---
title: "comp API"
description: "Version: inferred"
last_updated: "2026-05-06T07:33:43.368771+00:00"
canonical_url: "https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/api/api-overview"
---

# comp API

**Version:** inferred

**288** endpoints detected from `(inferred from code)`

## Endpoints

### General

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/api/docs` | Redirect to Swagger documentation ~~deprecated~~ |
| `POST` | `/cloud-security/scan/:connectionId` |  |
| `POST` | `/cloud-security/trigger/:connectionId` |  |
| `GET` | `/cloud-security/runs/:runId` |  |
| `GET` | `/v1/admin/integrations` | List all integrations with their credential status |
| `GET` | `/v1/admin/integrations/:providerSlug` | Get details for a specific integration |
| `POST` | `/v1/admin/integrations/credentials` | Save platform credentials for an integration |
| `DELETE` | `/v1/admin/integrations/credentials/:providerSlug` | Delete platform credentials for an integration |
| `GET` | `/integrations/checks/providers/:providerSlug` | List available checks for a provider |
| `GET` | `/integrations/checks/connections/:connectionId` | List available checks for a connection |
| `POST` | `/integrations/checks/connections/:connectionId/run` | Run checks for a connection |
| `POST` | `/integrations/checks/connections/:connectionId/run/:checkId` | Run a specific check for a connection |

### Assistant Chat

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/assistant-chat/history` | Get assistant chat history |
| `PUT` | `/assistant-chat/history` | Save assistant chat history |
| `DELETE` | `/assistant-chat/history` | Clear assistant chat history |

### Attachments

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/attachments/:attachmentId/download` | Get attachment download URL |

### Browserbase

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/browserbase/org-context` | Get or create organization browser context |
| `GET` | `/browserbase/org-context` | Get organization browser context status |
| `POST` | `/browserbase/session` | Create a new browser session |
| `POST` | `/browserbase/session/close` | Close a browser session |
| `POST` | `/browserbase/navigate` | Navigate to a URL |
| `POST` | `/browserbase/check-auth` | Check authentication status |
| `POST` | `/browserbase/automations` | Create a browser automation |
| `GET` | `/browserbase/automations/task/:taskId` | Get all browser automations for a task |
| `GET` | `/browserbase/automations/:automationId` | Get a browser automation by ID |
| `PATCH` | `/browserbase/automations/:automationId` | Update a browser automation |
| `DELETE` | `/browserbase/automations/:automationId` | Delete a browser automation |
| `POST` | `/browserbase/automations/:automationId/start-live` | Start automation with live view |
| `POST` | `/browserbase/automations/:automationId/execute` | Execute automation on existing session |
| `POST` | `/browserbase/automations/:automationId/run` | Run a browser automation |
| `GET` | `/browserbase/automations/:automationId/runs` | Get run history for an automation |
| `GET` | `/browserbase/runs/:runId` | Get a specific run by ID |

### Comments

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/comments` | Get comments for an entity |
| `POST` | `/comments` | Create a new comment |
| `PUT` | `/comments/:commentId` | Update a comment |
| `DELETE` | `/comments/:commentId` | Delete a comment |

### Context

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/context` | Get all context entries |
| `GET` | `/v1/context/:id` | Get context entry by ID |
| `POST` | `/v1/context` | Create a new context entry |
| `PATCH` | `/v1/context/:id` | Update a context entry |
| `DELETE` | `/v1/context/:id` | Delete a context entry |

### Device Agent

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/device-agent/mac` | Download macOS device agent |
| `GET` | `/v1/device-agent/windows` | Download Windows device agent |
| `GET` | `/api/device-agent/status` | Retrieve device agent status |
| `GET` | `/api/download-agent` | Download a device agent installer |
| `HEAD` | `/api/download-agent` | Get metadata for a device agent installer |
| `POST` | `/api/download-agent/token` | Create a one-time download token for a device agent |

### Devices

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/devices` | Get all devices |
| `GET` | `/v1/devices/member/:memberId` | Get devices by member ID |

