HackNotice Third Party Accounts API

Third-party vendor monitoring: hacks, hack updates, watchlists, alerts and vendor security assessments.

Operations 93

POST /assessmentdatafiles/count Get the count of documents #
GET /assessmentdatafiles/download/{documentId} Download a doc #
POST /assessmentdatafiles/invited Create a doc #
POST /assessmentdatafiles/invited/count Get the count of documents #
GET /assessmentdatafiles/invited/download/{documentId} Download a doc #
POST /assessmentdatafiles/invited/page/{pageNum} Read a page of documents #
GET /assessmentdatafiles/invited/{documentId} Read a doc #
DELETE /assessmentdatafiles/invited/{documentId} Delete a doc #
POST /assessmentdatafiles/page/{pageNum} Read a page of documents #
GET /assessmentdatafiles/{fileId} Read a doc #
PUT /assessmentdatafiles/{fileId} Update a doc #
DELETE /assessmentdatafiles/{fileId} Delete a doc #
POST /assessmentevents Create assessment event #
POST /assessmentevents/count Count assessment events #
POST /assessmentevents/invited Create invited assessment event #
POST /assessmentevents/invited/page/{pageNum} List invited assessment events (paginated) #
GET /assessmentevents/invited/{documentId} Get one invited assessment event #
DELETE /assessmentevents/invited/{documentId} Delete one invited assessment event #
PUT /assessmentevents/invited/{documentId} Update one invited assessment event #
POST /assessmentevents/page/{pageNum} List assessment events (paginated) #
GET /assessmentevents/{eventId} Get one assessment event #
DELETE /assessmentevents/{eventId} Delete one assessment event #
PUT /assessmentevents/{eventId} Update one assessment event #
POST /assessmentinvites Create invite #
POST /assessmentinvites/activate/{inviteCode} Activate invite #
GET /assessmentinvites/code/{inviteCode} Read invite by code #
POST /assessmentinvites/count Count invites #
GET /assessmentinvites/mine My invites (invited user view) #
POST /assessmentinvites/page/{pageNum} List invites (paginated) #
GET /assessmentinvites/{inviteId} Read invite by ID #
DELETE /assessmentinvites/{inviteId} Delete invite by ID #
PUT /assessmentinvites/{inviteId} Update invite by ID #
POST /assessmentpreferences Create preferences #
GET /assessmentpreferences Get preferences #
DELETE /assessmentpreferences Delete preferences #
PUT /assessmentpreferences Update preferences #
POST /assessments Create a doc #
POST /assessments/count post the count of documents #
GET /assessments/invited/{documentId} Read an invite #
PUT /assessments/invited/{documentId} update invite #
POST /assessments/page/{pageNum} post a page of documents #
POST /assessments/projection projection #
GET /assessments/{assessmentId} Read a doc #
DELETE /assessments/{assessmentId} Delete a doc #
PUT /assessments/{assessmentId} update a doc #
POST /assessmenttemplates Create template #
POST /assessmenttemplates/count Count templates #
GET /assessmenttemplates/frameworks List available frameworks #
POST /assessmenttemplates/page/{pageNum} List templates (paginated) #
GET /assessmenttemplates/{templateId} Read one template #
DELETE /assessmenttemplates/{templateId} Delete one template #
PUT /assessmenttemplates/{templateId} Update one template #
POST /breaches/count/range Read count of documents within a date range #
POST /breaches/new/count/ Read count of all documents #
POST /breaches/new/page/{pageNum} Read a page of documents #
GET /breaches/new/timestamp/page/{pageNum} Read a page of documents sorted by timestamp (creation) #
GET /breaches/new/{documentId} Read a document #
POST /breaches/search/page/{pageNum} Search a page #
GET /breachupdatedlog/count/ Read count of all documents #
GET /breachupdatedlog/page/{pageNum} Read a page of documents #
POST /breachupdatedlog/search Search all #
GET /breachupdatedlog/{documentId} Read a document #
PUT /hackalerts Fix hackalerts for a list of alert _ids #
GET /hackalerts/alertedcount/{number} Read count for a number of previous (timestamp) days of alerts #
