> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truu.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List NHI identities

> Fleet directory over `nhi_profiles`. An identity appears whether or not
Persona L has run. Same API key as the rest of the external API.




## OpenAPI

````yaml https://eris.platform.total.truu.ai/api/v1/external/docs get /nhi/personas
openapi: 3.0.3
info:
  title: TOTAL Public API
  version: 2.5.0
  description: >
    The TOTAL API gives you programmatic access to your organization's

    security data. Use it to query cases, threat events, personas, and

    non-human identities, and to feed verdicts back into the platform.


    ## Authentication


    All routes in this specification are served under `/api/v1/external` and

    require a domain-scoped API key via the `X-API-Key` header. Generate and

    manage keys from the API Keys page in Settings.


    The admin console (Atlas) uses separate JWT-authenticated routes under

    `/api/v1/eris/...` (for example `GET /api/v1/eris/integrations`); those are

    not part of this public API surface.


    ## Pagination

    List routes use cursor pagination: `page_size` (default 50, max 200) and

    optional `next_cursor` (pass the `case_id` or `event_id` UUID from the last

    item of the previous page). Responses include `next_cursor` when more

    results are available.


    ## Rate Limits

    Read endpoints in this API are limited to 1,000 requests/minute.

    Write endpoints in this API are limited to 200 requests/minute.


    ## Availability

    Some routes may return `423 Locked` when the requested data is not yet

    available for your domain.


    ---


    ## Appendix A — Azure Log Analytics: source_event_ids → KQL lookup


    Threat events include a `source_event_ids` array. Each value is the

    `_ItemId` of the originating row in your Azure Log Analytics workspace

    — the per-row GUID stamped by Log Analytics at ingest. It is row-unique

    on every supported table, so the same lookup pattern works regardless

    of source:

        <SourceTable> | where _ItemId == "<id>"

    Run the lookup against your Log Analytics workspace (the same workspace

    that backs Azure Log Analytics / Defender XDR Advanced Hunting). Use the

    `source` field on the event to pick the table.


    | Source table | KQL field | Example KQL |

    |---|---|---|

    | SigninLogs | _ItemId | `SigninLogs | where _ItemId == "<id>"` |

    | AuditLogs | _ItemId | `AuditLogs | where _ItemId == "<id>"` |

    | AADUserRiskEvents | _ItemId | `AADUserRiskEvents | where _ItemId ==
    "<id>"` |

    | CloudAppEvents | _ItemId | `CloudAppEvents | where _ItemId == "<id>"` |

    | OfficeActivity | _ItemId | `OfficeActivity | where _ItemId == "<id>"` |

    | EmailEvents | _ItemId | `EmailEvents | where _ItemId == "<id>"` |

    | EmailPostDeliveryEvents | _ItemId | `EmailPostDeliveryEvents | where
    _ItemId == "<id>"` |

    | EmailUrlInfo | _ItemId | `EmailUrlInfo | where _ItemId == "<id>"` |

    | EmailAttachmentInfo | _ItemId | `EmailAttachmentInfo | where _ItemId ==
    "<id>"` |

    | UrlClickEvents | _ItemId | `UrlClickEvents | where _ItemId == "<id>"` |

    | SecurityEvent | _ItemId | `SecurityEvent | where _ItemId == "<id>"` |

    | IdentityLogonEvents | _ItemId | `IdentityLogonEvents | where _ItemId ==
    "<id>"` |

    | IdentityQueryEvents | _ItemId | `IdentityQueryEvents | where _ItemId ==
    "<id>"` |

    | IdentityDirectoryEvents | _ItemId | `IdentityDirectoryEvents | where
    _ItemId == "<id>"` |

    | BehaviorAnalytics | _ItemId | `BehaviorAnalytics | where _ItemId ==
    "<id>"` |

    | Anomalies | _ItemId | `Anomalies | where _ItemId == "<id>"` |

    | AzureActivity | _ItemId | `AzureActivity | where _ItemId == "<id>"` |

    | MicrosoftPurviewInformationProtection | _ItemId |
    `MicrosoftPurviewInformationProtection | where _ItemId == "<id>"` |

    | CommonSecurityLog | _ItemId | `CommonSecurityLog | where _ItemId ==
    "<id>"` |

    | Syslog | _ItemId | `Syslog | where _ItemId == "<id>"` |

    | AADProvisioningLogs | _ItemId | `AADProvisioningLogs | where _ItemId ==
    "<id>"` |
servers:
  - url: https://eris.platform.total.truu.ai/api/v1/external
    description: TOTAL Public API
security:
  - ApiKeyAuth: []
tags:
  - name: Cases
    description: Threat investigation cases and verdicts
  - name: Users
    description: Provisioned users and monitoring
  - name: Personas
    description: Persona overviews
  - name: Threats
    description: Raw threat events
  - name: NHI
    description: Non-human identity personas and cluster catalogue
paths:
  /nhi/personas:
    get:
      tags:
        - NHI