### Evidence Forms

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/evidence-forms` | List evidence forms |
| `GET` | `/v1/evidence-forms/statuses` | Get submission statuses for all forms |
| `GET` | `/v1/evidence-forms/my-submissions` | Get current user submissions |
| `GET` | `/v1/evidence-forms/my-submissions/pending-count` | Get pending submission count for current user |
| `GET` | `/v1/evidence-forms/:formType` | Get form definition and submissions |
| `GET` | `/v1/evidence-forms/:formType/submissions/:submissionId` | Get a single submission |
| `POST` | `/v1/evidence-forms/:formType/submissions` | Submit evidence form entry |
| `PATCH` | `/v1/evidence-forms/:formType/submissions/:submissionId/review` | Review a submission |
| `POST` | `/v1/evidence-forms/uploads` | Upload evidence form file |
| `GET` | `/v1/evidence-forms/:formType/export.csv` | Export form submissions to CSV |
| `POST` | `/api/evidence-forms/analyze` | Analyze evidence form submissions using AI. |

### Finding Templates

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/finding-template` | Get all finding templates |
| `GET` | `/v1/finding-template/:id` | Get finding template by ID |
| `POST` | `/v1/finding-template` | Create a finding template |
| `PATCH` | `/v1/finding-template/:id` | Update a finding template |
| `DELETE` | `/v1/finding-template/:id` | Delete a finding template |

### Findings

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/findings` | Get findings for a task |
| `GET` | `/v1/findings/organization` | Get all findings for organization |
| `GET` | `/v1/findings/:id` | Get finding by ID |
| `POST` | `/v1/findings` | Create a finding |
| `PATCH` | `/v1/findings/:id` | Update a finding |
| `DELETE` | `/v1/findings/:id` | Delete a finding |
| `GET` | `/v1/findings/:id/history` | Get finding history |

### Framework Editor Task Templates

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/framework-editor/task-template` | Get all task templates |
| `GET` | `/v1/framework-editor/task-template/:id` | Get task template by ID |
| `PATCH` | `/v1/framework-editor/task-template/:id` | Update a task template |
| `DELETE` | `/v1/framework-editor/task-template/:id` | Delete a task template |

### Health

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/health` | Health check |

### Connections

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/integrations/connections/providers` | List all available integration providers |
| `GET` | `/integrations/connections/providers/:slug` | Get a specific provider's details |
| `GET` | `/integrations/connections` | List connections for an organization |
| `GET` | `/integrations/connections/:id` | Get a specific connection |
| `POST` | `/integrations/connections` | Create a new connection with API key credentials |
| `POST` | `/integrations/connections/:id/test` | Test a connection's credentials |
| `POST` | `/integrations/connections/:id/pause` | Pause a connection |
| `POST` | `/integrations/connections/:id/resume` | Resume a paused connection |
| `POST` | `/integrations/connections/:id/disconnect` | Disconnect (soft delete) a connection |
| `DELETE` | `/integrations/connections/:id` | Delete a connection permanently |
| `PATCH` | `/integrations/connections/:id` | Update connection metadata (connectionName, regions, etc.) |
| `POST` | `/integrations/connections/:id/ensure-valid-credentials` | Get valid credentials for a connection, refreshing OAuth tokens if needed. |
| `PUT` | `/integrations/connections/:id/credentials` | Update credentials for a custom auth connection |

### integrations

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/integrations/oauth-apps` | List custom OAuth apps for an organization |
| `GET` | `/v1/integrations/oauth-apps/setup/:providerSlug` | Get OAuth app setup info for a provider |
| `POST` | `/v1/integrations/oauth-apps` | Save custom OAuth app credentials for an organization |
| `DELETE` | `/v1/integrations/oauth-apps/:providerSlug` | Delete custom OAuth app credentials for an organization |
| `GET` | `/v1/integrations/oauth/availability` | Check if OAuth credentials are available for a provider |
| `POST` | `/v1/integrations/oauth/start` | Start OAuth flow - returns authorization URL |
| `GET` | `/v1/integrations/oauth/callback` | OAuth callback - exchanges code for tokens |

