Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
openapi: 3.2.0
info:
title: Abnormal Security Client Users API
version: 1.4.3
description: This is the specification for Abnormal Security Client API which can be used for managing security threats detected by Abnormal Security.
termsOfService: https://legal.abnormalsecurity.com/legal-hub/abnormal-security-api-terms-of-service-6feee5e3
contact:
name: Abnormal Security Support
email: support@abnormalsecurity.com
servers:
- url: https://api.abnormalplatform.com/v1
description: Production Server for managing threats
- url: https://eu.rest.abnormalsecurity.com/v1
description: EU Production Server for managing threats.
security:
- BearerAuth: []
tags:
- name: Users
description: API to retrieve users from RBAC system
paths:
/users:
get:
operationId: v1_users_retrieve
description: Retrieves users for an account from the RBAC user management system.
summary: Get a list of users from RBAC user management system
parameters:
- in: header
name: mock-data
schema:
type: string
default: 'False'
enum:
- 'False'
- 'True'
description: Returns test data if set to `True`
tags:
- Users
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/UserListResponse'
description: A list of users with their roles and resource permissions.
'401':
$ref: '#/components/responses/UnauthorizedError'
'403':
description: Forbidden - Insufficient permissions
'404':
$ref: '#/components/responses/NotFoundError'
'429':
$ref: '#/components/responses/TooManyRequestsError'
components:
responses:
TooManyRequestsError:
description: Request count exceeds allowed number of concurrent requests for this resource type
UnauthorizedError:
description: Access token is missing or invalid
NotFoundError:
description: Invalid user input when using the filter query parameter. Will return various error messages
schemas:
PolicySwagger:
type: object
description: Swagger serializer for policy object within a role.
properties:
resource:
type: string
description: The resource name (e.g., 'threats', 'cases')
permissions:
type: array
items:
type: string
description: List of permissions granted on this resource
required:
- permissions
- resource
UserListResponse:
type: object
description: Swagger serializer for user list response.
properties:
status:
type: string
default: success
description: Status of the response
status_code:
type: integer
default: 200
description: HTTP status code
data:
type: array
items:
$ref: '#/components/schemas/UserSwagger'
description: List of users from RBAC system with their roles and resource permissions
required:
- data
UserSwagger:
type: object
description: Swagger serializer for user object.
properties:
user_id:
type: integer
description: The unique identifier for the user
email:
type: string
format: email
description: Email address of the user
groups:
type: array
items:
type: string
default: []
description: List of group IDs the user belongs to
local_login_enabled:
type: boolean
default: false
description: Whether local login is enabled for the user
sso_enabled:
type: boolean
default: true
description: Whether SSO is enabled for the user
role:
allOf:
- $ref: '#/components/schemas/RoleSwagger'
description: Role assigned to the user with associated permissions
resource_permissions:
type: array
items:
$ref: '#/components/schemas/ResourcePermissionSwagger'
description: List of resource permissions granted to the user through their role (only includes enabled permissions)
required:
- email
- user_id
ResourcePermissionSwagger:
type: object
description: Swagger serializer for resource permissions.
properties:
resource:
type: string
description: Name of the resource (e.g., 'ato', 'threat_log')
permissions:
type: array
items:
type: string
description: List of permissions for this resource (e.g., 'view', 'write', 'manage')
required:
- permissions
- resource
RoleSwagger:
type: object
description: Swagger serializer for role object.
properties:
id:
type: integer
description: The unique identifier for the role
name:
type: string
description: Name of the role
description:
type: string
default: ''
description: Description of the role
policies:
type: array
items:
$ref: '#/components/schemas/PolicySwagger'
description: Simplified view of permissions granted by this role
required:
- id
- name
- policies
securitySchemes:
BearerAuth:
type: http
scheme: bearer