Skip to content
Updawg
Search
Ctrl
K
Cancel
Select theme
Dark
Light
Auto
Menu
Install the agent
Overview
Debian
Ubuntu
RHEL, Rocky, AlmaLinux, Oracle
Amazon Linux 2023
Without a package manager
Ansible
cloud-init
Golden images
Uninstall
The agent
Configuration
What it collects
Every field, exactly
Updating the agent
Policies
Reference
Examples
Your organization
Compliance reports
Single sign-on
SCIM provisioning
Using the API
Authentication
Pagination
Errors
Rate limits
Terraform and OpenTofu
API reference
Overview
session
Overview
`POST /v1/auth/logout`.
`POST /v1/auth/magic-link`.
`POST /v1/auth/magic-link/verify`.
`GET /v1/auth/oidc/{provider}/callback`.
`POST /v1/auth/oidc/{provider}/callback`: the same, for a provider that posts its answer (Apple).
`GET /v1/auth/oidc/{provider}/start`.
`GET /v1/auth/providers`.
`POST /v1/auth/sign-up`.
`POST /v1/auth/sign-up/verify`.
`GET /v1/auth/sso/callback`.
`GET /v1/auth/sso/discover`.
`GET /v1/auth/sso/{org}/start`.
`GET /v1/me`.
`DELETE /v1/me`: erase the caller (DAWG-170).
`GET /v1/me/export`: everything Updawg holds about the caller, as one JSON document (DAWG-170). A data subject access request, answered without having to ask.
organizations
Overview
`POST /v1/invitations/accept`.
`POST /v1/invitations/join`.
`POST /v1/orgs`.
`GET /v1/orgs/{org}`.
`PATCH /v1/orgs/{org}`.
`GET /v1/orgs/{org}/invitations`.
`POST /v1/orgs/{org}/invitations`.
`DELETE /v1/orgs/{org}/invitations/{id}`.
`GET /v1/orgs/{org}/members`.
`DELETE /v1/orgs/{org}/members/{user_id}`.
`PATCH /v1/orgs/{org}/members/{user_id}`.
enrollment
Overview
`GET /v1/orgs/{org}/enrollment-tokens`.
`POST /v1/orgs/{org}/enrollment-tokens`.
`DELETE /v1/orgs/{org}/enrollment-tokens/{token_id}`.
notifications
Overview
`POST /v1/digests/unsubscribe`.
`GET /v1/orgs/{org}/digest`.
`PUT /v1/orgs/{org}/digest`.
`GET /v1/orgs/{org}/notification-channels`.
`POST /v1/orgs/{org}/notification-channels`.
`DELETE /v1/orgs/{org}/notification-channels/{channel_id}`.
`PATCH /v1/orgs/{org}/notification-channels/{channel_id}`.
`GET /v1/orgs/{org}/notification-channels/{channel_id}/deliveries`.
`POST /v1/orgs/{org}/notification-channels/{channel_id}/deliveries/{delivery_id}/replay`.
`POST /v1/orgs/{org}/notification-channels/{channel_id}/test`.
`GET /v1/orgs/{org}/notification-rules`.
`POST /v1/orgs/{org}/notification-rules`.
`DELETE /v1/orgs/{org}/notification-rules/{rule_id}`.
`PATCH /v1/orgs/{org}/notification-rules/{rule_id}`.
groups
Overview
`GET /v1/orgs/{org}/groups`.
`POST /v1/orgs/{org}/groups`.
`GET /v1/orgs/{org}/groups/{group_id}`.
`DELETE /v1/orgs/{org}/groups/{group_id}`.
`PATCH /v1/orgs/{org}/groups/{group_id}`.
`PUT /v1/orgs/{org}/groups/{group_id}/hosts`.
audit
Overview
audit_log_list
`GET /v1/orgs/{org}/audit-log/export`.
compliance
Overview
`GET /v1/orgs/{org}/compliance/export`.
`GET /v1/orgs/{org}/compliance/report`.
`GET /v1/orgs/{org}/compliance/targets`.
`PUT /v1/orgs/{org}/compliance/targets`.
signing-keys
Overview
`GET /v1/orgs/{org}/signing-keys`.
`POST /v1/orgs/{org}/signing-keys/rotate`.
sso
Overview
`GET /v1/orgs/{org}/scim/token`.
`POST /v1/orgs/{org}/scim/token`.
`DELETE /v1/orgs/{org}/scim/token`.
`GET /v1/orgs/{org}/sso`.
`PUT /v1/orgs/{org}/sso`.
`DELETE /v1/orgs/{org}/sso`.
`POST /v1/orgs/{org}/sso/domains`.
`DELETE /v1/orgs/{org}/sso/domains/{domain}`.
`POST /v1/orgs/{org}/sso/domains/{domain}/verify`.
hosts
Overview
Which agent build each release channel holds (DAWG-46), for comparing with a host's `agent_version`. The channels are Updawg's and the same for every organization; this is under one only so that it asks for a session like everything else here. Empty until the worker has read a manifest.
hosts_list
`POST /v1/orgs/{org}/hosts/bulk` (DAWG-78): one action on many hosts.
hosts_show
`DELETE /v1/orgs/{org}/hosts/{host_id}` — decommission (DAWG-285).
