Generate a new access token using the provided refresh token.
Access Management
SCA API
Entities - Project
Policies - Project
CustomAttribute - Project
Alerts - Project
project-attribution-report-controller
Policies - Product
CustomAttribute - Product
Entities - Product
Settings - Whitelist
Settings - In-House
Policies - Organization
CustomAttribute - Organization
User Management - Groups
Entities - Organization
User Profile
Library - Product
User Management - Users
Update Request
Library - Organization
Access Management - Organizations
General Info - Vulnerabilities
Library - Source Files
User Management - Roles And Permissions
Library - Project
Alerts - Product
General Info - Permissions
Vulnerable Libraries
Summary - Organization
Asynchronous Process Control
domain-controller
General Info - Licenses
product-attribution-report-controller
Mend SCA API (2.0)
Mend's enhanced SCA API enables automation of workflows in a REST compliant format. The API features:
- Access for any user with Mend credentials, via a user key available in the user's profile page in the Mend App.
- Improved security with a JWT token per organization, which expires every 30 minutes.
- Added scalability with support for pagination, filtering and sorting search results.
- Broader functionality available programmatically.
- New standard API documentation for easy navigation and search.
If you have a dedicated instance of Mend, contact your Mend representative to access this API on your instance.
- Generated server urlhttps://api-saas.mend.io/api/v2.0/login/accessToken
- Payload
- cURL
- JS
- Go
- Ruby
- Java 8
No request payloadResponse
application/json
{ "correlationId": "string", "userUuid": "string", "userName": "string", "email": "string", "refreshToken": "string", "jwtToken": "string", "orgName": "Organization A", "orgUuid": "123e4567-e89b-12d3-a456-426655440000" }
Bodyapplication/jsonrequired
org UUID (by running Entities - Organization > Get User Organizations) or API Key (from the Mend SCA App: Integrate tab > API Key).
Example: "123e4567-e89b-12d3-a456-426655440000"
Equivalent to a personal access token. Avoid pasting as plain text where it might be compromised. For a service user (recommended), you can find the user key in the Mend SCA App in Admin > Users. Learn more. For local testing purposes, you could also use one of your own personal user keys from your user profile page in the Mend SCA App.
Example: "***********"
- Generated server urlhttps://api-saas.mend.io/api/v2.0/login
- Payload
- cURL
- JS
- Go
- Ruby
- Java 8
application/json
{ "email": "jon.smith@mail.com", "orgToken": "123e4567-e89b-12d3-a456-426655440000", "userKey": "***********" }
Response
application/json
{ "supportToken": "1171c60d", "retVal": { "correlationId": "string", "userUuid": "string", "userName": "string", "email": "string", "refreshToken": "string", "jwtToken": "string", "orgName": "Organization A", "orgUuid": "123e4567-e89b-12d3-a456-426655440000" } }