Users¶
User defines a subject entitled to connect to servers within monitored IT infrastructure. Detailed object definition (i.e. unique login and domain combination, full name, email address etc.) enables precise accountability of user actions when login and password are substituted with a shared account login credentials.
Data Structures: UserModel¶
Attribute |
Type |
Required |
Description |
|---|---|---|---|
|
string |
yes |
Read-only object identifier. Requires |
|
string |
yes |
Unique user’s name |
|
boolean; default value |
yes |
|
|
string |
||
|
string |
User’s domain |
|
|
string-array |
Read-only |
|
|
string |
User’s full name |
|
|
string |
User’s email address |
|
|
string |
User’s organization name |
|
|
string |
User’s phone number |
|
|
string |
User’s AD domain. Also used as the UPN suffix when the user is identified during an OpenID Connect sign-in. |
|
|
string |
User’s LDAP base |
|
|
string; default value |
yes |
Interface language |
|
datetime |
Read-only |
|
|
string |
Read-only |
|
|
datetime |
Read-only |
|
|
string |
Read-only |
|
|
datetime |
Read-only |
|
|
string |
Read-only |
|
|
number; default value |
yes |
Number of authentication failures |
|
boolean; default value |
yes |
Enable password complexity settings |
|
boolean; default value |
yes |
|
|
boolean; default value |
yes |
|
|
boolean |
Read-only |
|
|
boolean |
Read-only |
|
|
string |
Unique external identifier |
|
|
string |
Unique SCIM username (case-insensitive) |
|
|
string |
Type of the email address provisioned over SCIM, for example |
|
|
string |
Type of the phone number provisioned over SCIM, for example |
|
|
string |
||
|
string |
||
|
datetime (h:m:s); default value |
yes |
Beginning access time |
|
datetime (h:m:s); default value |
yes |
Ending access time |
|
string |
Id of the user’s LDAP server |
|
|
string |
||
|
string |
Read-only |
|
|
string {disabled, invited, untrusted, trusted} |
Read-only. Fudo ShareAccess membership state, derived from the user’s |
|
|
string |
Read-only. Fudo ShareAccess user name (the |
|
|
string |
Read-only. Id of the |
|
|
string |
Read-only; expensive to use. SHA256 fingerprint of the user’s Fudo ShareAccess key pair. |
|
|
object-array |
OpenID Connect sub claims. Read-only; expensive to use. |
|
|
object-array |
Read-only; expensive to use. |
|
|
string-array |
Read-only; hidden; expensive to use. |
|
|
string-array |
Read-only; hidden; expensive to use. |
|
|
object-array |
Read-only; expensive to use; JSON object array containing |
|
|
string-array |
Read-only; hidden; expensive to use |
|
|
string-array |
Read-only; hidden; expensive to use |
|
|
string-array |
IDs of the groups the user belongs to. Read-only; hidden; expensive to use. |
|
|
object-array |
Read-only; expensive to use; JSON object array containing |
|
|
string-array |
Types of authentication methods used by this user. Read-only; hidden; expensive to use. |
|
|
string-array |
IDs of external authentications used by this user. Read-only; hidden; expensive to use. |
|
|
string |
AI analysis context. Given to the AI that analyzes this user’s sessions. Describe what is normal here so expected activity is not flagged as a risk. |
|
|
string-array |
Read-only; list of rights the subject has to this object. |
|
|
boolean; default value |
yes |
If the user is enabled in the PSM module. Value false disables licence auto-activation. |
|
datetime |
