Tenable Profile API

A set of Checker option value

Operations 8

GET /api/profiles Retrieve all profile instances #
POST /api/profiles Create profile instance #
GET /api/profiles/{id} Get profile instance by id #
PATCH /api/profiles/{id} Update profile instance #
DELETE /api/profiles/{id} Delete profile instance #
POST /api/profiles/from/{fromId} Creates a new profile from another one #
POST /api/profiles/{id}/unstage Unstages change of the related profile #
POST /api/profiles/{id}/commit Commits change of the related profile #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/tenable-profile-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

tenable-profile-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Identity Exposure Profile API
  description: API to interact with Identity Exposure.
  version: production
servers:
- url: '{protocol}://customer.tenable.ad'
  variables:
    protocol:
      default: https
tags:
- name: Profile
  description: A set of Checker option value
paths:
  /api/profiles:
    get:
      summary: Retrieve all profile instances
      description: 'Required license type: ioe, ioa, ioaPreview'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: Validates the get /profiles response
                type: array
                items:
                  description: Profile
                  type: object
                  additionalProperties: false
                  required:
                  - id
                  - name
                  - deleted
                  - directories
                  - dirty
                  - hasEverBeenCommitted
                  properties:
                    id:
                      type: number
                      description: Unique numeric identifier of the profile
                    name:
                      type: string
                      description: User-defined name of the profile
                    deleted:
                      type: boolean
                      deprecated: true
                      description: Deprecated, profiles aren't soft-deleted anymore.
                    directories:
                      type: array
                      items:
                        type: number
                      deprecated: true
                      description: Deprecated, used to indicates which directories the profile applied to. See "directoryId" property in indicator options instead.
                      x-$comment: TO REMOVE once this field is not used anymore. Delete key DIRECTORY_PER_PROFILE
                    dirty:
                      type: boolean
                      description: Whether there are pending changes in the profile options
                    hasEverBeenCommitted:
                      type: boolean
                      description: Whether the profile has ever been applied
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - Profile
      x-tenablead-required-product-license-type:
      - ioe
      - ioa
      - ioaPreview
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      security:
      - ApiKey: []
      operationId: getApiProfiles
      x-operation-id-source: derived
    post:
      summary: Create profile instance
      description: 'Required license type: ioe, ioa, ioaPreview'
      responses:
        '201':
          description: ''
          content:
            application/json:
              schema:
                description: Validates the get /profiles response
                type: array
                minItems: 1
                items:
                  description: Profile
                  type: object
                  additionalProperties: false
                  required:
                  - id
                  - name
                  - deleted
                  - directories
                  - dirty
                  - hasEverBeenCommitted
                  properties:
                    id:
                      type: number
                      description: Unique numeric identifier of the profile
                    name:
                      type: string
                      description: User-defined name of the profile
                    deleted:
                      type: boolean
                      deprecated: true
                      description: Deprecated, profiles aren't soft-deleted anymore.
                    directories:
                      type: array
                      items:
                        type: number
                      deprecated: true
                      description: Deprecated, used to indicates which directories the profile applied to. See "directoryId" property in indicator options instead.
                      x-$comment: TO REMOVE once this field is not used anymore. Delete key DIRECTORY_PER_PROFILE
                    dirty:
                      type: boolean
                      description: Whether there are pending changes in the profile options
                    hasEverBeenCommitted:
                      type: boolean
                      description: Whether the profile has ever been applied
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - Profile
      x-tenablead-required-product-license-type:
      - ioe
      - ioa
      - ioaPreview
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      security:
      - ApiKey: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              description: Profile
              type: array
              minItems: 1
              items:
                type: object
                additionalProperties: false
                required:
                - name
                - directories
                properties:
                  name:
                    type: string
                    pattern: ^(?!([tT][eE][nN][aA][bB][lL][eE])$).*$
                  directories:
                    type: array
                    items:
                      type: integer
      operationId: postApiProfiles
      x-operation-id-source: derived
  /api/profiles/{id}:
    get:
      summary: Get profile instance by id
      description: 'Required license type: ioe, ioa, ioaPreview'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: Profile
                type: object
                additionalProperties: false
                required:
                - id
                - name
                - deleted
                - directories
                - dirty
                - hasEverBeenCommitted
                properties:
                  id:
                    type: number
                  name:
                    type: string
                  deleted:
                    type: boolean
                  directories:
                    type: array
                    items:
                      type: number
                  dirty:
                    type: boolean
                  hasEverBeenCommitted:
                    type: boolean
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - Profile
      x-tenablead-required-product-license-type:
