Skip to main content

API user roles

This section describes the predefined user roles that you can assign to API user accounts. Veracode APIs and integrations, specifically, require certain API roles. While UI users can use APIs, API users (non-human) are specifically designed for automation and use different role names.

Administrators assign roles when creating users or editing users in the Veracode Platform, or with the Identity API. If your organization uses SAML and just-in-time (JIT) provisioning, you can assign roles, including the Administrator role, automatically through SAML assertions. Users that are members of a team are limited to team-assigned resources, such as the application profile and scan results for a specific application.

Important

API users not assigned to a team have no team restrictions and can access all resources across the entire organization. This is the opposite of UI users, who, by default, can't access any resources unless they're members of a team, or an Administrator has granted them organization-wide permissions.

If you want to limit an API user's access to specific teams, you must explicitly assign the user to one or more teams when creating or editing their account. API users assigned to teams can only access resources assigned to those teams.

Some API roles support scan type restrictions when assigning permissions. You can restrict the following roles to specific scan types (SAST, DAST, SCA, Container, IaC):

When a role is restricted to specific scan types, the user can only perform create and submit actions for those scan types through the API.

Before creating and assigning user roles, we recommend reviewing User roles assignment planning.

note

In the tables in this section, the Scope column indicates the breadth of access granted by each role:

  • Organization-wide — Grants access to organizational settings and resources across all teams.
  • Team-level — Grants access only to resources assigned to the user's teams. For most roles, visibility is limited to application profiles assigned to the user's teams. To grant a user visibility across all application profiles without team assignments, you must assign the No Team Restrictions (noteamrestrictionapi) role.
  • Individual — Grants access to user-specific features or settings.

Admin API​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • Create user accounts
  • Access the Admin API
  • Delete teams
  • Create a curriculum
  • View the application portfolio
  • Edit organizations
  • Create, edit, and delete business units
  • Manage account level eLearning
  • Assign application profiles to any teams
  • Create and edit teams
  • Edit and delete users
Manage users, teams, organizations, and business units programmatically.Organization-wideBase Veracode Platform subscriptionAdmin API, Identity API
  • Can't submit scans
  • Can't be combined with the Team Admin UI user role.
  • To view scan results, combine with the Results API role.
  • Includes the ignoreTeamRestrictions permission that grants this role organization-wide access (manage users, teams, and configurations) regardless of team membership.
  • If the visibility for an application profile is set to Teams & Security Leads, before a user can access the application profile using the Veracode APIs, their user account must have a role for creating and submitting scans, or reviewing results, such as the Upload and Scan API role, and be a member of a team assigned to the application profile.
  • If you intend to use the Identity API to create a new user account, you must pass the role properties.

Archer Report API​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • Run and view Archer reports
Generate and retrieve Archer reports programmatically.Organization-wideVeracode for Archer GRC integration licenseArcher Report APIMust be combined with the Submitter UI user role.

Greenlight API User​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • Submit code for Greenlight scans
  • Review Greenlight scan results
Submit Greenlight scans and retrieve results with the Greenlight API.Team-levelVeracode Greenlight subscriptionGreenlight APIVeracode Greenlight is deprecated. We recommend using the Veracode Scan IDE plugins with the required roles.

Mitigation API​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • View and update results
  • Approve or reject proposed mitigations
Manage and approve finding mitigations programmatically.Team-levelVeracode Static Analysis or Veracode DAST subscriptionResults API, Mitigation API
  • Permissions to approve or reject mitigations are governed by the user's scan type permissions (e.g. SAST, DAST, SCA).
  • To view findings or update their status, must be combined with the Reviwer or Security Lead UI role.

No Team Restrictions​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • Access to all application profiles and resources
Grant API users access to all application profiles and resources across the organization without team assignment restrictions, including overriding team restrictions.Organization-wideBase Veracode Platform subscriptionAll APIs
  • Must be combined with other functional roles, such as Results API to view data.
  • Can be combined with other API roles to remove team restrictions for that role's permissions.

Reporting API User​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • Generate reports
  • View reports and analytics
Generate and retrieve security reports and analytics.Organization-wideBase Veracode Platform subscriptionReporting API
  • Must be combined with the Security Lead, Executive, or Security Insights UI user roles.
  • This role is for data extraction and analytics. It can't submit scans or manage application profiles.

Results API​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • View scan results and reports
  • Export custom data
  • View the list of sandboxes
  • Access the Results API
  • Download build and scan results data, and summary and detailed reports
Query scan results, download reports, and export data.Team-levelVeracode Static Analysis, Veracode SCA, or Veracode DAST subscriptionResults APICan't upload files or start scans. This role is strictly "read-only" for retrieving results, reports, and sandbox lists.

Upload and Scan API​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • Create, edit, and delete application profiles
  • Enable application profiles for next day consultations
  • Create and delete policy scans
  • Create and delete sandbox scans
  • Manage security policies
  • Create, delete, and view sandboxes for an application profile
  • Submit pipeline scans
  • Use the Dynamic Analysis REST API
  • Use Veracode Fix
Manage application profiles, submit scans, manage policies, and perform full scanning workflows.Team-levelVeracode Static Analysis, Veracode SCA, or Veracode DAST subscriptionUpload API, Upload and Scan API, Dynamic Analysis API
  • Compared to the Upload API - Submit Only role, this role can create application profiles and sandboxes.
  • Requires atleast one scan type role (e.g., apisubmitstaticscan, apisubmitdynamicscan) that grants permission to use one or more scan types (e.g., SAST, DAST, SCA).
  • Can use all scan types or be restricted to only specific scan types. This restriction limits the scope of policy and scan management for that user.
  • Required for creating application profiles using Veracode Static for Visual Studio and to create sandboxes using the Veracode Jenkins Plugin.

Upload API - Submit Only​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • Create a new build for an existing application profile, but can't create application profiles
  • Upload files to a build
  • Begin prescan
  • Check prescan status
  • Submit scans
  • Create and delete policy scans
  • Create and delete sandbox scans
  • View the list of sandboxes, but can't create sandboxes
  • Submit pipeline scans
  • Use Veracode Fix
Submit scans for existing applications only; upload binaries and trigger scanning.Team-levelVeracode Static Analysis, Veracode SCA, or Veracode DAST subscriptionUpload API (Submit only)
  • Requires atleast one scan type role (e.g., apisubmitstaticscan, apisubmitdynamicscan) that grants permission to use a one or more scan types (e.g., SAST, DAST, SCA).
  • Can use all scan types or be restricted to only specific scan types. This restriction limits the scope of policy and scan management for that user.

VRM Agent Service Writer​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
Provision VRM runtime agentsDeploy and manage Veracode Risk Manager agents.Organization-wideVeracode Risk Manager subscriptionVRM APIWe recommend assigning this role to a dedicated API user account for the runtime agent, instead of using the default token from VRM. This ensures the runtime agent follows the principle of least privilege.

VRM API Admin​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • Create, read, update, and delete VRM dashboards
  • Create, read, update, and delete VRM connectors
  • Create tickets in VRM
Manage VRM dashboards, connectors, and issue tickets.Organization-wideVeracode Risk Manager subscriptionVRM APIUsers with this role can access resources across the entire organization without team assignment restrictions.

VRM API Guest​

PermissionsUse caseScopeLicensingAPI endpointsImportant notes
  • Read VRM dashboards
  • Read VRM connectors
  • Create tickets from the Issues and Solutions pages in VRM
View VRM dashboards and create tickets, with read-only access to most VRM data.Organization-wideVeracode Risk Manager subscriptionVRM API (read-only)Users with this role can only view application profiles assigned to their teams.