> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plerion.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List risks in a tenant

> Use the list risks API to retrieve and filter risks across the tenant.



## OpenAPI

````yaml /api-reference/openapi.yaml get /v1/tenant/risks
openapi: 3.1.0
info:
  title: Plerion API Documentation
  version: v1
  termsOfService: https://www.plerion.com/terms-and-conditions
  contact:
    name: Plerion Pty Ltd
    url: https://www.plerion.com/contact-us
    email: support@plerion.com
  license:
    name: Plerion Use License
    url: https://www.plerion.com/terms-and-conditions
  description: |-
    <br/>
    The Plerion API allows you to programmatically interact with Plerion.<br/>
          <b>Base URL</b>: <code>https://{region}.api.plerion.com</code>
servers:
  - url: https://{region}.api.plerion.com
    description: Production API server - Select your preferred region
    variables:
      region:
        default: au
        enum:
          - au
          - sg1
          - in1
          - us1
security: []
tags:
  - name: QUICK_START
    x-displayName: Quick Start
    description: >-
      This section describes how to quickly get started with the Plerion API
      using curl. For a more detailed guide, see the sections below.

      <br/><br/>

      <h3><b> Getting started with curl </b></h3>

      <p>

      1. Install curl if it isn't already installed on your machine. To check if
      curl is installed, execute <code>curl --version</code> in the command
      line. If the output is information about the version of curl, it is
      installed. If you get a message similar to <code>command not found:
      curl</code>, you need to download and install <code>curl</code>. For more
      information, see the <a href="https://curl.se/download.html">curl project
      download page</a>.</li>

      </p>

      <br/>

      <p>

      2. Create a Tenant API key accessing <a href="/settings/api-keys">Tenant
      API Keys Dashboard</a>. 

      </br>

      <b>Warning: Treat your API key like a password. Do not store it as plain
      text or expose it in any code base.</b>

      </p>

      <p>

      <br/>

      3. Use the <code>curl</code> command to make your request. Pass your API
      key in an Authorization header. Replace <code>{PLERION_API_KEY}</code>
      with your API key.

      <br/><br/>

      <pre>
        export PLERION_API_URL=au.api.plerion.com
        export PLERION_API_KEY={PLERION_API_KEY}

        curl --request GET \\
        --url "https://$PLERION_API_URL/v1/tenant/findings" \\
        --header "Authorization: Bearer $PLERION_API_KEY"
      </pre>


      </p>
  - name: Overview
    x-displayName: Overview
    description: >-
      Plerion API uses API keys to authenticate requests. You can view and
      manage your API keys in the Plerion app <a
      href="/settings/api-keys">Tenant API Keys Dashboard</a>.

      API responses are JSON-encoded.


      <br/>

      <H3><b>Authentication</b></H3> 

      <p>

      To authenticate to Plerion API send the API Key using bearer auth in the
      Authorization header

      <pre>

      Authorization: Bearer $PLERION_API_KEY

      </pre>

      All API requests must be made over HTTPS. Calls made over plain HTTP will
      fail. API requests without authentication will also fail.

      </p>

      <br/>

      <H3><b>Errors</b></H3> 

      <p>

      Plerion uses conventional HTTP response codes to indicate the success or
      failure of an API request. In general: Codes in the 2xx range indicate
      success. Codes in the 4xx range indicate an error that failed given the
      information provided (e.g., a required parameter was omitted). Codes in
      the 5xx range indicate an error with Plerion's servers.

      Some 4xx errors that could be handled programmatically include an error
      code that briefly explains the error reported. Detailed description for
      the status code can be found in th <b>Response Status Codes</b> section.

      </p>

      <br/>

      <H3><b>Response Status Codes</b></H3> 


      The Plerion API endpoints return the following HTTP response status
      codes. 


      <TABLE> <TR> <TH>Status Code</TH><TH>Definition</TH><TH>Description</TH>
      </TR>  <TR> <TD> 200 </TD><TD> OK </TD><TD> The request has succeeded.
