Cisco Umbrella Utility API

The Utility API from Cisco Umbrella — 9 operation(s) for utility.

Operations 10

GET /applications Get Applications #
GET /categories Get Categories #
GET /identities Get Identities #
POST /identities Get Identities By IDs #
GET /identities/{identityid} Get Identity #
GET /threat-types Get Threat Types #
GET /threat-types/{threattypeid} Get Threat Type By Threat ID #
GET /threat-names Get Threat Names #
GET /threat-names/{threatnameid} Get Threat Name By Threat ID #
GET /providers/categories Get Provider Categories #

Documentation

📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-admin-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-admin-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-managed-providers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-managed-providers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-providers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-providers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-s3-key-rotation-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-s3-key-rotation-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-users-roles-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-users-roles-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-authentication/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-authentication/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/cloudlock-api-getting-started/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/cloudlock-api-getting-started/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-domains-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-domains-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-networks-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-networks-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-devices-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-devices-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-tunnels-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-tunnels-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-networks-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-networks-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-deployment-policies-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-deployment-policies-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-roaming-computers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-roaming-computers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-sites-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-sites-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-swg-devices-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-swg-devices-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-tagging-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-tagging-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-virtual-appliances-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-virtual-appliances-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-investigate-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-investigate-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-application-lists-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-application-lists-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-destination-lists-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-destination-lists-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-api-usage-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-api-usage-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-app-discovery-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-app-discovery-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reports-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reports-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reporting-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reporting-overview/

Specifications

Other Resources

🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/key-admin.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/managed-providers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/providers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/s3-key-rotation.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/service-providers-console.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/users-roles.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/auth/token.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/cloudlock/cloudlock.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/internal-domains.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/internal-networks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/network-devices.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/network-tunnels.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/networks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/policies.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/roaming-computers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/sites.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/swg-devices.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/tagging.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/virtual-appliances.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/investigate/investigate.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/policies/application-lists-internet-umb.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/policies/destination-lists.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/api-usage.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/app-discovery.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/provider-consoles.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/reporting.yaml

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cisco-umbrella-utility-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cisco-umbrella-utility-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cisco Umbrella Reporting Utility API
  description: The Reporting API provides the data to generate the Umbrella reports.
  version: 2.0.0
  contact:
    name: Cloud Security Developer Community
  x-provenance:
    method: harvested
    authored_by: Cisco Umbrella
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: pubhub.devnetcloud.com
    note: 26 first-party OpenAPI 3.0 documents (256 operations) listed by Cisco's own docs-nav config and fetched anonymously. Byte-identity reconfirmed 2026-08-19 by SHA-256 against the live source.
  x-evidence:
  - type: source
    url: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/umbrella-config.json
  - type: source
    url: https://developer.cisco.com/docs/cloud-security/
servers:
- url: https://api.umbrella.com/{basePath}
  variables:
    basePath:
      default: reports/v2
security:
- oauthFlow: []
tags:
- name: Utility
paths:
  /applications:
    get:
      tags:
      - Utility
      summary: Get Applications
      operationId: getApplications
      description: 'List the applications.


        **Access Scope:** Reports > Utilities > Read-Only'
      security:
      - oauthFlow:
        - reports.utilities:read
      parameters:
      - $ref: '#/components/parameters/applicationNameParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/ApplicationsWithCategories'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                  applications:
                  - id: 1
                    label: Web Hosting
                    type: AVC
                    category:
                      id: 40
                      label: Hosting Services
                  categories:
                  - id: 42
                    name: Education
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /categories:
    get:
      tags:
      - Utility
      summary: Get Categories
      description: 'List the categories.


        **Access Scope:** Reports > Utilities > Read-Only'
      operationId: getCategories
      security:
      - oauthFlow:
        - reports.utilities:read
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/CategoryWithLegacyId'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - id: 66
                  legacyid: 94
                  label: Malware
                  type: security
                  integration: true
                  deprecated: true
                - id: 110
                  legacyid: 176
                  label: DNS Tunneling VPN
                  type: security
                  integration: true
                  deprecated: false
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /identities:
    get:
      tags:
      - Utility
      summary: Get Identities
      operationId: getIdentities
      description: 'List the identities.


        **Access Scope:** Reports > Utilities > Read-Only'
      security:
      - oauthFlow:
        - reports.utilities:read
      parameters:
      - $ref: '#/components/parameters/limitParamIdentitiesUtility'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/searchParam'
      - $ref: '#/components/parameters/identityTypesParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/Identity'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - id: 1
                  label: Catch Rate Testing System
                  type:
                    id: 21
                    label: Sites
                    type: site
                  deleted: false
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
    post:
      tags:
      - Utility
      summary: Get Identities By IDs
      description: 'Get the identities information by providing a list of identity IDs in the request body.


