# Retrieve dangerous permissions count and total extensions Retrieves a summary count of extensions with dangerous permissions and the total extensions installed across managed devices. ## Endpoints **GET** `/bsp/api/v1/bmp/permissions/summary` ## Request ### Request URL ```text https://{server-hostname}:8383/bsp/api/v1/bmp/permissions/summary ``` ### Scope ```text BrowserManager.READ ``` ### Header ```text Authorization: d92d4xxxxxxxxxxxxx15f52 ``` ### Request Parameters #### Request Headers | Name | Type | Required | Value | |---|---|---|---| | Accept | string | Mandatory | application/json | ### Sample Request ```curl curl --request GET \ --url https://appdomain/bsp/api/v1/bmp/permissions/summary \ --header 'Accept: application/json' \ --header 'Authorization: d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 #### Response Body — application/json **JSON Object** Summary of extensions with dangerous permissions. | Attribute | Type | Description | |---|---|---| | dangerous_permission | string | Count of extensions that have dangerous permissions (such as webRequest, nativeMessaging, or proxy) | | total_extensions | string | Total number of extensions installed across managed devices | ### HTTP Code 401 #### Response Body — application/json **JSON Object** | Attribute | Type | Description | |---|---|---| | errorCode | long | Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required) | | errorMsg | string | Authentication failure reason | ### HTTP Code 403 #### Response Body — application/json **JSON Object** | Attribute | Type | Description | |---|---|---| | errorCode | long | Forbidden error code returned when the authenticated user does not have the required uem-roles (e.g., DataEncryption_Admin or DataEncryptionRecoveryKey_Admin) | | errorMsg | string | Message indicating insufficient privileges to access this resource | ### HTTP Code 429 #### Response Body — application/json **JSON Object** | Attribute | Type | Description | |---|---|---| | errorCode | long | Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes | | errorMsg | string | Rate limit exceeded message with retry guidance | ### HTTP Code 500 #### Response Body — application/json **JSON Object** Returned when an unexpected server error occurs. | Attribute | Type | Description | |---|---|---| | error_description | string | Message describing the internal server error | | error_code | string | Error code identifying the type of server error | ### Possible Response Codes - `200` — HTTP code - `401` — HTTP code - `403` — HTTP code - `429` — HTTP code - `500` — HTTP code ## Sample Responses ### HTTP 200 Summary showing 12 extensions with dangerous permissions out of 150 total. ```json { "dangerous_permission": 12, "total_extensions": 150 } ``` No extensions with dangerous permissions found. ```json { "dangerous_permission": 0, "total_extensions": 45 } ``` ### HTTP 401 Authentication credentials are missing or invalid. ```json { "errorCode": "UNAUTHORIZED", "errorMsg": "You are not authorized to perform this action" } ``` ### HTTP 403 The user does not have the required permissions to perform this action. ```json { "errorCode": "FORBIDDEN", "errorMsg": "You do not have permission to access this resource" } ``` ### HTTP 429 Too many API requests have been made. ```json { "errorCode": "RATE_LIMIT_EXCEEDED", "errorMsg": "You have exceeded the maximum number of API calls. Please try again later." } ``` ### HTTP 500 An unexpected server error occurred. ```json { "error_description": "Internal Server error, Please try again in a moment.", "error_code": "COM0004" } ``` ## Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 60 | **Lock period:** 5 minutes Duration — Time window for the threshold. Threshold — Number of API calls allowed within the specified duration. Lock Period — Wait time before consecutive API requests.