      </TD> </TR>  <TR> <TD> 201 </TD><TD> Created </TD><TD> The request has
      been fulfilled and resulted in a new resource being created. </TD> </TR> 
      <TR> <TD> 204 </TD><TD> No Content </TD><TD> The server has fulfilled the
      request but does not need to return an entity-body. </TD> </TR>  <TR> <TD>
      400 </TD><TD> Bad Request </TD><TD> The request could not be understood by
      the server due to malformed syntax. The client SHOULD NOT repeat the
      request without modifications. </TD> </TR>  <TR> <TD> 401 </TD><TD>
      Unauthorized </TD><TD> The request requires user authentication. If the
      request already included Authorization credentials, then the 401 response
      indicates that authorization has been refused for those credentials. </TD>
      </TR>  <TR> <TD> 403 </TD><TD> Forbidden </TD><TD> The server understood
      the request, but is refusing to fulfill it. Authorization will not fix the
      issue and the request SHOULD NOT be repeated. </TD> </TR>  <TR> <TD> 404
      </TD><TD> Not Found </TD><TD> The server has not found anything matching
      the Request-URI. </TD> </TR>  <TR> <TD> 405 </TD><TD> Method Not Allowed
      </TD><TD> The method specified in the Request-Line is not allowed for the
      resource identified by the Request-URI. </TD> </TR>  <TR> <TD> 409
      </TD><TD> Conflict </TD><TD> The request could not be completed due to a
      conflict with the current state of the resource. </TD> </TR>  <TR> <TD>
      429 </TD><TD> Too Many Requests </TD><TD> Too many requests occurred
      during the allotted time period and rate limiting was applied.</TD> </TR>
      <TR> <TD> 500 </TD><TD> Internal Server Error </TD><TD> The request did
      not complete due to an internal error on the server side. The server
      encountered an unexpected condition which prevented it from fulfilling the
      request. </TD> </TR>  <TR> <TD> 503 </TD><TD> Service Unavailable
      </TD><TD> The server is currently unable to handle the request due to a
      temporary overloading or maintenance of the server. </TD> </TR>  </TABLE>
  - name: Findings
    x-displayName: Findings
    description: >-
      Findings are the results of the Plerion Detection Engine (PDE) Detection
      reporting a finding and rating the severity of the finding as it relates
      to best practices or a relevant compliance standard.

      Plerion Findings enable customers to reduce the risk to their environments
      by continuously highlighting areas for improvement.
  - name: Assets
    x-displayName: Assets
    description: >-
      Plerion Assets form the basis upon which all Plerion contextual security
      is reported.


      Every unique cloud resource on which Plerion collects information is
      classified as a single asset on the Plerion platform.


      A detailed asset view combines various sources of security, compliance,
      and risk-related metrics to empower customers to make high-impact
      decisions when evaluating a single asset in relation to their overall
      cloud environments.
  - name: Asset groups
    x-displayName: Asset Groups
    description: >-
      Asset Group is classifying assets into specific group based on the
      different criteria such as integration, asset tag, resource type and
      resource name.  This helps users to manage, organize, and analyze their
      assets more efficiently.  User can group assets based on the teams,
      projects, business units, environments, tech stack etc.
  - name: Alerts
    x-displayName: Alerts
    description: >-
      The Plerion Risk Score (PRS) Engine has calculated Alerts that are the
      highest priority items based on the available information across Identity,
      Configuration, and Vulnerability Management. 

      Alerts offer the highest value CONTEXT from across the Plerion Platform.
      Alerts are accompanied by a narrative to guide customers on the overall
      risk and the recommended remediation steps to take to improve, reduce, or
      eradicate the identified risk.
  - name: Integrations
    x-displayName: Integrations
    description: >-
      Integrations enable customers to connect their own cloud environments to
      the Plerion platform.

      Integrations allow for the collection of data from the integrated
      environment, e.g. Connecting Plerion to your cloud service provider will
      facilitate Plerion to collect, analyze, and prioritize the most
      significant risks across your cloud operating environments.
  - name: Tenant
    x-displayName: Tenant
    description: >-
      The Plerion platform caters for multi-tenancy.

