Tenable Permissions API

The Permissions API from Tenable — 1 operation(s) for permissions.

Business capability
Identity & Access Management BC-620.20

Operations 2

GET /permissions/{object_type}/{object_id} Get object permissions #
PUT /permissions/{object_type}/{object_id} Update object permissions #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/tenable-permissions-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

tenable-permissions-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Tenable Platform & Settings Permissions API
  version: 1.0.0
servers:
- url: https://cloud.tenable.com
tags:
- name: Permissions
  x-displayName: Permissions
paths:
  /permissions/{object_type}/{object_id}:
    get:
      summary: Get object permissions
      description: 'Returns the object''s permissions.

        Requires the Basic [16] user role, or a custom role with one of the following privileges depending on the object type:

        * **Scanner objects** — `VM.VM_SENSOR.VM_SCANNER.READ`, `VM.VM_SENSOR.VM_WAS_SCANNER.READ`, or `VM.VM_SENSOR.VM_NETWORK_MONITOR.READ`

        * **Scanner-pool objects** — `VM.VM_SENSOR.SCANNER_GROUP.READ`

        * **Agent-group objects** — `VM.VM_SENSOR.AGENT_GROUP.READ`


        See Roles.'
      operationId: permissions-list
      tags:
      - Permissions
      parameters:
      - description: The type of object.
        required: true
        name: object_type
        in: path
        schema:
          type: string
          enum:
          - agent-group
          - policy
          - scan
          - scanner
      - description: The unique ID of the object.
        required: true
        name: object_id
        in: path
        schema:
          type: integer
          format: int32
      responses:
        '200':
          description: Returns the object permissions.
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/permissions_ACL_Response'
              examples:
                response:
                  value:
                    acls:
                    - type: user
                      id: 1
                      uuid: 1035e55d-a984-4b1c-acc7-fd2d472126f1
                      name: system
                      display_name: system
                      permissions: 128
                      owner: 1
                    - type: default
                      permissions: 16
        '401':
          description: Returned if the API keys specified in your request are invalid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/permissions_ErrorResponse'
              examples:
                response:
                  value:
                    statusCode: 401
                    error: Unauthorized
                    message: Invalid credentials.
        '403':
          description: Returned if you do not have permission to view the object.
        '404':
          description: Returned if Tenable Vulnerability Management cannot find the specified object.
        '429':
          description: Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](doc:rate-limiting).
          content:
            text/html:
              examples:
                response:
                  value: "<html>\n\n<head>\n    <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n    <center>\n        <h1>429 Too Many Requests</h1>\n    </center>\n    <hr>\n    <center>nginx</center>\n</body>\n\n</html>"
        '500':
          description: Returned if an internal error occurred.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/permissions_ErrorResponse'
              examples:
                response:
                  value:
                    statusCode: 500
                    error: Internal Server Error
                    message: An internal server error occurred. Please wait a moment and try your request again.
      security:
      - permissions_cloud: []
    put:
      summary: Update object permissions
      description: 'Updates the permissions for a Tenable Vulnerability Management object.

        Requires the Basic [16] user role, or a custom role with one of the following privileges depending on the object type:

        * **Scanner objects** — `VM.VM_SENSOR.VM_SCANNER.EDIT`

        * **Scanner-pool objects** — `VM.VM_SENSOR.SCANNER_GROUP.EDIT`

        * **Agent-group objects** — `VM.VM_SENSOR.AGENT_GROUP.EDIT`


        See Roles.'
      operationId: permissions-change
      tags:
      - Permissions
      parameters:
      - description: The type of object.
        required: true
        name: object_type
        in: path
        schema:
          type: string
          enum:
          - agent-group
          - policy
          - scan
          - scanner
      - description: The unique ID of the object (for example, scanner).
        required: true
        name: object_id
        in: path
        schema:
          type: integer
          format: int32
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                acls:
                  $ref: '#/components/schemas/permissions_ACL_Request'
      responses:
        '200':
          description: Returned if the object permissions were updated successfully.
          content:
            application/json:
              schema: {}
              examples:
                response:
                  value: {}
        '401':
          description: Returned if the API keys specified in your request are invalid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/permissions_ErrorResponse'
              examples:
                response:
                  value:
                    statusCode: 401
                    error: Unauthorized
                    message: Invalid credentials.
        '403':
          description: Returned if you do not have permission to edit the object.
        '404':
          description: Returned if Tenable Vulnerability Management cannot find the specified object.
        '429':
          description: Returned if you attempt to send too many requests in a specific period of time. For more information, see [Rate Limiting](doc:rate-limiting).
          content:
            text/html:
              examples:
                response:
                  value: "<html>\n\n<head>\n    <title>429 Too Many Requests</title>\n</head>\n\n<body bgcolor=\"white\">\n    <center>\n        <h1>429 Too Many Requests</h1>\n    </center>\n    <hr>\n    <center>nginx</center>\n</body>\n\n</html>"
        '500':
          description: Returned if an internal error occurred.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/permissions_ErrorResponse'
              examples:
                response:
                  value:
                    statusCode: 500
                    error: Internal Server Error
                    message: An internal server error occurred. Please wait a moment and try your request again.
      security:
      - permissions_cloud: []
components:
  schemas:
    permissions_ACL_Request:
      type: object
      properties:
        type:
          type: string
          description: The type of permission (default, user, group).
          enum:
          - default
          - user
          - group
        id:
          type: integer
          description: The unique ID of the user or group.
        permissions:
          type: integer
          description: The permission value to grant access as described in [Permissions](doc:permissions).
          format: int32
    permissions_ACL_Response:
      type: object
      properties:
        type:
          type: string
          description: The type of permission (default, user, group).
          enum:
          - default
          - user
          - group
        id:
          type: integer
          description: The unique ID of the user or group.
        uuid:
          type: string
          description: The UUID of the owner of the object.
        name:
          type: string
          description: The name of the user or group.
        display_name:
          type: string
          description: The display-friendly name of the user or group.
        permissions:
          type: integer
          description: The permission value to grant access as described in [Permissions](doc:permissions).
          format: int32
        owner:
          type: integer
          description: The ID of the owner of the object.
    permissions_ErrorResponse:
      type: object
      properties:
        statusCode:
          type: integer
          description: The HTTP status code of the error.
        error:
          type: string
          description: The standard HTTP error name.
        message:
          type: string
          description: A brief message about the cause of the error.
  securitySchemes:
    Access_Control_API_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Access_Control_Groups_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Access_Control_Permissions_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Access_Control_Roles_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Access_Control_Users_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    access-groups_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    access-groups_v2_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    activity-log_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    agents_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Agent_Config_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    agent-exclusions_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    agent-groups_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    agent-bulk-operations_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Cloud_Connectors_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    credentials_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    exclusions_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    networks_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    OT_Connectors_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    permissions_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Profiles_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    recast-rules_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Scanners_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Scanner_Config_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Scanner_Groups_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Scanner_Profiles_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    Scanner_Tasks_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    server_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    tags_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
    target-groups_cloud:
      type: apiKey
      in: header
      name: X-ApiKeys
      description: Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY
x-readme:
  proxy-enabled: false
  samples-languages:
  - python
  - curl
  - node
  - powershell
  - ruby
  - javascript
  - objectivec
  - java
  - php
  - csharp
  - go
  - swift
  - kotlin