Policy Reports
Policies API v1 endpoints for policy reports, scan findings, and publishing scan results.
Applies to: Nirmata Control Hub 4.0 and later
The Policies API v1 is a JSON REST API for the policy and compliance data in Nirmata Control Hub. Use it to read policy reports and findings, manage policy exceptions and exception requests, and work with compliance standards, controls, and compliance reports.
Unlike the model-based platform API, the v1 API uses fixed resource paths and plain
JSON request and response bodies. The URL parameters (fields, filter, query, and so on)
and common endpoints do not apply to v1 endpoints.
All endpoints are served under:
https://<your-nirmata-host>/policies/api/v1
For Nirmata Control Hub SaaS, <your-nirmata-host> is nirmata.io.
Every request needs an Authorization header. Two schemes are supported:
Authorization: NIRMATA-API <api-token>
Authorization: Bearer <jwt>
To create an API token, see API Tokens. Requests run as the user who owns the token, scoped to that user’s tenant. You never pass a tenant ID explicitly.
export NIRMATA_URL=https://nirmata.io
export NIRMATA_TOKEN=<api-token>
curl -s -H "Authorization: NIRMATA-API $NIRMATA_TOKEN" \
"$NIRMATA_URL/policies/api/v1/policy-reports?limit=10"
Access is controlled by the user roles in Nirmata Control Hub (see Users and Roles). Each endpoint lists the roles allowed to call it. The table below summarizes the default permissions for the resources in this reference:
| Resource | admin, platform | security | devops |
|---|---|---|---|
| Policy reports and findings | Read, write, delete | Read, write, delete | Read |
| Compliance standards, controls, and reports | Read, write, delete | Read, write, delete | Read |
| Policy exceptions | Read, write, delete | Read, write, delete | Read, write, delete (own only) |
| Policy exception requests | Read, write, delete | Read, write, delete | Read, write, delete (own only) |
An endpoint’s role list can be narrower than this table. For example, approving an exception request may be limited
to specific roles. A request from a user whose role is not allowed returns 403 Forbidden.
List endpoints accept limit and offset query parameters and return a page envelope:
{
"items": [ ... ],
"total": 132,
"limit": 50,
"offset": 0
}
| Parameter | Default | Description |
|---|---|---|
limit | 50 | Maximum number of items to return. |
offset | 0 | Number of items to skip. |
Some endpoints use a different envelope or extra filter parameters. Each endpoint’s reference documents its own response shape.
Errors return a standard HTTP status code and a JSON body with an error message:
{ "error": "Policy exception not found" }
| Status | Meaning |
|---|---|
400 | The request is malformed or failed validation. |
401, 403 | The credentials are missing or invalid, or the caller’s role is not allowed to perform the operation. |
404 | The resource does not exist in the caller’s tenant. |
500 | Unexpected server error. |
| Group | What it covers |
|---|---|
| Policy Reports | Policy reports, scan findings, and publishing scan results |
| Policy Exceptions | Kyverno policy exceptions and the resources they cover |
| Policy Exception Requests | Exception requests submitted for approval (read only) |
| Compliance Standards | Available standards, enablement, rescans, and custom standards |
| Compliance Reports | Compliance reports, control findings, history, and namespace compliance |
| Compliance Scans | Scheduled and on-demand compliance scans |
| Compliance Audit Reports | Generating and downloading audit report artifacts |
| Compliance Publishing | Publishing compliance snapshots and evidence packages |
| Compliance Catalog | The compliance standards and controls catalog |
Policies API v1 endpoints for policy reports, scan findings, and publishing scan results.
Policies API v1 endpoints for reading Kyverno policy exceptions.
Policies API v1 endpoints for reading policy exception requests.
Policies API v1 endpoints for compliance standards, enablement, and custom standards.
Policies API v1 endpoints for compliance reports, history, and namespace compliance.
Policies API v1 endpoints for compliance scan schedules and on-demand scans.
Policies API v1 endpoints for generating and downloading compliance audit reports.
Policies API v1 endpoints for publishing compliance snapshots and evidence packages.
Policies API v1 endpoints for the compliance standards and controls catalog.