"parse_json\"}]}],\"processors\":[],\"sources\":[{\"id\":\"datadog-agent-source\",\"type\":\"datadog_agent\"}]},\"name\":\"Main Observability Pipeline\"},\"id\":\"3fa85f64-5717-4562-b3fc-2c963f66afa6\",\"type\":\"pipelines\"}}\n\n@endpoint POST /api/v2/on-call/escalation-policies\n@desc Create On-Call escalation policy\n@required {data: map{attributes!: map, relationships: map, type!: str} # Represents the data for creating an escalation policy, including its attributes, relationships, and resource type.}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `teams`, `steps`, `steps.targets`.}\n@returns(201) {data: map{attributes: map{name: str, resolve_page_on_policy_end: bool, retries: int(int64)}, id: str, relationships: map{steps: map{data: [map]}, teams: map{data: [map]}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Escalation Policy 1\",\"resolve_page_on_policy_end\":true,\"retries\":2,\"steps\":[{\"assignment\":\"default\",\"escalate_after_seconds\":3600,\"targets\":[{\"id\":\"00000000-aba1-0000-0000-000000000000\",\"type\":\"users\"},{\"config\":{\"schedule\":{\"position\":\"previous\"}},\"id\":\"00000000-aba2-0000-0000-000000000000\",\"type\":\"schedules\"},{\"id\":\"00000000-aba3-0000-0000-000000000000\",\"type\":\"teams\"}]},{\"assignment\":\"round-robin\",\"escalate_after_seconds\":3600,\"targets\":[{\"id\":\"00000000-aba1-0000-0000-000000000000\",\"type\":\"users\"},{\"id\":\"00000000-abb1-0000-0000-000000000000\",\"type\":\"users\"}]}]},\"relationships\":{\"teams\":{\"data\":[{\"id\":\"00000000-da3a-0000-0000-000000000000\",\"type\":\"teams\"}]}},\"type\":\"policies\"}}\n\n@endpoint DELETE /api/v2/on-call/escalation-policies/{policy_id}\n@desc Delete On-Call escalation policy\n@required {policy_id: str # The ID of the escalation policy}\n@returns(204) No Content\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/on-call/escalation-policies/{policy_id}\n@desc Get On-Call escalation policy\n@required {policy_id: str # The ID of the escalation policy}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `teams`, `steps`, `steps.targets`.}\n@returns(200) {data: map{attributes: map{name: str, resolve_page_on_policy_end: bool, retries: int(int64)}, id: str, relationships: map{steps: map{data: [map]}, teams: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/on-call/escalation-policies/{policy_id}\n@desc Update On-Call escalation policy\n@required {policy_id: str # The ID of the escalation policy, data: map{attributes!: map, id!: str, relationships: map, type!: str} # Represents the data for updating an existing escalation policy, including its ID, attributes, relationships, and resource type.}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `teams`, `steps`, `steps.targets`.}\n@returns(200) {data: map{attributes: map{name: str, resolve_page_on_policy_end: bool, retries: int(int64)}, id: str, relationships: map{steps: map{data: [map]}, teams: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Escalation Policy 1\",\"resolve_page_on_policy_end\":false,\"retries\":2,\"steps\":[{\"assignment\":\"default\",\"escalate_after_seconds\":3600,\"id\":\"00000000-aba1-0000-0000-000000000000\",\"targets\":[{\"id\":\"00000000-aba1-0000-0000-000000000000\",\"type\":\"users\"},{\"id\":\"00000000-aba2-0000-0000-000000000000\",\"type\":\"schedules\"}]}]},\"id\":\"a3000000-0000-0000-0000-000000000000\",\"relationships\":{\"teams\":{\"data\":[{\"id\":\"00000000-da3a-0000-0000-000000000000\",\"type\":\"teams\"}]}},\"type\":\"policies\"}}\n\n@endpoint POST /api/v2/on-call/pages\n@desc Create On-Call Page\n@optional {data: map{attributes: map, type!: str} # The main request body, including attributes and resource type.}\n@returns(200) {data: map{id: str, type: str}} # OK.\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Page details.\",\"tags\":[\"service:test\"],\"target\":{\"identifier\":\"my-team\",\"type\":\"team_handle\"},\"title\":\"Page title\",\"urgency\":\"low\"},\"type\":\"pages\"}}\n\n@endpoint POST /api/v2/on-call/pages/{page_id}/acknowledge\n@desc Acknowledge On-Call Page\n@required {page_id: str(uuid) # The page ID.}\n@returns(202) Accepted.\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/on-call/pages/{page_id}/escalate\n@desc Escalate On-Call Page\n@required {page_id: str(uuid) # The page ID.}\n@returns(202) Accepted.\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/on-call/pages/{page_id}/resolve\n@desc Resolve On-Call Page\n@required {page_id: str(uuid) # The page ID.}\n@returns(202) Accepted.\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/on-call/schedules\n@desc Create On-Call schedule\n@required {data: map{attributes!: map, relationships: map, type!: str} # The core data wrapper for creating a schedule, encompassing attributes, relationships, and the resource type.}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `teams`, `layers`, `layers.members`, `layers.members.user`.}\n@returns(201) {data: map{attributes: map{name: str, tags: [str], time_zone: str}, id: str, relationships: map{layers: map{data: [map]}, teams: map{data: [map]}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"layers\":[{\"effective_date\":\"2025-02-03T05:00:00Z\",\"end_date\":\"2025-12-31T00:00:00Z\",\"interval\":{\"days\":1},\"members\":[{\"user\":{\"id\":\"00000000-aba1-0000-0000-000000000000\"}}],\"name\":\"Layer 1\",\"restrictions\":[{\"end_day\":\"friday\",\"end_time\":\"17:00:00\",\"start_day\":\"monday\",\"start_time\":\"09:00:00\"}],\"rotation_start\":\"2025-02-01T00:00:00Z\"}],\"name\":\"On-Call Schedule\",\"time_zone\":\"America/New_York\"},\"relationships\":{\"teams\":{\"data\":[{\"id\":\"00000000-da3a-0000-0000-000000000000\",\"type\":\"teams\"}]}},\"type\":\"schedules\"}}\n\n@endpoint DELETE /api/v2/on-call/schedules/{schedule_id}\n@desc Delete On-Call schedule\n@required {schedule_id: str # The ID of the schedule}\n@returns(204) No Content\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/on-call/schedules/{schedule_id}\n@desc Get On-Call schedule\n@required {schedule_id: str # The ID of the schedule}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `teams`, `layers`, `layers.members`, `layers.members.user`.}\n@returns(200) {data: map{attributes: map{name: str, tags: [str], time_zone: str}, id: str, relationships: map{layers: map{data: [map]}, teams: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/on-call/schedules/{schedule_id}\n@desc Update On-Call schedule\n@required {schedule_id: str # The ID of the schedule, data: map{attributes!: map, id!: str, relationships: map, type!: str} # Contains all data needed to update an existing schedule, including its attributes (such as name and time zone) and any relationships to teams.}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `teams`, `layers`, `layers.members`, `layers.members.user`.}\n@returns(200) {data: map{attributes: map{name: str, tags: [str], time_zone: str}, id: str, relationships: map{layers: map{data: [map]}, teams: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"layers\":[{\"effective_date\":\"2025-02-03T05:00:00Z\",\"end_date\":\"2025-12-31T00:00:00Z\",\"interval\":{\"seconds\":3600},\"members\":[{\"user\":{\"id\":\"00000000-aba1-0000-0000-000000000000\"}}],\"name\":\"Layer 1\",\"restrictions\":[{\"end_day\":\"friday\",\"end_time\":\"17:00:00\",\"start_day\":\"monday\",\"start_time\":\"09:00:00\"}],\"rotation_start\":\"2025-02-01T00:00:00Z\"}],\"name\":\"On-Call Schedule Updated\",\"time_zone\":\"America/New_York\"},\"id\":\"3653d3c6-0c75-11ea-ad28-fb5701eabc7d\",\"relationships\":{\"teams\":{\"data\":[{\"id\":\"00000000-da3a-0000-0000-000000000000\",\"type\":\"teams\"}]}},\"type\":\"schedules\"}}\n\n@endpoint GET /api/v2/on-call/schedules/{schedule_id}/on-call\n@desc Get scheduled on-call user\n@required {schedule_id: str # The ID of the schedule.}\n@optional {include: str # Specifies related resources to include in the response as a comma-separated list. Allowed value: `user`., filter[at_ts]: str # Retrieves the on-call user at the given timestamp in RFC3339 format (for example, `2025-05-07T02:53:01Z` or `2025-05-07T02:53:01+00:00`). When using timezone offsets with `+` or `-`, ensure proper URL encoding (`+` should be encoded as `%2B`). Defaults to the current time if omitted.}\n@returns(200) {data: map{attributes: map{end: str(date-time), start: str(date-time)}, id: str, relationships: map{user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/on-call/schedules/{schedule_id}/responders\n@desc Get on-call responders for a schedule\n@required {schedule_id: str # The ID of the schedule.}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `schedule`, `responders`, `responders.shifts`, `responders.shifts.user`., filter[position]: str # Comma-separated list of positions to retrieve. Allowed values: `previous`, `current`, `next`. Defaults to `current` if omitted., filter[at_ts]: str # Retrieves the on-call responders at the given timestamp in RFC3339 format (for example, `2025-05-07T02:53:01Z` or `2025-05-07T02:53:01+00:00`). When using timezone offsets with `+` or `-`, ensure proper URL encoding (`+` should be encoded as `%2B`). Defaults to the current time if omitted.}\n@returns(200) {data: map{attributes: map{scheduled_at: str(date-time)}, id: str, relationships: map{responders: map{data: [map]}, schedule: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/on-call/teams/{team_id}/on-call\n@desc Get team on-call users\n@required {team_id: str # The team ID}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `responders`, `escalations`, `escalations.responders`.}\n@returns(200) {data: map{id: str, relationships: map{escalations: map{data: [map]}, responders: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/on-call/teams/{team_id}/routing-rules\n@desc Get On-Call team routing rules\n@required {team_id: str # The team ID}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `rules`, `rules.policy`.}\n@returns(200) {data: map{id: str, relationships: map{rules: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n\n@endpoint PUT /api/v2/on-call/teams/{team_id}/routing-rules\n@desc Set On-Call team routing rules\n@required {team_id: str # The team ID}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `rules`, `rules.policy`., data: map{attributes: map, id: str, type!: str} # Holds the data necessary to create or update team routing rules, including attributes, ID, and resource type.}\n@returns(200) {data: map{id: str, relationships: map{rules: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"rules\":[{\"actions\":null,\"policy_id\":\"\",\"query\":\"tags.service:test\",\"time_restriction\":{\"restrictions\":[{\"end_day\":\"monday\",\"end_time\":\"17:00:00\",\"start_day\":\"monday\",\"start_time\":\"09:00:00\"},{\"end_day\":\"tuesday\",\"end_time\":\"17:00:00\",\"start_day\":\"tuesday\",\"start_time\":\"09:00:00\"}],\"time_zone\":\"\"},\"urgency\":\"high\"},{\"actions\":[{\"channel\":\"channel\",\"type\":\"send_slack_message\",\"workspace\":\"workspace\"}],\"policy_id\":\"fad4eee1-13f5-40d8-886b-4e56d8d5d1c6\",\"query\":\"\",\"time_restriction\":null,\"urgency\":\"low\"}]},\"id\":\"27590dae-47be-4a7d-9abf-8f4e45124020\",\"type\":\"team_routing_rules\"}}\n\n@endpoint GET /api/v2/on-call/users/{user_id}/notification-channels\n@desc List On-Call notification channels for a user\n@required {user_id: str # The user ID}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/on-call/users/{user_id}/notification-channels\n@desc Create an On-Call notification channel for a user\n@required {user_id: str # The user ID, data: map{attributes: map, type!: str} # Data for creating an on-call notification channel}\n@returns(201) {data: map{attributes: map{active: bool, config: any}, id: str, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"config\":{\"address\":\"foo@bar.com\",\"formats\":[\"html\"],\"type\":\"email\"}},\"type\":\"notification_channels\"}}\n\n@endpoint DELETE /api/v2/on-call/users/{user_id}/notification-channels/{channel_id}\n@desc Delete an On-Call notification channel for a user\n@required {user_id: str # The user ID, channel_id: str # The channel ID}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/on-call/users/{user_id}/notification-channels/{channel_id}\n@desc Get an On-Call notification channel for a user\n@required {user_id: str # The user ID, channel_id: str # The channel ID}\n@returns(200) {data: map{attributes: map{active: bool, config: any}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/on-call/users/{user_id}/notification-rules\n@desc List On-Call notification rules for a user\n@required {user_id: str # The user ID}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `channel`.}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/on-call/users/{user_id}/notification-rules\n@desc Create an On-Call notification rule for a user\n@required {user_id: str # The user ID, data: map{attributes: map, relationships: map, type!: str} # Data for creating an on-call notification rule}\n@returns(201) {data: map{attributes: map{category: str, channel_settings: any, delay_minutes: int(int64)}, id: str, relationships: map{channel: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"category\":\"high_urgency\",\"channel_settings\":{\"method\":\"sms\",\"type\":\"phone\"},\"delay_minutes\":1},\"relationships\":{\"channel\":{\"data\":{\"id\":\"1562fab3-a8c2-49e2-8f3a-28dcda2405e2\",\"type\":\"notification_channels\"}}},\"type\":\"notification_rules\"}}\n\n@endpoint DELETE /api/v2/on-call/users/{user_id}/notification-rules/{rule_id}\n@desc Delete an On-Call notification rule for a user\n@required {user_id: str # The user ID, rule_id: str # The rule ID}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/on-call/users/{user_id}/notification-rules/{rule_id}\n@desc Get an On-Call notification rule for a user\n@required {user_id: str # The user ID, rule_id: str # The rule ID}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `channel`.}\n@returns(200) {data: map{attributes: map{category: str, channel_settings: any, delay_minutes: int(int64)}, id: str, relationships: map{channel: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/on-call/users/{user_id}/notification-rules/{rule_id}\n@desc Update an On-Call notification rule for a user\n@required {user_id: str # The user ID, rule_id: str # The rule ID, data: map{attributes: map, id: str, relationships: map, type!: str} # Data for updating an on-call notification rule}\n@optional {include: str # Comma-separated list of included relationships to be returned. Allowed values: `channel`.}\n@returns(200) {data: map{attributes: map{category: str, channel_settings: any, delay_minutes: int(int64)}, id: str, relationships: map{channel: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"category\":\"high_urgency\",\"channel_settings\":{\"method\":\"sms\",\"type\":\"phone\"},\"delay_minutes\":1},\"id\":\"2462ace1-49e2-aab1-xc4f-29cc4ae1105n7\",\"relationships\":{\"channel\":{\"data\":{\"id\":\"1562fab3-a8c2-49e2-8f3a-28dcda2405e2\",\"type\":\"notification_channels\"}}},\"type\":\"notification_rules\"}}\n\n@endpoint GET /api/v2/org\n@desc List your managed organizations\n@optional {filter[name]: str: any # Filter managed organizations by name.}\n@returns(200) {data: map{id: str(uuid), relationships: map{current_org: map{data: map}, managed_orgs: map{data: [map]}}, type: str}, included: [map]} # OK\n@errors {401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/org/disable\n@desc Disable the authenticated customer organization\n@required {data: map{attributes: map, id: str, type!: str} # Data object for a customer org disable request.}\n@returns(200) {data: map{attributes: map{status: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"org_uuid\":\"abcdef01-2345-6789-abcd-ef0123456789\"},\"id\":\"1\",\"type\":\"customer_org_disable\"}}\n\n@endpoint PATCH /api/v2/org/saml_configurations\n@desc Update organization SAML preferences\n@required {data: map{attributes!: map, id: str, type!: str} # Data for updating an organization's SAML preferences.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"default_role_uuids\":[\"8dd1cf3c-0c75-11ea-ad28-fb5701eabc7d\"],\"jit_domains\":[\"example.com\"]},\"type\":\"saml_preferences\"}}\n\n@endpoint GET /api/v2/org_authorized_clients\n@desc List org authorized clients\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str=oauth2_client.name # Field to sort results by. Options include `oauth2_client.name`., filter: str # Filter results by client name, app title, or app description., filter[oauth2_client][name]: str # Filter results by the OAuth2 client name., filter[disabled]: str # Filter results by the org-level disabled status., include: str # Comma-separated list of related resources to include. Options: `oauth2_client`, `oauth2_client.app`, `user_authorized_clients.user`.}\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {403: Authentication error, 429: Too many requests}\n\n@endpoint DELETE /api/v2/org_authorized_clients/{org_authorized_client_id}\n@desc Delete an org authorized client\n@required {org_authorized_client_id: str # The ID of the org authorized client.}\n@returns(204) No Content\n@errors {403: Authentication error, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/org_authorized_clients/{org_authorized_client_id}\n@desc Get an org authorized client\n@required {org_authorized_client_id: str # The ID of the org authorized client.}\n@optional {include: str # Comma-separated list of related resources to include. Options: `oauth2_client`, `oauth2_client.app`, `oauth2_client.scopes`, `user_authorized_clients.user`., filter[user_authorized_clients][disabled]: str # Filter included user authorized clients by disabled status., filter[user_authorized_clients][user][disabled]: str # Filter included user authorized clients by user disabled status.}\n@returns(200) {data: map{attributes: map{disabled: bool, last_exercised: str(date-time)?, user_count: int(int64)}, id: str, relationships: map{oauth2_client: map{data: map}, user_authorized_clients: map{data: [map], links: map}}, type: str}} # OK\n@errors {403: Authentication error, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/org_authorized_clients/{org_authorized_client_id}\n@desc Update an org authorized client\n@required {org_authorized_client_id: str # The ID of the org authorized client., data: map{attributes: map, id!: str, type!: str} # Data object for updating an org authorized client.}\n@returns(200) {data: map{attributes: map{disabled: bool, last_exercised: str(date-time)?, user_count: int(int64)}, id: str, relationships: map{oauth2_client: map{data: map}, user_authorized_clients: map{data: [map], links: map}}, type: str}} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not Found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"disabled\":true},\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"org_authorized_clients\"}}\n\n@endpoint DELETE /api/v2/org_authorized_clients/{org_authorized_client_id}/user/{user_id}\n@desc Delete a user's authorizations for a client\n@required {org_authorized_client_id: str # The ID of the org authorized client., user_id: str # The ID of the user.}\n@returns(204) No Content\n@errors {403: Authentication error, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/org_authorized_clients/{org_authorized_client_id}/user_authorized_clients\n@desc List user authorizations for a client\n@required {org_authorized_client_id: str # The ID of the org authorized client.}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # Field to sort results by. Options: `user.name`, `user.email`, `oauth2_client.name`., filter[disabled]: str # Filter results by the user authorization disabled status., filter[user][name]: str # Filter results by user name., filter[user][email]: str # Filter results by user email., filter[user][disabled]: str # Filter results by whether the user is disabled.}\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {403: Authentication error, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/org_authorized_clients/{org_authorized_client_id}/user_authorized_clients/{user_authorized_client_id}\n@desc Delete a user authorization for a client\n@required {org_authorized_client_id: str # The ID of the org authorized client., user_authorized_client_id: str # The ID of the user authorized client.}\n@returns(204) No Content\n@errors {403: Authentication error, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/org_configs\n@desc List Org Configs\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/org_configs/{org_config_name}\n@desc Get a specific Org Config value\n@required {org_config_name: str # The name of an Org Config.}\n@returns(200) {data: map{attributes: map{description: str, modified_at: str(date-time)?, name: str, value: any, value_type: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/org_configs/{org_config_name}\n@desc Update a specific Org Config\n@required {org_config_name: str # The name of an Org Config., data: map{attributes!: map, type!: str} # An Org Config write operation.}\n@returns(200) {data: map{attributes: map{description: str, modified_at: str(date-time)?, name: str, value: any, value_type: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"value\":\"UTC\"},\"type\":\"org_configs\"}}\n\n@endpoint GET /api/v2/org_connections\n@desc List Org Connections\n@optional {sink_org_id: str # The Org ID of the sink org., source_org_id: str # The Org ID of the source org., limit: int(int64) # The limit of number of entries you want to return. Default is 1000., offset: int(int64) # The pagination offset which you want to query from. Default is 0.}\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/org_connections\n@desc Create Org Connection\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Org connection creation data.}\n@returns(200) {data: map{attributes: map{connection_types: [str], created_at: str(date-time)}, id: str(uuid), relationships: map{created_by: map{data: map}, sink_org: map{data: map}, source_org: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"connection_types\":[\"logs\"]},\"relationships\":{\"sink_org\":{\"data\":{\"id\":\"f9ec96b0-8c8a-4b0a-9b0a-1b2c3d4e5f6a\",\"name\":\"Example Org\",\"type\":\"orgs\"}}},\"type\":\"org_connection\"}}\n\n@endpoint DELETE /api/v2/org_connections/{connection_id}\n@desc Delete Org Connection\n@required {connection_id: str(uuid) # The unique identifier of the org connection.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/org_connections/{connection_id}\n@desc Update Org Connection\n@required {connection_id: str(uuid) # The unique identifier of the org connection., data: map{attributes!: map, id!: str(uuid), type!: str} # Org connection update data.}\n@returns(200) {data: map{attributes: map{connection_types: [str], created_at: str(date-time)}, id: str(uuid), relationships: map{created_by: map{data: map}, sink_org: map{data: map}, source_org: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"connection_types\":[\"logs\",\"metrics\"]},\"id\":\"f9ec96b0-8c8a-4b0a-9b0a-1b2c3d4e5f6a\",\"type\":\"org_connection\"}}\n\n@endpoint GET /api/v2/org_group_memberships\n@desc List org group memberships\n@optional {filter[org_group_id]: str(uuid): any # Filter memberships by org group ID. Required when `filter[org_uuid]` is not provided., filter[org_uuid]: str(uuid) # Filter memberships by org UUID. Returns a single-item list., page[number]: int(int64)=0 # The page number to return., page[size]: int(int64)=50 # The number of items per page. Maximum is 1000., sort: str # Field to sort memberships by. Supported values: `name`, `uuid`, `-name`, `-uuid`. Defaults to `uuid`.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str?, prev: str?, self: str}, meta: map{page: map{first_number: int(int64), last_number: int(int64)?, next_number: int(int64)?, number: int(int64), prev_number: int(int64)?, size: int(int64), total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint PATCH /api/v2/org_group_memberships/bulk\n@desc Bulk update org group memberships\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Data for bulk updating org group memberships.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str?, prev: str?, self: str}, meta: map{page: map{first_number: int(int64), last_number: int(int64)?, next_number: int(int64)?, number: int(int64), prev_number: int(int64)?, size: int(int64), total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"orgs\":[{\"org_site\":\"us1\",\"org_uuid\":\"c3d4e5f6-a7b8-9012-cdef-012345678901\"}]},\"relationships\":{\"source_org_group\":{\"data\":{\"id\":\"a1b2c3d4-e5f6-7890-abcd-ef0123456789\",\"type\":\"org_groups\"}},\"target_org_group\":{\"data\":{\"id\":\"d4e5f6a7-b890-1234-cdef-567890abcdef\",\"type\":\"org_groups\"}}},\"type\":\"org_group_membership_bulk_updates\"}}\n\n@endpoint GET /api/v2/org_group_memberships/{org_group_membership_id}\n@desc Get an org group membership\n@required {org_group_membership_id: str(uuid) # The ID of the org group membership.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), org_name: str, org_site: str, org_uuid: str(uuid)}, id: str(uuid), relationships: map{org_group: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/org_group_memberships/{org_group_membership_id}\n@desc Update an org group membership\n@required {org_group_membership_id: str(uuid) # The ID of the org group membership., data: map{id!: str(uuid), relationships!: map, type!: str} # Data for updating an org group membership.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), org_name: str, org_site: str, org_uuid: str(uuid)}, id: str(uuid), relationships: map{org_group: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"f1e2d3c4-b5a6-7890-1234-567890abcdef\",\"relationships\":{\"org_group\":{\"data\":{\"id\":\"a1b2c3d4-e5f6-7890-abcd-ef0123456789\",\"type\":\"org_groups\"}}},\"type\":\"org_group_memberships\"}}\n\n@endpoint GET /api/v2/org_group_policies\n@desc List org group policies\n@required {filter[org_group_id]: str(uuid): any # Filter policies by org group ID.}\n@optional {filter[policy_name]: str: any # Filter policies by policy name., page[number]: int(int64)=0 # The page number to return., page[size]: int(int64)=50 # The number of items per page. Maximum is 1000., sort: str # Field to sort policies by. Supported values: `id`, `name`, `-id`, `-name`. Defaults to `id`.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str?, prev: str?, self: str}, meta: map{page: map{first_number: int(int64), last_number: int(int64)?, next_number: int(int64)?, number: int(int64), prev_number: int(int64)?, size: int(int64), total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/org_group_policies\n@desc Create an org group policy\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Data for creating an org group policy.}\n@returns(201) {data: map{attributes: map{content: map, enforcement_tier: str, modified_at: str(date-time), policy_name: str, policy_type: str}, id: str(uuid), relationships: map{org_group: map{data: map}}, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"content\":{\"value\":\"UTC\"},\"enforcement_tier\":\"OVERRIDE_ALLOWED\",\"policy_name\":\"monitor_timezone\",\"policy_type\":\"org_config\"},\"relationships\":{\"org_group\":{\"data\":{\"id\":\"a1b2c3d4-e5f6-7890-abcd-ef0123456789\",\"type\":\"org_groups\"}}},\"type\":\"org_group_policies\"}}\n\n@endpoint DELETE /api/v2/org_group_policies/{org_group_policy_id}\n@desc Delete an org group policy\n@required {org_group_policy_id: str(uuid) # The ID of the org group policy.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/org_group_policies/{org_group_policy_id}\n@desc Get an org group policy\n@required {org_group_policy_id: str(uuid) # The ID of the org group policy.}\n@returns(200) {data: map{attributes: map{content: map, enforcement_tier: str, modified_at: str(date-time), policy_name: str, policy_type: str}, id: str(uuid), relationships: map{org_group: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/org_group_policies/{org_group_policy_id}\n@desc Update an org group policy\n@required {org_group_policy_id: str(uuid) # The ID of the org group policy., data: map{attributes!: map, id!: str(uuid), type!: str} # Data for updating an org group policy.}\n@returns(200) {data: map{attributes: map{content: map, enforcement_tier: str, modified_at: str(date-time), policy_name: str, policy_type: str}, id: str(uuid), relationships: map{org_group: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"content\":{\"value\":\"US/Eastern\"},\"enforcement_tier\":\"GROUP_MANAGED\"},\"id\":\"1a2b3c4d-5e6f-7890-abcd-ef0123456789\",\"type\":\"org_group_policies\"}}\n\n@endpoint GET /api/v2/org_group_policy_configs\n@desc List org group policy configs\n@returns(200) {data: [map]} # OK\n@errors {401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/org_group_policy_overrides\n@desc List org group policy overrides\n@required {filter[org_group_id]: str(uuid): any # Filter policy overrides by org group ID.}\n@optional {filter[policy_id]: str(uuid): any # Filter policy overrides by policy ID., page[number]: int(int64)=0 # The page number to return., page[size]: int(int64)=50 # The number of items per page. Maximum is 1000., sort: str # Field to sort overrides by. Supported values: `id`, `org_uuid`, `-id`, `-org_uuid`. Defaults to `id`.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str?, prev: str?, self: str}, meta: map{page: map{first_number: int(int64), last_number: int(int64)?, next_number: int(int64)?, number: int(int64), prev_number: int(int64)?, size: int(int64), total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/org_group_policy_overrides\n@desc Create an org group policy override\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Data for creating an org group policy override.}\n@returns(201) {data: map{attributes: map{content: map, created_at: str(date-time), modified_at: str(date-time), org_site: str, org_uuid: str(uuid)}, id: str(uuid), relationships: map{org_group: map{data: map}, org_group_policy: map{data: map}}, type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"org_site\":\"us1\",\"org_uuid\":\"c3d4e5f6-a7b8-9012-cdef-012345678901\"},\"relationships\":{\"org_group\":{\"data\":{\"id\":\"a1b2c3d4-e5f6-7890-abcd-ef0123456789\",\"type\":\"org_groups\"}},\"org_group_policy\":{\"data\":{\"id\":\"1a2b3c4d-5e6f-7890-abcd-ef0123456789\",\"type\":\"org_group_policies\"}}},\"type\":\"org_group_policy_overrides\"}}\n\n@endpoint DELETE /api/v2/org_group_policy_overrides/{org_group_policy_override_id}\n@desc Delete an org group policy override\n@required {org_group_policy_override_id: str(uuid) # The ID of the org group policy override.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/org_group_policy_overrides/{org_group_policy_override_id}\n@desc Get an org group policy override\n@required {org_group_policy_override_id: str(uuid) # The ID of the org group policy override.}\n@returns(200) {data: map{attributes: map{content: map, created_at: str(date-time), modified_at: str(date-time), org_site: str, org_uuid: str(uuid)}, id: str(uuid), relationships: map{org_group: map{data: map}, org_group_policy: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/org_group_policy_overrides/{org_group_policy_override_id}\n@desc Update an org group policy override\n@required {org_group_policy_override_id: str(uuid) # The ID of the org group policy override., data: map{attributes!: map, id!: str(uuid), type!: str} # Data for updating a policy override.}\n@returns(200) {data: map{attributes: map{content: map, created_at: str(date-time), modified_at: str(date-time), org_site: str, org_uuid: str(uuid)}, id: str(uuid), relationships: map{org_group: map{data: map}, org_group_policy: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"org_site\":\"us1\",\"org_uuid\":\"c3d4e5f6-a7b8-9012-cdef-012345678901\"},\"id\":\"9f8e7d6c-5b4a-3210-fedc-ba0987654321\",\"type\":\"org_group_policy_overrides\"}}\n\n@endpoint GET /api/v2/org_group_policy_suggestions\n@desc List org group policy suggestions\n@required {filter[org_group_id]: str(uuid): any # Filter policies by org group ID.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/org_groups\n@desc List org groups\n@optional {page[number]: int(int64)=0: any # The page number to return., page[size]: int(int64)=50 # The number of items per page. Maximum is 1000., sort: str # Field to sort org groups by. Supported values: `name`, `uuid`, `-name`, `-uuid`. Defaults to `uuid`.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str?, prev: str?, self: str}, meta: map{page: map{first_number: int(int64), last_number: int(int64)?, next_number: int(int64)?, number: int(int64), prev_number: int(int64)?, size: int(int64), total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/org_groups\n@desc Create an org group\n@required {data: map{attributes!: map, type!: str} # Data for creating an org group.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), name: str, owner_org_site: str, owner_org_uuid: str(uuid)}, id: str(uuid), type: str}} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"My Org Group\"},\"type\":\"org_groups\"}}\n\n@endpoint DELETE /api/v2/org_groups/{org_group_id}\n@desc Delete an org group\n@required {org_group_id: str(uuid) # The ID of the org group.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/org_groups/{org_group_id}\n@desc Get an org group\n@required {org_group_id: str(uuid) # The ID of the org group.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), name: str, owner_org_site: str, owner_org_uuid: str(uuid)}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/org_groups/{org_group_id}\n@desc Update an org group\n@required {org_group_id: str(uuid) # The ID of the org group., data: map{attributes!: map, id!: str(uuid), type!: str} # Data for updating an org group.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), name: str, owner_org_site: str, owner_org_uuid: str(uuid)}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Updated Org Group Name\"},\"id\":\"a1b2c3d4-e5f6-7890-abcd-ef0123456789\",\"type\":\"org_groups\"}}\n\n@endpoint GET /api/v2/permissions\n@desc List permissions\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Authentication error, 429: Too many requests}\n\n@endpoint GET /api/v2/personal_access_tokens\n@desc Get all access tokens\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # Access token attribute used to sort results. Sort order is ascending by default. In order to specify a descending sort, prefix the attribute with a minus sign., filter: str # Filter access tokens by the specified string., filter[owned_by]: [str] # Filter access tokens by the owner's ID. Supports multiple values.}\n@returns(200) {data: [map], meta: map{page: map{total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/personal_access_tokens\n@desc Create a personal access token\n@required {data: map{attributes!: map, type!: str} # Object used to create an access token.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), expires_at: str(date-time)?, key: str, name: str, public_portion: str, scopes: [str]}, id: str, relationships: map{owned_by: map{data: map}}, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"expires_at\":\"2025-12-31T23:59:59+00:00\",\"name\":\"My Personal Access Token\",\"scopes\":[\"dashboards_read\",\"dashboards_write\"]},\"type\":\"personal_access_tokens\"}}\n\n@endpoint DELETE /api/v2/personal_access_tokens/{token_id}\n@desc Revoke a personal access token\n@required {token_id: str # The ID of the access token.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/personal_access_tokens/{token_id}\n@desc Get a personal access token\n@required {token_id: str # The ID of the access token.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), expires_at: str(date-time)?, last_used_at: str(date-time)?, modified_at: str(date-time)?, name: str, public_portion: str, scopes: [str]}, id: str, relationships: map{owned_by: map{data: map}}, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/personal_access_tokens/{token_id}\n@desc Update a personal access token\n@required {token_id: str # The ID of the access token., data: map{attributes!: map, id!: str, type!: str} # Object used to update an access token.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), expires_at: str(date-time)?, last_used_at: str(date-time)?, modified_at: str(date-time)?, name: str, public_portion: str, scopes: [str]}, id: str, relationships: map{owned_by: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Updated Personal Access Token\",\"scopes\":[\"dashboards_read\",\"dashboards_write\"]},\"id\":\"00112233-4455-6677-8899-aabbccddeeff\",\"type\":\"personal_access_tokens\"}}\n\n@endpoint GET /api/v2/posture_management/findings\n@desc List findings\n@optional {page[limit]: int(int64)=100: any # Limit the number of findings returned. Must be <= 1000., snapshot_timestamp: int(int64) # Return findings for a given snapshot of time (Unix ms)., page[cursor]: str # Return the next page of findings pointed to by the cursor., filter[tags]: str # Return findings that have these associated tags (repeatable)., filter[evaluation_changed_at]: str # Return findings that have changed from pass to fail or vice versa on a specified date (Unix ms) or date range (using comparison operators)., filter[muted]: bool # Set to `true` to return findings that are muted. Set to `false` to return unmuted findings., filter[rule_id]: str # Return findings for the specified rule ID., filter[rule_name]: str # Return findings for the specified rule., filter[resource_type]: str # Return only findings for the specified resource type., filter[@resource_id]: str # Return only findings for the specified resource id., filter[discovery_timestamp]: str # Return findings that were found on a specified date (Unix ms) or date range (using comparison operators)., filter[evaluation]: str # Return only `pass` or `fail` findings., filter[status]: str # Return only findings with the specified status., filter[vulnerability_type]: [str] # Return findings that match the selected vulnerability types (repeatable)., detailed_findings: bool # Return additional fields for some findings.}\n@returns(200) {data: [map], meta: map{page: map{cursor: str, total_filtered_count: int(int64)}, snapshot_timestamp: int(int64)}} # OK\n@errors {400: Bad Request: The server cannot process the request due to invalid syntax in the request., 403:Forbidden: Access denied, 404: Not Found: The requested finding cannot be found., 429: Too many requests: The rate limit set by the API has been exceeded.}\n\n@endpoint GET /api/v2/posture_management/findings/{finding_id}\n@desc Get a finding\n@required {finding_id: str # The ID of the finding.}\n@optional {snapshot_timestamp: int(int64) # Return the finding for a given snapshot of time (Unix ms).}\n@returns(200) {data: map{attributes: map{evaluation: str, evaluation_changed_at: int(int64), message: str, mute: map{description: str, expiration_date: int(int64), muted: bool, reason: str, start_date: int(int64), uuid: str}, resource: str, resource_configuration: map, resource_discovery_date: int(int64), resource_type: str, rule: map{id: str, name: str}, status: str, tags: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request: The server cannot process the request due to invalid syntax in the request., 403:Forbidden: Access denied, 404: Not Found: The requested finding cannot be found., 429: Too many requests: The rate limit set by the API has been exceeded.}\n\n@endpoint GET /api/v2/powerpacks\n@desc Get all powerpacks\n@optional {page[limit]: int(int64)=25: any # Maximum number of powerpacks in the response., page[offset]: int(int64)=0 # Specific offset to use as the beginning of the returned page.}\n@returns(200) {data: [map], included: [map], links: map{first: str, last: str?, next: str, prev: str?, self: str}, meta: map{pagination: map{first_offset: int(int64), last_offset: int(int64)?, limit: int(int64), next_offset: int(int64), offset: int(int64), prev_offset: int(int64), total: int(int64), type: str}}} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/powerpacks\n@desc Create a new powerpack\n@optional {data: map{attributes: map, id: str, relationships: map, type: str} # Powerpack data object.}\n@returns(200) {data: map{attributes: map{description: str, group_widget: map{definition: map, layout: map, live_span: str}, name: str, tags: [str], template_variables: [map]}, id: str, relationships: map{author: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Powerpack for ABC\",\"group_widget\":{\"definition\":{\"layout_type\":\"ordered\",\"show_title\":true,\"title\":\"Sample Powerpack\",\"type\":\"group\",\"widgets\":[{\"definition\":{\"content\":\"example\",\"type\":\"note\"},\"layout\":{\"height\":5,\"width\":10,\"x\":0,\"y\":0}}]},\"layout\":{\"height\":0,\"width\":0,\"x\":0,\"y\":0},\"live_span\":\"5m\"},\"name\":\"Sample Powerpack\",\"tags\":[\"tag:foo1\"],\"template_variables\":[{\"defaults\":[\"*\"],\"name\":\"test\"}]},\"relationships\":{\"author\":{\"data\":{\"id\":\"00000000-0000-0000-2345-000000000000\",\"type\":\"users\"}}},\"type\":\"powerpack\"}}\n\n@endpoint DELETE /api/v2/powerpacks/{powerpack_id}\n@desc Delete a powerpack\n@required {powerpack_id: str # Powerpack id}\n@returns(204) OK\n@errors {404: Powerpack Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/powerpacks/{powerpack_id}\n@desc Get a Powerpack\n@required {powerpack_id: str # ID of the powerpack.}\n@returns(200) {data: map{attributes: map{description: str, group_widget: map{definition: map, layout: map, live_span: str}, name: str, tags: [str], template_variables: [map]}, id: str, relationships: map{author: map{data: map}}, type: str}, included: [map]} # OK\n@errors {404: Powerpack Not Found., 429: Too many requests}\n\n@endpoint PATCH /api/v2/powerpacks/{powerpack_id}\n@desc Update a powerpack\n@required {powerpack_id: str # ID of the powerpack.}\n@optional {data: map{attributes: map, id: str, relationships: map, type: str} # Powerpack data object.}\n@returns(200) {data: map{attributes: map{description: str, group_widget: map{definition: map, layout: map, live_span: str}, name: str, tags: [str], template_variables: [map]}, id: str, relationships: map{author: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 404: Powerpack Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Powerpack for ABC\",\"group_widget\":{\"definition\":{\"layout_type\":\"ordered\",\"show_title\":true,\"title\":\"Sample Powerpack\",\"type\":\"group\",\"widgets\":[{\"definition\":{\"content\":\"example\",\"type\":\"note\"},\"layout\":{\"height\":5,\"width\":10,\"x\":0,\"y\":0}}]},\"layout\":{\"height\":0,\"width\":0,\"x\":0,\"y\":0},\"live_span\":\"5m\"},\"name\":\"Sample Powerpack\",\"tags\":[\"tag:foo1\"],\"template_variables\":[{\"defaults\":[\"*\"],\"name\":\"test\"}]},\"relationships\":{\"author\":{\"data\":{\"id\":\"00000000-0000-0000-2345-000000000000\",\"type\":\"users\"}}},\"type\":\"powerpack\"}}\n\n@endpoint GET /api/v2/processes\n@desc Get all processes\n@optional {search: str # String to search processes by., tags: str # Comma-separated list of tags to filter processes by., from: int(int64) # Unix timestamp (number of seconds since epoch) of the start of the query window. If not provided, the start of the query window will be 15 minutes before the `to` timestamp. If neither `from` nor `to` are provided, the query window will be `[now - 15m, now]`., to: int(int64) # Unix timestamp (number of seconds since epoch) of the end of the query window. If not provided, the end of the query window will be 15 minutes after the `from` timestamp. If neither `from` nor `to` are provided, the query window will be `[now - 15m, now]`., page[limit]: int(int32)=1000 # Maximum number of results returned., page[cursor]: str # String to query the next page of results. This key is provided with each valid response from the API in `meta.page.after`.}\n@returns(200) {data: [map], meta: map{page: map{after: str, size: int(int32)}}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 429: Too many requests}\n\n@endpoint POST /api/v2/prodlytics\n@desc Send server-side events\n@required {application: map{id!: str} # The application in which you want to send your events., event: map{name!: str} # Fields used for the event., type: str # The type of Product Analytics event. Must be `server` for server-side events.}\n@optional {account: map{id!: str} # The account linked to your event., session: map{id!: str} # The session linked to your event., usr: map{id!: str} # The user linked to your event.}\n@returns(202) Request accepted for processing (always 202 empty JSON).\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 408: Request Timeout, 413: Payload Too Large, 429: Too Many Requests, 500: Internal Server Error, 503: Service Unavailable}\n@example_request {\"application\":{\"id\":\"123abcde-123a-123b-1234-123456789abc\"},\"event\":{\"name\":\"payment.processed\"},\"type\":\"server\",\"usr\":{\"id\":\"123\"}}\n\n@endpoint POST /api/v2/product-analytics/accounts/facet_info\n@desc Get account facet info\n@optional {data: map{attributes: map, id: str, type!: str} # The data object containing the resource type and attributes for the facet info request.}\n@returns(200) {data: map{attributes: map{result: map{range: map, values: [map]}}, id: str, type: str}} # Successful response with facet information\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"facet_id\":\"first_browser_name\",\"limit\":10,\"search\":{\"query\":\"user_org_id:5001 AND first_country_code:US\"},\"term_search\":{\"value\":\"Chrome\"}},\"id\":\"facet_info_request\",\"type\":\"users_facet_info_request\"}}\n\n@endpoint POST /api/v2/product-analytics/accounts/query\n@desc Query accounts\n@optional {data: map{attributes: map, id: str, type!: str} # The data object containing the resource type and attributes for querying accounts.}\n@returns(200) {data: map{attributes: map{hits: [any], total: int(int64)}, id: str, type: str}} # Successful response with account data\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"limit\":20,\"query\":\"plan_type:enterprise AND user_count:>100 AND subscription_status:active\",\"select_columns\":[\"account_id\",\"account_name\",\"user_count\",\"plan_type\",\"subscription_status\",\"created_at\",\"mrr\",\"industry\"],\"sort\":{\"field\":\"user_count\",\"order\":\"DESC\"},\"wildcard_search_term\":\"tech\"},\"id\":\"query_account_request\",\"type\":\"query_account_request\"}}\n\n@endpoint POST /api/v2/product-analytics/analytics/scalar\n@desc Compute scalar analytics\n@required {data: map{attributes!: map, type!: str} # Data object for an analytics request.}\n@returns(200) {data: map{attributes: map{columns: [map]}, id: str, type: str}, meta: map{request_id: str, status: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"from\":1771232048460,\"query\":{\"compute\":{\"aggregation\":\"count\"},\"query\":{\"data_source\":\"product_analytics\",\"search\":{\"query\":\"@type:view\"}}},\"to\":1771836848262},\"type\":\"formula_analytics_extended_request\"}}\n\n@endpoint POST /api/v2/product-analytics/analytics/timeseries\n@desc Compute timeseries analytics\n@required {data: map{attributes!: map, type!: str} # Data object for an analytics request.}\n@returns(200) {data: map{attributes: map{intervals: [map], series: [map], times: [int(int64)], values: [[num(double)]]}, id: str, type: str}, meta: map{request_id: str, status: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"from\":1771232048460,\"query\":{\"compute\":{\"aggregation\":\"count\"},\"query\":{\"data_source\":\"product_analytics\",\"search\":{\"query\":\"@type:view\"}}},\"to\":1771836848262},\"type\":\"formula_analytics_extended_request\"}}\n\n@endpoint POST /api/v2/product-analytics/users/event_filtered_query\n@desc Query event filtered users\n@optional {data: map{attributes: map, id: str, type!: str} # The data object containing the resource type and attributes for querying event-filtered users.}\n@returns(200) {data: map{attributes: map{hits: [any], total: int(int64)}, id: str, type: str}} # Successful response with filtered user data\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"event_query\":{\"query\":\"@type:view AND @view.loading_time:>3000 AND @application.name:ecommerce-platform\",\"time_frame\":{\"end\":1761309676,\"start\":1760100076}},\"include_row_count\":true,\"limit\":25,\"query\":\"user_org_id:5001 AND first_country_code:US AND first_browser_name:Chrome\",\"select_columns\":[\"user_id\",\"user_email\",\"first_country_code\",\"first_browser_name\",\"events_count\",\"session_count\",\"error_count\",\"avg_loading_time\"]},\"id\":\"query_event_filtered_users_request\",\"type\":\"query_event_filtered_users_request\"}}\n\n@endpoint POST /api/v2/product-analytics/users/facet_info\n@desc Get user facet info\n@optional {data: map{attributes: map, id: str, type!: str} # The data object containing the resource type and attributes for the facet info request.}\n@returns(200) {data: map{attributes: map{result: map{range: map, values: [map]}}, id: str, type: str}} # Successful response with facet information\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"facet_id\":\"first_browser_name\",\"limit\":10,\"search\":{\"query\":\"user_org_id:5001 AND first_country_code:US\"},\"term_search\":{\"value\":\"Chrome\"}},\"id\":\"facet_info_request\",\"type\":\"users_facet_info_request\"}}\n\n@endpoint POST /api/v2/product-analytics/users/query\n@desc Query users\n@optional {data: map{attributes: map, id: str, type!: str} # The data object containing the resource type and attributes for querying users.