### Integration Sync

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `integrations/sync/google-workspace/employees` | Sync employees from Google Workspace |
| `POST` | `integrations/sync/google-workspace/status` | Check if Google Workspace is connected for an organization |
| `POST` | `integrations/sync/rippling/employees` | Sync employees from Rippling |
| `POST` | `integrations/sync/rippling/status` | Check if Rippling is connected for an organization |
| `POST` | `integrations/sync/ramp/employees` | Sync employees from Ramp |
| `POST` | `integrations/sync/jumpcloud/employees` | Sync employees from JumpCloud |
| `POST` | `integrations/sync/jumpcloud/status` | Check if JumpCloud is connected for an organization |
| `POST` | `integrations/sync/ramp/status` | Check if Ramp is connected for an organization |
| `GET` | `integrations/sync/employee-sync-provider` | Get the current employee sync provider for an organization |
| `POST` | `integrations/sync/employee-sync-provider` | Set the employee sync provider for an organization |

### Task Integrations

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/integrations/tasks/template/:templateId/checks` | Get all integration checks that can auto-complete a specific task template |
| `GET` | `/integrations/tasks/:taskId/checks` | Get integration checks for a specific task (by task ID) |
| `POST` | `/integrations/tasks/:taskId/run-check` | Run a specific check for a task and store results |
| `GET` | `/integrations/tasks/:taskId/runs` | Get check run history for a task |

### Integration Variables

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/integrations/variables/providers/:providerSlug` | Get all variables required for a provider's checks |
| `GET` | `/integrations/variables/connections/:connectionId` | Get variables for a specific connection (with current values) |
| `GET` | `/integrations/variables/connections/:connectionId/options/:variableId` | Fetch dynamic options for a variable (requires active connection) |
| `POST` | `/integrations/variables/connections/:connectionId` | Save variable values for a connection |

### Webhooks

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/integrations/webhooks/:providerSlug/:connectionId` | Handle incoming webhooks for a specific provider and connection |

### Knowledge Base

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/knowledge-base/documents` | List all knowledge base documents for an organization |
| `POST` | `/knowledge-base/documents/upload` | Upload a knowledge base document |
| `POST` | `/knowledge-base/documents/:documentId/download` | Get a signed download URL for a knowledge base document |
| `POST` | `/knowledge-base/documents/:documentId/view` | Get a signed view URL for a knowledge base document |
| `POST` | `/knowledge-base/documents/:documentId/delete` | Delete a knowledge base document |
| `POST` | `/knowledge-base/documents/process` | Trigger processing of knowledge base documents |
| `POST` | `/knowledge-base/runs/:runId/token` | Create a public access token for a Trigger.dev run |
| `POST` | `/knowledge-base/manual-answers/:manualAnswerId/delete` | Delete a manual answer |
| `POST` | `/knowledge-base/manual-answers/delete-all` | Delete all manual answers for an organization |

### Org Chart

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/org-chart` | Get the organization chart |
| `PUT` | `/org-chart` | Create or update an interactive organization chart |
| `POST` | `/org-chart/upload` | Upload an image as the organization chart |
| `DELETE` | `/org-chart` | Delete the organization chart |

### Organization

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/organization` | Get organization details |
| `PATCH` | `/organization` | Update organization details |
| `POST` | `/organization/transfer-ownership` | Transfer organization ownership |
| `DELETE` | `/organization` | Delete an organization |
| `GET` | `/organization/primary-color` | Get organization primary color |

### People

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/people` | Get all people for an organization |
| `POST` | `/people` | Create a new person (member) |
| `POST` | `/people/bulk` | Bulk create people (members) |
| `GET` | `/people/:id` | Get a person (member) by ID |
| `PATCH` | `/people/:id` | Update a person (member) |
| `DELETE` | `/people/:id/host/:hostId` | Remove a host from a person (member) |
| `DELETE` | `/people/:id` | Delete a person (member) |
| `PATCH` | `/people/:id/unlink-device` | Unlink a device from a person (member) |

