Dependency-Track Permission API

The permission API from Dependency-Track — 5 operation(s) for permission.

Operations 7

GET /v1/permission Returns a list of all permissions #
PUT /v1/permission/team Replaces a team's permissions with the specified list #
PUT /v1/permission/user Replaces a users's permissions with the specified list #
DELETE /v1/permission/{permission}/team/{uuid} Remove permission from team #
POST /v1/permission/{permission}/team/{uuid} Add permission to team #
DELETE /v1/permission/{permission}/user/{username} Removes the permission from the user #
POST /v1/permission/{permission}/user/{username} Adds the permission to the specified username #

Documentation

Specifications

Schemas & Data

📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-component-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-vulnerability-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-project-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-notification-rule-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-portfolio-metrics-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-project-metrics-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-workload-identity-provider-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-clone-project-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-create-workload-identity-provider-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-create-oauth-token-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-create-component-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/dependency-track/refs/heads/main/json-schema/dependency-track-update-workload-identity-provider-request-schema.json

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/dependency-track:dependency-track-permission-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

dependency-track-permission-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Dependency Track Permission API
  version: 1.0.0
  contact:
    name: The Dependency-Track Authors
    url: https://github.com/DependencyTrack/dependency-track
  license:
    name: Apache-2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  description: 'Operations tagged permission across 2 of this provider''s published API definitions: dependency-track-openapi-v1.yaml, dependency-track-openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: /api
tags:
- name: Permission
paths:
  /v1/permission:
    get:
      description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_READ
      operationId: getAllPermissions
      responses:
        '200':
          content:
            application/json:
              schema:
                type: string
                enum:
                - BOM_UPLOAD
                - VIEW_PORTFOLIO
                - PORTFOLIO_ACCESS_CONTROL_BYPASS
                - PORTFOLIO_MANAGEMENT
                - PORTFOLIO_MANAGEMENT_CREATE
                - PORTFOLIO_MANAGEMENT_READ
                - PORTFOLIO_MANAGEMENT_UPDATE
                - PORTFOLIO_MANAGEMENT_DELETE
                - VIEW_VULNERABILITY
                - VULNERABILITY_ANALYSIS
                - VULNERABILITY_ANALYSIS_CREATE
                - VULNERABILITY_ANALYSIS_READ
                - VULNERABILITY_ANALYSIS_UPDATE
                - VIEW_POLICY_VIOLATION
                - VULNERABILITY_MANAGEMENT
                - VULNERABILITY_MANAGEMENT_CREATE
                - VULNERABILITY_MANAGEMENT_READ
                - VULNERABILITY_MANAGEMENT_UPDATE
                - VULNERABILITY_MANAGEMENT_DELETE
                - POLICY_VIOLATION_ANALYSIS
                - ACCESS_MANAGEMENT
                - ACCESS_MANAGEMENT_CREATE
                - ACCESS_MANAGEMENT_READ
                - ACCESS_MANAGEMENT_UPDATE
                - ACCESS_MANAGEMENT_DELETE
                - SECRET_MANAGEMENT
                - SECRET_MANAGEMENT_CREATE
                - SECRET_MANAGEMENT_UPDATE
                - SECRET_MANAGEMENT_DELETE
                - SYSTEM_CONFIGURATION
                - SYSTEM_CONFIGURATION_CREATE
                - SYSTEM_CONFIGURATION_READ
                - SYSTEM_CONFIGURATION_UPDATE
                - SYSTEM_CONFIGURATION_DELETE
                - PROJECT_CREATION_UPLOAD
                - POLICY_MANAGEMENT
                - POLICY_MANAGEMENT_CREATE
                - POLICY_MANAGEMENT_READ
                - POLICY_MANAGEMENT_UPDATE
                - POLICY_MANAGEMENT_DELETE
                - TAG_MANAGEMENT
                - TAG_MANAGEMENT_DELETE
          description: A list of all permissions
        '401':
          description: Unauthorized
      security:
      - ApiKeyAuth: []
      - BearerAuth: []
      summary: Returns a list of all permissions
      tags:
      - Permission
    servers:
    - url: /api
  /v1/permission/team:
    put:
      description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_UPDATE
      operationId: setTeamPermissions
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TeamPermissionsSetRequest'
        description: Team UUID and requested permissions
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Team'
          description: The updated team
        '304':
          description: The team already has the specified permission(s)