}\n@returns(200) {data: map{attributes: map{hits: [any], total: int(int64)}, id: str, type: str}} # Successful response with user data\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"limit\":25,\"query\":\"user_email:*@techcorp.com AND first_country_code:US AND first_browser_name:Chrome\",\"select_columns\":[\"user_id\",\"user_email\",\"user_name\",\"user_org_id\",\"first_country_code\",\"first_browser_name\",\"first_device_type\",\"last_seen\"],\"sort\":{\"field\":\"first_seen\",\"order\":\"DESC\"},\"wildcard_search_term\":\"john\"},\"id\":\"query_users_request\",\"type\":\"query_users_request\"}}\n\n@endpoint GET /api/v2/product-analytics/{entity}/mapping\n@desc Get mapping\n@required {entity: str # The entity for which to get the mapping}\n@returns(200) {data: map{attributes: map{attributes: [map]}, id: str, type: str}} # Successful response with entity mapping configuration\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/product-analytics/{entity}/mapping/connection\n@desc Create connection\n@required {entity: str # The entity for which to create the connection}\n@optional {data: map{attributes: map, id: str, type!: str} # The data object containing the resource type and attributes for creating a new connection.}\n@returns(201) Connection created successfully\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"fields\":[{\"description\":\"Customer subscription tier from `CRM`\",\"display_name\":\"Customer Tier\",\"id\":\"customer_tier\",\"source_name\":\"subscription_tier\",\"type\":\"string\"},{\"description\":\"Customer lifetime value in `USD`\",\"display_name\":\"Lifetime Value\",\"id\":\"lifetime_value\",\"source_name\":\"ltv\",\"type\":\"number\"}],\"join_attribute\":\"user_email\",\"join_type\":\"email\",\"type\":\"ref_table\"},\"id\":\"crm-integration\",\"type\":\"connection_id\"}}\n\n@endpoint PUT /api/v2/product-analytics/{entity}/mapping/connection\n@desc Update connection\n@required {entity: str # The entity for which to update the connection}\n@optional {data: map{attributes: map, id!: str, type!: str} # The data object containing the resource identifier and attributes for updating an existing connection.}\n@returns(200) Connection updated successfully\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"fields_to_add\":[{\"description\":\"Net Promoter Score from customer surveys\",\"display_name\":\"NPS Score\",\"groups\":[\"Satisfaction\",\"Metrics\"],\"id\":\"nps_score\",\"source_name\":\"net_promoter_score\",\"type\":\"number\"}],\"fields_to_delete\":[\"old_revenue_field\"],\"fields_to_update\":[{\"field_id\":\"lifetime_value\",\"updated_display_name\":\"Customer Lifetime Value (`USD`)\",\"updated_groups\":[\"Financial\",\"Metrics\"]}]},\"id\":\"crm-integration\",\"type\":\"connection_id\"}}\n\n@endpoint DELETE /api/v2/product-analytics/{entity}/mapping/connection/{id}\n@desc Delete connection\n@required {id: str # The connection ID to delete, entity: str # The entity for which to delete the connection}\n@returns(204) Connection deleted successfully\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/product-analytics/{entity}/mapping/connections\n@desc List connections\n@required {entity: str # The entity for which to list connections}\n@returns(200) {data: map{attributes: map{connections: [map]}, id: str, type: str}} # Successful response with list of connections\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/pruned_trace/{trace_id}\n@desc Get a pruned trace by ID\n@required {trace_id: str # The trace ID. Accepts either a 32-character hexadecimal string (128-bit trace ID) or a decimal string of up to 39 digits.}\n@optional {expand_span_id: int(int64) # Span ID to expand and preserve in the pruned tree even when its branch would normally be summarized., time_hint: int(int32) # Optional Unix time hint, in seconds, used to optimize the lookup of the trace in long-term storage., force_source: str # Force the trace to be loaded from a specific source. When unset, the API picks the source automatically., include_path: [str] # Restrict the pruned tree to spans matching the given `key:value` pairs. Values may be passed as repeated query parameters., tag_include: [str] # Regex patterns of tag keys whose values must be included in the pruned spans. Values may be passed as repeated query parameters., tag_exclude: [str] # Regex patterns of tag keys whose values must be excluded from the pruned spans. Values may be passed as repeated query parameters., only_service_entry_spans: bool # When set to `true`, only service entry spans are included in the pruned tree.}\n@returns(200) {data: map{attributes: map{is_truncated: bool, size_bytes: int(int32), summarized_trace: map{root: map, traceId: str}}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests, 504: Gateway Timeout}\n\n@endpoint POST /api/v2/query/scalar\n@desc Query scalar data across multiple products\n@required {data: map{attributes!: map, type!: str} # A single scalar query to be executed.}\n@returns(200) {data: map{attributes: map{columns: [any]}, type: str}, errors: str} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"formulas\":[{\"formula\":\"a+b\",\"limit\":{\"count\":10}}],\"from\":1568899800000,\"queries\":[{\"aggregator\":\"avg\",\"data_source\":\"metrics\",\"query\":\"avg:system.cpu.user{*} by {env}\"}],\"to\":1568923200000},\"type\":\"scalar_request\"}}\n\n@endpoint POST /api/v2/query/timeseries\n@desc Query timeseries data across multiple products\n@required {data: map{attributes!: map, type!: str} # A single timeseries query to be executed.}\n@returns(200) {data: map{attributes: map{series: [map], times: [int(int64)], values: [[num(double)]]}, type: str}, errors: str} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"formulas\":[{\"formula\":\"a+b\",\"limit\":{\"count\":10}}],\"from\":1568899800000,\"interval\":5000,\"queries\":[{\"data_source\":\"metrics\",\"query\":\"avg:system.cpu.user{*} by {env}\"}],\"to\":1568923200000},\"type\":\"timeseries_request\"}}\n\n@endpoint POST /api/v2/reference-tables/queries/batch-rows\n@desc Batch rows query\n@optional {data: map{attributes: map, type!: str} # Data object for a batch rows query request.}\n@returns(200) {data: map{id: str, relationships: map{rows: map{data: [map]}}, type: str}, included: [map]} # Successfully retrieved rows. Some or all requested rows were found. Response includes found rows in the included section.\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"row_ids\":[\"row_id_1\",\"row_id_2\"],\"table_id\":\"00000000-0000-0000-0000-000000000000\"},\"type\":\"reference-tables-batch-rows-query\"}}\n\n@endpoint GET /api/v2/reference-tables/tables\n@desc List tables\n@optional {page[limit]: int(int64)=15: any # Number of tables to return., page[offset]: int(int64)=0 # Number of tables to skip for pagination., sort: str # Sort field and direction for the list of reference tables. Use field name for ascending, prefix with \"-\" for descending., filter[status]: str # Filter by table status., filter[table_name][exact]: str # Filter by exact table name match., filter[table_name][contains]: str # Filter by table name containing substring.}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/reference-tables/tables\n@desc Create reference table\n@optional {data: map{attributes: map, type!: str} # The data object containing the table definition.}\n@returns(201) {data: map{attributes: map{created_by: str, description: str, file_metadata: map{access_details: map, error_message: str, error_row_count: int(int64), error_type: str, sync_enabled: bool}, last_updated_by: str, row_count: int(int64), schema: map{fields: [map], primary_keys: [str]}, source: str, status: str, table_name: str, tags: [str], updated_at: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Customer reference data synced from S3\",\"file_metadata\":{\"access_details\":{\"aws_detail\":{\"aws_account_id\":\"924305315327\",\"aws_bucket_name\":\"my-data-bucket\",\"file_path\":\"customers.csv\"}},\"sync_enabled\":true},\"schema\":{\"fields\":[{\"name\":\"customer_id\",\"type\":\"STRING\"},{\"name\":\"customer_name\",\"type\":\"STRING\"},{\"name\":\"email\",\"type\":\"STRING\"}],\"primary_keys\":[\"customer_id\"]},\"source\":\"S3\",\"table_name\":\"customer_reference_data\",\"tags\":[\"team:data-platform\"]},\"type\":\"reference_table\"}}\n\n@endpoint DELETE /api/v2/reference-tables/tables/{id}\n@desc Delete table\n@required {id: str # Unique identifier of the reference table to delete}\n@returns(200) OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/reference-tables/tables/{id}\n@desc Get table\n@required {id: str # Unique identifier of the reference table to retrieve}\n@returns(200) {data: map{attributes: map{created_by: str, description: str, file_metadata: map{access_details: map, error_message: str, error_row_count: int(int64), error_type: str, sync_enabled: bool}, last_updated_by: str, row_count: int(int64), schema: map{fields: [map], primary_keys: [str]}, source: str, status: str, table_name: str, tags: [str], updated_at: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/reference-tables/tables/{id}\n@desc Update reference table\n@required {id: str # Unique identifier of the reference table to update}\n@optional {data: map{attributes: map, type!: str} # The data object containing the partial table definition updates.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"this is a cloud table generated via a cloud bucket sync\",\"file_metadata\":{\"access_details\":{\"aws_detail\":{\"aws_account_id\":\"test-account-id\",\"aws_bucket_name\":\"test-bucket\",\"file_path\":\"test_rt.csv\"}},\"sync_enabled\":true},\"schema\":{\"fields\":[{\"name\":\"id\",\"type\":\"INT32\"},{\"name\":\"name\",\"type\":\"STRING\"}],\"primary_keys\":[\"id\"]},\"tags\":[\"test_tag\"]},\"type\":\"reference_table\"}}\n\n@endpoint DELETE /api/v2/reference-tables/tables/{id}/rows\n@desc Delete rows\n@required {id: str # Unique identifier of the reference table to delete rows from, data: [map{id!: str, type!: str}] # List of row resources to delete from the reference table.}\n@returns(200) Rows deleted successfully\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 412: Precondition Failed, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":[{\"id\":\"primary_key_value\",\"type\":\"row\"}]}\n\n@endpoint GET /api/v2/reference-tables/tables/{id}/rows\n@desc Get rows by id\n@required {id: str # Unique identifier of the reference table to get rows from, row_id: [str] # List of row IDs (primary key values) to retrieve from the reference table.}\n@returns(200) {data: [map]} # Some or all requested rows were found.\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/reference-tables/tables/{id}/rows\n@desc Upsert rows\n@required {id: str # Unique identifier of the reference table to upsert rows into, data: [map{attributes: map, id!: str, type!: str}] # List of row resources to create or update in the reference table.}\n@returns(200) Rows created or updated successfully\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 412: Precondition Failed, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":[{\"attributes\":{\"values\":{\"age\":25,\"example_key_value\":\"primary_key_value\",\"name\":\"row_name\"}},\"id\":\"primary_key_value\",\"type\":\"row\"}]}\n\n@endpoint GET /api/v2/reference-tables/tables/{id}/rows/list\n@desc List rows\n@required {id: str # Unique identifier of the reference table to list rows from.}\n@optional {page[limit]: int(int64)=100: any # Number of rows to return per page. Defaults to 100, maximum is 1000., page[continuation_token]: str # Opaque cursor from the previous response's next link. Pass this to retrieve the next page on the same consistent snapshot.}\n@returns(200) {data: [map], links: map{first: str, next: str, self: str}, meta: map{page: map{next_continuation_token: str}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/reference-tables/uploads\n@desc Create reference table upload\n@optional {data: map{attributes: map, type!: str} # Request data for creating an upload for a file to be ingested into a reference table.}\n@returns(201) {data: map{attributes: map{part_urls: [str]}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"headers\":[\"product_id\",\"product_name\",\"price\"],\"part_count\":3,\"part_size\":10000000,\"table_name\":\"my_products_table\"},\"type\":\"upload\"}}\n\n@endpoint GET /api/v2/remote_config/products/asm/waf/custom_rules\n@desc List all WAF custom rules\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/remote_config/products/asm/waf/custom_rules\n@desc Create a WAF custom rule\n@required {data: map{attributes!: map, type!: str} # Object for a single WAF custom rule.}\n@returns(201) {data: map{attributes: map{action: map{action: str, parameters: map}, blocking: bool, conditions: [map], enabled: bool, metadata: map{added_at: str(date-time), added_by: str, added_by_name: str, modified_at: str(date-time), modified_by: str, modified_by_name: str}, name: str, path_glob: str, scope: [map], tags: map{category: str, type: str}}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Not Authorized, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":{\"action\":\"block_request\",\"parameters\":{\"location\":\"/blocking\",\"status_code\":403}},\"blocking\":false,\"conditions\":[{\"operator\":\"match_regex\",\"parameters\":{\"data\":\"blocked_users\",\"regex\":\"path.*\",\"value\":\"custom_tag\"}}],\"enabled\":false,\"name\":\"Block request from a bad useragent\",\"path_glob\":\"/api/search/*\",\"scope\":[{\"env\":\"prod\",\"service\":\"billing-service\"}],\"tags\":{\"category\":\"business_logic\",\"type\":\"users.login.success\"}},\"type\":\"custom_rule\"}}\n\n@endpoint DELETE /api/v2/remote_config/products/asm/waf/custom_rules/{custom_rule_id}\n@desc Delete a WAF Custom Rule\n@required {custom_rule_id: str # The ID of the custom rule.}\n@returns(204) No Content\n@errors {403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n\n@endpoint GET /api/v2/remote_config/products/asm/waf/custom_rules/{custom_rule_id}\n@desc Get a WAF custom rule\n@required {custom_rule_id: str # The ID of the custom rule.}\n@returns(200) {data: map{attributes: map{action: map{action: str, parameters: map}, blocking: bool, conditions: [map], enabled: bool, metadata: map{added_at: str(date-time), added_by: str, added_by_name: str, modified_at: str(date-time), modified_by: str, modified_by_name: str}, name: str, path_glob: str, scope: [map], tags: map{category: str, type: str}}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint PUT /api/v2/remote_config/products/asm/waf/custom_rules/{custom_rule_id}\n@desc Update a WAF Custom Rule\n@required {custom_rule_id: str # The ID of the custom rule., data: map{attributes!: map, type!: str} # Object for a single WAF Custom Rule.}\n@returns(200) {data: map{attributes: map{action: map{action: str, parameters: map}, blocking: bool, conditions: [map], enabled: bool, metadata: map{added_at: str(date-time), added_by: str, added_by_name: str, modified_at: str(date-time), modified_by: str, modified_by_name: str}, name: str, path_glob: str, scope: [map], tags: map{category: str, type: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":{\"action\":\"block_request\",\"parameters\":{\"location\":\"/blocking\",\"status_code\":403}},\"blocking\":false,\"conditions\":[{\"operator\":\"match_regex\",\"parameters\":{\"data\":\"blocked_users\",\"inputs\":[{\"address\":\"server.request.query\",\"key_path\":[\"id\"]}],\"regex\":\"path.*\",\"value\":\"custom_tag\"}}],\"enabled\":false,\"name\":\"Block request from bad useragent\",\"path_glob\":\"/api/search/*\",\"scope\":[{\"env\":\"prod\",\"service\":\"billing-service\"}],\"tags\":{\"category\":\"business_logic\",\"type\":\"users.login.success\"}},\"type\":\"custom_rule\"}}\n\n@endpoint GET /api/v2/remote_config/products/asm/waf/exclusion_filters\n@desc List all WAF exclusion filters\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/remote_config/products/asm/waf/exclusion_filters\n@desc Create a WAF exclusion filter\n@required {data: map{attributes!: map, type!: str} # Object for creating a single WAF exclusion filter.}\n@returns(200) {data: map{attributes: map{description: str, enabled: bool, event_query: str, ip_list: [str], metadata: map{added_at: str(date-time), added_by: str, added_by_name: str, modified_at: str(date-time), modified_by: str, modified_by_name: str}, on_match: str, parameters: [str], path_glob: str, rules_target: [map], scope: [map], search_query: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Exclude false positives on a path\",\"enabled\":true,\"ip_list\":[\"198.51.100.72\"],\"on_match\":\"monitor\",\"parameters\":[\"list.search.query\"],\"path_glob\":\"/accounts/*\",\"rules_target\":[{\"rule_id\":\"dog-913-009\",\"tags\":{\"category\":\"attack_attempt\",\"type\":\"lfi\"}}],\"scope\":[{\"env\":\"www\",\"service\":\"prod\"}]},\"type\":\"exclusion_filter\"}}\n\n@endpoint DELETE /api/v2/remote_config/products/asm/waf/exclusion_filters/{exclusion_filter_id}\n@desc Delete a WAF exclusion filter\n@required {exclusion_filter_id: str # The identifier of the WAF exclusion filter.}\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n\n@endpoint GET /api/v2/remote_config/products/asm/waf/exclusion_filters/{exclusion_filter_id}\n@desc Get a WAF exclusion filter\n@required {exclusion_filter_id: str # The identifier of the WAF exclusion filter.}\n@returns(200) {data: map{attributes: map{description: str, enabled: bool, event_query: str, ip_list: [str], metadata: map{added_at: str(date-time), added_by: str, added_by_name: str, modified_at: str(date-time), modified_by: str, modified_by_name: str}, on_match: str, parameters: [str], path_glob: str, rules_target: [map], scope: [map], search_query: str}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/remote_config/products/asm/waf/exclusion_filters/{exclusion_filter_id}\n@desc Update a WAF exclusion filter\n@required {exclusion_filter_id: str # The identifier of the WAF exclusion filter., data: map{attributes!: map, type!: str} # Object for updating a single WAF exclusion filter.}\n@returns(200) {data: map{attributes: map{description: str, enabled: bool, event_query: str, ip_list: [str], metadata: map{added_at: str(date-time), added_by: str, added_by_name: str, modified_at: str(date-time), modified_by: str, modified_by_name: str}, on_match: str, parameters: [str], path_glob: str, rules_target: [map], scope: [map], search_query: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Exclude false positives on a path\",\"enabled\":true,\"ip_list\":[\"198.51.100.72\"],\"on_match\":\"monitor\",\"parameters\":[\"list.search.query\"],\"path_glob\":\"/accounts/*\",\"rules_target\":[{\"rule_id\":\"dog-913-009\",\"tags\":{\"category\":\"attack_attempt\",\"type\":\"lfi\"}}],\"scope\":[{\"env\":\"www\",\"service\":\"prod\"}]},\"type\":\"exclusion_filter\"}}\n\n@endpoint GET /api/v2/remote_config/products/asm/waf/policies\n@desc List all WAF policies\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/remote_config/products/asm/waf/policies\n@desc Create a WAF Policy\n@required {data: map{attributes!: map, type!: str} # Object for a single WAF policy.}\n@returns(201) {data: map{attributes: map{description: str, isDefault: bool, name: str, protectionPresets: [str], rules: [map], rulesets: [map], scope: [map], version: int(int64)}, id: str, meta: map{added_at: str(date-time), added_by: str, added_by_name: str, modified_at: str(date-time), modified_by: str, modified_by_name: str}, type: str}} # Created\n@errors {400: Bad Request, 403: Not Authorized, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"basedOn\":\"recommended\",\"description\":\"Policy applied to internal web applications.\",\"isDefault\":false,\"name\":\"Internal Network Policy\",\"protectionPresets\":[\"attack-tools\"],\"rules\":[{\"blocking\":false,\"enabled\":true,\"id\":\"rasp-001-002\"}],\"scope\":[{\"env\":\"prod\",\"service\":\"billing-service\"}],\"version\":0},\"type\":\"policy\"}}\n\n@endpoint DELETE /api/v2/remote_config/products/asm/waf/policies/{policy_id}\n@desc Delete a WAF Policy\n@required {policy_id: str # The ID of the policy.}\n@returns(204) No Content\n@errors {403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n\n@endpoint GET /api/v2/remote_config/products/asm/waf/policies/{policy_id}\n@desc Get a WAF Policy\n@required {policy_id: str # The ID of the policy.}\n@returns(200) {data: map{attributes: map{description: str, isDefault: bool, name: str, protectionPresets: [str], rules: [map], rulesets: [map], scope: [map], version: int(int64)}, id: str, meta: map{added_at: str(date-time), added_by: str, added_by_name: str, modified_at: str(date-time), modified_by: str, modified_by_name: str}, type: str}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint PUT /api/v2/remote_config/products/asm/waf/policies/{policy_id}\n@desc Update a WAF Policy\n@required {policy_id: str # The ID of the policy., data: map{attributes!: map, type!: str} # Object for a single WAF policy.}\n@returns(200) {data: map{attributes: map{description: str, isDefault: bool, name: str, protectionPresets: [str], rules: [map], rulesets: [map], scope: [map], version: int(int64)}, id: str, meta: map{added_at: str(date-time), added_by: str, added_by_name: str, modified_at: str(date-time), modified_by: str, modified_by_name: str}, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Policy applied to internal web applications.\",\"isDefault\":false,\"name\":\"Internal Network Policy\",\"protectionPresets\":[\"attack-tools\"],\"rules\":[{\"blocking\":false,\"enabled\":true,\"id\":\"rasp-001-002\"}],\"scope\":[{\"env\":\"prod\",\"service\":\"billing-service\"}],\"version\":0},\"type\":\"policy\"}}\n\n@endpoint GET /api/v2/remote_config/products/cws/agent_rules\n@desc Get all Workload Protection agent rules\n@optional {policy_id: str # The ID of the Agent policy}\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/remote_config/products/cws/agent_rules\n@desc Create a Workload Protection agent rule\n@required {data: map{attributes!: map, type!: str} # Object for a single Agent rule}\n@returns(200) {data: map{attributes: map{actions: [map]?, agentConstraint: str, blocking: [str], category: str, creationAuthorUuId: str, creationDate: int(int64), creator: map{handle: str, name: str?}, defaultRule: bool, description: str, disabled: [str], enabled: bool, expression: str, filters: [str], monitoring: [str], name: str, product_tags: [str], silent: bool, updateAuthorUuId: str, updateDate: int(int64), updatedAt: int(int64), updater: map{handle: str, name: str?}, version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"My Agent rule\",\"enabled\":true,\"expression\":\"exec.file.name == \\\"sh\\\"\",\"name\":\"my_agent_rule\",\"policy_id\":\"a8c8e364-6556-434d-b798-a4c23de29c0b\",\"silent\":false},\"type\":\"agent_rule\"}}\n\n@endpoint DELETE /api/v2/remote_config/products/cws/agent_rules/{agent_rule_id}\n@desc Delete a Workload Protection agent rule\n@required {agent_rule_id: str # The ID of the Agent rule}\n@optional {policy_id: str # The ID of the Agent policy}\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/remote_config/products/cws/agent_rules/{agent_rule_id}\n@desc Get a Workload Protection agent rule\n@required {agent_rule_id: str # The ID of the Agent rule}\n@optional {policy_id: str # The ID of the Agent policy}\n@returns(200) {data: map{attributes: map{actions: [map]?, agentConstraint: str, blocking: [str], category: str, creationAuthorUuId: str, creationDate: int(int64), creator: map{handle: str, name: str?}, defaultRule: bool, description: str, disabled: [str], enabled: bool, expression: str, filters: [str], monitoring: [str], name: str, product_tags: [str], silent: bool, updateAuthorUuId: str, updateDate: int(int64), updatedAt: int(int64), updater: map{handle: str, name: str?}, version: int(int64)}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/remote_config/products/cws/agent_rules/{agent_rule_id}\n@desc Update a Workload Protection agent rule\n@required {agent_rule_id: str # The ID of the Agent rule, data: map{attributes!: map, id: str, type!: str} # Object for a single Agent rule}\n@optional {policy_id: str # The ID of the Agent policy}\n@returns(200) {data: map{attributes: map{actions: [map]?, agentConstraint: str, blocking: [str], category: str, creationAuthorUuId: str, creationDate: int(int64), creator: map{handle: str, name: str?}, defaultRule: bool, description: str, disabled: [str], enabled: bool, expression: str, filters: [str], monitoring: [str], name: str, product_tags: [str], silent: bool, updateAuthorUuId: str, updateDate: int(int64), updatedAt: int(int64), updater: map{handle: str, name: str?}, version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"My Agent rule\",\"enabled\":true,\"expression\":\"exec.file.name == \\\"sh\\\"\",\"policy_id\":\"a8c8e364-6556-434d-b798-a4c23de29c0b\",\"silent\":false},\"id\":\"3dd-0uc-h1s\",\"type\":\"agent_rule\"}}\n\n@endpoint GET /api/v2/remote_config/products/cws/policy\n@desc Get all Workload Protection policies\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/remote_config/products/cws/policy\n@desc Create a Workload Protection policy\n@required {data: map{attributes!: map, type!: str} # Object for a single Agent rule}\n@returns(200) {data: map{attributes: map{blockingRulesCount: int(int32), datadogManaged: bool, description: str, disabledRulesCount: int(int32), enabled: bool, hostTags: [str], hostTagsLists: [[str]], monitoringRulesCount: int(int32), name: str, pinned: bool, policyType: str, policyVersion: str, priority: int(int64), ruleCount: int(int32), updateDate: int(int64), updatedAt: int(int64), updater: map{handle: str, name: str?}, versions: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"My agent policy\",\"enabled\":true,\"hostTagsLists\":[[\"env:test\"]],\"name\":\"my_agent_policy\"},\"type\":\"policy\"}}\n\n@endpoint GET /api/v2/remote_config/products/cws/policy/download\n@desc Download the Workload Protection policy\n@returns(200) OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint DELETE /api/v2/remote_config/products/cws/policy/{policy_id}\n@desc Delete a Workload Protection policy\n@required {policy_id: str # The ID of the Agent policy}\n@returns(202) OK\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/remote_config/products/cws/policy/{policy_id}\n@desc Get a Workload Protection policy\n@required {policy_id: str # The ID of the Agent policy}\n@returns(200) {data: map{attributes: map{blockingRulesCount: int(int32), datadogManaged: bool, description: str, disabledRulesCount: int(int32), enabled: bool, hostTags: [str], hostTagsLists: [[str]], monitoringRulesCount: int(int32), name: str, pinned: bool, policyType: str, policyVersion: str, priority: int(int64), ruleCount: int(int32), updateDate: int(int64), updatedAt: int(int64), updater: map{handle: str, name: str?}, versions: [map]}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/remote_config/products/cws/policy/{policy_id}\n@desc Update a Workload Protection policy\n@required {policy_id: str # The ID of the Agent policy, data: map{attributes!: map, id: str, type!: str} # Object for a single Agent policy}\n@returns(200) {data: map{attributes: map{blockingRulesCount: int(int32), datadogManaged: bool, description: str, disabledRulesCount: int(int32), enabled: bool, hostTags: [str], hostTagsLists: [[str]], monitoringRulesCount: int(int32), name: str, pinned: bool, policyType: str, policyVersion: str, priority: int(int64), ruleCount: int(int32), updateDate: int(int64), updatedAt: int(int64), updater: map{handle: str, name: str?}, versions: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"My agent policy\",\"enabled\":true,\"name\":\"my_agent_policy\"},\"id\":\"6517fcc1-cec7-4394-a655-8d6e9d085255\",\"type\":\"policy\"}}\n\n@endpoint GET /api/v2/remote_config/products/rum/configs/{config_id}\n@desc Get a RUM SDK configuration\n@required {config_id: str # The ID of the RUM SDK configuration.}\n@returns(200) {data: map{attributes: map{rum: map{allowed_tracing_urls: [map], allowed_tracking_origins: [map], application_id: str, context: [map], default_privacy_level: str, enable_privacy_for_action_name: bool, env: str, service: str, session_replay_sample_rate: int(int64), session_sample_rate: int(int64), trace_sample_rate: int(int64), track_session_across_subdomains: bool, user: [map], version: map}}, id: str, meta: map{updated_at: str(date-time), updated_by: str}, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/remote_config/products/rum/configs/{config_id}\n@desc Update a RUM SDK configuration\n@required {config_id: str # The ID of the RUM SDK configuration., data: map{attributes!: map, id!: str, type!: str} # The data object for updating a RUM SDK configuration.}\n@returns(200) {data: map{attributes: map{rum: map{allowed_tracing_urls: [map], allowed_tracking_origins: [map], application_id: str, context: [map], default_privacy_level: str, enable_privacy_for_action_name: bool, env: str, service: str, session_replay_sample_rate: int(int64), session_sample_rate: int(int64), trace_sample_rate: int(int64), track_session_across_subdomains: bool, user: [map], version: map}}, id: str, meta: map{updated_at: str(date-time), updated_by: str}, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"rum\":{\"default_privacy_level\":\"mask\",\"enable_privacy_for_action_name\":true,\"session_replay_sample_rate\":20,\"session_sample_rate\":75}},\"id\":\"abc12345-1234-5678-abcd-ef1234567890\",\"type\":\"rum_sdk_config\"}}\n\n@endpoint GET /api/v2/replay/heatmap/snapshots\n@desc List replay heatmap snapshots\n@required {filter[view_name]: str: any # View name to filter snapshots.}\n@optional {filter[device_type]: str: any # Device type to filter snapshots., page[limit]: int(int64) # Maximum number of snapshots to return., filter[application_id]: str # Filter by application ID.}\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/replay/heatmap/snapshots\n@desc Create replay heatmap snapshot\n@required {data: map{attributes: map, type!: str} # Data object for a heatmap snapshot creation request, containing the resource type and attributes.}\n@returns(201) {data: map{attributes: map{application_id: str, created_at: str(date-time), created_by: str, created_by_handle: str, created_by_user_id: int(int64), device_type: str, event_id: str, is_device_type_selected_by_user: bool, modified_at: str(date-time), org_id: int(int64), session_id: str, snapshot_name: str, start: int(int64), view_id: str, view_name: str}, id: str, type: str}} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"application_id\":\"aaaaaaaa-1111-2222-3333-bbbbbbbbbbbb\",\"device_type\":\"desktop\",\"event_id\":\"11111111-2222-3333-4444-555555555555\",\"is_device_type_selected_by_user\":false,\"snapshot_name\":\"My Snapshot\",\"start\":0,\"view_name\":\"/home\"},\"type\":\"snapshots\"}}\n\n@endpoint DELETE /api/v2/replay/heatmap/snapshots/{snapshot_id}\n@desc Delete replay heatmap snapshot\n@required {snapshot_id: str # Unique identifier of the heatmap snapshot.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/replay/heatmap/snapshots/{snapshot_id}\n@desc Update replay heatmap snapshot\n@required {snapshot_id: str # Unique identifier of the heatmap snapshot., data: map{attributes: map, id: str, type!: str} # Data object for a heatmap snapshot update request, containing the resource identifier, type, and attributes.}\n@returns(200) {data: map{attributes: map{application_id: str, created_at: str(date-time), created_by: str, created_by_handle: str, created_by_user_id: int(int64), device_type: str, event_id: str, is_device_type_selected_by_user: bool, modified_at: str(date-time), org_id: int(int64), session_id: str, snapshot_name: str, start: int(int64), view_id: str, view_name: str}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"event_id\":\"11111111-2222-3333-4444-555555555555\",\"is_device_type_selected_by_user\":false,\"start\":0},\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"snapshots\"}}\n\n@endpoint GET /api/v2/reporting/dataset/{dataset_id}/schedules\n@desc List dataset report schedules\n@required {dataset_id: str # The identifier of the published dataset to retrieve report schedules for.}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/reporting/print\n@desc Print a report\n@required {data: map{attributes!: map, type!: str} # The JSON:API data object for a print report request.}\n@returns(200) {data: map{attributes: map{download_url: str, from_ts: int(int64), resource_id: str, resource_type: str, template_variables: [map], timeframe: str, timezone: str, to_ts: int(int64)}, id: str(uuid), type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"resource_id\":\"abc-def-ghi\",\"resource_type\":\"dashboard\",\"template_variables\":[{\"name\":\"env\",\"values\":[\"prod\"]}],\"timeframe\":\"1w\",\"timezone\":\"America/New_York\"},\"type\":\"report\"}}\n\n@endpoint POST /api/v2/reporting/schedule\n@desc Create a report schedule\n@required {data: map{attributes!: map, type!: str} # The JSON:API data object for a report schedule creation request.}\n@returns(201) {data: map{attributes: map{delivery_format: str?, description: str, next_recurrence: int(int64)?, recipients: [str], resource_id: str, resource_type: str, rrule: str, status: str, tab_id: str?, template_variables: [map], timeframe: str?, timezone: str, title: str}, id: str, relationships: map{author: map{data: map}}, type: str}, included: [any]} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"delivery_format\":\"pdf\",\"description\":\"Weekly summary of infrastructure health.\",\"recipients\":[\"user@example.com\",\"slack:T01234567.C01234567.alerts\",\"teams:11111111-1111-1111-1111-111111111111|22222222-2222-2222-2222-222222222222|19:exampleChannelId@thread.tacv2\"],\"resource_id\":\"abc-def-ghi\",\"resource_type\":\"dashboard\",\"rrule\":\"DTSTART;TZID=America/New_York:20260601T090000\\nRRULE:FREQ=WEEKLY;BYDAY=MO;BYHOUR=9;BYMINUTE=0\",\"template_variables\":[{\"name\":\"env\",\"values\":[\"prod\"]}],\"timeframe\":\"1w\",\"timezone\":\"America/New_York\",\"title\":\"Weekly Infrastructure Report\"},\"type\":\"schedule\"}}\n\n@endpoint GET /api/v2/reporting/schedule/list\n@desc List report schedules\n@optional {page[limit]: int(int64)=25: any # The maximum number of schedules to return. The maximum value is 50., page[offset]: int(int64)=0 # The offset from which to start returning schedules., filter[title]: str # Filter schedules by report title., filter[author_uuid]: str(uuid) # Filter schedules by author UUID., filter[recipients]: str # Filter schedules by a comma-separated list of recipients.}\n@returns(200) {data: [map], included: [any], links: map{first: str?, last: str?, next: str?, prev: str?, self: str?}, meta: map{pagination: map{first_offset: int(int64), last_offset: int(int64)?, limit: int(int64), next_offset: int(int64), offset: int(int64), prev_offset: int(int64), total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/reporting/schedule/{resource_type}/{resource_id}\n@desc Get report schedules for a resource\n@required {resource_type: str # The type of resource to fetch report schedules for., resource_id: str # The identifier of the resource to fetch report schedules for.}\n@returns(200) {data: [map], included: [any], links: map{first: str?, last: str?, next: str?, prev: str?, self: str?}, meta: map{pagination: map{first_offset: int(int64), last_offset: int(int64)?, limit: int(int64), next_offset: int(int64), offset: int(int64), prev_offset: int(int64), total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/reporting/schedule/{schedule_uuid}\n@desc Delete a report schedule\n@required {schedule_uuid: str(uuid) # The unique identifier of the report schedule to delete.}\n@returns(200) {data: map{attributes: map{delivery_format: str?, description: str, next_recurrence: int(int64)?, recipients: [str], resource_id: str, resource_type: str, rrule: str, status: str, tab_id: str?, template_variables: [map], timeframe: str?, timezone: str, title: str}, id: str, relationships: map{author: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/reporting/schedule/{schedule_uuid}\n@desc Get a report schedule\n@required {schedule_uuid: str(uuid) # The unique identifier of the report schedule to fetch.}\n@returns(200) {data: map{attributes: map{delivery_format: str?, description: str, next_recurrence: int(int64)?, recipients: [str], resource_id: str, resource_type: str, rrule: str, status: str, tab_id: str?, template_variables: [map], timeframe: str?, timezone: str, title: str}, id: str, relationships: map{author: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/reporting/schedule/{schedule_uuid}\n@desc Update a report schedule\n@required {schedule_uuid: str(uuid) # The unique identifier of the report schedule to update., data: map{attributes!: map, type!: str} # The JSON:API data object for a report schedule update request.}\n@returns(200) {data: map{attributes: map{delivery_format: str?, description: str, next_recurrence: int(int64)?, recipients: [str], resource_id: str, resource_type: str, rrule: str, status: str, tab_id: str?, template_variables: [map], timeframe: str?, timezone: str, title: str}, id: str, relationships: map{author: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"delivery_format\":\"pdf\",\"description\":\"Updated weekly summary of infrastructure health.\",\"recipients\":[\"user@example.com\",\"slack:T01234567.C01234567.alerts\",\"teams:11111111-1111-1111-1111-111111111111|22222222-2222-2222-2222-222222222222|19:exampleChannelId@thread.tacv2\"],\"rrule\":\"DTSTART;TZID=America/New_York:20260601T090000\\nRRULE:FREQ=WEEKLY;BYDAY=MO;BYHOUR=9;BYMINUTE=0\",\"template_variables\":[{\"name\":\"env\",\"values\":[\"prod\"]}],\"timeframe\":\"1w\",\"timezone\":\"America/New_York\",\"title\":\"Weekly Infrastructure Report\"},\"type\":\"schedule\"}}\n\n@endpoint PATCH /api/v2/reporting/schedule/{schedule_uuid}/toggle\n@desc Toggle a report schedule\n@required {schedule_uuid: str(uuid) # The unique identifier of the report schedule to toggle., data: map{attributes!: map, type!: str} # The JSON:API data object for a report schedule toggle request.}\n@returns(200) {data: map{attributes: map{delivery_format: str?, description: str, next_recurrence: int(int64)?, recipients: [str], resource_id: str, resource_type: str, rrule: str, status: str, tab_id: str?, template_variables: [map], timeframe: str?, timezone: str, title: str}, id: str, relationships: map{author: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"status\":\"inactive\"},\"type\":\"schedule\"}}\n\n@endpoint DELETE /api/v2/restriction_policy/{resource_id}\n@desc Delete a restriction policy\n@required {resource_id: str # Identifier, formatted as `type:id`. Supported types: `dashboard`, `integration-service`, `integration-webhook`, `notebook`, `powerpack`, `reference-table`, `security-rule`, `slo`, `synthetics-global-variable`, `synthetics-test`, `synthetics-private-location`, `monitor`, `workflow`, `app-builder-app`, `connection`, `connection-group`, `rum-application`, `cross-org-connection`, `spreadsheet`, `on-call-schedule`, `on-call-escalation-policy`, `on-call-team-routing-rules`, `logs-pipeline`, `case-management-project`, `monitor-notification-rule`, `status-page`, `feature-flag`.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/restriction_policy/{resource_id}\n@desc Get a restriction policy\n@required {resource_id: str # Identifier, formatted as `type:id`. Supported types: `dashboard`, `integration-service`, `integration-webhook`, `notebook`, `powerpack`, `reference-table`, `security-rule`, `slo`, `synthetics-global-variable`, `synthetics-test`, `synthetics-private-location`, `monitor`, `workflow`, `app-builder-app`, `connection`, `connection-group`, `rum-application`, `cross-org-connection`, `spreadsheet`, `on-call-schedule`, `on-call-escalation-policy`, `on-call-team-routing-rules`, `logs-pipeline`, `case-management-project`, `monitor-notification-rule`, `status-page`, `feature-flag`.}\n@returns(200) {data: map{attributes: map{bindings: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/restriction_policy/{resource_id}\n@desc Update a restriction policy\n@required {resource_id: str # Identifier, formatted as `type:id`. Supported types: `dashboard`, `integration-service`, `integration-webhook`, `notebook`, `powerpack`, `reference-table`, `security-rule`, `slo`, `synthetics-global-variable`, `synthetics-test`, `synthetics-private-location`, `monitor`, `workflow`, `app-builder-app`, `connection`, `connection-group`, `rum-application`, `cross-org-connection`, `spreadsheet`, `on-call-schedule`, `on-call-escalation-policy`, `on-call-team-routing-rules`, `logs-pipeline`, `case-management-project`, `monitor-notification-rule`, `status-page`, `feature-flag`., data: map{attributes!: map, id!: str, type!: str} # Restriction policy object.}\n@optional {allow_self_lockout: bool # Allows admins (users with the `user_access_manage` permission) to remove their own access from the resource if set to `true`. By default, this is set to `false`, preventing admins from locking themselves out.}\n@returns(200) {data: map{attributes: map{bindings: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"bindings\":[{\"principals\":[\"user:4dee724d-00cc-11ea-a77b-570c9d03c6c5\"],\"relation\":\"editor\"}]},\"id\":\"dashboard:abc-def-ghi\",\"type\":\"restriction_policy\"}}\n\n@endpoint GET /api/v2/roles\n@desc List roles\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # Sort roles depending on the given field. Sort order is **ascending** by default. Sort order is **descending** if the field is prefixed by a negative sign, for example: `sort=-name`., filter: str # Filter all roles by the given string., filter[id]: str # Filter all roles by the given list of role IDs.}\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {403: Authentication error, 429: Too many requests}\n\n@endpoint POST /api/v2/roles\n@desc Create role\n@required {data: map{attributes!: map, relationships: map, type: str} # Data related to the creation of a role.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), name: str, receives_permissions_from: [str]}, id: str, relationships: map{permissions: map{data: [map]}}, type: str}} # OK\n@errors {400: Bad Request, 403: Authentication error, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"developers\"},\"type\":\"roles\"}}\n\n@endpoint GET /api/v2/roles/templates\n@desc List role templates\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint DELETE /api/v2/roles/{role_id}\n@desc Delete role\n@required {role_id: str # The unique identifier of the role.}\n@returns(204) OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint GET /api/v2/roles/{role_id}\n@desc Get a role\n@required {role_id: str # The unique identifier of the role.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), name: str, receives_permissions_from: [str], user_count: int(int64)}, id: str, relationships: map{permissions: map{data: [map]}}, type: str}} # OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/roles/{role_id}\n@desc Update a role\n@required {role_id: str # The unique identifier of the role., data: map{attributes!: map, id!: str, relationships: map, type!: str} # Data related to the update of a role.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), name: str, receives_permissions_from: [str], user_count: int(int32)}, id: str, relationships: map{permissions: map{data: [map]}}, type: str}} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"updated-role-name\"},\"id\":\"00000000-0000-1111-0000-000000000000\",\"type\":\"roles\"}}\n\n@endpoint POST /api/v2/roles/{role_id}/clone\n@desc Create a new role by cloning an existing role\n@required {role_id: str # The unique identifier of the role., data: map{attributes!: map, type!: str} # Data for the clone role request.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), modified_at: str(date-time), name: str, receives_permissions_from: [str], user_count: int(int64)}, id: str, relationships: map{permissions: map{data: [map]}}, type: str}} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"cloned-role\"},\"type\":\"roles\"}}\n\n@endpoint DELETE /api/v2/roles/{role_id}/permissions\n@desc Revoke permission\n@required {role_id: str # The unique identifier of the role.}\n@optional {data: map{id: str, type: str} # Relationship to permission object.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"6f66600e-dd12-11e8-9e55-7f30fbb45e73\",\"type\":\"permissions\"}}\n\n@endpoint GET /api/v2/roles/{role_id}/permissions\n@desc List permissions for a role\n@required {role_id: str # The unique identifier of the role.}\n@returns(200) {data: [map]} # OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint POST /api/v2/roles/{role_id}/permissions\n@desc Grant permission to a role\n@required {role_id: str # The unique identifier of the role.}\n@optional {data: map{id: str, type: str} # Relationship to permission object.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"6f66600e-dd12-11e8-9e55-7f30fbb45e73\",\"type\":\"permissions\"}}\n\n@endpoint DELETE /api/v2/roles/{role_id}/users\n@desc Remove a user from a role\n@required {role_id: str # The unique identifier of the role., data: map{id!: str, type!: str} # Relationship to user object.}\n@returns(200) {data: [map], included: [any], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"00000000-0000-0000-2345-000000000000\",\"type\":\"users\"}}\n\n@endpoint GET /api/v2/roles/{role_id}/users\n@desc Get all users of a role\n@required {role_id: str # The unique identifier of the role.}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str=name # User attribute to order results by. Sort order is **ascending** by default. Sort order is **descending** if the field is prefixed by a negative sign, for example `sort=-name`. Options: `name`, `email`, `status`., filter: str # Filter all users by the given string. Defaults to no filtering.}\n@returns(200) {data: [map], included: [any], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint POST /api/v2/roles/{role_id}/users\n@desc Add a user to a role\n@required {role_id: str # The unique identifier of the role., data: map{id!: str, type!: str} # Relationship to user object.}\n@returns(200) {data: [map], included: [any], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"00000000-0000-0000-2345-000000000000\",\"type\":\"users\"}}\n\n@endpoint POST /api/v2/rum/analytics/aggregate\n@desc Aggregate RUM events\n@optional {compute: [map{aggregation!: str, interval: str, metric: str, type: str}] # The list of metrics or timeseries to compute for the retrieved buckets., filter: map{from: str, query: str, to: str} # The search and filter query settings., group_by: [map{facet!: str, histogram: map, limit: int(int64), missing: any, sort: map, total: any}] # The rules for the group by., options: map{time_offset: int(int64), timezone: str} # Global query options that are used during the query. Note: Only supply timezone or time offset, not both. Otherwise, the query fails., page: map{cursor: str, limit: int(int32)} # Paging attributes for listing events.}\n@returns(200) {data: map{buckets: [map]}, links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"compute\":[{\"aggregation\":\"pc90\",\"interval\":\"5m\",\"metric\":\"@duration\",\"type\":\"timeseries\"}],\"filter\":{\"from\":\"now-15m\",\"query\":\"@type:session AND @session.type:user\",\"to\":\"now\"},\"group_by\":[{\"facet\":\"@view.time_spent\",\"histogram\":{\"interval\":10,\"max\":100,\"min\":50},\"sort\":{\"aggregation\":\"count\",\"order\":\"asc\"}}],\"options\":{\"timezone\":\"GMT\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\",\"limit\":25}}\n\n@endpoint GET /api/v2/rum/applications\n@desc List all the RUM applications\n@returns(200) {data: [map]} # OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/rum/applications\n@desc Create a new RUM application\n@required {data: map{attributes!: map, type!: str} # RUM application creation.}\n@returns(200) {data: map{attributes: map{api_key_id: int(int32), application_id: str, client_token: str, created_at: int(int64), created_by_handle: str, hash: str, is_active: bool, name: str, org_id: int(int32), product_scales: map{product_analytics_retention_scale: map, rum_event_processing_scale: map}, remote_config_id: str, type: str, updated_at: int(int64), updated_by_handle: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"my_new_rum_application\",\"product_analytics_retention_state\":\"MAX\",\"rum_event_processing_state\":\"ALL\",\"type\":\"browser\"},\"type\":\"rum_application_create\"}}\n\n@endpoint PATCH /api/v2/rum/applications/{app_id}/relationships/retention_filters\n@desc Order RUM retention filters\n@required {app_id: str # RUM application ID.}\n@optional {data: [map{id!: str, type!: str}] # A list of RUM retention filter IDs along with type.}\n@returns(200) {data: [map]} # Ordered\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":[{\"id\":\"051601eb-54a0-abc0-03f9-cc02efa18892\",\"type\":\"retention_filters\"}]}\n\n@endpoint GET /api/v2/rum/applications/{app_id}/retention_filters\n@desc Get all RUM retention filters\n@required {app_id: str # RUM application ID.}\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/rum/applications/{app_id}/retention_filters\n@desc Create a RUM retention filter\n@required {app_id: str # RUM application ID., data: map{attributes!: map, type!: str} # The new RUM retention filter properties to create.}\n@returns(201) {data: map{attributes: map{cross_product_sampling: map{trace_enabled: bool, trace_sample_rate: num(double)}, enabled: bool, event_type: str, name: str, query: str, sample_rate: num(double)}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"cross_product_sampling\":{\"trace_enabled\":true,\"trace_sample_rate\":25},\"enabled\":true,\"event_type\":\"session\",\"name\":\"Retention filter for session\",\"query\":\"@session.has_replay:true\",\"sample_rate\":50.5},\"type\":\"retention_filters\"}}\n\n@endpoint GET /api/v2/rum/applications/{app_id}/retention_filters/permanent\n@desc Get all permanent RUM retention filters\n@required {app_id: str # RUM application ID.}\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/rum/applications/{app_id}/retention_filters/permanent/{permanent_rf_id}\n@desc Get a permanent RUM retention filter\n@required {app_id: str # RUM application ID., permanent_rf_id: str # The identifier of the permanent RUM retention filter.