Fudo Enterprise 6.2 - API Documentation¶
Welcome!
The following are the enhancements and modifications introduced in version 6.2 of Fudo Enterprise.
AI Session Analysis:
LLM Providers 🆕 - configure the large language model endpoints the analysis runs on
AI Session Analysis Agents 🆕 - define the agents, attach them to safes and switch live analysis on
AI Session Analysis Results 🆕 - read the per-agent analyses and their verdicts, and adjudicate a verdict
Access Control:
Location Policies 🆕 - allow or block connections by country and network, applied to users through groups
Group-Derived Safe Access Policies 🆕 - narrow a single user’s group-derived access to a safe, with its own time policy
Access Request Reason Formats 🆕 - require access request reasons to follow a predefined set of fields
System Management:
Hardware Security Module 🆕 - store the master key in a hardware security module over PKCS#11
Secret Audit 🆕 - check password vault secrets against a database of compromised passwords
JWT Provider Management 🆕 - accept JSON Web Tokens issued by an external identity provider
Session Sharing:
Session Access History 🆕 - access history of a shared session, with identity, source address and view times
UAG - Session Sharing 🆕 and UAG - Session Share Access 🆕 - users share their own live sessions from the User Access Gateway
UAG - Live Sessions 🆕 and UAG - Shared Session Details 🆕 - watch a shared session and read its details
UAG - Session Resolution 🆕 and UAG - Session Comments 🆕 - resolve a share key to a session and comment on it
User Access Gateway Enhancements:
UAG - Change Password 🆕 - users change their own password from the portal
UAG - Access Request Reason Formats 🆕 - read the reason formats a request must follow
Updates to Existing Object Specifications:
Oracle protocol added to the protocol lists of Listeners, Servers, Sessions Management and Push Notifications, and to their TLS conditions
Session: live analysis results (
analysis_status,analysis_severity,analysis_peak_severity,analysis_summary,analysis_verdict_count),listener_hidden, and the newwaiting_supervisionstatusSafe:
jit_modefor time-based Just-in-Time approval,rdp_cliprdr_filesandrdp_sndrec, live sharing and supervision (allow_user_sharing,live_supervision_required,min_supervisors),analysis_contextUser: the Fudo ShareAccess attributes moved to the
fnetauthentication method - see the warning below - plusanalysis_context,group_ids,scim_email_typeandscim_phone_typeUser Authentication Method: new
fnettype carrying the Fudo ShareAccess identity, with itsfn_*attributesListener:
rdp_legacyselects the previous RDP engine; new listeners use FreeRDP 3Server:
tls_verify_hostnameandanalysis_contextOpenID Connect:
scopefor custom scopes sent to the identity providerPolicy: new
live_analysistype withlive_analysis_min_countandlive_analysis_min_severity;session_live_analysisadded to the notification and push event namesGroup-Safe Assignment:
blocked,valid_sinceandvalid_to, matching the user-safe assignment
Warning
The following endpoints were deprecated and have been removed. Please update your integrations accordingly:
GET /objspec/discovery
PATCH /account/<account_id>/discovery
PATCH /server/<server_id>/discovery
The following changes to existing object specifications are not backwards compatible:
User:
pubkey_ec,pubkey_rsa,pubkey_fingerprint,pubkey_trusted_by,pubkey_trusted_at,invite_code,invite_code_expires_at,invited_byandfudo_networkare gone from theUserModel. They are replaced byfudo_network_status,fudo_network_username,fudo_network_method_idandfudo_network_pubkey_fingerprint, and by thefn_*attributes of thefnetauthentication method.Secret: secret names are no longer required to be unique within a collection. Integrations that identified a secret by name must use its identifier.
Secret Change Policy:
rsa1024was dropped from the values ofssh_keytype.User Access Gateway access request:
reasonis no longer required - a request may instead carryreason_format_idwithreason_fields.
You can search for Fudo Enterprise API features by using the search bar located on your left or refer to the table of contents below.
