Retrieves CIS benchmark rule-level details for a specific profile and resource. Shows the hierarchical rule tree (groups/subgroups/rules), scan results, and remediation fix text
get /dcapi/scap/compliance/benchmark
https://{serverurl}/dcapi/scap/compliance/benchmark
Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52
CIS profile/benchmark ID
Profile type. 1 = XCCDF, 0 = OVAL
Computer/resource ID
Collection ID of the compliance association
curl --request GET \
--url https://appdomains/dcapi/scap/compliance/benchmark \
--header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52'Scan status. SCAN_COMPLETED or YET_TO_SCAN
The queried profile ID
Constructed as policyName - profileTitle
Profile description (sanitized HTML)
SCAP standard type. XCCDF or OVAL
Built-in or Custom
Upload timestamp of the benchmark
Hierarchical tree of groups/rules with scan results
Unique identifier of the group or rule
Title of the group or rule
Item type. group or rule
Rule result status code. 0=Passed, 1=Failed, 2=Unknown, 3=Error, 4=NotApplicable, 5=Unscored, 6=Unselected, 7=Informational, 8=Fixed
Human-readable status label (e.g., Passed, Failed, Error)
CSS class for status styling
Fix text label: View Resolution, View Details, or View Reason
Child groups and rules (recursive hierarchy)
Refer to benchmarkStepItemTotal number of rules
Unauthorized error code: credentials missing, expired, or invalid
Authentication failure reason
Rate limit error code returned when the API call reached threshold
Rate limit exceeded message with retry guidance
Benchmark details with scanned rule results
{
"summary": "This profile covers Level 1 CIS benchmark rules for Windows Server 2019",
"date": "2026-01-15 10:30:00",
"scapType": "XCCDF",
"profileId": 50001,
"scanStatus": "SCAN_COMPLETED",
"source": "Built-in",
"title": "CIS Windows Server 2019 - CIS Level 1 (L1)",
"totalCount": 245,
"steps": [
{
"itemId": 1,
"children": [
{
"itemId": 101,
"cssClass": "compliance--status__passed",
"statusText": "Passed",
"fixText": "View Details",
"title": "Ensure Account lockout threshold is set to 5 or fewer",
"type": "rule",
"status": 0
},
{
"itemId": 102,
"cssClass": "compliance--status__failed",
"statusText": "Failed",
"fixText": "View Resolution",
"title": "Ensure Password length is 14 or more",
"type": "rule",
"status": 1
}
],
"title": "Account Policies",
"type": "group"
}
]
}
Benchmark details before scan has been executed
{
"summary": "This profile covers Level 1 CIS benchmark rules for Windows Server 2019",
"date": "2026-01-15 10:30:00",
"scapType": "XCCDF",
"profileId": 50001,
"scanStatus": "YET_TO_SCAN",
"source": "Built-in",
"title": "CIS Windows Server 2019 - CIS Level 1 (L1)",
"totalCount": 245,
"steps": []
}
Authentication credentials are missing or invalid
{
"errorMessage": "Authentication required",
"errorCode": "UNAUTHORIZED"
}
API call threshold exceeded
{
"errorMessage": "Rate limit exceeded. Retry after some time",
"errorCode": "TOO_MANY_REQUESTS"
}
![]()
Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.