Tenable User API

A Tenable.ad user

Operations 10

GET /api/users Get all users #
POST /api/users Create user instance #
GET /api/users/whoami Get a user's information #
GET /api/users/{id} Get user instance by id #
PATCH /api/users/{id} Update user instance #
DELETE /api/users/{id} Delete user instance #
PATCH /api/users/password Update a user's password #
POST /api/login Logs in a user #
POST /api/logout Logs out a user #
PUT /api/users/{id}/roles Replace role list for a user #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/tenable-user-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

tenable-user-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Identity Exposure User API
  description: API to interact with Identity Exposure.
  version: production
servers:
- url: '{protocol}://customer.tenable.ad'
  variables:
    protocol:
      default: https
tags:
- name: User
  description: A Tenable.ad user
paths:
  /api/users:
    get:
      summary: Get all users
      description: 'Required license type: none'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: Validates the get /users response
                type: array
                items:
                  description: User
                  type: object
                  additionalProperties: false
                  required:
                  - id
                  - name
                  - email
                  - roles
                  - eulaVersion
                  - identifier
                  - provider
                  - lockedOut
                  properties:
                    id:
                      type: number
                    surname:
                      type:
                      - string
                      - 'null'
                    name:
                      type: string
                    email:
                      type: string
                    lockedOut:
                      type: boolean
                    department:
                      type:
                      - string
                      - 'null'
                    biography:
                      type:
                      - string
                      - 'null'
                    active:
                      type: boolean
                    roles:
                      type: array
                      items:
                        type: number
                    identifier:
                      type: string
                    provider:
                      description: User auth provider
                      type: string
                      enum:
                      - tenable
                      - ldap
                      - saml
                      - tone
                    eulaVersion:
                      type: number
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - User
      x-tenablead-required-product-license-type: []
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      security:
      - ApiKey: []
      operationId: getApiUsers
      x-operation-id-source: derived
    post:
      summary: Create user instance
      description: 'Required license type: none'
      responses:
        '201':
          description: ''
          content:
            application/json:
              schema:
                description: Validates the get /users response
                type: array
                minItems: 1
                items:
                  description: User
                  type: object
                  additionalProperties: false
                  required:
                  - id
                  - name
                  - email
                  - roles
                  - eulaVersion
                  - identifier
                  - provider
                  - lockedOut
                  properties:
                    id:
                      type: number
                    surname:
                      type:
                      - string
                      - 'null'
                    name:
                      type: string
                    email:
                      type: string
                    lockedOut:
                      type: boolean
                    department:
                      type:
                      - string
                      - 'null'
                    biography:
                      type:
                      - string
                      - 'null'
                    active:
                      type: boolean
                    roles:
                      type: array
                      items:
                        type: number
                    identifier:
                      type: string
                    provider:
                      description: User auth provider
                      type: string
                      enum:
                      - tenable
                      - ldap
                      - saml
                      - tone
                    eulaVersion:
                      type: number
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - User
      x-tenablead-required-product-license-type: []
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      security:
      - ApiKey: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              description: Validates the POST /users request
              type: array
              minItems: 1
              items:
                type: object
                additionalProperties: false
                required:
                - name
                - password
                - email
                properties:
                  surname:
                    type: string
                  name:
                    type: string
                  email:
                    type: string
                  password:
                    description: User password (one lowercase, one uppercase, one number & one special character)
                    type: string
                    pattern: ^(?=.*\d)(?=.*[a-z])(?=.*[A-Z])(?=.*\W).{12,}$
                    minLength: 12
                    x-secret: true
                  department:
                    type: string
                  biography:
                    type: string
                  active:
                    type: boolean
                    default: false
      operationId: postApiUsers
      x-operation-id-source: derived
  /api/users/whoami:
    get:
      summary: Get a user's information
      description: 'Required license type: none'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: User
                type: object
                additionalProperties: false
                required:
                - id
                - name
                - email
                - roles
                - eulaVersion
                - internal
                - provider
