Sift Stack External Sync Service API

The ExternalSyncService API from Sift Stack — 6 operation(s) for externalsyncservice.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sift-stack-externalsyncservice-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sift-stack-externalsyncservice-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Sift External Sync Service API
  version: '1.0'
servers:
- url: https://api.siftstack.com
  description: Production
- url: https://gov.api.siftstack.com
  description: Gov
security:
- BearerAuth: []
tags:
- name: ExternalSyncService
paths:
  /api/v1/external-sync:
    get:
      summary: GetTokenDetails
      description: Get details about the most recent token generated, does not include the token itself
      operationId: ExternalSyncService_GetExternalSync
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1GetExternalSyncResponse'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/rpcStatus'
      tags:
      - ExternalSyncService
    post:
      summary: SyncOrganization
      description: Synchronizes an organization's users and groups
      operationId: ExternalSyncService_SyncOrganization
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1SyncOrganizationResponse'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/rpcStatus'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/v1SyncOrganizationRequest'
        required: true
      tags:
      - ExternalSyncService
  /api/v1/external-sync/runs/{externalSyncRunId}:
    get:
      summary: GetExternalSyncRun
      description: Get one external sync run including the full diff payload
      operationId: ExternalSyncService_GetExternalSyncRun
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1GetExternalSyncRunResponse'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/rpcStatus'
      parameters:
      - name: externalSyncRunId
        in: path
        required: true
        schema:
          type: string
      tags:
      - ExternalSyncService
  /api/v1/external-sync:generate-token:
    post:
      summary: GenerateToken
      description: Generates a token for synchronizing an organization's users and groups
      operationId: ExternalSyncService_GenerateToken
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1GenerateTokenResponse'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/rpcStatus'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/v1GenerateTokenRequest'
        required: true
      tags:
      - ExternalSyncService
  /api/v1/external-sync:is-org-externally-provisioned:
    get:
      summary: GetIsOrgExternallyProvisioned
      description: Returns whether the organization is configured for external (SCIM) user provisioning
      operationId: ExternalSyncService_GetIsOrgExternallyProvisioned
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1GetIsOrgExternallyProvisionedResponse'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/rpcStatus'
      tags:
      - ExternalSyncService
  /api/v1/external-sync:list-runs:
    get:
      summary: ListExternalSyncRuns
      description: List historical external sync runs for the organization (newest first by default)
      operationId: ExternalSyncService_ListExternalSyncRuns
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1ListExternalSyncRunsResponse'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/rpcStatus'
      parameters:
      - name: pageSize
        in: query
        required: false
        schema:
          type: integer
          format: int64
      - name: pageToken
        in: query
        required: false
        schema:
          type: string
      - name: filter
        in: query
        required: false
        schema:
          type: string
      - name: orderBy
        in: query
        required: false
        schema:
          type: string
      tags:
      - ExternalSyncService
  /api/v1/external-sync:list-tokens:
    get:
      summary: ListExternalSyncTokens
      description: List all tokens created by org
      operationId: ExternalSyncService_ListExternalSyncTokens
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1ListExternalSyncTokensResponse'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/rpcStatus'
      parameters:
      - name: pageSize
        description: 'The maximum number of tokens to return. The service may return fewer than this value.

          If unspecified, at most 50 tokens will be returned. The maximum value is 1000; values above

          1000 will be coerced to 1000. Optional.'
        in: query
        required: false
        schema:
          type: integer
          format: int64
      - name: pageToken
        description: 'A page token, received from a previous `ListExternalSyncTokens` call.

          Provide this to retrieve the subsequent page.

          When paginating, all other parameters provided to `ListExternalSyncTokens` must match

          the call that provided the page token. Optional.'
        in: query
        required: false
        schema:
          type: string
      - name: filter
        description: 'A [Common Expression Language (CEL)](https://github.com/google/cel-spec) filter string.

          There are currently no available fields.

          For further information about how to use CELs, please refer to [this guide](https://github.com/google/cel-spec/blob/master/doc/langdef.md#standard-definitions).'
        in: query
        required: false
        schema:
          type: string
      - name: orderBy
        description: 'How to order the retrieved user defined functions. Formatted as a comma-separated string i.e. "FIELD_NAME[ desc],...".