      Multi-tenancy within the Plerion platform delivers isolation for the
      integrations supported by Plerion. Each Tenancy (Tenant) allows for
      multiple inbound or outbound integrations, like integrating with Cloud
      Service Providers (AWS, Azure, GCP), and their corresponding Audit log
      service (AWS: CloudTrail, Azure: AuditLog, GCP: Cloud Audit Log).
  - name: Risks
    x-displayName: Risks
    description: >-
      In a cloud environment there are usually many hundreds or thousands of
      misconfigurations, but which of those pose a clear and present danger of a
      breach? That’s what the Plerion risk is about.
  - name: AWS integration
    x-displayName: AWS Integration
    description: >-
      In order to connect your AWS account to Plerion or update existing
      account, you will need, <ol>
        <li> <b>CloudFormation Template URL</b>. Retrieve the template from <a href="#tag/AWS-Integration/operation/getCloudformationTemplate">Get CloudFormation template</a></li>
        <li> <b>External Id</b> of the tenant. Retrieve the External Id from <a href="#tag/AWS-Integration/operation/getExternalId">Get the external id of the tenant</a></li>
        <li> <b>Plerion AWS Account Id</b>. The value will always be <code>588158338731</code></li>
        <li> <b>Temporary Auth Token</b>. Token to be passed to CloudFormation template that auto registers the AWS integration. Retrieve the temporary auth token from <a href="#tag/AWS-Integration/operation/createTemporaryToken">Generate temporary token for creating AWS integration</a></li>
        <li> <b>Plerion API URL</b>. The value will always be <code>au.api.plerion.com</code></li>
        <li> Select <b>Capabilities</b>. Select CSPM for CSPM only capability or ALL for both CSPM and CWPP capability.</li>
        <li> Select <b>KMSKeyAccessMode</b>. When CWPP is enabled, you can choose the KMS Key access mode to facilitate Plerion's access to keys for decrypting volumes, images, and lambda code. In the <b>ALL_KEYS</b> mode, Plerion is granted access to all KMS keys in the account. However, you have the option to restrict access to certain keys by applying the "PlerionAccess: Denied" tag. Alternatively, the <b>SELECTED_KEYS</b> mode allows Plerion access solely to the KMS keys that have been tagged with "PlerionAccess: Granted".</li>
      </ol> Passing the parameters to the CloudFormation template will create a
      new AWS integration or update existing integration. <br/><br/>

      <h3><b>Quick Start</b></h3>

      Follow the guide to create a new AWS integration or update existing
      integration using <code>curl</code> command.  <br/> <b>Note:</b> Replace
      {$PLERION_API_KEY} with your API key. <br/><br/>

      <h4> <b>Create a new AWS Integration</b></h4>

      <pre>
        export PLERION_API_URL=au.api.plerion.com
        export PLERION_API_KEY={$PLERION_API_KEY}
        export PLERION_AWS_ACCOUNT_ID=588158338731
        # Fetch the template URL
        export TEMPLATE_URL=$(curl -s GET  "https://$PLERION_API_URL/v1/tenant/cloudformation-templates?type=AWSAccount" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.templateURL')
        # Generate the temporary auth token
        export TEMP_AUTH_TOKEN=$(curl -s -X POST  "https://$PLERION_API_URL/v1/tenant/integrations/token" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.token')
        # Fetch the external ID
        export EXTERNAL_ID=$(curl -s -X GET  "https://$PLERION_API_URL/v1/tenant/external-id" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.externalId')
        # Create the stack
        export PLERION_STACK_NAME=plerion-aws-integration
        aws cloudformation create-stack --stack-name $PLERION_STACK_NAME --template-url $TEMPLATE_URL --capabilities CAPABILITY_NAMED_IAM \
          --parameters ParameterKey=ExternalId,ParameterValue=$EXTERNAL_ID \
            ParameterKey=PlerionAccountId,ParameterValue=$PLERION_AWS_ACCOUNT_ID  \
            ParameterKey=AuthToken,ParameterValue=$TEMP_AUTH_TOKEN \
            ParameterKey=Capabilities,ParameterValue=ALL \
            ParameterKey=KMSKeyAccessMode,ParameterValue="ALL_KEYS" \
            ParameterKey=PlerionURL,ParameterValue=$PLERION_API_URL
        # Wait for the stack to complete
        aws cloudformation wait stack-create-complete --stack-name $PLERION_STACK_NAME