GET /hackalerts/alertedpage/{number} Read a page of alerts (sorted by timestamp) #
GET /hackalerts/count Read count for alerts #
GET /hackalerts/count/{number} Read count for a number of previous (published date) days of alerts #
GET /hackalerts/distinct/count Read count for distinct watchlist items #
GET /hackalerts/distinct/page/{pageNum} Read page for distinct watchlist items #
POST /hackalerts/hackwatchlist/remove Delete hackalerts for a hackwatchlist id #
POST /hackalerts/hackwatchlist/update Update hackalerts tags for a hackwatchlist id #
GET /hackalerts/harvester/all Read ransomware harvesters all #
GET /hackalerts/lastdate Read last alert date #
GET /hackalerts/page/{pageNum} Read a page of alerts (sorted by published date) #
POST /hackalerts/search Search domain within alerts #
GET /hackalerts/{alertId} Read a document #
PUT /hackalerts/{alertId} Update a document #
GET /hacknoticeupdates/page/{pageNum} Read a page of documents #
POST /hacknoticeupdates/search Search all #
GET /hacknoticeupdates/{documentId} Read a document #
GET /hackwatchlist/count Get the count of documents #
POST /hackwatchlist/count Get the count of documents with options #
POST /hackwatchlist/create Create a doc #
GET /hackwatchlist/page/{pageNum} Read a page of documents #
POST /hackwatchlist/page/{pageNum} Read a page of documents #
POST /hackwatchlist/search Search for a domain #
GET /hackwatchlist/{watchlistId} Read a doc #
PUT /hackwatchlist/{watchlistId} Update a doc tags #
DELETE /hackwatchlist/{watchlistId} Delete a doc #
POST /report/assessment Create assessment PDF report #
POST /report/assessment/excel Create assessment Excel report #
POST /report/assessment/invited Create invited assessment PDF report #
POST /report/assessment/invited/excel Create invited assessment Excel report #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/hacknotice-third-party-accounts-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

hacknotice-third-party-accounts-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: HackNotice Third Party Accounts API
  version: '2026-08-22'
  summary: External threat-intelligence API for first-party, third-party and end-user breach monitoring, threat research and vendor assessments.
  description: 'HackNotice''s REST API over its external threat-intelligence platform: credential and breach alerts for first-party domains, third-party vendors and end users; dark-web / hacker-forum research search; and AI-assisted vendor security assessments.


    PROVENANCE: this document was DERIVED by API Evangelist from HackNotice''s own published Postman collection "HackNotice-API", reached at https://api-docs.hacknotice.com (HTTP 301 -> https://documenter.getpostman.com/view/806684/2sBXiri7pT), linked from HackNotice''s help centre article "API". Paths, methods, parameters, request bodies and tags are transcribed from that collection; nothing was invented. Concrete record ids in the collection''s example URLs were templated into path parameters, and every token-shaped example value was redacted.


    HackNotice publishes a rate limit of 1 query per second, and states that API access is granted to approved accounts only after a 30-minute consultation call.'
  termsOfService: https://hacknotice.com/businesstandc/
  contact:
    name: HackNotice Support
    url: https://hacknotice.zendesk.com/hc/en-us
    email: support@hacknotice.com
  x-api-evangelist-derived-from: https://api-docs.hacknotice.com
servers:
- url: https://extensionapi.hacknotice.com
  description: HackNotice production API host, as declared by HackNotice's own first-party n8n node (API_BASE_URL in credentials/HackNoticeApi.credentials.ts, github.com/HackNotice/n8n-nodes-hacknotice). The published Postman collection ships an internal {{url}} variable pointing at a developer VPN host, which is not the production base.
security:
- jwtAuth: []
- apiKeyAuth: []
tags:
- name: Third Party Accounts
  description: 'Third-party vendor monitoring: hacks, hack updates, watchlists, alerts and vendor security assessments.'
