Get identity by filter
GET/intelligence/v1/identities
Requires tenant license idn:response-and-remediation.
Resolves exactly one identity by SCIM-style filters expression and returns the Intelligence envelope.
Supported queryable fields are id and email only.
The response embeds the first page of accounts, rare access, access-history access items, and
access-history certifications. Each paged slice includes totalCount from upstream
X-Total-Count when items is non-empty, and carries a next continuation URL when
totalCount exceeds the items returned on this page. Empty slices render as items: [] with no
totalCount. The privilegedAccess slice contains the full result and is not paged; it never
carries next or totalCount.
The outliers slice is omitted when the tenant lacks the IDA-outliers license.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 409
- 429
- 500
Exactly one identity matched.
Client Error - Returned if the request body is invalid.
Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.
Forbidden - Returned if the user you are running as, doesn't have access to this end-point.
Not Found - returned if the request URL refers to a resource or object that does not exist
Multiple identities matched the filter.
Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.
Internal Server Error - Returned if there is an unexpected error.