}\n@returns(200) {data: map{attributes: map{cross_product_sampling: map{trace_enabled: bool, trace_sample_rate: num(double)}, description: str, editability: map{trace_editable: bool}, name: str}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/rum/applications/{app_id}/retention_filters/permanent/{permanent_rf_id}\n@desc Update a permanent RUM retention filter\n@required {app_id: str # RUM application ID., permanent_rf_id: str # The identifier of the permanent RUM retention filter., data: map{attributes!: map, id!: str, type!: str} # The new permanent RUM retention filter configuration to update.}\n@returns(200) {data: map{attributes: map{cross_product_sampling: map{trace_enabled: bool, trace_sample_rate: num(double)}, description: str, editability: map{trace_editable: bool}, name: str}, id: str, type: str}} # Updated\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"cross_product_sampling\":{\"trace_enabled\":true,\"trace_sample_rate\":50}},\"id\":\"synthetics_sessions\",\"type\":\"permanent_retention_filters\"}}\n\n@endpoint DELETE /api/v2/rum/applications/{app_id}/retention_filters/{rf_id}\n@desc Delete a RUM retention filter\n@required {app_id: str # RUM application ID., rf_id: str # Retention filter ID.}\n@returns(204) No Content\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/rum/applications/{app_id}/retention_filters/{rf_id}\n@desc Get a RUM retention filter\n@required {app_id: str # RUM application ID., rf_id: str # Retention filter ID.}\n@returns(200) {data: map{attributes: map{cross_product_sampling: map{trace_enabled: bool, trace_sample_rate: num(double)}, enabled: bool, event_type: str, name: str, query: str, sample_rate: num(double)}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/rum/applications/{app_id}/retention_filters/{rf_id}\n@desc Update a RUM retention filter\n@required {app_id: str # RUM application ID., rf_id: str # Retention filter ID., data: map{attributes!: map, id!: str, type!: str} # The new RUM retention filter properties to update.}\n@returns(200) {data: map{attributes: map{cross_product_sampling: map{trace_enabled: bool, trace_sample_rate: num(double)}, enabled: bool, event_type: str, name: str, query: str, sample_rate: num(double)}, id: str, type: str}} # Updated\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"cross_product_sampling\":{\"trace_enabled\":true,\"trace_sample_rate\":25},\"enabled\":true,\"event_type\":\"session\",\"name\":\"Retention filter for session\",\"query\":\"@session.has_replay:true\",\"sample_rate\":50.5},\"id\":\"051601eb-54a0-abc0-03f9-cc02efa18892\",\"type\":\"retention_filters\"}}\n\n@endpoint DELETE /api/v2/rum/applications/{id}\n@desc Delete a RUM application\n@required {id: str # RUM application ID.}\n@returns(204) No Content\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/rum/applications/{id}\n@desc Get a RUM application\n@required {id: str # RUM application ID.}\n@returns(200) {data: map{attributes: map{api_key_id: int(int32), application_id: str, client_token: str, created_at: int(int64), created_by_handle: str, hash: str, is_active: bool, name: str, org_id: int(int32), product_scales: map{product_analytics_retention_scale: map, rum_event_processing_scale: map}, remote_config_id: str, type: str, updated_at: int(int64), updated_by_handle: str}, id: str, type: str}} # OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/rum/applications/{id}\n@desc Update a RUM application\n@required {id: str # RUM application ID., data: map{attributes: map, id!: str, type!: str} # RUM application update.}\n@returns(200) {data: map{attributes: map{api_key_id: int(int32), application_id: str, client_token: str, created_at: int(int64), created_by_handle: str, hash: str, is_active: bool, name: str, org_id: int(int32), product_scales: map{product_analytics_retention_scale: map, rum_event_processing_scale: map}, remote_config_id: str, type: str, updated_at: int(int64), updated_by_handle: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 422: Unprocessable Entity., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"updated_name_for_my_existing_rum_application\",\"product_analytics_retention_state\":\"MAX\",\"rum_event_processing_state\":\"ALL\",\"type\":\"browser\"},\"id\":\"abcd1234-0000-0000-abcd-1234abcd5678\",\"type\":\"rum_application_update\"}}\n\n@endpoint GET /api/v2/rum/config\n@desc Get the RUM configuration\n@returns(200) {data: map{attributes: map{disabled: bool, enforced_application_tags: bool, enforced_application_tags_updated_at: str(date-time), enforced_application_tags_updated_by: str, ootb_metrics_version: int(int64), ootb_metrics_version_installed_at: str(date-time), retention_filters_enabled: bool, retention_filters_enabled_updated_at: str(date-time), retention_filters_enabled_updated_by: str}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint PATCH /api/v2/rum/config\n@desc Update the RUM configuration\n@required {data: map{attributes!: map, type!: str} # Object describing the RUM configuration to update.}\n@returns(200) {data: map{attributes: map{disabled: bool, enforced_application_tags: bool, enforced_application_tags_updated_at: str(date-time), enforced_application_tags_updated_by: str, ootb_metrics_version: int(int64), ootb_metrics_version_installed_at: str(date-time), retention_filters_enabled: bool, retention_filters_enabled_updated_at: str(date-time), retention_filters_enabled_updated_by: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enforced_application_tags\":false},\"type\":\"rum_config\"}}\n\n@endpoint POST /api/v2/rum/config\n@desc Create the RUM configuration\n@required {data: map{attributes!: map, type!: str} # Object describing the RUM configuration to create.}\n@returns(201) {data: map{attributes: map{disabled: bool, enforced_application_tags: bool, enforced_application_tags_updated_at: str(date-time), enforced_application_tags_updated_by: str, ootb_metrics_version: int(int64), ootb_metrics_version_installed_at: str(date-time), retention_filters_enabled: bool, retention_filters_enabled_updated_at: str(date-time), retention_filters_enabled_updated_by: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enforced_application_tags\":true},\"type\":\"rum_config\"}}\n\n@endpoint GET /api/v2/rum/config/metrics\n@desc Get all RUM-based metrics\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/rum/config/metrics\n@desc Create a RUM-based metric\n@required {data: map{attributes!: map, id!: str, type!: str} # The new RUM-based metric properties.}\n@returns(201) {data: map{attributes: map{compute: map{aggregation_type: str, include_percentiles: bool, path: str}, event_type: str, filter: map{query: str}, group_by: [map], uniqueness: map{when: str}}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compute\":{\"aggregation_type\":\"distribution\",\"include_percentiles\":true,\"path\":\"@duration\"},\"event_type\":\"session\",\"filter\":{\"query\":\"@service:web-api\"},\"group_by\":[{\"path\":\"@browser.name\",\"tag_name\":\"browser_name\"}],\"uniqueness\":{\"when\":\"match\"}},\"id\":\"rum.sessions.web.count\",\"type\":\"rum_metrics\"}}\n\n@endpoint DELETE /api/v2/rum/config/metrics/{metric_id}\n@desc Delete a RUM-based metric\n@required {metric_id: str # The name of the RUM-based metric.}\n@returns(204) No Content\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/rum/config/metrics/{metric_id}\n@desc Get a RUM-based metric\n@required {metric_id: str # The name of the RUM-based metric.}\n@returns(200) {data: map{attributes: map{compute: map{aggregation_type: str, include_percentiles: bool, path: str}, event_type: str, filter: map{query: str}, group_by: [map], uniqueness: map{when: str}}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/rum/config/metrics/{metric_id}\n@desc Update a RUM-based metric\n@required {metric_id: str # The name of the RUM-based metric., data: map{attributes!: map, id: str, type!: str} # The new RUM-based metric properties.}\n@returns(200) {data: map{attributes: map{compute: map{aggregation_type: str, include_percentiles: bool, path: str}, event_type: str, filter: map{query: str}, group_by: [map], uniqueness: map{when: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compute\":{\"include_percentiles\":true},\"filter\":{\"query\":\"@service:web-api\"},\"group_by\":[{\"path\":\"@browser.name\",\"tag_name\":\"browser_name\"}]},\"id\":\"rum.sessions.web.count\",\"type\":\"rum_metrics\"}}\n\n@endpoint GET /api/v2/rum/events\n@desc Get a list of RUM events\n@optional {filter[query]: str: any # Search query following RUM syntax., filter[from]: str(date-time) # Minimum timestamp for requested events., filter[to]: str(date-time) # Maximum timestamp for requested events., sort: str # Order of events in results., page[cursor]: str # List following results with a cursor provided in the previous query., page[limit]: int(int32)=10 # Maximum number of events in the response.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/rum/events/search\n@desc Search RUM events\n@optional {filter: map{from: str, query: str, to: str} # The search and filter query settings., options: map{time_offset: int(int64), timezone: str} # Global query options that are used during the query. Note: Only supply timezone or time offset, not both. Otherwise, the query fails., page: map{cursor: str, limit: int(int32)} # Paging attributes for listing events., sort: str(timestamp/-timestamp) # Sort parameters when querying events.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"filter\":{\"from\":\"now-15m\",\"query\":\"@type:session AND @session.type:user\",\"to\":\"now\"},\"options\":{\"timezone\":\"GMT\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\",\"limit\":25},\"sort\":\"timestamp\"}\n\n@endpoint POST /api/v2/rum/operations\n@desc Create a RUM operation\n@required {data: map{attributes!: map, type!: str} # The data object for creating a RUM operation.}\n@returns(200) {data: map{attributes: map{application_id: str(uuid)?, category: str?, created_at: str(date-time), created_by: map{email: str, handle: str, name: str, uuid: str}, description: str?, display_name: str, feature_ids: [str], journey_rum: map{rum_steps: [map]}, name: str, org_id: int(int64), tags: [str], updated_at: str(date-time)?, updated_by: map{email: str, handle: str, name: str, uuid: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 409: Conflict. An operation with this name already exists., 429: Too many requests}\n\n@endpoint GET /api/v2/rum/operations/by-name/{name}\n@desc Get a RUM operation by name\n@required {name: str # The unique name of the RUM operation.}\n@returns(200) {data: map{attributes: map{application_id: str(uuid)?, category: str?, created_at: str(date-time), created_by: map{email: str, handle: str, name: str, uuid: str}, description: str?, display_name: str, feature_ids: [str], journey_rum: map{rum_steps: [map]}, name: str, org_id: int(int64), tags: [str], updated_at: str(date-time)?, updated_by: map{email: str, handle: str, name: str, uuid: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/rum/operations/search\n@desc Search RUM operations\n@optional {query: str # A search query to filter operations by name., page[offset]: int(int64)=0 # Offset for pagination., page[limit]: int(int64)=50 # Number of items per page. Maximum of 100., creator: str # Filter operations by the email of their creator., team: str # Filter operations by team. Accepts a comma-separated list of teams., feature_id: str # Filter operations by feature ID. Accepts a comma-separated list of feature IDs., application_id: str(uuid) # Filter operations by RUM application ID.}\n@returns(200) {data: [map], meta: map{page: map{first_offset: int(int64), last_offset: int(int64), limit: int(int64), next_offset: int(int64)?, offset: int(int64), prev_offset: int(int64)?, total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint GET /api/v2/rum/operations/strong_links\n@desc List RUM operation strong links\n@optional {operation_id: str # Filter strong links by RUM operation ID., feature_id: str # Filter strong links by feature ID., page[offset]: int(int64)=0 # Offset for pagination., page[limit]: int(int64)=50 # Number of items per page. Maximum of 200.}\n@returns(200) {data: [map], meta: map{limit: int(int64), offset: int(int64), total: int(int64)}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint POST /api/v2/rum/operations/strong_links\n@desc Create a RUM operation strong link\n@required {data: map{attributes!: map, type!: str} # The data object for creating a RUM operation strong link.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), description: str?, feature_id: str, operation_id: str, status: str, tags: [str], updated_at: str(date-time)?}, id: str, type: str}} # Created\n@errors {400: Bad Request, 404: Not Found. The referenced `operation_id` does not exist., 409: Conflict. A strong link between this operation and feature already exists., 429: Too many requests}\n\n@endpoint DELETE /api/v2/rum/operations/strong_links/{rum_operation_id}/{feature_id}\n@desc Delete a RUM operation strong link\n@required {rum_operation_id: str # The unique identifier of the RUM operation., feature_id: str # The unique identifier of the feature.}\n@returns(204) No Content\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/rum/operations/strong_links/{rum_operation_id}/{feature_id}\n@desc Update a RUM operation strong link\n@required {rum_operation_id: str # The unique identifier of the RUM operation., feature_id: str # The unique identifier of the feature., data: map{attributes!: map, type!: str} # The data object for updating a RUM operation strong link.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), description: str?, feature_id: str, operation_id: str, status: str, tags: [str], updated_at: str(date-time)?}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/rum/operations/{rum_operation_id}\n@desc Delete a RUM operation\n@required {rum_operation_id: str # The unique identifier of the RUM operation to delete.}\n@returns(204) No Content\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/rum/operations/{rum_operation_id}\n@desc Get a RUM operation\n@required {rum_operation_id: str # The unique identifier of the RUM operation.}\n@returns(200) {data: map{attributes: map{application_id: str(uuid)?, category: str?, created_at: str(date-time), created_by: map{email: str, handle: str, name: str, uuid: str}, description: str?, display_name: str, feature_ids: [str], journey_rum: map{rum_steps: [map]}, name: str, org_id: int(int64), tags: [str], updated_at: str(date-time)?, updated_by: map{email: str, handle: str, name: str, uuid: str}}, id: str, type: str}} # OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/rum/operations/{rum_operation_id}\n@desc Update a RUM operation\n@required {rum_operation_id: str # The unique identifier of the RUM operation to update., data: map{attributes!: map, id!: str, type!: str} # The data object for updating a RUM operation.}\n@returns(200) {data: map{attributes: map{application_id: str(uuid)?, category: str?, created_at: str(date-time), created_by: map{email: str, handle: str, name: str, uuid: str}, description: str?, display_name: str, feature_ids: [str], journey_rum: map{rum_steps: [map]}, name: str, org_id: int(int64), tags: [str], updated_at: str(date-time)?, updated_by: map{email: str, handle: str, name: str, uuid: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 409: Conflict. An operation with this name already exists., 429: Too many requests}\n\n@endpoint POST /api/v2/rum/query/insight/aggregated_long_tasks\n@desc Query aggregated long tasks\n@required {data: map{attributes!: map, type!: str} # Data envelope for an aggregated long tasks request.}\n@returns(201) {data: map{attributes: map{application_id: str, criteria: map{max: num(double), metric: str, min: num(double)}, from: int(int64), long_tasks_by_invoker_type: [map], sampled_view_ids: [str], to: int(int64), view_count: int(int32), view_name: str}, id: str, type: str}} # Successful response\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"application_id\":\"ccbc53b1-74f2-496b-bdd7-9a8fa7b7376b\",\"from\":1762437564,\"sample_size\":20,\"to\":1762523964,\"view_name\":\"/account/login(/:type)\"},\"type\":\"aggregated_long_tasks\"}}\n\n@endpoint POST /api/v2/rum/query/insight/aggregated_signals_problems\n@desc Query aggregated signals and problems\n@required {data: map{attributes!: map, type!: str} # Data envelope for an aggregated signals and problems request.}\n@returns(201) {data: map{attributes: map{application_id: str, criteria: map{max: num(double), metric: str, min: num(double)}, from: int(int64), problem_detections: map{high_frozen_frame_rates: [map], high_script_evaluations: [map], low_cache_hit_rates: [map], mobile_scroll_frictions: [map], slow_fcp_high_bytes: [map], slow_interaction_long_tasks: [map], uncompressed_resources: [map]}, sample_metadata: map{failed: int(int32), requested: int(int32), sampled_view_ids: [str], succeeded: int(int32), success_rate: num(double)}, to: int(int64), view_name: str}, id: str, type: str}} # Successful response\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"application_id\":\"ccbc53b1-74f2-496b-bdd7-9a8fa7b7376b\",\"from\":1762437564,\"sample_size\":30,\"to\":1762523964,\"view_name\":\"/account/login(/:type)\"},\"type\":\"aggregated_signals_problems\"}}\n\n@endpoint POST /api/v2/rum/query/insight/aggregated_waterfall\n@desc Query aggregated waterfall\n@required {data: map{attributes!: map, type!: str} # Data envelope for an aggregated waterfall request.}\n@returns(201) {data: map{attributes: map{application_id: str, criteria: map{max: num(double), metric: str, min: num(double)}, from: int(int64), resources: [map], sampled_view_ids: [str], to: int(int64), total_cache_hit_rate_pct: num(double), view_count: int(int32), view_name: str}, id: str, type: str}} # Successful response\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"application_id\":\"ccbc53b1-74f2-496b-bdd7-9a8fa7b7376b\",\"criteria\":{\"metric\":\"largest_contentful_paint\",\"min\":0.3},\"from\":1762437564,\"sample_size\":20,\"to\":1762523964,\"view_name\":\"/account/login(/:type)\"},\"type\":\"aggregated_waterfall\"}}\n\n@endpoint GET /api/v2/rum/replay/playlists\n@desc List RUM replay playlists\n@optional {filter[created_by_uuid]: str: any # Filter playlists by the UUID of the user who created them., filter[query]: str # Search query to filter playlists by name., page[number]: int(int64) # Page number for pagination (0-indexed)., page[size]: int(int64) # Number of items per page.}\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/rum/replay/playlists\n@desc Create RUM replay playlist\n@required {data: map{attributes: map, id: str, type!: str} # Data object representing a RUM replay playlist, including its identifier, type, and attributes.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), created_by: map{handle: str, icon: str, id: str, name: str, uuid: str}, description: str, name: str, session_count: int(int64), updated_at: str(date-time)}, id: str, type: str}} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"created_by\":{\"handle\":\"john.doe@example.com\",\"id\":\"00000000-0000-0000-0000-000000000001\",\"uuid\":\"00000000-0000-0000-0000-000000000001\"},\"name\":\"My Playlist\"},\"type\":\"rum_replay_playlist\"}}\n\n@endpoint DELETE /api/v2/rum/replay/playlists/{playlist_id}\n@desc Delete RUM replay playlist\n@required {playlist_id: int(int64) # Unique identifier of the playlist.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/rum/replay/playlists/{playlist_id}\n@desc Get RUM replay playlist\n@required {playlist_id: int(int64) # Unique identifier of the playlist.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: map{handle: str, icon: str, id: str, name: str, uuid: str}, description: str, name: str, session_count: int(int64), updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint PUT /api/v2/rum/replay/playlists/{playlist_id}\n@desc Update RUM replay playlist\n@required {playlist_id: int(int64) # Unique identifier of the playlist., data: map{attributes: map, id: str, type!: str} # Data object representing a RUM replay playlist, including its identifier, type, and attributes.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: map{handle: str, icon: str, id: str, name: str, uuid: str}, description: str, name: str, session_count: int(int64), updated_at: str(date-time)}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"created_by\":{\"handle\":\"john.doe@example.com\",\"id\":\"00000000-0000-0000-0000-000000000001\",\"uuid\":\"00000000-0000-0000-0000-000000000001\"},\"name\":\"My Playlist\"},\"type\":\"rum_replay_playlist\"}}\n\n@endpoint DELETE /api/v2/rum/replay/playlists/{playlist_id}/sessions\n@desc Bulk remove RUM replay playlist sessions\n@required {playlist_id: int(int64) # Unique identifier of the playlist., data: [map{id: str, type!: str}] # Array of session identifier data objects.}\n@returns(204) No Content\n@errors {429: Too many requests}\n@example_request {\"data\":[{\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"rum_replay_session\"}]}\n\n@endpoint GET /api/v2/rum/replay/playlists/{playlist_id}/sessions\n@desc List RUM replay playlist sessions\n@required {playlist_id: int(int64) # Unique identifier of the playlist.}\n@optional {page[number]: int(int64): any # Page number for pagination (0-indexed)., page[size]: int(int64) # Number of items per page.}\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint DELETE /api/v2/rum/replay/playlists/{playlist_id}/sessions/{session_id}\n@desc Remove RUM replay session from playlist\n@required {playlist_id: int(int64) # Unique identifier of the playlist., session_id: str # Unique identifier of the session.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint PUT /api/v2/rum/replay/playlists/{playlist_id}/sessions/{session_id}\n@desc Add RUM replay session to playlist\n@required {ts: int(int64) # Server-side timestamp in milliseconds., playlist_id: int(int64) # Unique identifier of the playlist., session_id: str # Unique identifier of the session.}\n@optional {data_source: str # Data source type. Valid values: 'rum' or 'product_analytics'. Defaults to 'rum'.}\n@returns(200) {data: map{attributes: map{session_event: map, track: str}, id: str, type: str}} # OK\n@returns(201) {data: map{attributes: map{session_event: map, track: str}, id: str, type: str}} # Created\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/rum/replay/sessions/{session_id}/views/{view_id}/segments\n@desc Get segments\n@required {view_id: str # Unique identifier of the view., session_id: str # Unique identifier of the session.}\n@optional {source: str # Storage source: 'event_platform' or 'blob'., ts: int(int64) # Server-side timestamp in milliseconds., max_list_size: int(int64) # Maximum size in bytes for the segment list., paging: str # Paging token for pagination.}\n@returns(200) OK\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/rum/replay/sessions/{session_id}/watchers\n@desc List RUM replay session watchers\n@required {session_id: str # Unique identifier of the session.}\n@optional {page[size]: int(int64): any # Number of items per page., page[number]: int(int64) # Page number for pagination (0-indexed).}\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint DELETE /api/v2/rum/replay/sessions/{session_id}/watches\n@desc Delete RUM replay session watch\n@required {session_id: str # Unique identifier of the session.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/rum/replay/sessions/{session_id}/watches\n@desc Create RUM replay session watch\n@required {session_id: str # Unique identifier of the session., data: map{attributes: map, id: str, type!: str} # Data object representing a session watch record, including its identifier, type, and attributes.}\n@returns(201) {data: map{attributes: map{application_id: str, data_source: str, event_id: str, timestamp: str(date-time)}, id: str, type: str}} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"application_id\":\"aaaaaaaa-1111-2222-3333-bbbbbbbbbbbb\",\"event_id\":\"11111111-2222-3333-4444-555555555555\",\"timestamp\":\"2026-01-13T17:15:53.208340Z\"},\"type\":\"rum_replay_watch\"}}\n\n@endpoint GET /api/v2/rum/replay/viewership-history/sessions\n@desc List RUM replay viewership history sessions\n@optional {filter[watched_at][start]: int(int64): any # Start timestamp in milliseconds for watched_at filter., page[number]: int(int64) # Page number for pagination (0-indexed)., filter[created_by]: str # Filter by user UUID. Defaults to current user if not specified., filter[watched_at][end]: int(int64) # End timestamp in milliseconds for watched_at filter., filter[session_ids]: str # Comma-separated list of session IDs to filter by., page[size]: int(int64) # Number of items per page., filter[application_id]: str # Filter by application ID.}\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/saml_configurations\n@desc List SAML configurations\n@returns(200) {data: [map], included: [map]} # OK\n@errors {403: Authentication Error, 429: Too many requests}\n\n@endpoint POST /api/v2/saml_configurations/idp_metadata\n@desc Upload IdP metadata\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/saml_configurations/{saml_config_uuid}\n@desc Get a SAML configuration\n@required {saml_config_uuid: str # The UUID of the SAML configuration.}\n@returns(200) {data: map{attributes: map{assertion_consumer_service: [str], created_at: str(date-time), entity_id: str, expires_at: str(date-time)?, idp_initiated: bool, jit_domains: [str], modified_at: str(date-time), sso_url: str?}, id: str, relationships: map{default_roles: map{data: [map]}}, type: str}, included: [map]} # OK\n@errors {403: Authentication Error, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/saml_configurations/{saml_config_uuid}\n@desc Update a SAML configuration\n@required {saml_config_uuid: str # The UUID of the SAML configuration., data: map{attributes: map, id!: str, relationships: map, type!: str} # Data for updating a SAML configuration.}\n@returns(200) {data: map{attributes: map{assertion_consumer_service: [str], created_at: str(date-time), entity_id: str, expires_at: str(date-time)?, idp_initiated: bool, jit_domains: [str], modified_at: str(date-time), sso_url: str?}, id: str, relationships: map{default_roles: map{data: [map]}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 403: Authentication Error, 404: Not Found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"idp_initiated\":true,\"jit_domains\":[\"example.com\"]},\"id\":\"3653d3c6-0c75-11ea-ad28-fb5701eabc7d\",\"relationships\":{\"default_roles\":{\"data\":[{\"id\":\"8dd1cf3c-0c75-11ea-ad28-fb5701eabc7d\",\"type\":\"roles\"}]}},\"type\":\"saml_configurations\"}}\n\n@endpoint GET /api/v2/scorecard/campaigns\n@desc List all campaigns\n@optional {page[limit]: int(int64)=10: any # Maximum number of campaigns to return., page[offset]: int(int64)=0 # Offset for pagination., filter[campaign][name]: str # Filter campaigns by name (full-text search)., filter[campaign][status]: str # Filter campaigns by status., filter[campaign][owner]: str # Filter campaigns by owner UUID.}\n@returns(200) {data: [map], meta: map{count: int(int64), limit: int(int64), offset: int(int64), total: int(int64)}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/scorecard/campaigns\n@desc Create a new campaign\n@required {data: map{attributes!: map, type!: str} # Data for creating a new campaign.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), description: str, due_date: str(date-time), entity_scope: str, guidance: str, key: str, modified_at: str(date-time), name: str, owner: str, start_date: str(date-time), status: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Campaign to improve security posture for Q1 2024.\",\"due_date\":\"2024-03-31T23:59:59Z\",\"entity_scope\":\"kind:service AND team:platform\",\"guidance\":\"Please ensure all services pass the security requirements.\",\"key\":\"q1-security-2024\",\"name\":\"Q1 Security Campaign\",\"owner_id\":\"550e8400-e29b-41d4-a716-446655440000\",\"rule_ids\":[\"q8MQxk8TCqrHnWkx\",\"r9NRyl9UDrsIoXly\"],\"start_date\":\"2024-01-01T00:00:00Z\",\"status\":\"in_progress\"},\"type\":\"campaign\"}}\n\n@endpoint DELETE /api/v2/scorecard/campaigns/{campaign_id}\n@desc Delete a campaign\n@required {campaign_id: str # Campaign ID or key.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/scorecard/campaigns/{campaign_id}\n@desc Get a campaign\n@required {campaign_id: str # Campaign ID or key.}\n@optional {include: str # Include related data (for example, scores)., include_meta: bool # Include metadata (entity and rule counts).}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), description: str, due_date: str(date-time), entity_scope: str, guidance: str, key: str, modified_at: str(date-time), name: str, owner: str, start_date: str(date-time), status: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/scorecard/campaigns/{campaign_id}\n@desc Update a campaign\n@required {campaign_id: str # Campaign ID or key., data: map{attributes!: map, type!: str} # Data for updating a campaign.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), description: str, due_date: str(date-time), entity_scope: str, guidance: str, key: str, modified_at: str(date-time), name: str, owner: str, start_date: str(date-time), status: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Campaign to improve security posture for Q1 2024.\",\"due_date\":\"2024-03-31T23:59:59Z\",\"entity_scope\":\"kind:service AND team:platform\",\"guidance\":\"Please ensure all services pass the security requirements.\",\"key\":\"q1-security-2024\",\"name\":\"Q1 Security Campaign\",\"owner_id\":\"550e8400-e29b-41d4-a716-446655440000\",\"rule_ids\":[\"q8MQxk8TCqrHnWkx\",\"r9NRyl9UDrsIoXly\"],\"start_date\":\"2024-01-01T00:00:00Z\",\"status\":\"in_progress\"},\"type\":\"campaign\"}}\n\n@endpoint GET /api/v2/scorecard/outcomes\n@desc List all rule outcomes\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[offset]: int(int64)=0 # Specific offset to use as the beginning of the returned page., include: str # Include related rule details in the response., fields[outcome]: str # Return only specified values in the outcome attributes., fields[rule]: str # Return only specified values in the included rule details., filter[outcome][service_name]: str # Filter outcomes on a specific service name., filter[outcome][state]: str # Filter outcomes by a specific state., filter[rule][enabled]: bool # Filter outcomes based on whether a rule is enabled or disabled., filter[rule][id]: str # Filter outcomes based on rule ID., filter[rule][name]: str # Filter outcomes based on rule name.}\n@returns(200) {data: [map], included: [map], links: map{next: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/scorecard/outcomes\n@desc Update Scorecard outcomes\n@optional {data: map{attributes: map, type: str} # Scorecard outcomes batch request data.}\n@returns(202) Accepted\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"results\":[{\"entity_reference\":\"service:my-service\",\"remarks\":\"See: <a href=\\\"https://app.datadoghq.com/services\\\">Services</a>\",\"rule_id\":\"q8MQxk8TCqrHnWkx\",\"state\":\"pass\"}]},\"type\":\"batched-outcome\"}}\n\n@endpoint POST /api/v2/scorecard/outcomes/batch\n@desc Create outcomes batch\n@optional {data: map{attributes: map, type: str} # Scorecard outcomes batch request data.}\n@returns(200) {data: [map], meta: map{total_received: int(int64), total_updated: int(int64)}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"results\":[{\"remarks\":\"See: <a href=\\\"https://app.datadoghq.com/services\\\">Services</a>\",\"rule_id\":\"q8MQxk8TCqrHnWkx\",\"service_name\":\"my-service\",\"state\":\"pass\"}]},\"type\":\"batched-outcome\"}}\n\n@endpoint GET /api/v2/scorecard/rules\n@desc List all rules\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[offset]: int(int64)=0 # Specific offset to use as the beginning of the returned page., include: str # Include related scorecard details in the response., filter[rule][id]: str # Filter the rules on a rule ID., filter[rule][enabled]: bool # Filter for enabled rules only., filter[rule][custom]: bool # Filter for custom rules only., filter[rule][name]: str # Filter rules on the rule name., filter[rule][description]: str # Filter rules on the rule description., fields[rule]: str # Return only specific fields in the response for rule attributes., fields[scorecard]: str # Return only specific fields in the included response for scorecard attributes.}\n@returns(200) {data: [map], links: map{next: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/scorecard/rules\n@desc Create a new rule\n@optional {data: map{attributes: map, type: str} # Scorecard create rule request data.}\n@returns(201) {data: map{attributes: map{category: str, created_at: str(date-time), custom: bool, description: str, enabled: bool, level: int(int32), modified_at: str(date-time), name: str, owner: str, scope_query: str, scorecard_name: str}, id: str, relationships: map{scorecard: map{data: map}}, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"name\":\"My Rule\",\"owner\":\"Datadog\",\"scorecard_name\":\"My Scorecard\"},\"type\":\"rule\"}}\n\n@endpoint DELETE /api/v2/scorecard/rules/{rule_id}\n@desc Delete a rule\n@required {rule_id: str # The ID of the rule.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/scorecard/rules/{rule_id}\n@desc Update an existing scorecard rule\n@required {rule_id: str # The ID of the rule.}\n@optional {data: map{attributes: map, type: str} # Data for the request to update a scorecard rule.}\n@returns(200) {data: map{attributes: map{category: str, created_at: str(date-time), custom: bool, description: str, enabled: bool, level: int(int32), modified_at: str(date-time), name: str, owner: str, scope_query: str, scorecard_name: str}, id: str, relationships: map{scorecard: map{data: map}}, type: str}} # Rule updated successfully\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Updated Description\",\"enabled\":false,\"name\":\"Updated Rule\",\"owner\":\"team:updated-team\",\"scope_query\":\"kind:service\",\"scorecard_name\":\"Updated Scorecard\"},\"type\":\"rule\"}}\n\n@endpoint GET /api/v2/scorecard/scorecards\n@desc List all scorecards\n@optional {page[offset]: int(int64)=0: any # Offset for pagination., page[size]: int(int64)=100 # Maximum number of scorecards to return., filter[scorecard][id]: str # Filter by scorecard ID., filter[scorecard][name]: str # Filter by scorecard name (partial match)., filter[scorecard][description]: str # Filter by scorecard description (partial match).}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/scorecard/scores/{aggregation}\n@desc List all scores\n@required {aggregation: str # The type of scores being requested.}\n@optional {filter[rule][id]: str: any # Filter scores by rule ID(s), comma-separated., filter[rule][name]: str # Filter scores by rule name., filter[rule][level]: str # Filter scores by rule level(s), comma-separated., filter[rule][scorecard_id]: str # Filter scores by scorecard ID(s), comma-separated., filter[rule][is_custom]: bool # Filter scores to show only custom rules., filter[rule][is_enabled]: bool # Filter scores to show only enabled rules., sort: str # Sort scores by field. Use a hyphen prefix for descending order. Options: score, numerator, denominator, total_pass, total_fail, total_skip, total_no_data., page[offset]: int(int64)=0 # Offset for pagination., page[limit]: int(int64)=100 # Number of scores to return. Max is 1000.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{count: int(int64), limit: int(int64), offset: int(int64), total: int(int64)}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint DELETE /api/v2/seats/users\n@desc Unassign seats from users\n@optional {data: map{attributes!: map, id: str, type!: str} # The request data object containing attributes for unassigning seats from users.}\n@returns(204) No Content\n@errors {400: Bad Request, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"product_code\":\"\",\"user_uuids\":[\"626a4e8e-64bd-409d-b80e-428f08ac0b62\"]},\"type\":\"seat-assignments\"}}\n\n@endpoint GET /api/v2/seats/users\n@desc Get users with seats\n@required {product_code: str # The product code for which to retrieve seat users.}\n@optional {page[limit]: int(int64): any # Maximum number of results to return., page[cursor]: str # Cursor for pagination.}\n@returns(200) {data: [map], meta: map{cursor: str, limit: int(int64), next_cursor: str}} # OK\n@errors {400: Bad Request, 422: Unprocessable Entity, 429: Too many requests}\n\n@endpoint POST /api/v2/seats/users\n@desc Assign seats to users\n@optional {data: map{attributes!: map, id: str, type!: str} # The request data object containing attributes for assigning seats to users.}\n@returns(201) {data: map{attributes: map{assigned_ids: [str], product_code: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"product_code\":\"\",\"user_uuids\":[\"\"]},\"type\":\"seat-assignments\"}}\n\n@endpoint GET /api/v2/security-entities/risk-scores\n@desc List Entity Risk Scores\n@optional {from: int(int64) # Start time for the query in Unix timestamp (milliseconds). Defaults to 2 weeks ago., to: int(int64) # End time for the query in Unix timestamp (milliseconds). Defaults to now., page[size]: int(int64)=10 # Size of the page to return. Maximum is 1000., page[number]: int(int64)=1 # Page number to return (1-indexed)., page[queryId]: str # Query ID for pagination consistency., filter[sort]: str # Sort order for results. Format: `field:direction` where direction is `asc` or `desc`. Supported fields: `riskScore`, `lastDetected`, `firstDetected`, `entityName`, `signalsDetected`., filter[query]: str # Supports filtering by entity attributes, risk scores, severity, and more. Example: `severity:critical AND entityType:aws_iam_user`, entityType: [str] # Filter by entity type(s). Can specify multiple values.}\n@returns(200) {data: [map], meta: map{pageNumber: int(int64), pageSize: int(int64), queryId: str, totalRowCount: int(int64)}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/security-entities/risk-scores/{entity_id}\n@desc Get Entity Risk Score\n@required {entity_id: str # The URL-encoded unique identifier for the entity.}\n@returns(200) {data: map{attributes: map{accountIds: [str], configRisks: map{hasIdentityRisk: bool, hasMisconfiguration: bool, hasPrivilegedRole: bool, isPrivileged: bool, isProduction: bool, isPubliclyAccessible: bool}, entityMetadata: map{accountID: str, environments: [str], mitreTactics: [str], mitreTechniques: [str], projectID: str, services: [str], sources: [str], subscriptionID: str}, entityName: str, entityProviders: [str], entityRoles: [str], entitySubTypes: [str], entityType: str, entityTypes: [str], firstDetected: int(int64), lastActivityTitle: str, lastDetected: int(int64), riskScore: int(int64), riskScoreEvolution: int(int64), severity: str, signalsDetected: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security/asm/services/{service_filter}\n@desc Get Application Security details for a service\n@required {service_filter: str # The name of the service to retrieve Application Security details for. Returns all matching services across environments.}\n@returns(200) {data: [map], meta: map{num_services_with_appsec: int(int64)}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/security/cloud_workload/policy/download\n@desc Download the Workload Protection policy (US1-FED)\n@returns(200) OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/security/findings\n@desc List security findings\n@optional {filter[query]: str=*: any # The search query following log search syntax., page[cursor]: str # Get the next page of results with a cursor provided in the previous query., page[limit]: int(int64)=10 # The maximum number of findings in the response., sort: str # Sorts by @detection_changed_at.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security/findings/assignee\n@desc Assign or unassign security findings\n@required {data: map{attributes: map, id: str, relationships!: map, type!: str} # Data of the assignee request.}\n@returns(202) {data: map{attributes: map{assignee_id: str}, id: str, type: str}, meta: map{failures: [map], warnings: [map]}} # Accepted\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assignee_id\":\"f315bdaf-9ee7-4808-a9c1-99c15bf0f4d0\"},\"id\":\"00000000-0000-0000-0000-000000000001\",\"relationships\":{\"findings\":{\"data\":[{\"id\":\"ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw==\",\"type\":\"findings\"}]}},\"type\":\"assignee\"}}\n\n@endpoint GET /api/v2/security/findings/automation/due_date_rules\n@desc Get all due date rules\n@optional {page[size]: int(int64)=1000: any # The number of rules per page. Maximum is 1000., page[number]: int(int64)=0 # The page number to return.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str, prev: str}, meta: map{page: map{total_filtered_count: int(int64)}}} # Successfully retrieved the list of due date rules\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/security/findings/automation/due_date_rules\n@desc Create a due date rule\n@required {data: map{attributes!: map, type!: str} # The data object for a due date rule create or update request.}\n@returns(201) {data: map{attributes: map{action: map{due_days_per_severity: [map], due_from: str, reason_description: str}, created_at: int(int64), created_by: map{id: str, name: str, type: str}, enabled: bool, modified_at: int(int64), modified_by: map{id: str, name: str, type: str}, name: str, rule: map{finding_types: [str], query: str}}, id: str(uuid), type: str}} # Successfully created the due date rule\n@errors {400: Bad Request, 403: Forbidden, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":{\"due_days_per_severity\":[{\"due_in_days\":7,\"severity\":\"critical\"},{\"due_in_days\":30,\"severity\":\"high\"}],\"due_from\":\"first_seen\"},\"enabled\":true,\"name\":\"Critical findings due in 7 days\",\"rule\":{\"finding_types\":[\"misconfiguration\"],\"query\":\"env:prod\"}},\"type\":\"due_date_rules\"}}\n\n@endpoint POST /api/v2/security/findings/automation/due_date_rules/reorder\n@desc Reorder due date rules\n@required {data: [map{id!: str(uuid), type!: str}] # The ordered list of all due date rules; every rule must be included.}\n@returns(200) {data: [map]} # Successfully reordered the due date rules\n@errors {400: Bad Request, 403: Forbidden, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":[{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"due_date_rules\"},{\"id\":\"11111111-1111-1111-1111-111111111111\",\"type\":\"due_date_rules\"}]}\n\n@endpoint DELETE /api/v2/security/findings/automation/due_date_rules/{rule_id}\n@desc Delete a due date rule\n@required {rule_id: str(uuid) # The ID of the due date rule.}\n@returns(204) Rule successfully deleted.\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security/findings/automation/due_date_rules/{rule_id}\n@desc Get a due date rule\n@required {rule_id: str(uuid) # The ID of the due date rule.}\n@returns(200) {data: map{attributes: map{action: map{due_days_per_severity: [map], due_from: str, reason_description: str}, created_at: int(int64), created_by: map{id: str, name: str, type: str}, enabled: bool, modified_at: int(int64), modified_by: map{id: str, name: str, type: str}, name: str, rule: map{finding_types: [str], query: str}}, id: str(uuid), type: str}} # Successfully retrieved the due date rule\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/security/findings/automation/due_date_rules/{rule_id}\n@desc Update a due date rule\n@required {rule_id: str(uuid) # The ID of the due date rule., data: map{attributes!: map, type!: str} # The data object for a due date rule create or update request.}\n@returns(200) {data: map{attributes: map{action: map{due_days_per_severity: [map], due_from: str, reason_description: str}, created_at: int(int64), created_by: map{id: str, name: str, type: str}, enabled: bool, modified_at: int(int64), modified_by: map{id: str, name: str, type: str}, name: str, rule: map{finding_types: [str], query: str}}, id: str(uuid), type: str}} # Successfully updated the due date rule\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":{\"due_days_per_severity\":[{\"due_in_days\":7,\"severity\":\"critical\"},{\"due_in_days\":30,\"severity\":\"high\"},{\"due_in_days\":90,\"severity\":\"medium\"}],\"due_from\":\"fix_available\"},\"enabled\":true,\"name\":\"Critical findings due in 7 days\",\"rule\":{\"finding_types\":[\"misconfiguration\"],\"query\":\"env:prod\"}},\"type\":\"due_date_rules\"}}\n\n@endpoint GET /api/v2/security/findings/automation/mute_rules\n@desc Get all mute rules\n@optional {page[size]: int(int64)=1000: any # The number of rules per page. Maximum is 1000., page[number]: int(int64)=0 # The page number to return.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str, prev: str}, meta: map{page: map{total_filtered_count: int(int64)}}} # Successfully retrieved the list of mute rules\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/security/findings/automation/mute_rules\n@desc Create a mute rule\n@required {data: map{attributes!: map, type!: str} # The data object for a mute rule create or update request.}\n@returns(201) {data: map{attributes: map{action: map{expire_at: int(int64), reason: str, reason_description: str}, created_at: int(int64), created_by: map{id: str, name: str, type: str}, enabled: bool, modified_at: int(int64), modified_by: map{id: str, name: str, type: str}, name: str, rule: map{finding_types: [str], query: str}}, id: str(uuid), type: str}} # Successfully created the mute rule\n@errors {400: Bad Request, 403: Forbidden, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":{\"expire_at\":4070908800000,\"reason\":\"risk_accepted\",\"reason_description\":\"Accepted for dev environments only\"},\"enabled\":true,\"name\":\"Mute accepted risks in dev\",\"rule\":{\"finding_types\":[\"misconfiguration\"],\"query\":\"env:dev team:platform @severity:low\"}},\"type\":\"mute_rules\"}}\n\n@endpoint POST /api/v2/security/findings/automation/mute_rules/reorder\n@desc Reorder mute rules\n@required {data: [map{id!: str(uuid), type!: str}] # The ordered list of all mute rules; every rule must be included.}\n@returns(200) {data: [map]} # Successfully reordered the mute rules\n@errors {400: Bad Request, 403: Forbidden, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":[{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"mute_rules\"},{\"id\":\"11111111-1111-1111-1111-111111111111\",\"type\":\"mute_rules\"}]}\n\n@endpoint DELETE /api/v2/security/findings/automation/mute_rules/{rule_id}\n@desc Delete a mute rule\n@required {rule_id: str(uuid) # The ID of the mute rule.}\n@returns(204) Rule successfully deleted.\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security/findings/automation/mute_rules/{rule_id}\n@desc Get a mute rule\n@required {rule_id: str(uuid) # The ID of the mute rule.}\n@returns(200) {data: map{attributes: map{action: map{expire_at: int(int64), reason: str, reason_description: str}, created_at: int(int64), created_by: map{id: str, name: str, type: str}, enabled: bool, modified_at: int(int64), modified_by: map{id: str, name: str, type: str}, name: str, rule: map{finding_types: [str], query: str}}, id: str(uuid), type: str}} # Successfully retrieved the mute rule\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/security/findings/automation/mute_rules/{rule_id}\n@desc Update a mute rule\n@required {rule_id: str(uuid) # The ID of the mute rule., data: map{attributes!: map, type!: str} # The data object for a mute rule create or update request.}\n@returns(200) {data: map{attributes: map{action: map{expire_at: int(int64), reason: str, reason_description: str}, created_at: int(int64), created_by: map{id: str, name: str, type: str}, enabled: bool, modified_at: int(int64), modified_by: map{id: str, name: str, type: str}, name: str, rule: map{finding_types: [str], query: str}}, id: str(uuid), type: str}} # Successfully updated the mute rule\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":{\"reason\":\"risk_accepted\"},\"enabled\":false,\"name\":\"Mute accepted risks in dev\",\"rule\":{\"finding_types\":[\"misconfiguration\"],\"query\":\"env:dev\"}},\"type\":\"mute_rules\"}}\n\n@endpoint GET /api/v2/security/findings/automation/ticket_creation_rules\n@desc Get all ticket creation rules\n@optional {page[size]: int(int64)=1000: any # The number of rules per page. Maximum is 1000., page[number]: int(int64)=0 # The page number to return.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str, prev: str}, meta: map{page: map{total_filtered_count: int(int64)}}} # Successfully retrieved the list of ticket creation rules\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/security/findings/automation/ticket_creation_rules\n@desc Create a ticket creation rule\n@required {data: map{attributes!: map, type!: str} # The data object for a ticket creation rule create or update request.}\n@returns(201) {data: map{attributes: map{action: map{assignee_id: str(uuid), auto_disabled_reason: str, fields: map, max_tickets_per_day: int(int64), project_id: str(uuid), target: str}, created_at: int(int64), created_by: map{id: str, name: str, type: str}, enabled: bool, modified_at: int(int64), modified_by: map{id: str, name: str, type: str}, name: str, rule: map{finding_types: [str], query: str}}, id: str(uuid), type: str}} # Successfully created the ticket creation rule\n@errors {400: Bad Request, 403: Forbidden, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":{\"max_tickets_per_day\":100,\"project_id\":\"11111111-1111-1111-1111-111111111111\",\"target\":\"jira\"},\"enabled\":true,\"name\":\"Auto-create Jira tickets for critical findings\",\"rule\":{\"finding_types\":[\"misconfiguration\"],\"query\":\"env:prod\"}},\"type\":\"ticket_creation_rules\"}}\n\n@endpoint POST /api/v2/security/findings/automation/ticket_creation_rules/reorder\n@desc Reorder ticket creation rules\n@required {data: [map{id!: str(uuid), type!: str}] # The ordered list of all ticket creation rules; every rule must be included.