How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Venafi Identity APIs API

The Identity interface manages users and group access. The Web SDK supports the following identity providers for viewing individuals and groups of users:|Provider|Requirements||---|---||AD|Read only. Allows view capability from an external Microsoft Active Directory (AD). Requires an Active Directory connection before making API calls. For more information, see the Administration Guide.||LDAP|Read only. Allows view capability from an external Lightweight Directory Access Protocol (LDAP) data source. Requires setup before making API calls. Use the LDAP Identity Provider Wizard. For more information, see the Administration Guide.||Local|Default. Allows view capability and password rotation only in Trust Protection Foundation.|**What is the difference between Credentials, Permissions, and Identity?*** Credentials endpoints manage certificate and other activities. For more information, see Credentials APIs.* Identity endpoints manage CyberArk users. For more information, see Identity APIs.* Permissions endpoints grant principals (users and groups) privileges to objects within Trust Protection Foundation. For more information, see Permission API.

Venafi Identity APIs API is one of 58 APIs that Venafi publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Identity APIs. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

This API exposes 13 operations across 13 paths, and defines 27 schemas. It is described by OpenAPI 3.2.0, at version 26.1.1.

Requests are made against 3 base URLs: /, https://REPLACEdnsnameME/, https://{dnsname}/.

13 operations 13 paths 27 schemas 1 DELETE1 GET8 POST3 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
26.1.1
Base URL
https://api.venafi.cloud
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Venafi Identity APIs API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (AccessToken). By default, every request must be authenticated.

Paths & Operations 13

Across 13 paths, the API surfaces 13 operations — 1 DELETE, 1 GET, 8 POST, 3 PUT. Each is listed below with its method, path, parameters, and response codes.

Identity APIs 13

The Identity interface manages users and group access.

POST
/vedsdk/identity/browse
Search Identity Entries
Venafi_Core_WebSDK_IdentityRest_Browse body → 200403400401
POST
/vedsdk/identity/getassociatedentries
Get Associated Identity Entries
Venafi_Core_WebSDK_IdentityRest_GetAssociatedEntries body → 200403400401
POST
/vedsdk/identity/getmembers
Get Group Members
Venafi_Core_WebSDK_IdentityRest_GetMembers body → 200403400401
POST
/vedsdk/identity/getmemberships
Get Groups
Venafi_Core_WebSDK_IdentityRest_GetMemberships body → 200403400401
POST
/vedsdk/identity/readattribute
Read Attribute
Venafi_Core_WebSDK_IdentityRest_ReadAttribute body → 200403400401
POST
/vedsdk/identity/validate
Verify Identity Entry
Venafi_Core_WebSDK_IdentityRest_Validate body → 200403400401
GET
/vedsdk/identity/self
Who Am I
Venafi_Core_WebSDK_IdentityRest_Self → 200403400401
POST
/vedsdk/identity/SetPassword
Change Password
Venafi_Core_WebSDK_IdentityRest_SetIdentityPassword body → 200403400401
POST
/vedsdk/identity/addgroup
Add Group
Venafi_Core_WebSDK_IdentityRest_AddGroup body → 200403400401
PUT
/vedsdk/identity/renamegroup
Rename Group
Venafi_Core_WebSDK_IdentityRest_RenameGroup body → 200403400401
DELETE
/vedsdk/identity/group/{prefix}/{principal}
Delete Group
Venafi_Core_WebSDK_IdentityRest_DeleteGroup 2 params → 200400
PUT
/vedsdk/identity/addgroupmembers
Add Group Members
Venafi_Core_WebSDK_IdentityRest_AddGroupMembers body → 200403400401
PUT
/vedsdk/identity/removegroupmembers
Remove Group Members
Venafi_Core_WebSDK_IdentityRest_RemoveGroupMembers body → 200403400401

Schemas 27

The contract defines 27 schemas that model the data the API accepts and returns. The most detailed are Core_WebSDK_IdentityWebRequest_browse (4 properties), Core_WebSDK_IdentityWebRequest_removegroupmembers (3 properties), Core_WebSDK_IdentityWebRequest_SetPassword (3 properties), Core_WebSDK_IdentityWebResponse_removegroupmembers (3 properties). Each schema is shown below with its type and property counts.

Core_WebSDK_IdentityWebRequest_SetPassword
object
3 properties
Core_WebSDK_IdentityWebRequest_validate
object
1 property
Core_WebSDK_IdentityWebRequest_addgroup
object
3 properties
Core_WebSDK_IdentityWebRequest_getmemberships
object
1 property
Web_SDK_Authentication_OAuthError
object
REST OAuth Error Response
2 properties
Core_WebSDK_IdentityWebRequest_addgroupmembers
object
2 properties
Core_WebSDK_IdentityWebResponse_removegroupmembers
object
3 properties
Core_WebSDK_IdentityWebResponse_readattribute
object
1 property
Core_WebSDK_IdentityWebResponse_browse
object
1 property
Core_WebSDK_IdentityWebResponse_addgroupmembers
object
2 properties
Core_WebSDK_IdentityWebRequest_readattribute
object
1 property
Core_WebSDK_IdentityWebResponse_getassociatedentries
object
1 property
Core_WebSDK_IdentityWebResponse_self
object
1 property
Core_WebSDK_IdentityWebRequest_getmembers
object
1 property
Core_WebSDK_IdentityWebResponse_getmemberships
object
1 property
Core_WebSDK_IdentityWebRequest_getassociatedentries
object
1 property
Core_IdentityType
integer
0: Undefined Undefined 1: User User object 2: Group Group object 4: Container Container of users and groups 8: DistributionList Distribution List 16: Machine M…
Core_WebSDK_IdentityWebRequest_removegroupmembers
object
3 properties
Core_WebSDK_IdentityWebResponse_group__prefix___principal_
object
1 property
Core_WebSDK_IdentityWebResponse_SetPassword
object
1 property
Core_WebSDK_IdentityWebRequest_renamegroup
object
2 properties
Core_WebSDK_IdentityWebResponse_validate
object
1 property
Core_WebSDK_IdentityWebResponse_renamegroup
object
1 property
Core_WebSDK_IdentityWebRequest_browse
object
4 properties
Core_WebSDK_IdentityWebResponse_addgroup
object
2 properties
Core_IdentityEntry_EntryState
integer
0: Normal No special state associated with the entry 1: Disabled The identity has been disabled 2: LockedOut The identity has been locked out 4: Deleted The id…
Core_WebSDK_IdentityWebResponse_getmembers
object
1 property

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

venafi-identity-apis-api-openapi.yml Raw ↑

Other APIs Venafi publishes across the network.

Venafi Access Management APIs API
Venafi AlgorithmSelector APIs API
Venafi Application API
Venafi Authentication Server APIs API
Venafi Certificate Approvals API
Venafi Certificate Auto-renewal Monitoring API
Venafi Certificate Discovery API
Venafi Certificate Expiration Reports API
Venafi Certificate Import API
Venafi Certificate Installations API
Venafi Certificate Inventory Monitoring API
Venafi Certificate Management APIs API
Where this information came from

This is an independent, third-party profile of Venafi Identity APIs API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.