      </pre> <br/><br/> <h4> <b>Update an existing AWS Integration</b></h4>

      <pre>
        export PLERION_API_URL=au.api.plerion.com
        export PLERION_API_KEY={$PLERION_API_KEY}
        export PLERION_AWS_ACCOUNT_ID=588158338731
        # Fetch the template URL
        export TEMPLATE_URL=$(curl -s GET  "https://$PLERION_API_URL/v1/tenant/cloudformation-templates?type=AWSAccount" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.templateURL')
        # Generate the temporary auth token
        export TEMP_AUTH_TOKEN=$(curl -s -X POST  "https://$PLERION_API_URL/v1/tenant/integrations/token" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.token')
        # Fetch the external ID
        export EXTERNAL_ID=$(curl -s -X GET  "https://$PLERION_API_URL/v1/tenant/external-id" -H "Authorization: Bearer $PLERION_API_KEY" | jq -r '.data.externalId')
        # Update an existing stack
        export PLERION_STACK_NAME=plerion-aws-integration
        aws cloudformation update-stack --stack-name $PLERION_STACK_NAME --template-url $TEMPLATE_URL --capabilities CAPABILITY_NAMED_IAM \
          --parameters ParameterKey=ExternalId,ParameterValue=$EXTERNAL_ID \
            ParameterKey=PlerionAccountId,ParameterValue=$PLERION_AWS_ACCOUNT_ID  \
            ParameterKey=AuthToken,ParameterValue=$TEMP_AUTH_TOKEN \
            ParameterKey=Capabilities,ParameterValue=ALL \
            ParameterKey=KMSKeyAccessMode,ParameterValue="ALL_KEYS" \
            ParameterKey=PlerionURL,ParameterValue=$PLERION_API_URL
        # Wait for the stack to complete
        aws cloudformation wait stack-update-complete --stack-name $PLERION_STACK_NAME
      </pre>
  - name: Compliance frameworks
    x-displayName: Compliance Frameworks
    description: >-
      Compliance Frameworks help our customers meet their regulatory and
      compliance obligations, and reduce compliance risk, enabling them to
      achieve their strategic objectives.

      Plerion offers customers hundreds of prebuilt detections delivering
      continuous assurance against industry standards and best practices.
  - name: Well-Architected frameworks
    x-displayName: Well-Architected Frameworks
    description: >-
      The AWS Well-Architected Framework helps customers design secure,
      high-performing, resilient, and efficient  cloud infrastructure.  Plerion
      continuously assesses your environment against the AWS Well-Architected
      pillars,  aligning your architecture with AWS best practices and
      accelerating improvement.
  - name: Tenant usage
    x-displayName: Tenant Usage
    description: Plerion Usage information for the Tenant
  - name: Audit logs
    x-displayName: Audit Logs
    description: >-
      Audit logs provide a comprehensive trail of user activities and system
      operations within a tenant.

      These logs capture important events such as user logins, API calls,
      configuration changes, and other security-relevant activities. Audit logs
      help with compliance, security monitoring, and troubleshooting.
paths:
  /v1/tenant/risks:
    get:
      tags:
        - Risks
      summary: List
      description: Use the list risks API to retrieve and filter risks across the tenant.
      operationId: listTenantRisks
      parameters:
        - $ref: '#/components/parameters/paramAuthHeader'
        - in: query
          name: ids
          schema:
            type: string
          description: Filter by risk IDs. Accepts a comma-separated list.
          example: id1,id2
        - in: query
          name: fields
          schema:
            type: string
          description: >-
            Select specific risk fields to include in the response. Only applies
            to risk properties. Accepts a comma-separated list of risk fields.
            Example fields: id, name, severityLevel, score
          example: id,name,severityLevel
        - in: query
          name: riskTypeIds
          schema:
            type: string
          description: Filter by risk type IDs. Accepts a comma-separated list.
          example: PLERION-RISK-1,PLERION-RISK-2
        - in: query
          name: environmentIds
          description: >-
            Filter risks on the environment. This parameter accepts any
            combination of environment name or environment IDs (UUIDs) in a
            comma-separated list.


