openapi: 3.0.1
info:
title: Mend Access Management General Info - Permissions API
description: 'Mend''s enhanced API enables automation of workflows in a REST compliant format. The API features:
+ Access for any user with Mend credentials, via a user key available in the user''s profile page in the Mend Platform.
+ Improved security with a JWT token per organization, which expires every 10 minutes.
+ Added scalability with support for cursor pagination and limiting results size.
+ Broader functionality available programmatically.
+ New standard API documentation for easy navigation and search.
**Note:** To help you get started with the Mend API 3.0, we recommend reviewing our onboarding guide -> [Getting Started with API 3.0](https://docs.mend.io/platform/latest/getting-started-with-mend-api-3-0).
This resource covers initial setup, authentication instructions, and helpful tips to help you successfully begin working with the Mend API 3.0. If you have a dedicated instance of Mend, contact your Mend representative to access this API on your instance.'
version: '3.0'
servers:
- url: https://baseUrl
description: Generated server url
security:
- bearer-key: []
tags:
- name: General Info - Permissions
paths:
/api/v2.0/permissions/byRole:
get:
tags:
- General Info - Permissions
summary: Get All Available Permissions Grouped By Roles
description: Returns a list of the current user's permissions grouped by roles
operationId: getAvailableRolePermissions
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/DWRResponseListRolePermissionsDTO'
'400':
description: Bad Request
content:
'*/*':
schema:
$ref: '#/components/schemas/DWRResponseBase'
'403':
description: Forbidden
content:
'*/*':
schema:
$ref: '#/components/schemas/DWRResponseBase'
components:
schemas:
DWRResponseListRolePermissionsDTO:
type: object
properties:
supportToken:
title: Support Token
type: string
example: 1171c60d
retVal:
type: array
items:
$ref: '#/components/schemas/RolePermissionsDTO'
RolePermissionsDTO:
type: object
properties:
role:
type: string
enum:
- DEFAULT_APPROVER
- ADMIN
- ALERT_EMAIL_RECEIVER
- ALERTS_IGNORER
- LICENSE_AND_COPYRIGHT_ASSIGNER
- AUDITOR
- USER
- PRODUCT_INTEGRATOR
- SBOM_EXPORTER
permissions:
type: array
items:
title: User Permissions
type: string
example: POLICIES__POLICY__VIEW
DWRResponseBase:
type: object
properties:
supportToken:
title: Support Token
type: string
example: 1171c60d
securitySchemes:
bearer-key:
type: http
description: JWT token Bearer
scheme: bearer
bearerFormat: JWT