        '400':
          description: Bad request
        '401':
          description: Unauthorized
        '404':
          description: The team could not be found
      security:
      - ApiKeyAuth: []
      - BearerAuth: []
      summary: Replaces a team's permissions with the specified list
      tags:
      - Permission
    servers:
    - url: /api
  /v1/permission/user:
    put:
      description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_UPDATE
      operationId: setUserPermissions
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserPermissionsSetRequest'
        description: A username and valid list permission
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
          description: The updated user
        '304':
          description: The user is already has the specified permission(s)
        '400':
          description: Bad request
        '401':
          description: Unauthorized
        '404':
          description: The user could not be found
      security:
      - ApiKeyAuth: []
      - BearerAuth: []
      summary: Replaces a users's permissions with the specified list
      tags:
      - Permission
    servers:
    - url: /api
  /v1/permission/{permission}/team/{uuid}:
    delete:
      description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_DELETE
      operationId: removePermissionFromTeam
      parameters:
      - description: A valid team uuid
        in: path
        name: uuid
        required: true
        schema:
          type: string
          format: uuid
      - description: A valid permission
        in: path
        name: permission
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Team'
          description: The updated team
        '304':
          description: The team already has the specified permission assigned
        '401':
          description: Unauthorized
        '404':
          description: The team could not be found
      security:
      - ApiKeyAuth: []
      - BearerAuth: []
      tags:
      - Permission
      summary: Remove permission from team
      x-summary-source: derived
    post:
      description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_UPDATE
      operationId: addPermissionToTeam
      parameters:
      - description: A valid team uuid
        in: path
        name: uuid
        required: true
        schema:
          type: string
          format: uuid
      - description: A valid permission
        in: path
        name: permission
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Team'
          description: The updated team
        '304':
          description: The team already has the specified permission assigned
        '401':
          description: Unauthorized
        '404':
          description: The team could not be found
      security:
      - ApiKeyAuth: []
      - BearerAuth: []
      tags:
      - Permission
      summary: Add permission to team
      x-summary-source: derived
    servers:
    - url: /api
  /v1/permission/{permission}/user/{username}:
    delete:
      description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_DELETE
      operationId: removePermissionFromUser
      parameters:
      - description: A valid username
        in: path
        name: username
        required: true
        schema:
          type: string
      - description: A valid permission
        in: path
        name: permission
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
          description: The updated user
        '304':
          description: The user already has the specified permission assigned
        '401':
          description: Unauthorized
        '404':
          description: The user could not be found
      security:
      - ApiKeyAuth: []
      - BearerAuth: []
      summary: Removes the permission from the user
      tags:
      - Permission
    post:
      description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_UPDATE
      operationId: addPermissionToUser
      parameters:
      - description: A valid username
        in: path
        name: username
        required: true
        schema:
          type: string
      - description: A valid permission
        in: path
        name: permission
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
          description: The updated user
        '304':
          description: The user already has the specified permission assigned
        '401':
          description: Unauthorized
        '404':
          description: The user could not be found
      security:
      - ApiKeyAuth: []
      - BearerAuth: []
      summary: Adds the permission to the specified username
      tags:
      - Permission
    servers:
    - url: /api
components:
  schemas:
    ManagedUser:
      type: object
      properties:
        confirmPassword:
          type: string
        email:
          type: string
          maxLength: 255
          minLength: 0
          pattern: '[\P{Cc}]+'
        forcePasswordChange:
          type: boolean
        fullname:
          type: string
          maxLength: 255
          minLength: 0
          pattern: '[\P{Cc}]+'
        lastPasswordChange:
          type: integer