          Available field to order_by is `created_date`.

          If left empty, items are ordered by `created_date` in descending order (newest-first).

          For more information about the format of this field, read [this](https://google.aip.dev/132#ordering)

          Example: "created_date asc".'
        in: query
        required: false
        schema:
          type: string
      tags:
      - ExternalSyncService
components:
  schemas:
    protobufAny:
      type: object
      properties:
        '@type':
          type: string
          description: "A URL/resource name that uniquely identifies the type of the serialized\nprotocol buffer message. This string must contain at least\none \"/\" character. The last segment of the URL's path must represent\nthe fully qualified name of the type (as in\n`path/google.protobuf.Duration`). The name should be in a canonical form\n(e.g., leading \".\" is not accepted).\n\nIn practice, teams usually precompile into the binary all types that they\nexpect it to use in the context of Any. However, for URLs which use the\nscheme `http`, `https`, or no scheme, one can optionally set up a type\nserver that maps type URLs to message definitions as follows:\n\n* If no scheme is provided, `https` is assumed.\n* An HTTP GET on the URL must yield a [google.protobuf.Type][]\n  value in binary format, or produce an error.\n* Applications are allowed to cache lookup results based on the\n  URL, or have them precompiled into a binary to avoid any\n  lookup. Therefore, binary compatibility needs to be preserved\n  on changes to types. (Use versioned type names to manage\n  breaking changes.)\n\nNote: this functionality is not currently available in the official\nprotobuf release, and it is not used for type URLs beginning with\ntype.googleapis.com. As of May 2023, there are no widely used type server\nimplementations and no plans to implement one.\n\nSchemes other than `http`, `https` (or the empty scheme) might be\nused with implementation specific semantics."
      additionalProperties: {}
      description: "`Any` contains an arbitrary serialized protocol buffer message along with a\nURL that describes the type of the serialized message.\n\nProtobuf library provides support to pack/unpack Any values in the form\nof utility functions or additional generated methods of the Any type.\n\nExample 1: Pack and unpack a message in C++.\n\n    Foo foo = ...;\n    Any any;\n    any.PackFrom(foo);\n    ...\n    if (any.UnpackTo(&foo)) {\n      ...\n    }\n\nExample 2: Pack and unpack a message in Java.\n\n    Foo foo = ...;\n    Any any = Any.pack(foo);\n    ...\n    if (any.is(Foo.class)) {\n      foo = any.unpack(Foo.class);\n    }\n    // or ...\n    if (any.isSameTypeAs(Foo.getDefaultInstance())) {\n      foo = any.unpack(Foo.getDefaultInstance());\n    }\n\n Example 3: Pack and unpack a message in Python.\n\n    foo = Foo(...)\n    any = Any()\n    any.Pack(foo)\n    ...\n    if any.Is(Foo.DESCRIPTOR):\n      any.Unpack(foo)\n      ...\n\n Example 4: Pack and unpack a message in Go\n\n     foo := &pb.Foo{...}\n     any, err := anypb.New(foo)\n     if err != nil {\n       ...\n     }\n     ...\n     foo := &pb.Foo{}\n     if err := any.UnmarshalTo(foo); err != nil {\n       ...\n     }\n\nThe pack methods provided by protobuf library will by default use\n'type.googleapis.com/full.type.name' as the type URL and the unpack\nmethods only use the fully qualified type name after the last '/'\nin the type URL, for example \"foo.bar.com/x/y.z\" will yield type\nname \"y.z\".\n\nJSON\n====\nThe JSON representation of an `Any` value uses the regular\nrepresentation of the deserialized, embedded message, with an\nadditional field `@type` which contains the type URL. Example:\n\n    package google.profile;\n    message Person {\n      string first_name = 1;\n      string last_name = 2;\n    }\n\n    {\n      \"@type\": \"type.googleapis.com/google.profile.Person\",\n      \"firstName\": <string>,\n      \"lastName\": <string>\n    }\n\nIf the embedded message type is well-known and has a custom JSON\nrepresentation, that representation will be embedded adding a field\n`value` which holds the custom JSON in addition to the `@type`\nfield. Example (for message [google.protobuf.Duration][]):\n\n    {\n      \"@type\": \"type.googleapis.com/google.protobuf.Duration\",\n      \"value\": \"1.212s\"\n    }"
    v1GetExternalSyncResponse:
      type: object
      properties:
        success:
          type: boolean
        externalSync:
          $ref: '#/components/schemas/v1ExternalSync'
      required:
      - success
      - externalSync
    v1ExternalSync:
      type: object
      properties:
        organizationId:
          type: string
        mostRecentSyncDate:
          type: string
          format: date-time
        mostRecentSyncByUserId:
          type: string
        scimServerUrl:
          type: string
        tokenCreatedDate:
          type: string
          format: date-time
        tokenLifetimeSeconds:
          type: integer
          format: int64
        mostRecentTokenByUserId:
          type: string
      required:
      - scimServerUrl
      - tokenLifetimeSeconds
    v1GetExternalSyncRunResponse:
      type: object
      properties:
        externalSyncRun:
          $ref: '#/components/schemas/v1ExternalSyncRun'