}\n@returns(200) {data: [map]} # Successfully reordered the ticket creation rules\n@errors {400: Bad Request, 403: Forbidden, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":[{\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"ticket_creation_rules\"},{\"id\":\"11111111-1111-1111-1111-111111111111\",\"type\":\"ticket_creation_rules\"}]}\n\n@endpoint DELETE /api/v2/security/findings/automation/ticket_creation_rules/{rule_id}\n@desc Delete a ticket creation rule\n@required {rule_id: str(uuid) # The ID of the ticket creation rule.}\n@returns(204) Rule successfully deleted.\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security/findings/automation/ticket_creation_rules/{rule_id}\n@desc Get a ticket creation rule\n@required {rule_id: str(uuid) # The ID of the ticket creation rule.}\n@returns(200) {data: map{attributes: map{action: map{assignee_id: str(uuid), auto_disabled_reason: str, fields: map, max_tickets_per_day: int(int64), project_id: str(uuid), target: str}, created_at: int(int64), created_by: map{id: str, name: str, type: str}, enabled: bool, modified_at: int(int64), modified_by: map{id: str, name: str, type: str}, name: str, rule: map{finding_types: [str], query: str}}, id: str(uuid), type: str}} # Successfully retrieved the ticket creation rule\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/security/findings/automation/ticket_creation_rules/{rule_id}\n@desc Update a ticket creation rule\n@required {rule_id: str(uuid) # The ID of the ticket creation rule., data: map{attributes!: map, type!: str} # The data object for a ticket creation rule create or update request.}\n@returns(200) {data: map{attributes: map{action: map{assignee_id: str(uuid), auto_disabled_reason: str, fields: map, max_tickets_per_day: int(int64), project_id: str(uuid), target: str}, created_at: int(int64), created_by: map{id: str, name: str, type: str}, enabled: bool, modified_at: int(int64), modified_by: map{id: str, name: str, type: str}, name: str, rule: map{finding_types: [str], query: str}}, id: str(uuid), type: str}} # Successfully updated the ticket creation rule\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"action\":{\"max_tickets_per_day\":50,\"project_id\":\"11111111-1111-1111-1111-111111111111\",\"target\":\"jira\"},\"enabled\":true,\"name\":\"Auto-create Jira tickets for critical findings\",\"rule\":{\"finding_types\":[\"misconfiguration\"],\"query\":\"env:prod\"}},\"type\":\"ticket_creation_rules\"}}\n\n@endpoint DELETE /api/v2/security/findings/cases\n@desc Detach security findings from their case\n@optional {data: map{relationships: map, type!: str} # Data for detaching security findings from their case.}\n@returns(204) No Content\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"relationships\":{\"findings\":{\"data\":[{\"id\":\"ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw==\",\"type\":\"findings\"}]}},\"type\":\"cases\"}}\n\n@endpoint POST /api/v2/security/findings/cases\n@desc Create cases for security findings\n@required {data: [map{attributes: map, relationships: map, type!: str}] # Array of case creation request data objects.}\n@returns(201) {data: [map]} # Created\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":[{\"attributes\":{\"assignee_id\":\"f315bdaf-9ee7-4808-a9c1-99c15bf0f4d0\",\"description\":\"A description of the case.\",\"priority\":\"NOT_DEFINED\",\"title\":\"A title for the case.\"},\"relationships\":{\"findings\":{\"data\":[{\"id\":\"YjdhNDM3N2QyNTFjYmUwYTY3NDdhMTg0YTk2Yjg5MDl-ZjNmMzAwOTFkZDNhNGQzYzI0MzgxNTk4MjRjZmE2NzE=\",\"type\":\"findings\"}]},\"project\":{\"data\":{\"id\":\"aeadc05e-98a8-11ec-ac2c-da7ad0900001\"}}},\"type\":\"cases\"}]}\n\n@endpoint PATCH /api/v2/security/findings/cases/{case_id}\n@desc Attach security findings to a case\n@required {case_id: str # Unique identifier of the case to attach security findings to}\n@optional {data: map{id!: str, relationships: map, type!: str} # Data of the case to attach security findings to.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time), assigned_to: map{data: map}, attributes: map, closed_at: str(date-time), created_at: str(date-time), creation_source: str, description: str, due_date: str, insights: [map], jira_issue: map{error_message: str, result: map, status: str}, key: str, linear_issue: map{error_message: str, result: map, status: str}, modified_at: str(date-time), priority: str, servicenow_ticket: map{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str}, id: str, relationships: map{created_by: map{data: map}, modified_by: map{data: map}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"c1234567-89ab-cdef-0123-456789abcdef\",\"relationships\":{\"findings\":{\"data\":[{\"id\":\"ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw==\"}]}},\"type\":\"cases\"}}\n\n@endpoint PATCH /api/v2/security/findings/jira_issues\n@desc Attach security findings to a Jira issue\n@optional {data: map{attributes: map, relationships: map, type!: str} # Data of the Jira issue to attach security findings to.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time), assigned_to: map{data: map}, attributes: map, closed_at: str(date-time), created_at: str(date-time), creation_source: str, description: str, due_date: str, insights: [map], jira_issue: map{error_message: str, result: map, status: str}, key: str, linear_issue: map{error_message: str, result: map, status: str}, modified_at: str(date-time), priority: str, servicenow_ticket: map{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str}, id: str, relationships: map{created_by: map{data: map}, modified_by: map{data: map}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"jira_issue_url\":\"https://datadoghq-sandbox-538.atlassian.net/browse/CSMSEC-105476\"},\"relationships\":{\"findings\":{\"data\":[{\"id\":\"ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw==\"}]},\"project\":{\"data\":{\"id\":\"aeadc05e-98a8-11ec-ac2c-da7ad0900001\",\"type\":\"projects\"}}},\"type\":\"jira_issues\"}}\n\n@endpoint POST /api/v2/security/findings/jira_issues\n@desc Create Jira issues for security findings\n@required {data: [map{attributes: map, relationships: map, type!: str}] # Array of Jira issue creation request data objects.}\n@returns(201) {data: [map]} # Created\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":[{\"attributes\":{\"assignee_id\":\"f315bdaf-9ee7-4808-a9c1-99c15bf0f4d0\",\"description\":\"A description of the Jira issue.\",\"fields\":{\"key1\":\"value\",\"key2\":[\"value\"],\"key3\":{\"key4\":\"value\"}},\"priority\":\"NOT_DEFINED\",\"title\":\"A title for the Jira issue.\"},\"relationships\":{\"project\":{\"data\":{\"id\":\"aeadc05e-98a8-11ec-ac2c-da7ad0900001\"}}},\"type\":\"jira_issues\"}]}\n\n@endpoint PATCH /api/v2/security/findings/linear_issues\n@desc Attach security findings to a Linear issue\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Data of the Linear issue to attach security findings to.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time), assigned_to: map{data: map}, attributes: map, closed_at: str(date-time), created_at: str(date-time), creation_source: str, description: str, due_date: str, insights: [map], jira_issue: map{error_message: str, result: map, status: str}, key: str, linear_issue: map{error_message: str, result: map, status: str}, modified_at: str(date-time), priority: str, servicenow_ticket: map{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str}, id: str, relationships: map{created_by: map{data: map}, modified_by: map{data: map}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"linear_issue_url\":\"https://linear.app/your-workspace/issue/ENG-123\"},\"relationships\":{\"findings\":{\"data\":[{\"id\":\"ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw==\",\"type\":\"findings\"}]},\"project\":{\"data\":{\"id\":\"aeadc05e-98a8-11ec-ac2c-da7ad0900001\",\"type\":\"projects\"}}},\"type\":\"linear_issues\"}}\n\n@endpoint POST /api/v2/security/findings/linear_issues\n@desc Create Linear issues for security findings\n@required {data: [map{attributes: map, relationships: map, type!: str}] # Array of Linear issue creation request data objects.}\n@returns(201) {data: [map]} # Created\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":[{\"attributes\":{\"assignee_id\":\"f315bdaf-9ee7-4808-a9c1-99c15bf0f4d0\",\"description\":\"A description of the Linear issue.\",\"label_ids\":[\"a1b2c3d4-5e6f-7a8b-9c0d-1e2f3a4b5c6d\"],\"linear_project_id\":\"d4c3b2a1-6f5e-8b7a-0d9c-2f1e4a3b6c5d\",\"priority\":\"NOT_DEFINED\",\"title\":\"A title for the Linear issue.\"},\"relationships\":{\"findings\":{\"data\":[{\"id\":\"ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw==\",\"type\":\"findings\"}]},\"project\":{\"data\":{\"id\":\"aeadc05e-98a8-11ec-ac2c-da7ad0900001\",\"type\":\"projects\"}}},\"type\":\"linear_issues\"}]}\n\n@endpoint PATCH /api/v2/security/findings/mute\n@desc Mute or unmute security findings\n@required {data: map{attributes!: map, id: str, relationships!: map, type!: str} # Data of the mute request.}\n@returns(202) {data: map{id: str, type: str}} # Accepted\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"mute\":{\"description\":\"To be resolved later.\",\"expire_at\":1778721573794,\"is_muted\":true,\"reason\":\"RISK_ACCEPTED\"}},\"relationships\":{\"findings\":{\"data\":[{\"id\":\"ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw==\",\"type\":\"findings\"}]}},\"type\":\"mute\"}}\n\n@endpoint POST /api/v2/security/findings/search\n@desc Search security findings\n@optional {data: map{attributes: map} # Request data for searching security findings.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"filter\":\"@severity:(critical OR high) @status:open team:platform\",\"page\":{\"cursor\":\"eyJhZnRlciI6IkF3QUFBWnPcm1pd0FBQUJbVlBQUKBa1pqRTVdZUzSTBNemN0YWiIsLTE3Mjk0MzYwMjFdfQ==\",\"limit\":25},\"sort\":\"@detection_changed_at\"}}}\n\n@endpoint PATCH /api/v2/security/findings/servicenow_tickets\n@desc Attach security findings to a ServiceNow ticket\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Data of the ServiceNow ticket to attach security findings to.}\n@returns(200) {data: map{attributes: map{archived_at: str(date-time), assigned_to: map{data: map}, attributes: map, closed_at: str(date-time), created_at: str(date-time), creation_source: str, description: str, due_date: str, insights: [map], jira_issue: map{error_message: str, result: map, status: str}, key: str, linear_issue: map{error_message: str, result: map, status: str}, modified_at: str(date-time), priority: str, servicenow_ticket: map{result: map, status: str}, status: str, status_group: str, status_name: str, title: str, type: str}, id: str, relationships: map{created_by: map{data: map}, modified_by: map{data: map}, project: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"servicenow_ticket_url\":\"https://example.service-now.com/now/nav/ui/classic/params/target/incident.do?sys_id=abcdef0123456789abcdef0123456789\"},\"relationships\":{\"findings\":{\"data\":[{\"id\":\"ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw==\",\"type\":\"findings\"}]},\"project\":{\"data\":{\"id\":\"aeadc05e-98a8-11ec-ac2c-da7ad0900001\",\"type\":\"projects\"}}},\"type\":\"servicenow_tickets\"}}\n\n@endpoint POST /api/v2/security/findings/servicenow_tickets\n@desc Create ServiceNow tickets for security findings\n@required {data: [map{attributes: map, relationships!: map, type!: str}] # Array of ServiceNow ticket creation request data objects.}\n@returns(201) {data: [map]} # Created\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":[{\"attributes\":{\"assignee_id\":\"f315bdaf-9ee7-4808-a9c1-99c15bf0f4d0\",\"description\":\"A description of the ServiceNow ticket.\",\"priority\":\"NOT_DEFINED\",\"title\":\"A title for the ServiceNow ticket.\"},\"relationships\":{\"findings\":{\"data\":[{\"id\":\"ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw==\",\"type\":\"findings\"}]},\"project\":{\"data\":{\"id\":\"aeadc05e-98a8-11ec-ac2c-da7ad0900001\",\"type\":\"projects\"}}},\"type\":\"servicenow_tickets\"}]}\n\n@endpoint GET /api/v2/security/sboms\n@desc List assets SBOMs\n@optional {page[token]: str: any # Its value must come from the `links` section of the response of the first request. Do not manually edit it., page[number]: int(int64) # The page number to be retrieved. It should be equal to or greater than 1., filter[asset_type]: str # The type of the assets for the SBOM request. Required for initial requests (when no `page[token]` is provided). Infrastructure types (`Host`, `HostImage`, `Image`, `ServerlessFunction`) and code types (`Repository`, `Service`) cannot be mixed in the same request., filter[asset_name]: str # The name of the asset for the SBOM request., filter[package_name]: str # The name of the component that is a dependency of an asset., filter[package_version]: str # The version of the component that is a dependency of an asset., filter[license_name]: str # The software license name of the component that is a dependency of an asset., filter[license_type]: str # The software license type of the component that is a dependency of an asset.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str, previous: str, self: str}, meta: map{count: int(int64), token: str, total: int(int64)}} # OK\n@errors {400: Bad request: The server cannot process the request due to invalid syntax in the request., 403:Forbidden: Access denied, 404: Not found: asset not found, 429: Too many requests}\n\n@endpoint GET /api/v2/security/sboms/{asset_type}\n@desc Get SBOM\n@required {asset_type: str # The type of the asset for the SBOM request., filter[asset_name]: str # The name of the asset for the SBOM request.}\n@optional {filter[repo_digest]: str: any # The container image `repo_digest` for the SBOM request. When the requested asset type is 'Image', this filter is mandatory., ext:format: str # The standard of the SBOM.}\n@returns(200) {data: map{attributes: map{bomFormat: str, components: [map], dependencies: [map], metadata: map{authors: [map], component: map, timestamp: str}, serialNumber: str, specVersion: str, version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad request: The server cannot process the request due to invalid syntax in the request., 403:Forbidden: Access denied, 404: Not found: asset not found, 429: Too many requests}\n\n@endpoint GET /api/v2/security/scanned-assets-metadata\n@desc List scanned assets metadata\n@optional {page[token]: str: any # Its value must come from the `links` section of the response of the first request. Do not manually edit it., page[number]: int(int64) # The page number to be retrieved. It should be equal to or greater than 1., filter[asset.type]: str # The type of the scanned asset., filter[asset.name]: str # The name of the scanned asset., filter[last_success.origin]: str # The origin of last success scan., filter[last_success.env]: str # The environment of last success scan.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str, previous: str, self: str}, meta: map{count: int(int64), token: str, total: int(int64)}} # OK\n@errors {400: Bad request: The server cannot process the request due to invalid syntax in the request., 403:Forbidden: Access denied, 404: Not found: asset not found, 429: Too many requests}\n\n@endpoint GET /api/v2/security/siem/ioc-explorer\n@desc List indicators of compromise\n@optional {limit: int(int32)=50 # Number of results per page., offset: int(int32)=0 # Pagination offset., query: str # Search/filter query (supports field:value syntax)., sort[column]: str=score # Sort column: score, first_seen_ts_epoch, last_seen_ts_epoch, indicator, indicator_type, signal_count, log_count, category, as_type., sort[order]: str=desc # Sort order: asc or desc., ocsf: bool=true # When true, return only OCSF field-based matches. When false, return regex/message-based matches., worked_by: str # Filter indicators whose triage state was updated by a specific user identified by their handle., triage_state: str # Filter by triage state.}\n@returns(200) {data: map{attributes: map{data: [map], metadata: map{count: int(int64)}, paging: map{offset: int(int64)}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/security/siem/ioc-explorer/indicator\n@desc Get an indicator of compromise\n@required {indicator: str # The indicator value to look up (for example, an IP address or domain).}\n@optional {ocsf: bool=true # When true, return only OCSF field-based matches. When false, return regex/message-based matches., include_triage_history: bool=false # Include full triage history for the indicator., triage_history_limit: int(int32)=50 # Maximum number of triage history events returned. Only applied when `include_triage_history` is true., triage_history_offset: int(int32)=0 # Pagination offset into the triage history. Only applied when `include_triage_history` is true.}\n@returns(200) {data: map{attributes: map{data: map{additional_data: map, as_cidr_block: str, as_geo: map, as_number: str, as_organization: str, as_type: str, benign_sources: [map]?, categories: [str], critical_assets: [str], first_seen: str(date-time), hosts: [str], id: str, indicator: str, indicator_type: str, last_seen: str(date-time), log_matches: int(int64), log_sources: [str], m_as_type: str, m_persistence: str, m_signal: str, m_sources: str, malicious_sources: [map]?, max_trust_score: str, score: num(double), services: [str], signal_matches: int(int64), signal_severity: [map], signal_tier: int(int64), suspicious_sources: [map]?, tags: [str], triage_history: [map], triage_state: str, triaged_at: str(date-time), triaged_by: str, users: map}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/security/siem/ioc-explorer/triage\n@desc Create or update an indicator triage state\n@required {data: map{attributes!: map, type!: str} # Data object for the triage write request.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), indicator: str, triage_state: str, triaged_at: str(date-time), triaged_by: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"indicator\":\"192.0.2.1\",\"triage_state\":\"reviewed\"},\"type\":\"ioc_triage_state\"}}\n\n@endpoint GET /api/v2/security/signals/notification_rules\n@desc Get the list of signal-based notification rules\n@returns(200) {data: [map]} # The list of notification rules.\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/security/signals/notification_rules\n@desc Create a new signal-based notification rule\n@optional {data: map{attributes!: map, type!: str} # Data of the notification rule create request: the rule type, and the rule attributes. All fields are required.}\n@returns(201) {data: map{attributes: map{created_at: int(int64), created_by: map{handle: str, name: str}, enabled: bool, modified_at: int(int64), modified_by: map{handle: str, name: str}, name: str, selectors: map{query: str, rule_types: [str], severities: [str], trigger_source: str}, targets: [str], time_aggregation: int(int64), version: int(int64)}, id: str, type: str}} # Successfully created the notification rule.\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"name\":\"Rule 1\",\"selectors\":{\"query\":\"(source:production_service OR env:prod)\",\"rule_types\":[\"misconfiguration\",\"attack_path\"],\"severities\":[\"critical\"],\"trigger_source\":\"security_findings\"},\"targets\":[\"@john.doe@email.com\"],\"time_aggregation\":86400},\"type\":\"notification_rules\"}}\n\n@endpoint DELETE /api/v2/security/signals/notification_rules/{id}\n@desc Delete a signal-based notification rule\n@required {id: str # ID of the notification rule.}\n@returns(204) Rule successfully deleted.\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security/signals/notification_rules/{id}\n@desc Get details of a signal-based notification rule\n@required {id: str # ID of the notification rule.}\n@returns(200) {data: map{attributes: map{created_at: int(int64), created_by: map{handle: str, name: str}, enabled: bool, modified_at: int(int64), modified_by: map{handle: str, name: str}, name: str, selectors: map{query: str, rule_types: [str], severities: [str], trigger_source: str}, targets: [str], time_aggregation: int(int64), version: int(int64)}, id: str, type: str}} # Notification rule details.\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security/signals/notification_rules/{id}\n@desc Patch a signal-based notification rule\n@required {id: str # ID of the notification rule.}\n@optional {data: map{attributes!: map, id!: str, type!: str} # Data of the notification rule patch request: the rule ID, the rule type, and the rule attributes. All fields are required.}\n@returns(200) {data: map{attributes: map{created_at: int(int64), created_by: map{handle: str, name: str}, enabled: bool, modified_at: int(int64), modified_by: map{handle: str, name: str}, name: str, selectors: map{query: str, rule_types: [str], severities: [str], trigger_source: str}, targets: [str], time_aggregation: int(int64), version: int(int64)}, id: str, type: str}} # Notification rule successfully patched.\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 422: The server cannot process the request because it contains invalid data., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"name\":\"Rule 1\",\"selectors\":{\"query\":\"(source:production_service OR env:prod)\",\"rule_types\":[\"misconfiguration\",\"attack_path\"],\"severities\":[\"critical\"],\"trigger_source\":\"security_findings\"},\"targets\":[\"@john.doe@email.com\"],\"time_aggregation\":86400,\"version\":1},\"id\":\"aaa-bbb-ccc\",\"type\":\"notification_rules\"}}\n\n@endpoint GET /api/v2/security/vulnerabilities\n@desc List vulnerabilities\n@optional {page[token]: str: any # Its value must come from the `links` section of the response of the first request. Do not manually edit it., page[number]: int(int64) # The page number to be retrieved. It should be equal or greater than `1`, filter[type]: str # Filter by vulnerability type., filter[cvss.base.score][`$op`]: num(double) # Filter by vulnerability base (i.e. from the original advisory) severity score., filter[cvss.base.severity]: str # Filter by vulnerability base severity., filter[cvss.base.vector]: str # Filter by vulnerability base CVSS vector., filter[cvss.datadog.score][`$op`]: num(double) # Filter by vulnerability Datadog severity score., filter[cvss.datadog.severity]: str # Filter by vulnerability Datadog severity., filter[cvss.datadog.vector]: str # Filter by vulnerability Datadog CVSS vector., filter[status]: str # Filter by the status of the vulnerability., filter[tool]: str # Filter by the tool of the vulnerability., filter[library.name]: str # Filter by library name., filter[library.version]: str # Filter by library version., filter[advisory.id]: str # Filter by advisory ID., filter[risks.exploitation_probability]: bool # Filter by exploitation probability., filter[risks.poc_exploit_available]: bool # Filter by POC exploit availability., filter[risks.exploit_available]: bool # Filter by public exploit availability., filter[risks.epss.score][`$op`]: num(double) # Filter by vulnerability [EPSS](https://www.first.org/epss/) severity score., filter[risks.epss.severity]: str # Filter by vulnerability [EPSS](https://www.first.org/epss/) severity., filter[language]: str # Filter by language., filter[ecosystem]: str # Filter by ecosystem., filter[code_location.location]: str # Filter by vulnerability location., filter[code_location.file_path]: str # Filter by vulnerability file path., filter[code_location.method]: str # Filter by method., filter[fix_available]: bool # Filter by fix availability., filter[repo_digests]: str # Filter by vulnerability `repo_digest` (when the vulnerability is related to `Image` asset)., filter[origin]: str # Filter by origin., filter[running_kernel]: bool # Filter for whether the vulnerability affects a running kernel (for vulnerabilities related to a `Host` asset)., filter[asset.name]: str # Filter by asset name. This field supports the usage of wildcards (*)., filter[asset.type]: str # Filter by asset type., filter[asset.version.first]: str # Filter by the first version of the asset this vulnerability has been detected on., filter[asset.version.last]: str # Filter by the last version of the asset this vulnerability has been detected on., filter[asset.repository_url]: str # Filter by the repository url associated to the asset., filter[asset.risks.in_production]: bool # Filter whether the asset is in production or not., filter[asset.risks.under_attack]: bool # Filter whether the asset is under attack or not., filter[asset.risks.is_publicly_accessible]: bool # Filter whether the asset is publicly accessible or not., filter[asset.risks.has_privileged_access]: bool # Filter whether the asset is publicly accessible or not., filter[asset.risks.has_access_to_sensitive_data]: bool # Filter whether the asset  has access to sensitive data or not., filter[asset.environments]: str # Filter by asset environments., filter[asset.teams]: str # Filter by asset teams., filter[asset.arch]: str # Filter by asset architecture., filter[asset.operating_system.name]: str # Filter by asset operating system name., filter[asset.operating_system.version]: str # Filter by asset operating system version.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str, previous: str, self: str}, meta: map{count: int(int64), token: str, total: int(int64)}} # OK\n@errors {400: Bad request: The server cannot process the request due to invalid syntax in the request., 403:Forbidden: Access denied, 404: Not found: There is no request associated with the provided token., 429: Too many requests}\n\n@endpoint POST /api/v2/security/vulnerabilities\n@desc Import security vulnerabilities\n@required {bomFormat: str # The BOM format identifier. Must be `CycloneDX`., components: [map{bom-ref!: str, name!: str, purl: str, type!: str, version!: str}] # The list of scanned software components. Cannot be empty., metadata: map{component!: map, tools!: map} # Metadata about the BOM, including the scanned asset and the scanner tool., specVersion: str # The CycloneDX specification version. Must be `1.5`., vulnerabilities: [map{advisories: [map], affects!: [map], analysis: map, cwes: [int(int64)], description: str, detail: str, id!: str, ratings!: [map], references: [map]}] # The list of detected vulnerabilities. Cannot be empty.}\n@optional {version: int(int64) # The version number of the BOM document.}\n@returns(200) Vulnerabilities accepted successfully.\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"bomFormat\":\"CycloneDX\",\"components\":[{\"bom-ref\":\"a3390fca-c315-41ae-ae05-af5e7859cdee\",\"name\":\"lodash\",\"purl\":\"pkg:npm/lodash@4.17.21\",\"type\":\"library\",\"version\":\"4.17.21\"}],\"metadata\":{\"component\":{\"name\":\"i-12345\",\"type\":\"operating-system\"},\"tools\":{\"components\":[{\"name\":\"my-scanner\",\"type\":\"application\"}]}},\"specVersion\":\"1.5\",\"version\":1,\"vulnerabilities\":[{\"affects\":[{\"ref\":\"a3390fca-c315-41ae-ae05-af5e7859cdee\"}],\"description\":\"Sample vulnerability detected in the application.\",\"id\":\"CVE-2021-1234\",\"ratings\":[{\"score\":9,\"severity\":\"high\",\"vector\":\"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N\"}]}]}\n\n@endpoint GET /api/v2/security/vulnerabilities/notification_rules\n@desc Get the list of vulnerability notification rules\n@returns(200) {data: [map]} # The list of notification rules.\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/security/vulnerabilities/notification_rules\n@desc Create a new vulnerability-based notification rule\n@optional {data: map{attributes!: map, type!: str} # Data of the notification rule create request: the rule type, and the rule attributes. All fields are required.}\n@returns(201) {data: map{attributes: map{created_at: int(int64), created_by: map{handle: str, name: str}, enabled: bool, modified_at: int(int64), modified_by: map{handle: str, name: str}, name: str, selectors: map{query: str, rule_types: [str], severities: [str], trigger_source: str}, targets: [str], time_aggregation: int(int64), version: int(int64)}, id: str, type: str}} # Successfully created the notification rule.\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"name\":\"Rule 1\",\"selectors\":{\"query\":\"(source:production_service OR env:prod)\",\"rule_types\":[\"misconfiguration\",\"attack_path\"],\"severities\":[\"critical\"],\"trigger_source\":\"security_findings\"},\"targets\":[\"@john.doe@email.com\"],\"time_aggregation\":86400},\"type\":\"notification_rules\"}}\n\n@endpoint DELETE /api/v2/security/vulnerabilities/notification_rules/{id}\n@desc Delete a vulnerability-based notification rule\n@required {id: str # ID of the notification rule.}\n@returns(204) Rule successfully deleted.\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security/vulnerabilities/notification_rules/{id}\n@desc Get details of a vulnerability notification rule\n@required {id: str # ID of the notification rule.}\n@returns(200) {data: map{attributes: map{created_at: int(int64), created_by: map{handle: str, name: str}, enabled: bool, modified_at: int(int64), modified_by: map{handle: str, name: str}, name: str, selectors: map{query: str, rule_types: [str], severities: [str], trigger_source: str}, targets: [str], time_aggregation: int(int64), version: int(int64)}, id: str, type: str}} # Notification rule details.\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security/vulnerabilities/notification_rules/{id}\n@desc Patch a vulnerability-based notification rule\n@required {id: str # ID of the notification rule.}\n@optional {data: map{attributes!: map, id!: str, type!: str} # Data of the notification rule patch request: the rule ID, the rule type, and the rule attributes. All fields are required.}\n@returns(200) {data: map{attributes: map{created_at: int(int64), created_by: map{handle: str, name: str}, enabled: bool, modified_at: int(int64), modified_by: map{handle: str, name: str}, name: str, selectors: map{query: str, rule_types: [str], severities: [str], trigger_source: str}, targets: [str], time_aggregation: int(int64), version: int(int64)}, id: str, type: str}} # Notification rule successfully patched.\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 422: The server cannot process the request because it contains invalid data., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"name\":\"Rule 1\",\"selectors\":{\"query\":\"(source:production_service OR env:prod)\",\"rule_types\":[\"misconfiguration\",\"attack_path\"],\"severities\":[\"critical\"],\"trigger_source\":\"security_findings\"},\"targets\":[\"@john.doe@email.com\"],\"time_aggregation\":86400,\"version\":1},\"id\":\"aaa-bbb-ccc\",\"type\":\"notification_rules\"}}\n\n@endpoint GET /api/v2/security/vulnerable-assets\n@desc List vulnerable assets\n@optional {page[token]: str: any # Its value must come from the `links` section of the response of the first request. Do not manually edit it., page[number]: int(int64) # The page number to be retrieved. It should be equal or greater than `1`, filter[name]: str # Filter by name. This field supports the usage of wildcards (*)., filter[type]: str # Filter by type., filter[version.first]: str # Filter by the first version of the asset since it has been vulnerable., filter[version.last]: str # Filter by the last detected version of the asset., filter[repository_url]: str # Filter by the repository url associated to the asset., filter[risks.in_production]: bool # Filter whether the asset is in production or not., filter[risks.under_attack]: bool # Filter whether the asset (Service) is under attack or not., filter[risks.is_publicly_accessible]: bool # Filter whether the asset (Host) is publicly accessible or not., filter[risks.has_privileged_access]: bool # Filter whether the asset (Host) has privileged access or not., filter[risks.has_access_to_sensitive_data]: bool # Filter whether the asset (Host)  has access to sensitive data or not., filter[environments]: str # Filter by environment., filter[teams]: str # Filter by teams., filter[arch]: str # Filter by architecture., filter[operating_system.name]: str # Filter by operating system name., filter[operating_system.version]: str # Filter by operating system version.}\n@returns(200) {data: [map], links: map{first: str, last: str, next: str, previous: str, self: str}, meta: map{count: int(int64), token: str, total: int(int64)}} # OK\n@errors {400: Bad request: The server cannot process the request due to invalid syntax in the request., 403:Forbidden: Access denied, 404: Not found: There is no request associated with the provided token., 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/cloud_workload_security/agent_rules\n@desc Get all Workload Protection agent rules (US1-FED)\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/cloud_workload_security/agent_rules\n@desc Create a Workload Protection agent rule (US1-FED)\n@required {data: map{attributes!: map, type!: str} # Object for a single Agent rule}\n@returns(200) {data: map{attributes: map{actions: [map]?, agentConstraint: str, blocking: [str], category: str, creationAuthorUuId: str, creationDate: int(int64), creator: map{handle: str, name: str?}, defaultRule: bool, description: str, disabled: [str], enabled: bool, expression: str, filters: [str], monitoring: [str], name: str, product_tags: [str], silent: bool, updateAuthorUuId: str, updateDate: int(int64), updatedAt: int(int64), updater: map{handle: str, name: str?}, version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"My Agent rule\",\"enabled\":true,\"expression\":\"exec.file.name == \\\"sh\\\"\",\"name\":\"my_agent_rule\"},\"type\":\"agent_rule\"}}\n\n@endpoint DELETE /api/v2/security_monitoring/cloud_workload_security/agent_rules/{agent_rule_id}\n@desc Delete a Workload Protection agent rule (US1-FED)\n@required {agent_rule_id: str # The ID of the Agent rule}\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/cloud_workload_security/agent_rules/{agent_rule_id}\n@desc Get a Workload Protection agent rule (US1-FED)\n@required {agent_rule_id: str # The ID of the Agent rule}\n@returns(200) {data: map{attributes: map{actions: [map]?, agentConstraint: str, blocking: [str], category: str, creationAuthorUuId: str, creationDate: int(int64), creator: map{handle: str, name: str?}, defaultRule: bool, description: str, disabled: [str], enabled: bool, expression: str, filters: [str], monitoring: [str], name: str, product_tags: [str], silent: bool, updateAuthorUuId: str, updateDate: int(int64), updatedAt: int(int64), updater: map{handle: str, name: str?}, version: int(int64)}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/cloud_workload_security/agent_rules/{agent_rule_id}\n@desc Update a Workload Protection agent rule (US1-FED)\n@required {agent_rule_id: str # The ID of the Agent rule, data: map{attributes!: map, id: str, type!: str} # Object for a single Agent rule}\n@returns(200) {data: map{attributes: map{actions: [map]?, agentConstraint: str, blocking: [str], category: str, creationAuthorUuId: str, creationDate: int(int64), creator: map{handle: str, name: str?}, defaultRule: bool, description: str, disabled: [str], enabled: bool, expression: str, filters: [str], monitoring: [str], name: str, product_tags: [str], silent: bool, updateAuthorUuId: str, updateDate: int(int64), updatedAt: int(int64), updater: map{handle: str, name: str?}, version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"My Agent rule\",\"enabled\":true,\"expression\":\"exec.file.name == \\\"sh\\\"\"},\"id\":\"3dd-0uc-h1s\",\"type\":\"agent_rule\"}}\n\n@endpoint GET /api/v2/security_monitoring/configuration/critical_assets\n@desc Get all critical assets\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/configuration/critical_assets\n@desc Create a critical asset\n@required {data: map{attributes!: map, type!: str} # Object for a single critical asset.}\n@returns(200) {data: map{attributes: map{creation_author_id: int(int64), creation_date: int(int64), creator: map{handle: str, name: str?}, description: str, editable: bool, enabled: bool, query: str, rule_query: str, severity: str, tags: [str], update_author_id: int(int64), update_date: int(int64), updater: map{handle: str, name: str?}, version: int(int32)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"query\":\"security:monitoring\",\"rule_query\":\"type:(log_detection OR signal_correlation OR workload_security OR application_security) source:cloudtrail\",\"severity\":\"increase\",\"tags\":[\"team:database\",\"source:cloudtrail\"]},\"type\":\"critical_assets\"}}\n\n@endpoint GET /api/v2/security_monitoring/configuration/critical_assets/rules/{rule_id}\n@desc Get critical assets affecting a specific rule\n@required {rule_id: str # The ID of the rule.}\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/security_monitoring/configuration/critical_assets/{critical_asset_id}\n@desc Delete a critical asset\n@required {critical_asset_id: str # The ID of the critical asset.}\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/configuration/critical_assets/{critical_asset_id}\n@desc Get a critical asset\n@required {critical_asset_id: str # The ID of the critical asset.}\n@returns(200) {data: map{attributes: map{creation_author_id: int(int64), creation_date: int(int64), creator: map{handle: str, name: str?}, description: str, editable: bool, enabled: bool, query: str, rule_query: str, severity: str, tags: [str], update_author_id: int(int64), update_date: int(int64), updater: map{handle: str, name: str?}, version: int(int32)}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/configuration/critical_assets/{critical_asset_id}\n@desc Update a critical asset\n@required {critical_asset_id: str # The ID of the critical asset., data: map{attributes!: map, type!: str} # The new critical asset properties; partial updates are supported.}\n@returns(200) {data: map{attributes: map{creation_author_id: int(int64), creation_date: int(int64), creator: map{handle: str, name: str?}, description: str, editable: bool, enabled: bool, query: str, rule_query: str, severity: str, tags: [str], update_author_id: int(int64), update_date: int(int64), updater: map{handle: str, name: str?}, version: int(int32)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"query\":\"security:monitoring\",\"rule_query\":\"type:log_detection source:cloudtrail\",\"severity\":\"increase\",\"tags\":[\"technique:T1110-brute-force\",\"source:cloudtrail\"],\"version\":1},\"type\":\"critical_assets\"}}\n\n@endpoint GET /api/v2/security_monitoring/configuration/integration_config\n@desc List entity context sync configurations\n@optional {filter[integration_type]: str: any # Filter the entity context sync configurations by source type.}\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/configuration/integration_config\n@desc Create an entity context sync configuration\n@required {data: map{attributes!: any, type!: str} # The entity context sync configuration to create.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), domain: str, enabled: bool, integration_type: str, modified_at: str(date-time), name: str, settings: map, state: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"domain\":\"siem-test.com\",\"integration_type\":\"GOOGLE_WORKSPACE\",\"name\":\"My GWS Integration\",\"secrets\":{\"admin_email\":\"test@example.com\"},\"settings\":{\"setting1\":\"value1\"}},\"type\":\"integration_config\"}}\n\n@endpoint GET /api/v2/security_monitoring/configuration/integration_config/entra_id/azure_app_registrations\n@desc Get Entra ID Azure App Registration prerequisites\n@returns(200) {data: map{attributes: map{azure_app_registrations: [map], has_valid_prerequisite: bool, integration_id: str, is_enabled: bool, subscribed_at: str(date-time)}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/configuration/integration_config/validate\n@desc Validate entity context sync credentials\n@required {data: map{attributes!: any, type!: str} # The credentials to validate.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"domain\":\"siem-test.com\",\"integration_type\":\"GOOGLE_WORKSPACE\",\"secrets\":{\"admin_email\":\"test@example.com\"}},\"type\":\"integration_config\"}}\n\n@endpoint DELETE /api/v2/security_monitoring/configuration/integration_config/{integration_config_id}\n@desc Delete an entity context sync configuration\n@required {integration_config_id: str # The ID of the entity context sync configuration.}\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/configuration/integration_config/{integration_config_id}\n@desc Get an entity context sync configuration\n@required {integration_config_id: str # The ID of the entity context sync configuration.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), domain: str, enabled: bool, integration_type: str, modified_at: str(date-time), name: str, settings: map, state: str}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/configuration/integration_config/{integration_config_id}\n@desc Update an entity context sync configuration\n@required {integration_config_id: str # The ID of the entity context sync configuration., data: map{attributes!: any, type!: str} # The entity context sync configuration fields to update.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), domain: str, enabled: bool, integration_type: str, modified_at: str(date-time), name: str, settings: map, state: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":false,\"name\":\"My GWS Integration (renamed)\"},\"type\":\"integration_config\"}}\n\n@endpoint POST /api/v2/security_monitoring/configuration/integration_config/{integration_config_id}/validate\n@desc Validate an entity context sync configuration\n@required {integration_config_id: str # The ID of the entity context sync configuration.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/configuration/integration_config/{integration_type}/activate\n@desc Activate an entity context sync integration\n@required {integration_type: str # The integration type to activate (for example, `entra_id`).}\n@optional {data: map{attributes: map, type: str} # The configuration overrides for the integration to activate.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), domain: str, enabled: bool, integration_type: str, modified_at: str(date-time), name: str, settings: map, state: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"My Entra ID Integration\"},\"type\":\"activate_entra_id_request\"}}\n\n@endpoint POST /api/v2/security_monitoring/configuration/integration_config/{integration_type}/deactivate\n@desc Deactivate an entity context sync integration\n@required {integration_type: str # The integration type to deactivate (for example, `entra_id`).}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), domain: str, enabled: bool, integration_type: str, modified_at: str(date-time), name: str, settings: map, state: str}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/configuration/notification_rules/send_notification_preview\n@desc Test a notification rule\n@optional {data: map{attributes!: map, type!: str} # Data of the notification rule create request: the rule type, and the rule attributes. All fields are required.}\n@returns(200) {data: map{attributes: map{preview_results: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"name\":\"Rule 1\",\"selectors\":{\"query\":\"env:prod\",\"rule_types\":[\"log_detection\"],\"severities\":[\"critical\"],\"trigger_source\":\"security_signals\"},\"targets\":[\"@john.doe@email.com\"]},\"type\":\"notification_rules\"}}\n\n@endpoint GET /api/v2/security_monitoring/configuration/security_filters\n@desc Get all security filters\n@returns(200) {data: [map], meta: map{warning: str}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/configuration/security_filters\n@desc Create a security filter\n@required {data: map{attributes!: map, type!: str} # Object for a single security filter.}\n@returns(200) {data: map{attributes: map{exclusion_filters: [map], filtered_data_type: str, is_builtin: bool, is_enabled: bool, name: str, query: str, version: int(int32)}, id: str, type: str}, meta: map{warning: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"exclusion_filters\":[{\"name\":\"Exclude staging\",\"query\":\"source:staging\"}],\"filtered_data_type\":\"logs\",\"is_enabled\":true,\"name\":\"Custom security filter\",\"query\":\"service:api\"},\"type\":\"security_filters\"}}\n\n@endpoint GET /api/v2/security_monitoring/configuration/security_filters/versions\n@desc Get the version history of security filters\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint DELETE /api/v2/security_monitoring/configuration/security_filters/{security_filter_id}\n@desc Delete a security filter\n@required {security_filter_id: str # The ID of the security filter.}\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/configuration/security_filters/{security_filter_id}\n@desc Get a security filter\n@required {security_filter_id: str # The ID of the security filter.}\n@returns(200) {data: map{attributes: map{exclusion_filters: [map], filtered_data_type: str, is_builtin: bool, is_enabled: bool, name: str, query: str, version: int(int32)}, id: str, type: str}, meta: map{warning: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/configuration/security_filters/{security_filter_id}\n@desc Update a security filter\n@required {security_filter_id: str # The ID of the security filter., data: map{attributes!: map, type!: str} # The new security filter properties.}\n@returns(200) {data: map{attributes: map{exclusion_filters: [map], filtered_data_type: str, is_builtin: bool, is_enabled: bool, name: str, query: str, version: int(int32)}, id: str, type: str}, meta: map{warning: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"exclusion_filters\":[],\"filtered_data_type\":\"logs\",\"is_enabled\":true,\"name\":\"Custom security filter\",\"query\":\"service:api\",\"version\":1},\"type\":\"security_filters\"}}\n\n@endpoint GET /api/v2/security_monitoring/configuration/suppressions\n@desc Get all suppression rules\n@optional {query: str # Query string., sort: str # Attribute used to sort the list of suppression rules. Prefix with `-` to sort in descending order., page[size]: int(int64)=-1 # Size for a given page. Use `-1` to return all items., page[number]: int(int64)=0 # Specific page number to return.}\n@returns(200) {data: [map], meta: map{page: map{pageNumber: int(int64), pageSize: int(int64), totalCount: int(int64)}}} # OK\n@errors {403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/configuration/suppressions\n@desc Create a suppression rule\n@required {data: map{attributes!: map, type!: str} # Object for a single suppression rule.}\n@returns(200) {data: map{attributes: map{creation_date: int(int64), creator: map{handle: str, name: str?}, data_exclusion_query: str, description: str, editable: bool, enabled: bool, expiration_date: int(int64), name: str, rule_query: str, start_date: int(int64), suppression_query: str, tags: [str], update_date: int(int64), updater: map{handle: str, name: str?}, version: int(int32)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"data_exclusion_query\":\"source:cloudtrail account_id:12345\",\"description\":\"This rule suppresses low-severity signals in staging environments.\",\"enabled\":true,\"expiration_date\":1703187336000,\"name\":\"Custom suppression\",\"rule_query\":\"type:log_detection source:cloudtrail\",\"start_date\":1703187336000,\"suppression_query\":\"env:staging status:low\",\"tags\":[\"technique:T1110-brute-force\",\"source:cloudtrail\"]},\"type\":\"suppressions\"}}\n\n@endpoint POST /api/v2/security_monitoring/configuration/suppressions/rules\n@desc Get suppressions affecting future rule\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"calculatedFields\":[{\"expression\":\"@request_end_timestamp - @request_start_timestamp\",\"name\":\"response_time\"}],\"cases\":[],\"filters\":[{\"action\":\"require\"}],\"groupSignalsBy\":[\"service\"],\"hasExtendedTitle\":true,\"isEnabled\":true,\"message\":\"\",\"name\":\"My security monitoring rule.\",\"options\":{\"anomalyDetectionOptions\":{\"bucketDuration\":300,\"detectionTolerance\":5,\"instantaneousBaseline\":false},\"complianceRuleOptions\":{\"regoRule\":{\"policy\":\"package datadog\\n\\nimport data.datadog.output as dd_output\\nimport future.keywords.contains\\nimport future.keywords.if\\nimport future.keywords.in\\n\\neval(resource) = \\\"skip\\\" if {\\n  # Logic that evaluates to true if the resource should be skipped\\n  true\\n} else = \\\"pass\\\" {\\n  # Logic that evaluates to true if the resource is compliant\\n  true\\n} else = \\\"fail\\\" {\\n  # Logic that evaluates to true if the resource is not compliant\\n  true\\n}\\n\\n# This part remains unchanged for all rules\\nresults contains result if {\\n  some resource in input.resources[input.main_resource_type]\\n  result := dd_output.format(resource, eval(resource))\\n}\",\"resourceTypes\":[\"gcp_iam_service_account\",\"gcp_iam_policy\"]},\"resourceType\":\"aws_acm\"},\"decreaseCriticalityBasedOnEnv\":false,\"detectionMethod\":\"threshold\",\"hardcodedEvaluatorType\":\"log4shell\",\"impossibleTravelOptions\":{\"baselineUserLocations\":true,\"baselineUserLocationsDuration\":7},\"newValueOptions\":{\"instantaneousBaseline\":false,\"learningMethod\":\"duration\"},\"thirdPartyRuleOptions\":{\"defaultStatus\":\"critical\",\"rootQueries\":[{\"query\":\"source:cloudtrail\"}]}},\"queries\":[],\"schedulingOptions\":{\"rrule\":\"FREQ=HOURLY;INTERVAL=1;\",\"start\":\"2025-07-14T12:00:00\",\"timezone\":\"America/New_York\"},\"tags\":[\"env:prod\",\"team:security\"],\"thirdPartyCases\":[],\"type\":\"api_security\"}\n\n@endpoint GET /api/v2/security_monitoring/configuration/suppressions/rules/{rule_id}\n@desc Get suppressions affecting a specific rule\n@required {rule_id: str # The ID of the rule.