Get accounts selections for identity
POST/access-requests/v1/accounts-selection
This API is currently in an experimental state. The API is subject to change based on feedback and further testing. You must include the X-SailPoint-Experimental header and set it to true to use this endpoint.
Use this API to fetch account information for an identity against the items in an access request.
Used to fetch accountSelection for the AccessRequest prior to submitting for async processing.
Machine identities
-
Must use
requestedForWithRequestedItemswithidentityType: MACHINEon each entry. -
Fields
requestedFor/requestedItemsare not supported and should be omitted. -
Only
ENTITLEMENTitems are supported. -
Mixed human and machine identities in one request are not supported.
-
Response identities use
type: MACHINE_IDENTITY. Use the returned accountaccountUuid/nativeIdentityvalues when submitting the access request; invalid or mismatched account details are rejected on create. -
If the machine has no account on a requested source, the item may be returned with
accountsSelectionBlocked: trueandaccountsSelectionBlockedReason: NO_ACCOUNT_ON_SOURCE(empty accounts on the response in that blocked case is expected). -
Same licensing,
machineIdentityAccessRequestEnabled, and request-on-behalf-of rules as create access request apply.
Request
Responses
- 200
- 400
- 401
- 403
- 429
- 500
Accounts Selection Response
Client Error - Returned if the request body is invalid.
Unauthorized - Returned if there is no authorization header, or if the JWT token is expired.
Forbidden - Returned if the user you are running as, doesn't have access to this end-point.
Too Many Requests - Returned in response to too many requests in a given period of time - rate limited. The Retry-After header in the response includes how long to wait before trying again.
Internal Server Error - Returned if there is an unexpected error.