      required:
      - externalSyncRun
    v1ExternalSyncRunSummary:
      type: object
      properties:
        externalSyncRunId:
          type: string
        syncedAt:
          type: string
          format: date-time
        triggerType:
          $ref: '#/components/schemas/v1ExternalSyncRunTriggerType'
        triggeredByUserId:
          type: string
        usersActivatedCount:
          type: integer
          format: int64
        usersDeactivatedCount:
          type: integer
          format: int64
        groupsCreatedCount:
          type: integer
          format: int64
        groupsDeletedCount:
          type: integer
          format: int64
        usersAddedToGroupsCount:
          type: integer
          format: int64
        usersRemovedFromGroupsCount:
          type: integer
          format: int64
      required:
      - externalSyncRunId
      - syncedAt
      - triggerType
      - usersActivatedCount
      - usersDeactivatedCount
      - groupsCreatedCount
      - groupsDeletedCount
      - usersAddedToGroupsCount
      - usersRemovedFromGroupsCount
    v1ExternalSyncToken:
      type: object
      properties:
        tokenId:
          type: string
        lifetimeSeconds:
          type: integer
          format: int64
        createdDate:
          type: string
          format: date-time
        createdByUserId:
          type: string
      description: The actual token value is not returned after it is first generated.
      required:
      - tokenId
      - lifetimeSeconds
      - createdDate
      - createdByUserId
    v1ExternalSyncMembershipChange:
      type: object
      properties:
        userId:
          type: string
        userName:
          type: string
        userGroupId:
          type: string
        groupName:
          type: string
      description: One membership edge that changed during the sync.
      required:
      - userId
      - userName
      - userGroupId
      - groupName
    v1ListExternalSyncTokensResponse:
      type: object
      properties:
        externalSyncTokens:
          type: array
          items:
            $ref: '#/components/schemas/v1ExternalSyncToken'
        nextPageToken:
          type: string
      required:
      - externalSyncTokens
    v1GenerateTokenResponse:
      type: object
      properties:
        externalSync:
          $ref: '#/components/schemas/v1ExternalSync'
        token:
          type: string
      required:
      - externalSync
      - token
    v1GenerateTokenRequest:
      type: object
    UserGroupResource:
      type: object
      properties:
        assetIds:
          type: array
          items:
            type: string
        allAssets:
          type: boolean
      required:
      - allAssets
    v1ExternalSyncUserRef:
      type: object
      properties:
        userId:
          type: string
        userName:
          type: string
      description: Sift user identity for display (user_name) and stable API use (user_id).
      required:
      - userId
      - userName
    v1SyncOrganizationResponse:
      type: object
      properties:
        externalSync:
          $ref: '#/components/schemas/v1ExternalSync'
        existingUserCount:
          type: integer
          format: int64
        addedToOrganizationUserIds:
          type: array
          items:
            type: string
        createdUsers:
          type: array
          items:
            $ref: '#/components/schemas/v1User'
        deactivatedUserIds:
          type: array
          items:
            type: string
        existingGroupCount:
          type: integer
          format: int64
        createdUserGroups:
          type: array
          items:
            $ref: '#/components/schemas/v2UserGroup'
        deletedUserGroupNames:
          type: array
          items:
            type: string
      required:
      - externalSync
      - existingUserCount
      - addedToOrganizationUserIds
      - createdUsers
      - deactivatedUserIds
      - existingGroupCount
      - createdUserGroups
      - deletedUserGroupNames
    v1ExternalSyncGroupRef:
      type: object
      properties:
        userGroupId:
          type: string
        groupName:
          type: string
      description: Sift user group identity for display (group_name) and stable API use (user_group_id).
      required:
      - userGroupId
      - groupName
    v1ExternalSyncRunDiff:
      type: object
      properties:
        usersActivated:
          type: array
          items:
            $ref: '#/components/schemas/v1ExternalSyncUserRef'
        usersDeactivated:
          type: array
          items:
            $ref: '#/components/schemas/v1ExternalSyncUserRef'
        groupsCreated:
          type: array
          items:
            $ref: '#/components/schemas/v1ExternalSyncGroupRef'
        groupsDeleted:
          type: array
          items:
            $ref: '#/components/schemas/v1ExternalSyncGroupRef'
        usersAddedToGroups:
          type: array
          items:
            $ref: '#/components/schemas/v1ExternalSyncMembershipChange'
        usersRemovedFromGroups:
          type: array
          items:
            $ref: '#/components/schemas/v1ExternalSyncMembershipChange'
      description: 'Snapshot of membership and lifecycle changes from one external sync run.

