Every API here is available over the APIs.io API and to AI agents over MCP.
openapi: 3.2.0
info:
title: AppOmni Monitored Services API
description: 'Registration and administration of monitored SaaS services, their custom fields, custom field values, tags and value lists.
Derived faithfully from the AppOmni public Postman collection published by AppOmni at https://api.appomni.com/ — every path, method, parameter, request body and example response below is taken verbatim from that collection. No operation was invented.'
version: 1.0.0
contact:
name: AppOmni
url: https://appomni.com/support/
license:
name: Proprietary
url: https://appomni.com/terms-of-service/
x-generated-from: AppOmni public Postman collection (publishedId 2sBXc7Mjib, published 2026-02-04)
x-generated-source: https://api.appomni.com/api/collections/45135595/2sBXc7Mjib?segregateAuth=true&versionTag=latest
x-generated-method: derived
x-generated-date: '2026-09-04'
servers:
- url: https://{instance}.appomni.com
description: AppOmni tenant. Replace {instance} with your AppOmni subdomain — e.g. `acme` if you log in at acme.appomni.com.
variables:
instance:
default: example
description: Your AppOmni tenant subdomain
security:
- bearerAuth: []
tags:
- name: Monitored Services
paths:
/api/v1/core/monitoredservice/:
get:
operationId: listMonitoredServices
summary: List monitored services
tags:
- Monitored Services
description: 'Returns a paginated list of all Monitored Services configured in your environment.
Each entry includes core metadata such as name, service type, score, status flags, and connection state. Supports filtering and annotations via query parameters.
Response Fields
Field
Data Type
Description
Example
id
Integer
Unique identifier for the monitored service. This is an AppOmni internal ID
5
created
String (ISO datetime)
Timestamp when the service was created
2022-11-29T05:56:26.372253Z
created_by
Integer
ID of the user who created the service
23
modified
String (ISO datetime)
Timestamp of the last modification
2022-11-29T05:56:26.372253Z
modified_by
Integer
ID of the user that last modified the entry
32
owner
Integer
ID of the user or team that owns the service
23
name
String
Display name of the monitored service
''MS Name''
external_id
String
Identifier from the external system
''1234-5683''
service_id
String
Unique identifier of the connected service instance. This is the ID set by the connected service provider.
''1234''
service_type
String
Type of service (e.g., box, github)
''box''
service_type_slug
String
Slug version of the service type
''box''
description
String
Optional human-readable description
enforcement_mode
String
Policy enforcement mode (monitor, enforce, etc.)
''monitor''
integration_connected
Boolean
Indicates if the service is currently connected
false
monitoring_reqs_satisfied
Boolean
Whether monitoring requirements are met
true
has_warnings
Boolean
True if the service has warnings
false
has_errors
Boolean
True if the service has errors
false
initial_ingest_complete
Boolean
True if initial data ingestion is complete
true
is_archived
Boolean
True if the service has been archived
false
tags
Array[Integer]
List of tag IDs assigned to the service
[34, 55, 66]
baseline_policies
Array[Integer]
IDs of applied baseline policies
[1]
detection_ingest_enabled
Boolean
True if detection ingest is enabled
true
score
Integer
Security score for the service (typically 0–100)
100
Annotations schema
When the query parameter annotations=1 is included in the request, each Monitored Service object in the results array includes the following read-only, computed fields :
Field
Type
Description
Example
open_issues_count
Integer
Number of unresolved issues associated with this service
1
last_run_insights
String (ISO datetime)
Timestamp of the last insights scan or analysis run
2022-11-29T05:56:26.372253Z
num_perspective_errors
Integer
Number of errors found across perspectives
33
any_perspective_errors
Boolean
Whether any perspective errors exist
false
service_installed_app_needs_update
Boolean
True if an installed app related to the service needs updating
false
total_users_count
Integer
Total number of users in the monitored service
123
inactive_user_count
Integer
Number of users marked as inactive
222
elevated_perm_user_count
Integer
Number of users with elevated permissions
32
admin_perm_user_count
Integer
Number of users with administrative permissions
432'
responses:
'200':
description: List Monitored Services
content:
text/plain:
schema:
type: string
example: "{\n \"count\": 6,\n \"next\": null,\n \"previous\": null,\n \"results\": [\n {\n \"id\": 1,\n \"created\": \"2025-03-10T20:10:45.013060Z\",\n \"created_by\": 1,\n \"modified\": \"2025-04-08T15:41:32.406310Z\",\n \"modified_by\": null,\n \"owner\": 1,\n \"name\": \"Box DE\",\n \"external_id\": null,\n \"service_id\": \"285415710\",\n \"service_type\": \"box\",\n \"service_type_slug\": \"box\",\n \"description\": null,\n \"enforcement_mode\": \"monitor\",\n \"integration_connected\": true,\n \"monitoring_reqs_satisfied\": true,\n \"has_warnings\": false,\n \"has_errors\": false,\n \"initial_ingest_complete\": true,\n \"is_archived\": false,\n \"tags\": [1],\n \"baseline_policies\": [],\n \"detection_ingest_enabled\": true,\n \"score\": 100\n },\n ...,\n ]\n}"
'401':
description: Unauthorized — missing or invalid AppOmni API token
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Forbidden — the token lacks permission for this resource
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/api/v1/core/monitoredservice/{serviceType}/{serviceType}org/{id}:
get:
operationId: monitoredServiceDetail
summary: Monitored service detail
tags:
- Monitored Services
description: 'Returns detailed metadata, sync status, user stats, preferences, and policy posture for a single monitored service instance by service type and org ID.
If using developer platform modules, run the following call instead: GET api/v1/core/custom/custommonitoredservice/{id}
Response Fields
Field
Type
Description
Example
id
Integer
Unique identifier for the monitored service
1
created
String (ISO datetime)
Timestamp of creation
2022-11-29T05:56:26.372253Z
modified
String (ISO datetime)
Timestamp of last modification
2022-11-29T05:56:26.372253Z
external_id
String
External service identifier
''12345''
created_by
Integer
ID of the creator
2022-11-29T05:56:26.372253Z
modified_by
Integer
ID of last modifier
2022-11-29T05:56:26.372253Z
owner
Integer
ID of the owning user/team
33
monitored_service_type
String
Type of the monitored service (e.g., box)
''box''
service_type_slug
String
Slugified type (same as above)
''box''
name
String
Display name
''MS Name''
authoritative_name
String
Authoritative identifier (if configured)
''123456''
description
String
Optional human-readable description
''description''
service_id
String
Unique identifier for the service instance
''5678''
initial_ingest_complete
Boolean
Whether the initial ingest completed
true
integration_connected
Boolean
Whether integration is connected
true
integration_failed_at
String (ISO datetime)
Timestamp of last failed integration (if any)
2022-11-29T05:56:26.372253Z
has_warnings
Boolean
Indicates if warnings exist
true
has_errors
Boolean
Indicates if errors exist
false
integration_installed_version
String
Installed version of the integration
''1234''
notify_ms_owner
Boolean
Whether to notify the monitored service owner
false
notify_user
Integer
ID of an additional user to notify
45
extra_notification_emails
Array[String]
Extra email addresses to notify
['' 123@email.com '']
allow_deploy_remediation
Boolean
Whether remediation actions can be deployed
false
enforcement_mode
String
Mode of policy enforcement
''monitor''
last_service_data_sync
String (ISO datetime)
Last successful service data sync
2022-11-29T05:56:26.372253Z
last_user_sync
String
Last user sync time
2022-11-29T05:56:26.372253Z
last_login_sync
String
Last login data sync time
2022-11-29T05:56:26.372253Z
String
Last security data sync time
2022-11-29T05:56:26.372253Z
String
Last apps data sync time
2022-11-29T05:56:26.372253Z
last_detection_collection
String
Last detection data collection time
2022-11-29T05:56:26.372253Z
total_internal_user_count
Integer
Count of internal users
54
internal_active_user_count
Integer
Active internal users
65
total_external_user_count
Integer
External users count
22
external_active_user_count
Integer
Active external users
43
inactive_user_count
Integer