          format: int64
          description: UNIX epoch timestamp in milliseconds
        newPassword:
          type: string
        nonExpiryPassword:
          type: boolean
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/Permission'
        suspended:
          type: boolean
        teams:
          type: array
          items:
            $ref: '#/components/schemas/Team'
        username:
          type: string
          maxLength: 255
          minLength: 1
          pattern: '[\P{Cc}]+'
      required:
      - lastPasswordChange
      - username
    TeamPermissionsSetRequest:
      type: object
      properties:
        permissions:
          type: array
          items:
            type: string
            enum:
            - BOM_UPLOAD
            - VIEW_PORTFOLIO
            - PORTFOLIO_ACCESS_CONTROL_BYPASS
            - PORTFOLIO_MANAGEMENT
            - PORTFOLIO_MANAGEMENT_CREATE
            - PORTFOLIO_MANAGEMENT_READ
            - PORTFOLIO_MANAGEMENT_UPDATE
            - PORTFOLIO_MANAGEMENT_DELETE
            - VIEW_VULNERABILITY
            - VULNERABILITY_ANALYSIS
            - VULNERABILITY_ANALYSIS_CREATE
            - VULNERABILITY_ANALYSIS_READ
            - VULNERABILITY_ANALYSIS_UPDATE
            - VIEW_POLICY_VIOLATION
            - VULNERABILITY_MANAGEMENT
            - VULNERABILITY_MANAGEMENT_CREATE
            - VULNERABILITY_MANAGEMENT_READ
            - VULNERABILITY_MANAGEMENT_UPDATE
            - VULNERABILITY_MANAGEMENT_DELETE
            - POLICY_VIOLATION_ANALYSIS
            - ACCESS_MANAGEMENT
            - ACCESS_MANAGEMENT_CREATE
            - ACCESS_MANAGEMENT_READ
            - ACCESS_MANAGEMENT_UPDATE
            - ACCESS_MANAGEMENT_DELETE
            - SECRET_MANAGEMENT
            - SECRET_MANAGEMENT_CREATE
            - SECRET_MANAGEMENT_UPDATE
            - SECRET_MANAGEMENT_DELETE
            - SYSTEM_CONFIGURATION
            - SYSTEM_CONFIGURATION_CREATE
            - SYSTEM_CONFIGURATION_READ
            - SYSTEM_CONFIGURATION_UPDATE
            - SYSTEM_CONFIGURATION_DELETE
            - PROJECT_CREATION_UPLOAD
            - POLICY_MANAGEMENT
            - POLICY_MANAGEMENT_CREATE
            - POLICY_MANAGEMENT_READ
            - POLICY_MANAGEMENT_UPDATE
            - POLICY_MANAGEMENT_DELETE
            - TAG_MANAGEMENT
            - TAG_MANAGEMENT_DELETE
          uniqueItems: true
        team:
          type: string
          minLength: 1
      required:
      - permissions
      - team
    MappedOidcGroup:
      type: object
      properties:
        group:
          $ref: '#/components/schemas/OidcGroup'
        uuid:
          type: string
          format: uuid
      required:
      - uuid
    UserPermissionsSetRequest:
      type: object
      properties:
        permissions:
          type: array
          items:
            type: string
            enum:
            - BOM_UPLOAD
            - VIEW_PORTFOLIO
            - PORTFOLIO_ACCESS_CONTROL_BYPASS
            - PORTFOLIO_MANAGEMENT
            - PORTFOLIO_MANAGEMENT_CREATE
            - PORTFOLIO_MANAGEMENT_READ
            - PORTFOLIO_MANAGEMENT_UPDATE
            - PORTFOLIO_MANAGEMENT_DELETE
            - VIEW_VULNERABILITY
            - VULNERABILITY_ANALYSIS
            - VULNERABILITY_ANALYSIS_CREATE
            - VULNERABILITY_ANALYSIS_READ
            - VULNERABILITY_ANALYSIS_UPDATE
            - VIEW_POLICY_VIOLATION
            - VULNERABILITY_MANAGEMENT
            - VULNERABILITY_MANAGEMENT_CREATE
            - VULNERABILITY_MANAGEMENT_READ
            - VULNERABILITY_MANAGEMENT_UPDATE
            - VULNERABILITY_MANAGEMENT_DELETE
            - POLICY_VIOLATION_ANALYSIS
            - ACCESS_MANAGEMENT
            - ACCESS_MANAGEMENT_CREATE
            - ACCESS_MANAGEMENT_READ
            - ACCESS_MANAGEMENT_UPDATE
            - ACCESS_MANAGEMENT_DELETE
            - SECRET_MANAGEMENT
            - SECRET_MANAGEMENT_CREATE
            - SECRET_MANAGEMENT_UPDATE
            - SECRET_MANAGEMENT_DELETE
            - SYSTEM_CONFIGURATION
            - SYSTEM_CONFIGURATION_CREATE
            - SYSTEM_CONFIGURATION_READ
            - SYSTEM_CONFIGURATION_UPDATE
            - SYSTEM_CONFIGURATION_DELETE
            - PROJECT_CREATION_UPLOAD
            - POLICY_MANAGEMENT
            - POLICY_MANAGEMENT_CREATE
            - POLICY_MANAGEMENT_READ
            - POLICY_MANAGEMENT_UPDATE
            - POLICY_MANAGEMENT_DELETE
            - TAG_MANAGEMENT
            - TAG_MANAGEMENT_DELETE
          uniqueItems: true
        username:
          type: string
          minLength: 1
          pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$
      required:
      - permissions
      - username
    ServiceAccount:
      type: object
      properties:
        email:
          type: string
          maxLength: 255
          minLength: 0
          pattern: '[\P{Cc}]+'
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/Permission'
        suspended:
          type: boolean
        teams:
          type: array
          items:
            $ref: '#/components/schemas/Team'
        username:
          type: string
          maxLength: 255
          minLength: 1