`PATCH /v1/orgs/{org}/hosts/{host_id}` (DAWG-285).
The host's timeline, newest first: jobs finishing, refused or expiring, and the host going stale and coming back. What a person did *to* the host — relabelling, decommissioning — is the audit log's, filtered by target.
`GET /v1/orgs/{org}/hosts/{host_id}/exposures` (DAWG-212).
`POST /v1/orgs/{org}/hosts/{host_id}/purge` — delete a decommissioned host (DAWG-286).
Whether this host's third-party repositories publish the releases it could upgrade to (DAWG-149), from the daily probe. One entry per repository and target release; empty until the probe has run, for a host with no third-party repositories, or one whose agent is older than protocol 0.6.
The vulnerabilities this host is affected by that **nothing fixes in its release** (DAWG-212 part 2): no advisory will ever name them, so neither the update list nor [`exposures`] can. Debian only, from the security tracker; worst first, then longest standing.
advisories
Overview
`GET /v1/orgs/{org}/advisories` (DAWG-288).
`GET /v1/orgs/{org}/advisories/{advisory_id}/hosts` (DAWG-288).
proposals
Overview
`GET /v1/orgs/{org}/jobs/{job_id}/logs`.
`GET /v1/orgs/{org}/proposals`.
`GET /v1/orgs/{org}/proposals/{proposal_id}`.
`POST /v1/orgs/{org}/proposals/{proposal_id}/approve`.
`POST /v1/orgs/{org}/proposals/{proposal_id}/cancel` (DAWG-100).
`GET /v1/orgs/{org}/proposals/{proposal_id}/comments`.
`POST /v1/orgs/{org}/proposals/{proposal_id}/comments`.
`POST /v1/orgs/{org}/proposals/{proposal_id}/halt` (DAWG-100).
`GET /v1/orgs/{org}/proposals/{proposal_id}/jobs`.
A proposal's preflight: whether one can be asked for, who asked last, and what each host it targets found (DAWG-153).
Ask every host a proposal targets whether it can take the change (DAWG-153).
`POST /v1/orgs/{org}/proposals/{proposal_id}/reject`.
`POST /v1/orgs/{org}/proposals/{proposal_id}/resume` (DAWG-110).
A proposal's rollback: whether one can be asked for, and exactly what it does to each host (DAWG-120). What the portal's confirmation says.
Roll a halted, merged or failed proposal back (DAWG-120).
`GET /v1/orgs/{org}/proposals/{proposal_id}/rollout`.
`POST /v1/orgs/{org}/proposals/{proposal_id}/snooze`.
`GET /v1/orgs/{org}/rollouts`.
policies
Overview
`GET /v1/orgs/{org}/policies`.
`POST /v1/orgs/{org}/policies`.
`POST /v1/orgs/{org}/policies/preview`.
`POST /v1/orgs/{org}/policies/validate`.
`GET /v1/orgs/{org}/policies/{policy_id}`, optionally `?version=2`.
`PUT /v1/orgs/{org}/policies/{policy_id}`.
`DELETE /v1/orgs/{org}/policies/{policy_id}`.
`GET /v1/orgs/{org}/policies/{policy_id}/versions`.
releases
Overview
Plan a release upgrade (DAWG-153): open a `dist_upgrade` proposal for every host on `from` — or those in one group — to `to`.
`GET /v1/orgs/{org}/releases`.
events
Overview
`GET /v1/orgs/{org}/events`.
billing
Overview
`GET /v1/orgs/{org}/billing`.
`POST /v1/orgs/{org}/billing/checkout`.
`POST /v1/orgs/{org}/billing/plan` (DAWG-145): move a live subscription between Team, Business and Enterprise.
`POST /v1/orgs/{org}/billing/portal` (DAWG-144, DAWG-145).
`GET /v1/orgs/{org}/billing/usage` (DAWG-144).
`POST /v1/stripe/webhook`.
api-tokens
`GET /v1/orgs/{org}/api-tokens`.
`POST /v1/orgs/{org}/api-tokens`.
`DELETE /v1/orgs/{org}/api-tokens/{api_token_id}`.
Security
Select theme
Dark
Light
Auto
Overview
hosts
Section titled “hosts”
The fleet: what is in it and what one host looks like.
Operations
Section titled “Operations”
GET
/v1/orgs/{org}/agent-releases
GET
/v1/orgs/{org}/hosts
POST
/v1/orgs/{org}/hosts/bulk
GET
/v1/orgs/{org}/hosts/{host_id}
DELETE
/v1/orgs/{org}/hosts/{host_id}
PATCH
/v1/orgs/{org}/hosts/{host_id}
GET
/v1/orgs/{org}/hosts/{host_id}/events
GET
/v1/orgs/{org}/hosts/{host_id}/exposures
POST
/v1/orgs/{org}/hosts/{host_id}/purge
GET
/v1/orgs/{org}/hosts/{host_id}/readiness
GET
/v1/orgs/{org}/hosts/{host_id}/unfixed