# Fetch available CIS benchmark profiles for a platform Retrieves all available CIS benchmark profiles for a given platform. Used when creating or editing a policy group to show the available profiles that can be selected. ## Endpoint `GET /dcapi/scap/compliance/policygroups/profilesList` ## Request ### Request URL `https://{server-hostname}:8383/dcapi/scap/compliance/policygroups/profilesList` ### Scope `VulnerabilityMgmt.READ` ### Header `Authorization: d92d4xxxxxxxxxxxxx15f52` ### Sample Request ```curl curl --request GET \ --url https://appdomain/dcapi/scap/compliance/policygroups/profilesList \ --header 'Authorization: d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 Response Body — `application/json` - JSON object ### HTTP Code 401 Response Body — `application/json` - JSON object - **errorCode**: `long` — Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required) - **errorMsg**: `string` — Authentication failure reason ### HTTP Code 429 Response Body — `application/json` - JSON object - **errorCode**: `long` — Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes - **errorMsg**: `string` — Rate limit exceeded message with retry guidance ## Possible Response Codes - **200**: HTTP code - **401**: HTTP code - **429**: HTTP code ## Sample Responses ### HTTP 200 Map of profileId to profileType for Windows platform ```json { "50001": 1, "50002": 1, "50003": 0, "50004": 1 } ``` ### HTTP 401 Authentication credentials are missing or invalid ```json { "errorMessage": "Authentication required", "errorCode": "UNAUTHORIZED" } ``` ### HTTP 429 API call threshold exceeded ```json { "errorMessage": "Rate limit exceeded. Retry after some time", "errorCode": "TOO_MANY_REQUESTS" } ``` ## API Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration — Time window for the threshold. Threshold — Number of API calls allowed within the specified duration. Lock Period — Wait time before consecutive API requests.