# Initiate an on-demand compliance scan Initiates an on-demand CIS compliance scan for all resources in the specified custom group. Subject to a cooling period between consecutive scan operations. ## Endpoint `POST /dcapi/scap/compliance/initiateComplianceScan` ## Request ### Request URL https://[{serverurl}](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html)/dcapi/scap/compliance/initiateComplianceScan ### Scope `DesktopCentralCloud.VulnerabilityMgmt.CREATE` ### Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ### Query Parameters - **customGrpId** `long` *(Optional)*: The resource ID of the custom group to scan. ## Sample Request ```curl curl --request POST \ --url https://appdomains/dcapi/scap/compliance/initiateComplianceScan \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 Response body: `application/json` `JSON Object` - **status** `string`: Scan initiation status. `inProgress` on success, `failed` on failure. - **message** `string`: Human-readable status message. ### HTTP Code 401 Response body: `application/json` `JSON Object` - **errorCode** `long`: Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required). - **errorMsg** `string`: Authentication failure reason. ### HTTP Code 412 Response body: `application/json` `JSON Object` - **errorCode** `string`: Precondition failed error code. Scan is still in cooling period from a previous scan. - **errorMessage** `string`: Message indicating the remaining cooling period minutes before next scan is allowed. ### HTTP Code 429 Response body: `application/json` `JSON Object` - **errorCode** `long`: Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes. - **errorMsg** `string`: Rate limit exceeded message with retry guidance. ## Sample Responses ### HTTP 200 #### Compliance scan initiated successfully ```json { "message": "Scan initiated successfully", "status": "inProgress" } ``` #### Scan initiation failed due to authorization ```json { "message": "Not Authorised", "status": "failed" } ``` #### Scan initiation failed ```json { "message": "Scan initiation failed", "status": "failed" } ``` ### HTTP 401 #### Authentication credentials are missing or invalid ```json { "errorMessage": "Authentication required", "errorCode": "UNAUTHORIZED" } ``` ### HTTP 412 #### Scan is in cooling period from previous scan ```json { "errorMessage": "All managed system(s) are currently being scanned. Retry scanning system(s) after 5 minute(s).", "errorCode": "COMPLIANCE_SCAN_ALL_FROZEN" } ``` ### HTTP 429 #### API call threshold exceeded ```json { "errorMessage": "Rate limit exceeded. Retry after some time", "errorCode": "TOO_MANY_REQUESTS" } ``` ## Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.