API user roles
This section describes the predefined user roles that you can assign to API user accounts. Veracode APIs and integrations, specifically, require certain API roles. While UI users can use APIs, API users (non-human) are specifically designed for automation and use different role names.
Administrators assign roles when creating users or editing users in the Veracode Platform, or with the Identity API. If your organization uses SAML and just-in-time (JIT) provisioning, you can assign roles, including the Administrator role, automatically through SAML assertions. Users that are members of a team are limited to team-assigned resources, such as the application profile and scan results for a specific application.
API users not assigned to a team have no team restrictions and can access all resources across the entire organization. This is the opposite of UI users, who, by default, can't access any resources unless they're members of a team, or an Administrator has granted them organization-wide permissions.
If you want to limit an API user's access to specific teams, you must explicitly assign the user to one or more teams when creating or editing their account. API users assigned to teams can only access resources assigned to those teams.
Some API roles support scan type restrictions when assigning permissions. You can restrict the following roles to specific scan types (SAST, DAST, SCA, Container, IaC):
- Upload and Scan API
- Submitter-equivalent roles (Upload API - Submit Only)
When a role is restricted to specific scan types, the user can only perform create and submit actions for those scan types through the API.
Before creating and assigning user roles, we recommend reviewing User roles assignment planning.
In the tables in this section, the Scope column indicates the breadth of access granted by each role:
- Organization-wide — Grants access to organizational settings and resources across all teams.
- Team-level — Grants access only to resources assigned to the user's teams. For most roles, visibility is limited to application profiles assigned to the user's teams. To grant a user visibility across all application profiles without team assignments, you must assign the No Team Restrictions (
noteamrestrictionapi) role. - Individual — Grants access to user-specific features or settings.
Admin API
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Manage users, teams, organizations, and business units programmatically. | Organization-wide | Base Veracode Platform subscription | Admin API, Identity API |
|
Archer Report API
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Generate and retrieve Archer reports programmatically. | Organization-wide | Veracode for Archer GRC integration license | Archer Report API | Must be combined with the Submitter UI user role. |
Greenlight API User
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Submit Greenlight scans and retrieve results with the Greenlight API. | Team-level | Veracode Greenlight subscription | Greenlight API | Veracode Greenlight is deprecated. We recommend using the Veracode Scan IDE plugins with the required roles. |
Mitigation API
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Manage and approve finding mitigations programmatically. | Team-level | Veracode Static Analysis or Veracode DAST subscription | Results API, Mitigation API |
|
No Team Restrictions
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Grant API users access to all application profiles and resources across the organization without team assignment restrictions, including overriding team restrictions. | Organization-wide | Base Veracode Platform subscription | All APIs |
|
Reporting API User
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Generate and retrieve security reports and analytics. | Organization-wide | Base Veracode Platform subscription | Reporting API |
|
Results API
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Query scan results, download reports, and export data. | Team-level | Veracode Static Analysis, Veracode SCA, or Veracode DAST subscription | Results API | Can't upload files or start scans. This role is strictly "read-only" for retrieving results, reports, and sandbox lists. |
Upload and Scan API
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Manage application profiles, submit scans, manage policies, and perform full scanning workflows. | Team-level | Veracode Static Analysis, Veracode SCA, or Veracode DAST subscription | Upload API, Upload and Scan API, Dynamic Analysis API |
|
Upload API - Submit Only
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Submit scans for existing applications only; upload binaries and trigger scanning. | Team-level | Veracode Static Analysis, Veracode SCA, or Veracode DAST subscription | Upload API (Submit only) |
|
VRM Agent Service Writer
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Provision VRM runtime agents | Deploy and manage Veracode Risk Manager agents. | Organization-wide | Veracode Risk Manager subscription | VRM API | We recommend assigning this role to a dedicated API user account for the runtime agent, instead of using the default token from VRM. This ensures the runtime agent follows the principle of least privilege. |
VRM API Admin
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| Manage VRM dashboards, connectors, and issue tickets. | Organization-wide | Veracode Risk Manager subscription | VRM API | Users with this role can access resources across the entire organization without team assignment restrictions. |
VRM API Guest
| Permissions | Use case | Scope | Licensing | API endpoints | Important notes |
|---|---|---|---|---|---|
| View VRM dashboards and create tickets, with read-only access to most VRM data. | Organization-wide | Veracode Risk Manager subscription | VRM API (read-only) | Users with this role can only view application profiles assigned to their teams. |