paths:
  /assessmentdatafiles/count:
    post:
      tags:
      - Third Party Accounts
      summary: Get the count of documents
      operationId: postGetTheCountOfDocuments2
      description: 'Folder: Assessments / assessment data files. Get the count of documents'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentdatafiles/download/{documentId}:
    get:
      tags:
      - Third Party Accounts
      summary: Download a doc
      operationId: getDownloadADoc2
      description: 'Folder: Assessments / assessment data files. Download a Doc Purpose: Download the binary file for an assessment data file. Path Parameters Parameter Description docId Assessment data file document ID Behavior Streams file content from private storage Sets Content-Disposition using stored filename when available Responses Status Description 200 Binary file stream 400 Missing docId path parameter 401 Unauthorized user 404 File not found'
      parameters:
      - name: documentId
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentdatafiles/invited:
    post:
      tags:
      - Third Party Accounts
      summary: Create a doc
      operationId: postCreateADoc5
      description: 'Folder: Assessments / assessment data files / invited assessment data files. Create Invited Assessment Data File Purpose: Upload a file for an assessment shared with the invited user. Auth Authorization: JWT REDACTED_EXAMPLE_TOKEN Content Type multipart/form-data Form-Data Fields Field Type Required Description assessment_id text Yes Target assessment ID the invited user can access data file Yes File to upload filename text No Optional display filename override note text No Optional note/description Responses Status Description 200 Created file metadata document 400 Missing assessment_id or missing data file field 401 Unauthorized user or invite access not valid'
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              type: object
              properties:
                data:
                  type: string
                  format: binary
                assessment_id:
                  type: string
                filename:
                  type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentdatafiles/invited/count:
    post:
      tags:
      - Third Party Accounts
      summary: Get the count of documents
      operationId: postGetTheCountOfDocuments
      description: 'Folder: Assessments / assessment data files / invited assessment data files. Get the Count of Documents Purpose: Return the total number of invited assessment data files for one assessment. Request Body Field Type Required Description assessment_id string Yes Assessment ID to count files for Body Example { "assessment_id": "69aadd3f4620e8b72b9ffffc" } Responses Status Description 200 Numeric count (for example 4 ) 400 Missing assessment_id 401 Unauthorized user or invite access not valid'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                assessment_id:
                  type: string
            example:
              assessment_id: 69aadd3f4620e8b72b9ffffc
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentdatafiles/invited/download/{documentId}:
    get:
      tags:
      - Third Party Accounts
      summary: Download a doc
      operationId: getDownloadADoc
      description: 'Folder: Assessments / assessment data files / invited assessment data files. Download a Doc Purpose: Download the binary file for an invited assessment data file. Path Parameters Parameter Description docId Assessment data file document ID Behavior Streams file content from private storage Sets Content-Disposition using stored filename when available Responses Status Description 200 Binary file stream 400 Missing docId path parameter 401 Unauthorized user or invite access not valid 404 File not found'
      parameters:
      - name: documentId
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentdatafiles/invited/page/{pageNum}:
    post:
      tags:
      - Third Party Accounts
      summary: Read a page of documents
      operationId: postReadAPageOfDocuments3
      description: 'Folder: Assessments / assessment data files / invited assessment data files. Read a Page of Documents Purpose: Return a paginated list of invited assessment data files for one assessment. Path Parameters Parameter Description pageNum Zero-based page index. Page size is fixed at 50 . Request Body Field Type Required Description assessment_id string Yes Assessment ID to list files for Body Example { "assessment_id": "69aadd3f4620e8b72b9ffffc" } Responses Status Description 200 Array of file metadata documents (newest first) 400 Missing assessment_id 401 Unauthorized user or invite access not valid'
      parameters:
      - name: pageNum
        in: path
        required: true
        schema:
          type: integer
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                assessment_id:
                  type: string
            example:
              assessment_id: 69aadd3f4620e8b72b9ffffc
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentdatafiles/invited/{documentId}:
    get:
      tags:
      - Third Party Accounts
      summary: Read a doc
      operationId: getReadADoc6
      description: 'Folder: Assessments / assessment data files / invited assessment data files. Read a Doc Purpose: Return metadata for one invited assessment data file by document ID. Path Parameters Parameter Description docId Assessment data file document ID Responses Status Description 200 File metadata document 400 Missing docId path parameter 401 Unauthorized user or invite access not valid 404 File not found'
      parameters:
      - name: documentId
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
    delete:
      tags:
      - Third Party Accounts
      summary: Delete a doc
      operationId: deleteADoc6
      description: 'Folder: Assessments / assessment data files / invited assessment data files. Delete a Doc Purpose: Delete an invited assessment data file by document ID. Path Parameters Parameter Description docId Assessment data file document ID Behavior Invited users can only delete files they uploaded themselves Valid invite/share access to the related assessment is still required Deletes both file record and underlying file object Responses Status Description 200 File successfully deleted 400 Missing docId path parameter 401 Unauthorized user or invite access not valid 404 File not found or user did not upload this file 200 Response Example { "message": "File successfully deleted" }'
      parameters:
      - name: documentId
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentdatafiles/page/{pageNum}:
    post:
      tags:
      - Third Party Accounts
      summary: Read a page of documents
      operationId: postReadAPageOfDocuments4
      description: 'Folder: Assessments / assessment data files. Read all domains.'
