/api/app/security-overview/merchant-posture
GET
/api/app/security-overview/merchant-posture
deprecated
Requires: AbpIdentity.Users, host scope.
**Required permissions**: `AbpIdentity.Users` **Scope**: host
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a . See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
MerchantId
required |
query | string (uuid) | |
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
Request body
application/json
, required
| Field | Type | Description |
|---|
This request body has no documented fields.
Responses
200 OK
Body: MerchantSecurityPostureDto
Each item has these fields.
| Field | Type | Description |
|---|---|---|
merchantId
required |
string (uuid) | The merchant the counts cover, when they cover exactly one. nullable |
isTenantWide
required |
boolean | Whether the counts cover every account and key in the tenant, which only an administrator reaches. |
scopedMerchantCount
required |
integer (int32) | How many merchants the counts cover. Zero alongside `isTenantWide` being `false` means the caller can act for no merchant, so there was nothing to count. |
userCount
required |
integer (int32) | Accounts in scope among those the scan examined. |
usersWithMfa
required |
integer (int32) | Accounts with a second factor enrolled. |
usersWithStalePassword
required |
integer (int32) | Accounts whose password is older than `stalePasswordThresholdDays`, or that have no recorded change at all. |
stalePasswordThresholdDays
required |
integer (int32) | The age at which a password counts as stale here. Follows the tenant's own rotation period when rotation is enforced, and otherwise falls back to a fixed default so the column still means something for a tenant that has not set a policy. |
userCountTruncated
required |
boolean | Whether the account scan reached its limit, in which case accounts in scope may never have been examined and every account count here is a floor rather than a total. |
apiKeyCount
required |
integer (int32) | API keys in scope. A total unless `apiKeyCountTruncated` is set. |
dormantApiKeys
required |
integer (int32) | Keys with no recorded use for longer than `dormantApiKeyThresholdDays`. A key that has never been used is measured from its creation, so one minted this morning is not reported as dormant. |
dormantApiKeyThresholdDays
required |
integer (int32) | The idle age at which a key counts as dormant. |
apiKeysWithoutSourceRestriction
required |
integer (int32) | Keys not bound to any source address, and so usable from anywhere. |
apiKeyCountTruncated
required |
boolean | Whether more keys are in scope than the scan examined. Unlike the account scan this one is narrowed store-side, so the keys counted are all in scope and only the bound was reached. |
This response has no documented body fields.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
400 Bad Request
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.