            **Supported environment names:**

            - `production` - Production environment

            - `non-production` - Non-production environment
          schema:
            type: string
            example: production,550e8400-e29b-41d4-a716-446655440000
        - in: query
          name: integrationIds
          schema:
            type: string
          description: Filter by integration IDs. Accepts a comma-separated list.
          example: integration1,integration2
        - in: query
          name: primaryAssetIds
          schema:
            type: string
          description: Filter by primary asset IDs. Accepts a comma-separated list.
          example: asset1,asset2
        - in: query
          name: severityLevels
          schema:
            type: string
            enum:
              - CRITICAL
              - HIGH
              - MEDIUM
              - LOW
          description: Filter by severity levels. Accepts a comma-separated list.
          example: CRITICAL,HIGH,MEDIUM,LOW
        - in: query
          name: lifecycleStates
          schema:
            type: string
            enum:
              - DISMISSED_ACCEPTED
              - DISMISSED_NOT_A_RISK
              - OPEN
          description: Filter by lifecycle states. Accepts a comma-separated list.
          example: DISMISSED_ACCEPTED,DISMISSED_NOT_A_RISK,OPEN
        - in: query
          name: resourceTypes
          schema:
            type: string
          description: Filter by resource types. Accepts a comma-separated list.
          example: AWS::S3::Bucket,AWS::Lambda::Function
        - in: query
          name: discoveredAtStart
          schema:
            type: string
            format: date-time
          description: >-
            Start of the date range for filtering risks based on the discovered
            date.  Specify the start of the range using a valid ISO 8601
            date-time string.  If `discoveredAtStart` is provided and
            `discoveredAtEnd` is omitted,  results will include risks from this
            date to the present. Supported formats include: -
            `yyyy-MM-ddTHH:mm:ssZ` (e.g., `2025-02-18T08:00:00Z`) -
            `yyyy-MM-ddTHH:mm:ss.SSSZ` (e.g., `2025-02-18T08:00:00.000Z`)
          example: '2025-02-01T18:09:07Z'
        - in: query
          name: discoveredAtEnd
          schema:
            type: string
            format: date-time
          description: >-
            End of the date range for filtering risks based on the discovered
            date. Specify the end of the range using a valid ISO 8601 date-time
            string.  If `discoveredAtEnd` is provided and `discoveredAtStart` is
            omitted,  results will include risks up to this date. Supported
            formats include: - `yyyy-MM-ddTHH:mm:ssZ` (e.g.,
            `2025-02-18T08:00:00Z`) - `yyyy-MM-ddTHH:mm:ss.SSSZ` (e.g.,
            `2025-02-18T08:00:00.000Z`)
          example: '2025-02-08T18:09:07Z'
        - in: query
          name: include
          description: >-
            This parameter is for loading relationships in the risk response.
            Available options: - `primaryAsset`: includes the complete primary
            asset object for each risk - `integration`: includes the complete
            integration object for each risk
          schema:
            type: string
            example: primaryAsset,integration
        - in: query
          name: sortBy
          description: >-
            Order the list by supported field. Can accept `discoveredAt` or
            `score`. The default is `discoveredAt`.
          schema:
            type: string
            enum:
              - discoveredAt
              - score
            example: score
        - in: query
          name: sortOrder
          description: >-
            The sort order of the list. Can accept `asc` or `desc`. The default
            is `desc`.
          schema:
            type: string
            enum:
              - asc
              - desc
            example: desc
        - in: query
          name: cursor
          description: Get the next batch of risks. Used for pagination.