Total inactive users
43
internal_inactive_user_count
Integer
Inactive internal users
54
external_inactive_user_count
Integer
Inactive external users
123
elevated_perm_user_count
Integer
Users with elevated permissions
424
internal_elevated_perm_user_count
Integer
Internal users with elevated permissions
243
external_elevated_perm_user_count
Integer
External users with elevated permissions
234
admin_perm_user_count
Integer
Admin users total
2343
internal_admin_perm_user_count
Integer
Internal admin users
12
external_admin_perm_user_count
Integer
External admin users
32
tags
Array[Integer]
Associated tag IDs
[1324]
classification_configurations
Array
Custom classification settings (if any)
[]
num_internal_users_covered
Integer
Covered internal users
43
num_external_users_covered
Integer
Covered external users
54
internal_user_covera'
parameters:
- name: serviceType
in: path
required: true
description: Path parameter serviceType
schema:
type: string
- name: id
in: path
required: true
description: Path parameter id
schema:
type: string
responses:
'200':
description: Monitored Service Detail
content:
application/json:
schema:
type: object
examples:
MonitoredServiceDetail:
summary: Monitored Service Detail
value:
id: 1
created: '2025-03-10T20:10:45.013060Z'
modified: '2025-04-08T15:41:32.406310Z'
external_id: null
created_by: 1
modified_by: null
owner: 1
monitored_service_type: box
service_type_slug: box
name: Box DE
authoritative_name: null
description: null
service_id: '285415710'
initial_ingest_complete: true
integration_connected: true
integration_failed_at: null
has_warnings: false
has_errors: false
integration_installed_version: null
notify_ms_owner: true
notify_user: null
extra_notification_emails: []
allow_deploy_remediation: false
enforcement_mode: monitor
last_service_data_sync: '2025-04-08T15:41:32.401611Z'
last_user_sync: null
last_login_sync: null
last_security_data_sync: null
last_apps_data_sync: null
last_detection_collection: null
total_internal_user_count: 20
internal_active_user_count: 20
total_external_user_count: 0
external_active_user_count: 0
inactive_user_count: null
internal_inactive_user_count: null
external_inactive_user_count: null
elevated_perm_user_count: null
internal_elevated_perm_user_count: null
external_elevated_perm_user_count: null
admin_perm_user_count: null
internal_admin_perm_user_count: null
external_admin_perm_user_count: null
tags:
- 1
classification_configurations: []
num_internal_users_covered: 0
num_external_users_covered: 0
internal_user_coverage: 0.0
external_user_coverage: 0.0
num_internal_users_represented: 0
num_external_users_represented: 0
service_installed_app_needs_update: false
service_statistics:
md_kind: fsb.ms.service_statics
file_count: 40
md_version: 2
site_count: 0
folder_count: 69
user_count_external: 0
user_count_internal: 20
user_msgs:
md_kind: core.monitoredservice.user_msgs
md_version: 1
msgs: []
open_issues_count: 0
monitoring_reqs_satisfied: true
is_archived: false
archived_at: null
prefs:
md_version: 1
md_kind: core.shared.prefs.ms_container
preference_groups:
modules:
group_label: Module Settings
group_description: Configure which modules are enabled
preferences:
- name: dam
label: Exposure - enabled
value_type: bool
show_in_ui: false
value: true
default_value: true
description: Data Exposure will be monitored
md_version: 1
md_kind: core.shared.prefs.entry
md_version: 1
md_kind: core.shared.prefs.group
flat_dict:
modules.dam: true
baseline_policies: []
degraded_feature_keys: []
detection_ingest_enabled: true
score: 100
score_last_calculated: '2025-04-09T18:07:02.533226Z'
admin_perspective: 9
preferences:
batch_perspectives: true
active_perspective_count: 1
perspective_count: 5
'401':
description: Unauthorized — missing or invalid AppOmni API token
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Forbidden — the token lacks permission for this resource
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/api/v1/{serviceType}/{serviceType}org/{id}/sync_timestamps/:
get:
operationId: dataSyncs
summary: Data syncs
tags:
- Monitored Services
description: 'Provides users with information pertaining to the status of syncing various data types to AppOmni from their SaaS application.