      parameters:
      - name: pageNum
        in: path
        required: true
        schema:
          type: integer
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentdatafiles/{fileId}:
    get:
      tags:
      - Third Party Accounts
      summary: Read a doc
      operationId: getReadADoc7
      description: 'Folder: Assessments / assessment data files. Read a Doc Purpose: Return metadata for one assessment data file by document ID. Path Parameters Parameter Description docId Assessment data file document ID Responses Status Description 200 File metadata document 400 Missing docId path parameter 401 Unauthorized user 404 File not found'
      parameters:
      - name: fileId
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
    put:
      tags:
      - Third Party Accounts
      summary: Update a doc
      operationId: putUpdateADoc4
      description: 'Folder: Assessments / assessment data files. Update a Doc Purpose: Update metadata for one assessment data file. Path Parameters Parameter Description docId Assessment data file document ID Request Body (Allowed Field) Field Type Description note string Updates note/description for the file Body Example { "note": "Updated evidence note" } Responses Status Description 200 Updated file metadata document 400 Missing docId path parameter 401 Unauthorized user 404 File not found'
      parameters:
      - name: fileId
        in: path
        required: true
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                note:
                  type: string
            example:
              note: note2
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
    delete:
      tags:
      - Third Party Accounts
      summary: Delete a doc
      operationId: deleteADoc7
      description: 'Folder: Assessments / assessment data files. Delete a Doc Purpose: Delete an assessment data file by document ID. Path Parameters Parameter Description docId Assessment data file document ID Behavior Deletes both file record and underlying file object Responses Status Description 200 File successfully deleted 400 Missing docId path parameter 401 Unauthorized user 404 File not found 200 Response Example { "message": "File successfully deleted" }'
      parameters:
      - name: fileId
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentevents:
    post:
      tags:
      - Third Party Accounts
      summary: Create assessment event
      operationId: postCreateAssessmentEvent
      description: 'Folder: Assessments / assessmentevents. Create a new assessment event for the authenticated customer. Access Rule User must belong to an allowed customer type and be authenticated. Request Body Field Type Required Description assessment_id string ✅ Required The ID of the assessment this event belongs to. action string Optional The action being recorded (e.g. review_started ). assessor_notes string Optional Notes added by the assessor. company_notes string Optional Notes added by the company/vendor. file_link string Optional URL to a linked evidence file. assessment_data_file_id string Optional ID of an uploaded assessment data file. complete boolean Optional Whether the event marks the assessment as complete. Body Example: { "assessment_id": "64f1c8...", "action": "review_started", "assessor_notes": "Initial review completed", "company_notes": "Vendor provided SOC report", "file_link": "https://example.com/evidence.pdf", "assessment_data_file_id": "65ab...", "complete": false } Server-side Behavior The following fields are set automatically by the API and should not be included in the request body: customer_id user_id timestamp Responses Status Description 200 OK Event successfully created. Returns the created event object. 400 Bad Request assessment_id is missing from the request body. 401 Unauthorized User is not authenticated or token is invalid.'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                assessment_id:
                  type: string
                action:
                  type: string
                assessor_notes:
                  type: string
                company_notes:
                  type: string
                file_link:
                  type: string
                complete:
                  type: boolean
            example:
              assessment_id: 69a73dc2c0deb2b4840f44fc
              action: review_started
              assessor_notes: Initial review completed. Waiting on vendor responses.