          pattern: '[\P{Cc}]+'
      required:
      - username
    OidcGroup:
      type: object
      properties:
        name:
          type: string
          maxLength: 255
          minLength: 1
          pattern: '[\P{Cc}]+'
        uuid:
          type: string
          format: uuid
      required:
      - name
      - uuid
    MappedLdapGroup:
      type: object
      properties:
        dn:
          type: string
          maxLength: 255
          minLength: 1
          pattern: '[\P{Cc}]+'
        uuid:
          type: string
          format: uuid
      required:
      - dn
      - uuid
    Permission:
      type: object
      properties:
        description:
          type: string
        ldapUsers:
          type: array
          items:
            $ref: '#/components/schemas/LdapUser'
        managedUsers:
          type: array
          items:
            $ref: '#/components/schemas/ManagedUser'
        name:
          type: string
          maxLength: 255
          minLength: 1
          pattern: ^[a-zA-Z_0-9]*$
        oidcUsers:
          type: array
          items:
            $ref: '#/components/schemas/OidcUser'
      required:
      - name
    Team:
      type: object
      properties:
        apiKeys:
          type: array
          items:
            $ref: '#/components/schemas/ApiKey'
        ldapUsers:
          type: array
          items:
            $ref: '#/components/schemas/LdapUser'
        managedUsers:
          type: array
          items:
            $ref: '#/components/schemas/ManagedUser'
        mappedLdapGroups:
          type: array
          items:
            $ref: '#/components/schemas/MappedLdapGroup'
        mappedOidcGroups:
          type: array
          items:
            $ref: '#/components/schemas/MappedOidcGroup'
        name:
          type: string
          maxLength: 255
          minLength: 1
          pattern: '[\P{Cc}]+'
        oidcUsers:
          type: array
          items:
            $ref: '#/components/schemas/OidcUser'
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/Permission'
        serviceAccounts:
          type: array
          items:
            $ref: '#/components/schemas/ServiceAccount'
        uuid:
          type: string
          format: uuid
      required:
      - name
      - uuid
    LdapUser:
      type: object
      properties:
        dn:
          type: string
          maxLength: 255
          minLength: 1
          pattern: '[\P{Cc}]+'
        email:
          type: string
          maxLength: 255
          minLength: 0
          pattern: '[\P{Cc}]+'
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/Permission'
        teams:
          type: array
          items:
            $ref: '#/components/schemas/Team'
        username:
          type: string
          maxLength: 255
          minLength: 1
          pattern: '[\P{Cc}]+'
      required:
      - username
    OidcUser:
      type: object
      properties:
        email:
          type: string
          maxLength: 255
          minLength: 0
          pattern: '[\P{Cc}]+'
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/Permission'
        subjectIdentifier:
          type: string
          maxLength: 255
          minLength: 1
          pattern: '[\P{Cc}]+'
        teams:
          type: array
          items:
            $ref: '#/components/schemas/Team'
        username:
          type: string
          maxLength: 255
          minLength: 1
          pattern: '[\P{Cc}]+'
      required:
      - username
    User:
      type: object
      properties:
        email:
          type: string
          maxLength: 255
          minLength: 0
          pattern: '[\P{Cc}]+'
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/Permission'
        teams:
          type: array
          items:
            $ref: '#/components/schemas/Team'
        username:
          type: string
          maxLength: 255
          minLength: 1
          pattern: '[\P{Cc}]+'
      required:
      - username
    ApiKey:
      type: object
      properties:
        comment:
          type: string
          maxLength: 255
          minLength: 0
        created:
          type: integer
          format: int64
          description: UNIX epoch timestamp in milliseconds
        expiresAt:
          type: integer
          format: int64
          description: UNIX epoch timestamp in milliseconds
        key:
          type: string
        lastUsed:
          type: integer
          format: int64
          description: UNIX epoch timestamp in milliseconds
        legacy:
          type: boolean
        maskedKey:
          type: string
        publicId:
          type: string
          maxLength: 8
          minLength: 5
  securitySchemes:
    ApiKeyAuth:
      description: Authentication via API key.
      in: header
      name: X-Api-Key
      type: apiKey
    BearerAuth:
      bearerFormat: Opaque
      description: 'Authentication via opaque server-issued session token.

        Tokens are obtained from `POST /api/v1/user/login` or

        `POST /api/v1/user/oidc/login`.'
      scheme: bearer
      type: http
x-refined-from:
- dependency-track-openapi-v1.yaml
- dependency-track-openapi.yml