}\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/configuration/suppressions/validation\n@desc Validate a suppression rule\n@required {data: map{attributes!: map, type!: str} # Object for a single suppression rule.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"data_exclusion_query\":\"source:cloudtrail account_id:12345\",\"description\":\"This rule suppresses low-severity signals in staging environments.\",\"enabled\":true,\"expiration_date\":1703187336000,\"name\":\"Custom suppression\",\"rule_query\":\"type:log_detection source:cloudtrail\",\"start_date\":1703187336000,\"suppression_query\":\"env:staging status:low\",\"tags\":[\"technique:T1110-brute-force\",\"source:cloudtrail\"]},\"type\":\"suppressions\"}}\n\n@endpoint DELETE /api/v2/security_monitoring/configuration/suppressions/{suppression_id}\n@desc Delete a suppression rule\n@required {suppression_id: str # The ID of the suppression rule}\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/configuration/suppressions/{suppression_id}\n@desc Get a suppression rule\n@required {suppression_id: str # The ID of the suppression rule}\n@returns(200) {data: map{attributes: map{creation_date: int(int64), creator: map{handle: str, name: str?}, data_exclusion_query: str, description: str, editable: bool, enabled: bool, expiration_date: int(int64), name: str, rule_query: str, start_date: int(int64), suppression_query: str, tags: [str], update_date: int(int64), updater: map{handle: str, name: str?}, version: int(int32)}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/configuration/suppressions/{suppression_id}\n@desc Update a suppression rule\n@required {suppression_id: str # The ID of the suppression rule, data: map{attributes!: map, type!: str} # The new suppression properties; partial updates are supported.}\n@returns(200) {data: map{attributes: map{creation_date: int(int64), creator: map{handle: str, name: str?}, data_exclusion_query: str, description: str, editable: bool, enabled: bool, expiration_date: int(int64), name: str, rule_query: str, start_date: int(int64), suppression_query: str, tags: [str], update_date: int(int64), updater: map{handle: str, name: str?}, version: int(int32)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Concurrent Modification, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"data_exclusion_query\":\"source:cloudtrail account_id:12345\",\"description\":\"This rule suppresses low-severity signals in staging environments.\",\"enabled\":true,\"expiration_date\":1703187336000,\"name\":\"Custom suppression\",\"rule_query\":\"type:log_detection source:cloudtrail\",\"start_date\":1703187336000,\"suppression_query\":\"env:staging status:low\",\"tags\":[\"technique:T1110-brute-force\",\"source:cloudtrail\"]},\"type\":\"suppressions\"}}\n\n@endpoint GET /api/v2/security_monitoring/configuration/suppressions/{suppression_id}/version_history\n@desc Get a suppression's version history\n@required {suppression_id: str # The ID of the suppression rule}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return.}\n@returns(200) {data: map{attributes: map{count: int(int32), data: map}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/content_packs/states\n@desc Get content pack states\n@returns(200) {data: [map], meta: map{cloud_siem_index_incorrect: bool, retention_months: int(int32), sku: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/security_monitoring/content_packs/{content_pack_id}/activate\n@desc Activate content pack\n@required {content_pack_id: str # The ID of the content pack to activate (for example, `aws-cloudtrail`).}\n@returns(202) Accepted\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/security_monitoring/content_packs/{content_pack_id}/deactivate\n@desc Deactivate content pack\n@required {content_pack_id: str # The ID of the content pack to deactivate (for example, `aws-cloudtrail`).}\n@returns(202) Accepted\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/datasets\n@desc List datasets\n@optional {page[size]: int(int64)=50: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=1 # Specific page number to return., sort: str # Attribute used to sort datasets. Prefix with `-` to sort in descending order., filter[query]: str # A search query to filter datasets by name or description.}\n@returns(200) {data: [map], meta: map{totalCount: int(int64)}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/datasets\n@desc Create a dataset\n@required {data: map{attributes!: map, type!: str} # The data wrapper of a dataset create request.}\n@returns(201) {data: map{id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"definition\":{\"columns\":[{\"column\":\"message\",\"type\":\"string\"}],\"data_source\":\"logs\",\"indexes\":[\"main\"],\"name\":\"sample_dataset\",\"search\":{\"query\":\"*\"}},\"description\":\"A sample dataset used for detection rules.\"},\"type\":\"datasetCreate\"}}\n\n@endpoint POST /api/v2/security_monitoring/datasets/dependencies\n@desc Get dataset dependencies\n@required {data: map{attributes!: map} # The data wrapper of a dataset dependencies request.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"datasetIds\":[\"123e4567-e89b-12d3-a456-426614174000\"]}}}\n\n@endpoint DELETE /api/v2/security_monitoring/datasets/{dataset_id}\n@desc Delete a dataset\n@required {dataset_id: str # The UUID of the dataset.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/datasets/{dataset_id}\n@desc Get a dataset\n@required {dataset_id: str # The UUID of the dataset.}\n@returns(200) {data: map{attributes: map{createdAt: str, createdByHandle: str, createdByName: str, definition: map{columns: [map], data_source: str, indexes: [str], name: str, query_filter: str, search: map, storage: str, table_name: str, time_window: map}, description: str, id: str, isDefault: bool, isDeprecated: bool, modifiedAt: str, name: str, updatedByHandle: str?, updatedByName: str?, version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/datasets/{dataset_id}\n@desc Update a dataset\n@required {dataset_id: str # The UUID of the dataset., data: map{attributes!: map, type!: str} # The data wrapper of a dataset update request.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"definition\":{\"columns\":[{\"column\":\"message\",\"type\":\"string\"}],\"data_source\":\"logs\",\"indexes\":[\"main\"],\"name\":\"sample_dataset\",\"search\":{\"query\":\"*\"}},\"description\":\"An updated description for the dataset.\",\"version\":1},\"type\":\"datasetUpdate\"}}\n\n@endpoint GET /api/v2/security_monitoring/datasets/{dataset_id}/version/{version}\n@desc Get a dataset at a specific version\n@required {dataset_id: str # The UUID of the dataset., version: int(int64) # The version number of the dataset to retrieve.}\n@returns(200) {data: map{attributes: map{createdAt: str, createdByHandle: str, createdByName: str, definition: map{columns: [map], data_source: str, indexes: [str], name: str, query_filter: str, search: map, storage: str, table_name: str, time_window: map}, description: str, id: str, isDefault: bool, isDeprecated: bool, modifiedAt: str, name: str, updatedByHandle: str?, updatedByName: str?, version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/datasets/{dataset_id}/version_history\n@desc Get the version history of a dataset\n@required {dataset_id: str # The UUID of the dataset.}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return.}\n@returns(200) {data: map{attributes: map{count: int(int64), data: map}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/entity_context\n@desc Get entity context\n@optional {query: str # A free-text query (for example, an email address or principal ID) used to filter the entities returned., from: str=now-7d # The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now-7d`). Defaults to `now-7d`. Ignored when `as_of` is set., to: str=now # The end of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now`). Defaults to `now`. Ignored when `as_of` is set., as_of: str # A point in time at which to query the entity revisions, as an RFC3339 timestamp, a Unix timestamp (in seconds), or a relative time (for example, `now-1d`). When set, `from` and `to` are ignored. Cannot be combined with custom `from` / `to` values., limit: int(int64)=250 # The maximum number of entities to return., page_token: str # An opaque token used to fetch the next page of results, as returned in `meta.page.next_token` of a previous response.}\n@returns(200) {data: [map], meta: map{page: map{next_token: str}, total_count: int(int32)}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/entity_context/{id}\n@desc Get a single entity context\n@required {id: str # The unique identifier of the entity to retrieve.}\n@optional {from: str=now-7d # The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now-7d`). Defaults to `now-7d`. Ignored when `as_of` is set., to: str=now # The end of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now`). Defaults to `now`. Ignored when `as_of` is set., as_of: str # A point in time at which to query the entity revisions, as an RFC3339 timestamp, a Unix timestamp (in seconds), or a relative time (for example, `now-1d`). When set, `from` and `to` are ignored. Cannot be combined with custom `from` / `to` values.}\n@returns(200) {data: map{attributes: map{revisions: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/rules\n@desc List rules\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., query: str # A search query to filter security rules. You can filter by attributes such as `type`, `source`, `tags`., sort: str # Attribute used to sort rules. Prefix with `-` to sort in descending order.}\n@returns(200) {data: [any], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/rules\n@desc Create a detection rule\n@returns(200) OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"cases\":[{\"condition\":\"a > 0\",\"name\":\"\",\"notifications\":[],\"status\":\"info\"}],\"filters\":[],\"hasExtendedTitle\":true,\"isEnabled\":true,\"message\":\"Test rule\",\"name\":\"My security monitoring rule.\",\"options\":{\"evaluationWindow\":900,\"keepAlive\":3600,\"maxSignalDuration\":86400},\"queries\":[{\"aggregation\":\"count\",\"distinctFields\":[],\"groupByFields\":[],\"metric\":\"\",\"query\":\"@test:true\"}],\"referenceTables\":[{\"checkPresence\":true,\"columnName\":\"value\",\"logFieldPath\":\"testtag\",\"ruleQueryName\":\"a\",\"tableName\":\"synthetics_test_reference_table_dont_delete\"}],\"tags\":[],\"type\":\"log_detection\"}\n\n@endpoint DELETE /api/v2/security_monitoring/rules/bulk_delete\n@desc Bulk delete security monitoring rules\n@required {data: map{attributes!: map, id: str, type!: str} # Data for bulk deleting security monitoring rules.}\n@returns(200) {data: map{attributes: map{deletedRules: [str], failedRules: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"ruleIds\":[\"abc-000-u7q\",\"abc-000-7dd\"]},\"id\":\"bulk_delete\",\"type\":\"bulk_delete_rules\"}}\n\n@endpoint POST /api/v2/security_monitoring/rules/bulk_export\n@desc Bulk export security monitoring rules\n@required {data: map{attributes!: map, id: str, type!: str} # Data for bulk exporting security monitoring rules.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"ruleIds\":[\"def-000-u7q\",\"def-000-7dd\"]},\"id\":\"bulk_export\",\"type\":\"security_monitoring_rules_bulk_export\"}}\n\n@endpoint POST /api/v2/security_monitoring/rules/convert\n@desc Convert a rule from JSON to Terraform\n@returns(200) {ruleId: str, terraformContent: str} # OK\n@errors {400: Bad Request, 401: Concurrent Modification, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"calculatedFields\":[{\"expression\":\"@request_end_timestamp - @request_start_timestamp\",\"name\":\"response_time\"}],\"cases\":[{\"condition\":\"a > 0\",\"name\":\"\",\"notifications\":[],\"status\":\"info\"}],\"filters\":[],\"groupSignalsBy\":[\"service\"],\"hasExtendedTitle\":true,\"isEnabled\":true,\"message\":\"My security monitoring rule.\",\"name\":\"My security monitoring rule.\",\"options\":{\"anomalyDetectionOptions\":{\"bucketDuration\":300,\"detectionTolerance\":5,\"instantaneousBaseline\":false},\"complianceRuleOptions\":{\"regoRule\":{\"policy\":\"package datadog\\n\\nimport data.datadog.output as dd_output\\nimport future.keywords.contains\\nimport future.keywords.if\\nimport future.keywords.in\\n\\neval(resource) = \\\"skip\\\" if {\\n  # Logic that evaluates to true if the resource should be skipped\\n  true\\n} else = \\\"pass\\\" {\\n  # Logic that evaluates to true if the resource is compliant\\n  true\\n} else = \\\"fail\\\" {\\n  # Logic that evaluates to true if the resource is not compliant\\n  true\\n}\\n\\n# This part remains unchanged for all rules\\nresults contains result if {\\n  some resource in input.resources[input.main_resource_type]\\n  result := dd_output.format(resource, eval(resource))\\n}\",\"resourceTypes\":[\"gcp_iam_service_account\",\"gcp_iam_policy\"]},\"resourceType\":\"aws_acm\"},\"decreaseCriticalityBasedOnEnv\":false,\"detectionMethod\":\"threshold\",\"evaluationWindow\":900,\"hardcodedEvaluatorType\":\"log4shell\",\"impossibleTravelOptions\":{\"baselineUserLocations\":true,\"baselineUserLocationsDuration\":7},\"keepAlive\":3600,\"maxSignalDuration\":86400,\"newValueOptions\":{\"instantaneousBaseline\":false,\"learningMethod\":\"duration\"},\"thirdPartyRuleOptions\":{\"defaultStatus\":\"critical\",\"rootQueries\":[{\"query\":\"source:cloudtrail\"}]}},\"queries\":[{\"aggregation\":\"count\",\"distinctFields\":[],\"groupByFields\":[],\"query\":\"source:cloudtrail\"}],\"schedulingOptions\":{\"rrule\":\"FREQ=HOURLY;INTERVAL=1;\",\"start\":\"2025-07-14T12:00:00\",\"timezone\":\"America/New_York\"},\"tags\":[\"env:prod\",\"team:security\"],\"thirdPartyCases\":[],\"type\":\"log_detection\"}\n\n@endpoint POST /api/v2/security_monitoring/rules/convert/bulk\n@desc Bulk convert rules to Terraform\n@required {data: map{attributes!: map, id: str, type!: str} # Data for bulk converting security monitoring rules to Terraform.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"ruleIds\":[\"def-000-u7q\",\"def-000-7dd\"]},\"id\":\"convert_bulk\",\"type\":\"security_monitoring_rules_convert_bulk\"}}\n\n@endpoint POST /api/v2/security_monitoring/rules/test\n@desc Test a rule\n@optional {rule: any # Test a rule., ruleQueryPayloads: [map{expectedResult: bool, index: int(int64), payload: map}] # Data payloads used to test rules query with the expected result.}\n@returns(200) {results: [bool]} # OK\n@errors {400: Bad Request, 401: Concurrent Modification, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"rule\":{\"calculatedFields\":[{\"expression\":\"@request_end_timestamp - @request_start_timestamp\",\"name\":\"response_time\"}],\"cases\":[{\"condition\":\"a > 0\",\"name\":\"\",\"notifications\":[],\"status\":\"info\"}],\"filters\":[{\"action\":\"require\"}],\"groupSignalsBy\":[\"service\"],\"hasExtendedTitle\":true,\"isEnabled\":true,\"message\":\"My security monitoring rule message.\",\"name\":\"My security monitoring rule.\",\"options\":{\"anomalyDetectionOptions\":{\"bucketDuration\":300,\"detectionTolerance\":5,\"instantaneousBaseline\":false},\"complianceRuleOptions\":{\"resourceType\":\"aws_acm\"},\"decreaseCriticalityBasedOnEnv\":false,\"detectionMethod\":\"threshold\",\"evaluationWindow\":0,\"hardcodedEvaluatorType\":\"log4shell\",\"impossibleTravelOptions\":{\"baselineUserLocations\":true,\"baselineUserLocationsDuration\":7},\"keepAlive\":0,\"maxSignalDuration\":0,\"newValueOptions\":{\"instantaneousBaseline\":false,\"learningMethod\":\"duration\"},\"thirdPartyRuleOptions\":{\"defaultStatus\":\"critical\"}},\"queries\":[{\"aggregation\":\"count\",\"distinctFields\":[],\"groupByFields\":[\"@userIdentity.assumed_role\"],\"name\":\"\",\"query\":\"source:cloudtrail\"}],\"schedulingOptions\":{\"rrule\":\"FREQ=HOURLY;INTERVAL=1;\",\"start\":\"2025-07-14T12:00:00\",\"timezone\":\"America/New_York\"},\"tags\":[\"env:prod\",\"team:security\"],\"thirdPartyCases\":[],\"type\":\"log_detection\"},\"ruleQueryPayloads\":[{\"expectedResult\":true,\"index\":0,\"payload\":{\"ddsource\":\"nginx\",\"ddtags\":\"env:staging,version:5.1\",\"hostname\":\"i-012345678\",\"message\":\"2019-11-19T14:37:58,995 INFO [process.name][20081] Hello World\",\"service\":\"payment\"}}]}\n\n@endpoint POST /api/v2/security_monitoring/rules/validation\n@desc Validate a detection rule\n@returns(204) OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"calculatedFields\":[{\"expression\":\"@request_end_timestamp - @request_start_timestamp\",\"name\":\"response_time\"}],\"cases\":[{\"condition\":\"a > 0\",\"name\":\"\",\"notifications\":[],\"status\":\"info\"}],\"filters\":[{\"action\":\"require\"}],\"groupSignalsBy\":[\"service\"],\"hasExtendedTitle\":true,\"isEnabled\":true,\"message\":\"My security monitoring rule\",\"name\":\"My security monitoring rule.\",\"options\":{\"anomalyDetectionOptions\":{\"bucketDuration\":300,\"detectionTolerance\":5,\"instantaneousBaseline\":false},\"complianceRuleOptions\":{\"regoRule\":{\"policy\":\"package datadog\\n\\nimport data.datadog.output as dd_output\\nimport future.keywords.contains\\nimport future.keywords.if\\nimport future.keywords.in\\n\\neval(resource) = \\\"skip\\\" if {\\n  # Logic that evaluates to true if the resource should be skipped\\n  true\\n} else = \\\"pass\\\" {\\n  # Logic that evaluates to true if the resource is compliant\\n  true\\n} else = \\\"fail\\\" {\\n  # Logic that evaluates to true if the resource is not compliant\\n  true\\n}\\n\\n# This part remains unchanged for all rules\\nresults contains result if {\\n  some resource in input.resources[input.main_resource_type]\\n  result := dd_output.format(resource, eval(resource))\\n}\",\"resourceTypes\":[\"gcp_iam_service_account\",\"gcp_iam_policy\"]},\"resourceType\":\"aws_acm\"},\"decreaseCriticalityBasedOnEnv\":false,\"detectionMethod\":\"threshold\",\"evaluationWindow\":1800,\"hardcodedEvaluatorType\":\"log4shell\",\"impossibleTravelOptions\":{\"baselineUserLocations\":true,\"baselineUserLocationsDuration\":7},\"keepAlive\":1800,\"maxSignalDuration\":1800,\"newValueOptions\":{\"instantaneousBaseline\":false,\"learningMethod\":\"duration\"},\"thirdPartyRuleOptions\":{\"defaultStatus\":\"critical\",\"rootQueries\":[{\"query\":\"source:cloudtrail\"}]}},\"queries\":[{\"aggregation\":\"count\",\"distinctFields\":[],\"groupByFields\":[\"@userIdentity.assumed_role\"],\"name\":\"\",\"query\":\"source:cloudtrail\"}],\"schedulingOptions\":{\"rrule\":\"FREQ=HOURLY;INTERVAL=1;\",\"start\":\"2025-07-14T12:00:00\",\"timezone\":\"America/New_York\"},\"tags\":[\"env:prod\",\"team:security\"],\"thirdPartyCases\":[],\"type\":\"log_detection\"}\n\n@endpoint DELETE /api/v2/security_monitoring/rules/{rule_id}\n@desc Delete an existing rule\n@required {rule_id: str # The ID of the rule.}\n@returns(204) OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/rules/{rule_id}\n@desc Get a rule's details\n@required {rule_id: str # The ID of the rule.}\n@returns(200) OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/security_monitoring/rules/{rule_id}\n@desc Update an existing rule\n@required {rule_id: str # The ID of the rule.}\n@optional {calculatedFields: [map{expression!: str, name!: str}] # Calculated fields. Only allowed for scheduled rules - in other words, when schedulingOptions is also defined., cases: [map{actions: [map], condition: str, customStatus: str, name: str, notifications: [str], status: str}] # Cases for generating signals., complianceSignalOptions: map{defaultActivationStatus: bool, defaultGroupByFields: [str], userActivationStatus: bool, userGroupByFields: [str]} # How to generate compliance signals. Useful for cloud_configuration rules only., customMessage: str # Custom/Overridden Message for generated signals (used in case of Default rule update)., customName: str # Custom/Overridden name (used in case of Default rule update)., filters: [map{action: str, query: str}] # Additional queries to filter matched events before they are processed. This field is deprecated for log detection, signal correlation, and workload security rules., groupSignalsBy: [str] # Additional grouping to perform on top of the existing groups in the query section. Must be a subset of the existing groups., hasExtendedTitle: bool # Whether the notifications include the triggering group-by values in their title., isEnabled: bool # Whether the rule is enabled., message: str # Message for generated signals., name: str # Name of the rule., options: map{anomalyDetectionOptions: map, complianceRuleOptions: map, decreaseCriticalityBasedOnEnv: bool, detectionMethod: str, evaluationWindow: int(int32), hardcodedEvaluatorType: str, impossibleTravelOptions: map, keepAlive: int(int32), maxSignalDuration: int(int32), newValueOptions: map, sequenceDetectionOptions: map, thirdPartyRuleOptions: map} # Options., queries: [any] # Queries for selecting logs which are part of the rule., referenceTables: [map{checkPresence: bool, columnName: str, logFieldPath: str, ruleQueryName: str, tableName: str}] # Reference tables for the rule., schedulingOptions: map{rrule: str, start: str, timezone: str} # Options for scheduled rules. When this field is present, the rule runs based on the schedule. When absent, it runs real-time on ingested logs., tags: [str] # Tags for generated signals., thirdPartyCases: [map{customStatus: str, name: str, notifications: [str], query: str, status: str}] # Cases for generating signals from third-party rules. Only available for third-party rules., version: int(int32) # The version of the rule being updated.}\n@returns(200) OK\n@errors {400: Bad Request, 401: Concurrent Modification, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"cases\":[{\"condition\":\"a > 0\",\"name\":\"\",\"notifications\":[],\"status\":\"info\"}],\"filters\":[],\"isEnabled\":true,\"message\":\"Test rule\",\"name\":\"My security monitoring rule.\",\"options\":{\"evaluationWindow\":900,\"keepAlive\":3600,\"maxSignalDuration\":86400},\"queries\":[{\"aggregation\":\"count\",\"distinctFields\":[],\"groupByFields\":[],\"metrics\":[],\"query\":\"@test:true\"}],\"tags\":[]}\n\n@endpoint GET /api/v2/security_monitoring/rules/{rule_id}/convert\n@desc Convert an existing rule from JSON to Terraform\n@required {rule_id: str # The ID of the rule.}\n@returns(200) {ruleId: str, terraformContent: str} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/rules/{rule_id}/restore/{version}\n@desc Restore a rule to a historical version\n@required {rule_id: str # The ID of the rule., version: int(int64) # The historical version number of the rule.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 409: Conflict, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/rules/{rule_id}/test\n@desc Test an existing rule\n@required {rule_id: str # The ID of the rule.}\n@optional {rule: any # Test a rule., ruleQueryPayloads: [map{expectedResult: bool, index: int(int64), payload: map}] # Data payloads used to test rules query with the expected result.}\n@returns(200) {results: [bool]} # OK\n@errors {400: Bad Request, 401: Concurrent Modification, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"rule\":{\"cases\":[{\"condition\":\"a > 0\",\"name\":\"\",\"notifications\":[],\"status\":\"info\"}],\"hasExtendedTitle\":true,\"isEnabled\":true,\"message\":\"My security monitoring rule message.\",\"name\":\"My security monitoring rule.\",\"options\":{\"decreaseCriticalityBasedOnEnv\":false,\"detectionMethod\":\"threshold\",\"evaluationWindow\":0,\"keepAlive\":0,\"maxSignalDuration\":0},\"queries\":[{\"aggregation\":\"count\",\"distinctFields\":[],\"groupByFields\":[\"@userIdentity.assumed_role\"],\"name\":\"\",\"query\":\"source:source_here\"}],\"tags\":[\"env:prod\",\"team:security\"],\"type\":\"log_detection\"},\"ruleQueryPayloads\":[{\"expectedResult\":true,\"index\":0,\"payload\":{\"ddsource\":\"source_here\",\"ddtags\":\"env:staging,version:5.1\",\"hostname\":\"i-012345678\",\"message\":\"2019-11-19T14:37:58,995 INFO [process.name][20081] Hello World\",\"service\":\"payment\",\"userIdentity\":{\"assumed_role\":\"fake assumed_role\"}}}]}\n\n@endpoint GET /api/v2/security_monitoring/rules/{rule_id}/version_history\n@desc Get a rule's version history\n@required {rule_id: str # The ID of the rule.}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return.}\n@returns(200) {data: map{attributes: map{count: int(int32), data: map}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/sample_log_generation/subscriptions\n@desc Get sample log generation subscriptions\n@optional {status: str # Filter the subscriptions by status. Use `active` to return only currently active subscriptions, or `all` to return every subscription including expired ones. Ignored when `start_timestamp` is provided. Defaults to `active`., start_timestamp: str(date-time) # The start of the time range, as an RFC3339 timestamp. When provided, the response includes every subscription that was active at any point in `[start_timestamp, end_timestamp]`, and the `status` filter is ignored., end_timestamp: str(date-time) # The end of the time range, as an RFC3339 timestamp. Ignored unless `start_timestamp` is set. Defaults to the current time when `start_timestamp` is provided.}\n@returns(200) {data: [map], meta: map{total_subscriptions: int(int32)}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/security_monitoring/sample_log_generation/subscriptions\n@desc Subscribe to sample log generation\n@required {data: map{attributes!: map, type!: str} # The subscription request body.}\n@returns(200) {data: map{attributes: map{content_pack_id: str, created_at: str(date-time), expires_at: str(date-time), is_active: bool, status: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"content_pack_id\":\"aws-cloudtrail\",\"duration\":\"3d\"},\"type\":\"subscription_requests\"}}\n\n@endpoint POST /api/v2/security_monitoring/sample_log_generation/subscriptions/bulk\n@desc Bulk subscribe to sample log generation\n@required {data: map{attributes!: map, type!: str} # The bulk subscription request body.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"content_pack_ids\":[\"aws-cloudtrail\"],\"duration\":\"3d\"},\"type\":\"bulk_subscription_requests\"}}\n\n@endpoint DELETE /api/v2/security_monitoring/sample_log_generation/subscriptions/{content_pack_id}\n@desc Unsubscribe from sample log generation\n@required {content_pack_id: str # The identifier of the Cloud SIEM content pack to operate on (for example, `aws-cloudtrail`).}\n@returns(200) {data: map{attributes: map{content_pack_id: str, created_at: str(date-time), expires_at: str(date-time), is_active: bool, status: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/security_monitoring/signals\n@desc Get a quick list of security signals\n@optional {filter[query]: str: any # The search query for security signals., filter[from]: str(date-time) # The minimum timestamp for requested security signals., filter[to]: str(date-time) # The maximum timestamp for requested security signals., sort: str # The order of the security signals in results., page[cursor]: str # A list of results using the cursor provided in the previous query., page[limit]: int(int32)=10 # The maximum number of security signals in the response.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{page: map{after: str}}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/signals/bulk/assignee\n@desc Bulk update triage assignee of security signals\n@required {data: [map{attributes!: map, id!: str, type: str}] # An array of signal assignee updates.}\n@returns(200) {result: map{count: int(int64), events: [map]}, status: str, type: str} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":[{\"attributes\":{\"assignee\":\"773b045d-ccf8-4808-bd3b-955ef6a8c940\"},\"id\":\"AAAAAWgN8Xwgr1vKDQAAAABBV2dOOFh3ZzZobm1mWXJFYTR0OA\",\"type\":\"signal\"}]}\n\n@endpoint PATCH /api/v2/security_monitoring/signals/bulk/state\n@desc Bulk update triage state of security signals\n@required {data: [map{attributes!: map, id!: str, type: str}] # An array of signal state updates.}\n@returns(200) {result: map{count: int(int64), events: [map]}, status: str, type: str} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":[{\"attributes\":{\"archive_reason\":\"none\",\"state\":\"archived\"},\"id\":\"AAAAAWgN8Xwgr1vKDQAAAABBV2dOOFh3ZzZobm1mWXJFYTR0OA\",\"type\":\"signal\"}]}\n\n@endpoint PATCH /api/v2/security_monitoring/signals/bulk/update\n@desc Bulk update security signals\n@required {data: [map{attributes!: map, id!: str, type: str}] # An array of signal updates.}\n@returns(200) {result: map{count: int(int64), events: [map]}, status: str, type: str} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":[{\"attributes\":{\"archive_reason\":\"none\",\"state\":\"archived\"},\"id\":\"AAAAAWgN8Xwgr1vKDQAAAABBV2dOOFh3ZzZobm1mWXJFYTR0OA\",\"type\":\"signal\"}]}\n\n@endpoint POST /api/v2/security_monitoring/signals/search\n@desc Get a list of security signals\n@optional {filter: map{from: str(date-time), query: str, to: str(date-time)} # Search filters for listing security signals., page: map{cursor: str, limit: int(int32)} # The paging attributes for listing security signals., sort: str(timestamp/-timestamp) # The sort parameters used for querying security signals.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{page: map{after: str}}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"filter\":{\"from\":\"2019-01-02T09:42:36.320Z\",\"query\":\"security:attack status:high\",\"to\":\"2019-01-03T09:42:36.320Z\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\",\"limit\":25},\"sort\":\"timestamp\"}\n\n@endpoint GET /api/v2/security_monitoring/signals/{signal_id}\n@desc Get a signal's details\n@required {signal_id: str # The ID of the signal.}\n@returns(200) {data: map{attributes: map{custom: map, message: str, tags: [str], timestamp: str(date-time)}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/signals/{signal_id}/assignee\n@desc Modify the triage assignee of a security signal\n@required {signal_id: str # The ID of the signal., data: map{attributes!: map} # Data containing the patch for changing the assignee of a signal.}\n@returns(200) {data: map{attributes: map{archive_comment: str, archive_comment_timestamp: int(int64), archive_comment_user: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}, archive_reason: str, assignee: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}, incident_ids: [int(int64)], state: str, state_update_timestamp: int(int64), state_update_user: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"assignee\":{\"uuid\":\"773b045d-ccf8-4808-bd3b-955ef6a8c940\"}}}}\n\n@endpoint GET /api/v2/security_monitoring/signals/{signal_id}/entities\n@desc Get entities related to a signal\n@required {signal_id: str # The ID of the signal.}\n@optional {limit: int(int32)=10 # The maximum number of entities to return.}\n@returns(200) {data: map{attributes: map{identities: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/signals/{signal_id}/incidents\n@desc Change the related incidents of a security signal\n@required {signal_id: str # The ID of the signal., data: map{attributes!: map} # Data containing the patch for changing the related incidents of a signal.}\n@returns(200) {data: map{attributes: map{archive_comment: str, archive_comment_timestamp: int(int64), archive_comment_user: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}, archive_reason: str, assignee: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}, incident_ids: [int(int64)], state: str, state_update_timestamp: int(int64), state_update_user: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"incident_ids\":[2066]}}}\n\n@endpoint GET /api/v2/security_monitoring/signals/{signal_id}/investigation_queries\n@desc Get investigation queries for a signal\n@required {signal_id: str # The ID of the signal.}\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/signals/{signal_id}/state\n@desc Change the triage state of a security signal\n@required {signal_id: str # The ID of the signal., data: map{attributes!: map, id: any, type: str} # Data containing the patch for changing the state of a signal.}\n@returns(200) {data: map{attributes: map{archive_comment: str, archive_comment_timestamp: int(int64), archive_comment_user: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}, archive_reason: str, assignee: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}, incident_ids: [int(int64)], state: str, state_update_timestamp: int(int64), state_update_user: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"archive_reason\":\"none\",\"state\":\"archived\"},\"type\":\"signal_metadata\"}}\n\n@endpoint GET /api/v2/security_monitoring/signals/{signal_id}/suggested_actions\n@desc Get suggested actions for a signal\n@required {signal_id: str # The ID of the signal.}\n@returns(200) {data: [map]} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/security_monitoring/signals/{signal_id}/update\n@desc Update security signal triage state or assignee\n@required {signal_id: str # The ID of the signal., data: map{attributes!: map, type: str} # Data containing the triage state or assignee update for a security signal.}\n@returns(200) {data: map{attributes: map{archive_comment: str, archive_comment_timestamp: int(int64), archive_comment_user: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}, archive_reason: str, assignee: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}, incident_ids: [int(int64)], state: str, state_update_timestamp: int(int64), state_update_user: map{handle: str, icon: str, id: int(int64), name: str?, uuid: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"archive_reason\":\"none\",\"state\":\"archived\"},\"type\":\"signal_metadata\"}}\n\n@endpoint POST /api/v2/security_monitoring/terraform/{resource_type}/bulk\n@desc Export security monitoring resources to Terraform\n@required {resource_type: str # The type of security monitoring resource to export., data: map{attributes!: map, type!: str} # The bulk export request data object.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"resource_ids\":[\"abc-123-def\"]},\"type\":\"bulk_export_resources\"}}\n\n@endpoint POST /api/v2/security_monitoring/terraform/{resource_type}/convert\n@desc Convert security monitoring resource to Terraform\n@required {resource_type: str # The type of security monitoring resource to export., data: map{attributes!: map, id!: str, type!: str} # The convert request data object.}\n@returns(200) {data: map{attributes: map{output: str, resource_id: str, type_name: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"resource_json\":{\"enabled\":true,\"name\":\"Example-Security-Monitoring\",\"rule_query\":\"source:cloudtrail\",\"suppression_query\":\"env:test\"}},\"id\":\"abc-123\",\"type\":\"convert_resource\"}}\n\n@endpoint GET /api/v2/security_monitoring/terraform/{resource_type}/{resource_id}\n@desc Export security monitoring resource to Terraform\n@required {resource_type: str # The type of security monitoring resource to export., resource_id: str # The ID of the security monitoring resource to export.}\n@returns(200) {data: map{attributes: map{output: str, resource_id: str, type_name: str}, id: str, type: str}} # OK\n@errors {403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/sensitive-data-scanner/config\n@desc List Scanning Groups\n@returns(200) {data: map{attributes: map, id: str, relationships: map{groups: map{data: [map]}}, type: str}, included: [any], meta: map{count_limit: int(int64), group_count_limit: int(int64), has_highlight_enabled: bool, has_multi_pass_enabled: bool, is_pci_compliant: bool, version: int(int64)}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 429: Too many requests}\n\n@endpoint PATCH /api/v2/sensitive-data-scanner/config\n@desc Reorder Groups\n@required {data: map{id: str, relationships: map, type: str} # Data related to the reordering of scanning groups., meta: map{version: int(int64)} # Meta payload containing information about the API.}\n@returns(200) {meta: map{count_limit: int(int64), group_count_limit: int(int64), has_highlight_enabled: bool, has_multi_pass_enabled: bool, is_pci_compliant: bool, version: int(int64)}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 429: Too many requests}\n@example_request {\"data\":{\"relationships\":{\"groups\":{\"data\":[{\"id\":\"a796feff-a0cc-4a9f-8c61-16c4d5e44964\",\"type\":\"sensitive_data_scanner_group\"}]}},\"type\":\"sensitive_data_scanner_configuration\"},\"meta\":{\"version\":0}}\n\n@endpoint POST /api/v2/sensitive-data-scanner/config/groups\n@desc Create Scanning Group\n@optional {data: map{attributes!: map, relationships: map, type!: str} # Data related to the creation of a group., meta: map{version: int(int64)} # Meta payload containing information about the API.}\n@returns(201) {data: map{attributes: map{description: str, filter: map{query: str}, is_enabled: bool, name: str, product_list: [str], samplings: [map]}, id: str, relationships: map{configuration: map{data: map}, rules: map{data: [map]}}, type: str}, meta: map{version: int(int64)}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"filter\":{\"query\":\"*\"},\"is_enabled\":false,\"product_list\":[\"logs\"],\"samplings\":[{\"product\":\"logs\",\"rate\":100}]},\"relationships\":{\"configuration\":{\"data\":{\"type\":\"sensitive_data_scanner_configuration\"}}},\"type\":\"sensitive_data_scanner_group\"},\"meta\":{\"version\":0}}\n\n@endpoint DELETE /api/v2/sensitive-data-scanner/config/groups/{group_id}\n@desc Delete Scanning Group\n@required {group_id: str # The ID of a group of rules., meta: map{version: int(int64)} # Meta payload containing information about the API.}\n@returns(200) {meta: map{version: int(int64)}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 404: Not Found, 429: Too many requests}\n@example_request {\"meta\":{\"version\":0}}\n\n@endpoint PATCH /api/v2/sensitive-data-scanner/config/groups/{group_id}\n@desc Update Scanning Group\n@required {group_id: str # The ID of a group of rules., data: map{attributes: map, id: str, relationships: map, type: str} # Data related to the update of a group., meta: map{version: int(int64)} # Meta payload containing information about the API.}\n@returns(200) {meta: map{version: int(int64)}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"filter\":{\"query\":\"*\"},\"is_enabled\":false,\"product_list\":[\"logs\"],\"samplings\":[{\"product\":\"logs\",\"rate\":100}]},\"relationships\":{\"configuration\":{\"data\":{\"type\":\"sensitive_data_scanner_configuration\"}}},\"type\":\"sensitive_data_scanner_group\"},\"meta\":{\"version\":0}}\n\n@endpoint POST /api/v2/sensitive-data-scanner/config/rules\n@desc Create Scanning Rule\n@required {data: map{attributes!: map, relationships!: map, type!: str} # Data related to the creation of a rule., meta: map{version: int(int64)} # Meta payload containing information about the API.}\n@returns(201) {data: map{attributes: map{description: str, excluded_namespaces: [str], included_keyword_configuration: map{character_count: int(int64), keywords: [str], use_recommended_keywords: bool}, is_enabled: bool, name: str, namespaces: [str], pattern: str, priority: int(int64), suppressions: map{ends_with: [str], exact_match: [str], starts_with: [str]}, tags: [str], text_replacement: map{number_of_chars: int(int64), replacement_string: str, should_save_match: bool, type: str}}, id: str, relationships: map{group: map{data: map}, standard_pattern: map{data: map}}, type: str}, meta: map{version: int(int64)}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"excluded_namespaces\":[\"admin.name\"],\"included_keyword_configuration\":{\"character_count\":30,\"keywords\":[\"email\",\"address\",\"login\"]},\"is_enabled\":true,\"namespaces\":[\"admin\"],\"suppressions\":{\"ends_with\":[\"@example.com\",\"another.example.com\"],\"exact_match\":[\"admin@example.com\",\"user@example.com\"],\"starts_with\":[\"admin\",\"user\"]},\"tags\":[\"sensitive_data:true\"],\"text_replacement\":{\"type\":\"none\"}},\"relationships\":{\"group\":{\"data\":{\"type\":\"sensitive_data_scanner_group\"}},\"standard_pattern\":{\"data\":{\"type\":\"sensitive_data_scanner_standard_pattern\"}}},\"type\":\"sensitive_data_scanner_rule\"},\"meta\":{\"version\":0}}\n\n@endpoint DELETE /api/v2/sensitive-data-scanner/config/rules/{rule_id}\n@desc Delete Scanning Rule\n@required {rule_id: str # The ID of the rule., meta: map{version: int(int64)} # Meta payload containing information about the API.}\n@returns(200) {meta: map{version: int(int64)}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 404: Not Found, 429: Too many requests}\n@example_request {\"meta\":{\"version\":0}}\n\n@endpoint PATCH /api/v2/sensitive-data-scanner/config/rules/{rule_id}\n@desc Update Scanning Rule\n@required {rule_id: str # The ID of the rule., data: map{attributes: map, id: str, relationships: map, type: str} # Data related to the update of a rule., meta: map{version: int(int64)} # Meta payload containing information about the API.}\n@returns(200) {meta: map{version: int(int64)}} # OK\n@errors {400: Bad Request, 403: Authentication Error, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"excluded_namespaces\":[\"admin.name\"],\"included_keyword_configuration\":{\"character_count\":30,\"keywords\":[\"email\",\"address\",\"login\"]},\"is_enabled\":true,\"namespaces\":[\"admin\"],\"suppressions\":{\"ends_with\":[\"@example.com\",\"another.example.com\"],\"exact_match\":[\"admin@example.com\",\"user@example.com\"],\"starts_with\":[\"admin\",\"user\"]},\"tags\":[\"sensitive_data:true\"],\"text_replacement\":{\"type\":\"none\"}},\"relationships\":{\"group\":{\"data\":{\"type\":\"sensitive_data_scanner_group\"}},\"standard_pattern\":{\"data\":{\"type\":\"sensitive_data_scanner_standard_pattern\"}}},\"type\":\"sensitive_data_scanner_rule\"},\"meta\":{\"version\":0}}\n\n@endpoint GET /api/v2/sensitive-data-scanner/config/standard-patterns\n@desc List standard patterns\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Authentication Error, 429: Too many requests}\n\n@endpoint POST /api/v2/series\n@desc Submit metrics\n@required {series: [map{interval: int(int64), metadata: map, metric!: str, points!: [map], resources: [map], source_type_name: str, tags: [str], type: int(int32), unit: str}] # A list of timeseries to submit to Datadog.}\n@optional {Content-Encoding: str # HTTP header used to compress the media-type.}\n@returns(202) {errors: [str]} # Payload accepted\n@errors {400: Bad Request, 403: Authentication error, 408: Request timeout, 413: Payload too large, 429: Too many requests}\n@example_request {\"series\":[{\"metric\":\"system.load.1\",\"points\":[{\"timestamp\":1636629071,\"value\":1.1}],\"resources\":[{\"name\":\"dummyhost\",\"type\":\"host\"}],\"type\":0}]}\n\n@endpoint POST /api/v2/service_accounts\n@desc Create a service account\n@required {data: map{attributes!: map, relationships: map, type!: str} # Object to create a service account User.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), disabled: bool, email: str, handle: str, icon: str, last_login_time: str(date-time)?, mfa_enabled: bool, modified_at: str(date-time), name: str?, service_account: bool, status: str, title: str?, uuid: str, verified: bool}, id: str, relationships: map{org: map{data: map}, other_orgs: map{data: [map]}, other_users: map{data: [map]}, roles: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Authentication error, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"email\":\"jane.doe@example.com\",\"service_account\":true},\"relationships\":{\"roles\":{\"data\":[{\"id\":\"3653d3c6-0c75-11ea-ad28-fb5701eabc7d\"}]}},\"type\":\"users\"}}\n\n@endpoint GET /api/v2/service_accounts/{service_account_id}/access_tokens\n@desc List access tokens for a service account\n@required {service_account_id: str # The ID of the service account.}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # Access token attribute used to sort results. Sort order is ascending by default. In order to specify a descending sort, prefix the attribute with a minus sign., filter: str # Filter access tokens by the specified string.}\n@returns(200) {data: [map], meta: map{page: map{total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/service_accounts/{service_account_id}/access_tokens\n@desc Create an access token for a service account\n@required {service_account_id: str # The ID of the service account., data: map{attributes!: map, type!: str} # Object used to create a service account access token.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), expires_at: str(date-time)?, key: str, name: str, public_portion: str, scopes: [str]}, id: str, relationships: map{owned_by: map{data: map}}, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Service Account Access Token\",\"scopes\":[\"dashboards_read\",\"dashboards_write\"]},\"type\":\"service_access_tokens\"}}\n\n@endpoint DELETE /api/v2/service_accounts/{service_account_id}/access_tokens/{token_id}\n@desc Revoke an access token for a service account\n@required {service_account_id: str # The ID of the service account., token_id: str # The ID of the access token.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/service_accounts/{service_account_id}/access_tokens/{token_id}\n@desc Get an access token for a service account\n@required {service_account_id: str # The ID of the service account., token_id: str # The ID of the access token.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), expires_at: str(date-time)?, last_used_at: str(date-time)?, modified_at: str(date-time)?, name: str, public_portion: str, scopes: [str]}, id: str, relationships: map{owned_by: map{data: map}}, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/service_accounts/{service_account_id}/access_tokens/{token_id}\n@desc Update an access token for a service account\n@required {service_account_id: str # The ID of the service account., token_id: str # The ID of the access token., data: map{attributes!: map, id!: str, type!: str} # Object used to update a service account access token.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), expires_at: str(date-time)?, last_used_at: str(date-time)?, modified_at: str(date-time)?, name: str, public_portion: str, scopes: [str]}, id: str, relationships: map{owned_by: map{data: map}}, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Updated Service Access Token\",\"scopes\":[\"dashboards_read\",\"dashboards_write\"]},\"id\":\"00112233-4455-6677-8899-aabbccddeeff\",\"type\":\"service_access_tokens\"}}\n\n@endpoint GET /api/v2/service_accounts/{service_account_id}/application_keys\n@desc List application keys for this service account\n@required {service_account_id: str # The ID of the service account.}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # Application key attribute used to sort results. Sort order is ascending by default. In order to specify a descending sort, prefix the attribute with a minus sign., filter: str # Filter application keys by the specified string., filter[created_at][start]: str # Only include application keys created on or after the specified date., filter[created_at][end]: str # Only include application keys created on or before the specified date.}\n@returns(200) {data: [map], included: [any], meta: map{max_allowed_per_user: int(int64), page: map{total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/service_accounts/{service_account_id}/application_keys\n@desc Create an application key for this service account\n@required {service_account_id: str # The ID of the service account., data: map{attributes!: map, type!: str} # Object used to create an application key.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), key: str, last4: str, last_used_at: str(date-time)?, name: str, scopes: [str]?}, id: str, relationships: map{owned_by: map{data: map}}, type: str}, included: [any]} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Application Key for managing dashboards\",\"scopes\":[\"dashboards_read\",\"dashboards_write\",\"dashboards_public_share\"]},\"type\":\"application_keys\"}}\n\n@endpoint DELETE /api/v2/service_accounts/{service_account_id}/application_keys/{app_key_id}\n@desc Delete an application key for this service account\n@required {service_account_id: str # The ID of the service account., app_key_id: str # The ID of the application key.}\n@returns(204) No Content\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/service_accounts/{service_account_id}/application_keys/{app_key_id}\n@desc Get one application key for this service account\n@required {service_account_id: str # The ID of the service account., app_key_id: str # The ID of the application key.}\n@returns(200) {data: map{attributes: map{created_at: str, last4: str, last_used_at: str?, name: str, scopes: [str]?}, id: str, relationships: map{owned_by: map{data: map}}, type: str}, included: [any]} # OK\n@errors {403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/service_accounts/{service_account_id}/application_keys/{app_key_id}\n@desc Edit an application key for this service account\n@required {service_account_id: str # The ID of the service account., app_key_id: str # The ID of the application key., data: map{attributes!: map, id!: str, type!: str} # Object used to update an application key.}\n@returns(200) {data: map{attributes: map{created_at: str, last4: str, last_used_at: str?, name: str, scopes: [str]?}, id: str, relationships: map{owned_by: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Application Key for managing dashboards\",\"scopes\":[\"dashboards_read\",\"dashboards_write\",\"dashboards_public_share\"]},\"id\":\"00112233-4455-6677-8899-aabbccddeeff\",\"type\":\"application_keys\"}}\n\n@endpoint GET /api/v2/services/definitions\n@desc Get all service definitions\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., schema_version: str # The schema version desired in the response.