        **Access Scope:** Reports > Utilities > Read-Only'
      operationId: postIdentities
      security:
      - oauthFlow:
        - reports.utilities:read
      parameters:
      - $ref: '#/components/parameters/limitParam'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              description: Provide an array of identity ID.
              properties:
                identityids:
                  description: A list of identity ID.
                  type: array
                  items:
                    type: integer
                    description: An identity ID.
                    example: 234567891
            example:
              identityids:
              - 234567891
              - 234567892
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/Identity'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - id: 1
                  label: Catch Rate Testing System
                  type:
                    id: 21
                    label: Sites
                    type: site
                  deleted: false
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /identities/{identityid}:
    get:
      tags:
      - Utility
      summary: Get Identity
      description: 'Get identity by identity ID.


        **Access Scope:** Reports > Utilities > Read-Only'
      operationId: getIdentity
      security:
      - oauthFlow:
        - reports.utilities:read
      parameters:
      - $ref: '#/components/parameters/identityIdParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/Identity'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                  id: 1
                  label: Catch Rate Testing System
                  type:
                    id: 21
                    label: Sites
                    type: site
                  deleted: true
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /threat-types:
    get:
      tags:
      - Utility
      summary: Get Threat Types
      description: 'List the threat types.


        **Access Scope:** Reports > Utilities > Read-Only'
      operationId: getThreatTypes
      security:
      - oauthFlow:
        - reports.utilities:read
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/ThreatType'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - name: Ransomware
                  description: a description
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /threat-types/{threattypeid}:
    get:
      tags:
      - Utility
      summary: Get Threat Type By Threat ID
      description: 'List the threat types by threat ID.


        **Access Scope:** Reports > Utilities > Read-Only'
      operationId: getThreatType
      security:
      - oauthFlow:
        - reports.utilities:read
      parameters:
      - $ref: '#/components/parameters/threatTypeIdParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/ThreatType'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                  name: Ransomware
                  description: a description
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /threat-names:
    get:
      tags:
      - Utility
      summary: Get Threat Names
      description: 'List the threat names.


        **Access Scope:** Reports > Utilities > Read-Only'
      operationId: getThreatNames
      security:
      - oauthFlow:
        - reports.utilities:read
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/ThreatName'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - name: WannaCry
                  description: a description
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /threat-names/{threatnameid}:
    get:
      tags:
      - Utility
      summary: Get Threat Name By Threat ID
      description: 'Get the threat name by threat ID.


        **Access Scope:** Reports > Utilities > Read-Only'
      operationId: getThreatName
      security:
      - oauthFlow:
        - reports.utilities:read
      parameters:
      - $ref: '#/components/parameters/threatNameIdParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/ThreatName'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                  name: WannaCry
                  description: WannaCry threat description
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /providers/categories:
    get:
      tags:
      - Utility
      summary: Get Provider Categories
      description: 'List the Provider categories


        **Access Scope:** Reports > Customer > Read-Only'
      operationId: getProviderCategories
      security:
      - oauthFlow:
        - reports.utilities:read
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/CategoryWithLegacyId'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - id: 66
                  legacyid: 94
                  label: Malware
                  type: security
                  integration: true
                  deprecated: false
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
components:
  parameters:
    threatTypeIdParam:
      name: threattypeid
      in: path
      description: The name of the threat type.
      required: true
      schema:
        type: string
      example: Ransomware
    threatNameIdParam:
      name: threatnameid
      in: path
      description: The name of the threat.
      required: true
      schema:
        type: string
      example: WannaCry
    offsetParam:
      name: offset
      in: query
      description: A number that represents an index in the collection.
      schema:
        type: number
        default: 0
      example: 0
    identityIdParam:
      name: identityid
      in: path
      description: An identity ID.
      required: true
      schema:
        type: number
      example: 42
    searchParam:
      name: search
      in: query
      description: 'A string that represents a search parameter.

        Filter data for requests where the search string appears in the endpoint data.'
      schema:
        type: string
      example: somelabel
    limitParam:
      name: limit
      in: query
      description: The maximum number of records to return from the collection.
      required: true
      schema:
        type: number
        default: 100
      example: 100
    limitParamIdentitiesUtility:
      name: limit
      in: query
      description: '(Identities utility endpoint) The number of records to return from the collection.