                - tenableCloudUserName
                properties:
                  id:
                    type: number
                  surname:
                    type:
                    - string
                    - 'null'
                  name:
                    type: string
                  email:
                    type: string
                  provider:
                    type: string
                  lockedOut:
                    type: boolean
                  department:
                    type:
                    - string
                    - 'null'
                  roles:
                    type: array
                    items:
                      description: Role
                      type: object
                      additionalProperties: false
                      required:
                      - id
                      - name
                      - description
                      - permissions
                      properties:
                        id:
                          type: number
                        name:
                          type: string
                        description:
                          type: string
                        permissions:
                          type: array
                          items:
                            description: Permission
                            type: object
                            additionalProperties: false
                            required:
                            - entityIds
                            - action
                            - entityName
                            properties:
                              entityName:
                                type: string
                              action:
                                type: string
                              entityIds:
                                type:
                                - array
                                - 'null'
                                items:
                                  type: string
                              dynamicId:
                                type:
                                - string
                                - 'null'
                                enum:
                                - self-user-id
                                - null
                                default: null
                  biography:
                    type:
                    - string
                    - 'null'
                  active:
                    type: boolean
                  identifier:
                    type: string
                  eulaVersion:
                    type: number
                  internal:
                    type: boolean
                  tenableCloudUserName:
                    type:
                    - string
                    - 'null'
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - User
      x-tenablead-required-product-license-type: []
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      security:
      - ApiKey: []
      operationId: getApiUsersWhoami
      x-operation-id-source: derived
  /api/users/{id}:
    get:
      summary: Get user instance by id
      description: 'Required license type: none'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: User
                type: object
                additionalProperties: false
                required:
                - id
                - name
                - email
                - roles
                - eulaVersion
                - identifier
                - provider
                - lockedOut
                properties:
                  id:
                    type: number
                  surname:
                    type:
                    - string
                    - 'null'
                  name:
                    type: string
                  email:
                    type: string
                  lockedOut:
                    type: boolean
                  department:
                    type:
                    - string
                    - 'null'
                  biography:
                    type:
                    - string
                    - 'null'
                  active:
                    type: boolean
                  roles:
                    type: array
                    items:
                      type: number
                  identifier:
                    type: string
                  provider:
                    description: User auth provider
                    type: string
                    enum:
                    - tenable
                    - ldap
                    - saml
                    - tone
                  eulaVersion:
                    type: number
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - User
      x-tenablead-required-product-license-type: []
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: id
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      security:
      - ApiKey: []
      operationId: getApiUsersById
      x-operation-id-source: derived
    patch:
      summary: Update user instance
      description: 'Required license type: none'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: User
                type: object
                additionalProperties: false
                required:
                - id
                - name
                - email
                - roles
                - eulaVersion
                - identifier
                - provider
                - lockedOut
                properties:
                  id:
                    type: number
                  surname:
                    type:
                    - string
                    - 'null'
                  name:
                    type: string
                  email:
                    type: string
                  lockedOut:
                    type: boolean
                  department:
                    type:
                    - string
                    - 'null'
                  biography:
                    type:
                    - string
                    - 'null'
                  active:
                    type: boolean
                  roles:
                    type: array
                    items:
                      type: number
                  identifier:
                    type: string
                  provider:
                    description: User auth provider
                    type: string
                    enum:
                    - tenable
                    - ldap
                    - saml
                    - tone
                  eulaVersion:
                    type: number
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - User
