External user certs info¶
GET/
Email Management API · SMIME
Get information about external users with S/MIME certificates.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
email | query | string (email) | No | Filter by exact email address. Must be 3–255 characters long. |
emailStartsWith | query | string | No | Filter by email addresses that start with this prefix. Must be 3–255 characters long. |
certValidBefore | query | string (date) | No | Returns certificates that activate on or before this date. |
certValidAfter | query | string (date) | No | Returns certificates that activate on or after this date. |
certExpiryBefore | query | string (date) | No | Returns certificates that expire on or before this date. |
certExpiryAfter | query | string (date) | No | Returns certificates that expire on or after this date. |
certFingerprint | query | string | No | SHA-256 fingerprint of the certificate. This is not case sensitive. Must match the pattern ^[a-fA-F0-9]{64}$. Must be exactly 64 characters long. |
issuerCN | query | string | No | Filter by certificate issuer common name containing this text. Must be 3–255 characters long. |
pageFromKey | query | string | No | The key of the item from where to fetch a page. |
pageSize | query | integer | No | The size of the page requested. |
Request samples¶
curl -X GET "https://api-<data-region>.central.sophos.com/email/v1/smime/users/external" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"
import requests
response = requests.get(
"https://api-<data-region>.central.sophos.com/email/v1/smime/users/external",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/email/v1/smime/users/external" -Headers $headers
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/email/v1/smime/users/external", nil)
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/email/v1/smime/users/external", {
method: "GET",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
});
const data = await response.json();
console.log(data);
Responses¶
200 — List of external users with their associated certificates.¶
Response fields
itemsarray of objectrequiredList of external users with certificate information.
External user with associated certificate information.
Show child attributesHide child attributes
emailstring (email)requiredEmail address of the user.
Must be 3–255 characters long.
Must be 3–255 characters long.
associatedCertificatesInfoarray of objectrequiredList of certificates associated with the user.
Information about certificates associated with a user.
Show child attributesHide child attributes
fingerprintstringrequiredSHA-256 fingerprint of the certificate.
Must match the pattern
Must match the pattern
^[a-fA-F0-9]{64}$. Must be exactly 64 characters long.certificateDetailsobjectrequiredDetailed information about a certificate.
Show child attributesHide child attributes
issuerstringrequiredCertificate issuer distinguished name.
Must be at most 255 characters long.
Must be at most 255 characters long.
validFromstring (date-time)requiredCertificate validity start date.
expiresAtstring (date-time)requiredCertificate validity end date.
originstringrequiredIndicates how the certificate was obtained.
Must be one of:
Must be one of:
created, uploaded, extracted, unknown.pagesobjectrequiredShow child attributesHide child attributes
fromKeystringThe key of the first item in the returned page.
nextKeystringThe key to use when fetching the next page.
sizeintegerrequiredThe size of the page being returned.
maxSizeintegerrequiredThe maximum page size that can be requested.
Errors¶
| Status | Meaning |
|---|---|
400 | Invalid request. |
401 | Authentication required. |
403 | Authorization required. |
500 | Internal server error. |
503 | Server Unavailable. |
All error responses share the same shape — see the error response object.
Response examples¶
200¶
{
"items": [
{
"email": "john.doe@sophos.com",
"associatedCertificatesInfo": [
{
"fingerprint": "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2",
"certificateDetails": {
"issuer": "C=UK,O=Sophos Limited,CN=Sophos Root CA",
"validFrom": "2024-12-31T14:25:09Z",
"expiresAt": "2029-12-31T18:30:12Z",
"origin": "created"
}
}
]
}
],
"pages": {
"fromKey": "string",
"nextKey": "string",
"size": 0,
"maxSize": 0
}
}
See the guide for a narrative walkthrough of this API.