        The default limit is 100. In a single response, the server returns at most 5000 records from the collection.'
      required: true
      schema:
        type: number
        default: 100
      example: 100
    applicationNameParam:
      name: application
      in: query
      description: Filter on the name of the application.
      schema:
        type: string
      example: Games
    identityTypesParam:
      name: identitytypes
      in: query
      description: An identity type or comma-delimited list of identity types.
      schema:
        type: string
      example: network,roaming
  responses:
    500Error:
      description: Internal Server Error
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
            example:
              message: Internal Server Error
    403Error:
      description: Forbidden
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
            example:
              message: Forbidden
    401Error:
      description: Unauthorized
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
            example:
              message: Unauthorized
    404Error:
      description: Not Found
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
            example:
              message: Not Found
    400Error:
      description: Bad Request
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
            example:
              message: Bad Request
  schemas:
    IdentityType:
      type: object
      description: The information about the identity including the type.
      properties:
        id:
          type: number
          description: The ID of the origin type for the identity.
        label:
          type: string
          description: The label of the origin type for the identity.
        type:
          type: string
          description: The name of the origin type for the identity.
    ThreatType:
      type: object
      description: The properties of the threat type.
      properties:
        name:
          type: string
          description: The name of the threat type.
        description:
          type: string
          description: The name of the threat type.
      required:
      - name
      - description
      example:
        name: Ransomware
        description: a description
    Meta:
      type: object
      description: The properties of the metadata.
      example: {}
    Application:
      type: object
      description: The information about the application.
      properties:
        id:
          type: number
          description: The ID of the application.
        label:
          type: string
          description: The descriptive label for the application.
        type:
          type: string
          description: 'The type of the application: NBAR or AVC.'
          enum:
          - NBAR
          - AVC
          example: AVC
        category:
          type: object
          description: The category of the application.
          properties:
            id:
              type: number
              description: The ID of the application category.
            label:
              type: string
              description: The label of the application category.
      example:
        id: 1
        label: malware
        type: AVC
        category:
          id: 2
          label: Education
    CategoryWithLegacyId:
      type: object
      description: The information about the category with legacy ID.
      properties:
        id:
          type: number
          description: The ID of the category.
        legacyid:
          type: number
          description: The legacy category ID.
        label:
          type: string
          description: The label of the category.
        type:
          type: string
          description: The type of the category.
        integration:
          type: boolean
          description: Specifies whether the category is an integration.
        deprecated:
          type: boolean
          description: Specifies whether the legacy category is deprecated.
          example: true
      required:
      - id
      - integration
      - label
      - legacyid
      - type
      - deprecated
      example:
        id: 66
        legacyid: 94
        label: Malware
        type: security
        integration: true
        deprecated: false
    Identity:
      type: object
      description: The information about the identity.
      properties:
        id:
          type: number
          description: The ID of the identity.
        label:
          type: string
          description: The descriptive label for the identity.
        type:
          $ref: '#/components/schemas/IdentityType'
        deleted:
          type: boolean
          description: Indicates whether the identity was deleted.
          example: true
      required:
      - id
      - label
      - type
      - deleted
      example:
        id: 1
        label: Catch Rate Testing System
        type:
          id: 21
          label: Sites
          type: site
        deleted: false
    ApplicationsWithCategories:
      type: object
      description: The information about the applications and categories.
      properties:
        applications:
          type: array
          description: The list of applications.
          items:
            $ref: '#/components/schemas/Application'
        categories:
          type: array
          description: The list of application categories.
          items:
            $ref: '#/components/schemas/ApplicationCategories'
      example:
        applications:
        - id: 1
          label: Web Hosting
          type: AVC
          category:
            id: 40
            label: Hosting Services
        categories:
        - id: 42
          name: Education
    ApplicationCategories:
      type: object
      description: The information about the applications.
      properties:
        id:
          type: number
          description: The ID of the application category.
          example: 1234
        name:
          type: string
          description: The name of the application category.
          example: Travel
      example:
        id: 1234
        name: Travel
    ThreatName:
      type: object
      description: The properties of the threat name.
      properties:
        name:
          type: string
          description: The name of the threat.
        description:
          type: string
          description: The description of the threat name.
      required:
      - name
      - description
      example:
        name: WannaCry
        description: a description
  securitySchemes:
    oauthFlow:
      type: oauth2
      description: client credential flow
      flows:
        clientCredentials:
          tokenUrl: https://api.umbrella.com/auth/v2/token
          scopes:
            reports.granularEvents:read: Read reports granular events
            reports.utilities:read: Read reports utilities
            reports.aggregations:read: Read reports aggregations
            reports.summariesByRule:read: Read reports for the summaries of the rule
            reports.customers:read: Read reports for the customers
x-provenance:
  method: harvested
  first_party: true
  harvested: '2026-08-19'
  source: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/reporting.yaml
  publisher: Cisco Systems, Inc. (Cisco DevNet Cloud Security docs)
x-evidence:
  fetched: '2026-08-19'
  url: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/reporting.yaml
  http_status: 200
  docs: https://developer.cisco.com/docs/cloud-security/