      x-tenablead-required-product-license-type: []
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: id
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      security:
      - ApiKey: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              description: User
              type: object
              additionalProperties: false
              properties:
                surname:
                  type: string
                name:
                  type: string
                password:
                  description: User password (one lowercase, one uppercase, one number & one special character)
                  type: string
                  pattern: ^(?=.*\d)(?=.*[a-z])(?=.*[A-Z])(?=.*\W).{12,}$
                  minLength: 12
                  x-secret: true
                email:
                  type: string
                department:
                  type: string
                biography:
                  type: string
                active:
                  type: boolean
                lockedOut:
                  type: boolean
                  enum:
                  - false
      operationId: patchApiUsersById
      x-operation-id-source: derived
    delete:
      summary: Delete user instance
      description: 'Required license type: none'
      responses:
        '204':
          description: ''
          content:
            application/json:
              schema:
                description: User
                additionalProperties: false
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - User
      x-tenablead-required-product-license-type: []
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: id
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      security:
      - ApiKey: []
      operationId: deleteApiUsersById
      x-operation-id-source: derived
  /api/users/password:
    patch:
      summary: Update a user's password
      description: 'Required license type: none'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: Validates the get /users response
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - User
      x-tenablead-required-product-license-type: []
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      security:
      - ApiKey: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              description: Validates the PUT /users/password request
              type: object
              additionalProperties: false
              required:
              - oldPassword
              - newPassword
              properties:
                oldPassword:
                  description: User password (one lowercase, one uppercase, one number & one special character)
                  type: string
                  pattern: ^(?=.*\d)(?=.*[a-z])(?=.*[A-Z])(?=.*\W).{12,}$
                  minLength: 12
                  x-secret: true
                newPassword:
                  description: User password (one lowercase, one uppercase, one number & one special character)
                  type: string
                  pattern: ^(?=.*\d)(?=.*[a-z])(?=.*[A-Z])(?=.*\W).{12,}$
                  minLength: 12
                  x-secret: true
      operationId: patchApiUsersPassword
      x-operation-id-source: derived
  /api/login:
    post:
      summary: Logs in a user
      description: 'Required license type: none'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                type: object
                additionalProperties: false
                required:
                - authToken
                - needPasswordReset
                properties:
                  authToken:
                    type: string
                    x-secret: true
                  needPasswordReset:
                    type: boolean
        '500':
          description: Internal server error
      tags:
      - User
      x-tenablead-required-product-license-type: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              description: User
              type: object
              additionalProperties: false
              required:
              - password
              - email
              properties:
                password:
                  type: string
                  minLength: 1
                  x-secret: true
                email:
                  type: string
                  minLength: 1
      operationId: postApiLogin
      x-operation-id-source: derived
  /api/logout:
    post:
      summary: Logs out a user
      description: 'Required license type: none'
      responses:
        '204':
          description: ''
          content:
            application/json:
              schema:
                enum:
                - 'null'
                - undefined
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - User
      x-tenablead-required-product-license-type: []
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      security:
      - ApiKey: []
      operationId: postApiLogout
      x-operation-id-source: derived
  /api/users/{id}/roles:
    put:
      summary: Replace role list for a user
      description: 'Required license type: none'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: Validates the POST /users/:userId/roles response
                type: object
                additionalProperties: false
                required:
                - roles
                properties:
                  roles:
                    type: array
                    items:
                      minItems: 1
                      type: integer
        '401':
          description: Unauthorized
        '500':
          description: Internal server error
      tags:
      - User
      x-tenablead-required-product-license-type: []
      parameters:
      - name: x-api-key
        description: The user's API key
        in: header
        schema:
          type: string
          default: put-your-api-key-here
        required: true
        deprecated: false
      - name: id
        in: path
        schema:
          type: string
          pattern: ^[0-9]+$
          x-patternError: should be a numerical string
        required: true
        deprecated: false
      security:
      - ApiKey: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              description: User roles
              type: object
              additionalProperties: false
              required:
              - roles
              properties:
                roles:
                  type: array
                  items:
                    minItems: 1
                    type: integer
      operationId: putApiUsersByIdRoles
      x-operation-id-source: derived
components:
  securitySchemes:
    ApiKey:
      name: x-api-key
      description: The user's API key
      in: header
      type: apiKey
x-readme:
  explorer-enabled: true
  proxy-enabled: true