For example, if a sync hadn''t started or finished for a few days, AppOmni would be operating on data from whenever the last data sync completed successfully, and could be missing important configuration changes or repo additions that occurred during that interim period.
For developer platform modules, run:
GET api/v1/custom/custommonitoredservice/{id}/sync_timestamps/
Response Fields
Field
Type
Description
Example
timestamp_field
String
Internal field name for the last sync timestamp (used for lookups and logic)
''timestamp''
label
String
i18n key or label describing the sync category
''label''
allow_adhoc_refresh
Boolean
Whether ad-hoc manual sync is allowed for this type
true
description
String
i18n key or full description of the sync category
''description''
rate_limited
Boolean
Whether triggering this sync is rate-limited
true
rate_limit_category
String
Indicates how heavily the sync is rate-limited (e.g., light, medium, heavy)
''light''
last_sync_timestamp
String (ISO datetime)
Time the last sync finished (or was recorded as completed)
2022-11-29T05:56:26.372253Z
required_syncs
Array[String]
List of dependent sync steps that must be completed first
[]
status
String
Current sync status (pending, failed, complete, etc.)
''complete''
last_sync_start_time
String (ISO datetime)
Time the sync last began (useful for tracking duration)
2022-11-29T05:56:26.372253Z
long_sync_detected
Boolean
True if the system has flagged the sync as taking unusually long
false
messages
String
Optional additional info or warning messages
""'
parameters:
- name: serviceType
in: path
required: true
description: Path parameter serviceType
schema:
type: string
- name: id
in: path
required: true
description: Path parameter id
schema:
type: string
responses:
'200':
description: Data Syncs
content:
text/plain:
schema:
type: string
example: "[\n {\n \"timestamp_field\": \"last_org_sync\",\n \"label\": \"common.monitored_service.data_timestamps.last_security_data_sync.label\",\n \"allow_adhoc_refresh\": true,\n \"description\": \"common.monitored_service.data_timestamps.last_security_data_sync.description\",\n \"rate_limited\": false,\n \"rate_limit_category\": \"light\",\n \"last_sync_timestamp\": \"2025-04-08T23:50:20.161334+00:00\",\n \"required_syncs\": [\n \"org_settings_sync\"\n ],\n \"status\": \"complete\",\n \"last_sync_start_time\": \"2025-04-08T23:50:15.463009+00:00\",\n \"long_sync_detected\": false,\n \"messages\": null\n },\n ...,\n]"
'401':
description: Unauthorized — missing or invalid AppOmni API token
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Forbidden — the token lacks permission for this resource
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/api/v1/{serviceType}/{serviceType}org/{id}/request_adhoc_sync/:
post:
operationId: requestSyncDataType
summary: Request sync data type
tags:
- Monitored Services
description: 'Request an on-demand resync of the provided data type.
Affected by rate_limits and availability. Data syncs are enqueued. Only syncs with ‘allow_adhoc_refresh: true’ and ‘rate_limited: false’ will be requested.
For the payload, specify the timestamp_field to resync.
For developer platform module types, run:
POST - api/v1/{serviceType}/{serviceType}org/{id}/request_adhoc_sync/.
Response Fields
Field
Data Type
Required
Description
Example
sync_type
String
Yes
Timestamp field to resync (use value from Data syncs)
last_security_data_sync'
parameters:
- name: serviceType
in: path
required: true
description: Path parameter serviceType
schema:
type: string
- name: id
in: path
required: true
description: Path parameter id
schema:
type: string
requestBody:
required: true
content:
application/json:
schema:
type: object
example: '{ sync_type: "last_security_data_sync"}'
responses:
'200':
description: Successful response
'401':
description: Unauthorized — missing or invalid AppOmni API token
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Forbidden — the token lacks permission for this resource
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/api/v1/{serviceType}/{serviceType}org/{id}/request_adhoc_all_sync/:
post:
operationId: requestSyncAllDataTypes
summary: Request sync all data types
tags:
- Monitored Services
description: 'Request on-demand resyncs of all data types meeting the required criteria.
No payload is necessary.