Timestamp of the last activity of the user in the PSM module. Last established session or secret checkout via account. Read-only. |
|
|
string {active, inactive, disabled} |
yes |
User activation status in the PSM module. Read-only; expensive to use. |
|
boolean; default value |
yes |
If the user is enabled in the Vault module. Value false disables licence auto-activation. |
|
datetime |
Timestamp of the last activity of the user in the Vault module. Last secret checkout in password vault. Read-only. |
|
|
string {active, inactive, disabled} |
yes |
User activation status in the Vault module. Read-only; expensive to use. |
|
datetime |
Read-only. Timestamp of creation. |
|
|
datetime |
Read-only. Timestamp of modification. |
|
|
boolean |
Read-only |
|
|
boolean |
Read-only; expensive to use; if |
|
|
boolean |
Read-only; expensive to use; if |
Get Available Attributes of the UserModel¶
Request
Method |
|
Path |
|
Data Structures: UserSafeAssignmentModel¶
Attribute |
Type |
Required |
Description |
|---|---|---|---|
|
string |
yes |
Read-only object Identifier. |
|
string |
yes |
Immutable. Uniqueness is required in the combination of attribute |
|
object-array |
Read-only; expensive to use. |
|
|
string-array |
Read-only; hidden; expensive to use. |
|
|
string-array |
Read-only; hidden; expensive to use. |
|
|
string |
yes |
Immutable. Uniqueness is required in the combination of attribute |
|
boolean; default value |
yes |
Access to this safe is disabled for the user. |
|
number |
||
|
boolean; default value |
yes |
Allow a user to use Secret Checkout feature and view passwords in the User Access Gateway. |
|
string |
Read-only; expensive to use. Checksum computed from time policies used for this user-safe connection. |
|
|
boolean; default value |
yes |
Enables the daily access policy for this user-safe connection. On a Safe with |
|
datetime (h:m:s); default value |
yes |
Beginning access time. |
|
datetime (h:m:s); default value |
yes |
Ending access time. |
|
string |
Read-only; expensive to use. |
|
|
string |
Read-only; expensive to use. |
|
|
string |
Read-only; expensive to use. |
|
|
string |
Read-only; expensive to use. |
|
|
string |
Read-only; expensive to use. |
|
|
boolean |
Read-only; expensive to use; |
|
|
boolean |
Read-only; expensive to use; |
|
|
datetime |
Read-only. |
|
|
datetime |
Read-only. |
|
|
boolean |
Read-only. |
|
|
boolean |
Read-only; expensive to use; if |
|
|
boolean |
Read-only; expensive to use; if |
Retrieve Available Attributes of the UserSafeAssignmentModel¶
Request
Method |
|
Path |
|
Data Structures: UserSafeTimePolicyAssignmentModel¶
Attribute |
Type |
Required |
Description |
|---|---|---|---|
|
string |
yes |
Read-only object Identifier. |
|
string |
Read-only object Identifier. |
|
|
string |
yes |
Immutable. Requires |
|
string |
yes |
Immutable. Requires |
|
string |
Read-only; expensive to use. |
|
|
string |
Read-only; expensive to use. |
|
|
string |
Read-only; expensive to use. |
|
|
number |
yes |
Value range from |
|
datetime (h:m:s) |
yes |
Beginning access time. |
|
datetime (h:m:s) |
yes |
Ending access time. |
|
datetime |
Read-only. |
|
|
datetime |
Read-only. |
|
|
boolean |
Read-only. |
Retrieve Available Attributes of the UserSafeTimePolicy - AssignmentModel¶
Request
Method |
|
Path |
|
To check allowed methods, available URL parameters and possible responses please refer to the API Overview section.
Refer to the Batch operations topic to create nested requests for operating on the User objects.