      summary: List NHI identities
      description: |
        Fleet directory over `nhi_profiles`. An identity appears whether or not
        Persona L has run. Same API key as the rest of the external API.
      operationId: listNhiPersonas
      parameters:
        - name: search
          in: query
          schema:
            type: string
          description: Filter by display name, principal id, or app id.
        - name: nhi_class
          in: query
          schema:
            type: string
          description: Comma-separated identity classes.
        - name: archetype
          in: query
          schema:
            type: string
        - name: provider
          in: query
          schema:
            type: string
          description: Comma-separated platform family keys or labels.
        - name: status
          in: query
          schema:
            type: string
            enum:
              - active
              - dormant
              - all
            default: active
        - name: has_persona
          in: query
          schema:
            type: boolean
          description: >-
            When true, only identities with a Persona L row. When false, only
            the rest of the fleet.
        - name: page_size
          in: query
          schema:
            type: integer
            default: 50
            maximum: 200
        - name: next_cursor
          in: query
          schema:
            type: string
            format: uuid
          description: '`nuid` of the last item from the previous page.'
      responses:
        '200':
          description: Paginated NHI directory rows
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/CursorPage'
                  - type: object
                    properties:
                      items:
                        type: array
                        items:
                          $ref: '#/components/schemas/NhiPersonaListItem'
        '401':
          description: Invalid or inactive API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '423':
          description: Resource not ready yet for this domain
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResourceNotReady'
components:
  schemas:
    CursorPage:
      type: object
      properties:
        next_cursor:
          type: string
          nullable: true
    NhiPersonaListItem:
      type: object
      properties:
        nuid:
          type: string
          format: uuid
        display_name:
          type: string
          nullable: true
        nhi_class:
          type: string
        nhi_class_label:
          type: string
          nullable: true
        identity_type:
          type: object
          nullable: true
          properties:
            id:
              type: string
            label:
              type: string
        archetype:
          type: string
          nullable: true
        archetype_label:
          type: string
          nullable: true
        provider:
          type: object
          properties:
            key:
              type: string
            label:
              type: string
        status:
          type: string
          enum:
            - active
            - dormant
        has_persona:
          type: boolean
        steward_upn:
          type: string
          nullable: true
        first_seen:
          type: string
          format: date-time
          nullable: true
        last_seen:
          type: string
          format: date-time
          nullable: true
    Error:
      type: object
      properties:
        error:
          type: string
    ResourceNotReady:
      type: object
      properties:
        error:
          type: string
          description: Always `resource_not_ready`
        resource:
          type: string
          description: One of `cases`, `threats`, `personas`, `nhi`, `nhi-clusters`
        message:
          type: string
          description: Human-readable readiness status message
        details:
          type: string
          description: Resource-specific not-ready detail
        days_until_ready:
          type: number
          format: float
          description: Days remaining until the resource is available
        external_api_enabled_at_utc:
          type: string
          format: date-time
        now_utc:
          type: string
          format: date-time
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: |
        Domain-scoped API key. Generate and manage keys from the API Keys
        page in Settings.

        Accepted in two forms:
        - `X-API-Key: <key>` header (preferred)
        - `Authorization: Bearer <key>` header (also accepted)

````