}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/services/definitions\n@desc Create or update service definition\n@returns(200) {data: [map]} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"application\":\"my-app\",\"ci-pipeline-fingerprints\":[\"j88xdEy0J5lc\",\"eZ7LMljCk8vo\"],\"contacts\":[{\"contact\":\"https://teams.microsoft.com/myteam\",\"name\":\"My team channel\",\"type\":\"slack\"}],\"dd-service\":\"my-service\",\"description\":\"My service description\",\"extensions\":{\"myorg/extension\":\"extensionValue\"},\"integrations\":{\"opsgenie\":{\"region\":\"US\",\"service-url\":\"https://my-org.opsgenie.com/service/123e4567-e89b-12d3-a456-426614174000\"},\"pagerduty\":{\"service-url\":\"https://my-org.pagerduty.com/service-directory/PMyService\"}},\"languages\":[\"dotnet\",\"go\",\"java\",\"js\",\"php\",\"python\",\"ruby\",\"c++\"],\"lifecycle\":\"sandbox\",\"links\":[{\"name\":\"Runbook\",\"provider\":\"Github\",\"type\":\"runbook\",\"url\":\"https://my-runbook\"}],\"schema-version\":\"v2.2\",\"tags\":[\"my:tag\",\"service:tag\"],\"team\":\"my-team\",\"tier\":\"High\",\"type\":\"web\"}\n\n@endpoint DELETE /api/v2/services/definitions/{service_name}\n@desc Delete a single service definition\n@required {service_name: str # The name of the service.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/services/definitions/{service_name}\n@desc Get a single service definition\n@required {service_name: str # The name of the service.}\n@optional {schema_version: str # The schema version desired in the response.}\n@returns(200) {data: map{attributes: map{meta: map{github-html-url: str, ingested-schema-version: str, ingestion-source: str, last-modified-time: str, origin: str, origin-detail: str, warnings: [map]}, schema: any}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 409: Conflict, 429: Too many requests}\n\n@endpoint GET /api/v2/siem-historical-detections/histsignals\n@desc List hist signals\n@optional {filter[query]: str: any # The search query for security signals., filter[from]: str(date-time) # The minimum timestamp for requested security signals., filter[to]: str(date-time) # The maximum timestamp for requested security signals., sort: str # The order of the security signals in results., page[cursor]: str # A list of results using the cursor provided in the previous query., page[limit]: int(int32)=10 # The maximum number of security signals in the response.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{page: map{after: str}}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/siem-historical-detections/histsignals/search\n@desc Search hist signals\n@optional {filter: map{from: str(date-time), query: str, to: str(date-time)} # Search filters for listing security signals., page: map{cursor: str, limit: int(int32)} # The paging attributes for listing security signals., sort: str(timestamp/-timestamp) # The sort parameters used for querying security signals.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{page: map{after: str}}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"filter\":{\"from\":\"2019-01-02T09:42:36.320Z\",\"query\":\"security:attack status:high\",\"to\":\"2019-01-03T09:42:36.320Z\"},\"page\":{\"limit\":25},\"sort\":\"timestamp\"}\n\n@endpoint GET /api/v2/siem-historical-detections/histsignals/{histsignal_id}\n@desc Get a hist signal's details\n@required {histsignal_id: str # The ID of the historical signal.}\n@returns(200) {data: map{attributes: map{custom: map, message: str, tags: [str], timestamp: str(date-time)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/siem-historical-detections/jobs\n@desc List historical jobs\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # The order of the jobs in results., filter[query]: str # Query used to filter items from the fetched list.}\n@returns(200) {data: [map], meta: map{totalCount: int(int32)}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/siem-historical-detections/jobs\n@desc Run a historical job\n@optional {data: map{attributes: map, type: str} # Data for running a historical job request.}\n@returns(201) {data: map{id: str, type: str}} # Status created\n@errors {400: Bad Request, 401: Concurrent Modification, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"jobDefinition\":{\"cases\":[{\"condition\":\"a > 1\",\"name\":\"Condition 1\",\"notifications\":[],\"status\":\"info\"}],\"from\":1730387522611,\"index\":\"main\",\"message\":\"A large number of failed login attempts.\",\"name\":\"Excessive number of failed attempts.\",\"options\":{\"evaluationWindow\":900,\"keepAlive\":3600,\"maxSignalDuration\":86400},\"queries\":[{\"aggregation\":\"count\",\"distinctFields\":[],\"groupByFields\":[],\"query\":\"source:non_existing_src_weekend\"}],\"tags\":[],\"to\":1730391122611,\"type\":\"log_detection\"}},\"type\":\"historicalDetectionsJobCreate\"}}\n\n@endpoint POST /api/v2/siem-historical-detections/jobs/signal_convert\n@desc Convert a job result to a signal\n@optional {data: map{attributes: map, type: str} # Data for converting historical job results to signals.}\n@returns(204) OK\n@errors {400: Bad Request, 401: Concurrent Modification, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"jobResultIds\":[\"\"],\"notifications\":[\"\"],\"signalMessage\":\"A large number of failed login attempts.\",\"signalSeverity\":\"critical\"},\"type\":\"historicalDetectionsJobResultSignalConversion\"}}\n\n@endpoint DELETE /api/v2/siem-historical-detections/jobs/{job_id}\n@desc Delete an existing job\n@required {job_id: str # The ID of the job.}\n@returns(204) OK\n@errors {400: Bad Request, 401: Concurrent Modification, 403: Not Authorized, 404: Not Found, 409: Conflict, 429: Too many requests}\n\n@endpoint GET /api/v2/siem-historical-detections/jobs/{job_id}\n@desc Get a job's details\n@required {job_id: str # The ID of the job.}\n@returns(200) {data: map{attributes: map{createdAt: str, createdByHandle: str, createdByName: str, createdFromRuleId: str, jobDefinition: map{calculatedFields: [map], cases: [map], from: int(int64), groupSignalsBy: [str], index: str, message: str, name: str, options: map, queries: [map], referenceTables: [map], tags: [str], thirdPartyCases: [map], to: int(int64), type: str}, jobName: str, jobStatus: str, modifiedAt: str, progressRate: num(double), signalOutput: bool}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/siem-historical-detections/jobs/{job_id}/cancel\n@desc Cancel a historical job\n@required {job_id: str # The ID of the job.}\n@returns(204) OK\n@errors {400: Bad Request, 401: Concurrent Modification, 403: Not Authorized, 404: Not Found, 409: Conflict, 429: Too many requests}\n\n@endpoint GET /api/v2/siem-historical-detections/jobs/{job_id}/histsignals\n@desc Get a job's hist signals\n@required {job_id: str # The ID of the job.}\n@optional {filter[query]: str: any # The search query for security signals., filter[from]: str(date-time) # The minimum timestamp for requested security signals., filter[to]: str(date-time) # The maximum timestamp for requested security signals., sort: str # The order of the security signals in results., page[cursor]: str # A list of results using the cursor provided in the previous query., page[limit]: int(int32)=10 # The maximum number of security signals in the response.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{page: map{after: str}}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/slo/report\n@desc Create a new SLO report\n@required {data: map{attributes!: map} # The data portion of the SLO report request.}\n@returns(200) {data: map{id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"from_ts\":1690901870,\"interval\":\"weekly\",\"query\":\"slo_type:metric\",\"timezone\":\"America/New_York\",\"to_ts\":1706803070}}}\n\n@endpoint GET /api/v2/slo/report/{report_id}/download\n@desc Get SLO report\n@required {report_id: str # The ID of the report job.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/slo/report/{report_id}/status\n@desc Get SLO report status\n@required {report_id: str # The ID of the report job.}\n@returns(200) {data: map{attributes: map{status: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/slo/{slo_id}/status\n@desc Get SLO status\n@required {slo_id: str # The ID of the SLO., from_ts: int(int64) # The starting timestamp for the SLO status query in epoch seconds., to_ts: int(int64) # The ending timestamp for the SLO status query in epoch seconds.}\n@optional {disable_corrections: bool=false # Whether to exclude correction windows from the SLO status calculation. Defaults to false.}\n@returns(200) {data: map{attributes: map{error_budget_remaining: num(double), raw_error_budget_remaining: map{unit: str, value: num(double)}, sli: num(double), span_precision: int(int64), state: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/snapshot\n@desc Create a graph snapshot\n@required {data: map{attributes!: map, type!: str} # Data envelope for snapshot creation.}\n@returns(200) {data: map{attributes: map{url: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/sourcemaps\n@desc Delete source maps\n@required {mapkind: str # The type of source map. Valid values are `js`, `jvm`, `ios`, `react`, `flutter`, `elf`, `ndk`, `il2cpp`., dry_run: bool # When set to `true`, returns the source maps that would be deleted without performing the actual deletion. When set to `false`, performs the deletion.}\n@optional {filter[service]: [str]: any # Filter by service names (multiple values allowed). Required for `js`, `jvm`, `react`, and `flutter` map kinds., filter[version]: [str] # Filter by version values (multiple values allowed, maximum 10). Required for `js`, `jvm`, `react`, and `flutter` map kinds., filter[variant]: [str] # Filter by variant values (multiple values allowed). Supported for `jvm`., filter[id]: [str] # Filter by source map ID values (multiple values allowed). Supported for all map kinds., filter[build_id]: [str] # Filter by build ID values (multiple values allowed). Supported for `jvm`, `ndk`, and `il2cpp`., filter[uuid]: [str] # Filter by UUID values (multiple values allowed). Supported for `ios`., filter[platform]: [str] # Filter by platform values (multiple values allowed). Supported for `react`., filter[build_number]: [str] # Filter by build number values (multiple values allowed). Supported for `react`., filter[bundle_name]: [str] # Filter by bundle name values (multiple values allowed). Supported for `react`., filter[arch]: [str] # Filter by architecture values (multiple values allowed). Supported for `flutter`, `elf`, and `ndk`., filter[symbol_source]: [str] # Filter by symbol source values (multiple values allowed). Supported for `elf`., filter[origin]: [str] # Filter by origin values (multiple values allowed). Supported for `elf`., filter[origin_version]: [str] # Filter by origin version values (multiple values allowed). Supported for `elf`., filter[filename]: str # Filter by filename (single value). Supported for `js`, `elf`, and `ndk`., filter[debug_id]: str # Filter by debug ID (single value). Supported for `react`., filter[gnu_build_id]: str # Filter by GNU build ID (single value). Supported for `elf`., filter[go_build_id]: str # Filter by Go build ID (single value). Supported for `elf`., filter[file_hash]: str # Filter by file hash (single value). Supported for `elf`.}\n@returns(200) {data: [any]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/sourcemaps\n@desc Get a JavaScript source map\n@required {filename: str # The path to the source map file., service: str # The service name associated with the source map., version: str # The version of the service associated with the source map.}\n@returns(200) {data: map{attributes: map{file: str, mappings: str, minifiedLineLengths: [int(int64)], names: [any], sourceRoot: str, sources: [str], sourcesContent: [str], version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/sourcemaps/list\n@desc List source maps\n@optional {mapkind: str # The type of source map. Defaults to `js`., page[size]: int(int64)=20 # The number of results to return per page. Must be at least 1., page[number]: int(int64)=1 # The page number to retrieve, starting from 1., filter[service]: [str] # Filter by service names (multiple values allowed). Required for `js`, `jvm`, `react`, and `flutter` map kinds., filter[version]: [str] # Filter by version values (multiple values allowed). Required for `js`, `jvm`, `react`, and `flutter` map kinds., filter[variant]: [str] # Filter by variant values (multiple values allowed). Supported for `jvm`., filter[id]: [str] # Filter by source map ID values (multiple values allowed). Supported for all map kinds., filter[build_id]: [str] # Filter by build ID values (multiple values allowed). Supported for `jvm`, `ndk`, and `il2cpp`., filter[uuid]: [str] # Filter by UUID values (multiple values allowed). Supported for `ios`., filter[platform]: [str] # Filter by platform values (multiple values allowed). Supported for `react`., filter[build_number]: [str] # Filter by build number values (multiple values allowed). Supported for `react`., filter[bundle_name]: [str] # Filter by bundle name values (multiple values allowed). Supported for `react`., filter[arch]: [str] # Filter by architecture values (multiple values allowed). Supported for `flutter`, `elf`, and `ndk`., filter[symbol_source]: [str] # Filter by symbol source values (multiple values allowed). Supported for `elf`., filter[origin]: [str] # Filter by origin values (multiple values allowed). Supported for `elf`., filter[origin_version]: [str] # Filter by origin version values (multiple values allowed). Supported for `elf`., filter[filename]: str # Filter by filename (single value). Supported for `js`, `elf`, and `ndk`., filter[debug_id]: str # Filter by debug ID (single value). Supported for `react`., filter[gnu_build_id]: str # Filter by GNU build ID (single value). Supported for `elf`., filter[go_build_id]: str # Filter by Go build ID (single value). Supported for `elf`., filter[file_hash]: str # Filter by file hash (single value). Supported for `elf`.}\n@returns(200) {data: [any], meta: map{page: map{has_more_results: bool, total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 413: Request Entity Too Large, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint PATCH /api/v2/sourcemaps/restore\n@desc Restore source maps\n@required {mapkind: str # The type of source map. Valid values are `js`, `jvm`, `ios`, `react`, `flutter`, `elf`, `ndk`, `il2cpp`., dry_run: bool # When set to `true`, returns the source maps that would be restored without performing the actual restoration. When set to `false`, performs the restoration.}\n@optional {filter[service]: [str]: any # Filter by service names (multiple values allowed). Required for `js`, `jvm`, `react`, and `flutter` map kinds., filter[version]: [str] # Filter by version values (multiple values allowed, maximum 10). Required for `js`, `jvm`, `react`, and `flutter` map kinds., filter[variant]: [str] # Filter by variant values (multiple values allowed). Supported for `jvm`., filter[id]: [str] # Filter by source map ID values (multiple values allowed). Supported for all map kinds., filter[build_id]: [str] # Filter by build ID values (multiple values allowed). Supported for `jvm`, `ndk`, and `il2cpp`., filter[uuid]: [str] # Filter by UUID values (multiple values allowed). Supported for `ios`., filter[platform]: [str] # Filter by platform values (multiple values allowed). Supported for `react`., filter[build_number]: [str] # Filter by build number values (multiple values allowed). Supported for `react`., filter[bundle_name]: [str] # Filter by bundle name values (multiple values allowed). Supported for `react`., filter[arch]: [str] # Filter by architecture values (multiple values allowed). Supported for `flutter`, `elf`, and `ndk`., filter[symbol_source]: [str] # Filter by symbol source values (multiple values allowed). Supported for `elf`., filter[origin]: [str] # Filter by origin values (multiple values allowed). Supported for `elf`., filter[origin_version]: [str] # Filter by origin version values (multiple values allowed). Supported for `elf`., filter[filename]: str # Filter by filename (single value). Supported for `js`, `elf`, and `ndk`., filter[debug_id]: str # Filter by debug ID (single value). Supported for `react`., filter[gnu_build_id]: str # Filter by GNU build ID (single value). Supported for `elf`., filter[go_build_id]: str # Filter by Go build ID (single value). Supported for `elf`., filter[file_hash]: str # Filter by file hash (single value). Supported for `elf`.}\n@returns(200) {data: [any]} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/sourcemaps/service_repository_info\n@desc Get service repository information\n@required {data: map{attributes!: map, type!: str} # Data object for the service repository info request.}\n@returns(200) {data: map{attributes: map{commit_sha: str, repository_url: str, status: str}, id: str, type: str}} # OK\n@errors {401: Unauthorized, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"service\":\"my-web-service\",\"version\":\"1.0.0\"},\"type\":\"service_repository_info\"}}\n\n@endpoint GET /api/v2/spa/recommendations/{service}\n@desc Get SPA Recommendations\n@required {service: str # The service name for a spark job.}\n@optional {bypass_cache: str # The recommendation service should not use its metrics cache.}\n@returns(200) {data: map{attributes: map{confidence_level: num(double), driver: map{estimation: map}, executor: map{estimation: map}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/spa/recommendations/{service}/{shard}\n@desc Get SPA Recommendations with a shard parameter\n@required {shard: str # The shard tag for a spark job, which differentiates jobs within the same service that have different resource needs, service: str # The service name for a spark job}\n@optional {bypass_cache: str # The recommendation service should not use its metrics cache.}\n@returns(200) {data: map{attributes: map{confidence_level: num(double), driver: map{estimation: map}, executor: map{estimation: map}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n\n@endpoint POST /api/v2/spans/analytics/aggregate\n@desc Aggregate spans\n@optional {data: map{attributes: map, type: str} # The object containing the query content.}\n@returns(200) {data: [map], meta: map{elapsed: int(int64), request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"compute\":[{\"aggregation\":\"pc90\",\"interval\":\"5m\",\"metric\":\"@duration\",\"type\":\"timeseries\"}],\"filter\":{\"from\":\"now-15m\",\"query\":\"service:web* AND @http.status_code:[200 TO 299]\",\"to\":\"now\"},\"group_by\":[{\"facet\":\"host\",\"histogram\":{\"interval\":10,\"max\":100,\"min\":50},\"sort\":{\"aggregation\":\"count\",\"order\":\"asc\"}}],\"options\":{\"timezone\":\"GMT\"}},\"type\":\"aggregate_request\"}}\n\n@endpoint GET /api/v2/spans/events\n@desc Get a list of spans\n@optional {filter[query]: str: any # Search query following spans syntax., filter[from]: str # Minimum timestamp for requested spans. Supports date-time ISO8601, date math, and regular timestamps (milliseconds)., filter[to]: str # Maximum timestamp for requested spans. Supports date-time ISO8601, date math, and regular timestamps (milliseconds)., sort: str # Order of spans in results., page[cursor]: str # List following results with a cursor provided in the previous query., page[limit]: int(int32)=10 # Maximum number of spans in the response.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request., 403:Forbidden: Access denied., 422: Unprocessable Entity., 429: Too many requests: The rate limit set by the API has been exceeded.}\n\n@endpoint POST /api/v2/spans/events/search\n@desc Search spans\n@optional {data: map{attributes: map, type: str} # The object containing the query content.}\n@returns(200) {data: [map], links: map{next: str}, meta: map{elapsed: int(int64), page: map{after: str}, request_id: str, status: str, warnings: [map]}} # OK\n@errors {400: Bad Request., 403:Forbidden: Access denied., 422: Unprocessable Entity., 429: Too many requests: The rate limit set by the API has been exceeded.}\n@example_request {\"data\":{\"attributes\":{\"filter\":{\"from\":\"now-15m\",\"query\":\"service:web* AND @http.status_code:[200 TO 299]\",\"to\":\"now\"},\"options\":{\"timezone\":\"GMT\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\",\"limit\":25},\"sort\":\"timestamp\"},\"type\":\"search_request\"}}\n\n@endpoint POST /api/v2/static-analysis-sca/dependencies\n@desc Post dependencies for analysis\n@optional {data: map{attributes: map, id: str, type!: str} # The data object in an SCA request, containing the dependency graph attributes and request type.}\n@returns(200) OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"type\":\"scarequests\"}}\n\n@endpoint POST /api/v2/static-analysis-sca/dependencies/scan\n@desc Submit libraries for vulnerability scanning\n@required {data: map{attributes!: map, id: str, type!: str} # The data object in an MCP SCA scan request, containing the scan attributes and request type.}\n@returns(202) {data: map{attributes: map{job_id: str}, id: str, type: str}} # Accepted\n@errors {400: Bad Request, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"commit_hash\":\"0e9fc8de83eaabecd722e1cd0ed44fb489fe15fc\",\"libraries\":[{\"exclusions\":[],\"is_dev\":false,\"is_direct\":true,\"package_manager\":\"nuget\",\"purl\":\"pkg:nuget/Newtonsoft.Json@13.0.1\",\"target_frameworks\":[\"net8.0\"]}],\"resource_name\":\"my-org/my-repo\"},\"type\":\"mcpscanrequest\"}}\n\n@endpoint GET /api/v2/static-analysis-sca/dependencies/scan/{job_id}\n@desc Retrieve a dependency scan result\n@required {job_id: str # The job identifier returned when the scan was submitted.}\n@returns(200) OK\n@errors {404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/static-analysis-sca/licenses/list\n@desc Get the list of SPDX licenses\n@returns(200) {data: map{attributes: map{licenses: [map]}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/static-analysis-sca/vulnerabilities/resolve-vulnerable-symbols\n@desc POST request to resolve vulnerable symbols\n@optional {data: map{attributes: map, id: str, type!: str} # The data object in a request to resolve vulnerable symbols, containing the package PURLs and request type.}\n@returns(200) {data: map{attributes: map{results: [map]}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"type\":\"resolve-vulnerable-symbols-request\"}}\n\n@endpoint GET /api/v2/static-analysis/ai/memory\n@desc List AI memory violation results\n@returns(200) {data: [map]} # Successful response\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/static-analysis/ai/memory\n@desc Create an AI memory violation result\n@optional {data: map{attributes: map, id: str, type: str} # Request data for creating an AI memory violation result.}\n@returns(200) Successfully created\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"line\":10,\"message\":\"This is a false positive.\",\"name\":\"src/main.py\",\"repository_id\":\"my-repo\",\"rule\":\"my-ai-ruleset/my-ai-rule\",\"sha\":\"abc123def456789012345678901234567890abcd\",\"type\":\"FP\"},\"id\":\"violation-abc\",\"type\":\"ai_memory_violation_result\"}}\n\n@endpoint DELETE /api/v2/static-analysis/ai/memory/{id}\n@desc Delete an AI memory violation result\n@required {id: str # The numeric identifier of the memory violation result.}\n@returns(200) Successfully deleted\n@errors {400: Bad Request, 401: Unauthorized, 404: Memory violation result not found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/static-analysis/ai/prompts\n@desc List AI prompts\n@returns(200) {data: [map]} # Successful response\n@errors {400: Bad Request, 401: Unauthorized, 404: Not Found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/static-analysis/ai/rulesets\n@desc List AI custom rulesets\n@optional {page[offset]: int(int64)=0: any # The offset for pagination., page[limit]: int(int64)=100 # The maximum number of rulesets to return.}\n@returns(200) {data: [map]} # Successful response\n@errors {401: Unauthorized, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/static-analysis/ai/rulesets\n@desc Create an AI custom ruleset\n@optional {data: map{attributes: map, id: str, type: str} # Request data for creating an AI custom ruleset.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, description: str, name: str, rules: [map]?, short_description: str}, id: str, type: str}} # Successfully created\n@errors {400: Bad Request, 401: Unauthorized, 409: Conflict - ruleset already exists, 412: Precondition Failed - validation error, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Ruleset description\",\"name\":\"my-ai-ruleset\",\"short_description\":\"Ruleset short description\"},\"id\":\"my-ai-ruleset\",\"type\":\"ai_ruleset\"}}\n\n@endpoint DELETE /api/v2/static-analysis/ai/rulesets/{ruleset_name}\n@desc Delete an AI custom ruleset\n@required {ruleset_name: str # The ruleset name.}\n@returns(200) Successfully deleted\n@errors {400: Bad Request, 401: Unauthorized, 404: Ruleset not found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/static-analysis/ai/rulesets/{ruleset_name}\n@desc Get an AI custom ruleset\n@required {ruleset_name: str # The ruleset name.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, description: str, name: str, rules: [map]?, short_description: str}, id: str, type: str}} # Successful response\n@errors {400: Bad Request, 401: Unauthorized, 404: Ruleset not found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint PATCH /api/v2/static-analysis/ai/rulesets/{ruleset_name}\n@desc Update an AI custom ruleset\n@required {ruleset_name: str # The ruleset name.}\n@optional {data: map{attributes: map, id: str, type: str} # Request data for updating an AI custom ruleset.}\n@returns(200) Successfully updated\n@errors {400: Bad Request, 401: Unauthorized, 412: Precondition Failed - validation error or ruleset not found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"description\":\"Ruleset description\",\"name\":\"my-ai-ruleset\",\"short_description\":\"Ruleset short description\"},\"id\":\"my-ai-ruleset\",\"type\":\"ai_ruleset\"}}\n\n@endpoint POST /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules\n@desc Create an AI custom rule\n@required {ruleset_name: str # The ruleset name.}\n@optional {data: map{attributes: map, id: str, type: str} # Request data for creating an AI custom rule.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, last_revision: map{category: str, checksum: str, content: str, created_at: str(date-time), created_by: str, cwe: str?, description: str, directories: [str], execution_mode: str, globs: [str], is_default: bool, is_published: bool, is_testing: bool, severity: str, short_description: str, version_id: int(int64)}, name: str}, id: str, type: str}} # Successfully created\n@errors {400: Bad Request, 401: Unauthorized, 409: Conflict - rule already exists, 412: Precondition Failed - validation error or ruleset not found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"name\":\"my-ai-rule\"},\"type\":\"ai_rule\"}}\n\n@endpoint DELETE /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}\n@desc Delete an AI custom rule\n@required {ruleset_name: str # The ruleset name., rule_name: str # The rule name.}\n@returns(200) Successfully deleted\n@errors {400: Bad Request, 401: Unauthorized, 404: Rule not found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}\n@desc Get an AI custom rule\n@required {ruleset_name: str # The ruleset name., rule_name: str # The rule name.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, last_revision: map{category: str, checksum: str, content: str, created_at: str(date-time), created_by: str, cwe: str?, description: str, directories: [str], execution_mode: str, globs: [str], is_default: bool, is_published: bool, is_testing: bool, severity: str, short_description: str, version_id: int(int64)}, name: str}, id: str, type: str}} # Successful response\n@errors {400: Bad Request, 401: Unauthorized, 404: Rule not found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}/revisions\n@desc List AI custom rule revisions\n@required {ruleset_name: str # The ruleset name., rule_name: str # The rule name.}\n@optional {page[offset]: int(int64)=0: any # The offset for pagination., page[limit]: int(int64)=100 # The maximum number of revisions to return.}\n@returns(200) {data: [map]} # Successful response\n@errors {400: Bad Request, 401: Unauthorized, 404: Rule not found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint POST /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}/revisions\n@desc Create an AI custom rule revision\n@required {ruleset_name: str # The ruleset name., rule_name: str # The rule name.}\n@optional {data: map{attributes: map, id: str, type: str} # Request data for creating an AI custom rule revision.}\n@returns(200) Successfully created\n@errors {400: Bad Request, 401: Unauthorized, 404: Rule not found, 429: Too many requests, 500: Internal Server Error}\n@example_request {\"data\":{\"attributes\":{\"category\":\"SECURITY\",\"content\":\"Content\",\"description\":\"Ruleset description\",\"directories\":[],\"execution_mode\":\"auto\",\"globs\":[\"**/*.py\"],\"is_published\":false,\"is_testing\":false,\"severity\":\"ERROR\",\"short_description\":\"Ruleset short description\",\"version_id\":1},\"id\":\"revision-abc-123\",\"type\":\"ai_rule_revision\"}}\n\n@endpoint GET /api/v2/static-analysis/ai/rulesets/{ruleset_name}/rules/{rule_name}/revisions/{id}\n@desc Get an AI custom rule revision\n@required {ruleset_name: str # The ruleset name., rule_name: str # The rule name., id: str # The revision identifier.}\n@returns(200) {data: map{attributes: map{category: str, checksum: str, content: str, created_at: str(date-time), created_by: str, cwe: str?, description: str, directories: [str], execution_mode: str, globs: [str], is_default: bool, is_published: bool, is_testing: bool, severity: str, short_description: str, version_id: int(int64)}, id: str, type: str}} # Successful response\n@errors {400: Bad Request, 401: Unauthorized, 404: Revision not found, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/static-analysis/codegen/rulesets\n@desc List codegen rulesets\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n\n@endpoint GET /api/v2/static-analysis/custom/rulesets\n@desc List Custom Rulesets\n@returns(200) {data: [map]} # OK\n@errors {401: Unauthorized, 429: Too many requests}\n\n@endpoint PUT /api/v2/static-analysis/custom/rulesets\n@desc Create Custom Ruleset\n@optional {data: map{attributes: map, id: str, type: str} # Data object for a custom ruleset create or update request.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, description: str, name: str, rules: [map]?, short_description: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 409: Conflict, 412: Precondition Failed, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"My custom ruleset.\",\"name\":\"my-custom-ruleset\"},\"type\":\"custom_ruleset\"}}\n\n@endpoint DELETE /api/v2/static-analysis/custom/rulesets/{ruleset_name}\n@desc Delete Custom Ruleset\n@required {ruleset_name: str # The ruleset name}\n@returns(200) Successfully deleted\n@errors {400: Bad request, 401: Unauthorized - custom rules not enabled, 404: Ruleset not found, 429: Too many requests}\n\n@endpoint GET /api/v2/static-analysis/custom/rulesets/{ruleset_name}\n@desc Show Custom Ruleset\n@required {ruleset_name: str # The ruleset name}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, description: str, name: str, rules: [map]?, short_description: str}, id: str, type: str}} # Successful response\n@errors {400: Bad request, 401: Unauthorized - custom rules not enabled, 404: Ruleset not found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/static-analysis/custom/rulesets/{ruleset_name}\n@desc Update Custom Ruleset\n@required {ruleset_name: str # The ruleset name}\n@optional {data: map{attributes: map, id: str, type: str} # Data object for a custom ruleset create or update request.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, description: str, name: str, rules: [map]?, short_description: str}, id: str, type: str}} # Successfully updated\n@errors {400: Bad request, 401: Unauthorized - custom rules not enabled, 412: Precondition failed - validation error or ruleset not found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"rules\":[{\"created_at\":\"2026-01-09T13:00:57.473141Z\",\"created_by\":\"foobarbaz\",\"last_revision\":{\"id\":\"revision-123\"},\"name\":\"my-rule\"}]},\"type\":\"custom_ruleset\"}}\n\n@endpoint PUT /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules\n@desc Create Custom Rule\n@required {ruleset_name: str # The ruleset name}\n@optional {data: map{attributes: map, id: str, type: str} # Data object for a custom rule create or update request.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, last_revision: map{attributes: map, id: str, type: str}, name: str}, id: str, type: str}} # Successfully created\n@errors {400: Bad request, 401: Unauthorized - custom rules not enabled, 409: Conflict - rule already exists, 412: Precondition failed - validation error or ruleset not found, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"custom_rule\"}}\n\n@endpoint DELETE /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name}\n@desc Delete Custom Rule\n@required {ruleset_name: str # The ruleset name, rule_name: str # The rule name}\n@returns(200) Successfully deleted\n@errors {400: Bad request, 401: Unauthorized - custom rules not enabled, 404: Rule not found, 429: Too many requests}\n\n@endpoint GET /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name}\n@desc Show Custom Rule\n@required {ruleset_name: str # The ruleset name, rule_name: str # The rule name}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, last_revision: map{attributes: map, id: str, type: str}, name: str}, id: str, type: str}} # Successful response\n@errors {400: Bad request, 401: Unauthorized - custom rules not enabled, 404: Rule not found, 429: Too many requests}\n\n@endpoint GET /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name}/revisions\n@desc List Custom Rule Revisions\n@required {ruleset_name: str # The ruleset name, rule_name: str # The rule name}\n@optional {page[offset]: int(int64)=0: any # Pagination offset, page[limit]: int(int64)=10 # Pagination limit}\n@returns(200) {data: [map]} # Successful response\n@errors {400: Bad request, 401: Unauthorized - custom rules not enabled, 404: Rule not found, 429: Too many requests}\n\n@endpoint PUT /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name}/revisions\n@desc Create Custom Rule Revision\n@required {ruleset_name: str # The ruleset name, rule_name: str # The rule name}\n@optional {data: map{attributes: map, id: str, type: str} # Data object for a custom rule revision create request.}\n@returns(200) Successfully created\n@errors {400: Bad request, 401: Unauthorized - custom rules not enabled, 404: Rule not found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"arguments\":[{\"description\":\"Maximum call depth to analyze\",\"name\":\"max_depth\"}],\"category\":\"SECURITY\",\"code\":\"def rule(node): return node.type == 'call'\",\"creation_message\":\"Initial revision\",\"cve\":\"CVE-2024-1234\",\"cwe\":\"CWE-79\",\"description\":\"Detects insecure coding patterns that may lead to vulnerabilities\",\"documentation_url\":\"https://docs.example.com/rules/my-rule\",\"is_published\":false,\"is_testing\":false,\"language\":\"PYTHON\",\"severity\":\"ERROR\",\"short_description\":\"Rule to detect insecure patterns\",\"should_use_ai_fix\":false,\"tags\":[\"security\",\"custom\"],\"tests\":[{\"annotation_count\":1,\"code\":\"result = insecure_function()\",\"filename\":\"test.yaml\"}],\"tree_sitter_query\":\"(call_expression) @call\"},\"type\":\"custom_rule_revision\"}}\n\n@endpoint POST /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name}/revisions/revert\n@desc Revert Custom Rule Revision\n@required {ruleset_name: str # The ruleset name, rule_name: str # The rule name}\n@optional {data: map{attributes: map, id: str, type: str} # Data object for a request to revert a custom rule to a previous revision.}\n@returns(200) Successfully reverted\n@errors {400: Bad request, 401: Unauthorized - custom rules not enabled, 429: Too many requests}\n@example_request {\"data\":{\"type\":\"revert_custom_rule_revision_request\"}}\n\n@endpoint GET /api/v2/static-analysis/custom/rulesets/{ruleset_name}/rules/{rule_name}/revisions/{id}\n@desc Show Custom Rule Revision\n@required {ruleset_name: str # The ruleset name, rule_name: str # The rule name, id: str # The revision ID}\n@returns(200) {data: map{attributes: map{arguments: [map], category: str, checksum: str, code: str, created_at: str(date-time), created_by: str, creation_message: str, cve: str?, cwe: str?, description: str, documentation_url: str?, is_published: bool, is_testing: bool, language: str, severity: str, short_description: str, should_use_ai_fix: bool, tags: [str], tests: [map], tree_sitter_query: str}, id: str, type: str}} # Successful response\n@errors {400: Bad request, 401: Unauthorized - custom rules not enabled, 404: Revision not found, 429: Too many requests}\n\n@endpoint GET /api/v2/static-analysis/default-rulesets/{language}\n@desc Get default rulesets for a language\n@required {language: str # The programming language for which to retrieve the default rulesets.}\n@returns(200) {data: map{attributes: map{rulesets: [str]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 429: Too many requests}\n\n@endpoint POST /api/v2/static-analysis/rulesets\n@desc Ruleset get multiple\n@optional {data: map{attributes: map, id: str, type!: str} # The primary data object in the get-multiple-rulesets request, containing request attributes and resource type.}\n@returns(200) {data: map{attributes: map{rulesets: [map]}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"type\":\"get_multiple_rulesets_request\"}}\n\n@endpoint GET /api/v2/static-analysis/rulesets/{ruleset_name}\n@desc Get a SAST ruleset\n@required {ruleset_name: str # The name of the ruleset to retrieve.}\n@optional {include_tests: bool # When true, test cases for each rule are included in the response., include_testing_rules: bool # When true, rules that are in testing mode are included in the response.}\n@returns(200) {data: map{attributes: map{description: str, name: str, rules: [map], short_description: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/static-analysis/secrets/rules\n@desc Returns a list of Secrets rules\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/static-analysis/static-analysis-server/analyze\n@desc Analyze code\n@required {data: map{attributes!: map, id: str, type!: str} # The primary data object in the analysis request.}\n@returns(200) {data: map{attributes: map{errors: [str], rule_responses: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"code\":\"aW1wb3J0IHN5cw==\",\"file_encoding\":\"utf-8\",\"filename\":\"test.py\",\"language\":\"python\",\"rules\":[]},\"type\":\"analysis_request\"}}\n\n@endpoint POST /api/v2/static-analysis/static-analysis-server/get-ast\n@desc Get AST for source code\n@required {data: map{attributes!: map, id: str, type!: str} # The primary data object in the get-AST request.}\n@returns(200) {data: map{attributes: map{ast: map}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"code\":\"aW1wb3J0IHN5cw==\",\"file_encoding\":\"utf-8\",\"language\":\"python\"},\"type\":\"get_ast_request\"}}\n\n@endpoint GET /api/v2/static-analysis/static-analysis-server/node-types/{language}\n@desc Get node types for a language\n@required {language: str # The programming language for which to retrieve node type definitions.}\n@returns(200) {data: map{attributes: map{node_types: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n\n@endpoint GET /api/v2/static-analysis/static-analysis-server/tree-sitter-wasm/{file}\n@desc Get tree-sitter WASM file\n@required {file: str # The name of the WASM file to download.}\n@returns(200) BLOB with the content of the WASM file\n@errors {400: Bad Request, 401: Unauthorized, 429: Too many requests}\n\n@endpoint GET /api/v2/statuspages\n@desc List status pages\n@optional {page[offset]: int(int64)=0: any # Offset to use as the start of the page., page[limit]: int(int64)=50 # The number of status pages to return per page., filter[domain_prefix]: str # Filter status pages by exact domain prefix match. Returns at most one result., include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user.}\n@returns(200) {data: [map], included: [any], meta: map{page: map{first_offset: int(int64), last_offset: int(int64)?, limit: int(int64), next_offset: int(int64)?, offset: int(int64), prev_offset: int(int64)?, total: int(int64)?, type: str}}} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/statuspages\n@desc Create status page\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user., data: map{attributes!: map, type!: str} # The data object for creating a status page.}\n@returns(201) {data: map{attributes: map{company_logo: str?, components: [map], created_at: str(date-time), custom_domain: str?, custom_domain_enabled: bool, domain_prefix: str, email_header_image: str?, enabled: bool, favicon: str?, modified_at: str(date-time), name: str, page_url: str, slack_app_icon: str, slack_subscriptions_enabled: bool, subscriptions_enabled: bool, type: str, visualization_type: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"company_logo\":\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEAAIKMMMM\",\"components\":[{\"name\":\"API\",\"position\":0,\"type\":\"component\"},{\"components\":[{\"name\":\"Login\",\"position\":0,\"type\":\"component\"},{\"name\":\"Settings\",\"position\":1,\"type\":\"component\"}],\"name\":\"Web App\",\"position\":1,\"type\":\"group\"},{\"name\":\"Webhooks\",\"position\":2,\"type\":\"component\"}],\"domain_prefix\":\"status-page-us1\",\"email_header_image\":\"data:image/png;base64,pQSLAw0KGgoAAAANSUhEUgAAAQ4AASJKFF\",\"favicon\":\"data:image/png;base64,kWMRNw0KGgoAAAANSUhEUgAAAEAAAABACA\",\"name\":\"Status Page US1\",\"subscriptions_enabled\":true,\"type\":\"public\",\"visualization_type\":\"bars_and_uptime_percentage\"},\"type\":\"status_pages\"}}\n\n@endpoint GET /api/v2/statuspages/degradations\n@desc List degradations\n@optional {filter[page_id]: str: any # Optional page id filter., page[offset]: int(int64)=0 # Offset to use as the start of the page., page[limit]: int(int64)=50 # The number of degradations to return per page., include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., filter[status]: str # Optional degradation status filter. Supported values: investigating, identified, monitoring, resolved., sort: str # Sort order. Prefix with '-' for descending. Supported values: created_at, -created_at, modified_at, -modified_at., filter[source_id]: str # Optional source ID filter. Returns only degradations whose source matches this ID (for example, an incident ID).}\n@returns(200) {data: [map], included: [any], meta: map{page: map{first_offset: int(int64), last_offset: int(int64)?, limit: int(int64), next_offset: int(int64)?, offset: int(int64), prev_offset: int(int64)?, total: int(int64)?, type: str}}} # OK\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/statuspages/maintenances\n@desc List maintenances\n@optional {filter[page_id]: str: any # Optional page id filter., page[offset]: int(int64)=0 # Offset to use as the start of the page., page[limit]: int(int64)=50 # The number of maintenances to return per page., include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., filter[status]: str # Optional maintenance status filter. Supported values: scheduled, in_progress, completed., sort: str # Sort order. Prefix with '-' for descending. Supported values: created_at, -created_at, start_date, -start_date.}\n@returns(200) {data: [map], included: [any], meta: map{page: map{first_offset: int(int64), last_offset: int(int64)?, limit: int(int64), next_offset: int(int64)?, offset: int(int64), prev_offset: int(int64)?, total: int(int64)?, type: str}}} # OK\n@errors {429: Too many requests}\n\n@endpoint DELETE /api/v2/statuspages/{page_id}\n@desc Delete status page\n@required {page_id: str(uuid) # The ID of the status page.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/statuspages/{page_id}\n@desc Get status page\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user.}\n@returns(200) {data: map{attributes: map{company_logo: str?, components: [map], created_at: str(date-time), custom_domain: str?, custom_domain_enabled: bool, domain_prefix: str, email_header_image: str?, enabled: bool, favicon: str?, modified_at: str(date-time), name: str, page_url: str, slack_app_icon: str, slack_subscriptions_enabled: bool, subscriptions_enabled: bool, type: str, visualization_type: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/statuspages/{page_id}\n@desc Update status page\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {delete_subscribers: bool=false # Whether to delete existing subscribers when updating a status page's type., include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user., data: map{attributes!: map, id!: str(uuid), type!: str} # The data object for updating a status page.}\n@returns(200) {data: map{attributes: map{company_logo: str?, components: [map], created_at: str(date-time), custom_domain: str?, custom_domain_enabled: bool, domain_prefix: str, email_header_image: str?, enabled: bool, favicon: str?, modified_at: str(date-time), name: str, page_url: str, slack_app_icon: str, slack_subscriptions_enabled: bool, subscriptions_enabled: bool, type: str, visualization_type: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"company_logo\":\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEAAIKMMMM\",\"domain_prefix\":\"status-page-us1-east\",\"email_header_image\":\"data:image/png;base64,pQSLAw0KGgoAAAANSUhEUgAAAQ4AASJKFF\",\"favicon\":\"data:image/png;base64,kWMRNw0KGgoAAAANSUhEUgAAAEAAAABACA\",\"name\":\"Status Page US1 East\",\"subscriptions_enabled\":false,\"type\":\"internal\",\"visualization_type\":\"bars_only\"},\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"type\":\"status_pages\"}}\n\n@endpoint GET /api/v2/statuspages/{page_id}/components\n@desc List components\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page, group.}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/statuspages/{page_id}/components\n@desc Create component\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page, group., data: map{attributes!: map, relationships: map, type!: str} # The data object for creating a component.}\n@returns(201) {data: map{attributes: map{components: [map], created_at: str(date-time), modified_at: str(date-time), name: str, position: int(int64), status: str, type: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, group: map{data: map?}, last_modified_by_user: map{data: map}, status_page: map{data: map}}, type: str}, included: [any]} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Metrics Intake\",\"position\":0,\"type\":\"component\"},\"relationships\":{\"group\":{\"data\":null}},\"type\":\"components\"}}\n\n@endpoint DELETE /api/v2/statuspages/{page_id}/components/{component_id}\n@desc Delete component\n@required {page_id: str(uuid) # The ID of the status page., component_id: str(uuid) # The ID of the component.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/statuspages/{page_id}/components/{component_id}\n@desc Get component\n@required {page_id: str(uuid) # The ID of the status page., component_id: str(uuid) # The ID of the component.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page, group.}\n@returns(200) {data: map{attributes: map{components: [map], created_at: str(date-time), modified_at: str(date-time), name: str, position: int(int64), status: str, type: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, group: map{data: map?}, last_modified_by_user: map{data: map}, status_page: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/statuspages/{page_id}/components/{component_id}\n@desc Update component\n@required {page_id: str(uuid) # The ID of the status page., component_id: str(uuid) # The ID of the component.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page, group., data: map{attributes!: map, id!: str(uuid), type!: str} # The data object for updating a component.}\n@returns(200) {data: map{attributes: map{components: [map], created_at: str(date-time), modified_at: str(date-time), name: str, position: int(int64), status: str, type: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, group: map{data: map?}, last_modified_by_user: map{data: map}, status_page: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"Metrics Intake Service\",\"position\":4},\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"type\":\"components\"}}\n\n@endpoint GET /api/v2/statuspages/{page_id}/degradation_templates\n@desc List degradation templates\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page.}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/statuspages/{page_id}/degradation_templates\n@desc Create degradation template\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., data: map{attributes: map, type!: str} # The data object for creating a degradation template.}\n@returns(201) {data: map{attributes: map{components_affected: [map], created_at: str(date-time), degradation_title: str, modified_at: str(date-time), name: str, updates: [map]}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}}, type: str}, included: [any]} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"components_affected\":[{\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"status\":\"degraded\"}],\"degradation_title\":\"Elevated API Latency\",\"name\":\"Elevated API Latency\",\"updates\":[{\"message\":\"We are investigating the issue.