              company_notes: Vendor requested 2-week extension.
              file_link: https://storage.example.com/assessments/evidence.pdf
              complete: false
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentevents/count:
    post:
      tags:
      - Third Party Accounts
      summary: Count assessment events
      operationId: postCountAssessmentEvents
      description: 'Folder: Assessments / assessmentevents. Return the total number of assessment events for the authenticated customer. Request Body All fields are optional. If no body is provided, the count covers all events for the caller''s customer. Field Type Required Description assessment_id string Optional If provided, restricts the count to events belonging to this assessment. Body Example: { "assessment_id": "64f1c8..." } Behavior Counts only records scoped to the caller''s customer_id . If assessment_id is provided, returns the count for that specific assessment only. Responses Status Description 200 OK Returns a numeric count of matching assessment events. 401 Unauthorized User is not authenticated or token is invalid. 200 Response Example: 42'
      requestBody:
        required: true
        content:
          text/plain:
            schema:
              type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentevents/invited:
    post:
      tags:
      - Third Party Accounts
      summary: Create invited assessment event
      operationId: postCreateInvitedAssessmentEvent
      description: 'Folder: Assessments / assessmentevents / invited. Creates a new event, note, or action for an assessment that the invited user has access to. Access Rule The user must have a valid invite or share link for the specified assessment_id . Request Body (JSON) Field Type Required Description assessment_id string ✅ Yes The ID of the assessment to attach the event to action string No The type of action (e.g. comment , review_started ) assessor_notes string No Notes added by the assessor company_notes string No Notes added by the company file_link string No URL to an associated file assessment_data_file_id string No ID of an uploaded assessment data file complete boolean No Whether the assessment is marked as complete Example: { "assessment_id": "64f1c8...", "action": "comment", "assessor_notes": "Reviewed controls", "company_notes": "Need SOC2 evidence", "file_link": "https://example.com/file.pdf", "assessment_data_file_id": "65ab...", "complete": false } Responses Status Description 200 OK Event created successfully. Returns the created event object. 400 Bad Request assessment_id is missing from the request body. 401 Unauthorized User is not authorized for the specified assessment.'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                assessment_id:
                  type: string
                action:
                  type: string
                assessor_notes:
                  type: string
                company_notes:
                  type: string
                file_link:
                  type: string
                complete:
                  type: boolean
            example:
              assessment_id: 69a73dc2c0deb2b4840f44fc
              action: review_started
              assessor_notes: Initial review completed. Waiting on vendor responses.
              company_notes: Vendor requested 2-week extension.
              file_link: https://storage.example.com/assessments/evidence.pdf
              complete: false
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentevents/invited/page/{pageNum}:
    post:
      tags:
      - Third Party Accounts
      summary: List invited assessment events (paginated)
      operationId: postListInvitedAssessmentEventsPaginated
      description: 'Folder: Assessments / assessmentevents / invited. Returns up to 50 events for a single assessment, sorted by newest first. Path Parameters Parameter Description pageNum Zero-based page number. Page 0 returns the first 50 records. Request Body (JSON) Field Type Required Description assessment_id string ✅ Yes The ID of the assessment to retrieve events for Note: assessment_id is required in the request body even though this is a paginated read operation, due to the current implementation. Example: { "assessment_id": "64f1c8..." } Responses Status Description 200 OK Returns an array of event objects for the assessment. 400 Bad Request assessment_id is missing from the request body. 401 Unauthorized The invite or share link is invalid or has expired.'
