# Fetch compliance graph data aggregated across a custom group Retrieves compliance graph data aggregated across all resources in a custom group, showing the overall compliance posture of the entire group. ## Endpoints `GET /dcapi/scap/compliance/result/CGGraph` ## Request URL https://[*{serverurl}*](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html)/dcapi/scap/compliance/result/CGGraph ## Scope `DesktopCentralCloud.VulnerabilityMgmt.READ` ### Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Query Parameters - **groupResourceId** `long` (Optional): Custom group resource ID ## Sample Request ### Curl ```curl curl --request GET \ --url https://appdomains/dcapi/scap/compliance/result/CGGraph \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 Response Body — `application/json` `JSON Object` - **scan** `string`: Overall scan status. SCAN_COMPLETED - **status** `JSON Object`: Compliance status breakdown for the custom group ### HTTP Code 401 Response Body — `application/json` `JSON Object` - **errorCode** `long`: Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required) - **errorMsg** `string`: Authentication failure reason ### HTTP Code 429 Response Body — `application/json` `JSON Object` - **errorCode** `long`: Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes - **errorMsg** `string`: Rate limit exceeded message with retry guidance ## Possible Response Codes - **200** `HTTP code` - **401** `HTTP code` - **429** `HTTP code` ## Sample Response: HTTP 200 Custom group compliance graph data ```json { "scan": "SCAN_COMPLETED", "status": { "percentage": 80, "breakdown": { "vulnerable": 3, "decreasedCompliance": 2, "increasedCompliance": 8, "secure": 15 }, "attention": 5, "deployed": 25 } } ``` ## Sample Response: HTTP 401 Authentication credentials are missing or invalid ```json { "errorMessage": "Authentication required", "errorCode": "UNAUTHORIZED" } ``` ## Sample Response: HTTP 429 API call threshold exceeded ```json { "errorMessage": "Rate limit exceeded. Retry after some time", "errorCode": "TOO_MANY_REQUESTS" } ``` ## API Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.