How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Sonatype Source Control API

Use this REST API to:Create, update and delete source control management (SCM) configuration for the root organization, sub-organizations and applications.Automatically assign the developer role to all contributors of the associated repository, who are registered IQ users.

Sonatype Source Control API is one of 58 APIs that Sonatype publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 2 JSON Schema definitions.

Tagged areas include Source Control. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, and 2 JSON Schemas.

This API exposes 8 operations across 4 paths, and defines 5 schemas. It is described by OpenAPI 3.2.0, at version 1.201.0-02.

Requests are made against the base URL https://{iq-server-host}/.

8 operations 4 paths 5 schemas 2 DELETE2 GET3 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.201.0-02
Base URL
https://{iq-server-host}/
Authentication
HTTP Basic, HTTP Bearer
Resource Areas
1

Authentication & Security 2

Sonatype Source Control API declares 2 security schemes for authenticating requests. It accepts HTTP basic authentication (BasicAuth). It accepts HTTP bearer tokens (JWT) (BearerAuth). By default, every request must be authenticated.

Paths & Operations 8

Across 4 paths, the API surfaces 8 operations — 2 DELETE, 2 GET, 3 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Source Control 8

Use this REST API to: Create, update and delete source control management (SCM) configuration for the root organization, sub-organizations and applications. Automatically assign t…

DELETE
/api/v2/sourceControl/automaticRoleAssignment/userMappings/{organizationId}
Use this method to delete existing SCM user mappings for an organization. Permissions required: Edit IQ Elements
deleteUserMappings 1 param → 204
POST
/api/v2/sourceControl/automaticRoleAssignment/userMappings/{organizationId}
Use this method to apply user mappings from SCM (GitHub) to Lifecycle. The user mappings will be inherited by all child organizations and applications in the organization hierarchy. If a user mapping…
addUserMappings 1 param body → 204
GET
/api/v2/sourceControl/automaticRoleAssignment/userMappings/{ownerType}/{internalOwnerId}
Use this method to retrieve SCM user mappings for an organization or application. Permissions required: View IQ Elements
getUserMappingsByOwner 2 params → 200
POST
/api/v2/sourceControl/automaticRoleAssignment/{publicId}
Use this method to automatically grant the supplied role to all contributors of a repository on a given application. Prerequisites for automatic role assignment are: SCM configuration for the applica…
automaticRoleAssignment 1 param body → 200
DELETE
/api/v2/sourceControl/{ownerType}/{internalOwnerId}
Use this method to delete a SCM setting for the specified ownerType/ownerId. Permissions required: Edit IQ Elements
deleteSourceControl 2 params → 204
GET
/api/v2/sourceControl/{ownerType}/{internalOwnerId}
Use this method to retrieve the source control configuration settings for an organization or an application. Permissions required: View IQ Elements
getSourceControl_1 2 params → 200
POST
/api/v2/sourceControl/{ownerType}/{internalOwnerId}
Use this method to create a source control configuration setting. Permissions required: Edit IQ Elements
addSourceControl 2 params body → 200
PUT
/api/v2/sourceControl/{ownerType}/{internalOwnerId}
Use this method to update an existing SCM setting. Permissions required: Edit IQ Elements
updateSourceControl 2 params body → 200

Schemas 5

The contract defines 5 schemas that model the data the API accepts and returns. The most detailed are ApiSourceControlDTO (22 properties), SCMUserMappingsResponseDTO (3 properties), SCMUserMatchingResultDTO (2 properties), UserMapping (2 properties). Each schema is shown below with its type and property counts.

SCMUserMappingsDTO
object
2 properties
UserMapping
object
2 properties
ApiSourceControlDTO
object
22 properties
SCMUserMappingsResponseDTO
object
3 properties
SCMUserMatchingResultDTO
object
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

sonatype-source-control-api-openapi.yml Raw ↑

Other APIs Sonatype publishes across the network.

Sonatype Advanced Search API
Sonatype Application Categories API
Sonatype Application Report Data API
Sonatype Applications API
Sonatype Audit Logs API
Sonatype Auto Policy Waiver Exclusions API
Sonatype Auto Policy Waivers API
Sonatype CI Configuration API
Sonatype Claim Components API
Sonatype Component Labels API
Sonatype Component Search API
Sonatype Components API
Where this information came from

This is an independent, third-party profile of Sonatype Source Control API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.