### Policies

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/policies` | Get all policies for an organization |
| `GET` | `/policies/download-all` | Download all published policies as a single PDF |
| `GET` | `/policies/:id` | Get a policy by ID |
| `POST` | `/policies` | Create a new policy |
| `PATCH` | `/policies/:id` | Update a policy |
| `DELETE` | `/policies/:id` | Delete a policy |
| `GET` | `/policies/:id/versions` | Get all versions for a policy |
| `GET` | `/policies/:id/versions/:versionId` | Get a policy version by ID |
| `POST` | `/policies/:id/versions` | Create a new policy version |
| `PATCH` | `/policies/:id/versions/:versionId` | Update policy version content |
| `DELETE` | `/policies/:id/versions/:versionId` | Delete a policy version |
| `POST` | `/policies/:id/versions/publish` | Publish a policy version |
| `POST` | `/policies/:id/versions/:versionId/activate` | Set a policy version as active |
| `POST` | `/policies/:id/versions/:versionId/submit-for-approval` | Submit a policy version for approval |
| `POST` | `/policies/:id/ai-chat` | Chat with AI about a policy |

### Questionnaire

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/questionnaire/parse` | Parse questionnaire content |
| `POST` | `/questionnaire/answer-single` | Generated single answer result |
| `POST` | `/questionnaire/save-answer` | Save manual or generated answer |
| `POST` | `/questionnaire/delete-answer` | Delete questionnaire answer |
| `POST` | `/questionnaire/export` | Export questionnaire by ID to specified format |
| `POST` | `/questionnaire/upload-and-parse` | Upload file, parse questions (no answers), save to DB, return questionnaireId |
| `POST` | `/questionnaire/upload-and-parse/upload` | Upload file, parse questions (no answers), save to DB, return questionnaireId |
| `POST` | `/questionnaire/parse/upload` |  |
| `POST` | `/questionnaire/parse/upload/token` |  |
| `POST` | `/questionnaire/answers/export` |  |
| `POST` | `/questionnaire/answers/export/upload` |  |
| `POST` | `/questionnaire/auto-answer` |  |

### Risks

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/risks` | Get all risks for an organization |
| `GET` | `/risks/:id` | Get a risk by its ID |
| `POST` | `/risks` | Create a new risk |
| `PATCH` | `/risks/:id` | Update an existing risk |
| `DELETE` | `/risks/:id` | Delete a risk |

### SOA

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/soa/save-answer` | Save a SOA answer |
| `POST` | `/soa/auto-fill` | Auto-fill SOA document |
| `POST` | `/soa/create-document` | Create a new SOA document |
| `POST` | `/soa/ensure-setup` | Ensure SOA configuration and document exist |
| `POST` | `/soa/approve` | Approve a SOA document |
| `POST` | `/soa/decline` | Decline a SOA document |
| `POST` | `/soa/submit-for-approval` | Submit SOA document for approval |

### Task Management

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/task-management/stats` | Get task items statistics for an entity |
| `GET` | `/task-management` | Get task items for an entity |
| `POST` | `/task-management` | Create a new task item |
| `PUT` | `/task-management/:id` | Update a task item |
| `DELETE` | `/task-management/:id` | Delete a task item |
| `POST` | `/task-management/attachments` | Upload attachment to task item |
| `DELETE` | `/task-management/attachments/:attachmentId` | Delete attachment from task item |
| `GET` | `/task-management/:id/activity` | Get task item activity log |

### Task Automations

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/tasks/:taskId/automations` | Get all automations for a task |
| `GET` | `/tasks/:taskId/automations/:automationId` | Get automation details |
| `POST` | `/tasks/:taskId/automations` | Create a new automation |
| `PATCH` | `/tasks/:taskId/automations/:automationId` | Update an automation |
| `DELETE` | `/tasks/:taskId/automations/:automationId` | Delete an automation |
| `GET` | `/tasks/:taskId/automations/:automationId/versions` | Get all versions for an automation |
| `GET` | `/tasks/:taskId/automations/runs` | Get all automation runs for a task |

### Evidence Export

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/tasks/:taskId/evidence` | Get task evidence summary |
| `GET` | `/v1/tasks/:taskId/evidence/automation/:automationId/pdf` | Export automation evidence as PDF |
| `GET` | `/v1/tasks/:taskId/evidence/export` | Export task evidence as ZIP |

### Evidence Export (Auditor)

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/evidence-export/all` | Export all organization evidence as ZIP (Auditor only) |