Utilizes the same schema as Request Sync Data Type.
For developer platform module types, run:
POST - api/v1/custom/custommonitoredservice/{id}/request_adhoc_all_sync/'
parameters:
- name: serviceType
in: path
required: true
description: Path parameter serviceType
schema:
type: string
- name: id
in: path
required: true
description: Path parameter id
schema:
type: string
responses:
'200':
description: Successful response
'401':
description: Unauthorized — missing or invalid AppOmni API token
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Forbidden — the token lacks permission for this resource
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/api/v1/core/monitoredservice/{ms_id}/rotate_ingest_token/:
patch:
operationId: rotateIngestToken
summary: Rotate ingest token
tags:
- Monitored Services
description: 'Each sync event for a monitored service is a job that requires authentication to push data to AppOmni. An ingest token is the authentication that makes the sync secure. You might require the ingest token to make direct API calls when you''re using the AppOmni Developer Platform. Rotating a token immediately replaces the ingest token with a new value. Any existing integrations using the old/previous ingest token cease to work.
Only users with Admin or Service Onboarder roles are able to use this endpoint. Users without permission will return a 403.
Run the "List Monitored Services" endpoint to obtain the ms_id variable.
There is no payload required for this endpoint.
Response Fields
Field
Data Type
Description
Example
token
String (UUID)
New ingest token value
a5633c0d-a9dd-46c5-903d-5007dc6d6e42
rotate_time
String (ISO datetime)
Time the token was rotated
2024-07-17T18:41:02.452800+00:00
url
String
Ingest API endpoint URL
https://your-domain.appomni.com/platform/ingest/v2/ingest/'
parameters:
- name: ms_id
in: path
required: true
description: Path parameter ms_id
schema:
type: string
responses:
'200':
description: Rotate Ingest Token
content:
application/json:
schema:
type: object
examples:
RotateIngestToken:
summary: Rotate Ingest Token
value:
token: a5633c0d-a9dd-46c5-903d-5007dc6d6e42
rotate_time: '2024-07-17T18:41:02.452800+00:00'
url: https://[your-domain].appomni.com/platform/ingest/v2/ingest/
'401':
description: Unauthorized — missing or invalid AppOmni API token
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Forbidden — the token lacks permission for this resource
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/api/v1/core/monitoredservice/{ms_id}/get_ingest_token/:
get:
operationId: getIngestToken
summary: Get ingest token
tags:
- Monitored Services
description: 'Each sync event for a monitored service is a job that requires authentication to push data to AppOmni. An ingest token is the authentication that makes the sync secure. You might require the ingest token to make direct API calls when you''re using the AppOmni Developer Platform.
Only users with Admin or Service Onboarder roles are able to use this endpoint. Users without permission will return a 403.
Run the "List Monitored Services" endpoint to obtain the ms_id variable.
Response Fields
Field
Data Type
Description
Example
token
String (UUID)
Current ingest token value
3ea1ae3e-792f-4682-ae01-c07e6c63ea39
rotate_time
String (ISO datetime) or null
Time the token was rotated (if ever)
null
url
String
Ingest API endpoint URL
https://your-domain.appomni.com/platform/ingest/v2/ingest/'
parameters:
- name: ms_id
in: path
required: true
description: Path parameter ms_id
schema:
type: string
responses:
'200':
description: Get Ingest Token
content:
application/json:
schema:
type: object
examples:
GetIngestToken:
summary: Get Ingest Token
value:
token: 3ea1ae3e-792f-4682-ae01-c07e6c63ea39
rotate_time: null
url: https://[your-domain].appomni.com/platform/ingest/v2/ingest/
'401':
description: Unauthorized — missing or invalid AppOmni API token
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Forbidden — the token lacks permission for this resource
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
components:
schemas:
Error:
type: object
title: Error
description: Standard Django REST Framework error envelope returned by the AppOmni API.
properties:
detail:
type: string
description: Human readable error message
securitySchemes:
bearerAuth:
type: http
scheme: bearer
description: 'AppOmni API access token, created and managed in the AppOmni platform under Settings > API Settings. Sent as `Authorization: Bearer <token>`.'