Table of Contents¶
Getting Started
Core Resources - Users & Groups
- Role-Based Access Control and User Groups
- Users
- Data Structures: UserModel
- Get Available Attributes of the UserModel
- Data Structures: UserSafeAssignmentModel
- Retrieve Available Attributes of the UserSafeAssignmentModel
- Data Structures: UserSafeTimePolicyAssignmentModel
- Retrieve Available Attributes of the UserSafeTimePolicy - AssignmentModel
- Create a User
- Get Users List
- Get a User
- Modify a User
- Get User-Safe Assignments List
- Create a User-Safe Assignment
- Get Users’ Time Policy Settings Within Safes
- Get Users’ Time Policy Settings Within Safes by ID
- Modify User’s Time Policy Settings Within a Safe
- Create User’s Time Policy Settings Within a Safe
- Delete User’s Time Policy Settings Within a Safe
- Delete User-Safe Assignment
- Delete User
- User Authentication Methods Management
- Retrieve Available Attributes of the UserAuthentication - MethodModel
- Listing User Authentication Configurations
- Listing Authentication Configurations for User
- Retrieve User Authentication Configuration by ID
- Create User Authentication Method
- Modify User Authentication Method
- Deleting User Authentication Method
- Location Policies 🆕
- Data Structures
- Retrieve Available Attributes
- List Location Policies
- Get a Location Policy
- Create a Location Policy
- Modify a Location Policy
- Delete a Location Policy
- List Location Policy Entries
- Get a Location Policy Entry
- Create a Location Policy Entry
- Modify a Location Policy Entry
- Delete a Location Policy Entry
- List Group Assignments
- Get a Group Assignment
- Assign a Location Policy to a Group
- Remove a Location Policy from a Group
- Get the Policies Effective for a User
- User Devices
- User Mobile Access (Fudo Officer)
- User Organization
Core Resources - Accounts
- Accounts
- Account-Safe-Listener Assignment
- Data Structures: AccountSafeListenerAssignmentModel
- Retrieve Available Attributes of the AccountSafeListener- AssignmentModel
- Get Account-Safe-Listener Assignment List
- Get Account-Safe-Listener Assignment by ID’s
- Create an Account-Safe-Listener Assignments
- Modify an Account-Safe-Listener Assignment
- Delete an Account-Safe-Listener Assignment
- Managing Secret Changers and Remote Apps in Accounts
- Data Structures
- Retrieve Available Attributes of the AccountScriptModel
- Get Secret Changers and Remote Apps Assigned to Accounts
- Get Secret Changer or Remote App Assigned to an Account by Assignment ID
- Assign Secret Changer or Remote App to an Account
- Modify Secret Changer or Remote App Assignment for an Account
- Delete Secret Changer or Remote App Assignment from an Account
- Account Notes
Core Resources - Connection Assets
Access Requests
Password Management
Automation & Discovery
- Discovery
- Discovery Scanner
- Discovery Rule
- Retrieve Available Attributes of the DiscoveryRuleModel
- Get Rules List
- Get Rule by ID
- Create Rule
- Modify Rule
- Delete Rule
- Discovery Scanner-Rule Assignment
- Discovery Rule-Listener Assignment
- Discovery Rule-Pool Assignment
- Discovery Rule-Safe Assignment
- Managing Discovery State
Sessions & Monitoring
- Sessions
- Sessions Management
- Sharing Sessions
- Session Access History 🆕
- Revoking Sharing Sessions
- Terminating Sessions
- Session Text
- Session OCR
- Session Comment
- Sessions Approval
- Restoring Session
- Session Last Activity
- Session Data Replication
- Session Timestamping
- Session Download
- Session Backup
- Session SCP File
- Session Summary
- Session Commands
- AI Session Analysis Agents 🆕
- Data Structures
- Retrieve Available Attributes
- List Analysis Agents
- Get an Analysis Agent
- Create an Analysis Agent
- Modify an Analysis Agent
- Delete an Analysis Agent
- List Safe Assignments
- Get a Safe Assignment
- Attach an Agent to a Safe
- Detach an Agent from a Safe
- Get the Live Analysis Switch
- Switch Live Analysis On or Off
- AI Session Analysis Results 🆕
- Reports
- Data Structures: ReportModel
- Retrieve Available Attributes of the ReportModel
- Data Structures: DefinedReportSubscriptionModel
- Retrieve Available Attributes of the DefinedReportSubscriptionModel
- Data Structures: DefinedReportModel
- Retrieve Available Attributes of the DefinedReportModel
- Get List of Generated Reports
- Get List of Predefined Report Definitions
- Get List of Subscriptions to Periodic Reports
- Get or Download Report File
- Subscribe to a Periodic Report
- Create New Report Definition (Custom Filter)
- Generate User Report on Demand
- Update Report Definition (Custom Filter)
- Delete Generated User Report
- Delete Report Definition (Custom Filter)
- Unsubscribe from a Recurring Report
- User Productivity Analytics
- Logs
- Syslog Server Management
- Notification Filter
- Push Notifications
- Downloads
- Machine Learning - Session Scoring
- Machine Learning Settings
- Machine Learning - Model Profiles
Integrations - Authentication
- External Authentication
- OpenID Connect Configuration
- OpenID Connect Users Assignment
- Data Structures
- Retrieve Available Attributes of the UserOpenIDModel
- Get the List of Existing OpenID Connect Configuration Assignments to Users
- Get Existing OpenID Connect Configuration Assigned to User
- Defining OpenID Connect Configuration Assignment to User
- Modify OpenID Connect Configuration Assignment to User
- Deleting OpenID Connect Configuration Assignment to User
- JWT Provider Management 🆕
- User Directory
Integrations - External Services
System Administration
- Backup
- Create Backup Target
- Get Backup Definitions List
- Get a Backup Definition by ID
- Assign Backup Definition to Session
- Delete Backup Definition
- Upgrade
- Hotfix
- License
- Exporting/Importing System Configuration
- Hardware Security Module 🆕
- Network
- Get Network Settings
- Healthcheck
- Status
- IPMI
- Disk Probe
- Dashboard Storage
User Access Gateway - Core
- Authentication Confirmation
- Profile Authentication Methods Management
- Overview
- Authentication Flow
- Data Structures
- Retrieve Available Attributes of the Authentication MethodModel
- Step 1: Obtain Reauthentication Token
- Step 2: List User’s Authentication Methods
- Create Authentication Method
- Get Authentication Method by ID
- Update Authentication Method
- Delete Authentication Method
- Invalidate Reauthentication Token
- UAG - Current User Identity
- UAG - Accounts List
- UAG - Account Safe Listener
- UAG - Account Access Request
- UAG - Access Request Reason Formats 🆕
- UAG - Session Timeout Check
User Access Gateway - Sessions
User Access Gateway - Features
User Access Gateway - Vault
User Access Gateway - Settings