### Internal - Tasks

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/v1/internal/tasks/notify-status-change` | Send task status change notifications (email + in-app) without a user actor (internal) |
| `POST` | `/v1/internal/tasks/notify-automation-failures` | Send automation failure notifications (email + in-app) when one or more automations fail (internal) |

### Tasks

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/v1/tasks` | Get all tasks |
| `PATCH` | `/v1/tasks/bulk` | Update status for multiple tasks |
| `PATCH` | `/v1/tasks/bulk/assignee` | Update assignee for multiple tasks |
| `POST` | `/v1/tasks/bulk/submit-for-review` | Bulk submit tasks for review |
| `DELETE` | `/v1/tasks/bulk` | Delete multiple tasks |
| `GET` | `/v1/tasks/:taskId` | Get task by ID |
| `GET` | `/v1/tasks/:taskId/activity` | Get task activity |
| `PATCH` | `/v1/tasks/:taskId` | Update a task |
| `POST` | `/v1/tasks/:taskId/submit-for-review` | Submit task for review |
| `POST` | `/v1/tasks/:taskId/approve` | Approve a task |
| `POST` | `/v1/tasks/:taskId/reject` | Reject a task review |
| `GET` | `/v1/tasks/:taskId/attachments` | Get task attachments |
| `POST` | `/v1/tasks/:taskId/attachments` | Upload attachment to task |
| `GET` | `/v1/tasks/:taskId/attachments/:attachmentId/download` | Get attachment download URL |
| `DELETE` | `/v1/tasks/:taskId/attachments/:attachmentId` | Delete task attachment |

### Training

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/training/send-completion-email` | Send training completion email with certificate |
| `POST` | `/training/generate-certificate` | Generate training completion certificate PDF |

### Trust Access

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/v1/trust-access/:friendlyUrl/requests` | Submit data access request |
| `GET` | `/v1/trust-access/admin/requests` | List access requests |
| `GET` | `/v1/trust-access/admin/requests/:id` | Get access request details |
| `POST` | `/v1/trust-access/admin/requests/:id/approve` | Approve access request |
| `POST` | `/v1/trust-access/admin/requests/:id/deny` | Deny access request |
| `GET` | `/v1/trust-access/admin/grants` | List access grants |
| `POST` | `/v1/trust-access/admin/grants/:id/revoke` | Revoke access grant |
| `POST` | `/v1/trust-access/admin/grants/:id/resend-access-email` | Resend access granted email |
| `GET` | `/v1/trust-access/nda/:token` | Get NDA details by token |
| `POST` | `/v1/trust-access/nda/:token/preview-nda` | Preview NDA by token |
| `POST` | `/v1/trust-access/nda/:token/sign` | Sign NDA |
| `POST` | `/v1/trust-access/admin/requests/:id/resend-nda` | Resend NDA email |
| `POST` | `/v1/trust-access/admin/requests/:id/preview-nda` | Preview NDA PDF |
| `POST` | `/v1/trust-access/:friendlyUrl/reclaim` | Reclaim access |
| `GET` | `/v1/trust-access/access/:token` | Get grant data by access token |
| `GET` | `/v1/trust-access/access/:token/policies` | List policies by access token |
| `GET` | `/v1/trust-access/access/:token/policies/download-all` | Download all policies as watermarked PDF |
| `GET` | `/v1/trust-access/access/:token/policies/download-all-zip` | Download all policies as ZIP with individual PDFs |
| `GET` | `/v1/trust-access/access/:token/compliance-resources` | List compliance resources by access token |
| `GET` | `/v1/trust-access/access/:token/documents` | List additional documents by access token |
| `GET` | `/v1/trust-access/access/:token/documents/download-all` | Download all additional documents as a ZIP by access token |
| `GET` | `/v1/trust-access/access/:token/documents/:documentId` | Download additional document by access token |
| `GET` | `/v1/trust-access/access/:token/compliance-resources/:framework` | Download compliance resource by access token |
| `GET` | `/v1/trust-access/:friendlyUrl/faqs` | Get FAQs for a trust portal |
| `GET` | `/v1/trust-access/:friendlyUrl/overview` | Get overview section for a trust portal |
| `GET` | `/v1/trust-access/:friendlyUrl/custom-links` | Get custom links for a trust portal |
| `GET` | `/v1/trust-access/:friendlyUrl/favicon` | Get favicon URL for a trust portal |
| `GET` | `/v1/trust-access/:friendlyUrl/vendors` | Get vendors/subprocessors for a trust portal |