      parameters:
      - name: pageNum
        in: path
        required: true
        schema:
          type: integer
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                assessment_id:
                  type: string
            example:
              assessment_id: 69a73dc2c0deb2b4840f44fc
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentevents/invited/{documentId}:
    get:
      tags:
      - Third Party Accounts
      summary: Get one invited assessment event
      operationId: getOneInvitedAssessmentEvent
      description: 'Folder: Assessments / assessmentevents / invited. Fetch a single assessment event by its ID. Access Rule The user must have valid access to the assessment the event belongs to. Path Parameters Parameter Description docId The ID of the event to retrieve. Responses Status Description 200 OK Returns the event object. 400 Bad Request docId is missing. 401 Unauthorized User does not have valid access to the assessment. 404 Not Found No event found for the given ID.'
      parameters:
      - name: documentId
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
    delete:
      tags:
      - Third Party Accounts
      summary: Delete one invited assessment event
      operationId: deleteOneInvitedAssessmentEvent
      description: 'Folder: Assessments / assessmentevents / invited. Delete an event previously created by the invited user. Path Parameters Parameter Description docId The ID of the event to delete. Responses Status Description 200 OK Event successfully deleted. 400 Bad Request docId is missing. 401 Unauthorized User does not have valid access. 404 Not Found Event not found, or not owned by this invited user. 200 Response Example: { "message": "Assessment event successfully deleted" }'
      parameters:
      - name: documentId
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
    put:
      tags:
      - Third Party Accounts
      summary: Update one invited assessment event
      operationId: putUpdateOneInvitedAssessmentEvent
      description: 'Folder: Assessments / assessmentevents / invited. Update an event previously created by the invited user. Path Parameters Parameter Description docId The ID of the event to update. Request Body (JSON) Only the following fields can be updated: Field Type Description action string The type of action (e.g. comment ) assessor_notes string Notes added by the assessor company_notes string Notes added by the company file_link string URL to an associated file assessment_data_file_id string ID of an uploaded assessment data file complete boolean Whether the assessment is marked as complete Example: { "assessor_notes": "Updated after follow-up", "complete": true } Responses Status Description 200 OK Returns the updated event object. 400 Bad Request docId is missing. 401 Unauthorized User does not have valid access. 404 Not Found Event not found, or not owned by this invited user.'
      parameters:
      - name: documentId
        in: path
        required: true
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                file_link:
                  type: string
            example:
              file_link: https://storage.example.com/assessments/evidence2.pdf
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentevents/page/{pageNum}:
    post:
      tags:
      - Third Party Accounts
      summary: List assessment events (paginated)
      operationId: postListAssessmentEventsPaginated
      description: 'Folder: Assessments / assessmentevents. Get a paginated list of assessment events for the authenticated customer. Path Parameters Parameter Type Description pageNum integer Zero-based page index. Use 0 for the first page. Request Body (Optional) Field Type Description assessment_id string If provided, filters results to events belonging to this assessment. Example: { "assessment_id": "64f1c8..." } Behavior Returns only events belonging to the authenticated user''s customer_id If assessment_id is provided, results are filtered to that assessment Results are sorted by timestamp descending (most recent first) Page size is fixed at 50 events per page Responses Status Description 200 OK Returns an array of assessment event objects. 401 Unauthorized User is not authenticated or token is invalid.'
      parameters:
      - name: pageNum
        in: path
        required: true
        schema:
          type: integer
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                assessment_id:
                  type: string
            example:
              assessment_id: 69a73dc2c0deb2b4840f44fc
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Unauthorized — missing or invalid JWT / API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - jwtAuth: []
      - apiKeyAuth: []
  /assessmentevents/{eventId}:
    get:
      tags:
      - Third Party Accounts
      summary: Get one assessment event
      operationId: getOneAssessmentEvent
      description: 'Folder: Assessments / assessmentevents. Fetch a single assessment event by its ID, scoped to the authenticated customer. Path Parameters Parameter Type Description docId string The ID of the assessment event to retrieve. Behavior Returns only events belonging to the authenticated user''s customer_id Returns null if the event exists but does not belong to your customer scope Responses Status Description 200 

# --- truncated at 32 KB (270 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/hacknotice/refs/heads/main/openapi/hacknotice-third-party-accounts-api-openapi.yml