          schema:
            type: string
            example: k3d83a9b-k3dk-5lkd-2ldk-9kd77c1beb6
        - in: query
          name: perPage
          schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 100
          description: Number of items per page
          example: 50
      responses:
        '200':
          description: Risks list
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      allOf:
                        - $ref: '#/components/schemas/Risk'
                        - type: object
                          properties:
                            primaryAsset:
                              $ref: '#/components/schemas/Asset'
                            integration:
                              $ref: '#/components/schemas/Integration'
                  meta:
                    type: object
                    properties:
                      perPage:
                        type: integer
                        example: 100
                      total:
                        type: integer
                        example: 200
                      cursor:
                        type: integer
                        example: 100
        '400':
          $ref: '#/components/responses/400'
        '500':
          $ref: '#/components/responses/500'
      security:
        - APIKey: []
components:
  parameters:
    paramAuthHeader:
      name: Authorization
      in: header
      description: Bearer API Key. For example, "Bearer {Tenant API Key}"
      required: true
      schema:
        type: string
  schemas:
    Risk:
      type: object
      additionalProperties: false
      properties:
        id:
          type: string
          description: Unique identifier of the risk
        riskTypeId:
          type: string
          description: ID of the risk type
        organizationId:
          type: string
          description: ID of the organization
        tenantId:
          type: string
          description: ID of the tenant
        integrationId:
          type: string
          description: ID of the integration that the risk is a part of
        description:
          type: string
          description: Description of the risk
        primaryAssetId:
          type: string
          description: ID of the primary asset affected by the risk
        region:
          type:
            - string
            - 'null'
          description: >-
            AWS/Azure/GCP region of the primary asset affected by the risk
            (e.g., ap-southeast-2), null when unknown
        resolutions:
          type: array
          description: List of possible resolutions for the risk
          items:
            type: object
            additionalProperties: false
            properties:
              key:
                type: string
                description: Unique key for the resolution
              type:
                type: string
                description: Type of resolution
              title:
                type: string
                description: Title of the resolution
        score:
          type: number
          description: Overall risk score
          format: float
          minimum: 0
          maximum: 10
        likelihood:
          type: number
          description: Likelihood score of the risk
          format: float
          minimum: 0
          maximum: 10
        impact:
          type: number
          description: Impact score of the risk
          format: float
          minimum: 0
          maximum: 10
        severityLevel:
          type: string
          description: Severity level of the risk
          enum:
            - CRITICAL
            - HIGH
            - MEDIUM
            - LOW
        factors:
          type: array
          description: Contributing factors to the risk
          items:
            type: object
            additionalProperties: false
            properties:
              key:
                type: string
                description: Unique key for the factor
              meta:
                type: object
                description: Additional metadata for the factor
              title:
                type: string
                description: Title of the factor
              value:
                type: number
                description: Numerical value of the factor
              verificationState:
                type: string
                description: Current verification state
              description:
                type: string
                description: Detailed description of the factor
        meta:
          type: object
          additionalProperties: false
          description: Additional metadata about the risk
          properties:
            assetName:
              type: string
              description: Name of the associated asset
            resourceType:
              type: string
              description: Type of the resource
            fullResourceName:
              type: string
              description: Full resource name/path
        discoveredAt:
          type: string
          description: Timestamp when the risk was discovered
          format: date-time
        lifecycleState:
          type: string
          description: Current state in the risk lifecycle
          enum:
            - DISMISSED_ACCEPTED
            - DISMISSED_NOT_A_RISK
            - OPEN
    Asset:
      type: object
      properties:
        schemaVersion:
          type: string
          example: '2022-06-09'
        id:
          type: string
          example: >-
            prn:assets:afeb4e5f-0370-4b43-8e37-7e4efc719358:aws:ec2:instance:ap-southeast-2:i-085a328dba59f229b
