How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

UpGuard userrisk API

The userrisk API from UpGuard — 15 operation(s) for userrisk.

UpGuard userrisk API is one of 18 APIs that UpGuard publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include userrisk. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 15 operations across 15 paths, and defines 35 schemas. It is described by OpenAPI 2.0, at version 1.13.2.

Requests are made against the base URL https://cyber-risk.upguard.com/api/public.

15 operations 15 paths 35 schemas 15 GET

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 2.0
API Version
1.13.2
Base URL
https://cyber-risk.upguard.com/api/public
Authentication
API Key
Resource Areas
1

Authentication & Security 1

UpGuard userrisk API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (API key in header). By default, every request must be authenticated.

Paths & Operations 15

Across 15 paths, the API surfaces 15 operations — 15 GET. Each is listed below with its method, path, parameters, and response codes.

userrisk 15
GET
/user_risk/app_categories/list
List app categories
getUserRiskAppCategoriesList 4 params → 200403422429500
GET
/user_risk/apps/list
List apps
getUserRiskAppsList 13 params → 200403422429500
GET
/user_risk/apps/permissions/list
List app permissions
getUserRiskAppsPermissionsList 5 params → 200403422429500
GET
/user_risk/apps/users/list
List app users
getUserRiskAppUsersList 5 params → 200403422429500
GET
/user_risk/identity_breaches/list
List identity breaches
getUserRiskIdentityBreachesList 10 params → 200403422429500
GET
/user_risk/identity_breaches/users/list
List identity breach users
listIdentityBreachUsers 5 params → 200403422429500
GET
/user_risk/permissions/apps/list
List permission apps
getUserRiskPermissionsAppsList 5 params → 200403422429500
GET
/user_risk/permissions/list
List permissions
getUserRiskPermissionsList 7 params → 200403422429500
GET
/user_risk/permissions/users/list
List permission users
getUserRiskPermissionsUsersList 5 params → 200403422429500
GET
/user_risk/roles/list
List roles
getUserRiskRolesList 4 params → 200403422429500
GET
/user_risk/teams/list
List teams
getUserRiskTeamsList 4 params → 200403422429500
GET
/user_risk/users/apps/list
List a user apps
getUserRiskUserAppsList 5 params → 200403422429500
GET
/user_risk/users/identity_breaches/list
List a user identity breaches
getUserRiskUserIdentityBreachesList 5 params → 200403422429500
GET
/user_risk/users/list
List users
getUserRiskUsersList 7 params → 200403422429500
GET
/user_risk/users/permissions/list
List a user permissions
getUserRiskUserPermissionsList 5 params → 200403422429500

Schemas 35

The contract defines 35 schemas that model the data the API accepts and returns. The most detailed are App (18 properties), UserApp (15 properties), User (10 properties), IdentityBreach (10 properties). Each schema is shown below with its type and property counts.

App
object
18 properties 7 required
User
object
10 properties 7 required
AppPermission
object
7 properties 6 required
UserRiskAppsListResponse
object
2 properties 1 required
GetUserRiskPermissionsListResponse
object
2 properties 1 required
AppUser
object
9 properties 5 required
endpointError
object
Error details coming from an endpoint
1 property
GetUserRiskTeamsListResponse
object
2 properties 1 required
GetUserRiskAppsPermissionsListResponse
object
2 properties 1 required
ApprovedReplacementApp
object
3 properties 1 required
GetUserRiskAppCategoriesListResponse
object
2 properties 1 required
AppMetadata
object
1 property
Team
object
2 properties 2 required
Role
object
2 properties 2 required
UsagePolicyRule
object
3 properties 3 required
GetUserRiskPermissionsUsersListResponse
object
2 properties 1 required
IdentityBreachesListResponse
object
2 properties 1 required
Permission
object
7 properties 6 required
UserRiskAppUsersListResponse
object
2 properties 1 required
PermissionUser
object
6 properties 3 required
UserAppStats
object
1 property 1 required
UserApp
object
15 properties 4 required
UserIdentityBreachesStats
object
2 properties 1 required
UserRiskUsersListResponse
object
2 properties 1 required
IdentityBreach
object
10 properties 8 required
UserRiskUserPermissionsListResponse
object
2 properties 1 required
UsagePolicy
object
UsagePolicy describes the app usage policy applied to an application, including the base rule applied by default and any custom rules that override it for spec…
3 properties 2 required
UserIdentityBreachesListResponse
object
2 properties 1 required
UserMetadata
object
1 property
UserPermission
object
7 properties 5 required
IdentityBreachUsersListResponse
object
2 properties 1 required
GetUserRiskRolesListResponse
object
2 properties 1 required
UserRiskUseAppsListResponse
object
2 properties 1 required
IdentityBreachUser
object
7 properties 4 required
GetUserRiskPermissionsAppsListResponse
object
2 properties 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

upguard-userrisk-api-openapi.yml Raw ↑

Other APIs UpGuard publishes across the network.

UpGuard breaches API
UpGuard bulk API
UpGuard dataleaks API
UpGuard domains API
UpGuard ips API
UpGuard labels API
UpGuard notifications API
UpGuard organisation API
UpGuard reports API
UpGuard risks API
UpGuard subsidiaries API
UpGuard threatmonitoring API
Where this information came from

This is an independent, third-party profile of UpGuard userrisk API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.