\",\"status\":\"investigating\"}]},\"type\":\"degradation_templates\"}}\n\n@endpoint DELETE /api/v2/statuspages/{page_id}/degradation_templates/{template_id}\n@desc Delete degradation template\n@required {page_id: str(uuid) # The ID of the status page., template_id: str(uuid) # The ID of the degradation or maintenance template.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/statuspages/{page_id}/degradation_templates/{template_id}\n@desc Get degradation template\n@required {page_id: str(uuid) # The ID of the status page., template_id: str(uuid) # The ID of the degradation or maintenance template.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page.}\n@returns(200) {data: map{attributes: map{components_affected: [map], created_at: str(date-time), degradation_title: str, modified_at: str(date-time), name: str, updates: [map]}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/statuspages/{page_id}/degradation_templates/{template_id}\n@desc Update degradation template\n@required {template_id: str(uuid) # The ID of the degradation or maintenance template., page_id: str(uuid) # The ID of the status page.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., data: map{attributes: map, id!: str, type!: str} # The data object for updating a degradation template.}\n@returns(200) {data: map{attributes: map{components_affected: [map], created_at: str(date-time), degradation_title: str, modified_at: str(date-time), name: str, updates: [map]}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"degradation_title\":\"Elevated API Latency for 40 minutes\",\"name\":\"Elevated API Latency\"},\"id\":\"00000000-0000-0000-0000-000000000003\",\"type\":\"degradation_templates\"}}\n\n@endpoint POST /api/v2/statuspages/{page_id}/degradations\n@desc Create degradation\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {notify_subscribers: bool=true # Whether to notify page subscribers of the degradation., include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., data: map{attributes!: map, relationships: map, type!: str} # The data object for creating a degradation., meta: map{idempotency_key: str(uuid)} # The supported metadata for a degradation request.}\n@returns(201) {data: map{attributes: map{components_affected: [map], created_at: str(date-time), description: str, is_backfilled: bool, modified_at: str(date-time), source: map{created_at: str(date-time), source_id: str, type: str}, status: str, title: str, updates: [map]}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}, template: map{data: map}}, type: str}, included: [any]} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"components_affected\":[{\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"status\":\"degraded\"}],\"description\":\"Our API is experiencing elevated latency. We are investigating the issue.\",\"status\":\"investigating\",\"title\":\"Elevated API Latency\"},\"type\":\"degradations\"}}\n\n@endpoint POST /api/v2/statuspages/{page_id}/degradations/backfill\n@desc Create backfilled degradation\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., data: map{attributes: map, relationships: map, type!: str} # The data object for creating a backfilled degradation.}\n@returns(201) {data: map{attributes: map{components_affected: [map], created_at: str(date-time), description: str, is_backfilled: bool, modified_at: str(date-time), source: map{created_at: str(date-time), source_id: str, type: str}, status: str, title: str, updates: [map]}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}, template: map{data: map}}, type: str}, included: [any]} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"title\":\"Past API Outage\",\"updates\":[{\"components_affected\":[{\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"status\":\"degraded\"}],\"description\":\"We detected elevated error rates in the API.\",\"started_at\":\"2026-04-27T13:37:31Z\",\"status\":\"investigating\"},{\"components_affected\":[{\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"status\":\"operational\"}],\"description\":\"The issue has been resolved.\",\"started_at\":\"2026-04-27T14:37:31Z\",\"status\":\"resolved\"}]},\"type\":\"degradations\"}}\n\n@endpoint DELETE /api/v2/statuspages/{page_id}/degradations/{degradation_id}\n@desc Delete degradation\n@required {page_id: str(uuid) # The ID of the status page., degradation_id: str(uuid) # The ID of the degradation.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/statuspages/{page_id}/degradations/{degradation_id}\n@desc Get degradation\n@required {page_id: str(uuid) # The ID of the status page., degradation_id: str(uuid) # The ID of the degradation.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page.}\n@returns(200) {data: map{attributes: map{components_affected: [map], created_at: str(date-time), description: str, is_backfilled: bool, modified_at: str(date-time), source: map{created_at: str(date-time), source_id: str, type: str}, status: str, title: str, updates: [map]}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}, template: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/statuspages/{page_id}/degradations/{degradation_id}\n@desc Update degradation\n@required {page_id: str(uuid) # The ID of the status page., degradation_id: str(uuid) # The ID of the degradation.}\n@optional {notify_subscribers: bool=true # Whether to notify page subscribers of the degradation., include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., data: map{attributes!: map, id!: str(uuid), relationships: map, type!: str} # The data object for updating a degradation., meta: map{idempotency_key: str(uuid)} # The supported metadata for a degradation request.}\n@returns(200) {data: map{attributes: map{components_affected: [map], created_at: str(date-time), description: str, is_backfilled: bool, modified_at: str(date-time), source: map{created_at: str(date-time), source_id: str, type: str}, status: str, title: str, updates: [map]}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}, template: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"components_affected\":[{\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"status\":\"operational\"}],\"description\":\"We've deployed a fix and latency has returned to normal. This issue has been resolved.\",\"status\":\"resolved\",\"title\":\"Elevated API Latency in US1\"},\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"type\":\"degradations\"}}\n\n@endpoint DELETE /api/v2/statuspages/{page_id}/degradations/{degradation_id}/updates/{update_id}\n@desc Soft delete degradation update\n@required {degradation_id: str(uuid) # The ID of the degradation., page_id: str(uuid) # The ID of the status page., update_id: str(uuid) # The ID of the degradation update.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/statuspages/{page_id}/degradations/{degradation_id}/updates/{update_id}\n@desc Edit degradation update\n@required {degradation_id: str(uuid) # The ID of the degradation., page_id: str(uuid) # The ID of the status page., update_id: str(uuid) # The ID of the degradation update.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, degradation, status_page., data: map{attributes: map, id: str, type!: str} # The data object for editing a degradation update.}\n@returns(200) {data: map{attributes: map{components_affected: [map], created_at: str(date-time), deleted_at: str(date-time), description: str, modified_at: str(date-time), started_at: str(date-time), status: str}, id: str, relationships: map{created_by_user: map{data: map}, degradation: map{data: map}, deleted_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"We've identified the source of the latency increase and are deploying a fix.\",\"status\":\"identified\"},\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"degradation_updates\"}}\n\n@endpoint GET /api/v2/statuspages/{page_id}/maintenance_templates\n@desc List maintenance templates\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page.}\n@returns(200) {data: [map], included: [any]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/statuspages/{page_id}/maintenance_templates\n@desc Create maintenance template\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., data: map{attributes: map, type!: str} # The data object for creating a maintenance template.}\n@returns(201) {data: map{attributes: map{completed_description: str, component_ids: [str], created_at: str(date-time), in_progress_description: str, maintenance_title: str, modified_at: str(date-time), name: str, scheduled_description: str}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}}, type: str}, included: [any]} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"completed_description\":\"We have completed maintenance on the API to improve performance.\",\"component_ids\":[\"1234abcd-12ab-34cd-56ef-123456abcdef\"],\"in_progress_description\":\"We are currently performing maintenance on the API to improve performance.\",\"maintenance_title\":\"API Maintenance\",\"name\":\"API Maintenance\",\"scheduled_description\":\"We will be performing maintenance on the API to improve performance.\"},\"type\":\"maintenance_templates\"}}\n\n@endpoint DELETE /api/v2/statuspages/{page_id}/maintenance_templates/{template_id}\n@desc Delete maintenance template\n@required {page_id: str(uuid) # The ID of the status page., template_id: str(uuid) # The ID of the degradation or maintenance template.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/statuspages/{page_id}/maintenance_templates/{template_id}\n@desc Get maintenance template\n@required {page_id: str(uuid) # The ID of the status page., template_id: str(uuid) # The ID of the degradation or maintenance template.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page.}\n@returns(200) {data: map{attributes: map{completed_description: str, component_ids: [str], created_at: str(date-time), in_progress_description: str, maintenance_title: str, modified_at: str(date-time), name: str, scheduled_description: str}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/statuspages/{page_id}/maintenance_templates/{template_id}\n@desc Update maintenance template\n@required {page_id: str(uuid) # The ID of the status page., template_id: str(uuid) # The ID of the degradation or maintenance template.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., data: map{attributes: map, id!: str, type!: str} # The data object for updating a maintenance template.}\n@returns(200) {data: map{attributes: map{completed_description: str, component_ids: [str], created_at: str(date-time), in_progress_description: str, maintenance_title: str, modified_at: str(date-time), name: str, scheduled_description: str}, id: str, relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"completed_description\":\"We have completed maintenance on the API to improve performance.\",\"in_progress_description\":\"We are currently performing maintenance on the API to improve performance for 40 minutes.\",\"maintenance_title\":\"API Maintenance\",\"scheduled_description\":\"We will be performing maintenance on the API to improve performance for 40 minutes.\"},\"id\":\"00000000-0000-0000-0000-000000000004\",\"type\":\"maintenance_templates\"}}\n\n@endpoint POST /api/v2/statuspages/{page_id}/maintenances\n@desc Schedule maintenance\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {notify_subscribers: bool=true # Whether to notify page subscribers of the maintenance., include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., data: map{attributes!: map, relationships: map, type!: str} # The data object for creating a maintenance.}\n@returns(201) {data: map{attributes: map{completed_date: str(date-time), completed_description: str, components_affected: [map], in_progress_description: str, is_backfilled: bool, modified_at: str(date-time), published_date: str(date-time), scheduled_description: str, start_date: str(date-time), status: str, title: str, updates: [map]}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}, template: map{data: map}}, type: str}, included: [any]} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"completed_date\":\"2026-02-18T19:51:13.332360075Z\",\"completed_description\":\"We have completed maintenance on the API to improve performance.\",\"components_affected\":[{\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"status\":\"operational\"}],\"in_progress_description\":\"We are currently performing maintenance on the API to improve performance.\",\"scheduled_description\":\"We will be performing maintenance on the API to improve performance.\",\"start_date\":\"2026-02-18T19:21:13.332360075Z\",\"title\":\"API Maintenance\"},\"type\":\"maintenances\"}}\n\n@endpoint POST /api/v2/statuspages/{page_id}/maintenances/backfill\n@desc Create backfilled maintenance\n@required {page_id: str(uuid) # The ID of the status page.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., data: map{attributes: map, relationships: map, type!: str} # The data object for creating a backfilled maintenance.}\n@returns(201) {data: map{attributes: map{completed_date: str(date-time), completed_description: str, components_affected: [map], in_progress_description: str, is_backfilled: bool, modified_at: str(date-time), published_date: str(date-time), scheduled_description: str, start_date: str(date-time), status: str, title: str, updates: [map]}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}, template: map{data: map}}, type: str}, included: [any]} # Created\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"title\":\"Past Database Maintenance\",\"updates\":[{\"components_affected\":[{\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"status\":\"maintenance\"}],\"description\":\"Database maintenance is in progress.\",\"started_at\":\"2026-04-27T13:37:31Z\",\"status\":\"in_progress\"},{\"components_affected\":[{\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"status\":\"operational\"}],\"description\":\"Database maintenance has been completed.\",\"started_at\":\"2026-04-27T14:37:31Z\",\"status\":\"completed\"}]},\"type\":\"maintenances\"}}\n\n@endpoint GET /api/v2/statuspages/{page_id}/maintenances/{maintenance_id}\n@desc Get maintenance\n@required {page_id: str(uuid) # The ID of the status page., maintenance_id: str(uuid) # The ID of the maintenance.}\n@optional {include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page.}\n@returns(200) {data: map{attributes: map{completed_date: str(date-time), completed_description: str, components_affected: [map], in_progress_description: str, is_backfilled: bool, modified_at: str(date-time), published_date: str(date-time), scheduled_description: str, start_date: str(date-time), status: str, title: str, updates: [map]}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}, template: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/statuspages/{page_id}/maintenances/{maintenance_id}\n@desc Update maintenance\n@required {page_id: str(uuid) # The ID of the status page., maintenance_id: str(uuid) # The ID of the maintenance.}\n@optional {notify_subscribers: bool=true # Whether to notify page subscribers of the maintenance., include: str # Comma-separated list of resources to include. Supported values: created_by_user, last_modified_by_user, status_page., data: map{attributes!: map, id!: str(uuid), relationships: map, type!: str} # The data object for updating a maintenance.}\n@returns(200) {data: map{attributes: map{completed_date: str(date-time), completed_description: str, components_affected: [map], in_progress_description: str, is_backfilled: bool, modified_at: str(date-time), published_date: str(date-time), scheduled_description: str, start_date: str(date-time), status: str, title: str, updates: [map]}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, status_page: map{data: map}, template: map{data: map}}, type: str}, included: [any]} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"completed_date\":\"2026-02-18T20:01:13.332360075Z\",\"in_progress_description\":\"We are currently performing maintenance on the API to improve performance for 40 minutes.\",\"scheduled_description\":\"We will be performing maintenance on the API to improve performance for 40 minutes.\",\"start_date\":\"2026-02-18T19:21:13.332360075Z\",\"title\":\"API Maintenance\"},\"id\":\"1234abcd-12ab-34cd-56ef-123456abcdef\",\"type\":\"maintenances\"}}\n\n@endpoint PATCH /api/v2/statuspages/{page_id}/maintenances/{maintenance_id}/updates/{update_id}\n@desc Edit maintenance update\n@required {page_id: str(uuid) # The ID of the status page., maintenance_id: str(uuid) # The ID of the maintenance., update_id: str(uuid) # The ID of the maintenance update.}\n@optional {data: map{attributes: map, id!: str, type!: str} # The data object for editing a maintenance update.}\n@returns(200) {data: map{attributes: map{components_affected: [map], created_at: str(date-time), description: str, manual_transition: bool, modified_at: str(date-time), started_at: str(date-time), status: str}, id: str(uuid), relationships: map{created_by_user: map{data: map}, last_modified_by_user: map{data: map}, maintenance: map{data: map}}, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"We have completed maintenance on the API to improve performance.\"},\"id\":\"00000000-0000-0000-0000-000000000000\",\"type\":\"maintenance_updates\"}}\n\n@endpoint POST /api/v2/statuspages/{page_id}/publish\n@desc Publish status page\n@required {page_id: str(uuid) # The ID of the status page.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/statuspages/{page_id}/unpublish\n@desc Unpublish status page\n@required {page_id: str(uuid) # The ID of the status page.}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/stegadography/get-widgets\n@desc Get widgets from an image\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 415: Unsupported Media Type, 429: Too many requests, 500: Internal Server Error}\n\n@endpoint GET /api/v2/synthetics/api-multistep/subtests/{public_id}\n@desc Get available subtests for a multistep test\n@required {public_id: str # The public ID of the API multistep test.}\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/synthetics/api-multistep/subtests/{public_id}/parents\n@desc Get parent tests for a subtest\n@required {public_id: str # The public ID of the subtest.}\n@returns(200) {data: [map]} # OK\n@errors {404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/synthetics/downtimes\n@desc List Synthetics downtimes\n@optional {filter[test_ids]: str: any # Comma-separated list of Synthetics test public IDs to filter downtimes by., filter[active]: str # If set to `true`, return only downtimes that are currently active.}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/synthetics/downtimes\n@desc Create a Synthetics downtime\n@required {data: map{attributes!: map, type!: str} # The data object for a Synthetics downtime create or update request.}\n@returns(201) {data: map{attributes: map{createdAt: str(date-time), createdBy: str, createdByName: str, description: str, isEnabled: bool, name: str, tags: [str], testIds: [str], timeSlots: [map], updatedAt: str(date-time), updatedBy: str, updatedByName: str}, id: str, type: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"isEnabled\":true,\"name\":\"Weekly maintenance\",\"testIds\":[\"abc-def-123\"],\"timeSlots\":[{\"duration\":3600,\"start\":{\"day\":15,\"hour\":10,\"minute\":30,\"month\":1,\"year\":2024},\"timezone\":\"Europe/Paris\"}]},\"type\":\"downtime\"}}\n\n@endpoint DELETE /api/v2/synthetics/downtimes/{downtime_id}\n@desc Delete a Synthetics downtime\n@required {downtime_id: str # The ID of the downtime to delete.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/synthetics/downtimes/{downtime_id}\n@desc Get a Synthetics downtime\n@required {downtime_id: str # The ID of the downtime to retrieve.}\n@returns(200) {data: map{attributes: map{createdAt: str(date-time), createdBy: str, createdByName: str, description: str, isEnabled: bool, name: str, tags: [str], testIds: [str], timeSlots: [map], updatedAt: str(date-time), updatedBy: str, updatedByName: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/synthetics/downtimes/{downtime_id}\n@desc Update a Synthetics downtime\n@required {downtime_id: str # The ID of the downtime to update., data: map{attributes!: map, type!: str} # The data object for a Synthetics downtime create or update request.}\n@returns(200) {data: map{attributes: map{createdAt: str(date-time), createdBy: str, createdByName: str, description: str, isEnabled: bool, name: str, tags: [str], testIds: [str], timeSlots: [map], updatedAt: str(date-time), updatedBy: str, updatedByName: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"isEnabled\":true,\"name\":\"Weekly maintenance\",\"testIds\":[\"abc-def-123\"],\"timeSlots\":[{\"duration\":3600,\"start\":{\"day\":15,\"hour\":10,\"minute\":30,\"month\":1,\"year\":2024},\"timezone\":\"Europe/Paris\"}]},\"type\":\"downtime\"}}\n\n@endpoint DELETE /api/v2/synthetics/downtimes/{downtime_id}/tests/{test_id}\n@desc Remove a test from a Synthetics downtime\n@required {downtime_id: str # The ID of the downtime., test_id: str # The public ID of the Synthetics test to disassociate from the downtime.}\n@returns(200) {data: map{attributes: map{createdAt: str(date-time), createdBy: str, createdByName: str, description: str, isEnabled: bool, name: str, tags: [str], testIds: [str], timeSlots: [map], updatedAt: str(date-time), updatedBy: str, updatedByName: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/synthetics/downtimes/{downtime_id}/tests/{test_id}\n@desc Add a test to a Synthetics downtime\n@required {downtime_id: str # The ID of the downtime., test_id: str # The public ID of the Synthetics test to associate with the downtime.}\n@returns(200) {data: map{attributes: map{createdAt: str(date-time), createdBy: str, createdByName: str, description: str, isEnabled: bool, name: str, tags: [str], testIds: [str], timeSlots: [map], updatedAt: str(date-time), updatedBy: str, updatedByName: str}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/synthetics/settings/on_demand_concurrency_cap\n@desc Get the on-demand concurrency cap\n@returns(200) {data: map{attributes: map{on_demand_concurrency_cap: num(double)}, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/synthetics/settings/on_demand_concurrency_cap\n@desc Save new value for on-demand concurrency cap\n@optional {on_demand_concurrency_cap: num(double) # Value of the on-demand concurrency cap.}\n@returns(200) {data: map{attributes: map{on_demand_concurrency_cap: num(double)}, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"on_demand_concurrency_cap\":20}\n\n@endpoint POST /api/v2/synthetics/suites\n@desc Create a test suite\n@required {data: map{attributes!: map, type!: str} # Data object for creating or editing a Synthetic test suite.}\n@returns(200) {data: map{attributes: map{message: str, monitor_id: int(int64), name: str, options: map{alerting_threshold: num(double)}, public_id: str, tags: [str], tests: [map], type: str}, id: str, type: str}} # OK\n@errors {400: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"message\":\"Notification message\",\"monitor_id\":12345678,\"name\":\"Example suite name\",\"public_id\":\"123-abc-456\",\"tags\":[\"env:production\"],\"tests\":[{\"alerting_criticality\":\"critical\",\"public_id\":\"\"}],\"type\":\"suite\"},\"type\":\"suites\"}}\n\n@endpoint POST /api/v2/synthetics/suites/bulk-delete\n@desc Bulk delete suites\n@required {data: map{attributes!: map, id: str, type: str} # Data object for a bulk delete Synthetic test suites request.}\n@returns(200) {data: [map]} # OK\n@errors {400: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"public_ids\":[\"\"]},\"type\":\"delete_suites_request\"}}\n\n@endpoint GET /api/v2/synthetics/suites/search\n@desc Search test suites\n@optional {query: str # The search query., sort: str=name,asc # The sort order for the results (e.g., `name,asc` or `name,desc`)., facets_only: bool=false # If true, return only facets instead of full test details., start: int(int64)=0 # The offset from which to start returning results., count: int(int64)=50 # The maximum number of results to return.}\n@returns(200) {data: map{attributes: map{suites: [map], total: int(int32)}, id: str(uuid), type: str}} # OK\n@errors {400: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/synthetics/suites/{public_id}\n@desc Get a suite\n@required {public_id: str # The public ID of the suite to get details from.}\n@returns(200) {data: map{attributes: map{message: str, monitor_id: int(int64), name: str, options: map{alerting_threshold: num(double)}, public_id: str, tags: [str], tests: [map], type: str}, id: str, type: str}} # OK\n@errors {404: API error response., 429: Too many requests}\n\n@endpoint PUT /api/v2/synthetics/suites/{public_id}\n@desc Edit a test suite\n@required {public_id: str # The public ID of the suite to edit., data: map{attributes!: map, type!: str} # Data object for creating or editing a Synthetic test suite.}\n@returns(200) {data: map{attributes: map{message: str, monitor_id: int(int64), name: str, options: map{alerting_threshold: num(double)}, public_id: str, tags: [str], tests: [map], type: str}, id: str, type: str}} # OK\n@errors {400: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"message\":\"Notification message\",\"monitor_id\":12345678,\"name\":\"Example suite name\",\"public_id\":\"123-abc-456\",\"tags\":[\"env:production\"],\"tests\":[{\"alerting_criticality\":\"critical\",\"public_id\":\"\"}],\"type\":\"suite\"},\"type\":\"suites\"}}\n\n@endpoint PATCH /api/v2/synthetics/suites/{public_id}/jsonpatch\n@desc Patch a test suite\n@required {public_id: str # The public ID of the Synthetic test suite to patch., data: map{attributes: map, type: str} # Data object for a JSON Patch request on a Synthetic test suite.}\n@returns(200) {data: map{attributes: map{message: str, monitor_id: int(int64), name: str, options: map{alerting_threshold: num(double)}, public_id: str, tags: [str], tests: [map], type: str}, id: str, type: str}} # OK\n@errors {400: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"json_patch\":[{\"op\":\"add\",\"path\":\"/name\"}]},\"type\":\"suites_json_patch\"}}\n\n@endpoint GET /api/v2/synthetics/tests/browser/{public_id}/results\n@desc Get a browser test's latest results\n@required {public_id: str # The public ID of the Synthetic browser test for which to search results.}\n@optional {from_ts: int(int64) # Timestamp in milliseconds from which to start querying results., to_ts: int(int64) # Timestamp in milliseconds up to which to query results., status: str # Filter results by status., runType: str # Filter results by run type., probe_dc: [str] # Locations for which to query results., device_id: [str] # Device IDs for which to query results.}\n@returns(200) {data: [map], included: [map]} # OK\n@errors {400: API error response., 404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/synthetics/tests/browser/{public_id}/results/{result_id}\n@desc Get a browser test result\n@required {public_id: str # The public ID of the Synthetic browser test to which the target result belongs., result_id: str # The ID of the result to get.}\n@optional {event_id: str # The event ID used to look up the result in the event store., timestamp: int(int64) # Timestamp in seconds to look up the result.}\n@returns(200) {data: map{attributes: map{batch: map{id: str}, ci: map{pipeline: map, provider: map, stage: map, workspace_path: str}, device: map{browser: map, id: str, name: str, platform: map, resolution: map, type: str}, git: map{branch: str, commit: map, repository_url: str}, location: map{id: str, name: str, version: str, worker_id: str}, result: map{assertions: [map], bucket_keys: map, call_type: str, cert: map, compressed_json_descriptor: str, compressed_steps: str, connection_outcome: str, dns_resolution: map, duration: num(double), exited_on_step_success: bool, failure: map, finished_at: int(int64), handshake: map, id: str, initial_id: str, is_fast_retry: bool, is_last_retry: bool, netpath: map, netstats: map, ocsp: map, ping: map, received_email_count: int(int64), received_message: str, request: map, resolved_ip: str, response: map, run_type: str, sent_message: str, start_url: str, started_at: int(int64), status: str, steps: [map], time_to_interactive: int(int64), timings: map, trace: map, traceroute: [map], triggered_at: int(int64), tunnel: bool, turns: [map], unhealthy: bool, variables: map}, test_sub_type: str, test_type: str}, id: str, relationships: map{test: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: API error response., 404: API error response., 429: Too many requests}\n\n@endpoint POST /api/v2/synthetics/tests/bulk-delete\n@desc Bulk delete tests\n@required {data: map{attributes!: map, id: str, type: str} # Data object for a bulk delete Synthetic tests request.}\n@returns(200) {data: [map]} # OK\n@errors {400: API error response., 404: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"public_ids\":[\"abc-def-123\",\"xyz-uvw-456\"]},\"type\":\"delete_tests_request\"}}\n\n@endpoint GET /api/v2/synthetics/tests/fast/{id}\n@desc Get a fast test result\n@required {id: str # The UUID of the fast test to retrieve the result for.}\n@returns(200) {data: map{attributes: map{device: map{browser: map, id: str, name: str, platform: map, resolution: map, type: str}, location: map{id: str, name: str, version: str, worker_id: str}, result: map{assertions: [map], call_type: str, cert: map, duration: num(double), failure: map, finished_at: int(int64), id: str, is_fast_retry: bool, request: map, resolved_ip: str, response: map, run_type: str, started_at: int(int64), status: str, steps: [map], timings: map, traceroute: [map], triggered_at: int(int64), tunnel: bool}, test_sub_type: str, test_type: str, test_version: int(int64)}, id: str, type: str}} # OK\n@errors {400: API error response., 404: API error response., 429: Too many requests}\n\n@endpoint POST /api/v2/synthetics/tests/network\n@desc Create a Network Path test\n@required {data: map{attributes!: map, type!: str} # Data object for creating or editing a Network Path test.}\n@returns(200) {data: map{attributes: map{config: map{assertions: [any], request: map}, locations: [str], message: str, monitor_id: int(int64), name: str, options: map{min_failure_duration: int(int64), min_location_failed: int(int64), monitor_name: str, monitor_options: map, monitor_priority: int(int32), restricted_roles: [str], retry: map, scheduling: map, tick_every: int(int64)}, public_id: str, status: str, subtype: str, tags: [str], type: str}, id: str, type: str}} # OK\n@errors {400: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"config\":{\"assertions\":[{\"operator\":\"lessThan\",\"property\":\"avg\",\"target\":500,\"type\":\"latency\"}],\"request\":{\"e2e_queries\":50,\"host\":\"\",\"max_ttl\":30,\"port\":443,\"tcp_method\":\"prefer_sack\",\"traceroute_queries\":3}},\"locations\":[\"aws:us-east-1\",\"agent:my-agent-name\"],\"message\":\"Network Path test notification\",\"monitor_id\":12345678,\"name\":\"Example Network Path test\",\"options\":{\"monitor_options\":{\"notification_preset_name\":\"show_all\"},\"scheduling\":{\"timeframes\":[{\"day\":1,\"from\":\"07:00\",\"to\":\"16:00\"},{\"day\":3,\"from\":\"07:00\",\"to\":\"16:00\"}],\"timezone\":\"America/New_York\"}},\"public_id\":\"abc-def-123\",\"status\":\"live\",\"subtype\":\"tcp\",\"tags\":[\"env:production\"],\"type\":\"network\"},\"type\":\"network\"}}\n\n@endpoint GET /api/v2/synthetics/tests/network/{public_id}\n@desc Get a Network Path test\n@required {public_id: str # The public ID of the Network Path test to get details from.}\n@returns(200) {data: map{attributes: map{config: map{assertions: [any], request: map}, locations: [str], message: str, monitor_id: int(int64), name: str, options: map{min_failure_duration: int(int64), min_location_failed: int(int64), monitor_name: str, monitor_options: map, monitor_priority: int(int32), restricted_roles: [str], retry: map, scheduling: map, tick_every: int(int64)}, public_id: str, status: str, subtype: str, tags: [str], type: str}, id: str, type: str}} # OK\n@errors {400: API error response., 404: API error response., 429: Too many requests}\n\n@endpoint PUT /api/v2/synthetics/tests/network/{public_id}\n@desc Edit a Network Path test\n@required {public_id: str # The public ID of the Network Path test to edit., data: map{attributes!: map, type!: str} # Data object for creating or editing a Network Path test.}\n@returns(200) {data: map{attributes: map{config: map{assertions: [any], request: map}, locations: [str], message: str, monitor_id: int(int64), name: str, options: map{min_failure_duration: int(int64), min_location_failed: int(int64), monitor_name: str, monitor_options: map, monitor_priority: int(int32), restricted_roles: [str], retry: map, scheduling: map, tick_every: int(int64)}, public_id: str, status: str, subtype: str, tags: [str], type: str}, id: str, type: str}} # OK\n@errors {400: API error response., 404: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"config\":{\"assertions\":[{\"operator\":\"lessThan\",\"property\":\"avg\",\"target\":500,\"type\":\"latency\"}],\"request\":{\"e2e_queries\":50,\"host\":\"\",\"max_ttl\":30,\"port\":443,\"tcp_method\":\"prefer_sack\",\"traceroute_queries\":3}},\"locations\":[\"aws:us-east-1\",\"agent:my-agent-name\"],\"message\":\"Network Path test notification\",\"monitor_id\":12345678,\"name\":\"Example Network Path test\",\"options\":{\"monitor_options\":{\"notification_preset_name\":\"show_all\"},\"scheduling\":{\"timeframes\":[{\"day\":1,\"from\":\"07:00\",\"to\":\"16:00\"},{\"day\":3,\"from\":\"07:00\",\"to\":\"16:00\"}],\"timezone\":\"America/New_York\"}},\"public_id\":\"abc-def-123\",\"status\":\"live\",\"subtype\":\"tcp\",\"tags\":[\"env:production\"],\"type\":\"network\"},\"type\":\"network\"}}\n\n@endpoint GET /api/v2/synthetics/tests/poll_results\n@desc Poll for test results\n@required {result_ids: str # A JSON-encoded array of result IDs to poll for.}\n@returns(200) {data: [map], included: [map]} # OK\n@errors {400: API error response., 404: API error response., 429: Too many requests}\n\n@endpoint POST /api/v2/synthetics/tests/{public_id}/files/download\n@desc Get a presigned URL for downloading a test file\n@required {public_id: str # The public ID of the Synthetic test., bucketKey: str # The bucket key referencing the file to download.}\n@returns(200) {url: str} # OK\n@errors {400: API error response., 403: Forbidden., 404: API error response., 429: Too many requests}\n@example_request {\"bucketKey\":\"api-upload-file/abc-def-123/2024-01-01T00:00:00_uuid.json\"}\n\n@endpoint POST /api/v2/synthetics/tests/{public_id}/files/multipart-presigned-urls\n@desc Get presigned URLs for uploading a test file\n@required {public_id: str # The public ID of the Synthetic test., bucketKeyPrefix: str(api-upload-file/browser-upload-file-step) # The bucket key prefix indicating the type of file upload., parts: [map{md5!: str, partNumber!: int(int64)}] # Array of part descriptors for the multipart upload.}\n@returns(200) {bucketKey: str, multipart_presigned_urls_params: map{key: str, upload_id: str, urls: map}} # OK\n@errors {400: API error response., 403: Forbidden., 404: API error response., 429: Too many requests}\n@example_request {\"bucketKeyPrefix\":\"api-upload-file\",\"parts\":[{\"md5\":\"1B2M2Y8AsgTpgAmY7PhCfg==\",\"partNumber\":1}]}\n\n@endpoint POST /api/v2/synthetics/tests/{public_id}/files/multipart-upload-abort\n@desc Abort a multipart upload of a test file\n@required {public_id: str # The public ID of the Synthetic test., key: str # The full storage path of the file whose upload should be aborted., uploadId: str # The upload ID of the multipart upload to abort.}\n@returns(204) No Content\n@errors {400: API error response., 403: Forbidden., 404: API error response., 429: Too many requests}\n@example_request {\"key\":\"org-123/api-upload-file/abc-def-123/2024-01-01T00:00:00_uuid.json\",\"uploadId\":\"upload-id-abc123\"}\n\n@endpoint POST /api/v2/synthetics/tests/{public_id}/files/multipart-upload-complete\n@desc Complete a multipart upload of a test file\n@required {public_id: str # The public ID of the Synthetic test., key: str # The full storage path for the uploaded file., parts: [map{ETag!: str, PartNumber!: int(int64)}] # Array of completed parts with their ETags., uploadId: str # The upload ID returned when the multipart upload was initiated.}\n@returns(204) No Content\n@errors {400: API error response., 403: Forbidden., 404: API error response., 429: Too many requests}\n@example_request {\"key\":\"org-123/api-upload-file/abc-def-123/2024-01-01T00:00:00_uuid.json\",\"parts\":[{\"ETag\":\"\\\"d41d8cd98f00b204e9800998ecf8427e\\\"\",\"PartNumber\":1}],\"uploadId\":\"upload-id-abc123\"}\n\n@endpoint GET /api/v2/synthetics/tests/{public_id}/parent-suites\n@desc Get parent suites for a test\n@required {public_id: str # The public ID of the Synthetic test.}\n@returns(200) {data: [map]} # OK\n@errors {404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/synthetics/tests/{public_id}/results\n@desc Get a test's latest results\n@required {public_id: str # The public ID of the Synthetic test for which to search results.}\n@optional {from_ts: int(int64) # Timestamp in milliseconds from which to start querying results., to_ts: int(int64) # Timestamp in milliseconds up to which to query results., status: str # Filter results by status., runType: str # Filter results by run type., probe_dc: [str] # Locations for which to query results., device_id: [str] # Device IDs for which to query results.}\n@returns(200) {data: [map], included: [map]} # OK\n@errors {400: API error response., 404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/synthetics/tests/{public_id}/results/{result_id}\n@desc Get a test result\n@required {public_id: str # The public ID of the Synthetic test to which the target result belongs., result_id: str # The ID of the result to get.}\n@optional {event_id: str # The event ID used to look up the result in the event store., timestamp: int(int64) # Timestamp in seconds to look up the result.}\n@returns(200) {data: map{attributes: map{batch: map{id: str}, ci: map{pipeline: map, provider: map, stage: map, workspace_path: str}, device: map{browser: map, id: str, name: str, platform: map, resolution: map, type: str}, git: map{branch: str, commit: map, repository_url: str}, location: map{id: str, name: str, version: str, worker_id: str}, result: map{assertions: [map], bucket_keys: map, call_type: str, cert: map, compressed_json_descriptor: str, compressed_steps: str, connection_outcome: str, dns_resolution: map, duration: num(double), exited_on_step_success: bool, failure: map, finished_at: int(int64), handshake: map, id: str, initial_id: str, is_fast_retry: bool, is_last_retry: bool, netpath: map, netstats: map, ocsp: map, ping: map, received_email_count: int(int64), received_message: str, request: map, resolved_ip: str, response: map, run_type: str, sent_message: str, start_url: str, started_at: int(int64), status: str, steps: [map], time_to_interactive: int(int64), timings: map, trace: map, traceroute: [map], triggered_at: int(int64), tunnel: bool, turns: [map], unhealthy: bool, variables: map}, test_sub_type: str, test_type: str}, id: str, relationships: map{test: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: API error response., 404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/synthetics/tests/{public_id}/version_history\n@desc Get version history of a test\n@required {public_id: str # The public ID of the Synthetic test.}\n@optional {last_version_number: int(int64) # The version number of the last item from the previous page. Omit to get the first page., limit: int(int64) # Maximum number of version records to return per page.}\n@returns(200) {data: [map], meta: map{next_last_version_number: int(int64)?, retention_period_in_days: int(int64)}} # OK\n@errors {403: API error response., 404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/synthetics/tests/{public_id}/version_history/{version_number}\n@desc Get a specific version of a test\n@required {public_id: str # The public ID of the Synthetic test., version_number: int(int64) # The version number to retrieve.}\n@optional {include_change_metadata: bool # If `true`, include change metadata in the response., only_check_existence: bool # If `true`, only check whether the version exists without returning its full payload. Returns an empty object if the version exists, or 404 if not.}\n@returns(200) {data: map{attributes: map{author: map{email: str, handle: str, id: str, name: str}, change_metadata: [map], payload: map, version_payload_created_at: str(date-time)}, id: str, type: str}} # OK\n@errors {404: API error response., 429: Too many requests}\n\n@endpoint PATCH /api/v2/synthetics/variables/{variable_id}/jsonpatch\n@desc Patch a global variable\n@required {variable_id: str # The ID of the global variable., data: map{attributes: map, type: str} # Data object for a JSON Patch request on a Synthetic global variable.}\n@returns(200) {data: map{attributes: map{attributes: map{restricted_roles: [str]}, description: str, id: str, is_fido: bool, is_totp: bool, name: str, parse_test_options: map{field: str, localVariableName: str, parser: map, type: str}, parse_test_public_id: str, tags: [str], value: map{options: map, secure: bool, value: str}}, id: str, type: str}} # OK\n@errors {400: Bad Request, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"json_patch\":[{\"op\":\"add\",\"path\":\"/name\"}]},\"type\":\"global_variables_json_patch\"}}\n\n@endpoint GET /api/v2/tag_policies\n@desc List tag policies\n@optional {include_disabled: bool # Whether to include policies that are currently disabled. Defaults to `false`., include_deleted: bool # Whether to include policies that have been soft-deleted. Defaults to `false`., include: str # Comma-separated list of related resources to include alongside each policy in the response. Currently the only supported value is `score`., filter[source]: str # Restrict the result set to policies whose source matches the given value., ts_start: int(int64) # Start of the time window used for compliance score computation, as a Unix timestamp in milliseconds. Defaults to a recent window appropriate for the source., ts_end: int(int64) # End of the time window used for compliance score computation, as a Unix timestamp in milliseconds. Must be in the past and greater than `ts_start`.}\n@returns(200) {data: [map], included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/tag_policies\n@desc Create a tag policy\n@required {data: map{attributes!: map, type!: str} # Data object for creating a tag policy.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), created_by: str, deleted_at: str(date-time)?, deleted_by: str?, enabled: bool, modified_at: str(date-time), modified_by: str, negated: bool, policy_name: str, policy_type: str, required: bool, scope: str, source: str, tag_key: str, tag_value_patterns: [str], version: int(int64)}, id: str, relationships: map{score: map{data: map}}, type: str}, included: [map]} # Created\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"negated\":false,\"policy_name\":\"Service tag must be one of api or web\",\"policy_type\":\"surfacing\",\"required\":true,\"scope\":\"env\",\"source\":\"logs\",\"tag_key\":\"service\",\"tag_value_patterns\":[\"api\",\"web\"]},\"type\":\"tag_policy\"}}\n\n@endpoint DELETE /api/v2/tag_policies/{policy_id}\n@desc Delete a tag policy\n@required {policy_id: str # The unique identifier of the tag policy to delete.}\n@optional {hard_delete: bool # Whether to permanently delete the policy instead of performing a soft delete. Defaults to `false`.}\n@returns(204) No Content\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/tag_policies/{policy_id}\n@desc Get a tag policy\n@required {policy_id: str # The unique identifier of the tag policy.}\n@optional {include: str # Comma-separated list of related resources to include alongside the policy. Currently the only supported value is `score`., ts_start: int(int64) # Start of the time window used for compliance score computation, as a Unix timestamp in milliseconds., ts_end: int(int64) # End of the time window used for compliance score computation, as a Unix timestamp in milliseconds. Must be in the past and greater than `ts_start`.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, deleted_at: str(date-time)?, deleted_by: str?, enabled: bool, modified_at: str(date-time), modified_by: str, negated: bool, policy_name: str, policy_type: str, required: bool, scope: str, source: str, tag_key: str, tag_value_patterns: [str], version: int(int64)}, id: str, relationships: map{score: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/tag_policies/{policy_id}\n@desc Update a tag policy\n@required {policy_id: str # The unique identifier of the tag policy to update., data: map{attributes: map, id!: str, type!: str} # Data object for updating a tag policy.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), created_by: str, deleted_at: str(date-time)?, deleted_by: str?, enabled: bool, modified_at: str(date-time), modified_by: str, negated: bool, policy_name: str, policy_type: str, required: bool, scope: str, source: str, tag_key: str, tag_value_patterns: [str], version: int(int64)}, id: str, relationships: map{score: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"policy_name\":\"Service tag must be one of api, web, or worker\"},\"id\":\"123\",\"type\":\"tag_policy\"}}\n\n@endpoint GET /api/v2/tag_policies/{policy_id}/score\n@desc Get a tag policy compliance score\n@required {policy_id: str # The unique identifier of the tag policy.}\n@optional {ts_start: int(int64) # Start of the time window used for compliance score computation, as a Unix timestamp in milliseconds., ts_end: int(int64) # End of the time window used for compliance score computation, as a Unix timestamp in milliseconds. Must be in the past and greater than `ts_start`.}\n@returns(200) {data: map{attributes: map{score: num(double)?, ts_end: int(int64), ts_start: int(int64), version: int(int64)}, id: str, type: str}} # OK\n@errors {400: Bad Request, 401: Unauthorized, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/tags/enrichment\n@desc List tag pipeline rulesets\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/tags/enrichment\n@desc Create tag pipeline ruleset\n@optional {data: map{attributes: map, id: str, type!: str} # The definition of `CreateRulesetRequestData` object.}\n@returns(200) {data: map{attributes: map{created: map{nanos: int(int32), seconds: int(int64)}, enabled: bool, last_modified_user_uuid: str, modified: map{nanos: int(int32), seconds: int(int64)}, name: str, position: int(int32), processing_status: str, rules: [map], version: int(int64)}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"rules\":[{\"enabled\":true,\"name\":\"Add Cost Center Tag\",\"query\":{\"addition\":{\"key\":\"cost_center\",\"value\":\"engineering\"},\"case_insensitivity\":false,\"if_tag_exists\":\"do_not_apply\",\"query\":\"account_id:\\\"123456789\\\" AND service:\\\"web-api\\\"\"}}]},\"id\":\"New Ruleset\",\"type\":\"create_ruleset\"}}\n\n@endpoint POST /api/v2/tags/enrichment/reorder\n@desc Reorder tag pipeline rulesets\n@required {data: [map{id: str, type!: str}] # The `ReorderRulesetResourceArray` `data`.}\n@returns(204) Successfully reordered rulesets\n@errors {429: Too many requests}\n@example_request {\"data\":[{\"id\":\"55ef2385-9ae1-4410-90c4-5ac1b60fec10\",\"type\":\"ruleset\"},{\"id\":\"a7b8c9d0-1234-5678-9abc-def012345678\",\"type\":\"ruleset\"},{\"id\":\"f1e2d3c4-b5a6-9780-1234-567890abcdef\",\"type\":\"ruleset\"}]}\n\n@endpoint GET /api/v2/tags/enrichment/status\n@desc List tag pipeline ruleset statuses\n@returns(200) {data: [map]} # OK\n@errors {429: Too many requests}\n\n@endpoint POST /api/v2/tags/enrichment/validate-query\n@desc Validate query\n@optional {data: map{attributes: map, id: str, type!: str} # The definition of `RulesValidateQueryRequestData` object.}\n@returns(200) {data: map{attributes: map{Canonical: str}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"Query\":\"example:query AND test:true\"},\"type\":\"validate_query\"}}\n\n@endpoint DELETE /api/v2/tags/enrichment/{ruleset_id}\n@desc Delete tag pipeline ruleset\n@required {ruleset_id: str # The unique identifier of the ruleset}\n@returns(204) No Content\n@errors {429: Too many requests}\n\n@endpoint GET /api/v2/tags/enrichment/{ruleset_id}\n@desc Get a tag pipeline ruleset\n@required {ruleset_id: str # The unique identifier of the ruleset}\n@returns(200) {data: map{attributes: map{created: map{nanos: int(int32), seconds: int(int64)}, enabled: bool, last_modified_user_uuid: str, modified: map{nanos: int(int32), seconds: int(int64)}, name: str, position: int(int32), processing_status: str, rules: [map], version: int(int64)}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n\n@endpoint PATCH /api/v2/tags/enrichment/{ruleset_id}\n@desc Update tag pipeline ruleset\n@required {ruleset_id: str # The unique identifier of the ruleset}\n@optional {data: map{attributes: map, id: str, type!: str} # The definition of `UpdateRulesetRequestData` object.