      - ioe
      - ioa
      - ioaPreview
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: id
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      security:
      - ApiKey: []
      operationId: getApiProfilesById
      x-operation-id-source: derived
    patch:
      summary: Update profile instance
      description: 'Required license type: ioe, ioa, ioaPreview'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: Profile
                type: object
                additionalProperties: false
                required:
                - id
                - name
                - deleted
                - directories
                - dirty
                - hasEverBeenCommitted
                properties:
                  id:
                    type: number
                  name:
                    type: string
                  deleted:
                    type: boolean
                  directories:
                    type: array
                    items:
                      type: number
                  dirty:
                    type: boolean
                  hasEverBeenCommitted:
                    type: boolean
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - Profile
      x-tenablead-required-product-license-type:
      - ioe
      - ioa
      - ioaPreview
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: id
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      security:
      - ApiKey: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              description: Profile
              type: object
              additionalProperties: false
              properties:
                name:
                  type: string
                  pattern: ^(?!([tT][eE][nN][aA][bB][lL][eE])$).*$
                deleted:
                  type: boolean
                directories:
                  type: array
                  items:
                    type: number
                    minimum: 0
                    maximum: 2147483647
      operationId: patchApiProfilesById
      x-operation-id-source: derived
    delete:
      summary: Delete profile instance
      description: 'Required license type: ioe, ioa, ioaPreview'
      responses:
        '204':
          description: ''
          content:
            application/json:
              schema:
                description: Profile
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - Profile
      x-tenablead-required-product-license-type:
      - ioe
      - ioa
      - ioaPreview
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: id
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      security:
      - ApiKey: []
      operationId: deleteApiProfilesById
      x-operation-id-source: derived
  /api/profiles/from/{fromId}:
    post:
      summary: Creates a new profile from another one
      description: 'Required license type: ioe, ioa, ioaPreview'
      responses:
        '204':
          description: ''
          content:
            application/json:
              schema:
                description: Validates the POST /profiles/from/{fromId} response
                type: object
                additionalProperties: false
                required:
                - id
                - name
                - deleted
                - directories
                - dirty
                - hasEverBeenCommitted
                properties:
                  id:
                    type: number
                    description: Unique numeric identifier of the profile
                  name:
                    type: string
                    description: User-defined name of the profile
                  deleted:
                    type: boolean
                    deprecated: true
                    description: Deprecated, profiles aren't soft-deleted anymore.
                  directories:
                    type: array
                    items:
                      type: number
                    deprecated: true
                    description: Deprecated, used to indicates which directories the profile applied to. See "directoryId" property in indicator options instead.
                    x-$comment: TO REMOVE once this field is not used anymore. Delete key DIRECTORY_PER_PROFILE
                  dirty:
                    type: boolean
                    description: Whether there are pending changes in the profile options
                  hasEverBeenCommitted:
                    type: boolean
                    description: Whether the profile has ever been applied
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - Profile
      x-tenablead-required-product-license-type:
      - ioe
      - ioa
      - ioaPreview
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: fromId
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      security:
      - ApiKey: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              description: Profile
              type: object
              additionalProperties: false
              required:
              - name
              - directories
              properties:
                name:
                  type: string
                  pattern: ^(?!([tT][eE][nN][aA][bB][lL][eE])$).*$
                directories:
                  type: array
                  items:
                    type: integer
      operationId: postApiProfilesFromByFromId
      x-operation-id-source: derived
  /api/profiles/{id}/unstage:
    post:
      summary: Unstages change of the related profile
      description: 'Required license type: ioe, ioa, ioaPreview'
      responses:
        '204':
          description: ''
          content:
            application/json:
              schema:
                description: Profile
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - Profile
      x-tenablead-required-product-license-type:
      - ioe
      - ioa
      - ioaPreview
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: id
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      security:
      - ApiKey: []
      operationId: postApiProfilesByIdUnstage
      x-operation-id-source: derived
  /api/profiles/{id}/commit:
    post:
      summary: Commits change of the related profile
      description: 'Required license type: ioe, ioa, ioaPreview'
      responses:
        '204':
          description: ''
          content:
            application/json:
              schema:
                description: Profile
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - Profile
      x-tenablead-required-product-license-type:
      - ioe
      - ioa
      - ioaPreview
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: id
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      security:
      - ApiKey: []
      operationId: postApiProfilesByIdCommit
      x-operation-id-source: derived
components:
  securitySchemes:
    ApiKey:
      name: x-api-key
      description: The user's API key
      in: header
      type: apiKey
x-readme:
  explorer-enabled: true
  proxy-enabled: true