        organizationId:
          type: string
          example: dc16d897-7f52-4b73-be57-96c7c9a853da
        tenantId:
          type: string
          example: 42749bc1-c99b-4c2c-a081-a6cda9370081
        integrationId:
          type: string
          example: 458511a1-9bc2-4fce-97a0-0e3139588e6e
        executionId:
          type: string
          example: 1675576960384
        provider:
          type: string
          example: AWS
        type:
          type: string
          example: AWS::EC2::Instance
        name:
          oneOf:
            - type: string
            - type: 'null'
          example: i-085a328dba59f229b
        createdAt:
          oneOf:
            - type: string
            - type: 'null'
          example: '2023-02-04T06:07:09.092Z'
        firstObservedAt:
          oneOf:
            - type: string
            - type: 'null'
          example: '2023-02-04T06:02:40.594Z'
        lastObservedAt:
          oneOf:
            - type: string
            - type: 'null'
          example: '2023-02-05T06:02:40.384Z'
        updatedAt:
          oneOf:
            - type: string
            - type: 'null'
          example: '2023-02-05T06:07:02.959Z'
        tags:
          oneOf:
            - type: array
              items:
                type: object
                properties:
                  Key:
                    type: string
                    description: Name of the Tag's Key
                    example: Department
                  Value:
                    type: string
                    description: Value of the Tag's Key
                    example: Finance
            - type: 'null'
        isPubliclyExposed:
          oneOf:
            - type: boolean
            - type: 'null'
          example: false
        isVulnerable:
          oneOf:
            - type: boolean
            - type: 'null'
          example: false
        numberOfLowVulnerabilities:
          oneOf:
            - type: number
            - type: 'null'
          example: 85
        numberOfMediumVulnerabilities:
          oneOf:
            - type: number
            - type: 'null'
          example: 60
        numberOfHighVulnerabilities:
          oneOf:
            - type: number
            - type: 'null'
          example: 15
        numberOfCriticalVulnerabilities:
          oneOf:
            - type: number
            - type: 'null'
          example: 5
        vulnerabilityScore:
          oneOf:
            - type: string
            - type: 'null'
          example: 9
        hasKev:
          oneOf:
            - type: boolean
            - type: 'null'
          example: false
        hasExploit:
          oneOf:
            - type: boolean
            - type: 'null'
          example: false
        isExploitable:
          oneOf:
            - type: boolean
            - type: 'null'
          example: false
        isInVpc:
          oneOf:
            - type: boolean
            - type: 'null'
          example: false
        lastScanId:
          oneOf:
            - type: string
            - type: 'null'
          example: 1679594910265
        lastScannedAt:
          oneOf:
            - type: string
            - type: 'null'
          example: '2023-03-23T18:17:20.003Z'
        imageId:
          oneOf:
            - type: string
            - type: 'null'
        platform:
          oneOf:
            - type: string
            - type: 'null'
        hasAdminPrivileges:
          oneOf:
            - type: boolean
            - type: 'null'
          example: false
        hasOverlyPermissivePrivileges:
          oneOf:
            - type: boolean
            - type: 'null'
          example: false
        hasAuthorizer:
          oneOf:
            - type: boolean
            - type: 'null'
          example: false
        hasTracingEnabled:
          oneOf:
            - type: boolean
            - type: 'null'
          example: false
        policy:
          oneOf:
            - $ref: '#/components/schemas/DynamicObject'
              type: object
            - type: 'null'
        numberOfLowSecrets:
          oneOf:
            - type: number
            - type: 'null'
          example: 3
        numberOfMediumSecrets:
          oneOf:
            - type: number
            - type: 'null'
          example: 1
        numberOfHighSecrets:
          oneOf:
            - type: number
            - type: 'null'
          example: 0
        numberOfCriticalSecrets:
          oneOf:
            - type: number
            - type: 'null'
          example: 2
        lowSecrets:
          oneOf:
            - $ref: '#/components/schemas/DynamicObjectArray'
            - type: 'null'
        mediumSecrets:
          oneOf:
            - $ref: '#/components/schemas/DynamicObjectArray'
            - type: 'null'
        highSecrets:
          oneOf:
            - $ref: '#/components/schemas/DynamicObjectArray'
            - type: 'null'
        criticalSecrets:
          oneOf:
            - $ref: '#/components/schemas/DynamicObjectArray'
            - type: 'null'
        operatingSystem:
          oneOf:
            - type: array
              items:
                $ref: '#/components/schemas/OperatingSystem'
            - type: 'null'
        riskScore:
          oneOf:
            - type: string
            - type: 'null'
          example: 9.36
        operationalState:
          type: string
          enum:
            - active
            - inactive
          description: >
            The operational state of the resource. Present only for resource
            types that support operational state.

