Retrieves compliance graph data for a specific profile on a specific resource, showing the pass/fail breakdown for that profile's rules
https://{server-hostname}:8383/dcapi/scap/compliance/result/profilesGraph/{resourceId}
VulnerabilityMgmt.READCopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
Computer/resource ID. Fetch from Get CG Association Details
curl --request GET \
--url https://appdomain/dcapi/scap/compliance/result/profilesGraph/{resourceId} \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52'Scan status. SCAN_COMPLETED or YET_TO_SCAN
Results summary, e.g., 200/245 Rules Passed or NA
Compliance status breakdown for the profile
Number of failed rules
Total rules in the profile
Pass percentage or NA
Detailed rule breakdown
Rules passed
Rules failed
Rules in error
Unscored rules
Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required)
Authentication failure reason
Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes
Rate limit exceeded message with retry guidance
Profile graph data after scan completion
{
"result": "200/245 Rules Passed",
"scan": "SCAN_COMPLETED",
"status": {
"percentage": "82",
"breakdown": {
"unscored": 15,
"passed": 200,
"failed": 25,
"error": 5
},
"attention": 25,
"totalRules": 245
}
}
Profile graph data before scan
{
"result": "NA",
"scan": "YET_TO_SCAN",
"status": {
"percentage": "NA",
"breakdown": {
"unscored": 245,
"passed": 0,
"failed": 0,
"error": 0
},
"attention": 0,
"totalRules": 245
}
}
Authentication credentials are missing or invalid
{
"errorMessage": "Authentication required",
"errorCode": "UNAUTHORIZED"
}
API call threshold exceeded
{
"errorMessage": "Rate limit exceeded. Retry after some time",
"errorCode": "TOO_MANY_REQUESTS"
}
![]()
Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.