Create a User¶
Request
Method |
|
Path |
|
Headers |
|
Body |
|
Example Request
POST /api/v2/user
{
"role": "user",
"name": "test-user",
"language":"en"
}
Response
{
"result": "success",
"user": {
"id": "12345678901234567890"
}}
Get Users List¶
Request
Method |
|
Path |
|
Example Request
GET /api/v2/user
Response
{
"result": "success",
"user": [
{
"id": "1234567891012345",
"name": "tet",
"blocked": false,
"role": "user",
"full_name": "",
"email": "",
"phone": "",
"ad_domain": "",
"ldap_base": "",
"language": "en",
"failures": 0,
"password_complexity": false,
"external_sync": false,
"valid_since": "-infinity",
"valid_to": "infinity",
"created_at": "2022-10-20 02:09:49.818029-07",
"modified_at": "2022-10-20 02:09:49.818029-07"
},
{
"id": "12345678910123456",
"name": "admin",
"blocked": false,
"role": "superadmin",
"language": "en",
"previous_success": "2022-10-25 05:33:19.377878-07",
"last_success": "2022-10-25 06:03:39.084783-07",
"last_failure": "2022-10-24 04:19:35.204557-07",
"failures": -1,
"password_complexity": false,
"external_sync": false,
"valid_since": "-infinity",
"valid_to": "infinity",
"created_at": "2022-10-20 02:01:32.093269-07",
"modified_at": "2022-10-25 06:03:39.085472-07"
}
]}
Get a User¶
Request
Method |
|
Path |
|
Modify a User¶
Request
Method |
|
Path |
|
Headers |
|
Body |
|
Example Request: Changing User Login
PATCH /api/v2/user/<id>
{
"name": "new-user"
}
Response
{ "result": "success"}
Example Request: Blocking a User
PATCH /api/v2/user/<id>
{"blocked": true,
"reason": "lost rights"}
Response
{ "result": "success" }
Get User-Safe Assignments List¶
Request
Method |
|
Path |
|
Create a User-Safe Assignment¶
Request
Method |
|
Path |
|
Body |
|
Example Request
POST /api/v2/user/safe
{ "user_id": "1232678819172646915",
"safe_id": "1232678819172646913" }
Response
{ "result": "success",
"user_safe": {} }
Get Users’ Time Policy Settings Within Safes¶
Request
Method |
|
Path |
|
Example Request
GET /api/v2/user/safe/time_policy
Response (User’s time policy is declared separately for each day)
{
"result": "success",
"user_safe_time_policy": [
{
"id": "4602678819172646913",
"safe_id": "4602678819172646913",
"user_id": "4602678819172646914",
"day_of_week": 2, <--- A user has access to the safe on Tuesday
"valid_from": "09:00:00", <--- User's access starts at 9:00
"valid_to": "14:00:00", <--- and ends at 14:00
"created_at": "2022-10-26 02:25:19.155648-07",
"modified_at": "2022-10-26 02:30:40.677788-07"
},
{
"id": "4602678819172646914",
"safe_id": "4602678819172646913",
"user_id": "4602678819172646914",
"day_of_week": 3, <--- A user has access to the safe on Wednesday
"valid_from": "09:15:00", <--- User's access starts at 9:15
"valid_to": "14:15:00", <--- and ends at 14:15
"created_at": "2022-10-26 02:32:11.781045-07",
"modified_at": "2022-10-26 02:32:11.781045-07"
}]}
Get Users’ Time Policy Settings Within Safes by ID¶
Request
Method |
|
Path |
|
Example Request
GET /api/v2/user/safe/time_policy/<id>
Response (User’s time policy is declared separately for each day)
{
"result": "success",
"user_safe_time_policy": [
{
"id": "4602678819172646914",
"safe_id": "4602678819172646913",
"user_id": "4602678819172646914",
"day_of_week": 3, <--- A user has access to the safe on Wednesday
"valid_from": "09:15:00", <--- User's access starts at 9:15
"valid_to": "14:15:00", <--- and ends at 14:15
"created_at": "2022-10-26 02:32:11.781045-07",
"modified_at": "2022-10-26 02:32:11.781045-07"
}]}
Modify User’s Time Policy Settings Within a Safe¶
Request
Method |
|
Path |
|
Body |
|
Example Request: Changing the day of user’s access to Monday
PATCH /api/v2/user/safe/time_policy/<id>
{ "day_of_week": 1}
Response
{ "result": "success" }
Create User’s Time Policy Settings Within a Safe¶
Request
Method |
|
Path |
|
Body |
|
Example Request: Creating User’s Access to the the Safe for Thursday From 16:00 Till 23:00
POST /api/v2/user/safe/time_policy
{ "user_id": "1232678819172646915",
"safe_id": "1232678819172646913",
"day_of_week": 4,
"valid_from": "16:00:00",
"valid_to": "23:00:00"
}
Response
{ "result": "success",
"user_safe_time_policy": {
"id": "1232678819172646915" }}
Delete User’s Time Policy Settings Within a Safe¶
Request
Method |
|
Path |
|
Delete User-Safe Assignment¶
Request
Method |
|
Path |
|
Delete User¶
Request
Method |
|
Path |
|