### Trust Portal

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/trust-portal/domain/status` | Get domain verification status |
| `POST` | `/trust-portal/compliance-resources/upload` | Upload or replace a compliance certificate (PDF only) |
| `POST` | `/trust-portal/compliance-resources/signed-url` | Generate a temporary signed URL for a compliance certificate |
| `POST` | `/trust-portal/compliance-resources/list` | List uploaded compliance certificates for the organization |
| `POST` | `/trust-portal/documents/upload` | Upload an additional trust portal document |
| `POST` | `/trust-portal/documents/list` | List additional trust portal documents for the organization |
| `POST` | `/trust-portal/documents/:documentId/download` | Generate a temporary signed URL for a trust portal document |
| `POST` | `/trust-portal/documents/:documentId/delete` | Delete (deactivate) a trust portal document |
| `POST` | `/trust-portal/overview` | Update trust portal overview section |
| `GET` | `/trust-portal/overview` | Get trust portal overview |
| `POST` | `/trust-portal/custom-links` | Create a custom link for trust portal |
| `POST` | `/trust-portal/custom-links/:linkId` | Update a custom link |
| `POST` | `/trust-portal/custom-links/:linkId/delete` | Delete a custom link |
| `POST` | `/trust-portal/custom-links/reorder` | Reorder custom links |
| `GET` | `/trust-portal/custom-links` | List custom links for trust portal |
| `POST` | `/trust-portal/vendors/:vendorId/trust-settings` | Update vendor trust portal settings |
| `GET` | `/trust-portal/vendors` | List vendors configured for trust portal |

### Internal - Vendors

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/internal/vendors/risk-assessment/trigger-batch` | Trigger vendor risk assessment tasks for a batch of vendors (internal) |
| `POST` | `/internal/vendors/risk-assessment/trigger-single` | Trigger vendor risk assessment for a single vendor and return run info (internal) |

### Vendors

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/vendors` | Get all vendors for an organization |
| `GET` | `/vendors/:id` | Get a vendor by ID |
| `POST` | `/vendors` | Create a new vendor |
| `PATCH` | `/vendors/:id` | Update an existing vendor |
| `DELETE` | `/vendors/:id` | Delete a vendor |

### Auth

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/api/auth/invitation` | Handle invitation link redirection |
| `GET` | `/api/auth/test-db` | Test database connection (E2E only) |
| `POST` | `/api/auth/test-login` | Perform a test login for E2E (Internal Only) |

### AI

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/api/chat` | Engage in AI chat |

### Cloud Tests

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/api/cloud-tests/findings` | Retrieve cloud test findings for an organization. |
| `GET` | `/api/cloud-tests/providers` | Retrieve active cloud providers for an organization. |

### File Management

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/api/get-image-url` | Get a signed URL for an image stored in S3. |

### QA Internal

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/api/qa/approve-org` | Approve an organization by setting hasAccess to true (QA internal). |
| `POST` | `/api/qa/delete-user` | Delete a user and all associated data (QA internal). |

### Retool Internal

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/api/retool/reset-org` | Resets an organization's data |

### Secrets

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/api/secrets/:id` | Get a specific secret |
| `PUT` | `/api/secrets/:id` | Update a secret |
| `DELETE` | `/api/secrets/:id` | Delete a secret |
| `GET` | `/api/secrets` | List all secrets for the organization |
| `POST` | `/api/secrets` | Create a new secret |

### User Data

| Method | Path | Description |
|--------|------|-------------|
| `GET` | `/api/user-frameworks` | Retrieve user frameworks |

### Fleet Policies

| Method | Path | Description |
|--------|------|-------------|
| `POST` | `/api/confirm-fleet-policy` | Confirms a fleet policy and uploads attachments. |


## Sitemap

See the full [sitemap](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/llms.txt) for all pages in this wiki.
