canonical: https://jentic.com/apis/snyk.io/snyk-api

# Snyk API

The Snyk API is available to customers on [Business and Enterprise plans](https://snyk.io/plans) and allows you to programatically integrate with Snyk. REST API We are in the process of building a new, improved API (`https://api.snyk.io/rest`) built using the OpenAPI and JSON API standards. We welcome you to try it out as we shape and release endpoints until it, ultimately, becomes a full replacem. The API exposes 103 endpoints.

## For AI agents

Programmatically get group level audit logs, list all members in a group. Covers 103 operations.

## Scope

Does not handle payments, crm, or developer tools - use for communications only.

## Capabilities

- Get group level audit logs
- List all members in a group
- Add a member to an organization within a group
- View group settings
- Update group settings

## Use cases

### Communications Operations

Use the Snyk API to perform communications operations programmatically. The API provides 103 endpoints covering core functionality including get group level audit logs, list all members in a group, add a member to an organization within a group.

Example prompt: Call POST /group/{groupId}/audit to get group level audit logs

### Automated Users Management

Automate users operations by combining multiple Snyk API endpoints. Agents can list all members in a group and then add a member to an organization within a group in a single workflow.

Example prompt: Call GET /group/{groupId}/members to list all members in a group, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Snyk API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle none tokens manually.

Example prompt: Search Jentic for 'get group level audit logs', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | /group/{groupId}/audit | Get group level audit logs |
| GET | /group/{groupId}/members | List all members in a group |
| POST | /group/{groupId}/org/{orgId}/members | Add a member to an organization within a group |
| GET | /group/{groupId}/orgs | List all organizations in a group |
| GET | /group/{groupId}/roles | List all roles in a group |
| GET | /group/{groupId}/settings | View group settings |
| PUT | /group/{groupId}/settings | Update group settings |
| GET | /group/{groupId}/tags | List all tags in a group |

## Key resources

- **Users** — For more information users and different user types see [Snyk docs](https://docs.snyk.io/introducing
- **Groups** — Groups can contain multiple organizations, allowing you to collaborate with multiple teams. For more
- **Organizations** — For more information on organizations see [Snyk docs](https://docs.snyk.io/introducing-snyk/snyks-co
- **Integrations** — Integrations are connections to places where code lives. They can be configured from the [Integratio
- **Import Projects** — Import projects into Snyk. Projects can be Git repositories, Docker images, containers, configuratio

## Why Jentic

- **Setup:** Wiring the Snyk API by hand means attaching your Snyk token to every request, pointing at the api.snyk.io/api/v1 host, and threading the group and org ids through each call yourself. Through Jentic you install once, import the Snyk API from the API Directory, store the token once, and your agent calls it.
- **Permission scoping:** Snyk puts the group id in the URL path (/group/{groupId}/...), so a rule can pin your agent to one group: it can read members, orgs, roles, and settings there and nothing else. You choose the operations it may call, so writes like updating group settings or adding org members are not included unless you add them.
- **Credential handling:** Your Snyk API token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'get group audit logs' or 'list organizations in a group', and Jentic returns the matching Snyk API operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Twilio** — Alternative communications API
- **Sendgrid** — Alternative communications API
- **Pusher** — Complementary communications API

## FAQ

### What authentication does the Snyk API use?

The Snyk API uses no authentication. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I get group level audit logs with the Snyk API?

Yes. Use the POST /group/{groupId}/audit endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Snyk API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I get group level audit logs through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'get group level audit logs'. Jentic returns the matching Snyk API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Snyk API have?

The Snyk API exposes 103 endpoints covering users, groups, organizations operations.

### Can I limit what my agent is allowed to do with the Snyk API?

Yes. Because you run Jentic One yourself, your own rules decide which Snyk API operations and credentials the agent may use. Snyk puts the group id in the URL path, so a rule can pin the agent to a single group and let it read only members, organizations, roles, and settings there. Write operations such as updating group settings or adding a member to an organization stay off limits unless you explicitly add them.