        Identifiers are Sift `user_id` / `user_group_id` UUIDs and human-readable names as stored in Sift

        (not Keycloak SCIM ids). Older stored runs may have empty ids with names only.'
      required:
      - usersActivated
      - usersDeactivated
      - groupsCreated
      - groupsDeleted
      - usersAddedToGroups
      - usersRemovedFromGroups
    v2UserGroup:
      type: object
      properties:
        userGroupId:
          type: string
        name:
          type: string
        roleId:
          type: string
        isDefault:
          type: boolean
        resources:
          $ref: '#/components/schemas/UserGroupResource'
        userIds:
          type: array
          items:
            type: string
        isExternal:
          type: boolean
      required:
      - name
      - isDefault
      - isExternal
    v1ExternalSyncRunTriggerType:
      type: string
      enum:
      - EXTERNAL_SYNC_RUN_TRIGGER_TYPE_UNSPECIFIED
      - EXTERNAL_SYNC_RUN_TRIGGER_TYPE_MANUAL_USER
      - EXTERNAL_SYNC_RUN_TRIGGER_TYPE_SCHEDULED
      default: EXTERNAL_SYNC_RUN_TRIGGER_TYPE_UNSPECIFIED
      description: ' - EXTERNAL_SYNC_RUN_TRIGGER_TYPE_MANUAL_USER: User triggered sync via the Sift UI or API.'
    v1GetIsOrgExternallyProvisionedResponse:
      type: object
      properties:
        isExternallyProvisioned:
          type: boolean
      required:
      - isExternallyProvisioned
    v1ExternalSyncRun:
      type: object
      properties:
        externalSyncRunId:
          type: string
        syncedAt:
          type: string
          format: date-time
        triggerType:
          $ref: '#/components/schemas/v1ExternalSyncRunTriggerType'
        triggeredByUserId:
          type: string
        diff:
          $ref: '#/components/schemas/v1ExternalSyncRunDiff'
      required:
      - externalSyncRunId
      - syncedAt
      - triggerType
      - diff
    rpcStatus:
      type: object
      properties:
        code:
          type: integer
          format: int32
        message:
          type: string
        details:
          type: array
          items:
            $ref: '#/components/schemas/protobufAny'
    v1Organization:
      type: object
      properties:
        organizationId:
          type: string
        organizationName:
          type: string
        isAbacEnabled:
          type: boolean
      required:
      - organizationId
      - organizationName
    v1ListExternalSyncRunsResponse:
      type: object
      properties:
        externalSyncRunSummaries:
          type: array
          items:
            $ref: '#/components/schemas/v1ExternalSyncRunSummary'
        nextPageToken:
          type: string
      required:
      - externalSyncRunSummaries
    v1User:
      type: object
      properties:
        userId:
          type: string
        userName:
          type: string
        organizations:
          type: array
          items:
            $ref: '#/components/schemas/v1Organization'
      required:
      - userId
      - userName
    v1SyncOrganizationRequest:
      type: object
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT