Retrieves the compliance overview of a browser across managed devices against the specified compliance profile, including vulnerability counts and the average security score.
https://{server-hostname}:8383/bsp/api/v1/bmp/browsers/{browser_id}/compliance/{compliance_id}
BrowserManager.READCopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
Browser type ID from List Browsers response (browser_type field)
Compliance profile ID from List Compliance Profiles response (profileid field)
curl --request GET \
--url https://appdomain/bsp/api/v1/bmp/browsers/{browser_id}/compliance/{compliance_id} \
--header 'Accept: application/json' \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52'Count of very high vulnerability severity rules
Count of high vulnerability severity rules
Count of low risk rules
Count of rules in secure state
Total compliant rules
Total non-compliant rules
Average security score percentage
Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required)
Authentication failure reason
Forbidden error code returned when the authenticated user does not have the required uem-roles (e.g., DataEncryption_Admin or DataEncryptionRecoveryKey_Admin)
Message indicating insufficient privileges to access this resource
Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes
Rate limit exceeded message with retry guidance
Message describing the server-side failure
Internal server error code
Compliance overview filtered by the specified profile
{
"noncompliant": 11,
"HighVul": 8,
"LowRisk": 20,
"secure_avg": 92.3,
"Secure": 169,
"compliant": 189,
"VeryHighVul": 3
}
No applicable rules for the browser under this profile
{}
Unauthorized
{
"errorCode": "UNAUTHORIZED",
"errorMsg": "You are not authorized to perform this action"
}
Forbidden
{
"errorCode": "FORBIDDEN",
"errorMsg": "User does not have permission to perform this operation"
}
Rate limit exceeded
{
"errorCode": "RATE_LIMIT_EXCEEDED",
"errorMsg": "Too many requests. Please try again after 5 minutes"
}
Server error
{
"error_description": "Internal Server error, Please try again in a moment.",
"error_code": "COM0004"
}
![]()
Duration: 1 minute | Threshold: 60 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.