            Supported resource types: AWS EC2 Instance.
          example: active
        region:
          type: string
          example: us-east-1
        service:
          type: string
          example: AWS::EC2
        resourceId:
          type: string
          example: i-085a328dba59f229b
        resourceName:
          type: string
          example: test-instance
        resourceTags:
          oneOf:
            - type: array
              items:
                type: object
                properties:
                  Key:
                    type: string
                    example: Public
                  Value:
                    type: string
                    example: true
            - type: 'null'
        resourceType:
          type: string
          example: AWS::EC2::Instance
        fullResourceName:
          type: string
          example: arn:aws:iam::1111222233334444:policy/test-policy
        providerAccountId:
          type: string
          example: 123456789012
        resourceURL:
          type: string
          example: >-
            https://us-east-1.console.aws.amazon.com/iam/home#/policies/arn:aws:iam::1111222233334444:policy/test-policy
    Integration:
      type: object
      properties:
        integrationId:
          type: string
          example: 31497927-86af-4fba-afc6-c0cf2311a55b
        name:
          type: string
          example: Integration 001
        tenantId:
          type: string
          example: 12345678-86af-4fba-afc6-c0cf12345678
        organizationId:
          type: string
          example: 12345678-86af-4fba-afc6-c0cf87654321
        schedule:
          type: string
          description: String representing a cron expression for scan schedule
          example: 59 6 * * *
        scanInterval:
          type: number
          enum:
            - 6
            - 8
            - 12
            - 24
          description: Represents the scan interval.
          example: 24
        createdAt:
          type: string
          format: date-time
          example: '2023-02-04T06:07:09.092Z'
        updatedAt:
          type: string
          format: date-time
          example: '2023-02-05T06:07:02.959Z'
        provider:
          type: string
          example: AWS
        type:
          type: string
          enum:
            - AWSAccount
            - AzureAccount
            - AzureActiveDirectory
            - AzureSubscription
            - GCPProject
            - CdrAws
            - Kubernetes
            - CASM
          description: Type of integration.
          example: AWSAccount
        detectionSettingId:
          type: string
          description: >-
            Available if Integration is attached to any custom Detection
            Setting.
          example: 12345678-86af-4fba-afc6-c0cf87654321
        status:
          type: string
          enum:
            - Active
            - Delete Failed
            - Delete In Progress
        riskScore:
          type: number
          format: float
          description: Risk score of the integration (if available)
          example: 8.19
        awsAccountId:
          type: string
          description: AWS account ID. Only returned for AWS integrations.
          example: '123456789012'
        azureSubscriptionId:
          type: string
          description: Azure Subscription ID. Only returned for Azure integrations.
          example: 12345678-1234-5678-1234-567812345678
        azureDirectoryId:
          type: string
          description: Azure Directory (Tenant) ID. Only returned for Azure integrations.
          example: 87654321-4321-8765-4321-876543218765
        gcpProjectId:
          type: string
          description: GCP Project ID. Only returned for GCP integrations.
          example: my-gcp-project
    DynamicObject:
      type: object
      additionalProperties:
        type: string
    DynamicObjectArray:
      type: array
      items:
        $ref: '#/components/schemas/DynamicObject'
    OperatingSystem:
      type: object
      properties:
        architecture:
          type: string
          description: The architecture of the operating system.
          example: x86_64
        name:
          type: string
          description: The name of the operating system.
          example: Ubuntu
        platform:
          type: string
          description: The OS platform.
          example: Linux/UNIX
        version:
          type: string
          description: The version of the operating system including version name.
          example: 24.04.2 LTS (Noble Numbat)
        versionId:
          type: string
          description: The version of the operating system.
          example: 24.04
        activeKernel:
          type: string
          description: The kernel version of the operating system.
          example: 4.14.246-197.484.amzn2.x86_64
        buildNumber:
          type: string
          description: The build number of the windows operating system.
          example: 20348.fe_release.210507-1500
        lcuVersion:
          type: string
          description: The latest cumulative update version of the windows operating.
          example: 10.0.20348.2762
    InternalServerErrorResponse:
      type: object
      properties:
        message:
          type: string
          example: Internal server error
  responses:
    '400':
      description: Bad Request
      content:
        application/json:
          schema:
            properties:
              errors:
                type: array
                items:
                  type: object
                  properties:
                    field:
                      type: string
                    code:
                      type: string
                    message:
                      type: string
    '500':
      description: Internal Server Error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/InternalServerErrorResponse'
  securitySchemes:
    APIKey:
      type: http
      scheme: bearer
      bearerFormat: apiKey
      description: Bearer API Key. For example, "Bearer {Tenant API Key}"

````