# 403 when using the cc/api/system/refreshidentities api with Python

**URL:** <https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284>\
**Category:** SHF Discussion and Questions\
**Tags:** apis, identity-security-cloud\
**Created:** [January 16, 2024, 1:39pm UTC](https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284 "2024-01-16T13:39:08Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ts\_fpatterson](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ts_fpatterson/32/26704_2.png) [@ts\_fpatterson](https://developer.sailpoint.com/discuss/u/ts_fpatterson)\
**Post date:** [January 16, 2024, 1:39pm UTC](https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284/1 "2024-01-16T13:39:08Z")

</div>

I have pasted the python script below, any help on why this wouldn’t be working? I’m using my PAT client id and secret. My Identity is an Org Admin.

Is there a beta api that replaces this functionality?

```auto
import requests
import json

# Set the necessary variables
client_id = "<pat client id>"
client_secret = "<pat secret>"
base_url = f"https://example.api.identitynow.com"
url = f"{base_url}/cc/api/system/refreshidentities"

# Get an access token
auth_url = f"{base_url}/oauth/token"
auth_data = {
    "grant_type": "client_credentials",
    "client_id": client_id,
    "client_secret": client_secret,
}
auth_response = requests.post(auth_url, data=auth_data)
print(auth_response)

#Extract the access token from the response
access_token = auth_response.json()["access_token"]
print(access_token)

payload = json.dumps({
    "filter": "costCenterId == \"01.74100\"",
    "refreshArgs": {
        "correlateEntitlements": "true",
        "promoteAttributes": "true",
        "refreshManagerStatus": "true",
        "provision": "true",
        "synchronizeAttributes": "true"
    }
})

headers = {
    'Authorization': f'Bearer {access_token}',
	'Content-Type': 'application/json'
}

response = requests.request("PUT",url, headers=headers, data=payload)

if response.status_code == 200:
    data = response.json()
  
else:
    print(f"Request for sources failed with status code: {response.status_code}")
    print("Response content:", response.text)
    

```

---

<div class="post-metadata">

**Author:** ![RAKGDS](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/rakgds/32/2795_2.png) [@RAKGDS](https://developer.sailpoint.com/discuss/u/RAKGDS)\
**Post date:** [January 16, 2024, 2:05pm UTC](https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284/2 "2024-01-16T14:05:51Z")

</div>

baseurl should be [https://tenant.api.identitynow-demo.com//cc/api/system/refreshIdentities](https://tenant.api.identitynow-demo.com//cc/api/system/refreshIdentities)

---

<div class="post-metadata">

**Author:** ![ts\_fpatterson](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ts_fpatterson/32/26704_2.png) [@ts\_fpatterson](https://developer.sailpoint.com/discuss/u/ts_fpatterson)\
**Post date:** [January 16, 2024, 2:43pm UTC](https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284/3 "2024-01-16T14:43:27Z")

</div>

Rakesh, this helped, thanks!

I also had a PUT rather than a POST, which generated a 405 error.

I’m now not seeing any errors, but I also don’t see any status change. I would have thought the manager name would have displayed. I tried to do a manual aggregation on the account. The source is workday.

Does this API trigger an evaluation / manager correlation for the identity, or does something else need to happen?

---

<div class="post-metadata">

**Author:** ![RAKGDS](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/rakgds/32/2795_2.png) [@RAKGDS](https://developer.sailpoint.com/discuss/u/RAKGDS)\
**Post date:** [January 16, 2024, 2:47pm UTC](https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284/4 "2024-01-16T14:47:45Z")

</div>

Hi Fred,  
It does evaluate based on the inputs you add. Let me check if it works for manage change as well.

---

<div class="post-metadata">

**Author:** ![ts\_fpatterson](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ts_fpatterson/32/26704_2.png) [@ts\_fpatterson](https://developer.sailpoint.com/discuss/u/ts_fpatterson)\
**Post date:** [January 16, 2024, 2:57pm UTC](https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284/5 "2024-01-16T14:57:25Z")

</div>

One note, the manager didn’t change. Just the correlation had issues early on and it isn’t correlating for a given manager and their direct reports. So the MANAGER\_ID in workday on the account is present, but the Manager Name (manager) is not populated. I’m trying to find a way for it to re-evaluate the manager correlation without HR having to change the manager and then change it back after an aggregation.

---

<div class="post-metadata">

**Author:** ![kjakubiak](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/kjakubiak/32/7052_2.png) [@kjakubiak](https://developer.sailpoint.com/discuss/u/kjakubiak)\
**Post date:** [January 16, 2024, 2:57pm UTC](https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284/6 "2024-01-16T14:57:56Z")

</div>

Hi Fred,  
I think you may try to combine this 2 together

> **[start-identity-processing | SailPoint Developer Community](https://developer.sailpoint.com/idn/api/beta/start-identity-processing)**
>
> Process a list of identityIds

> **[synchronize-attributes-for-identity | SailPoint Developer Community](https://developer.sailpoint.com/idn/api/beta/synchronize-attributes-for-identity)**
>
> Attribute synchronization for single identity.

---

<div class="post-metadata">

**Author:** ![ts\_fpatterson](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ts_fpatterson/32/26704_2.png) [@ts\_fpatterson](https://developer.sailpoint.com/discuss/u/ts_fpatterson)\
**Post date:** [January 16, 2024, 4:34pm UTC](https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284/7 "2024-01-16T16:34:17Z")

</div>

Kamil, this didn’t seem to do anything towards re-evaluating the manager correlation when processing it for a given id. However, maybe I ran it wrong as the 202 message back stated:  
Response content: {“type”:“TASK\_RESULT”,“id”:“09aea8e2-76ee-4b0a-b59e-11223716c6d2”,“name”:null}

---

<div class="post-metadata">

**Author:** ![kjakubiak](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/kjakubiak/32/7052_2.png) [@kjakubiak](https://developer.sailpoint.com/discuss/u/kjakubiak)\
**Post date:** [January 16, 2024, 6:36pm UTC](https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284/8 "2024-01-16T18:36:46Z")

</div>

That might be also interesting for you

> [@POST /api/system/refreshIdentities](https://developer.sailpoint.com/discuss/t/post-api-system-refreshidentities/24315):
>
> This API has a number of features that can be controlled in the request body. Here are the replacements for the following capabilities. To “promoteAttributes”, use [start-identity-processing | SailPoint Developer Community](https://developer.sailpoint.com/idn/api/beta/start-identity-processing) To “pruneIdentities”, use [delete-identity | SailPoint Developer Community](https://developer.sailpoint.com/idn/api/beta/delete-identity) To “synchronizeAttributes”, use [synchronize-attributes-for-identity | SailPoint Developer Community](https://developer.sailpoint.com/idn/api/beta/synchronize-attributes-for-identity) “filter” can be implemented using the [search API](https://developer.sailpoint.com/idn/api/v3/search-post) or [list identities API](https://developer.sailpoint.com/idn/api/beta/list-identities) to get a list of identities ba…

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [March 16, 2024, 6:37pm UTC](https://developer.sailpoint.com/discuss/t/403-when-using-the-cc-api-system-refreshidentities-api-with-python/24284/9 "2024-03-16T18:37:40Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