}\n@returns(200) {data: map{attributes: map{created: map{nanos: int(int32), seconds: int(int64)}, enabled: bool, last_modified_user_uuid: str, modified: map{nanos: int(int32), seconds: int(int64)}, name: str, position: int(int32), processing_status: str, rules: [map], version: int(int64)}, id: str, type: str}} # OK\n@errors {429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"enabled\":true,\"last_version\":1,\"name\":\"Updated Ruleset\",\"rules\":[{\"enabled\":true,\"name\":\"Add Cost Center Tag\",\"query\":{\"addition\":{\"key\":\"cost_center\",\"value\":\"engineering\"},\"case_insensitivity\":false,\"if_tag_exists\":\"do_not_apply\",\"query\":\"account_id:\\\"123456789\\\" AND service:\\\"web-api\\\"\"}},{\"enabled\":true,\"mapping\":{\"destination_key\":\"team_owner\",\"if_tag_exists\":\"do_not_apply\",\"source_keys\":[\"account_name\",\"account_id\"]},\"name\":\"Account Name Mapping\",\"query\":null},{\"enabled\":true,\"name\":\"New table rule with new UI\",\"query\":null,\"reference_table\":{\"case_insensitivity\":true,\"field_pairs\":[{\"input_column\":\"status_type\",\"output_key\":\"status\"},{\"input_column\":\"status_description\",\"output_key\":\"dess\"}],\"if_tag_exists\":\"append\",\"source_keys\":[\"http_status\",\"status_description\"],\"table_name\":\"http_status_codes\"}}]},\"type\":\"update_ruleset\"}}\n\n@endpoint GET /api/v2/team\n@desc Get all teams\n@optional {page[number]: int(int64)=0: any # Specific page number to return., page[size]: int(int64)=10 # Size for a given page. The maximum allowed value is 100., sort: str # Specifies the order of the returned teams, include: [str] # Included related resources optionally requested. Allowed enum values: `team_links, user_team_permissions`, filter[keyword]: str # Search query. Can be team name, team handle, or email of team member, filter[me]: bool # When true, only returns teams the current user belongs to, fields[team]: [str] # List of fields that need to be fetched.}\n@returns(200) {data: [map], included: [any], links: map{first: str, last: str?, next: str, prev: str?, self: str}, meta: map{pagination: map{first_offset: int(int64), last_offset: int(int64), limit: int(int64), next_offset: int(int64), offset: int(int64), prev_offset: int(int64), total: int(int64), type: str}}} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/team\n@desc Create a team\n@required {data: map{attributes!: map, relationships: map, type!: str} # Team create}\n@returns(201) {data: map{attributes: map{avatar: str?, banner: int(int64)?, created_at: str(date-time), description: str?, handle: str, hidden_modules: [str]?, is_managed: bool, link_count: int(int32), modified_at: str(date-time), name: str, summary: str?, user_count: int(int32), visible_modules: [str]?}, id: str, relationships: map{team_links: map{data: [map], links: map}, user_team_permissions: map{data: map?, links: map}}, type: str}} # CREATED\n@errors {403: Forbidden, 409: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"avatar\":\"🥑\",\"handle\":\"example-team\",\"name\":\"Example Team\"},\"relationships\":{\"users\":{\"data\":[]}},\"type\":\"team\"}}\n\n@endpoint GET /api/v2/team-hierarchy-links\n@desc Get team hierarchy links\n@optional {page[number]: int(int64)=0: any # Specific page number to return., page[size]: int(int64)=10 # Size for a given page. The maximum allowed value is 100., filter[parent_team]: str # Filter by parent team ID, filter[sub_team]: str # Filter by sub team ID}\n@returns(200) {data: [map], included: [map], links: map{first: str?, last: str?, next: str?, prev: str?, self: str}, meta: map{page: map{first_number: int(int64), last_number: int(int64), next_number: int(int64)?, number: int(int64), prev_number: int(int64)?, size: int(int64), total: int(int64), type: str}}} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/team-hierarchy-links\n@desc Create a team hierarchy link\n@required {data: map{relationships!: map, type!: str} # Data provided when creating a team hierarchy link}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), provisioned_by: str}, id: str, relationships: map{parent_team: map{data: map}, sub_team: map{data: map}}, type: str}, included: [map], links: map{first: str?, last: str?, next: str?, prev: str?, self: str}} # OK\n@errors {403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":{\"relationships\":{\"parent_team\":{\"data\":{\"id\":\"692e8073-12c4-4c71-8408-5090bd44c9c8\",\"type\":\"team\"}},\"sub_team\":{\"data\":{\"id\":\"692e8073-12c4-4c71-8408-5090bd44c9c8\",\"type\":\"team\"}}},\"type\":\"team_hierarchy_links\"}}\n\n@endpoint DELETE /api/v2/team-hierarchy-links/{link_id}\n@desc Remove a team hierarchy link\n@required {link_id: str # The team hierarchy link's identifier}\n@returns(204) No Content\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/team-hierarchy-links/{link_id}\n@desc Get a team hierarchy link\n@required {link_id: str # The team hierarchy link's identifier}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), provisioned_by: str}, id: str, relationships: map{parent_team: map{data: map}, sub_team: map{data: map}}, type: str}, included: [map], links: map{first: str?, last: str?, next: str?, prev: str?, self: str}} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint DELETE /api/v2/team/connections\n@desc Delete team connections\n@required {data: [map{id!: str, type!: str}] # Array of team connection IDs to delete.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":[{\"id\":\"12345678-1234-5678-9abc-123456789012\",\"type\":\"team_connection\"}]}\n\n@endpoint GET /api/v2/team/connections\n@desc List team connections\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., filter[sources]: [str] # Filter team connections by external source systems., filter[team_ids]: [str] # Filter team connections by Datadog team IDs., filter[connected_team_ids]: [str] # Filter team connections by connected team IDs from external systems., filter[connection_ids]: [str] # Filter team connections by connection IDs.}\n@returns(200) {data: [map], meta: map{page: map{first_number: int(int64), last_number: int(int64), next_number: int(int64)?, number: int(int64), prev_number: int(int64)?, size: int(int64), total: int(int64), type: str}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/team/connections\n@desc Create team connections\n@required {data: [map{attributes: map, relationships: map, type!: str}] # Array of team connections to create.}\n@returns(201) {data: [map], meta: map{page: map{first_number: int(int64), last_number: int(int64), next_number: int(int64)?, number: int(int64), prev_number: int(int64)?, size: int(int64), total: int(int64), type: str}}} # Created\n@errors {400: Bad Request, 403: Forbidden, 409: Conflict, 429: Too many requests}\n@example_request {\"data\":[{\"attributes\":{\"managed_by\":\"github_sync\",\"source\":\"github\"},\"relationships\":{\"connected_team\":{\"data\":{\"id\":\"@GitHubOrg/team-handle\"}},\"team\":{\"data\":{\"id\":\"87654321-4321-8765-dcba-210987654321\"}}},\"type\":\"team_connection\"}]}\n\n@endpoint GET /api/v2/team/sync\n@desc Get team sync configurations\n@required {filter[source]: str: any # Filter by the external source platform for team synchronization}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/team/sync\n@desc Link Teams with GitHub Teams\n@required {data: map{attributes!: map, id: str, type!: str} # A configuration governing syncing between Datadog teams and teams from an external system.}\n@returns(200) OK\n@returns(204) No Content\n@errors {403: Forbidden, 429: Too many requests, 500: Internal Server Error - Unexpected error during linking.}\n@example_request {\"data\":{\"attributes\":{\"source\":\"github\",\"type\":\"link\"},\"type\":\"team_sync_bulk\"}}\n\n@endpoint GET /api/v2/team/{super_team_id}/member_teams\n@desc Get all member teams\n@required {super_team_id: str # None}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., fields[team]: [str] # List of fields that need to be fetched.}\n@returns(200) {data: [map], included: [any], links: map{first: str, last: str?, next: str, prev: str?, self: str}, meta: map{pagination: map{first_offset: int(int64), last_offset: int(int64), limit: int(int64), next_offset: int(int64), offset: int(int64), prev_offset: int(int64), total: int(int64), type: str}}} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint POST /api/v2/team/{super_team_id}/member_teams\n@desc Add a member team\n@required {super_team_id: str # None, data: map{id!: str, type!: str} # A member team}\n@returns(204) Added\n@errors {403: Forbidden, 409: API error response., 429: Too many requests}\n@example_request {\"data\":{\"id\":\"aeadc05e-98a8-11ec-ac2c-da7ad0900001\",\"type\":\"member_teams\"}}\n\n@endpoint DELETE /api/v2/team/{super_team_id}/member_teams/{member_team_id}\n@desc Remove a member team\n@required {super_team_id: str # None, member_team_id: str # None}\n@returns(204) No Content\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint DELETE /api/v2/team/{team_id}\n@desc Remove a team\n@required {team_id: str # None}\n@returns(204) No Content\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/team/{team_id}\n@desc Get a team\n@required {team_id: str # None}\n@returns(200) {data: map{attributes: map{avatar: str?, banner: int(int64)?, created_at: str(date-time), description: str?, handle: str, hidden_modules: [str]?, is_managed: bool, link_count: int(int32), modified_at: str(date-time), name: str, summary: str?, user_count: int(int32), visible_modules: [str]?}, id: str, relationships: map{team_links: map{data: [map], links: map}, user_team_permissions: map{data: map?, links: map}}, type: str}} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint PATCH /api/v2/team/{team_id}\n@desc Update a team\n@required {team_id: str # None, data: map{attributes!: map, relationships: map, type!: str} # Team update request}\n@returns(200) {data: map{attributes: map{avatar: str?, banner: int(int64)?, created_at: str(date-time), description: str?, handle: str, hidden_modules: [str]?, is_managed: bool, link_count: int(int32), modified_at: str(date-time), name: str, summary: str?, user_count: int(int32), visible_modules: [str]?}, id: str, relationships: map{team_links: map{data: [map], links: map}, user_team_permissions: map{data: map?, links: map}}, type: str}} # OK\n@errors {400: API error response., 403: Forbidden, 404: API error response., 409: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"avatar\":\"🥑\",\"handle\":\"example-team\",\"name\":\"Example Team\"},\"relationships\":{\"team_links\":{\"data\":[{\"id\":\"f9bb8444-af7f-11ec-ac2c-da7ad0900001\"}],\"links\":{\"related\":\"/api/v2/team/c75a4a8e-20c7-11ee-a3a5-da7ad0900002/links\"}}},\"type\":\"team\"}}\n\n@endpoint GET /api/v2/team/{team_id}/links\n@desc Get links for a team\n@required {team_id: str # None}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint POST /api/v2/team/{team_id}/links\n@desc Create a team link\n@required {team_id: str # None, data: map{attributes!: map, type!: str} # Team link create}\n@returns(200) {data: map{attributes: map{label: str, position: int(int32), team_id: str, url: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: API error response., 422: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"label\":\"Link label\",\"position\":0,\"url\":\"https://example.com\"},\"type\":\"team_links\"}}\n\n@endpoint DELETE /api/v2/team/{team_id}/links/{link_id}\n@desc Remove a team link\n@required {team_id: str # None, link_id: str # None}\n@returns(204) No Content\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/team/{team_id}/links/{link_id}\n@desc Get a team link\n@required {team_id: str # None, link_id: str # None}\n@returns(200) {data: map{attributes: map{label: str, position: int(int32), team_id: str, url: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint PATCH /api/v2/team/{team_id}/links/{link_id}\n@desc Update a team link\n@required {team_id: str # None, link_id: str # None, data: map{attributes!: map, type!: str} # Team link create}\n@returns(200) {data: map{attributes: map{label: str, position: int(int32), team_id: str, url: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"label\":\"Link label\",\"url\":\"https://example.com\"},\"type\":\"team_links\"}}\n\n@endpoint GET /api/v2/team/{team_id}/memberships\n@desc Get team memberships\n@required {team_id: str # None}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str # Specifies the order of returned team memberships, filter[keyword]: str # Search query, can be user email or name}\n@returns(200) {data: [map], included: [any], links: map{first: str, last: str?, next: str, prev: str?, self: str}, meta: map{pagination: map{first_offset: int(int64), last_offset: int(int64), limit: int(int64), next_offset: int(int64), offset: int(int64), prev_offset: int(int64), total: int(int64), type: str}}} # Represents a user's association to a team\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint POST /api/v2/team/{team_id}/memberships\n@desc Add a user to a team\n@required {team_id: str # None, data: map{attributes: map, relationships: map, type!: str} # A user's relationship with a team}\n@returns(200) {data: map{attributes: map{provisioned_by: str?, provisioned_by_id: str?, role: str?}, id: str, relationships: map{team: map{data: map}, user: map{data: map}}, type: str}, included: [any]} # Represents a user's association to a team\n@errors {403: Forbidden, 404: API error response., 409: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"role\":\"admin\"},\"relationships\":{\"team\":{\"data\":{\"id\":\"d7e15d9d-d346-43da-81d8-3d9e71d9a5e9\",\"type\":\"team\"}},\"user\":{\"data\":{\"id\":\"b8626d7e-cedd-11eb-abf5-da7ad0900001\",\"type\":\"users\"}}},\"type\":\"team_memberships\"}}\n\n@endpoint DELETE /api/v2/team/{team_id}/memberships/{user_id}\n@desc Remove a user from a team\n@required {team_id: str # None, user_id: str # None}\n@returns(204) No Content\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint PATCH /api/v2/team/{team_id}/memberships/{user_id}\n@desc Update a user's membership attributes on a team\n@required {team_id: str # None, user_id: str # None, data: map{attributes: map, type!: str} # A user's relationship with a team}\n@returns(200) {data: map{attributes: map{provisioned_by: str?, provisioned_by_id: str?, role: str?}, id: str, relationships: map{team: map{data: map}, user: map{data: map}}, type: str}, included: [any]} # OK\n@errors {400: API error response., 403: Forbidden, 404: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"role\":\"admin\"},\"type\":\"team_memberships\"}}\n\n@endpoint GET /api/v2/team/{team_id}/notification-rules\n@desc Get team notification rules\n@required {team_id: str # None}\n@returns(200) {data: [map], meta: map{page: map{first_offset: int(int64), last_offset: int(int64), limit: int(int64), next_offset: int(int64)?, offset: int(int64), prev_offset: int(int64)?, total: int(int64), type: str}}} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint POST /api/v2/team/{team_id}/notification-rules\n@desc Create team notification rule\n@required {team_id: str # None, data: map{attributes!: map, id: str, type!: str} # Team notification rule}\n@returns(201) {data: map{attributes: map{email: map{enabled: bool}, ms_teams: map{connector_name: str}, pagerduty: map{service_name: str}, slack: map{channel: str, workspace: str}}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: API error response., 409: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"email\":{\"enabled\":true},\"slack\":{\"channel\":\"test-ops\",\"workspace\":\"Datadog\"}},\"type\":\"team_notification_rules\"}}\n\n@endpoint DELETE /api/v2/team/{team_id}/notification-rules/{rule_id}\n@desc Delete team notification rule\n@required {team_id: str # None, rule_id: str # None}\n@returns(204) No Content\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/team/{team_id}/notification-rules/{rule_id}\n@desc Get team notification rule\n@required {team_id: str # None, rule_id: str # None}\n@returns(200) {data: map{attributes: map{email: map{enabled: bool}, ms_teams: map{connector_name: str}, pagerduty: map{service_name: str}, slack: map{channel: str, workspace: str}}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint PUT /api/v2/team/{team_id}/notification-rules/{rule_id}\n@desc Update team notification rule\n@required {team_id: str # None, rule_id: str # None, data: map{attributes!: map, id: str, type!: str} # Team notification rule}\n@returns(200) {data: map{attributes: map{email: map{enabled: bool}, ms_teams: map{connector_name: str}, pagerduty: map{service_name: str}, slack: map{channel: str, workspace: str}}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"pagerduty\":{\"service_name\":\"Datadog-prod\"},\"slack\":{\"channel\":\"test-ops\",\"workspace\":\"Datadog\"}},\"id\":\"b8626d7e-cedd-11eb-abf5-da7ad0900001\",\"type\":\"team_notification_rules\"}}\n\n@endpoint GET /api/v2/team/{team_id}/permission-settings\n@desc Get permission settings for a team\n@required {team_id: str # None}\n@returns(200) {data: [map]} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n\n@endpoint PUT /api/v2/team/{team_id}/permission-settings/{action}\n@desc Update permission setting for team\n@required {team_id: str # None, action: str # None, data: map{attributes: map, type!: str} # Team permission setting update}\n@returns(200) {data: map{attributes: map{action: str, editable: bool, options: [str], title: str, value: str}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: API error response., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"value\":\"admins\"},\"type\":\"team_permission_settings\"}}\n\n@endpoint PATCH /api/v2/test/flaky-test-management/tests\n@desc Update flaky test states\n@required {data: map{attributes!: map, type!: str} # The JSON:API data for updating flaky test states.}\n@returns(200) {data: map{attributes: map{has_errors: bool, results: [map]}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"tests\":[{\"id\":\"4eb1887a8adb1847\",\"new_state\":\"active\"}]},\"type\":\"update_flaky_test_state_request\"}}\n\n@endpoint POST /api/v2/test/flaky-test-management/tests\n@desc Search flaky tests\n@optional {data: map{attributes: map, type: str} # The JSON:API data for flaky tests search request.}\n@returns(200) {data: [map], meta: map{pagination: map{next_page: str?}}} # OK\n@errors {400: Bad Request, 403: Not Authorized, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"filter\":{\"query\":\"flaky_test_state:active @git.repository.id_v2:\\\"github.com/datadog/test-service\\\"\"},\"page\":{\"cursor\":\"eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==\",\"limit\":25},\"sort\":\"failure_rate\"},\"type\":\"search_flaky_tests_request\"}}\n\n@endpoint GET /api/v2/trace/{trace_id}\n@desc Get a trace by ID\n@required {trace_id: str # The trace ID. Accepts either a 32-character hexadecimal string (128-bit trace ID) or a decimal string of up to 39 digits.}\n@optional {include_fields: [str] # List of span fields to include in the response. When omitted, every available field is returned. Values may be passed as repeated query parameters or as a single comma-separated value.}\n@returns(200) {data: map{attributes: map{is_truncated: bool, spans: [map]}, id: str, type: str}} # OK\n@errors {403: Forbidden, 404: Not Found, 413: Payload Too Large, 429: Too many requests}\n\n@endpoint GET /api/v2/usage/application_security\n@desc Get hourly usage for application security\n@required {start_hr: str(date-time) # Datetime in ISO-8601 format, UTC, precise to hour: `[YYYY-MM-DDThh]` for usage beginning at this hour.}\n@optional {end_hr: str(date-time) # Datetime in ISO-8601 format, UTC, precise to hour: `[YYYY-MM-DDThh]` for usage ending **before** this hour.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/usage/billing_dimension_mapping\n@desc Get billing dimension mapping for usage endpoints\n@optional {filter[month]: str(date-time): any # Datetime in ISO-8601 format, UTC, and for mappings beginning this month. Defaults to the current month., filter[view]: str=active # String to specify whether to retrieve active billing dimension mappings for the contract or for all available mappings. Allowed views have the string `active` or `all`. Defaults to `active`.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/usage/cost_by_org\n@desc Get cost across multi-org account\n@required {start_month: str(date-time) # Datetime in ISO-8601 format, UTC, precise to month: `[YYYY-MM]` for cost beginning this month.}\n@optional {end_month: str(date-time) # Datetime in ISO-8601 format, UTC, precise to month: `[YYYY-MM]` for cost ending this month.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/usage/estimated_cost\n@desc Get estimated cost across your account\n@optional {view: str # String to specify whether cost is broken down at a parent-org level or at the sub-org level. Available views are `summary` and `sub-org`. Defaults to `summary`., start_month: str(date-time) # Datetime in ISO-8601 format, UTC, precise to month: `[YYYY-MM]` for cost beginning this month. **Either start_month or start_date should be specified, but not both.** (start_month cannot go beyond two months in the past). Provide an `end_month` to view month-over-month cost., end_month: str(date-time) # Datetime in ISO-8601 format, UTC, precise to month: `[YYYY-MM]` for cost ending this month., start_date: str(date-time) # Datetime in ISO-8601 format, UTC, precise to day: `[YYYY-MM-DD]` for cost beginning this day. **Either start_month or start_date should be specified, but not both.** (start_date cannot go beyond two months in the past). Provide an `end_date` to view day-over-day cumulative cost., end_date: str(date-time) # Datetime in ISO-8601 format, UTC, precise to day: `[YYYY-MM-DD]` for cost ending this day., cost_aggregation: str # Controls how costs are aggregated when using `start_date`. The `cumulative` option returns month-to-date running totals., include_connected_accounts: bool=false # Boolean to specify whether to include accounts connected to the current account as partner customers in the Datadog partner network program. Defaults to `false`.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/usage/historical_cost\n@desc Get historical cost across your account\n@required {start_month: str(date-time) # Datetime in ISO-8601 format, UTC, precise to month: `[YYYY-MM]` for cost beginning this month.}\n@optional {view: str # String to specify whether cost is broken down at a parent-org level or at the sub-org level. Available views are `summary` and `sub-org`.  Defaults to `summary`., end_month: str(date-time) # Datetime in ISO-8601 format, UTC, precise to month: `[YYYY-MM]` for cost ending this month., include_connected_accounts: bool=false # Boolean to specify whether to include accounts connected to the current account as partner customers in the Datadog partner network program. Defaults to `false`.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/usage/hourly_usage\n@desc Get hourly usage by product family\n@required {filter[timestamp][start]: str(date-time): any # Datetime in ISO-8601 format, UTC, precise to hour: [YYYY-MM-DDThh] for usage beginning at this hour., filter[product_families]: str # Comma separated list of product families to retrieve. Available families are `all`, `ai`, `analyzed_logs`, `application_performance_monitoring`, `application_security`, `audit_trail`, `bits_ai`, `serverless`, `ci_app`, `cloud_cost_management`, `cloud_siem`, `csm_container_enterprise`, `csm_host_enterprise`, `csm_host_pro`, `cspm`, `custom_events`, `cws`, `data_observability`, `dbm`, `digital_experience_management`, `error_tracking`, `fargate`, `infra_hosts`, `incident_management`, `indexed_logs`, `indexed_spans`, `infrastructure_monitoring`, `ingested_spans`, `iot`, `lambda_traced_invocations`, `llm_observability`, `log_management`, `logs`, `network_flows`, `network_hosts`, `network_monitoring`, `observability_pipelines`, `online_archive`, `platform_capabilities`, `product_analytics`, `profiling`, `rum`, `rum_browser_sessions`, `rum_mobile_sessions`, `sds`, `security`, `snmp`, `software_delivery`, `synthetics_api`, `synthetics_browser`, `synthetics_mobile`, `synthetics_parallel_testing`, `timeseries`, `vuln_management` and `workflow_executions`. The following product family has been **deprecated**: `audit_logs`.}\n@optional {filter[timestamp][end]: str(date-time): any # Datetime in ISO-8601 format, UTC, precise to hour: [YYYY-MM-DDThh] for usage ending **before** this hour., filter[include_descendants]: bool=false # Include child org usage in the response. Defaults to false., filter[include_connected_accounts]: bool=false # Boolean to specify whether to include accounts connected to the current account as partner customers in the Datadog partner network program. Defaults to false., filter[include_breakdown]: bool=false # Include breakdown of usage by subcategories where applicable (for product family logs only). Defaults to false., filter[versions]: str # Comma separated list of product family versions to use in the format `product_family:version`. For example, `infra_hosts:1.0.0`. If this parameter is not used, the API will use the latest version of each requested product family. Currently all families have one version `1.0.0`., page[limit]: int(int32)=500 # Maximum number of results to return (between 1 and 500) - defaults to 500 if limit not specified., page[next_record_id]: str # List following results with a next_record_id provided in the previous query.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/usage/lambda_traced_invocations\n@desc Get hourly usage for Lambda traced invocations\n@required {start_hr: str(date-time) # Datetime in ISO-8601 format, UTC, precise to hour: `[YYYY-MM-DDThh]` for usage beginning at this hour.}\n@optional {end_hr: str(date-time) # Datetime in ISO-8601 format, UTC, precise to hour: `[YYYY-MM-DDThh]` for usage ending **before** this hour.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/usage/observability_pipelines\n@desc Get hourly usage for observability pipelines\n@required {start_hr: str(date-time) # Datetime in ISO-8601 format, UTC, precise to hour: `[YYYY-MM-DDThh]` for usage beginning at this hour.}\n@optional {end_hr: str(date-time) # Datetime in ISO-8601 format, UTC, precise to hour: `[YYYY-MM-DDThh]` for usage ending **before** this hour.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/usage/projected_cost\n@desc Get projected cost across your account\n@optional {view: str # String to specify whether cost is broken down at a parent-org level or at the sub-org level. Available views are `summary` and `sub-org`. Defaults to `summary`., include_connected_accounts: bool=false # Boolean to specify whether to include accounts connected to the current account as partner customers in the Datadog partner network program. Defaults to `false`.}\n@returns(200) OK\n@errors {400: Bad Request, 403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/usage/summary/available_fields\n@desc Get available fields for usage summary\n@returns(200) OK.\n@errors {403: Forbidden - User is not authorized., 429: Too many requests.}\n\n@endpoint GET /api/v2/usage/usage-attribution-types\n@desc Get usage attribution types\n@returns(200) OK\n@errors {403: Forbidden - User is not authorized, 429: Too many requests}\n\n@endpoint GET /api/v2/user_authorized_clients\n@desc List user authorized clients\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., filter: str # Filter results by client name, app title, or app description., filter[disabled]: str # Filter results by the user-level disabled status., include: str # Comma-separated list of related resources to include. Options: `oauth2_client`, `oauth2_client.app`.}\n@returns(200) {data: [map], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {403: Authentication error, 429: Too many requests}\n\n@endpoint DELETE /api/v2/user_authorized_clients/client/{client_id}\n@desc Delete all user authorized clients for a client\n@required {client_id: str # The ID of the OAuth2 client.}\n@returns(204) No Content\n@errors {403: Authentication error, 404: Not Found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/user_authorized_clients/{user_authorized_client_id}\n@desc Delete a user authorized client\n@required {user_authorized_client_id: str # The ID of the user authorized client.}\n@returns(204) No Content\n@errors {403: Authentication error, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/user_authorized_clients/{user_authorized_client_id}\n@desc Get a user authorized client\n@required {user_authorized_client_id: str # The ID of the user authorized client.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), disabled: bool, last_exercised: str(date-time)?, modified_at: str(date-time), org_disabled: bool}, id: str, relationships: map{oauth2_client: map{data: map}, scopes: map{data: [map]}, user: map{data: map}}, type: str}} # OK\n@errors {403: Authentication error, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/user_invitations\n@desc Send invitation emails\n@required {data: [map{relationships!: map, type!: str}] # List of user invitations.}\n@returns(201) {data: [map]} # OK\n@errors {400: Bad Request, 403: Authentication error, 429: Too many requests}\n@example_request {\"data\":[{\"relationships\":{\"user\":{\"data\":{\"id\":\"6cf192b6-d1d9-11ec-ad3d-da7ad0900002\",\"type\":\"users\"}}},\"type\":\"user_invitations\"}]}\n\n@endpoint GET /api/v2/user_invitations/{user_invitation_uuid}\n@desc Get a user invitation\n@required {user_invitation_uuid: str # The UUID of the user invitation.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), expires_at: str(date-time), invite_type: str, uuid: str}, id: str, relationships: map{user: map{data: map}}, type: str}} # OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint GET /api/v2/users\n@desc List all users\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return., sort: str=name # User attribute to order results by. Sort order is ascending by default. Sort order is descending if the field is prefixed by a negative sign, for example `sort=-name`. Options: `name`, `modified_at`, `user_count`., sort_dir: str # Direction of sort. Options: `asc`, `desc`., filter: str # Filter all users by the given string. Defaults to no filtering., filter[status]: str # Filter on status attribute. Comma separated list, with possible values `Active`, `Pending`, and `Disabled`. Defaults to no filtering.}\n@returns(200) {data: [map], included: [any], meta: map{page: map{total_count: int(int64), total_filtered_count: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Authentication error, 429: Too many requests}\n\n@endpoint POST /api/v2/users\n@desc Create a user\n@required {data: map{attributes!: map, relationships: map, type!: str} # Object to create a user.}\n@returns(201) {data: map{attributes: map{created_at: str(date-time), disabled: bool, email: str, handle: str, icon: str, last_login_time: str(date-time)?, mfa_enabled: bool, modified_at: str(date-time), name: str?, service_account: bool, status: str, title: str?, uuid: str, verified: bool}, id: str, relationships: map{org: map{data: map}, other_orgs: map{data: [map]}, other_users: map{data: [map]}, roles: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Authentication error, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"email\":\"jane.doe@example.com\"},\"relationships\":{\"roles\":{\"data\":[{\"id\":\"3653d3c6-0c75-11ea-ad28-fb5701eabc7d\"}]}},\"type\":\"users\"}}\n\n@endpoint DELETE /api/v2/users/{user_id}\n@desc Disable a user\n@required {user_id: str # The ID of the user.}\n@returns(204) OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint GET /api/v2/users/{user_id}\n@desc Get user details\n@required {user_id: str # The ID of the user.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), disabled: bool, email: str, handle: str, icon: str, last_login_time: str(date-time)?, mfa_enabled: bool, modified_at: str(date-time), name: str?, service_account: bool, status: str, title: str?, uuid: str, verified: bool}, id: str, relationships: map{org: map{data: map}, other_orgs: map{data: [map]}, other_users: map{data: [map]}, roles: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/users/{user_id}\n@desc Update a user\n@required {user_id: str # The ID of the user., data: map{attributes!: map, id!: str, type!: str} # Object to update a user.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), disabled: bool, email: str, handle: str, icon: str, last_login_time: str(date-time)?, mfa_enabled: bool, modified_at: str(date-time), name: str?, service_account: bool, status: str, title: str?, uuid: str, verified: bool}, id: str, relationships: map{org: map{data: map}, other_orgs: map{data: [map]}, other_users: map{data: [map]}, roles: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 422: Unprocessable Entity, 429: Too many requests}\n@example_request {\"data\":{\"id\":\"00000000-0000-feed-0000-000000000000\",\"type\":\"users\"}}\n\n@endpoint GET /api/v2/users/{user_id}/identity_providers\n@desc Get identity provider overrides for a user\n@required {user_id: str # The ID of the user.}\n@returns(200) {data: [map]} # OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint DELETE /api/v2/users/{user_id}/invitations\n@desc Delete a pending user's invitations\n@required {user_id: str(uuid) # The UUID of the user whose pending invitations should be canceled.}\n@returns(200) OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint GET /api/v2/users/{user_id}/orgs\n@desc Get a user organization\n@required {user_id: str # The ID of the user.}\n@returns(200) {data: map{attributes: map{created_at: str(date-time), disabled: bool, email: str, handle: str, icon: str, last_login_time: str(date-time)?, mfa_enabled: bool, modified_at: str(date-time), name: str?, service_account: bool, status: str, title: str?, uuid: str, verified: bool}, id: str, relationships: map{org: map{data: map}, other_orgs: map{data: [map]}, other_users: map{data: [map]}, roles: map{data: [map]}}, type: str}, included: [any]} # OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint GET /api/v2/users/{user_id}/permissions\n@desc Get a user permissions\n@required {user_id: str # The ID of the user.}\n@returns(200) {data: [map]} # OK\n@errors {403: Authentication error, 404: Not found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/users/{user_id}/relationships/identity_providers\n@desc Update identity provider overrides for a user\n@required {user_id: str # The ID of the user., data: [map{id!: str, type!: str}] # List of identity provider resource identifiers for a relationship update.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Authentication error, 404: Not found, 429: Too many requests}\n@example_request {\"data\":[{\"id\":\"00000000-0000-0000-0000-000000000001\",\"type\":\"identity_providers\"}]}\n\n@endpoint GET /api/v2/users/{user_uuid}/memberships\n@desc Get user memberships\n@required {user_uuid: str # None}\n@returns(200) {data: [map], included: [any], links: map{first: str, last: str?, next: str, prev: str?, self: str}, meta: map{pagination: map{first_offset: int(int64), last_offset: int(int64), limit: int(int64), next_offset: int(int64), offset: int(int64), prev_offset: int(int64), total: int(int64), type: str}}} # Represents a user's association to a team\n@errors {404: API error response., 429: Too many requests}\n\n@endpoint GET /api/v2/validate\n@desc Validate API key\n@returns(200) {data: map{attributes: map{api_key_id: str, api_key_scopes: [str], valid: bool}, id: str, type: str}} # OK\n@errors {403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/validate_keys\n@desc Validate API and application keys\n@returns(200) {status: str} # OK\n@errors {401: Unauthorized, 403: Forbidden, 429: Too many requests}\n\n@endpoint GET /api/v2/web-integrations/{integration_name}/accounts\n@desc List web integration accounts\n@required {integration_name: str # The name of the integration (for example, `databricks`).}\n@returns(200) {data: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint POST /api/v2/web-integrations/{integration_name}/accounts\n@desc Create a web integration account\n@required {integration_name: str # The name of the integration (for example, `databricks`)., data: map{attributes!: map, type!: str} # Data object for creating a web integration account.}\n@returns(201) {data: map{attributes: map{name: str, settings: map}, id: str, type: str}} # CREATED\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 422: The server cannot process the request because it contains invalid data., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"my-databricks-account\",\"secrets\":{\"client_secret\":\"my-client-secret\"},\"settings\":{\"workspace_url\":\"https://example.azuredatabricks.net\"}},\"type\":\"Account\"}}\n\n@endpoint DELETE /api/v2/web-integrations/{integration_name}/accounts/{account_id}\n@desc Delete a web integration account\n@required {integration_name: str # The name of the integration (for example, `databricks`)., account_id: str # The unique identifier of the web integration account.}\n@returns(204) OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/web-integrations/{integration_name}/accounts/{account_id}\n@desc Get a web integration account\n@required {integration_name: str # The name of the integration (for example, `databricks`)., account_id: str # The unique identifier of the web integration account.}\n@returns(200) {data: map{attributes: map{name: str, settings: map}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/web-integrations/{integration_name}/accounts/{account_id}\n@desc Update a web integration account\n@required {integration_name: str # The name of the integration (for example, `databricks`)., account_id: str # The unique identifier of the web integration account., data: map{attributes!: map, type!: str} # Data object for updating a web integration account.}\n@returns(200) {data: map{attributes: map{name: str, settings: map}, id: str, type: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 422: The server cannot process the request because it contains invalid data., 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"name\":\"my-databricks-account\",\"secrets\":{\"client_secret\":\"my-new-client-secret\"},\"settings\":{\"workspace_url\":\"https://updated.azuredatabricks.net\"}},\"type\":\"Account\"}}\n\n@endpoint GET /api/v2/widgets/{experience_type}\n@desc Search widgets\n@required {experience_type: str # The experience type for the widget.}\n@optional {filter[widgetType]: str: any # Filter widgets by widget type., filter[creatorHandle]: str # Filter widgets by the email handle of the creator., filter[isFavorited]: bool # Filter to only widgets favorited by the current user., filter[title]: str # Filter widgets by title (substring match)., filter[tags]: str # Filter widgets by tags. Format as bracket-delimited CSV, e.g. `[tag1,tag2]`., sort: str=-modified_at # Sort field for the results.  **`title`, `created_at`, `modified_at`** — both ascending and descending are supported. Use the bare field name for ascending (e.g. `sort=title`) or prefix with `-` for descending (e.g. `sort=-modified_at`).  **`is_favorited`** — returns favorites-first ordering (favorited widgets first, then the rest). Direction is fixed; the `-` prefix is ignored for this field., page[number]: int(int64)=0 # Page number for pagination (0-indexed)., page[size]: int(int64)=50 # Number of widgets per page.}\n@returns(200) {data: [map], included: [map], meta: map{created_by_anyone_total: int(int64), created_by_you_total: int(int64), favorited_by_you_total: int(int64), filtered_total: int(int64)}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/widgets/{experience_type}\n@desc Create a widget\n@required {experience_type: str # The experience type for the widget., data: map{attributes!: map, type!: str} # Data for creating or updating a widget.}\n@returns(200) {data: map{attributes: map{created_at: str, definition: map{title: str, type: str}, is_favorited: bool, modified_at: str, tags: [str]?}, id: str, relationships: map{created_by: map{data: map}, modified_by: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"definition\":{\"graph_options\":[{\"type\":\"query_value\",\"view\":\"total\"},{\"type\":\"query_value\",\"view\":\"change\"},{\"display_type\":\"bars\",\"type\":\"timeseries\"},{\"type\":\"cloud_cost_table\",\"view\":\"summary\"}],\"requests\":[{\"formulas\":[{\"formula\":\"query1\"}],\"queries\":[{\"data_source\":\"cloud_cost\",\"name\":\"query1\",\"query\":\"sum:aws.cost.amortized{*} by {aws_product}.rollup(sum, daily)\"}],\"response_format\":\"timeseries\"}],\"time\":{\"type\":\"live\",\"unit\":\"day\",\"value\":30},\"title\":\"AWS spend by service (last 30 days)\",\"type\":\"cloud_cost_summary\"},\"tags\":[\"finops\",\"aws\"]},\"type\":\"widgets\"}}\n\n@endpoint DELETE /api/v2/widgets/{experience_type}/{uuid}\n@desc Delete a widget\n@required {experience_type: str # The experience type for the widget., uuid: str(uuid) # The UUID of the widget.}\n@returns(204) No Content\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint GET /api/v2/widgets/{experience_type}/{uuid}\n@desc Get a widget\n@required {experience_type: str # The experience type for the widget., uuid: str(uuid) # The UUID of the widget.}\n@returns(200) {data: map{attributes: map{created_at: str, definition: map{title: str, type: str}, is_favorited: bool, modified_at: str, tags: [str]?}, id: str, relationships: map{created_by: map{data: map}, modified_by: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/widgets/{experience_type}/{uuid}\n@desc Update a widget\n@required {experience_type: str # The experience type for the widget., uuid: str(uuid) # The UUID of the widget., data: map{attributes!: map, type!: str} # Data for creating or updating a widget.}\n@returns(200) {data: map{attributes: map{created_at: str, definition: map{title: str, type: str}, is_favorited: bool, modified_at: str, tags: [str]?}, id: str, relationships: map{created_by: map{data: map}, modified_by: map{data: map}}, type: str}, included: [map]} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"definition\":{\"graph_options\":[{\"type\":\"query_value\",\"view\":\"total\"},{\"type\":\"query_value\",\"view\":\"change\"},{\"display_type\":\"bars\",\"type\":\"timeseries\"},{\"type\":\"cloud_cost_table\",\"view\":\"summary\"}],\"requests\":[{\"formulas\":[{\"formula\":\"query1\"}],\"queries\":[{\"data_source\":\"cloud_cost\",\"name\":\"query1\",\"query\":\"sum:aws.cost.amortized{*} by {aws_product}.rollup(sum, daily)\"}],\"response_format\":\"timeseries\"}],\"time\":{\"type\":\"live\",\"unit\":\"day\",\"value\":30},\"title\":\"AWS spend by service (last 30 days)\",\"type\":\"cloud_cost_summary\"},\"tags\":[\"finops\",\"aws\"]},\"type\":\"widgets\"}}\n\n@endpoint GET /api/v2/workflows\n@desc List workflows\n@optional {limit: int(int64)=50 # The maximum number of workflows to return per page., page: int(int64)=0 # The page number to return, starting from 0., sort: str # The sort order for the returned workflows. Provide a comma-separated list of fields, each optionally prefixed with `-` for descending order. Supported fields are `name`, `createdAt`, `updatedAt`, `creatorName`, `ownerName`, and `lastExecutedAt`., filter[query]: str # A search query used to filter the returned workflows. The query performs a case-insensitive substring match against each workflow's name, creator name, and handle. If the query contains a colon (for example, `team:infra`), the query is treated as a `key:value` tag filter., filter[triggerIds]: [str] # Filters the returned workflows by one or more trigger types, such as `monitor`, `schedule`, or `githubWebhook`. To specify the multiple types, repeat this parameter., filter[includeUnpublished]: bool=false # Whether to include unpublished workflows in the response., filter[includeSpecs]: bool=false # Whether to include the full spec of each workflow in the response. When `false` (the default), each workflow's `spec` is returned as `null`.}\n@returns(200) {data: [map], meta: map{page: map{totalCount: int(int64), totalFilteredCount: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/workflows\n@desc Create a Workflow\n@required {data: map{attributes!: map, id: str, relationships: map, type!: str} # Data related to the workflow.}\n@returns(201) {data: map{attributes: map{createdAt: str(date-time), description: str, name: str, published: bool, spec: map{annotations: [map], connectionEnvs: [map], handle: str, inputSchema: map, outputSchema: map, steps: [map], triggers: [any]}, tags: [str], updatedAt: str(date-time), webhookSecret: str}, id: str, relationships: map{creator: map{data: map}, owner: map{data: map}}, type: str}} # Successfully created a workflow.\n@errors {400: Bad request, 403: Forbidden, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"A sample workflow.\",\"name\":\"Example Workflow\",\"published\":true,\"spec\":{\"annotations\":[{\"display\":{\"bounds\":{\"height\":150,\"width\":300,\"x\":-375,\"y\":-0.5}},\"id\":\"99999999-9999-9999-9999-999999999999\",\"markdownTextAnnotation\":{\"text\":\"Example annotation.\"}}],\"connectionEnvs\":[{\"connections\":[{\"connectionId\":\"e1e64943-c7c5-4487-aece-25aaec7d3aad\",\"label\":\"INTEGRATION_DATADOG\"}],\"env\":\"default\"}],\"handle\":\"my-handle\",\"inputSchema\":{\"parameters\":[{\"defaultValue\":\"default\",\"name\":\"input\",\"type\":\"STRING\"}]},\"outputSchema\":{\"parameters\":[{\"name\":\"output\",\"type\":\"ARRAY_OBJECT\",\"value\":\"{{ Steps.Step1 }}\"}]},\"steps\":[{\"actionId\":\"com.datadoghq.dd.monitor.listMonitors\",\"connectionLabel\":\"INTEGRATION_DATADOG\",\"name\":\"Step1\",\"outboundEdges\":[{\"branchName\":\"main\",\"nextStepName\":\"Step2\"}],\"parameters\":[{\"name\":\"tags\",\"value\":\"service:monitoring\"}]},{\"actionId\":\"com.datadoghq.core.noop\",\"name\":\"Step2\"}],\"triggers\":[{\"monitorTrigger\":{\"rateLimit\":{\"count\":1,\"interval\":\"3600s\"}},\"startStepNames\":[\"Step1\"]},{\"githubWebhookTrigger\":{},\"startStepNames\":[\"Step1\"]}]},\"tags\":[\"team:infra\",\"service:monitoring\"]},\"type\":\"workflows\"}}\n\n@endpoint DELETE /api/v2/workflows/{workflow_id}\n@desc Delete an existing Workflow\n@required {workflow_id: str # The ID of the workflow.}\n@returns(204) Successfully deleted a workflow.\n@errors {403: Forbidden, 404: Not found, 429: Too many requests}\n\n@endpoint GET /api/v2/workflows/{workflow_id}\n@desc Get an existing Workflow\n@required {workflow_id: str # The ID of the workflow.}\n@returns(200) {data: map{attributes: map{createdAt: str(date-time), description: str, name: str, published: bool, spec: map{annotations: [map], connectionEnvs: [map], handle: str, inputSchema: map, outputSchema: map, steps: [map], triggers: [any]}, tags: [str], updatedAt: str(date-time), webhookSecret: str}, id: str, relationships: map{creator: map{data: map}, owner: map{data: map}}, type: str}} # Successfully got a workflow.\n@errors {400: Bad request, 403: Forbidden, 404: Not found, 429: Too many requests}\n\n@endpoint PATCH /api/v2/workflows/{workflow_id}\n@desc Update an existing Workflow\n@required {workflow_id: str # The ID of the workflow., data: map{attributes!: map, id: str, relationships: map, type!: str} # Data related to the workflow being updated.}\n@returns(200) {data: map{attributes: map{createdAt: str(date-time), description: str, name: str, published: bool, spec: map{annotations: [map], connectionEnvs: [map], handle: str, inputSchema: map, outputSchema: map, steps: [map], triggers: [any]}, tags: [str], updatedAt: str(date-time), webhookSecret: str}, id: str, relationships: map{creator: map{data: map}, owner: map{data: map}}, type: str}} # Successfully updated a workflow.\n@errors {400: Bad request, 403: Forbidden, 404: Not found, 429: Too many requests}\n@example_request {\"data\":{\"attributes\":{\"description\":\"A sample workflow.\",\"name\":\"Example Workflow\",\"published\":true,\"spec\":{\"annotations\":[{\"display\":{\"bounds\":{\"height\":150,\"width\":300,\"x\":-375,\"y\":-0.5}},\"id\":\"99999999-9999-9999-9999-999999999999\",\"markdownTextAnnotation\":{\"text\":\"Example annotation.\"}}],\"connectionEnvs\":[{\"connections\":[{\"connectionId\":\"e1e64943-c7c5-4487-aece-25aaec7d3aad\",\"label\":\"INTEGRATION_DATADOG\"}],\"env\":\"default\"}],\"handle\":\"my-handle\",\"inputSchema\":{\"parameters\":[{\"defaultValue\":\"default\",\"name\":\"input\",\"type\":\"STRING\"}]},\"outputSchema\":{\"parameters\":[{\"name\":\"output\",\"type\":\"ARRAY_OBJECT\",\"value\":\"{{ Steps.Step1 }}\"}]},\"steps\":[{\"actionId\":\"com.datadoghq.dd.monitor.listMonitors\",\"connectionLabel\":\"INTEGRATION_DATADOG\",\"name\":\"Step1\",\"outboundEdges\":[{\"branchName\":\"main\",\"nextStepName\":\"Step2\"}],\"parameters\":[{\"name\":\"tags\",\"value\":\"service:monitoring\"}]},{\"actionId\":\"com.datadoghq.core.noop\",\"name\":\"Step2\"}],\"triggers\":[{\"monitorTrigger\":{\"rateLimit\":{\"count\":1,\"interval\":\"3600s\"}},\"startStepNames\":[\"Step1\"]},{\"githubWebhookTrigger\":{},\"startStepNames\":[\"Step1\"]}]},\"tags\":[\"team:infra\",\"service:monitoring\"]},\"id\":\"22222222-2222-2222-2222-222222222222\",\"type\":\"workflows\"}}\n\n@endpoint GET /api/v2/workflows/{workflow_id}/instances\n@desc List workflow instances\n@required {workflow_id: str # The ID of the workflow.}\n@optional {page[size]: int(int64)=10: any # Size for a given page. The maximum allowed value is 100., page[number]: int(int64)=0 # Specific page number to return.}\n@returns(200) {data: [map], meta: map{page: map{totalCount: int(int64)}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n\n@endpoint POST /api/v2/workflows/{workflow_id}/instances\n@desc Execute a workflow\n@required {workflow_id: str # The ID of the workflow.}\n@optional {meta: map{payload: map} # Additional information for creating a workflow instance.}\n@returns(200) {data: map{id: str}} # Created\n@errors {400: Bad Request, 403: Forbidden, 429: Too many requests}\n@example_request {\"meta\":{\"payload\":{\"input\":\"value\"}}}\n\n@endpoint GET /api/v2/workflows/{workflow_id}/instances/{instance_id}\n@desc Get a workflow instance\n@required {workflow_id: str # The ID of the workflow., instance_id: str # The ID of the workflow instance.}\n@returns(200) {data: map{attributes: map{id: str}}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@endpoint PUT /api/v2/workflows/{workflow_id}/instances/{instance_id}/cancel\n@desc Cancel a workflow instance\n@required {workflow_id: str # The ID of the workflow., instance_id: str # The ID of the workflow instance.}\n@returns(200) {data: map{id: str}} # OK\n@errors {400: Bad Request, 403: Forbidden, 404: Not Found, 429: Too many requests}\n\n@end\n"}}